South Korea - AI Impact Assessment

Notice on Personal Information Impact Assessment

개인정보 영향평가에 관한 고시

South Korea

RAI-KR-NA-NPIIAXX-2025
Possible change, not yet verified. An automated check on September 7, 2026 read an official page suggesting that this instrument may now be In Force (Amended). We could not confirm it. The status shown is the last verified. Source page. If you know this instrument, use “Report an issue” to confirm or correct it.
In Force(In Force)
RegulationData Protection and PrivacyRisk Management
Export PDF

In September 2025 the Personal Information Protection Commission (PIPC) of Korea amended the "Notice on Personal Information Impact Assessment" to add AI-specific assessment subfields and concrete evaluation criteria for public institutions. The amendment (decided 3 September 2025, effective 5 September 2025) requires public sector projects using AI to assess training-data management, legal basis, responsibilities between developers/operators, AUPs for generative AI, reporting mechanisms and other mitigation measures prior to deployment.

Summary

Background and purpose: The Personal Information Protection Commission (PIPC) of the Republic of South Korea adopted an amendment to the "Notice on Personal Information Impact Assessment (개인정보 영향평가에 관한 고시)" in early September 2025 and put it into effect on 5 September 2025. The change was driven by rapid public-sector adoption of AI systems and a recognition that the existing impact-assessment framework lacked AI-specific guidance. Before the amendment, public institutions were required to carry out privacy impact assessments (PIAs) for large-scale or sensitive personal-data processing projects, but AI projects had to devise bespoke questions without standardised criteria. The 2025 amendment therefore creates clear AI-focused subfields, evaluation items and procedural clarifications to ensure privacy, security and fundamental-rights protections for AI uses in public services.

Key elements: The amendment adds two explicit AI-related subfields to the PIA framework: (1) "AI system learning and development" and (2) "AI system operation and management." For the learning & development phase the new notice requires evaluators to verify the presence of a lawful legal basis for processing; to ensure that sensitive personal data (including unique identifiers, biometric data, health data and data concerning children under 14) is not included unnecessarily in training sets; and to confirm explicit retention and destruction policies for training data and recorded datasets. For the operation & management phase the notice establishes evaluation points that include: clear allocation of responsibilities between developers and operators; acceptable-use policies (AUPs) for generative AI offerings; mechanisms to receive, escalate and remediate reports of inappropriate outputs (including so-called "hallucinations") or inadvertent disclosure of personal data; and testing and monitoring programs to detect leaks, bias and performance drift.

Procedures and enforcement: The amended notice integrates the AI subfields into the existing PIA submission, evaluation and publication process that applies to public institutions meeting statutory thresholds (e.g., processing of sensitive/unique-identifier data for 50,000 or more data subjects; linkage involving 500,000+ data subjects; or 1,000,000+ data subjects overall). Public institutions must include AI-focused assessment items in PIA reports and ensure that short summary reports are submitted to the PIPC and (where required) publicly disclosed. The notice also aligns PIA obligations with existing administrative penalties under the Personal Information Protection Act and related subordinate rules: failure to perform required impact assessments or to submit results can trigger fines or administrative sanctions (the PIPC has previously indicated administrative fines up to KRW 30,000,000 for failure to perform/submit assessments under relevant statutes), and the notice clarifies remedial timelines and monitoring expectations.

Support and guidance: The PIPC published the amendment through its public press channels and indicated that a revised "Impact Assessment Implementation Guide" (영향평가 수행안내서) and practical examples will be made available on the Personal Information Portal to help public agencies and evaluators operationalize the new AI items. The PIPC also signalled that the new criteria are meant as a benchmark that private-sector entities may voluntarily follow to strengthen their own PIA practice for AI.

Implications: The amendment narrows regulatory uncertainty for public-sector AI projects by providing structured evaluation questions spanning data collection, retention, annotation, model training, access control, developer/operator responsibilities, user-facing safeguards and reporting. It also tightens the link between PIA findings and operational controls (security, data-minimisation, redress mechanisms) and creates a more standardised basis for audits, transparency reporting and cross-agency compliance reviews. Additionally, the new criteria reflect international trends (e.g., EU AI Act risk categorisations and DPIA/FRIA concepts) and signal South Korea's intent to harmonize privacy and AI governance in public services while protecting fundamental rights.

Full article

Read full text ↗

Overview

The Personal Information Protection Commission (PIPC) adopted an amendment to the "Notice on Personal Information Impact Assessment (개인정보 영향평가에 관한 고시)" which took effect on 5 September 2025. The amendment creates two AI-specific subfields — "AI system learning and development" and "AI system operation and management" — and prescribes concrete evaluation items for public institutions using AI. The PIPC press announcement summarising the decision is available at PIPC press release (Korean) — 3 Sep 2025, and additional background and guidance materials (including the revised Impact Assessment Implementation Guide) are published on the Personal Information Portal at Privacy Portal — Impact Assessment materials.

Definitions

The amendment reuses and expands existing PIA terminology. Key definitions include: "AI system learning and development" (activities to collect, label, preprocess, store and use personal data for model training and testing); "AI system operation and management" (deployment, monitoring, update, user interaction and incident-handling for operational models); "training data retention policy" (documented retention and deletion rules for datasets used in AI development); "acceptable use policy (AUP)" (enumerated prohibited/allowed uses and foreseeable misuse for generative AI services); and "information subject safeguards" (mechanisms for reporting errors, requesting deletion, or contesting automated decisions). The notice continues to rely on thresholds and terminologies defined in the Personal Information Protection Act and prior PIPC guidance.

Governance and Institutional Framework

The amendment places new responsibilities on the governance structures of public institutions. Agencies must: designate accountable officers for AI data governance (often the existing Personal Information Protection Officer or a named AI data protection lead); document the split of responsibilities between model developers, third-party vendors and service operators; and ensure PIA-certified personnel or accredited assessment teams conduct the AI sections of impact assessments. The PIPC indicated it will update designation criteria for authorised evaluation bodies and expedite timelines for short-term corrective measures; see the PIPC announcement for planned procedural changes at PIPC - prior PIA authority update (Oct 2024/2025 discussion). The amendment also ties PIA performance to transparency obligations (summary publication) and to corrective timelines when remediation items are categorized as short-term.

Key Focus Areas

The AI-specific evaluation criteria concentrate on several areas: (1) Legal basis and purpose limitation — confirming that AI training and inference processing have valid legal grounds under Korean law; (2) Data minimisation and sensitivity — ensuring that sensitive personal information and data on children under 14 are not present in training sets unless strictly necessary and authorised; (3) Training-data lifecycle management — requiring explicit retention, access-control and secure deletion rules for datasets used for model training and evaluation; (4) Model testing and safety — requiring pre-deployment safety testing for leakage, privacy attacks, bias and harmful outputs, together with test documentation and performance metrics; (5) Operation & management responsibilities — explicit contractual and operational liability delineation between developers, vendors and agency operators; (6) User-facing safeguards — acceptable use policies (AUPs), explicit user notices for AI-driven services, and reporting/appeals channels for problematic outputs; (7) Incident management — plan for detection, notification and remediation of privacy incidents arising from AI outputs; and (8) Monitoring and drift detection — post-deployment monitoring to detect data or concept drift and to re-run safety evaluations when model inputs or outputs materially change. These items reflect the PIPC's objective to integrate privacy-by-design throughout the AI lifecycle.

Implementation Framework

Public institutions that meet statutory thresholds (e.g., processing of sensitive or unique-identifier personal data for 50,000+ individuals, linkage involving 500,000+, or 1,000,000+ total personal data entries) must: incorporate the AI subfields into their standard PIA checklist; prepare a PIA report with AI-specific sections (learning/development and operation/management); submit required summaries and full assessments to the PIPC where applicable; appoint qualified evaluators (in accordance with the PIPC's rules for certified impact-assessment practitioners); and implement remediation measures following the prioritisation indicated in the PIA. The PIPC announced that an updated "Impact Assessment Implementation Guide" and case examples will be published to assist agencies in operationalising the new items — see the Privacy Portal listing for the guide at Privacy Portal — guide files.

Monitoring and Evaluation

The PIPC expects agencies to conduct ongoing monitoring for AI-driven systems and to report significant PIA findings or incidents. Monitoring includes scheduled re-assessments when training data or model architectures change materially, continuous logging and audit trails of model inputs/outputs for forensic purposes, and metrics for fairness, accuracy and privacy leakage. The PIPC also indicated that summary publication performance will be considered in future public-sector privacy-level assessments and audits. Where remediation items are identified, agencies must meet tightened timelines for short-term measures and submit implementation evidence to the PIPC as specified in the notice and the related guidance.

Penalties, Liability, and Appeals

The amendment does not create a new punitive regime but clarifies obligations that tie into existing enforcement tools under the Personal Information Protection Act and subordinate rules. Failure to perform a required impact assessment or to submit results can trigger administrative fines and corrective orders (the PIPC has referenced administrative penalties up to KRW 30,000,000 in past enforcement notices for failure to perform or submit required impact assessments under statutory authority). Agencies may also be subject to further administrative sanctions, mandatory remediation orders and public disclosure of non-compliance. The notice also emphasises the need to record remedial steps and maintain documentation for potential appeals or dispute resolution.

Relationship to Other Instruments

The AI-specific PIA criteria are explicitly linked to the Personal Information Protection Act, the PIPC's "Impact Assessment Implementation Guide" and other PIPC guidance documents (for example, guidance on processing publicly available data for AI). The amendment complements the PIPC's earlier guidance on pseudonymisation, automated decision-making and safety measures, and is intended to be used together with technical security standards (e.g., ISMS-P) and sector-specific rules. Cross-references to other PIPC materials and the Personal Information Portal ensure that PIAs remain harmonised with wider privacy obligations and technical controls.

International Alignment

The PIPC framed the amendment to reflect international best practices: it mirrors the concept of DPIA/FRIA for risky AI systems that appears in the EU AI Act and other jurisdictions' emerging AI governance approaches. The criteria on testing, minimisation, transparency and remedial channels aim to facilitate interoperability with international standards and cross-border cooperation. The PIPC's public materials emphasise participation in international forums (e.g., GPA) and coordination with other DPAs to align surveillance, enforcement and guidance practices; see the PIPC English portal for international engagement details at PIPC English site.

Implementation Timeline

EventDate
PIPC decision (Plenary meeting)2025-09-03
PIPC press release2025-09-04
Amendment effective date (enforcement)2025-09-05
Public availability of revised Implementation Guide (expected)Q4 2025 (guidance release/illustrative examples)

Sources and References

SourceType
PIPC — Press release: Amendment to "Notice on Personal Information Impact Assessment" (3 Sep 2025)Primary Source
Personal Information Portal — Impact Assessment Implementation Guide and related materials (Privacy Portal)Primary Source (Guidance)
ETNews — Coverage: PIPC sets criteria for AI use in public institutions (4 Sep 2025)Secondary Source

Requirements for a company

What an organisation has to do under South Korea - AI Impact Assessment, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

15
  • Incorporate AI-specific subfields into the standard Personal Information Impact Assessment checklist.Public institutions meeting statutory PIA thresholds for AI projects.
  • Prepare a Personal Information Impact Assessment report including AI-specific learning/development and operation/management sections.Public institutions meeting statutory PIA thresholds for AI projects.
  • Submit required Personal Information Impact Assessment summaries and full assessments to the PIPC.Public institutions meeting statutory PIA thresholds for AI projects.
  • Implement remediation measures identified in the Personal Information Impact Assessment, adhering to prioritised timelines.Public institutions conducting Personal Information Impact Assessments.
  • Confirm a valid legal basis and purpose limitation for all AI training and inference processing activities.Public institutions using AI systems.
  • Ensure sensitive personal information and children's data are excluded from AI training sets unless strictly necessary and authorised.Public institutions using AI systems.
  • +9 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under South Korea - AI Impact Assessment, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Public institutions meeting statutory PIA thresholds for AI projects.Incorporate AI-specific subfields into the standard Personal Information Impact Assessment checklist.
incorporate the AI subfields into their standard PIA checklist
Sep 5, 2025Critical
2Public institutions meeting statutory PIA thresholds for AI projects.Prepare a Personal Information Impact Assessment report including AI-specific learning/development and operation/management sections.
prepare a PIA report with AI-specific sections (learning/development and operation/management)
Before deploymentCritical
3Public institutions meeting statutory PIA thresholds for AI projects.Submit required Personal Information Impact Assessment summaries and full assessments to the PIPC.
submit required summaries and full assessments to the PIPC where applicable
Before deploymentCritical
4Public institutions conducting Personal Information Impact Assessments.Implement remediation measures identified in the Personal Information Impact Assessment, adhering to prioritised timelines.
implement remediation measures following the prioritisation indicated in the PIA.
As specified in PIACritical
5Public institutions using AI systems.Confirm a valid legal basis and purpose limitation for all AI training and inference processing activities.
confirming that AI training and inference processing have valid legal grounds under Korean law
Before deploymentCritical
6Public institutions using AI systems.Ensure sensitive personal information and children's data are excluded from AI training sets unless strictly necessary and authorised.
ensuring that sensitive personal information and data on children under 14 are not present in training sets unless strictly necessary and authorised
Before deploymentCritical
7Public institutions deploying AI systems.Conduct pre-deployment safety testing for AI models, covering leakage, privacy attacks, bias, and harmful outputs.
requiring pre-deployment safety testing for leakage, privacy attacks, bias and harmful outputs
Before deploymentCritical
8Public institutions using AI systems.Designate an accountable officer responsible for AI data governance within the institution.
designate accountable officers for AI data governance
Sep 5, 2025Important
9Public institutions using AI systems.Document the split of responsibilities between model developers, third-party vendors, and service operators for AI systems.
document the split of responsibilities between model developers, third-party vendors and service operators
Before deploymentImportant
10Public institutions using AI systems.Establish explicit retention, access-control, and secure deletion rules for datasets used in AI model training and evaluation.
requiring explicit retention, access-control and secure deletion rules for datasets used for model training and evaluation
Before deploymentImportant
11Public institutions operating AI-driven services.Publish acceptable use policies (AUPs) and explicit user notices for AI-driven services.
acceptable use policies (AUPs), explicit user notices for AI-driven services
Before deploymentImportant
12Public institutions operating AI-driven services.Implement reporting and appeals channels for users to address problematic outputs or contest automated decisions from AI services.
reporting/appeals channels for problematic outputs
Before deploymentImportant
13Public institutions operating AI systems.Develop a plan for detection, notification, and remediation of privacy incidents arising from AI outputs.
plan for detection, notification and remediation of privacy incidents arising from AI outputs
Before deploymentImportant
14Public institutions operating AI systems.Implement post-deployment monitoring to detect data or concept drift and re-run safety evaluations for AI systems.
post-deployment monitoring to detect data or concept drift
After deploymentImportant
15Public institutions operating AI systems.Conduct scheduled re-assessments of AI systems when training data or model architectures change materially.
scheduled re-assessments when training data or model architectures change materially
When changes occurImportant

© Regulations.AI · updated on 13-Jun-2026