Korea's privacy regulator has published a second-half work plan committing it to an AI original-data exemption while a 10 percent turnover penalty starts in September

Korea PIPC Work Plan: AI Original Data, 10% Fines. The Leveraged Years regulation briefing card.

A work plan is not a rule. But this one names the month a 10 percent turnover penalty starts, and it tells you which bill the agency is spending its political capital on.

The short version

Bottom line: A work plan reported at the Cheong Wa Dae State Guest House alongside fifteen other agencies. It binds nobody and creates no obligation on its own. The one hard date in it comes from a law already amended in March 2026: punitive fines take effect in September.

Who this affects: Privacy counsel and CPOs at Korean subsidiaries of foreign firms, Korean platform and financial operators, and AI developers building on Korean personal data.

Issue date: 16 July 2026, reported at the Cheong Wa Dae state guest house. The punitive fine regime the plan describes takes effect in September 2026. No comment deadline attaches to a work plan.

What changed: The PIPC committed publicly to pushing an AI original-data special exception, to adding standard contractual clauses and binding corporate rules as cross-border transfer routes, and to rebuilding the fine calculation rules, on no stated timetable.

Analysis: The exemption is still a bill. The PIPC's own text says the amendment cleared the National Assembly's National Policy Committee on 14 May 2026, which is a committee vote, not enactment. Anyone planning a Korean training-data pipeline on the strength of this announcement is planning on a bill.

Primary sources: PIPC press release, 16 July 2026 (Korean)

Instrument (EN)
2026 Second-Half Work Plan of the Personal Information Protection Commission
Authority
Personal Information Protection Commission (PIPC), chaired by Song Kyung-hee
Jurisdiction
Republic of Korea
Status
Reported at a 16-agency government work-report session on 16 July and published as a press release. Several components require statutory amendment that has not completed.
Bindingness
Not binding. A work plan. The September penalty ceiling derives from the March 2026 amendment to the Personal Information Protection Act, not from the plan.
Issue date / next deadline
16 July 2026. Punitive fines of up to 10 percent of turnover apply from September 2026.
Language of record
Korean. Figures and quotations here are translated from the PIPC release.
Primary source
https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12281

The one date that matters

Most of this document is a list of intentions. One line is not. The PIPC states that from September, serious or repeated violations carry a penalty of up to 10 percent of turnover, replacing the previous ceiling of 3 percent. That change was made by an amendment to the Personal Information Protection Act in March 2026; the work plan's contribution is to say the agency will rebuild the enforcement decree, notices and the wider sanctions framework, without saying when that work will be finished.

So the fine ceiling is settled and the calculation method is not. For anyone modelling exposure in Korea, the second half of that sentence is the live variable.

The AI original-data exemption is a bill, not a law

The plan describes a proposed AI wonbon hwaryong teungnye, an exemption permitting the use of original personal data, not pseudonymised data, for AI development where the purpose is of public or social benefit and tailored safety measures are in place. The PIPC frames this as answering steady field demand for higher-performing models trained on unaltered data.

A footnote in the release does the useful work here. It records that the amendment bill was resolved by the National Assembly's National Policy Committee on 14 May 2026. A committee resolution is a stage, not an outcome. On the regulator's own account this permission does not yet exist.

The agency also promises sector guides on agentic AI and public-sector AI transformation. Those would be guidance documents when they appear, with whatever weight guidance carries.

What the enforcement numbers show

The release publishes its own breach-report counts: 307 in 2024, 447 in 2025, and 432 in the first half of 2026 alone. The PIPC notes that the half-year figure is already close to the whole of 2025.

Against that, the agency says it will stand up dedicated task forces for incidents above one million records and a fast-track procedure for small ones. It also proposes a warning-in-lieu-of-sanction mechanism for minor incidents at small and micro enterprises, conditional on remediation.

There is a second, less discussed thread. The plan says fines will be reduced where a firm invested in prevention beyond its legal minimum, including a strong security system and a genuinely expert chief privacy officer. Separately, it says the agency will take incident response into account when setting a fine, naming rapid detection and reporting, containment of the damage, and recurrence-prevention measures. It also says fines will be increased for deliberate neglect, and flags a proposed offence for concealing or destroying evidence after an incident.

Cross-border transfers and the dark-web offence

Two items deserve a note from anyone running data out of Korea. The PIPC says it will permit outbound transfers via standard contractual clauses it prepares itself, and via binding corporate rules it approves, alongside the existing consent and adequacy routes. It also signals strategic cooperation focused on Asia-Pacific counterparts.

Separately the plan proposes a new prohibition on knowingly circulating leaked personal data on dark web venues, carrying up to five years imprisonment or a fine of up to 50 million won, plus a statutory basis for the PIPC to collect, detect, delete and block such material. Both are legislative proposals in this document.

What we did not verify

We opened the PIPC press release of 16 July 2026 in Korean and read it in full, including the four attached files listed on the page.

We did not open the four attachments themselves, which include the full work-report PDF and the presentation deck. We did not open the March 2026 amendment to the Personal Information Protection Act, the 14 May 2026 committee record, or the enforcement decree that the PIPC says it will revise.

We do not claim the AI original-data exemption is law, that the September commencement covers any particular conduct, or that any specific fine reduction described here is available today. The calculation rules the PIPC says it will rebuild were not published with this release, and we make no claim about their content.

Key compliance takeaway

Two things in this plan are firm: the 10 percent ceiling and the September start. Everything about AI training on original personal data is a bill that cleared one committee in May. Treat the fine timeline as a planning input and treat the exemption as a watch item, not a permission.

Source File

https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12281

Open the PIPC press release of 16 July 2026 and confirm three things: the 10 percent figure appears under the fourth priority task with a September commencement; the AI original-data exemption footnote cites a National Policy Committee resolution dated 14 May 2026; and the breach-report series reads 307, 447, 432.

Following last year's large-scale leak incidents, we are raising the effectiveness of sanctions while shifting the personal data protection system toward prevention. (translated from Korean) ยท Song Kyung-hee, PIPC Chairperson, 16 July 2026

FAQ

Can I train a model on original Korean personal data now?

Not on the strength of this document. The PIPC describes the exemption as a proposal whose amendment bill was resolved by a National Assembly committee on 14 May 2026. The release does not say the exemption is in force.

Does the 10 percent penalty apply to every violation?

The release describes it as applying to serious or repeated violations, replacing a previous ceiling of 3 percent of turnover. The detailed calculation framework is what the PIPC says it will revise before commencement.

Is there a deadline I need to diary?

September 2026 for the punitive fine regime, on the PIPC's account. A work plan itself carries no consultation or compliance deadline.

What changes for cross-border transfers?

The PIPC says it will add standard contractual clauses that it prepares and binding corporate rules that it approves as permitted transfer routes. Neither text was published with this release.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}