Skip to content
StartupXO Startup ideas, news, talent
Menu

Quick links

Language

Regulation & Policy

Korea Will Start Counting 72 Hours at Suspicion, Not at Confirmation

Published: 2026-09-05

Korea PIPABreach NotificationIncident ResponsePIPCEnforcement Decree

In short

From September 11, Korean law requires notice on a suspected leak and on data corrupted in place. The decree defining that trigger is still a draft.

Mr. Latte's take

For a small team the real exposure here is not the fine, it's timekeeping. Korean startups typically have no security owner separate from the founding engineer, and alerts pile up in a channel nobody acknowledges. If you cannot say who noticed the odd login and when, you cannot argue you met the deadline either way. The trigger language still being unsettled is not a reason to wait; whatever wording lands, the log of when you knew is what you will be asked for.

Data That Never Left the Building Is Now Reportable

Korea’s amended Personal Information Protection Act, Act No. 21445, was promulgated on March 10, 2026 and takes effect on September 11. The statement of reasons filed with the national law information center describes two separate expansions of the notification regime.

The first is the list of incidents. Until now a company owed notice to affected individuals when personal data was lost, stolen or leaked. From September 11 it also owes notice when data is forged, altered or corrupted. Ransomware that encrypts records and carries no copy out lands on that list when backups cannot bring them back. The draft response manual from Korea’s Personal Information Protection Commission treats a case as corruption when recovery is impossible.

The second expansion is the larger one. The duty also attaches where there is a possibility of leakage, in the cases the presidential decree specifies. That moves the starting line. The count no longer waits until you have established what went out and how much of it. It opens while you still have a suspicion and no answer.

Administrative fines were reworked alongside. The existing ceiling of 3 percent of total revenue stays where it is, and a separate 10 percent ceiling was added above it. Three grounds reach the higher one: violating the same subparagraph again before three years pass from the day a fine was imposed, harm reaching 10 million data subjects or more, and a leak or similar incident that happens because a corrective order from the commission went unheeded. The first two presuppose intent or gross negligence, and in the repeat case both the earlier violation and the later one have to carry it. The third ground comes with no such requirement, and it leaves out an incident where the processor had taken every security measure the statute requires.

Six Days Out, the Decree Is Still a Draft

The statute leaves one thing open, and it is the operative one: what a possibility of leakage actually is. The decree decides that.

The commission put its draft amendment out for public comment from June 2 to July 13. Two situations in it open the duty. In the first, you learn that an unlawful access reached a personal data processing system or a device belonging to someone who handles personal data, objective circumstances point to data having gone out, and you cannot tell whose data it was. In the second, it is objectively confirmed that personal data you process is being unlawfully traded or circulated, and the data of subjects beyond those already identified is judged highly likely to have gone out as well. The 72 hours runs from the moment you learn of the unlawful access in the first case, and from the moment you learn of the trading or circulation in the second. Where there is objectively no possibility of leakage, no notice is owed.

None of that is settled law yet. As of September 5, no amended decree carrying a September 11 effective date has appeared on the national law information center.

The commission wrote the gap into its own documents. It published the draft manual on responding to leaks and similar incidents on August 21 and took comments from August 24 to September 3. The posting carries a note that the decree written into the guidance is currently being amended, so some of the wording may change. The effective date is settled. The condition that sets the duty in motion is not yet in a final document.

If you already run a breach process built for another jurisdiction, 72 hours is the part that will look solved, and it is not the part that changed. What Korea moved is the event that opens the window, and the draft opens it on a suspicion rather than on a finding.

The 10 Percent Headline Sits Behind a Narrow Door

Most coverage of this amendment leads with 10 percent of revenue. Three grounds reach that ceiling, and every one of them is written tightly. Harm has to reach 10 million people or more, or the same subparagraph has to be violated again inside three years of a fine, or the leak has to happen because a corrective order went unmet. The first two require intent or gross negligence. The third exists only once the commission has already told you to fix something. A company with tens of thousands of users arrives there through what it did after an incident rather than through the incident.

The other duties in the draft decree are cut by size as well. A dedicated privacy officer was already required of large processors. What the draft does is lift the revenue line for that appointment from 150 billion won to 180 billion won, which narrows who owes it, and then set the reach of a new obligation to match that narrowed group: appointing, replacing or releasing that officer will take a board resolution and a report to the commission. The narrowed group is organizations with annual revenue of 180 billion won or more that also process sensitive or unique identifying information for 50,000 people or more, or personal data for 1 million people or more, together with universities enrolling 20,000 students or more, tertiary general hospitals handling sensitive information at scale, and operators of designated public systems.

ISMS-P certification splits into four groups: public system operators the commission designates, mobile carriers, identity verification agencies, and companies with prior-year revenue of 1 trillion won or more that earn 10 billion won or more from information and communications services and store data on a daily average of 30 million domestic individuals or more across the preceding three months. Financial companies under the Electronic Financial Transactions Act fall outside that last group. This one is not part of the September 11 tranche. The proviso to Article 1 of the addenda, in the statute and in the draft decree alike, sets the effective date at July 1, 2027. The deadline for obtaining the certification sits elsewhere: Article 3 of the draft decree’s addenda gives organizations that qualify until December 31, 2028.

No seed-stage team touches those numbers. The notification duty, on the other hand, has no revenue floor at all. It attaches to processing personal data. What a small company actually receives from this amendment is not a fine. It is 72 hours.

For a team outside Korea, the practical reading is narrower than the legal one. Whether a specific foreign entity falls within scope is a question for counsel, not one this amendment settles by itself. A Korean build, a launch there, or accounts that signed up from Korea are the sort of facts that question turns on. If the answer comes back yes, the part that changes on September 11 is the incident process rather than the finance line.

The First Thing They Ask For Is a Timestamp

The change in practice is easy to state. Finding signs of an intrusion used to mean investigating first, confirming what went out, then preparing notice. From September 11 the investigation and the notice preparation run side by side. Work that used to wait for the analysis to finish now starts alongside it.

Because the count opens at awareness, writing down when you became aware gets you half the way there. An admin login from an unfamiliar region, an abnormal query pattern in the server logs, a tip that accounts on your domain are changing hands elsewhere: someone has to be named as the person those reach. A team whose alert channel fills with bot messages that nobody ever acknowledges will not be able to say when it knew, and in that state it can prove neither that it met the 72 hours nor that it missed them.

Three things are worth settling before the eleventh. Which signals count as evidence of an incident. Who makes that call. And where the time of that call gets written down. The third looks like the smallest of the three, and after an incident it is the one you cannot reconstruct.

When the decree is finally promulgated, the sentences to read are already known. Whether the first situation still requires all three elements together, the unlawful access, the circumstances pointing to data having gone out, and the inability to identify whose. Whether the count still opens at the moment of awareness each situation names. And how far the exception for cases with objectively no possibility of leakage reaches. The same alert is a reportable event or an ordinary Tuesday depending on how those three land.