South Korea
Tier 3 Comprehensive law Asia-PacificPrincipal framework: PIPA (as amended 2023) (2011). Regulator: PIPC. PIPA was heavily amended in 2023 (turnover-based fines, automated-decision rights); EU adequacy since 2021; the PIPC is among Asia’s most active enforcers.
At a glance
- Principal law
- PIPA (as amended 2023)
- Regulator
- PIPC
- Breach notification
- 72 hours to the PIPC and affected individuals
- Maximum penalty
- Up to 3% of related turnover for major violations
- DPO required
- Chief Privacy Officer mandatory; qualification rules for larger firms
- Digital consent age
- 14 — legal-representative consent below
- Extraterritorial reach
- Yes — conduct affecting Korean data subjects; overseas-transfer rules tightened 2023
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- KR
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
- Holds EU adequacy
- Yes
- Granted
- 17 December 2021
- Review
- First review concluded 2026
South Korea; GDPR Art.45.
Instruments
No instrument profiled yet.
Sources
- Regulator Personal Information Protection Commission (PIPC)
- Primary Adequacy decision
Never independently verified — seeded from the prototype.