Skip to main content
Republic of Korea · Reviewed September 2026

What Is Personal Information Protection Act (Republic of Korea)?

The Republic of Korea's Personal Information Protection Act (PIPA) is the country's general framework for protecting personal information and the rights and interests of individuals. In the 16 September 2026 review, the effective Korean text is Act No. 20897, amended on 1 April 2025 and effective from 2 October 2025. The Korean Law Information Center also lists Enforcement Decree No. 36121 as effective from 20 August 2026 and Act No. 21445, promulgated on 10 March 2026, as effective from 11 September 2026; date-specific conclusions should distinguish effective law from future-dated changes still pending. For private controllers, the reviewed current matrix provides 10 days for access and for notifying the result of a correction/deletion or processing-stop request, while the underlying correction, deletion, and processing-stop duties operate without delay. Breach notice to affected individuals and qualifying breach reports to PIPC or KISA operate within 72 hours; large-controller source notice can be due within 3 months, with an annual alternative for recurring consent-based receipt. The current surcharge ceiling is up to 3% of total turnover, or KRW 2 billion where turnover is absent or difficult to calculate, for listed violations. Effective 11 September 2026, Act No. 21445 adds a punitive surcharge of up to 10% only in three specified circumstances; it is not a blanket new ceiling for every PIPA violation. A further mandatory certification provision remains delayed until 1 July 2027. Official PIPC materials describe individual rights to request access, correction or erasure, and suspension of processing, subject to statutory limits. The PIPC also publishes an infringement-report route operated by the Korea Internet & Security Agency (KISA), including the 118 Privacy Call Center, and a separate personal-information dispute-mediation system. This page is a source-backed orientation, not legal advice. PIPC states that its English law and guidance materials are convenience translations and that Korean materials should be consulted for complete information. No Korea-specific data-broker complaint or deletion channel was established in the reviewed primary sources, and no standalone GDPR-style targeting or monitoring test was found; Korean residence or mere possession of data alone does not establish that every non-Korean broker is in scope. This page remains noindex.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated September 16, 2026

At a glance

Full name
Personal Information Protection Act (Republic of Korea)
Short code
Korea PIPA
Jurisdiction
Republic of Korea
Enacted
2011
Last major update
Act No. 20897 is effective from 2 October 2025; Enforcement Decree No. 36121 took effect on 20 August 2026, and Act No. 21445 took effect on 11 September 2026; the Korean text controls
Regulator
Personal Information Protection Commission (PIPC)
Private right of action
Limited

Scope, who Korea PIPA covers

PIPA regulates the processing and protection of personal information by organizations and other actors within the scope defined by the Act. Personal information includes information relating to a living individual who can be identified directly or indirectly, including through combination with other information. The Act contains statutory exclusions, sector rules, and detailed conditions that are not fully summarized here; a listing visible in Korea does not by itself establish that every provision applies. The reviewed sources did not establish a standalone GDPR-style targeting or monitoring test, so Korean residence or mere possession of Korean data does not establish that every non-Korean data broker is in scope; the controller, processing, PIPA scope, and any domestic-representative or overseas-transfer provisions must be assessed.

Protected data

Personal information is information about a living person that can identify the person directly or indirectly. The Act and its implementing framework distinguish additional categories and safeguards, including sensitive information, unique identifying information, pseudonymized information, and security or retention controls. The controlling Korean statute and current regulations should be checked for a particular data set.

Data subject rights

Right to request access to personal information

Right to request correction of inaccurate personal information

Right to request erasure, subject to statutory and other-law exceptions

Right to request suspension of processing, subject to statutory exceptions

Right to receive an access-request response within 10 days, subject to the Act and Enforcement Decree

Right to receive the result of a correction/deletion or processing-stop request within 10 days, while the underlying action or stop duty operates without delay

Right to receive breach notice within 72 hours when the current Enforcement Decree’s rule applies

Right to report an infringement of personal-information rights or interests to the PIPC-designated KISA Privacy Call Center

Right to seek personal-information dispute mediation, including requests related to access, correction, deletion, suspension, or compensation

Right to use the remedies and appeal routes provided by the Act and applicable implementing rules

Notable features

Korea combines a comprehensive personal-information statute with a central PIPC, KISA infringement reporting, and a dedicated dispute-mediation system. PIPC publishes English reference materials, but its official law page warns that the original Korean materials are the more complete source; translated summaries should therefore carry an explicit currency and language boundary.

