Cybersecurity 2026

SOUTH KOREA Trends and Developments Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

ing administrative penalties. The previous standard – “up to 3% of revenue related to the violation” – was replaced with “up to 3% of revenue calculated based on total revenue, excluding revenue unrelated to the violation”. In practice, revenue considered unrelated to the violation has been interpreted narrowly, contrib - uting to a trend of higher penalty assessments. In addition, the PIPC has increasingly issued detailed corrective orders requiring structural and operational changes. For example, in connection with the SK Tel - ecom data breach, the PIPC observed that the chief privacy officer’s (CPO) authority had been limited pri - marily to certain IT services, which it determined had contributed to the incident. As part of its corrective measures, the PIPC ordered the company to expand the CPO’s managerial and supervisory authority to encompass the company’s overall telecommunica - tions infrastructure. This enforcement trajectory has been further reinforced by the February 2026 amend - ment to PIPA, which increases the maximum adminis - trative penalty for serious or repeated breach incidents to 10% of revenue and strengthens the statutory sta - tus and responsibilities of the CPO. Evaluation based on substantive governance rather than formal compliance In the course of recent investigations and sanctions related to cybersecurity incidents, relevant regulators such as the PIPC have shown a tendency to assess – rather than focusing only on technical vulnerabilities or individual violations – the overall level of data protec - tion and security governance across the organisation. In practice, when determining the responsibility of a data handler, regulators comprehensively consider whether the data handler took protective measures that are reasonably expected under social norms, tak - ing into account factors such as the level of informa - tion security technology generally known at the time of the incident, the industry and business scale of the ICSP and the overall content of its security measures, the economic costs and benefits of information secu - rity measures, the possibility of avoiding damage in light of the level of hacking technology and develop - ments in information security technology, the nature of the collected personal information and the extent of

harm that users may suffer due to leakage of personal information. In the wake of recent major incidents, regulators have tended to interpret more proactively the standard of “protective measures reasonably expected under social norms”, and accordingly, companies that have proactively taken measures above the level expected in the industry – such as adopting new technologies, managing supply chain risks and leveraging threat intelligence – are more likely to receive favourable determinations in connection with administrative pen - alties or civil liability exposure if an incident occurs. Increased Risk of Civil Damages In addition to general liability for damages related to violations by data handlers, PIPA establishes enhanced liability mechanisms for incidents such as data breaches resulting from a data handler’s intent or negligence. Specifically, PIPA provides for: • statutory damages of up to KRW3 million per data subject, under which the data handler may avoid liability only by proving the absence of intent or negligence; and • an aggravated damages regime allowing courts to award up to five times the amount of actual dam - ages. These mechanisms are designed to alleviate the evi - dentiary burden on data subjects and to facilitate effective compensation. In practice, statutory dam - ages are most frequently invoked in connection with data breach incidents. Moreover, as both the number of data breaches and the scale of affected individuals have increased sig - nificantly, and as public awareness of data protection issues has grown, there have been increasing calls to introduce class-action mechanisms for large-scale data breach incidents. Although Korean courts have historically awarded relatively modest damages for the mere exposure of personal information, it is dif - ficult to rule out the possibility that future decisions in large-scale cases may expand both the amounts of compensation and the recognised scope of recover - able harm. In particular, where aggravated damages

322 CHAMBERS.COM

Powered by