South Korea PIPA vs GDPR: Criminal Penalties, RRN Rules, and Cross-Border Transfer Powers Compared (2026)

Independently fact-checkedBy Recording Law Editorial Team23 min read

Independently fact-checked against primary sources (last audited July 23, 2026). · 5 primary sources cited on this page. How we verify our legal content

South Korea PIPA vs GDPR: Criminal Penalties, RRN Rules, and Cross-Border Transfer Powers Compared (2026)

Frequently Asked Questions

Does South Korea's privacy law actually put people in prison?

Yes. PIPA's Penal Provisions chapter (Articles 70-73) sets four tiers of imprisonment for data-privacy violations, up to 10 years for the most serious conduct, such as obtaining personal information by fraud and providing it to a third party for profit. GDPR, by contrast, has no criminal offense in the regulation itself; its penalties are administrative fines against the controller or processor entity.

Can a company be fined under PIPA even if an individual employee committed the violation?

Yes. PIPA Article 74's joint penalty provision allows both the individual offender and the corporation or business owner to be punished for the same Article 70-73 offense, with the corporation facing a separate fine. The one exception is a due-care defense: the provision does not apply if the corporation or business owner was not negligent in exercising due care and supervision to prevent the offense.

Is processing a Resident Registration Number a criminal offense in Korea?

No. RRN violations under Article 24-2 are enforced administratively, not criminally -- they draw fines of up to KRW 30 million per violation type and can also trigger PIPA's revenue-based penalty surcharge, but they do not appear in PIPA's criminal chapter (Articles 70-73). The criminal exposure under Article 71 applies to the broader Article 24(1) 'personally identifiable information' provision covering unique identifiers generally, which is a separate provision from the RRN-specific rule.

Is South Korea's maximum data-privacy fine 10% of revenue?

Not yet. The current ceiling on PIPA's revenue-based penalty surcharge (Article 64-2) is 3% of total sales. A 2026 amendment raising that ceiling to 10% in aggravated cases -- repeated willful or grossly negligent violations, breaches affecting 10 million or more subjects, or non-compliance with a corrective order -- was promulgated in March 2026 but its penalty-ceiling provisions do not take effect until September 11, 2026. Every enforcement action before that date, including the record Coupang penalty, is calculated under the 3% ceiling.

What was the largest data-privacy fine in South Korean history?

The PIPC's June 11, 2026 penalty against Coupang and Coupang Fulfillment Services, approximately KRW 624.68 billion (roughly US$409 million), covering a data breach affecting 37.55 million records and unlawful collection of over 15.6 million URLs from more than 11.17 million users. It is roughly 4.6 times the prior record, an approximately KRW 134.7 billion penalty against SK Telecom in August 2025.

Can Korea's regulator stop a data transfer that is already underway?

Yes. Under PIPA Article 28-9, the PIPC can order a controller to suspend an ongoing or imminent cross-border transfer if it violates the Article 28-8 transfer conditions, or if the recipient country or organization fails to adequately protect the data and the data subject has suffered, or is highly likely to suffer, damage. The controller has 7 days to object to the order. GDPR has no equivalent unilateral suspension-order power; it relies on the validity of the underlying transfer mechanism plus after-the-fact enforcement.

Does South Korea have an EU adequacy decision?

Yes, and it works in both directions. The European Commission's adequacy decision covering Korea has been in force since December 2021, allowing data to flow from the EU to Korea without additional safeguards. Separately, the PIPC recognized the EU's framework as providing an equivalent level of protection, and that recognition entered into force on September 16, 2025, allowing data to flow from Korea to the EU on the same basis.

How does PIPA treat criminal-conviction records differently from GDPR?

PIPA classifies criminal records as ordinary sensitive information under Article 23, processable with separately obtained consent, alongside categories like health data and genetic information. GDPR handles criminal-offense data under a standalone provision, Article 10, which generally reserves that processing to official authorities acting under official authority or requires specific member-state legal authorization, and does not typically accept consent as a basis for most non-authority controllers. PIPA's approach is meaningfully more permissive on this specific category.

Updates

Independently fact-checked against the cited primary sources

PIPC fined Coupang approximately KRW 624.68 billion (~US$409 million), with a further KRW 248 million against its logistics affiliate Coupang Fulfillment Services, over a data breach affecting 37.55 million records and unlawful URL collection covering 15.6 million+ URLs on 11.17 million users, the largest data-privacy fine in South Korean history, about 4.6 times the prior record set by SK Telecom in August 2025.

PIPA amendment raising the maximum penalty surcharge from 3% to 10% of total revenue in aggravated cases (willful/grossly negligent repeat violations within 3 years, breaches affecting 10 million+ subjects, or non-compliance with a corrective order) passed the National Assembly on February 12, 2026 and was promulgated on March 10, 2026. The 10% ceiling does not take effect until September 11, 2026 -- the operative ceiling today remains 3%.

Sources and References

  1. PIPA Article 70 (Penal Provisions, top criminal tier), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  2. PIPA Article 71 (Penal Provisions, 5-year/KRW 50M tier), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  3. PIPA Article 72 (Penal Provisions, 3-year/KRW 30M tier), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  4. PIPA Article 73 (Penal Provisions, 2-year/KRW 20M tier), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  5. PIPA Article 74 (Joint Penalty Provisions), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  6. PIPA Article 24 (Restriction on Processing of Personally Identifiable Information), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  7. PIPA Article 24-2 (Restriction on Processing of Resident Registration Numbers), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  8. PIPA Article 37-2 (Right relating to automated decisions), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  9. PIPA Article 28-8 (Cross-border transfer mechanisms), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  10. PIPA Article 28-9 (PIPC order to suspend cross-border transfer), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  11. PIPA Article 64-2 (Penalty surcharge, current 3% ceiling and 2026 amendment), Korea Legislation Research Institute official English translation(elaw.klri.re.kr)
  12. Personal Information Protection Commission (PIPC), Republic of Korea(pipc.go.kr).gov
  13. PIPC enforcement notice: The PIPC Sanctions Coupang and CFS for Data Breaches and Infringements on Privacy (June 11, 2026)(pipc.go.kr).gov
  14. European Commission joint press statement: entry into force of Korea-EU reciprocal recognition (September 16, 2025)(commission.europa.eu).gov
  15. European Commission Adequacy Decisions(commission.europa.eu).gov
  16. Regulation (EU) 2016/679 (General Data Protection Regulation)(eur-lex.europa.eu).gov
  17. DLA Piper: Data Protection Laws of the World -- South Korea(dlapiperdataprotection.com)
  18. Hunton Andrews Kurth: South Korea Amends Privacy Law to Authorize Fines of Up to 10% of Total Revenue(hunton.com)
Share: