Regulatory landscape ยท East Asia
South Korea: file security and audit obligations
South Korea pairs one of the region's strictest privacy statutes with a mandatory certification scheme: amended PIPA raises fines to 10% of total revenue and makes ISMS-P certification compulsory for in-scope controllers from July 2027.
At a glance
How South Korea regulates file security
- 01
Regime
Prescriptive privacy statute with mandatory security certification (ISMS-P)
- 02
File security
ISMS-P technical safeguards over personal data processing systems
- 03
Audit and evidence
72-hour breach notification; ISMS-P certification evidence
Overview
The regulatory picture
South Korea's regime is unusually prescriptive for the region, and the direction of travel is toward heavier enforcement rather than lighter. The Personal Information Protection Act (PIPA) is the principal statute, administered by the Personal Information Protection Commission, and it requires controllers to implement technical and administrative safeguards over personal data and to notify data subjects within 72 hours of discovering unauthorised access or unlawful distribution.
An amendment passed by the National Assembly on 12 February 2026 and promulgated as Act No. 21445 on 10 March 2026 authorises administrative fines of up to 10% of a company's total revenue in high-severity breach cases. Most provisions take effect on 11 September 2026. The provisions making ISMS-P certification mandatory for certain controllers take effect later, on 1 July 2027, with applicable thresholds to be set by Enforcement Decree based on turnover and the scale of personal data processing. ISMS-P extends the existing ISMS scheme with personal-data-specific requirements, and certification is assessed against documented technical safeguards rather than policy alone.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Personal Information Protection Act (as amended 2026) | PIPC | In force | Direct |
| ISMS-P certification scheme | KISA | In force | Direct |
PIPC
Personal Information Protection Act (as amended 2026)
Requires technical and administrative safeguards over personal data and 72-hour breach notification. The 2026 amendment authorises fines up to 10% of total revenue and mandates ISMS-P certification for in-scope controllers from 1 July 2027.
Why it matters for file security. Personal data in documents falls squarely inside the safeguards obligation, and the move to revenue-based fines makes the volume of personal data sitting in unmanaged files a quantifiable financial exposure rather than a housekeeping issue.
How Glasswall addresses it. Find & Redact removes named data patterns from documents before they are stored or shared, and Storage Monitor applies the same treatment to files already at rest in Microsoft 365, recording what was processed per tenant. Both reduce the personal data population that a revenue-based penalty would be assessed against.
Find & RedactStorage Monitor + SM AuditGlasswall Halo
KISA
ISMS-P certification scheme
Information Security Management System with Personal information protection. Extends ISMS with personal-data controls. Becomes mandatory for certain controllers under amended PIPA from 1 July 2027.
Why it matters for file security. Certification is assessed against implemented technical safeguards, including malware protection and controls over data entering and leaving processing systems. Documented, deterministic file handling is straightforward to evidence to an assessor.
How Glasswall addresses it. CDR gives an ISMS-P assessor a control whose behaviour is the same on every file, which is easier to evidence than a detection posture that varies with signature currency. The per-file verdict record supplies the processing evidence the certification assessment expects.
Content Disarm and ReconstructionPer-file verdict recordGlasswall Halo / Glasswall Meteor
Latest developments
What has changed in South Korea
Most recent first.
-
Amended PIPA promulgated with revenue-based fines and mandatory ISMS-P
The PIPA amendment was promulgated as Act No. 21445, authorising administrative fines of up to 10% of total revenue in high-severity breach cases. Most provisions take effect 11 September 2026; mandatory ISMS-P certification provisions take effect 1 July 2027.
Why it matters for file security. Revenue-based penalties materially change the business case for reducing personal data held in documents, and the ISMS-P mandate creates a dated deadline for evidencing technical safeguards.
How Glasswall addresses it
Two dated deadlines to plan against: September 2026 for the penalty regime and July 2027 for ISMS-P certification. Reducing personal data in documents addresses the first; documented deterministic file handling with a per-file verdict record addresses the second.
Find & RedactContent Disarm and ReconstructionPer-file verdict recordGlasswall Halo
- banking
- healthcare
- telco
- education
Scope
About this page
This page is a working reference for organisations operating in South Korea.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.