South Korea PIPA vs GDPR: Criminal Penalties, RRN Rules, and Cross-Border Transfer Powers Compared (2026)

South Korea's Personal Information Protection Act (PIPA) and the EU's General Data Protection Regulation (GDPR) both regulate how organizations collect and use personal data, but they diverge sharply on enforcement. PIPA backs its rules with a four-tier criminal code that can send a compliance officer to prison, layers a near-absolute ban on Resident Registration Number (RRN) processing that GDPR has no counterpart to, and gives Korea's regulator a power the EU has never had: the authority to unilaterally order a company to stop an overseas data transfer already underway.
The two frameworks share a broad family resemblance -- both grant individuals rights over their data, both require a lawful basis for processing, both regulate cross-border transfers -- but the machinery behind PIPA is built differently, and the difference matters most in exactly the places a compliance team is most likely to get wrong: who can go to prison, what a Resident Registration Number is, and how fast a regulator can stop a transfer already in flight.
This article addresses South Korea's Personal Information Protection Act (PIPA), enforced by the Personal Information Protection Commission (PIPC), compared with the EU's General Data Protection Regulation (GDPR). For PIPA's full framework outside the GDPR comparison, see our South Korea data privacy laws guide. This article does not constitute legal advice.
PIPA vs GDPR: At a Glance
| Feature | PIPA (South Korea) | GDPR (EU) |
|---|---|---|
| Regulator | Personal Information Protection Commission (PIPC) | National DPAs, coordinated by the EDPB |
| Criminal liability | Yes -- four tiers, up to 10 years imprisonment (Arts. 70-73) | No criminal track under the regulation itself |
| Corporate + individual joint liability | Yes (Art. 74, joint penalty provision, due-care defense available) | No equivalent; liability is against the controller/processor entity |
| National ID number regime | Near-total ban on RRN processing, consent cannot override it (Art. 24-2) | No EU-wide ban; national ID numbers left to member-state derogation (Art. 87) |
| Criminal-record data | Sensitive information, processable with separate consent (Art. 23) | Separate category (Art. 10); consent generally unavailable for non-authority controllers |
| Automated decision-making | Opt-out objection right, explicitly names AI (Art. 37-2) | Default prohibition with statutory exceptions and safeguards (Art. 22) |
| Cross-border transfer mechanisms | Separate consent, treaty, contract necessity, PIPC certification, PIPC equivalence recognition (Art. 28-8) | Adequacy, SCCs, BCRs, certification, derogations (Arts. 45-49) |
| Regulator power to halt a specific transfer | Yes -- PIPC suspension order, 7-day objection window (Art. 28-9) | No equivalent unilateral order power |
| Current administrative penalty ceiling | 3% of total sales (Art. 64-2); rising to 10% in aggravated cases from September 11, 2026 | Up to EUR 20 million or 4% of global annual turnover |
| Largest fine to date | ~KRW 624.68 billion / ~US$409 million (Coupang/CFS, June 2026) | Varies by DPA; Irish DPC has issued the largest individual GDPR fines |
| Adequacy status | EU adequacy decision for Korea in force since December 2021; Korea's reciprocal recognition of the EU in force since September 16, 2025 | N/A (GDPR is the reference standard) |

Background
PIPA is South Korea's comprehensive personal data protection statute, enforced by the Personal Information Protection Commission (PIPC). It has been amended repeatedly since its original enactment, most consequentially by a 2023 amendment that added the automated-decision rights at Article 37-2 and the cross-border transfer regime at Articles 28-8 and 28-9, and most recently by a 2026 amendment raising the ceiling on the revenue-based penalty surcharge in aggravated cases. Some older English-language mirrors of PIPA, including a widely cited translation stamped to the 2020 version of the law, predate these additions and should not be relied on for current text.
The GDPR, in force since May 25, 2018, is the reference point this comparison uses throughout. Where PIPA borrows GDPR-style structure -- a controller/processor framework, enumerated legal bases, a chapter of individual rights -- the resemblance is real. Where it doesn't, the divergence tends to be sharp rather than incremental, and criminal liability is the clearest example.

Scope and Consent-Centric Design
PIPA applies to any "personal information processor" handling personal information in Korea, and its territorial reach extends to processing that affects data subjects in Korea even when the processor is based abroad, broadly comparable to GDPR's extraterritorial reach under Article 3.
The bigger structural difference sits in how each law lets an organization justify processing in the first place. GDPR's Article 6 offers six co-equal, non-hierarchical lawful bases, and organizations frequently prefer contract necessity or legitimate interests specifically to avoid consent's stricter withdrawal mechanics. PIPA is explicitly consent-centric: consent is the primary and most commonly used basis, and the statutory alternatives function more as narrow substitutes for consent than as equally weighted options.
PIPA's alternative bases include: a statutory obligation or unavoidable duty under another law; work a public institution is statutorily assigned to perform; steps necessary to perform or prepare a contract with the data subject; protecting life, body, or property from imminent danger; and a "legitimate interests" analog available only where the controller's interest is "manifestly superior" to the data subject's rights and the processing stays substantially related and within reasonable scope. That "manifestly superior" bar is a materially stricter formulation than GDPR's balancing test, which requires only that the controller's interest not be overridden by the subject's interests on balance, not that it clearly outweigh them.

Definitions and Sensitive Data
| Term | PIPA | GDPR |
|---|---|---|
| Protected individual | Data subject | Data subject |
| Data handler | Personal information processor | Controller / processor |
| Sensitive category | Sensitive information (Art. 23) | Special categories of personal data (Art. 9) |
| National ID numbers | Unique identification information; RRN singled out for near-total ban (Art. 24, Art. 24-2) | Left to member-state derogation (Art. 87) |
| Automated-decision provision | Art. 37-2 | Art. 22 |
PIPA's sensitive information category (Article 23) covers ideology, faith, labor union or political party membership, political views, health and medical treatment information, sexual orientation, genetic information, criminal records, biometric data used to uniquely identify a person, and race or ethnic information. That list is close to a superset of GDPR's special categories under Article 9 (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, and sex life or sexual orientation), with one notable structural exception: PIPA folds criminal records directly into the sensitive-information category that can be processed on separately obtained consent, while GDPR handles criminal-conviction data under a standalone provision, Article 10, that generally reserves processing to official authorities or requires specific member-state legal authorization rather than accepting consent as a basis for most non-authority controllers. This is a genuine, not merely semantic, difference in how the two laws treat a criminal record: PIPA's consent-eligible design is more permissive than GDPR's authority-gated one.
Separately from "sensitive information," PIPA also defines "unique identification information": the Resident Registration Number, driver's license number, passport number, and foreigner registration number. Non-RRN members of that category can be processed on either a statutory basis or consent. The RRN itself cannot -- see below.
The Resident Registration Number regime
South Korea's Resident Registration Number functions similarly to a national ID number, and PIPA treats it as close to untouchable. Article 24-2 provides that a controller shall not process an RRN at all -- and this holds even where the data subject consents -- except where a specific statute, Presidential Decree, or a National Assembly, court, election-commission, or audit-board regulation explicitly requires or permits it; where processing is manifestly necessary to protect life, body, or property from imminent danger; or in narrow PIPC-notified circumstances tracking those two categories. Where an RRN is processed under one of those exceptions, the controller must retain it "in a safe manner by means of encryption," with the specific scope and timing of that duty set by Presidential Decree according to data volume and breach impact, and must offer an alternative sign-up method for online membership registration that does not require the RRN at all.
Nothing in GDPR resembles this. GDPR does not create an EU-wide near-prohibition on processing a national identification number; instead, Article 87 leaves the conditions for processing a "national identification number" to individual member states' domestic law, so the rule (if any) varies by country rather than applying uniformly across the EEA the way PIPA's RRN ban applies uniformly across Korea. "Consent cannot authorize it" is the feature with no GDPR counterpart at all -- under GDPR, consent remains a valid basis for most categories of data, including most member-state ID-number rules; under PIPA, consent is affirmatively excluded as a basis for RRN processing.
This is a critical distinction to get right: RRN violations are enforced administratively, not criminally. Article 24-2 does not appear anywhere in PIPA's criminal chapter (Articles 70-73). Only the broader Article 24(1) provision -- covering "personally identifiable information," i.e., unique identifiers generally, not the RRN-specific rule -- carries criminal exposure under Article 71. An RRN violation instead draws an administrative fine of up to KRW 30 million for each of three separate failures: processing an RRN in violation of Article 24-2(1), failing to encrypt one as required by Article 24-2(2), or failing to offer the RRN-free alternative sign-up method required by Article 24-2(3). Processing an RRN in violation of Article 24-2(1) is also a separate trigger for PIPA's revenue-based penalty surcharge under Article 64-2, meaning the fixed KRW 30 million administrative fine and the percentage-of-revenue surcharge can both apply to the same violation, but neither route involves imprisonment.

Data Subject Rights and Automated Decisions
PIPA grants data subjects rights that broadly parallel GDPR's Chapter 3 catalog: access, correction, erasure, and the right to object to or restrict processing. A data portability right under a 2023 amendment took effect in March 2025.
The area with the most operationally interesting divergence is automated decision-making. PIPA Article 37-2 grants a data subject the right to object to a decision made by a "completely automated system" -- the statute explicitly names AI -- where that decision has a significant effect on the subject's rights or duties, along with a separate right to request an explanation of an automated decision already made. On objection or an explanation request, the controller generally must not apply the automated decision (absent a compelling reason) or must take remedial steps, including re-processing with human involvement. Controllers must also proactively disclose the criteria, procedures, and methods behind their automated decisions.
The structure differs from GDPR's Article 22 in an important way. GDPR frames the right as a default prohibition: a data subject "shall have the right not to be subject to" a solely automated decision with legal or similarly significant effects, subject to exceptions for contract necessity, legal authorization, or explicit consent, and even within those exceptions the controller must implement safeguards such as the right to obtain human intervention and to contest the decision. PIPA's Article 37-2 is structured the other way, as an opt-in objection right: the automated decision happens, and the subject can then object or request an explanation -- except the objection right does not apply where the automated decision was made under a consent, contract-necessity, or legal-obligation basis, precisely the situations where GDPR would still require safeguards. In that narrow sense PIPA's citizen-facing right is narrower than GDPR's default-prohibition model. But PIPA is also more explicit than GDPR's operative text about naming AI systems specifically and about requiring proactive disclosure of decision-making criteria, rather than leaving that detail mostly to guidance and recitals.
| Right | PIPA | GDPR |
|---|---|---|
| Access | Yes | Art. 15 |
| Correction | Yes | Art. 16 |
| Erasure | Yes | Art. 17 |
| Object / restrict processing | Yes | Arts. 18, 21 |
| Data portability | Yes (effective March 2025) | Art. 20 |
| Automated-decision rights | Art. 37-2: opt-out objection + explanation right, names AI explicitly, narrowed where basis is consent/contract/legal obligation | Art. 22: default prohibition with statutory exceptions and mandatory safeguards |
Supervisory Structure and Enforcement Posture
The PIPC is Korea's single, centralized data protection authority, with investigative, order, and penalty powers. GDPR enforcement is decentralized across 30-plus national supervisory authorities in the EEA, coordinated through the European Data Protection Board and a one-stop-shop mechanism for cross-border cases. In practice, the PIPC's centralized structure and its willingness to combine large administrative penalties with public disclosure orders and corrective orders gives it a more concentrated, and in the largest recent cases faster-moving, enforcement posture than the EU's multi-authority model, where the largest fines typically move through a single lead DPA (commonly Ireland's) over a longer procedural timeline.
Cross-Border Data Transfers
PIPA Article 28-8 allows a cross-border transfer only where one of five conditions is met:
- Separate consent from the data subject, distinct from consent to general processing;
- A specific provision in a statute, a treaty Korea is party to, or another international convention;
- Necessity to perform a contract with the data subject, with the transfer particulars either disclosed in the privacy policy or separately communicated -- functionally similar to GDPR's Article 49(1)(b) contract-necessity derogation;
- The recipient has obtained PIPC-designated certification and has implemented safety and rights-guarantee measures, comparable in function to GDPR's Binding Corporate Rules or certification mechanisms; or
- The PIPC recognizes the destination country's or organization's protection system, scope of data-subject rights, and remedy procedures as "substantially equal" to PIPA's own level -- Korea's version of an adequacy decision.
The EU is the confirmed working example of that fifth mechanism. The European Commission's own adequacy decision covering Korea has been in force since December 2021, and the PIPC's reciprocal recognition of the EU framework as equivalent entered into force on September 16, 2025, per a joint press statement from the European Commission and the PIPC. That mutual arrangement means personal data can move in both directions between the EU and Korea without relying on case-by-case mechanisms such as Standard Contractual Clauses -- see our broader guide to EU adequacy decisions for how that mechanism works generally.
Before any cross-border transfer, PIPA Article 28-8(2) requires the controller to notify the data subject in advance of what data will be transferred, the destination country, date and method of transfer, the recipient's name and contact details, the recipient's purpose and retention period for the data, and how to refuse the transfer and what refusing means for the subject.
The PIPC's power to order suspension of a transfer already underway has no GDPR counterpart. Under Article 28-9, the PIPC may order a controller to suspend an ongoing or imminent cross-border transfer where the transfer violates the Article 28-8 conditions, or where the recipient country or organization fails to properly protect the data compared to PIPA's own standard and the data subject has suffered, or is highly likely to suffer, damage as a result. The controller may object to the PIPC within 7 days of receiving the order. GDPR relies instead on the validity of the transfer mechanism itself -- an adequacy decision, SCCs, or BCRs -- plus after-the-fact enforcement and fines; there is no EU-level power for a regulator to issue a bespoke stop-this-transfer-now order against a specific ongoing transfer the way Article 28-9 allows.
Criminal Penalties: The Structural Differentiator
This is where PIPA and GDPR diverge most sharply, and it is the single most important thing a foreign organization operating under both laws needs to understand: PIPA is a criminal statute as well as a regulatory one. GDPR's entire penalty regime is administrative -- fines against the controller or processor entity, up to EUR 20 million or 4% of global turnover -- and there is no EU-law criminal offense for a GDPR violation itself (individual member states can criminalize related conduct under their own domestic law, but not under the GDPR text). PIPA runs a criminal track in parallel with its administrative one, and the same underlying conduct can trigger both at once.
PIPA's Penal Provisions chapter sets out four tiers of imprisonment:
| Article | Maximum penalty | Core conduct |
|---|---|---|
| Art. 70 | Up to 10 years imprisonment or a fine up to KRW 100 million | Disturbing a public institution's data processing by altering or erasing data to cause suspension or paralysis of its work; obtaining personal information by fraud or improper means and providing it to a third party for a profit-making or unjust purpose |
| Art. 71 | Up to 5 years or a fine up to KRW 50 million | Unauthorized third-party disclosure of personal information without consent (both the discloser and a knowing recipient are liable); using or providing personal information for profit-making or improper purposes; collecting a child under 14's data without parental consent; processing sensitive information without a lawful basis; processing personally identifiable information (unique identifiers generally) without a lawful basis; unlawfully re-identifying pseudonymized information; divulging personal information acquired in the course of official duties |
| Art. 72 | Up to 3 years or a fine up to KRW 30 million | Misusing CCTV or body-cam devices beyond their installed purpose, or recording audio without authorization; acquiring personal information or consent by fraud for a profit-making or improper purpose; divulging confidential information acquired during a regulatory or investigative role |
| Art. 73 | Up to 2 years or a fine up to KRW 20 million | Continuing to use or disclose personal information after failing to correct, erase, or suspend processing as ordered; failing to comply with a PIPC confidentiality order without cause (prosecution here requires a complaint from the person who requested the order); obstructing a PIPC investigation through concealment, refusal, or forged materials |
Who can be held liable -- Article 74's joint penalty provision. If a corporation's representative, agent, employee, or other worker commits an Article 70 offense in connection with the corporation's or individual business owner's business, both the individual offender and the corporation or business owner are punished: the corporation or owner faces a fine up to KRW 70 million for an Article 70 offense, or the fine amount prescribed by the relevant article for an Article 71-73 offense. The one carve-out is a due-care defense -- Article 74 does not apply if the corporation or individual owner was not negligent in exercising due care and supervision to prevent the offense. This is the provision to point to when the question is "can the business itself be fined alongside the employee who actually committed the violation" -- under PIPA, yes, absent a documented compliance program defense. GDPR has no equivalent; its liability model is corporate and administrative only, with no track for personally fining or imprisoning the individual who committed the underlying act.
