South Korea - Personal Data Protection (19234/2023)

Personal Information Protection Act (amendment including provisions on automated decision-making/AI)

개인정보 보호법 (자동화된 의사결정/AI 관련 조항 포함 개정)

South Korea

RAI-KR-NA-PIPAIXX-2023
In Force(In Force)
ActData Protection and PrivacyTransparency and DisclosureGovernance and Oversight
Export PDF

The 14 March 2023 amendment to Korea's Personal Information Protection Act (PIPA) (Act No. 19234) modernised the law to address large-scale data use and AI-driven processing. Key changes include new rights for data subjects against fully automated decisions (explanation, review, and refusal), expanded data portability, strengthened CPO qualifications, and delegation of implementation detail to the Enforcement Decree and PIPC guidance.

Summary

Background and Purpose: The Personal Information Protection Act (PIPA) of the Republic of South Korea underwent a major amendment adopted by the National Assembly on 14 March 2023 (Act No. 19234). The amendment responds to the rapid growth of data-driven services and artificial intelligence (AI) and aims to strike a balance between enabling data use for innovation and strengthening protection of individual rights. Many of the delegated details were implemented through the Enforcement Decree (Presidential Decree No. 34309) and administrative guidance issued by the Personal Information Protection Commission (PIPC).

Automated decision-making and AI-specific provisions: One of the most significant novelties is the formal recognition of data-subject rights in relation to decisions produced by fully automated systems (including AI). The amendment introduces a right for data subjects to request a concise, meaningful explanation or human review of decisions made through a fully automated process that materially affects their rights or obligations; data subjects may also refuse such automated decisions in cases with significant impact. Controllers are required to disclose, in advance (for example through privacy policies), the fact that automated decision-making is used and the criteria and processing procedures that will be applied, in a form that is accessible and intelligible to data subjects.

Data portability and data-subject empowerment: The amendment expands the right to data portability, allowing data subjects to request transmission of their personal information to themselves or to third-party controllers. The Enforcement Decree and subsequent PIPC guidance specify the procedures, formats, permissible limits, and exceptional grounds for refusal or suspension.

Governance, accountability and organisational obligations: The amendment strengthens organisational responsibilities, requiring larger controllers and certain public institutions to appoint Chief Privacy Officers (CPOs) who meet prescribed experience and qualification thresholds (e.g., minimum years of experience). Controllers must adopt internal management plans, implement technical and organisational measures (including de-identification, pseudonymization, access control, and logging), perform privacy impact assessments where appropriate, and keep records of processing.

Cross-border transfers and transparency: The law increases transparency obligations for overseas transfers: privacy notices must indicate the legal basis for transfers, the categories of recipients, and the countries where processing occurs. Administrative guidance and PIPC materials provide practical steps and examples for safe use of publicly available data in AI training, acceptable measures for de-identification, and risk assessment models.

Enforcement and sanctions: The amended regime enhances administrative enforcement powers, emphasizes corrective orders and fines over certain criminal punishments, and grants regulators (notably the PIPC) expanded oversight authority, including privacy-level assessment powers for public institutions and large controllers. The Enforcement Decree sets administrative procedures, thresholds, and timelines for specific provisions.

Regulatory guidance and AI governance: Following the amendment and the Enforcement Decree, the PIPC has published AI-focused materials — including a July 2024 guideline on processing publicly available personal information for AI development and later guidance addressing generative AI and other AI-specific risks — to clarify legal bases (including legitimate interest), de-identification standards, and lifecycle governance practices.

Implications for actors: The amendment creates concrete obligations for controllers, processors, and foreign entities targeting Korean data subjects. It raises compliance costs for AI projects that process personal data at scale, but also provides clearer rules to enable lawful innovation when controllers can demonstrate governance, risk mitigation, and respect for data-subject rights. Data subjects gain strengthened remedies and new practical rights against opaque automated decision-making.

Full article

Read full text ↗

Overview

The March 14, 2023 amendment to the Personal Information Protection Act (PIPA) modernises South Korea's core privacy law to address large-scale data processing and AI-driven automated decision-making. The amendment (Act No. 19234) and its implementing measures (notably the Enforcement Decree and PIPC guidance) create new data-subject rights—including the right to refuse fully automated decisions, and to request explanations or human review—and expand data portability and transparency requirements. The law also ramps up organisational responsibilities (CPO qualification, internal management plans, mandatory security measures) while delegating technical detail and operational rules to the Enforcement Decree and regulatory guidance. Official texts are available from the Korean Law Information Center and the government's privacy portal (see PERSONAL INFORMATION PROTECTION ACT (KLRI)) and implementing decrees at the national law portal (Enforcement Decree (law.go.kr)).

