PIPC Announces Measures to Expedite Investigations and Enhance Investigative Capabilities
Five Major Tasks to Be Pursued, Including Case Management and Processing Procedures

Last year, a record-high number of approximately 103.55 million personal data entries were leaked from a total of 447 private and public organizations. In response, the government has taken decisive action to expedite investigations and strengthen capabilities for handling such incidents.


On October 2, 2026, the Personal Information Protection Commission (PIPC) announced its new "Measures for Rapid Investigation and Enhanced Investigation Capabilities of Personal Data Leaks and Infringement Incidents.” The PIPC will pursue five major tasks: ▲Strategic case management ▲Introduction of expedited procedures ▲Enhancing procedural transparency ▲Strengthening investigative capabilities ▲Public disclosure of case processing. The goal is to establish an investigation system that not only responds swiftly and professionally to incidents but also enhances fairness and transparency.


Song Kyunghee, Chairperson of the Personal Information Protection Commission, attends and speaks at the full meeting of the Personal Information Protection Commission held at the Government Seoul Office in Jongno-gu, Seoul on July 29, 2026. Photo by Jo Yongjun

Song Kyunghee, Chairperson of the Personal Information Protection Commission, attends and speaks at the full meeting of the Personal Information Protection Commission held at the Government Seoul Office in Jongno-gu, Seoul on July 29, 2026. Photo by Jo Yongjun

View original image

Major cases to be processed within 12 months, minor cases within 3 months


The PIPC has set a principle to process major cases within 12 months, general cases within 6 months, and minor cases within 3 months. Major incidents causing large-scale damage, such as data leaks affecting over 1 million people or significant cyberattacks on key public systems, will be prioritized through dedicated investigation teams. Immediately after an incident occurs, an on-site response team will be formed to assess systems impacted by the leak and preserve related evidence. In addition, notifications of personal data breaches and implementation of measures to prevent further damage will be conducted alongside the investigations to ensure both investigation and prevention are carried out simultaneously.


For general cases, the Commission will categorize cases by type based on their specific characteristics, and standardize violation and penalty guidelines for processing. According to an analysis by the PIPC at the end of the first half of the year of 621 completed leak cases, for the private sector, the main causes were hacking (235 cases), work negligence (192 cases), and system errors (51 cases). For public institutions, the main causes were work negligence (79 cases), hacking (33 cases), and system errors (9 cases).


In addition, for minor cases, the Commission will introduce a post-management system focused on improving root causes and preventing recurrence, including a first-offense exemption of fines and technical support for small and micro businesses.


To expedite case processing, the current subcommittee, which mainly handles cases involving administrative fines, will expand its authority to handle penalty surcharge cases of up to KRW 100 million. Of the 200 cases for which the PIPC had imposed penalty surcharges to date, 107 involved amounts below KRW 100 million, accounting for more than half. Ten cases had penalty surcharges exceeding KRW 10 billion. Going forward, the Commission plans to gradually extend the scope to cases involving up to KRW 1 billion, with the expectation that 54 to 85 percent of penalty surcharge cases can be processed by the subcommittee, thereby enabling faster resolutions.


Procedural transparency in the investigation process will also be enhanced. At the outset of each case, dedicated personnel within each department will be assigned to quickly determine whether or not to initiate an investigation. If a case is deemed minor and closed without investigation, the data subject will be notified. If the investigation period is extended, the Commission will notify the relevant parties every 6 or 12 months to increase predictability. For large-scale or complex incidents, preliminary explanations of the findings will be provided, and following the official notification of results, ample opportunities will be offered for formal feedback.


The capabilities of investigators will be further strengthened. This includes enhanced role-specific training and foundational training for new investigators to foster expertise, as well as designating key investigators as specialists to prevent disruption caused by job rotation. Kang Dae-hyun, Head of General Investigation at the PIPC, stated, "We will establish a system to nurture key investigators and reduce unnecessary job rotation, thereby fostering a deeper understanding of the industry. Each investigator will be provided with a tailored career plan to further develop their expertise."


The Commission also plans to transparently disclose the status of case processing to help each organization prevent incidents and improve their personal data protection standards. Previously, the PIPC only disclosed the number of administered cases, but now the scope will be expanded to include annual and institutional data on case intake and disposition, average investigation period, litigation status, and major leak cases. Furthermore, the process for calculating penalty surcharges—including severity assessments, aggravation and mitigation rates, the basic assessment rate, and a newly introduced investment mitigation rate—will also be disclosed.


Number of data leaks in 2025 reaches 103.55 million, setting all-time high


The PIPC's latest measures reflect the rapidly increasing number of personal data leaks and infringement incidents, which are being exacerbated by the spread of artificial intelligence (AI) technology and increasingly sophisticated attack methods. The PIPC reported that in 2025, personal data leaks occurred at a total of 447 private and public organizations, with the number of leaked data entries reaching approximately 103.55 million—an all-time high. This surge has been attributed to successive major leak incidents at leading telecommunications companies and e-commerce platforms with large user bases.


In the first half of this year alone, there were leak reports from 432 organizations with about 29.8 million personal data entries involved. The cumulative number of reports in the first half of 2026 is nearly equal to the total number reported for all of 2025.


As a result, the annual number of cases disposed by the PIPC continues to grow, exceeding 400 for the first time last year with 421 cases handled. Amid the surge in leak reports and the Commission’s limited number of investigators, the average time from investigation initiation to resolution approached one year. The average processing time last year was 345 days, and from January to June this year, it was 369 days.



Song Kyunghee, Chairperson of the PIPC, stated, "With personal data breaches and infringements quickly increasing and large-scale, complex cases on the rise, it is necessary to allocate investigative resources according to the importance and characteristics of each case, rather than handling all cases identically. We aim to build an investigation system that ensures not only speed, but also fairness and transparency."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing