skip to main content skip to main menu

Government Legislation

  • [IT & IPR] Draft Amendment to the Enforcement Decree of the Personal Information Protection Act
    • Competent Ministry : Personal Information Protection Commission
    • Advance Publication of Legislation : 2026-06-01
    • Opinion Submission Deadline : 2026-07-13

[Background] 

Background

- The Personal Information and Information Security Management System certification (ISMS-P certification) is a system that certifies whether a series of measures regarding the processing and protection of personal information by a personal information controller comply with the Personal Information Protection Act, among other things, and is operated for purposes such as improving security levels and preventing accidents.
- Despite the positive effects of ISMS-P certification, obtaining the certification has been left to the discretion of institutions and enterprises, raising concerns about potential gaps in the management system for core infrastructure, such as large-scale personal information processing.
- Accordingly, a public consensus was formed on the need to strengthen the certification system, leading to an amendment to the Personal Information Protection Act (promulgated on Mar 10, 2026, enforcing on Jul 1, 2027) to mandate ISMS-P certification for personal information controllers meeting certain criteria, taking into account sales revenue, scale of personal information processing, etc.


Need for Government Intervention

- As the scope of entities subject to mandatory ISMS-P certification—taking into account sales revenue, scale of personal information processing, etc.—is delegated to be set via the Enforcement Decree (proviso to Article 32-2, Paragraph 1 of the Personal Information Protection Act), it is necessary to define and specify these standards in detail.
- Considering that ISMS-P certification is changing from voluntary acquisition to partially mandatory acquisition, and that there is a need to minimize burdens and confusion for institutions and enterprises due to the implementation of mandatory certification to promote the early settlement of the revised system, it is necessary for the government to establish reasonable standards.


[Regulatory Details] 

Mandating ISMS-P certification for critical public and private personal information processing systems in consideration of the characteristics and scale of personal information, sales revenue, etc. (Newly adding Article 34-9 of the Enforcement Decree of the Personal Information Protection Act)

- Entities subject to the obligation are broadly divided into four categories: ① operators of major public systems, ② mobile telecommunications business operators, ③ identity verification agencies, and ④ large-scale personal information controllers considering sales revenue and the number of processed personal information items.
Regulatory effect assessment
Legislative proposal (draft)