The dual exposure this creates is real, not theoretical: unauthorized third-party disclosure without consent is a criminal offense under Article 71 (up to 5 years or KRW 50 million) for the individual or responsible officer, and the same disclosure can separately trigger the revenue-based penalty surcharge under Article 64-2 against the company. Prison exposure for the person and a percentage-of-revenue fine for the company, arising from the same act, is the genuine structural rarity that sets PIPA apart from GDPR.
Administrative Penalties and the Ceiling Change
PIPA's administrative track runs on a revenue-based penalty surcharge under Article 64-2, separate from the criminal fines above and from the RRN-specific fixed fines described earlier. As of today, the operative ceiling is 3% of total sales, or up to KRW 2 billion where sales figures do not exist or cannot be calculated. Triggers for the surcharge include unlawful processing under the law's core processing articles, collecting a child under 14's data without parental consent, processing sensitive information without consent, personally-identifiable-information or RRN processing violations, negligent oversight of an entrusted processor that causes it to violate the Act, unlawful re-identification of pseudonymized data, unlawful cross-border transfer or defiance of a transfer-suspension order, and a data breach where the controller did not take all statutorily required safety measures.
A 2026 amendment raises that ceiling to 10% of total revenue, but only in specific aggravated circumstances: repeated violations involving willful misconduct or gross negligence within a 3-year period, violations affecting 10 million or more data subjects, or failure to comply with a PIPC corrective order. The amendment was promulgated around March 10, 2026, but its penalty-ceiling provisions do not take effect until September 11, 2026. Until that date, 3% remains the governing ceiling for every enforcement action, including the record-setting Coupang penalty described below, which was calculated under the current 3% regime. Any statement that Korea's penalty ceiling is already 10% is describing a future rule as though it were current law.
| PIPA (Art. 64-2) | GDPR (Art. 83) | |
|---|---|---|
| Standard ceiling | 3% of total sales (current, through September 10, 2026) | Up to EUR 10M or 2% of global annual turnover |
| Upper ceiling | 10% of total revenue for aggravated cases, effective September 11, 2026 | Up to EUR 20M or 4% of global annual turnover |
| Fallback (no calculable sales) | Up to KRW 2 billion | N/A |
| Criminal exposure in parallel | Yes, up to 10 years imprisonment (see above) | No |
Recent Developments
Coupang, June 11, 2026. The record KRW 624.68 billion penalty described above breaks down into roughly KRW 423.6 billion for the breach itself, KRW 201.1 billion for the unlawful URL collection, KRW 248 million against Coupang Fulfillment Services for an unlawful blacklist, and KRW 16.8 million in administrative fines, alongside corrective and public-disclosure orders.
SK Telecom, August 28, 2025. The prior record: approximately KRW 134.7 billion (roughly US$89-97 million) over a USIM/SIM-key breach affecting 23.2-23.5 million subscribers involving unencrypted SIM authentication keys, plus a separate fine for delayed breach notification.
Data portability. A data portability right added by a 2023 amendment took effect in March 2025, giving PIPA a rights catalog closer to full parity with GDPR Chapter 3.
2026 penalty-ceiling amendment. The 3%-to-10% change described above was promulgated around March 10, 2026, with the higher ceiling not taking effect until September 11, 2026.
Dual-Compliance Guidance
Organizations subject to both PIPA and GDPR should treat the following as the areas most likely to require a structural, not just a documentation, response.
| Issue | PIPA | GDPR | Compliance approach |
|---|---|---|---|
| Individual criminal exposure | Officers/employees can face imprisonment under Arts. 70-73; the company can be separately fined under Art. 74 absent a due-care defense | No criminal track | Maintain a documented, actively supervised compliance program in Korea specifically to support an Art. 74 due-care defense |
| National ID numbers | RRN processing is banned even with consent, outside narrow statutory exceptions (Art. 24-2) | No EU-wide ban; national ID rules vary by member state (Art. 87) | Never collect or store an RRN unless a specific statutory exception applies; build an RRN-free registration path by default |
| Criminal-record data | Sensitive information, consent-eligible (Art. 23) | Separate Art. 10 category, consent generally unavailable for non-authority controllers | Do not assume a GDPR-compliant consent flow for criminal-record data is sufficient for Korea, or vice versa; treat each jurisdiction's rule independently |
| Automated decisions / AI | Opt-out objection + explanation right, explicit AI reference, narrowed on consent/contract/legal-obligation bases (Art. 37-2) | Default prohibition with mandatory safeguards (Art. 22) | Build the stronger GDPR-style default safeguards globally where feasible; layer Korea's proactive disclosure duty on top |
| Cross-border transfer | Five mechanisms including PIPC equivalence recognition; PIPC can order a transfer suspended mid-flight (Art. 28-9) | Adequacy, SCCs, BCRs, certification, derogations; no unilateral suspension-order power | Rely on the EU-Korea reciprocal equivalence recognition where applicable; maintain a rapid-response plan for a Korea-specific suspension order, since the objection window is only 7 days |
| Penalty exposure | 3% of total sales now, rising to 10% in aggravated cases from September 11, 2026, plus criminal fines up to KRW 100M and imprisonment | Up to EUR 20M or 4% of global turnover, administrative only | Do not benchmark PIPA risk against GDPR's fine-only model; PIPA risk includes personal liberty exposure for responsible individuals |
| CPO / privacy officer | Chief Privacy Officer required; board-approval threshold for CPO appointment at larger controllers was still pending finalization as of DLA Piper's most recent review | Data Protection Officer required for public bodies, large-scale monitoring, or sensitive-data processing | See our DPO/CPO requirements by country guide for the current appointment threshold in each jurisdiction |
Disclaimer
This article presents general legal information about South Korea's Personal Information Protection Act (PIPA) and the EU General Data Protection Regulation (GDPR). It does not constitute legal advice. PIPA continues to change through amendment; the 10% penalty-ceiling provision described above is not yet in force as of this writing. Organizations subject to PIPA or GDPR should consult a lawyer licensed in the relevant jurisdiction for advice specific to their situation.
Authorities Cited
- PIPA Article 70 (Penal Provisions -- top criminal tier). https://prighter.com/resources/laws/korean-pipa/main/articles/article-70
- PIPA Article 71 (Penal Provisions -- 5-year/KRW 50M tier). https://prighter.com/resources/laws/korean-pipa/main/articles/article-71
- PIPA Article 72 (Penal Provisions -- 3-year/KRW 30M tier). https://prighter.com/resources/laws/korean-pipa/main/articles/article-72
- PIPA Article 73 (Penal Provisions -- 2-year/KRW 20M tier). https://prighter.com/resources/laws/korean-pipa/main/articles/article-73
- PIPA Article 74 (Joint Penalty Provisions -- corporate/individual dual liability, due-care defense). https://prighter.com/resources/laws/korean-pipa/main/articles/article-74
- PIPA Article 24 (Restriction on Processing of Personally Identifiable Information). https://prighter.com/resources/laws/korean-pipa/main/articles/article-24
- PIPA Article 24-2 (Restriction on Processing of Resident Registration Numbers). https://prighter.com/resources/laws/korean-pipa/main/articles/article-24-2
- PIPA Article 37-2 (Right relating to automated decisions). https://prighter.com/resources/laws/korean-pipa/main/articles/article-37-2
