관보 (Republic of Korea Official Gazette) · 10 Sep 2026 · 5 vistas
South Korea Tightens Personal Data Protection Duties in Decree Overhaul
Por FactBox Admin

The Republic of Korea has promulgated Presidential Decree No. 36671, a partial amendment to the Enforcement Decree of the Personal Information Protection Act, published in the Republic of Korea Official Gazette (관보) No. 21319 of 10 September 2026. Signed by President Lee Jae-myung, Prime Minister Han Sung-sook and Minister of the Interior and Safety Yoon Ho-jung under the remit of the Personal Information Protection Commission (PIPC), the decree takes effect on 11 September 2026.
The amendment implements the Personal Information Protection Act as revised by Act No. 21445 (promulgated 10 March 2026, effective 11 September 2026), which strengthened the authority and independence of privacy officers and introduced a notification duty for possible data leakage. The decree also raises administrative fines that were set far below the statutory ceilings, sharpening the deterrent effect of enforcement.
Expanded duty to designate a privacy officer
The decree broadens the category of data controllers that must appoint a privacy officer, and requires that the officer be chosen from persons meeting the qualification criteria in Annex 1. The newly inserted Article 32(3) covers controllers meeting any of the following thresholds:
- Annual sales exceeding 180 billion won (excluding schools and medical institutions under the Medical Service Act) that process sensitive or unique-identification information of 50,000 or more data subjects, or personal information of 1 million or more data subjects;
- Schools under the Higher Education Act with 20,000 or more enrolled students (including graduate students);
- Tertiary general hospitals (상급종합병원) under the Medical Service Act;
- Public system operating institutions.
Controllers that newly fall under these criteria must report the designation, change or removal of their privacy officer to the PIPC within six months of the triggering event, using a form set by PIPC notice. The deadline may be extended by up to one year where the board of directors cannot be convened for business reasons. A transitional rule requires controllers that had already designated an officer before the decree took effect to file the report within six months of the entry into force.
New 72-hour notification duty for possible leakage
The decree introduces Articles 39-2 and 39-3, creating a duty to notify data subjects when a possible leakage is suspected but not yet confirmed. Notification must be given in writing within 72 hours of learning of the event in two situations:
- An illegal access to a personal-information processing system or device has occurred and leakage is suspected, but the affected data subjects cannot yet be identified;
- A partial leakage has been confirmed and other data subjects’ information may also have been compromised.
The notice must state the items of personal information possibly affected, the suspected time and circumstances of the leakage, and the fact that a further notice will be issued once the leakage is confirmed. If the controller later confirms that no leakage actually occurred, it must notify data subjects immediately. Where contact details are unknown, the controller may instead post the notice on its website or at a visible place of business for at least 30 days.
Broader “leakage” concept and higher penalties
The decree expands the term “유출등” (leakage, etc.) — previously limited to loss, theft and leakage — to also cover forgery, alteration and damage of personal information, aligning the notification and reporting obligations with the wider concept. It also details the criteria for reducing administrative surcharges (과징금) for controllers that invest in privacy protection, allowing a reduction of up to 40% of the base amount, and raises administrative fines for failing to take required security measures from 6/12/24 million won to 9/18/30 million won for first, second and third-or-more violations respectively.
For businesses and institutions handling large volumes of personal data, the decree means tighter compliance duties, faster breach communication to the public, and materially higher financial exposure for non-compliance. For citizens, the 72-hour notification rule and the expanded “leakage” concept strengthen their right to be informed promptly when their data may be at risk, even before a breach is fully confirmed.
Source: Republic of Korea Official Gazette (관보), No. 21319, 10 September 2026, Section I (Presidential Decrees) (official reference: Presidential Decree No. 36671).