SOUTH KOREA Trends and Developments Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
reporting and enhanced critical infrastructure protec - tion. Korea’s Basic Regulatory Framework for Data Protection and Cybersecurity Korea does not regulate data protection and cyberse - curity issues through a single, unified statute. Instead, it employs a multifaceted regulatory approach across several laws, including the Act on Promotion of Infor - mation and Communications Network Utilization and Information Protection, etc. (the “Network Act”), the Personal Information Protection Act (PIPA), the Elec - tronic Financial Transactions Act (EFTA), the Act on the Protection of Information and Communications Infrastructure, and the Act on the Development of Cloud Computing and Protection of Its Users (“Cloud Computing Act”). Among these, the primary statutes governing cyber - security across all industries – rather than specific sectors – are the Network Act, PIPA and the Act on the Protection of Information and Communications The Network Act serves as the foundational statute comprehensively governing cybersecurity in Korea. Designed to ensure network stability and informa - tion protection, it expressly prohibits various forms of intrusions into information and communications net - works – such as hacking, the distribution of malware and distributed denial-of-service (DDoS) attacks – and provides for criminal penalties in the event of viola - tions. Furthermore, it mandates that information and communications service providers (ICSPs) meeting specific operational thresholds designate and report a chief information security officer (CISO) responsible for overseeing internal controls and protection plans. Additionally, qualifying ICSPs must obtain information security management system (ISMS) certification to externally validate the adequacy of their organisation - al, technical and physical security measures. PIPA PIPA functions as the comprehensive general law for data protection across both the public and private sectors. Regarding cybersecurity, PIPA legally man - dates that “data handlers” – a concept analogous to Infrastructure. Network Act
data controllers under the General Data Protection Regulation GDPR – implement specific technical and organisational security measures to safeguard per - sonal information. PIPA and various regulations issued thereunder prescribe the minimum legal baselines organisations must meet, which include establishing internal management plans, enforcing access controls for systems processing personal information, utilising encryption, retaining and monitoring log records, pre - venting malware infections and preparing for disaster recovery. Act on the Protection of Information and Communications Infrastructure This Act establishes the Critical Information Infrastruc - ture Protection System to safeguard assets vital to national security and the economy. It imposes strict obligations – such as establishing proactive protection measures, conducting vulnerability assessments and executing incident reporting – on the heads of organi - sations managing designated “critical information and communications infrastructure”. Trend Towards Stricter Enforcement by Regulatory Authorities Recent regulatory enforcement actions concerning cybersecurity and data breaches demonstrate a clear pivot towards more rigorous and substantive enforce - ment. Strengthening of substantive enforcement With the increasing frequency of cybersecurity inci - dents, there have been growing calls for more robust enforcement by the relevant authorities. In response, both regulatory practice and the applicable statutory framework have evolved towards the imposition of more substantial sanctions. For example, PIPA pro - vides that administrative penalties may be imposed where personal information processed by a data han - dler is lost, stolen, leaked, forged, altered or dam - aged, and the data handler failed to take necessary measures to ensure security. Recently, however, the Personal Information Protection Commission (PIPC) has demonstrated a greater willingness to impose administrative penalties in individual cases, and the amounts imposed have shown a tendency to increase significantly compared to the past. Notably, a 2023 amendment to PIPA revised the basis for calculat -
321 CHAMBERS.COM
Powered by FlippingBook