What Is Personal Information Protection Act (Republic of Korea)?
The Republic of Korea's Personal Information Protection Act (PIPA) is the country's general framework for protecting personal information and the rights and interests of individuals. In the 16 September 2026 review, the effective Korean text is Act No. 20897, amended on 1 April 2025 and effective from 2 October 2025. The Korean Law Information Center also lists Enforcement Decree No. 36121 as effective from 20 August 2026 and Act No. 21445, promulgated on 10 March 2026, as effective from 11 September 2026; date-specific conclusions should distinguish effective law from future-dated changes still pending. For private controllers, the reviewed current matrix provides 10 days for access and for notifying the result of a correction/deletion or processing-stop request, while the underlying correction, deletion, and processing-stop duties operate without delay. Breach notice to affected individuals and qualifying breach reports to PIPC or KISA operate within 72 hours; large-controller source notice can be due within 3 months, with an annual alternative for recurring consent-based receipt. The current surcharge ceiling is up to 3% of total turnover, or KRW 2 billion where turnover is absent or difficult to calculate, for listed violations. Effective 11 September 2026, Act No. 21445 adds a punitive surcharge of up to 10% only in three specified circumstances; it is not a blanket new ceiling for every PIPA violation. A further mandatory certification provision remains delayed until 1 July 2027. Official PIPC materials describe individual rights to request access, correction or erasure, and suspension of processing, subject to statutory limits. The PIPC also publishes an infringement-report route operated by the Korea Internet & Security Agency (KISA), including the 118 Privacy Call Center, and a separate personal-information dispute-mediation system. This page is a source-backed orientation, not legal advice. PIPC states that its English law and guidance materials are convenience translations and that Korean materials should be consulted for complete information. No Korea-specific data-broker complaint or deletion channel was established in the reviewed primary sources, and no standalone GDPR-style targeting or monitoring test was found; Korean residence or mere possession of data alone does not establish that every non-Korean broker is in scope. This page remains noindex.
At a glance
- Full name
- Personal Information Protection Act (Republic of Korea)
- Short code
- Korea PIPA
- Jurisdiction
- Republic of Korea
- Enacted
- 2011
- Last major update
- Act No. 20897 is effective from 2 October 2025; Enforcement Decree No. 36121 took effect on 20 August 2026, and Act No. 21445 took effect on 11 September 2026; the Korean text controls
- Regulator
- Personal Information Protection Commission (PIPC)
- Private right of action
- Limited
- Statutory citation
- Personal Information Protection Act (Republic of Korea)
Scope, who Korea PIPA covers
Protected data
Data subject rights
Right to request access to personal information
Right to request correction of inaccurate personal information
Right to request erasure, subject to statutory and other-law exceptions
Right to request suspension of processing, subject to statutory exceptions
Right to receive an access-request response within 10 days, subject to the Act and Enforcement Decree
Right to receive the result of a correction/deletion or processing-stop request within 10 days, while the underlying action or stop duty operates without delay
Right to receive breach notice within 72 hours when the current Enforcement Decree’s rule applies
Right to report an infringement of personal-information rights or interests to the PIPC-designated KISA Privacy Call Center
Right to seek personal-information dispute mediation, including requests related to access, correction, deletion, suspension, or compensation
Right to use the remedies and appeal routes provided by the Act and applicable implementing rules
Notable features
Korea combines a comprehensive personal-information statute with a central PIPC, KISA infringement reporting, and a dedicated dispute-mediation system. PIPC publishes English reference materials, but its official law page warns that the original Korean materials are the more complete source; translated summaries should therefore carry an explicit currency and language boundary.
Enforcement & penalties
Regulator: Personal Information Protection Commission (PIPC)
Penalties: The current surcharge ceiling is up to 3% of total turnover, or up to KRW 2 billion where turnover is absent or difficult to calculate, for listed violations; this is not a universal penalty for every PIPA breach. An enacted amendment taking effect on 11 September 2026 provides a punitive surcharge of up to 10% only for three specified circumstances: a qualifying same-category violation within three years after a prior surcharge, intentional or grossly negligent qualifying conduct affecting at least 10 million individuals, or failure to comply with a corrective order leading to a qualifying violation. It is not a blanket 10% ceiling. Current administrative fines are separate, including up to KRW 30 million for specified source-information, use/provision-history, or destruction failures. The mandatory certification provision for specified future controllers is delayed until 1 July 2027; future implementing details remain open.
Private right of action: PIPC materials describe personal-information dispute mediation, compensation-related applications, and civil-suit alternatives when mediation is not accepted. This explainer does not characterize every route as a universal private cause of action; the exact remedy depends on the current Korean Act, implementing rules, facts, and the selected forum.
