Overview of South Korea’s Personal Information Protection Act (PIPA)

Author

Omer Imran Malik

Data Privacy Legal Manager, Securiti

FIP, CIPT, CIPM, CIPP/US

Published April 3, 2022 / Updated September 24, 2026

Listen to the content

1. Introduction

South Korea has elaborate laws and regulations related to personal data protection. The Personal Information Protection Act ("PIPA") was first enacted on September 30, 2011. The Act sets strict rules that govern the collection, usage, disclosure, and other processing of personal information by government bodies, private entities, and individuals.  The PIPA's Enforcement Decree was most recently amended effective October 2, 2025, strengthening the domestic agent regime and expanding the definition of "public institution."

Most significantly, following a series of large-scale breaches in the telecommunications, platform and financial services sectors, the National Assembly passed a further major amendment to the PIPA on February 12, 2026. It was promulgated as Act No. 21445 on March 10, 2026 and took effect on September 11, 2026 (the provisions mandating ISMS-P certification take effect on July 1, 2027). This amendment raises the maximum administrative fine to 10% of total revenue in high-severity cases, designates the business owner or representative as the "ultimate responsible person" for data protection, and expands breach reporting obligations. A corresponding amendment to the Enforcement Decree, announced in draft on March 16, 2026, sets out how revenue is calculated for fining purposes and the grounds for fine reduction.

Under the PIPA, South Korea has laid out specific requirements for handling personal information and taking the data subject's consent as an integral part of almost every step.

2. Who Needs to Comply with PIPA

A. Personal Scope

The PIPA applies to any personal information controller. A personal information controller could be an individual, a public agency, a juridical person, or an organization that handles the data subject's personal information either themselves or through a third party. If PIPA applies to an entity, it must comply with the law.

The PIPA applies to the processing of personal information. ‘Processing’ under the law is defined as the 'collection, generation, recording, storage, retention, processing, editing, search, outputting, rectification, restoration, use, provision, disclosure, or destruction of personal information or any other action similar to any of the preceding.'

B. Territorial Scope

The PIPA does not explicitly define its territorial or extraterritorial scope. Nonetheless, it considers several factors when determining whether a foreign entity is subject to the PIPA (for instance, whether the entity provides services targeted at Koreans or whether the company generates revenue from doing business in South Korea).

3. Definitions of Key Terms

A. Personal Information

The PIPA has an extensive meaning of ‘personal information.’ For easier understanding purposes, personal information under PIPA refers to a natural living person with a:

  • Name
  • Resident registration number (RRN)
  • Image.

B. Sensitive Data

Under the PIPA, sensitive data is regarded as the personal information of an individual's:

  • Ideology
  • Faith
  • Trade union
  • Political party membership
  • Political views
  • Health
  • Sexual orientation
  • Genetic information
  • Criminal records
  • Physical information
  • Physiological information
  • Behavioral characteristics
  • Any other personal information that may cause a material threat to the privacy of the data subject
  • Race or ethnic origin

C. Biometric Data

While the PIPA does not explicitly define biometric data, it takes an individual's physical, physiological, and behavioral characteristics from ‘sensitive data’ as a means to identify the person.

D. Personal Information Controller

The PIPA takes inspiration from the EU’s GDPR regarding the concept of a personal information controller. It includes natural and legal entities that process personal information.

E. Personal Information Handler

Under the PIPA, the concept of personal information controller is defined extensively. Therefore, data processing entities must regularly provide personal information handlers with necessary educational programs to ensure the appropriate handling of personal information.

To ensure the safe administration of personal information, personal information controllers must perform proper control and supervision against those who process personal information under their command and supervision, such as officers or employees, temporary agency workers, and part-time workers.

4. Obligations for Organizations Under PIPA

Under the PIPA, personal information controllers must issue a notice when processing personal information. Generally, explicit consent is required before collecting, using, and providing third parties’ personal information, subject to certain exceptions.

Personal information controllers and Information and Communications Service Providers (ICSPs) are required to specify the following matters when seeking consent from data subjects for the collection and use of their personal information:

  • the purpose of the collection and use of personal information;
  • the items of personal information to be collected/used;
  • the period for retaining and using personal information; and
  • the data subject's right to refuse his/her consent and outline any disadvantages, if any, which may follow from such refusal.

Additionally, personal information controllers and ICSPs are required to explicitly state the following matters when seeking consent from data subjects for the provision of personal information to third parties:

  • the specific name of the third-party recipient;
  • items of personal information to be shared;
  • third-party recipients' purposes of use;
  • period of retention and use by the third-party recipient; and
  • the data subject's right to refuse his/her consent and outline any disadvantages, if any, which may follow from such refusal.

The PIPA allows additional flexibility where processing is necessary to protect individuals from imminent threats to life, bodily safety or property, for emergency rescue operations, or to respond to public health emergencies.

Moreover, the Personal Information Protection Commission (PIPC) has clarified certain principles for using personal information without consent. They have stated that as per the PIPA Enforcement Decree:

  • Personal information necessary for fulfilling a service contract can be processed without requiring explicit consent from the data subject. However, to ensure transparency and compliance, it must be separated from other information requiring consent.
  • If sensitive information or unique identifiers are needed for the service, separate explicit consent must be obtained unless otherwise provided by PIPA.

B. Security Requirements

The PIPA demands that personal information controllers maintain the security of personal information in their possession. They must diligently evade risks of infringement of data subjects' privacy by taking technical, administrative, and physical measures necessary to ensure the security of their personal information.

Moreover, under the recent amendments, certain personal information controllers, determined by scale of processing and revenue thresholds set in the Enforcement Decree, will be required to obtain ISMS-P (Personal Information & Information Security Management System) certification. This requirement is likely to take effect on July 1, 2027, giving in-scope organizations a lead-in period to prepare. Organizations that can demonstrate qualifying investment in privacy safeguards such as, dedicated staffing, budget allocation and technical measures, may also qualify for reductions in administrative fines.

C. Data Breach Requirements

Where a personal information controller becomes aware of the loss, theft, leakage, forgery, alteration or damage of personal information, it must notify affected data subjects within 72 hours of becoming aware. The notification must set out:

  • the categories of personal information involved;
  • when and how the breach occurred;
  • steps data subjects can take to minimise potential harm;
  • the controller's countermeasures and remediation procedures; and
  • contact details for the department handling reports and claims.

A separate report must be filed with the PIPC or KISA within 72 hours where the breach involves:

  • the personal information of 1,000 or more data subjects;
  • sensitive information or unique identification information; or
  • unlawful external access to the controller's information systems.

Under the amendment effective September 11, 2026, reporting is no longer confined to confirmed incidents; notification may be required once a meaningful possibility of an incident has been identified, even where a breach has not been conclusively established. Failure to notify data subjects or report within 72 hours can attract an administrative fine of up to KRW 30 million, and breaches connected to gross negligence or non-compliance with a corrective order now expose the organization to the new 10%-of-revenue penalty ceiling

D. Chief Privacy Officer (CPO) Requirement

The PIPA enables all personal information controllers to appoint certified officials as privacy officers. These privacy officers will eventually take control of how personal information is handled.

The CPO's responsibilities under the PIPA are:

  • Creating and implementing personal information protection plans,
  • Conducting periodic investigations and updating the status and procedures of personal information processing,
  • Resolving complaints and repairing damage caused by the processing of personal information,
  • Developing internal control measures to avoid personal information loss, misuse, and abuse,
  • Designing and implementing personal information protection training sessions,
  • Monitoring, managing, and protecting personal information files,
  • Developing, updating, and putting into effect a personal information processing policy,
  • Managing items relating to the security of personal information, and
  • Discarding personal information after the processing goal has been met or the retention time has passed.

Since March 15, 2024, the Enforcement Decree has imposed qualification requirements on the CPOs of larger controllers (minimum years of relevant experience in personal information protection), and the PIPA requires controllers to guarantee the CPO's independence; the CPO must be able to report directly to the representative or board, must not be disadvantaged for performing the role, and must be given the resources and access necessary to do so.

The CPO is not required to be a Korean national. Failure to designate a CPO may attract an administrative fine of up to KRW 10 million.

Under the amendment effective September 11, 2026, governance obligations are considerably tighter:

  • the business owner or representative (i.e. the CEO) is formally designated the "ultimate responsible person" for personal information protection, creating personal supervisory liability rather than liability resting solely with the CPO; and
  • certain organizations must report their CPO designation to the PIPC.

E. Privacy Policy Requirements

The PIPA outlines a series of personal information processing policies that must be included in a privacy policy, including, but not limited to:

  • the purposes of processing,
  • retention period,
  • information on provision and outsourcing,
  • disposal of personal information.

The PIPA instructs personal information controllers to publicly disclose their privacy policies in a way that allows data subjects to thoroughly examine the stated terms of these privacy policies, including any revisions made to them, at any time.

F. Data Protection Impact Assessment

Under the PIPA,  public institutions shall conduct a Data Protection Impact Assessment (DPIA). A DPIA is mandatory for public institutions operating personal information files that meet the thresholds in the Enforcement Decree (broadly, files involving large volumes of sensitive or unique identification information, or files linked with other institutions' files). Private-sector controllers are encouraged but not required to conduct DPIAs. Following the Enforcement Decree amendment, institutions newly brought within the definition of "public institution," including local government-funded and -invested institutions, must register their personal information files within 60 days and complete any required DPIA within 2 years of October 2, 2025 (i.e. by October 2, 2027).

The head of the respective public institution will conduct an impact assessment to analyze risk factors (if any) and ways to improve them, and the findings will be submitted to the Personal Information Protection Commission (PIPC).

G. Record of Processing Activities

Even though the PIPA does not require organizations to maintain a record of processing activities, it does require personal information controllers to manage and sustain login records that document access given by personal information controllers to a data processing system.

Access could be given to officers, employees, workers, or anyone else who processed personal information under the direction and supervision of the personal information controller for at least one year. In addition, PIPA demands that the log-in records contain the reason of access, an ID number, date and time of entry, information to identify the person of access, and the number or types of tasks performed by the personal information controller while on the processing system.

H. Cross-Border Information Transfer Requirements

Personal information controllers are advised not to enter into information transfer agreements with vendors not complying with privacy laws and regulations. The Personal Information Protection Commission has released Regulations on the Overseas Transfer of Personal Information.

The PIPC delineates the operations of the Overseas Transfer Expert Committee, specifying procedures for recognizing the level of personal information protection in the destination country and addressing matters related to the cancellation and modification of such recognition.

This committee evaluates overseas data transfers and has the authority to issue certifications or order the suspension of transfers based on its assessments. Since the 2023 amendment, consent is no longer the only route for overseas transfers. Under Article 28-8 of the PIPA, a controller may transfer personal information abroad where any one of the following applies:

  • the data subject has given separate consent to the overseas transfer;
  • the transfer is required by statute or an international treaty;
  • the transfer is necessary to perform a contract with the data subject, and the required disclosures are made to the data subject;
  • the recipient holds a PIPC-recognised certification and has implemented the necessary protective measures; or
  • the destination country or recipient has been recognised by the PIPC as providing a level of protection equivalent to the PIPA.

Moreover, as of September 16, 2025, the PIPC has recognized the EU’s personal data protection system as equivalent to Korea’s, allowing private and public entities to transfer personal information to EU countries without additional consent requirements. This equivalence recognition applies to providing, viewing, outsourcing, or storing personal data in the EU, but excludes resident registration numbers and personal credit information. In the event of a personal information breach, the PIPC will coordinate with EU authorities to ensure proper response and remediation. Moreover, if equivalence-recognized transfers result in improper protection of personal information or pose a significant risk to data subjects, the PIPC may order the suspension of the transfer.

I. Appointing a Domestic Agent

Overseas personal information controllers without a place of business in Korea, where they meet the revenue or data-volume thresholds set in the Enforcement Decree, must appoint a domestic agent in Korea. The agent must have a physical address or place of business in South Korea and be designated by written agreement They are responsible for:

  • handling complaints related to the processing of personal data,
  • reporting personal data breaches,
  • submitting requested materials to the relevant authorities,
  •  perform ongoing checks/improvements based on inspection results.

Overseas controllers that have a subsidiary or affiliate in Korea must designate that entity as their domestic agent, third-party agency services are no longer sufficient in those cases, and must actively supervise the agent's performance, including annual training, planning and inspections. Affected controllers were required to appoint or switch to a qualifying domestic entity by April 2, 2026. Non-compliance may attract high administrative fines, and the PIPC now conducts regular on-site inspections of domestic agents.

J. Preliminary Adequacy Review System

The Personal Information Protection Commission (PIPC) also initiated the 'Preliminary Adequacy Review System’ on October 13, 2023. This initiative is designed to ensure secure personal information use in emerging technologies, such as artificial intelligence.

The system allows business operators uncertain about compliance with the PIPA to apply for a prior adequacy review by the PIPC. This review process determines a compliance plan.

1. Exceptions to the General Rule

The following situations are exceptions to the general rule:

  • Whenever any Act contains special provisions, or it is required to comply with an obligation imposed by or under any Act or subordinate Act,
  • When it is necessary for a public institution to carry out its responsibilities as set out in any Act or subordinate statute, and
  • Where it is evident that it is necessary for a data subject's physical safety and property interests or the data subject is unable to give consent for whatever reason.

A personal information controller must acquire consent after notifying the data subject of:

  • The individual or entity to whom personal information is transferred,
  • The intended use of the personal information by the person or the entity,
  • Categories of personal information transferred,
  • The timeframe for which the person or the entity will possess the personal information, and
  • The data subject has the right to refuse consent.

3. Notification after Transfer of Information

In an event where personal information is transferred to a third party, PIPA makes it imperative that data subjects be notified of the following:

  • The third-party source (transferor) from which the personal information was acquired,
  • The intended purpose and use of obtaining the personal information, and
  • The data subject has the right to suspend the use of their personal information.

According to the recent amendments, the transfer of personal information to third-party destinations abroad has been broadened to allow it to countries with the same level of data protection as South Korea, or to certain certified companies. While the personal information controller is not subject to any additional obligations beyond the general standards for third-party transfer outlined above, there is a special provision for cross-border transfer of users' personal information. All controllers are subject to the unified requirements of Article 28-8 (Transfer of Personal Information Abroad)

Where consent is the chosen legal basis for an overseas transfer, the controller must notify the data subject of:

  • the items of personal information to be transferred;
  • the destination country and the date, time and method of transfer;
  • the name of the recipient and the contact details of its person responsible for personal information;
  • the recipient's purpose of use and retention/use period; and
  • the data subject's right to refuse the transfer, and the consequences of refusal.

The PIPC may order the suspension of a cross-border transfer where the transfer is made in violation of the PIPA, where the destination country's protections are materially inadequate, or where the transfer poses a significant risk to data subjects.

5. Data Subject Rights

The PIPA grants data subjects the following rights:

A. Right to be Informed

Under the PIPA, data subjects have the right to be informed of the storage, processing, and sharing of their personal information. Personal information controllers and ICSPs are responsible for informing the data subjects.

B. Right to Access

PIPA enables a data subject to request access to his/her personal information that is processed by the personal information controller and with whom it is shared.

C. Right to Rectification

The PIPA enables data subjects the right to request the rectification of their information by the relevant personal information controller if they have previously accessed their personal information. Data subjects who may have been denied access to their personal information may not exercise their right to request rectification of their personal information.

D. Right to Erasure

Under the PIPA, data subjects who have previously accessed their personal information have the right to request the erasure of their personal information from the relevant personal information controller.

E. Right to Object/Opt-Out

All personal information controllers must allow data subjects to withdraw consent to the processing of their personal information at any time, and the method of withdrawal must be no more difficult than the method by which consent was given. In addition, personal information controllers must also respond to a data subject's request if they wish further to suspend the processing of his/her personal information.

The data subjects have the right to choose whether or not to consent to the processing of their personal information, as well as the scope of that consent.

G. Right to Redressal

Data subjects have the right to swift and reasonable remedies for any harm caused by the processing of their personal information. The recent amendments state that a more prompt remedy is to be provided through a privacy-related dispute resolution procedure and that both public institutions and private companies are mandated to participate in dispute resolution proceedings.

