Hello, this is Kim Kwang-sik, attorney at Cheongchul Law Firm.
On 16 July 2026, the Personal Information Protection Commission (PIPC) released its work plan for the second half of 2026, signalling a fundamental change in how personal data breaches will be sanctioned. The core idea is a shift from an after-the-fact model of “punish once an incident occurs” to a prevention-first model in which “how much you invested in prevention” feeds directly into the sanction. The flagship instrument of that shift is the so-called “reward-penalty linked” administrative fine system.
Until now, data breach incidents were met with fines and corrective orders only after the fact, and critics pointed out that a company’s ordinary investment in security and privacy protection was not adequately reflected in the level of sanction. The new plan aims to change the incentive structure itself: companies that invest in prevention receive reduced fines, while companies that leave incidents unaddressed face increased fines. The plan also contains measures with direct practical impact on business, including a special exception for the use of data in training artificial intelligence (AI) and a shift in the burden of proof in breach damages claims.
Today I will walk through the structure of the reward-penalty linked fine system announced by the PIPC, the punitive fines being strengthened from September, the special exception for AI training data, the change in the burden of proof for damages, and the items companies should be checking from now on.
[Question]
What is the “reward-penalty linked” fine announced by the PIPC, and will a company’s fine actually be reduced if it invests in prevention? What changes are coming for AI training data use and for breach damages claims?
[Answer]
1. A shift in regulatory paradigm — from “punishment after the fact” to “prevention in advance”
In this second-half work plan, the PIPC made clear that it will move the centre of gravity of data protection from after-the-fact response to advance and continuous prevention. The move stems from the recognition that ex post sanctions alone have limits in the face of repeated large-scale breaches, and it shifts the regulatory focus from “how heavily should we punish after an incident” to “what should companies be required to have in place at all times to prevent one”.
This direction is already visible in concrete scheduling. Advance on-site inspections are planned for high-risk private sectors such as funeral-plan companies and finance, while in the public sector measures are scheduled in sequence for major public systems: mandatory registration of a qualified Chief Privacy Officer (CPO), regular penetration testing, and phased mandatory certification under the Personal Information & Information Security Management System (ISMS-P). In short, the trend is that a company’s “everyday level of management” itself becomes the direct object of regulation.
▶ Card news summary The centre of gravity of privacy regulation is moving from “punishment after an incident” to “everyday prevention”. A company’s standing level of management is now itself the direct object of regulation.
2. Reward-penalty linked fines and the September tightening — mitigation, aggravation, and punitive fines
The reward-penalty linked fine is a system that reflects a company’s preventive efforts and its attitude in responding to an incident when the fine is calculated. On one hand, a company that has invested in prevention beyond its statutory obligations — for example by putting in place a strong security system or appointing a qualified CPO, thereby voluntarily raising its level of protection — receives a reduced fine. On the other hand, a company that becomes aware of a breach and deliberately leaves it unaddressed faces an increased fine.
Under the current Personal Information Protection Act, an administrative fine is calculated within a ceiling of 3/100 of total turnover, excluding turnover unrelated to the violation. The reward-penalty framework means that, within that calculation, whether the company invested in prevention and whether it neglected the incident will be reflected in substance as grounds for mitigation or aggravation. Ordinary investment in security and data protection thus becomes a direct risk-management tool that determines the level of sanction when an incident occurs.
Furthermore, the PIPC has announced that from this coming September it will strengthen punitive fines against companies with serious or repeated violations (press reports refer to a raised turnover-based level). Conversely, incentives are planned for companies that report a breach diligently and respond early, and rewards for whistle-blowers who report violations in the public interest. Meanwhile the Ministry of Science and ICT is also pushing to strengthen fines against operators with repeated security incidents, so companies should be alert to a dual regulatory risk in which a single breach may trigger both a sanction under the Personal Information Protection Act and network security regulation.
▶ Card news summary Preventive investment earns a reduced fine; neglecting an incident earns an increased one. From September, serious or repeated violations face punitive fines, while diligent and early reporting earns incentives.
