Two clocks, not one

A company that becomes aware of a personal data breach in Korea is on two separate 72-hour clocks. One runs to the data subjects. The other runs to the regulator, and only starts if one of three triggers is met. Meeting one duty does not discharge the other, and the two have different content requirements.

Since 11 September 2026 there is a third clock, and it is the one that catches foreign groups by surprise: it starts on suspicion, before any leakage has been confirmed.

What follows is the shape of the duty, taken from the Act and the Enforcement Decree, with the basis for each line. The figures are read from the same rule file the Korean page uses, so the two cannot drift apart.

72hto notify data subjects
72hto report to the PIPC or KISA
3reporting triggers — any one is enough

1 · Notifying data subjects

Clock startsbecoming aware that personal data has been leaked, lost or stolen (together, “leakage”)
Deadlinewithin 72 hours
Who must be toldthe data subjects whose personal data was leaked
Howin writing or by equivalent means — post, email, telephone, text message and the like
BasisAct art. 34(1); Decree art. 39(1)

The notice must carry all 6 items below. A notice sent inside the deadline but missing an item has itself been treated as a breach of the duty.

#What must be in the noticeBasis
1the categories of personal data leakedAct art. 34(1)1
2when the leakage occurred and how it happenedAct art. 34(1)2
3what the data subject can do to limit the harm, in concrete termsAct art. 34(1)3
4the steps the controller has taken and how the data subject can seek redressAct art. 34(1)4
5the team and contact details for reporting harmAct art. 34(1)5
6the data subject’s legal rights — damages, statutory damages and dispute mediation — and how to exercise themAct art. 34(1)6 (new, in force 11 September 2026)

When the 72 hours can move

GroundEffectBasis
urgent measures are needed to stop the spread or further leakage — closing the access path, checking for vulnerabilities, recovering or deleting the datanotify immediately once that ground has been resolvedDecree art. 39(1)1
a natural disaster or other unavoidable cause makes notification within the deadline impracticablenotify immediately once that ground has been resolvedDecree art. 39(1)2
the categories (item 1) or the timing and circumstances (item 2) have not yet been established in detailnotify first of the fact of leakage, what is known so far and items 3 to 6; notify the rest as soon as it is establishedDecree art. 39(2)
there is good reason, such as not knowing how to reach the data subjectpost the matters in Act art. 34(1) on the website for at least 30 days (if there is no website, in a conspicuous place at the place of business for at least 30 days)Act art. 34(1) proviso; Decree art. 39(3)

2 · Reporting to the authority

Tothe Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA)
Deadlinewithin 72 hours
Howin writing or by equivalent means
BasisAct art. 34(4); Decree art. 40(1); Decree art. 40(3)

Any one of the 3 triggers below is enough. They are not cumulative — a single sensitive-information record can bring the duty even where the headcount is small.

TriggerBasis
personal data of 1,000 or more data subjects was leakedDecree art. 40(1)1
sensitive information or unique identifying information was leakedDecree art. 40(1)2
the leakage resulted from unlawful external access to the personal data processing system or to a handler’s deviceDecree art. 40(1)3
GroundEffectBasis
a natural disaster or other unavoidable cause makes reporting within the deadline impracticablereport immediately once that ground has been resolvedDecree art. 40(1) proviso
the route of the leakage has been established and the risk to the data subjects has become markedly low because the data was recovered or deletedthe controller may choose not to reportDecree art. 40(1) proviso (new, in force 11 September 2026)
the categories (item 1) or the timing and circumstances (item 2) have not been establishedreport first the fact of leakage, what is known so far and items 3 to 5; report the rest as soon as it is establishedDecree art. 40(2)

3 · Notifying a possible leakage — new, in force 11 September 2026

Until 11 September 2026 the duty to notify arose only once a leakage was established. Two situations now start the clock on suspicion, and the notice goes to every data subject whose personal data may have been leaked within 72 hours (Act art. 34(2); Decree art. 39-2; Decree art. 39-3).

