Skip to the content
Global Data RulesData governance rules, country by country

South Korea

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in South Korea — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Aggressive

You can send personal data out of South Korea, but only on one of five grounds. Most companies use consent. The person has to tick a separate box just for the transfer. Since September 2025 you can send data to 30 European countries with no extra paperwork. Some industries are closed no matter what consent you get. That covers banking, health records, government cloud and detailed maps. The regulator fines foreign companies often.

Data governance in South Korea

The eight things that decide how you handle data about people in South Korea. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore. They collected Korean users' data and sent it abroad without a proper legal basis. You must also appoint a representative in Korea if you pass either size test. Test one: worldwide revenue of 1 trillion won (about $720 million) or more last year. Test two: data on an average of 1 million or more people in Korea per day, over the last three months of last year. Since April 2026 there is an extra step. If you already own or control a Korean company, that company has to be the representative.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, but you need one of five grounds. Most companies use consent. The person must tick a separate box just for the transfer. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein. That takes no extra step. The regulator has formally accepted that their protection matches Korea's. No other country is on that list. Six industries override all of this. They are covered below.

Ways to send data out:
Official 'this country is safe' decision · Certification scheme · Explicit consent · Needed for a contract

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Korea does not check where you send data. It checks your paperwork. There is no list of banned countries and no application to file. You pick one of the five grounds. For most companies that means asking each person for a separate transfer consent. That consent must say what data goes, where, to whom, for how long, and how to refuse. One country list exists, and it is a positive one. It holds 30 countries: the European Union plus Norway, Iceland and Liechtenstein. If you send data anywhere else, you must also keep security measures, a complaints route and a dispute process in place. You must write the transfer into your contract with the recipient.

What you have to do here:
Put a transfer safeguard in place · Written vendor contract
Ways to send data out:
Official 'this country is safe' decision · Explicit consent

The regulator, and whether it actually acts

The Personal Information Protection Commission enforces the law. Song Kyoung-hee chairs it. It is one of the busiest privacy regulators in the world right now. In July 2026 it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach. It fined TikTok about 10.3 billion won (roughly $7.4 million). It fined Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation. It asked police to investigate LG U+ for destroying a server before the inquiry started. Other regulators cover other industries. Finance goes to the Financial Services Commission and the Financial Supervisory Service. Health goes to the health ministry. Maps go to a committee of several agencies that includes the intelligence service.

What it costs if you get it wrong:
Percentage of global turnover · Criminal liability · Order to stop

How long you must keep it — and when to delete it

Two rules pull in opposite directions. First, you must destroy personal data as soon as you no longer need it. You must destroy it so it cannot be recovered. Second, other laws make you keep some records. An online seller must keep advertising records for 6 months. Complaint and dispute records: 3 years. Contract, cancellation, payment and delivery records: 5 years. Almost everyone must keep system access logs for at least 1 year. That becomes 2 years if the system holds data on 50,000 or more people. It is also 2 years if the system holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two rules clash, the keeping rule wins. You must then store that data separately from everything else.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count two clocks. In telecoms and finance, count a third. Under the privacy law you have 72 hours to tell the people affected. You have a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. Three things start that reporting clock. If 1,000 or more people are affected. If any sensitive data or national ID numbers leaked. Or if someone broke in from outside. An internet service provider must also report a cyber attack to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that will cost you a weekend. One: the age line for children is 14, not 13 or 16. Using an under-14's data without a parent's consent is a crime. It carries up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime. The regulator used that power in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all. And if a supplier abroad handles customers' financial transaction data, you must report it to the supervisor 30 business days before the work starts. Five: to run a personal location service you must be a corporation and be registered. So you cannot serve Korea from abroad with no Korean entity.

What you have to do here:
Get a parent's consent for children · Register or notify
What it costs if you get it wrong:
Criminal liability

What's changing next

The privacy regulator has started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026. It ran a public suggestion window from 6 to 31 August 2026. It plans to publish the direction of reform before the end of 2026. Consent-based rules are on the table. So is the block on sending pseudonymised data abroad for research. Separately, Apple's request to export detailed Korean map data is still pending. Its deadline was extended in December 2025. Google's request was granted in February 2026 on strict conditions. So the mapping rules can change again at any time.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: 전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions) · Financial Services Commission Notice No. 2026-29, Articles 11(1) and 14-2(7) · Directly binding regulation

In forceNo — it stays put

A financial company with its head office in South Korea must keep its computer room and its disaster recovery centre in the country. You may use cloud. But if national ID numbers or personal credit information are handled on it, that system must sit in Korea too.

In force since 15 July 2026

Enforced by Financial Services Commission

How this country controls where data goes: Not allowed

Finance

Finance data must stay in the country

Official name: 금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies) · Articles 5(1) and 7(1) · Directly binding regulation

In forceNo — it stays put

A financial company may use a supplier abroad to handle data. But individual customers' national ID numbers must never leave the country. If a supplier abroad will handle customers' financial transaction data, you must report it to the supervisor 30 business days before the work starts.

In force since 22 July 2015

Enforced by Financial Supervisory Service

How this country controls where data goes: Not allowed

Health and social care

Health and social care data must stay in the country

Official name: 전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records) · Ministry of Health and Welfare Notice No. 2023-245, Article 7 and Annexes 1 and 2 · Government rules

In forceNo — it stays put

Electronic medical record systems and their backup equipment must sit inside South Korea. The rule applies to any hospital that stores records outside its own building. It applies to the cloud route too.