Enforcement & penalties

Regulator: Personal Information Protection Commission (PIPC)

Penalties: The current surcharge ceiling is up to 3% of total turnover, or up to KRW 2 billion where turnover is absent or difficult to calculate, for listed violations; this is not a universal penalty for every PIPA breach. An enacted amendment taking effect on 11 September 2026 provides a punitive surcharge of up to 10% only for three specified circumstances: a qualifying same-category violation within three years after a prior surcharge, intentional or grossly negligent qualifying conduct affecting at least 10 million individuals, or failure to comply with a corrective order leading to a qualifying violation. It is not a blanket 10% ceiling. Current administrative fines are separate, including up to KRW 30 million for specified source-information, use/provision-history, or destruction failures. The mandatory certification provision for specified future controllers is delayed until 1 July 2027; future implementing details remain open.

Private right of action: PIPC materials describe personal-information dispute mediation, compensation-related applications, and civil-suit alternatives when mediation is not accepted. This explainer does not characterize every route as a universal private cause of action; the exact remedy depends on the current Korean Act, implementing rules, facts, and the selected forum.

Relevance to data brokers

A people-search, directory, advertising, or other data intermediary may need to assess PIPA obligations based on its role, processing purpose, source, notice, retention, and applicable sector rules. No Korea-specific data-broker complaint or deletion channel was established in the reviewed primary sources. The verified route is to submit an Article 35, 36, or 37 request directly to the controller, then report an infringement through the KISA Privacy Infringement Report Center/PIPC route or use general dispute mediation where appropriate; the Financial Supervisory Service 1332 route is for credit-information and personal-credit-information complaints, not the general data-broker route. No standalone GDPR-style targeting or monitoring test was found, so “every non-Korean broker holding Korean data is in scope” is not established. Identify the current controller, use its current privacy contact, retain delivery evidence, and do not assume a universal broker form or guaranteed removal result.

Generate requests in under 60 seconds

Generate removal requests for 1,034 US/global profiles, $9

OfflistMe helps draft opt-out requests using the details you choose. Review the provider route and legal basis, then send from your own inbox. The tool is not legal advice and does not guarantee a broker's response.

FAQ

What is South Korea's main privacy law?+

The Personal Information Protection Act (PIPA) is South Korea's general privacy statute. The effective text identified for the 7 September 2026 review is Act No. 20897, amended on 1 April 2025 and effective on 2 October 2025. The Korean Law Information Center also lists Enforcement Decree No. 36121 as effective on 20 August 2026 and Act No. 21445 as enacted for 11 September 2026, so date-specific advice should distinguish current law from future changes.

What rights does Korea's PIPA provide?+

PIPA provides access, correction, erasure, and processing-stop rights subject to statutory limits. For a private controller, the reviewed rules provide 10 days for access and for notifying the result of a correction/deletion or processing-stop request; the underlying correction, deletion, and processing-stop duties operate without delay. The current Enforcement Decree also provides a 72-hour breach-notice rule when its conditions apply.

Can I ask a Korean data broker to delete my information?+

You can ask the current controller to correct or erase personal information when the Act's conditions apply, but no Korea-specific data-broker complaint or deletion channel was established in the reviewed primary sources. Submit the applicable request directly to the controller, and use the general KISA/PIPC infringement-report route or dispute mediation where appropriate. The Financial Supervisory Service 1332 channel is a separate financial-sector route, not the general broker route.

How do I report a personal-information infringement in Korea?+

The PIPC publishes an infringement-report system operated by KISA. Its official page lists the Privacy Call Center at 118, the reporting website at privacy.kisa.or.kr, and 118@kisa.or.kr. Check the official page immediately before filing because channels and instructions can change.