- PIPA Article 28-8 (Cross-border transfer mechanisms). https://prighter.com/resources/laws/korean-pipa/main/articles/article-28-8
- PIPA Article 28-9 (PIPC order to suspend cross-border transfer). https://prighter.com/resources/laws/korean-pipa/main/articles/article-28-9
- PIPA Article 64-2 (Penalty surcharge -- current 3% ceiling and 2026 amendment). https://prighter.com/resources/laws/korean-pipa/main/articles/article-64-2
- Personal Information Protection Commission (PIPC), Republic of Korea. https://www.pipc.go.kr/eng
- PIPC enforcement notice, Coupang / Coupang Fulfillment Services penalty, June 2026. https://www.pipc.go.kr/eng/user/ltn/new/newsDetail.do?bbsId=BBSMSTR_000000000003&nttId=2711
- European Commission. Joint press statement, Commissioner Michael McGrath and PIPC Chairperson Haksoo Ko, entry into force of Korea-EU reciprocal recognition, September 16, 2025. https://commission.europa.eu/news-and-media/news/joint-press-statement-commissioner-michael-mcgrath-and-chairperson-haksoo-ko-entry-force-korean-2025-09-16_en
- European Commission. Adequacy Decisions. https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
- Regulation (EU) 2016/679 (General Data Protection Regulation). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- DLA Piper. Data Protection Laws of the World -- South Korea. https://www.dlapiperdataprotection.com/guide.pdf?c=KR
- Hunton Andrews Kurth Privacy and Cybersecurity Law Blog. South Korea Amends Privacy Law to Authorize Fines of Up to 10% of Total Revenue. https://www.hunton.com/privacy-and-cybersecurity-law-blog/south-korea-amends-privacy-law-to-authorize-fines-of-up-to-10-of-total-revenue
Laws and enforcement figures cited reflect their status as of the article's last review date. PIPA's 10% penalty-ceiling provision is scheduled to take effect September 11, 2026 and is not in force as of this writing.
Frequently Asked Questions
Does South Korea's privacy law actually put people in prison?
Yes. PIPA's Penal Provisions chapter (Articles 70-73) sets four tiers of imprisonment for data-privacy violations, up to 10 years for the most serious conduct, such as obtaining personal information by fraud and providing it to a third party for profit. GDPR, by contrast, has no criminal offense in the regulation itself; its penalties are administrative fines against the controller or processor entity.
Can a company be fined under PIPA even if an individual employee committed the violation?
Yes. PIPA Article 74's joint penalty provision allows both the individual offender and the corporation or business owner to be punished for the same Article 70-73 offense, with the corporation facing a separate fine. The one exception is a due-care defense: the provision does not apply if the corporation or business owner was not negligent in exercising due care and supervision to prevent the offense.
Is processing a Resident Registration Number a criminal offense in Korea?
No. RRN violations under Article 24-2 are enforced administratively, not criminally -- they draw fines of up to KRW 30 million per violation type and can also trigger PIPA's revenue-based penalty surcharge, but they do not appear in PIPA's criminal chapter (Articles 70-73). The criminal exposure under Article 71 applies to the broader Article 24(1) 'personally identifiable information' provision covering unique identifiers generally, which is a separate provision from the RRN-specific rule.
Is South Korea's maximum data-privacy fine 10% of revenue?
Not yet. The current ceiling on PIPA's revenue-based penalty surcharge (Article 64-2) is 3% of total sales. A 2026 amendment raising that ceiling to 10% in aggravated cases -- repeated willful or grossly negligent violations, breaches affecting 10 million or more subjects, or non-compliance with a corrective order -- was promulgated in March 2026 but its penalty-ceiling provisions do not take effect until September 11, 2026. Every enforcement action before that date, including the record Coupang penalty, is calculated under the 3% ceiling.
What was the largest data-privacy fine in South Korean history?
The PIPC's June 11, 2026 penalty against Coupang and Coupang Fulfillment Services, approximately KRW 624.68 billion (roughly US$409 million), covering a data breach affecting 37.55 million records and unlawful collection of over 15.6 million URLs from more than 11.17 million users. It is roughly 4.6 times the prior record, an approximately KRW 134.7 billion penalty against SK Telecom in August 2025.
