Korea PIPA Compliance for Foreign Companies: Penalties, Data Transfers and Breach Response

Korea PIPA compliance for foreign companies
Korea PIPA Compliance for Foreign Companies: Penalties, Data Transfers and Breach Response 6

Korean rules, translated into decisions

Korea PIPA Compliance for Foreign Companies: Penalties, Data Transfers and Breach Response

A company does not need to be incorporated in South Korea before Korean privacy law becomes relevant. The Personal Information Protection Commission’s guidance says the Personal Information Protection Act, usually called PIPA, may apply when an overseas business targets Korean data subjects, processes their personal information in a way that has a direct and significant effect on them, or operates relevant data-processing activities through a Korean establishment.

For a foreign SaaS company, marketplace, app, retailer or platform, the expensive mistakes are often not exotic cyberattacks. They are quieter: a global privacy notice that does not describe the Korean data flow properly, overseas cloud access treated as an afterthought, the wrong legal basis for a transfer, or an incident team that discovers too late that Korea has its own 72-hour breach clock.

APPLICABILITY
Being offshore does not automatically put you outside PIPA.
TRANSFERS
Overseas provision, outsourced processing and storage need to be mapped separately.
BREACHES
Do not wait for perfect forensic certainty before assessing the 72-hour obligations.

The first useful compliance document is not a 70-page policy. It is a one-page map showing what Korean personal data you collect, why you use it, where it goes and who can access it.

Snapshot

This guide is for foreign companies processing personal information connected with Korean users, customers or other data subjects. Start by deciding whether PIPA applies and identifying every Korean data flow. Then classify overseas transfers, confirm whether a Korean domestic agent is required, and build a breach playbook around the 72-hour notification and reporting rules. As of August 2026, the general PIPA penalty-surcharge ceiling remains up to 3% under Article 64-2, while a stricter maximum of up to 10% for specified serious or repeat cases is scheduled to take effect on September 11, 2026.

Korea PIPA compliance for foreign companies
Korea PIPA Compliance for Foreign Companies: Penalties, Data Transfers and Breach Response 7

Does Korean PIPA Apply to Your Foreign Company?

A foreign headquarters address is not a reliable PIPA exemption. The PIPC’s guidance for overseas business operators identifies three important situations in which Korean privacy requirements may reach a foreign business: providing goods or services to Korean data subjects, processing Korean personal information in a way that has a direct and significant effect on Korean data subjects, or maintaining a relevant place of business in Korea.

For targeted services, the regulator may look at practical signals rather than the wording in your corporate chart. A Korean-language interface, KRW pricing, Korean delivery or customer-support arrangements, Korean marketing and the way the service is actually offered can all help show that Korean users are being targeted.

A simple applicability test

  • Are you deliberately selling to or enrolling Korean users? Treat PIPA as a live compliance issue.
  • Do you collect or publish information about people in Korea even without targeting the Korean market? Examine whether the processing has a direct and significant effect on them.
  • Does a Korean subsidiary, branch or establishment participate in the processing? Map which legal entity actually determines the purposes and means of processing.
  • Does an overseas parent receive, query or remotely access Korean customer data? Do not stop the analysis at the Korean entity. The international data movement may trigger separate requirements.

The last point causes particular trouble in multinational groups. Corporate ownership does not turn separate legal entities into one privacy-law organism. Data moving from a Korean operation to a Singapore, U.S., UK or European parent may still require a Korean-law transfer analysis.

Before You Act

This article can help you identify the compliance questions and evidence your company should organize. It cannot determine whether a particular processing operation is lawful without the facts, contracts and technical data flow. Obtain Korean privacy advice before launching a high-risk processing activity, responding to a regulator, relying on an uncertain cross-border transfer basis, or making a breach-notification decision where the facts are contested.

Build the Korean Data Map Before Fixing the Privacy Policy

The fastest way to create a beautiful but inaccurate PIPA program is to begin by rewriting the privacy policy. Start with the processing operations underneath it.

PIPA permits collection and use under several legal bases, including consent, legal obligations, contractual necessity and, under defined conditions, legitimate interests that clearly override the data subject’s rights and remain within a reasonable scope. Consent is therefore important, but it is not the only possible basis for every ordinary processing activity.

For each Korean data flow, record eight things

  1. The category of data collected.
  2. The business purpose for collecting and using it.
  3. The legal basis relied upon.
  4. The legal entity acting as the personal information controller.
  5. Every internal and external recipient.
  6. Every country from which the information can be accessed, processed or stored.
  7. The retention period and deletion trigger.
  8. The security controls and contractual safeguards attached to the processing.

This exercise often uncovers the real compliance problems. A company may discover that its Korean privacy notice describes a Seoul entity while the customer database is controlled from California, fraud reviews are handled in Singapore, support tickets are searchable from India and analytics data is retained by a different vendor in Japan.

PIPA also requires controllers to take technical, managerial and physical measures necessary to protect personal information, including measures involving internal management and access records. A privacy program that exists only in legal documents is therefore incomplete.

Key decision: If your privacy policy says data stays with one entity but your architecture diagram shows four overseas recipients, fix the map before fixing the prose. Korean disclosure obligations follow the real processing, not the tidiest version of the org chart.

Cross-Border Transfers: The Rule Foreign Companies Most Often Misread

Under Article 28-8, cross-border transfer is broader than simply sending a spreadsheet overseas. The statute addresses overseas provision of personal information, including situations in which information can be queried, as well as entrusted processing and overseas storage.

That means a foreign company’s compliance inventory should capture cloud hosting, offshore customer support, remote administrative access, fraud review, global CRM access, analytics platforms, centralized HR systems and group-company access where Korean personal information is involved.

The lawful basis depends on what kind of transfer you are making

Transfer situationWhat to testTypical compliance question
Separate consentWhether the data subject has given legally sufficient separate consent for the overseas transferWere the required transfer details clearly presented?
Contract-performance outsourcing or storageWhether overseas entrusted processing or storage is necessary to conclude or perform the contract with the data subjectWere the prescribed transfer details disclosed in the privacy policy or otherwise communicated as permitted?
Statutory, treaty or international-agreement basisWhether a specific legal instrument authorizes the transferDoes the instrument actually cover this data and purpose?
Recognized certification routeWhether the recipient meets a PIPC-recognized certification route and required safeguardsDoes the certification cover the recipient and processing at issue?
Recognized equivalent protectionWhether the destination country or international organization has been recognized by the PIPC as providing a substantially equivalent level of protectionIs there a current recognition applicable to this transfer?

The contract-performance route deserves particular care. Article 28-8 permits necessary overseas entrusted processing or storage for contract conclusion or performance where the statutory disclosure or notice conditions are satisfied. It should not be casually stretched into a universal exemption for every overseas disclosure to an independent third party.

What separate transfer consent needs to explain

Where separate consent is the chosen basis, Article 28-8 identifies information that must be given to the data subject, including the personal information transferred, destination country, timing and method, recipient and contact information, recipient’s purpose and retention period, and how the data subject can refuse the transfer along with the effect of refusing.

This is one reason a generic sentence such as “we may share information with global partners” is a poor compliance foundation.

Show me the nerdy details: “provision” vs “entrustment”

A common multinational habit is to put every external data flow under the English word “sharing.” Korean compliance analysis needs more precision.

Entrusted processing generally describes a recipient performing processing on behalf of the controller. Provision to a third party can involve the recipient using the information under its own responsibility or purpose. Those classifications can lead to different legal requirements.

The PIPC’s foreign-business guidance specifically warns overseas companies to distinguish provision from consignment rather than collapsing both into an undifferentiated “sharing” label.

The PIPC has enforced this distinction against foreign platforms. In 2024 it imposed a KRW 1.978 billion penalty surcharge on AliExpress in connection with cross-border transfer violations, along with other measures, and in 2025 it sanctioned Temu over unlawful cross-border data-transfer practices and related PIPA issues.

Korea PIPA compliance for foreign companies
Korea PIPA Compliance for Foreign Companies: Penalties, Data Transfers and Breach Response 8

Do You Need a Domestic Agent in Korea?

Large overseas controllers with no address or place of business in Korea may have to appoint a domestic agent. This is not simply a mailing-address service. The statutory role covers specified Korean privacy functions including complaints and redress, breach notification and reporting, and responding to PIPC requests for materials.

Under the current Enforcement Decree, the designation requirement applies when an overseas controller without a Korean address or business office meets at least one prescribed condition, including the following thresholds:

  • KRW 1 trillion or more in total sales in the preceding business year;
  • an average of at least 1 million Korean data subjects per day whose personal information was stored or managed during the three months immediately preceding the end of the prior year; or
  • a PIPC determination that appointment is necessary after the controller has been required to submit materials under Article 63.

The sales test uses total sales, and foreign-currency sales are converted using the previous year’s average exchange rate.

The domestic-agent regime was strengthened from October 2025. Where a controller subject to the rule has a qualifying Korean corporation that it established or controls within the statutory framework, the controller must designate an eligible Korean corporation as its domestic agent. The implementing rules also require management and supervision, including at least annual training and checks on the agent’s work plan and implementation.

Key decision: Do not assume that appointing a local law firm or consultant solves the domestic-agent issue. First determine whether the requirement applies, then confirm whether the amended rules require an existing qualifying Korean affiliate to take the role.

PIPA Penalties: What the 3% and Coming 10% Numbers Really Mean

As of August 18, 2026, Article 64-2 permits the PIPC to impose a penalty surcharge of up to 3% of total sales for specified serious PIPA violations. Where the business has no sales or sales cannot be calculated in circumstances prescribed by decree, the present statutory ceiling is KRW 2 billion.

The headline needs one important qualification. For calculating a penalty surcharge, the law provides for exclusion of sales unrelated to the violation. The Enforcement Decree describes unrelated sales as including revenue from goods or services unrelated to personal-information processing and revenue the PIPC recognizes as not directly or indirectly affected by the violation.

A major change is already on the calendar

On September 11, 2026, an amended PIPA is scheduled to introduce a higher penalty ceiling of up to 10% of annual turnover for defined aggravated cases. This is not a blanket 10% maximum for every privacy mistake. The higher tier is aimed at circumstances such as specified repeat violations involving intent or gross negligence, intentional or grossly negligent violations affecting at least 10 million data subjects, and certain breaches connected with failure to comply with corrective orders.

RiskPosition on August 18, 2026What changes September 11, 2026
Ordinary Article 64-2 surcharge casesUp to 3% under the existing frameworkThe baseline 3% framework remains relevant
Specified aggravated casesNo general 10% tier yet in forceUp to 10% may become available for the defined serious or repeat cases
Corrective measuresPIPC can order cessation, temporary suspension or other necessary protective actionRegulatory governance and accountability requirements are also being strengthened

Financial exposure also should not be reduced to the surcharge percentage. Depending on the violation, a company may face administrative fines, corrective orders, publication consequences, remediation expenses, forensic investigation, customer notification, contract disputes and individual compensation claims.

Recent Korean cases make the enforcement scale concrete. The PIPC imposed a KRW 134.79 billion penalty surcharge on SK Telecom in 2025 after a major breach investigation, and in June 2026 announced a KRW 624.681 billion surcharge against Coupang following its investigation into a breach affecting tens of millions of users. Those cases are not automatic benchmarks for another company, but they show why governance and breach preparedness cannot be treated as a small website-policy project.

A Korean Data Breach Starts a 72-Hour Decision Process

PIPA’s incident-response timetable moves before many corporate investigations feel “finished.” Under the current Enforcement Decree, affected data subjects generally must be notified within 72 hours after the controller becomes aware that personal information has been lost, stolen or leaked, subject to limited exceptions. If key facts are not yet confirmed, the rules allow an initial notification based on what is known, followed by additional information as it becomes available.

Reporting to the PIPC or KISA also carries a 72-hour deadline when at least one of the regulatory reporting triggers applies:

  • personal information concerning 1,000 or more data subjects is affected;
  • sensitive information or unique identifying information is affected; or
  • the leak results from external unlawful access to a personal-information system or an information device used by a personal-information handler.

The Enforcement Decree also contains a limited exception from regulatory reporting where the route of the leak has been identified and measures such as recovery or deletion reduce the possibility of harm to data subjects to a markedly low level. That exception deserves documented legal analysis rather than optimistic improvisation during an incident call.

1. Start the clockRecord when the company first became aware of the incident.
2. Contain + preserveBlock access where appropriate while preserving logs and forensic evidence.
3. Map Korean impactIdentify affected people, data types, systems and access path.
4. Test 72-hour dutiesSeparate data-subject notification from the regulator-reporting triggers.
5. Notify, then updateDo not wait for perfect certainty if an initial legally required notice or report is due.

Real-world example: the small breach that still triggers reporting

Imagine an overseas health platform discovers that an attacker used an internet-facing vulnerability to access a database containing Korean customer information. The team initially believes fewer than 1,000 Korean users are involved.

The number alone does not finish the analysis. External unlawful access to a personal-information system is itself one of the regulatory reporting triggers, and health information may also fall within sensitive-information rules. The company therefore needs to assess Korean reporting duties immediately rather than waiting to see whether the affected population crosses 1,000.

The lesson is practical: build your incident checklist around the alternative triggers, not around a single headcount threshold.

Key decision: Your global incident policy should tell responders to identify Korean data on day one. “We will check country-specific requirements after forensics is complete” is not a workable 72-hour protocol.

Cloud, SaaS and Vendor Contracts Need a Korean-Law Pass

Cross-border compliance is partly a notice problem and partly a contract problem. When personal information is transferred overseas under Article 28-8, the controller must take prescribed protective measures, and the Enforcement Decree requires matters including security, grievance handling and dispute resolution to be discussed with the recipient and reflected in contracts or equivalent arrangements.

A standard GDPR data-processing addendum may be helpful evidence, but it should not automatically be treated as a complete Korean solution. The legal concepts overlap without being identical.

For each important overseas vendor, ask

  • Is this recipient an entrusted processor, an independent third party, or something more complicated?
  • Which legal entity receives or can query the data?
  • In which countries can personnel access it?
  • Are subprocessors identified and controlled?
  • What is the purpose and retention period?
  • What happens when the service terminates?
  • Can the vendor return or permanently delete Korean personal information?
  • What incident-notification period does the contract impose on the vendor?
  • Will that period leave your company enough time to meet Korea’s 72-hour clock?
  • What technical evidence can the vendor provide about access control, logging, encryption and account security?
  • Who bears third-party forensic, notification and remediation costs after a vendor-caused incident?

The ninth question is easy to underestimate. A vendor promise to notify you “without undue delay” can sound respectable until the vendor takes 48 hours to escalate the incident internally and your Korean team receives the first usable facts with only a day left on its own regulatory clock.

DIY Compliance vs Korean Privacy Counsel

A foreign company does not need external counsel for every privacy-policy edit. It does need a sensible threshold for when an internal checklist stops being enough.

LevelWhen it may be enoughWhat to spend professional time on
Internal organizationLow-complexity inventory work where the company is documenting systems and existing contractsBuild data map, vendor list, transfer register and breach contacts
Targeted Korean-law reviewThe data flows are known but the lawful basis, notice wording or transfer classification is uncertainReview the disputed legal questions rather than outsourcing the entire inventory
Ongoing counsel / privacy supportLarge Korean user base, sensitive data, multiple overseas processors, domestic-agent duties, regulatory inquiry or recurring product changesGovernance, contract review, launch approvals and incident preparation
Incident representationA potentially reportable breach, regulator contact, contested notification decision or serious evidence problemPreserve privilege where applicable, coordinate Korean reporting, regulator communications and remediation

How to compare privacy-law quotes without comparing apples to staplers

There is no useful universal “Korea PIPA lawyer cost” because the work can range from reviewing one transfer clause to rebuilding a multinational compliance program. Ask each provider to quote the same scope.

  • Does the fee include the initial data-flow review?
  • How many privacy notices, products and legal entities are included?
  • Are vendor agreements and cross-border transfer clauses included?
  • Is Korean-language drafting included or separately billed?
  • Does the engagement include domestic-agent analysis?
  • Are employee and applicant data included, or only customer data?
  • Will counsel review the incident-response plan?
  • Are calls with overseas headquarters included?
  • What work is billed hourly outside the fixed scope?
  • What happens if the PIPC opens an inquiry?

For many mid-sized companies, the economical sequence is to do the factual inventory internally and pay Korean counsel to test the difficult classifications. Paying lawyers to discover the names of your own SaaS vendors is rarely the clever part of the budget.

Six Compliance Mistakes That Become Expensive Later

1. Translating the global privacy notice and calling it Korean compliance

The PIPC has specifically highlighted problems with foreign operators’ privacy notices, including terminology and translation that do not align well with Korean requirements. Korean compliance needs substance first, translation second.

2. Treating every overseas recipient as a “processor”

If a recipient actually uses the data under its own responsibility, the legal analysis may differ materially from an outsourced-processing arrangement. Classification affects the transfer basis, disclosures and contracts.

3. Assuming intra-group transfers are harmless

A parent company is still another legal entity. Centralized fraud, analytics, CRM, HR and customer-support functions should appear on the Korean data map.

4. Using consent where the business cannot tolerate refusal

If a service genuinely cannot operate when the user refuses a transfer, counsel should test whether a contract-performance basis is available rather than mechanically inserting another checkbox. If consent is used, the refusal consequences must be explained accurately.

5. Starting the breach clock when management declares an “incident”

The relevant analysis centers on when the controller became aware of the loss, theft or leak. Preserve that chronology. Security tickets, vendor emails and internal escalation records can become important evidence.

