Core regulator, statutory basis, and material scope are Confirmed via T1/T2 sources; only territorial scope carries residual definitional ambiguity noted by secondary legal commentary.
Primary frameworkPersonal Information Protection Act (PIPA), as amended (2011, 2020 'Data 3 Act', 2023, 2025, 2026)
Traffic-light rationale — GreenCore regulator, statutory basis, and material scope are Confirmed via T1/T2 sources; only territorial scope carries residual definitional ambiguity noted by secondary legal commentary.
Sub-modules (5)
Regulator And AuthorityGreen
PIPC is the statutory enforcement authority for PIPA and its Enforcement Decree.
Claims: CLM-KR-1a2b3c4d
Act And InstrumentsGreen
PIPA, enacted September 30, 2011, is a comprehensive statute applying broadly, including to government entities.
Claims: CLM-KR-2b3c4d5e
Material ScopeGreen
PIPA applies to most organisations, public and private, processing personal information.
Claims: CLM-KR-5e6f7081
Territorial ScopeAmber
PIPA does not explicitly codify territorial/extraterritorial scope; application to foreign entities is assessed on factors such as Korea-targeted services.
Claims: CLM-KR-3c4d5e6f
Regulator Registration And FilingGreen
Foreign business operators meeting statutory criteria must establish a domestic corporation and designate/supervise a local representative, in force since October 2, 2025.
Claims: CLM-KR-4d5e6f70
Category narrative86 words
South Korea's Personal Information Protection Act (PIPA), enacted 2011 and substantially rewritten since, is enforced by the Personal Information Protection Commission (PIPC), which received EU-adequacy-driving independence and enforcement powers through the 2020 'Data 3 Act' reform. PIPA is comprehensive, applying to public and private controllers, and was further amended in March 2025 (foreign representative/domestic-corporation requirements, effective Oct 2, 2025) and March 2026 (CEO liability, 10% turnover penalty ceiling, effective Sept 11, 2026). PIPA's territorial/extraterritorial scope is not explicitly codified in the statute text, requiring case-by-case analysis.
Sources and claims (5)
ConfirmedDataGuidance — The Personal Information Protection Commission (PIPC) is responsible for enforcing PIPA and the PIPA Enforcement Decree.
ConfirmedIAPP — South Korea's comprehensive Personal Information Protection Act was enacted September 30, 2011 and is considered one of the world's strictest privacy regimes, enforced with criminal and regulatory penalties.
ConfirmedIAPP — PIPA protects privacy rights from the data subject's perspective and applies broadly to most organizations, including government entities.
ProbableDataGuidance / Lee & Ko — PIPA does not explicitly specify its territorial or extraterritorial scope; in practice, applicability to foreign entities is determined by factors such as whether services are targeted at Koreans.
ConfirmedDataGuidance — Foreign business operators processing personal information who meet statutory criteria must establish a domestic corporation and designate a local representative, with the overseas headquarters required to manage and supervise that representative; the amendment was signed April 1, 2025 and took effect October 2, 2025.
Special-category and pseudonymisation rules are Confirmed, but the absence of a statutory consent definition and comparative uncertainty flagged by secondary legal sources keep the lawful-bases sub-module at Probable confidence.
Primary frameworkPersonal Information Protection Act (PIPA)
Traffic-light rationale — AmberSpecial-category and pseudonymisation rules are Confirmed, but the absence of a statutory consent definition and comparative uncertainty flagged by secondary legal sources keep the lawful-bases sub-module at Probable confidence.
Sub-modules (4)
Lawful BasesAmber
PIPA recognises consent as a legal basis for processing but does not define 'consent'; Korean Supreme Court case law has filled interpretive gaps.
Claims: CLM-KR-6f708192
Consent ThresholdsGreen
Controllers must present consent requests in a clearly recognisable manner, distinctly presenting each matter requiring consent.
Claims: CLM-KR-708192a3
Special CategoriesGreen
Biometric data used to uniquely identify a person is classified as sensitive/special-category information requiring separate consent.
Claims: CLM-KR-8192a3b4
Pseudonymisation And AnonymisationGreen
PIPA Article 2(1-2) defines pseudonymous processing as partial deletion or replacement of data such that an individual cannot be identified without additional information.
