Song Gyeong-hee, Chairperson of the Personal Information Protection Commission, speaks at the 19th full commission meeting at Government Complex Seoul in Jongno-gu, Seoul, on the 9th. /Courtesy of Yonhap News

A system that allows punitive penalty surcharges of up to 10% of total sales to be imposed on corporations that cause repeated or serious personal information leakage incidents will take effect on the 11th. A system to reduce penalty surcharges by up to 40% for corporations that proactively invest in personal information protection will also be introduced.

The Personal Information Protection Commission said on the 10th that the amended Personal Information Protection Act, revised in March, and the amended Enforcement Decree of the Personal Information Protection Act, which specifies delegated matters, will take effect on the 11th. The reform was pursued to strengthen the responsibility of corporations and institutions for large-scale personal information leaks and to prevent related incidents in advance.

The Enforcement Decree amendment that the Personal Information Protection Commission preannounced in June further specified the criteria and procedures for imposing penalty surcharges, the criteria for reducing penalty surcharges for preemptive preventive investments, and the criteria for targets and reporting methods for requiring board resolutions and filings when designating, changing, or releasing a chief privacy officer (CPO).

First, a special penalty surcharge provision will be implemented to allow penalty surcharges of up to 10% of total sales for repetitive or serious personal information infringements.

Cases subject to punitive penalty surcharges include repeating violations within three years due to intent or gross negligence, causing large-scale harm to 10 million or more people, or causing a personal information leakage incident by failing to comply with a corrective order. The Personal Information Protection Commission prepared a procedure to calculate a baseline amount by comprehensively considering the nature, degree, and circumstances of the violation and the scale of harm to data subjects, and then to determine the imposed penalty surcharge within 10% of total sales through aggravating or mitigating factors.

Efforts to proactively invest in and strengthen protection systems for personal information protection will be reflected in the calculation of penalty surcharges. Representative factors include the scale, ratio, continuity, and growth of investments in budgets, personnel, facilities, and devices for personal information protection; the content and level of the personal information protection system, including the chief executive officer (CEO) and the CPO as well as other professionals; and additional efforts to ensure safety beyond statutory obligations. Based on these, reductions may be made within 40% of the baseline amount for imposing penalty surcharges.

Sanctions will be strengthened by raising the aggravation ratio of penalty surcharges for repeated legal violations. If an entity fails to make required reports or notifications of personal information leaks within the statutory deadline and does not take measures to prevent the spread of harm to data subjects, the penalty surcharge may be increased by up to 30%. This measure aims to eliminate the structure in which not reporting a leak incident results in fewer disadvantages.

Also, previously the surcharge was aggravated by 15% for a first violation and 30% for two or more, but going forward it will be aggravated by 20% for the first, 40% for the second, and 80% for three or more.

In addition, the reduction ratios for penalty surcharges based on personal information protection efforts such as ISMS-P certification and self-regulatory codes will be lowered from up to 50% to 30% and from up to 40% to 20%, respectively, and the reduction ratio based on protection level assessments will be adjusted from up to 30% to 15%.

Post-incident response efforts will also be reflected in reducing penalty surcharges. If an entity establishes and operates a response system in preparation for incidents and, when an incident occurs, detects it early and promptly reports or notifies it or takes measures to prevent the spread of harm, the penalty surcharge may be reduced by up to 40%.

The amended law strengthens the CPO's job authority over professional personnel management and securing budgets for personal information protection. A new obligation was established to undergo a board resolution and to report to the Personal Information Protection Commission when designating, changing, or releasing a CPO.

The Personal Information Protection Commission will operate a guidance period until Dec. 31 next year to ease the burden on target institutions due to the introduction of the new CPO system and to ensure the system's stable settlement.

A "personal information leak possibility notification system" will also be introduced to notify data subjects when a leak is objectively deemed highly likely, even before the fact of a personal information leak is finally confirmed.

Song Gyeong-hee, Chairperson of the Personal Information Protection Commission, said, "With the enforcement of the amended laws and decrees, we expect a preventive-centered personal information protection and a strengthened safety management system to be established, and for investments in personal information protection to be recognized not as an 'expense' but as a 'preemptive investment' to secure customer trust and expand corporations' profits."

※ This article has been translated by AI. Share your feedback here.