Privacy
South Korea's 10% Privacy Fine Regime Starts as Musk PAC Sells Voter Data
Korea's amended PIPA takes effect with the world's highest fine ceiling, while Musk's America PAC quietly expands what it can do with VoteSafe users' data.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
South Korea’s Amended PIPA Takes Effect With 10% Global Revenue Fines and CEO Liability
South Korea’s amended Personal Information Protection Act, promulgated March 10, 2026 as Act No. 21445, took effect September 11, 2026, creating the first explicit legal framework in any national data protection law for training AI systems on personal data. The amendment triples the maximum fine ceiling and establishes a two-tier penalty structure: a baseline administrative fine of up to 3% of revenue related to a violation for standard cases, and an elevated tier of up to 10% of a company’s total global annual revenue when at least one aggravating factor is present. Those factors include a violation repeated within three years involving intentional or grossly negligent conduct, a single incident affecting 10 million or more individuals under the same conditions, or a breach occurring after a company has already failed to comply with a formal PIPC corrective order. The 10% ceiling exceeds the EU GDPR’s 4% and the EU AI Act’s 7%, making it the highest national penalty ceiling in the world by that metric. The Personal Information Protection Commission has framed the escalation as a deterrence recalibration rather than punishment escalation, and companies documenting verified investment in privacy can qualify for fine reductions of up to 40%.
The amended law designates the CEO, business owner, or representative as the ultimate responsible person for data protection compliance. For large organizations meeting criteria to be specified in a Presidential Decree, appointment and dismissal of a Chief Privacy Officer must be approved by the board of directors and formally reported to the PIPC, and the CPO must secure an adequate budget and report directly to the CEO and board. Available surveys indicate roughly 70% of organizations in South Korea have one or fewer dedicated privacy staff. The PIPC’s three-tier classification of AI adoption sets obligations by tier: service-based adoption through a third-party API requires input filtering to prevent personal data from flowing into external model prompts and management of cross-border transfer rules; fine-tuning or retrieval-augmented generation on proprietary data requires a specific legal basis and management of the risk that personal data could resurface in model outputs; and self-developed models require the ability to reconstruct the origin, consent history, and pseudonymization record of every piece of training data. Article 28-2 permits processing of pseudonymized data without individual consent for statistical compilation, scientific research, and archiving in the public interest, and PIPC guidance signals that AI model training can qualify as scientific research if the methodology has genuine research characteristics. That exemption applies to training and analysis only; deployment in live service that could re-identify a specific individual requires a separate legal basis, and training-stage and service-stage legal bases must be documented as separate records.
Two additional provisions took effect September 11. The breach notification trigger moves earlier, requiring notification before a breach is confirmed as soon as a reasonable likelihood exists, and the scope of notifiable events expands to include forgery, alteration, and destruction of personal data, bringing ransomware and data-corruption attacks within the law’s reach. Mandatory ISMS-P certification, previously voluntary, becomes mandatory for large data controllers beginning July 1, 2027. PIPA applies extraterritorially to foreign operators providing goods or services to Korean data subjects or whose processing substantially affects them, and foreign operators must designate a domestic representative in South Korea, an obligation strengthened effective October 2, 2025. The 10% fine ceiling and CEO accountability provision apply to total global revenue, not Korean-derived revenue alone. A further PIPA amendment, draft Articles 28-12 through 28-15, was approved by the National Assembly’s Political Affairs Committee on May 14, 2026, and cleared by the Legislation and Judiciary Committee on July 29, 2026 with bipartisan support; it would allow lawfully collected personal data, original and non-pseudonymized, to be used for AI development without the data subject’s consent, subject to case-by-case PIPC approval. Kyoungsic Min, privacy counsel and Asia regional lead at VeraSafe, has said the bill relocates the decision about whether personal data can be used in AI training from accountable controllers operating within enforceable rules to the regulator itself on a case-by-case basis, raising the question of who supervises the supervisor.
