GlobalOS
Regional Deep Dive/APAC

Tax & Regulatory // South Korea

Entity type: Yuhan Hoesa (YH) or Jusik Hoesa (JH)

High Complexity

Core Compliance

Corporate Tax
9–24%
Tiered: 9% up to ₩200M, 19% up to ₩20B, 24% above — relatively progressive
VAT
10%
Standard rate; electronic services to KR consumers require VAT registration even for foreign companies (simplified VAT).
PIPA Penalty
Up to 3% of revenue
Personal Information Protection Act penalties based on relevant revenue — among strictest in APAC.

Regulatory Vectors

PIPA Compliance
REQUIRED
urgent

Personal Information Protection Act is actively enforced. Requires: separate privacy consent, data processing records, DPO appointment for large processors, KR-language privacy policy, and breach notification within 72 hours. Get certified early.

KISA Security Assessment
CONDITIONAL
watch

Korea Internet & Security Agency (KISA) assessments may be required for information and communication services. Relevant for cloud service providers.

Data Residency
SECTOR-SPECIFIC
watch

KR financial data and certain personal data types require domestic storage. Financial sector (FSS/FSC) has strong data localisation expectations.

FSS / FSC Licensing (fintech)
REQUIRED for finance
urgent

Financial Supervisory Service and Financial Services Commission regulate all financial activities. Fintech licensing is a complex, multi-year process.

Key Legislation

Personal Information Protection Act (PIPA)

South Korea's primary data privacy law — comprehensively covers collection, processing, and transfer of personal data.

Act on Promotion of IT Network Utilization

Governs online privacy and information security for IT service providers.

Electronic Financial Transactions Act

Governs digital payments and electronic financial services.

Entry Recommendation

PIPA compliance is the first gate before any KR enterprise conversation. Invest in a KR-language privacy policy, documented consent flows, and breach notification procedures. Engage a Seoul-based data privacy lawyer. The PIPA certification signals seriousness to enterprise buyers.

Regulatory Flashpoints — Evidence Base

Primary regulatory flashpoint
confidence 40

PIPA compliance on data processing and protection duties.

Needs human review