SOUTH KOREA Law and Practice Contributed by: Heejun Choi, Kyoung-Ho Kim, Sungsok Yang, Eunjee Kim and Kwang-Chun Park, Dentons Lee
that process personal information for business pur - poses. PIPA protects information relating to an identified or identifiable living individual, including information identifiable in combination with other data. Sensitive information, including health, political opinions, trade union membership and genetic information, receives enhanced protection. PIPA adopts a consent- and purpose-based frame - work. Personal information may generally be collected and used only for the notified purpose unless another statutory basis applies. It also regulates third-party provision, outsourcing, cross-border transfers, reten - tion, destruction and the processing of sensitive or unique identifying information. Data controllers must maintain a privacy policy, appoint a privacy officer where required, implement appropriate technical, administrative and physi - cal safeguards and respond to data subject rights, including access, correction, deletion and suspension of processing. The Act on Promotion of Information and Communica - tions Network Utilisation and Information Protection (“Network Act”) remains relevant to information secu - rity, cybersecurity and network protection, although most of its personal information provisions have been incorporated into PIPA. Sector-specific legislation may also apply, including the Credit Information Act, the Location Information Act, the Medical Service Act and legislation govern - ing telecommunications, electronic finance and pub - lic-sector data. Certain commercially valuable data assets are also receiving protection under the Data Industry Promotion and Utilisation Act and the Unfair Competition Prevention and Trade Secret Protection Act. The principal regulator is the Personal Information Protection Commission (“PIPC”), which has inves - tigative and enforcement powers, including correc - tive orders, administrative fines, penalty surcharges, criminal referrals and civil enforcement. Data subjects
may also seek relief through litigation or the personal information dispute mediation system. Accordingly, Korea’s data protection framework is centred on PIPA and supplemented by cybersecurity, sector-specific and data-related legislation. 8.2 Geographical Scope Korean data protection laws may apply to foreign companies whose activities involve Korean data sub - jects or otherwise have a sufficient connection with Korea. A foreign company targeting Korean custom - ers, offering services in Korea or processing Korean users’ personal information may therefore be subject to the Personal Information Protection Act (“PIPA”), even if incorporated or operating servers outside Korea. PIPA regulates the collection, use, provision, outsourc - ing, retention, destruction and cross-border transfer of personal information. Foreign companies processing Korean users’ personal information must comply with Korean requirements regarding consent, notification, purpose limitation, security measures, privacy policies and data subject rights, unless a statutory exception applies. Choice-of-law clauses do not necessarily exclude Korea’s mandatory data protection rules. Korean courts have recognised that statutory protections for Korean users may apply even where a contract pro - vides for foreign law, particularly in consumer-facing online services. Cross-border transfers are permitted only where a statutory basis exists, including: • separate consent from the data subject; • a statutory, treaty-based or international legal basis; • transfer to a jurisdiction recognised as providing an adequate level of protection; • standard contractual clauses or other recognised safeguards; or • other grounds permitted under PIPA. The Personal Information Protection Commission (“PIPC”) may order suspension of overseas transfers
981 CHAMBERS.COM
Powered by FlippingBook