Claims: CLM-KR-92a3b4c5
Category narrative56 words
PIPA recognises consent alongside other legal bases for processing, but the statute does not itself define 'consent,' leaving interpretive gaps filled by Supreme Court rulings and PIPC guidance. Biometric data used for unique identification is treated as a special/sensitive category requiring separate consent. Pseudonymisation is statutorily defined (Art 2(1-2)) and forms the basis for research/statistics safe-harbours.
Sources and claims (4)
ProbableDataGuidance / Lee & Ko — PIPA does not statutorily define 'consent,' unlike more prescriptive comparator regimes, creating interpretive reliance on case law and PIPC guidance.
ProbableDataGuidance / Lee & Ko — To obtain valid consent, a data handler must present the consent request to the data subject in a clearly recognisable manner with each matter requiring consent distinctly presented.
ConfirmedarXiv — PIPA classifies biometric data collected for the purpose of uniquely identifying a person as a special class of sensitive information, necessitating separate consent for its collection and processing.
ConfirmedEUR-Lex / European Union — Under PIPA, 'pseudonymous processing' is processing by methods such as partially deleting or partially/entirely replacing personal data such that no specific individual can be recognised without additional information (Article 2(1-2) PIPA).
Core access/rectification/erasure and suspension rights are Confirmed via a T1 EU adequacy instrument and T2/T3 secondary sources; portability (MyData) expansion is Probable as a policy-plan item rather than a fully generalized statutory right at this time.
Primary frameworkPersonal Information Protection Act (PIPA)
Traffic-light rationale — GreenCore access/rectification/erasure and suspension rights are Confirmed via a T1 EU adequacy instrument and T2/T3 secondary sources; portability (MyData) expansion is Probable as a policy-plan item rather than a fully generalized statutory right at this time.
Sub-modules (5)
Access RightGreen
PIPA grants individuals the right to be informed of, and to access, their personal information held by controllers.
Claims: CLM-KR-a3b4c5d6
Rectification And ErasureGreen
PIPA grants rights to rectify and erase personal information.
Claims: CLM-KR-a3b4c5d7
Restriction And ObjectionGreen
In lieu of a general consent-withdrawal right, PIPA (Art 37) provides a right to suspension of processing, which can also be invoked where processing rests on consent, leading to termination and deletion.
Claims: CLM-KR-b4c5d6e7
Data PortabilityAmber
The PIPC's 2024-2026 basic plan aims to activate 'MyData' (the right to request transmission of personal information) across all fields, building on its existing financial-sector implementation.
Claims: CLM-KR-c5d6e7f8
Deadlines And Response WindowsGreen
Requests for access to personal information held by public institutions may be made directly or indirectly via the PIPC, which must transmit the request without delay (Art 35(2) PIPA; Art 41(3) Enforcement Decree).
Claims: CLM-KR-d6e7f809
Category narrative69 words
PIPA grants individuals rights to be informed, access, rectify, and erase personal data. Rather than a general right of consent withdrawal, PIPA provides a right to obtain suspension of processing (Art 37), which terminates processing and triggers deletion. The PIPC's 2024-2026 basic plan aims to expand 'MyData' (the right to request transmission of personal information) across all sectors. Public-institution access requests must be transmitted by the PIPC without delay.
Sources and claims (5)
ConfirmedarXiv — PIPA grants individuals significant rights over their personal information, including the right to be informed of and to access data held about them.
ConfirmedarXiv — PIPA grants individuals the right to rectify and erase their personal information held by controllers.
ConfirmedEDPB — PIPA does not provide a general right to withdraw consent; instead, Article 37 grants a general right to suspension of processing, which can also be invoked where data is processed on the basis of consent, terminating processing and triggering deletion.
ProbableDataGuidance — The PIPC's 2024-2026 basic plan aims to activate 'MyData' (the right to request transmission of personal information) in all fields as part of South Korea's data-driven society transition.
ConfirmedEUR-Lex / European Union — Access to personal information processed by a public institution may be obtained directly or, indirectly, by lodging a request with the PIPC, which must transmit the request without delay.
Core breach-notification and DPIA rules are Confirmed and in force, but the most consequential governance/penalty provisions (CEO liability, 10% turnover ceiling, CPO/ISMS-P thresholds) are either enacted-not-yet-effective or still in draft/proposed stage.
