[Home](/)/[Resources](/resources)/Korea PIPA — Connected Devices

KoreaData Privacy

# Korea PIPA: Personal Information Protection for Connected Device Manufacturers

Korea's Personal Information Protection Act (개인정보 보호법) underwent its most sweeping reform in September 2023 — raising maximum fines to KRW 3 billion or 3% of revenue, introducing a 72-hour breach notification window, and tightening cross-border transfer rules. For connected device manufacturers collecting health, location, or usage data from Korean users, this guide covers every obligation you need to build into your product and data infrastructure.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fkorea-personal-information-protection-act)

At a glance

Regulator

PIPC (개인정보보호위원회)

Major Amendment

September 2023

Breach Notification

72 hours (≥1,000 data subjects)

Max Administrative Fine

KRW 3B or 3% of revenue

Deletion Deadline

5 business days after purpose fulfilled

## Key regulatory concepts

### PIPA Overview and the 2023 Major Amendment

Korea's Personal Information Protection Act (개인정보 보호법, PIPA) was enacted in 2011 as a unified, sector-neutral data protection statute. Its September 2023 amendment was the most significant reform since enactment, substantially harmonising PIPA with the EU's GDPR in structure and terminology while retaining distinctly Korean requirements. The Personal Information Protection Commission (개인정보보호위원회, PIPC) serves as the independent supervisory authority and has broad enforcement powers including the ability to conduct on-site investigations, issue corrective orders, and impose administrative fines. The 2023 amendment also introduced mobile-first enforcement mechanisms and expanded PIPC's authority to act on cross-border violations. For connected device manufacturers, PIPA is the primary data privacy statute that governs all personal data collected by the device — sensor readings tied to identified users, account data, location history, and usage analytics all fall within scope.

### Extraterritorial Scope and Foreign Manufacturer Obligations

PIPA applies to any personal information processor that handles personal data of Korean data subjects, regardless of where the processor is located. Foreign companies selling connected devices in Korea — even without a Korean legal entity — are subject to PIPA if their devices collect personal data from Korean users. The 2023 amendment reinforced this extraterritorial reach and introduced a domestic representative designation requirement for foreign processors meeting certain volume thresholds. The domestic representative acts as PIPC's contact point and is jointly liable for the foreign processor's PIPA compliance. For practical purposes, any foreign manufacturer with a meaningful Korean user base should assume PIPA applies and build compliance infrastructure accordingly — the PIPC's enforcement actions following the 2023 amendment have targeted foreign companies explicitly.

### Legal Bases for Data Collection

PIPA requires a lawful basis for each personal data processing activity. The primary legal bases available are: explicit consent of the data subject, necessity for performance of a contract with the data subject, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, and legitimate interests of the processor (introduced more explicitly in the 2023 amendment, bringing PIPA closer to GDPR Article 6). For connected device manufacturers, consent is the most commonly used basis for analytics, personalisation, and optional features, while contractual necessity covers core device functionality that requires an account. Sensitive data categories — health data, biometric data, and precise location — always require explicit consent regardless of whether another legal basis might otherwise be available. A separate consent collection must be made for each sensitive data type.

### Data Retention and Purpose Limitation

PIPA imposes strict purpose limitation and retention rules. Personal data may only be used for the purpose for which it was collected, and once that purpose is fulfilled the data must be deleted within five business days. This five-business-day deletion window is a distinctly Korean requirement with no direct GDPR equivalent, and it creates significant operational demands for connected device platforms that accumulate user data continuously. Data that must be retained under other Korean laws — for example, e-commerce transaction records under the Act on Consumer Protection in Electronic Commerce — may be held for the legally required retention period but must be segregated from active processing systems. Automated data lifecycle management is effectively mandatory for any platform processing significant volumes of Korean user data.

### 72-Hour Breach Notification Requirement

The 2023 amendment introduced a 72-hour breach notification requirement aligned with GDPR Article 33. When a personal data breach affects 1,000 or more data subjects, the processor must notify the PIPC within 72 hours of becoming aware of the breach. Notification must include the categories and approximate number of data subjects affected, the categories and approximate volume of personal data involved, the likely consequences of the breach, and the measures taken or proposed. Affected data subjects must also be notified without undue delay. For connected device manufacturers operating at scale, this requires a breach detection and response capability that can produce a regulatory-quality notification within three days of incident discovery — a demanding standard that requires pre-built response playbooks and clear internal escalation paths.

### Data Protection Officer (DPO) Appointment

PIPA requires the appointment of a Data Protection Officer (개인정보 보호책임자, DPO) in two situations: companies with five or more employees whose core business activity is personal information processing, or any company that routinely processes the personal data of 10,000 or more data subjects per day. For connected device manufacturers with a Korean user base at scale, the 10,000 daily data-subjects threshold is typically crossed quickly once the device has any meaningful market penetration. The DPO must be designated in writing, and their identity and contact information must be disclosed in the privacy policy published to Korean users. Unlike the GDPR, PIPA does not require the DPO to be a single individual — a team or committee structure is permissible if the responsibilities are clearly allocated.

### Cross-Border Data Transfer Mechanisms

Transferring personal data of Korean data subjects outside Korea requires one of four mechanisms under PIPA: explicit consent from each affected data subject, an adequacy decision by the PIPC designating the destination country as providing equivalent protection, standard contractual clauses (SCCs) approved by the PIPC, or certification under a cross-border privacy rules (CBPR) framework such as the APEC CBPR system. The consent mechanism is impractical at scale — each individual transfer requires fresh consent. The 2023 amendment expanded PIPC's adequacy assessment programme, but few countries have obtained decisions to date. For most connected device manufacturers transferring data to servers in the US, EU, or Singapore, PIPC-approved SCCs are the standard mechanism. PIPC published its SCC template following the 2023 amendment.

## Compliance process: step by step

01

Map every category of personal data collected by your connected device and its companion applications — this includes direct identifiers (account email, device serial number), indirect identifiers (persistent device IDs), sensor data linked to identified users (health metrics, location history, usage patterns), and any data shared with third-party SDKs embedded in your app. Mapping must be specific enough to determine the legal basis and retention period for each data type.

02

Assign a legal basis to each processing activity identified in your data map. Consent is required for analytics, advertising, and personalisation. Contractual necessity covers core device functionality. Sensitive categories — health, biometric, and precise location — require explicit consent regardless of other applicable bases. Document your legal basis determinations in a processing register that can be produced to PIPC on request.

03

Establish a data retention schedule that specifies the purpose fulfilment trigger and deletion deadline for each data category. Build automated deletion workflows to enforce the five-business-day deletion requirement once purpose is fulfilled. For data subject to legal retention obligations under other Korean statutes, implement segregation controls to separate retained data from active processing systems.

04

Assess whether your organisation meets either DPO appointment threshold: five or more employees in a personal-data-processing core business, or 10,000 or more daily data subjects. If either threshold applies, designate a DPO (개인정보 보호책임자) in writing and publish their contact information in your Korean-language privacy policy.

05

Select and implement a cross-border data transfer mechanism for all personal data flowing outside Korea. For most manufacturers, PIPC-approved standard contractual clauses (SCCs) are the appropriate mechanism for transfers to the US, EU, or other major cloud hosting regions. Execute SCC agreements with all processors and sub-processors receiving Korean personal data and retain signed copies.

06

Build a 72-hour breach notification procedure. The procedure must include: incident detection triggers, internal escalation paths, a pre-drafted PIPC notification template covering all required content fields, and a data-subject notification template in Korean. Conduct a tabletop exercise to verify the procedure can deliver a complete PIPC notification within 72 hours of incident discovery.

07

Draft or update your Korean-language privacy policy to meet PIPA disclosure requirements — including purpose of processing, legal basis for each activity, retention periods, data subject rights, cross-border transfer details, DPO contact information, and the right to lodge a complaint with the PIPC. PIPA requires the privacy policy to be disclosed in a conspicuous location accessible before data collection begins.

## Frequently asked questions

### Does Korea's PIPA apply to foreign companies selling connected devices in Korea?

Yes. PIPA applies to any personal information processor handling the personal data of Korean data subjects, regardless of where the processor is headquartered or incorporated. Foreign manufacturers selling connected devices in Korea — even without a Korean legal entity — are subject to PIPA if their devices collect personal data from Korean users. The 2023 amendment reinforced extraterritorial jurisdiction and introduced a domestic representative designation requirement for qualifying foreign processors. PIPC has actively enforced against foreign companies following the 2023 reform.

### What is the 72-hour data breach notification requirement under PIPA?

When a breach affects 1,000 or more data subjects, the processor must notify the PIPC within 72 hours of becoming aware of the incident. The notification must cover the categories and approximate number of affected data subjects, the categories and volume of personal data involved, the likely consequences of the breach, and the measures taken or proposed to address it. Affected data subjects must also be notified without undue delay. This requirement was introduced by the September 2023 PIPA amendment and mirrors GDPR Article 33 in structure.

### When is a Data Protection Officer required under Korea's PIPA?

A DPO (개인정보 보호책임자) must be appointed in two situations: first, if the organisation has five or more employees and personal information processing is a core business activity; second, if the organisation routinely processes personal data of 10,000 or more data subjects per day. For connected device manufacturers with a meaningful Korean user base, the 10,000 daily data-subjects threshold is typically reached quickly. The DPO's identity and contact details must be disclosed in the Korean-language privacy policy.

### What are the penalties for PIPA violations in Korea?

Administrative fines under the 2023 amended PIPA reach up to KRW 3 billion or 3% of domestic revenue — whichever is higher. This revenue-based cap, introduced by the 2023 amendment, significantly increased the maximum exposure for large companies. Criminal penalties for wilful violations include up to five years' imprisonment or a KRW 50 million fine. PIPC can also issue corrective orders, public naming of violators, and require independent privacy audits as part of its enforcement toolkit.

**Disclaimer:** Educational resource only. Regulatory requirements change. Consult a qualified compliance specialist before making decisions.

[

Map your product, free

Every standard, document, and test that applies — free, no account required.

Start mapping](/platform/start)

Related guides

*   [Korea KC Certification Deep DiveA deep dive into South Korea's KC mark: RRA radio certification, KTC electrical safety testing, the Conformity Registration vs Certification tracks, Korean Authorised Representative requirements, and the KC Portal application process.](/guides/korea-kc-certification-deep-dive)
*   [Japan APPI Connected ProductsJapan's APPI (Act on Protection of Personal Information) obligations for IoT and connected hardware makers: consent requirements for data collection, cross-border transfer restrictions, and 2022 amendment penalties.](/guides/japan-appi-connected-products)
*   [Canada Bill C-27 (CPPA and AIDA)Bill C-27's Consumer Privacy Protection Act and Artificial Intelligence and Data Act for IoT and connected hardware makers: consent and de-identification rules, high-impact AI system duties, and what to put in place before Royal Assent.](/guides/canada-digital-privacy-bill-c27)
*   [UK GDPR for Connected ProductsUK GDPR applies to any connected hardware product collecting or transmitting personal data about UK users.](/guides/uk-gdpr-connected-products)
*   [US State Privacy LawsUS state consumer privacy laws affecting connected electronics: CCPA/CPRA, Virginia CDPA, Colorado CPA — data minimisation, opt-out rights, and hardware product privacy-by-design obligations.](/guides/us-state-consumer-privacy-laws-electronics)