South Korea
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in South Korea — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of South Korea, but only on one of five grounds. Most companies use consent. The person has to tick a separate box just for the transfer. Since September 2025 you can send data to 30 European countries with no extra paperwork. Some industries are closed no matter what consent you get. That covers banking, health records, government cloud and detailed maps. The regulator fines foreign companies often.
Data governance in South Korea
The eight things that decide how you handle data about people in South Korea. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore. They collected Korean users' data and sent it abroad without a proper legal basis. You must also appoint a representative in Korea if you pass either size test. Test one: worldwide revenue of 1 trillion won (about $720 million) or more last year. Test two: data on an average of 1 million or more people in Korea per day, over the last three months of last year. Since April 2026 there is an extra step. If you already own or control a Korean company, that company has to be the representative.
- What you have to do here:
- Appoint a representative
The Personal Information Protection Act does not say in words that it applies to companies outside Korea. The Commission applies it anyway to overseas companies that use data about people in Korea. The rule on appointing a Korean representative (Article 31-2) assumes foreign companies are covered. The Network Act is explicit. It applies to acts done outside Korea that affect the Korean market or Korean users. The Enforcement Decree sets two size tests. Total revenue of 1 trillion won. Or a daily average of 1 million people in Korea over the last three months of the previous year. There is also a third route. The Commission can decide that a company it has asked for documents needs a representative. An amendment of 1 April 2025 took effect on 2 October 2025. If you have set up a Korean company, or you control one, that company must be your representative. You control a company if you appoint its chief executive. You also control it if you appoint half or more of its directors, or hold 30 percent or more of its shares. Companies that already had a representative had six months to re-appoint, so until 2 April 2026. You must train your representative at least once a year. You must also check that it is doing its job. Getting the appointment or the supervision wrong costs up to 20 million won (about $14,000). Leaving the representative's details out of your privacy policy costs up to 10 million won (about $7,200).
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Act No. 20897, Article 31-2 (designation of domestic representative), in force 2 October 2025
law.go.kr
“국내에 주소 또는 영업소가 없는 개인정보처리자로서 매출액, 개인정보의 보유 규모 등을 고려하여 대통령령으로 정하는 자는 다음 각 호의 사항을 대리하는 자(이하 "국내대리인"이라 한다)를 지정하여야 한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationEnforcement Decree of the Personal Information Protection Act, Article 32-3 (who must appoint a domestic representative)
law.go.kr
“1. 전년도(법인인 경우에는 전 사업연도를 말한다) 전체 매출액이 1조원 이상인 자 2. 전년도 말 기준 직전 3개월 간 그 개인정보가 저장ㆍ관리되고 있는 국내 정보주체의 수가 일일평균 100만명 이상인 자”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionCommission sanctions TikTok and Apple for collecting and using personal data without a lawful basis, 23 July 2026
pipc.go.kr
Link checked 18 August 2026
Where the data is allowed to live
Yes, but you need one of five grounds. Most companies use consent. The person must tick a separate box just for the transfer. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein. That takes no extra step. The regulator has formally accepted that their protection matches Korea's. No other country is on that list. Six industries override all of this. They are covered below.
- Ways to send data out:
- Official 'this country is safe' decision · Certification scheme · Explicit consent · Needed for a contract
The starting point is a ban. You must not send personal data out of Korea, let anyone abroad view it, hand it to a supplier abroad, or store it abroad. Five things let you do it anyway. One: the person gives a separate consent for the transfer. Two: a Korean law or a treaty allows it. Three: you need to send or store the data abroad to sign or carry out a contract with that person. For this one you must either put the details in your privacy policy or tell the person by email or a similar route. Four: the recipient holds a certification that the Commission has designated, and has put the promised protections and rights in place in the destination country. Five: the Commission has recognised the destination country or international body as giving protection close to Korea's. Route five has been used once, in September 2025, for the European Union and the European Economic Area. That is 30 countries. Route four exists on paper. We found no evidence that any certification has been granted for it. If your recipient passes the data on to a third country, the same rules apply again. Six industries override all of this, each with its own rating. BANKING AND PAYMENTS: closed. A financial company or electronic payment business with its head office in Korea must keep its computer room and its disaster recovery centre in Korea. If it uses national ID numbers or personal credit information on a cloud service, that system must be in Korea too. Individual customers' national ID numbers may not go abroad at all. HEALTH: closed. Electronic medical record systems and their backup equipment must sit inside Korea. GOVERNMENT AND PUBLIC SECTOR: closed. The cloud systems, the backups, the data and the staff who manage and run them must all be in Korea. MAPPING AND GEOSPATIAL: decided case by case, and closed by default. Nobody may take basic survey results, maps or survey photographs out of Korea without the Minister's permission. Security-sensitive results need a decision from a committee of several agencies, including the intelligence service and the defence ministry. LOCATION SERVICES: allowed with conditions, and you need a Korean company. A business handling personal location data must be a corporation and must register with the media and communications regulator. TELECOMS AND ADVANCED TECHNOLOGY: allowed with conditions, but the government holds an unused power. It can order measures to stop nationally important security and advanced technology information leaving Korea over networks. We found no evidence it has ever done so.