Korea PIPA Takes Effect Tomorrow: World’s First AI Training Data Law Is Now Enforceable →
Musk’s America PAC Expands Data Sharing From VoteSafe Registration Tool
Elon Musk’s America PAC is promoting VoteSafe.org as a tool to help people check their voter registration, but using the site can give the political group access to far more information than whether someone is registered to vote. Journalist Judd Legum, author of the political newsletter Popular Information, reported on Tuesday, September 8, that VoteSafe.org collects users’ names, birth dates, full home addresses, email addresses, cellphone numbers, IP addresses and location data. The site also collects information about users’ activity, including the pages they view and links they click. Their voter registration status, which VoteSafe warns may not necessarily be accurate, is derived from a voter file held by America PAC or its vendors rather than directly from state election records.
The site’s privacy policy was updated August 29. The previous policy prohibited America PAC from sharing the information with advertisers, political organizations or unaffiliated third parties. The updated policy says America PAC may share or sell personal information to business partners, including information about whether someone is registered to vote and, where permitted by law, how you submit your vote. The policy also allows America PAC to sell inferences about users, including information about their psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitude. VoteSafe’s business partners include Facebook, Google, X, advertising firm The Trade Desk, tracking company Increment Data and marketing company Iterable.
America PAC spent more than $180,000 promoting VoteSafe on Meta in the week before Legum’s report was published. The PAC spent about $800,000 on similar digital advertising during the 2024 presidential election, with some users in battleground states providing their information without being directed to an actual voter registration page. Musk has pledged to spend more than $100 million on the 2026 midterms, making the data practices behind VoteSafe a significant privacy question as the midterm cycle accelerates.
Elon Musk Is Collecting Voters’ Personal Data Ahead Of Midterms →
Austrian Activist Sues EU Data Protection Supervisor Over Europol Records
An Austrian national, Natalie Gruber, has filed a case at the EU General Court against the European Data Protection Supervisor, accusing the EU’s data protection watchdog of shielding Europol and failing to protect her rights. Gruber documented fundamental rights violations against migrants in Greece through her now-disbanded organisation Josoor. She is represented by Iftach Cohen, a lawyer at Front-lex, a Dutch-based civil society organisation. The case was lodged earlier this week, and Gruber spoke to EUobserver on Thursday, September 10. The plaintiffs are seeking 130,000 euros in damages.
Gruber spent years trying to obtain her own personal information held by Europol amid a Greek-led criminal investigation that was later dismissed. After she finally obtained indirect partial access, the EDPS revealed that her data had been held for the alleged crime of forcing the competent authorities to rescue migrants, according to court documents filed by Front-lex. Cohen called this a manifest non-crime, suggesting it would entitle Europol to process the personal data of a political activist for opposing a referendum or for trying to organise a Gay Pride event.
Gruber’s backstory leading to the EDPS court case dates to 2020, when Turkey allowed thousands of people to cross through the Greek land border, sparking an international crisis with Athens temporarily suspending asylum. Thousands more were stuck at the land border. Josoor arrived at the scene in March 2020, providing humanitarian relief and documenting violations. A month later, the Greeks quietly launched a criminal investigation into Josoor and three other NGOs, going public with a press release in September 2020. Gruber said the authorities were exposing their crimes, so they tried their best to discredit and deter the organisation. She said she has lived in a state of emergency for almost six years.
Cleared in Greek border case, Austrian activist now sues EU data chief over Europol record →
The Data That Should Never Go Into an AI Tool, and the Questions That Settle It
Credentials of any kind, including passwords, API keys, access tokens, connection strings and private keys, should never go into any AI tool. A key pasted into a chat window should be treated as compromised and rotated, and this is one of the most common findings when companies audit their AI usage. Payment card details have no legitimate reason to enter a chat interface, and doing so may put a user outside their card processing obligations. Health information is special category data under GDPR with a higher bar for lawful processing, covering employee sick notes, medical certificates, and anything about someone’s condition. Other special category data includes racial or ethnic origin, political opinions, religious beliefs, trade union membership, biometric and genetic data, and sex life or sexual orientation. Material under a confidentiality obligation that cannot be verified to cover the tool, such as client material under NDA, unpublished deal information or another company’s trade secrets, may breach a contract that keeps information within an organisation if sent to a third-party processor.
Three questions settle most cases. Under GDPR, any vendor processing personal data requires an Article 28 data processing agreement, and without a DPA personal data should not go in. Vendors’ homepage claims that they do not train on customer data should be checked against the contract, which is the version that binds them. The sub-processor annex in the DPA names every third party that touches the data and where they sit; for AI tools this matters more than usual, since inference frequently runs through providers in the United States even when the product is European and the storage is not. A single-sentence rule is more likely to be followed than an elaborate policy: if it contains a password, someone’s health information, or a client’s confidential material, it does not go into an AI tool; if it contains personal data, it only goes into tools on the approved list. The approved list should be short and its tools should have DPAs.
Redacting before pasting, replacing real identifiers with placeholders, costs seconds and removes the issue. Business accounts, not personal ones, should be used, since business tiers generally carry different data handling terms and can be administered, audited and revoked when someone leaves. Prompts are not the only channel: uploaded files, connected integrations and browser extensions all move data, and integrations move it continuously rather than once. Connecting an AI tool to email, a drive or an accounting system grants standing access to everything in it, so permissions granted, whether they include write access, and how to revoke them should be checked. Anything put into a tool could be read by someone at the vendor; for most business work with a properly contracted vendor that is acceptable, but for credentials, health data and other people’s confidential material it is not.
What You Should Never Put Into an AI Tool →
Europe’s Cookie Law Is Really a Law About Surveillance, and Its Future Is Being Rewritten
In 2022, a reporter paid $160 for a week’s worth of location data linked to visits to over 600 Planned Parenthood clinics in the United States. The dataset showed where groups of visitors had come from, how long they stayed, and where they went next. The broker withdrew the product after the story was published, but the market behind it remained. Journalists have obtained billions of commercially traded location records from Germany and Belgium, exposing movements around hospitals, religious sites, trade union offices, government ministries, military sites, EU institutions and NATO buildings. EU law recognizes two distinct fundamental rights: Article 7 of the Charter protects private life, the home and communications, while Article 8 protects personal data. Data protection largely governs what happens when personal data are processed; privacy and communications confidentiality also protect the space from which information is obtained.
The ePrivacy framework adds specific rules for the confidentiality of communications and access to information stored on, or generated by, people’s devices, including communications, metadata, and location. Article 5(3) of the ePrivacy Directive controls when an actor may store information on, or obtain information from, a person’s terminal equipment, which includes phones and laptops, connected cars, televisions, wearables, smart glasses and other parts of the Internet of Things. The rule covers fingerprinting, tracking pixels, local storage, operating-system identifiers and instructions that make a device send information elsewhere. The ePrivacy Directive was written around traditional telephone and communications providers, so many online services were originally excluded from its protection. Messaging and webmail services can now fall under communications confidentiality rules, but coverage depends on legal classifications users cannot see; the same message, location trail, or device data can receive different protection depending on whether the company is labeled a telecom provider, messaging service, or platform. A GDPR legal basis does not give a free pass through the ePrivacy door; both layers must be satisfied.
On state surveillance, Article 15 allows restrictions for public objectives, subject to the Charter, including necessity and proportionality requirements in Article 52. Court of Justice case law, from Digital Rights Ireland, Tele2 Sverige and Watson, La Quadrature du Net, SpaceNet and more recently HADOPI, rejects general and indiscriminate retention of traffic and location data as the default, while allowing targeted retention and some limited forms of general retention. A record of who contacted whom, when, for how long and from where can reconstruct a life without revealing the content of a single message; repeated calls to an oncology department may disclose a diagnosis, and a phone present at an abortion clinic, mosque, union office or demonstration may reveal health, religion, employment relations or political activity. In 2017, the Commission proposed an ePrivacy Regulation covering internet-based communications, metadata, tracking technologies and connected devices, but after years of negotiations the Commission withdrew the proposal in 2025. The Commission has since proposed the ChatControl framework and its temporary derogation, is working towards a new EU approach to data retention, and has proposed moving important terminal-equipment rules into the GDPR through the Digital Omnibus. The Digital Omnibus keeps consent as the general rule for storing or accessing personal data on a person’s device while widening exceptions, and would split the same act between two regimes: access to personal data would fall under the GDPR, while other information could remain under ePrivacy, with oversight shifting towards the GDPR’s one-stop-shop system.
Europe’s Cookie Law Is Really a Law About Surveillance →