klri logo klt logo

2-column view

PERSONAL INFORMATION PROTECTION ACT

2-column view table
PERSONAL INFORMATION PROTECTION ACT No.21445 20260911
PERSONAL INFORMATION PROTECTION ACT No.20897 20251002
PERSONAL INFORMATION PROTECTION ACT No.19234 20240315
PERSONAL INFORMATION PROTECTION ACT No.16930 20200805
PERSONAL INFORMATION PROTECTION ACT No.14839 20170726
PERSONAL INFORMATION PROTECTION ACT No.14765 20171019
PERSONAL INFORMATION PROTECTION ACT No.14107 20160930
PERSONAL INFORMATION PROTECTION ACT No.13423 20150724
PERSONAL INFORMATION PROTECTION ACT No.12844 20141119
PERSONAL INFORMATION PROTECTION ACT No.12504 20140324
PERSONAL INFORMATION PROTECTION ACT No.11990 20140807
PERSONAL INFORMATION PROTECTION ACT No.11690 20130323
PERSONAL INFORMATION PROTECTION ACT No.10465 20110930
CHAPTER I GENERAL PROVISIONS
법령 이단보기
Article 1 (Purpose)
The purpose of this Act is to protect the freedom and rights of individuals, and further, to realize the dignity and value of the individuals, by prescribing the processing and protection of personal information. <Amended by Act No. 12504, Mar. 24, 2014>
법령 이단보기
Article 2 (Definitions)
The terms used in this Act shall be defined as follows: <Amended by Act No. 12504, Mar. 24, 2014; Act No. 16930, Feb. 4, 2020>
1. The term "personal information" means any of the following information relating to a living individual:
(a) Information that identifies a particular individual by his or her full name, resident registration number, image, etc.;
(b) Information which, even if it by itself does not identify a particular individual, may be easily combined with other information to identify a particular individual. In such cases, whether or not there is ease of combination shall be determined by reasonably considering the time, cost, technology, etc. used to identify the individual such as likelihood that the other information can be procured;
(c) Information under items (a) or (b) above that is pseudonymized in accordance with subparagraph 1-2 below and thereby becomes incapable of identifying a particular individual without the use or combination of information for restoration to the original state (hereinafter referred to as “pseudonymized information”);
1-2. The term “pseudonymization” means a procedure to process personal information so that the information cannot identify a particular individual without additional information, by deleting in part, or replacing in whole or in part, such information;
2. The term “processing” means the collection, generation, connecting, interlocking, recording, storage, retention, value-added processing, editing, searching, output, correction, recovery, use, provision, disclosure, and destruction of personal information and other similar activities;
3. The term “data subject” means an individual who is identifiable through the information processed and is the subject of that information;
4. The term “personal information file” means a set or sets of personal information arranged or organized in a systematic manner based on a certain rule for easy search of the personal information;
5. The term “personal information controller” means a public institution, legal person, organization, individual, etc. that processes personal information directly or indirectly to operate the personal information files as part of its activities;
6. The term "public institution" means any of the following institutions:
(a) The administrative bodies of the National Assembly, the Courts, the Constitutional Court, and the National Election Commission; the central administrative agencies (including agencies under the Presidential Office and the Prime Minister’s Office) and their affiliated entities; and local governments;
(b) Other national agencies and public entities prescribed by Presidential Decree;
7. The term "visual data processing devices" means the devices prescribed by Presidential Decree, which are continuously installed at a certain place to take pictures of persons or images of things, or transmit such pictures or images via wired or wireless networks.
8. The term “scientific research” means research that applies scientific methods, such as technological development and demonstration, fundamental research, applied research and privately funded research.
법령 이단보기
Article 3 (Principles for Protecting Personal Information)
(1) The personal information controller shall specify explicitly the purposes for which personal information is processed; and shall collect personal information lawfully and fairly to the minimum extent necessary for such purposes.
(2) The personal information controller shall process personal information in an appropriate manner necessary for the purposes for which the personal information is processed, and shall not use it beyond such purposes.
(3) The personal information controller shall ensure personal information is accurate, complete, and up to date to the extent necessary in relation to the purposes for which the personal information is processed.
(4) The personal information controller shall manage personal information safely according to the processing methods, types, etc. of personal information, taking into account the possibility of infringement on the data subject’s rights and the severity of the relevant risks.
(5) The personal information controller shall make public its privacy policy and other matters related to personal information processing; and shall guarantee the data subject’s rights, such as the right to access their personal information.
(6) The personal information controller shall process personal information in a manner to minimize the possibility of infringing the privacy of a data subject.
(7) If it is still possible to fulfil the purposes of collecting personal information by processing anonymized or pseudonymised personal information, the personal information controller shall endeavor to process personal information through anonymization, where anonymization is possible, or through pseudonymisation, if it is impossible to fulfil the purposes of collecting personal information through anonymization. <Amended by Act No. 16930, 4. February, 2020 >
(8) The personal information controller shall endeavor to obtain trust of data subjects by observing and performing such duties and responsibilities as provided for in this Act and other related statutes.
법령 이단보기
Article 4 (Rights of Data Subjects)
A data subject has the following rights in relation to the processing of his or her own personal information:
1. The right to be informed of the processing of such personal information;
2. The right to determine whether or not to consent and the scope of consent regarding the processing of such personal information;
3. The right to confirm whether or not personal information is being processed and to request access (including the provision of copies; hereinafter the same applies) to such personal information;
4. The right to suspend the processing of, and to request correction, deletion, and destruction of such personal information;
5. The right to appropriate redress for any damage arising out of the processing of such personal information through a prompt and fair procedure.
법령 이단보기
Article 5 (Obligations of State, etc.)
(1) The State and a local government shall formulate policies to prevent harmful consequences of beyond-purpose collection, abuse and misuse of personal information, indiscrete surveillance and tracking, etc. and to enhance the dignity of human beings and individual privacy.
(2) The State and a local government shall establish policy measures, such as improving statutes, necessary to protect the data subject's rights as provided for in Article 4.
(3) The State and local government shall respect, promote, and support self-regulating data protection activities of personal information controllers to improve unreasonable social practices relating to the processing of personal information.
(4) The State and a local government shall enact or amend any statutes or municipal ordinances in conformity with the purpose of this Act.
법령 이단보기
Article 6 (Relationship to other Acts)
The protection of personal information shall be governed by this Act, except where special provisions exist in other laws. <Amended by Act No. 12504, Mar. 24, 2014>
CHAPTER II ESTABLISHMENT OF PERSONAL INFORMATION PROTECTION POLICIES, ETC.
법령 이단보기
Article 7 (Personal Information Protection Commission)
(1) The Personal Information Protection Commission (hereinafter referred to as the “Protection Commission”) shall be established under the Prime Minister to independently conduct work relating to the protection of personal information. <Amended by Act No. 16930, 4. February, 2020 >
(2) The Protection Commission shall be deemed a central administrative agency under Article 2 of the Government Organization Act: Provided, That Article 18 of the Government Organization Act shall not apply to any of the following matters: <Amended by Act No. 16930, 4. February, 2020 >
1. Affairs specified in subparagraphs 3 and 4 of Article 7-8 (1);
2. Matters falling under subparagraph 1 among those to be deliberated and resolved on under Article 7-9 (1).
(2) through (9) Deleted. <by Act No. 16930, Feb. 4, 2020>
법령 이단보기
Article 7-2 (Composition of the Protection Commission)
(1) The Protection Commission shall be comprised of nine Commissioners including two Standing Commissioners (one Chairperson and one Vice Chairperson).
(2) Commissioners of the Protection Commission shall be selected from among any of the following persons with sufficient experience and expertise in the protection of personal information, with the Chairperson and Vice Chairperson being proposed by the Prime Minister, two other Commissioners being proposed by Chairperson, two other Commissioners being recommended by the negotiation body of the political party to which the President belongs or belonged, and three other persons being recommended by another negotiation body and named or appointed by the President:
1. A person who serves, or served, as a public official of Grade III or higher (including public officials belonging to the Senior Executive Service) who is responsible for personal information protection;
2. A person who has been serving, or served, as a judge, prosecutor or lawyer for ten years or longer;
3. A person who served as an officer at a public institution or group (including groups comprised of personal information controllers) for three years or longer or a person recommended by the above public institution or group who was in charge of personal information protection for three years or longer;
4. A person who has expertise in a field relating to personal information and has been serving, or served, as an associate professor or higher at a school set forth in subparagraph 1 of Article2 of the Higher Education Act for five years or longer.
(3) The Chairperson and the Vice Chairperson shall be appointed from among public officials in political service.
(4) The Chairperson, Vice Chairperson and the head of the secretariat under Article 7-13 shall become cabinet member, notwithstanding Article 10 of the Government Organization Act.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-3 (Chairperson)
(1) The Chairperson shall represent the Protection Commission, preside over meetings of the Protection Commission, and oversee the related work.
(2) If the Chairperson cannot perform his/her duties for inevitable reasons, the Vice Chairperson shall act on his or her behalf, and if both the Chairperson and Vice Chairperson cannot perform his/her duties for inevitable reasons, another Commissioner, determined by the Protection Commission in advance, shall act on behalf of Chairperson.
(3) The Chairperson may attend the National Assembly and make statements in relation to the work of the Protection Commission, and if required by the National Assembly, he or she shall attend the National Assembly to make a report or respond to questions.
(4) The Chairperson may attend a meeting of the State Council and recommend the Prime Minister to submit a bill concerning the affairs under his/her jurisdiction.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-4 (Term of Office of Commissioners)
(1) A Commissioner shall serve for a term of three years but may be consecutively appointed one time.
(2) When the post of a Commissioner becomes vacant, a new Commissioner shall be named or appointed without delay. In such cases, the term of the named or appointed succeeding Commissioner shall be newly commenced.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-5 (Status Guarantee for Commissioners)
(1) No Commissioner shall be dismissed or de-commissioned against his or her will except in the following cases:
1. Where he or she is unable to perform his/her duties for a long period due to mental or physical disorder;
2. Where he or she falls under any ground for disqualification provided for in Article 7-7;
3. Where he or she violates his/her official duties under this Act or any other Act.
(2) Each Commissioner shall independently perform his or her duties in compliance with the law and his/her conscience.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-6 (Prohibition on Dual Office Holding)
(1) Each Commissioner shall neither concurrently engage in any of the following posts, nor engage in any affairs for profits related to his or her duties:
1. Member of the National Assembly or Local Council;
2. State or local public official;
3. Other positions prescribed by Presidential Decree.
(2) Matters relating to for-profit businesses set forth in paragraph (1) shall be prescribed by Presidential Decree.
(3) A Commissioner shall not engage in political activities.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-7 (Grounds for Disqualification)
(1) Persons falling under any of the following cannot be a Commissioner:
1. Non-Korean national;
2. A person falling under any of the subparagraphs under Article 33 of the State Public Officials Act;
3. A Member of political party set forth in Article 22 of the Political Parties Act.
(2) A Commissioner falling under any of the above subparagraphs 1 through 3 shall be automatically discharged from his or her position; provided, in the case of subparagraph 2 of Article 33 of the State Public Officials Act, this only applies to a person who was declared bankrupt and did not apply for immunity within the application deadline, or received a confirmed decision of immunity disapproval or cancellation, according to the Debtor Rehabilitation and Bankruptcy Act; in the case of subparagraph 5 of Article 33 of the Same Act, this only applies to Articles 129 through 132 of the Criminal Act, Article 2 of the Act on Special Cases Concerning the Punishment, Etc. of Sexual Crimes, subparagraph 2 of Article 2 of the Act on the Protection of Children and Youth against Sex Offenses and a person who committed a crime prescribed in Articles 355 or 356 of the Criminal Act with regard to his or her duties and received a suspended sentence of imprisonment without labor or a heavier punishment.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-8 (Affairs under Jurisdiction of the Protection Commission)
The Protection Commission shall perform the following affairs:
1. Matters concerning the improvement of law relating to personal information protection;
2. Matters concerning the establishment or execution of policies, systems or plans relating to personal information protection;
3. Matters concerning investigation into infringement upon the right of data subjects and the ensuing dispositions;
4. Handling of complaints or remedial procedures relating to personal information processing and mediation of disputes over personal information;
5. Exchange and cooperation with international organizations and foreign personal information protection agencies to protect personal information;
6. Matters concerning the investigation and study, education and promotion of law, policies, systems and status relating to personal information protection;
7. Matters concerning the support of technological development and dissemination relating to personal information protection and nurturing of experts;
8. Matters provided for in this Act and other statutes as affairs under the jurisdiction of the Protection Commission.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-9 (Matters to be Deliberated and Resolved on by the Protection Commission)
(1) The Protection Commission shall deliberate and resolve on the following matters:
1. Matters concerning the assessment of data breach incident factors under Article 8-2;
2. Establishment of the Master Plan referred to in Article 9 and the Implementation Plan referred to in Article 10;
3. Matters concerning the improvement of policies, systems, and law relating to personal information protection;
4. Matters concerning the coordination of positions taken by public institutions with respect to the processing of personal information;
5. Matters concerning the interpretation and operation of law related to the protection of personal information;
6. Matters concerning the use and provision of personal information under Article 18 (2) 5;
7. Matters concerning the results of the privacy impact assessment under Article 33 (3);
8. Matters concerning the imposition of penalty surcharges under Articles 28-6, 34-2 and 39-15;
9. Matters concerning the presentation of opinions and recommendation for improvement under Article 61;
10. Matters concerning corrective measures under Article 64;
11. Matters concerning indictment and recommendation for disciplinary actions under Article 65;
12. Matters concerning the publication of processing results under Article 66;
13. Matters concerning the imposition of administrative fines under Article 75;
14. Matters concerning the enactment, amendment and abolition of law under its jurisdiction and rules of the Protection Commission;
15. Matters referred to a meeting by Chairperson or at least two Commissioners of the Protection Commission with respect to the protection of personal information;
16. Other matters which the Protection Commission deliberates or resolves pursuant to this Act or other statutes.
(2) The Protection Commission may take the following measures if necessary to deliberate and resolve matters provided for in paragraph (1):
1. Listening to the opinions of relevant public officials, experts in personal information protection, civic organizations and relevant business operators;
2. Requesting submission of relevant materials or facts with respect to relevant agencies.
(3) Relevant agencies in receipt of a request made under paragraph (2) 2 shall comply with the request unless there are extraordinary circumstances.
(4) Upon deliberating and resolving on matters provided for in paragraph (1) 3, the Protection Commission may advise on the improvement of such matters to the relevant agency.
(5) The Protection Commission may inspect whether the details of its advice given under paragraph (4) has been implemented or not.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-10 (Meetings)
(1) Meetings of the Protection Commission shall be convened by the Chairperson when he or she deems it necessary or at the request of not less than 1/4 of all incumbent Commissioners.
(2) The Chairperson or at least two Commissioners of the Protection Commission may propose a bill to the Protection Commission.
(3) The quorum for holding meetings of the Protection Commission shall be the presence of a majority of its members enrolled, and any resolution shall require the affirmative votes of a majority of the members present.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-11 (Disqualification of, Challenge to, and Refrainment by, Commissioners)
(1) A Commissioner of the Protection Commission shall be excluded from participating in deliberation and resolution for a case if:
1. The Commissioner or his or her current or former spouse is a party to the relevant case or is a joint right holder or a joint obligator with respect to the case;
2. The Commissioner is or was a relative of a party to the case;
3. The Commissioner has given any testimony, expert opinion, or legal advice with respect to the case;
4. The Commissioner is or was involved in the case as an agent or representative of a party to the case;
5. The Commissioner or a public institution, corporation or group where he or she belongs shares interests with a person who provides advice or other support for the case.
(2) When any party finds it impracticable to expect fair deliberation and resolution from a Commissioner, he or she may file an application for recusal, and the Protection Commission shall make a decision by resolution.
(3) A Commissioner may refrain from the case on the grounds provided for in paragraphs (1) or (3).
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-12 (Subcommission)
(1) The Protection Commission may have sub-commissions which will deliberate and resolve minor personal information infringement cases or similar or repetitive matters to ensure more efficient work procedures.
(2) Each sub-commission shall be comprised of three members.
(3) Matters deliberated and resolved by the sub-commission pursuant to paragraph (1) shall be deemed deliberated and resolved by the Protection Commission.
(4) Resolution for a meeting of the sub-commission shall be made by the presence of all the members enrolled and affirmative votes of all members present.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-13 (Secretariat)
The Protection Commission shall have a secretariat to handle its work, and matters that are not specified in this Act in relation to the organization of the Protection Commission shall be prescribed by Presidential Decree.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 7-14 (Operation)
Matters that are not specified in this Act and other statutes in relation to the operation of the Protection Commission shall be prescribed by the rules of the Protection Commission.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 8 Deleted. <by Act No. 16930, Feb. 4, 2020>
법령 이단보기
Article 8-2 (Assessment of Data Breach Incident Factors)
(1) The head of a central administrative agency shall request the Protection Commission to assess the factors of data breach incident where a policy or system that entails personal information processing is adopted or changed by the enactment or amendment of any statute under his or her jurisdiction.
(2) Upon receipt of a request made pursuant to paragraph (1), the Protection Commission may advise the head of the relevant agency of the matters necessary to improve the relevant statute by analyzing and reviewing the data breach incident factors of such statute.
(3) Necessary matters concerning the procedure and method to assess the data breach incident factors under paragraph (1) shall be prescribed by Presidential Decree.
[This Article Newly Inserted by Act No. 13423, Jul. 24, 2015]
법령 이단보기
Article 9 (Master Plan)
(1) The Protection Commission shall establish a Master Plan to protect personal information (hereinafter referred to as a “Master Plan”) every three years in consultation with the heads of related central administrative agencies to ensure the protection of personal information and the rights and interests of data subjects. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015>
(2) The Master Plan shall include the following:
1. Basic goals and intended directions of the protection of personal information;
2. Improvement of systems and statutes related to the protection of personal information;
3. Measure to prevent personal information breaches;
4. Vitalization of self-regulation to protect personal information;
5. Promoting education and public relations to protect personal information;
6. Training of specialists in the protection of personal information;
7. Other matters necessary to protect personal information.
(3) The National Assembly, the Court, the Constitutional Court, and the National Election Commission may establish and implement its own Master Plan to protect personal information of relevant institutions, (including affiliated entities).
법령 이단보기
Article 10 (Implementation Plan)
(1) The head of a central administrative agency shall establish an implementation plan to protect personal information each year in accordance with the Master Plan and submit it to the Protection Commission, and shall execute the implementation plan subject to the deliberation and resolution of the Protection Commission.
(2) Matters necessary for the establishment and execution of the implementation plan shall be prescribed by Presidential Decree.
법령 이단보기
Article 11 (Request for Materials, etc.)
(1) To efficiently establish the Master Plan, the Protection Commission may request materials or opinions regarding the status of regulatory compliance, personal information management, etc. by personal information controllers from personal information controllers, the heads of relevant central administrative agencies, the heads of local governments and related organizations or associations, etc. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015>
(2) The Protection Commission may conduct an investigation with respect to data controllers, the competent head of the central administrative departments or agencies and local governments, and the competent agencies and organizations about the level and actual status of how personal data is managed where necessary to implement policies for personal data protection and to evaluate performance, etc.<Newly Inserted by Act No. 13423, Jul. 24, 2015; Act No. 14839, Jul. 26, 2017; Act No. 16930, 4. February, 2020 >
(3) The head of a central administrative agency may request the materials referred to in paragraph (1) from personal information controllers in the fields under his or her jurisdiction to efficiently establish and promote Implementation Plans. <Amended by Act No. 13423, Jul. 24, 2015>
(4) Any person in receipt of a request to furnish the materials under paragraphs (1) through (3) shall comply with the request unless there are extraordinary circumstances. <Amended by Act No. 13423, Jul. 24, 2015>
(5) The scope and method to furnish the materials under paragraphs (1) through (3) and other necessary matters shall be prescribed by Presidential Decree.<Amended by Act No. 13423, Jul. 24, 2015>
법령 이단보기
Article 12 (Personal Information Protection Guidelines)
(1) The Protection Commission may establish the Standard Personal Information Protection Guidelines (hereinafter referred to as the “Standard Guidelines”) regarding the personal information processing standard, types of personal information breaches, preventive measures, etc., and recommend that personal information controllers comply with such Guidelines. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(2) The head of a central administrative agency may establish the personal information protection guidelines regarding the personal information processing in the fields under his or her jurisdiction in accordance with the Standard Guidelines; and may recommend that personal information controllers comply with such guidelines.
(3) The National Assembly, the Court, the Constitutional Court, and the National Election Commission may establish and implement its own personal information protection guidelines for each relevant institution (including affiliated entities).
법령 이단보기
Article 13 (Promotion and Support of Self-Regulation)
The Protection Commission shall establish policies necessary for the following matters to promote and support self-regulating activities of personal information controllers to protect personal information:<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
1. Education and public relations concerning the protection of personal information;
2. Promotion and support of agencies and organizations related to the protection of personal information;
3. Introduction and facilitation of privacy mark;
4. Support for personal information controllers in the establishment and implementation of self-regulatory rules;
5. Other matters necessary to support the self-regulating data protection activities of personal information controllers.
법령 이단보기
Article 14 (International Cooperation)
(1) The Government shall establish policy measures necessary to enhance the personal information protection standard in the international environment.
(2) The Government shall establish relevant policy measures so that the rights of data subjects may not be infringed on owing to the cross-border transfer of personal information.
CHAPTER III PROCESSING OF PERSONAL INFORMATION
SECTION 1 Collection, Use, Provision, etc. of Personal Information
법령 이단보기
Article 15 (Collection and Use of Personal Information)
(1) A personal information controller may collect personal information in any of the following circumstances, and use it with the scope of the purpose of collection:
1. Where consent is obtained from a data subject;
2. Where special provisions exist in other laws or it is inevitable to observe legal obligations;
3. Where it is inevitable for a public institution’s performance of its duties under its jurisdiction as prescribed by statutes, etc.;
4. Where it is inevitably necessary to execute and perform a contract with a data subject;
5. Where it is deemed manifestly necessary for the protection of life, bodily or property interests of the data subject or third party from imminent danger where the data subject or his or her legal representative is not in a position to express intention, or prior consent cannot be obtained owing to unknown addresses, etc.;
6. Where it is necessary to attain the justifiable interest of a personal information controller, which such interest is manifestly superior to the rights of the data subject. In such cases, processing shall be allowed only to the extent the processing is substantially related to the justifiable interest of the personal information controller and does not go beyond a reasonable scope.
(2) A personal information controller shall inform a data subject of the following matters when it obtains consent under paragraph (1) 1. The same shall apply when any of the following is modified.
1. The purpose of the collection and use of personal information;
2. Particulars of personal information to be collected;
3. The period for retaining and using personal information;
4. The fact that the data subject is entitled to deny consent, and disadvantages, if any, resulting from the denial of consent.
(3) A personal information controller may use personal information without the consent of a data subject within the scope reasonably related to the initial purpose of the collection as prescribed by Presidential Decree, in consideration whether disadvantages have been caused to the data subject and whether necessary measures have been taken to secure such as encryption, etc. <This Article Newly Inserted by Act No. 16930, February 4, 2020>
법령 이단보기
Article 16 (Limitation to Collection of Personal Information)
(1) A personal information controller shall collect the minimum personal information necessary to attain the purpose when collecting personal information pursuant to Article 15 (1). In such cases, the burden of proof that the minimum personal information is collected shall be borne by the personal information controller.
(2) A personal information controller shall collect personal information by specifically informing a data subject of the fact that he or she may deny the consent to the collection of other personal information than the minimum information necessary in case of collecting the personal information through the consent of the data subject.<Newly Inserted by Act No. 11990, Aug. 6, 2013>
(3) A personal information controller shall not deny the provision of goods or services to a data subject on ground that the data subject does not consent to the collection of personal information exceeding minimum requirement. <Amended by Act No. 11990, Aug. 6, 2013>
법령 이단보기
Article 17 (Provision of Personal Information)
(1) A personal information controller may provide (or share; hereinafter the same shall apply) the personal information of a data subject to a third party in any of the following circumstances: <Amended by Act No 16930, February. 4, 2020>
1. Where the consent is obtained from the data subject;
2. Where the personal information is provided within the scope of purposes for which it is collected pursuant to Articles 15 (1) 2, 3 and 5 and 39-3 (2) 2 and 3.
(2) A personal information controller shall inform a data subject of the following matters when it obtains the consent under paragraph (1) 1. The same shall apply when any of the following is modified:
1. The recipient of personal information;
2. The purpose for which the recipient of personal information uses such information;
3. Particulars of personal information to be provided;
4. The period during which the recipient retains and uses personal information;
5. The fact that the data subject is entitled to deny consent, and disadvantages, if any, resulting from the denial of consent.
(3) A personal information controller shall inform a data subject of the matters provided for in paragraph (2), and obtain the consent from the data subject in order to provide personal information to a third party overseas; and shall not enter into a contract for the cross-border transfer of personal information in violation of this Act.
(4) A personal information controller may provide personal information without the consent of a data subject within the scope reasonably related to the purposes for which the personal information was initially collected, in accordance with the matters prescribed by Presidential Decree taking into consideration whether disadvantages are caused to the data subject, whether necessary measures to secure safety, such as encryption, have been taken, etc. .<Newly Inserted by Act No. 16930, 4. February, 2020 >
법령 이단보기
Article 18 (Limitation to Out-of-Purpose Use and Provision of Personal Information)
(1) A personal information controller shall not use personal information beyond the scope provided for in Articles 15 (1) and 39-3 (1) and (2), or provide it to any third party beyond the scope provided for in Article 17 (1) and (3). <Amended by Act No. 16930, Feb. 4, 2020>
(2) Notwithstanding paragraph (1), where any of the following subparagraphs applies, a personal information controller may use personal information or provide it to a third party for other purposes, unless doing so is likely to unfairly infringe on the interest of a data subject or third party: Provided, That information and communications service providers (as set forth in Article 2 (1) 3 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.; hereinafter the same shall apply) processing the personal information of users (as set forth in Article 2 (1) 4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.; hereinafter the same shall apply) are only subject to subparagraphs 1 and 2, and subparagraphs 5 through 9 are applicable only to public institutions: <Amended by Act No. 16930, Feb. 4, 2020>
1. Where additional consent is obtained from the data subject;
2. Where special provisions exist in other laws;
3. Where it is deemed manifestly necessary for the protection of life, bodily or property interests of the data subject or third party from imminent danger where the data subject or his or her legal representative is not in a position to express intention, or prior consent cannot be obtained owing to unknown addresses;
4. Deleted; <by Act No. 16930, Feb. 4, 2020>
5. Where it is impossible to perform the duties under its jurisdiction as provided for in any Act, unless the personal information controller uses personal information for other purpose than the intended one, or provides it to a third party, and it is subject to the deliberation and resolution by the Commission;
6. Where it is necessary to provide personal information to a foreign government or international organization to perform a treaty or other international convention;
7. Where it is necessary for the investigation of a crime, indictment and prosecution;
8. Where it is necessary for a court to proceed with trial-related duties;
9. Where it is necessary for the enforcement of punishment, probation and custody.
(3) A personal information controller shall inform the data subject of the following matters when it obtains the consent under paragraph (2) 1. The same shall apply when any of the following is modified.
1. The recipient of personal information;
2. The purpose of use of personal information (in the case of provision of personal information, it means the purpose of use by the recipient);
3. Particulars of personal information to be used or provided;
4. The period for retaining and using personal information (where personal information is provided, it means the period for retention and use by the recipient);
5. The fact that the data subject is entitled to deny consent, and disadvantages, if any, resulting from the denial of consent.
(4) Where a public institution uses personal information, or provides it to a third party for other purpose than the intended one collected under paragraph (2) 2 through 6, 8, and 9, the public institution shall post the legal grounds for such use or provision, purpose and scope, and other necessary matters on the Official Gazette or its website requirements for such use or provision including the legal basis, purpose, scope, etc. as prescribed by Notification of the Protection Commission.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, Feb. 4, 2020>
(5) Where a personal information controller provides personal information to a third party for other purpose than the intended one in any case provided for in paragraph (2), the personal information controller shall request the recipient of the personal information to limit the purpose and method of use and other necessary matters, or to prepare necessary safeguards to ensure the safety of the personal information. In such cases, the person in receipt of such request shall take necessary measures to ensure the safety of the personal information.
법령 이단보기
Article 19 (Limitation to Use and Provision of Personal Information on Part of Its Recipients)
A person who receives personal information from a personal information controller shall not use the personal information, or provide it to a third party, for any purpose other than the intended one, except in the following circumstances:
1. Where additional consent is obtained from the data subject;
2. Where special provisions exist in other laws.
법령 이단보기
Article 20 (Notification on Sources, etc. of Personal Information Collected from Third Parties)
(1) When a personal information controller processes personal information collected from third parties, the personal information controller shall immediately notify the data subject of the following matters at the request of such data subject:
1. The source of collected personal information;
2. The purpose of processing personal information;
3. The fact that the data subject is entitled to demand suspension of processing of personal information, as prescribed in Article 37.
(2) Notwithstanding paragraph (1), when a personal information controller satisfying the criteria prescribed by Presidential Decree taking into account the types and amount of processed personal information, number of employees, amount of sales, etc., collects personal information from third parties and processes the same pursuant to Article 17 (1) 1, the personal information controller shall notify the data subject of the matters referred to in paragraph (1): Provided, That this shall not apply where the information collected by the personal information controller does not contain any personal information, such as contact information, through which notification can be given to the data subject.<Newly Inserted by Act No. 14107, Mar. 29, 2016; Act No 16930, February. 4, 2020>
(3) Necessary matters in relation to the time, method, and procedure of giving notification to the data subject pursuant to the main sentence of paragraph (2), shall be prescribed by Presidential Decree.<Newly Inserted by Act No. 14107, Mar. 29, 2016>
(4) Paragraph (1) and the main clause of paragraph (2) shall not apply to any of the following circumstances: Provided, That this shall be the case only where it is manifestly superior to the rights of data subjects under this Act:<Amended by Act No. 14107, Mar. 29, 2016>
1. Where personal information, which is subject to a notification request, is included in the personal information files referred to in any of the subparagraphs of Article 32 (2);
2. Where such notification is likely to cause harm to the life or body of any other person, or unfairly damages the property and other interests of any other person.
법령 이단보기
Article 21 (Destruction of Personal Information)
(1) A personal information controller shall destroy personal information without delay when the personal information becomes unnecessary owing to the expiry of the retention period, attainment of the purpose of processing the personal information, etc.: Provided, That this shall not apply where the retention of such personal information is mandatory by other statutes.
(2) When a personal information controller destroys personal information pursuant to paragraph (1), necessary measures to prevent recovery and revival shall be taken.
(3) Where a personal information controller is obliged to retain, rather than destroy, personal information pursuant to the proviso to paragraph (1), the relevant personal information or personal information files shall be stored and managed separately from other personal information.
(4) Other necessary matters, such as the methods to destroy personal information and its destruction process, shall be prescribed by Presidential Decree.
법령 이단보기
Article 22 (Methods of Obtaining Consent)
(1) Where a personal information controller intends to obtain the consent of the data subject (including his or her legal representative as stated in paragraph (6): hereafter in this Article the same applies) to the processing of his or her personal information, the personal information controller shall present the request for consent to the data subject in a clearly recognizable manner where each matter requiring consent is distinctly presented, and obtain his or her consent thereto, respectively. <Amended by Act No. 14765, Apr. 18, 2017>
(2) Where a personal information controller obtains the consent under paragraph (1) in writing (including electronic documents under Article 2, subparagraph 1 of the Framework Act on Electronic Documents and Transactions), the personal information controller shall clearly specify important matters prescribed by Presidential Decree such as the purpose of collection and use of personal information and the items of personal information to be collected and used, in the manner prescribed by Notification of the Protection Commission, so as to make such matters easy to be understood. <Newly Inserted by Act No. 14765, Apr. 18, 2017; Act No. 14839, Jul. 26, 2017; Act No. 16930, 4. February, 2020 >
(3) Where a personal information controller obtains the consent of a data subject to the processing of his or her personal information pursuant to Articles 15 (1) 1, 17 (1) 1, 23 (1) 1, and 24 (1) 1, the personal information controller shall distinguish personal information that may be processed without the data subject’s consent for the purpose of executing a contract with the data subject, etc., from personal information that may be processed only with the data subject’s consent. In such cases, the burden of proof that no consent is required in processing the personal information shall be borne by the personal information controller.<Amended by Act No. 14107, Mar. 29, 2016; Act No. 14765, Apr. 18, 2017>
(4) Where a personal information controller intends to obtain the consent of the data subject to the processing of his or her personal information in order to promote goods or services or solicit purchase thereof, the personal information controller shall notify the data subject of the fact in a clearly recognizable manner, and obtain his/her consent thereto. <Amended by Act No. 14765, Apr. 18, 2017>
(5) A personal information controller shall not deny the provision of goods or services to a data subject on ground that the data subject would not consent to the matter eligible for selective consent pursuant to paragraph (3), or would not consent pursuant to paragraph (4) and Article 18 (2) 1. <Amended by Act No. 14765, Apr. 18, 2017>
(6) When it is required to obtain consent pursuant to this Act to process personal information of a child under 14 years of age, a personal information controller shall obtain the consent of his/her legal representative. In such cases, minimum personal information necessary to obtain the consent of the legal representative may be collected directly from such child without the consent of his/her legal representative. <Amended by Act No. 14765, Apr. 18, 2017>
(7) Except as otherwise expressly provided for in paragraphs (1) through (6), other matters necessary in relation to detailed methods to obtain the consent of data subjects and the minimum information referred to in paragraph (6) shall be prescribed by Presidential Decree, in consideration of the collection media of personal information. <Amended by Act No. 14765, Apr. 18, 2017>
SECTION 2 Limitation to Processing of Personal Information
법령 이단보기
Article 23 (Limitation to Processing of Sensitive Information)
(1) A personal information controller shall not process any information prescribed by Presidential Decree (hereinafter referred to as “sensitive information”), including ideology, belief, admission to or withdrawal from a trade union or political party, political opinions, health, sex life, and other personal information that is likely to markedly threaten the privacy of any data subject: Provided, That this shall not apply in any of the following circumstances: <Amended by Act No. 14107, Mar. 29, 2016>
1. Where the personal information controller informs the data subject of the matters provided for in Article 15 (2) or 17 (2), and obtains the consent of the data subject apart from the consent to the processing of other personal information;
2. Where other statutes require or permit the processing of sensitive information.
(2) Where a personal information controller processes sensitive information pursuant to paragraph (1), the personal information controller shall take measures necessary to ensure safety pursuant to Article 29 so that the sensitive information may not be lost, stolen, divulged, forged, altered, or damaged. <Newly Inserted by Act No. 14107, Mar. 29, 2016>
법령 이단보기
Article 24 (Limitation to Processing of Personally Identifiable Information)
(1) A personal information controller shall not process any information prescribed by Presidential Decree that can be used to identify an individual in accordance with statutes (hereinafter referred to as "personally identifiable information"), except in any of the following cases:
1. Where the personal information controller informs a data subject of the matters provided for in Article 15 (2) or 17 (2), and obtains the consent of the data subject apart from the consent to the processing of other personal information;
2. Where other statutes specifically require or permit the processing of personally identifiable information.
(2) Deleted. <Act No. 11990, Aug. 6, 2013>
(3) Where a personal information controller processes personally identifiable information pursuant to paragraph (1), the personal information controller shall take measures necessary to ensure safety, including encryption, as prescribed by Presidential Decree, so that the personally identifiable information may not be lost, stolen, divulged, forged, altered, or damaged. <Amended by Act No. 13423, Jul. 24, 2015>
(4) The Protection Commission shall regularly inspect whether a personal information controller meeting the criteria prescribed by Presidential Decree taking into account the types and amount of processed personal information, number of employees, amount of sales, etc., has taken the measures necessary to ensure safety pursuant to paragraph (3), as prescribed by Presidential Decree.<Newly Inserted by Act No. 14107, Mar. 29, 2016; Act No. 14839, Jul. 26, 2017 ; Act No 16930, February. 4, 2020>
(5) The Protection Commission may authorize specialized institutions prescribed by Presidential Decree to conduct the inspection referred to in paragraph (4).<Newly Inserted by Act No. 14107, Mar. 29, 2016; Act No. 14839, Jul. 26, 2017 ; Act No 16930, February. 4, 2020>
법령 이단보기
Article 24-2 (Limitation to Processing of Resident Registration Numbers)
(1) Notwithstanding Article 24 (1), a personal information controller shall not process any resident registration number, except in any of the following cases: <Amended by Act No. 14107, Mar. 29, 2016; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
1. Where any Act, Presidential Decree, National Assembly Regulations, Supreme Court Regulations, Constitutional Court Regulations, National Election Commission Regulations or Board of Audit and Inspection Regulations specifically requires or permits the processing of resident registration numbers;
2. Where it is deemed manifestly necessary for the protection, from imminent danger, of life, bodily and property interests of a data subject or a third party;
3. Where it is inevitable to process resident registration numbers in line with subparagraphs 1 and 2 in circumstances publicly notified by the Protection Commission.
(2) Notwithstanding Article 24 (3), a personal information controller shall retain resident registration numbers in a safe manner by means of encryption so that the resident registration numbers may not be lost, stolen, divulged, forged, altered, or damaged. In such cases, any necessary matters in relation to the scope of encryption objects and encryption timing by object, etc. shall be prescribed by Presidential Decree, taking into account the amount of personal information processed, data breach impact, etc.<Newly Inserted by Act No. 12504, Mar. 24, 2014; Act No. 13423, Jul. 24, 2015>
(3) A personal information controller shall provide data subjects with an alternative sign-up tool without using their resident registration numbers in the stage of being admitted to membership via the website while processing the resident registration numbers pursuant to paragraph (1).
(4) The Protection Commission may prepare and support such measures as legislative arrangements, policy-making, necessary facilities, and systems build-up in order to support the provision of the measures provided for in paragraph (3). <Amended by Act No. 12504, Mar. 24, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
[This Article Newly Inserted by Act No. 11990, Aug. 6, 2013]
법령 이단보기
Article 25 (Limitation to Installation and Operation of Visual Data Processing Devices)
(1) No one shall install and operate any visual data processing device at open places, except in any of the following circumstances:
1. Where specifically allowed by statutes;
2. Where it is necessary for the prevention and investigation of crimes;
3. Where it is necessary for the safety of facilities and prevention of fire;
4. Where it is necessary for regulatory control of traffic;
5. Where it is necessary for the collection, analysis, and provision of traffic information.
(2) No one shall install and operate any visual data processing device so as to look into the places which is likely to noticeably threaten individual privacy, such as a bathroom, restroom, sauna, and dressing room used by multiple unspecified persons: Provided, That the same shall not apply to the facilities prescribed by Presidential Decree, which detain or protect persons in accordance with statutes, such as correctional facilities and mental health care centers.
(3) The head of a public institution who intends to install and operate visual data processing devices pursuant to paragraph (1) and a person who intends to install and operate visual data processing devices pursuant to the proviso to paragraph (2) shall gather opinions of relevant specialist and interested persons through the formalities prescribed by Presidential Decree such as public hearings and information sessions.
(4) A person who installs and operates visual data processing devices pursuant to paragraph (1) (hereinafter referred to as “VDPD operator”) shall take necessary measures including posting on a signboard the following matters, so that data subjects may easily recognize such devices: Provided, That this shall not apply to military installations defined in subparagraph 2 of Article 2 of the Protection of Military Bases and Installations Act, important national facilities defined in subparagraph 13 of Article 2 of the United Defense Act, and other facilities prescribed by Presidential Decree:<Amended by Act No. 14107, Mar. 29, 2016>
1. The purpose and place of installation;
2. The scope and hours of photographing;
3. The name and contact information of the person in charge of its management;
4. Other matters prescribed by Presidential Decree.
(5) A VDPD operator shall not handle arbitrarily the visual data processing devices for other purposes than the initial one; direct the said devices toward different spots; nor use sound recording functions.
(6) Every VDPD operator shall take measures necessary to ensure safety pursuant to Article 29 so that the personal information may not be lost, stolen, divulged, forged, altered, or damaged. <Amended by Act No. 13423, Jul. 24, 2015>
(7) Every VDPD operator shall establish an appropriate policy to operate and manage the visual data processing devices, as prescribed by Presidential Decree. In such cases, the VDPD operator may be exempted from adopting a Privacy Policy pursuant to Article 30.
(8) A VDPD operator may outsource the installation and operation of visual data processing devices to a third party: Provided, That the public institutions shall comply with the procedures and requirements prescribed by Presidential Decree when outsourcing the installation and operation of visual data processing devices to a third party.
법령 이단보기
Article 26 (Limitation to Personal Information Processing Subsequent to Outsourcing of Work)
(1) A personal information controller shall, when outsourcing personal information processing to a third party, effect such outsourcing through a document that states the following:
1. Prevention of personal information processing for other purposes than the outsourced purpose;
2. Technical and managerial safeguards of personal information;
3. Other matters prescribed by Presidential Decree to ensure safe management of personal information.
(2) A personal information controller that outsources personal information processing pursuant to paragraph (1) (hereinafter referred to as "outsourcer") shall disclose the details of the outsourced work and the entity that processes personal information (hereinafter referred to as “outsourcee”) under an outsourcing contract in the manner prescribed by Presidential Decree so that data subjects may recognize it with ease at any time.
(3) The outsourcer shall, in case of outsourcing the promotion of goods or services, or soliciting of sales thereof, notify data subjects of the outsourced work and the outsourcee in the manners prescribed by Presidential Decree. The same shall apply where the outsourced work or the outsourcee has been changed.
(4) The outsourcer shall educate the outsourcee so that personal information of data subjects may not be lost, stolen, leaked, forged, altered, or damaged owing to the outsourcing of work, and supervise how the outsourcee processes such personal information safely by inspecting the status of processing, etc., as prescribed by Presidential Decree. <Amended by Act No. 13423, Jul. 24, 2015>
(5) An outsourcee shall not use any personal information beyond the scope of the work outsourced by the personal information controller, nor provide personal information to a third party.
(6) With respect to the compensation of damage arising out of the processing of personal information outsourced to an outsourcee in violation of this Act, the outsourcee shall be deemed an employee of the personal information controller.
(7) Articles 15 through 25, 27 through 31, 33 through 38, and 59 shall apply mutatis mutandis to outsourcees.
법령 이단보기
Article 27 (Limitation to Transfer of Personal Information following Business Transfer, etc.)
(1) A personal information controller shall notify in advance the data subjects of the following matters in the manner prescribed by Presidential Decree in the case of transfer of personal information to a third party owing to the transfer of some or all of his or her business, a merger, etc.:
1. The fact that the personal information will be transferred;
2. The name (referring to the company name in case of a legal person), address, telephone number and other contact information of the recipient of the personal information (hereinafter referred to as “business transferee, etc.”);
3. The method and procedure for withdrawing consent if the data subject does not wish his or her personal information to be transferred.
(2) Upon receiving personal information, the business transferee, etc. shall, without delay, notify data subjects of the fact in the manner prescribed by Presidential Decree: Provided, That this shall not apply where the personal information controller has already notified the data subjects of the fact of such transfer pursuant to paragraph (1).
(3) Upon receiving personal information owing to business transferee, etc., a merger, etc., the business transferee may use, or provide a third party with, the personal information only for the initial purposes dating to the time of the transfer. In such cases, the business transferee shall be deemed the personal information controller.
법령 이단보기
Article 28 (Supervision of Personal Information Handlers)
(1) While processing personal information, a personal information controller shall conduct appropriate control and supervision against the persons who process the personal information under his or her command and supervision, such as an officer or employee, temporary agency worker and part-time worker (hereinafter referred to as “personal information handler”) to ensure the safe management of the personal information.
(2) A personal information controller shall provide personal information handlers with necessary educational programs on a regular basis in order to ensure the appropriate handling of personal information.
SECTION 3 Special Cases concerning Pseudonymous Data
법령 이단보기
Article 28-2 (Processing of Pseudonymous Data)
(1) A personal information controller may process pseudonymized information without the consent of data subjects for statistical purposes, scientific research purposes, and archiving purposes in the public interest, etc.
(2) A personal information controller shall not include information that may be used to identify a certain individual when providing pseudonymized information to a third party according to paragraph (1).
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 28-3 (Restriction on Combination of Pseudonymous Data)
(1) Notwithstanding Article 28-2, the combination of pseudonymized information processed by different personal information controllers for statistical purposes, scientific research and preservation of records for public interest, etc. shall be conducted by a specialized institution designated by the Protection Commission or the head of the related central administrative agency.
(2) A personal information controller who intends to release the combined information outside the organization that combined the information shall obtain approval from the head of the specialized institution after processing the information into pseudonymized information or the form referred to in Article 58-2.
(3) Necessary matters including the procedures and methods of combination pursuant to paragraph (1), standards and procedures to designate, or cancel the designation of, a specialized institution management and supervision, and standards and procedures of exporting and approval pursuant to paragraph (2) shall be prescribed by Presidential Decree.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 28-4 (Obligation to Take Safety Measures for Pseudonymous Data)
(1) When processing the pseudonymized information, a personal information controller shall take such technical, organizational and physical measures as separately storing and managing additional information needed for restoration to the original state, as may be necessary to ensure safety as prescribed by Presidential Decree so that the personal information may not be lost, stolen, divulged, forged, altered, or damaged.
(2) A personal information controller who intends to process the pseudonymized information shall prepare and keep records relating to matters prescribed by the Presidential Decree including the purpose of processing the pseudonymized information, and a third party recipient when pseudonymized information is provided, to manage the processing of pseudonymized information.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 28-5 (Prohibited Acts for the Processing of the Pseudonymized Information)
(1) No one shall process the pseudonymized information for the purpose of identifying a certain individual.
(2) When information identifying a certain individual is generated while the pseudonymized information is processed, the personal information controller shall cease the processing of the information, and retrieve and destroy the information immediately.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 28-6 (Imposition of Administrative Surcharges for the Processing of the Pseudonymized Information)
(1) The Commission may impose a fine equivalent to less than three-hundredths of total sales on data controller who has processed data for the purpose of identifying a specific individual in violation of Article 28-5 (1): Provided, That in case where there is no sales or difficulty in calculating the sales revenues, the data controller may be subject to a fine of not more than 400 million won or three-hundredths of the capital amount, whichever is greater.
(2) Article 34-2 (3) through (5) shall apply mutatis mutandis to matters necessary to impose and collect administrative surcharges.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 28-7 (Scope of Application)
Articles 20, 21, 27, 34 (1), 35 through 37, 39-3, 39-4, 39-6 through 39-8 shall not apply to the pseudonymized information.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
CHAPTER IV SAFEGUARD OF PERSONAL INFORMATION
법령 이단보기
Article 29 (Duty of Safeguards)
Every personal information controller shall take such technical, managerial, and physical measures as establishing an internal management plan and preserving access records, etc. that are necessary to ensure safety as prescribed by Presidential Decree so that the personal information may not be lost, stolen, divulged, forged, altered, or damaged.<Amended by Act No. 13423, Jul. 24, 2015>
법령 이단보기
Article 30 (Establishment and Disclosure of Privacy Policy)
(1) Every personal information controller shall establish a personal information processing policy including the following matters (hereinafter referred to as "Privacy Policy"). In such cases, public institutions shall establish the Privacy Policy for the personal information files to be registered pursuant to Article 32: <Amended by Act No. 14107, Mar. 29, 2016>
1. The purposes for which personal information is processed;
2. The period for processing and retaining personal information;
3. Provision of personal information to a third party (if applicable);
3-2. Procedures and methods for destroying personal information (if personal information shall be preserved according to the proviso of Article 21 (1), this shall include the basis of preservation and particulars of personal information to be preserved);
4. Outsourcing personal information processing (if applicable);
5. The rights and obligations of data subjects and legal representatives, and how to exercise such rights;
6. Contact information, such as the name of a privacy officer designated under Article 31 or the name, telephone number, etc. of the department which performs the duties related to personal information protection and handles related grievances;
7. Installation and operation of an automatic collection tool for personal information, including internet access data files, and the denial thereof (if applicable);
8. Other matters prescribed by Presidential Decree regarding the processing of personal information.
(2) Upon establishing or modifying the Privacy Policy, a personal information controller shall disclose the content so that data subjects may easily recognize it in such a way as prescribed by Presidential Decree.
(3) Where there exist discrepancies between the Privacy Policy and the agreement executed by and between the personal information controller and data subjects, the terms that are beneficial to the data subjects shall prevail.
(4) The Protection Commission may prepare the Privacy Policy Guidelines and encourage the personal information controllers to comply with such Guidelines.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
법령 이단보기
Article 31 (Designation of Privacy Officers)
(1) A personal information controller shall designate a privacy officer who comprehensively takes charge of personal information processing.
(2) Every privacy officer shall perform the following functions:
1. To establish and implement a personal information protection plan;
2. To conduct a regular survey of the status and practices of personal information processing, and to improve shortcomings;
3. To handle grievances and remedial compensation in relation to personal information processing;
4. To build the internal control system to prevent the divulgence, abuse, and misuse of personal information;
5. To prepare and implement an education program about personal information protection;
6. To protect, control, and manage the personal information files;
7. Other functions prescribed by Presidential Decree for the appropriate processing of personal information.
(3) In performing the functions provided for in paragraph (2), a privacy officer may inspect the status of personal information processing and systems frequently, if necessary, and may request a report thereon from the relevant parties.
(4) Where a privacy officer becomes aware of any violation of this Act or other relevant statutes in relation to the protection of personal information, the privacy officer shall take corrective measures immediately, and shall report such corrective measures to the head of the institution or organization to which he or she belongs, if necessary.
(5) A personal information controller shall not have the chief privacy officer impose or be subject to disadvantages without any justifiable ground while performing the functions provided for in paragraph (2).
(6) The requirements for designation as privacy officers, functions, qualifications, and other necessary matters, shall be prescribed by Presidential Decree.
법령 이단보기
Article 32 (Registration and Disclosure of Personal Information Files)
(1) Upon operating personal information files, the head of a public institution shall register the following matters with the Protection Commission. The same shall also apply where the registered matters are modified. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
1. The titles of the personal information files;
2. The grounds and purposes for the operation of the personal information files;
3. Particulars of personal information that are recorded in the personal information files;
4. The method of processing personal information;
5. The period for retaining personal information;
6. The recipient of personal information, if it is provided routinely or repetitively;
7. Other matters prescribed by Presidential Decree.
(2) Paragraph (1) shall not apply to any of the following personal information files:
1. Personal information files that record national security, diplomatic secrets, and other matters relating to grave national interests;
2. Personal information files that record the investigation of crimes, indictment and prosecution, punishment, and probation and custody, corrective orders, protective orders, security observation orders, and immigration;
3. Personal information files that record the investigations of violations of the Punishment of Tax Offenses Act and the Customs Act;
4. Personal information files exclusively used for internal job performance of public institutions;
5. Classified personal information files pursuant to other statutes.
(3) The Protection Commission may, if necessary, review the registration and content of the personal information files referred to in paragraph (1), and advise the head of the relevant public institution to make improvements.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(4) The Protection Commission shall make public the status of registered personal information files under paragraph (1) so that anyone may access them with ease.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(5) Necessary matters regarding the registration referred to in paragraph (1), the method, scope, and procedure of public disclosure referred to in paragraph (4), shall be prescribed by Presidential Decree.
(6) The registration and public disclosure of the personal information files retained by the National Assembly, the Court, the Constitutional Court and the National Election Commission (including their affiliated entities) shall be prescribed by the National Assembly Regulations, the Supreme Court Regulations, the Constitutional Court Regulations, and the National Election Commission Regulations.
법령 이단보기
Article 32-2 (Certification of Personal Information Protection)
(1) The Protection Commission may certify whether the data processing and other data protection-related action of a personal information controller abide by this Act, etc. <Amended by Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(2) The certification provided for in paragraph (1) shall be effective for three years.
(3) In any of the following cases, the Protection Commission may revoke the certification granted under paragraph (1), as prescribed by Presidential Decree: Provided, That it shall be revoked in cases falling under subparagraph 1: <Amended by Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
1. Where personal information protection has been certified by fraud or other unjust means;
2. Where follow-up management provided for in paragraph (4) has been denied or obstructed;
3. Where the certification criteria provided for in paragraph (8) have not been satisfied;
4. Where personal information protection-related statutes are breached seriously.
(4) The Protection Commission shall conduct follow-up management at least once annually to maintain the effectiveness of the certification of personal information protection. <Amended by Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(5) The Protection Commission may authorize the specialized institutions prescribed by Presidential Decree to perform the duties related to certification under paragraph (1), revocation of certification under paragraph (3), follow-up management under paragraph (4), management of certification examiners under paragraph (7). <Amended by Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(6) Any person who has obtained certification subject to paragraph (1) may indicate or promote the certification, as prescribed by Presidential Decree.
(7) Qualifications of certification examiners who conduct the certification examination subject to paragraph (1), criteria for disqualification, and other related matters shall be prescribed by Presidential Decree, taking into account specialty, career, and other necessary matters.
(8) Other necessary matters for the certification criteria, method, procedure, etc. subject to paragraph (1), including whether the personal information management system, guarantee of data subjects’ rights, and measures to ensure safety are based on this Act, shall be prescribed by Presidential Decree.
[This Article Newly Inserted by Act No. 13423, Jul. 24, 2015]
법령 이단보기
Article 33 (Privacy Impact Assessment)
(1) In the case there is a risk of an infringement with respect to personal information of data subjects due to the operation of personal information files meeting the criteria prescribed by Presidential Decree, the head of a public institution shall conduct an assessment to analyze risk factors and improve them (hereinafter referred to as “privacy impact assessment”), and submit the results thereof to the Protection Commission. In such cases, the head of the public institution shall request the privacy impact assessment from any of the institutions designated by the Protection Commission (hereinafter referred to as “PIA institution”). <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(2) The privacy impact assessment shall cover the following matters:
1. The number of personal information being processed;
2. Whether the personal information is provided to a third party;
3. The probability to violate the rights of the data subjects and the degree of risks;
4. Other matters prescribed by Presidential Decree.
(3) The Protection Commission may provide its opinion on the results of the privacy impact assessment submitted under paragraph (1).<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(4) The head of a public institution shall register the personal information files in accordance with Article 32 (1), for which the privacy impact assessment has been conducted pursuant to paragraph (1), with the results of the privacy impact assessment attached thereto.
(5) The Protection Commission shall take necessary measures, such as fostering relevant specialists, and developing and disseminating criteria for the privacy impact assessment, to promote the privacy impact assessment. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(6) Necessary matters in relation to the privacy impact assessment, such as the criteria for designation as PIA institutions, revocation of designation, assessment criteria, method and procedure, etc. pursuant to paragraph (1), shall be prescribed by Presidential Decree.
(7) Matters regarding the privacy impact assessment conducted by the National Assembly, the Court, the Constitutional Court and the National Election Commission (including their affiliated entities) shall be prescribed by the National Assembly Regulations, the Supreme Court Regulations, the Constitutional Court Regulations, and the National Election Commission Regulations.
(8) A personal information controller other than public institutions shall proactively endeavor to conduct a privacy impact assessment, if there is a risk of an infringement with respect to personal information of data subjects in operating the personal information files.
법령 이단보기
Article 34 (Data Breach Notification)
(1) A personal information controller shall notify data subjects of the following matters without delay when the personal information controller becomes aware their personal information has been divulged:
1. Particulars of the personal information divulged;
2. When and how personal information has been divulged;
3. Any information about how the data subjects can minimize the risk of damage from divulgence, etc.;
4. Countermeasures taken by the personal information controller and remedial procedure;
5. Help desk and contact points for the data subjects to report damage.
(2) A personal information controller shall prepare countermeasures to minimize the risk of damage in the case of divulgence of personal information and take necessary measures.
(3) Where a breach of personal information above the scale prescribed by Presidential Decree takes place, the personal information controller shall, without delay, report the results of notification given under paragraph (1) and the results of measures taken under paragraph (2) to the Protection Commission or a specialized institution designated by Presidential Decree. In such cases, the Protection Commission and the specialized institution designated by Presidential Decree may provide technical assistance for the prevention and recovery of further damage, etc.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(4) Necessary matters in relation to the time, method, and procedure of data breach notification pursuant to paragraph (1), shall be prescribed by Presidential Decree.
법령 이단보기
Article 34-2 (Imposition, etc. of Penalty Surcharges)
(1) The Protection Commission may impose and collect a penalty surcharge not exceeding 500 million won where a personal information controller has failed to prevent any loss, theft, divulgence, forgery, alteration, or damage of resident registration numbers: Provided, That this shall not apply where the personal information controller has fully taken measures necessary to ensure safety under Article 24 (3) to prevent any loss, theft, divulgence, forgery, alteration, or damage of resident registration numbers. <Amended by Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(2) The Protection Commission shall take into account the following when imposing the administrative surcharge pursuant to paragraph (1): <Amended by Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
1. Scale of efforts taken to perform the measures necessary to ensure safety under Article 24 (3);
2. Status of the resident registration numbers which have been lost, stolen, divulged, forged, altered or damaged;
3. Fulfillment of subsequent measures to prevent further damage.
(3) The Protection Commission shall collect a late-payment penalty prescribed by Presidential Decree in an amount not exceeding 6/100 per annum of the unpaid administrative surcharge for the period beginning on the following day of the expiration of the payment deadline and ending on the day immediately preceding the day of payment of the administrative surcharge where a person liable to pay the administrative surcharge under paragraph (1) fails to pay the same by the payment deadline. In such cases, the late-payment penalty shall be collected for a maximum period of 60 months.<Amended by Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(4) Where a person liable to pay the administrative surcharge under paragraph (1) fails to pay the same by the payment deadline, the Protection Commission shall give notice with the period of payment specified therein; and where the administrative surcharge and late-payment penalty are not paid within the specified period, the Protection Commission shall collect such administrative surcharge and late-payment penalty in the same manner as delinquent national taxes are collected.<Amended by Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(5) Other matters necessary for imposing and collecting penalty surcharges shall be prescribed by Presidential Decree.
[This Article Newly Inserted by Act No. 11990, Aug. 6, 2013]
CHAPTER V GUARANTEE OF RIGHTS OF DATA SUBJECTS
법령 이단보기
Article 35 (Access to Personal Information)
(1) A data subject may request access to his or her own personal information, which is processed by a personal information controller, from the personal information controller.
(2) Notwithstanding paragraph (1), where a data subject intends to request access to his or her own personal information from a public institution, the data subject may request such access directly from the said public institution, or indirectly via the Protection Commission, as prescribed by Presidential Decree.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No 16930, February. 4, 2020>
(3) Upon receipt of a request for access filed under paragraphs (1) and (2), a personal information controller shall grant the data subject access to his or her own personal information within the period prescribed by Presidential Decree. In such cases, if there is any justifiable ground not to permit access during such period, the personal information controller may postpone access after notifying the relevant data subject of the said ground. If the said ground ceases to exist, the data subject shall be permitted to access the personal information without delay.
(4) In any of the following cases, a personal information controller may limit or deny access after it notifies a data subject of the cause:
1. Where access is prohibited or limited by Acts;
2. Where access may cause damage to the life or body of a third party, or unjustified infringement of property and other interests of any other person;
3. Where a public institution has grave difficulties in performing any of the following duties:
(a) Imposition, collection or refund of taxes;
(b) Evaluation of academic achievements or admission affairs at the schools of each level established under the Elementary and Secondary Education Act and the Higher Education Act, lifelong educational facilities established under the Lifelong Education Act, and other higher educational institutions established under other Acts;
(c) Testing and qualification examination regarding academic competence, technical capability and employment;
(d) Ongoing evaluation or decision-making in relation to compensation or grant assessment;
(e) Ongoing audit and examination under other Acts.
(5) Necessary matters in relation to the methods and procedures to file access requests, to limit access, to give notification, etc. pursuant to paragraphs (1) through (4) shall be prescribed by Presidential Decree.
법령 이단보기
Article 36 (Rectification or Erasure of Personal Information)
(1) A data subject who has accessed his or her personal information pursuant to Article 35 may request a correction or erasure of such personal information from the relevant personal information controller: Provided, That the erasure is not permitted where the said personal information shall be collected by other statutes.
(2) Upon receipt of a request by a data subject pursuant to paragraph (1), the personal information controller shall investigate the personal information in question without delay; shall take necessary measures to correct or erase as requested by the data subject unless otherwise specifically provided by other statutes in relation to correction or erasure; and shall notify such data subject of the result.
(3) The personal information controller shall take measures not to recover or revive the personal information in case of erasure pursuant to paragraph (2).
(4) Where the request of a data subject falls under the proviso to paragraph (1), a personal information controller shall notify the data subject of the details thereof without delay.
(5) While investigating the personal information in question pursuant to paragraph (2), the personal information controller may, if necessary, request from the relevant data subject the evidence necessary to confirm a correction or erasure of the personal information.
(6) Necessary matters in relation to the request of correction and erasure, notification method and procedure, etc. pursuant to paragraphs (1), (2) and (4) shall be prescribed by Presidential Decree.
법령 이단보기
Article 37 (Suspension of Processing of Personal Information)
(1) A data subject may request the relevant personal information controller to suspend the processing of his or her personal information. In such cases, if the personal information controller is a public institution, the data subject may request the suspension of processing of only the personal information contained in the personal information files to be registered pursuant to Article 32.
(2) Upon receipt of the request under paragraph (1), the personal information controller shall, without delay, suspend processing of some or all of the personal information as requested by the data subject: Provided, That, where any of the following is applicable, the personal information controller may deny the request of such data subject:
1. Where special provisions exist in other laws or it is inevitable to observe legal obligations;
2. Where access may cause damage to the life or body of a third party, or unjustified infringement of property and other interests of any other person;
3. Where the public institution cannot perform its work as prescribed by any Act without processing the personal information in question;
4. Where it is impracticable to perform a contract such as the provision of services as agreed upon with the said data subject without processing the personal information in question, and the data subject has not clearly expressed the desire to terminate the agreement.
(3) When denying the request pursuant to the proviso to paragraph (2), the personal information controller shall notify the data subject of the reason without delay.
(4) The personal information controller shall, without delay, take necessary measures including destruction of the relevant personal information when suspending the processing of personal information as requested by data subjects.
(5) Necessary matters in relation to the methods and procedures to request the suspension of processing, to deny such request, and to give notification, etc. pursuant to paragraphs (1) through (3) shall be prescribed by Presidential Decree.
법령 이단보기
Article 38 (Methods and Procedures for Exercise of Rights)
(1) A data subject may authorize his or her representative to file requests for access pursuant to Article 35, correction or erasure pursuant to Article 36, suspension of processing pursuant to Article 37, and withdrawal of consent pursuant to Article 39-7 (hereinafter referred to as “request for access, etc.”) by the methods and procedure prescribed by Presidential Decree, such as written documents. <Amended by Act No 16930, February. 4, 2020>
(2) The legal representative of a child under 14 years of age may file a request for access, etc. to the personal information of the child with a personal information controller.
(3) A personal information controller may demand a fee and postage (only in case of a request to mail the copies), as prescribed by Presidential Decree, from a person who files a request for access, etc.
(4) A personal information controller shall prepare the detailed method and procedure to enable data subjects to file requests for access, etc., and publicly announce such method and procedure so that the data subjects may become aware of them.
(5) A personal information controller shall prepare and provide necessary procedures for data subjects to raise objections regarding the denial of a request for access, etc. from such data subjects.
법령 이단보기
Article 39 (Responsibility for Compensation)
(1) A data subject who suffers damage by reason of a violation of this Act by a personal information controller is entitled to claim compensation from the personal information controller for such damage. In such cases, the said personal information controller may not be released from responsibility for compensation if it fails to prove the non-existence of wrongful intent or negligence.
(2) Deleted. <by Act No. 13423, Jul. 24, 2015>
(3) Where a data subject suffers damage out of loss, theft, divulgence, forgery, alteration, or damage of his or her own personal information, caused by wrongful intent or negligence of a personal information controller, the Court may determine the amount of compensation for damage not exceeding three times such damage: Provided, That the same shall not apply to the personal information controller who has proved non-existence of his or her wrongful intent or negligence. <Newly Inserted by Act No. 13423, Jul. 24, 2015>
(4) The Court shall take into account the following when determining the amount of compensation for damage pursuant to paragraph (3): <Newly Inserted by Act No. 13423, Jul. 24, 2015>
1. The degree of wrongful intent or expectation of damage;
2. The amount of loss caused by the violation;
3. Economic benefits the personal information controller gained in relation to the violation;
4. A fine and a penalty surcharge to be levied subject to the violation;
5. The duration, frequency, etc. of violations;
6. The property of the personal information controller;
7. The personal information controller’s efforts to retrieve the affected personal information after the loss, theft, or divulgence of personal information;
8. The personal information controller’s efforts to remedy damage suffered by the data subject.
법령 이단보기
Article 39-2 (Claims for Statutory Compensation)
(1) Notwithstanding Article 39 (1), a data subject, who suffers damage out of loss, theft, divulgence, forgery, alteration, or damage of his or her own personal information, caused by wrongful intent or negligence of a personal information controller, may claim a reasonable amount of damages not exceeding three million won. In such cases, the said personal information controller may not be released from the responsibility for compensation if it fails to prove non-existence of his or her wrongful intent or negligence.
(2) In the case of a claim made under paragraph (1), the Court may determine a reasonable amount of damages not exceeding the amount provided for in paragraph (1) taking into account all arguments in the proceedings and the results of examining evidence.
(3) A data subject who has claimed compensation pursuant to Article 39 may change such claim to the claim provided for in paragraph (1) until the closure of fact-finding proceedings.
[This Article Newly Inserted by Act No. 13423, Jul. 24, 2015]
CHAPTER VI SPECIAL CASES CONCERNING PROCESSING OF PERSONAL INFORMATION BY PROVIDERS OF INFORMATION AND COMMUNICATIONS SERVICES OR SIMILAR
법령 이단보기
Article 39-3 (Special Cases on Consent to the Collection and Use of Personal Information)
(1) Notwithstanding Article 15 (1), an information and communications service provider who intends to collect and use personal information of users shall notify users of the following matters and obtain consent therefor. The same shall apply when changes are made for the following matters:
1. The purpose of the collection and use of personal information;
2. Particulars of personal information to be collected;
3. The period for retaining and using personal information.
(2) An information and communications service provider may collect and use personal information of users without their consent under paragraph (1) in any of the following cases:
1. Where the information is necessary in implementing a contract for provision of information and communications services (referring to the information and communications services defined in Article 2 (1) 2 of the Act on Promotion of Information and Communications Network Utilization and Information Protection; hereinafter the same shall apply), but it is clearly difficult to obtain ordinary consent for economic and technical reasons;
2. Where the information is necessary to calculate fees for the provision of information and communications services;
3. Where special provisions exist in other laws.
(3) No information and communications service provider shall reject the provision of services for the reason that a user does not provide his/her personal information beyond the minimum personal information required. The minimum personal information refers to information that is necessary for the performance of the fundamental functions of the services.
(4) An information and communications provider who intends to obtain consent from children aged under 14 for the collection, use and provision of personal information shall obtain such consent from his/her legal representative and confirm whether the legal representative has granted consent as prescribed by the Presidential Decree.
(5) An information and communications provider shall, when notifying children aged under 14 of matters relating to the processing of personal information, use understandable forms and plain and readily comprehensible language.
(6) The Protection Commission shall take measures to protect the personal information of children aged under 14 who may not clearly understand matters such as the risks and results of personal information processing and users’ rights.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-4 (Special Cases on the Notification and Reporting on the Divulgence of Personal Information)
(1) Notwithstanding Article 34 (1) and (3), information and communications service provider and a person who receives personal information of users therefrom pursuant to Article 17 (1) (hereinafter referred to as “information and communications service provider, etc.”) shall notify the relevant users of the following matters without delay upon becoming aware that their personal information has been lost, stolen or divulged (hereinafter referred to as “divulgence, etc.”), report such case to a specialized institution prescribed by the Protection Commission or Presidential Decree, and shall notify the users or report that matter not later than 24 hours since he or she became aware of such fact, without a justifiable reason: Provided, That if there is a justifiable reason such as users’ contact number being unknown, other measures may be taken in lieu of notification as prescribed by Presidential Decree:
1. Particulars of the personal information divulged, etc.;
2. The time when the personal information has been divulged, etc.;
3. Any measure that users can take;
4. Countermeasures to be taken by of the information and communications service provider, etc.;
5. Department and contact points to which the user can apply for consultation.
(2) A specialized institution prescribed by Presidential Decree which receives a report pursuant to paragraph (1) shall notify the Protection Commission of the case without delay.
(3) An information and communications service provider, etc. shall explain any justifiable reason pursuant to paragraph (1) to the Protection Commission.
(4) Necessary matters in relation to the methods and procedures of notification and reporting under paragraph (1) shall be prescribed by the Presidential Decree.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-5 (Special Cases on Safeguards for Personal Information)
Information and communications service provider, etc. shall limit the number of persons who process users’ personal information to the minimum extent.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-6 (Special Cases on the Destruction of Personal Information)
(1) Information and communications service provider, etc. shall take necessary measures as prescribed by Presidential Decree such as destruction to protect the personal information of users who have not used information and communications services for one year: Provided, That, if the period is designated otherwise by other statutes or at the request of the user, the designated period shall apply.
(2) Information and communications service provider, etc. shall notify users of matters prescribed by Presidential Decree such as the fact that their personal information will be destroyed, the expiration date, and the particulars of personal information to be destroyed by a method prescribed by Presidential Decree such as e-mail, at least 30 days prior to the expiration of the above designated period.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-7 (Special Cases on Users’ Rights)
(1) Users may withdraw consent to the collection, use and provision of personal information at any time from information and communications service provider, etc.
(2) Information and communications service providers, etc. must make it easier for users to request to withdraw their consent under paragraph (1), to access their information under Article 35, and to rectify under Article 36 than to give consent to the collection of their personal information.
(3) Once a user withdraws his or her consent pursuant to paragraph (1), the information and communications service provider, etc. shall take necessary measures without delay such as destroying the information to such an extent that it is not recoverable or revivable.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-8 (Notification of the Use History of Personal Information)
(1) Information and communications service provider, etc. meeting standards prescribed by President Decree shall notify users of the use history of their personal information collected pursuant to Articles 23 and 39-3 (including provision pursuant to Article 17) on a regular basis: Provided, That this shall not apply where the collected information does not include a contact number, etc. that enables notification to users,
(2) The type of information to be notified to users under paragraph (1), the types of information to be notified, the frequency and method of notification, and other matters necessary for the notification of the details shall be determined by Presidential Decree.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-9 (Indemnity for Losses)
(1) Information and communications service providers, etc. shall take necessary measures such as purchasing insurance or deduction plans or accumulating reserves to fulfil its liabilities for compensation pursuant to Articles 39 and 39-2.
(2) Necessary matters including the scope of personal information controllers subject to the obligation pursuant to paragraph (1) and relevant standards shall be prescribed by Presidential Decree.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-10 (Deletion and Blocking of Exposed Personal Information)
(1) Information and communications service provider, etc. shall ensure that users’ personal information including resident registration number, bank account information and credit card information is not exposed to the public through information and communications networks.
(2) Notwithstanding paragraph (1), at the request of the Protection Commission or specialized institutions designated by Presidential Decree in relation to personal information exposed to the public, information and communications service provider, etc. shall take necessary measures such as deleting and blocking.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-11 (Designation of Domestic Agents)
(1) Information and communications service provider, etc. with no address or business office in Korea meeting the criteria prescribed by Presidential Decree in consideration of the number of users and revenues shall designate an agent to act on his or her behalf with respect to the following (hereinafter referred to as "domestic agent") in writing:
1. Duties of a privacy officer under Article 31;
2. Notification and reporting under Article 39-4;
3. Submission of related articles, documents, etc. under Article 63 (1).
(2) A domestic agent shall have an address or business office in Korea.
(3) When a domestic agent is designated pursuant to paragraph (1), the following matters shall all be included in the Privacy Policy pursuant to Article 30:
1. Name of the domestic agent (for a corporation, the title and name of the representative);
2. Address of the domestic agent (for a corporation, location of a business office), telephone number, e-mail address.
(4) If the domestic agent violates this Act in relation to each item of paragraph (1), the information and communications service provider, etc. shall be deemed to have committed such a violation.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-12 (Protection of Information Transferred Overseas)
(1) The information and communications service provider, etc. shall not execute an international contract in violation of this Act in relation to users’ personal information.
(2) Notwithstanding Article 17 (3), information and communications service provider, etc. shall obtain users’ consent if intending to provide (including accessing), outsource the processing of, or store (hereinafter referred to as “transfer” in this Article) users’ personal information overseas: Provided, That if all items of paragraph (3) below are made public pursuant to Article 30 (2) or notified to users by a method prescribed by the Presidential Decree such as e-mail, the information and communications service provider, etc. may opt not to obtain users’ consent to outsourcing the processing of, or storing, personal information.
(3) The information and communications service provider, etc. shall notify users of the following matters in advance if intending to obtain consent under paragraph (2):
1. Particulars of the personal information to be transferred;
2. The country to which the personal information is transferred, transfer date and method;
3. Name of the entity to which the personal information is transferred (referring to the name of a corporation and the contact information of the person responsible for the management of information, if the person is a corporation);
4. The purpose of using personal information by the entity to which the information is transferred and the period of retaining and using personal information.
(4) The information and communications service provider, etc. shall implement safeguards as prescribed by Presidential Decree if intending to transfer personal information overseas with consent obtained pursuant to paragraph (2).
(5) where a person who receives personal information of the users transfers it to a third country, he or she shall comply with paragraphs (1) through (4). In such cases, "information and communications service providers, etc." shall be regarded as "personal information recipient," and "personal information recipient" shall be regarded as "a person who receives personal information from a third country.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-13 (Reciprocity)
Notwithstanding Article 39-12, information and communications service providers, etc. in a country that restricts cross-border transfer may face an equivalent level of restrictions in another country: Provided, That this shall not apply where cross-border transfer is necessary to implement a pact or other international arrangements.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-14 (Special Cases for Broadcasting Service Providers)
If entities falling under subparagraphs 3 (a) through (e), 6, 9, 12 and 14 of Article 2 of the Broadcasting Act (hereinafter referred to as “broadcasting service provider, etc.”) process the personal information of viewers, the broadcasting service provider, etc. shall observe regulations applicable to an information and communications service provider, etc. In such cases, “broadcasting service provider, etc.” shall be deemed to be “information and communications service provider, etc.” and “viewers” to be “users.”
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 39-15 (Special Cases for the Imposition of Administrative Surcharges)
(1) Upon information and communications service provider, etc. conducting any of the following acts, the Protection Commission may impose administrative surcharges not exceeding 3/100 of the total revenues relating to the concerned violation:
1. Using or providing personal information in violation of Articles 17 (1), 17 (2), 18 (1), 18 (2), and 19 (including applicable cases pursuant to Article 39-14);
2. Collecting personal information of a child aged under 14 without his/her legal representative’s consent in violation of Article 22 (6) (including applicable cases pursuant to Article 39-14);
3. Collecting sensitive information without the user’s consent in violation of Article 23 (1) 1 (including applicable cases pursuant to Article 39-14);
4. Where it neglects its control, supervision, or education under Article 26 (4) (including where the aforesaid provisions apply mutatis mutandis pursuant to Article 39-14), thereby causing an outsourcee subject to special cases to violate this Act;
5. Losing, stealing, divulging, forging, altering, or damaging users’ personal information and failing to take measures (excluding matters on the establishment of internal management plan) set forth in Article 29 (including applicable cases pursuant to Article 39-14);
6. Collecting users’ personal information without their consent in violation of Article 39-3 (1) (including applicable cases pursuant to Article 39-14);
7. Providing users’ personal information overseas without their consent in violation of the main clause of Article 39-12 (2) (including applicable cases pursuant to paragraph (5) of the same Article).
(2) When administrative surcharges are imposed in accordance to paragraph (1), but the information and communications service provider, etc. either refuses to submit basic materials for revenue calculation or submits false documents, their revenues may be estimated based on the accounting documents, such as financial statements, and operational status, such as the number of subscribers and usage fees, of similar-sized information and communications service providers, etc.: Provided, That up to 400 won million may be imposed as administrative surcharges on an information and communications service provider, etc. having no revenues or revenues difficult to calculate as prescribed by Presidential Decree.
(3) The Protection Commission shall consider the following matters to impose administrative surcharges under paragraph (1):
1. Details and degree of the violation;
2. Period and number of the violation;
3. Size of profits gained from the violation.
(4) Administrative surcharges under paragraph (1) shall be calculated in consideration of paragraph (3), but the detailed calculation standards and procedures shall be prescribed by Presidential Decree.
(5) The Protection Commission shall collect a late-payment penalty in the amount not exceeding 6/100 per annum of the unpaid administrative surcharges for the period beginning on the following day of the expiration of the payment deadline.
(6) Where a person liable to pay the administrative surcharges under paragraph (1) fails to pay it by the payment deadline, the Protection Commission shall give notice with the period of payment specified in it; and where the administrative surcharges and late-payment penalty under paragraph (5) are not paid within the specified period, the Protection Commission shall collect such administrative surcharges and late-payment penalty in the same manner as delinquent national taxes are collected.
(7) When the administrative surcharges imposed according to paragraph (1) are refunded for such reasons as a court’s decision, the Protection Commission shall make additional payments in the amount calculated based on the interest rate prescribed by Presidential Decree considering the deposit interest rates of financial companies, etc., for the period beginning on the following day of the payment of administrative surcharges and ending on the day of the refund.
(8) Notwithstanding paragraph (7), when a disposition of imposing administrative surcharges is revoked due to a court’s decision and new administrative surcharges are imposed based on the reasoning of the decision, additional payments shall be calculated and paid with respect to the amount that remains after the newly imposed administrative surcharges are deducted from the already paid administrative surcharges.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
CHAPTER VII PERSONAL INFORMATION DISPUTE MEDIATION COMMITTEE
법령 이단보기
Article 40 (Establishment and Composition)
(1) There shall be established a Personal Information Dispute Mediation Committee (hereinafter referred to as the “Dispute Mediation Committee”) to mediate disputes over personal information.
(2) The Dispute Mediation Committee shall be comprised of not more than 20 members, including one chairperson, and the members shall be ex officio members and commissioned members. <Amended by Act No. 13423, Jul. 24, 2015>
(3) The commissioned members shall be commissioned by the Chairperson of the Protection Commission from among the following persons, and public officials of the national agencies prescribed by Presidential Decree shall be ex officio members: <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015>
1. Persons who previously served as members of the Senior Executive Service of the central administrative agencies in charge of personal information protection, or persons who presently work or have worked at equivalent positions in the public sector and related organizations, and have job experience in personal information protection;
2. Persons who presently serve or have served as associate professors or higher positions in universities or in publicly recognized research institutes;
3. Persons who presently serve or have served as judges, public prosecutors, or attorneys-at-law;
4. Persons recommended by data protection-related civic organizations or consumer groups;
5. Persons who presently work or have worked as senior officers for the trade associations comprised of personal information controllers.
(4) The chairperson shall be commissioned by the Chairperson of the Protection Commission from among Committee members who are not public officials. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015>
(5) The term of office for the chairperson and commissioned members shall be two years, and their term may be renewable for one further term. <Amended by Act No. 13423, Jul. 24, 2015>
(6) In order to conduct dispute settlement efficiently, the Dispute Mediation Committee may, if necessary, establish a mediation panel that is comprised of not more than five Committee members in each sector of mediation cases, as prescribed by Presidential Decree. In this case, the resolution of the mediation panel delegated by the Dispute Mediation Committee shall be construed as that of the Dispute Mediation Committee.
(7) The quorum for holding a Dispute Mediation Committee or a mediation panel shall be the presence of a majority of its members, and any resolution shall require the affirmative votes of a majority of the members present.
(8) The Protection Commission may deal with the administrative affairs necessary for dispute mediation, such as receiving dispute mediation cases and fact-finding. <Amended by Act No. 13423, Jul. 24, 2015>
(9) Except as otherwise expressly provided for in this Act, matters necessary to operate the Dispute Mediation Committee shall be prescribed by Presidential Decree.
법령 이단보기
Article 41 (Guarantee of Members’ Status)
None of the Committee members shall be dismissed or de-commissioned against his or her will except when he or she is sentenced to the suspension of qualification or a heavier punishment, or unable to perform his or her duties due to mental or physical incompetence.
법령 이단보기
Article 42 (Exclusion, Recusal, and Refrainment of Members)
(1) A member of the Dispute Mediation Committee shall be excluded from participating in the deliberation and resolution of a case requested for dispute mediation pursuant to Article 43 (1) (hereafter in this Article referred to as “case”) if:
1. The member or his/her current or former spouse is a party to the case or is a joint right holder or a joint obligator with respect to the case;
2. The member is or was a relative of a party to the case;
3. The member has given any testimony, expert opinion, or legal advice with respect to the case;
4. The member is or was involved in the case as an agent or representative of a party to the case.
(2) Where any party finds it impracticable to expect a fair deliberation and resolution from a Committee member, such party may file an application for recusal with the chairperson. In such cases, the chairperson shall determine with respect to such application for recusal without any resolution of the Dispute Mediation Committee.
(3) Where any committee member falls under the case of paragraph (1) or (2), he/she may refrain from the deliberation and resolution of the case.
법령 이단보기
Article 43 (Application for Mediation)
(1) Any person who wishes a dispute over personal information mediated may apply for mediation of the dispute to the Dispute Mediation Committee.
(2) Upon receipt of an application for dispute mediation from a party to the case, the Dispute Mediation Committee shall notify the counterparty of the application for mediation.
(3) Where a public institution is notified of dispute mediation under paragraph (2), the public institution shall respond to it unless there are extraordinary circumstances.
법령 이단보기
Article 44 (Time Limitation of Mediation Proceedings)
(1) The Dispute Mediation Committee shall examine the case and prepare a draft mediation decision within 60 days from the date of receiving an application pursuant to Article 43 (1): Provided, That the Dispute Mediation Committee may pass a resolution to extend such period by reason of inevitable circumstances.
(2) Where the period is extended pursuant to the proviso to paragraph (1), the Dispute Mediation Committee shall inform the applicant of the reasons for extending the period and other matters concerning the extension of such period.
법령 이단보기
Article 45 (Request for Materials)
(1) Upon receipt of an application for dispute mediation pursuant to Article 43 (1), the Dispute Mediation Committee may request disputing parties to provide materials necessary to mediate the dispute. In such cases, such parties shall comply with the request unless any justifiable ground exists.
(2) The Dispute Mediation Committee may require disputing parties or relevant witnesses to appear before the Committee to hear their opinions, if deemed necessary.
법령 이단보기
Article 46 (Settlement Advice before Mediation)
Upon receipt of an application for dispute mediation pursuant to Article 43 (1), the Dispute Mediation Committee may present a draft settlement to the disputing parties and recommend a settlement before mediation.
법령 이단보기
Article 47 (Dispute Mediation)
(1) The Dispute Mediation Committee may prepare a draft mediation decision including the following matters:
1. Suspension of the violation to be investigated;
2. Restitution, compensation and other necessary remedies;
3. Any measure necessary to prevent recurrence of the identical or similar violations.
(2) Upon preparing a draft mediation pursuant to paragraph (1), the Dispute Mediation Committee shall present the draft mediation to each party without delay.
(3) Each party presented with the draft mediation decision prepared under paragraph (1) shall notify the Dispute Mediation Committee of his/her acceptance or denial of the draft mediation decision within 15 days from the date of receipt of such draft mediation decision, without which such mediation shall be deemed rejected.
(4) If the parties accept the draft mediation decision, the Dispute Mediation Committee shall prepare a written mediation decision, and the chairperson of the Dispute Mediation Committee and the parties shall have their names and seals affixed thereon.
(5) The mediation agreed upon pursuant to paragraph (4) shall have the same effect as a settlement before the court.
법령 이단보기
Article 48 (Rejection and Suspension of Mediation)
(1) Where the Dispute Mediation Committee deems that it is inappropriate to mediate any dispute in view of its nature, or that an application for mediation of any dispute is filed for an unfair purpose, it may reject the mediation. In this case, the reasons for rejecting the mediation shall be notified to the applicant.
(2) If one of the parties files a lawsuit while mediation proceedings are pending, the Dispute Mediation Committee shall suspend the dispute mediation and notify the parties thereof.
법령 이단보기
Article 49 (Collective Dispute Mediation)
(1) The State, a local government, a data protection organization or institution, a data subject, and a personal information controller may request or apply for a collective dispute mediation (hereinafter referred to as “collective dispute mediation”) to the Dispute Mediation Committee where damages or infringement on rights occur to multiple data subjects in an identical or similar manner, and such incident is such as prescribed by Presidential Decree.
(2) Upon receipt of a request or an application for collective dispute mediation under paragraph (1), the Dispute Mediation Committee may commence, by its resolution, collective dispute mediation proceedings pursuant to paragraphs (3) through (7). In such cases, the Dispute Mediation Committee shall publicly announce the commencement of such proceedings for a period prescribed by Presidential Decree.
(3) The Dispute Mediation Committee may accept an application from any data subject or personal information controller other than the parties to the collective dispute mediation to participate in the collective dispute mediation additionally as a party.
(4) The Dispute Mediation Committee may, by its resolution, select one or a few persons as a representative party, who most appropriately represents the common interest among the parties to the collective dispute mediation pursuant to paragraphs (1) and (3).
(5) When the personal information controller accepts a collective dispute mediation award presented by the Dispute Mediation Committee, the Dispute Mediation Committee may advise the personal information controller to prepare and submit a compensation plan for the benefit of the non-party data subjects suffered from the same incident.
(6) Notwithstanding Article 48 (2), if a group of data subjects among a multitude of data subject parties to the collective dispute mediation files a lawsuit before the court, the Dispute Mediation Committee shall not suspend the proceedings but exclude the relevant data subjects, who have filed the lawsuit, from the proceedings.
(7) The period for collective dispute mediation shall not exceed 60 days from the following day when public announcement referred to in paragraph (2) ends: Provided, That the period can be extended by the resolution of the Dispute Mediation Committee in extenuating circumstances.
(8) Other necessary matters, such as the procedures for collective dispute mediation, shall be prescribed by Presidential Decree.
법령 이단보기
Article 50 (Mediation Procedures)
(1) Except as otherwise expressly provided for in Articles 43 through 49, the method and procedures to mediate disputes and matters necessary to deal with such dispute mediation shall be prescribed by Presidential Decree.
(2) Except as otherwise expressly provided for in this Act, the Judicial Conciliation of Civil Disputes Act shall apply mutatis mutandis to the operation of the Dispute Mediation Committee and dispute mediation proceedings.
CHAPTER VIII CLASS-ACTION LAWSUIT OVER DATA INFRINGEMENT
법령 이단보기
Article 51 (Parties to Class Action Lawsuit)
Any of the following organizations may file a lawsuit (hereinafter referred to as “class action lawsuit”) with the court to prevent or suspend an infringement with respect to personal information if a personal information controller rejects or would not accept the collective dispute mediation under Article 49:
1. A consumer group registered with the Fair Trade Commission pursuant to Article 29 of the Framework Act on Consumers that meets all of the following criteria:
(a) Its by-laws shall constantly state the purpose to augment the rights and interests of data subjects;
(b) The number of full members shall exceed 1000;
(c) Three years shall have passed since the registration under Article 29 of the Framework Act on Consumers;
2. A non-profit, non-governmental organization referred to in Article 2 of the Assistance for Non-Profit, Non-Governmental Organizations Act that meets all of the following criteria:
(a) At least 100 data subjects, who experienced the same infringement as a matter of law or fact, shall submit a request to file a class action lawsuit;
(b) Its by-laws shall state the purpose of data protection and it has conducted such activities for the most recent 3 years;
(c) The number of regular members shall be at least 5000;
(d) It shall be registered with any central administrative agency.
법령 이단보기
Article 52 (Exclusive Jurisdictions)
(1) A class action lawsuit shall be subject to the exclusive jurisdiction of the competent district court (panel of judges) at the place of business or main office, or at the address of the business manager in the case of no business establishment, of the defendant.
(2) Where paragraph (1) applies to a foreign business entity, the same shall be determined by the place of business or main office, or the address of the business manager located in the Republic of Korea.
법령 이단보기
Article 53 (Retention of Litigation Attorney)
The plaintiff of a class-action lawsuit shall retain an attorney-at-law as a litigation attorney.
법령 이단보기
Article 54 (Application for Permission of Lawsuit)
(1) An organization that intends to file a class action shall submit to the court an application for permission of lawsuit describing the following in addition to the complaint:
1. Plaintiff and his or her litigation attorney;
2. Defendant;
3. Detailed violation of the rights of data subjects.
(2) An application for certification of lawsuit filed under paragraph (1) shall be accompanied by the following materials:
1. Materials that prove that the organization which has filed a lawsuit meets all criteria provided for in Article 51;
2. Documentary evidence that proves that the personal information controller has rejected the dispute mediation or would not accept the mediation award.
법령 이단보기
Article 55 (Requirements for Permission of Lawsuit)
(1) The court shall permit a class action only when all of the following requirements are satisfied:
1. That the personal information controller has rejected the dispute mediation or would not accept the mediation award;
2. That none of the descriptions in the application for permission of lawsuit filed under Article 54 is defective.
(2) The court decision that permits, or refuses to permit, a class action may be challenged through immediate appeal.
법령 이단보기
Article 56 (Effect of Conclusive Judgment)
When a judgment dismissing a plaintiff's complaint becomes conclusive, any other organizations provided for in Article 51 cannot file a class-action lawsuit regarding the identical case: Provided, That this shall not apply in any of the following circumstances:
1. Where, after the judgment became conclusive, new evidence has been found by the State, a local government, or a State or local government-invested institution regarding the said case;
2. Where the judgment dismissing the lawsuit proves to have been caused intentionally by the plaintiff.
법령 이단보기
Article 57 (Application of Civil Procedure Act)
(1) Except as otherwise expressly provided for in this Act, the Civil Procedure Act shall apply to a class action.
(2) When a decision to permit a class action lawsuit is made under Article 55, a preservation order provided for in PART IV of the Civil Execution Act may be issued.
(3) Matters necessary for class action lawsuit proceedings shall be provided by the Supreme Court Regulations.
CHAPTER IX SUPPLEMENTARY PROVISIONS
법령 이단보기
Article 58 (Partial Exclusion of Application)
(1) Chapter III through VII shall not apply to any of the following personal information:
1. Personal information collected pursuant to the Statistics Act for processing by public institutions;
2. Personal information collected or requested to be provided for the analysis of information related to national security;
3. Personal information processed temporarily where it is urgently necessary for the public safety and security, public health, etc.;
4. Personal information collected or used for its own purposes of reporting by the press, missionary activities by religious organizations, and nomination of candidates by political parties, respectively.
(2) Articles 15, 22, 27 (1) and (2), 34, and 37 shall not apply to any personal information that is processed by means of the visual data processing devices installed and operated at open places pursuant to Article 25 (1).
(3) Articles 15, 30 and 31 shall not apply to any personal information that is processed by a personal information controller to operate a group or association for friendship, such as an alumni association and a hobby club.
(4) In the case of processing personal information pursuant to paragraph (1), a personal information controller shall process the personal information to the minimum extent necessary to attain the intended purpose for the minimum period; and shall also make necessary arrangements, such as technical, managerial and physical safeguards, individual grievance handling and other necessary measures for the safe management and appropriate processing of such personal information.
법령 이단보기
Article 58-2 (Exemption from Application)
This Act shall not apply to information that no longer identifies a certain individual when combined with other information, reasonably considering time, cost, technology, etc.
[This Article Newly Inserted by Act No. 16930, Feb. 4, 2020]
법령 이단보기
Article 59 (Prohibited Activities)
Anyone who processes or has processed personal information shall be prohibited from undertaking any of the following activities:
1. To acquire personal information or to obtain consent to personal information processing by fraud, improper or unjust means;
2. To divulge personal information acquired in the course of business, or to provide it for any third party’s use without authority;
3. To damage, destroy, alter, forge, or divulge other’s personal information without legal authority or beyond proper authority.
법령 이단보기
Article 60 (Confidentiality)
Any person who performs or has performed the following affairs shall not divulge any confidential information acquired in the course of performing his or her duties to any other person, nor use such information for any purpose other than for his or her duties: Provided, That, the same shall not apply where special provisions exist in other laws: <Amended by Act No. 16930, Feb. 4, 2020>
1. Affairs of the Protection Commission provided for in Article 8;
1-2. Certification of personal information protection provided for in Article 32-2;
2. Impact assessments provided for in Article 33;
3. Dispute mediation of the Dispute Mediation Committee established under Article 40.
법령 이단보기
Article 61 (Suggestions and Recommendations for Improvements)
(1) The Protection Commission may provide its opinion to any relevant agency through deliberation and resolution where it is deemed necessary with respect to the statutes or municipal ordinances containing provisions that are likely to affect the protection of personal information. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, February. 4, 2020>
(2) The Protection Commission may advise a personal information controller to improve the status of personal information processing where doing so is deemed necessary to protect personal information. In such cases, upon receiving the advice, the personal information controller shall make sincere efforts to comply with the advice, and shall inform the Protection Commission of the results. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(3) The head of a related central administrative agency may recommend that a personal information controller improve the status of personal information processing pursuant to the statutes under the related central administrative agency’s jurisdiction where doing so is deemed necessary to protect personal information. In such cases, upon receiving the recommendation, the personal information controller shall make sincere efforts to comply with the recommendation, and shall inform the head of the related central administrative agency of the results.
(4) Central administrative agencies, local governments, the National Assembly, the Court, the Constitutional Court, and the National Election Commission may provide their opinions, or provide guidance or inspection with respect to the protection of personal information to their affiliated entities and the public institutions under their jurisdiction.
법령 이단보기
Article 62 (Reporting on Infringements)
(1) Anyone who suffers infringement of rights or interests relating to his or her personal information in the course of personal information processing by a personal information controller may report such infringement to the Protection Commission. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(2) The Protection Commission may designate a specialized institution in order to efficiently receive and handle the claim reports pursuant to paragraph (1), as prescribed by Presidential Decree. In such cases, such specialized institution shall establish and operate a personal information infringement call center (hereinafter referred to as the “Privacy Call Center”). <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(3) The Privacy Call Center shall perform the following duties:
1. To receive claim reports and provide consultation in relation to personal information processing;
2. To investigate and confirm incidents and hear opinions of related parties;
3. Duties incidental to subparagraphs 1 and 2.
(4) The Protection Commission may, if necessary, dispatch its public official to the specialized institution designated under paragraph (2) pursuant to Article 32-4 of the State Public Officials Act in order to efficiently investigate and confirm the incidents pursuant to paragraph (3) 2. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
법령 이단보기
Article 63 (Requests for Materials and Inspections)
(1) The Protection Commission may request relevant materials, such as articles and documents, from a personal information controller in any of the following cases: <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
1. Where any violation of this Act is found or suspected;
2. Where any violation of this Act is reported or a civil complaint thereon is received;
3. In cases prescribed by Presidential Decree where it is necessary to protect the personal information of data subjects.
(2) Where a personal information controller fails to furnish materials pursuant to paragraph (1) or is regarded as having violated this Act, the Protection Commission may require its public official to enter the offices or places of business of the personal information controller and other persons related to such violation to inspect the status of business operations, ledgers, documents, etc. In such cases, the public official who conducts the inspection shall carry a certificate indicating his/her authority and show it to the related persons. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 13423, Jul. 24, 2015; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(3) The head of a related central administrative agency may, in accordance with statutes under the related central administrative agency’s jurisdiction, request materials from a personal information controller pursuant to paragraph (1), or may inspect the personal information controller and other persons related to the relevant violation of such statutes pursuant to paragraph (2). <Amended by Act No. 13423, Jul. 24, 2015>
(4) Upon discovering any violation of this Act or becoming aware of any suspected violation of this Act, the Protection Commission may demand that the head of the related central administrative agency (if there is a corporation authorized to conduct inspection in accordance with the direction and supervision of the head of the related central administrative agency, this refers to the corporation) investigate the personal information controller after setting a specific scope, and if necessary, request a public official under the Protection Commission to jointly engage in the investigation. In such cases, upon receiving such demand, the head of the related central administrative agency shall comply therewith unless there are extraordinary circumstances. <Amended by Act No. 16930, Feb. 4, 2020>
(5) The Protection Commission may request the head of the related central administrative agency (if there is a corporation authorized to conduct inspection in accordance with the direction and supervision of the head of the related central administrative agency, this refers to the corporation) to take corrective measures on the relevant personal information processer with regard to the result of the inspection conducted pursuant to paragraph (4) or provide opinions on dispositions, etc. <Amended by Act No. 16930, Feb. 4, 2020>
(6) Matters concerning the methods, procedures, etc. for paragraphs (4) and (5) shall be prescribed by Presidential Decree. <Amended by Act No. 16930, Feb. 4, 2020>
(7) The Protection Commission may inspect the status of personal information protection jointly with the head of a related central administrative agency for the prevention of personal information breach incidents and efficient response. <Newly Inserted by Act No. 13423, Jul. 24, 2015; Amended by Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(8) The Protection Commission and the head of the related central administrative agency shall not provide any third party with the documents, materials, etc. furnished or collected pursuant to paragraphs (1) and (2), nor disclose them to the general public, except as otherwise required by this Act. <Newly Inserted by Act No. 16930, Feb. 4, 2020>
(9) Where receiving materials via information and communications networks, or digitalizing the collected materials, etc., the Protection Commission and the head of the related central administrative agency shall take systematic and technical security measures to prevent the breach of personal information, trade secrets, etc. <Newly Inserted by Act No. 16930, Feb. 4, 2020>
법령 이단보기
Article 64 (Corrective Measures)
(1) Where the Protection Commission deems that there is substantial ground to deem that there has been infringement with respect to personal information, and failure to take action is likely to cause damage that is difficult to remedy, it may order the violator of this Act (excluding central administrative agencies, local governments, the National Assembly, the Court, the Constitutional Court, and the National Election Commission) to take any of the following measures: <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
1. To suspend infringement with respect to personal information;
2. To temporarily suspend personal information processing;
3. Other measures necessary to protect personal information and to prevent personal information infringement.
(2) Where the head of a related central administrative agency deems that there is substantial ground to deem that there has been an infringement of personal information, and failure to take action is likely to cause damage that is difficult to remedy, he or she may order a personal information controller to take any of the measures provided for in paragraph (1) pursuant to the statutes under such related central administrative agency’s jurisdiction.
(3) A local government, the National Assembly, the Court, the Constitutional Court, or the National Election Commission may order their affiliated entities and public institutions, which are found to have violated this Act, to take any of the measures provided for in paragraph (1).
(4) When a central administrative agency, a local government, the National Assembly, the Court, the Constitutional Court, or the National Election Commission violates this Act, the Protection Commission may recommend the head of the relevant agency to take any of the measures provided for in paragraph (1). In such cases, upon receiving the recommendation, the agency shall comply therewith unless there are extraordinary circumstances.
법령 이단보기
Article 65 (Accusation and Recommendation for Disciplinary Action)
(1) When there is deemed substantial ground for suspecting a criminal violation of this Act or other data protection-related statutes, the Protection Commission may make an accusation to the competent investigative agency. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(2) When there is deemed substantial ground for deeming that there has been a violation of this Act or other data protection-related statutes, the Protection Commission may recommend the relevant personal information controller to take disciplinary action against the person responsible for such violation (including the representative and the executive officer in charge). In such cases, upon receiving the recommendation, the relevant personal information controller shall comply therewith, and notify the Protection Commission of the results.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 11990, Aug. 6, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(3) The head of a related central administrative agency may file a criminal complaint against a personal information controller pursuant to paragraph (1), or recommend that the head of an affiliated agency, organization, etc. take disciplinary action pursuant to paragraph (2), in accordance with the statutes under the central administrative agency’s jurisdiction. In such cases, upon receiving the recommendation under paragraph (2), the head of an affiliated agency, organization, etc. shall comply therewith, and notify the head of the related central administrative agency of the results.
법령 이단보기
Article 66 (Disclosure of Results)
(1) The Protection Commission may disclose the recommendation for improvement pursuant to Article 61; the order to take corrective measures pursuant to Article 64; the accusation or recommendation to take disciplinary action pursuant to Article 65; and the imposition of administrative fines pursuant to Article 75 and the results thereof. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(2) The head of a related central administrative agency may disclose the matters provided for in paragraph (1) in accordance with the statutes under the central administrative agency’s jurisdiction.
(3) The method, criteria, procedure, etc. for disclosure pursuant to paragraphs (1) and (2) shall be prescribed by Presidential Decree.
법령 이단보기
Article 67 (Annual Reports)
(1) The Protection Commission shall prepare a report each year, based on necessary materials furnished by related agencies, etc., in relation to the establishment and implementation of personal information protection policy measures, and submit (including transmission via an information and communications networks) it to the National Assembly before the opening of the regular session.
(2) The annual report referred to in paragraph (1) shall contain the following matters: <Amended by Act No. 14107, Mar. 29, 2016>
1. Infringement on the rights of data subjects and the status of remedies thereof;
2. Results of the survey in relation to the status of personal information processing;
3. Status of implementation of the personal information protection policy measures and achievements;
4. Global legislative and policy trends regarding personal information;
5. Status of the enactment and amendment of Acts, Presidential Decrees, the National Assembly Regulations, the Supreme Court Regulations, the Constitutional Court Regulations, the National Election Commission Regulations, and the Board of Audit and Inspection Regulations, in relation to processing of resident registration numbers;
6. Other matters to be disclosed or reported in relation to the personal information protection policy.
법령 이단보기
Article 68 (Delegation and Entrustment of Authority)
(1) The authority of the Protection Commission or the head of a related central administrative agency under this Act may in part be delegated or entrusted, as prescribed by Presidential Decree, to the Special Metropolitan City Mayor, Metropolitan City Mayors, Do Governors, Special Self-Governing Province Governors, or the specialized institutions prescribed by Presidential Decree. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, February. 4, 2020>
(2) The agencies to which the authority of the Protection Commission or the head of a related central administrative agency has been partially delegated or entrusted pursuant to paragraph (1) shall notify the Protection Commission or the head of the related central administrative agency of the results of performing the affairs delegated or entrusted.<Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
(3) Where delegating or entrusting a part of the authority to a specialized institution pursuant to paragraph (1), the Protection Commission may provide a contribution to the special institution to cover expenses incurred in performing the affairs. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
법령 이단보기
Article 69 (Persons Deemed to be Public Officials for Purposes of Penalty Provisions)
(1) Among the Commissioners of the Protection Commission, Commissioners other than public officials and employees other than public officials shall be deemed a public official for the purposes of applying penalty under the Criminal Act or other statutes. <Newly Inserted by Act No. 16930, Feb. 4, 2020>
(2) Any executive or employee of a relevant agency that performs the affairs entrusted by the Protection Commission or the head of a related central administrative agency shall be deemed a public official for the purposes of Articles 129 through 132 of the Criminal Act. <Newly Inserted by Act No. 16930, Feb. 4, 2020>
CHAPTER X PENALTY PROVISIONS
법령 이단보기
Article 70 (Penalty Provisions)
Any of the following persons shall be punished by imprisonment with labor for not more than 10 years, or by a fine not exceeding 100 million won: <Amended by Act No. 13423, Jul. 24, 2015>
1. A person who causes the suspension, paralysis or other severe hardship of work of a public institution by altering or erasing the personal information processed by the public institution for the purpose of disturbing the personal information processing of such public institution;
2. A person who obtains any personal information processed by third parties by fraud or other unjust means or methods and provides it to a third party for a profit-making or unjust purpose, and a person who abets or arranges such conduct.
법령 이단보기
Article 71 (Penalty Provisions)
Any of the following persons shall be punished by imprisonment with labor for not more than 5 years, or by a fine not exceeding 50 million won: <Amended by Act No. 14107, Mar. 29, 2016; Act No. 16930, Feb. 4, 2020>
1. A person who provides personal information to a third party without the consent of a data subject in violation of Article 17 (1) 1 even through Article 17 (1) 2 is not applicable, and a person who knowingly receives such personal information;
2. A person who uses personal information or provides personal information to a third party in violation of Articles 18 (1) and (2) (including where the aforesaid provisions apply mutatis mutandis pursuant to Article 39-14), 19, 26 (5), 27 (3), or 28-2 and a person who knowingly receives such personal information for a profit-making or unfair purpose;
3. A person who processes sensitive information in violation of Article 23 (1);
4. A person who processes personally identifiable information in violation of Article 24 (1);
4-2. A person who processes or provides a third party with pseudonymised information in violation of Article 28-3, and a person who knowingly receives such pseudonymised information for profit-making or unfair purposes;
4-3. A person who processes pseudonymised information for the purpose of identifying a certain individual in violation of Article 28-5 (1);
4-4. An information and communications service provider who uses or provides a third party with personal information without taking necessary measures for correction or deletion requests (including necessary measures to be taken in accordance with a request for access, etc. provided for in Article 38 (2)) pursuant to Article 36 (2) (including a person to whom personal information has been transferred from information and communications service provider, etc. pursuant to Article 27 and applicable cases pursuant to Article 39-14);
4-5. A person who collects personal information without users’ consent in violation of Article 39-3 (1) (including where the aforesaid provisions apply mutatis mutandis pursuant to Article 39-14);
4-6. A person who collects the personal information of children aged under 14 without his or her legal representative’s consent or without confirming whether the legal representative has given consent or not in violation of Article 39-3 (4) (including applicable cases pursuant to Article 39-14);
5. A person who divulges personal information acquired in the course of business or provides it for any other person's use without authority in violation of subparagraph 2 of Article 59, and a person who knowingly receives such personal information for a profit-making or unfair purposes;
6. A person who damages, destroys, alters, forges, or divulges any third party's personal information in violation of subparagraph 3 of Article 59.
법령 이단보기
Article 72 (Penalty Provisions)
Any of the following persons shall be punished by imprisonment with labor for not more than 3 years, or by a fine not exceeding 30 million won:
1. A person who arbitrarily handles visual data processing devices for any purpose other than the purpose for which the device was installed, directs such devices toward different spots, or uses a sound recording function in violation of Article 25 (5);
2. A person who acquires personal information or obtains consent to personal information processing by fraud or other unjust means in violation of subparagraph 1 of Article 59, and a person who knowingly receives such personal information for a profit-making or unfair purpose;
3. A person who divulges confidential information acquired while performing his or her duties, or uses such information for purposes other than for the purpose of discharging his/her duties in violation of Article 60.
법령 이단보기
Article 73 (Penalty Provisions)
Any of the following persons shall be punished by imprisonment with labor for not more than 2 years, or by a fine not exceeding 20 million won:<Amended by Act No. 13423, Jul. 24, 2015; Act No. 14107, Mar. 29, 2016; Act No. 16930, Feb. 4, 2020>
1. A person who fails to take necessary measures to ensure safety in violation of Article 23 (2), 24 (3), 25 (6), 28-4 (1), or 29 and causes personal information to be lost, stolen, divulged, forged, altered, or damaged;
1-2. Information and communications service provider, etc. who fails to destroy personal information in violation of Article 21 (1) (including applicable cases pursuant to Article 39-14);
2. A person who fails to take necessary measures to rectify or erase personal information in violation of Article 36 (2), and continuously uses, or provides a third party with, the personal information;
3. A person who fails to suspend processing of personal information in violation of Article 37 (2), and continuously uses, or provides a third party with, the personal information.
법령 이단보기
Article 74 (Joint Penalty Provisions)
(1) If the representative of a corporation, or an agent or employee of, or any other person employed by, a corporation or an individual commits any of the offenses provided for in Article 70 in connection with the business affairs of the corporation or individual, not only shall such offender be punished, but also the corporation or individual shall be punished by a fine not exceeding 70 million won: Provided, That the same shall not apply where such corporation or individual has not been negligent in taking due care and supervisory activities concerning the relevant business affairs to prevent such offense.
(2) If the representative of a corporation, or an agent or employee of, or any other person employed by, a corporation or an individual commits any of the offenses provided for in Articles 71 through 73 in connection with the business affairs of the corporation or individual, not only shall such offender be punished, but also the corporation or individual shall be punished by a fine prescribed in the relevant Article: Provided, That the same shall not apply where such corporation or individual has not been negligent in taking due care and supervisory activities concerning the relevant business affairs to prevent such offense.
법령 이단보기
Article 74-2 (Confiscation and Collection)
Any money or goods or other profits acquired by a person who has violated Articles 70 through 73 in relation to such violation may be confiscated, or, if confiscation is impossible, the value thereof may be collected. In such cases, such confiscation or collection may be levied in addition to other penalty provisions.
[This Article Newly Inserted by Act No. 13423, Jul. 24, 2015]
법령 이단보기
Article 75 (Administrative Fines)
(1) Any of the following persons shall be subject to an administrative fine not exceeding 50 million won: <Amended by Act No. 14765, Apr. 18, 2017>
1. A person who collects personal information in violation of Article 15 (1);
2. A person who fails to obtain the consent of a legal representative in violation of Article 22 (6);
3. A person who installs and operates visual data processing devices in violation of Article 25 (2).
(2) Any of the following persons shall be subject to an administrative fine not exceeding 30 million won: <Amended by Act No. 11990, Aug. 6, 2013; Act No. 12504, Mar. 24, 2014; Act No. 13423, Jul. 24, 2015; Act No. 14107, Mar. 29, 2016; Act No. 14765, Apr. 18, 2017; Act No. 16930, Feb. 4, 2020>
1. A person who fails to notify a data subject of necessary information in violation of Article 15 (2), 17 (2), 18 (3), or 26 (3);
2. A person who denies the provision of goods or services to a data subject in violation of Article 16 (3) or 22 (5);
3. A person who fails to notify a data subject of the matters provided for in Article 20 (1) or (2) in violation of Article 20 (1) or (2);
4. A person who fails to take necessary measures, such as destroying personal information, in violation of Article 21 (1) or Article 39-6 (including applicable cases pursuant to Article 39-14);
4-2. A person who processes resident registration numbers in violation of Article 24-2 (1);
4-3. A person who fails to adopt encryption measures in violation of Article 24-2 (2);
5. A person who fails to provide a data subject with an alternative method without using his or her resident registration number in violation of Article 24-2 (3);
6. A person who fails to take measures necessary to ensure safety in violation of Article 23 (2), 24 (3), 25 (6), 28-4 (1), or 29;
7. A person who installs and operates visual data processing devices in violation of Article 25 (1);
7-2. A person who fails to cease the use of, collect or destroy, information which has been generated to identify a certain individual, in violation of Article 28-5 (2);
7-3. A person who indicates and promotes the certification by fraud despite a failure to obtain such certification, in violation of Article 32-2 (6);
8. A person who fails to notify a data subject of the facts provided for in Article 34 (1) in violation of the same paragraph;
9. A person who fails to report the results of measures taken, in violation of Article 34 (3);
10. A person who limits or denies access to personal information in violation of Article 35 (3);
11. A person who fails to take necessary measures to correct or erase personal information, in violation of Article 36 (2);
12. A person who fails to take necessary measures, such as destruction of the personal information whose processing has been suspended, in violation of Article 37 (4);
12-2. A person who refuses to provide services in violation of Article 39-3 (3) (including applicable cases pursuant to Article 39-14);
12-3. A person who fails to notify or report the relevant users, the Protection Commission or a specialized institution or notifies or reports after the lapse of 24 hours without any just cause, in violation of Article 39-4 (1) (including applicable cases pursuant to Article 39-14);
12-4. A person who fails to explain or falsely explains just cause, in violation of Article 39-4 (3);
12-5. A person who fails to provide methods of withdrawing consent, and accessing to, or correcting, personal information, in violation of Article 39-7 (2) (including applicable cases pursuant to Article 39-14);
12-6. Information and communications service provider, etc. who fails to take necessary measures in violation of Article 39-7 (3) (including applicable cases pursuant to Article 39-14 and any person to whom personal information has been transferred from information and communications service provider, etc. pursuant to Article 27);
12-7. A person who fails to notify users of the use history of their personal information in violation of the main clause of Article 39-8 (1) (including applicable cases pursuant to Article 39-14);
12-8. A person who fails to take protective measures, in violation of Article 39-12 (4) (including applicable cases pursuant to paragraph (5) of the same Article);
13. A person who fails to comply with corrective orders taken under Article 64 (1).
(3) Any of the following persons shall be subject to an administrative fine not exceeding 20 million won: <Newly Inserted by Act No. 16930, Feb. 4, 2020>
1. A person who fails to take necessary measures such as purchasing an insurance, joining a mutual aid organization, or accumulating reserves, in violation of Article 39-9 (1);
2. A person who fails to designate a domestic agent, in violation of Article 39-11 (1);
3. A person who outsources the processing of, or stores, users’ personal information overseas without disclosing or informing all matters provided for in Article 39-12 (3) or notifying users in violation of the proviso of Article 39-12 (2).
(4) Any of the following persons shall be subject to an administrative fine not exceeding 10 million won: <Amended by Act No. 14765, Apr. 18, 2017; Act No. 16930, Feb. 4, 2020>
1. A person who fails to store and manage personal information separately in violation of Article 21 (3);
2. A person who obtains consent in violation of Article 22 (1) through (4);
3. A person who fails to take necessary measures including posting a signboard in violation of Article 25 (4);
4. A person who fails to execute a document stating the matters provided for in Article 26 (1) when outsourcing the work in violation of the same paragraph;
5. A person who fails to disclose the outsourced work and the outsourcee in violation of Article 26 (2);
6. A person who fails to notify a data subject of the transfer of his or her personal information in violation of Article 27 (1) or (2);
6-2. A person who fails to prepare and keep a record of relevant matters in violation of Article 28-4 (2);
7. A person who fails to establish, or disclose, the Privacy Policy in violation of Article 30 (1) or (2);
8. A person who fails to designate a privacy officer in violation of Article 31 (1);
9. A person who fails to notify a data subject of necessary information in violation of Article 35 (3) and (4), 36 (2) and (4), or 37 (3);
10. A person who fails to furnish materials, such as articles and documents pursuant to Article 63 (1), or who submits false materials;
11. A person who refuses, interferes with, or evades access or an inspection pursuant to Article 63 (2).
(5) Administrative fines provided for in paragraphs (1) through (4) shall be imposed and collected by the Protection Commission and the head of a related central administrative agency, as prescribed by Presidential Decree. In such cases, the head of a related central administrative agency shall impose and collect administrative fines from the personal information controllers in the field under his or her jurisdiction. <Amended by Act No. 11690, Mar. 23, 2013; Act No. 12844, Nov. 19, 2014; Act No. 14839, Jul. 26, 2017; Act No. 16930, Feb. 4, 2020>
법령 이단보기
Article 76 (Special Exemption to Application of Provisions on Administrative Fines)
For the purposes of the provisions on administrative fines provided for in Article 75, no additional administrative fine shall be imposed on any act subject to penalty surcharges pursuant to Article 34-2.
[This Article Newly Inserted by Act No. 11990, Aug. 6, 2013]
ADDENDA
Article 1 (Enforcement Date)
This Act shall enter into force six months after the date of its promulgation: Provided, That Articles 24 (2) and 75 (2) 5 shall enter into force one year after the date of its promulgation.
Article 2 (Repeal of other Acts)
Article 3 (Transitional Measures concerning Personal Information Dispute Mediation Committee)
An act performed by or against the Personal Information Dispute Mediation Committee under the previous Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. as at the time this Act enters into force shall be deemed an act performed by or against the Personal Information Dispute Mediation Committee corresponding thereto under this Act.
Article 4 (Transitional Measures concerning Personal Information being Processed)
Any personal information legitimately processed under other Acts before this Act enters into force shall be deemed to have been processed under this Act.
Article 5 (Transitional Measures concerning Application of Penalty Provisions)
(1) The application of the penalty provisions to a violation of the previous Act on the Protection of Personal Information Maintained by Public Institutions before this Act enters into force shall be governed by the previous Act on the Protection of Personal Information Maintained by Public Institutions.
(2) The application of the penalty provisions to a violation of the previous Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. before this Act enters into force shall be governed by the previous Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.
Article 6 Omitted.
Article 7 (Relationship to other Acts)
Where the previous Act on the Protection of Personal Information Maintained by Public Institutions or the provisions thereof are cited in other statutes at the time this Act enters into force, and any provision corresponding thereto exists in this Act, this Act or the corresponding provision of this Act shall be deemed cited in lieu of the previous provision.
ADDENDA <Act No. 11690, Mar. 23, 2013>
Article 1 (Enforcement Date)
(1) This Act shall enter into force on the date of its promulgation.
(2) Omitted.
Articles 2 through 7 Omitted.
ADDENDA <Act No. 11990, Aug. 6, 2013>
Article 1 (Enforcement Date)
This Act shall enter into force one year after the date of its promulgation.
Article 2 (Transitional Measures concerning Limitation to Processing of Resident Registration Numbers)
(1) A person who processes resident registration numbers as at the time this Act enters into force shall destroy the resident registration numbers possessed, within two years after this Act enters into force: Provided, That any of the cases falling under the amended subparagraphs of Article 24-2 (1) shall be excluded from the destruction.
(2) Where resident registration numbers are not destroyed within the period referred to in paragraph (1), the amended provisions of Article 24-2 (1) shall be deemed to have been violated.
ADDENDUM <Act No. 12504, Mar. 24, 2014>
This Act shall enter into force on the date of its promulgation: Provided, That the amended provisions of Articles 24-2 and 75 (2) 5 of the Personal Information Protection Act (Act No. 11990) shall enter into force on January 1, 2016.
ADDENDA <Act No. 12844, Nov. 19, 2014>
Article 1 (Enforcement Date)
This Act shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 7 Omitted.
ADDENDA <Act No. 13423, Jul. 24, 2015>
Article 1 (Enforcement Date)
This Act shall enter into force on the date of its promulgation: Provided, That the amended provisions of Articles 8 (1), 8-2, 9, 11 (1), 32-2, 39 (3) and (4), 39-2, 40, and 75 (2) 7-2 shall enter into force one year after the date of its promulgation, and the amended provisions of the former part of Article 24-2 (2) and Article 75 (2) 4-3 of the Personal Information Protection Act (Act No. 12504) shall enter into force on January 1, 2016, respectively.
Article 2 (Applicability to Compensation)
The amended provisions of Articles 39 (3) and (4) and 39-2 shall apply, beginning with the first claim for compensation for personal information suffering loss, theft, divulgence, forgery, alteration, or damage after this Act enters into force.
Article 3 (Transitional Measures concerning Personal Information Protection Certification)
Any person who has obtained the personal information protection certification from the Minister of the Interior before this Act enters into force shall be deemed obtained the personal information protection certification under the amended provisions of Article 32-2.
Article 4 (Transitional Measures concerning Qualifications for Certification Examiners of Personal Information Protection)
Any person qualified as a certification examiner of personal information protection before this Act enters into force shall be deemed qualified under this Act.
Article 5 (Transitional Measures concerning Terms of Office of Members of Personal Information Dispute Mediation Committee)
Members of the Dispute Mediation Committee appointed or commissioned by the Minister of the Interior before this Act enters into force shall be deemed members of the Dispute Mediation Committee commissioned by the Protection Commission under the amended provisions of Article 40.
Article 6 (Transitional Measures concerning Penalty Provisions, etc.)
The former provisions shall apply to the application of penalty provisions or imposition of administrative fines for offenses committed before this Act enters into force.
ADDENDA <Act No. 14107, Mar. 29, 2016>
Article 1 (Enforcement Date)
This Act shall enter into force six months after the date of its promulgation: Provided, That the amended provisions of Articles 24-2 (1) 1 and 67 (2) 5 shall enter into force one year after the date of its promulgation.
Article 2 (Applicability to Notification of Other Sources, etc. of Personal Information than Data Subjects)
The amended provisions of Article 20 (2) and (3) shall apply, beginning with the first case where any personal information is collected from a person other than the data subjects after this Act enters into force.
Article 3 (Transitional Measures concerning Privacy Policy)
(1) The Privacy Policy established under the former provisions as at the time this Act enters into force shall be deemed the Privacy Policy established under the amended provisions of Article 30 (1).
(2) Each personal information controller shall amend the Privacy Policy referred to in paragraph (1) to meet the purport of amending Article 30 (1) within six months after this Act enters into force.
ADDENDUM <Act No. 14765, Apr. 18, 2017>
This Act shall enter into force six months after the date of its promulgation.
ADDENDA <Act No. 14839, Jul. 26, 2017>
Article 1 (Enforcement Date)
This Act shall enter into force on the date of its promulgation: Provided, That any amendment to the Acts made pursuant to Article 5 of this Addenda, promulgated before this Act enters into force, which have not yet entered into force, shall enter into force on the date the corresponding Act takes effect.
Articles 2 through 6 Omitted.
ADDENDA <Act No. 16930, Feb. 4, 2020>
Article 1 (Enforcement Date)
This Act shall enter into force six months after the date of its promulgation.
Article 2 (Transitional Measures concerning Terms of Office of Commissioners)
The term of office of the Commissioners of the Protection Commission appointed under the previous provisions as at the time this Act enters into force, shall be deemed expired on the date preceding the enforcement date of this Act.
Article 3 (Transitional Measures concerning Duties Following Adjustment of Functions)
(1) Among the duties of the Korea Communications Commission under Article 11 (1) of the Act on the Establishment and Operation of Korea Communications Commission as at the time this Act enters into force, those relating to personal information protection shall be transferred to the Protection Commission.
(2) Among the duties of the Minister of the Interior and Safety as at the time this Act enters into force, those pursuant to the amended provisions in Article 7-8 shall be assumed by the Protection Commission.
(3) Among the notifications, administrative dispositions and other acts of the Minister of the Interior and Safety, and acts conducted with respect to the Minister of the Interior and Safety such as filing of an application or report before this Act enters into force, those relating to matters for which competent authority is transferred from the Minister of the Interior and Safety to the Protection Commission shall be deemed to be the acts of, or acts conducted with respect to, the Protection Commission.
(4) Among the notifications, administrative dispositions and other acts of the Korea Communications Commission, and acts conducted with respect to the Korea Communications Commission such as filing of a report before this Act enters into force, those relating to matters for which competent authority is transferred from the Korea Communications Commission to the Protection Commission shall be deemed to be the acts of, or acts conducted with respect to, the Protection Commission pursuant to this Act.
(5) Among the public officials of the Ministry of the Interior and Safety or the Korea Communications Commission as at the time this Act enters into force, those prescribed by Presidential Decree shall be deemed to be the public officials of the Protection Commission pursuant to this Act.
Article 4 (Transitional Measures concerning the Protection Commission)
(1) The acts of, or acts conducted with respect to, the Protection Commission pursuant to the previous provisions as at the time this Act enters into force shall be deemed to be the acts of, or acts conducted with respect to, the Protection Commission pursuant to this Act.
Article 5 (Transitional Measures concerning Certifying Organizations for Personal Information Protection Management System)
(1) Entities designated as a certifying or examining organization pursuant to Article 47-3 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (hereinafter referred to as the “Network Act”) as at the time this Act enters into force, shall be deemed to have been designated as a specialized organization in accordance with Article 32-2 of this Act.
(2) Entities certified for personal information protection management system or qualified as a certification examiner pursuant to Article 47-3 of the Network Act as of the effective date of this Act shall be deemed to have been certified for personal information protection management system or qualified as a certification examiner pursuant to Article 32-2 of this Act.
Article 6 (Transitional Measures concerning Delegation or Entrustment of Authority)
The Special Metropolitan City Mayor, a Metropolitan City Mayor, a Do Governor, the Special Self-Governing Province Governor, the Special Self-Governing City Mayor or specialized institutions who have been delegated or entrusted with part of the authority of the Minister of the Interior and Safety pursuant to the previous provisions as of the effective date of this Act shall be deemed to have been delegated or entrusted with part of the authority of the Protection Commission pursuant to this Act.
Article 7 (Transitional Measures concerning Penalty Provisions and Administrative Fines)
Application of penalty and administrative fines on acts that were committed before this Act enters into force shall be governed by the previous provisions.
Article 8 (Transitional Measures concerning Imposition of Administrative Surcharges)
Imposition of administrative surcharges on acts that were committed before this Act enters into force shall be governed by the previous provisions.
Article 9 Omitted.
Article 10 (Relationship to Other Statutes)
(1) When other statutes (including statutes that were promulgated before this Act enters into force but the enforcement date of which has not arrived yet) state the “Korea Communications Commission” or “Chairperson of the Korea Communications Commission” in relation to the work of the Korea Communications Commission and the Ministry of the Interior and Safety that is transferred to the Protection Commission according to this Act as at the time this Act enters into force, such terms are regarded as the “Protection Commission” or “Chairperson of the Protection Commission” as applicable; “public officials of the Korea Communications Commission” as “public officials of the Protection Commission;” “Ministry of the Interior and Safety” or “Minister of the Interior and Safety” as “Protection Commission” or “Chairperson of the Protection Commission” as applicable; and “public officials of the Ministry of the Interior and Safety” as “public officials of the Protection Commission”.
(2) If other statutes quote the previous Network Act or provisions therein as at the time this Act enters into force, and if there is any corresponding provision in this Act, such statutes or the provisions therein are regarded as this Act or provisions of this Act.

ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT

2-column view table
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.36671 20260911
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.36340 20260519
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.36121 20260820
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.35780 20251002
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.35343 20250313
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.34309 20240315
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.33723 20230915
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.32813 20221020
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.32528 20220308
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.31429 20210205
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.30892 20200805
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.30833 20200715
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.30509 20200303
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.29421 20190101
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.28355 20171019
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.28211 20170726
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.28150 20170627
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.28074 20170530
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.27522 20160930
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.27370 20160725
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.26776 20151230
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.26728 20151223
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.26140 20150311
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.25840 20150101
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.25751 20141119
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.25531 20140807
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.24425 20130323
ENFORCEMENT DECREE OF THE PERSONAL INFORMATION PROTECTION ACT No.23169 20110930
CHAPTER I GENERAL PROVISIONS
법령 이단보기
Article 1 (Purpose)
The purpose of this Decree is to prescribe matters mandated by the Personal Information Protection Act and matters necessary for the enforcement thereof.
법령 이단보기
Article 2 (Scope of public institutions)
"National agencies and public entities prescribed by Presidential Decree" in subparagraph 6 (b) of Article 2 of the Personal Information Protection Act (hereinafter referred to as the "Act") means: <Amended on Jul.14, 2020>
1. The National Human Rights Commission of Korea established under Article 3 of the National Human Rights Commission of Korea Act;
3. Local government-invested public corporations and local government public corporations established under the Local Public Enterprises Act;
4. Special corporations incorporated under any special Act;
5. Schools of each level established under the Elementary and Secondary Education Act, the Higher Education Act, and under any other statutes.
법령 이단보기
Article 3 (Scope of visual data processing devices)
(1) "Devices prescribed by Presidential Decree" in subparagraph 7 of Article 2 of the Act means the following: <Amended on Sep. 12, 2023>
1. A closed-circuit television means either of the following devices:
(a) A device that takes pictures, etc. continuously or regularly through a camera installed at a certain place, or transmits such pictures, etc. to a specified place via transmission channel of wired or wireless closed circuits, etc.;
(b) A device that can videotape or record the visual data photographed or transmitted under item (a);
2. A network camera means a device with which a person who installs or manages such device can collect, store, or otherwise process visual data filmed continuously or regularly through a device installed at a certain place, via the wired or wireless Internet at any place.
(2) "Device prescribed by Presidential Decree" in subparagraph 7-2 of Article 2 of the Act means the following: <Added on Sep. 12, 2023>
1. A wearable device: A device, such as eyeglasses or a watch, which is worn on the body or clothes of a person to take pictures, etc. or to collect, store, or transmit such pictures, etc.;
2. A portable device: A device, such as a mobile communications terminal or a digital camera, which a person carries to take pictures, etc. or to collect, store, or transmit such pictures, etc.;
3. An attachable or mountable device: A device that is attached to or mounted on a movable object, such as a vehicle or drone, to take pictures, etc. or to collect, store, or transmit such pictures, etc.
CHAPTER II PERSONAL INFORMATION PROTECTION COMMISSION
법령 이단보기
Article 4 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 4-2 (Prohibition on work for profit)
The Commissioners of the Personal Information Protection Commission (hereinafter referred to as the "Protection Commission") provided for in Article 7 (1) of the Act shall not engage in any of the following work for the purpose of making profits in accordance with Article 7-6 (1) of the Act:
1. Work related to the matters to be deliberated and resolved by the Protection Commission in accordance with Article 7-9 (1) of the Act;
2. Work related to the matters to be mediated by the Personal Information Dispute Mediation Committee referred to in Article 40 (1) of the Act (hereinafter referred to as the "Dispute Mediation Committee").
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 5 (Expert committees)
(1) The Protection Commission shall establish an expert committee for each of the following sectors (hereinafter referred to as "expert committee") to professionally conduct a preliminary review on the matters to be deliberated and resolved on under Article 7-9 (1) of the Act: <Amended on Aug. 4, 2020; Sep. 12, 2023>
1. Cross-border transfer of personal information;
2. Other sectors deemed necessary by the Protection Commission.
(2) An expert committee established under paragraph (1) shall be composed of up to 20 members with gender equality being taken into consideration, including one chairperson, who are designated or commissioned by the Chairperson of the Protection Commission from among the following persons; and the chairperson of the expert committee shall be designated by the Chairperson of the Protection Commission from among the expert committee members: <Amended on Jul. 22, 2016; Aug. 4, 2020; Sep. 12, 2023>
1. Commissioners of the Protection Commission;
2. A relevant public official of a central administrative agency who is responsible for work related to personal information protection;
3. Persons with abundant expertise and experience in personal information protection;
4. Persons belonging to, or recommended by, personal information protection-related organizations or trade associations.
(3) Except as provided in paragraphs (1) and (2), matters necessary for the composition, operation, etc. of expert committees shall be determined by the Chairperson of the Protection Commission subject to resolution by the Protection Commission. <Added on Sep. 12, 2023>
법령 이단보기
Article 5-2 (Personal Information Protection Policy Council)
(1) For the consistent implementation of personal information protection policies, and to facilitate consultation among relevant central administrative agencies with respect to matters related to the protection of personal information, the Personal Information Protection Policy Council (hereinafter referred to as the "Policy Council") may be established within the Protection Commission.
(2) The Policy Council shall consult on the following matters:
1. Major personal information protection policies, including the Master Plan for the protection of personal information under Article 9 of the Act and the implementation plan under Article 10 of the Act;
2. The enactment and amendment of major statutes or regulations related to the protection of personal information;
3. Cooperation and coordination of opinions on major personal information protection policies;
4. The prevention of and response to personal information breach incidents;
5. The development of technology and professional workforce for the protection of personal information;
6. Other matters requiring consultation among relevant central administrative agencies in connection with the protection of personal information.
(3) The Policy Council shall be comprised of the Senior Executive Service members of the relevant central administrative agencies or equivalent public officials in charge of work related to personal information protection, and they shall be appointed by the head of the relevant central administrative agencies, but the chairperson of the Policy Council (hereinafter referred to as the "Chairperson" in this Article) shall be the Vice Chairperson of the Protection Commission.
(4) If necessary to perform its duties, the Policy Council may have working-level councils or sector-specific councils.
(5) The chairpersons of the sector-specific councils and working-level councils shall be the Protection Commission’s public officials designated by the Chairperson of the Protection Commission.
(6) If necessary to do the work, the Policy Council, and working-level councils and sector-specific councils may request attendance, submission of materials or opinions, or other necessary cooperation from the related agency, organization, expert, etc.
(7) Except as provided in paragraphs (1) through (6), matters necessary for the operation of the Policy Council shall be determined by the chairperson through a resolution of the Policy Council.
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 5-3 (City/Do inter-agency personal information protection council)
(1) In order to efficiently implement personal information protection policies and strengthen autonomous protection of personal information, each Special Metropolitan City, Metropolitan City, Special Self-Governing City, Do and Special Self-Governing Province (hereinafter collectively referred to as "City/ Do") may have a City/Do inter-agency personal information protection council (hereinafter referred to as the "City/Do Council").
(2) The City/Do Councils shall discuss the following matters:
1. Personal information protection policies of the City/Do;
2. Collection and delivery of opinions from/to related agencies/organizations;
3. Sharing of best practices on protecting personal information;
4. Other matters requiring discussion at the City/Do Councils in relation to the protection of personal information.
(3) Except as provided in paragraphs (1) and (2), matters necessary for the composition and operation of a City/Do Council shall be prescribed by the ordinance of City/Do.
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 6 (Disclosure of proceedings)
Meetings of the Protection Commission shall be open to the public; provided, a meeting may be held as a closed session, if deemed necessary by the Chairperson of the Protection Commission.
법령 이단보기
Article 7 (Dispatch of public officials)
The Protection Commission may request a public institution to dispatch a public official, executive officer, or employee who works for the public institution, where it deems necessary to perform its work.
법령 이단보기
Article 8 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 9 (Allowances for attendance)
A Commissioner who attends a meeting of the Protection Commission, the expert committee, or the Policy Council; or a person who attends a meeting of the Protection Commission, the expert committee, or the Policy Council pursuant to Article 7-9 (2) of the Act may be paid allowances, travel expenses, and other necessary costs within the budget; provided, this shall not apply where any public official attends a meeting in direct connection with his or her duties. <Amended on Aug. 4, 2020>
법령 이단보기
Article 9-2 (Procedures for advising improvement of policies, systems, statutes, and regulations)
(1) The Protection Commission shall advise the improvement of policies, systems, statutes, and regulations to the relevant agency pursuant to Article 7-9 (4) of the Act, along with the details of and reasons for such improvement. <Amended on Aug. 4, 2020>
(2) The Protection Commission may request the relevant agency to submit materials about the results of the implementation of its advice in order to examine whether such advice has been implemented pursuant to Article 7-9 (5) of the Act. <Amended on Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 9-3 (Procedures for assessment of personal information breach incident factors)
(1) The head of a central administrative agency who intends to request an assessment of personal information breach incident factors pursuant to Article 8-2 (1) of the Act (hereinafter referred to as "assessment of personal information breach incident factors") shall submit to the Protection Commission a written request (or an electronic request form) for an assessment of personal information breach incident factors which contains the following matters:
1. The purposes and major contents of the policy and systems in need of personal information processing to be adopted or changed by the statutes or regulations (including the draft);
2. Self-analysis of personal information breach incident factors with respect to the matters prescribed in paragraph (2) following the adoption and change of the policy and system in need of personal information processing;
3. Measures to protect personal information following the adoption and change of the policy and system in need of personal information processing.
(2) Upon receipt of a written request under paragraph (1), the Protection Commission shall assess data breach incident factors taking into account the following matters, and shall notify the result thereof to the head of the related central administrative agency:
1. Necessity for processing personal information;
2. Appropriateness of guarantees for the rights of data subjects;
3. Safety in the management of personal information;
4. Other matters necessary to assess data breach incident factors.
(3) The head of a central administrative agency who has been advised as prescribed in Article 8-2 (2) of the Act shall endeavor to implement as advised, such as incorporating such advice in the relevant draft statute or regulation; provided, where it is impracticable to implement as advised by the Protection Commission, the reason therefor shall be notified to the Protection Commission.
(4) The Protection Commission may request materials necessary to assess data breach incident factors from the head of the related central administrative agency.
(5) The Protection Commission may establish guidelines necessary to assess data breach incident factors, including detailed criteria for and methods of the assessment of data breach incident factors; and shall notify the heads of central administrative agencies of the guidelines.
(6) The Protection Commission may seek counsel, etc. from relevant experts where necessary to assess data breach incident factors.
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 10 Deleted. <Aug. 4, 2020>
CHAPTER III PROCEDURES TO ESTABLISH MASTER PLANS AND IMPLEMENTATION PLANS
법령 이단보기
Article 11 (Procedures to establish master plans)
(1) The Protection Commission shall establish a Master Plan to protect personal information under Article 9 of the Act (hereinafter referred to as "Master Plan") every three years no later than June 30 of the year preceding the start of the third-year plan. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016; Aug. 4, 2020>
(2) To establish the Master Plan pursuant to paragraph (1), the Protection Commission may receive sub-plans by sector, in which mid- and long-term plans, policies, etc. related to personal information protection are reflected, from the heads of the related central administrative agencies, and may reflect them in the Master Plan. In such cases, the Protection Commission shall consult with the heads of the related central administrative agencies about the goals of the Master Plan, intended directions, guidelines to prepare sub-plans by sector, and other relevant matters. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016>
(3) Upon finalizing the Master Plan, the Protection Commission shall notify the heads of the related central administrative agencies of the Master Plan without delay. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016>
법령 이단보기
Article 12 (Procedures to establish implementation plans)
(1) The Protection Commission shall develop guidelines on how to establish implementation plans for the next year no later than June 30 each year, and notify the heads of the related central administrative agencies of such guidelines. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016; Aug. 4, 2020>
(2) The head of a related central administrative agency shall establish the implementation plan for the sector under his or her jurisdiction, to be implemented during the following year based upon the Master Plan according to the guidelines notified under paragraph (1); and shall submit the same to the Protection Commission no later than September 30 each year. <Amended on Aug. 4, 2020>
(3) The Protection Commission shall deliberate and resolve on the implementation plans submitted pursuant to paragraph (2) no later than December 31 of that year. <Amended on Aug. 4, 2020>
법령 이단보기
Article 13 (Scope of materials requested and methods of request)
(1) The Protection Commission may request materials or opinions regarding the following from a personal information controller pursuant to Article 11 (1) of the Act: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016; Sep. 12, 2023>
1. Matters concerning the management of personal information and personal information files processed by the personal information controller and the installation and operation of fixed or mobile visual data processing devices;
2. Matters concerning whether the privacy officer has been designated pursuant to Article 31 of the Act;
3. Matters concerning technical, managerial, and physical measures to ensure the safety of personal information;
4. Matters concerning access by data subjects, requests for correction, deletion, suspension of personal information processing, and the status of measures taken;
5. Other matters necessary to establish and implement a Master Plan, such as compliance with the Act and this Decree.
(2) When requesting materials, opinions, etc. pursuant to paragraph (1), the Protection Commission shall request the same to the minimum extent necessary to efficiently establish and implement the Master Plan. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016>
(3) Paragraphs (1) and (2) shall apply mutatis mutandis where the head of a central administrative agency requests materials, etc. from a personal information controller under his or her jurisdiction pursuant to Article 11 (3) of the Act. In such cases, the "Protection Commission" shall be construed as the "head of a central administrative agency", and "Article 11 (1) of the Act" as "Article 11 (3) of the Act", respectively. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 22, 2016>
법령 이단보기
Article 13-2 (Subject matters, standards, methods, and procedures for evaluation of level of personal information protection)
(1) "Institutions prescribed by Presidential Decree" in Article 11-2 (1) of the Act means the following institutions:
2. Public corporations and public agencies under the Local Public Enterprises Act;
3. Other public institutions referred to in subparagraphs 4 and 5 of Article 2, which meet the standards publicly notified by the Protection Commission in consideration of the characteristics of personal information processing business of the public institutions.
(2) The standards for the evaluation of the level of personal information protection under Article 11-2 (1) of the Act (hereinafter referred to as "evaluation of the level of personal information protection") shall be as follows:
1. Personal information protection policies and performance records and degree of improvement;
2. Appropriateness of personal information management system;
3. Measures taken to guarantee rights of data subjects and degree of implementation;
4. Measures to prevent infringement of personal information and degree of implementation of measures to ensure safety;
5. Compliance with other measures necessary for the processing and safe management of personal information.
(3) Before conducting evaluation of the level of personal information protection level, the Protection Commission shall prepare an evaluation plan including the subject matter, criteria, methods, indexes, etc. of evaluation and notify the head of an institution subject to evaluation of the level of personal information protection (hereinafter referred to as "institution subject to evaluation") of the evaluation of the level of personal information protection.
(4) In order to efficiently conduct the evaluation of the level of personal information protection, the Protection Commission may organize and operate an evaluation team, including experts with abundant expertise and experience in personal information protection.
(5) The Protection Commission may require the following materials to be submitted pursuant to Article 11-2 (2) of the Act:
1. Where an institution subject to evaluation conducts its own inspection of the level of personal information protection, the results thereof and evidential data;
2. Data necessary for verifying evidentiary materials under subparagraph 1;
3. Other data necessary to evaluate the level of personal information protection, such as whether personal information is safely managed.
(6) The Protection Commission may conduct an evaluation based on the data submitted by the head of an institution subject to evaluation pursuant to paragraph (5) or visit an institution subject to evaluation to conduct such evaluation.
(7) The Protection Commission may request the head of a central administrative agency or the head of a local government to provide support necessary for measures to protect personal information based on the preparation for evaluation or the results of evaluation by an institution subject to evaluation in the relevant field, such as an institution under its jurisdiction. In such cases, upon receipt of such request, the head of a central administrative agency or the head of a local government shall endeavor to provide support upon receipt of such request.
(8) Details of the evaluation of the level of personal information protection under paragraphs (1) through (7) shall be determined and publicly notified by the Protection Commission.
[This Article Added on Mar. 12, 2024]
법령 이단보기
Article 14 (Promotion and support of self-regulation)
The Protection Commission may provide necessary support to agencies and organizations related to the protection of personal information within budgetary limits to promote self-regulating data-protection activities of personal information controllers pursuant to subparagraph 2 of Article 13 of the Act. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
CHAPTER IV PROCESSING OF PERSONAL INFORMATION
법령 이단보기
Article 14-2 (Standards on additional use and provision of personal information)
(1) If a personal information controller uses or provides personal information (hereinafter referred to as "additional use or provision of personal information") without the consent of the data subject in accordance with Article 15 (3) or Article 17 (4) of the Act, the personal information controller shall consider the following matters:
1. Whether it is reasonably related to the original purpose for which the personal information was collected;
2. Whether additional use or provision of personal information is foreseeable in light of the circumstances under which the personal information was collected and processing practices;
3. Whether additional use or provision of personal information does not unfairly infringe on the interests of the data subject;
4. Whether the measures required to ensure safety such as pseudonymization or encryption have been taken.
(2) Where additional use or provision of personal information continues to take place, a personal information controller shall disclose the criteria for assessing the matters referred to in the subparagraphs of paragraph (1) in the Privacy Policy under Article 30 (1) of the Act, and a privacy officer under Article 31 (1) of the Act shall check whether the personal information controller is using or providing additional personal information in accordance with the relevant criteria. <Amended on Sep. 12, 2023>
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 15 (Control of out-of-purpose use of personal information or provision thereof to third parties)
Where a public institution uses personal information for other than the intended purpose, or provides it to a third party pursuant to Article 18 (2) of the Act, it shall record the following in the Register for Control of Out-of-Purpose Use or Provision of Personal Information in the form determined and publicly notified by the Protection Commission; and shall manage the Register: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
1. The name of the personal information or personal information file to be used or provided;
2. The name of the institution that uses, or is provided with, personal information;
3. The purpose of use or provision;
4. The statutory ground for such use or provision;
5. Particulars of personal information to be used or provided;
6. The date, frequency, or period for using or providing personal information;
7. Methods of use or provision of personal information;
8. Any limitation or necessary measure that the personal information controller has requested from the recipient pursuant to Article 18 (5) of the Act.
법령 이단보기
Article 15-2 (Matters subject to notification, such as sources of personal information collected, and methods and procedures for notification)
(1) "Personal information controller satisfying the criteria prescribed by Presidential Decree" in the main clause of Article 20 (2) of the Act means any of the following personal information controllers; in such cases, the number of data subjects prescribed in the following shall be calculated based on the daily average during the immediately preceding three months as of the end of the previous year: <Amended on Sep. 12, 2023>
1. A person who processes sensitive information defined in Article 23 of the Act (hereinafter referred to as "sensitive information") or personally identifiable information defined in Article 24 (1) of the Act (hereinafter referred to as "personally identifiable information") of at least 50 thousand data subjects;
2. A person who processes personal information of at least one million data subjects.
(2) A personal information controller who falls under any subparagraph of paragraph (1) shall notify data subjects of the matters referred to in the subparagraphs of Article 20 (1) of the Act by any of the following methods within three months from the date of being provided with their personal information; provided, where the personal information controller is regularly provided with and processes personal information at least twice a year to the extent that the personal information controller has obtained consent from the data subjects under Article 17 (1) 1 of the Act about the matters prescribed in Article 17 (2) 1 through 4 of the Act, he or she shall notify the data subjects within three months from the date of being provided with their personal information, or at least once a year counting from the date of the consent: <Amended on Sep. 12, 2023>
1. A method by which a data subject can easily confirm the details of notification, such as in writing, electronic mail, telephone, or text message;
2. Giving notification in the course of providing goods or services through a notification window so that the data subjects can easily recognize the relevant matters.
(3) A personal information controller may give the following notices simultaneously: <Amended on Feb. 25, 2025>
1. Notification of sources, etc. of personal information collected under Article 20 (2) of the Act;
2. Notification of details of use and provision of personal information under Article 20-2 (1) of the Act;
3. Notification of details of transmission of information subject to request for transmission under the main clause of Article 42-6 (10).
(4) A personal information controller specified in any subparagraph of paragraph (1) who has made notification under paragraph (2) shall retain and manage the following matters until the relevant personal information is destroyed pursuant to Article 21 or 37 (5) of the Act: <Amended on Sep. 12, 2023>
1. The fact that data subjects are notified;
2. When notification is made;
3. How notification is made.
[This Article Added on Sep. 29, 2016]
[Title Amended on Sep. 12, 2023]
법령 이단보기
Article 15-3 (Notification of details of use and provision of personal information)
(1) "Personal information controller who meets the criteria prescribed by Presidential Decree" in the main clause of Article 20-2 (1) of the Act means any of the following personal information controllers; in such cases, the number of data subjects prescribed in the following subparagraphs shall be calculated based on the daily average during the immediately preceding three months as of the end of the previous year:
1. A person who processes sensitive information or personally identifiable information of at least 50 thousand data subjects;
2. A person who processes personal information of at least one million data subjects.
(2) A data subject to be given notification under Article 20-2 (1) of the Act shall be a data subject except the following:
1. A data subject who expresses his or her intention to refuse notification;
2. Where a personal information controller processes the personal information of executive officers and employees under his or her control to perform his or her work, the relevant data subject;
3. Where a personal information controller processes the personal information of executive officers or employees of other public institutions, corporations, or organizations or individuals, including their contact information, to perform his or her work, the relevant data subject;
4. A data subject of personal information that is used or provided under provisions otherwise provided in statutes or for the purpose of complying with legal obligations;
5. A data subject of personal information that is used or provided by public institutions for the purpose of performing their work prescribed in statutes, regulations, etc.
(3) Information to be notified to data subjects under Article 20-2 (1) of the Act shall be as follows:
1. The purpose of collecting and using personal information and the particulars of the personal information collected and used;
2. A third party provided with personal information, the purpose of providing the personal information, and the particulars of the personal information provided; provided, excluded herefrom shall be information provided under Articles 13, 13-2, and 13-4 of the Protection of Communications Secrets Act and Article 83 (3) of the Telecommunications Business Act.
(4) Notification under Article 20-2 (1) of the Act shall be given at least once a year by any of the following methods:
1. A method by which a data subject can easily confirm the details of notification, such as in writing, electronic mail, telephone, or text message;
2. Giving notification in the course of providing goods or services through a notification window so that a data subject can easily recognize the relevant details (limited to where notification is given regarding the methods of accessing the information system through which the details of the use and provision of personal information are confirmed under Article 20-2 (1) of the Act).
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 16 (Methods of destroying personal information)
(1) A personal information controller shall destroy personal information pursuant to Article 21 of the Act by the following methods: <Amended on Aug. 6, 2014; Jul. 19, 2022>
1. Personal information in electronic files shall be permanently deleted so that it cannot be restored; provided, where it is substantially impracticable to permanently delete the files due to technical characteristics, the personal information controller shall take measures to make it impossible to restore the information by treating it as information falling under Article 58-2 of the Act;
2. Other records, printouts, paper documents, and media containing personal information, other than those referred to in subparagraph 1, shall be shredded or incinerated.
(2) Detailed matters concerning the safe destruction of personal information subject to paragraph (1) shall be determined and publicly notified by the Protection Commission. <Added on Aug. 6, 2014; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
법령 이단보기
Article 17 (Methods of obtaining consent)
(1) A personal information controller shall meet all of the following requirements when obtaining consent from a data subject to the processing of his or her personal information pursuant to Article 22 of the Act: <Added on Sep. 12, 2023>
1. The data subject shall be able to decide whether to give his or her consent based on his or her free will;
2. Details requiring the consent of the data subject shall be specific and clear;
3. The personal information controller shall use phrases that are easily readable and understandable for the relevant details;
4. The personal information controller shall provide the data subject with the methods of clearly indicating whether to give consent.
(2) A personal information controller shall obtain consent from a data subject to the processing of his or her personal information pursuant to Article 22 of the Act by any of the following methods: <Amended on Sep. 12, 2023>
1. To issue a document stating the matters requiring consent, either in person or by mail or facsimile, to the data subject, and obtain a written consent on which the data subject has affixed his or her signature or seal;
2. To inform the data subject of the matters requiring consent, and confirm his or her intent of consent by telephone;
3. To inform the data subject of the matters requiring consent by telephone, have the data subject confirm the matters requiring his or her consent posted on a designated website, etc.; and reconfirm his or her intent of consent by telephone;
4. To post the matters requiring consent on a designated website, etc., and have the data subject express his or her consent thereto;
5. To send an electronic mail containing the matters requiring consent to the data subject, and receiving an e-mail indicating his or her consent thereto;
6. Other methods to inform the data subject of the matters requiring consent by a method similar to those referred to in subparagraphs 1 through 5 and confirm his or her intent of consent.
(3) "Important matters prescribed by Presidential Decree" in Article 22 (2) of the Act means the following: <Added on Oct. 17, 2017; Sep. 12, 2023>
1. The fact that a data subject may be contacted to promote goods or services or solicit purchase thereof using the data subject’s personal information with respect to the purpose of collecting and using personal information;
2. The following matters with respect to the particulars of personal information to be processed:
(a) Sensitive information;
(b) Passport numbers, driver’s license numbers, and alien registration numbers as set forth in subparagraphs 2 through 4 of Article 19;
3. The period for retaining and using personal information (in the case of provision, meaning the period for retaining and using personal information by the recipient);
4. The recipient of personal information and the purpose for which the recipient of the personal information uses such information.
(4) Where a personal information controller intends to obtain consent from a data subject under the subparagraphs of Article 22 (1) of the Act, he or she shall clearly indicate the fact that the data subject may choose whether to give consent. <Amended on Sep. 12, 2023>
(5) "Means prescribed by Presidential Decree" in the former part of Article 22 (3) of the Act means in writing, or by electronic mail, facsimile, telephone, or text message, or any other means equivalent thereto (hereinafter referred to as "in writing, etc."). <Amended on Sep. 12, 2023>
(6) The head of a central administrative agency may establish the standards for appropriate methods of obtaining consent, out of the various methods of consent stated in paragraph (2), through the personal information protection guidelines under Article 12 (2) of the Act (hereinafter referred to as "personal information protection guidelines"), in consideration of the work of each personal information controller under his or her jurisdiction, the characteristics of their business, the number of data subjects, etc., and may encourage personal information controllers to obtain consent in accordance with such standards. <Added on Dec. 30, 2015; Oct. 17, 2017; Sep. 12, 2023>
법령 이단보기
Article 17-2 (Protection of children's personal information)
(1) A personal information controller shall confirm whether a legal representative has granted consent pursuant to Article 22-2 (1) of the Act by any of the following methods:
1. Requesting the legal representative to indicate whether to give consent on the website where matters requiring consent are posted, and informing him or her by mobile phone text message that the personal information controller confirms the indication of the consent;
2. Requesting the legal representative to indicate whether to give consent on the website where matters requiring consent are posted, and being provided with information on his or her card, such as a credit card or debit card;
3. Requesting the legal representative to indicate whether to give consent on the website where matters requiring consent are posted, and verifying the identity of the legal representative through identity verification on his or her mobile phone;
4. Issuing the legal representative a document specifying matters requiring consent, either in person or by mail or fax, and requesting him or her to submit the document after signing and affixing seal on it with respect to such matters;
5. Sending the legal representative an electronic mail that specifies matters requiring consent, and requesting him or her to send an electronic mail with consent indicated;
6. Notifying the legal representative of matters requiring consent by telephone to obtain consent, or providing him or her with information on the methods of confirming matters requiring consent, such as via the Internet address, to obtain consent by telephone;
7. Other methods equivalent to those prescribed in subparagraphs 1 through 6 by which matters requiring consent are notified to the legal representative and an indication of his or her consent is confirmed.
(2) "Information prescribed by Presidential Decree" in Article 22-2 (2) of the Act means information on the name and contact details of a legal representative.
(3) Where it is impracticable for a personal information controller to indicate all matters requiring consent due to the characteristics of a medium by which personal information is collected, the personal information controller may provide a legal representative with information on the methods of confirming matters requiring consent, such as the Internet address or the telephone number of the place of business.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 18 (Scope of sensitive information)
"Information prescribed by Presidential Decree" in the main clause, with the exception of the subparagraphs, of Article 23 (1) of the Act means the following data or information; provided, where the public institutions process any of the following data or information pursuant to Article 18 (2) 5 through 9 of the Act, the said information shall be excluded herefrom: <Amended on Sep. 29, 2016; Aug. 4, 2020>
1. DNA information acquired from genetic testing, etc.;
2. Data that constitute a criminal history record defined in subparagraph 5 of Article 2 of the Act on the Lapse of Criminal Sentences;
3. Personal information resulting from specific technical processing of data relating to the physical, physiological or behavioral characteristics of an individual for the purpose of uniquely identifying that individual;
4. Personal information revealing racial or ethnic origin.
법령 이단보기
Article 19 (Scope of personally identifiable information)
"Information prescribed by Presidential Decree" in the provisions, with the exception of the subparagraphs, of Article 24 (1) of the Act means any of the following information; provided, such information does not include any of the following information processed by the public institutions pursuant to Article 18 (2) 5 through 9 of the Act: <Amended on Sep. 29, 2016; Jun. 27, 2017; Aug. 4, 2020>
1. Resident registration numbers under Article 7-2 (1) of the Resident Registration Act;
2. Passport numbers under Article 7 (1) 1 of the Passport Act;
3. Driver’s license numbers under Article 80 of the Road Traffic Act;
4. Alien registration numbers under Article 31 (5) of the Immigration Act.
법령 이단보기
Article 20 Deleted. <Aug. 6, 2014>
법령 이단보기
Article 21 (Measures to ensure safety of personally identifiable information)
(1) Article 30 shall apply mutatis mutandis to measures to ensure the safety of personally identifiable information under Article 24 (3) of the Act. In such cases, "Article 29 of the Act" shall be construed as "Article 24 (3) of the Act"; and "personal information" as "personally identifiable information", respectively. <Amended on Aug. 4, 2020; Sep. 12, 2023>
(2) "Personal information controller" who meets the standards prescribed by Presidential Decree in Article 24 (4) of the Act means any of the following personal information controllers: <Amended on Mar. 12, 2024>
1. A public institution that processes personally identifiable information of at least 10,000 data subjects;
2. A public institution which the Protection Commission deems it necessary to conduct an investigation under Article 24 (4) of the Act in consideration of the history of violations of the Act, the details and degree of violation, the risk of processing personally identifiable information, etc.;
3. A person, other than a public institution, who processes personally identifiable information on at least 50,000 data subjects.
(3) The Protection Commission shall investigate whether a personal information controller falling under any subparagraph of paragraph (2) has taken measures necessary to ensure safety pursuant to Article 24 (4) of the Act at least once every three years. <Amended on Jul. 26, 2017; Aug. 4, 2020; Mar. 12, 2024>
(4) Inspection of measures to ensure the safety of personally identifiable information has been conducted in any of the following cases, an investigation under paragraph (3) shall be deemed to have been conducted. <Added on Mar. 12, 2024>
1. Where the evaluation of the level of personal information protection has been conducted pursuant to Article 11-2 of the Act;
2. Where personal information protection is certified pursuant to Article 32-2 of the Act;
3. Where a regular inspection is conducted on whether measures to ensure the safety of personally identifiable information have been implemented under other Acts, such as a regular evaluation of the status of utilization and management of personal credit information under Article 45-5 of the Credit Information Use and Protection Act, and where the Protection Commission deems that the relevant inspection is equivalent to an investigation under paragraph (3) at the request of the head of the relevant central administrative agency.
(5) The investigation under paragraph (3) shall be conducted by requiring a personal information controller falling under any subparagraph of paragraph (2) to submit necessary materials online or in writing. <Amended on Mar. 12, 2024>
(6) "Specialized Institution prescribed by Presidential Decree” in Article 24 (5) of the Act means any of the following institutions: <Amended on Jul. 26, 2017; Aug. 4, 2020; Mar. 12, 2024>
1. The Korea Internet and Security Agency established under Article 52 of the Act on Promotion of Information and Communications Network Utilization and Information Protection. (hereinafter referred to as the "Korea Internet and Security Agency");
2. A corporation, organization, or institution determined and publicly notified by the Protection Commission as deemed to have technical and financial capacity and equipment to conduct the inspection pursuant to Article 24 (4) of the Act.
[This Article Wholly Amended on Sep. 29, 2016]
법령 이단보기
Article 21-2 (Persons who must encrypt resident registration numbers)
(1) Any personal information controller who retains resident registration numbers by electronic means shall take encryption measures pursuant to Article 24-2 (2) of the Act.
(2) The encryption of resident registration numbers by a personal information controller under paragraph (1) shall start from one of the following dates:
1. As to the personal information controllers who retain the resident registration numbers of less than one million data subjects: January 1, 2017;
2. As to the personal information controllers who retain the resident registration numbers of at least one million data subjects: January 1, 2018.
(3) The Protection Commission may determine and publicly notify the detailed matters regarding encryption measures under paragraph (1), taking into account the technical and economic feasibility and other factors. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Dec. 30, 2015]
법령 이단보기
Article 22 (Exception to restriction on installation and operation of fixed visual data processing devices)
(1) "Cases prescribed by Presidential Decree" in Article 25 (1) 6 of the Act means any of the following cases: <Added on Sep. 12, 2023>
1. Where any photographed visual data is temporarily processed to compute statistical values or statistical characteristic values, such as the number, genders, and ages of visitors;
2. Other cases equivalent to that prescribed in subparagraph 1, which have been deliberated and resolved on by the Protection Commission.
(2) "Facilities prescribed by Presidential Decree" in the proviso of Article 25 (2) of the Act means the following facilities: <Amended on May 29, 2017; Aug. 4, 2020; Sep. 12, 2023>
1. Correctional facilities defined in subparagraph 1 of Article 2 of the Execution of Sentences and Treatment of Inmates;
2. Mental medical institutions (with accommodation facilities), mental treatment facilities, and mental patient rehabilitation facilities defined in subparagraph 5 through 7 of Article 3 of the Act on the Improvement of Mental Health and the Support for Welfare Services for Mental Patients.
(3) The head of a central administrative agency may establish a Privacy Policy which includes the detailed matters necessary to minimize infringement on the privacy of data subjects; and may encourage the personal information controllers under his or her jurisdiction to comply with the Privacy Policy when they install and operate fixed visual data processing devices at the facilities referred to in the subparagraphs of paragraph (2) pursuant to the proviso of Article 25 (2) of the Act. <Amended on Sep. 12, 2023>
[Title Amended on Sep. 12, 2023]
법령 이단보기
Article 23 (Gathering opinions on installation of fixed visual data processing devices)
(1) The head of a public institution that intends to install and operate fixed visual data processing devices pursuant to Article 25 (1) of the Act shall gather opinions from relevant experts and interested parties through any of the following procedures: <Amended on Sep. 12, 2023>
1. To give administrative advance notice or to hear opinions under the Administrative Procedures Act;
2. To hold an information session or to conduct a survey or polling with respect to the neighborhood residents, etc. directly affected by the installation of those fixed visual data processing devices.
(2) A person who intends to install and operate fixed visual data processing devices at the facilities specified in the proviso of Article 25 (2) of the Act shall gather opinions from the following persons: <Amended on Sep. 12, 2023>
1. Relevant experts;
2. Persons working in the relevant facilities, persons detained or accommodated in the relevant facilities, or interested parties, including the guardians of such persons.
[Title Amended on Sep. 12, 2023]
법령 이단보기
Article 24 (Posting of notice on signboard)
(1) A person who installs and operates fixed visual data processing devices pursuant to Article 25 (1) of the Act (hereinafter referred to as "fixed visual data processing device operator") shall post the matters referred to in the subparagraphs of Article 25 (4) of the Act on a signboard so that data subjects may easily recognize that such devices have been installed and in operation; provided, a signboard, indicating the operation of fixed visual data processing devices in the pertinent facilities and whole area, may be posted at the entry and other easily noticeable place where several fixed visual data processing devices are installed in a building: <Amended on Sep. 29, 2016; Sep. 12, 2023>
1. Deleted; <Sep. 29, 2016>
2. Deleted; <Sep. 29, 2016>
3. Deleted. <Sep. 29, 2016>
(2) Notwithstanding paragraph (1), where any of the following applies to a fixed visual data processing device installed and operated by a fixed visual data processing device operator, the operator may post the matters referred to in the subparagraphs of Article 25 (4) of the Act on its website, in lieu of posting them on the signboard: <Amended on Sep. 29, 2016; Sep. 12, 2023>
1. Where the fixed visual data processing device is installed by a public institution for such purposes as long range photographing, over-speed and traffic signal violation enforcement service, or traffic flow survey, while the possibility of a personal information breach is significantly low;
2. Where a signboard cannot be posted because of the characteristics of the location or is not easily noticeable by data subjects even if posted, e.g., a fixed visual data processing device installed for surveillance of mountain fire.
(3) If the matters referred to in the subparagraphs of Article 25 (4) of the Act cannot be posted on a website under paragraph (2), a fixed visual data processing device operator shall make public the said matters in one or more of the following methods: <Amended on Sep. 29, 2016; Aug. 2020; Sep. 12, 2023>
1. Posting at easily noticeable places of the fixed visual data processing device operator’s workplace, business premise, office, shop, etc. (hereinafter referred to as "workplace, etc.");
2. Publishing them in the Official Gazette (only where the fixed visual data processing device operator is a public institution) or a general daily newspaper, weekly newspaper or online newspaper, as defined in subparagraph 1 (a) and (c), or 2 of Article 2 of the Act on the Promotion of Newspapers circulating mainly over the Special Metropolitan City, Metropolitan City, Do, or Special Self-Governing Province (hereinafter referred to as "City/ Do") where the fixed visual data processing device operator’s workplace is located.
(4) "Facilities prescribed by Presidential Decree" in the proviso, with the exception of the subparagraphs, of Article 25 (4) of the Act means the national security facilities provided for in Article 32 of the Regulations on Security Work. <Amended on Sep. 29, 2016>
법령 이단보기
Article 25 (Policy on operation and management of fixed visual data processing devices)
(1) Each fixed visual data processing device operator shall establish a policy to operate and manage fixed visual data processing devices including the following matters pursuant to Article 25 (7) of the Act: <Amended on Sep. 12, 2023>
1. The statutory ground and purpose for installing the fixed visual data processing devices;
2. The number of the fixed visual data processing devices installed, the locations of installation, and the scope of photographing;
3. The manager and department in charge, and the person who is entitled to access the visual data;
4. The duration of filming, retention period, retention place, and processing method of the visual data;
5. How and where the fixed visual data processing device operator checks the visual data;
6. The measures taken to deal with the data subject’s request to access the visual data;
7. The technical, managerial, and physical safeguards to protect the visual data;
8. Other matters necessary to install, operate, and manage the fixed visual data processing devices.
(2) Article 31 (2) and (3) shall apply mutatis mutandis to the disclosure of the policy to operate and manage fixed visual data processing devices established pursuant to paragraph (1). In such cases, "personal information controller" shall be construed as "fixed visual data processing device operator", "Article 30 (2) of the Act" as "Article 25 (7) of the Act", and "Privacy Policy" as "policy to operate and manage fixed visual data processing devices", respectively. <Amended on Sep. 12, 2023>
[Title Amended on Sep. 12, 2023]
법령 이단보기
Article 26 (Entrustment of installation and operation of fixed visual data processing devices by public institutions)
(1) Where a public institution entrusts the installation and operation of fixed visual data processing devices to a third party pursuant to the proviso of Article 25 (8) of the Act, it shall do so in writing stating the following: <Amended on Sep. 12, 2023>
1. The purpose and scope of entrusted business affairs;
2. Matters concerning limitation to re-entrustment;
3. Matters concerning the measures to ensure safety, including limitation to access to visual data;
4. Matters concerning the inspection of the status of visual data retained;
5. Matters concerning damage liability in case of breach of contractual obligation on the part of a person to whom the work is entrusted.
(2) Where business affairs are entrusted pursuant to paragraph (1), the name and contact information of the person entrusting shall be posted on the signboard, etc. referred to in Article 24 (1) through (3).
[Title Amended on Sep. 12, 2023]
법령 이단보기
Article 27 (Exception to restriction on operation of mobile visual data processing devices)
"Cases prescribed by Presidential Decree" in the proviso of Article 25-2 (2) of the Act means where it is necessary to take photographs of a person or things related to such person (limited to where such photographs constitute personal information; hereinafter the same shall apply) for the lifesaving, first-aid services, etc. in the event of a crime, fire, disaster, or any other situation equivalent thereto.
[This Article Added on Sep. 12, 2023]
[Previous Article 27 moved to Article 27-3 <Sep. 12, 2023>]
법령 이단보기
Article 27-2 (Indication of photographing with mobile visual data processing devices)
Where persons or things related to such persons are photographed with a mobile visual data processing device in cases falling under the subparagraphs of Article 25-2 (1) of the Act, the fact of photographing shall be indicated and informed by means of light, sound, signboard, written notice, or announcement, or other means or methods equivalent thereto so that data subjects can easily recognize such fact; provided, the fact of photographing may be informed by the means notified on the website established by the Protection Commission where it is difficult to inform data subjects of the fact due to the characteristics of photographing methods, such as aerial photographing using a drone.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 27-3 (Guidelines for installing and operating visual data processing devices)
Except as provided in the Act and this Decree, the Protection Commission may establish the Standard Personal Information Protection Guidelines referred to in Article 12 (1) of the Act regarding the standards for installing and operating fixed visual data processing devices and for operating mobile visual data processing devices, the entrusting of their installation and operation, and other matters; and may encourage fixed visual data processing device operators and persons who operate mobile visual data processing devices to comply with the Standard Guidelines. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
[Moved from Article 27 <Sep. 12, 2023>]
법령 이단보기
Article 28 (Measures to be taken when entrusting personal information processing)
(1) "Matters prescribed by Presidential Decree" in Article 26 (1) 3 of the Act means the following:
1. The purpose and scope of entrusted work;
2. Matters concerning limitation to re-entrustment;
3. Matters concerning measures to ensure safety, including limitation to access to personal information;
4. Matters concerning supervision and inspection of the status of management of personal information retained in relation to entrusted work;
5. Matters concerning liability, such as compensation for damages caused by a breach of contractual obligations on the part of a person entrusted under Article 26 (2) of the Act (hereinafter referred to as "person entrusted").
(2) "Manner prescribed by Presidential Decree" in Article 26 (2) of the Act means the method wherein a personal information controller that has entrusted personal information processing (hereinafter referred to as "person entrusting") continuously posts details of the entrusted work and the person entrusted on its website.
(3) Where it is impossible to post on the website as prescribed in paragraph (2), the entrusted work and the person entrusted shall make public in one or more of the following manners: <Amended on Sep. 12, 2023>
1. Posting at easily noticeable places such as workplace of a person entrusting;
2. Publishing in the Official Gazette (only where the person entrusting is a public institution) or a general daily newspaper, weekly newspaper, or online newspaper, as defined in subparagraphs 1 (a) and (c) and 2 of Article 2 of the Act on the Promotion of Newspapers which mainly covers the City/Do where the person entrusting’s workplace, etc. is located;
3. Publishing at a periodical, newsletter, PR magazine, or invoice to be published under the same title at least twice a year and distributed to data subjects on a continual basis;
4. Stipulating in an agreement, etc. for the supply of goods and services executed between the person entrusting and the data subjects and providing a copy of the same to the data subjects.
(4) "Manners prescribed by Presidential Decree" in the former part of Article 26 (3) of the Act means in writing, etc. <Amended on Sep. 12, 2023>
(5) Where a person entrusting is unable to inform the data subjects of the entrusted work and the person entrusted in the manner stated in paragraph (4) without its negligence, the person entrusting shall post the relevant matters on its website for at least 30 days; provided, a person entrusting who has no website shall post them at easily noticeable places of its workplace, etc. for at least 30 days.
(6) Where a person entrusted processes personal information, the person entrusting shall supervise whether the person entrusting complies with the obligations of a personal information controller provided for in the Act and this Decree and the matters referred to in Article 26 (1) of the Act, pursuant to Article 26 (4) of the Act.
법령 이단보기
Article 29 (Notification of transfer of personal information following business transfer)
(1) "Manner prescribed by Presidential Decree" in the provisions, with the exception of the subparagraphs, of Article 27 (1) of the Act and the main clause of Article 27 (2) of the Act means in writing, etc.
(2) Where a person who intends to transfer personal information pursuant to Article 27 (1) of the Act (hereinafter referred to as "business transferor, etc." in this Article) fails to inform the data subjects of the matters stated in Article 27 (1) of the Act in the manner stated in paragraph (1) without his or her negligence, the person shall post the relevant matters on the website for at least 30 days; provided, if there is a good reason for not being able to post the required information on its website, the business transferor, etc. may inform the data subjects of the matters stated in each subparagraph of Article 27 (1) of the Act through any of the following methods: <Amended on Aug. 4, 2020>
1. Posting the information at easily noticeable places of the workplace, etc. of the business transferor, etc. for at least 30 days;
2. Publishing the information in a general daily newspaper, weekly newspaper, or online newspaper, as defined in subparagraphs 1 (a) and (c) or 2 of Article 2 of the Act on the Promotion of Newspapers which mainly covers the City/Do where the business transferor, etc.’s workplace, etc. is located.
CHAPTER IV-2 SPECIAL CASES CONCERNING PROCESSING OF PSEUDONYMIZED INFORMATION
법령 이단보기
Article 29-2 (Designation and cancellation of designation of expert data combination agency)
(1) The standards for the designation of an expert agency (hereinafter referred to as "Expert Data Combination Agency") pursuant to Article 28-3 (1) of the Act shall be as follows: <Amended on Feb. 25, 2025>
1. The agency shall have formed an organization responsible for the combination and release of pseudonymized information and employed at least three full-time personnel with qualifications or experience relating to personal information protection, as determined and publicly notified by the Protection Commission;
2. The agency shall have set up space, facilities and equipment necessary to combine pseudonymized information safely and prepared policies and procedures relating to the combination and release of pseudonymized information, as determined and publicly notified by the Protection Commission;
3. The agency shall have financial capabilities in compliance with the standards determined and publicly notified by the Protection Commission;
4. The relevant agency shall not have been subject to public announcement pursuant to Article 66 (1) of the Act nor been ordered to make a public announcement under Article 66 (2) within the last 3 years;
5. The agency shall not have failed to obtain re-designation after applying for an extension of the effective period under paragraph (4) and shall not have had its designation revoked pursuant to paragraph (5) within the last 1 year.
(2) Any corporation, organization, or institution intending to be designated as an Expert Data Combination Agency pursuant to Article 28-3 (1) of the Act shall submit to the head of the Protection Commission or the related central administrative agency an application for the Designation of Expert Data Combination Agency determined and publicly notified by the Protection Commission with the following documents attached (including electronic documents; the same shall apply hereinafter):
1. Articles of incorporation or bylaws;
2. Documents prescribed and notified by the Protection Commission supporting that the agency satisfies the designation standards under paragraph (1).
(3) The head of the Protection Commission or related central administrative agency may designate the corporation, organization, or institution which submitted the application for the Designation of Expert Data Combination Agency under paragraph (2) as an Expert Data Combination Agency if it satisfies the designation standards under paragraph (1).
(4) Designation as an Expert Data Combination Agency shall be effective for 3 years from the date of designation, and if the Expert Data Combination Agency requests extension of the effective period, the head of the Protection Commission or the relevant central administrative agency may re-designate it as an Expert Data Combination Agency after reviewing the following matters: <Amended on Feb. 25, 2025>
1. Whether it meets the standards for designation under paragraph (1);
2. Whether the future business performance plan is suitable for achieving the purpose of designation;
3. Whether it has properly performed its business affairs according to the purpose of designation;
4. Whether it has unduly restricted data combinations, such as by charging excessive fees under Article 29(3) 5.
(5) If the Expert Data Combination Agency falls under any of the following, the head of the Protection Commission or related central administrative agency may cancel the designation of the Expert Data Combination Agency; provided, in the cases of subparagraph 1 or 2, designation shall be canceled:
1. If the agency has received the designation by fraud or improper means;
2. If the agency voluntarily requests cancellation of its designation or discontinues its business;
3. If the agency becomes non-compliant with the standards for designation of an Expert Data Combination Agency under paragraph (1);
4. If a personal information breach incident, including divulgence of information, occurs in connection with data combination, release, etc.;
5. If the agency otherwise violates any obligation under the Act or this Decree.
(6) The head of the Protection Commission or related central administrative agency shall hold a hearing when seeking to cancel the designation of an Expert Data Combination Agency in accordance with paragraph (5).
(7) The head of the Protection Commission or related central administrative agency shall publicly announce any designation, re-designation or cancellation of designation of an Expert Data Combination Agency in the Official Gazette or the websites of the Protection Commission or related central administrative agency. In such cases, if the head of the related central administrative agency designated, re-designated, or canceled the designation of any Expert Data Combination Agency, the head of the central administrative agency shall notify the Protection Commission of the same.
(8) Except as provided in paragraphs (1) through (7), matters necessary in connection with the designation, re-designation and cancellation of designation of an Expert Data Combination Agency shall be determined and publicly notified by the Protection Commission.
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 29-3 (Combination and release of pseudonymized information processed by different personal information controllers)
(1) Any personal information controller intending to request an Expert Data Combination Agency to combine pseudonymized information (hereinafter referred to as "Applicant") shall submit the data combination request in the form determined and publicly notified by the Protection Commission, together with the following documents, to the relevant Expert Data Combination Agency:
1. Documents related to the Applicant such as business registration certificate, certified copy of register of corporation, etc.;
2. Documents related to the pseudonymized information for combination;
3. Documents proving the purpose of combination;
4. Other documents determined and publicly notified by the Protection Commission’s notification as necessary for combining and releasing pseudonymized information.
(2) Any Expert Data Combination Agency intending to combine pseudonymized information under Article 28-3 (1) of the Act shall make sure that the combined information does not identify a particular individual. In such cases, the Protection Commission may make the Korea Internet and Security Agency or other agencies designated and publicly notified by the Protection Commission assist with relevant work necessary to make a particular individual unidentifiable.
(3) The Applicant that intends to take the information which was combined by the Expert Data Combination Agency pursuant to Article 28-3 (2) of the Act out of the Expert Data Combination Agency shall pseudonymize or otherwise process the information combined pursuant to paragraph (2) as the information under Article 58-2 of the Act at a place which was established within the Expert Data Combination Agency and underwent the necessary technical, managerial and physical measures required to ensure safety and receive permission therefor from the Expert Data Combination Agency.
(4) The Expert Data Combination Agency shall permit the release pursuant to Article 28-3 (2), if each of the following standards are met. In such cases, the Expert Data Combination Agency shall form a Release Review Committee to grant permission for release of combined information:
1. There is a relationship between the purpose of combination and the released information;
2. It is not possible to identify any particular individual using such information;
3. A security plan is established with regard to the released information.
(5) The Expert Data Combination Agency may charge the Applicant for the costs necessary for the combination, release, etc. of information.
(6) Except as provided in paragraphs (1) through (5), the procedures and methods of combining pseudonymized information, release of combined information and permission therefor, shall be determined and publicly notified by the Protection Commission.
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 29-4 (Management, and supervision of expert data combination agency)
(1) Any head of the Protection Commission or related central administrative agency who has designated an Expert Data Combination Agency shall manage and supervise, among others, whether the Expert Data Combination Agency has maintained the work performance capacity, technologies and facilities required.
(2) An Expert Data Combination Agency shall submit the following documents to the Protection Commission or the head of the relevant central administrative agency for the management and supervision under paragraph (1), as determined and publicly notified by the Protection Commission: <Amended on Feb. 25, 2025>
1. Report on the combination and release of pseudonymized information;
2. Documents supporting that the agency continues to meet the standards for designation as an Expert Data Combination Agency;
3. Documents determined and publicly notified by the Protection Commission supporting that the agency has taken measures to secure the safety of pseudonymized information.
(3) The Protection Commission shall manage/supervise the following matters:
1. The Expert Data Combination Agency’s violation of law in the process of approving the combination and release of pseudonymized information;
2. The Applicant’s processing status with respect to pseudonymized information;
3. Other necessary matters required for the safe processing of pseudonymized information determined and publicly notified by the Protection Commission.
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 29-5 (Measures to ensure safety of pseudonymized information)
(1) A personal information controller shall implement the following safety measures for pseudonymized information and additional information to restore pseudonymized information to the original state (hereinafter in this Article referred to as "additional information") in accordance with Article 28-4 (1) of the Act: <Amended on Feb. 2, 2021; Sep. 12, 2023>
1. Measures to ensure safety under Article 30;
2. Separate storage of pseudonymized information and additional information; provided, any unnecessary additional information shall be destroyed;
3. Separation of access rights to pseudonymized information and additional information; provided, if the personal information controller finds it difficult to separate access rights due to good reason such as the personal information controller being a micro enterprise defined in Article 2 of the Framework Act on Micro Enterprises which cannot afford an additional employee to handle pseudonymized information, it shall manage and control access rights by granting the minimum degree of access necessary to do the work and recording the status of access rights granted.
(2) "Matters prescribed by Presidential Decree" in Article 28-4 (3) of the Act mean any of the following: <Amended on Sep. 12, 2023>
1. Purpose of processing pseudonymized information;
2. Items of pseudonymized personal information;
3. Use history of pseudonymized information;
4. Recipient of pseudonymized information provided by a third party;
5. Processing period of pseudonymized information (limited to where the processing period of pseudonymized information is separately determined pursuant to Article 28-4 (2) of the Act);
6. Other matters determined and publicly notified by the Protection Commission as deemed necessary for the management of the processing of pseudonymized information.
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 29-6 Deleted. <Sep. 12, 2023>
CHAPTER IV-3 Cross-Border Transfer of Personal Information
법령 이단보기
Article 29-7 (Means of notifying data subjects in cases of cross-border entrusted processing or storage of personal information)
"Means prescribed by Presidential Decree, such as electronic mail" in Article 28-8 (1) 3 (b) of the Act means in writing, etc.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 29-8 (Certification of cross-border transfer of personal information)
(1) Where the Protection Commission intends to publicly notify certification under the provisions, with the exception of the items, of Article 28-8 (1) 4 of the Act, it shall complete all of the following procedures:
1. Evaluation by an institution specializing in certifying personal information protection under Article 34-6;
2. Evaluation by an expert committee for cross-border transfer of personal information under Article 5 (1) 1 (hereinafter referred to as "expert committee for cross-border transfer");
3. Consultation with the Policy Council.
(2) When the Protection Commission publicly notifies certification under the provisions, with the exception of the items, of Article 28-8 (1) 4 of the Act, it may determine and publicly notify its effective period of up to five years.
(3) Except as provided in paragraphs (1) and (2), matters necessary for the procedures, etc. for publicly notifying certification shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 29-9 (Recognition of countries' personal information protection levels)
(1) If the Protection Commission intends to recognize that a country or an international organization (hereinafter referred to as "recipient country, etc.") where personal information is provided (including inquired), processed under entrustment, or stored (hereafter in this Chapter referred to as "transfer") under Article 28-8 (1) 5 of the Act has a personal information protection system, the scope of guarantee of the rights of data subjects, the procedures for damage relief, etc. at a level substantially equal to the level of personal information protection under this Act, it shall comprehensively take into account the following matters:
1. Whether the personal information protection system of the recipient country, etc., including its statutes, regulations, and rules, is in conformity with the principles of information protection under Article 3 of the Act and guarantees the rights of data subjects under Article 4 of the Act;
2. Whether the recipient country, etc. has an independent supervisory authority responsible for guaranteeing and implementing the personal information protection system;
3. Whether the public institutions (including institutions that conduct business affairs similar to those of public institutions) of the recipient country, etc. process personal information under statutes and whether means to protect data subjects, such as the procedures for damage relief, exist and are effectively guaranteed;
4. Whether the recipient country, etc. has the procedures for damage relief that are easily available to data subjects and whether such procedures effectively protect data subjects;
5. Whether the supervisory authority of the recipient country, etc. is able to facilitate mutual cooperation with the Protection Commission in protecting the rights of data subjects;
6. Other matters determined and publicly notified by the Protection Commission as necessary to recognize the personal information protection level of the recipient country, etc., such as the personal information protection system, the scope of guarantee of the rights of data subjects, the procedures for damage relief.
(2) If the Protection Commission intends to grant recognition under paragraph (1), it shall follow the following procedures:
1. Evaluation by an expert committee for cross-border transfer;
2. Consultation with the Policy Council.
(3) If necessary for the protection of the rights of data subjects, etc., the Protection Commission may, when granting recognition under paragraph (1), determine the scope of the personal information to be transferred to a recipient country, etc., the scope of the personal information controllers to which personal information is transferred, the recognition period, the conditions of cross-border transfer, and other relevant matters differently for each recipient country, etc.
(4) Upon granting recognition under paragraph (1), the Protection Commission shall examine whether a recipient country, etc. maintains its personal information protection level that is substantially equal to the level under this Act.
(5) Where any change is made to the personal information system, the scope of guarantee of the rights of data subjects, the procedures for damage relief, etc. of a recipient country, etc. that are recognized under paragraph (1), the Protection Commission may revoke the recognition of the recipient country, etc. or change the details of the recognition, after hearing its opinions.
(6) Where the Protection Commission grants recognition under paragraph (1) or revokes such recognition or changes the details thereof under paragraph (5), it shall give public notice of such fact in the Official Gazette and publish it on its website.
(7) Except as provided in paragraphs (1) through (6), matters necessary for the recognition of a recipient country, etc. shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 29-10 (Protective measures in cases of cross-border transfers of personal information)
(1) Where a personal information controller makes a cross-border transfer of personal information under the proviso, with the exception of the subparagraphs, of Article 28-8 (1) of the Act, he or she shall take the following protective measures under Article 28-8 (4) of the Act:
1. Measures to ensure safety for protecting personal information under Article 30 (1);
2. Measures to handle grievances and resolve disputes with respect to personal information breach;
3. Other measures necessary to protect the personal information of data subjects.
(2) Where a personal information controller makes a cross-border transfer of personal information under the proviso, with the exception of the subparagraphs, of Article 28-8 (1) of the Act, it shall have a prior consultation with the recipient of the personal information on the matters specified in the subparagraphs of paragraph (1) and shall reflect the results of such consultation in the details of a contract, etc.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 29-11 (Standards for orders to suspend cross-border transfers)
(1) Where the Protection Commission orders the suspension of cross-border transfers of personal information under Article 28-9 (1) of the Act, it shall comprehensively consider the following matters:
1. The type and scale of personal information, the cross-border transfer of which has been made or any further cross-border transfer of which is expected;
2. The severity of a violation of Article 28-8 (1), (4), or (5) of the Act;
3. Whether any damage that occurs or is likely to occur to data subjects is material or irrecoverable;
4. Whether ordering the suspension of cross-border transfers obviously brings more benefits to data subjects than not doing so;
5. Whether it is possible to protect personal information and to prevent personal information breach with the measures taken under the subparagraphs of Article 64 (1) of the Act;
6. Whether the recipient of personal information or the recipient country, etc. to which personal information is transferred has effective means of relieving damage suffered by data subjects;
7. Whether there is any reason to deem that it is difficult to adequately protect personal information, such as that the recipient of personal information or the recipient country, etc. to which personal information is transferred suffers a serious personal information breach.
(2) If the Protection Commission orders the suspension of cross-border transfers of personal information under Article 28-9 (1) of the Act, it shall undergo the evaluation by the expert committee for cross-border transfer.
(3) When the Protection Commission orders the suspension of cross-border transfers of personal information pursuant to Article 28-9 (1) of the Act, it shall notify in writing the relevant personal information controller of the details of and the grounds for such order, the procedures and methods for filing objections, and other necessary matters.
(4) Except as provided in paragraphs (1) through (3), matters necessary for the standards, etc. for orders to suspend cross-border transfers of personal information shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 29-12 (Filing objections to orders to suspend cross-border transfers)
(1) A person who intends to file an objection pursuant to Article 28-9 (2) of the Act shall submit to the Protection Commission a written objection determined by the Protection Commission along with a document substantiating the grounds for the objection, within seven days from the date of receipt of an order to suspend cross-border transfer under Article 28-9 (1) of the Act.
(2) The Protection Commission shall notify in writing the relevant personal information controller of the results of processing a written objection submitted under paragraph (1) within 30 days from the date of receipt of the written objection.
(3) Except as provided in paragraphs (1) and (2), matters necessary for the procedures, etc. for filing an objection shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
CHAPTER V SAFEGUARD OF PERSONAL INFORMATION
법령 이단보기
Article 30 (Measures to ensure safety of personal information)
(1) Each personal information controller shall take the following measures to ensure safety pursuant to Article 29 of the Act: <Amended on Sep. 12, 2023>
1. Formulating, implementing, and examining an internal management plan that includes the following to safely process personal information:
(a) Matters regarding the management, supervision, and education of a personal information handler under Article 28 (1) of the Act (hereinafter referred to as "personal information handler");
(b) Matters regarding the composition and operation of an organization responsible for protecting personal information, including the designation of privacy officers, under Article 31 of the Act;
(c) Details necessary to implement the measures provided in subparagraphs 2 through 8;
2. The following measures to restrict access authority to personal information:
(a) Establishing and implementing the standards for granting, changing, or canceling access authority to a system systematically designed to process personal information including a database system (hereinafter referred to as "personal information processing system");
(b) Establishing and operating the standards for applying authentication means necessary to verify whether access is made by a person with legitimate authority;
(c) Other measures necessary to restrict access authority to personal information;
3. The following measures to control access to personal information:
(a) Measures necessary to detect and block intrusions into a personal information processing system;
(b) Blocking Internet access to and from computers satisfying the standards determined and publicly notified by the Protection Commission, such as the computers of personal information handlers accessing a personal information processing system; provided, this shall apply only to a personal information controller with an average of at least one million daily users defined in Article 2 (1) 4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection whose personal information is stored and managed for the immediately preceding three months as of the end of the previous year;
(c) Other measures necessary to control access to personal information;
4. The following measures necessary to safely store and transmit personal information:
(a) Storing encrypted authentication information, including the storage of one-way encrypted passwords, or other measures equivalent thereto;
(b) Encrypting information determined and publicly notified by the Protection Commission for storage, including resident registration numbers, or other measures equivalent thereto;
(c) Where the personal information or authentication information of data subjects is transmitted or received through the information and communications network defined in Article 2 (1) 1 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, encrypting the relevant information or other measures equivalent thereto;
(d) Other measures to ensure security using encryption or other technologies equivalent thereto;
5. The following measures to retain the records of access and prevent such records from being forged or altered in case of a personal information breach incident:
(a) Storing, inspecting, confirming, and supervising the records of access, such as the date and time when persons access a personal information processing system, and the details of processing personal information;
(b) Safely storing the records of access to a personal information processing system;
(c) Other measures necessary to retain the records of access and prevent such records from being forged or altered;
6. Installing, operating, and periodically updating and inspecting programs that can detect at all times whether any malicious program, such as a computer virus, spyware, and ransomware, intrudes into a personal information processing system and an information technology equipment used by personal information handlers for processing personal information and that can delete such malicious program;
7. Preparing storage facilities and installing locking devices to safely store personal information, or taking other physical measures;
8. Other measures necessary to ensure safety of personal information.
(2) The Protection Commission may provide necessary assistance, such as building a system with which personal information controllers can take the measures to ensure safety pursuant to paragraph (1). <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4. 2020>
(3) Detailed standards for the measures to ensure safety under paragraph (1) shall be determined and publicly notified by the Protection Commission. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
법령 이단보기
Article 30-2 (Measures to ensure safety of personal information taken by institutions operating public systems)
(1) Pursuant to Article 29 of the Act, a public institution that operates a personal information processing system that meets the standards publicly notified by the Protection Commission (hereinafter referred to as "public system operating institution"), such as the scale of personal information processing and the number of persons handling personal information with access authority, shall additionally take the following measures in addition to measures to ensure safety under Article 30 of this Decree: <Amended on Mar. 12, 2024>
1. Including measures to ensure safety prepared for each public system in an internal management plan under Article 30 (1) 1;
2. Measures necessary to safely manage access authority, such as allowing an institution that accesses a public system to process personal information (hereafter in this Article referred to as "institution using public systems") to grant access authority to a personal information handler with legitimate authority and to change and cancel such authority;
3. Measures such as storage, analysis, inspection, and management of the records of access to public systems to prevent illegal access to personal information and personal information breach incidents.
