Guides
From November 1, Korea Treats Seller Logins Like Staff Logins
Open Korea's Standards for Ensuring the Security of Personal Information on the national law portal today and Article 8(2) no longer says "once a month." That does not mean the monthly access-log review can stop. The amended wording was placed in the body of the notice right away, while the date it starts to apply sits in the addendum.
This matters to anyone who processes the personal data of users in Korea: a marketplace that onboards Korean merchants, a booking platform with Korean partner venues, a SaaS product whose Korean customers log in to an admin console. The Personal Information Protection Commission (PIPC) amended the notice on October 31, 2025. Some changes, such as relaxing the internet isolation rule, applied that day. Seven clauses that need preparation were deferred by a year, and the PIPC's guidebook marks each of them "in force from November 1, 2026."
If sellers, merchants, or partners log in to your admin screens, from November 1 their accounts need the same treatment as staff accounts: least-privilege permissions, lockout after repeated failed logins, extra authentication when they connect from outside, and retained access logs. If only your own staff log in, the work is mostly a revision of your internal management plan. Either way, the old text applies until then, so October's once-a-month review still has to be done.
Four terms the whole change turns on
- Personal information controller (PIPA Article 2(5)): the company or person that runs personal data files for business purposes.
- Personal information handler (PIPA Article 28(1)): employees, dispatched workers, part-timers and others who process personal data under the controller's direction and supervision.
- Data subject (PIPA Article 2(3)): the person the data identifies, such as a registered user.
- Outside operator: our term, not a legal one, for someone who is not the controller's handler but logs in to its system for work, such as a marketplace seller. The PIPC press release calls this group "persons performing tasks."
Most of the amendment simply swaps which of these groups a clause covers. The notice carries legal weight because PIPA Article 29 requires controllers to take the security measures set by Presidential Decree, and Article 30(3) of the Enforcement Decree delegates the detailed standards to the PIPC. Breaching the notice is therefore a breach of Article 29.
Why the guide says November 1
The addendum to Notice No. 2025-9 says the seven clauses take effect "one year after the date of issuance." Read literally, that could land on October 31, 2026, and at least one Korean blog commentary gives October 30. The PIPC guidebook published on November 28, 2025, a 196-page PDF, writes "in force from November 1, 2026" next to every one of the seven. That also matches the Korean practice of not counting the first day of a period: the PIPA amendment promulgated on March 10, 2026 "six months after promulgation" is listed as in force from September 11, not September 10. We follow the regulator's date, and the gap is a day or two. Finish the new setup by October 30 and keep doing the monthly review through October, and no reading leaves a hole.
The seven clauses, before and after
| Clause | Until October 31 | From November 1 | In practice |
|---|---|---|---|
| Art. 4(1) items 12, 13 (internal management plan) | 16 items; nothing on printing, copying or destruction | 18 items; printing and copying safeguards (item 12) and destruction of personal data (item 13) added, old items 12 to 16 renumbered 14 to 18 | Duties already in Articles 12 and 13 now also belong in the plan |
| Art. 5(1) (access rights) | Least-privilege access granted "only to personal information handlers" | Least-privilege access, with the "handlers only" wording removed | Accounts issued to non-staff also get only the menus and actions their job needs |
| Art. 5(6) (failed logins) | Only legitimate handlers or data subjects may access; limit access after repeated failures | Only "persons with legitimate authority" may access | Every account that logs in, sellers included, needs a lockout |
| Art. 6(2) (outside access) | Handlers connecting from outside need a certificate, security token, one-time password or similar | Anyone with legitimate access rights, excluding data subjects | Sellers and partners reaching the admin screen from outside need more than a password; end users logging in to their own accounts are excluded |
| Art. 8(1) (log retention) | Handlers' access logs kept at least one year | Logs of anyone who accessed the system, excluding data subjects, kept at least one year | Seller access logs are retained too; the two-year conditions are unchanged |
| Art. 8(2) (log review) | Review access logs at least once a month and confirm the reason for any download | Set the review cycle, method and follow-up for handlers' access logs and downloads in the internal management plan, then follow it | "Monthly" and "confirm the download reason" disappear; review follows your own plan and still covers staff only |
Logs must be kept for at least two years, before and after the amendment, if the system holds data on 50,000 or more data subjects, processes unique identifiers (such as resident registration or passport numbers) or sensitive data, or belongs to a registered or reported facilities-based telecom carrier.
