Doing Business In..._2026

SOUTH KOREA Law and Practice Contributed by: Heejun Choi, Kyoung-Ho Kim, Sungsok Yang, Eunjee Kim and Kwang-Chun Park, Dentons Lee

that violate PIPA or pose a significant risk to data sub - jects. Korea has received an EU adequacy decision and participates in the APEC Cross-Border Privacy Rules framework. Accordingly, the Korean data protection law has a practical extraterritorial effect where foreign compa - nies process Korean users’ personal information or target the Korean market, while cross-border transfers remain subject to specific statutory requirements. 8.3 Role and Authority of the Data Protection Agency The principal data protection regulator in Korea is the Personal Information Protection Commission (“PIPC”). The PIPC is an independent central administrative agency established under the Personal Information Protection Act (“PIPA”), responsible for formulating, supervising and enforcing Korea’s data protection framework. Its principal functions include: • establishing national data protection policy; • issuing guidance and interpreting PIPA; • supervising compliance by public and private sec - tor data controllers; • investigating suspected violations and data breaches; • overseeing cross-border transfers; • operating dispute resolution mechanisms; and • promoting international cooperation on data pro - tection. The PIPC has broad investigative and enforcement powers, including requesting information, conduct - ing inspections ordering remedial measures, imposing administrative fines and penalty surcharges, making criminal referrals, publishing enforcement outcomes where permitted by law and suspending overseas data transfers that violate PIPA or pose significant risks to data subjects. The PIPC also oversees public-sector personal infor - mation files, privacy impact assessments, privacy

certification systems and the personal information dispute mediation framework. Although the PIPC is the principal privacy regulator, sector-specific regulators may also have jurisdiction, including financial regulators for credit information and communications authorities for network security. Accordingly, the PIPC serves as Korea’s central data protection authority, exercising broad policy-mak - ing and enforcement powers, including oversight of cross-border data transfers. No single omnibus reform is expected to overhaul the Korean legal system. However, several areas remain subject to active legislative and regulatory develop - ment. In technology and data, the most significant develop - ment is the implementation of Korea’s AI regulatory framework. The AI Basic Act establishes a general framework for AI governance, including obligations related to high-impact AI, transparency, safety and reliability, with implications for data protection, con - sumer protection, employment, financial services and technology compliance. 9. Looking Forward 9.1 Upcoming Legal Reforms Data protection law also continues to evolve. Amend - ments to the Personal Information Protection Act focus on governance, security, cross-border trans - fers, automated decision-making and privacy offic - ers, while enforcement by the Personal Information Protection Commission is becoming more active. Corporate law reforms continue to focus on directors’ duties, shareholder protection, virtual shareholders’ meetings and corporate governance. In tax, Korea has implemented the OECD Pillar Two framework, includ - ing the Income Inclusion Rule and domestic minimum top-up tax, with further technical guidance expected. Competition law reforms continue to focus on digi - tal platforms, online marketplaces, merger control in data-driven markets and stronger enforcement by the

982 CHAMBERS.COM

Powered by