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Article 28-8 (transfer of personal data abroad)
law.go.kr
“개인정보처리자는 개인정보를 국외로 제공(조회되는 경우를 포함한다)ㆍ처리위탁ㆍ보관(이하 이 절에서 "이전"이라 한다)하여서는 아니 된다. 다만, 다음 각 호의 어느 하나에 해당하는 경우에는 개인정보를 국외로 이전할 수 있다.”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionStatus of equivalence recognitions granted by Korea
pipc.go.kr
“한국이 동등성 인정을 한 국가ㆍ국제기구 유럽연합 및 유럽경제지역('25.9월)”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationRegulation on Supervision of Electronic Financial Transactions, FSC Notice No. 2026-29, Articles 11 and 14-2, in force 15 July 2026
law.go.kr
“국내에 본점을 둔 금융회사 또는 전자금융업자의 전산실 및 재해복구센터는 국내에 설치할 것”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationAct on the Establishment and Management of Spatial Data, Article 16 (prohibition on taking basic survey results abroad)
law.go.kr
“누구든지 국토교통부장관의 허가 없이 기본측량성과 중 지도등 또는 측량용 사진을 국외로 반출하여서는 아니 된다.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Korea does not check where you send data. It checks your paperwork. There is no list of banned countries and no application to file. You pick one of the five grounds. For most companies that means asking each person for a separate transfer consent. That consent must say what data goes, where, to whom, for how long, and how to refuse. One country list exists, and it is a positive one. It holds 30 countries: the European Union plus Norway, Iceland and Liechtenstein. If you send data anywhere else, you must also keep security measures, a complaints route and a dispute process in place. You must write the transfer into your contract with the recipient.
- What you have to do here:
- Put a transfer safeguard in place · Written vendor contract
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent
The model is a ban with exceptions. Korea does not keep a list of banned countries. It does not limit you to a list of approved ones either. It does keep one positive list, recognised in September 2025: the European Union and the European Economic Area. Being on that list removes the paperwork. It is not something you need before you send data. For every transfer under the exceptions, the Enforcement Decree requires three things. Security measures. A route for complaints and for settling disputes. And prior agreement with the recipient, written into your contract. The Decree also sets out what a country must show before Korea recognises it. Sound protection principles. An independent regulator. Lawful government access to data. Real redress for people. And a willingness to work with the Commission. An expert committee on cross-border transfers must assess the country. A policy council must be consulted. Only then can the Commission recognise it. The Commission can attach limits to a recognition. It must keep watching the country afterwards. It can withdraw or change the recognition. Two powers over destinations sit unused. First, Korea can mirror another country's restrictions back onto that country's companies if that country restricts transfers to Korea. We found no evidence this has been applied. Second, the government can order measures to stop nationally important information leaving over networks. Again, we found no evidence of use.
Sources
- Official sourcePersonal Information Protection CommissionCross-border transfer regime: the five grounds and the safeguards required
pipc.go.kr
“국외이전 요건 (개인정보 보호법 제28조의8) 1) 정보주체 별도 동의 2) 법률, 조약 또는 국제협정상 특별한 규정 3) 정보주체와의 계약 체결/이행을 위하여 필요한 처리위탁/보관 4) 개인정보위가 고시한 인증 5) 국가/국제기구 보호수준에 대한 동등성 인정”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationEnforcement Decree of the Personal Information Protection Act, Articles 29-9 and 29-10 (equivalence recognition; protective measures on transfer)
law.go.kr
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Articles 28-10 (reciprocity) and 28-11 (onward transfers)
law.go.kr
“개인정보의 국외 이전을 제한하는 국가의 개인정보처리자에 대해서는 해당 국가의 수준에 상응하는 제한을 할 수 있다.”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Personal Information Protection Commission enforces the law. Song Kyoung-hee chairs it. It is one of the busiest privacy regulators in the world right now. In July 2026 it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach. It fined TikTok about 10.3 billion won (roughly $7.4 million). It fined Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation. It asked police to investigate LG U+ for destroying a server before the inquiry started. Other regulators cover other industries. Finance goes to the Financial Services Commission and the Financial Supervisory Service. Health goes to the health ministry. Maps go to a committee of several agencies that includes the intelligence service.