The two paragraphs of Article 8 now cover different people on purpose. The PIPC press release says marketplace seller logs are to be kept, while review and follow-up are limited to personal information handlers "in consideration of practical circumstances." A seller who is not your handler must be logged but does not have to be reviewed. A "partner" who in fact works under your direction may well be a handler, and then the review applies.
The gap the amendment closes
Most of the old duties named "personal information handlers," meaning people under the controller's supervision. A marketplace seller who is not the platform's employee, yet logs in to pull a buyer's name, address and phone number, fell outside them. The press release says exactly that, and notes that large platforms had been offering some of these features to sellers through voluntary codes. The notice's stated reason is to keep unauthorized people out and, if data is misused or leaked, to trace who did what from the stored logs. The monthly review went because the old rule was criticized for pushing formal box-ticking, so the controller now designs the review itself. The duty did not disappear; the responsibility for defining it moved to you.
What to build
Split accounts into three types. Without this field in your user model you cannot decide which rule applies where.
| Account type | Least privilege | Lockout | Outside auth | Log retention | Log review |
|---|---|---|---|---|---|
| Staff (personal information handlers) | Yes | Yes | Yes | Yes | Yes |
| Outside operators (sellers who are not handlers) | From Nov 1 | From Nov 1 | From Nov 1 | From Nov 1 | Not required (retain only) |
| End users (data subjects) | Not applicable | Yes, already before | Excluded | Excluded | Excluded |
Permissions by menu and action. The guidebook asks for access split into menus and detailed rights (view, input, delete, edit, download, print) and gives view-only access to anyone who can work with that. A sensible seller default is "view the fields needed to ship my own orders," with downloads and bulk queries as separately granted rights. Records of granting, changing and revoking rights are kept for three years under Article 5(3).
Lockout. The threshold is yours to set; the guidebook says it can reflect the system's characteristics and a risk analysis. Unlocking requires confirming the legitimate user first. The FAQ adds that delays or a CAPTCHA alone are not enough: after a set number of failures the account still has to lock.
Extra authentication for outside access. The guidebook describes a method that others cannot easily steal or forge, such as a one-time password on top of the password. A time-based one-time password (TOTP) from an authenticator app is usually the lightest to build. Tell sellers how to enroll before switching it on, or support tickets will pile up on the first morning.
Access logs. Five fields are required: identifier, date and time, access location, the data subject whose data was processed, and the task performed. The FAQ says logins, logouts and failed logins belong in the log too. There is no fixed format; this is one way to write a seller entry:
{"actor_id":"S-10293","actor_type":"seller","ts":"2026-11-02T10:15:03+09:00",
"src_ip":"203.0.113.24","subject":"order:20261102-000123","action":"view_shipping_contact"}
Record actor_type, because seller logs only need retaining while staff logs also need reviewing. If one query touches many people, the query itself can stand in for the data subject, with a database snapshot kept alongside. Protect logs against tampering (separate backup storage, write-once media, or message authentication codes or signatures stored elsewhere) and restrict who can edit or delete them.
Review rules for the internal management plan. The guidebook's table lists four things to define: cycle (real time to quarterly, allowing for holidays), method (automated, scripted or manual), criteria (unauthorized access, bulk downloads in a short time, excessive lookups, off-hours activity) and follow-up (report, notification, explanation, then reporting, recovery or deletion). It also wants the review done by a team other than the one handling the data. In a very small team, at least keep the reviewer and the reviewed account apart. If a script does the review, write down what it flags; that document is your evidence that you set a rule and followed it.
What a breach of the standards can cost
Under PIPA as in force since September 11, 2026, failing to take the required security measures can bring an administrative fine of up to KRW 30 million (Article 75(2)5), even without a leak. If data is lost, stolen, leaked, forged, altered or damaged, the penalty surcharge can reach 3% of total revenue, or KRW 2 billion where revenue cannot be calculated (Article 64-2(1)9). It can reach 10%, or KRW 5 billion, for an intentional or grossly negligent repeat within three years of a surcharge, an intentional or grossly negligent violation harming 10 million or more people, or a leak caused by ignoring a corrective order (Article 64-2(2)).