SituationClock startsBasis
there has been unlawful access to the personal data processing system or to a handler’s device, there are signs of leakage, but it is difficult to identify whose data is affectedwhen the controller became aware of that unlawful accessDecree art. 39-2(1)1
it is confirmed that some of the personal data has been leaked — for example, it is being traded by a third party in breach of law — and other data subjects’ data may also have been leakedwhen the controller became aware of that factDecree art. 39-2(1)2
#What the possible-leakage notice must carryBasis
1the categories of personal data that may have been leakedDecree art. 39-2(2)1
2when the leakage is suspected or accepted to have occurred, and howDecree art. 39-2(2)2
3the matters in Act art. 34(1)3 to 5 — how to limit the harm, the controller’s response and redress, and the contact pointDecree art. 39-2(2)3
4that a further notice will follow once it is established whether a leakage occurredDecree art. 39-2(2)4
What happens nextEffectBasis
an actual leakage is confirmed within the deadlinegive the notice under Act art. 34(1) instead of the possible-leakage noticeDecree art. 39-3(2)
it is later confirmed that no leakage in fact occurredtell the data subjects that immediatelyDecree art. 39-3(3)
there is good reason, such as not knowing how to reach the data subjectpost on the website for at least 30 days (if there is no website, at the place of business for at least 30 days)Decree art. 39-3(4)

4 · The duty that has no deadline

take measures to keep the harm to a minimum, including recovering or deleting the leaked data to stop the harm spreading (Act art. 34(3)). This is a separate duty from notification and reporting, and it carries no deadline of its own. It is one of the items the Commission actually weighs as a mitigating factor in its decisions.

Rules as at 2026-09-11 · Personal Information Protection Act (Act No. 21445, in force 11 September 2026) · Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 36671, in force 11 September 2026)

What the Commission has actually done about late notification

Deadlines read the same in every jurisdiction. What differs is what the regulator does when they are missed, and that is visible in the published decisions.

Of the decisions the Personal Information Protection Commission has published, 110 turned on breach of the notification or reporting duty. Where the decision records both the date of awareness and the date of notification, the median delay in notifying data subjects was 10 days, and the median delay in reporting to the authority was 6 days. The slowest notification in that set took 667 days.

Two things follow for a group with a Korean subsidiary.

The delays that get punished are measured in days, not months. A median of 10 days means the Commission is not reserving enforcement for companies that sat on an incident for a quarter. An internal escalation path that routes a Korean incident through a regional office and then headquarters will consume that budget on its own.

Completeness is a separate exposure from timing. There are decisions where the notice went out inside the deadline and the company was still found in breach, because one of the statutory items was missing. A template written for another regime will not carry all six items — the sixth, on the data subject’s right to damages, statutory damages and dispute mediation, was added on 11 September 2026 and has no direct counterpart elsewhere.

Where this differs from what your playbook probably says

  • The clock starts at awareness, not at confirmation. For the possible-leakage notice it starts at awareness of unlawful access, even where you cannot yet say whose data is involved.
  • The reporting triggers are alternatives. One record of sensitive information or unique identifying information brings the duty regardless of headcount.
  • "Notify the regulator" is not one address. The report goes to the Commission or to KISA.
  • Deferral is narrow and must be justified. The grounds are listed above; commercial inconvenience is not among them.
  • Recovering or deleting the data is a third duty, separate from the two notices and with no deadline of its own. It is also one of the things the Commission weighs when it comes to the amount.

Frequently asked questions

Q. How long do you have to report a data breach in South Korea?

72 hours, on two separate clocks. Data subjects must be notified within 72 hours of the controller becoming aware of the leakage (Personal Information Protection Act art. 34(1)), and the Personal Information Protection Commission or KISA must be notified within 72 hours where any one of three triggers is met (art. 34(4) and Enforcement Decree art. 40(1)). The two duties are separate: meeting one does not discharge the other.

Q. What is the penalty for late breach notification in Korea?

Late notification is itself a breach of the duty and is dealt with in the Commission’s enforcement decisions rather than by a fixed tariff. The published decisions show both the frequency and the scale: the counts on this page are read from the decisions themselves rather than estimated. A notice sent inside the deadline but missing one of the statutory items has also been treated as a breach.

Q. Does Korea require notification when a breach is only suspected?

Since 11 September 2026, yes, in two situations: unlawful access to the processing system or a handler’s device where the affected data subjects cannot be identified, and confirmation that some data has been leaked — for example that it is being traded — where other data subjects may also be affected. The notice goes out within 72 hours to everyone who may be affected, and a further notice follows once the position is established.


This page is general information on Korean law and is not legal advice; what a particular incident requires depends on its facts. Korean is the governing language of the statutes cited — the English renderings here are unofficial. Before relying on a figure, check the decision or provision it comes from.