SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
entrustment (outsourcing), of personal information to a third party located outside Korea, but also access - ing personal information from abroad and storing per - sonal information abroad. Where personal information is transferred abroad, in addition to satisfying the general lawful basis require - ments for personal information transfers (eg, consent for third-party provision or obligations associated with entrustment of processing), additional legal require - ments apply. Specifically, the data handler must either: • provide notice of the cross-border transfer and obtain separate consent; or • disclose cross-border transfer matters in its privacy policy (limited to cases of entrustment of process - ing or storage). Further, in response to increasing global data exchanges and co-operation, a 2023 amendment to PIPA added the following as “additional lawful bases” for cross-border transfers, to align with international standards. • Where laws, treaties to which Korea is a party or other international agreements contain special provisions on cross-border transfers of personal information: however, in practice, Korea has not enacted such legal provisions or entered into trea - ties specifically governing cross-border transfers. • Cross-border transfer certification: where the overseas recipient is certified by the PIPC and has implemented required safeguards. To date, there has been no case recognised by the PIPC in practice. • Equivalence recognition by the PIPC: where the PIPC recognises that the level of data protection in a given country or international organisation is equivalent to the level under PIPA. This is similar to the GDPR adequacy decision mechanism. In September 2025, the PIPC recognised equivalence with respect to the EU, such that Korea and the EU currently mutually recognise the adequacy/ equivalence of data protection. No country or international organisation other than the EU has yet been recognised as equivalent by the PIPC, but the PIPC plans to expand such recognitions gradually.
Separately, PIPA grants the PIPC authority to order a data handler to suspend cross-border transfers of personal information. Specifically, where cross-border transfers are ongoing or further cross-border transfers are anticipated, the PIPC may order suspension if: • the data handler has violated PIPA’s cross-border transfer provisions; or • the overseas recipient, the destination country or an international organisation does not adequately protect personal information compared to PIPA, and harm to data subjects has occurred or there is a significant risk that harm will occur. Because the Credit Information Act (a special law vis- à-vis PIPA) does not separately stipulate cross-border transfer rules, cross-border transfers of personal credit information by financial institutions are not necessar - ily impossible if PIPA’s cross-border transfer require - ments are satisfied. However, under Article 5 (1) of the Regulations on the Outsourcing of Data Processing by Financial Institutions, outsourcing of data processing abroad is prohibited for unique identification informa - tion of individual customers (eg, resident registration numbers, passport numbers), even if safeguards such as encryption are applied. In general, use of cloud computing services is interpreted as an entrustment (outsourcing) of data processing, and these restric - tions therefore constitute a key practical considera - tion for financial institutions seeking to use overseas cloud regions. Accordingly, when a financial institution builds cloud-based infrastructure, it is necessary to confirm whether the physical location of systems that Restrictions on Cross-Border Transfers in Outsourced Information Processing in the Financial Sector process and store data is within Korea. 3.6 Threat-Led Penetration Testing Vulnerability Analysis and Assessment Under the Regulations on the Supervision of Electronic Financial Transactions Under Article 37-2 of the Regulations on the Super - vision of Electronic Financial Transactions, financial institutions with total assets of KRW2 trillion or more and 300 or more regular employees must conduct vul - nerability analyses and assessments of their IT func - tions at least once per year. With respect to websites,
314 CHAMBERS.COM
Powered by FlippingBook