Korea's New Data Breach Fines (Oct 2026)
Korea's amended PIPA keeps the 3% fine cap but allows up to 10% of revenue in aggravated cases, plus 72-hour likely-leak notices. What to check now.
As of October 2026, the general cap on Korea's privacy fines is still 3% of total revenue, but the regulator can now fine up to 10% in three aggravated cases: repeated or large-scale violations involving intent or gross negligence, and leaks after ignoring a corrective order. The amended Personal Information Protection Act (PIPA) took effect on September 11, 2026. It also adds a duty to warn people within 72 hours when a leak is likely but not yet confirmed. Three weeks later, four Korean banks disclosed breaches that came through side systems such as staff and partner mobile tools, not their core banking platforms. If your company runs a website, app or internal system that handles Korean users' data, this guide covers what changed and which parts of your systems to look at first.
This article explains the rules and the system side. It is not legal advice; for how the law applies to your company, talk to a Korean privacy lawyer.
What changed in Korea's privacy law on September 11, 2026?
The amendments were passed by the National Assembly in February, promulgated on March 10, 2026, and took effect on September 11, 2026, together with a revised Enforcement Decree. The Personal Information Protection Commission (PIPC) summarised the changes in a press release on September 10.
| Change | Before | From September 11, 2026 |
|---|---|---|
| Maximum fine | 3% of total revenue | Still 3% generally; up to 10% in aggravated cases |
| Fine if revenue can't be calculated | Up to KRW 2 billion | Up to KRW 5 billion in aggravated cases |
| When to notify people | Once you know a leak has happened | Also when a leak is likely, within 72 hours |
| Incidents covered | Loss, theft, leakage | Adds forgery, alteration and damage, such as ransomware |
| Repeat-violation surcharge | +15% (once), +30% (twice or more) | +20%, +40%, +80% (three or more) |
| Late notice and no containment | — | Surcharge of up to 30% |
| Reductions | Mainly for certifications such as ISMS-P (up to 50%) | Up to 40% for prior investment in protection; certification reductions cut (ISMS-P up to 30%) |
| Who is ultimately responsible | Not explicit | The business owner or CEO |
A few other points worth knowing:
- Revenue that has nothing to do with the violation is excluded when the fine is calculated (Article 64-2, paragraph 3).
- CEO and CPO duties. The law now names the business owner or representative as ultimately responsible for protecting personal information. Large processors must get board approval for appointing or replacing their Chief Privacy Officer and report it to the PIPC.
- The grace period is narrow. Until December 31, 2027, the PIPC will not impose administrative fines for violations of the new CPO rules (not appointing a CPO, CPO qualifications, board approval, late reports). It is not a grace period for breaches or the 10% fine.
- ISMS-P certification becomes mandatory for major public and private processors from July 1, 2027.
When can the fine reach 10% of total revenue?
Korea's 10% breach fine: since September 11, 2026, the PIPC can fine a company up to 10% of total revenue, instead of the general 3%, if it repeats an intentional or grossly negligent violation within three years of an earlier fine, causes harm to 10 million or more people through intent or gross negligence, or suffers a data leak after failing to follow a PIPC corrective order (PIPA Article 64-2(2)).
The 10% ceiling is for serious cases. Most breaches will still be judged against the 3% ceiling, and the decree adds reductions: up to 40% for prior investment in budget, staff, equipment and safeguards beyond the legal minimum, and up to 40% for early detection, prompt reporting and containment. The investment reduction doesn't apply where the violation was intentional or grossly negligent.
For a company planning its budget, the message is that spending on protection before an incident now counts in the fine calculation.
What does the 72-hour notification rule mean in practice?
Korea already required notice within 72 hours once a company knew a leak had happened. The new rule moves the trigger earlier. Under the revised Enforcement Decree, you must notify affected people within 72 hours of learning that:
- someone has illegally accessed a system that processes personal information, or a device staff use to process it, and a leak is suspected but you can't yet identify whose data was taken; or
- some data has been confirmed leaked, for example because it is being traded illegally, and other people's data may have leaked too.
The notice has to cover broadly the same points as a breach notice: what data, when and how it was suspected, what people can do to limit harm, how to get help, a contact point, and that you'll follow up once the leak is confirmed. If it turns out nothing leaked, you send a correction.
Separately, a confirmed breach must be reported to the PIPC or KISA within 72 hours when it affects 1,000 or more people, involves sensitive or unique identification data, or results from unlawful outside access. The decree allows an exception where the leaked data has been recovered or deleted and the risk to people is significantly reduced.
You can't meet a 72-hour clock if you can't tell what happened. In system terms, that means:
- Logs you can actually read. Who logged in, from where, and what records they viewed or exported.
- An inventory. Which systems hold which personal data, and roughly how many people's.
- A named owner and a template. Who decides to notify, and a pre-written notice in Korean.
What did the October 2026 bank breaches have in common?
On October 2, 2026, The Korea Herald reported breaches at four lenders:
| Bank | People affected | System involved |
|---|---|---|
| Shinhan Bank | About 25,000 customers | A mobile service used by loan agents to look up customers |
| KB Kookmin Bank | 119 customers | A mobile support system for employees |
| Hana Bank | 89 customers | A sales support system |
| BNK Financial Group | 11 records of outsourced staff | Not specified |
In the three cases where the system was named, the way in was not the core banking platform but a tool built for staff or partners and reachable from outside the office. Financial authorities ordered banks to check externally accessible systems, strengthen authentication, tighten access controls and share threat information faster, and the Financial Supervisory Service began an emergency on-site inspection of Shinhan.
