Law / South Korea

Information and Communications Network Act, Report on Computer Security Incidents

Arts. 48-3 and 48-4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection Etc. (Act No. 20069, Jan. 23, 2024)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 10 June 2022.

A vulnerability and incident reporting rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds a provider of information and communications services, the Act's own broad term for a person who, for profit, provides information or acts as an intermediary in providing information using a telecommunications business operator's services, with no revenue or user threshold gating this particular duty; a separate certification duty in this Act binds only a designated information and communications service provider identified by revenue or user count and is not raised here.
  • Immediately report a computer security incident to the Minister of Science and ICT or to the Korea Internet and Security Agency upon discovering it; a report already made for the same incident under another statute satisfies this duty and need not be repeated.
  • Analyze the cause of the incident, respond based on the results of that analysis, and take measures to keep the resulting damage at bay.
  • Preserve, and submit on demand to the Minister of Science and ICT or the Korea Internet and Security Agency, the data needed to analyze the incident's cause; submitting false data or refusing to submit it is separately finable.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Failing to report an incident or to submit demanded data is enforced only as an administrative fine under Article 76(1); no provision reviewed here makes either failure, standing alone, a criminal offense.

Penalty structure

Shared cap for every Article 76(1) violation in its list, including failing to report a computer security incident (Art. 48-3(1)) and failing to submit, or submitting false, data demanded under Art. 48-4(5).

Rule
Fixed only
As of
12 September 2026
Currency
KRW
Fixed cap
30,000,000

Who enforces it

Enforcement body

The Minister of Science and ICT, supported by the Korea Internet and Security Agency (KISA); the Korea Communications Commission holds a parallel corrective-order power over related provisions of the same Act.

Settledness

As of
12 September 2026
Open questions
A Network Act amendment (Bill No. 14896) is reported to have been promulgated Mar. 31, 2026 and to take effect Oct. 1, 2026, expanding the Chief Information Security Officer's duties and adding an information-security-level assessment system effective Apr. 1, 2027: does it also change the Art. 48-3/48-4 incident-reporting clock or threshold?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A provider of information and communications services, a person who for profit provides information or acts as an intermediary in providing information using a telecommunications business operator's services, must immediately report a computer security incident to the Minister of Science and ICT or the Korea Internet and Security Agency (KISA) upon discovering it; a report already made for the same incident under another statute satisfies this duty.

The same class of person must then analyze the cause of the incident, respond based on that analysis, and take measures to keep the resulting damage at bay, and must preserve or submit the data the Minister or KISA demands for that analysis when ordered to. Failing to report the incident, or failing to submit the demanded data or submitting false data, is an administrative fine of up to KRW 30,000,000.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official English translation, Korea Legislation Research Institute (elaw.klri.re.kr), consolidated through Act No. 20069 (Jan. 23, 2024)
both law.go.kr's own desktop and side-panel viewers for this Act render only a JavaScript navigation shell, so this mobile-viewer full-text render is the only reachable copy of the current text

Back to the example  ·  Lint your app