You sell to customers in Korea. Maybe it's a K-beauty reseller with a Seoul mailing list, an app with a few thousand Korean users, or a Singapore shop that ships to Busan every week. And somewhere in your feed a headline landed: "South Korea authorizes privacy fines of up to 10% of total revenue."
Ten percent. Of everything. From 11 September.
Take a breath. That number is real, it is in the law, and it is not written for you. Here is what the amendment actually says, what changes for a business your size, and the short list to check.
In a hurry? Two things change for a small business on 11 September: what counts as a breach, and when you have to say so. The six-item checklist is at the end of this article. Everything in between explains why the fine headline is not your problem.
First, the date — and why some articles have it wrong
The Personal Information Protection Act (PIPA) is Korea's main privacy law. The amending Act was promulgated as Act No. 21445 on 10 March 2026, after the National Assembly passed it on 12 February, and most of it takes effect six months later: 11 September 2026. A handful of provisions on mandatory security certification wait until 1 July 2027.
If you have read "August 2026" somewhere, the likely cause is commentary counting six months from the vote rather than from promulgation. The date in the Act is 11 September. That much is fixed.
The fine print arrived at the last minute. The Enforcement Decree amendment that fills in the operating detail — the investment-based fine reduction, the small-business waiver conditions, the procedure for the new "possible breach" notice — went through public comment in June and July and cleared legal review only on 31 August. On 10 September the regulator confirmed that the amended Decree and its accompanying notices take effect alongside the Act on 11 September. So the whole package lands on the same day, and the regulator's own guidance is still being finalized around it.
What "10% of revenue" actually means
Since 2023, the ceiling on a PIPA penalty surcharge has been 3% of total revenue, with revenue unrelated to the violation excludable from the calculation — though the burden is on the business to show which revenue is unrelated. That 3% ceiling is retained. It remains the ordinary maximum.
The amendment adds a second, higher tier of up to 10% of total revenue that the regulator, the Personal Information Protection Commission (PIPC), can reach for only in three situations:
- a business repeats a violation within three years, intentionally or through gross negligence;
- an intentional or grossly negligent violation affects 10 million or more people; or
- a business ignores a PIPC corrective order and a breach follows.
Two of those three are effectively size-gated. A three-year repeat offender acting with intent. An incident touching ten million people. The 10% tier is built for the largest platforms, and describing it as "Korea now fines 10%" is simply wrong.
One of the three is not about size. If the PIPC tells you to fix something and you do not, and then something leaks, the tier is open regardless of how small you are. That is the one to remember: a corrective order is not correspondence, it is a deadline.
Three more things the same amendment does, which get far less coverage:
- Fines can now go down as well as up. A business that can show real investment in data protection — budget, people, equipment, and a record of actually operating it — can have the surcharge reduced by up to 40% of the base amount. A business that detects an incident quickly, notifies on time and limits the damage can earn a further reduction of up to 40%. Neither applies to violations that were intentional or grossly negligent.
- There is an off-ramp for small businesses that fix things. The Decree also allows the surcharge to be waived entirely for a small or medium-sized business that corrects a minor violation — including where it does so with technical support from the regulator. Fixing it fast counts.
- The person at the top is named. The business owner or representative is now explicitly the person ultimately responsible for personal data protection. For a small business, that is a formality — you already were. For larger companies it comes with new board-approval and filing duties for their privacy officer, triggered at thresholds (annual revenue of ₩180 billion and up, combined with large data volumes) that a small business will not meet.
What actually changed for a business your size
Strip out the large-company provisions and two changes are left that matter from 11 September.
1. "Breach" now includes data being altered or destroyed, not only leaked. Until now the notification duty was framed around loss, theft and disclosure. From 11 September it also covers forgery, alteration and damage. The practical case is ransomware: if an attacker encrypts your customer file and nothing leaves the building, that can still be a notifiable incident.
2. You may have to notify on the possibility of a breach. The amendment adds a duty to notify when you have confirmed unauthorized access but cannot yet identify who is affected, or when you have confirmed part of a breach and suspect more. The 72-hour clock that already applied to confirmed breaches applies here too — and it can mean notifying even if you later establish that nothing was actually taken.
That second change is the one to update your incident plan for. The instinct in the first hours of an incident is to wait until you know everything. Korean law now says: if you know enough to know something happened, start the notification.
What did not change — your baseline
Everything below was already the law before 11 September and still is. If your privacy program covers it, the amendment does not add to your list.
- Korea's law reaches you. The PIPC applies PIPA to processing that affects people in Korea, and it has enforced against companies with no Korean establishment — including marketplace operators in 2024 and 2025, for cross-border transfer failures and, in one case, an account-deletion page that was only in English.
- A privacy notice, published. Korea calls it a personal information processing policy (개인정보 처리방침; the official English translation of the Act renders it "privacy policy"). It has to exist, be findable, and say what you collect, why, for how long, and who else sees it.
- Consent, and separate consent. Korea leans on consent harder than most regimes. Marketing messages and sharing data with third parties each need their own opt-in, not a line buried in the terms. Sending Korean customers' data overseas needs consent or one of the recognized alternatives.
- Breach notification within 72 hours. Affected people must be told within 72 hours of you becoming aware. The PIPC must also be notified within 72 hours where 1,000 or more people are affected, sensitive data is involved, or the cause was unauthorized external access.
- A privacy officer. Every business must have one. If you have fewer than ten staff (fewer than five in some sectors), Korean law already treats the owner as the officer where nobody is named. Above that, you have to name someone.
- Delete what you no longer need. When the purpose is met or the retention period ends, the data goes — unless another law says keep it.
- A domestic representative — but only at scale. The much-discussed requirement to appoint a representative inside Korea applies to foreign businesses with annual global revenue over ₩1 trillion or more than a million Korean users a day. It was tightened in October 2025 and is unchanged by this amendment. A small business is nowhere near it.
The short list
- Update your incident plan with the two new branches: altered-or-destroyed data counts, and a "possible breach" notice goes out within 72 hours even before you have the full picture. If you do not have an incident plan yet, our hour-by-hour guide to the first 72 hours is the place to start.
- Check your privacy notice is live and says what you actually do — including whether Korean customers' data is stored or processed outside Korea.
- If a Korean customer can sign up in Korean, they should be able to leave in Korean. The pages that let people withdraw consent, delete an account, or ask for their data should be reachable and in Korean. An English-only account-deletion page was one of the findings in a 2024 PIPC decision against a marketplace operator.
- Confirm the consents you rely on are separate — marketing, third-party sharing, overseas transfer — and that you could show when each one was given.
- Write down who your privacy officer is. If you have fewer than ten staff, Korean law already treats the owner as the officer where nobody is named — write it down anyway. Above that, name someone.
- Keep a record of what you spend on protection. It now counts in your favor if something goes wrong.
The part that makes this a long exhale
None of the six items above is new work if your privacy operation already runs on records rather than memory. Dxtra keeps your processing activity log and data mapping current, so "what Korean customer data do we hold, where is it, and who touches it" is a report, not a Friday-afternoon reconstruction. Its consent management records each opt-in separately with a timestamp. The breach & incident reporting workflow walks through containment, risk assessment and regulator deadlines by region — and your incident log is the evidence of what you did and when, which is what a regulator looks at first. Your privacy notice and the pages behind it can be published in Korean alongside English; plans include English plus one to ten additional languages, chosen from 75.
Plans start at $10/month, with a 14-day money-back guarantee on the START plan.
If you want to know where you stand before a regulator asks, the free privacy scan reads your site the way a regulator would and returns a risk band with cited findings — including where your privacy-notice, consent and data-handling evidence has gaps. No website? The 30-second quiz covers you too.
Sources
Current as of 10 September 2026. Effective dates, fine tiers and thresholds move, and the regulator's guidance on the new provisions is still being finalized; check the linked source before you rely on any of it.
- 개인정보 보호법 — 국가법령정보센터 (Korea National Law Information Center) — amending Act No. 21445, promulgated 10 March 2026, in force 11 September 2026 (some provisions 1 July 2027); Act No. 20897 in force 2 October 2025
- 개인정보위, 개인정보 유출 사전예방·피해구제 강화를 위한 개인정보 보호법·시행령·고시 9월 11일부터 시행 — PIPC announcement, 10 September 2026 (Korean, republished) — the amended Act, Enforcement Decree and notices all in force 11 September 2026; reduction of up to 40% for protection investment and a further up to 40% for rapid detection, notification and mitigation; surcharge waiver for small and medium-sized businesses correcting minor violations, including with technical support
- 개인정보 보호법 시행령 일부개정령안 입법예고 (공고 제2026-59호) — 법제처 — notice period 2 June to 13 July 2026, the 72-hour "possible breach" notification procedure
- "최대 매출 10% 과징금"… 개인정보보호법 시행령 개정안 입법예고 — ZDNet Korea (Korean) — the reduction for protection investment excluded for intentional or grossly negligent violations; the waiver for small and medium-sized businesses that correct minor violations
- Amendments to the PIPA, its Enforcement Decree, and the Network Act — Yulchon — promulgation and effective dates, the ISMS-P provisions from 1 July 2027
- 2026. 2. 12. 국회 본회의를 통과한 개인정보보호법 개정안의 주요 내용 — 법률신문 (Korean) — the retained 3% ceiling, the 10% tier and its three conditions, the "ultimate responsible person" provision and privacy-officer board approval
- South Korea amends privacy law to authorize fines of up to 10% of total revenue — Hunton — the three 10% triggers and the expanded breach definition (forgery, alteration, damage)
- 2026년 개정 개인정보 보호법 — 9월 11일까지 무엇을 해야 하나 — datalaw.kr (Korean) — the "possible breach" notification triggers and privacy-officer thresholds
- Proposed amendment to the PIPA passes the National Assembly (2023) — Shin & Kim — the 2023 move to 3% of total revenue and the exclusion of unrelated revenue, with the burden of proof on the business
- Data protection laws of the world: South Korea — DLA Piper — 72-hour notification to individuals and to the PIPC (1,000+ people, sensitive data, or unauthorized external access)
- Data protection laws of the world: South Korea — collection and processing — DLA Piper — consent as the primary basis, separate consents per processing activity and for third-party provision, and the cross-border transfer rules
- 개인정보 관련 의무 < 인터넷쇼핑몰 창업자 — 찾기쉬운 생활법령정보 (Korean government guide) — the privacy-officer duty, the small-business default that the owner is the officer, retention and destruction
- Domestic representative in Korea: new PIPA requirements in 2025 — Lexsimon — the ₩1 trillion revenue and one-million-daily-users thresholds, in force 2 October 2025; the 5-to-10-employee small-business band for the privacy-officer exception
- An overview of South Korea and Japan privacy enforcement (2020–present) — Loeb & Loeb — how the PIPC applies PIPA to foreign businesses, and its 2024 and 2025 actions against overseas marketplace operators, including the English-only account-deletion finding
- Dxtra pricing — $10/month START plan, 14-day refund on START, English plus one to ten additional languages by plan
This article is general information, not legal advice. Rules change — and the regulator's guidance on these provisions is still being finalized; confirm anything that matters with the Personal Information Protection Commission (개인정보보호위원회) or a qualified adviser before you rely on it. For a live incident, get advice now, not after the deadline.
Ready to have the answer before anyone asks?
The businesses that do well under a stricter law are not the ones with the biggest legal budget. They are the ones with the records. Get started with Dxtra from $10/month, or take the product tour to see the consent, incident and privacy-notice workflows.
