Data Protection Atlas

South Korea

Tier 3 Comprehensive law Asia-Pacific

Principal framework: PIPA (as amended 2023) (2011). Regulator: PIPC. PIPA was heavily amended in 2023 (turnover-based fines, automated-decision rights); EU adequacy since 2021; the PIPC is among Asia’s most active enforcers.

At a glance

Principal law
PIPA (as amended 2023)
Regulator
PIPC
Breach notification
72 hours to the PIPC and affected individuals
Maximum penalty
Up to 3% of related turnover for major violations
DPO required
Chief Privacy Officer mandatory; qualification rules for larger firms
Digital consent age
14 — legal-representative consent below
Extraterritorial reach
Yes — conduct affecting Korean data subjects; overseas-transfer rules tightened 2023

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
KR

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No
Holds EU adequacy
Yes
Granted
17 December 2021
Review
First review concluded 2026

South Korea; GDPR Art.45.

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.