Primary frameworkPersonal Information Protection Act (PIPA) and PIPA Enforcement Decree
Traffic-light rationale — AmberCore breach-notification and DPIA rules are Confirmed and in force, but the most consequential governance/penalty provisions (CEO liability, 10% turnover ceiling, CPO/ISMS-P thresholds) are either enacted-not-yet-effective or still in draft/proposed stage.
Sub-modules (7)
Accountability And DpiaAmber
PIPA currently only requires public organisations to conduct a Data Protection Impact Assessment (DPIA); no general private-sector DPIA mandate exists.
Claims: CLM-KR-2b3c4d5f
Dpo RequirementsAmber
A June 2026 draft Enforcement Decree amendment would require organisations meeting revenue/data-volume thresholds to obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer (CPO).
Claims: CLM-KR-e7f8091a
Ropa RequirementsRed
No dedicated Records-of-Processing-Activities (ROPA) provision distinct from PIPA's general processing-policy disclosure obligations was located in this research pass.
Absence provenance: No claim populated; recommend targeted primary-source review of PIPA Art. 30-32 processing-policy provisions.. Searched: PIPA records of processing activities requirement, PIPA processing policy disclosure obligation.
Joint Controller ArrangementsAmber
PIPA distinguishes between 'provision' of personal information (analogous to controller-to-controller transfer) and 'outsourcing' of processing (analogous to controller-processor arrangements), each carrying distinct obligations.
Claims: CLM-KR-c5d6e7fa
Security MeasuresAmber
ICSPs and third parties receiving user data are subject to specified security obligations (internal management plans, access control, encryption, malware detection); a draft amendment would mandate ISMS-P certification for certain entities by December 31, 2028.
Claims: CLM-KR-f8091a2b
Breach NotificationGreen
ICSPs must notify affected users and the PIPC within 24 hours of becoming aware that personal information was lost, stolen, or leaked (Art 39-4(1) PIPA); a June 2026 draft amendment would extend a 72-hour data-subject notification standard more broadly.
Claims: CLM-KR-091a2b3c, CLM-KR-1a2b3c4e
Retention And DisposalRed
No retention-limit/disposal-specific claim was populated in this research pass beyond general breach/pseudonymisation provisions.
Absence provenance: Explicit retention-period statutory text not retrieved in this pass; recommend primary-source follow-up on PIPA Art. 21 destruction obligations.. Searched: PIPA data retention limit disposal obligation.
Category narrative91 words
PIPA currently mandates DPIAs only for public organisations. A June 2026 draft Enforcement Decree amendment would require board-approved CPO appointment/removal notifications for large processors, mandatory ISMS-P certification for certain entities by December 31, 2028, and a 72-hour data-subject breach notification standard; these remain proposed as of this research pass. Information-and-communication service providers (ICSPs) are already bound by a stricter 24-hour breach notification rule under Article 39-4(1) PIPA. The March 2026 PIPA amendment (effective September 11, 2026) introduces personal CEO supervisory liability and raises the penalty ceiling to 10% of total turnover.
Sources and claims (7)
ConfirmedDataGuidance / Lee & Ko — PIPA only requires public organisations to conduct a Data Protection Impact Assessment (DPIA).
ProbableDataGuidance — A draft amendment to the PIPA Enforcement Decree (announced June 2, 2026) would require organisations with annual revenue of at least KRW 180 billion processing sensitive data of 50,000+ people or personal data of 1 million+ people, universities with 20,000+ students, large general hospitals, and public information-system operators to obtain board approval and notify the PIPC when appointing, changing, or removing a Chief Privacy Officer.
ProbableDataGuidance / Lee & Ko — PIPA distinguishes between the 'provision' of personal information, akin to a controller-to-controller data transfer, and 'outsourcing' of processing, akin to a controller-processor arrangement under the GDPR.
ProbableDataGuidance — A June 2026 draft PIPA Enforcement Decree amendment would mandate ISMS-P certification for certain entities by December 31, 2028.
ConfirmedEUR-Lex / European Union — Information and communication service providers are required to notify the data subject and the PIPC within 24 hours after becoming aware that personal information has been lost, stolen, or leaked (Article 39-4(1) PIPA).
