Two clocks, not one
A company that becomes aware of a personal data breach in Korea is on two separate 72-hour clocks. One runs to the data subjects. The other runs to the regulator, and only starts if one of three triggers is met. Meeting one duty does not discharge the other, and the two have different content requirements.
Since 11 September 2026 there is a third clock, and it is the one that catches foreign groups by surprise: it starts on suspicion, before any leakage has been confirmed.
What follows is the shape of the duty, taken from the Act and the Enforcement Decree, with the basis for each line. The figures are read from the same rule file the Korean page uses, so the two cannot drift apart.
1 · Notifying data subjects
| Clock starts | becoming aware that personal data has been leaked, lost or stolen (together, “leakage”) |
| Deadline | within 72 hours |
| Who must be told | the data subjects whose personal data was leaked |
| How | in writing or by equivalent means — post, email, telephone, text message and the like |
| Basis | Act art. 34(1); Decree art. 39(1) |
The notice must carry all 6 items below. A notice sent inside the deadline but missing an item has itself been treated as a breach of the duty.
| # | What must be in the notice | Basis |
|---|---|---|
| 1 | the categories of personal data leaked | Act art. 34(1)1 |
| 2 | when the leakage occurred and how it happened | Act art. 34(1)2 |
| 3 | what the data subject can do to limit the harm, in concrete terms | Act art. 34(1)3 |
| 4 | the steps the controller has taken and how the data subject can seek redress | Act art. 34(1)4 |
| 5 | the team and contact details for reporting harm | Act art. 34(1)5 |
| 6 | the data subject’s legal rights — damages, statutory damages and dispute mediation — and how to exercise them | Act art. 34(1)6 (new, in force 11 September 2026) |
When the 72 hours can move
| Ground | Effect | Basis |
|---|---|---|
| urgent measures are needed to stop the spread or further leakage — closing the access path, checking for vulnerabilities, recovering or deleting the data | notify immediately once that ground has been resolved | Decree art. 39(1)1 |
| a natural disaster or other unavoidable cause makes notification within the deadline impracticable | notify immediately once that ground has been resolved | Decree art. 39(1)2 |
| the categories (item 1) or the timing and circumstances (item 2) have not yet been established in detail | notify first of the fact of leakage, what is known so far and items 3 to 6; notify the rest as soon as it is established | Decree art. 39(2) |
| there is good reason, such as not knowing how to reach the data subject | post the matters in Act art. 34(1) on the website for at least 30 days (if there is no website, in a conspicuous place at the place of business for at least 30 days) | Act art. 34(1) proviso; Decree art. 39(3) |
2 · Reporting to the authority
| To | the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) |
| Deadline | within 72 hours |
| How | in writing or by equivalent means |
| Basis | Act art. 34(4); Decree art. 40(1); Decree art. 40(3) |
Any one of the 3 triggers below is enough. They are not cumulative — a single sensitive-information record can bring the duty even where the headcount is small.
| Trigger | Basis |
|---|---|
| personal data of 1,000 or more data subjects was leaked | Decree art. 40(1)1 |
| sensitive information or unique identifying information was leaked | Decree art. 40(1)2 |
| the leakage resulted from unlawful external access to the personal data processing system or to a handler’s device | Decree art. 40(1)3 |
| Ground | Effect | Basis |
|---|---|---|
| a natural disaster or other unavoidable cause makes reporting within the deadline impracticable | report immediately once that ground has been resolved | Decree art. 40(1) proviso |
| the route of the leakage has been established and the risk to the data subjects has become markedly low because the data was recovered or deleted | the controller may choose not to report | Decree art. 40(1) proviso (new, in force 11 September 2026) |
| the categories (item 1) or the timing and circumstances (item 2) have not been established | report first the fact of leakage, what is known so far and items 3 to 5; report the rest as soon as it is established | Decree art. 40(2) |
3 · Notifying a possible leakage — new, in force 11 September 2026
Until 11 September 2026 the duty to notify arose only once a leakage was established. Two situations now start the clock on suspicion, and the notice goes to every data subject whose personal data may have been leaked within 72 hours (Act art. 34(2); Decree art. 39-2; Decree art. 39-3).
| Situation | Clock starts | Basis |
|---|---|---|
| there has been unlawful access to the personal data processing system or to a handler’s device, there are signs of leakage, but it is difficult to identify whose data is affected | when the controller became aware of that unlawful access | Decree art. 39-2(1)1 |
| it is confirmed that some of the personal data has been leaked — for example, it is being traded by a third party in breach of law — and other data subjects’ data may also have been leaked | when the controller became aware of that fact | Decree art. 39-2(1)2 |
| # | What the possible-leakage notice must carry | Basis |
|---|---|---|
| 1 | the categories of personal data that may have been leaked | Decree art. 39-2(2)1 |
| 2 | when the leakage is suspected or accepted to have occurred, and how | Decree art. 39-2(2)2 |
| 3 | the matters in Act art. 34(1)3 to 5 — how to limit the harm, the controller’s response and redress, and the contact point | Decree art. 39-2(2)3 |
| 4 | that a further notice will follow once it is established whether a leakage occurred | Decree art. 39-2(2)4 |
| What happens next | Effect | Basis |
|---|---|---|
| an actual leakage is confirmed within the deadline | give the notice under Act art. 34(1) instead of the possible-leakage notice | Decree art. 39-3(2) |
| it is later confirmed that no leakage in fact occurred | tell the data subjects that immediately | Decree art. 39-3(3) |
| there is good reason, such as not knowing how to reach the data subject | post on the website for at least 30 days (if there is no website, at the place of business for at least 30 days) | Decree art. 39-3(4) |
4 · The duty that has no deadline
take measures to keep the harm to a minimum, including recovering or deleting the leaked data to stop the harm spreading (Act art. 34(3)). This is a separate duty from notification and reporting, and it carries no deadline of its own. It is one of the items the Commission actually weighs as a mitigating factor in its decisions.
Rules as at 2026-09-11 · Personal Information Protection Act (Act No. 21445, in force 11 September 2026) · Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 36671, in force 11 September 2026)
What the Commission has actually done about late notification
Deadlines read the same in every jurisdiction. What differs is what the regulator does when they are missed, and that is visible in the published decisions.
Of the decisions the Personal Information Protection Commission has published, 110 turned on breach of the notification or reporting duty. Where the decision records both the date of awareness and the date of notification, the median delay in notifying data subjects was 10 days, and the median delay in reporting to the authority was 6 days. The slowest notification in that set took 667 days.
Two things follow for a group with a Korean subsidiary.
The delays that get punished are measured in days, not months. A median of 10 days means the Commission is not reserving enforcement for companies that sat on an incident for a quarter. An internal escalation path that routes a Korean incident through a regional office and then headquarters will consume that budget on its own.
Completeness is a separate exposure from timing. There are decisions where the notice went out inside the deadline and the company was still found in breach, because one of the statutory items was missing. A template written for another regime will not carry all six items — the sixth, on the data subject’s right to damages, statutory damages and dispute mediation, was added on 11 September 2026 and has no direct counterpart elsewhere.
Where this differs from what your playbook probably says
- The clock starts at awareness, not at confirmation. For the possible-leakage notice it starts at awareness of unlawful access, even where you cannot yet say whose data is involved.
- The reporting triggers are alternatives. One record of sensitive information or unique identifying information brings the duty regardless of headcount.
- "Notify the regulator" is not one address. The report goes to the Commission or to KISA.
- Deferral is narrow and must be justified. The grounds are listed above; commercial inconvenience is not among them.
- Recovering or deleting the data is a third duty, separate from the two notices and with no deadline of its own. It is also one of the things the Commission weighs when it comes to the amount.
Related
- PIPC enforcement decisions — the published decisions, by article, disposition and year
- Penalty surcharge calculator — how the amount is built under the Act and the Notice
- Domestic representative — who must appoint one, and what the appointment actually carries
- English notes — the rest of the English material
Frequently asked questions
Q. How long do you have to report a data breach in South Korea?
72 hours, on two separate clocks. Data subjects must be notified within 72 hours of the controller becoming aware of the leakage (Personal Information Protection Act art. 34(1)), and the Personal Information Protection Commission or KISA must be notified within 72 hours where any one of three triggers is met (art. 34(4) and Enforcement Decree art. 40(1)). The two duties are separate: meeting one does not discharge the other.
Q. What is the penalty for late breach notification in Korea?
Late notification is itself a breach of the duty and is dealt with in the Commission’s enforcement decisions rather than by a fixed tariff. The published decisions show both the frequency and the scale: the counts on this page are read from the decisions themselves rather than estimated. A notice sent inside the deadline but missing one of the statutory items has also been treated as a breach.
Q. Does Korea require notification when a breach is only suspected?
Since 11 September 2026, yes, in two situations: unlawful access to the processing system or a handler’s device where the affected data subjects cannot be identified, and confirmation that some data has been leaked — for example that it is being traded — where other data subjects may also be affected. The notice goes out within 72 hours to everyone who may be affected, and a further notice follows once the position is established.
This page is general information on Korean law and is not legal advice; what a particular incident requires depends on its facts. Korean is the governing language of the statutes cited — the English renderings here are unofficial. Before relying on a figure, check the decision or provision it comes from.