Definitions

PIPA defines key terms relevant to automated decision-making and AI: "personal information" (identifiable natural person data), "sensitive information" (민감정보), "processing" (collection, use, provision, etc.), and for the first time the framework recognises "automated decision" or "fully automated process" meaning a decision that affects a data subject's rights or obligations made by a system operating without substantive human intervention. The Enforcement Decree and PIPC guidance provide interpretive detail about what constitutes 'significant impact,' the scope of automated decision-making, and the boundary between automated and human-in-the-loop systems.

Governance and Institutional Framework

The PIPC remains the principal regulator responsible for supervision, guidance, and enforcement; it has been given expanded powers to assess privacy-management levels of public institutions and large private controllers, and to publish sectoral guidance. Controllers meeting size or processing thresholds must designate a Chief Privacy Officer (CPO) who satisfies qualification criteria; transitional provisions allow a grace period for certain entities to meet the enhanced CPO qualification rules. The government’s privacy portal hosts PIPC guidance documents including the July 2024 "Guideline for Processing Publicly Available Personal Information for AI Development" (see PIPC AI/Public Data Guidance (privacy.go.kr)), and the Enforcement Decree (Presidential Decree No. 34309) sets procedural and threshold rules for implementation.

Key Focus Areas

Automated decision-making: data subjects may request explanations or human review and may refuse fully automated decisions that significantly affect rights/obligations. Controllers must inform subjects when automated decisions will occur and publish decision criteria and processing procedures in accessible formats. Data portability: subjects can request transmission of their data to themselves or third parties; the Decree defines the methods, formats, permissible exceptions and refusal grounds. De-identification & pseudonymization: the amendment strengthens provisions enabling lawful use of de-identified or pseudonymized data for research and AI training while emphasizing technical safeguards and risk assessment. Cross-border transfers & transparency: controllers must disclose the legal basis for overseas transfers and the destination countries. Accountability & security: enhanced internal management plans, privacy impact assessments, access controls, and logging are required for entities processing significant volumes of personal or sensitive information.

Implementation Framework

Implementation is staged and partly delegated: many amendment provisions were effective on 15 September 2023, while the provisions on automated decision-making, data portability and certain technical/delegated matters became effective on 15 March 2024 with enactment of the Enforcement Decree (see KLRI e-book record). The Enforcement Decree establishes numeric thresholds (e.g., daily averages of subject counts), methods for notification, procedures for refusal/review requests related to automated decisions, and transitional measures for CPO qualification. The PIPC has issued practical guidance and templates to support compliance and to interpret delegated rules.

Monitoring and Evaluation

The PIPC is authorised to conduct privacy-level assessments for public institutions and large controllers, to require corrective measures, and to publish guidance and assessment outcomes. The law and Decree mandate recordkeeping and periodic internal reviews; PIPC guidance recommends privacy impact assessments (PIAs) and risk-model frameworks for AI projects and suggests periodic re-evaluation of deployed models to monitor accuracy, bias, and security risks such as model inversion or data leakage.

Penalties, Liability, and Appeals

The amended PIPA strengthens administrative enforcement and emphasizes corrective powers, administrative fines, and remedial orders for violations; it also clarifies liability for misuse of personal data in automated decision contexts. The regime focuses on proportionate administrative penalties and remediation, though criminal sanctions may remain for specific offences. Affected entities retain rights of appeal against administrative orders to administrative courts; the PIPC’s procedural rules and the Enforcement Decree set detailed timelines and remedy mechanisms.

Relationship to Other Instruments

PIPA interacts with sectoral laws (e.g., Act on Promotion of Information and Communications Network Utilization, Medical Services Act, Financial sector AI guidance) and international rules. The PIPC’s AI-specific guidance and industry-specific regulators’ rules (e.g., Financial Services Commission guidance) operationalise sectoral expectations. The amendment anticipates future related legislation such as South Korea’s AI Basic Act and complements standards for data protection and model safety.

International Alignment

South Korea’s amendments borrow concepts similar to other modern privacy regimes—data portability and protections against fully automated decisions comparable to the EU's GDPR—while tailoring rules to local administrative structures and innovation policy. PIPC guidance explicitly references international good practices and seeks interoperability for cross-border data flows, while establishing South Korea-specific thresholds and administrative procedures to govern foreign entities targeting Korean data subjects (see PIPC materials on foreign controllers).

Implementation Timeline

EventDate
National Assembly adoption (Act No. 19234)2023-03-14
Partial provisions effective (first tranche)2023-09-15
Enforcement Decree published (Presidential Decree No. 34309) and automated decision/data portability effective2024-03-15
Additional delegated measures, guidance and PIPC guidelines (AI/public data guidance)2024-07-17 (guideline published)

Sources and References

SourceType
PERSONAL INFORMATION PROTECTION ACT (KLRI) — Act No. 19234 (2023)Primary Source
Enforcement Decree (Presidential Decree No. 34309) — law.go.krPrimary Source
PIPC: Guideline for Processing Publicly Available Personal Information for AI Development (2024.7)Primary Source

Requirements for a company

What an organisation has to do under South Korea - Personal Data Protection (19234/2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

13
  • Inform data subjects when fully automated decisions will occur.Controllers making fully automated decisions that significantly affect rights.
  • Publish decision criteria and processing procedures for automated decisions in accessible formats.Controllers making fully automated decisions that significantly affect rights.
  • Provide explanations for fully automated decisions upon data subject request.Controllers making fully automated decisions that significantly affect rights.
  • Allow data subjects to request human review of fully automated decisions.Controllers making fully automated decisions that significantly affect rights.
  • Enable data subjects to request transmission of their data to themselves or third parties.Controllers processing personal information.
  • Adopt defined methods and formats for data portability requests.Controllers processing personal information.
  • +7 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Periodically re-evaluate deployed AI models for accuracy, bias, and security risks.Controllers deploying AI models.

Should not do

0

Nothing in this category.

Who must do what

The obligations under South Korea - Personal Data Protection (19234/2023), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Controllers making fully automated decisions that significantly affect rights.Inform data subjects when fully automated decisions will occur.
Controllers must inform subjects when automated decisions will occur.
Mar 15, 2024Critical
2Controllers making fully automated decisions that significantly affect rights.Publish decision criteria and processing procedures for automated decisions in accessible formats.
publish decision criteria and processing procedures in accessible formats.
Mar 15, 2024Critical
3Controllers making fully automated decisions that significantly affect rights.Provide explanations for fully automated decisions upon data subject request.
data subjects may request explanations or human review and may refuse fully automated decisions.
Mar 15, 2024Critical
4Controllers making fully automated decisions that significantly affect rights.Allow data subjects to request human review of fully automated decisions.
data subjects may request explanations or human review and may refuse fully automated decisions.
Mar 15, 2024Critical
5Controllers processing personal information.Enable data subjects to request transmission of their data to themselves or third parties.
subjects can request transmission of their data to themselves or third parties.
Mar 15, 2024Critical
6Controllers processing personal information.Adopt defined methods and formats for data portability requests.
the Decree defines the methods, formats, permissible exceptions and refusal grounds.
Mar 15, 2024Critical
7Controllers meeting size or processing thresholds.Designate a Chief Privacy Officer (CPO) who meets qualification criteria.
Controllers meeting size or processing thresholds must designate a Chief Privacy Officer (CPO) who satisfies qualification criteria.
Critical
8Entities processing significant volumes of personal or sensitive information.Implement enhanced internal management plans for personal and sensitive information.
enhanced internal management plans... are required for entities processing significant volumes of personal or sensitive information.
Sep 15, 2023Critical
9Entities processing significant volumes of personal or sensitive information.Conduct privacy impact assessments (PIAs) for significant processing activities.
privacy impact assessments... are required for entities processing significant volumes of personal or sensitive information.
Sep 15, 2023Critical
10Entities processing significant volumes of personal or sensitive information.Implement access controls and maintain logging for personal and sensitive information.
access controls, and logging are required for entities processing significant volumes of personal or sensitive information.
Sep 15, 2023Critical
11Controllers using de-identified or pseudonymized data for research and AI training.Implement technical safeguards and risk assessment for de-identified or pseudonymized data.
emphasizing technical safeguards and risk assessment
Sep 15, 2023Critical
12Controllers transferring personal data across borders.Disclose the legal basis and destination countries for overseas personal data transfers.
controllers must disclose the legal basis for overseas transfers and the destination countries.
Sep 15, 2023Critical
13All controllers.Maintain records and conduct periodic internal reviews as mandated by law.
The law and Decree mandate recordkeeping and periodic internal reviews.
Sep 15, 2023Important
14Controllers deploying AI models.Periodically re-evaluate deployed AI models for accuracy, bias, and security risks.
PIPC guidance suggests periodic re-evaluation of deployed models to monitor accuracy, bias, and security risks.
Recommended

© Regulations.AI · updated on 13-Jun-2026