- What it costs if you get it wrong:
- Percentage of global turnover · Criminal liability · Order to stop
Rating: aggressive. The evidence comes from the regulator's own July 2026 press releases. At its 22 July 2026 meeting it fined TikTok Pte. Ltd. 10.306 billion won. TikTok had collected behavioural data on 9.45 million active Korean users through its Pixel and software development kit tools. Those tools sat on about 71,000 Korean businesses. It had no valid legal basis, and it sent the data abroad in breach of the transfer rule. The same meeting fined Apple Distribution International and Apple Services Pte. Ltd. 252 million won over Siri voice recordings and transcripts. Apple's privacy policy did not properly explain the transfer to Apple Inc. in the United States. At its 29 July 2026 meeting it fined KT 53.979 billion won for failing its security duties. Hackers used cloned femtocells to intercept data on 16,647 subscribers. That led to about 240 million won of fraudulent small payments. The Commission ordered KT to fix the problems within three months. It recommended that the affected network get the national information security and privacy certification, known as ISMS-P. It also resolved to file a criminal complaint against KT for deleting logs and handing over false material during the investigation. The Commission runs a review service you can use before you launch something new. It runs a dispute mediation committee too. It is fully staffed and issuing decisions. By late July 2026 its full meetings for the year were numbered in the teens.
Sources
- Official sourcePersonal Information Protection CommissionCommission resolves sanctions over KT's personal data breach, 30 July 2026
pipc.go.kr
“㈜KT(이하 'KT')에 대해 과징금 539억 7,900만 원을 부과하고, 시정명령, 개선권고, 공표, 공표명령하고, 조사과정에서 거짓자료 제출 등으로 조사를 방해한 행위에 대해 고발을 의결하였다.”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionCommission sanctions TikTok and Apple, 23 July 2026
pipc.go.kr
“틱톡의 법적 근거 없는 타사 행태정보 수집ㆍ이용과 국외 이전이 각각 보호법 제15조(개인정보의 수집ㆍ이용)제1항 및 제28조의8(개인정보의 국외 이전)제1항 위반에 해당한다고 보아, 과징금 103억 600만 원과 함께 시정명령 및 공표명령을 부과하기로 결정했다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Article 64-2 (administrative fines up to 3 percent of total revenue)
law.go.kr
“해당 개인정보처리자에게 전체 매출액의 100분의 3을 초과하지 아니하는 범위에서 과징금을 부과할 수 있다.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Two rules pull in opposite directions. First, you must destroy personal data as soon as you no longer need it. You must destroy it so it cannot be recovered. Second, other laws make you keep some records. An online seller must keep advertising records for 6 months. Complaint and dispute records: 3 years. Contract, cancellation, payment and delivery records: 5 years. Almost everyone must keep system access logs for at least 1 year. That becomes 2 years if the system holds data on 50,000 or more people. It is also 2 years if the system holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two rules clash, the keeping rule wins. You must then store that data separately from everything else.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs
The ceiling. The Personal Information Protection Act tells you to destroy personal data without delay in three cases. The retention period has run out. You have done what you collected it for. Or the time allowed for using pseudonymised data has run out. The exception is where another law makes you keep it. Data kept under that exception must be stored and managed apart from your other personal data. Failing to destroy data costs up to 30 million won (about $22,000). The floors. The consumer protection rules for online selling set the record-keeping periods. Display and advertising records: 6 months. Contract and cancellation records: 5 years. Payment and delivery records: 5 years. Consumer complaints and disputes: 3 years. The access-log periods come from the Commission's safety standards, Notice No. 2026-9, in force 1 July 2026. Some industries must keep records longer. Financial and medical record-keeping runs longer, and the medical rules also fix where the records may sit.