ProbableDataGuidance — A June 2026 draft amendment to the PIPA Enforcement Decree would require organisations to notify data subjects within 72 hours of discovering unauthorized access or illegal distribution of personal data.
ConfirmedIAPP — A March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.
Adequacy-received status and general transfer-mechanism rules are Confirmed via a T1 EU legal instrument and T1 EDPB opinion; however, SCC/BCR-equivalent instruments, transfer-impact-assessment practice, and data-localisation specifics were not evidenced in this pass.
Primary frameworkPersonal Information Protection Act (PIPA); EU Commission Implementing Decision (EU) 2022/254 (adequacy)
Traffic-light rationale — AmberAdequacy-received status and general transfer-mechanism rules are Confirmed via a T1 EU legal instrument and T1 EDPB opinion; however, SCC/BCR-equivalent instruments, transfer-impact-assessment practice, and data-localisation specifics were not evidenced in this pass.
Sub-modules (6)
Transfer MechanismsGreen
PIPA recognises consent, international agreements, and other legal bases as grounds for cross-border transfer, and grants the PIPC power to suspend or cease transfers in certain cases. South Korea is also a member of the APEC CBPR system.
Claims: CLM-KR-6f7081a3, CLM-KR-8192a3c5
Adequacy ReceivedGreen
The European Commission's adequacy decision for South Korea concludes PIPA and PIPC-issued notifications offer protection essentially equivalent to the GDPR; the decision is subject to periodic review at least every four years, with the first review period shortened to three years.
Claims: CLM-KR-4d5e6f81, CLM-KR-5e6f7092
Adequacy GrantedRed
No evidence located in this pass of South Korea granting outbound adequacy-equivalent recognition to other jurisdictions.
Absence provenance: No claim populated; PIPA's outbound-adequacy-granting mechanism (if any) requires further primary-source review.. Searched: South Korea PIPA adequacy decision EU GDPR cross-border transfer mechanism.
Sccs And BcrsRed
No PIPA-specific SCC/BCR-equivalent instrument text was retrieved in this research pass.
Absence provenance: PIPA's contractual-clause equivalent (if formalized) not confirmed in retrieved sources.. Searched: South Korea PIPA adequacy decision EU GDPR cross-border transfer mechanism.
Transfer Impact AssessmentRed
No PIPA-specific transfer-impact-assessment requirement was retrieved in this research pass.
Absence provenance: No claim populated; recommend dedicated search on PIPC transfer risk-assessment guidance.. Searched: South Korea PIPA adequacy decision EU GDPR cross-border transfer mechanism.
Data LocalisationAmber
The adequacy decision excludes personal credit information governed by the Credit Information Act, which remains under FSC oversight; no general data-localisation mandate was otherwise evidenced.
Claims: CLM-KR-708192b4
Category narrative90 words
The European Commission adopted an adequacy decision for South Korea (Commission Implementing Decision (EU) 2022/254), concluding that PIPA offers protection essentially equivalent to the GDPR, including on redress and independence of the PIPC. The decision excludes processing of personal credit information under the Credit Information Act (CIA), which remains under Financial Services Commission (FSC) oversight outside PIPC's adequacy-relevant scope. PIPA itself recognises consent, international agreements, and other bases for cross-border transfers, and empowers the PIPC to suspend transfers. South Korea also participates in the APEC Cross-Border Privacy Rules (CBPR) system.
Sources and claims (5)
ConfirmedDataGuidance / Lee & Ko — PIPA recognises consent, international agreements, and other legal bases as valid grounds for cross-border transfers, and grants the PIPC power to cease cross-border transfers in certain cases.
ConfirmedIAPP — South Korea became the fifth member of the APEC Cross-Border Privacy Rules (CBPR) system, joining the U.S., Japan, Canada, and Mexico.
ConfirmedIAPP — The European Commission concludes that, for each relevant component including rights of individuals and redress mechanisms, South Korean law under PIPA offers a level of protection essentially equivalent to the GDPR, and that the PIPC meets the independence test required under the GDPR.
ConfirmedIAPP — The South Korea adequacy decision is subject to periodic review at least every four years under GDPR Article 45(3), with the first revision period for Korea shortened to three years.