What is Korea's personal-information dispute mediation system?+

The PIPC describes a Personal Information Dispute Mediation Committee that can handle disputes about processing, access, correction, deletion, suspension, and compensation-related requests. If both parties accept an established mediation, the PIPC explains that it can have the effect of a settlement before the court; a rejected mediation may lead to other remedies such as a civil suit.

Is there a general PIPA response deadline for every data broker?+

For a private controller, the reviewed PIPA framework provides 10 days for access and for notifying the result of a correction/deletion or processing-stop request; correction, deletion, and processing-stop action itself is due without delay. This is not an unconditional 10-day deletion-completion guarantee, and the request type, exceptions, controller, statutory text, and implementing rules must be checked separately.

Can I rely on an English translation of Korea's PIPA?+

Use the English material as a research aid, not as the controlling text. PIPC states that its documents are produced in Korean in principle and that English translations are provided for convenience; the current Korean statute and regulations should control a legal conclusion.

Does Korea's PIPA guarantee removal from a public-record listing?+

No. Access, correction, erasure, and suspension rights have statutory conditions and exceptions. A broker's source, role, purpose, retention duty, sector rules, and the accuracy or legality of the processing all matter; OfflistMe can help draft a request for review and sending but cannot guarantee a result.

Does PIPA apply to every non-Korean broker holding Korean data?+

That is not established. The reviewed sources cover overseas transfers and qualifying foreign controllers with domestic-representative duties, but did not establish a standalone GDPR-style targeting or monitoring test. Korean residence or mere possession of Korean data alone does not prove that every non-Korean broker is in scope; the controller, processing, statutory scope, and applicable thresholds must be assessed.

Official sources & citations

Other international privacy regimes

Korea PIPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:

United Kingdom · enacted 2018What is UK GDPR?Canada · enacted 2000What is PIPEDA?Brazil · enacted 2018What is LGPD?India · enacted 2023What is DPDP Act?Australia · enacted 1988What is Privacy Act 1988?Japan · enacted 2003What is APPI?China · enacted 2021What is PIPL?France · enacted 1978What is Loi Informatique et Libertés?Germany · enacted 2018What is BDSG?Argentina · enacted 2000What is Law 25.326?Philippines · enacted 2012What is RA 10173?South Africa · enacted 2013What is POPIA?Malaysia · enacted 2010What is Malaysia PDPA?United Arab Emirates · enacted 2021What is UAE PDPL?Netherlands · enacted 2018What is UAVG?Nigeria · enacted 2023What is NDPA?Pakistan · enacted 2016What is PECA + Art. 14?Peru · enacted 2011What is Law 29733?Saudi Arabia · enacted 2021What is PDPL?Thailand · enacted 2019What is Thai PDPA?Türkiye · enacted 2016What is KVKK?Viet Nam · enacted 2025What is Law No. 91/2025?Poland · enacted 2018What is Poland GDPR + UODO Act?Portugal · enacted 2019What is Portugal GDPR + Lei 58/2019?Romania · enacted 2018What is Romania GDPR + Law 190/2018?Bangladesh · enacted 2026What is Act No. 63 of 2026?Chile · enacted 2024What is Law 21.719?Colombia · enacted 2012What is Law 1581?Egypt · enacted 2020What is Law No. 151 of 2020?Indonesia · enacted 2022What is UU PDP?Israel · enacted 1981What is Privacy Law 5741-1981?Kazakhstan · enacted 2013What is Law No. 94-V?Mexico · enacted 2025What is LFPDPPP (2025)?Albania · enacted 2024What is Law 124/2024?Armenia · enacted 2015What is HO-49-N?Azerbaijan · enacted 2010What is Law 998-IIIQ?Bosnia and Herzegovina · enacted 2025What is Law 12/25?Hungary · enacted 2011What is Info tv. + GDPR?Iceland · enacted 2018What is Act No. 90/2018 + GDPR?Jamaica · enacted 2020What is Data Protection Act 2020?Kenya · enacted 2019What is Data Protection Act 2019?Kyrgyzstan · enacted 2025What is Digital Code?Latvia · enacted 2018What is PDL?Luxembourg · enacted 2018What is Law of 1 August 2018?Malta · enacted 2018What is Chapter 586?Republic of Moldova · enacted 2024What is Law no. 195/2024?Mongolia · enacted 2021What is Law on Personal Data Protection?Montenegro · enacted 2008What is Law on Personal Data Protection?Morocco · enacted 2009What is Law 09-08?Estonia · enacted 2018What is IKS?Georgia · enacted 2023What is Law No. 3144?Ghana · enacted 2012What is Act 843?Greece · enacted 2019What is Law 4624/2019?North Macedonia · enacted 2020What is Law 42/2020?Russian Federation · enacted 2006What is 152-FZ?Senegal · enacted 2008What is Law No. 2008-12?Serbia · enacted 2018What is Law 87/2018?Slovakia · enacted 2018What is Act No. 18/2018 Coll.?Slovenia · enacted 2022What is ZVOP-2?Sri Lanka · enacted 2022What is PDPA?Tunisia · enacted 2004What is Organic Law No. 2004-63?Ukraine · enacted 2010What is Law No. 2297-VI?Bulgaria · enacted 2001What is PDPA?Croatia · enacted 2018What is Act on the Implementation of the GDPR?Cyprus · enacted 2018What is Law 125(I)/2018?Czechia · enacted 2019What is Act No. 110/2019 Coll.?Austria · enacted 1999What is DSG?Belgium · enacted 2018What is Belgian Data Protection Act?Denmark · enacted 2018What is Databeskyttelsesloven?Finland · enacted 2018What is Data Protection Act 1050/2018?Norway · enacted 2018What is Personal Data Act?Afghanistan · enacted 2010What is Sectoral Privacy Protections?Algeria · enacted 2018What is Law No. 18-07 + Law No. 25-11?Andorra · enacted 2021What is LQPD?Angola · enacted 2011What is Law No. 22/11?Antigua and Barbuda · enacted 2013What is Data Protection Act 2013?Bahamas · enacted 2003What is DPA 2003?Bahrain · enacted 2018What is Law No. 30 of 2018?Barbados · enacted 2019What is Data Protection Act 2019-29?Belarus · enacted 2021What is Law No. 99-Z?Belize · enacted 2021What is Data Protection Act 2021?Benin · enacted 2018What is Code du numérique, Book V?Bhutan · enacted 2018What is ICM Act 2018 + NDGF 2025?Bolivia (Plurinational State of) · enacted 2009What is Art. 21(2), 25, 130–131 + Law 254?Botswana · enacted 2024What is Data Protection Act 2024?Brunei Darussalam · enacted 2025What is PDPO 2025?Burkina Faso · enacted 2021What is Loi n°001-2021/AN?Burundi · enacted 2026What is Law No. 1/03 of 2026?Cabo Verde · enacted 2001What is Lei n.