Republic of Korea: President signed Bill amending Network Act including incident response obligations and enforcement measures

Description

President signed Bill amending Network Act including incident response obligations and enforcement measures

On 31 March 2026, the President of Korea promulgated the Act on Promotion of Information and Communications Network Utilization and Information Protection as Law No. 21500. The Bill includes provisions on incident response and enforcement. It applies to information and communications service providers, including major providers and colocation facility operators. The Bill introduces obligations to designate a Chief Information Security Officer, establish an Information Security Committee, and undergo annual government evaluations of network stability and reliability, as well as compliance with statutory requirements. The Bill also requires providers to report cybersecurity incidents within 24 hours of becoming aware of them and to notify affected users without delay. In addition, it provides for enforcement levies in cases of non-compliance and penalty surcharges of up to 3% of revenue for repeated incidents resulting from intent or gross negligence. Further provisions require providers to prepare and submit cybersecurity incident management and response manuals and to implement measures aimed at addressing user harm. The main provisions of the Act will enter into force on 1 October 2026. The Information Security Level Evaluation obligations will enter into force on 1 April 2027.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2025-11-24
under deliberation

On 24 November 2025, a Bill amending the Network Act was introduced to the National Assembly. The B…

2026-03-20
adopted

On 20 March 2026, the Bill amending the Network Act, including incident response obligations and en…

2026-03-31
adopted

On 31 March 2026, the President of Korea promulgated the Act on Promotion of Information and Commun…

2026-10-01
in grace period

On 1 October 2026, the incident response, user notification, and organisational obligations in the …

2027-04-01
in force

On 1 April 2027, the Information Security Level Evaluation obligations in the Act on Promotion of I…