H. Right to Data Portability

The right to personal information transmission (data portability) took effect on March 13, 2025. It entitles data subjects to request that their personal information be transmitted directly to themselves, or to another controller or a specialised transmission institution, in a structured, machine-readable format.

The right applies to information collected with consent, under a contract, or as required by law, and is being phased in by sector and by controller size as specified in the Enforcement Decree. In practice, in-scope controllers must build the delivery mechanism; typically a secure download or an API. The right extends Korea's "MyData" model, previously confined to the financial sector, across the wider economy.

I. Right to Object to Automated Decision-Making

Effective March 15, 2024, where a fully automated decision (including one made using artificial intelligence) produces a significant effect on a data subject's rights or obligations, the data subject has the right to:

  • refuse that decision, where it is not based on their consent or on a contract; and
  • request an explanation of the decision, and request human review.

Controllers must disclose the criteria and procedures for automated decision-making, and the types of data used, in their privacy policy. This is the provision most directly relevant to organizations deploying AI in customer-facing decisions in Korea.

6. Regulatory Authority

The main data protection authorities for PIPA are:

  1. PIPC;
  2. Korea Communications Commission;
  3. Korea Internet & Security Agency (KISA); and
  4. Financial Services Commission.

The PIPC is the central and primary supervisory authority for the PIPA. Other bodies with related jurisdiction are:

  1. PIPC — the lead data protection authority; supervises, investigates and sanctions PIPA violations;
  2. Korea Internet & Security Agency (KISA) — receives breach reports, operates the privacy call centre, and administers ISMS-P certification;
  3. Korea Communications Commission — jurisdiction under the Network Act (including illegal spam and, from October 1, 2026, expanded CISO obligations), rather than under the PIPA itself; and
  4. Financial Services Commission — jurisdiction over personal credit information under the Credit Information Use and Protection Act.

7. Penalties for Non-Compliance

Data regulators such as the PIPC, the KCC, and the FSC have the power to impose numerous administrative penalties such as:

  • corrective orders,
  • administrative fines, and
  • penalty surcharges for violations of respective laws and regulations.

The PIPC issued comprehensive guidelines in accordance with Article 65(2) of the PIPA and Article 58 of the PIPA Enforcement Decree. These guidelines outline specific standards for disciplinary action concerning violations of personal information protection laws and regulations while empowering the PIPC to recommend disciplinary actions in certain cases.

In addition, public prosecutors are empowered to conduct examinations on any violations that may lead to criminal punishment. Moreover, under the amendments to the Enforcement Decree, PIPC is empowered to conduct regular on-site inspections of domestic agents and newly included public institutions to ensure compliance.Simultaneously, under the PIPA, personal information controllers may become civilly liable to any data subjects who may suffer damages due to such violations.

Criminal penalties under the PIPA extend to up to 10 years' imprisonment or a fine of up to KRW 100 million for the most serious offences, such as unlawfully obtaining and providing personal information for profit.

On the administrative side, the 2023 amendment changed the penalty surcharge base from revenue related to the violation to up to 3% of total revenue, excluding revenue unrelated to the violation, a substantially wider base.

The amendment effective September 11, 2026 goes considerably further. The PIPC may now impose a penalty surcharge of up to 10% of total revenue where a controller:

intentionally or with gross negligence commits a violation and repeats it within three years;

engages in intentional or grossly negligent conduct affecting 10 million or more individuals; or

fails to comply with a PIPC corrective order and a breach subsequently occurs.

The PIPC through the recent amendments has set out how total revenue is calculated for these purposes, and the basis on which fines may be reduced where an organization can evidence qualifying investment in privacy safeguards (dedicated personnel, budget and technical measures). Transitional rules govern application of the new ceiling.

With the CEO now designated the ultimate responsible person for data protection, the exposure is both financial and personal — placing Korea among the highest-risk privacy enforcement jurisdictions globally.