In force since 14 December 2023

Enforced by Ministry of Health and Welfare

How this country controls where data goes: Not allowed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Rules for sending data abroad

Official name: 개인정보 보호법 (Personal Information Protection Act) · Act No. 20897, Articles 28-8 to 28-11 · Act of parliament

In forceYes, with paperwork

Personal data may not leave South Korea unless one of five things applies. A separate consent. A Korean law or a treaty. A contract with the person, where you disclose the transfer. A certification the Commission has designated. Or a country the Commission has recognised as giving equal protection. Only the European Union and the European Economic Area have been recognised, in September 2025.

In force since 15 September 2023

Enforced by Personal Information Protection Commission

How this country controls where data goes: Any country except banned ones (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Certification scheme, Explicit consent, Needed for a contract

General data protection law

Official name: 개인정보 보호법 시행령 및 개인정보의 안전성 확보조치 기준 (Enforcement Decree of the Personal Information Protection Act and Standards for Securing the Safety of Personal Data) · Decree Articles 39 and 40; PIPC Notice No. 2026-9, Article 8 · Directly binding regulation

In forceYes — store it anywhere

Two 72-hour clocks start when you learn about a leak. One to tell the people affected. One to report to the regulator. System access logs must be kept for at least a year. Larger or more sensitive systems need two years.

In force since 15 September 2023Enforced from 1 July 2026

Enforced by Personal Information Protection Commission

Telecoms

State and security data rules (Telecoms)

Official name: 정보통신망 이용촉진 및 정보보호 등에 관한 법률 (Act on Promotion of Information and Communications Network Utilisation and Information Protection) · Article 51 · Act of parliament

In forceYes, with paperwork

The government may order network operators or users to take measures stopping nationally important information from flowing out of the country. That covers national security information and details of advanced technology developed in Korea. The power sits on the books unused.

In force since 13 June 2008

Enforced by Ministry of Science and ICT

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • 개인정보보호위원회

    General privacy law: collection, use, transfer abroad, breach reporting, enforcement across all sectors

    Fully staffed and highly active. Chaired by Song Kyoung-hee. Held its 14th and 15th full meetings on 22 and 29 July 2026. It fined TikTok 10.306 billion won, Apple companies 252 million won and KT 53.979 billion won. It also resolved to file criminal complaints over obstruction of its investigations.

  • 금융위원회

    Rules for banks, payment firms, insurers and securities firms, including where their systems may be located

    Issues the Regulation on Supervision of Electronic Financial Transactions; the version in force is Notice No. 2026-29 dated 15 July 2026, so the rulebook is being actively maintained.

  • 금융감독원

    Day-to-day supervision of financial firms, including reports of overseas outsourcing and cloud use

    Receives the 30-business-day advance report when a supplier abroad will handle customers' financial transaction information. Also receives the 3-month cloud contract reports.

  • 보건복지부

    Electronic medical records, hospital data, treatment-information incidents

    Sets the equipment and facility standards for electronic medical records, including the requirement that the systems sit inside Korea. Current standard is Notice No. 2023-245.

  • 과학기술정보통신부

    Cloud security certification, cyber incident reporting, artificial intelligence law

    Runs the Cloud Security Assurance Program. Receives break-in reports jointly with the Korea Internet and Security Agency. Administers the artificial intelligence law that took effect on 22 January 2026.

  • 국토교통부 / 국토지리정보원

    Permission to take Korean survey results, maps and survey photographs abroad

    Chairs the committee of several agencies that decides on exporting survey results. That committee also seats the science, foreign affairs, unification, defence, interior and trade ministries, the National Intelligence Service and at least one civilian expert. It decided Google's application on 27 February 2026. Apple's application is still open after the deadline was extended in December 2025. Its own website blocks automated access, so its releases were read through the government's policy briefing portal.

  • 한국인터넷진흥원

    Receives breach reports on the Commission's behalf and cyber incident reports; runs security certification schemes

    Named in the Enforcement Decree as the specialist body for breach reports and for takedown of exposed personal data.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Commission has never issued a cross-border transfer suspension order under Article 28-9

    We can show that the power exists and how it works. We found no announcement that it has ever been used. You cannot prove a thing has never happened from a search of press releases. Checked 18 August 2026. Our confidence is medium.

  • That no certification has been designated or granted under the Article 28-8(1)4 certification route for transfers abroad

    The Commission's transfer page lists this route. Its recognition page names only the European decision. We found no list of certified recipients. Ask the Commission before you rely on this route. Checked 18 August 2026.

  • Whether the artificial intelligence law's administrative fines carry a grace period

    The Act started on 22 January 2026, and more amended rules started on 20 July 2026. We confirmed those start dates. We could not confirm whether the government has delayed the fines. If the fines matter to your plan, check the Enforcement Decree and the ministry's announcements.

  • The current status of Apple's application to export high-precision Korean map data

    The most recent government release we can point to is the 5 December 2025 extension of the review period. We found nothing newer as at 18 August 2026. That suggests the request is still pending, but it does not prove it. Check the government's map export announcements before you rely on this.

  • The official website of the renamed Broadcasting, Media and Communications Commission

    The Location Information Act moved these functions from the Korea Communications Commission to a body named 방송미디어통신위원회 on 1 October 2025. We confirmed the name change in the law. We could not confirm the new body's own website, so it is not listed as an authority here.

  • Whether the Google map export has actually happened in practice

    The 27 February 2026 decision allows the export only after the government confirms that every security condition has been met. We have the decision. We found no sign that the confirmation step has happened.

  • Whether the National Intelligence Service imposes further location rules on public-sector systems beyond the published cloud certification standard

    The certification annex points to the Director of the National Intelligence Service for product certification rules. Korean public-sector security guidance is not published. Assume there is a stricter layer you cannot read. Ask your government customer before you design around this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.