WorldPrivacyAtlasInternational Privacy & Data Protection Law Matcher

Jurisdiction Guide

South Korea Privacy & Data Protection Laws

Every regime below can apply to a business handling South Korea residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

September 30, 2011 (original); current version in force since September 15, 2023
Personal Information Protection Act
PIPA
Verify details

PIPA has no express extraterritoriality clause. The Personal Information Protection Commission's Guidelines on Applying PIPA to Foreign Business Operators (Apr 2024) apply the law to foreign operators that provide goods/services to Korean data subjects, process data in a way that directly and substantially affects them (a broad test reaching monitoring/profiling activity), or maintain a place of business in Korea. Art. 58(1) excludes press, missionary/religious, and political-party candidate-nomination processing from most obligations. No general small-business, nonprofit, or sector-specific exemption.

Act No. 10465 (2011), as amended by Act No. 19234 (effective Sep 15, 2023); exclusions: Art. 58(1); territorial scope via PIPC interpretive guidelinesRead regulation →