Personal Information Protection Act Violation Lawyer | What to do when a data incident becomes a legal case
Summary
A violation of the Personal Information Protection Act (개인정보 보호법) rarely stays in one lane. The PIPC can impose administrative fines and corrective orders on a company for a data breach or unlawful processing, while the same conduct can simultaneously be referred to police or prosecutors as a criminal matter against the individuals responsible (개인정보 보호법 제71조부터 제75조까지). Many people first learn they are a target when they receive a request for a written statement from PIPC or an attendance notice from a police cyber investigation unit, not a formal indictment. Understanding which provisions apply to your specific conduct — negligent leakage versus intentional misuse, for example — determines whether you are facing a fine, a criminal record, or both.
Criminal · AdministrativeGoverning law: Personal Information Protection Act (개인정보 보호법)PIPC investigationCorporate & individual liability
Personal Information Protection Act Violation | Why one incident can mean two separate cases
The Act splits sanctions into administrative fines handled by the PIPC and criminal penalties handled by the courts. These two tracks run on different standards of proof and different timelines, and a favorable outcome in one does not automatically resolve the other.
Administrative fines (과태료/과징금)
The PIPC can levy a 과태료 for procedural violations such as failing to obtain proper consent or not appointing a data protection officer, and a separate, often much larger 과징금 for unlawful use or disclosure of personal data, calculated with reference to related sales revenue (개인정보 보호법 제64조의2). These are civil-administrative in nature, so there is no criminal record even if imposed, but the amounts can be substantial for a company handling large volumes of data.
Criminal penalties (형사처벌)
Separately, provisions such as Articles 71 through 73 impose imprisonment or criminal fines for specific acts — for example, processing sensitive information without consent, providing personal data to a third party without authorization, or failing to take required security measures resulting in a leak (개인정보 보호법 제71조, 제73조). Whether a given incident is treated as criminal often turns on intent, the sensitivity of the data, and whether harm actually resulted.
Why coordination between the two matters
Statements made to PIPC investigators during the administrative inquiry can later surface in a parallel police or prosecutorial investigation. Treating a PIPC written-statement request as a low-stakes formality, when in fact a criminal referral is being considered in parallel, is one of the more common mistakes we see.
Personal Information Protection Act Violation | Breach notification duties and how failing them adds exposure
Beyond the underlying data mishandling, the Act imposes its own notification and reporting duties once a leak is discovered, and failing to meet those duties is a separate source of liability layered on top of the original incident.
Notice to affected individuals
Once a personal data controller becomes aware of a leak, it must notify the affected individuals of what happened, what data was involved, and what measures are being taken, without undue delay (개인정보 보호법 제34조). Delay in notification, even where the underlying leak was accidental, can itself be treated as an aggravating factor in a PIPC sanction.
Reporting to the PIPC or KISA
Depending on the scale of the breach, the controller may also be required to report the incident to the PIPC or the Korea Internet & Security Agency. How and when this report was filed is frequently the first thing an investigator checks, because it establishes the timeline against which the company's later conduct is measured.
Internal investigation before external disclosure
Before any public notice or regulator report goes out, it is worth conducting an internal fact-finding review — what data was actually exposed, how, and to whom — since the content of that first notification is difficult to walk back later and inconsistent statements between the notice, the regulator report, and later investigation testimony create their own legal risk.
Personal Information Protection Act Violation | Which acts actually carry criminal, not just administrative, risk
Not every data-handling mistake is a crime. Criminal liability under the Act generally attaches to intentional or grossly negligent acts involving unauthorized collection, use, provision to third parties, or destruction of personal data, rather than to every technical compliance gap.
Unauthorized provision to a third party
Providing personal data to a third party beyond the scope of the original consent, or receiving such data knowing it was unlawfully provided, is one of the most commonly prosecuted acts under the Act (개인정보 보호법 제71조 제1호, 제17조). This covers situations ranging from an employee selling customer lists to a company sharing user data with an affiliate without proper consent.
Processing sensitive or unique identifying information without a legal basis
Health information, political views, and resident registration numbers receive heightened protection, and processing them without a specific statutory basis or separate consent carries its own criminal exposure distinct from ordinary personal data (개인정보 보호법 제23조, 제24조). Small businesses that casually collect resident registration numbers for membership sign-up are a recurring example.
Failure to take security measures leading to a leak
Where a controller failed to implement the technical and administrative safeguards required by law and that failure caused a leak, criminal liability can attach even without any intent to misuse the data (개인정보 보호법 제73조 제1호, 제29조). The defense here typically focuses on whether the specific safeguard alleged to be missing was actually required for the type and volume of data at issue.