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Article 21 (destruction of personal data)
law.go.kr
“개인정보처리자는 보유기간의 경과, 개인정보의 처리 목적 달성, 가명정보의 처리 기간 경과 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 그 개인정보를 파기하여야 한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationEnforcement Decree of the Act on Consumer Protection in Electronic Commerce, Article 6 (transaction records a business must preserve)
law.go.kr
“1. 표시ㆍ광고에 관한 기록: 6개월 2. 계약 또는 청약철회 등에 관한 기록: 5년 3. 대금결제 및 재화등의 공급에 관한 기록: 5년 4. 소비자의 불만 또는 분쟁처리에 관한 기록: 3년”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationStandards for Securing the Safety of Personal Data, PIPC Notice No. 2026-9, Article 8 (access log retention), in force 1 July 2026
law.go.kr
“개인정보처리자는 개인정보처리시스템에 접속한 자(다만, 정보주체는 제외한다)의 접속기록을 1년 이상 보관ㆍ관리하여야 한다.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count two clocks. In telecoms and finance, count a third. Under the privacy law you have 72 hours to tell the people affected. You have a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. Three things start that reporting clock. If 1,000 or more people are affected. If any sensitive data or national ID numbers leaked. Or if someone broke in from outside. An internet service provider must also report a cyber attack to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
You have 72 hours to tell the people affected. You can delay only in two cases. You need the time to contain the attack. Or a disaster makes it impossible. You have a separate 72 hours to report to the Commission or the Korea Internet and Security Agency. Three things start that clock. 1,000 or more people affected. A leak of sensitive data or national ID numbers. Or a leak caused by someone getting into your system, or into a staff device, without permission. If you do not yet know the cause or the size, file what you have. Add the rest as soon as you confirm it. The duty to report can fall away if you find the leak route and recover or delete the data, so the risk drops sharply. Third clock: an internet or communications service provider must report a break-in immediately. It goes to the Minister of Science and Information and Communications Technology, or to the Korea Internet and Security Agency. The exact timing is set by decree. A report already made under another law counts. Fourth clock, health only: a hospital must tell the Minister of Health and Welfare about a break-in involving treatment information. The overlap is where companies go wrong. One event usually starts the privacy clock and an industry clock at the same time. The KT case shows the cost of getting reporting wrong. The Commission filed a criminal complaint over deleted logs and false submissions.
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationEnforcement Decree of the Personal Information Protection Act, Articles 39 and 40 (72-hour notice and 72-hour report)
law.go.kr
“개인정보처리자는 다음 각 호의 어느 하나에 해당하는 경우로서 개인정보가 유출등이 되었음을 알게 되었을 때에는 72시간 이내에 ... 신고해야 한다. 1. 1천명 이상의 정보주체에 관한 개인정보가 유출등이 된 경우”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationAct on Promotion of Information and Communications Network Utilisation and Information Protection, Article 48-3 (reporting intrusion incidents)
law.go.kr
“정보통신서비스 제공자는 침해사고가 발생하면 즉시 그 사실을 과학기술정보통신부장관이나 한국인터넷진흥원에 신고하여야 한다.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that will cost you a weekend. One: the age line for children is 14, not 13 or 16. Using an under-14's data without a parent's consent is a crime. It carries up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime. The regulator used that power in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all. And if a supplier abroad handles customers' financial transaction data, you must report it to the supervisor 30 business days before the work starts. Five: to run a personal location service you must be a corporation and be registered. So you cannot serve Korea from abroad with no Korean entity.
- What you have to do here:
- Get a parent's consent for children · Register or notify
- What it costs if you get it wrong:
- Criminal liability
1. The age line is 14. Using a younger child's data without the legal guardian's consent can bring up to 5 years in prison. It can also bring a fine of up to 50 million won (about $36,000). It can also bring the administrative fine of up to 3 percent of revenue. 2. It is a crime to refuse to hand over material, or to hand over false material, to hide a breach. It is also a crime to hide, destroy or fake material during an inspection. Either one costs up to 2 years in prison or 20 million won (about $14,000). The Commission filed a criminal complaint against KT on this basis in July 2026. It also asked police to investigate LG U+ for scrapping a server. 3. Pseudonymised data still counts as personal data when you send it abroad. The Commission itself flagged this in August 2026 as a barrier to international joint research. You need consent to send pseudonymised data abroad. But you can no longer tell who the people are, so you cannot ask them. 4. Under the Regulation on Outsourcing of Data Processing by Financial Companies, individual customers' unique government ID numbers must be encrypted. They must not be sent abroad. If your supplier is abroad, a report must reach the Governor of the Financial Supervisory Service 30 business days before that supplier starts work. 5. A personal location information business must be a corporation and must register with the regulator. The same law changed on 1 October 2025 to move that job to the renamed Broadcasting, Media and Communications Commission. 6. One more trap. The administrative fine starts from your total revenue, not from the revenue linked to the breach. Unrelated revenue is taken off afterwards. If you refuse to hand over your revenue figures, the Commission can estimate them.
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Articles 22-2, 71 and 73 (children under 14; criminal penalties; obstruction of inspection)
law.go.kr
“제22조의2제1항을 위반하여 법정대리인의 동의를 받지 아니하고 만 14세 미만인 아동의 개인정보를 처리한 자 ... 5년 이하의 징역 또는 5천만원 이하의 벌금에 처한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationRegulation on Outsourcing of Data Processing Business by Financial Companies, Articles 5 and 7
law.go.kr
“개인고객의 고유식별정보는 암호화 등의 보호 조치를 하여야 하며, 특히 국외로 이전되지 않도록 하여야 한다.”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionCommission opens public consultation on privacy rules for the artificial intelligence era, 5 August 2026
pipc.go.kr
“해외 연구기관과 공동연구 진행 시 국외이전에 대해서 정보주체의 동의를 받아야 하는데, 이미 개인을 식별할 수 없는 상황에서 재동의를 받는 것이 현실적으로 어려우므로 국제 공동연구에 제한이 발생한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationAct on the Protection and Use of Location Information, Article 5 (registration of personal location information businesses)
law.go.kr
Link checked 18 August 2026
What's changing next
The privacy regulator has started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026. It ran a public suggestion window from 6 to 31 August 2026. It plans to publish the direction of reform before the end of 2026. Consent-based rules are on the table. So is the block on sending pseudonymised data abroad for research. Separately, Apple's request to export detailed Korean map data is still pending. Its deadline was extended in December 2025. Google's request was granted in February 2026 on strict conditions. So the mapping rules can change again at any time.
Coming in the next 12 months: the Commission's plan for privacy in the age of artificial intelligence. It is promised for late 2026, with new law to follow. Already in force, and worth checking against what you are building: the Framework Act on Artificial Intelligence Development and Trust started on 22 January 2026. A foreign artificial intelligence business above the size limits set by decree must appoint a Korean representative. It must also tell the Minister of Science and Information and Communications Technology. A further set of amended rules took effect on 20 July 2026. Five unused powers matter more than any pending bill. First, the Commission can order you to stop sending data abroad, and you get only 7 days to object. We found no public record of it being used, so the first use will surprise people. Second, Korea can mirror another country's restrictions back onto that country's companies. Unused. Third, the government can order measures to stop nationally important security and advanced technology information leaving over networks. Unused. Fourth, the Commission can withdraw or change its recognition of Europe if it decides protection there has slipped. That would put 30 countries back into needing consent overnight. Fifth, the mapping committee kept the right to suspend or withdraw Google's export permission if Google keeps breaking the conditions or breaks them badly.
Sources
- Official sourcePersonal Information Protection CommissionCommission designs privacy reform for the artificial intelligence era with the public, 5 August 2026
pipc.go.kr
“지난 7월 30일 「개인정보 제도 혁신 TF」를 구성했고, 8월 6일부터 ... 국민 정책 제안 접수를 실시한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationFramework Act on Artificial Intelligence Development and Establishment of a Foundation of Trust, Article 36 and commencement clause
law.go.kr
“이 법은 2026년 1월 22일부터 시행한다.”
Link checked 18 August 2026
- Official sourceKorea Policy Briefing (Ministry of Land, Infrastructure and Transport)Processing period extended for Apple's request to take Korean map data abroad, 5 December 2025
korea.kr
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: 전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions) · Financial Services Commission Notice No. 2026-29, Articles 11(1) and 14-2(7) · Directly binding regulation
A financial company with its head office in South Korea must keep its computer room and its disaster recovery centre in the country. You may use cloud. But if national ID numbers or personal credit information are handled on it, that system must sit in Korea too.
Enforced by Financial Services Commission
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe computer room and disaster recovery centre of a financial company or electronic payment business with its head office in Korea must be inside Korea. Cloud is an exception to that rule. But if unique government ID numbers or personal credit information are handled on the cloud system, that system must be in Korea.
- Independent auditBefore you use cloud you must do several things. Assess how critical the work is. Assess whether the provider is sound. Write business continuity and safety plans. Get approval from your internal information protection committee. Then report to the Financial Supervisory Service within 3 months of signing, or within 3 months of a major change.
What it costs if you get it wrong
- Loss of your licence: Supervisory sanction under the Electronic Financial Transactions ActOperating core systems outside Korea in breach of the supervision regulation
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationRegulation on Supervision of Electronic Financial Transactions, FSC Notice No. 2026-29, Articles 11 and 14-2
law.go.kr
“금융회사 또는 전자금융업자 ... 가 고유식별정보 또는 개인신용정보를 클라우드컴퓨팅서비스를 통하여 처리하는 경우에는 ... 해당 정보처리시스템을 국내에 설치하여야 한다.”
Link checked 18 August 2026
Finance data must stay in the country
Official name: 금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies) · Articles 5(1) and 7(1) · Directly binding regulation
A financial company may use a supplier abroad to handle data. But individual customers' national ID numbers must never leave the country. If a supplier abroad will handle customers' financial transaction data, you must report it to the supervisor 30 business days before the work starts.
Enforced by Financial Supervisory Service
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryIndividual customers' unique government ID numbers, mainly the resident registration number, must not be sent abroad. There is no exemption, and consent does not help.
- Register or notifyYour supplier abroad may handle individual customers' financial transaction information. A report must reach the Governor of the Financial Supervisory Service 30 business days before that supplier actually starts the work.
- Written vendor contractThe bank stays liable alongside its supplier. If the supplier breaks the rules or the contract and customers are harmed, both are on the hook.
What it costs if you get it wrong
- Loss of your licence: Supervisory sanctionExporting unique identifying information or failing to report an overseas outsourcee
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationRegulation on Outsourcing of Data Processing Business by Financial Companies, Articles 5 and 7
law.go.kr
“업무를 수탁받는 자가 국외에 소재하는 경우에는 그 사실을 업무를 위탁받은 자가 그 위탁받은 업무를 실제로 수행하려는 날의 30영업일 이전에 ... 금융감독원장에게 보고하여야 한다.”
Link checked 18 August 2026
Health and social care data must stay in the country
Official name: 전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records) · Ministry of Health and Welfare Notice No. 2023-245, Article 7 and Annexes 1 and 2 · Government rules
Electronic medical record systems and their backup equipment must sit inside South Korea. The rule applies to any hospital that stores records outside its own building. It applies to the cloud route too.
Enforced by Ministry of Health and Welfare
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThis applies whenever electronic medical records are kept anywhere other than the hospital's own premises. That covers every cloud or outsourced hosting arrangement. The limit sits in the standard route and the cloud route alike. Certification does not buy you an option abroad.
- Hold a security certificateFor the cloud route you need one of two things. An information security management system certification plus the international cloud security certification. Or you follow the cloud security standard set under the Cloud Computing Act.
What it costs if you get it wrong
- Fixed maximum fine: Sanction under the Medical Service ActStoring electronic medical records outside Korea
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationStandards for Facilities and Equipment for Electronic Medical Records, MOHW Notice No. 2023-245, Annexes 1 and 2
law.go.kr
“전자의무기록 시스템 및 그 백업장비의 물리적 위치는 국내로 한정한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationEnforcement Rule of the Medical Service Act, Article 16 (facilities and equipment for electronic medical records)
law.go.kr
Link checked 18 August 2026
Cloud and outsourcing rules (Government)
Official name: 클라우드컴퓨팅서비스 보안인증에 관한 고시 (Notice on Security Certification of Cloud Computing Services) · Ministry of Science and ICT Notice No. 2023-4, Annex 4, items 14.2.1 and 14.3.3 · Government rules
To sell cloud services to Korean government bodies you need a security certification. To get it, the cloud system, the backups, the data and the staff who run it must all be physically in South Korea.
Enforced by Ministry of Science and ICT
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe cloud system, the backup system, the data itself and the people who manage and run them must all be physically inside Korea. The staff must be in Korea, not just the data.
- Hold a security certificateYou cannot sell cloud to Korean public bodies at all without certification under the Cloud Security Assurance Program.
- Prove the data stays under local controlCloud for government must be physically separate from your commercial cloud. You must also plug into the state's security monitoring and incident investigation.
What it costs if you get it wrong
- Loss of your licence: Loss or refusal of certificationFailing the location or separation criteria
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationNotice on Security Certification of Cloud Computing Services, MSIT Notice No. 2023-4, Annex 4 (protective measures for cloud used by state bodies)
law.go.kr
“클라우드 시스템, 백업 시스템 및 데이터와 이를 위한 관리·운영 인력의 물리적 위치는 국내로 한정하여야 한다.”
Link checked 18 August 2026
State and security data rules
Official name: 공간정보의 구축 및 관리 등에 관한 법률 (Act on the Establishment and Management of Spatial Data) · Article 16 · Act of parliament
Nobody may take Korean basic survey results, maps or survey photographs abroad without the Minister's permission. Security-sensitive data also needs a decision from a committee of several agencies, including the intelligence and defence ministries. Google's request was granted on 27 February 2026 with heavy conditions. Apple's is still pending.
Enforced by Ministry of Land, Infrastructure and Transport, with the National Geographic Information Institute
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryRaw high-precision map data stays in Korea by default. In the February 2026 Google decision the committee required the raw data to be handled on a Korean partner's servers in Korea. Only a limited approved subset could be exported.
- Appoint a representativeThe same decision required a Local Responsible Officer for Korean maps. That person must live in Korea and be reachable by the government at all times.
- Do not hand data to foreign authorities on demandA 'red button' emergency technical measure had to be built so the government can force rapid action if national security is threatened.
