Information and Communications Network Act, Report on Computer Security Incidents
Arts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection Etc. (Act No. 20069, Jan. 23, 2024)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 10 June 2022.
A vulnerability and incident reporting rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a provider of information and communications services, the Act's own broad term for a person who, for profit, provides information or acts as an intermediary in providing information using a telecommunications business operator's services, with no revenue or user threshold gating this particular duty; a separate certification duty in this Act binds only a designated information and communications service provider identified by revenue or user count and is not raised here.
- Immediately report a computer security incident to the Minister of Science and ICT or to the Korea Internet and Security Agency upon discovering it; a report already made for the same incident under another statute satisfies this duty and need not be repeated.
- Analyze the cause of the incident, respond based on the results of that analysis, and take measures to keep the resulting damage at bay.
- Preserve, and submit on demand to the Minister of Science and ICT or the Korea Internet and Security Agency, the data needed to analyze the incident's cause; submitting false data or refusing to submit it is separately finable.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Failing to report an incident or to submit demanded data is enforced only as an administrative fine under Article 76(1); no provision reviewed here makes either failure, standing alone, a criminal offense.
Penalty structure
Shared cap for every Article 76(1) violation in its list, including failing to report a computer security incident (Art. 48-3(1)) and failing to submit, or submitting false, data demanded under Art. 48-4(5).
- Rule
- Fixed only
- As of
- 12 September 2026
- Currency
- KRW
- Fixed cap
- 30,000,000
Who enforces it
Enforcement body
The Minister of Science and ICT, supported by the Korea Internet and Security Agency (KISA); the Korea Communications Commission holds a parallel corrective-order power over related provisions of the same Act.
Settledness
- As of
- 12 September 2026
- Open questions
- A Network Act amendment (Bill No. 14896) is reported to have been promulgated Mar. 31, 2026 and to take effect Oct. 1, 2026, expanding the Chief Information Security Officer's duties and adding an information-security-level assessment system effective Apr. 1, 2027: does it also change the Art. 48-3/48-4 incident-reporting clock or threshold?
What it reaches
Obligation class
Security, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A provider of information and communications services, a person who for profit provides information or acts as an intermediary in providing information using a telecommunications business operator's services, must immediately report a computer security incident to the Minister of Science and ICT or the Korea Internet and Security Agency (KISA) upon discovering it; a report already made for the same incident under another statute satisfies this duty.
The same class of person must then analyze the cause of the incident, respond based on that analysis, and take measures to keep the resulting damage at bay, and must preserve or submit the data the Minister or KISA demands for that analysis when ordered to. Failing to report the incident, or failing to submit the demanded data or submitting false data, is an administrative fine of up to KRW 30,000,000.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official English translation, Korea Legislation Research Institute (elaw.klri.re.kr), consolidated through Act No. 20069 (Jan. 23, 2024)
both law.go.kr's own desktop and side-panel viewers for this Act render only a JavaScript navigation shell, so this mobile-viewer full-text render is the only reachable copy of the current text