Skip to content
StartupXO Startup ideas, news, talent

Regulation & Policy

The 72-Hour Breach Clock Starts Before You Know What Leaked

Published: 2026-09-22

Korea PIPABreach NotificationIncident Response72 HoursSecurity Operations

The Problem

Since September 11, 2026, Korean law requires notice to data subjects within 72 hours of learning that personal data may have leaked, and a team whose alerts pile up unacknowledged in a channel cannot even say when it knew.

Why Now

The amended Personal Information Protection Act and its enforcement decree (Presidential Decree No. 36671, amended on September 10, 2026) took effect on September 11, and the notice duty has no revenue threshold.

Recommended Talent

A security engineer who has run incident response and has stitched alert logs, access records and on-call handoffs into a single timeline

From September 11, 2026, Korean law requires notice to data subjects within 72 hours even when a leak is only possible [1]. The clock starts when you learn of the possibility, not when you confirm what left. For a team with no separate security owner, the first wall is not the penalty math but one question: when did you know? This idea is a lightweight incident desk that records the answer from the first hour of suspicion.

The clock starts at awareness, not confirmation

The amended Personal Information Protection Act widened notification in two directions. Beyond loss, theft and leaks, forgery, alteration and destruction must now be reported too, and the notice duty applies at the possibility stage, before a leak is confirmed [1]. The enforcement decree that sets the criteria was amended on September 10, 2026 and took effect on September 11 [2].

The draft decree listed two conditions that start the duty. One is learning of unlawful access to a processing system or a handler's device, with objective signs that personal data left but no way yet to identify whose. The other is confirming that the personal data you process is being traded or circulated unlawfully, with a high likelihood that data of other data subjects also left. In each case the 72 hours run from the moment you learned of the access or the trading [3].

Where small teams actually get stuck

The notice duty has no revenue threshold. If you process personal data, it applies. The threshold for appointing a dedicated privacy officer, by contrast, is annual revenue of 180 billion won under the draft decree [3]. Seed-stage teams never reach it, so the security owner is usually the engineer who built the product.

In teams like that, an unfamiliar admin login, an abnormal query in server logs or a tip that your accounts are being sold elsewhere just pile up in an alert channel. If nobody records who saw the signal and when it was judged an incident, the team cannot prove even to itself whether it met the 72 hours.

What to build

A one-page desk you open the moment an incident is suspected. Four functions are enough.

  • Record when suspicion first arose: one line on who saw which signal and when it was judged a possible incident, with the timestamp fixed.
  • Preserve the first evidence: attach the log excerpt, the original alert and screenshots from that moment, and lock them against later edits.
  • Assign the next check: who verifies what by when, with the time left in the 72 hours shown beside it.
  • Export a regulator-ready timeline: one document with awareness, judgment, action and notice times in order.

It is for startups without a privacy officer. It does not replace an alerting tool or a SIEM; it only keeps the time and the grounds for the alerts a team has judged to be incidents.

What to check first

Open the final decree and check whether the draft's two trigger conditions and starting points survived as written. The breach-response manual draft the Personal Information Protection Commission published on August 21 carried a caveat that the decree wording could change [4]. Match the criteria the desk displays to the final articles and the confirmed manual.

References

[1] Korea Policy Briefing (korea.kr), "개인정보 유출 가능성, 이제 통지합니다" (Possible data leaks now require notice), 2026-09-18 (in Korean). https://www.korea.kr/news/policyNewsView.do?newsId=148972151

[2] Korea Law Information Center, Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 36671, amended 2026-09-10), in force from 2026-09-11 (in Korean). https://www.law.go.kr/LSW/lsInfoP.do?lsId=011468

[3] Ministry of Government Legislation, Pre-announcement of the amended Enforcement Decree of the Personal Information Protection Act (PIPC Notice No. 2026-59) (in Korean). https://www.moleg.go.kr/lawinfo/makingInfo.mo?lawSeq=86980&lawCd=0&lawType=TYPE5&mid=a10104010000

[4] Personal Information Protection Commission (PIPC), Draft breach-response manual published for comment (in Korean). https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS061&mCode=C010010000&nttId=12399