ConfirmedEUR-Lex / European Union — The EU adequacy decision for South Korea excludes the processing of personal credit information pursuant to the Credit Information Act (CIA) by controllers subject to FSC oversight, since such processing falls outside the Decision's scope.
Financial and telecoms overlays are Confirmed via T1/T2 sources; health, education, employment, and insurance overlays carry no populated claims in this pass.
Primary frameworkPIPA; Credit Information Use and Protection Act; Network Act (ICNA); Act on Real Name Financial Transactions and Guarantee of Secrecy
Traffic-light rationale — AmberFinancial and telecoms overlays are Confirmed via T1/T2 sources; health, education, employment, and insurance overlays carry no populated claims in this pass.
Sub-modules (7)
Financial Sector OverlayGreen
The Credit Information Use and Protection Act governs personal credit information and is enforced by the FSC; the FSC also operates a 'MyData' licence mechanism for financial companies/FinTechs; the Act on Real Name Financial Transactions applies separately to financial institutions.
No health-sector-specific data-protection overlay was evidenced in this research pass.
Absence provenance: No dedicated health-sector statute/claim retrieved; recommend targeted search on Korea's Bioethics and Safety Act or medical-data provisions.. Searched: PIPC Korea AI guidelines biometric data facial recognition 2025 2026.
Telecoms And EprivacyGreen
The Network Act (ICNA) imposes additional, stricter consent and security obligations on information-and-communication service providers (ICSPs).
Claims: CLM-KR-b4c5d6f8
Employment DataRed
No employment-sector-specific data-protection overlay was evidenced in this research pass.
Absence provenance: No employment-specific statute/claim retrieved in this pass.. Searched: South Korea Credit Information Act financial sector data protection overlay PIPC FSC.
Credit And ScoringGreen
The Credit Information Use and Protection Act governs personal credit information used in credit ratings, under FSC enforcement.
Claims: CLM-KR-92a3b4d6
EducationRed
No education-sector-specific data-protection overlay was evidenced in this research pass.
Absence provenance: No education-specific statute/claim retrieved in this pass.. Searched: South Korea Credit Information Act financial sector data protection overlay PIPC FSC.
InsuranceRed
No insurance-sector-specific data-protection overlay was evidenced in this research pass.
Absence provenance: No insurance-specific statute/claim retrieved in this pass.. Searched: South Korea Credit Information Act financial sector data protection overlay PIPC FSC.
Category narrative97 words
Beyond PIPA, South Korea maintains sector-specific overlays: the Credit Information Use and Protection Act (Credit Act) governs personal credit information used in credit ratings and is enforced by the Financial Services Commission (FSC); the Act on Real Name Financial Transactions and Guarantee of Secrecy applies separately to financial institutions; and the Act on Promotion of Information and Communications Network Utilization and Information Protection (Network Act/ICNA) imposes stricter obligations on information-and-communication service providers. The FSC's 'MyData' credit-information platform operates under its own manual/licence mechanism. Health, education, employment, and insurance sector-specific overlays were not evidenced in this research pass.
Sources and claims (4)
ConfirmedEUR-Lex / European Union — The Use and Protection of Credit Information Act applies to credit information used in credit ratings, and the Financial Services Commission is Korea's supervisory authority for the financial sector in that capacity.
ConfirmedDataGuidance — The FSC published a manual and licence mechanism (July 2020) for financial companies and FinTechs to access and use the credit-information management platform 'MyData,' covering data security, outsourcing, and collection/use checklists.
ConfirmedIAPP — The Act on Real Name Financial Transactions and Guarantee of Secrecy applies separately to financial or financial-services institutions, distinct from PIPA's general regime.
ConfirmedEUR-Lex / European Union — Information-and-communication service providers face additional consent obligations under Article 39-3(1) PIPA and further security obligations under Article 48-2 of the PIPA Enforcement Decree, including internal management plans, access control, and encryption.
Only the direct_marketing sub-module has Confirmed claims; five of six declared sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) carry no populated claims and are flagged with explicit absent_field_provenance.
Primary frameworkAct on Promotion of Information and Communications Network Utilization and Information Protection (Network Act/ICNA); PIPA
Traffic-light rationale — RedOnly the direct_marketing sub-module has Confirmed claims; five of six declared sub-modules (cookies, dark patterns, opt-out signals, clean rooms, cross-context advertising) carry no populated claims and are flagged with explicit absent_field_provenance.
Sub-modules (6)
Cookies And TrackersRed
No PIPA/Network-Act-specific cookie-consent statutory text was retrieved in this research pass beyond the general ICSP consent framework.
Absence provenance: Dedicated cookie-consent provisions not retrieved verbatim; DataGuidance 'South Korea - Cookies & Similar Technologies' note exists but content was paywalled in retrieved snippet.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.
Dark PatternsRed
No dark-pattern-specific prohibition text was retrieved in this research pass.
Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.
Opt Out SignalsRed
No Global-Privacy-Control/DAA-equivalent opt-out signal framework was retrieved in this research pass.
Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room rule was retrieved in this research pass.
Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.
Cross Context AdvertisingRed
No cross-context-advertising-specific ('sale'/'share'-equivalent) provision was retrieved in this research pass.
Absence provenance: No claim populated in this pass.. Searched: Korea Network Act direct marketing opt-in consent cookies e-privacy.
Direct MarketingGreen
Senders of advertising messages must clearly indicate that consent relates to 'advertising information' (vague terms disallowed) and must provide simplified refusal mechanisms, per the KISA/KCC revised Network Act anti-spam guide (March 2026).
Claims: CLM-KR-d6e7f81a, CLM-KR-e7f8092b
Category narrative60 words
Under the Network Act, senders of commercial advertising messages must obtain clear, specific consent to 'advertising information' (vague terms such as 'benefit notifications' are disallowed) and must provide simplified opt-out mechanisms, per a March 2026 KISA/KCC revised anti-spam guide. Cookie/tracker-specific consent rules, dark-pattern prohibitions, opt-out signal (GPC/DAA-equivalent) frameworks, clean-room/data-collaboration rules, and cross-context-advertising-specific provisions were not evidenced in this research pass.
Sources and claims (2)
ConfirmedDataGuidance — Senders requesting consent to receive advertising messages must clearly indicate that the consent relates to 'advertising information,' with vague expressions such as 'benefit notifications' disallowed, per KISA's revised guide to the Network Act.
ConfirmedDataGuidance — Users must be able to refuse advertising communications through simplified means, such as app-notification opt-out, without complex procedures.
Enforcement precedent (model deletion, biometric special-category status, law-enforcement carve-out) is Confirmed via T1/T2 sources, but the Generative AI Guide is non-binding soft guidance and genetic-data-specific rules were not evidenced.
Primary frameworkPersonal Information Protection Act (PIPA); PIPC Guide for Development and Use of Generative AI (non-binding guidance)
Traffic-light rationale — AmberEnforcement precedent (model deletion, biometric special-category status, law-enforcement carve-out) is Confirmed via T1/T2 sources, but the Generative AI Guide is non-binding soft guidance and genetic-data-specific rules were not evidenced.
Sub-modules (6)
Profiling RestrictionsAmber
The PIPC's Kakao Pay/Alipay enforcement action addressed unlawful profiling (an 'NSF score' built without notice or consent from transferred user data).
Claims: CLM-KR-091a2b4d
Automated Decision Making TransparencyAmber
The same Kakao Pay/Alipay decision required destruction of the AI-derived scoring algorithm, evidencing PIPC's willingness to compel algorithmic transparency/remediation beyond monetary fines.
Claims: CLM-KR-091a2b4d
Ai Risk AssessmentsAmber
The PIPC published a Guide for the Development and Use of Generative AI (August 6, 2025), a non-binding reference outlining minimum legal/safety requirements, impact assessments, and Privacy by Design across the AI lifecycle.
Claims: CLM-KR-f8091a3c
Biometric RegimeGreen
Biometric data collected for unique identification is treated as sensitive/special-category information under PIPA, requiring separate consent.
Claims: CLM-KR-1a2b3c5f
Genetic DataRed
No genetic-data-specific provision was evidenced in this research pass.
Absence provenance: No genetic-data-specific statute/claim retrieved in this pass.. Searched: PIPC Korea AI guidelines biometric data facial recognition 2025 2026.
