South Korea proposes stricter ISMS-P reviews, one-year grace period on fines
( September 16, 2026, 04:03 GMT | Official Statement) -- MLex Summary: South Korea’s privacy regulator has proposed changes to the enforcement decree of the Personal Information Protection Act to strengthen the effectiveness of the country’s ISMS-P certification regime, with the proposal open for public consultation through Oct. 26. The Personal Information Protection Commission said Wednesday the amendments would clarify that document and onsite reviews may be conducted together and allow qualified technical personnel to carry out vulnerability assessments and penetration testing in certain cases, including after data breaches. The proposal would also provide a clearer basis for applying different certification standards depending on factors such as the scale of personal-data processing and potential social impact. Companies subject to mandatory certification whose certification is revoked would also receive a one-year grace period before fines for failing to hold certification would apply, except where certification was obtained fraudulently.Statement is attached (in Korean)....
Prepare for tomorrow’s regulatory change, today
MLex identifies risk to business wherever it emerges, with specialist reporters across the globe providing exclusive news and deep-dive analysis on the proposals, probes, enforcement actions and rulings that matter to your organization and clients, now and in the longer term.
Know what others in the room don’t, with features including:
- Daily newsletters for Antitrust, M&A, Trade, Data Privacy & Security, Technology, AI and more
- Custom alerts on specific filters including geographies, industries, topics and companies to suit your practice needs
- Predictive analysis from expert journalists across North America, the UK and Europe, Latin America and Asia-Pacific
- Curated case files bringing together news, analysis and source documents in a single timeline
Experience MLex today with a 14-day free trial.