A revised Personal Information Protection Act and enforcement decree aimed at strengthening corporate responsibility for data breaches and encouraging preventive investments will take effect on September 11. Companies that intentionally or through gross negligence repeatedly leak personal data or cause large-scale damage affecting over 10 million individuals may face fines of up to 10% of their total revenue.
The authority and responsibilities of Chief Privacy Officers (CPOs) will also be enhanced, requiring notification to affected individuals if there is a high likelihood of a data breach, even before a breach is confirmed.
The Personal Information Protection Commission announced on September 10 that the revised law and related regulations will come into force on September 11. The key focus of this revision is to strengthen post-incident penalties for data breaches while incorporating companies' preventive investments into the calculation of fines.
Fines for repeated or severe violations of personal data protection will increase. Companies that repeat violations within three years or cause large-scale damage affecting over 10 million individuals, or fail to comply with corrective orders leading to data breaches, will be subject to higher penalties. The commission will assess fines based on the nature, severity, circumstances, and scale of the violations, up to 10% of total revenue.
Conversely, companies that invest in data protection will receive reductions in fines. The extent and sustainability of investments in data protection, including budget, personnel, equipment, and measures exceeding legal obligations, will be considered, allowing for reductions of up to 40% from the base fine.
The penalty escalation for repeated violations will also increase. The current rates of 15% for the first violation and 30% for subsequent violations will be adjusted to 20% for the first, 40% for the second, and 80% for three or more violations. Fines may be increased by up to 30% if companies fail to report breaches within the legal timeframe or do not take measures to prevent further damage.
Prompt response after an incident will also be a factor in reducing fines. Companies that establish a response system in advance and implement early detection, reporting, and damage prevention measures during an incident may receive reductions of up to 40%. Additional reductions of up to 50% may be applied based on the nature of the violations and the scale of damage, while minor violations by small and medium-sized enterprises may be exempt from fines if corrected with technical support.
The authority and responsibilities of CPOs will be strengthened. Companies and organizations required to designate a CPO must report the appointment, change, or removal of the CPO to the commission following board approval. This requirement applies to businesses with annual revenues exceeding 180 billion won that handle personal data of over 1 million individuals or sensitive information of more than 50,000 individuals, as well as universities with over 20,000 students, major hospitals, and key public system operators.
After the law takes effect, companies must report any CPO appointments, changes, or removals within six months of the occurrence of the relevant circumstances. CPOs designated before the law's implementation must also report within six months of the effective date without requiring separate board approval.
To facilitate the establishment of this system, the commission will operate a grace period until December 31, 2027, during which no fines will be imposed for failure to designate a CPO, lack of qualifications, violations of board approval requirements, or failure to report.
A new notification system for potential data breaches will also be introduced. If there is a reasonable belief that a data breach may occur, even if not confirmed, affected individuals must be notified. If there is suspicion of illegal access leading to a breach but it is difficult to identify victims, or if illegal transactions of some personal data are confirmed, notification must occur within 72 hours of becoming aware of the situation.
The scope of notification and reporting will expand from loss, theft, and leaks to include forgery, alteration, and damage. This means that incidents involving ransomware that compromise personal data will also be subject to reporting and notification. Notification will include legal remedies such as claims for damages and dispute resolution, and measures to prevent further damage, such as data recovery and deletion, will be specified.
However, the requirement for major public and private personal data processors to obtain Personal Information Management System (ISMS-P) certification will take effect on July 1, 2027, to allow time for budget allocation. Related enforcement decrees will be amended before implementation.
Song Kyung-hee, chair of the Personal Information Protection Commission, stated, “With the implementation of this revised legislation, we expect to establish a preventive approach to personal data protection and a strengthened safety management system, transforming the perception of investments in data protection from a 'cost' to a 'proactive investment' for securing customer trust and expanding corporate profits.”
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.