Law note · South Korea
Personal Information Protection Act, breach notification duties
Art. 34(1) requires a controller to notify affected data subjects without delay on becoming aware personal information has been divulged, and the Enforcement Decree sets this at within 72 hours.
Art. 34(3) separately requires reporting to the PIPC, or the Korea Internet and Security Agency, without delay for a breach above a Presidential Decree set scale, which the Decree sets at 1,000 or more affected subjects, any sensitive information or unique identification information involved, or a breach caused by illegal external access, also within 72 hours.
What it asks of an app
- An app that suffers a leak, theft, or unauthorized disclosure of Korean personal data must notify affected data subjects without delay, and must report the breach to the PIPC without delay if it affects 1,000 or more people, involves sensitive information such as a biometric identifier, or resulted from illegal external access.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics, processes_voice
Primary source: official KLRI English translation of the current consolidated PIPA text