6. Budgeting for compliance but not for evidence

A policy saying “access is restricted” is weaker than access-control settings, audit logs, approval records, training evidence, vendor assessments and documented deletion tests. PIPA’s security obligations make implementation evidence part of the compliance file, not administrative decoration.

The one-page evidence file

For each major Korean processing activity, keep the controller, purpose, legal basis, data categories, recipients, destination countries, retention period, transfer mechanism, contract owner and system owner on one page. Link that page to the underlying contracts and technical evidence. During a breach or regulator inquiry, this small index can save hours of corporate archaeology.

Official Sources to Verify

PIPA changes often enough that a foreign company’s compliance file should contain links to the live Korean authorities, not just an old legal memo saved in a shared drive.

If you are publishing or approving a compliance policy after September 11, 2026, recheck the newly effective provisions and implementing rules rather than relying on the August 2026 position described here. The PIPC has confirmed that the 2026 amendment takes effect on September 11, 2026, while the new mandatory ISMS-P provisions are scheduled for July 1, 2027.

Korea PIPA compliance for foreign companies
Korea PIPA Compliance for Foreign Companies: Penalties, Data Transfers and Breach Response 9

Frequently Asked Questions

Does PIPA apply if my company has no office in South Korea?

Potentially, yes. PIPC guidance says overseas businesses may fall within PIPA where they provide goods or services to Korean data subjects or where their processing of Korean personal information has a direct and significant effect on Korean data subjects. Physical incorporation in Korea is therefore not the only relevant factor.

Does hosting Korean customer data on AWS, Azure or another overseas cloud count as a cross-border transfer?

Overseas storage is expressly within Article 28-8’s cross-border-transfer framework. The specific legal basis and disclosure obligations depend on why the data is stored overseas and how the arrangement is structured.

Do we always need separate consent before Korean data leaves Korea?

No. Separate consent is one statutory route, but Article 28-8 provides other bases. One particularly relevant route allows necessary overseas entrusted processing or storage for conclusion or performance of a contract where the prescribed disclosure or notification requirements are satisfied. Do not assume that route covers an independent third-party provision.

Is the PIPA fine already 10% of global revenue?

Not as of August 18, 2026. The current Article 64-2 framework generally provides a surcharge ceiling of up to 3% for specified violations. A special maximum of up to 10% for defined aggravated cases is scheduled to take effect on September 11, 2026. The 10% figure should not be described as the automatic penalty for every PIPA violation.

Does every data breach have to be reported to the PIPC?

No. Regulatory reporting is triggered under the Enforcement Decree when specified conditions are met, including a breach affecting at least 1,000 data subjects, a breach involving sensitive or unique identifying information, or a leak caused by external unlawful access to a covered system or device. Separate duties to notify affected data subjects must also be analyzed.

Can we wait until the forensic investigation is complete before notifying anyone?

That can be dangerous. The rules contemplate initial notification or reporting where some details remain unconfirmed, followed by updates as further information becomes known. Incident teams should therefore work backward from the Korean 72-hour deadline rather than from the projected end of the forensic investigation.

Does a GDPR-compliant privacy program automatically satisfy PIPA?

No. GDPR work can provide a strong operational foundation, but Korea has its own rules on consent, privacy notices, domestic agents, data-subject rights, overseas transfers, security measures and breach response. Map the global program to Korean requirements instead of assuming equivalence.

When should a foreign company hire Korean privacy counsel?

A targeted review is especially sensible when the company handles sensitive information, has a substantial Korean user base, uses multiple overseas processors, cannot confidently classify an international transfer, may meet the domestic-agent thresholds, is preparing a major Korean launch, receives a PIPC inquiry or discovers a potentially reportable breach.

Your Next 15 Minutes

Open a blank spreadsheet and create eight columns: Korean data, purpose, controller, legal basis, overseas recipient, destination country, retention period, transfer basis.

Then add your five largest Korean-facing systems: customer database, payment or commerce platform, support system, analytics stack and identity or account system. Do not try to solve every legal question yet. Mark uncertain entries in a separate review column.

If you cannot name the controller, overseas recipients and destination countries for those five systems, that is the first compliance problem to fix. Once the map exists, a Korean privacy review becomes narrower, faster and considerably more useful.

The point of PIPA compliance is not to collect policies until a shared drive resembles a paper fortress. It is to know where Korean personal information goes, why it is there, what rule permits it, who is responsible for it and what happens when something goes wrong.

Last reviewed: 2026-09