SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
• actionable steps data subjects can take to mini - mise damage; • the data handler’s remediation measures and dam - age relief procedures; and • the contact details of the dedicated response department (Article 34 (1) of PIPA). Under the amended PIPA (passed in February 2026), this notification must also detail rights relief mecha - nisms, such as claiming damages and utilising dis - pute resolution. Crucially, the amendment triggers the notification obligation even if an actual breach is not confirmed, provided there is a “possibility” of a breach or similar incident. Furthermore, the data handler must report the breach to the PIPC or KISA within 72 hours if the incident involves: • the personal information of 1,000 or more data subjects; • sensitive information or unique identification infor - mation; or • unauthorised external access (eg, hacking) to the data processing system or the IT devices used by personnel of the data handler (Article 34 (3) of the PIPA; Article 40 of its Enforcement Decree). Consequently, any data breach resulting from a cyber- attack triggers an automatic statutory reporting obli - gation. Administrative Penalties and Punitive Damages In the event of a data breach, unless the data han - dler successfully demonstrates full compliance with the implementation of all required security measures under PIPA, the PIPC may impose a penalty sur - charge of up to 3% of the data handler’s total rev - enue (excluding revenue proved to be unrelated to the violation) (Article 64-2 of the PIPA). Significantly, once the February 2026 amendment to PIPA takes effect, this ceiling increases dramatically. The PIPC will be authorised to impose administrative penalties of up to 10% of total revenue for breaches caused by: • repeated violations within three years due to intent or gross negligence;
• large-scale damage affecting 10 million or more individuals due to intent or gross negligence; or • the failure to comply with prior corrective orders. Additionally, a 2023 amendment to PIPA introduced an aggravated damages mechanism. If a data breach is caused by the intent or gross negligence of the data handler, courts are authorised to award damages up to five times the actual proven amounts (Article 39 (3) of PIPA). Security Protection of IT Systems Processing Credit Information Within the financial sector, Article 19 of the Credit Information Act mandates that credit information companies establish robust technical, physical and organisational security measures for their IT systems processing credit information. The detailed content of such measures is set out in Article 16 of the Enforce - ment Decree of the Credit Information Act and Appen - dix 3 to the Supervisory Regulations on Credit Infor - mation Business. 6.2 Cybersecurity and AI Regulations Under the AI Framework Act The AI Framework entered into force on 22 January 2026. This legislation imposes affirmative safety obli - gations on AI operators meeting specific statutory criteria. Specifically, an AI operator must fulfil safety obligations prescribed by the MSIT’s Notification on Methods for Fulfilling Safety Assurance Obligations for AI if their AI systems: • utilised a cumulative compute exceeding 1,026 floating-point operations (FLOPs) during training; • are constructed and operated using the most cutting-edge AI technologies currently available; or • pose a risk of causing widespread and severe impacts on human life, physical safety and funda - mental rights (Articles 32 and 34). Furthermore, operators of “high-impact AI” – defined as AI systems utilised in critical sectors such as healthcare and energy that harbour the potential to significantly impact or endanger human life, physical safety and fundamental rights – must adhere to sup - plementary regulatory controls outlined in the MSIT’s Guidelines on the Responsibilities of High-impact
317 CHAMBERS.COM
Powered by FlippingBook