Compliance

Korea’s PIPA: multiple lawful grounds and strict consent rules.

PIPA Article 15 provides several grounds for processing personal information. Where a controller relies on consent, the information and separation requirements are strict, and the PIPC has brought fact-specific enforcement actions involving behavioural advertising.

Law
Personal Information Protection Act
Detected as
PIPA
Regulator
PIPC
Default model
Opt-in

What each region profile resolves to

Region profileResolved modelWhat the visitor sees
Regional defaultsopt-inNothing optional loads until a choice is made
Global strictopt-inNothing optional loads until a choice is made, everywhere
Global balancedopt-inNothing optional loads until a choice is made
EU and UK opt-innoneNo banner

KR is in the engine’s opt-in set. That is a conservative product choice for optional website technologies, not a claim that Article 15 permits processing only with consent. Global strict gives every visitor the same per-category structure where that operational simplicity suits the property.

Configuring for Korea

  • Add ko to the property translations, including the category labels and descriptions rather than just the buttons
  • Keep categories granular. Custom purposes carry their own keys and their own stored decisions, which is closer to the separate-consent structure than one broad marketing bucket
  • State retention. PIPA expects the retention period to be part of what the individual is told; the property’s consent duration and your own data retention both belong in the privacy notice
  • Make refusal consequence-free. Necessary technologies stay active; nothing else should degrade the service when it is refused

Penalty provisions depend on the contravention. Amendments effective in September 2026 introduced an administrative surcharge of up to 10% of annual turnover for repeated or severe personal-data breaches, with revenue unrelated to the violation excluded from the calculation. Other PIPA violations use different penalty provisions, and defined conduct can also carry criminal liability; do not present 10% as a universal ceiling for every contravention.

This is a product reference, not legal advice

It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.

Common questions

Does PIPA require consent before setting cookies?

Not as a universal cookie rule. If a cookie or related processing handles personal information, the controller needs a valid Article 15 ground and must meet the corresponding transparency and other requirements. Consent is often the conservative approach for optional advertising and cross-service profiling, but the answer is purpose- and configuration-specific.

What is the separate-consent rule?

Consent for optional collection must be obtained separately from consent for what is necessary to provide the service, and refusing the optional part cannot be grounds to refuse the service. Per-category choices in a preference centre reflect that structure directly.

Does a Korean-language banner matter?

Yes. Consent is only valid if the individual was told the purposes, items, retention and right to refuse in a way they can understand. Translate the categories and their descriptions, not only the button labels.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.