The clause worth reading twice is the proviso to Article 64-2(1)9: no surcharge if the controller had taken all the required measures. From November 1, extra authentication and access logs on seller accounts are part of that proof. A hijacked seller account with neither makes the proviso hard to claim. A fine and a surcharge are not imposed for the same act (Article 76). We list statutory ceilings only.
Before October 30
- Run October's monthly review under the old rule and record it, including download reasons.
- List every account that reaches your admin screens and sort it into staff, outside operator or end user. No outside operators means far less to do.
- Draw up a permission table for outside operators, with download off by default.
- Add lockout and extra authentication to their login, and announce the change before it goes live.
- Check their logs carry all five fields, and set log retention to one or two years as your conditions require.
- Get a revised internal management plan approved: items 12 and 13, renumbering, the Article 8(2) review rules, and outside operator permissions.
- Book the first November review now; a plan only counts as followed once a review actually happens.
- Public system operators must also run a vulnerability check and an outside penetration test on each public system at least once a year from January 1, 2027 (Article 18).
What is still open
- The date follows the guidebook. The addendum says "one year after issuance," one commentary gives October 30, and we found no court ruling or Ministry of Government Legislation interpretation. The press release only says "one-year grace period."
- Who counts as a "person with legitimate access rights" is shown only by example ("marketplace sellers, etc."). Franchisees, outsourced call centers and partner staff depend on the contract and on who directs whom.
- Whether the three-year record of permission changes (Article 5(3)) extends to outside operator accounts is not spelled out. We recommend keeping it.
- The guidebook does not say how a small business exempt from the internal management plan should set its Article 8(2) review. A short written rule is the safer course, in our view.
- Until November 1 the guidebook points to its October 2024 edition for the deferred clauses.
- This is not legal advice. For your own case, ask the PIPC's legal interpretation help line (+82-2-2100-3043, Korean) or counsel.
Follow One Seller Login From Start to Finish
Bring the list of accounts that reach your admin console and the schema of the table your access logs land in. With Weple's backend development, the first session traces a single seller login: which role it enters with, what it looks up, and how many of the five fields the trace leaves behind. Gaps such as a login path with no lockout or a log row with no account type show up quickly, and we sort them into what must be closed before November 1. How the work is scoped and billed is on the pricing page. How the breach penalty cap is set is covered in What Changed on September 11, 2026 for Anyone Running a Service in Korea. If no seller ever logs in, we start instead with a first draft of the review rules for your internal management plan.
Sources
All primary sources were opened and checked on September 26, 2026. The notice and statute texts were compared article by article from the national law portal's public API.
- Korea Law Information Center, Standards for Ensuring the Security of Personal Information, PIPC Notice No. 2023-6 (in force 2023-09-22, in Korean). Old wording of the deferred clauses.
- Korea Law Information Center, PIPC Notice No. 2025-9 (issued 2025-10-31, in Korean). Addendum Article 1, reasons for amendment, new wording.
- Korea Law Information Center, PIPC Notice No. 2026-9 (issued 2026-07-01, current, in Korean). Articles 12, 13, 15 and 18, addendum for 2027-01-01.
- PIPC, Guidebook on the Standards for Ensuring the Security of Personal Information (November 2025), 196-page PDF posted 2025-11-28 (in Korean). The November 1, 2026 notation, seller guidance, review table, FAQ.
- PIPC press release, Reform of blanket internet isolation takes full effect, posted 2025-10-31 (in Korean). Seller gap, voluntary codes, why Article 8(2) stays with handlers.
- Korea Law Information Center, Personal Information Protection Act, Act No. 21445 (in force 2026-09-11) and its Enforcement Decree (in Korean). Articles 2, 28, 29, 64-2, 75, 76 and Decree Article 30(3).
- Kim & Chang newsletter, Enforcement of the Amended Standards for Ensuring the Security of Personal Information (2025-11-05, in Korean). Cross-check of the amendment. Secondary.
- IntoTheSec, blog post on the amended standards (2025-11-13, in Korean). Example of a commentary giving October 30, 2026. Secondary.
If the PIPC issues new guidance on the date or the clauses, this article will be updated with the revision date.
In a similar spot
Send us where things stand and we reply with the scope and the price within 24 hours.