What it costs if you get it wrong
- Criminal liability: Penalty under the Act on the Establishment and Management of Spatial DataTaking basic survey results out of Korea without permission
- Loss of your licence: Suspension or withdrawal of the export permissionContinued or serious failure to meet the attached conditions
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationAct on the Establishment and Management of Spatial Data, Article 16 (ban on taking basic survey results abroad)
law.go.kr
“누구든지 국토교통부장관의 허가 없이 기본측량성과 중 지도등 또는 측량용 사진을 국외로 반출하여서는 아니 된다.”
Link checked 18 August 2026
- Official sourceKorea Policy Briefing (Ministry of Science and ICT / Ministry of Land, Infrastructure and Transport)Decision to permit Google's export of 1:5,000 map data, 27 February 2026
korea.kr
“구글사(社)의 국내 제휴기업이 국내에 보유한 서버에서 원본 데이터를 가공하고, 간행 심사 등 정부 검토·확인을 거친 데이터만 반출하되 ... 한국 지도 전담관(Local Responsible Officer)을 국내 상주하도록 하고”
Link checked 18 August 2026
AI rules
Official name: 인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 (Framework Act on Artificial Intelligence Development and Establishment of a Foundation of Trust) · Act No. 21311, Article 36 · Act of parliament
South Korea's artificial intelligence law took effect on 22 January 2026. It does not force data to stay in Korea. But a large foreign artificial intelligence provider must appoint a named representative in Korea. It must register that person with the science ministry.
Enforced by Ministry of Science and ICT
What you have to do
- Appoint a representative — from 22 January 2026If your artificial intelligence business is foreign and passes the user-number and revenue limits set by decree, you must appoint a Korean representative in writing. You must tell the Minister of Science and Information and Communications Technology. If your representative breaks the rules, that counts as you breaking them.
- Assess high-risk projectsIf your artificial intelligence product or service is high-impact, you must make efforts to assess its effect on people's basic rights before launch. You must take account of vulnerable groups.
- Check your algorithmsFor foreign businesses, all of this goes through the Korean representative. That includes safety and trustworthiness measures. It also includes asking the ministry whether your system counts as high-impact.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under the Framework ActFailing to appoint or notify a domestic representative
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationFramework Act on Artificial Intelligence Development and Establishment of a Foundation of Trust, Article 36 and Addenda
law.go.kr
“국내에 주소 또는 영업소가 없는 인공지능사업자로서 이용자 수, 매출액 등이 대통령령으로 정하는 기준에 해당하는 자는 ... 국내대리인 ... 을 서면으로 지정하고, 이를 과학기술정보통신부장관에게 신고하여야 한다.”
Link checked 18 August 2026
- Official sourceKorea Policy BriefingKorea Policy Briefing press releases referencing the Framework Act's Enforcement Decree in operation, 2026
korea.kr
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Rules for sending data abroad
Official name: 개인정보 보호법 (Personal Information Protection Act) · Act No. 20897, Articles 28-8 to 28-11 · Act of parliament
Personal data may not leave South Korea unless one of five things applies. A separate consent. A Korean law or a treaty. A contract with the person, where you disclose the transfer. A certification the Commission has designated. Or a country the Commission has recognised as giving equal protection. Only the European Union and the European Economic Area have been recognised, in September 2025.
Enforced by Personal Information Protection Commission
How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Certification scheme, Explicit consent, Needed for a contract
What you have to do
- Put a transfer safeguard in placeSecurity measures, a complaints route and a dispute-resolution route must be agreed with the recipient in advance and written into the contract.
- Get consentYou must ask for transfer consent separately from every other consent. It must state the data, the destination country, the timing, the method and the recipient. It must also state the purpose, how long the data is kept, and how to refuse.
- Tell people what you doYour privacy policy must say which ground you are relying on.
What it costs if you get it wrong
- Percentage of global turnover: 3% of total revenueTransferring personal data abroad without one of the five grounds, or ignoring a transfer suspension order
- Order to stop: Order to stop the transferContinuing or expected transfers that breach the rules, or a destination that does not protect the data adequately
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationPersonal Information Protection Act, Articles 28-8, 28-9, 28-10 and 28-11
law.go.kr
“개인정보처리자는 개인정보를 국외로 제공(조회되는 경우를 포함한다)ㆍ처리위탁ㆍ보관 ... 하여서는 아니 된다.”
Link checked 18 August 2026
- Official sourcePersonal Information Protection CommissionEquivalence recognition status: European Union and European Economic Area, September 2025
pipc.go.kr
Link checked 18 August 2026
General data protection law
Official name: 개인정보 보호법 시행령 및 개인정보의 안전성 확보조치 기준 (Enforcement Decree of the Personal Information Protection Act and Standards for Securing the Safety of Personal Data) · Decree Articles 39 and 40; PIPC Notice No. 2026-9, Article 8 · Directly binding regulation
Two 72-hour clocks start when you learn about a leak. One to tell the people affected. One to report to the regulator. System access logs must be kept for at least a year. Larger or more sensitive systems need two years.
