Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
Asia PacificDEEP coverage4 enforcement actions

South Korea Personal Information Protection Act (PIPA) — AI Provisions: AI Compliance Requirements

South Korea's PIPA (Personal Information Protection Act) is one of Asia's most comprehensive privacy laws, significantly strengthened by 2023 amendments effective March 2024. Enforced by the Personal Information Protection Commission (PIPC), it applies to any organization processing personal data of South Korean residents. Article 37-2 (2023) adds automated decision-making rights for Korean data subjects. PIPC fine authority expanded to KRW 3 billion or 3% of global revenue.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

September 30, 2011

Enforcement Begins

March 15, 2024

Maximum Penalty

KRW 3,000,000,000 (₩3 Billion / ~$2.2M USD) OR 3% of global revenue, whichever is higher (current, through 2026-09-10). From 2026-09-11, a PIPA amendment raises the ceiling to 10% of total turnover for repeated/serious violations (intentional or grossly-negligent repeat breaches within 3 years; damage affecting 10M+ people; non-compliance with corrective orders) — nearly 3.3x the current cap. Criminal sanctions: up to 5 years imprisonment.

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Lawful Basis and Minimal Data Collection

Critical

PIPA Article 15 requires a lawful basis for all personal information processing: consent, contract, legal obligation, vital interests, public interest, or legitimate interest (added in 2023 amendments). AI systems must document their lawful basis and apply data minimization.

PIPA Art. 15

Automated Decision-Making Rights (PIPA Art. 37-2)

Critical

PIPA Article 37-2 (2023 amendment) grants data subjects the right to request human review of automated decisions that significantly affect them (credit, hiring, insurance, etc.). Organizations must notify individuals when a decision is fully automated and provide a mechanism to request explanation and human review within 30 days.

PIPA Art. 37-2

Personal Information Processing Policy — AI Disclosure

High Priority

PIPA Articles 30-31 require a comprehensive Personal Information Processing Policy (privacy notice). AI processing activities must be explicitly described: what personal data is processed, for what AI purpose, with what legal basis, and how automated decisions are made.

PIPA Art. 30-31

Cross-Border Transfer of Korean Personal Data for AI

High Priority

Transfer of Korean personal information outside Korea for AI processing requires: (1) consent from the data subject; or (2) standard contractual clauses approved by PIPC; or (3) adequacy decision. PIPC has not issued adequacy decisions for most countries — standard contracts are the primary mechanism for Korean data processed by overseas AI APIs.

PIPA Art. 28-8 to 28-11

Who Does This Apply To?

Extraterritorial reach: applies to any organization processing personal information of South Korean residents, regardless of where the organization is located. Korean residents are persons physically located in Korea, not just Korean nationals. AI-specific: PIPA Art. 37-2 (2023 amendment, effective March 2024) requires notification and human review rights for fully automated significant decisions. Foreign companies processing Korean personal data via AI must comply with Art. 37-2 and designate a domestic representative. R{cycle6} (web-verified 2026-08-22): a further PIPA amendment takes effect 2026-09-11, designating the CEO as the "ultimate responsible person" for data processing/protection, raising the maximum fine to 10% of total turnover for repeated/serious violations, strengthening the CPO/DPO role, and changing breach-notification triggers to the "possibility of breach." A separate ISMS-P certification requirement for major controllers takes effect 2027-07-01.

Recent Enforcement Actions

PIPC2024-11-04KRW 21,623,200,000 (≈$15.67M USD)Source verified· as of 2026-08-22

Against: Meta Platforms (Facebook/Instagram Korea)

PIPC fined Meta ₩21.6232B for: (1) unlawfully collecting sensitive personal information (political/religious views, same-sex marital status) from ~980,000 Korean users and using it, alongside behavioral data (Facebook likes, ad clicks), to create advertising "topics" tied to sensitive categories, without adequate consent (Meta's broad privacy-policy language was found insufficient); (2) sharing this data with ~4,000 advertisers for targeted ads (including on religious affiliation, gender identity, North-Korean-defector status) without adequate disclosure. R{cycle6}: penalty figure corrected from a rounded "≈$16M" to the precise KRW/USD figures verified this cycle (multiple converging sources). Established that behavioral advertising AI using sensitive categories requires explicit opt-in consent.

Source
PIPC2021-04-28KRW 103,300,000 (~$92,900 USD)Source verified· as of 2026-08-22

Against: ScatterLab, Inc. (Iruda chatbot)

The FIRST case where PIPA was applied to an AI system. PIPC found ScatterLab violated PIPA by using ~9.4 billion KakaoTalk messages from 600,000 users to train its "Iruda" AI chatbot without valid consent (a generic "New Service Development" clause in its terms of service was insufficient for users to anticipate this use). ScatterLab also failed to delete/encrypt personal information (names, phone numbers, addresses), posted AI models on GitHub containing 1,431 messages with identifiable user information (violating pseudonymization requirements), and collected data from 200,000+ children under 14 without parental consent. ScatterLab agreed to implement PIPC's corrective actions. This is the foundational Korean precedent for AI training-data consent requirements — squarely on point for this registry's audience and previously entirely absent.

Source
PIPC2025-01-24KRW 8,370,000,000 total (~$5.7-5.8M USD) — Kakao Pay KRW 5.968B, Apple Distribution International KRW 2.45B + KRW 2.2M — PLUS an order to DESTROY the AI model built from the unlawfully transferred data.Source verified· as of 2026-08-22

Against: Kakao Pay Corp. + Apple Distribution International Limited (data transferred to Alipay, an Alibaba affiliate)

Between April-July 2018, Kakao Pay transferred Korean users' personal data (24 categories — phone numbers, email addresses, account balances, and more) to Alipay (an Alibaba affiliate) without proper consent, covering all Kakao Pay users even though only ~20% had registered Apple Pay, to calculate "NSF" (Non-Sufficient Funds) risk scores as part of Apple Pay's payment-evaluation process — affecting ~40 million users. PIPC's most significant remedy: it ordered Alipay to DESTROY the NSF-scoring AI model itself, trained on the unlawfully transferred data — not merely a fine, but deletion of the AI asset built from the violation. This is a directly on-point precedent for this registry's audience: an AI model itself can be ordered destroyed as a PIPA remedy, not just penalized with a fine.

Source
PIPC2022-09-14Google: KRW 69,200,000,000 (≈$50M USD). Meta: KRW 30,800,000,000 (≈$22M USD). Combined ≈KRW 100 billion (≈$72M USD).Source verified· as of 2026-08-22

Against: Google LLC + Meta Platforms, Inc.

PIPC's first-ever investigation into behavioral-data collection and use by online advertising platforms, and (at the time) the largest PIPA penalty ever imposed. Google was fined for a 6-year failure to clearly inform users at sign-up that it would collect and use behavioral data for targeted advertising. Meta was fined for a 4-year failure to display mandatory consent-notification information in an easily viewable manner and for not obtaining actual user consent to collect/use behavioral data during Facebook/Instagram sign-up. Directly relevant precedent for AI-driven ad-personalization/profiling systems processing Korean users' behavioral data.

Source

Recent Regulatory Guidance

guidance2024-03-15

PIPC Guidance on PIPA 2023 Amendments — Automated Decision-Making

PIPC published implementation guidance for Art. 37-2 automated decision-making rights: (1) "significant effect" includes employment decisions, credit scoring, insurance underwriting, and access to public services; (2) "fully automated" requires no meaningful human involvement — AI-assisted decisions with genuine human review are excluded; (3) organizations must respond to human review requests within 30 days with: the specific data used, how the decision was made, and ability to challenge the decision; (4) AI decision logs must be retained for at least 3 years for PIPC inspection.

