South Korea - Automated Decision Rights Guide

Automated Decision Rights Guide

자동화된 결정에 대한 정보주체의 권리 안내서

South Korea

RAI-KR-NA-ADRGPXX-2024
Adopted(Adopted)
GuidelineData Protection and PrivacyGovernance and OversightRisk Management
Export PDF

The Personal Information Protection Commission (PIPC) of the Republic of Korea published the "Automated Decision Rights Guide" in September 2024 to explain new legal rights and controller obligations introduced by the 2024 amendments to the Personal Information Protection Act. The guide clarifies the scope of "automated decisions," the information subject's rights (refusal, explanation, and corrective measures), and recommended compliance steps and examples for public and private sector actors.

Summary

The "Automated Decision Rights Guide" (Automated Decision Rights Guide (자동화된 결정에 대한 정보주체의 권리 안내서), PIPC, 2024.9) is an explanatory framework document published by the Personal Information Protection Commission of South Korea to support implementation of amendments to the Personal Information Protection Act that introduced explicit rights for data subjects with respect to automated decision-making. The guide complements statutory provisions (notably the newly added automated decision provisions in the Act and associated enforcement decrees and subordinate rules) by: (1) defining the scope of "automated decision" and providing concrete case examples; (2) setting out the rights available to information subjects (including the right to refuse a decision based solely on automated processing resulting in significant adverse effects, the right to request an explanation, and remedies where errors or discrimination occur); (3) detailing the procedural and technical measures data controllers should adopt when deploying automated decision systems, such as documentation, human oversight, risk assessment, transparency disclosures and mechanisms for review and appeal; (4) providing practical compliance checklists and model workflows which illustrate how controllers and processors should respond to data subject requests and implement safeguards; and (5) explaining enforcement approaches and potential sanctions under the Personal Information Protection Act and related measures.

The guide is explicitly practice-oriented: it includes illustrative scenarios across sectors (e.g., credit scoring, employment screening, healthcare triage, public benefits, and law enforcement-adjacent uses) to clarify when an automated decision triggers legal obligations. It emphasizes proportionality and human oversight for decisions that have significant or legal effects on individuals, recommends impact assessments and monitoring practices, and promotes transparency by advising clear pre-notification and post-decision explanations to affected individuals. The document also describes interaction with related legal instruments (the Personal Information Protection Act, enforcement decrees and PIPC notices/guidelines) and supports harmonization with international norms by referencing comparable concepts (e.g., EU GDPR automated decision provisions) while reflecting Korean law specifics.

For practitioners, the guide prescribes concrete administrative steps: maintain auditable records of model inputs and decisions, design channels for information subjects to exercise their rights, implement technical measures to enable human review and correction, and run testing and evaluation to detect bias, safety and cybersecurity risks. It also outlines supervisory expectations for organizations in demonstrating compliance (documentation, staff training, periodic review) and summarizes enforcement levers available to authorities (administrative corrective orders, fines, public disclosure of violations). The guide is intended for use by private-sector controllers, public agencies, legal and compliance officers, data protection officers, and IT/security teams engaged in the design, procurement or operation of automated decision systems. The guide was published as part of a staged implementation following the 2024 statutory amendments and after public consultation on a draft released in May 2024.

Full article

Read full text ↗

Overview

The "Automated Decision Rights Guide" is a practice-oriented explanatory document published by the Personal Information Protection Commission (PIPC) in September 2024 to assist controllers, processors and other stakeholders in implementing rights and obligations introduced by the 2024 amendments to South Korea's Personal Information Protection Act. The guide provides definitions, scope guidance, sectoral examples, and step-by-step compliance recommendations to help organizations identify when automated decision protections apply and how to operationalize them. It is available from the PIPC and the national privacy portal; the primary publication page is hosted on the Government Privacy Portal and PIPC websites (Privacy Portal - Automated Decision Rights Guide (2024.9)) and is intended to be read alongside the statutory text and subordinate measures published by the PIPC.

Definitions

The guide defines key terms used throughout the document, including "automated decision" (decisions made wholly or substantially through algorithmic or automated processing without meaningful human intervention that produce legal or similarly significant effects for individuals), "significant adverse effect" (effects on legal status, access to services, employment, credit, benefits, or other materially consequential outcomes), "information subject" (the data subject whose personal data is processed), and "personal information controller/processor" (entities that determine purposes and means or process on behalf of controllers). The definitions align with the amended Personal Information Protection Act while clarifying borderline cases, for example hybrid systems with human-in-the-loop and human-on-the-loop arrangements that may or may not trigger the automated decision-specific obligations.

Governance and Institutional Framework

The guide sets roles and responsibilities within organizations for governance of automated decision systems. It recommends that controllers assign clear internal ownership (e.g., privacy officer/CPO, compliance lead, security lead and an AI governance committee) and document decision authority. The PIPC expects organizations to maintain records of automated decision systems and to conduct internal review before deployment; this includes performing privacy impact assessments and risk assessments. The guide also explains the PIPC's institutional role in supervision and guidance: PIPC issues explanatory materials, runs consultations, and provides channels for reporting and dispute resolution. The guide references the PIPC web portal and notices (Personal Information Protection Commission) for further regulatory instruments and clarifications.

Key Focus Areas

The guide organizes compliance around a set of core focus areas: (1) Scope and Identification — determining whether a given system constitutes an automated decision under the law; (2) Transparency and Pre-notification — informing individuals when automated decision-making is used and what data/logic influences decisions; (3) Rights and Remedies — procedural steps to allow data subjects to refuse, request explanation, seek review, and request correction; (4) Human Oversight and Review — defining human intervention points and responsibilities for review outcomes; (5) Risk Management — conducting algorithmic impact assessments to assess discrimination, fairness, and accuracy risks; (6) Documentation and Accountability — maintaining model cards, data lineage logs, and audit trails; (7) Testing, Validation and Monitoring — pre-deployment evaluation and ongoing monitoring for performance drift and bias; and (8) Security and Data Governance — protecting model inputs, outputs and training data from unauthorized access and ensuring data minimization. The guide provides examples for each focus area and suggests scalable measures for small and large organizations while emphasizing that measures should be proportionate to the risk posed by the decision's consequences.

Implementation Framework

The implementation section outlines a stepwise approach: identification and inventory (catalog automated decision systems), risk assessment (classify systems by potential harm and sensitivity), design controls (transparency mechanisms, human review protocols, appeal processes), technical safeguards (logging, versioning, access controls, explainability tooling), test & validate (bias testing, accuracy assessments, cybersecurity checks), operationalize (service-level procedures for exercising rights and responding to incidents), and governance (periodic audits, training, third-party oversight). The guide also provides sample templates for impact assessments, decision documentation, and information subject notices. It emphasizes contractual controls for third-party vendors, including audit rights and specific obligations for suppliers of AI models and decisioning platforms.

Monitoring and Evaluation

Monitoring expectations include continuous performance tracking, periodic re-validation for models in production, and maintenance of auditable logs that support ex-post review. The guide recommends key performance indicators (e.g., false positive/negative rates by protected class, decision latency, appeal outcomes) and describes how to run periodic sampling and red-teaming exercises to detect emerging risks. It instructs organizations on incident reporting procedures and encourages proactive engagement with the PIPC when systemic problems arise. The guide also sets out expectations for transparency reporting to regulators and recommends public-facing summaries for high-impact systems to aid accountability.

Penalties, Liability, and Appeals

The guide explains that non-compliance with statutory automated decision provisions may trigger the enforcement regime under the Personal Information Protection Act, including administrative corrective orders, fines, criminal penalties in applicable cases, and public disclosure of sanctions. It clarifies procedural rights for information subjects to appeal decisions internally, escalate to supervisory authorities, or pursue remedies through dispute resolution channels. The guide provides a flowchart for appeal handling and recommends a timeline for controllers to respond to information subject requests consistent with statutory response deadlines. Liability considerations for controllers and processors are discussed, with guidance on indemnity and contractual allocation of risk for third-party AI vendors.

Relationship to Other Instruments

The guide situates automated decision obligations within South Korea's broader privacy framework: it references the Personal Information Protection Act amendments (which introduced the explicit automated decision protections), related enforcement decrees and subordinate rules, PIPC notices and guidelines on privacy management, and sectoral rules (e.g., financial regulators' guidance on credit scoring, healthcare data rules). It clarifies overlaps and differences with related obligations such as data minimization, purpose limitation, and special protections for sensitive information. The guide advises organizations to coordinate compliance with sector-specific regulators when automated decisions intersect regulated activities.

International Alignment

Recognizing the transnational nature of AI systems, the guide compares Korean automated decision protections with international approaches (notably the EU GDPR automated decision provisions) and highlights compatibility points and differences. It recommends adopting internationally recognized technical standards for testing and explainability where appropriate and encourages cross-border cooperation and information sharing with foreign supervisory authorities. The guide also notes that controllers operating across jurisdictions should map obligations and apply the most protective measures where necessary.

Implementation Timeline

MilestoneDate
Draft guide published for consultation2024-05-24
Public consultation period (deadline for comments)2024-06-21
Final guide published (PIPC)2024-09 (published)
Posted to Privacy Portal2024-10-21

Sources and References

SourceType
Automated Decision Rights Guide (2024.9.) — Privacy Portal (PIPC)Primary Source
Personal Information Protection Commission (PIPC) official sitePrimary Source

Requirements for a company

What an organisation has to do under South Korea - Automated Decision Rights Guide, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.

Must do

13
  • Inform individuals when automated decision-making is used and what data influences decisions.Personal information controllers using automated decision systems.
  • Enable individuals to refuse automated decisions that produce legal or significant effects.Personal information controllers using automated decision systems.
  • Provide clear explanations for automated decisions upon an individual's request.Personal information controllers using automated decision systems.
  • Allow individuals to seek review and request correction of automated decisions affecting them.Personal information controllers using automated decision systems.
  • Respond to information subject requests regarding automated decisions within statutory deadlines.Personal information controllers.
  • Assign clear internal ownership and document decision authority for automated decision systems.Personal information controllers.
  • +7 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under South Korea - Automated Decision Rights Guide, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Personal information controllers using automated decision systems.Inform individuals when automated decision-making is used and what data influences decisions.
Transparency and Pre-notification — informing individuals when automated decision-making is used and what data/logic influences decisions
Before making automated decisionsKey Focus AreasCritical
2Personal information controllers using automated decision systems.Enable individuals to refuse automated decisions that produce legal or significant effects.
Rights and Remedies — procedural steps to allow data subjects to refuse, request explanation, seek review, and request correction
Before making automated decisionsKey Focus AreasCritical
3Personal information controllers using automated decision systems.Provide clear explanations for automated decisions upon an individual's request.
Rights and Remedies — procedural steps to allow data subjects to refuse, request explanation, seek review, and request correction
Upon requestKey Focus AreasCritical
4Personal information controllers using automated decision systems.Allow individuals to seek review and request correction of automated decisions affecting them.
Rights and Remedies — procedural steps to allow data subjects to refuse, request explanation, seek review, and request correction
Upon requestKey Focus AreasCritical
5Personal information controllers.Respond to information subject requests regarding automated decisions within statutory deadlines.
recommends a timeline for controllers to respond to information subject requests consistent with statutory response deadlines.
Consistent with statutory response deadlinesPenalties, Liability, and AppealsCritical
6Personal information controllers.Assign clear internal ownership and document decision authority for automated decision systems.
recommends that controllers assign clear internal ownership (e.g., privacy officer/CPO, compliance lead...) and document decision authority.
Before deploymentGovernance and Institutional FrameworkImportant
7Personal information controllers.Maintain records of all automated decision systems in use.
The PIPC expects organizations to maintain records of automated decision systems and to conduct internal review before deployment
OngoingGovernance and Institutional FrameworkImportant
8Personal information controllers.Conduct privacy impact assessments and risk assessments before deploying automated decision systems.
this includes performing privacy impact assessments and risk assessments.
Before deploymentGovernance and Institutional FrameworkImportant
9Personal information controllers.Design and implement human oversight mechanisms and intervention points for automated decisions.
Human Oversight and Review — defining human intervention points and responsibilities for review outcomes
Before deploymentKey Focus AreasImportant
10Personal information controllers.Maintain comprehensive documentation, including model cards, data lineage logs, and audit trails.
Documentation and Accountability — maintaining model cards, data lineage logs, and audit trails
OngoingKey Focus AreasImportant
11Personal information controllers.Perform pre-deployment testing and ongoing monitoring for performance drift and bias in automated systems.
Testing, Validation and Monitoring — pre-deployment evaluation and ongoing monitoring for performance drift and bias
Before deployment and ongoingKey Focus AreasImportant
12Personal information controllers engaging third-party AI vendors.Implement contractual controls, including audit rights, for third-party vendors supplying AI models or decisioning platforms.
emphasizes contractual controls for third-party vendors, including audit rights and specific obligations for suppliers of AI models
Before engaging vendorsImplementation FrameworkImportant
13Personal information controllers.Establish incident reporting procedures and proactively engage with the PIPC when systemic problems arise.
It instructs organizations on incident reporting procedures and encourages proactive engagement with the PIPC when systemic problems arise.
OngoingMonitoring and EvaluationImportant

© Regulations.AI · updated on 13-Jun-2026