Enforced by Personal Information Protection Commission
What you have to do
- Tell affected people — within 72 hoursYou can delay only if you need the time to contain the attack, or a disaster prevents it.
- Report breaches to the regulator — applies at: 1,000 or more data subjects, or any sensitive or unique identifying information, or leakage caused by unlawful external access, within 72 hoursReport goes to the Commission or to the Korea Internet and Security Agency. File what you know and top it up as facts emerge.
- Keep logs — 1 yearIt is 24 months instead if the system holds data on 50,000 or more people. The same applies if it holds unique government ID numbers or sensitive data, or belongs to a registered telecoms carrier.
What it costs if you get it wrong
- Percentage of global turnover: 3% of total revenueLoss, theft or leakage of personal data where the controller did not take the required safety measures
- Criminal liability: 2 years imprisonment or 20 million won — about $14 thousandConcealing, destroying or falsifying material, or refusing access, during a Commission inspection
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationEnforcement Decree of the Personal Information Protection Act, Articles 39 and 40
law.go.kr
“72시간 이내에 법 제34조제1항 각 호의 사항을 서면등의 방법으로 보호위원회 또는 ... 전문기관에 신고해야 한다.”
Link checked 18 August 2026
- Official sourceKorean Law Information Center, Ministry of Government LegislationStandards for Securing the Safety of Personal Data, PIPC Notice No. 2026-9, Article 8
law.go.kr
“접속기록을 1년 이상 보관ㆍ관리하여야 한다. 다만 ... 2년 이상 보관ㆍ관리하여야 한다.”
Link checked 18 August 2026
State and security data rules (Telecoms)
Official name: 정보통신망 이용촉진 및 정보보호 등에 관한 법률 (Act on Promotion of Information and Communications Network Utilisation and Information Protection) · Article 51 · Act of parliament
The government may order network operators or users to take measures stopping nationally important information from flowing out of the country. That covers national security information and details of advanced technology developed in Korea. The power sits on the books unused.
Enforced by Ministry of Science and ICT
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThis power is unused. It exists and has no expiry date, but we found no published case of it being used. Treat it as something the government can switch on without warning, not as a live duty.
Sources
- Official sourceKorean Law Information Center, Ministry of Government LegislationNetwork Act, Article 51 (restriction on important information flowing abroad)
law.go.kr
“정부는 국내의 산업ㆍ경제 및 과학기술 등에 관한 중요 정보가 정보통신망을 통하여 국외로 유출되는 것을 방지하기 위하여 정보통신서비스 제공자 또는 이용자에게 필요한 조치를 하도록 할 수 있다.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the Commission has never issued a cross-border transfer suspension order under Article 28-9
We can show that the power exists and how it works. We found no announcement that it has ever been used. You cannot prove a thing has never happened from a search of press releases. Checked 18 August 2026. Our confidence is medium.
That no certification has been designated or granted under the Article 28-8(1)4 certification route for transfers abroad
The Commission's transfer page lists this route. Its recognition page names only the European decision. We found no list of certified recipients. Ask the Commission before you rely on this route. Checked 18 August 2026.
Whether the artificial intelligence law's administrative fines carry a grace period
The Act started on 22 January 2026, and more amended rules started on 20 July 2026. We confirmed those start dates. We could not confirm whether the government has delayed the fines. If the fines matter to your plan, check the Enforcement Decree and the ministry's announcements.
The current status of Apple's application to export high-precision Korean map data
The most recent government release we can point to is the 5 December 2025 extension of the review period. We found nothing newer as at 18 August 2026. That suggests the request is still pending, but it does not prove it. Check the government's map export announcements before you rely on this.
The official website of the renamed Broadcasting, Media and Communications Commission
The Location Information Act moved these functions from the Korea Communications Commission to a body named 방송미디어통신위원회 on 1 October 2025. We confirmed the name change in the law. We could not confirm the new body's own website, so it is not listed as an authority here.
Whether the Google map export has actually happened in practice
The 27 February 2026 decision allows the export only after the government confirms that every security condition has been met. We have the decision. We found no sign that the confirmation step has happened.
Whether the National Intelligence Service imposes further location rules on public-sector systems beyond the published cloud certification standard
The certification annex points to the Director of the National Intelligence Service for product certification rules. Korean public-sector security guidance is not published. Assume there is a stricter layer you cannot read. Ask your government customer before you design around this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.