3. Special exception for original data in AI training — the “AX safe support framework”
The plan contains not only tighter regulation but also measures to support data utilisation. A special exception is being pursued that would allow, solely for AI development pursued for public-interest or social purposes, the use of original data that has not undergone pseudonymisation or anonymisation. The plan also proposes consolidating and reorganising the innovation-support schemes that have until now been operated separately into what is called the “AX safe support framework”.
The intent is to ease the bottleneck in securing training data during AI development. However, the exception is premised on a purpose limitation — “public-interest or social purpose” — and on certain safeguard requirements; it does not mean that every company will be free to use original data. Companies preparing AI or data businesses should examine closely, in advance, the scope and requirements of the exception and the safeguard obligations that come with it.
▶ Card news summary AI development for public-interest or social purposes gains a special exception for using original data. But the purpose limitation and safeguard requirements are preconditions, so not all use becomes free.
4. Shifting the burden of proof in damages — a changing landscape for breach litigation
The element with the greatest practical impact is the overhaul of the damages regime. In relation to damages arising from a breach, the PIPC is pursuing a reform of the statutory damages system under which the company itself would have to prove whether or not it is liable. At present, victims bear a heavy burden of proving the company’s intent or negligence, the loss, and causation, so claims often fail to translate into actual compensation. If the burden of proof shifts to the company, the structure changes to one in which the company must itself prove that “it was not at fault”.
Once the burden shifts, class disputes and damages claims surrounding breach incidents may increase sharply, and a company that cannot prove in litigation that it actually implemented safeguards will find it hard to escape liability. In addition, a plan to create an integrated fund financed in part by collected fines is under discussion, making the drive to improve the effectiveness of victim relief unmistakable. Ultimately, whether safeguards were implemented as a matter of routine — and how those records are managed — will determine the outcome of litigation.
▶ Card news summary The burden of proof in breach damages is expected to shift to companies. Because a company must itself prove “no fault”, it should prepare for a rise in class disputes.
5. What companies should check now
First, secure “documentary evidence” of preventive investment. To obtain mitigation under the reward-penalty linked fine system, a company must keep documents and records enabling it to prove after the fact its security system investment, appointment of a qualified CPO, and the establishment and implementation of an internal management plan. Second, review the CPO’s expertise and independence. As the CPO’s standing is strengthened — with qualified-CPO registration becoming mandatory in the public sector — private companies too need to overhaul the CPO’s qualifications, authority, and reporting lines.
Third, put in order the breach response system and the timing of notification. Since incentives are attached to diligent and early reporting while delay or concealment invites aggravation, companies should prepare in advance internal response procedures (the flow of detection, internal reporting, regulatory notification, and notice to data subjects) capable of meeting the statutory reporting deadline. Fourth, review the legality of AI and data use in advance; and fifth, continuously document the implementation of safeguards such as access control, encryption, and retention of access logs, in preparation for the shift in the burden of proof.
▶ Card news summary Evidence of preventive investment, CPO overhaul, a reporting system, review of the AI exception requirements, and records of safeguard implementation — these five are the key checkpoints.
Much of this second-half work plan will take concrete shape through future amendments to statutes and the reorganisation of public notices, so the final form of the fine ceiling or of the shift in the burden of proof may change during the legislative process. The direction of regulation, however, is clear. Personal data protection is no longer an after-the-fact risk of “being punished once an incident occurs”, but an object of continuous management in which “everyday investment and records determine the level of sanction and the liability for damages”. Investment in prevention, and the evidence of it, has become a company’s most reliable risk-management tool.
Cheongchul Law Firm advises on the full range of corporate privacy compliance — from responding to personal data breach incidents and defending against fines and administrative dispositions, to privacy impact assessments and the overhaul of internal management plans, building CPO frameworks, reviewing the legality of AI and data use, and handling personal data damages claims and class disputes. If you need to respond to these regulatory changes, please feel free to contact us.
Related work cases that are good to see together
서울 강남구 테헤란로 403 리치타워 7층
Tel. 02-6959-9936
Fax. 02-6959-9967
cheongchul@cheongchul.com
개인정보처리방침
면책공고
© 2025. Cheongchul. All rights reserved