(2) Where an institution operating public systems or an institution using public systems finds out access to personal information without authority or beyond authorized access thereto, it shall without delay notify data subjects of the relevant fact and matters necessary for the prevention of any damage, etc.; in such cases, notification shall be deemed given in any of the following cases:
1. Where data subjects are notified of loss, theft, or divulgence of personal information under Article 34 (1) of the Act;
2. Where data subjects are notified of access to their personal information and matters necessary for the prevention of any damage, etc. pursuant to other statutes or regulations.
(3) An institution operating public systems (where there is a separate public institution that develops and distributes a public system, such public institution shall be included; hereafter in this Article, the same shall apply) shall designate and operate a department dedicated to work related to the safe management of personal information or shall assign personnel dedicated to such work, taking into account the size and characteristics of the relevant public system, the number of institutions using the relevant public system, and other relevant factors.
(4) An institution operating public systems shall designate the head of a department responsible for the general management of the relevant public system as a manager for each public system; provided, where there is no such department, it shall designate a manager from among the heads of relevant departments in consideration of work-relatedness, work capabilities, and other relevant factors.
(5) An institution operating public systems shall establish and operate a public system operation council comprised of the following institutions for each public system to consult on matters related to examining the implementation of measures to ensure the safety of public systems and improving such systems; provided, where one public institution operates at least two public systems, an integrated public system operation council may be established and operated:
1. The institution operating public systems;
2. Where the operation of public systems is entrusted, the person entrusted;
3. An institution using public systems deemed necessary by the institution operating public systems.
(6) The Protection Commission may provide institutions operating public systems with support necessary to implement measures to ensure the safety of personal information.
(7) Except as provided in paragraphs (1) through (6), matters necessary for the measures to ensure the safety of personal information taken by institutions operating public systems, etc. shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 31 (Details of privacy policy and methods for disclosure thereof)
(1) "Matters prescribed by Presidential Decree" in Article 30 (1) 8 of the Act means the following: <Amended on Sep. 29, 2016; Aug. 4, 2020; Sep. 12, 2023; Mar. 12, 2024>
1. Particulars of personal information to be processed;
2. Where personal information is transferred to a foreign country pursuant to each subparagraph of Article 28-8 (1) of the Act, the grounds for transferring personal information to a foreign country and the matters referred to in each subparagraph of paragraph (2) of the same Article;
3. Matters regarding measures to ensure the safety of personal information under Article 30;
4. Where the personal information of a domestic data subject is directly collected and processed from a foreign country, the name of the country in which the personal information is processed.
(2) A personal information controller shall post continuously the Privacy Policy established or modified pursuant to Article 30 (2) of the Act on its website.
(3) Where it is impossible to post the Privacy Policy on the website as prescribed in paragraph (2), the personal information controller shall make public the established or modified Privacy Policy in at least one of the following manners: <Amended on Sep. 12, 2023>
1. Posting at easily noticeable location of the personal information controller’s workplace, etc.;
2. Publishing in the Official Gazette (only in cases the personal information controller is a public institution) or general daily newspaper, weekly newspaper, or online newspaper, as defined in subparagraphs 1 (a) and (c) and 2 of Article 2 of the Act on the Promotion of Newspapers circulating mainly over the City/Do where the personal information controller’s workplace, etc. is located;
3. Publishing at a periodical, newsletter, PR magazine, or invoice to be published under the same title at least twice a year and distributed to data subjects on a continual basis;
4. Stipulating in an agreement, etc. for the supply of goods or services executed between the personal information controller and the data subjects and providing a copy of the same to the data subject.
법령 이단보기
Article 31-2 (Those subject to, and procedures for, evaluation of privacy policy)
(1) Where the Protection Commission evaluates the Privacy Policy pursuant to Article 30-2 (1) of the Act, it shall select persons subject to evaluation by comprehensively considering the following matters: <Amended on Mar. 12, 2024>
1. Type of personal information controller and scale of sales (referring to income generated from profit-making business under Article 4 (3) 1 of the Corporate Tax Act, if sales are not calculated; hereafter referred to as "sales, etc." in Articles 32 and 48-7);
2. The type and scale of personal information processed, such as sensitive information and personally identifiable information;
3. The legal grounds and methods for personal information processing;
4. Whether any statute is violated;
5. The characteristics of data subjects, such as children and youth.
(2) Upon selecting those subject to the evaluation of the Privacy Policy pursuant to paragraph (1), the Protection Commission shall notify the relevant personal information controller of an evaluation plan including the details, time schedule, procedures, etc. of the evaluation no later than 10 days before the commencement of the evaluation.
(3) Where necessary to evaluate the Privacy Policy under Article 30-2 of the Act, the Protection Commission may request the relevant personal information controller to present its opinion.
(4) The Protection Commission shall evaluate the Privacy Policy pursuant to Article 30-2 of the Act and notify the relevant personal information controller of the results of such evaluation without delay.
(5) Except as provided in paragraphs (1) through (4), the detailed standards and procedures for selecting those subject to the evaluation of the Privacy Policy shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 32 (Work of privacy officer and requirements for designation)
(1) "Personal information controller whose number of employees, turnover, etc. meet the criteria prescribed by Presidential Decree" in terms of the number of employees, sales, etc. in the proviso of Article 31 (1) of the Act means a personal information controller who is a micro enterprise defined in Article 2 (1) of the Framework Act on Micro Enterprises. <Added on Mar. 12, 2024>
(2) "Work prescribed by Presidential Decree" in Article 31 (3) 7 of the Act shall be as follows: <Amended on Mar. 12, 2024>
1. To establish, modify, and implement the Privacy Policy pursuant to Article 30 of the Act;
2. Management of human and physical resources and information related to personal information processing;
3. To destroy personal information whose purpose of processing is attained or retention period expires.
(3) Where a personal information controller intends to designate a person in charge of personal information protection pursuant to Article 31 (1) of the Act, he or she shall designate the person according to the following classifications: <Amended on Jul. 22, 2016; Mar. 12, 2024>
1. Public institutions: Public officials, etc. who satisfy the below standards:
(a) The administrative bodies of the National Assembly, the Court, the Constitutional Court, and the National Election Commission; and central administrative agencies: A member of the Senior Executive Service (hereinafter referred to as "senior executive") or equivalent public official;
(b) Other national agencies than item (a), headed by a public official in political service: A public official of Grade III or higher (including a senior executive) or equivalent thereto;
(c) Other national agencies than items (a) and (b), headed by a senior executive, a Grade III or higher public official, or an equivalent public official: A public official of Grade IV or higher or equivalent thereto;
(d) Other national agencies than items (a) through (c) (including their affiliated bodies): The head of a department in charge of the work related to personal information processing in the relevant agency;
(e) City/Do, City/Do Offices of Education: A public official of Grade III or higher or equivalent thereto;
(f) Si/Gun/autonomous Gu: A public official of Grade IV or higher or a public official equivalent thereto;
(g) Schools of various levels under subparagraph 5 of Article 2: A person who exercises overall control over the administrative affairs of the relevant school; provided, in cases falling under paragraph (4) 2, it means teachers and staff;
(h) Other public institutions than items (a) through (g): The head of a department in charge of the work related to personal information processing in the relevant institution; provided,, where the heads of at least two departments are in charge of the work related to personal information processing, the head of the relevant institution shall designate the privacy officer from among them;
2. An institution other than public institutions: Any of the following persons:
(a) The business owner or representative;
(b) An executive officer (or the head of a department in charge of the work related to personal information processing, if no executive officer exists).
(4) Any of the following personal information controllers (limited to cases falling under subparagraphs 2 through 5 of Article 2 in cases of public institutions) shall designate a person who meets the requirements prescribed in Appendix 1, from among persons classified in the subparagraphs of paragraph (3), as a person in charge of protecting personal information: <Amended on Mar. 12, 2024>
1. Any of the following persons (excluding schools of various levels defined in subparagraph 5 of Article 2 and medical institutions defined in Article 3 of the Medical Service Act) whose annual sales, etc. are at least 150 billion won:
(a) A person who processes sensitive information or personally identifiable information concerning at least 50,000 data subjects;
(b) A person who processes personal information of at least one million data subjects;
2. The School under Article 2 of the Higher Education Act, the number of enrolled students (including the number of enrolled students at a graduate school) of which is at least 20,000 as of Dec. 31 of the immediately preceding year;
3. High-tier general care hospitals under Article 3-4 of the Medical Service Act;
4. Institutions operating public systems.
(5) The Protection Commission may provide support, such as the establishment and operation of educational courses for persons in charge of personal information protection so that the person in charge of personal information protection can smoothly perform the duties prescribed in Article 31 (3) of the Act. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Mar. 12, 2024>
(6) A personal information controller (excluding where a business owner or representative becomes a person in charge of protection of personal information pursuant to Article 31 (2) of the Act) shall comply with the following to ensure the independence of the person in charge of personal information protection under Article 31 (6) of the Act: <Added on Mar. 12, 2024>
1. Protecting personal information protection officer's access to information related to personal information processing;
2. Establishment of a system in which a person in charge of personal information protection may regularly report the establishment and implementation of a personal information protection plan and the results thereof to the representative or the board of directors on a regular basis;
3. Preparation of an organizational system suitable for persons in charge of personal information protection to perform their duties and provision of human and material resources.
법령 이단보기
Article 32-2 (Scope of business of council of privacy officers)
(1) "Joint projects prescribed by Presidential Decree" in Article 31 (7) of the Act means the following projects:
1. Support for survey, research, and establishment of policies for strengthening personal information protection of personal information controllers;
2. Analysis of personal information infringement incidents and research on measures therefor;
3. Research to ascertain actual conditions of designation and operation of personal information protection officers and current status of performance of duties and to improve systems therefor;
4. Enhancement of personal information protection capabilities and expertise of persons in charge of personal information protection including education for personal information protection officers;
5. Research, analysis, and sharing of major domestic and international trends related to duties of persons in charge of personal information protection;
6. Other projects necessary for safe management of personal information processing system, etc.
(2) The Protection Commission may provide administrative and technical support necessary for the operation and projects of the council of privacy officers within budgetary limits pursuant to Article 31 (8) of the Act.
[This Article Added on Mar. 12, 2024]
[Previous Article 32-2 moved to Article 32-3 <Mar. 12, 2024>]
법령 이단보기
Article 32-3 (Scope of persons subject to designation of domestic agents)
(1) "Who is prescribed by Presidential Decree" in the former part, with the exception of the subparagraphs, of Article 31-2 (1) of the Act means any of the following persons:
1. A person whose total sales for the previous year (referring to the previous business year in the case of a corporation) is at least one trillion won;
2. A person who has an average of at least one million domestic data subjects whose personal information is stored and managed for the immediately preceding three months as of the end of the previous year;
3. A person who is requested to submit relevant materials, such as articles and documents, pursuant to Article 63 (1) of the Act and for whom the Protection Commission deliberates and resolves on the need to designate a domestic agent.
(2) The total sales under paragraph (1) 1 shall be based on the amount converted into Korean won by applying the average exchange rate for the previous year.
[This Article Added on Sep. 12, 2023]
[Moved from Article 32-2 <Mar. 12, 2024>]
법령 이단보기
Article 33 (Registered matters of personal information files)
(1) "Matters prescribed by Presidential Decree" in Article 32 (1) 7 of the Act means the following: <Amended on Sep. 12, 2023>
1. The name of the public institution that operates personal information files;
2. The number of data subjects whose personal information is retained in personal information files;
3. The department in charge of the work related to personal information processing in the relevant public institution;
4. The department that receives and processes requests for access to personal information pursuant to Article 41;
5. The scope of personal information to which access can be limited or denied pursuant to Article 35 (4) of the Act, among personal information in personal information files, and the grounds for limitation or denial.
(2) "Personal information files prescribed by Presidential Decree" in Article 32 (2) 4 of the Act means any of the following information files: <Added on Sep. 12, 2023>
1. Personal information files that are operated to perform simple work, such as paying allowances for attending meetings, sending data and goods, and settling money, and that have little need for continuous management;
2. Personal information files that are urgently necessary for the public safety and security, public health, etc., and that are processed temporarily;
3. Other personal information files that are collected to handle one-off work and that are not stored or recorded.
[Title Amended on Sep. 12, 2023]
법령 이단보기
Article 34 (Registration and disclosure of personal information files)
(1) The head of a public institution that operates personal information files (excluding the personal information files under Article 32 (2) of the Act and Article 33 (2) of this Decree; hereafter in this Article, the same shall apply) shall file for registration of the matters provided in Article 32 (1) of the Act and Article 33 (1) of this Decree (hereinafter referred to as "registered matters") with the Protection Commission within 60 days from the date it starts operating the personal information files, as determined and publicly notified by the Protection Commission. The same shall also apply to any modification of registered matters. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
(2) The Protection Commission shall post the status of personal information files registered pursuant to Article 32 (4) of the Act on the website established by the Protection Commission. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
(3) The Protection Commission may build and operate a system so that the registration or modification of the registered matters, referred to in paragraph (1), of personal information files may be electronically processed. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
법령 이단보기
Article 34-2 (Criteria, method, and procedure for certification of personal information protection)
(1) The Protection Commission shall determine and publicly notify the criteria for certification referred to in Article 32-2 (1) of the Act, including the establishment of managerial, technical, and physical safeguards to protect personal information, taking into account the matters provided in the subparagraphs of Article 30 (1). <Amended on Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
(2) A person who intends to obtain certification of personal information protection pursuant to Article 32-2 (1) of the Act (hereafter in this Article and Article 34-3, referred to as "applicant"), shall submit an application (including an electronic application) for certification of personal information protection which includes the following matters to an institution specializing in the certification of personal information protection referred to in Article 34-6 (hereinafter referred to as "certification institution"): <Amended on Mar. 12, 2024>
1. A list of personal information processing systems subject to certification;
2. Methods and procedures for establishing and operating the personal information management system;
3. A list of documents related to the personal information management system and the implementation of safeguards.
(3) Upon receipt of an application for certification pursuant to paragraph (2), a certification institution shall consult with the applicant regarding the scope, time schedule, etc. of certification.
(4) An examination to certify personal information protection under Article 32-2 (1) of the Act shall be either a paper-based examination or an on-site examination conducted by the certification examiners for personal information protection subject to Article 34-8.
(5) Each certification institution shall establish and operate a certification committee comprised of members with extensive knowledge and experience in information protection to deliberate on the results of examinations for certification conducted pursuant to paragraph (4).
(6) Except as provided in paragraphs (1) through (5), detailed matters necessary for certification of personal information protection, including filing an application for certification, examination for certification, establishment and operation of the certification committee, and issuance of certificates, shall be determined and publicly notified by the Protection Commission. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 34-3 (Fees for certification of personal information protection)
(1) Each applicant shall pay a fee incurred in examining certification of personal information protection to the certification institution.
(2) The Protection Commission shall determine and publicly notify the detailed standards for calculating fees referred to in paragraph (1), based upon the number of certification examiners required for examining certification of personal information protection, number of days necessary to examine certification, and other relevant matters. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 34-4 (Revocation of certification)
(1) A certification institution that intends to revoke certification of personal information protection pursuant to Article 32-2 (3) of the Act shall submit the case for deliberation and resolution by the certification committee established under Article 34-2 (5).
(2) Upon revoking certification pursuant to Article 32-2 (3) of the Act, the Protection Commission or the certification institution shall notify the affected party of such revocation; and shall publicly announce or post the same in the Official Gazette or on the certification institution’s website. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 34-5 (Follow-up management of certification)
(1) An examination for follow-up management subject to Article 32-2 (4) of the Act shall be either a paper-based examination or an on-site examination.
(2) Where a certification institution discovers any of the causes provided for in Article 32-2 (3) of the Act through its follow-up management pursuant to paragraph (1), the certification institution shall submit the case for deliberation by the certification committee established under Article 34-2 (5) for deliberation; and shall notify the Protection Commission of the results of such deliberation. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 34-6 (Institutions specializing in certifying personal information protection)
(1) "Specialized institutions prescribed by Presidential Decree" in Article 32-2 (5) of the Act means the following: <Amended on Sep. 29, 2016; Jul. 26, 2017; Aug. 4, 2020>
1. The Korea Internet and Security Agency;
2. A corporation or an organization or institution designated and publicly notified by the Protection Commission among the corporations, organizations or institutions that satisfy all of the following requirements:
(a) To have at least five certification examiners for personal information protection referred to in Article 34-8;
(b) To have been qualified by the Protection Commission through an examination of requirements and capacity for performing its work.
(2) Detailed criteria, etc. necessary for designating a corporation, organization or institution referred to in paragraph (1) 2 and revocation of such designation shall be determined and publicly notified by the Protection Commission. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 34-7 (Certification mark and promotion)
Where a person who has obtained certification pursuant to Article 32-2 (6) of the Act intends to indicate or promote the certification, the person may use the personal information protection mark determined and publicly notified by the Protection Commission. In such cases, the person shall also indicate the scope and term of validity of the certification in the personal information protection mark. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 34-8 (Qualifications for certification examiners for personal information protection and grounds for disqualification)
(1) A certification institution shall qualify persons with expertise in personal information protection, who pass an examination after having completed a specialized educational program necessary for certification examinations, as certification examiners for personal information protection (hereinafter referred to as "certification examiners") pursuant to Article 32-2 (7) of the Act.
(2) A certification institution may disqualify a certification examiner pursuant to Article 32-2 (7) of the Act in any of the following cases; provided, the certification examiner must be disqualified in cases falling under subparagraph 1:
1. Where the certification examiner has been qualified by fraud or other unjust means;
2. Where the certification examiner has received money, goods, or other profits in relation to the examination for certification of personal information protection;
3. Where the certification examiner has divulged any information acquired in the course of examining the certification of personal information protection, or has used such information for other than the purpose for work without good cause.
(3) Detailed matters concerning completion of the specialized educational programs, qualification and disqualification as certification examiners, and other relevant matters under paragraphs (1) and (2) shall be determined and publicly notified by the Protection Commission. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
법령 이단보기
Article 35 (Object of privacy impact assessment)
"Personal information files meeting the criteria prescribed by Presidential Decree" in Article 33 (1) of the Act means any of the following personal information files that can be processed electronically: <Amended on Sep. 29, 2016>
1. Personal information files that will be established, operated, or modified, and contain sensitive information or personally identifiable information of at least 50 thousand data subjects for processing;
2. Personal information files that is established and operated, and will be matched with other personal information files being established and operated inside or outside the relevant public institution, and, as a result of matching, will contain the personal information of at least 500 thousand data subjects;
3. Personal information files that will be established, operated, or modified, and contain the personal information of at least one million data subjects;
4. Personal information files whose operating system, including the data retrieval system, will be changed after the privacy impact assessment under Article 33 (1) of the Act (hereinafter referred to as "privacy impact assessment"). In such cases, the privacy impact assessment shall be limited to the changed system.
법령 이단보기
Article 36 (Designation of assessment institutions and revocation of designation)
(1) The Protection Commission may designate a corporation that satisfies all of the following requirements as a privacy impact assessment institution (hereinafter referred to as "assessment institution") pursuant to Article 33 (2) of the Act: <Amended on Mar. 23, 2013; Nov. 19, 2014; Dec. 22, 2015; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
1. A corporation whose total revenue derived from any of the following work is 200 million won or more during the last five years:
(a) Privacy impact assessments or work similar thereto;
(b) Data protection consulting (which means the analysis and assessment of information systems and the provision of corresponding countermeasures against electronic infringement incidents; hereinafter the same shall apply) among the work related to establishing information systems, as defined in subparagraph 13 of Article 2 of the Electronic Government Act (including the information protection system);
(c) Data protection consulting among the work related to monitoring information systems, as defined in subparagraph 14 of Article 2 of the Electronic Government Act;
(d) Data protection consulting among the work related to the information security industry defined in Article 2 (1) 2 of the Act on the Promotion of the Information Security Industry;
(e) Work prescribed in Article 23 (1) 1 and 2 of the Act on the Promotion of the Information Security Industry;
2. A corporation that employs at least 10 full-time experts who meet the qualification requirements determined and publicly notified by the Protection Commission, including work experience in the field related to privacy impact assessment;
3. A corporation with the following offices and facilities:
(a) An office with facilities for identification and access control;
(b) Facilities for the safe management of records and materials.
(2) A person who intends to be designated as an assessment institution shall file an application for designation as an assessment institution, in the form determined and publicly notified by the Protection Commission, with the Protection Commission, along with the following documents (including electronic documents; hereinafter the same shall apply): <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
1. The articles of incorporation;
2. The representative’s name;
3. Documents verifying the qualifications of the experts referred to in paragraph (1) 2;
4. Other documents determined and publicly notified by the Protection Commission.
(3) Upon receipt of an application for designation as an assessment institution filed under paragraph (2), the Protection Commission shall verify the following documents through administrative data matching pursuant to Article 36 (1) of the Electronic Government Act; provided, where the applicant does not give consent to the verification of subparagraph 2, the Protection Commission shall require the applicant to submit the relevant document: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
1. The corporation registration certificate;
2. The certificate of alien registration issued under Article 88 (2) of the Immigration Act (applicable only to aliens).
(4) Upon designating an assessment institution pursuant to paragraph (1), the Protection Commission shall, without delay, issue a written designation to the relevant applicant, and make a public notice thereof in the Official Gazette. The same shall also apply to any modification of the matters publicly notified: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
1. The name, address, and telephone number of the assessment institution, and the name of its representative;
2. Terms and conditions attached to the designation, if any.
(5) "Cases that fall under any ground prescribed by Presidential Decree" in Article 33 (7) 5 of the Act means any of the following cases: <Amended on Sep. 12, 2023>
1. Where an assessment institution fails to comply with the obligation to submit a report under paragraph (6);
2. Where an assessment institution has no records of privacy impact assessment for two consecutive years from the date of obtaining designation without good cause;
3. Where an assessment institution divulges any information that it has obtained in the course of conducting privacy impact assessments, such as a privacy impact assessment report under the provisions, with the exception of the subparagraphs, of Article 38 (2);
4. Other cases where an assessment institution breaches the duties under the Act or this Decree.
(6) An assessment institution designated under paragraph (1) shall, upon occurrence of any of the following events after designation, submit a report to the Protection Commission, as determined and publicly notified by the Protection Commission, within 14 days from the date of occurrence; provided, it shall submit a report to the Protection Commission within 60 days from the date of occurrence in cases falling under subparagraph 3: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
1. Where any matter referred to in paragraph (1) is changed;
2. Where any matter referred to in paragraph (4) 1 is changed;
3. Where the transfer, acquisition, or merger of the assessment institution, or similar event occurs.
(7) Deleted. <Sep. 12, 2023>
[Moved from Article 37; previous Article 36 moved to Article 37 <Sep. 12, 2023>]
법령 이단보기
Article 37 (Consideration at the time of privacy impact assessment)
"Matters prescribed by Presidential Decree" in Article 33 (3) 4 of the Act means the following: <Amended on Sep. 12, 2023>
1. Whether sensitive information or personally identifiable information will be processed;
2. The retention period of personal information.
[Moved from Article 36; previous Article 37 moved to Article 36 <Sep. 12, 2023>]
법령 이단보기
Article 38 (Criteria for privacy impact assessment)
(1) The criteria for privacy impact assessments (hereinafter referred to as "assessment criteria") under Article 33 (9) of the Act shall be as follows: <Amended on Jul. 22, 2016; Sep. 12, 2023>
1. The type and nature of personal information contained in the relevant personal information files, the number of data subjects, and the possibility of subsequent personal information breach;
2. The level of measures to ensure safety taken under Articles 23 (2), 24 (3), 24-2 (2), 25 (6) (including cases applied mutatis mutandis in Article 25-2 (4)), and 29 of the Act, and the subsequent possibility of personal information breach;
3. Countermeasures against risk factors of personal information breach, if any;
4. Other necessary measures subject to the Act or this Decree, or any factor affecting breach of duties.
(2) An assessment institution requested to conduct a privacy impact assessment under Article 33 (2) of the Act shall, in accordance with the assessment criteria, analyze and assess the risk factors of personal information breaches that result from the operation of personal information files, and shall prepare a privacy impact assessment report based on the results of the evaluation that includes the following and send such report to the head of the relevant public institution, who shall submit the report to the Protection Commission before operating and changing personal information files falling under the subparagraphs of Article 35: <Amended on Sep. 12, 2023>
1. Those subject to the privacy impact assessment and the scope thereof;
2. Fields and items of the evaluation;
3. Analysis and assessment of the risk factors of personal information breaches in accordance with the assessment criteria;
4. The details of measures taken based on the results of the analysis and evaluation under subparagraph 3 and a plan for improvement;
5. The results of the privacy impact assessment;
6. A summary of the matters prescribed in subparagraphs 1 through 5.
(3) The Protection Commission or the head of a public institution may disclose the details of a summary of a privacy impact assessment report prescribed in paragraph (2) 6. <Added on Sep. 12, 2023>
(4) Except as provided in the Act and this Decree, the Protection Commission may determine and publicly notify the detailed standards for designating assessment institutions, procedures for privacy impact assessments, etc. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
법령 이단보기
Article 39 (Notification of divulgence of personal information)
(1) When a personal information controller becomes aware of loss, theft, or divulgence (hereafter in this Article and Article 40 referred to as "divulgence, etc.") of personal information, the personal information controller shall notify data subjects of the matters specified in the subparagraphs of Article 34 (1) of the Act in writing, etc. within 72 hours; provided, notification may be given to data subjects without delay after the relevant cause ceases to exist in any of the following cases:
1. Where urgent measures need to be taken to prevent widespread divulgence, etc. of personal information and any further divulgence, etc., such as blocking access routes, inspecting and addressing vulnerabilities, and recovering and deleting the relevant personal information;
2. Where it is impracticable to give notification within 72 hours due to a natural disaster or any other unavoidable cause.
(2) Notwithstanding paragraph (1), where a personal information controller intends to give notification under paragraph (1) but fails to confirm the specific details of the matters prescribed in Article 34 (1) 1 or 2 of the Act, the personal information controller shall first give notification of the divulgence, etc. of personal information, the details that have already been confirmed, and the matters specified in Article 34 (1) 3 through 5 of the Act in writing, etc., and shall notify the details further confirmed immediately upon confirmation. <Amended on Mar. 12, 2024>
(3) Notwithstanding paragraphs (1) and (2), where the contact information of a data subject is unknown or any other good cause exists, a personal information controller shall post the matters provided in the subparagraphs of Article 34 (1) of the Act on its website for at least 30 days to ensure that the data subject can easily recognize such matters, in lieu of giving notification under paragraphs (1) and (2), pursuant to the proviso, with the exception of the subparagraphs, of Article 34 (1) of the Act; provided, in the case of a personal information controller that does not operate its website, the matters specified in the subparagraphs of Article 34 (1) of the Act may be posted at a conspicuous place of the workplace, etc. for at least 30 days in lieu of giving notification under paragraphs (1) and (2).
[This Article Wholly Amended on Sep. 12, 2023]
[Moved from Article 40; previous Article 39 moved to Article 40 <Sep. 12, 2023>]
법령 이단보기
Article 40 (Reporting on divulgence of personal information)
(1) When a personal information controller becomes aware of divulgence, etc. of personal information in any of the following cases, the personal information controller shall, in writing, etc., file a report with the Protection Commission or a specialized institution prescribed in the former part of Article 34 (3) of the Act with regard to the matters provided in the subparagraphs of Article 34 (1) of the Act within 72 hours; provided, where it is impracticable to file a report within 72 hours due to a natural disaster or any other unavoidable cause, a report may be filed without delay after the relevant cause ceases to exist; and where the possibility of infringing on the rights and interests of data subjects is substantially reduced after the path of divulgence, etc. of personal information is confirmed and measures are taken such as the recovery and deletion of the relevant personal information, the personal information controller need not file a report thereon:
1. Where divulgence, etc. of personal information of at least 1,000 data subjects occurs;
2. Where divulgence, etc. of sensitive information or personally identifiable information occur;
3. Where divulgence, etc. of personal information occurs due to illegal external access to personal information processing systems or information technology equipment used by personal information handlers for processing personal information.
(2) Notwithstanding paragraph (1), where a personal information controller intends to file a report pursuant to paragraph (1) but fails to confirm the specific details of the matters provided in Article 34 (1) 1 or 2 of the Act, the personal information controller shall first file a report on divulgence, etc. of personal information, the details that have already been confirmed, and the matters specified in Article 34 (1) 3 through 5 of the Act in writing, etc., and shall notify the details further confirmed immediately upon confirmation.
(3) "Specialized institution designated by Presidential Decree" in the former and latter parts of Article 34 (3) of the Act means the Korea Internet and Security Agency.
[This Article Wholly Amended on Sep. 12, 2023]
[Moved from Article 39; previous Article 40 moved to Article 39 <Sep. 12, 2023>]
법령 이단보기
Article 40-2 (Institution requesting erasure and blocking of exposed personal information)
"Specialized institution designated by Presidential Decree" in Article 34-2 (2) of the Act means the Korea Internet and Security Agency.
[This Article Wholly Amended on Sep. 12, 2023]
CHAPTER VI GUARANTEE OF RIGHTS OF DATA SUBJECTS
법령 이단보기
Article 41 (Procedures for access to personal information)
(1) A data subject who intends to request access to his or her own personal information processed by a personal information controller pursuant to Article 35 (1) of the Act shall submit a request, stating the information that he or she intends to access among the following information, in the manner and following the procedure determined by the personal information controller; <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017>
1. Particulars and substance of personal information;
2. The purpose of collecting and using personal information;
3. The period for retaining and using personal information;
4. Status of personal information provided to a third party;
5. The fact that the data subject has given consent to the processing of his or her personal information and the content thereof.
(2) To determine the manner and procedure for requesting access under paragraph (1), a personal information controller shall comply with the following to ensure that such manner and procedure are not more difficult than the manner and procedure that the personal information controller uses to collect the relevant personal information: <Added on Oct. 17, 2017>
1. To provide the requested personal information in a data subject-friendly manner, such as in writing, by telephone or electronic mail, or via the Internet;
2. To allow data subjects to request access to their own personal information at least through the same window or in the same manner that the personal information controller uses to collect such personal information, unless good cause exists, such as difficulty in continuously operating such window;
3. To post on a website the manner and procedure for requesting access if the personal information controller operates the website.
(3) A data subject who intends to request access to his or her own personal information via the Protection Commission pursuant to Article 35 (2) of the Act shall submit to the Protection Commission a Personal Information Access Request specifying the information to access among the information referred to in paragraph (1), as determined and publicly notified by the Protection Commission. In such cases, the Protection Commission shall forward the Personal Information Access Request to the relevant public institution without delay. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
(4) "Period prescribed by Presidential Decree" in the former part of Article 35 (3) of the Act means 10 days. <Amended on Oct. 17, 2017>
(5) Where a personal information controller allows a data subject to access the relevant personal information within 10 days from the receipt of the Personal Information Access Request under paragraph (1) or (3), or limits access to the relevant person information under Article 42 (1), the personal information controller shall serve the data subject with the Access Notice, stating the accessible personal information, date and time, venue, etc. for access (in the case of partial access pursuant to Article 42 (1), the ground therefor and how to appeal shall be included), in the form determined and publicly notified by the Protection Commission; provided, where he or she allows immediate access, the Access Notice may be omitted. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
법령 이단보기
Article 42 (Limitation to, and postponement and denial of, access to personal information)
(1) Where any information to which a personal information controller receives a request for access pursuant to Article 41 (1) falls under Article 35 (4) of the Act, the personal information controller may limit access to such information; and shall allow the data subject to access other personal information than the restricted part.
(2) Where a personal information controller intends to postpone a data subject’s access to his or her own personal information pursuant to the latter part of Article 35 (3) of the Act, or to deny the access pursuant to Article 35 (4) of the Act, the personal information controller shall serve the data subject with the Access Postponement or Denial Notice, stating the grounds for postponement or denial and how to appeal, in the form determined and publicly notified by the Protection Commission within 10 days from the receipt of the access request. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
법령 이단보기
Article 42-2 (Standards for information transmitters)
“Personal information controller satisfying the criteria prescribed by Presidential Decree” in the provisions, with the exception of the subparagraphs, of Article 35-2 (1) and (2) of the Act means any of the following persons (hereinafter referred to as "information transmitter"), respectively:
1. Any of the following persons among agencies, corporations, and organizations related to health and medical services (hereinafter referred to as "transmitter of health and medical services information"):
a. The Korea Disease Control and Prevention Agency;
b. The National Health Insurance Service under Article 13 of the National Health Insurance Act and the Health Insurance Review and Assessment Service under Article 62 of that Act;
c. A tertiary care hospital under Article 3-4 of the Medical Service Act;
d. Other persons publicly notified by the Protection Commission in consultation with the Minister of Health and Welfare, taking into consideration the technical and financial capacity to transmit personal information, the number of data subjects whose personal information is stored and managed, etc. among public health and medical institutions defined in subparagraph 4 of Article 3 of the Framework Act on Health and Medical Services;
2. Any of the following persons (hereinafter referred to as "transmitter of communications information") among agencies, corporations, or organizations related to communications:
a. A person who provides mobile communications services after being assigned radio frequencies pursuant to Article 10 of the Radio Waves Act and who has entered into a contract for the use of mobile communications services with a data subject;
b. Other persons determined and publicly notified jointly by the Protection Commission and the Minister of Science and ICT, taking into consideration the technical and financial capability to transmit personal information, the number of data subjects whose personal information is stored and managed, etc. among persons who manage the facilities-based telecommunications business under Article 5 (2) of the Telecommunications Business Act;
3. Any of the following persons (hereinafter referred to as "transmitter of energy information") among energy-related agencies, corporations, and organizations:
a. An electric sales business entity defined in subparagraph 10 of Article 2 of the Electric Utility Act;
b. A person who falls under any of the following and is jointly determined and publicly notified by the Protection Commission and the Minister of Trade, Industry and Energy, taking into consideration the technical and financial capabilities to transmit personal information and the number of data subjects whose personal information is stored and managed, etc.:
1) Urban gas business entities defined in subparagraph 2 of Article 2 of the Urban Gas Business Act;
2) Other agencies, corporations, and organizations related to urban gas business under subparagraph 1-2 of Article 2 of the Urban Gas Business Act.
[This Article Added on Feb. 25, 2025]
[Enforcement Date: Jun. 1, 2026]
법령 이단보기
Article 42-3 (Standards for general recipients)
(1) “Person who ... meets the standards for facilities and technology prescribed by Presidential Decree” in Article 35-2 (2) 2 of the Act means a person who receives personal information transmitted for the purpose of verifying the authenticity or other aspects of information collected in the course of performing his or her inherent duties, using facilities and technology determined and publicly notified by the Protection Commission regarding the following matters:
1. A system related to transmission requests that conform to the standard transmission procedures and the standards for linkage with transmission systems and transmission security, etc.;
2. A system for recording and keeping transmission history and separate storage of personal information received; dld
3. A system for detecting and blocking of unlawful access to personal information and preventing intrusion incidents;
4. A system to manage and control access to personal information.
(2) If a person who has fulfilled his or her obligation to take safety measures under Article 29 of the Act and has facilities and technology under paragraph (1) (hereinafter referred to as "general recipient") intends to suspend or discontinue all or part of the business affairs of receiving transmitted personal information in compliance with a request for transmission under Article 35-2 (2) of the Act (hereinafter referred to as "third-party transmission request"), he or she shall notify a specialized relay agency under Article 42-9 (1) 1 (hereinafter referred to as "specialized relay agency") of such fact in advance and register it in the personal information transmission support platform under Article 35-4 (2) of the Act (hereinafter referred to as "personal information transmission support platform").