Can Korea's regulator stop a data transfer that is already underway?
Yes. Under PIPA Article 28-9, the PIPC can order a controller to suspend an ongoing or imminent cross-border transfer if it violates the Article 28-8 transfer conditions, or if the recipient country or organization fails to adequately protect the data and the data subject has suffered, or is highly likely to suffer, damage. The controller has 7 days to object to the order. GDPR has no equivalent unilateral suspension-order power; it relies on the validity of the underlying transfer mechanism plus after-the-fact enforcement.
Does South Korea have an EU adequacy decision?
Yes, and it works in both directions. The European Commission's adequacy decision covering Korea has been in force since December 2021, allowing data to flow from the EU to Korea without additional safeguards. Separately, the PIPC recognized the EU's framework as providing an equivalent level of protection, and that recognition entered into force on September 16, 2025, allowing data to flow from Korea to the EU on the same basis.
How does PIPA treat criminal-conviction records differently from GDPR?
PIPA classifies criminal records as ordinary sensitive information under Article 23, processable with separately obtained consent, alongside categories like health data and genetic information. GDPR handles criminal-offense data under a standalone provision, Article 10, which generally reserves that processing to official authorities acting under official authority or requires specific member-state legal authorization, and does not typically accept consent as a basis for most non-authority controllers. PIPA's approach is meaningfully more permissive on this specific category.
Updates
PIPC fined Coupang and Coupang Fulfillment Services approximately KRW 624.68 billion (~US$409 million) over a data breach affecting 37.55 million records and unlawful URL collection covering 15.6 million+ URLs on 11.17 million users, the largest data-privacy fine in South Korean history, about 4.6 times the prior record set by SK Telecom in August 2025.
PIPA amendment raising the maximum penalty surcharge from 3% to 10% of total revenue in aggravated cases (willful/grossly negligent repeat violations, breaches affecting 10 million+ subjects, or non-compliance with a corrective order) passed and was promulgated. The 10% ceiling does not take effect until September 11, 2026 -- the operative ceiling today remains 3%.
Sources and References
- PIPA Article 70 (Penal Provisions, top criminal tier)(prighter.com)
- PIPA Article 71 (Penal Provisions, 5-year/KRW 50M tier)(prighter.com)
- PIPA Article 72 (Penal Provisions, 3-year/KRW 30M tier)(prighter.com)
- PIPA Article 73 (Penal Provisions, 2-year/KRW 20M tier)(prighter.com)
- PIPA Article 74 (Joint Penalty Provisions)(prighter.com)
- PIPA Article 24 (Restriction on Processing of Personally Identifiable Information)(prighter.com)
- PIPA Article 24-2 (Restriction on Processing of Resident Registration Numbers)(prighter.com)
- PIPA Article 37-2 (Right relating to automated decisions)(prighter.com)
- PIPA Article 28-8 (Cross-border transfer mechanisms)(prighter.com)
- PIPA Article 28-9 (PIPC order to suspend cross-border transfer)(prighter.com)
- PIPA Article 64-2 (Penalty surcharge, current 3% ceiling and 2026 amendment)(prighter.com)
- Personal Information Protection Commission (PIPC), Republic of Korea(pipc.go.kr).gov
- PIPC enforcement notice: Coupang / Coupang Fulfillment Services penalty (June 2026)(pipc.go.kr).gov
- European Commission joint press statement: entry into force of Korea-EU reciprocal recognition (September 16, 2025)(commission.europa.eu).gov
- European Commission Adequacy Decisions(commission.europa.eu).gov
- Regulation (EU) 2016/679 (General Data Protection Regulation)(eur-lex.europa.eu).gov
- DLA Piper: Data Protection Laws of the World -- South Korea(dlapiperdataprotection.com)
- Hunton Andrews Kurth: South Korea Amends Privacy Law to Authorize Fines of Up to 10% of Total Revenue(hunton.com)