Source
guidance2026

PIPA amendment (effective 2026-09-11) — 10% turnover fine ceiling, CEO liability

A PIPA amendment effective 2026-09-11 raises the maximum administrative fine from 3% to 10% of total turnover for repeated/serious violations, designates the CEO the "ultimate responsible person" for personal data processing/protection, strengthens the CPO/DPO role (budget authority, board reporting), and changes breach-notification triggers to the "possibility of breach." A separate ISMS-P certification requirement for major controllers takes effect 2027-07-01.

Source
guidance2025-08-06

PIPC generative AI guidelines — personal-information processing for AI development/use

PIPC released generative AI guidelines covering personal-information handling across the AI development and deployment lifecycle, described by commentators as positioning Korea as a leader in AI-specific privacy governance. Separately, on 2026-03-04, the PIPC issued recommendations following direct discussions with generative AI companies on improving their personal-information handling policies. As of this cycle (2026-08-22), South Korea is also working on new special statutory provisions that would let lawfully-collected personal data be used for AI development on a case-by-case PIPC resolution basis — not yet enacted, a monitoring item rather than current law.

Source

Key Case Law & Precedent

PIPC v. Meta Platforms

PIPC Administrative Decision · 2024

A leading PIPA enforcement action (not the largest — see the 2022 Google+Meta ₩100B combined action in enforcementActions, which predates and exceeds it). Meta fined ₩21.6232B for using Korean users' sensitive personal data in behavioral AI advertising without adequate consent. Established that PIPA sensitive category data (political views, religion, health status inferred from AI behavioral analysis) requires explicit opt-in consent separate from general terms of service. Any AI system inferring sensitive categories from behavioral data of Korean users must obtain explicit consent.

Outcome: ₩21.6B fine. Meta required to implement consent management overhaul for Korean users.

Case reference

Quarterly Enforcement Digest

Q1 2026: PIPA fully enforced. R{cycle6} CORRECTION: the Meta ₩21.6B fine (September 2024) is a leading benchmark for AI behavioral-advertising violations specifically involving sensitive-category data — but is NOT the largest PIPA penalty on record; the 2022 Google (₩69.2B) + Meta (₩30.8B) combined ₩100B action, added to this entry this cycle, remains larger. Art. 37-2 automated decision rights effective since March 2024 — organizations should have AI decision logging and human review mechanisms operational. PIPC announced 2026 enforcement focus on cross-border AI data transfers: companies sending Korean user data to overseas AI APIs must ensure PIPC-approved standard contractual clauses are in place. Combined with AI Basic Act obligations (effective January 22, 2026), Korea now has dual-track AI compliance requirements. NEW this cycle: a PIPA amendment effective 2026-09-11 raises the maximum fine to 10% of total turnover for repeated/serious violations and designates the CEO as the "ultimate responsible person" — see deadlineCalendar and maxPenalty.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering South Korea Personal Information Protection Act (PIPA) — AI Provisions

These industry playbooks include jurisdiction-specific checklist items and guidance for South Korea Personal Information Protection Act (PIPA) — AI Provisions.

Frequently Asked Questions

Does South Korea Personal Information Protection Act (PIPA) — AI Provisions apply to my business?

South Korea's PIPA (Personal Information Protection Act) is one of Asia's most comprehensive privacy laws, significantly strengthened by 2023 amendments effective March 2024. Enforced by the Personal Information Protection Commission (PIPC), it… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under South Korea Personal Information Protection Act (PIPA) — AI Provisions is: KRW 3,000,000,000 (₩3 Billion / ~$2.2M USD) OR 3% of global revenue, whichever is higher (current, through 2026-09-10). From 2026-09-11, a PIPA amendment raises the ceiling to 10% of total turnover for repeated/serious violations (intentional or grossly-negligent repeat breaches within 3 years; damage affecting 10M+ people; non-compliance with corrective orders) — nearly 3.3x the current cap. Criminal sanctions: up to 5 years imprisonment.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with South Korea Personal Information Protection Act (PIPA) — AI Provisions?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.pipc.go.kr/eng/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan