Personal information controller
The primary duty holder. Unlike the EU split, PIPA puts almost every obligation on the controller and treats outsourced processing as a delegation the controller must supervise.
Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.
Open the guideWe scope against the laws that actually apply to you, then sequence the work by risk.
Start the assessmentWhat must be operational before the substantive obligations commence in 2027.
Read the briefingAnswer 18 questions and get a prioritised control roadmap instantly.
Start the assessmentTrack 01 assumes no prior knowledge of governance, risk and compliance.
Start Track 01Asia Pacific
PIPA is one of the strictest general privacy regimes in Asia. It is consent-first rather than balancing-first, it applies to the public and private sectors through a single statute, and it is enforced by a regulator, the Personal Information Protection Commission, with the power to impose turnover-based penalties. The 2023 amendment package removed the separate rules that had applied to information and communications service providers, introduced a statutory right to opt out of solely automated decisions, and brought in a transfer regime with several distinct routes.
Applicability
PIPA regulates the “personal information controller”, meaning any person, public institution, corporation or organisation that processes personal information to operate personal information files as part of its activities. There is no size threshold for the core duties, and the PIPC has asserted reach over foreign operators serving users in Korea.
The primary duty holder. Unlike the EU split, PIPA puts almost every obligation on the controller and treats outsourced processing as a delegation the controller must supervise.
Outsourcing requires a written document setting out the scope and security duties, disclosure of the delegatee, and active supervision. The controller remains liable for the delegatee’s acts in damages claims.
May be processed without consent for statistical, scientific research and public-interest archiving purposes, subject to strict re-identification prohibitions and separate safeguards.
Foreign controllers meeting the prescribed scale thresholds must designate a representative in Korea and publish those details in the privacy policy.
Ideology, health, genetic and biometric data, and resident registration numbers, carry separate and stricter rules. The resident registration number cannot be processed without a specific statutory hook.
Processing the information of a child under fourteen requires the consent of a legal guardian, and the notice must be given in language the child can understand.
Processing conditions
PIPA lists the permitted grounds exhaustively. Consent remains the default in practice, and Korean consent is granular: separate, individually refusable consents are required for optional processing, for sensitive data, for marketing and for transfers abroad. Bundling optional consent into a service is prohibited.
| Ground | When it works | Practitioner caution |
|---|---|---|
| Consent of the data subject | The individual has given specific, informed and separately obtained consent. | Must be separable. Refusing optional consent cannot be a reason to deny the service, and you must tell the individual that they may refuse. |
| Special provision of law | A statute or a legal obligation requires the processing. | Identify the specific provision. Sectoral financial and telecommunications statutes carry their own overlays. |
| Necessary for a contract | Unavoidably necessary to conclude or perform a contract with the data subject. | The 2023 amendment widened this, but the PIPC reads ‘unavoidably necessary’ narrowly. It does not cover analytics or marketing bolted onto the contract. |
| Urgent interests of life, body or property | Where the individual or a third party faces an urgent risk and consent cannot be obtained. | Emergency facing. Document the urgency at the time, not afterwards. |
| Legitimate interests of the controller | Where the interest is manifestly superior to the rights of the data subject and the processing is substantially related to it. | A high bar, notably higher than the EU balancing test. Record the assessment and keep the scope tight. |
| Public institution duties | A public institution performing a task prescribed by law. | Public sector only; not available to private controllers. |
Cross-border
The 2023 amendment replaced a consent-only model with several routes, which was a significant practical improvement. It also gave the PIPC the power to order a transfer suspended where the destination lacks adequate protection.
Still available, and still the most common route. The notice must state the recipient, the country, the purpose, the categories, the retention period and the fact that consent may be refused.
Where the transfer is needed to perform a contract, it can rest on publication in the privacy policy or direct notice, rather than separate consent.
A transfer to a recipient holding a PIPC-recognised certification, with protective measures in place.
Where the PIPC has determined that the destination country or recipient offers protection equivalent to PIPA.
Where a treaty or another statute provides for the transfer.
The PIPC can order an existing transfer stopped. Build a contingency so a suspension does not halt the underlying service.
Individual rights
Individuals may inspect their information and require correction or deletion, with limited statutory grounds for refusal that must be explained in writing.
A distinctive PIPA right allowing an individual to require processing to stop, separate from deletion.
Where a decision is made solely by automated means, including artificial intelligence, and significantly affects rights, the individual may refuse it or request an explanation.
A portability-style right, rolled out sector by sector rather than all at once. Check the implementation status for your sector.
Statutory damages are available without proof of actual loss in defined circumstances, and punitive damages up to a multiple of actual loss apply for wilful or grossly negligent loss of data.
Requests must be handled within ten days for access, with the reasons for any extension or refusal given to the individual.
Operational duties
Controllers must designate a CPO. The amendment strengthened the role with independence guarantees and a prohibition on disadvantaging the CPO for performing their duties. Prescribed controllers must appoint a CPO with defined qualifications.
Notify affected individuals and the PIPC or KISA without delay once a breach is known, within the period set by the enforcement decree. Korea sets short clocks, so rehearse the decision path in advance.
Mandatory for public institutions operating qualifying files, and strongly encouraged for private controllers handling large or sensitive volumes.
The PIPC reviews published privacy policies for adequacy and can require changes, so the policy is a supervised document, not a formality.
The enforcement decree prescribes specific technical and organisational measures, including access control, encryption of prescribed identifiers and access log retention.
Administrative fines can reach a percentage of total turnover for serious violations, alongside criminal liability for certain acts. Enforcement is active and published.
Where to go next
Korea is often assessed alongside its neighbours. Our Japan guide covers the APPI, China covers PIPL and the transfer routes, and the jurisdiction index lists every regime we track. If you need help mapping a Korean programme against an existing GDPR baseline, talk to us.