Personal Information Protection Act Violation | Company, executive, or employee — who bears the liability
A PIPA case rarely targets only the company. The Act's joint penalty provision can reach the business owner or representative even for acts committed by an employee, unless the company can show it exercised reasonable supervision.
The joint penalty clause for business owners
Where an employee or agent commits a violation in the course of performing duties for the business, the Act allows a fine to be imposed on the business owner as well, unless the owner proves that reasonable care and supervision was exercised to prevent the violation (개인정보 보호법 제74조). This 양벌규정 structure means a company's compliance record — training logs, access control policies, audit history — becomes central defense evidence, not just paperwork.
Individual employees facing personal exposure
An employee who personally accessed, copied, or transmitted data outside their authorized scope can be prosecuted individually regardless of what happens to the company, particularly where the act was for personal gain such as selling customer information. Whether the employee acted within the scope of assigned duties, and whether the company's internal system permitted or should have prevented the access, is often the central factual dispute.
Third-party processors and outsourcing arrangements
A company that outsources data processing to a vendor is not automatically shielded if the vendor mishandles the data; the outsourcing company retains supervisory obligations under the Act (개인정보 보호법 제26조). Disputes over which party bears responsibility for a breach often hinge on the specific contractual terms and whether contractual oversight duties were actually performed.
Personal Information Protection Act Violation | From incident to resolution
1
Initial contact and internal fact review Whether the trigger is a self-discovered leak, a user complaint, or a PIPC/KISA inquiry, the first step is establishing exactly what happened before any statement is given to a regulator or investigator.
2
Statutory notification and reporting Where required, notice to affected individuals and reports to the PIPC or KISA are prepared and filed within the applicable timeframe, coordinated with legal review to avoid inconsistent statements later.
3
PIPC fact-finding and hearing The PIPC investigates through document requests and on-site inspection, and before imposing a 과징금 or 과태료, gives the party subject to sanction an opportunity to submit an opinion or attend a hearing (개인정보 보호법 제64조).
4
Parallel criminal referral, if any If the PIPC or police determine a criminal provision may have been violated, the matter is referred for investigation separately from the administrative sanction, and the individual may be summoned for questioning as a suspect.
5
Administrative appeal or criminal defense proceedings A PIPC fine can be challenged through an administrative appeal or lawsuit, while a criminal referral proceeds through police and prosecutorial investigation toward a decision on indictment, each requiring separate strategy.
Personal Information Protection Act Violation | How fees are typically calculated
Case complexity Fees generally reflect whether the matter involves only a PIPC administrative fine review, or a parallel criminal investigation as well, since the latter requires additional preparation for police or prosecutor interviews.
Scope of representation Representing a company at the PIPC fact-finding and hearing stage is priced differently from representing an individual employee or executive facing personal criminal exposure, and fees are structured accordingly when both are involved.
Administrative appeal or litigation If a PIPC decision is challenged through an administrative appeal or an administrative lawsuit seeking to reduce or cancel a fine, this is generally billed as a distinct stage from the initial investigation representation.
Disbursements Costs such as expert review of technical logs, document translation, or forensic analysis of the data incident are billed separately as actual expenses incurred.
※ Costs vary depending on case complexity and specific circumstances; exact fees will be provided during consultation. No specific outcome is guaranteed.
Personal Information Protection Act Violation | Self-Check Before You Respond
1️⃣ If You Just Discovered a Data Leak
Have you identified exactly which data fields and how many individuals were affected?
Has more than a few days passed since discovery without notifying affected individuals?
Have you determined whether this incident meets the threshold requiring a report to the PIPC or KISA?
Have employees been instructed not to alter or delete relevant logs before they are reviewed?
2️⃣ If You Received a PIPC Document Request or Attendance Notice
Does the notice specify whether you are being asked to respond as the company or as an individual?
Have you reviewed what documents or logs are being requested before submitting anything?
Is there a deadline stated on the notice, and have you calendared it?
Have you considered whether your response could later be used in a separate criminal referral?
3️⃣ If You Are a Business Owner or Executive
Can you show documented employee training and access-control policies predating the incident?
Was the employee involved acting within the scope of assigned duties, or outside it?
Do you have records of prior audits or compliance reviews relevant to the alleged violation?
4️⃣ If You Are an Individual Employee Under Investigation
Did your access to the data fall within your authorized job function?
Do you have a record of instructions or approvals for the action being questioned?
Have you been asked to attend as a witness, or explicitly as a suspect?
Frequently Asked Questions
Q. What is the difference between a 과태료 and a 과징금 under the Personal Information Protection Act?
A. A 과태료 is a smaller administrative fine typically imposed for procedural failures, such as not obtaining proper consent forms or failing to designate a data protection officer. A 과징금 is imposed for substantive violations like unlawful use or third-party disclosure of personal data and can be calculated based on related sales revenue, making it potentially far larger (개인정보 보호법 제64조의2).
Q. Can I be criminally prosecuted even though the leak was accidental and not intentional?
A. Yes, in some circumstances. Certain provisions attach criminal liability where a controller failed to implement required security safeguards and that failure resulted in a leak, even without intent to misuse the data (개인정보 보호법 제73조 제1호). Whether prosecution actually follows often depends on the scale of harm and whether the missing safeguard was clearly required for the data involved.
Q. If the PIPC only issues a corrective order, does that mean there is no criminal risk?
A. Not necessarily. A corrective order or fine from the PIPC addresses the administrative side of the case, but police or prosecutors can independently open a criminal investigation into the same underlying conduct. The two processes are legally separate even when they arise from the same incident.
Q. Can my company be punished for something an employee did without my knowledge?
A. Under the joint penalty provision, a business owner can face a fine for an employee's violation committed in the course of work duties, unless the company demonstrates it exercised reasonable care and supervision to prevent it (개인정보 보호법 제74조). This is why documented training and access-control records matter even if management had no direct knowledge of the specific act.
Q. How long do I have to notify customers after discovering a data breach?
A. The Act requires notification to affected individuals without undue delay once the leak becomes known, though the exact expected timeframe depends on the circumstances and scale of the incident (개인정보 보호법 제34조). Waiting an extended period without a clear justification can itself become a point of criticism in a later PIPC review.
Q. Is receiving personal data that was unlawfully collected also a violation, even if I didn't collect it myself?
A. Yes. The Act penalizes not only the party who unlawfully provides personal data to a third party but also, in certain cases, a recipient who receives it knowing it was unlawfully provided (개인정보 보호법 제71조 제1호). This is relevant for companies that purchase marketing lists or receive customer data from business partners.
Q. Can I appeal a PIPC fine, and does appealing stop the fine from being enforced?
A. A PIPC fine decision can be challenged through an administrative appeal or an administrative lawsuit seeking cancellation or reduction, but filing an appeal does not automatically suspend enforcement unless a separate stay of execution is granted. Whether to seek a stay is a strategic decision made based on the specific fine amount and grounds for appeal.
Q. What should I do if I receive a request to submit a written statement from PIPC?
A. Treat it seriously even though it may look like routine paperwork, because statements made at this stage can later be referenced in a parallel criminal investigation. Reviewing exactly what is being asked and what documents support your position before responding is generally advisable rather than submitting a hurried reply.
Q. Does it matter whether the data that leaked was sensitive information like health records versus ordinary contact information?
A. Yes. Sensitive information and unique identifiers such as resident registration numbers carry heightened protection and separate statutory bases are required for their processing, so a leak involving this category of data tends to draw more serious administrative and criminal scrutiny than a leak of ordinary contact details (개인정보 보호법 제23조, 제24조).
Q. If I am an employee being questioned, should I attend the PIPC or police interview alone?
A. Whether to attend with counsel depends on whether you are being treated as a witness or a suspect, and on how the underlying facts might expose you individually versus the company. Clarifying your status before the interview, rather than during it, generally allows for better preparation.
법무법인 프런티어(이하 “사무소”)는 개인정보보호법에 따라 정보주체의 개인정보 및 권익을 보호하고 개인정보와 관련된 정보주체의 고충을 신속하고 원활하게 처리하기 위하여 본 개인정보 처리방침을 수립·공개합니다.
제 1 조 수집하는 개인정보의 항목, 목적, 방법
제 2 조 개인정보의 처리 및 보유기간
제 3 조 개인정보의 제3자 제공
제 4 조 개인정보 처리업무의 위탁
제 5 조 정보주체의 권리·의무 및 그 행사방법
제 6 조 개인정보의 파기
제 7 조 의견수렴 및 불만처리
제 8 조 개인정보 처리방침의 변경
제 9 조 개인정보의 안전성 확보 조치
제 1 조 (수집하는 개인정보의 항목, 목적, 방법)
① 게시판 글 작성 시 필수 항목에 대한 수집목적은 ‘별도의 구체적 상담을 위하여’이며 수집항목은 ‘이름, 이메일, 연락처’입니다.
② 전항 외에 고객의 서비스 이용 과정이나 요청 사항 처리 과정에서 ‘IP주소, 접속로그, 단말기 및 환경정보, 서비스 이용기록, 쿠키’와 같은 정보들이 자동으로 수집 및 저장될 수 있으며, 이 때의 수집목적은 ‘사용자 홈페이지 이용, 사이트 이용에 대한 문의 민원 등 고객 고충 처리’입니다.
③ 사무소는 ‘홈페이지 고객 문의/고충 처리 시 전화 또는 인터넷을 통한 상담’과 같은 방법으로 개인정보를 수집합니다
제 2 조 (개인정보의 처리 및 보유기간)
관계법령의 규정에 따라 개인정보를 보존하여야 하는 의무가 있는 경우가 아닌 한, 정보주체의 개인정보는 원칙적으로 해당 개인정보의 처리목적이 달성될 때까지 보유 및 이용되며, 그 목적이 달성되면 지체 없이 파기됩니다.
제 3 조 (개인정보의 제3자 제공)
사무소는 정보주체의 개인정보를 본 처리방침에서 명시한 목적에 한해서만 처리하며 정보주체의 사전동의가 있는 경우 또는 개인정보보호법 등 관계법령의 규정에 의거한 경우에만 개인정보를 제3자에게 제공합니다. 사무소는 현재 개인정보를 제3자에게 제공하지 않고 있습니다.
제 4 조 (개인정보 처리업무의 위탁)
사무소는 현재 귀하의 개인정보 보호를 위해 귀하의 개인정보를 직접 취급 관리하고 있습니다. 단, 향후 보다 전문적인 서비스를 제공하기 위하여 제3의 전문기관에 귀하의 정보를 위탁할 필요가 있다고 판단되는 경우, 귀하의 사전 동의 하에 개인정보에 대한 취급을 위탁할 수 있습니다.
제 5 조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 개인정보보호법 등 관계법령이 정하는 바에 따라 사무소에 대해 개인정보의 열람, 정정 및 삭제, 처리정지 요구 등 개인정보 보호 관련 권리를 행사할 수 있습니다.
② 제1항에 따른 권리행사는 정보주체의 법정대리인이나 위임을 받은 사람을 통해서도 할 수 있습니다. 다만, 이 경우에는 개인정보보호법 시행규칙에 따른 위임장을 사무소에 제출하여야 합니다.
③ 사무소는 정보주체의 권리행사에 대하여 개인정보보호법 등 관계법령이 정하는 바에 따라 지체 없이 조치하겠습니다.
제 6 조 (개인정보의 파기)
① 사무소는 원칙적으로 개인정보의 처리목적이 달성된 경우 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
② 사무소가 관계법령의 규정에 따라 개인정보를 파기하지 아니하고 보존하여야 하는 경우에는 해당 개인정보 또는 개인정보파일을 다른 개인정보와 분리해서 저장·관리 합니다.
③ 사무소는 파기사유가 발생한 개인정보를 선정하여 개인정보 보호책임자의 승인을 받아 해당 개인정보를 파기합니다.
④ 사무소는 파기하여야 할 개인정보가 전자적 파일 형태인 경우 복원이 불가능한 방법으로 영구 삭제하며, 이외의 기록물, 인쇄물, 서면, 그 밖의 기록매체인 경우 파쇄 또는 소각합니다.
제 7 조 (의견수렴 및 불만처리)
정보주체는 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 아래 개인정보 보호책임자 또는 담당부서에 문의하실 수 있습니다. 사무소는 정보주체의 문의에 대하여 신속하고 충분한 답변을 드릴 것입니다.
개인정보 보호 책임자 : 변호사
연락처 : 02.
제 8 조 (개인정보 처리방침의 변경)
사무소의 개인정보 처리방침은 관련 법령, 지침 및 사무소 내부규정에 따라 변경될 수 있으며, 개인정보 처리방침이 변경되는 경우 관련 법령이 정하는 방법에 따라 공개합니다.
제 9 조 (개인정보의 안전성 확보 조치)
사무소는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
관리적 조치 : 내부관리계획의 수립 및 시행, 구성원에 대한 정기적인 개인정보 보호교육 등
기술적 조치 : 개인정보처리시스템 등의 접근권한 관리, 접근통제시스템 설치, 고유식별정보 등의 암호화, 보안프로그램의 설치 등
물리적 조치 : 전산실, 자료보관실 등 개인정보 보관장소에 대한 접근통제