PrivacyTerrainStructured privacy law intelligence

Editorial caveat

Structured values summarize official materials for research and planning. They are reviewed by humans before publication and should not be treated as legal advice.

medium confidence, Needs more precision on recent reforms and sector overlap.

Breach

Breach deadline (hours)
24
Breach notification required
Yes

Marketing

Cookie consent rule
Tracking and behavioral advertising obligations are affected by consent, telecom rules, and regulator guidance.

Transfers

Cross-border transfer restricted
Yes
Data localization required
No

Governance

DPO required
Yes
Impact assessment required
Yes
Records of processing required
Yes

Identity

Effective date
2011-09-30
Effective status
in-force
Last amended
2023-09-15
Law status
active

Scope

Extraterritorial application
Yes
Private sector coverage
Applies broadly to personal information controllers in the private sector.
Public sector coverage
Public institutions are also subject to the core framework and related public-sector rules.
Territorial scope
Applies broadly to domestic processing and extraterritorially in some circumstances involving individuals in Korea.

Legal Basis

Legal bases
consent, statutory basis, contract necessity
Requires legal basis
Yes

Enforcement

Maximum fine
South Korea permits substantial fines and corrective orders, especially after recent reforms.
Private right of action
Yes
Regulator or enforcement authority summary
PIPC

Definitions

Personal data definition
Personal information means information relating to a living person that identifies the person.
Sensitive data recognized
Yes

Rights

Right of access
Yes
Right to appeal
Yes
Right to deletion
Yes
Right to erasure or delete summary
Deletion and destruction rights
Right to object
Yes
Right to portability
No
Right to rectification or correction summary
Correction right

Official sources

Recent change workflow