On March 12, 2026, the National Assembly passed an amendment to the Act on Promotion of Information and Communications Network Utilization and Information Protection (“Network Act”), and an amendment to the Telecommunications Business Act (“TBA”). These amendments follow several instances of large-scale cyberattacks and data breach incidents that occurred throughout 2025, and the Korean government’s October 22, 2025 announcement of the Comprehensive Information Security Measures, a government policy that was developed to enhance Korea’s information security infrastructure and establish a rapid response system to cybersecurity incidents.
The main provisions of the amendment to the Network Act include the following.
|
1. |
Major changes to post-incident response requirements, sanctions and remedies |
|
2. |
Strengthening of information security governance and internal management framework |
|
3. |
Enhancement of government-led management and supervision frameworks, and certification frameworks |
The main provisions of the amendment to the TBA include the following:
(i) The amendment reassigned the government agency responsible for evaluating user protection as related to security incidents from the Korea Media and Communications Commission to the MSIT (Amended TBA, Article 32(2)).
(ii) The amendment requires facilities-based telecommunications service providers and value-added telecommunications service providers that include online service providers to 1) prepare and implement user protection manuals, 2) establish measures for responding to security incidents, including facilitating transfers of membership/plans and handling termination of membership/plans. Furthermore, the amendment created a new legal basis that can be used by the MSIT to mandate user protection measures, including the provisions of certain supplementary services, in urgent cases.
Overall, the amended Network Act and the amended TBA expand the investigative powers of the government, strengthens the CISO’s roles and responsibilities, establishes new legal bases for imposing administrative fines and enforcement penalties, and emphasizes the business entities’ roles and responsibilities regarding information security. As the government is expected to introduce additional regulations, business entities may want to conduct a review of their information security management systems and enhance their information security compliance systems.