State Surveillance CarveoutsAmber
The EDPB's adequacy opinion notes that PIPA's provisions apply without limitation in the area of law enforcement, a carve-out subject to continued EU monitoring under the adequacy decision.
Claims: CLM-KR-2b3c4d60
Category narrative112 words
The PIPC has taken an increasingly assertive posture on algorithmic accountability: its January 2025 Kakao Pay/Alipay decision fined the companies KRW 8.3 billion and ordered destruction of an AI-trained credit-scoring algorithm built on unlawfully transferred user data, following on from the 2021 Scatter Lab precedent confirming PIPA's reach into AI training data. In August 2025 the PIPC published a Guide for the Development and Use of Generative AI, setting minimum legal/safety requirements across the AI lifecycle. Biometric data used for unique identification is a special category requiring separate consent. The EDPB's adequacy assessment notes that PIPA's provisions apply without limitation in the law-enforcement area, a national-security carve-out subject to ongoing EU monitoring.
Sources and claims (4)
ConfirmedIAPP — The PIPC's January 2025 Kakao Pay decision found the wallet provider sent 40 million users' data to Alipay, which built 'NSF scores' for Apple Pay without notice or consent, resulting in a KRW 8.3 billion fine and an order to erase the algorithm itself.
ConfirmedDataGuidance — The PIPC published a Guide for the Development and Use of Generative AI on August 6, 2025, outlining minimum requirements for legal and safe personal-data processing across the generative-AI lifecycle, including impact assessments and Privacy by Design.
ConfirmedarXiv — PIPA classifies biometric data used to uniquely identify an individual as a special category of sensitive information requiring separate consent for collection and processing.
ConfirmedEDPB — PIPA's provisions apply without limitation in the area of law enforcement, per the EDPB's assessment of the Korea adequacy decision, a carve-out the EDPB flagged for continued monitoring.
Only two of five declared sub-modules carry populated claims, and even those rest on comparative (Probable/Uncertain) rather than direct PIPA-primary-text confirmation of the exact age threshold.
Primary frameworkPersonal Information Protection Act (PIPA); Act on the Protection and Use of Location Information (analogous child-consent threshold)
Traffic-light rationale — RedOnly two of five declared sub-modules carry populated claims, and even those rest on comparative (Probable/Uncertain) rather than direct PIPA-primary-text confirmation of the exact age threshold.
Sub-modules (5)
Age VerificationAmber
The Act on the Protection and Use of Location Information sets a 14-years-old threshold requiring legal-representative consent for collecting children's location data; whether PIPA itself uses an identical threshold was not directly confirmed in this pass.
Claims: CLM-KR-4d5e6f82
Parental ConsentAmber
PIPA requires the consent of a guardian or legal representative to process children's personal information, similar to the GDPR, though without COPPA-style granular children's-privacy provisions.
Claims: CLM-KR-3c4d5e71
Minor Profiling BansRed
No minor-specific profiling ban was evidenced in this research pass.
Absence provenance: No claim populated in this pass.. Searched: PIPA Article 22-2 children under 14 legal representative consent Korea.
Education SettingsRed
No education-settings-specific children's-data rule was evidenced in this research pass.
Absence provenance: No claim populated in this pass.. Searched: PIPA Article 22-2 children under 14 legal representative consent Korea.
Dependent AdultsRed
No dependent-adult-specific protection was evidenced in this research pass.
Absence provenance: No claim populated in this pass.. Searched: PIPA Article 22-2 children under 14 legal representative consent Korea.
Category narrative88 words
PIPA requires the consent of a guardian or legal representative to process children's personal information, paralleling GDPR Art 8, but the statute lacks provisions specifically targeted at protecting children's data comparable to COPPA's granular regime. A precise, PIPA-specific statutory age threshold was not confirmed verbatim in this research pass; the analogous Location Information Act sets a 14-years-old threshold for requiring legal-representative consent to collect children's location data, which is indicative but not conclusive for PIPA's own child-consent age. Minor-profiling bans, education-settings-specific rules, and dependent-adult protections were not evidenced.
Sources and claims (2)
UncertainDataGuidance (hosting official statute translation) — Under Korea's Act on the Protection and Use of Location Information, a location-information provider seeking to collect, use, or provide personal location information from children under the age of 14 must obtain the consent of their legal representative.
