Cybersecurity 2026

SOUTH KOREA Trends and Developments Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko

2026 amendment to PIPA Passed on 12 February 2026, this critical amendment codifies the regulatory urgency sparked by recent breaches by fundamentally strengthening the sanc - tions regime, accountability structures and reporting duties (expected to be promulgated by early March and effective six months thereafter). • Introduction of up to 10% penalty surcharge: To maximise deterrence, the PIPC may now impose a penalty of up to 10% of total revenue if a data handler (i) commits repeated violations within three years due to intent or gross negligence; (ii) causes large-scale damage affecting 10 million or more individuals due to intent or gross negligence; or (iii) triggers a leak by failing to comply with a prior cor - rective order. • Specifying executive responsibility and strengthen - ing the CPO: The amended PIPA explicitly des - ignates the representative (eg, CEO) or business owner as the ultimate party responsible for data processing and protection, mandating they allocate sufficient personnel and budgets. Furthermore, companies must now execute a formal board resolution to appoint or dismiss a CPO. The CPO is granted explicit authority over security budgets and is legally obligated to report critical matters directly to the representative and the board of directors. • Expanded scope of notification and early reporting: The amended PIPA expands mandatory breach notifications beyond lost, stolen or leaked per - sonal information to include personal information that is forged, altered or damaged. Additionally, by introducing a “potential data breach” notifica - tion requirement, data handlers must proactively inform data subjects to mitigate harm even before a breach is definitively confirmed. Key Focus Areas for Domestic and Foreign Businesses In light of Korea’s increasingly stringent regulatory environment and evolving enforcement posture, businesses should focus on the following key areas in practice. Clarifying regulatory scope and accountability As discussed above, the amended PIPA clarifies that a data handler’s representative (or the business owner)

provisions apply, the resulting financial exposure may be substantial, depending on the circumstances. Additional Moves Towards Stronger Regulation of Data Protection and Cybersecurity Meanwhile, as large-scale incidents have occurred in succession targeting telecom companies and platform operators, the government and the National Assem - bly have been re-examining the adequacy of existing data protection and cybersecurity regulations and are pushing forward with policy formulation and legisla - tive amendments aimed at strengthening the overall regulatory framework. Key developments include the following. Joint government “Comprehensive Information Security Countermeasures” The government – involving relevant ministries and agencies including the Ministry of Science and ICT, the Office of National Security, the Financial Servic - es Commission, the PIPC, the National Intelligence Service, and the Ministry of the Interior and Safety – launched its “1st Comprehensive Interagency Infor - mation Security Countermeasures” in October 2025, followed by a refined “2nd Comprehensive Counter - measures” in January 2026. These initiatives heavily prioritise tangible consumer damage relief. Key mandates include: • introducing a public dispute resolution mecha - nism for general incidents like service outages and account takeovers • requiring immediate user notification of potential leaks, alongside explicit instructions on how to claim damages; • incentivising voluntary corporate security upgrades; • deploying “red teams” to assess AI security mod - els; and • elevating data encryption and infrastructure audit - ing standards. These frameworks serve as the blueprint for current legislative overhauls.

323 CHAMBERS.COM

Powered by