| name | korea-pipa |
| title | South Korea PIPA Compliance |
| description | Guides compliance with South Korea's Personal Information Protection Act (PIPA, 개인정보 보호법). Covers pseudonymisation framework, notification requirements, PIPC enforcement, consent standards, and cross-border transfer rules under the 2023 amendments. Keywords: PIPA, Korea data protection, PIPC, pseudonymisation, consent, cross-border transfers. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/korea-pipa |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | kr |
| practice | data-protection |
| language | en |
South Korea PIPA Compliance
Overview
The Personal Information Protection Act (PIPA, 개인정보 보호법) is South Korea's comprehensive data protection law, originally enacted on 29 September 2011 (Act No. 10465) and significantly amended in 2020 (effective 5 August 2020) and 2023 (effective 15 September 2023). The Personal Information Protection Commission (PIPC, 개인정보보호위원회) is the independent supervisory authority with centralised enforcement jurisdiction since the 2020 amendments consolidated regulatory authority from multiple agencies.
South Korea received an adequacy decision from the European Commission on 17 December 2021, recognising PIPA as providing an adequate level of data protection for GDPR transfer purposes.
Scope and Definitions
Personal Information (Art. 2(1))
Information relating to a living individual that identifies or can identify the individual through the information alone or in combination with other information that can be easily used. Includes:
- Name, resident registration number, image
- Information that individually does not identify but can identify when combined with other easily accessible information
Pseudonymised Information (Art. 2(1-2), introduced 2020)
Personal information processed by partially deleting or replacing to make it impossible to identify a specific individual without the use of additional information. Pseudonymised information may be processed for statistical purposes, scientific research, and preservation of records in the public interest without consent (Art. 28-2).
Sensitive Information (Art. 23)
- Ideology, beliefs, membership of trade unions or political parties
- Political opinions, health information, sex life
- Genetic information, criminal record information
- Biometric information used for identification
- Race and ethnic origin (added by 2023 amendments)
Consent Framework
General Consent Requirements
| Requirement | PIPA Provision | Detail |
|---|
| Informed consent | Art. 15(2) | Must disclose: purpose, items collected, retention period, right to refuse and consequences |
| Separate consent | Art. 22(1) | Consent for processing beyond the purpose must be separated from other consent items |
| Clear distinction | Art. 22(1) | Important content must be clearly displayed (larger font, colour, bold) |
| Opt-in for marketing | Art. 22(2) | Marketing purpose collection requires separate opt-in consent |