Law note · South Korea
Personal Information Protection Act, enforcement and private civil remedy
The Personal Information Protection Commission (PIPC), Korea's independent data protection authority, enforces PIPA with investigative, corrective order, and administrative fine power, including a fine of up to 3% of a controller's total sales revenue for major violations under Art. 64-2.
Individuals separately have a private civil remedy: Art. 39 lets a court award damages up to five times actual loss where the controller acted with intention or negligence, and Art. 39-2 lets a data subject recover statutory damages up to KRW 3,000,000 for loss, theft, or divulgence without proving actual loss, with the controller bearing the burden of proving it was not negligent.
Art. 51 separately authorizes an injunction only group action by qualified consumer or civic organizations to stop an ongoing infringement, not a damages class action.
A further amendment reported as promulgated 2026-03-10 is reported to raise the Art. 64-2 fine cap toward 10% of total revenue for repeated or large scale violations and to add personal liability for a controller's chief executive, effective 2026-09-11, but no directly fetched official source for that amendment was found this session, so it is not recorded as a coded stage.
What it asks of an app
- An app processing Korean personal data must be able to answer to the PIPC for its lawful basis and safeguards, and an individual harmed by a security failure may bring a private civil claim for statutory damages, or damages up to five times the actual loss, without needing to prove the controller's negligence.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: official statute text, KLRI English translation