{
 "jurisdiction_id": "KR",
 "jurisdiction": "South Korea",
 "url": "https://dataprotection.gi/jurisdictions/south-korea/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 43,
  "sub_modules": 57,
  "source_register": 21
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Core regulator, statutory basis, and material scope are Confirmed via T1/T2 sources; only territorial scope carries residual definitional ambiguity noted by secondary legal commentary.",
   "claims": [
    {
     "statement": "The Personal Information Protection Commission (PIPC) is responsible for enforcing PIPA and the PIPA Enforcement Decree.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/south-korea-data-breach",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "South Korea's comprehensive Personal Information Protection Act was enacted September 30, 2011 and is considered one of the world's strictest privacy regimes, enforced with criminal and regulatory penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-koreas-personal-information-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA protects privacy rights from the data subject's perspective and applies broadly to most organizations, including government entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-koreas-personal-information-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA does not explicitly specify its territorial or extraterritorial scope; in practice, applicability to foreign entities is determined by factors such as whether services are targeted at Koreans.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Foreign business operators processing personal information who meet statutory criteria must establish a domestic corporation and designate a local representative, with the overseas headquarters required to manage and supervise that representative; the amendment was signed April 1, 2025 and took effect October 2, 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/node/643112",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Special-category and pseudonymisation rules are Confirmed, but the absence of a statutory consent definition and comparative uncertainty flagged by secondary legal sources keep the lawful-bases sub-module at Probable confidence.",
   "claims": [
    {
     "statement": "PIPA does not statutorily define 'consent,' unlike more prescriptive comparator regimes, creating interpretive reliance on case law and PIPC guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "To obtain valid consent, a data handler must present the consent request to the data subject in a clearly recognisable manner with each matter requiring consent distinctly presented.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA classifies biometric data collected for the purpose of uniquely identifying a person as a special class of sensitive information, necessitating separate consent for its collection and processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2510.03035",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under PIPA, 'pseudonymous processing' is processing by methods such as partially deleting or partially/entirely replacing personal data such that no specific individual can be recognised without additional information (Article 2(1-2) PIPA).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0254",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core access/rectification/erasure and suspension rights are Confirmed via a T1 EU adequacy instrument and T2/T3 secondary sources; portability (MyData) expansion is Probable as a policy-plan item rather than a fully generalized statutory right at this time.",
   "claims": [
    {
     "statement": "PIPA grants individuals significant rights over their personal information, including the right to be informed of and to access data held about them.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2510.03035",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA grants individuals the right to rectify and erase their personal information held by controllers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2510.03035",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA does not provide a general right to withdraw consent; instead, Article 37 grants a general right to suspension of processing, which can also be invoked where data is processed on the basis of consent, terminating processing and triggering deletion.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-09/edpb_opinion322021_republicofkoreaadequacy_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PIPC's 2024-2026 basic plan aims to activate 'MyData' (the right to request transmission of personal information) in all fields as part of South Korea's data-driven society transition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-publishes-plan-2024-2026",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Access to personal information processed by a public institution may be obtained directly or, indirectly, by lodging a request with the PIPC, which must transmit the request without delay.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0254",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core breach-notification and DPIA rules are Confirmed and in force, but the most consequential governance/penalty provisions (CEO liability, 10% turnover ceiling, CPO/ISMS-P thresholds) are either enacted-not-yet-effective or still in draft/proposed stage.",
   "claims": [
    {
     "statement": "PIPA only requires public organisations to conduct a Data Protection Impact Assessment (DPIA).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A draft amendment to the PIPA Enforcement Decree (announced June 2, 2026) would require organisations with annual revenue of at least KRW 180 billion processing sensitive data of 50,000+ people or personal data of 1 million+ people, universities with 20,000+ students, large general hospitals, and public information-system operators to obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-announces-draft-amendment-pipa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA distinguishes between the 'provision' of personal information, akin to a controller-to-controller data transfer, and 'outsourcing' of processing, akin to a controller-processor arrangement under the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A June 2026 draft PIPA Enforcement Decree amendment would mandate ISMS-P certification for certain entities by December 31, 2028.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-announces-draft-amendment-pipa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Information and communication service providers are required to notify the data subject and the PIPC within 24 hours after becoming aware that personal information has been lost, stolen, or leaked (Article 39-4(1) PIPA).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0254",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A June 2026 draft amendment to the PIPA Enforcement Decree would require organisations to notify data subjects within 72 hours of discovering unauthorized access or illegal distribution of personal data.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-announces-draft-amendment-pipa",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/south-korea-overhauls-pipa-and-ties-fines-to-ceo-accountability",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Adequacy-received status and general transfer-mechanism rules are Confirmed via a T1 EU legal instrument and T1 EDPB opinion; however, SCC/BCR-equivalent instruments, transfer-impact-assessment practice, and data-localisation specifics were not evidenced in this pass.",
   "claims": [
    {