8. How an Organization Can Operationalize the PIPA

To comply with PIPA, organizations must:

  1. Conduct a thorough data mapping exercise to better understand the types of data an organization uses, its purposes, and well data chambers are protected.
  2. Should Identify personal information that they consider as “sensitive.”
  3. Stay consistent with the data mapping exercise to ensure it stays current and eliminate the need for ‘additional personal information’ that isn’t necessarily required by the organization or the law.
  4. Update the organization’s processes, policies, procedures, and systems to comply with the PIPA requirements.
  5. Conduct a data protection impact assessment.
  6. Possibly engage a third party to conduct a cybersecurity audit of the organization’s processes, especially if they might pose a risk to consumers’ privacy or security.
  7. Adopt Privacy by Design principles when developing new products and services.
  8. Confirm whether the organization falls within the mandatory ISMS-P certification scope and begin preparation ahead of the July 1, 2027 deadline.
  9. Verify its CPO meets the statutory qualification requirements, has guaranteed independence and direct reporting lines, and has been reported to the PIPC where required.
  10. Review board- and CEO-level governance of privacy, given the CEO's designation as ultimate responsible person.
  11. Test its 72-hour breach notification and reporting workflow, including the lower "meaningful possibility of an incident" trigger.
  12. If the organisation is an overseas controller with a Korean subsidiary or affiliate, confirm your domestic agent designation meets the post-October 2025 requirement.
  13. Map its  automated decision-making use cases and build refusal/explanation/human-review workflows.
  14. Assess readiness for data portability requests in its sector.

9. How Securiti Can Help

The worldwide dynamics of accessing and sharing personal data are rapidly evolving, pushing businesses to become more privacy-conscious in their processes and responsible guardians of their customer's data, all while automating privacy and security operations for quick response.

With an ever-growing database of users and potential users, businesses must embrace robotic automation to operationalize compliance and avoid falling behind. While multiple services offer software that enables companies to comply with global privacy regulations, those solutions only go as far as possible with various restrictions or elementary data-driven functions.

Securiti binds reliability, intelligence, and simplicity, working on the PrivacyOps framework to allow end-to-end automation for organizations. Securiti can help you comply with South Korea’s PIPA and other privacy and security regulations worldwide.

See how it works. Request a demo today.

Frequently Asked Questions (FAQs)

The personal information protection law in South Korea is the "Personal Information Protection Act" (PIPA), which governs the processing of personal information in the country and applies to any personal information controller.

Under the PIPA, the PIPC imposes a penalty amount not exceeding 100 million won and imprisonment of no more than 10 years. PIPA stipulates penalties for varying offenses, ranging from 70 million won to 10 million won. Additionally, imprisonment has also been prescribed for certain offenses, ranging from 2 years to 5 years. However, the recent amendments showcase a shift from certain criminal sanctions to economic sanctions in the form of administrative penalties.

The PIPA in South Korea refers to the Personal Information Protection Act, a law regulating personal information collection and processing.

PIPA sets requirements for obtaining consent, data breach, appointing a chief privacy officer, establishing a privacy notice, conducting data protection impact assessments, maintaining a record of processing activities, protecting sensitive information, and implementing security measures for personal information.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
A Complete DSPM Needs Classification and Context
Classification is one of the core functions a DSPM program handles, and it usually runs in tandem with discovery, since together they form the...
The EU Cyber Resilience Act (CRA): A Complete Guide for Compliance View More
The EU Cyber Resilience Act (CRA): A Complete Guide for Compliance
Here’s what you need to know about the EU’s Cyber Resilience Act (CRA), including the best solutions to aid your compliance efforts. Read on...
What is Access Control? Definition, Types, & Components View More
What is Access Control? Definition, Types, & Components
Discover what access control is, how it works, types, components, importance in ensuring regulatory compliance, and much more.
Stop Storing Risk: An Executive's Guide to ROT Data Minimization View More
Stop Storing Risk: An Executive’s Guide to ROT Data Minimization
An executive's guide to reducing redundant, obsolete, and trivial (ROT) data to cut storage costs, shrink your attack surface, and improve compliance.
The Context Layer for Data+AI Security View More
The Context Layer for Data+AI Security
Discover how Securiti’s DataAI Command Graph connects data, identity, cloud, and AI findings to uncover contextual risk and toxic combinations.
The Toxic Combination Problem in DataAI Risks View More
The Toxic Combination Problem in DataAI Risks
Discover how siloed security alerts create hidden toxic risk combinations and how correlated context helps reduce alert fatigue and uncover compound risks faster.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New