WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

South Korea Privacy & Data Protection Laws

Every regime below can apply to a business handling South Korea residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

September 30, 2011 (original); current version in force since September 15, 2023
Personal Information Protection Act
PIPA
Verify details

PIPA has no express extraterritoriality clause. The Personal Information Protection Commission's Guidelines on Applying PIPA to Foreign Business Operators (Apr 2024) apply the law to foreign operators that provide goods/services to Korean data subjects, process data in a way that directly and substantially affects them (a broad test reaching monitoring/profiling activity), or maintain a place of business in Korea. Art. 58(1) excludes press, missionary/religious, and political-party candidate-nomination processing from most obligations. No general small-business, nonprofit, or sector-specific exemption. The PIPC has been among the most active enforcers in Asia against foreign platforms, with turnover-linked fines and a domestic-representative requirement for qualifying overseas operators.

Act No. 10465 (2011), as amended by Act No. 19234 (effective Sep 15, 2023); exclusions: Art. 58(1); territorial scope via PIPC interpretive guidelinesRead regulation →

Sector-Specific Law · 1

1995; the pseudonymised-data and MyData amendments in force from August 5, 2020
Act on the Use and Protection of Credit Information
Korea Credit Information Act
Verify details

For financial institutions and credit information companies operating in Korea, the Credit Information Act — not PIPA — is usually the operative statute for personal credit information, and it generally takes precedence where the two overlap. The January 2020 amendment package (passed alongside amendments to PIPA and the Network Act) did two things that still shape the market. It introduced 'pseudonymised data' as a legal category that may be used for statistical, research and public-interest purposes without the data subject's consent, with a designated expert institution able to certify that data has been properly pseudonymised or anonymised. And it created the licensed MyData industry — businesses authorised to aggregate an individual's financial information across institutions and provide consolidated inquiry, advice and product recommendation services. Marked 'check': the primary text is Korean-language, the licensing regime is administered by the Financial Services Commission and has evolved since 2020, and the boundary between this Act and PIPA is fact-specific.

Act on the Use and Protection of Credit Information, as amended by Act No. 16957 of February 4, 2020Read regulation →

Children & Minors Protections · 1

Korea sets its threshold at 14 and, unusually, applies it OFF-LINE as well as online. Art. 22-2 requires the controller to obtain the consent of a legal representative before processing the personal information of a child under 14, to verify that the consent is genuinely the representative's, and to give the child notice in language they can readily understand. Before the 2023 amendment the duty sat in the online-services provisions; the amendment unified it, so a business collecting children's data through offline channels no longer falls outside it. Collecting or using an under-14's personal information without the legal representative's consent is separately subject to administrative penalty.

Personal Information Protection Act, Art. 22-2 (introduced by Act No. 19234 of March 14, 2023)Read regulation →

Cross-Border Data Transfer · 1

Korea's default remained separate, specific consent to overseas transfer for years, which made it one of the harder regimes to operationalise. The 2023 amendment opened alternatives: transfer without separate consent is permitted where the overseas recipient holds a personal information protection certification recognised by the PIPC, where the PIPC has recognised the destination country as offering an equivalent level of protection, where a statute or treaty provides for the transfer, or where the transfer is necessary to outsource or store personal information for performance of a contract with the data subject and the data subject is notified through the privacy policy or another prescribed method. The PIPC can also order a transfer suspended. Note the practical asymmetry: the consent-free routes depend on recognitions the PIPC grants, so their availability changes over time and should be checked rather than assumed.

Personal Information Protection Act, Art. 28-8 (as amended by Act No. 19234 of March 14, 2023)Read regulation →

Data Security & Breach Notification · 1

September 30, 2011 (Art. 34); current unified 72-hour regime from the amendment in force September 15, 2023
Personal Information Protection Act — notification and reporting of personal data leakage
PIPA Art. 34

Controllers must notify affected data subjects without delay on becoming aware of a leak, and must report to the PIPC (or KISA) within 72 hours where the incident meets any of the Enforcement Decree Art. 40 thresholds: 1,000 or more data subjects affected, sensitive or uniquely identifying information involved, or the leak resulted from unauthorized external access to the processing system. Note that Korea's thresholds are cumulative alternatives, not a risk test — the 1,000-record and external-intrusion limbs bite regardless of whether harm is likely, which makes Korea more reportable than the GDPR for routine intrusions. Failure to notify or report within 72 hours is separately fineable. Korea's 2023 amendment unified what had been split online/offline regimes; a 'potential leak' notification concept has since been developed by the PIPC, which a reviewer should check for current status before finalizing an incident-response runbook.

Act No. 10465, Art. 34; PIPA Enforcement Decree, Art. 40Read regulation →

Other Asia-Pacific jurisdictions