Cybersecurity 2026

SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

Concurrently, legislative discussions remain ongoing regarding the potential enactment of the Framework Act on Cybersecurity (working title), which aims to provide a statutory basis for an integrated cyberse - curity response mechanism spanning both the pub - lic and private sectors. However, its passage has stalled due to protracted debates over the scope of the NIS’s authority and related concerns regarding digital privacy rights. If ultimately enacted, this legis - lation is expected to establish a unified governance framework, effectively integrating and co-ordinating the nation’s currently fragmented cybersecurity appa - ratus. 1.2 Cybersecurity Laws The primary cybersecurity-related laws and regula - tions in Korea are outlined in the following. Given the varying scopes and subjects of application across these statutes, establishing a universal hierarchy of precedence is challenging. Depending on the specific circumstances of a case, a particular statute may take precedence, or multiple laws may apply concurrently. Network Act The Network Act prohibits and penalises malicious activities that threaten cybersecurity via information and communications networks (eg, hacking, distrib - uted denial-of-service (DDoS) attacks and the trans - mission or distribution of malware). It imposes spe - cific cybersecurity obligations on “information and communications service providers” (ICSPs; telecom - munications operators and online service providers). These include the mandates to designate and report a Chief Information Security Officer (CISO) and to obtain information security management system (ISMS) cer - tification. Notably, the Network Act features an extraterritorial application provision, meaning it applies to acts com - mitted outside Korea that impact the domestic market or its users (Article 5-2). PIPA PIPA serves as the comprehensive general law for the protection of personal information. Its primary regulatory subjects are “data handlers” (a concept analogous to data controllers under the General Data Protection Regulation – GDPR). PIPA imposes vari -

ous cybersecurity obligations related to data protec - tion, including the duty to implement robust security measures for the protection of personal information (Article 29) and the obligation to notify and report data breaches (ie, incidents involving the loss, theft or unauthorised disclosure of personal information) (Article 34). Specifically, the Standards of Personal Information Security Measures, which elaborates on these statutory security obligations, set forth detailed technical and organisational measures required for the protection of personal information. Recently, hacking incidents and massive data breach - es involving critical telecommunications companies and e-commerce platforms have emerged as signifi - cant social issues in Korea, driving demand for height - ened corporate cybersecurity measures. In response, the National Assembly recently passed an amend - ment to PIPA. This amendment explicitly clarifies the data protection responsibilities of a data handler’s representative (eg, the CEO), augments the statu - tory authority of the chief privacy officer (CPO) and significantly increases the administrative penalties for repeated or severe data breaches. The amended PIPA is scheduled to take effect six months following its formal promulgation. While PIPA lacks an explicit extraterritoriality clause, Korean courts and regulatory authorities have consist - ently interpreted it as applicable to foreign operators, depending on the specific facts and circumstances of each case. For reference, the Credit Information Use and Protec - tion Act (the “Credit Information Act”) specifically reg - ulates the protection of credit information handled by financial institutions and imposes particularly stringent security requirements. With respect to credit informa - tion that also constitutes personal information (ie, per - sonal credit information), the Credit Information Act operates as a special law and therefore takes prec - edence over PIPA to the extent of any inconsistency. EFTA The EFTA governs the security and reliability of elec - tronic financial transactions, applying directly to finan - cial institutions and electronic financial businesses. It serves as the primary cybersecurity framework for

306 CHAMBERS.COM

Powered by