WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Personal Information Protection Act — notification and reporting of personal data leakage

PIPA Art. 34

South Korea · September 30, 2011 (Art. 34); current unified 72-hour regime from the amendment in force September 15, 2023

Controllers must notify affected data subjects without delay on becoming aware of a leak, and must report to the PIPC (or KISA) within 72 hours where the incident meets any of the Enforcement Decree Art. 40 thresholds: 1,000 or more data subjects affected, sensitive or uniquely identifying information involved, or the leak resulted from unauthorized external access to the processing system. Note that Korea's thresholds are cumulative alternatives, not a risk test — the 1,000-record and external-intrusion limbs bite regardless of whether harm is likely, which makes Korea more reportable than the GDPR for routine intrusions. Failure to notify or report within 72 hours is separately fineable. Korea's 2023 amendment unified what had been split online/offline regimes; a 'potential leak' notification concept has since been developed by the PIPC, which a reviewer should check for current status before finalizing an incident-response runbook.

Act No. 10465, Art. 34; PIPA Enforcement Decree, Art. 40Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.