Korea's Surcharge Discounts Shift From Certificates to Breach Response
On July 16, Korea's Personal Information Protection Commission (PIPC) posted two items together: a partial revision to the surcharge criteria (Notice No. 2026-90) and a newly enacted administrative-fine criteria (Notice No. 2026-92). Both take effect on September 11, 2026, the same day as the amended Personal Information Protection Act (Act No. 21445). Comments are open until August 5.
The provisions get fairly intricate, but for practitioners the through-line is one thing. Cut back the discounts you got just for holding a certificate, and look instead at how you actually responded when a breach happened.
Certification discounts got cut in half
Here's how the discount rates change at the second-adjustment stage of the surcharge calculation.
| Discount ground | Current | Revised |
|---|---|---|
| Certification recognized by the PIPC | up to 50% | up to 30% |
| Compliance with a self-regulatory code | up to 40% | up to 20% |
| Top-grade privacy-policy/level assessment, impact assessment | up to 30% | up to 15% |
All three are exactly halved. The explanatory note only says "reducing surcharge discounts for certification, voluntary protection activities, and the like."
Given what it costs to maintain ISMS-P, it's a disappointing change. Still, the direction makes sense. With large breaches repeatedly happening at certified organizations, the premise that holding a certificate equals having implemented safeguards has genuinely been shaken.
In its place: a breach-response system discount
For what came out, something new went in. The second adjustment adds this discount ground.
Where an organization has built and operated a response system in preparation for breaches and the like, and accordingly — upon a breach — recovered and improved back to a safe protection posture through early detection, prompt reporting/notification, and measures to prevent the spread of harm. Up to a 40% discount on the amount after the first adjustment.
That's larger than the certification discount (30%). It's the single biggest discount ground in this revision.
Pull the wording apart and the demand is clear. Having a system isn't enough; "accordingly" you had to actually detect early, report and notify promptly, and stop the spread. It's the difference between leaving your incident-response procedure in a filing cabinet and leaving behind logs stamped with the time of detection, the time of reporting, and the time of notification.
Conversely, an aggravating factor arises at this same point. If you knew a breach had occurred but failed to report/notify within the statutory deadline and took no measures to prevent the spread of harm, that's up to a 30% add-on. For the same conduct, the range swings 70 percentage points top to bottom.
Breach response is now a single item that carries both a discount and an aggravation. Time-stamped evidence at the moment of the breach weighs more heavily on the amount than keeping a certificate does.
A new stage called "investment discount"
The calculation structure itself changes. Previously you went straight from the base amount to the first adjustment; now an investment discount slots in between.
Base amount → investment discount → first adjustment → second adjustment → final surcharge.
The investment discount is up to 40% of the base amount. Three things are considered. The scale and ratio of investment in budget, staff, facilities, and equipment for data protection, along with its continuity and rate of increase. The CEO's fulfillment of responsibility under Article 30-3, and the CPO's designation, authority, fulfillment of responsibility, level of work performance, and the composition and operation of the team. And the level of safeguards beyond statutory obligations, such as applying enhanced protection technologies.
The assessment period is the three business years preceding the business year in which the violation occurred. In other words, ramping up your budget in a panic after a breach breaks, in principle, doesn't count. The Commission may look at the current business year too if it deems it substantial.
The fact that this sits at the front matters quite a bit. Because it's carved off the base amount first, it shrinks the whole basis for the later first and second adjustments. Conversely, if you don't get the investment discount, the aggravations that come afterward are calculated on top of a larger amount.
For CPOs, it stands out that "designation, authority, fulfillment of responsibility, and level of work performance" is now explicitly a discount factor. Not a single appointment letter, but a record that authority was actually granted and the work was carried out.
Repeat violations got much heavier
The repeat-violation aggravation in the first adjustment changes like this. It's based on the number of surcharge dispositions received over the past three years for a violation under the same subparagraph.
One prior goes from 15% to 20%. Two priors adds a new 40%. Three or more goes from 30% to 80%. What used to be lumped together as "two or more, 30%" was split apart, pushing the top end way up.
The public-institution discount narrows too. National agencies, local governments, and public-system operators are explicitly excluded from the discount granted on grounds of the type and scale of operations (up to 50%). It reads as an adjustment prompted by the run of public-sector breaches.
Administrative fines head the same way, but with a condition attached
On the administrative-fine side, it's formally an enactment, but in substance it's closer to a rework of the existing notice (2023.9.11.). The structure is simple. You set the imposed amount by adding to or subtracting from the base amount; discounts go up to 90%, aggravations up to 50%.
The 40% breach-response-system discount landed here too, with the same wording as on the surcharge side.
The certification discounts are laid out as ISMS-P 30%, ISMS 20%, ISO 27701 20%, ISO 27001 / BS 10012 20%, and a private voluntary protection mark 10%. If more than one applies, only the single highest rate is used.
There's one condition here you can't miss. It applies only where the personal-information processing system in which the violation occurred falls within the certification scope. Meaning it's not the certificate itself but whether the certification scope overlaps with the point of the breach. An organization that drew its ISMS-P scope narrowly to save on certification costs won't get the discount when a breach hits a system outside that scope. Scoping the certification is wired directly into the sanction amount.
On the aggravation side, obstructing the investigation is the heaviest at 50%. It covers refusing to submit materials, destroying evidence, concealment, fabrication, providing false information, and even asking data subjects to give false statements. Beyond that: a violation period over two years is 30%, three or more violations of the detailed safeguard standards is 30%, and leading the violation is 20%.
Connecting Information entered the severity assessment
In the severity criteria of the surcharge's Annex 1, Connecting Information is added to the item "type of personal data the violator processes." The notice defines Connecting Information as a resident registration number irreversibly encrypted for the purpose of service linkage. That's the CI.
For businesses that handle CI during identity verification, this one line can bump up the severity grade itself. Sectors where linking to an identity-verification agency is mandatory — telecom, finance, platforms — are squarely in the blast radius. Even at the same breach scale, whether CI was mixed in changes the starting point for the base amount.
The harm-scale bands in the newly added aggravation criteria (Annex 2) are also worth noting. Ten million or more people is "low," 20 million or more is "medium," and 30 million or more is "high." They're used to set the aggravation multiplier applied to the revenue-based surcharge.
This is still at the pre-announcement stage, so the provisions aren't final. But the effective date is pinned to September 11, the same as the Act's, so there doesn't seem to be much room for the broad framework to change. If you're listing what to do over the next two months, it's this: run your breach-response procedure once to see whether it actually works outside the document. The key is whether the structure leaves behind time-stamped evidence from early detection all the way through to reporting and notification.
Sources