Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

Lee & Ko Hanjin Building 63 Namdaemun-ro Jung-gu Seoul 04532 South Korea Tel: +82 2 772 4000 Fax: +82 2 7724 0012 Email: mail@leeko.com Web: www.leeko.com

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy National Cybersecurity Strategy and National Cybersecurity Basic Plan The South Korean (“Korean”) government has estab - lished the National Cybersecurity Strategy and its corresponding National Cybersecurity Basic Plan to ensure comprehensive implementation, both of which underwent revisions in 2024. The updated Strategy delineates five core objectives: • bolstering offensive cyber defence capabilities; • forging a robust global cyber co-operation frame - work; • fortifying the cyber resilience of critical national infrastructure; • securing a competitive edge in emerging technolo - gies; and • reinforcing the operational foundation for these tasks. Complementing this, the Basic Plan prescribes 100 actionable initiatives for various government ministries to systematically execute the Strategy. Cybersecurity-Related Laws and Enactment of New Laws The cybersecurity regulatory framework of South Korea (“Korea”) comprises a complex patchwork of sector-specific legislation. Notably, the Act on Pro - motion of Information and Communications Network

Utilization and Information Protection, etc. (the “Net - work Act”) predominantly governs the information and communications sector; the Personal Informa - tion Protection Act (PIPA) regulates the protection of personal information; the Electronic Financial Trans - actions Act (EFTA) covers the financial sector; the Act on the Protection of Information and Communications Infrastructure safeguards critical infrastructure; and the Cyber Security Work Regulations (the “Cyberse - curity Regulations”) of the National Intelligence Ser - vice (NIS) dictate standards for the public sector. For private enterprises, the Network Act, PIPA and the EFTA serve as the primary governing statutes. Given these overlapping jurisdictional scopes, multiple laws frequently apply concurrently in the aftermath of a cybersecurity incident. Another critical legislative development is the Act on Fostering the Artificial Intelligence Industry and Securing Trust (the “AI Framework Act”), which took effect on 22 January 2026. This legislation imposes affirmative safety obligations on artificial intelligence (AI) operators that meet specific criteria. Crucially, if an AI operator provides “high-impact AI” or associ - ated products and services, the Act mandates the implementation and operation of comprehensive risk management protocols to guarantee the safety and reliability of these systems (Articles 32 and 34 of the AI Framework Act). For a more detailed analysis of this legislation, please refer to Section 6.2 Cybersecurity and AI .

305 CHAMBERS.COM

Powered by