This site is written in Korean. Where a topic regularly comes up with headquarters legal teams, global DPOs or deal teams outside Korea, the article carries an English summary at the end. This page collects those summaries, together with a small number of self-contained English notes and one English data table.

A note on what these are. They are not translations of the Korean articles — they are shorter notes written separately for a reader who needs the Korean position but does not read Korean. Statutory references follow the Ministry of Government Legislation’s English translation of the Personal Information Protection Act ("PIPA") where one exists. All English translations of Korean statutes are unofficial and carry no legal effect; the Korean text governs.

About the author — Hyunsub Lee, a Korean-qualified lawyer and partner at SEUM Law in Seoul, and what this site is.

Enforcement

Korea PIPC Enforcement Tracker — every published decision, searchable in English The whole published record of Korean privacy enforcement in one filterable table: respondent, date, provisions breached, sanction and amount, with English labels for provisions, sanction types and committee bodies. The Commission’s own board is searchable by title only, and almost every sanction decision carries the same title, so a company name or an article number returns nothing there. Administrative fines are the norm and surcharges the exception, and the safety-measures duty in art. 29 accounts for about half of the record. Same underlying rows as the Korean tracker.

How Korean privacy fines are calculated — a surcharge calculator and the fine table A surcharge under PIPA art. 64-2 starts from relevant turnover — total turnover less the turnover unrelated to the violation — multiplied by a base rate set by the seriousness grade, and is then adjusted, capped and rounded. The calculator applies that formula to the figures you enter, in your browser, and shows the four grades side by side because the grade is the Commission’s to decide. The page also carries the base rates, the grounds for increase and reduction, and the administrative fine amounts that come up most often for a foreign operator.

How Korea’s PIPC sanctions foreign companies — every published decision, in one table Every Personal Information Protection Commission decision against a named foreign operator, with country, respondent type, provisions breached, sanction and the respondent’s arguments. Cross-border transfer was the basis of a surcharge in two decisions (Apple, Temu), and in both the breach was a failure to disclose outsourcing abroad; one decision is 94% of the surcharges, and the point contested most often is how much turnover counts as Korean. Like the domestic representative note, this is a self-contained English page; the Korean table it is drawn from is here.

Cross-border transfers

Signing the group DPA is not the whole transfer analysis PIPA separates two layers that a global DPA usually merges: the legal basis for an outbound transfer under Article 28-8(1), and the terms Korean law separately requires the contract to contain. Signing the group-wide agreement completes only one of them.

Certification as a transfer ground — only one scheme is on the list Article 28-8(1)(iv) recognises a certification-based ground, but the certification must be one the Personal Information Protection Commission has designated and published, and the entity that must hold it is the recipient. Headquarters certifications generally do not satisfy either condition.

Erasure requests do not follow the data abroad Article 28-8(4) keeps the transferring Korean entity bound by Chapter 5 after the data has left. When a request concerns records held on headquarters systems, the obligation and the statutory clock still sit with the Korean entity.

Governance and global policy

Nine points where a global privacy programme breaks in Korea Several Korean requirements attach not to the content of a document but to who decides and what is published. Translating the programme does not address those.

Legitimate interest exists in Korea, with an added limb PIPA art. 15(1)(6) permits processing necessary for the controller’s legitimate interests, but only where those interests manifestly override the data subject’s rights. A GDPR lawful-basis mapping does not transfer one-for-one.

Which English text of PIPA to cite — and which to avoid Since 11 September 2026 the Act in force is Act No. 21445; the official English translation still reflected Act No. 20897 as at 11 September 2026. A widely-ranking English copy hosted elsewhere is the 2020 version and omits provisions your team may be looking for.

Appointing a domestic representative — full note Who must appoint one, the Enforcement Decree thresholds, and why a law firm can no longer hold the role for a group with a Korean subsidiary. The re-designation deadline passed on 2 April 2026, and the representative’s statutory remit widened on 11 September 2026. Unlike the other entries on this page, this one is a self-contained English note rather than a summary appended to a Korean article; the Korean article is here, and the short summary at the end of it remains in place.

Breach and incident response

Notification in Korea is not risk-based A headquarters playbook built on GDPR puts a risk assessment at the first decision point. PIPA Article 34(1) does not — notification is triggered by awareness, not by a risk threshold. The two procedures diverge at the first step.

Artificial intelligence

Bias testing with sensitive data — the EU exception has no Korean counterpart Article 10(5) of the EU AI Act permits processing special categories of data to detect and correct bias. PIPA Article 23(1) has no equivalent exception, so a headquarters bias-testing procedure may not be lawful in Korea as written.

Automated decisions made abroad, answered in Korea A Korean subsidiary that transferred the data remains the obligated party for refusal and explanation requests about a decision made by a headquarters system, and the response period runs in Korea.

Data portability

The 20 August 2026 date means opposite things depending on which side you are on Reporting described the right as extending "to all industries" from that date. That collapses two different positions — most private companies do not become recipients of transmission requests until 20 February 2027, while agents retrieving data through automated tools are affected immediately.

Transactions and diligence

Privacy diligence: the two violations that leave no trace Incident-type violations have a date and an external record a buyer can find. State-type violations — retention past the destruction deadline, a missing transfer basis — produce none, so they have to be requested. This note lists what to ask for.

About

These notes are written by Hyunsub Lee, a partner at SEUM Law in Seoul (firm profile — the page opens in Korean; use the ENG switch at the top right for the English version). Principal practice areas are IT, personal information and data, and startup advisory.

They are general information on Korean law and are not legal advice; conclusions depend on the facts of each case. Where an entry is a summary, the link leads to the Korean article it is drawn from; the self-contained notes and the data table stand on their own.