BKL Legal Update

2026.03.18

AMENDMENT TO THE IT NETWORK ACT: KEY CONTENTS AND IMPLICATIONS

I. BACKGROUND 

A series of large-scale hacking and data breach incidents has prompted the need to reexamine the overall information security framework. In particular, the current system operates on a structure where regulatory investigations are initiated only upon a report filed by the affected company, which has been criticized for delaying initial responses and allowing damage to spread.

Against this backdrop, amendments to the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (hereinafter the "IT Network Act") passed the National Assembly plenary session on March 12, 2026.

This amendment goes beyond simply reinforcing sanctions; it structurally overhauls the incident response framework while elevating information security to the level of corporate internal controls and management responsibility. It also strengthens sanctions on the transmission of commercial advertising messages, with a focus on preventing harm caused by illegal spam.


II. KEY AMENDMENTS 

A. Strengthening Corporate Internal Controls 

This amendment makes clear that information security is a matter of corporate governance and management responsibility.

  • CISO Qualification Restrictions and Expanded Authority/Responsibility: Telecommunications providers must designate an executive officer as Chief Information security Officer (CISO) (provided that CISO designation requirements for mid-sized enterprises will be prescribed by the Enforcement Decree). The CISO's duties include managing personnel and budgeting necessary for information security and reporting the status of information security and key matters to the board of directors (Draft Article 45-3).

  • Mandatory Establishment of an Information Security Committee: Telecommunications providers meeting certain criteria must establish and operate an Information Security Committee as a deliberative body on information security matters, with the CISO serving as its chairperson (Draft Article 45-4).


B. Reorganization of the Government's Supervisory Framework

This amendment simultaneously strengthens corporate internal controls and institutionally expands the government's ongoing supervisory functions.

  • Annual Information Security Level Assessment and Disclosure: The Minister of Science and ICT may annually evaluate telecommunications providers meeting certain criteria on their compliance with obligations under the IT Network Act and the level of stability and reliability of their networks, and may disclose the results on an internet website, among other methods. The Minister may request the submission of materials during the evaluation process and may recommend improvements for deficiencies identified through the evaluation. Entities receiving such improvement recommendations must submit the results of their remedial actions (Draft Article 45-5).

  • Tiered Application of ISMS Certification: Enhanced Information Security Management System (ISMS) certification standards and procedures may be applied to certain businesses, taking into account factors such as the scale of information generated and processed and the social impact thereof (Draft Article 47-7(2)).


C. Strengthened Notification, Investigation, and Sanctions Framework for Security Incidents

This amendment strengthens the responsibilities of telecommunications providers when security incidents occur.

  • User Notification Obligation: Telecommunications providers must promptly notify users when a security incident meeting certain criteria occurs (Draft Article 48-3(4)).

  • Expanded Grounds for Initiating Investigations and Establishment of a Deliberative Body: A Security Incident Investigation Deliberation Committee is newly established (Draft Article 48-2(7) and (8)). Investigations to analyze the occurrence and cause of a security incident and implement measures to prevent damage from spreading—or for the Minister of Science and ICT to order the implementation of such measures—may now be conducted not only when a security incident has occurred, but also when there are circumstances giving rise to a suspicion that one has occurred and the Security Incident Investigation Deliberation Committee recognizes the need for an investigation into whether one has in fact occurred (Draft Article 48-4(1) and (2)).

  • Introduction of Penalty Surcharges and Compulsory Performance Levies for Repeated Incidents: Where multiple security incidents occur within a five-year period due to the willful misconduct or gross negligence of a telecommunications provider, a penalty surcharge of up to 3% of revenue as prescribed by the Enforcement Decree may be imposed. Factors such as the number of incidents, the relevance to and scale of information leakage, the nature and scale of the business, and the extent of user harm must be considered (Draft Article 48-8) when imposing such a penalty. Additionally, for failure to submit or submission of false materials, obstruction of on-site inspections, or non-compliance with corrective orders during investigations, a renewed order with a compliance deadline may be issued, and failure to comply may result in compulsory performance levies of up to 0.03% of average daily revenue per day as prescribed by the Enforcement Decree, accruing from the day after the compliance deadline expires (Draft Article 48-7).


D. Strengthened Sanctions on Illegal Spam

In addition to provisions related to security incidents, this amendment strengthens transmission eligibility restrictions and sanctions to prevent illegal spam.

  • Restrictions on Outsourcing of the Electronic Transmission of Commercial Advertising Messages: When outsourcing the transmission of commercial advertising messages to services that send text messages by directly or indirectly connecting a text messaging system to telecommunications equipment (as specified by Article 2, subparagraph 14(b) of the Telecommunications Business Act), such outsourcing must be made only to entities that have obtained transmission eligibility certification from the Korea Media and Communications Commission pursuant to Article 22-11(1) of the Telecommunications Business Act (Draft Article 50-3(1)).

  • Introduction of Penalty Surcharges for Violations of Rules on the Electronic Transmission of Commercial Advertising Messages: Violations of rules governing the transmission of commercial advertising messages (such as Article 50 of the IT Network Act, which requires prior consent from recipients) may result in a penalty surcharge of up to 6% of revenue as prescribed by the Enforcement Decree (Draft Article 50-9(1)).


III. EFFECTIVE DATE AND IMPLICATIONS

This amendment will, in principle, take effect six months after promulgation. However, the periodic evaluation system for information security levels (Draft Article 45-5) and the related administrative fine provisions (Draft Article 76(2), subparagraph 6-8) will take effect one year after promulgation (Addendum Article 1).

Given the six-month lead time before the amendment takes effect, companies should proactively overhaul their internal control systems and security incident response manuals within that period, and should be aware that compulsory performance levy provisions, among others, may be applied during investigations after the amended law takes effect.

Bae, Kim & Lee LLC will continue to monitor the process of amending the Enforcement Decree and developing detailed standards in connection with this amendment to the IT Network Act, as well as corporate needs, and will provide tailored advice and optimal response strategies considering the specific circumstances.


*    *    *


For any inquiry or questions regarding the content of this newsletter, please contact us. 

 

[Korean version]

  • This update is intended as a summary news report only, and not as advice. For legal advice, please inquire with your contact at Bae, Kim & Lee LLC, or the authors of this legal update.