Guides
What Changed on September 11, 2026 for Anyone Running a Service in Korea
If you run a service in Korea, the way penalty surcharges for a personal data breach are set changed on September 11, 2026. This is not an amendment a company can sidestep because its revenue is small. One of the three new grounds for the 10% special cap ignores the size of the incident: it applies on the single fact that a breach occurred while an order you had already received was not yet carried out. Whether overseas operators are treated the same way is something we have not yet confirmed in the source text, and that point is noted separately below.
Korea's amended Personal Information Protection Act took effect on September 11, 2026[1]. The penalty cap is not the only thing that changed. The core question is under which circumstances the cap changes. The general cap of 3% of total revenue stays as it is[2], and on top of it a special provision was added that allows a penalty of up to 10% of total revenue. Article 64-2, Paragraph 2 of the act sets this out[2].
Only Three Situations Reach 10%
There are three cases in which the special provision applies[2].
First, committing the same type of violation again within three years of the date a penalty surcharge was imposed. Second, causing harm to 10 million or more people through intent or gross negligence. Third, a breach that occurs because a corrective order was not carried out.
Put the three side by side and a common thread appears. Only the second reaches 10% on the scale of a single incident alone. The other two look at what happened before. The first presupposes an earlier disposition; the third, an earlier order. The threshold for a higher cap takes in not only the size of the incident but also the record of how it was handled.
The Most Dangerous Stretch Comes After a Corrective Order
The third of the three special grounds is different in kind. The first two ask about the violation itself; the third applies when a breach occurs while an order already received has not been carried out[2]. From the moment the order is received until compliance is complete is the reach of this clause.
In this stretch the size of the incident does not decide the cap. Even below the 10-million-person threshold, even without any repeat, the fact alone that the order was not carried out takes the cap to 10%.
Repeats Stack as Multipliers
PIPC Notice No. 2026-12 sets the imposition base rates together with the aggravation rates for repeat violations[3]. The more times a penalty surcharge has been imposed for a violation under the same subparagraph within three years of the disposition date, the higher the aggravation rate: 20% for one prior case, 40% for two, and 80% for three or more[3].
The same notice also divides the base rate by the severity of the violation: 1.5% or more but under 2.1% for a serious violation, and 2.1% up to and including 2.7% for a very serious one[3].
Because the two are multiplied, the same incident can end in a very different final amount depending on how many prior dispositions there were. Repeat the same type of violation within three years of one penalty, and the second penalty costs far more than the first.
What Could Not Be Confirmed
Some items cannot be settled without opening the notice itself and its annexed tables: the detailed scoring that separates severity grades, the upper and lower bounds of the aggravation ratio applied under the 10% special provision, how intent and gross negligence are each scored, the alternative formula for operators whose total revenue cannot be calculated, and the order in which mitigation and aggravation are combined into the final amount. Whether public institutions and overseas operators are treated the same way also needs to be checked against the source text.
Put the Stretch Between the Order and Its Completion on the Schedule
When Weple takes on maintenance for a service running in Korea, this stretch is where we start. When was the corrective order received and how far has compliance gone; if a penalty has ever been imposed, on what date. With those two dates the work can be put in order and the first thing to finish becomes clear. The contract gets a target date for completing compliance, and the operations calendar gets a check slot, inside three years of the disposition date, for every other system where the same type of problem could still be sitting. If you have the order or the penalty notice on file, two lines with the dates are enough. If you have received neither an order nor a penalty, there is no date to write down yet, and the first conversation turns to which system gets its check slot ahead of the rest.
References
[1] Personal Information Protection Commission (PIPC), Standards for Imposing Penalty Surcharges for Violations of the Personal Information Protection Act (PIPC Notice No. 2026-12), in force from 2026-09-11 (in Korean). https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS216&mCode=D010020010&nttId=12490
[2] Korea Policy Briefing (korea.kr), Penalty surcharges raised for repeated and serious violations of the Personal Information Protection Act, 2026-09-17 (in Korean). https://www.korea.kr/multi/visualNewsView.do?newsId=148972051
[3] PIPC Notice No. 2026-12, imposition base rates and repeat-violation aggravation rates (in Korean). https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS216&mCode=D010020040&nttId=12490
In a similar spot
Send us where things stand and we reply with the scope and the price within 24 hours.