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-4 (Scope of information subject to request for transmission)
(1) Pursuant to Article 35-2 (1) or (2) of the Act, a data subject may request an information transmitter to transmit the following information to himself or herself, a specialized personal information management agency designated pursuant to Article 35-3 (1) of the Act (hereinafter referred to as "institution specializing in managing personal information"), or a general recipient according to the following classifications:
1. A transmitter of health and medical services information: Information (hereinafter referred to as "health and medical services information subject to transmission") held by the relevant transmitter of health and medical services information, among the following information related to health and medical services, which is publicly notified by the Protection Commission after consultation with the Minister of Health and Welfare, in consideration of the interests of the data subject, the time and cost necessary for transmission, the technically reasonable scope of transmission, etc.:
a. Information generated in relation to medical treatment, such as medical records under Articles 22 and 23 of the Medical Service Act;
b. Information generated in relation to dispensing, such as records of dispensing under Article 30 of the Pharmaceutical Affairs Act;
c. Information generated or collected through medical devices under Article 2 (1) of the Medical Devices Act;
d. Other information related to health and medical services similar to those referred to in items (a) through (c);
2. A transmitter of communications information: Information held by the relevant transmitter of communications information, which is jointly determined and publicly notified by the Protection Commission and the Minister of Science and ICT (hereinafter referred to as “communications transmission information subject to transmission”), taking into account the interests of the data subject, the time and cost necessary for transmission, and the technically reasonable scope of transmission, among information generated by providing facilities-based telecommunications services defined in subparagraph 11 of Article 2 of the Telecommunications Business Act, such as information on subscription, information on use, information on claims for use charges, information on payment of use charges, information on payment, etc.;
3. A transmitter of energy information: Information held by the relevant transmitter of energy information, as jointly determined and publicly notified by the Protection Commission and the Minister of Trade, Industry and Energy (hereinafter referred to as "energy information subject to transmission"), in consideration of the interests of the data subject, the time and expenses necessary for the transmission, and the technically reasonable scope of transmission, among the following energy-related information:
a. Information, such as information on energy consumption generated by the supply of electricity under Article 14 of the Electricity Business Act, information on billing and payment of electricity charges, etc.;
b. Information, such as information on energy consumption generated by the supply of urban gas under Article 19 of the Urban Gas Business Act, information on billing and payment of urban gas charges, etc.;
c. Other energy-related information similar to those referred to in items a and b.
(2) In addition to the information referred to in paragraph (1), a data subject may request that the information transmitter transmit to him or her any information which the information transmitter has voluntarily determined it can transmit to the data subject in consideration of time, cost, technology, and other factors (hereinafter referred to as "information subject to voluntary transmission"), from among the information it holds under Article 35-2 (1) of the Act.
(3) Notwithstanding paragraph (1), where a data subject requests that an information transmitter transmit health and medical services information subject to transmission, communications information subject to transmission, or energy information subject to transmission to an institution specializing in managing personal information or a general recipient pursuant to Article 35-2 (2) of the Act, he or she may not request the transmission of information determined and publicly notified by the Protection Commission, depending on the recipient of information.
(4) If the information referred to in the subparagraphs of paragraph (1) corresponds to information on the data subject himself or herself, which is retained by an administrative agency, etc. under Article 43-2 (1) of the Electronic Government Act, the Protection Commission (including the heads of the relevant central administrative agencies jointly determined and publicly notified by the Protection Commission pursuant to paragraph (1) 2 and 3) shall have a prior consultation with the Minister of the Interior and Safety about the information subject to a request for transmission and the method of transmission before making a public notice under paragraph (1).
[This Article Added on Feb. 25, 2025]
[Enforcement Date: Jun. 1, 2026]
법령 이단보기
Article 42-5 (Methods of requesting transmission)
(1) If a data subject makes a request for transmission under Article 35-2 (1) of the Act (hereinafter referred to as "data subject access request"), the data subject shall specify the purpose of the request for transmission and the personal information requested for transmission.
(2) If a data subject makes a third-party transmission request, he or she shall specify the following matters:
1. Purpose of the request for transmission;
2. The person to whom the request for transmission is made;
3. The person to whom personal information is transmitted;
4. Personal information requested to be transmitted;
5. Whether regular transmission is required and, if so, the frequency thereof [limited to cases where a request for transmission to a third-party is made to the information transmitter to transmit data to a general specialized agency under Article 42-9 (1) 2 (hereinafter referred to as “general specialized agency”) and a special specialized agency under subparagraph 3 of that paragraph (hereinafter referred to as “special specialized agency”);
6. The time when the request for transmission expires;
7. Period for retaining and using personal information requested for transmission.
(3) A data subject may submit a third-party transmission request to an information transmitter through either an agency specializing in personal information or a general recipient. In such cases, the institution specializing in managing personal information or a general recipient shall notify the data subject in advance, ensuring that the data subject clearly understands the details of the matters referred to in the subparagraphs of paragraph (2) before making the request.
(4) When a data subject requests a third-party transmission with regard to a general specialized agency or a special specialized agency, the data subject may request the information transmitter to transmit personal information of the same details on a regular basis.
(5) A data subject may change or withdraw a request for transmission under paragraphs (1) through (4). In such cases, an information transmitter, an institution specializing in managing personal information, and a general recipient shall ensure that the methods and procedures for changing and withdrawing the request for transmission are not more difficult than the methods and procedures as at the time of the request for transmission.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-6 (Deadline and methods of transmission of personal information)
(1) An information transmitter in receipt of a request for transmission pursuant to Article 35-2 (1) and (2) of the Act shall transmit personal information without delay unless there is a reason for delay or inability to transmit due to an information system failure or other issues. In such cases, if there is a legitimate reason why transmission cannot be done without delay, the information transmitter may postpone transmission after notifying the data subject of the reason and, if the reason ceases to exist, the personal information shall be transmitted without delay.
(2) When an information transmitter transmits personal information, he or she shall maintain the accuracy, completeness, and up-to-datedness of personal information.
(3) An information transmitter shall transmit personal information by the following means (in cases of a data subject access request, limited to subparagraph 1) so as to ensure the safety and reliability of transmission:
1. A method of encrypting and transmitting information using a safe encryption algorithm when transmitting information;
2. The method determined by prior consultation between the information transmitter and the institution specializing in managing personal information or the general recipient;
3. A method for mutual identification and authentication between the information transmitter and the institution specializing in managing personal information or the general recipient;
4. A method of mutual verification between the information transmitter and the agency specializing in personal information management or the general recipient.
(4) If an information transmitter transmits personal information at a third-party transmission request, he or she shall transmit such information through a specialized relay agency. In such cases, the information transmitter shall transmit health and medical services information subject to transmission only to a special specialized agency through a specialized relay agency.
(5) An information transmitter shall post the method of requesting the transmission of personal information, the current status of transmission, and the method of verifying the details of transmission on its website, etc. so that information subjects can request the transmission of personal information and verify the details of transmission, etc. pursuant to Article 35-2 (1) of the Act; provided, in cases of the transmitter of health and medical services information and the transmitter of energy information, a specialized relay agency may do so on behalf of such information transmitter.
(6) When a general recipient receives personal information according to a request for third-party transmission, he or she shall endeavor not to infringe on the interests of data subjects or impede the transmission processing system by any of the following acts:
1. Requesting to transmit personal information not related to the purpose of requesting transmission, in violation of Article 16 (1) of the Act;
2. Receiving consent to the third-party provision of transmitted information at the same time as the request for transmission, even if it is not essential for the operation of the service pursuant to Article 16 (3) of the Act;
3. Coercing or unduly inducing a request for transmission pursuant to Article 35 (2) 1 and (2) of the Act or the exercise of rights under Article 38(1) of the Act by proxy;
4. Performing the business affairs prescribed in the subparagraphs of Article 35-3 (1) of the Act without being designated as an agency specialized in managing personal information under Article 35-3 (1) of the Act;
5. Requesting personal information by changing the details of the request for transmission under Article 42-5 (2) without the consent of the data subject;
6. Infringing on the interests of a specific data subject for his or her own or a third party's interests;
7. Continuously or repeatedly accessing the electronic computer system of a personal information controller by reasons of a request for transmission by a data subject, thereby failures;
8. Other acts similar to those referred to in subparagraphs 1 through 7, which infringe on the interests of data subjects or impede the transmission processing system.
(7) No general specialized agency, special specialized agency, or general recipient shall collect health and medical services information subject to transmission, communications information subject to transmission, and energy information subject to transmission by using or storing the means of access by a data subject under subparagraph 1 in the manner prescribed in subparagraph 2:
1. The following means of access by a data subject:
a. Digital signature creation information under subparagraph 3 of Article 2 of the Digital Signature Act and certificates under subparagraph 6 of that Article;
b. The identifier or authenticated information of a data subject registered with the information transmitter for a third-party transmission request;
c. Biometric information of a data subject;
2. Perusal in the name of a data subject by the following methods:
a. Directly storing the means of access referred to in subparagraph 1;
b. Securing authority to accessing the means of access referred to in subparagraph 1;
c. Effectively securing the control, the right to use, or the right to accessing the means of access referred to in subparagraph 1.
(8) An institution specializing in managing personal information and the general recipient shall keep the information processed as an institution specializing in managing personal information and the general recipient separately from the information processed as another personal information controller; provided, where a special specialized agency (limited to a medical institution under Article 3 of the Medical Service Act) receives health and medical services information subject to transmission for the purpose of medical treatment through an electronic medical record system under Article 23-2 (1) of that Act and where electronic medical records are safely managed and retained pursuant to Article 23 (2), storage need not be separated.
(9) An information transmitter, an institution specializing in managing personal information, and a general recipient shall keep the details of transmission of the following health and medical services information subject to transmission, communications information subject to transmission, energy information subject to transmission, and information subject to voluntary transmission (hereinafter referred to as "information subject to transmission request") for 3 years: provided, in cases of an information transmitter, an specialized relay agency may keep such details in lieu of the information transmitter:
1. Matters referred to in the subparagraphs of Article 42-5 (2);
2. Records of sending and receiving information in response to a data subject's request for transmission;
3. Details of and reasons for the withdrawal or rejection of a request for transmission and the suspension of transmission.
(10) A general specialized agency or a special specialized agency shall notify the data subject of the details of transmission of information subject to request for transmission under paragraph (9) at least once a year by any means falling under any subparagraph of Article 15-3 (4); provided, such notification may be omitted if the data subject has expressed a desire not to receive it.
(11) The Protection Commission and the head of a relevant central administrative agency may provide subsidies to cover expenses incurred by an information transmitter in complying with requests for transmission, such as expenses incurred in establishing and operating facilities and technologies necessary for transmitting personal information, within the budget.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-8 (Rejection of request for transmission and suspension of transmission)
(1) "Cases prescribed by Presidential Decree, such as where it is impossible to verify whether a data subject is the person in question" in Article 35-2 (6) of the Act means any of the following cases:
1. Where it is impossible to verify whether the consent of the legal representative under Article 22-2 (1) of the Act is not verified;
2. Where the grounds for restricting or refusing access arise under Article 35 (4) of the Act;
3. Where the transmission of information subject to a request for transmission under Article 35-2 (1) and (2) of the Act infringes on the rights or legitimate interests of a third party;
4. Where it is impossible to verify whether the applicant is the representative under Article 38 (1) of the Act;
5. Where the matters subject to the request for transmission under Article 42-5 (1) and (2) are not specified;
6. Where the identity of the data subject is not verified;
7. Where it is found that the request for transmission is made by improper means, such as stealing authentication information of the data subject;
8. Where the request for transmission is to a person other than the data subject, a general specialized agency, a special specialized agency, or a general recipient
9. Where Personal Information is used by improper means, such as being abused for a crime, thereby clearly infringing on the interests of a data subject;
10. Where the data subject requests excessive and repeated transmission of the same personal information without good cause, causing disruption to the business affairs;
11. Where there are reasonable grounds to reject a request for transmission or to suspend the transmission, such as it is confirmed that circumstances suggesting that the data subject has made a request for transmission due to deception or intimidation of a third party.
(2) If an information transmitter rejects a data subject's request for transmission or suspends transmission due to a cause falling under any of the subparagraphs of paragraph (1), he or she shall notify the data subject of such fact and the reasons therefor without delay; provided, if the data subject makes a request for transmission through an institution specializing in managing personal information or a general recipient, he or she may notify it through the relevant institution specializing in managing personal information or the general recipient.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-9 (Business affairs of institutions specializing in managing personal information)
(1) Institutions specializing in managing personal information shall be classified as follows:
1. A specialized relay agency: A person who performs services referred to in Article 35-3 (1) 1 and 2 of the Act, which include the service of providing functions necessary for relaying the transmission of personal information, operating a related system, and supporting the transmission by an information transmitter (hereinafter referred to as "relay service");
2. A general specialized agency: A person who performs services referred to in Article 35-3 (1) 3 of the Act, which include the management and analysis of personal information (excluding health and medical services information subject to transmission) transmitted by an information transmitter for the purposes of integrated inquiries, customized services, research, education, etc.;
3. A special specialized agency: A person who performs services referred to in Article 35-3 (1) 3 of the Act, which include the management and analysis of health and medical services information subject to transmission transmitted by an information transmitter for the purposes of integrated inquiries, customized services, research, education, etc.
(2) A specialized relay agency shall not concurrently perform the services of a general specialized agency, a special specialized agency, and a general recipient.
(3) A specialized relay agency may process linked information under Article 23-5 (1) of the Act on Promotion of Information and Communications Network Utilization and Information Protection, if necessary for performing relay services.
(4) The Protection Commission or the head of a relevant central administrative agency may provide subsidies to cover expenses incurred in operating a specialized relay agency within the budget.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-10 (Application for designation of institution specializing in managing personal information)
(1) A person who intends to be designated as an institution specializing in managing personal information pursuant to Article 35-3 (1) of the Act shall file an application for designation to the designating authority under paragraph (2) by submitting the following documents; in such cases, a person who intends to be designated as an institution specializing in managing personal information may submit it through the personal information transmission support platform:
1. Application for designation;
2. Articles of incorporation or bylaws (not applicable to public institutions falling under subparagraph 6 (a) of Article 2 of the Act);
3. A business plan;
4. A personal information management plan;
5. Financial statements for the last 3 years (not applicable to public institutions falling under subparagraph 6 (a) of Article 2 of the Act);
6. Documents proving that the requirements for designation under Article 35-3 (2) of the Act are satisfied.
(2) A person who may designate an institution specializing in managing personal information pursuant to Article 35-3 (1) of the Act (hereinafter referred to as "designating authority") shall be as follows:
1. A specialized relay agency: The head of a relevant central administrative agency related to the information that the Protection Commission or specialized relay agency intends to receive; provided, the Minister of Health and Welfare shall be the specialized relay agency in the case of an agency specializing in relaying health and medical services information subject to transmission;
2. A general specialized agency: The head of a relevant central administrative agency related to the information to be transmitted to the Protection Commission or a general specialized agency;
3. A special specialized agency: The Minister of Health and Welfare.
(3) Upon receipt of an application for designation under paragraph (1), the designating authority shall verify the corporation registration certificate (limited to where a person who intends to be designated as an institution specializing in managing personal information is a corporation) through administrative data matching under Article 36 (1) of the Electronic Government Act.
(4) A person who intends to be designated as an institution specializing in managing personal information may apply for a preliminary examination to the designating authority before filing an application for designation under paragraph (1) to determine whether the detailed criteria for designation under Article 42-11 are satisfied.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-11 (Detailed criteria for designation of institutions specializing in managing personal information)
(1) The detailed standards for each requirement for the designation of an institution specializing in managing personal information under Article 35-3 (2) of the Act shall be as follows:
1. It shall have all of the following technological levels and expertise:
a. A business plan for enhancing the rights, interests, etc. of data subjects and preventing conflicts of interest with data subjects shall be reasonable and sound;
b. A personal information management plan for the services of an institution specializing in managing personal information shall be appropriate;
c. It shall have facilities and technologies prescribed and publicly notified by the Protection Commission to effectively perform the services of an agency specializing managing personal information;
2. It shall meet all of the following levels in terms of measures to ensure safety:
a. It shall meet the requirements for fulfilling the duty of safeguards under Article 29 of the Act;
b. In order to safely operate an institution specializing in managing personal information, a protection system determined and publicly notified by the Protection Commission shall be in place appropriately;
3. It shall have all of the following financial capabilities (not applicable to public institutions falling under subparagraph 6 (a) of Article 2 of the Act):
a. Its financial structure shall be sound and safe;
b. It shall have capital according to the following classifications [in the case of a corporation, the paid-in capital (in the case of a non-profit corporation, the basic property), and in the case of an organization that is not a corporation, it means the value of the assets held by the relevant organization; hereafter in this item the same shall apply];
1) A specialized relay agency: At least 1 billion won in capital;
2) A general specialized agency or a special specialized agency: At least 100 million won in capital;
c. It shall purchase an insurance policy or mutual aid or accumulate reserves for the performance of liability for damage compensation (not applicable to any person falling under any subparagraph of Article 39-7 (2) of the Act). The standards for the minimum amount of insurance policy or mutual aid or the minimum amount of reserves in such cases shall be as specified in Appendix 1-2.
(2) Notwithstanding paragraph (1), if any of the following agencies, corporations, or organizations intends to be designated as an institution specializing in managing personal information, it shall file a request therefor with the Protection Commission (excluding cases where the Protection Commission is the designating authority) and, after deliberation and resolution by the Protection Commission, may be treated as meeting the detailed criteria for designation under the subparagraphs of paragraph (1) without undergoing examination on some or all of the criteria; provided, the examination of all the requirements of the detailed criteria for designation under the subparagraphs of paragraph (1) may be omitted only in cases where the agency, corporation, or organization referred to in subparagraphs 1 and 2 intends to be designated as an institution specializing in managing personal information:
1. A medical institution under Article 3 of the Medical Service Act (limited to where health and medical services information subject to transmission is transmitted);
2. A central administrative agency or local government;
3. A public institution other than those referred to in subparagraph 2.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-12 (Designation of institutions specializing in managing personal information)
(1) If a person who has filed an application for designation pursuant to Article 42-10 (1) is deemed to meet the detailed criteria for designation under Article 42-11, the designating authority may designate such person as an institution specializing in managing personal information. In such cases, if a person who has filed an application for designation pursuant to Article 42-10 (1) fails to meet some of the detailed criteria for designation, the designating authority may grant the designation on the condition that he or she shall meet such criteria within a specified period and verify whether such conditions are fulfilled after designation.
(2) If an institution specializing in managing personal information intends to change any of the following matters (excluding minor matters determined and publicly notified by the Protection Commission), it shall obtain prior approval from the designating authority:
1. A business plan (including adding or changing the information to be transmitted);
2. A personal information management plan;
(3) The effective period of the designation of an institution specializing in managing personal information shall be 3 years.
(4) If an institution specializing in managing personal information applies for an extension of the effective period of designation under paragraph (3), the designating authority may re-designate it as an institution specializing in managing personal information if it deems that the institution meets the detailed criteria for designation under Article 42-11.
(5) When a designating authority (excluding the Protection Commission) intends to make the following decisions, it shall have a prior consultation with the Protection Commission:
1. Designation under paragraph (1) and re-designation under paragraph (4) (limited to specialized relay agencies);
2. Approval for modification under paragraph (2) (in cases of a general specialized agency or special specialized agency, limited to cases related to information subject to request for transmission).
(6) If a designating authority (excluding the Protection Commission in cases falling under subparagraph 1) grants designation under paragraph (1), approval for modification under paragraph (2), or re-designation under paragraph (4), it shall take the following measures:
1. Notification to the Protection Commission;
2. Public announcement in the Official Gazette or posting it on the website of the designating authority (excluding approval for modification).
(7) If a specialized relay agency intends to suspend or discontinue part or all of its relay services, it shall notify the designating authority thereof not later than 6 months prior to the scheduled date of suspension or discontinuance. In such cases, the designating authority may order the relevant specialized relay agency to take any of the following measures:
1. Destruction of personal information held by the relevant specialized relay agency (excluding cases where it is required to preserve personal information pursuant to other statutes or regulations);
2. Transfer of services being performed to another specialized relay agency;
3. Notifying any of the following persons of the planned suspension or discontinuation of services:
a. Data subjects of personal information held by the relevant specialized relay agency;
b. An information transmitter who transmits information to the relevant specialized relay agency;
c. A general specialized agency, a special specialized agency, or a general recipient to which information is transmitted by the relevant specialized relay agency.
(8) If a general specialized institution or special specialized institution intends to suspend or discontinue part or all of its services related to the transmission of personal information, it shall provide prior notification of such fact to a specialized relay institution and register it on the personal information transmission support platform.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-13 (Prohibited acts for institutions specializing in managing personal information)
“Acts prescribed by Presidential Decree” in Article 35-3 (3) 2 of the Act means the acts specified in Appendix 1-3.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-14 (Revocation of designation of institutions specialized in managing personal information)
(1) If an institution specializing in managing personal information fails to comply with the conditions under the latter part of Article 42-12 (1) pursuant to Article 35-3 (4) of the Act, the designating authority may revoke the designation of the institution specializing in managing personal information.
(2) When a designating authority (excluding the Protection Commission) intends to revoke the designation of an institution specializing in managing personal information, it shall have a prior consultation with the Protection Commission.
(3) If a designating authority (excluding the Protection Commission in cases falling under subparagraph 1) revokes the designation of an institution specializing in managing personal information, it shall take the following measures:
1. Notification to the Protection Commission;
2. Public announcement in the Official Gazette or posting on the website of the designating authority.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-15 (Management and supervision of Protection Committee on requests for transmission of personal information)
(1) In order to manage and supervise the current status of information transmitters pursuant to Article 35-4 (1) of the Act, the Protection Commission may request personal information controllers to submit data necessary for verifying whether they are information transmitters.
(2) The Protection Commission may request an information transmitter, an institution specializing in managing personal information, or a general recipient to submit data according to the following classifications in order to manage and supervise matters regarding whether an information transmitter complies with data subject access requests and third-party transmission requests, whether an institution specializing in managing personal information meets the requirements for designation, or whether a general recipient meets the facilities and technical standards, and the person requested to submit data shall comply with such request unless there is a compelling reason not to do so:
1. An information transmitter: Data on the details of transmission of personal information under Article 42-6 (9);
2. An institution specializing in managing personal information: the following data:
a. Data referred to in subparagraph 1;
b. Data on the processing and management of personal information;
c. Data on the method of requesting transmission (limited to general specialized agencies and special specialized agencies);
d. Data proving that it meets the requirements for designation of an institution specializing in managing personal information;
3. A general recipient: Any of the following data:
a. Data referred to in subparagraphs 1 and 2 (b);
b. Data on the method of requesting transmission;
c. Data proving that facilities and technologies under Article 42-3 (1) are in place.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 42-16 (Establishment and operation of personal information transmission support platform)
(1) If it is necessary for the safe and efficient transmission of personal information in relation to a third-party transmission request, the Protection Commission shall have the information transmitter, the institution specializing in managing personal information, and the general recipient be registered on the personal information transmission support platform.
(2) An information transmitter, a general specialized agency, a special specialized institution, or a general recipient registered on the personal information transmission support platform pursuant to paragraph (1) shall submit the following data to the personal information transmission platform through a specialized relay agency when transmitting or receiving personal information according to a third-party transmission request:
1. Details of personal information transmission under Article 42-6 (9);
2. Details of consent to the provision of the transmitted information to a third party (excluding information transmitters).
(3) If necessary for the efficient management of the history of personal information transmission, the Protection Commission may request a person who operates an information system supporting the transmission of personal information pursuant to other statutes or regulations to provide the details of a request for transmission by a data subject through interlinking with the personal information transmission support platform.
[This Article Added on Feb. 25, 2025]
법령 이단보기
Article 43 (Correction, and erasure of personal information)
(1) A data subject who intends to request a personal information controller to correct or erasure his or her own personal information pursuant to Article 36 (1) of the Act shall submit a request in the manner and following the procedure determined by the personal information controller. In such cases, Article 41 (2) shall apply mutatis mutandis where the personal information controller determines the manner and procedure for requesting the correction or erasure of personal information; and "access" shall be construed as "correction or erasure". <Amended on Oct. 17, 2017>
(2) Upon receipt of a request to correct or erasure personal information pursuant to Article 36 (1) of the Act, a personal information controller who processes personal information files provided by other personal information controller shall correct or erase the relevant personal information as requested; or shall, without delay, notify the personal information controller who has provided the relevant personal information of the request to correct or erasure the personal information, and take necessary measures based on the result of such processing. <Amended on Oct. 17, 2017>
(3) A personal information controller shall inform the relevant data subject of the fact that he or she has duly corrected or erased the relevant personal information pursuant to Article 36 (2) of the Act within 10 days from the receipt of a request to correct or erasure personal information under paragraph (1) or (2); otherwise, if the erasure of personal information is denied because it falls under the proviso of Article 36 (1) of the Act, the personal information controller shall serve the data subject with the Personal Information Correction or erasure Outcome Notice, stating the fact and grounds for the denial and how to appeal, in the form determined and publicly notified by determined and publicly notified by the Protection Commission. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
법령 이단보기
Article 44 (Suspension of processing personal information)
(1) A data subject who intends to request a personal information controller to suspend the processing of his or her own personal information pursuant to Article 37 (1) of the Act shall submit a request in the manner and following the procedure determined by the personal information controller. In such cases, Article 41 (2) shall apply mutatis mutandis where the personal information controller determines the manner and procedure for requesting the suspension of processing personal information; and "access" shall be construed as "suspension of processing". <Amended on Oct. 17, 2017>
(2) A personal information controller shall inform the relevant data subject of the fact that it has duly suspended the processing of personal information pursuant to the main clause of Article 37 (2) of the Act within 10 days from the receipt of a request to suspend the processing of personal information made under paragraph (1); otherwise, if the suspension of processing personal information is denied because it falls under the proviso of Article 37 (2) of the Act, the personal information controller shall serve the relevant data subject with the Personal Information Processing Suspension Outcome Notice, stating the fact and grounds for the denial and how to appeal, in the form determined and publicly notified by the Protection Commission. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
법령 이단보기
Article 44-2 (Methods and procedures for requesting refusal, and explanation of automated decisions)
(1) Where a data subject rejects an automated decision under Article 37-2 (1) of the Act (hereinafter referred to as "automated decision") pursuant to the main clause of the same paragraph, the data subject shall comply with the methods and procedures for disclosure prepared by the personal information controller pursuant to Article 44-4 (1) 5.
(2) The data subject may request a personal information controller to provide the following explanation or review on an automated decision pursuant to Article 37-2 (2) of the Act; in such cases, the data subject's request for explanation or review shall be in accordance with the methods and procedures established by the personal information controller and disclosed under Article 44-4 (1) 5:
1. Explaining the standards for the relevant automated decision and the processing process, etc. of the relevant automated decision;
2. Review of whether a data subject submits opinions, such as the addition of personal information, etc., and the personal information controller can reflect the relevant opinions in an automated decision.
(3) Article 41 (2) shall apply mutatis mutandis to matters to be observed where a personal information controller prepares the methods and procedures for refusing, explaining, and reviewing automated decisions by data subjects under paragraphs (1) and (2) (hereinafter referred to as "request for refusal, explanation, etc."). In such cases, "request for inspection" shall be construed as "request for refusal, explanation, etc."
[This Article Added on Mar. 12, 2024]
법령 이단보기
Article 44-3 (Measures following request for refusal, and explanation)
(1) Where a data subject refuses to make an automated decision pursuant to Article 44-2 (1), a personal information controller shall take any of the following measures and notify the data subject of the results thereof, unless there is a compelling reason not to do so:
1. Measures not to apply automated decisions;
2. Reprocessing by personal intervention.
(2) Where a data subject requests an explanation under Article 44-2 (2) for an automated decision pursuant to Article 44-2 (2), the personal information controller shall provide the data subject with a concise and meaningful explanation, including the following matters, unless there is good cause; provided, where the relevant automated determination does not significantly affect the rights or obligations of the data subject, the personal information controller may notify the data subject of the matters referred to in Article 44-4 (1) 2 and 3:
1. The result of the relevant automated decision;
2. The types of major personal information used for the relevant automated decision;
3. Major criteria for automated decisions, such as the impact of the types of personal information under subparagraph 2 on automated decisions;
4. Procedures in which automated decisions are made, such as the process of major personal information used for the relevant automated decisions.
(3) Where a data subject requests a review under Article 44-2 (2) 2 pursuant to Article 44-2 (2), a personal information controller shall review whether the opinions submitted by the data subject are reflected and notify the data subject of whether the opinions are reflected and the results of reflection, unless there is a compelling reason not to do so.
(4) Where a personal information controller refuses a request for refusal or explanation, etc. pursuant to Article 38 (5) of the Act due to justifiable grounds, such as likelihood of unfairly infringing on the life, body, property, and other interests of other persons, the personal information controller shall notify the data subject of the grounds therefor in writing, etc. without delay.
(5) Where a personal information controller takes measures in accordance with a request for refusal or explanation by a data subject pursuant to paragraphs (1) through (3), he or she shall take such measures in writing, etc. within 30 days from the date he or she receives a request for refusal or explanation by the data subject; provided, where there exist any justifiable grounds that make it impracticable to process within 30 days, the personal information controller may extend the period by up to 30 days only twice after notifying the data subject of the grounds therefor.
(6) Detailed matters concerning measures taken in response to a request for refusal or explanation by a data subject under paragraphs (1) through (5) shall be determined and publicly notified by the Protection Commission.
[This Article Added on Mar. 12, 2024]
법령 이단보기
Article 44-4 (Disclosure of standards and procedures for automated decisions)
(1) A personal information controller shall disclose the following matters on its website, etc. so that data subjects can easily identify the following matters pursuant to Article 37-2 (4) of the Act; provided, where the personal information controller does not operate the website, etc. or it is not necessary to continuously inform the data subjects, the personal information controller may inform the data subjects in advance by means of written documents, etc.
1. The fact that an automated decision is made and the purpose and scope of the data subject to be subject to such decision;
2. Types of major personal information used for automated decisions and relationship between automated decisions;
3. Considerations in automated decision-making process and procedures for processing major personal information;
4. Where sensitive information is processed in the process of automated decision-making or personal information of a child under 14 years of age, the purpose of such processing and specific details of personal information to be processed;
5. The fact that the data subject may make a request for refusal, explanation, etc. of an automated decision and the method and procedure therefor.
(2) When a personal information controller discloses the matters referred to in the subparagraphs of paragraph (1), he or she shall use standardized and systematic terms so that data subjects can easily understand the relevant details, and may utilize visual methods, such as video, pictures, drawings, etc., so that data subjects can easily understand such details.
[This Article Added on Mar. 12, 2024]
법령 이단보기
Article 45 (Scope of representative)
(1) A person who can represent a data subject under Article 38 of the Act shall be any of the following:
1. A legal representative of the data subject;
2. A person delegated by the data subject.
(2) A representative referred to in paragraph (1), representing a data subject pursuant to Article 38 of the Act, shall submit a power of attorney of the data subject, in the form determined and publicly notified by the Protection Commission, to the personal information controller. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
법령 이단보기
Article 46 (Confirmation of data subjects or representatives)
(1) Upon receipt of a request for access under Article 41 (1), correction or erasure of personal information under Article 43 (1), transmission under Article 35-2 of the Act, suspension of processing of personal information or withdrawal of consent under Article 37 (1) of the Act (hereafter in this Article and Articles 47 and 48 referred to as "request for access, etc."), a personal information controller shall confirm whether the person who has submitted the request for access, etc. is the principal or the duly authorized representative. <Amended on Aug. 4, 2020; Sep. 12, 2023; Feb. 25, 2025>
(2) Any personal information controller, which is a public institution eligible for the administrative data matching pursuant to Article 36 (1) of the Electronic Government Act, shall confirm as provided in paragraph (1) through administrative data matching; provided, this shall not apply where the public institution is unable to use administrative data matching or the data subject does not consent to such confirmation.
(3) In relation to a request for transmission of personal information under Article 35-2 of the Act, the Protection Commission and the head of a relevant central administrative agency may request the relevant agencies for electronic data on resident registration information under Article 30 (1) of the Resident Registration Act and computerized registration data under Article 11 (6) of the Act on Registration of Family Relations in order to assist the personal information controller under paragraph (1) in ascertaining whether the request is made by the data subject or his or her representative. <Added on Feb. 25, 2025>
법령 이단보기
Article 47 (Amounts of fees)
(1) The amounts of fees and postage provided for in Article 38 (3) of the Act shall be determined by the relevant personal information controller within the actual expenses necessary for the processing of the request for access, etc.; provided, if a personal information controller is a local government, they shall be prescribed by ordinance of the relevant local government , and the fees under the proviso of Article 38 (3) of the Act shall be calculated in accordance with the standards determined and publicly notified by the Protection Commission in consideration of the characteristics of information subject to request for transmission, expenses incurred in establishing and operating necessary facilities, etc. <Amended on Feb. 25, 2025>
(2) A personal information controller shall not demand any fee or postage if the cause for submitting the request for access, etc. lies with the personal information controller.
(3) Any fee and postage provided in Article 38 (3) of the Act shall be paid as follows; provided, a personal information controller, which is the National Assembly, the Court, the Constitutional Court, the National Election Commission, a central administrative agency, or its affiliated body (hereafter in this Article referred to as "national agency") or a local government, may claim such fee and postage by the electronic payment means defined in subparagraph 11 of Article 2 of the Electronic Financial Transactions Act, or telecommunications billing services defined in Article 2 (1) 10 of the Act on Promotion of Information and Communications Network Utilization and Information Protection: <Amended on Sep. 12, 2023>
1. Where the fee or postage is paid to a personal information controller that is a national agency: Revenue stamp;
2. Where the fee or postage is paid to a personal information controller that is a local government: Revenue certificate;
3. Where the fee and postage is paid to other personal information controller than a national agency or local government: In the manner determined by the relevant personal information controller.
(4) If a general specialized agency, special specialized agency, or general recipient requests third-party transmission on behalf of a data subject pursuant to the former part of Article 42-5 (3), the information transmitter may charge the general specialized agency, special specialized agency, or general recipient with a fee under the proviso of Article 38 (3) of the Act. <Added on Feb. 25, 2025>
법령 이단보기
Article 48 (Establishing access request support system)
(1) A personal information controller may establish and operate a support system that enables the request for access, etc. to be processed and notified electronically, and determine other work procedures.
(2) The Protection Commission may establish and operate a system to support the public institutions which are personal information controllers efficiently process the request for access, etc. for personal information they possess and notify the results thereof. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
CHAPTER VI-2 Deleted.
법령 이단보기
Article 48-2 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-3 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-4 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-5 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-6 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-7 (Scope, and standards of the parties required to purchase an insurance for performance of damage compensation responsibilities)
(1) "Person who meets the standards prescribed by Presidential Decree" in Article 39-7 (1) of the Act means a person who meets all of the following requirements (hereinafter referred to as "subscribed personal information controller"): <Amended on Mar. 12, 2024>
1. The same sales, etc. of the previous year (in cases of a corporation, referring to the immediately preceding business year) shall be at least one billion won;
2. The number of data subjects (excluding data subjects falling under Article 15-3 (2) 2; hereafter the same shall apply in this Article) whose personal information has been stored and managed for three months immediately preceding the end of the previous year shall be at least 10,000 per day average daily; provided, where personal information has been transferred due to acquisition of all or part of business, division, merger, etc. in the relevant year, the number of data subjects shall be at least 10,000 persons as of the time of transfer.
(2) "Public institutions, non-profit corporations, and organizations prescribed by Presidential Decree" in Article 39-7 (2) 1 of the Act means the following institutions: <Added on Mar. 12, 2024>
1. Public Institutions; provided, this shall not apply to public institutions falling under subparagraphs 2 through 5 of Article 2, which fall under the subparagraphs of Article 32 (4);
(3) "Person prescribed by Presidential Decree" in Article 39-7 (2) 2 of the Act means a person who meets all of the following requirements: <Amended on Mar. 12, 2024>
1. A person entrusted with the storage and management of personal information by a micro enterprise under Article 2 (1) of the Framework Act on Micro Enterprises to prevent personal information from being lost, stolen, divulged, divulged, forged, altered, or damaged;
2. A person who takes necessary measures, such as purchasing an insurance policy or joining a mutual aid agreement or accumulating reserves to guarantee the fulfillment of liability for damage compensation under Articles 39 and 39-2 of the Act with respect to affairs entrusted pursuant to subparagraph 1.
(4) The standards for the minimum subscription amount (referring to the minimum reserve amount in cases of accumulating reserves; hereafter the same shall apply in this Article) where a subscribed personal information controller subscribes to insurance or mutual aid or accumulates reserves shall be as specified in Appendix 1-4; provided, where a personal information controller subject to enrollment subscribes to insurance or mutual aid or accumulates reserves simultaneously, the aggregate of the amount of insurance or mutual aid and reserves shall be at least the standards for the minimum subscription amount prescribed in Appendix 1-4. <Amended on Sep. 12, 2023; Mar. 12, 2024>
[This Article Added on Aug. 4, 2020]
법령 이단보기
Article 48-8 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-9 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-10 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-11 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-12 Deleted. <Sep. 12, 2023>
법령 이단보기
Article 48-13 Deleted. <Sep. 12, 2023>
CHAPTER VII PERSONAL INFORMATION DISPUTE MEDIATION
법령 이단보기
Article 48-14 (Ex officio members)
The ex officio members of the Dispute Mediation Committee shall be appointed by the Chairperson of the Protection Commission from among members in general service of the Senior Executive Service of the Protection Commission, who are in charge of the work related to the protection of personal information. <Amended on Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jul. 22, 2016]
[Moved from Article 48-2 <Aug. 4, 2020>]
법령 이단보기
Article 49 (Composition and operation of mediation panels)
(1) The mediation panel referred to in Article 40 (6) of the Act (hereinafter referred to as "mediation panel") shall be comprised of up to five members appointed by the chairperson of the Dispute Mediation Committee, and one of whom shall be a commissioner with an attorney-in-law license. <Amended on Jul. 22, 2016>
(2) The chairperson of the Dispute Mediation Committee shall convene the meetings of the mediation panel.