ProbableDataGuidance / Lee & Ko — Both the GDPR and PIPA provide that the consent of a guardian or legal representative is required to process the personal information of children, though PIPA does not contain provisions specifically targeted at protecting children's personal information comparable to COPPA.
Enforcement activity and the forthcoming penalty regime are Confirmed at high materiality, but collective-redress and private-right-of-action mechanisms carry no populated claims, and regulator funding/capacity information rests on a non-binding EDPB observation.
Primary frameworkPersonal Information Protection Act (PIPA), as amended March 2026
Traffic-light rationale — AmberEnforcement activity and the forthcoming penalty regime are Confirmed at high materiality, but collective-redress and private-right-of-action mechanisms carry no populated claims, and regulator funding/capacity information rests on a non-binding EDPB observation.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, effective September 11, 2026.
Claims: CLM-KR-5e6f7093
Enforcement Activity IndexGreen
Recent enforcement includes the July 2026 Apple fine (Siri voice data) and the January 2025 Kakao Pay/Alipay fine with algorithm-deletion order.
Claims: CLM-KR-6f7081a4, CLM-KR-708192b5
Regulator Funding And CapacityAmber
The EDPB's 2021 adequacy opinion noted the draft decision lacked reference to PIPC staffing and financial resources, and requested further clarification.
Claims: CLM-KR-92a3b4d7
Collective Redress And Class ActionsRed
No PIPA-specific collective-redress or class-action mechanism was evidenced in this research pass.
Absence provenance: No claim populated in this pass.. Searched: PIPC Korea enforcement fine 2026.
Private Right Of ActionRed
No PIPA-specific private-right-of-action mechanism distinct from PIPC administrative enforcement was evidenced in this research pass.
Absence provenance: No claim populated in this pass.. Searched: PIPC Korea enforcement fine 2026.
Recent Developments 180DGreen
Within the last 180 days: the July 23, 2026 Apple fine, and the June 2, 2026 draft PIPA Enforcement Decree amendment (CPO governance, ISMS-P, 72-hour breach notice).
Claims: CLM-KR-8192a3c6, CLM-KR-6f7081a4
Category narrative112 words
The PIPC has demonstrated sustained, aggressive enforcement, including a KRW 252 million fine against Apple (July 23, 2026) over unauthorized Siri voice-data collection and the KRW 8.3 billion Kakao Pay/Alipay fine plus algorithm-deletion order (January 2025). The March 2026 PIPA amendment substantially raises the stakes, introducing a 10%-of-turnover penalty ceiling and personal CEO supervisory liability, effective September 11, 2026; the June 2026 draft Enforcement Decree amendment would further formalize CPO governance, ISMS-P certification, and 72-hour breach notification. The EDPB's 2021 opinion flagged a lack of detailed information on PIPC's staffing and financial resources as an area needing clarification. Collective-redress/class-action and private-right-of-action mechanisms specific to PIPA were not evidenced in this research pass.
Sources and claims (5)
ConfirmedIAPP — South Korea's March 2026 PIPA amendment introduces a penalty ceiling of 10% of total turnover and places personal supervisory liability on the CEO, taking effect September 11, 2026.
ConfirmedDataGuidance — On July 23, 2026, the PIPC fined Apple Distribution International Limited KRW 252 million (approx. $171,400) for violations of PIPA and the former Information and Communications Network Act, following an investigation into unauthorized collection of Siri voice data until August 2019.
ConfirmedIAPP — The PIPC's January 2025 Kakao Pay decision levied a KRW 8.3 billion fine on the wallet provider after finding it sent 40 million users' data to Alipay without consent, and ordered destruction of the resulting AI-derived scoring algorithm.
ConfirmedEDPB — The EDPB's 2021 opinion on the draft Korea adequacy decision noted that no reference was made to the specificities of PIPC staffing or the financial resources made available to it, and welcomed additional information.
ProbableDataGuidance — On June 2, 2026, the PIPC announced a draft amendment to the PIPA Enforcement Decree introducing CPO board-approval/notification requirements, mandatory ISMS-P certification by December 31, 2028, and a 72-hour breach-notification standard.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for South Korea
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 21 source(s) in the cumulative register.