Severe Fine of 10% of Total Revenue for Leaks Affecting More Than 10 Million People
- Input
- 2026-09-10 12:32:13
- Updated
- 2026-09-10 12:32:13
In addition, data subjects must be notified of a suspected breach even if there is merely suspicion that personal information has been leaked.
The Personal Information Protection Commission (PIPC) announced that the amended Personal Information Protection Act, its Enforcement Decree, and related notices, which introduce punitive surcharges, will take effect on the 11th. The Personal Information Protection Act was amended last March and comes into effect on September 11 following a six-month transitional period.
With a series of large-scale personal information leaks recently occurring in sectors closely related to people's daily lives, such as finance, telecommunications, and shopping, the purpose of the law amendment is to strengthen the responsibility of companies and institutions regarding personal information leaks and to prevent such incidents in advance.

Punitive Fines for Personal Information Leaks
The core of the revised Personal Information Protection Act is the imposition of punitive surcharges on companies that leak personal information. In cases such as repeated violations within three years due to intent or gross negligence; large-scale damage affecting more than 10 million people due to intent or gross negligence; or a personal information leakage incident resulting from failure to comply with a corrective order, a surcharge may be calculated at up to 10% of total revenue. However, revenue unrelated to the violation is excluded.
The specific calculation of the surcharge is based on a comprehensive assessment of the content, extent, and circumstances of the violation of the Personal Information Protection Act and the scale of the damage to determine a standard amount, with aggravating and mitigating factors also taken into account.
The surcharge increase rate has been raised to 20% for one repeat violation, 40% for two, and 80% for three or more. Under the previous law, it was 15% for one repeat violation and 30% for two or more.
In addition, if a report or notification is not made within the legally prescribed period and measures to prevent the spread of damage, such as warnings, are not implemented, the surcharge will be increased by up to 30%.
Notification Required Even When a Personal Information Leak Is Merely Suspected
Conversely, if the personal information protection system has been strengthened through prior investment, the base amount of the surcharge will be reduced by up to 40%. The criteria include the scale, ratio, continuity, and degree of increase of investment in budgets, personnel, facilities, and equipment; the level of the personal information protection system, including the Chief Executive Officer (CEO), personal information protection officer, and professional personnel; and additional efforts beyond legal obligations.
A Personal Information Leakage Possibility Notification System will also be introduced to notify data subjects of a possible leak when it is reasonably judged that there is a high probability of leakage, even before the leak is finally confirmed.
This applies when unauthorized access to a personal information processing system or a device used by a personal information handler raises suspicion of a leak but makes it difficult to identify the data subjects, or when the leak of some personal information is confirmed, such as through the illegal trading of personal information, and it is recognized that the personal information of other data subjects may also have been leaked.
In such cases, data subjects must be notified within 72 hours of the organization becoming aware of the incident, including the categories of personal information involved, the suspected time and circumstances, methods for minimizing damage, and procedures for seeking redress.
The forgery, alteration, or damage of personal information has also been newly included among incidents subject to breach reporting and notification, meaning that the obligation to report and notify applies even when personal information is damaged by ransomware or similar attacks.
"With the implementation of the revised Personal Information Protection Act, I expect that prevention-oriented personal information protection and an enhanced safety management system will be established, and that investment in personal information protection will come to be viewed not as a 'cost' but as a 'preemptive investment' to secure customer trust and expand corporate profits," said Song Kyung-hee, Chairperson of the Personal Information Protection Commission.
Meanwhile, the Personal Information Protection Commission will operate a guidance period until December 31, 2027, to ensure the stable establishment of the system.
[email protected] Lee Gu-sun Reporter