Relevance to data brokers
A people-search, directory, advertising, or other data intermediary may need to assess PIPA obligations based on its role, processing purpose, source, notice, retention, and applicable sector rules. No Korea-specific data-broker complaint or deletion channel was established in the reviewed primary sources. The verified route is to submit an Article 35, 36, or 37 request directly to the controller, then report an infringement through the KISA Privacy Infringement Report Center/PIPC route or use general dispute mediation where appropriate; the Financial Supervisory Service 1332 route is for credit-information and personal-credit-information complaints, not the general data-broker route. No standalone GDPR-style targeting or monitoring test was found, so “every non-Korean broker holding Korean data is in scope” is not established. Identify the current controller, use its current privacy contact, retain delivery evidence, and do not assume a universal broker form or guaranteed removal result.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What is South Korea's main privacy law?+
The Personal Information Protection Act (PIPA) is South Korea's general privacy statute. The effective text identified for the 7 September 2026 review is Act No. 20897, amended on 1 April 2025 and effective on 2 October 2025. The Korean Law Information Center also lists Enforcement Decree No. 36121 as effective on 20 August 2026 and Act No. 21445 as enacted for 11 September 2026, so date-specific advice should distinguish current law from future changes.
What rights does Korea's PIPA provide?+
PIPA provides access, correction, erasure, and processing-stop rights subject to statutory limits. For a private controller, the reviewed rules provide 10 days for access and for notifying the result of a correction/deletion or processing-stop request; the underlying correction, deletion, and processing-stop duties operate without delay. The current Enforcement Decree also provides a 72-hour breach-notice rule when its conditions apply.
Can I ask a Korean data broker to delete my information?+
You can ask the current controller to correct or erase personal information when the Act's conditions apply, but no Korea-specific data-broker complaint or deletion channel was established in the reviewed primary sources. Submit the applicable request directly to the controller, and use the general KISA/PIPC infringement-report route or dispute mediation where appropriate. The Financial Supervisory Service 1332 channel is a separate financial-sector route, not the general broker route.
How do I report a personal-information infringement in Korea?+
The PIPC publishes an infringement-report system operated by KISA. Its official page lists the Privacy Call Center at 118, the reporting website at privacy.kisa.or.kr, and 118@kisa.or.kr. Check the official page immediately before filing because channels and instructions can change.
What is Korea's personal-information dispute mediation system?+
The PIPC describes a Personal Information Dispute Mediation Committee that can handle disputes about processing, access, correction, deletion, suspension, and compensation-related requests. If both parties accept an established mediation, the PIPC explains that it can have the effect of a settlement before the court; a rejected mediation may lead to other remedies such as a civil suit.
Is there a general PIPA response deadline for every data broker?+
For a private controller, the reviewed PIPA framework provides 10 days for access and for notifying the result of a correction/deletion or processing-stop request; correction, deletion, and processing-stop action itself is due without delay. This is not an unconditional 10-day deletion-completion guarantee, and the request type, exceptions, controller, statutory text, and implementing rules must be checked separately.
Can I rely on an English translation of Korea's PIPA?+
Use the English material as a research aid, not as the controlling text. PIPC states that its documents are produced in Korean in principle and that English translations are provided for convenience; the current Korean statute and regulations should control a legal conclusion.
Does Korea's PIPA guarantee removal from a public-record listing?+
No. Access, correction, erasure, and suspension rights have statutory conditions and exceptions. A broker's source, role, purpose, retention duty, sector rules, and the accuracy or legality of the processing all matter; OfflistMe can help draft a request for review and sending but cannot guarantee a result.
Does PIPA apply to every non-Korean broker holding Korean data?+
That is not established. The reviewed sources cover overseas transfers and qualifying foreign controllers with domestic-representative duties, but did not establish a standalone GDPR-style targeting or monitoring test. Korean residence or mere possession of Korean data alone does not prove that every non-Korean broker is in scope; the controller, processing, statutory scope, and applicable thresholds must be assessed.
Official sources & citations
- Korean Law Information Center: current Personal Information Protection Act search
- Korean Law Information Center: English translations of privacy laws
- Korean Law Information Center: PIPA amendment history
- Korean Law Information Center: PIPA current text
- Korean Law Information Center: PIPA Enforcement Decree current entry
- PIPC: Laws and Regulations
- PIPC: Privacy Policy and Individual Rights
- PIPC: Reporting on Infringement of Personal Information
- PIPC: Personal Information Dispute Mediation
- Korean Law Information Center: PIPA Article 35
- Korean Law Information Center: PIPA Article 36
- Korean Law Information Center: PIPA Article 37
- Korean Law Information Center: PIPA Enforcement Decree Articles 41 and 42
- Korean Law Information Center: PIPA Enforcement Decree Article 43
- Korean Law Information Center: PIPA Enforcement Decree Article 44
- Korean Law Information Center: PIPA Enforcement Decree Articles 39 and 40
- Korean Law Information Center: PIPA Enforcement Decree Article 15-2
- Korean Law Information Center: PIPA Article 20-2 and Enforcement Decree Article 15-3
- Korean Law Information Center: PIPA Article 64-2 surcharge
- Korean Law Information Center: PIPA Article 75
- Korean Law Information Center: Law No. 21445 amendment history
- PIPC: Law No. 21445 amendment release
- PIPC: infringement-report procedure
- Korean Law Information Center: PIPA Article 62
- Korean Law Information Center: PIPA Articles 28-8 to 28-11
- Korean Law Information Center: PIPA Article 31-2
- Korean Law Information Center: PIPA Enforcement Decree Article 32-3
Other international privacy regimes
Korea PIPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