     "statement": "PIPA recognises consent, international agreements, and other legal bases as valid grounds for cross-border transfers, and grants the PIPC power to cease cross-border transfers in certain cases.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "South Korea became the fifth member of the APEC Cross-Border Privacy Rules (CBPR) system, joining the U.S., Japan, Canada, and Mexico.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-koreas-personal-information-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission concludes that, for each relevant component including rights of individuals and redress mechanisms, South Korean law under PIPA offers a level of protection essentially equivalent to the GDPR, and that the PIPC meets the independence test required under the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/eu-adequacy-decision-for-south-korea",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The South Korea adequacy decision is subject to periodic review at least every four years under GDPR Article 45(3), with the first revision period for Korea shortened to three years.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/eu-adequacy-decision-for-south-korea",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU adequacy decision for South Korea excludes the processing of personal credit information pursuant to the Credit Information Act (CIA) by controllers subject to FSC oversight, since such processing falls outside the Decision's scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0254",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and telecoms overlays are Confirmed via T1/T2 sources; health, education, employment, and insurance overlays carry no populated claims in this pass.",
   "claims": [
    {
     "statement": "The Use and Protection of Credit Information Act applies to credit information used in credit ratings, and the Financial Services Commission is Korea's supervisory authority for the financial sector in that capacity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0254",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The FSC published a manual and licence mechanism (July 2020) for financial companies and FinTechs to access and use the credit-information management platform 'MyData,' covering data security, outsourcing, and collection/use checklists.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-fsc-publishes-manual-and-licence-mechanism-financial-companies-using-credit",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act on Real Name Financial Transactions and Guarantee of Secrecy applies separately to financial or financial-services institutions, distinct from PIPA's general regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-matchup-south-koreas-personal-information-protection-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Information-and-communication service providers face additional consent obligations under Article 39-3(1) PIPA and further security obligations under Article 48-2 of the PIPA Enforcement Decree, including internal management plans, access control, and encryption.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022D0254",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only the direct_marketing sub-module has Confirmed claims; five of six declared sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) carry no populated claims and are flagged with explicit absent_field_provenance.",
   "claims": [
    {
     "statement": "Senders requesting consent to receive advertising messages must clearly indicate that the consent relates to 'advertising information,' with vague expressions such as 'benefit notifications' disallowed, per KISA's revised guide to the Network Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-kisa-publishes-revised-guide-information",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Users must be able to refuse advertising communications through simplified means, such as app-notification opt-out, without complex procedures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-kisa-publishes-revised-guide-information",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Enforcement precedent (model deletion, biometric special-category status, law-enforcement carve-out) is Confirmed via T1/T2 sources, but the Generative AI Guide is non-binding soft guidance and genetic-data-specific rules were not evidenced.",
   "claims": [
    {
     "statement": "The PIPC's January 2025 Kakao Pay decision found the wallet provider sent 40 million users' data to Alipay, which built 'NSF scores' for Apple Pay without notice or consent, resulting in a KRW 8.3 billion fine and an order to erase the algorithm itself.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/south-korea-s-pipc-flexes-its-muscles-what-to-know-about-ai-model-deletion-cross-border-transfers-and-more",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PIPC published a Guide for the Development and Use of Generative AI on August 6, 2025, outlining minimum requirements for legal and safe personal-data processing across the generative-AI lifecycle, including impact assessments and Privacy by Design.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-publishes-guide-development-and-use",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA classifies biometric data used to uniquely identify an individual as a special category of sensitive information requiring separate consent for collection and processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "arXiv",
     "source_url": "https://arxiv.org/pdf/2510.03035",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "PIPA's provisions apply without limitation in the area of law enforcement, per the EDPB's assessment of the Korea adequacy decision, a carve-out the EDPB flagged for continued monitoring.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-09/edpb_opinion322021_republicofkoreaadequacy_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Only two of five declared sub-modules carry populated claims, and even those rest on comparative (Probable/Uncertain) rather than direct PIPA-primary-text confirmation of the exact age threshold.",
   "claims": [
    {
     "statement": "Under Korea's Act on the Protection and Use of Location Information, a location-information provider seeking to collect, use, or provide personal location information from children under the age of 14 must obtain the consent of their legal representative.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance (hosting official statute translation)",
     "source_url": "https://www.dataguidance.com/sites/default/files/SKorea_Law_on_the_Protection_and_Use_of_Location_Information_2008.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Both the GDPR and PIPA provide that the consent of a guardian or legal representative is required to process the personal information of children, though PIPA does not contain provisions specifically targeted at protecting children's personal information comparable to COPPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / Lee & Ko",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_pipa_may_2023_update.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/south-korea/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement activity and the forthcoming penalty regime are Confirmed at high materiality, but collective-redress and private-right-of-action mechanisms carry no populated claims, and regulator funding/capacity information rests on a non-binding EDPB observation.",
   "claims": [
    {
     "statement": "South Korea's March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/south-korea-overhauls-pipa-and-ties-fines-to-ceo-accountability",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On July 23, 2026, the PIPC fined Apple Distribution International Limited KRW 252 million (approx. $171,400) for violations of PIPA and the former Information and Communications Network Act, following an investigation into unauthorized collection of Siri voice data until August 2019.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-fines-apple-krw-252m-unauthorized",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The PIPC's January 2025 Kakao Pay decision levied a KRW 8.3 billion fine on the wallet provider after finding it sent 40 million users' data to Alipay without consent, and ordered destruction of the resulting AI-derived scoring algorithm.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/south-korea-s-pipc-flexes-its-muscles-what-to-know-about-ai-model-deletion-cross-border-transfers-and-more",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB's 2021 opinion on the draft Korea adequacy decision noted that no reference was made to the specificities of PIPC staffing or the financial resources made available to it, and welcomed additional information.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-09/edpb_opinion322021_republicofkoreaadequacy_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On June 2, 2026, the PIPC announced a draft amendment to the PIPA Enforcement Decree introducing CPO board-approval/notification requirements, mandatory ISMS-P certification by December 31, 2028, and a 72-hour breach-notification standard.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/south-korea-pipc-announces-draft-amendment-pipa",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}