South Korea's data-breach fines now reach 10% of total revenue
EditorialBy TrustList Editorial
The revised Personal Information Protection Act raises the ceiling from 3% of related sales to 10% of total revenue, adds a 72-hour notification duty and puts supervisory liability on the chief executive. It applies to anyone holding Korean personal data.
About South Korea's data-breach fines now reach 10% of total revenue
South Korea's data-breach fines now reach 10% of total revenue
20 September 2026 — The revised Personal Information Protection Act took effect this month, and it changes the arithmetic of a breach for any business that holds personal data about people in South Korea — including businesses with no office there.
What changed
The penalty ceiling moves from 3% of the revenue related to a violation to 10% of total revenue. The base is the part that matters: a percentage of a company's whole turnover is a different instrument from a percentage of the revenue attached to the product that leaked.
The regulator can reach for the higher ceiling in three situations, as reported: a leak affecting ten million or more people through intent or gross negligence; a repeated intentional or grossly negligent violation within three years; or a failure to comply with a corrective order followed by a breach.
Two further changes matter as much as the number. Companies must notify users within 72 hours where the risk from a breach is high, even before exposure has been confirmed — a clock that starts during the part of an incident when nobody yet knows what happened. And the reform places personal supervisory liability on the chief executive, which moves the conversation from the security team to the board.
There is relief in both directions: fines can be reduced by up to 40% for demonstrable prior investment in data protection, and by up to 40% for prompt detection and reporting.
What it means for a buyer
If your supplier chain touches Korean personal data, three questions are now worth asking in writing, and they are the same three whatever your own jurisdiction.
Which entity would be liable, and does your contract allocate that exposure or leave it where it falls? A supplier's indemnity is only as good as the entity that gave it.
Can your processors actually meet a 72-hour notification duty — not their own contractual notice period, but yours? Many data processing agreements promise notification "without undue delay", which is not a clock, and a supplier that learns of an incident on day two leaves you a day to file.
And can they evidence the investment that earns the reduction? The mitigation provisions reward documentation that exists before an incident, not after it.
For scale, the regulator fined one e-commerce company 624.6 billion won in June 2026 over a leak affecting 37.55 million people — under the previous, lower ceiling.
One date discrepancy worth noting: the national press dated the act taking effect Friday 12 September 2026, while a privacy-profession body dated it 11 September. Both are within the same week and neither changes what the law now says.
Sources
- Korea JoongAng Daily, "Korea raises data breach fines to 10% of revenue" — 10 September 2026
- IAPP, "South Korea overhauls PIPA and ties fines to CEO accountability" — 12 March 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.