Skip to the content
Global Data RulesData governance rules, country by country

South Korea

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Aggressive

South Korea's privacy law bans sending personal data abroad unless you have one of five grounds. The usual one is a separate consent, ticked apart from every other consent. Since September 2025 the 30 European countries need no extra paperwork. But banking, health records, government cloud and detailed maps have hard walls no consent can unlock, and the regulator fines foreign companies often.

Eight questions about South Korea

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do South Korea's rules apply to my company?

Yes. The regulator fines companies with no Korean office. In July 2026 it fined TikTok's Singapore company and two Apple companies based in Ireland and Singapore for collecting Korean users' data and sending it abroad without a proper legal basis. If your worldwide revenue was 1 trillion won (about $720 million) or more last year, or you held data on an average of 1 million or more people in Korea per day over the last three months of last year, you must appoint a representative in Korea. Since April 2026, if you already own or control a Korean company, that Korean company has to be the representative.

High confidenceNational rulesAppoint a local representativeLocal representative

Can I store my users' data outside South Korea?

In general yes, but only if you have one of five grounds, and the usual one is a separate consent that the person ticks apart from every other consent. Since September 2025 you can also send data to the 27 European Union countries plus Norway, Iceland and Liechtenstein with no extra step at all, because the regulator has formally accepted their protection as equal to Korea's. That is the only such list, and no other country is on it. Six industries override all of this and are covered below.

High confidenceDepends on your industryOfficial 'this country is safe' decisionCertification schemeExplicit consentNeeded for a contract

What do I need in place before data leaves South Korea?

Korea does not police the destination. It polices your paperwork. There is no banned-country list and no approval application to file: you pick one of the five grounds, and for most companies that means asking each person for a separate transfer consent that lists what goes, where, to whom, for how long and how to refuse. The one destination list that exists is a positive one, and it holds exactly 30 countries: the European Union plus Norway, Iceland and Liechtenstein. Send data anywhere else and you also have to keep security measures, a complaints route and a dispute process in place, and write the transfer into your contract with the recipient.

High confidenceBlocklistOfficial 'this country is safe' decisionExplicit consentPut a transfer safeguard in placeWritten vendor contract

Who enforces the rules in South Korea, and what can they do?

The Personal Information Protection Commission, chaired by Song Kyoung-hee, and it is one of the busiest privacy regulators in the world right now. In July 2026 alone it fined the telecoms company KT about 54 billion won (roughly $39 million) over a data breach, fined TikTok about 10.3 billion won (roughly $7.4 million) and Apple about 252 million won (roughly $180,000). It referred KT to prosecutors for obstructing the investigation and asked police to investigate LG U+ for destroying a server before the inquiry started. Finance is separately policed by the Financial Services Commission and the Financial Supervisory Service; health by the health ministry; maps by an inter-agency committee that includes the intelligence service.

High confidenceAggressivePercentage of global turnoverCriminal liabilityOrder to stop

How long do I have to keep the data?

Two forces pull in opposite directions. The ceiling: you must destroy personal data without delay once you no longer need it, and destroy it so it cannot be recovered. The floor: other laws make you keep things. An online seller must keep advertising records for 6 months, complaint and dispute records for 3 years, and contract, cancellation, payment and delivery records for 5 years. Almost everyone must keep system access logs for at least 1 year, and 2 years if the system holds data on 50,000 or more people, holds national ID numbers or sensitive data, or belongs to a licensed telecoms carrier. When the two clash, the keeping rule wins, but you must store that data separately from everything else.

High confidenceDelete data after a periodKeep data for a minimum periodKeep logs

What happens if there is a breach?

Count two clocks, and in telecoms and finance a third. Under the privacy law you have 72 hours to tell the affected people, and a separate 72 hours to report to the Commission or to the Korea Internet and Security Agency. The reporting clock starts if 1,000 or more people are affected, or if any sensitive data or national ID numbers leaked, or if the cause was someone breaking in from outside. Separately, an internet service provider must report a cyber incident to the science ministry or the same agency immediately. A hospital must also tell the health ministry about a medical-records incident.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in South Korea?

Five things that will cost you a weekend. One: the children's age line is 14, not 13 or 16, and processing an under-14's data without a parent's consent is a crime punishable by up to five years in prison, not just a fine. Two: hiding or destroying material during a regulator's inspection is itself a crime, and the regulator used it in July 2026. Three: stripping names out of a dataset does not free it. Four: a bank's Korean customers' national ID numbers may not leave the country at all, and any offshore processing of customers' financial transaction data needs a report to the supervisor 30 business days before work starts. Five: if you want to run a personal location service you must be a corporation and be registered, so you cannot serve Korea from abroad with no entity.

High confidenceCriminal liabilityChildren's dataGet a parent's consent for childrenRegister or notify

What is changing soon in South Korea?

The privacy regulator started rewriting the rulebook for artificial intelligence. It set up a reform task force on 30 July 2026, ran a public suggestion window from 6 to 31 August 2026, and plans to publish the direction of reform before the end of 2026. Consent-based rules and the block on sending pseudonymised data abroad for research are both explicitly on the table. Separately, Apple's request to export detailed Korean map data has been pending since its deadline was extended in December 2025, and Google's equivalent request was granted in February 2026 on strict conditions, so the mapping picture can move again at any time.

High confidenceIn forceGovernment policy document

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

개인정보 보호법 (Personal Information Protection Act)

Act of parliament · Act No. 20897, Articles 28-8 to 28-11

In forceYes, with paperwork

Personal data may not leave South Korea unless one of five grounds applies: separate consent, a statute or treaty, contract necessity with disclosure, a Commission-designated certification, or a country the Commission has recognised as equivalent. Only the European Union and European Economic Area have been recognised, in September 2025.

In force since 15 September 2023

Enforced by Personal Information Protection Commission

Transfer model: Blocklist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Certification scheme, Explicit consent, Needed for a contract

High confidence

개인정보 보호법 시행령 및 개인정보의 안전성 확보조치 기준 (Enforcement Decree of the Personal Information Protection Act and Standards for Securing the Safety of Personal Data)

Directly binding regulation · Decree Articles 39 and 40; PIPC Notice No. 2026-9, Article 8

In forceYes — store it anywhere

Two 72-hour clocks run from the moment you know about a leak: one to tell the people affected, one to report to the regulator. System access logs must be kept for at least a year, and two years for larger or more sensitive systems.

In force since 15 September 2023But only enforceable from 1 July 2026

Enforced by Personal Information Protection Commission

High confidence

정보통신망 이용촉진 및 정보보호 등에 관한 법률 (Act on Promotion of Information and Communications Network Utilisation and Information Protection)

Act of parliament · Article 51 · Telecoms

In forceYes, with paperwork

The government may order network operators or users to take measures stopping nationally important information from flowing out of the country. That covers national security information and details of advanced technology developed in Korea. The power sits on the books unused.

In force since 13 June 2008

Enforced by Ministry of Science and ICT

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed

Medium confidence

Industry rules6 rules

전자금융감독규정 (Regulation on Supervision of Electronic Financial Transactions)

Directly binding regulation · Financial Services Commission Notice No. 2026-29, Articles 11(1) and 14-2(7) · Banking

In forceNo — it stays put

A financial company headquartered in South Korea must keep its computer room and its disaster recovery centre inside the country. Cloud is allowed, but the moment national ID numbers or personal credit information are processed on it, that system must sit in Korea too.

In force since 15 July 2026

Enforced by Financial Services Commission

Transfer model: Not allowed

High confidence

금융회사의 정보처리 업무 위탁에 관한 규정 (Regulation on Outsourcing of Data Processing Business by Financial Companies)

Directly binding regulation · Articles 5(1) and 7(1) · Finance

In forceNo — it stays put

A financial company may outsource data processing overseas, but individual customers' national ID numbers must never leave the country, and any offshore outsourcing of customers' financial transaction data must be reported to the supervisor 30 business days before the work starts.

In force since 22 July 2015

Enforced by Financial Supervisory Service

Transfer model: Not allowed

High confidence

전자의무기록의 관리·보존에 필요한 시설과 장비에 관한 기준 (Standards for the Facilities and Equipment Required to Manage and Preserve Electronic Medical Records)

Government rules · Ministry of Health and Welfare Notice No. 2023-245, Article 7 and Annexes 1 and 2 · Health and social care

In forceNo — it stays put

Electronic medical record systems and their backup equipment must physically sit inside South Korea. The rule bites on any hospital that stores records outside its own building, and it applies equally to the cloud route.

In force since 14 December 2023

Enforced by Ministry of Health and Welfare

Transfer model: Not allowed

High confidence

Who you would hear from

  • 개인정보보호위원회

    General privacy law: collection, use, transfer abroad, breach reporting, enforcement across all sectors

    Fully staffed and highly active. Chaired by Song Kyoung-hee. Held its 14th and 15th plenary meetings on 22 and 29 July 2026, imposing fines of 10.306 billion won on TikTok, 252 million won on Apple companies and 53.979 billion won on KT, and resolving to file criminal complaints over obstruction of its investigations.

  • 금융위원회

    Rules for banks, payment firms, insurers and securities firms, including where their systems may be located

    Issues the Regulation on Supervision of Electronic Financial Transactions; the version in force is Notice No. 2026-29 dated 15 July 2026, so the rulebook is being actively maintained.

  • 금융감독원

    Day-to-day supervision of financial firms, including reports of overseas outsourcing and cloud use

    Receives the 30-business-day advance report for offshore processing of customers' financial transaction information and the 3-month cloud contract reports.

  • 보건복지부

    Electronic medical records, hospital data, treatment-information incidents

    Sets the equipment and facility standards for electronic medical records, including the requirement that the systems sit inside Korea. Current standard is Notice No. 2023-245.

  • 과학기술정보통신부

    Cloud security certification, cyber incident reporting, artificial intelligence law

    Runs the Cloud Security Assurance Program, receives intrusion incident reports jointly with the Korea Internet and Security Agency, and administers the artificial intelligence law that took effect on 22 January 2026.

  • 국토교통부 / 국토지리정보원

    Permission to take Korean survey results, maps and survey photographs abroad

    Chairs the inter-agency committee on export of survey results, which also seats the science, foreign affairs, unification, defence, interior and trade ministries, the National Intelligence Service and at least one civilian expert. It decided Google's application on 27 February 2026 and has Apple's application still open after extending the deadline in December 2025. Its own website blocks automated access, so its releases were read through the government's policy briefing portal.

  • 한국인터넷진흥원

    Receives breach reports on the Commission's behalf and cyber incident reports; runs security certification schemes

    Named in the Enforcement Decree as the specialist body for breach reports and for takedown of exposed personal data.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the Commission has never issued a cross-border transfer suspension order under Article 28-9

    We can evidence the power and its procedure from the statute and the decree, and we found no press release announcing its use, but a negative cannot be proved from a press-release search. Checked 18 August 2026, confidence medium.

  • That no certification has been designated or granted under the Article 28-8(1)4 certification route for transfers abroad

    The Commission's own transfer page lists the route but its equivalence page names only the European recognition. We found no list of certified recipients. Checked 18 August 2026.

  • Whether the artificial intelligence law's administrative fines carry a grace period

    The Act commenced on 22 January 2026 and a further tranche of amended provisions on 20 July 2026. We verified the commencement clause but not whether the government has deferred enforcement of the penalty provisions, which would need the Enforcement Decree and a ministry announcement we could not retrieve.

  • The current status of Apple's application to export high-precision Korean map data

    The last government release we can evidence is the 5 December 2025 extension of the processing period. No later release appears in the government policy briefing portal as at 18 August 2026, which suggests it is still pending but does not prove it.

  • The official website of the renamed Broadcasting, Media and Communications Commission

    The Location Information Act was amended with effect from 1 October 2025 to transfer functions from the Korea Communications Commission to a body named 방송미디어통신위원회. We verified the statutory renaming but could not verify the new body's own domain, so it is not listed as an authority here.

  • Whether the Google map export has actually happened in practice

    The 27 February 2026 decision made actual export conditional on the government first confirming that every security condition has been met. We have the decision but no evidence of the confirmation step being completed.

  • Whether the National Intelligence Service imposes further location rules on public-sector systems beyond the published cloud certification standard

    The certification annex refers to the Director of the National Intelligence Service for product certification requirements, and Korean public-sector security guidance is not published. Assume there is a stricter unpublished layer.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.