º 133/V/2001?Cambodia · enacted 2019What is Fragmented privacy framework?Cameroon · enacted 2024What is Law No. 2024/017?Central African Republic · enacted 2024What is Law No. 24.001?Costa Rica · enacted 2011What is Ley 8968?Ecuador · enacted 2021What is LOPDP?El Salvador · enacted 2024What is LPDP?Dominican Republic · enacted 2013What is Ley 172-13?Sweden · enacted 2018What is GDPR + Data Protection Act?Malawi · enacted 2024What is Malawi DPA 2024?Mali · enacted 2013What is Mali Law 2013-015?Mauritania · enacted 2017What is Mauritania Law 2017-020?Mauritius · enacted 2017What is Mauritius DPA 2017?Monaco · enacted 2024What is Monaco Law 1.565?Nepal · enacted 2018What is Nepal Privacy Act 2075?Oman · enacted 2022What is Oman PDPL?Panama · enacted 2019What is Panama Ley 81/2019?Paraguay · enacted 2025What is Paraguay Law 7593/2025?Qatar · enacted 2016What is Qatar Law No. 13 of 2016?Rwanda · enacted 2021What is Rwanda Law 058/2021?Saint Lucia · enacted 2011What is Saint Lucia DPA 2011?Togo · enacted 2019What is Togo Law 2019-014?Turkmenistan · enacted 2017What is Turkmenistan Law 519-V?United Republic of Tanzania · enacted 2022What is Tanzania PDPA 2022?Uruguay · enacted 2008What is Uruguay Ley 18.331?Vanuatu · enacted 2024What is Vanuatu DPPA 2024?Zimbabwe · enacted 2021What is Zimbabwe Cyber and Data Protection Act?Chad · enacted 2015What is Chad Law 007/PR/2015?Comoros · not enacted in this profileWhat is Comoros Personal Data Law 2014?Congo · enacted 2019What is Congo Law 29-2019?Côte d'Ivoire · enacted 2013What is Côte d'Ivoire Law 2013-450?Cuba · enacted 2022What is Cuba Law 149/2022?Democratic People's Republic of Korea · enacted 2022What is DPRK Information Law materials?Democratic Republic of the Congo · enacted 2023What is DRC Digital Code 2023?Djibouti · enacted 2025What is Djibouti Digital Code 2025?Equatorial Guinea · enacted 2016What is Equatorial Guinea Law 1/2016?Eswatini · enacted 2022What is Eswatini Data Protection Act 2022?Ethiopia · enacted 2024What is Ethiopia Proclamation No. 1321/2024?Fiji · enacted 2018What is Fiji Privacy Framework?Gabon · enacted 2023What is Gabon Law 025/2023?Grenada · enacted 2023What is Grenada Data Protection Act 2023?Guinea · enacted 2016What is Guinea Law L/2016/037/AN?Guyana · enacted 2023What is Guyana Data Protection Act 2023?Haiti · enacted 2018What is Haiti 2018 Data Privacy Order?Iran (Islamic Republic of) · enacted 2003What is Iran Electronic Commerce Act 2003?Jordan · enacted 2023What is Jordan Personal Data Protection Law No. 24 of 2023?Kiribati · enacted 2025What is Kiribati Data Protection Act 2025?Kuwait · enacted 2024What is Kuwait CITRA Decision 2024/26?Lao People's Democratic Republic · enacted 2017What is Lao Law 25/NA?Lebanon · enacted 2018What is Lebanon Law 81/2018?Lesotho · enacted 2011What is Lesotho Data Protection Act 2011?Liberia · not enacted in this profileWhat is Liberia Data Protection Act 2024?Libya · enacted 2022What is Libya Law No. 6 of 2022?Liechtenstein · enacted 2026What is Liechtenstein DSG 2026?Madagascar · enacted 2015What is Madagascar Law 2014-038?Marshall Islands · enacted 2025What is Marshall Islands PDPA 2025?Mozambique · not enacted in this profileWhat is Mozambique Privacy Framework?Myanmar · enacted 2017What is Myanmar Privacy and Security Law?Nicaragua · enacted 2012What is Nicaragua Law No. 787?Niger · enacted 2022What is Niger Law No. 2022-59?Saint Kitts and Nevis · enacted 2018What is Saint Kitts and Nevis DPA No. 5 of 2018?Saint Vincent and the Grenadines · enacted 2003What is Saint Vincent and the Grenadines Privacy Act No. 18 of 2003?San Marino · enacted 2018What is San Marino Law No. 171/2018?Sao Tome and Principe · enacted 2016What is Lei n.º 03/2016?Seychelles · enacted 2023What is Seychelles Data Protection Act 2023?Somalia · enacted 2023What is Somalia Data Protection Act 2023?Syrian Arab Republic · enacted 2024What is Law No. 12 of 2024?Tajikistan · enacted 2018What is Law No. 1537?Tonga · enacted 2025What is Privacy Act 2025?Trinidad and Tobago · enacted 2011What is Trinidad and Tobago DPA 2011?Uganda · enacted 2019What is Uganda DPA 2019?United States of America · enacted 2013What is U.S. Privacy Law?Uzbekistan · enacted 2019What is Law No. O‘RQ-547?Venezuela (Bolivarian Republic of) · enacted 1999What is Constitution Article 28?Yemen · enacted 2012What is Law No. 13 of 2012?Zambia · enacted 2021What is Zambia Data Protection Act 2021?Holy See · enacted 2024What is Decree DCLVII?State of Palestine · not enacted in this profileWhat is Palestinian Data Protection Law (draft)?

Related concepts & guides