(3) The chairperson of the Dispute Mediation Committee shall notify each member of the mediation panel of the date, time, venue, and agenda no later than seven days prior to the meeting; provided, this shall not apply in case of emergency.
(4) The presider of the mediation panel shall be elected by and from among its members.
(5) Except as provided in paragraphs (1) through (4), matters necessary for the composition and operation of the mediation panel, and other necessary matters, shall be determined by the chairperson of the Dispute Mediation Committee subject to the resolution of the Dispute Mediation Committee.
법령 이단보기
Article 49-2 (Specialized committee for dispute mediation)
(1) The Dispute Mediation Committee may establish a specialized committee for each field (hereinafter referred to as "specialized committee for dispute mediation") to conduct a specialized examination of the matters related to mediation of disputes regarding personal information.
(2) Each specialized committee for dispute mediation shall be composed of up to 10 members, including one chairperson.
(3) Members of each specialized committee for dispute mediation shall be appointed or commissioned by the chairperson of the Dispute Mediation Committee from among the following persons, and the chairperson of each specialized committee for dispute mediation shall be designated by the chairperson of the Dispute Mediation Committee from among the members of the relevant specialized committee for dispute mediation:
1. A member of the Dispute Mediation Committee;
2. A relevant public official of a central administrative agency who is responsible for work related to personal information protection;
3. A person who holds or has held the position of assistant professor or higher in a university or college in the field of personal information protection;
4. A person who has at least five years’ research experience at an accredited research institute in the field related to personal information protection;
5. A person who has at least one year’s work experience in the field related to personal information protection after being qualified as an attorney-at-law;
6. Other persons with extensive expertise and experience in personal information protection and dispute mediation.
(5) Except as provided in paragraphs (1) through (3), matters necessary for the composition, operation, etc. of specialized committees for dispute mediation shall be determined by the chairperson of the Dispute Mediation Committee following its resolution.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 50 (Secretariat)
(1) The secretariat of the Protection Commission shall conduct administrative affairs necessary for dispute mediation, such as receiving dispute mediation cases and fact-finding pursuant to Article 40 (8) of the Act. <Amended on Aug. 4, 2020>
(2) The secretariat may establish and operate a dispute mediation system in order to electronically process the business affairs required for dispute mediation, including receiving dispute mediation requests, advancing the dispute mediation process and providing notifications to the parties. <Added on Aug. 4, 2020>
[This Article Wholly Amended on Jul. 22, 2016]
법령 이단보기
Article 51 (Operation of Dispute Mediation Committee)
(1) The chairperson of the Dispute Mediation Committee shall convene and preside over meetings of the Dispute Mediation Committee.
(2) The chairperson of the Dispute Mediation Committee shall notify each member of the Dispute Mediation Committee of the date, time, venue, and agenda no later than seven days prior to the meeting; provided, this shall not apply in case of emergency.
(3) The meetings of the Dispute Mediation Committee and the mediation panel shall not be open to the public; provided, attendance of the parties or interested parties is allowed by the resolution of the Dispute Mediation Committee, if deemed necessary.
법령 이단보기
Article 51-2 (Notification of intention not to respond to mediation)
Where a personal information controller intends not to respond to dispute mediation due to any compelling reason under Article 43 (3) of the Act, the personal information controller shall notify the Dispute Mediation Committee of such intention specifying the grounds therefor within 10 days from the date of being notified of dispute mediation under Article 43 (2) of the Act.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 51-3 (Secretariat of, and investigation and inspection by, Dispute Mediation Committee)
(1) "Secretariat prescribed by Presidential Decree" in the former part of Article 45 (2) of the Act means the secretariat of the Protection Commission, which is in charge of conducting administrative affairs necessary for dispute mediation pursuant to Article 50 (1).
(2) Where the Dispute Mediation Committee intends to conduct an investigation or inspection pursuant to Article 45 (2) of the Act, it shall notify a person subject to such investigation or inspection of the following matters in writing no later than seven days before the investigation or inspection; provided, where the purpose of the investigation or inspection is likely to be compromised, prior notification need not be given:
1. The purpose of the investigation and inspection;
2. The period and place of the investigation and inspection;
3. The position and name of a person who conducts the investigation or inspection;
4. The scope and details of the investigation and inspection;
5. The fact that the person may refuse the investigation or inspection, where there is good cause;
6. The details of disadvantageous measures, where the person refuses, obstructs, or evades the investigation or inspection without good cause;
7. Other matters necessary for the investigation or inspection for dispute mediation.
(3) When the Dispute Mediation Committee conducts an investigation or inspection pursuant to Article 45 (2) of the Act, it may request disputing parties or persons designated by the disputing parties to be present during the investigation or inspection or to present their opinions.
(4) To hear the opinions of disputing parties or relevant witnesses pursuant to Article 45 (5) of the Act, the Dispute Mediation Committee shall determine the date, time, and place of a meeting and notify the disputing parties or relevant witnesses thereof no later than 15 days before the meeting is held.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 51-4 (Notification of intention to reject proposal of mediation)
(1) When the Dispute Mediation Committee presents each party with a proposal of mediation pursuant to Article 47 (2) of the Act, it shall notify him or her of the fact that the proposal of mediation is deemed accepted unless he or she notifies the Dispute Mediation Committee of his or her acceptance or denial within 15 days from the date of being presented with the decision pursuant to paragraph 47 (3) of the Act.
(2) Where each party presented with a proposal of mediation pursuant to Article 47 (2) of the Act intends to reject the proposal of mediation, he or she shall notify the Dispute Mediation Committee of his or her intention by a person, registered mail, or electronic mail within 15 days from the date of being presented with the decision.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 52 (Incidents eligible for collective dispute mediation)
"Incident is prescribed by Presidential Decree" in Article 49 (1) of the Act means any incident that satisfies all of the following conditions:
1. The number of data subjects suffering from damage or infringement on their rights shall be not less than 50 persons, except the following:
(a) Data subjects who have agreement with the personal information controller on the dispute settlement or compensation for damage;
(b) Data subjects whose dispute is based on the same cause and is dealt with by a dispute mediation body established by other statutes or regulations;
(c) Data subjects who have filed a lawsuit with a court regarding damages from the relevant personal information breach;
2. Major issues of the incident are common factually or legally.
법령 이단보기
Article 53 (Commencement of collective dispute mediation proceedings)
(1) "Period prescribed by Presidential Decree" in the latter part of Article 49 (2) of the Act means a period of at least 14 days.
(2) Public announcement of commencing the collective dispute mediation proceedings referred to in the latter part of Article 49 (2) of the Act shall be posted on the website of the Dispute Mediation Committee or a general daily newspaper circulating nationwide under the Act on the Promotion of Newspapers. <Amended on Dec. 30, 2015>
법령 이단보기
Article 54 (Applications for participation in collective dispute mediation proceedings)
(1) A data subject or personal information controller, other than the parties to collective dispute mediation subject to Article 49 of the Act (hereinafter referred to as "collective dispute mediation"), who intends to participate in such collective dispute mediation additionally as a party pursuant to Article 49 (3) of the Act, shall file a written application during the notice period subject to the latter part of Article 49 (2) of the Act.
(2) Upon receiving a written application for collective dispute mediation as a party pursuant to paragraph (1), the Dispute Mediation Committee shall inform the applicant of whether it has accepted his or her application within 10 days from the expiry of the application period referred to in paragraph (1).
법령 이단보기
Article 55 (Collective dispute mediation proceedings)
(1) After the collective dispute mediation proceedings commence, a data subject who falls under any of subparagraph 1 (a) through (c) of Article 52 shall be excluded from participation as a party.
(2) Once the collective dispute mediation proceedings of the case which satisfies the conditions referred to in Article 52 commence, such proceedings shall not be suspended even if the conditions referred to in subparagraph 1 of Article 52 are not satisfied because a data subject falls under any of subparagraph 1 (a) through (c) of that Article.
법령 이단보기
Article 56 (Allowances and travel expenses)
Members, etc. who attend a meeting of the Dispute Mediation Committee, the mediation panel, or a specialized committee for dispute mediation may be paid allowances and travel expenses within the budget; provided, this shall not apply where a public official attends any meeting in direct connection with his or her duties. <Amended on Sep. 12, 2023>
법령 이단보기
Article 57 (Dispute mediation rule)
Except as provided in the Act and this Decree, matters necessary for the operation of the Dispute Mediation Committee and collective dispute mediation, such as the procedures for dispute mediation and dealing with dispute mediation, shall be determined by the chairperson of the Dispute Mediation Committee following its resolution. <Amended on Sep. 12, 2023>
CHAPTER VIII SUPPLEMENTARY PROVISIONS AND PENALTY PROVISIONS
법령 이단보기
Article 58 (Recommendation for improvements and disciplinary action)
(1) An advice for improvement under Article 61 (2) and (3) of the Act and an advice for disciplinary action under Article 65 (2) and (3) of the Act shall be made in writing that explicitly state the matters to be advised, grounds therefor, outcomes of the action, reply period, etc.
(2) A person who has received an advice under paragraph (1) shall take necessary measures as advised, and notify the Protection Commission or the head of the related central administrative agency of the outcome in writing; provided, special circumstances, in which it is deemed impracticable to take measures as advised, shall be explained in the notice. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017: Aug. 4, 2020>
법령 이단보기
Article 59 (Reporting on infringements)
The Protection Commission shall designate the Korea Internet and Security Agency as a specialized institution to efficiently receive and handle the claim reports on infringements on personal information-related rights or interests pursuant to Article 62 (2) of the Act. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
법령 이단보기
Article 60 (Requests for materials and inspections)
(1) "Cases prescribed by Presidential Decree" in Article 63 (1) 3 of the Act means circumstances in which a case or incident which infringes on data subject’s right or interest related to personal information, such as a divulgence of personal information, has occurred or is likely to occur.
(2) The Protection Commission may request the head of the Korea Internet and Security Agency to provide necessary assistance, including technical advice, in order to request materials and to conduct inspections, etc. pursuant to Article 63 (1) and (2) of the Act. <Amended on Mar. 23, 2013; Nov. 19, 2014; Dec. 30, 2015; Jul. 26, 2017; Aug. 4, 2020>
(3) Deleted. <Sep. 12, 2023>
(4) Deleted. <Sep. 12, 2023>
(5) Deleted. <Sep. 12, 2023>
(6) Deleted. <Sep. 12, 2023>
(7) Deleted. <Sep. 12, 2023>
법령 이단보기
Article 60-2 (Criteria for calculation of penalty surcharges)
(1) The total sales under the main clause, with the exception of the subparagraphs, of Article 64-2 (1) of the Act shall be the average annual sales of the relevant personal information controller for three business years immediately preceding the business year in which any violation is committed (hereafter in this Article referred to as the "relevant business year"); provided, where three years have not elapsed since the date of commencement of business as of the first day of the relevant business year, the total sales shall be the amount calculated by converting the sales from the date of commencement of business to the end of the immediately preceding business year into the average annual sales; and where business commences in the relevant business year, the total sales shall be the amount calculated by converting the sales from the date of commencement of business to the date a violation is committed into the average annual sales.
(2) "Cases prescribed by Presidential Decree" in the proviso, with the exception of the subparagraphs, of Article 64-2 (1) of the Act means any of the following cases:
1. Where there is no sales records due to any of the following reasons:
(a) No commencement of business;
(b) Suspension of business;
(c) Any other reason equivalent to those specified in items (a) and (b), such as no engagement in profit-making business;
2. Where it is impracticable to objectively calculate the sales because sales calculation data are lost or damaged due to a disaster, etc.
(3) Sales unrelated to a violation under Article 64-2 (2) of the Act shall be any of the following amounts of the total sales specified in paragraph (1):
1. Sales of goods or services which are unrelated to personal information processing;
2. Sales recognized by the Protection Commission as not the sales of goods or services directly or indirectly affected by a violation, based on the data, etc. submitted pursuant to paragraph (4).
(4) Where the Protection Commission needs financial statements or other data for the calculation of sales, etc. under paragraphs (1) through (3), it may request the relevant personal information controller to submit the relevant data within a specified period not exceeding 20 days.
(5) "Ground prescribed by Presidential Decree" in Article 64-2 (5) 4 of the Act means where the relevant personal information controller rectifies a violation and meets the criteria determined and publicly notified by the Protection Commission.
(6) The criteria and procedures for calculating penalty surcharges under Article 64-2 (6) of the Act shall be as specified in Appendix 1-5.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 60-3 (Imposition and payment of penalty surcharges)
(1) Where the Protection Commission intends to impose a penalty surcharge under Article 64-2 of the Act, it shall investigate and verify the relevant violation and shall give the person subject to the penalty surcharge written notification specifying the violation, the amount imposed, the methods and period of filing an objection, etc.
(2) A person notified under paragraph (1) shall pay the relevant penalty surcharge to a financial institution designated by the Protection Commission within 30 days from the date of being notified.
(3) Upon receipt of a penalty surcharge under paragraph (2), a financial institution shall issue a receipt to the person who has paid the penalty surcharge.
(4) Upon receipt of a penalty surcharge pursuant to paragraph (2), a financial institution shall notify the Protection Commission of such fact without delay.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 60-4 (Extensions of payment deadline for penalty surcharges and payment by installment)
(1) Where the Protection Commission extends the payment deadline for penalty surcharges specified in Article 64-2 (1) of the Act pursuant to Article 29 of the Framework Act on Administration and Article 7 of the Enforcement Decree of that Act, an extended payment period shall not exceed two years from the date of expiry of the initial payment deadline.
(2) Where the Protection Commission allows a penalty surcharge under Article 64-2 (1) of the Act to be paid in installments pursuant to Article 29 of the Framework Act on Administration and Article 7 of the Enforcement Decree of that Act, the interval between each deadline for payment in installments shall not exceed six months and the number of installments shall not exceed six times.
(3) Except as provided in paragraphs (1) and (2), matters necessary for an extension of the payment deadline for penalty surcharges, an application for payment in installments, etc. shall be determined and publicly notified by the Protection Commission.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 60-5 (Interest rate on additional refund)
"Interest rate prescribed by Presidential Decree" in Article 64-2 (9) of the Act means the interest rate prescribed in the main clause of Article 43-3 (2) of the Enforcement Decree of the Framework Act on National Taxes.
[This Article Added on Sep. 12, 2023]
법령 이단보기
Article 61 (Publication of results)
(1) The Protection Commission may publish the following matters by posting them on its website, etc. under Article 66 (1) of the Act:
1. The details of violations;
2. The violators;
3. Recommendations for improvement, orders to take corrective measures, the imposition of penalty surcharges, accusations, and recommendations for disciplinary actions, and the details and outcomes of imposition of administrative fines.
(2) The Protection Commission may order a person subject to a recommendation for improvement, an order to take corrective measures, the imposition of a penalty surcharge, an accusation, a recommendation for a disciplinary action, the imposition of an administrative fine, etc. under Article 66 (2) of the Act (hereafter in this Article referred to as "disposition, etc.") to publish the following matters; in such cases, the Protection Commission shall, when issuing such order, determine the details, frequency, media of such publication, the size of pages, etc., and may consult with the person subject to the disposition, etc. on the text of the publication, etc.:
1. The details of violations;
2. The violators;
3. The fact that the person is subject to the disposition, etc.
(3) Where the Protection Commission intends to make the publication under paragraph (1) or to issue an order for publication under paragraph (2), it shall take into account the details, severity, period, and frequency of a violation, the scope and consequences of the damage caused by such violation, and other relevant matters.
(4) The Protection Commission shall provide a person subject to a disposition, etc. with an opportunity to submit explanatory materials or to present his or her opinion before deliberating and resolving on publication or an order for publication.
[This Article Wholly Amended on Sep. 12, 2023]
법령 이단보기
Article 62 (Entrustment of work)
(1) Deleted. <Dec. 30, 2015>
(2) The Protection Commission may entrust the work to support the provision of alternative sign-up tool subject to Article 24-2 (4) of the Act to the following institutions under Article 68 (1) of the Act: <Amended on Mar. 23, 2013; Nov. 19, 2014; Dec. 30, 2015; Jul. 26, 2017; Aug. 4, 2020; Jul. 19, 2022>
1. The Korea Local Information Research and Development Institute established under Article 72 (1) of the Electronic Government Act;
2. The Korea Internet and Security Agency;
3. A corporation, institution, or organization determined and publicly notified by the Protection Commission after being recognized as having technical and financial capacity and facilities to develop, provide, and manage the alternative sign-up tool safely.
(3) The Protection Commission (including a designating authority other than the Protection Commission in cases falling under subparagraph 10; hereafter the same shall apply in the provisions, with the exception of the subparagraphs, of paragraph (4) and paragraph (5)) may entrust the following business affairs to an institution provided in paragraph (4), under Article 68 (1) of the Act: <Amended on Mar. 23, 2013; Nov. 19, 2014; Dec. 30, 2015; Jul. 26, 2017; Aug. 4, 2020; Jul. 19, 2022; Sep. 12, 2023; Feb. 25, 2025>
1. Exchange and cooperation with international organizations and foreign personal information protection agencies for the protection of personal information under subparagraph 5 of Article 7-8 of the Act;
2. Surveys and research on statutes and regulations, policies, systems, actual conditions, etc. related to the protection of personal information under subparagraph 6 of Article 7-8 of the Act;
3. Support for and dissemination of technology development for the protection of personal information under subparagraph 7 of Article 7-8 of the Act;
4. Education and public relations regarding the protection of personal information under subparagraph 1 of Article 13 of the Act;
5. Promotion of and support for agencies and organizations related to the protection of personal information under subparagraph 2 of Article 13 of the Act;
6. Training of relevant specialists and development of criteria for privacy impact assessments under Article 33 (6) of the Act;
7. Receipt and processing of access requests under Article 35 (2) of the Act;
8. Requests for materials and inspections under Article 63 of the Act that are related to the following matters:
(a) Technical assistance for reporting under the former part of Article 34 (3) of the Act;
(b) Receipt and processing of, and counseling on, reports received by the Privacy Call Center pursuant to Article 62 of the Act;
9. Receipt of applications for designating an assessment institution under Article 36 (2) and receipt of reports under paragraph (6) of that Article.
10. The following matters regarding the designation of an institution specializing in managing personal information under Article 35-3 of the Act:
a. Receipt of an application for designation as an institution specializing in managing personal information under Article 42-10 (1) and verification of the details of such application;
b. Preliminary examination on the designation of an institution specializing in managing personal information under Article 42-10 (4);
c. Verification as to whether the conditions for designation under the latter part of Article 42-12 (1) are fulfilled;
11. Operation of a personal information transmission support platform under Article 35-4 (2) of the Act.
(4) The institutions to which the Protection Commission may entrust its work regarding the matters specified in the subparagraphs of paragraph (3) shall be as follows: <Added on Jul. 19, 2022>
1. The Korea Internet and Security Agency;
2. A corporation, institution, or organization determined and publicly notified by the Protection Commission as having expertise in the field of personal information protection.
(5) Where the Protection Commission entrusts its work pursuant to paragraphs (2) through (4), it shall publicly announce the institutions to be entrusted with the affairs and details of the entrusted affairs in the Official Gazette or on its website. <Amended on Jul. 19, 2022>
[Title Amended on Jul. 19, 2022]
법령 이단보기
Article 62-2 (Processing of sensitive information and personally identifiable information)
(1) The Protection Commission (including persons entrusted with the authority of the Protection Commission under Article 62 (3)) may process sensitive information and data that contain resident registration numbers, passport numbers, driver’s license numbers, or alien registration numbers referred to in Article 19, if inevitable to perform the following business affairs: <Amended on Aug. 4, 2020; Sep. 12, 2023>
1. Business affairs regarding deliberation and resolution on any matter under Article 7-9 (1) 4 through 6 of the Act;
2. Business affairs regarding preparing for and supporting the establishment of systems providing alternative sign-up tools under Article 24-2 (4) of the Act;
3. Deleted; <Sep. 12, 2023>
4. Business affairs regarding work of the Privacy Call Center established pursuant to Article 62 (3) of the Act;
5. Business affairs regarding submission of materials and inspections under Articles 63 (1) and (2);
6. Business affairs regarding preliminary fact-finding inspections conducted under Article 63-2 of the Act;
7. Business affairs regarding imposing and collecting penalty surcharges under Article 64-2 of the Act.
(2) The Dispute Mediation Committee may process sensitive information and data that contain resident registration numbers, passport numbers, driver’s license numbers, or alien registration numbers referred to in Article 19, if inevitable to perform the business affairs related to personal information dispute mediation under Articles 45, 47, and 49 of the Act. <Amended on Aug. 4, 2020; Sep. 12, 2023>
(3) Where it is unavoidable for the information transmitter or the specialized relay agency to perform the business affairs related to the request for transmission of personal information under Article 35-2 of the Act, it may process data containing a resident registration number, passport number, driver's license number, or alien registration number (limited to the resident registration number held by him or her in the case of an information transmitter) under Article 19 (limited to the case of verifying the identity of the person). <Added on Feb. 25, 2025>
[This Article Added on Aug. 6, 2014]
[Title Amended on Aug. 4, 2020]
법령 이단보기
Article 62-3 (Re-examination of regulation)
(1) The Protection Commission shall examine the appropriateness of the following matters every 3 years, counting from each base date specified in the following (referring to the period that ends on the day before the base date of every 3rd year) and shall take measures, such as making improvements. <Added on Aug. 4, 2020; Mar. 8, 2022; Sep. 12, 2023; Mar. 12, 2024; Feb. 25, 2025>
1. Deleted; <Feb. 25, 2025>
2. Scope of the persons required to be notified of the details of the use and provision of personal information, the types of information required to be notified, and the frequency and method of notification under Article 15-3: September 15, 2023;
3. Scope and standards of the parties required to purchase an insurance, etc. for performance of damage compensation responsibilities under Article 48-7: August 5, 2020.
4. Combination of pseudonymized information between personal information controllers under Article 29-3: Jan. 1, 2024.
5. Matters regarding information transmitters and information transmitted under Articles 42-2 through 42-4: January 1, 2025;
6. Matters regarding requests for and methods of transmitting personal information under Articles 42-5 through 42-8: January 1, 2025;
7. Matters regarding institutions specializing in managing personal information under Articles 42-9 through 42-16: January 1, 2025;
8. Matters regarding the designation, etc. of an Expert Data Combination Agency under Article 29-2: January 1, 2026;
9. Matters regarding the management, supervision, etc. of an Expert Data Combination Agency under Article 29-4: January 1, 2025.
(2) The Protection Commission shall examine the appropriateness of the following matters every 2 years, counting from each base date specified in the following (referring to the period that ends on the day before January 1 of every 2nd year) and shall take measures, such as making improvements. <Amended on Mar. 12, 2024; Feb. 25, 2025>
1. Deleted; <Feb. 25, 2025>
2. The qualification requirements for persons in charge of personal information protection under Article 32 (4) and (6) and Appendix 1 and matters to be observed by personal information controllers to guarantee the independence of persons in charge of personal information protection: Jan. 1, 2025;
3. Procedures and Methods for Requesting Rejection of Automated Decisions or Requesting Explanation, Measures Following Requests for Rejection of Automated Decisions or Requests for Explanation, etc., Standards and Procedures for Automated Decisions, etc. under Articles 44-2 through 44-4: Jan. 1, 2025.
(3) Deleted. <Mar. 8, 2022>
[This Article Wholly Amended on Dec. 9, 2014]
법령 이단보기
Article 63 (Criteria for imposition of administrative fines)
The criteria for the imposition of administrative fines under Article 75 of the Act shall be as specified in Appendix 2. <Amended on Aug. 4, 2020; Sep. 12, 2023>
ADDENDA <Presidential Decree No. 23169, Sep. 29, 2011>
Article 1 (Enforcement date)
This Decree shall enter into force on September 30, 2011; provided, Article 20 and subparagraph 2 (i) of Appendix 2 shall enter into force on March 30, 2012.
Article 2 (Repeal of other Acts)
Article 3 (Transitional measures concerning establishment of master plans and implementation plans)
(1) Notwithstanding Article 11, the Minister of Public Administration and Security shall establish the Master Plan for the period from 2012 to 2014 by December 31, 2011 subject to the deliberation and resolution of the Protection Commission.
(2) Notwithstanding Article 12, the head of a central administrative agency shall submit the implementation plan for the period from 2012 and 2013 according to the relevant Master Plan established under paragraph (1) and submit it to the Protection Commission by February 28, 2012 and establish it by April 30, 2012 subject to the deliberation and resolution of the Protection Commission.
Article 4 (Transitional measures concerning encryption of personal information collected and retained by personal information controllers)
Personal information controllers who have collected and retained personal information as at the time this Decree enters into force shall complete the encryption of the personal information stored in electronic media (including the encryption of personally identifiable information to which Article 21 shall apply mutatis mutandis) pursuant to Article 30 (1) 3 no later than December 31, 2012.
Article 5 (Transitional measures concerning registration of personal information files)
The head of a public institution that operates personal information files as at the time this Decree enters into force (excluding institutions that have already registered personal information files before this Decree enters into force) shall apply for the registration thereof to the Minister of Public Administration and Security pursuant to Article 34 within 60 days from the date this Decree enters into force.
Article 6 (Transitional measures concerning privacy impact assessment)
The head of a public institution operating, or building up to operate, personal information files prescribed in the subparagraphs of Article 35 as at the time this Act enters into force shall conduct a privacy impact assessment of such personal information and submit the result thereof to the Minister of Public Administration and Security within five years from the date this Decree enters into force.
Article 7 Omitted.
Article 8 (Relationship with other statutes or regulations)
A citation of the former Enforcement Decree of the Act on the Protection of Personal Information Maintained by Public Institutions or the provisions thereof in any other Act or subordinate statute as at the time this Decree enters into force shall be deemed a citation of this Decree or the provisions of this Decree in lieu of the former provisions, if corresponding provisions exist herein.
ADDENDA <Presidential Decree No. 24425, Mar. 23, 2013>
Article 1 (Enforcement date)
This Decree shall enter into force on the date of its promulgation; provided, any amendment made by Presidential Decree promulgated before this Act enters into force, but the dates on which such amendment enters into force has yet arrived among the Presidential Decrees amended pursuant to Article 6 of the Addenda shall respectively enter into force on the date such Presidential Decree enters into force.
Articles 2 through 6 Omitted.
ADDENDUM <Presidential Decree No. 25531, Aug. 6, 2014>
This Decree shall enter into force on August 7, 2014.
ADDENDA <Presidential Decree No. 25751, Nov. 19, 2014>
Article 1 (Enforcement date)
This Decree shall enter into force on the date of its promulgation; provided, any amendment made by Presidential Decree promulgated before this Act enters into force, but the dates on which such amendment enters into force has yet arrived among the Presidential Decrees amended pursuant to Article 5 of the Addenda shall respectively enter into force on the date such Presidential Decree enters into force.
Articles 2 through 5 Omitted.
ADDENDA <Presidential Decree No. 25840, Dec. 9, 2014>
Article 1 (Enforcement date)
This Decree shall enter into force on January 1, 2015.
Articles 2 through 16 Omitted.
ADDENDA <Presidential Decree No. 26140, Mar. 11, 2015>
Article 1 (Enforcement date)
This Decree shall enter into force on the date of its promulgation.
Article 2 Omitted.
Article 3 Omitted.
ADDENDUM <Presidential Decree No. 26728, Dec. 22, 2015>
Article 1 (Enforcement date)
This Decree shall enter into force on December 23, 2015.
Article 2 Omitted.
Article 3 Omitted.
ADDENDUM <Presidential Decree No. 26776, Dec. 30, 2015>
This Decree shall enter into force on the date of its promulgation; provided, the amended provisions of Articles 21-2, 62 (2), 62-2 (1) 1, and Appendix 2 shall enter into force on January 1, 2016.
ADDENDA <Presidential Decree No. 27370, Jul. 22, 2016>
Article 1 (Enforcement date)
This Decree shall enter into force on July 25, 2016.
Article 2 (Transitional measures concerning establishment of master plans and implementation plans)
(1) The Master Plan for 2015 to 2017 established pursuant to the former provisions of Article 11 shall be deemed the Master Plan established pursuant to the amended provisions of Article 11.
(2) The implementation plans for 2016 and 2017 established pursuant to the former provisions of Article 12 shall be deemed the implementation plans established pursuant to the amended provisions of Article 12, respectively.
ADDENDUM <Presidential Decree No. 27522, Sep. 29, 2016>
This Decree shall enter into force on September 30, 2016.
ADDENDA <Presidential Decree No. 28074, May 29, 2017>
Article 1 (Enforcement date)
This Decree shall enter into force on May 30, 2017.
Article 2 Omitted.
Article 3 Omitted.
Article 4 Omitted.
ADDENDUM <Presidential Decree No. 28150, Jun. 27, 2017>
Article 1 (Enforcement date)
This Decree shall enter into force on July 1, 2017; provided, the amended provisions of Article 3 of this Addenda shall enter into force on the date of its promulgation.
Article 2 Omitted.
Article 3 Omitted.
ADDENDA <Presidential Decree No. 28211, Jul. 26, 2017>
Article 1 (Enforcement date)
This Decree shall enter into force on the date of its promulgation; provided, any amendment of the Presidential Decrees made pursuant to Article 8 of this Addenda, which were promulgated before this Decree comes into force, but the enforcement date of which has yet to arrive, shall enter into force on the date the corresponding Presidential Decree takes effect.
Articles 2 through 8 Omitted.
ADDENDA <Presidential Decree No. 28355, Oct. 17, 2017>
Article 1 (Enforcement date)
This Decree shall enter into force on October 19, 2017.
Article 2 (Applicability to reporting on data breach notification)
The amended provisions of Articles 39 (1) and 40 (3) shall begin to apply from the first divulgence of any personal information after this Decree enters into force.
Article 3 (Transitional measures concerning request for access to personal information)
Notwithstanding the amended provisions of Articles 41 (1), 43 (1), and 44 (1), a person who has requested access to, correction or erasure, or suspension of processing of, his or her personal information before this Decree enters into force shall be governed by the former provisions.
ADDENDUM <Presidential Decree No. 29421, Dec. 24, 2018>
This Decree shall enter into force on January 1, 2019.
ADDENDUM <Presidential Decree No. 30509, Mar. 3, 2020>
This Decree shall enter into force on the date of its promulgation.
ADDENDUM <Presidential Decree No. 30833, Jul. 14, 2020>
This Decree shall enter into force on July 15, 2020.
ADDENDA <Presidential Decree No. 30892, Aug. 4, 2020. >
Article 1 (Enforcement date)
This Decree shall enter into force on August 5, 2020; provided, the amended provisions of Article 5-3 shall enter into force six months after the date of its promulgation.
Article 2 (General transitional measures)
Before this Decree enters into force, designation, measures, notifications, reports, and other acts performed by Information and Communications service providers, etc. pursuant to the Enforcement Decree of the Act on Promotion of Information and Communications Network Utilization and Information Protection shall be deemed to have been performed in accordance with the provisions of this Decree.
Article 3 (Transitional measures on processing sensitive information)
Personal information that has been lawfully processed pursuant to this Decree or other statutes or regulations before this Decree enters into force and falls under the amended provisions of subparagraphs 3 and 4 of Article 18 shall be deemed to have been processed in accordance with this Decree or other statutes and regulations.
Article 4 (Transitional measures on calculating penalty surcharge)
Administrative dispositions received pursuant to the Act on Promotion of Information and Communications Network Utilization and Information Protection for violations prior to the enforcement of this Decree shall be included in the calculation of the number of violations stipulated in the amended provisions of Appendix 1-5.
Article 5 (Transitional measures on imposing penalty surcharge)
Penalty surcharges imposed pursuant to the Act on Promotion of Information and Communication Network Utilization and Information Protection or the previous provisions for violations prior to the enforcement of this Decree shall be included in the calculation of the number of violations stipulated in the amended provisions of Appendix 2.
Article 6 Omitted
Article 7 (Relationship to other statutes or regulations)
Upon the enforcement of this Decree, if other statutes and regulations in relation to the protection of personal information refer to the Enforcement Decree of the Act on Promotion of Information and Communication Network Utilization and Information Protection or its provisions, and if there are concerning regulations, it shall be deemed that this Decree or the relevant regulations of this Decree was referred in place of the previous regulations.
ADDENDUM <Presidential Decree No. 31429, Feb. 2, 2021>
Article 1 (Enforcement date)
This Decree shall enter into force on February 5, 2021.
Article 2 Omitted.
Article 3 Omitted.
ADDENDUM <Presidential Decree No. 32528, Mar. 8, 2022>
This Decree shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 32813, Jul. 19, 2022>
Article 1 (Enforcement date)
This Decree shall enter into force three months after the date of its promulgation; provided, the amended provisions of Articles 16 (1) and 62 shall enter into force on the date of the promulgation.
Article 2 (Applicability to standards for calculation of penalty surcharge)
The amended provisions of Appendices 1, 1-3 and 1-5 shall also apply to violations committed before this Decree enters into force.
ADDENDA <Presidential Decree No. 33723, Sep. 12, 2023>
Article 1 (Enforcement date)
This Decree shall enter into force on September 15, 2023; provided, the following amended provisions shall enter into force on the date prescribed in the relevant subparagraph:
1. The amended provisions of Articles 17 (1) and 30-2: September 15, 2024;
2. The amended provisions of the latter part of Article 15-2 (1): January 1, 2024;
3. The amended provisions of subparagraph 2 (a), (ac), (ah), (ai), and (al) of Appendix 2: March 15, 2024.
Article 2 (Transitional measures concerning imposition of administrative fines)
Notwithstanding the amended provisions of Appendix 2, the previous provisions shall apply to violations under subparagraph 2 (a), (b), (h), and (al) of the previous Appendix 2 committed before this Decree enters into force.
Article 3 Omitted.
ADDENDA <Presidential Decree No. 34309, Mar. 12, 2024>
Article 1 (Enforcement date)
This Decree shall enter into force on Mar. 15, 2024; Provided, That the amended provisions of Articles 30-2 (1) and 32 (4) 4 of the partially amended Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 33723) shall enter into force on September 15, 2024.
Article 2 (Transitional measures concerning persons responsible for protection of personal information)
(1) Where a personal information controller who has designated a personal information controller pursuant to the previous Article 32 (2) as at the time this Decree enters into force falls under a personal information controller (excluding public system operating agencies) under the amended provisions of Article 32 (4) as at the time this Decree enters into force, he or she shall be deemed to have designated a personal information controller pursuant to Article 32 (3) and (4) and Appendix 1 for two years from the date this Decree enters into force.
(2) Where a personal information controller who has designated a personal information controller pursuant to the previous Article 32 (2) as at the enforcement date pursuant to the proviso of Article 1 of the Addenda falls under a public system operation institution under the amended provisions of Article 32 (4) 4 (limited to where he or she does not fall under a personal information controller pursuant to the amended provisions of subparagraphs 1 through 3 of the same paragraph), he or she shall be deemed to have designated a personal information controller pursuant to Article 32 (3) and (4) and Appendix 1 for two years from the enforcement date pursuant to the proviso of Article 1 of the Addenda.
ADDENDA <Presidential Decree No. 35343, Feb. 25, 2025>
Article 1 (Enforcement date)
This Decree shall enter into force on March 13, 2025; provided, the following amended provisions shall enter into force on the date prescribed in the relevant subparagraph:
1. The amended provisions of Articles 29-4 (2), 42-9 through 42-16, 62 (3), 62-3 (1) 1, 7, and 9, and the provisions, with the exception of the subparagraphs, of paragraph (2) of that Article, subparagraph 1 of that paragraph, and Appendix 1-3: The date of promulgation;
2. The amended provisions of Articles 29-2 (1) and (4) and 62-3 (1) 8: July 1, 2025;
3. The amended provisions of subparagraph 3 of Article 42-2 and Article 42-4 (1) 3: June 1, 2026.
(2) "Date prescribed by Presidential Decree" in subparagraph 2 of Article 1 of the Addenda to the Personal Information Protection Act (Act No. 19234) means March 13, 2025.
Article 2 (Applicability to re-designation of Expert Data Combination Agency)
The amended provisions of Article 29-2 (4) shall begin to apply to applications for an extension of the effective period of designation of an Expert Data Combination Agency after the enforcement date under Article 1 (1) 2 of the Addenda.
Article 3 (Special cases concerning designation of institutions specializing in managing personal information)
A business entity who has obtained a temporary permission or designation of special cases similar thereto pursuant to other statutes or regulations such as Article 37 of the Special Act on Promotion of Information and Communications Technology and Vitalization of Convergence Thereof as at the enforcement date under Article 1 (1) 1 of the Addenda shall be deemed to have been designated as an institution specializing in managing personal information pursuant to the amended provisions of the former part of Article 42-12 (1); provided, it shall meet the requirements for designation under the amended provisions of Article 42-11 and be designated as an institution specializing in managing personal information by the designating authority within 1 year from the enforcement date under Article 1 (1) 1 of the Addenda (where the effective period of a temporary permission, etc. expires before 1 year elapses from the enforcement date under Article 1 (1) 1 of the Addenda, the expiration date of the effective period; hereafter in this Article referred to as “designated effective period”), and a person who fails to obtain designation as an institution specializing in managing personal information by the designating authority within the designated effective period, its designation as an institution specializing in managing personal information shall be deemed revoked on the day following the expiration date of the designated effective period.