What about AI? Security analysts found traces of an AI penetration-testing tool on a server linked to the Shinhan attack, and experts quoted by Bloomberg suspected AI agents were used to probe for weaknesses. As of the October 2 reports, neither the bank nor the authorities had confirmed that the tool was used in the breach.
Which parts of your Korean website or app should you check first?
Foreign companies tend to focus on the customer-facing site. The bank cases suggest looking at everything around it. A practical order:
- List every system reachable from the internet that touches Korean users' data: the website, admin panels, partner and reseller portals, staff mobile tools, test servers and old campaign sites.
- Require strong sign-in on staff and partner tools. Multi-factor authentication on every admin and partner login, and no shared accounts.
- Check access control on every record. Can a logged-in partner change an ID in the URL or the API request and see another customer's data? This is the most common hole in custom portals.
- Limit what each role can export. A loan agent or reseller rarely needs bulk download.
- Patch what the system is built on. Frameworks, libraries and plugins, on a schedule rather than when someone remembers.
- Turn on logging that answers the 72-hour questions. Who accessed what, when and from where, kept long enough to investigate.
- Retire what you don't use. An old campaign site with a database behind it is still a system holding personal data.
If your company has no address or office in Korea and meets the thresholds in the Enforcement Decree, Article 31-2 also requires a domestic representative in Korea. That representative handles breach notices and reports on your behalf, so they need to be part of your incident plan.
Do tracking pixels and third-party scripts matter here?
They matter for a different part of the law. Pixels, chat widgets and analytics tags collect data about Korean visitors and send it to other companies, which raises questions of consent and disclosure in your privacy notice. They are also code you don't control running on your pages. When you list your systems in step 1, list the third-party scripts on each page too, and remove the ones nobody uses. How consent should work for each one is a question for your privacy lawyer.
What we do on client projects
We are a two-person development studio in Korea that builds websites, portals and internal systems for Korean users, including for foreign companies. We don't sell security audits or penetration testing. What we do is build with security checks as part of development:
- Permissions designed per role, with every record request checked on the server, not only hidden in the interface.
- Input validation on forms and APIs.
- Dependency patching for the frameworks and libraries a system runs on.
- Exposure checks before launch: which pages, admin paths and files can be reached from outside.
We develop and review code every day with Claude Code, an AI coding agent, and a person reviews each change before it ships. Hosting and maintenance, including ongoing patching, are agreed in a separate contract. Our English-speaking founder handles consultations and documents directly, and we can meet your team in person in Korea.
If you're comparing ways to staff a Korean system build, see outsourcing software development in South Korea. For internal tools specifically, an English intranet for teams in Korea and ERP for foreign companies in Korea cover the common set-ups.
Frequently asked questions
Does the new PIPA fine apply to foreign companies serving Korean users?
The law applies to personal information processors handling Korean users' data, and it expects some foreign companies to take part: Article 31-2 requires processors without a Korean address or office that meet the decree's thresholds to appoint a domestic representative who handles breach notices. Whether and how the fine applies to your company is a question for a Korean privacy lawyer.
Is there a grace period for the new rules?
Only for the new CPO obligations. Until December 31, 2027, the PIPC won't fine companies for not appointing a CPO, CPO qualifications, missing board approval or late CPO reports. The higher fines and the 72-hour likely-leak notice applied from September 11, 2026.
Who is the "ultimate responsible person" under the amended law?
The business owner or representative, usually the CEO. The amendment makes their final responsibility for personal information protection explicit and strengthens the Chief Privacy Officer's authority over staff, budget and reporting to the board.
What counts as a breach that must be reported within 72 hours?
People must be notified within 72 hours of learning of a confirmed leak, and now also of a likely leak after illegal access. A confirmed breach must be reported to the PIPC or KISA within 72 hours if it affects 1,000 or more people, involves sensitive or unique identification data, or results from unlawful outside access.
Was AI used in the Shinhan Bank breach?
Not confirmed. Analysts found traces of an AI penetration-testing tool on a server linked to the attack, and experts suspected AI agents were used, but as of October 2, 2026, neither Shinhan nor the financial authorities had confirmed it.
Sources
All checked October 2026. Korean-language sources are marked (Korean).
- Personal Information Protection Commission, press release on the amended PIPA, Enforcement Decree and notices taking effect September 11, 2026, issued September 10, 2026 (Korean), via the KDI Economic Information and Education Center
- Korea Ministry of Government Legislation, Personal Information Protection Act, Act No. 21445, promulgated March 10, 2026, effective September 11, 2026: Articles 31-2, 34 and 64-2 (Korean)
- Korea Ministry of Government Legislation, Enforcement Decree of the Personal Information Protection Act, effective September 11, 2026: Articles 39, 39-2, 39-3 and 40 (Korean)
- Hunton Andrews Kurth, South Korea amends privacy law to authorize fines of up to 10% of total revenue, February 13, 2026
- The Korea Herald, bank data breach report, October 2, 2026
- Bloomberg via Insurance Journal, AI tools suspected in Shinhan Bank hack, October 2, 2026
Running a portal, admin panel or internal system for Korean users, or planning one? See how we build for foreign companies on our Korea market entry and software development in Korea pages, then send us your project details or email dwkim@nqsolution.kr.

