This website uses cookies

Read our Privacy policy and Terms of use for more information.

Korea's CEO-Liability Privacy Law Takes Effect in 17 Days

South Korea's amended Personal Information Protection Act takes legal effect on 11 September 2026 — raising fines to up to 10% of turnover and making CEOs personally liable for systemic privacy failures.

Why It Matters

South Korea's amended Personal Information Protection Act (PIPA), signed 10 March 2026, takes effect on 11 September 2026 — 17 days from now. Three changes reset the risk calculus: the maximum administrative fine rises to up to 10% of total turnover for serious violations, personal supervisory liability now attaches to the CEO for systemic compliance failures, and breach notification must happen "without delay" once a company becomes aware of even the possibility of a breach. For any organization handling Korean residents' data, privacy has moved from a delegated function to a board-level duty.

The same week, regulators elsewhere pushed disclosure and accountability further. The FTC opened a comment window on a proposed enforcement policy statement warning that undisclosed personalized pricing may violate Section 5. The EDPB put draft guidelines on anonymisation and generative-AI web scraping out for consultation until 30 October. And California kept up its data-broker enforcement cadence under the Delete Act, with the DROP deletion platform now live.

The throughline: accountability is moving up to the board, and "we anonymised it" or "we didn't disclose it" are getting harder to defend across jurisdictions.

Action Items

  1. Brief the CEO and board on PIPA personal liability — before 11 September, and document the privacy-governance accountability chain.

  2. Re-test breach-notification runbooks — against the new "possibility of a breach → notify without delay" trigger.

  3. Review personalized-pricing disclosures — if you set prices using behavioral data, assess Section 5 adequacy before the FTC comment window closes.

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Default to read the rest.

Become a paying subscriber of Default to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you: