Privacy responsibilities need a route to management decisions about people, systems and budgets. A named privacy contact is useful only when concerns can reach someone able to act.
The development
Main commencement: 11 September 2026; certification provisions: 1 July 2027
PIPC’s announcement sets 11 September 2026 for the main PIPA amendments, strengthening breach accountability and CEO/CPO responsibilities. Mandatory ISMS-P certification provisions have a separate 1 July 2027 date. Certification scope depends on the implementing rules; do not assume every SME must certify.
Connect incident response to business decisions
Use the change as a prompt to test how privacy issues reach decision-makers. Who can approve access restrictions, fund a supplier change or resolve disagreement about an unsafe process? An organisation chart should be supported by a working escalation route and records of decisions.
Actions to consider
- Confirm who owns privacy decisions and who substitutes when that person is unavailable.
- Review how the privacy lead reports unresolved risks to management.
- Link the incident response process to decision authority and available resources.
- Keep records of prevention work, follow-up actions and management review.
- Assess Korean applicability and any certification requirements against the current implementing rules.
Scope and timing
The source linked below is PIPC’s English translation of its Korean announcement. Use the Korean legislation and current implementing rules for an applicability decision. The certification date is separate from the main amendment date.
What to prepare
A documented escalation route, a management review record and an action register with named owners and follow-up dates.
Official sources
General information, not a determination of your organisation’s legal obligations. The actions are Averisdata’s practical suggestions; check the cited rules against your circumstances.