{"id":733,"date":"2021-11-18T08:50:00","date_gmt":"2021-11-18T08:50:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=733"},"modified":"2026-03-12T09:15:29","modified_gmt":"2026-03-12T08:15:29","slug":"south-korea-pipa","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/south-korea-pipa\/","title":{"rendered":"PIPA - South Korea\u2019s Personal Information Protection Act"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-pipa-in-south-korea-quick-summary\">PIPA in South Korea, quick summary<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-personal-information-protection-act-korea-condensed\">Personal Information Protection Act Korea, condensed<\/h3>\n\n\n\n<p>South Korea\u2019s <strong>Personal Information Protection Act<\/strong>&nbsp;(PIPA) was passed in September 2011 and became one of the strictest data privacy laws in the world.<\/p>\n\n\n\n<p>Just like it is the case with many <a href=\"\/en\/gdpr\/\">other data privacy laws<\/a>, the purpose of the PIPA in South Korea is to <strong>protect the privacy rights of the data subject<\/strong>. This protection applies to most organisations, including government entities. This is one of the reasons why it is so comprehensive.<\/p>\n\n\n\n<p>The PIPA in South Korea provides very prescriptive and specific requirements throughout the lifecycle of the handling of personal data. This includes requirements like <strong>prior notification, opt-in consent and heavy sanctions<\/strong>&nbsp;prescribed by law, which makes it one of the strictest data protection laws in the world.<\/p>\n\n\n\n<p>Regarding the scope of application, <strong>the South Korean PIPA is applicable to a data handler<\/strong>. In the South Korean PIPA, a data handler in considered to be a person that, by itself or through a third party, handles personal data to make use of any operation on a personal data file in the course of its business activities.<\/p>\n\n\n\n<p>It doesn\u2019t matter if the person is an individual, public agency, organisation or juridical person, and personal data means <strong>data that is systematically&nbsp;<\/strong><strong>organised<\/strong>&nbsp;in accordance with certain rules for easy search or use of such personal data.<\/p>\n\n\n\n<p><strong>\u2018Handling of personal data\u2019<\/strong>&nbsp;is defined in the South Korea Personal Information Protection Act as \u201cprocessing, storage, retention, search, outputting, restoration, rectification, use, collection, generation, recording, provision, disclosure or destruction of personal data or any other action similar to any of the foregoing.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see all cookies and trackers in use<\/a><\/p>\n\n\n\n<p>The PIPA in South Korea differs from the GDPR by <strong>not demanding explicit, written consent from the data subject.<\/strong><\/p>\n\n\n\n<p>The PIPA in South Korea specifies that when obtaining consent from the data subjects, the personal information processor needs to <strong>notify the data subjects<\/strong>&nbsp;of the fact by separating the matters requiring consent from the ones who does not require consent. Additionally, you are expected to help the data subject with recognising it explicitly.<\/p>\n\n\n\n<p>This means that when obtaining consent for processing reasons, <strong>the personal information that requires consent needs to be segregated from the personal information not requiring consent<\/strong>. Therefore, the personal information processor should not deny goods and services because the data subjects did not consent to specific processing.<\/p>\n\n\n\n<p>Lastly, while the territorial scope is not specified in the law, it is worth noticing that the standard for enforcement of South Korea\u2019s data privacy law is similar to the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a><\/p>\n\n\n\n<p>This means, that <strong>companies established in South Korea are subject to the law<\/strong>, while foreign companies that target South Korean users are likely to be affected by the law as well.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4194\/hero.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustration of a hand holding a fan - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">The PIPA in South Korea is very comprehensive due to it applying to most organisations including government entities.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipa-in-korea-timeline\">PIPA in Korea - timeline<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The Pipa in South Korea<\/strong>&nbsp;went into effect in September 2011<\/li>\n\n\n\n<li>On April 7, 2017, <strong>the Supreme Court of Korea invalidated the consent from data subjects<\/strong>&nbsp;in a case where the defendant had asked for consent in a way that made it difficult for the data subject to know what they had consented to. It was difficult because the defendant had written the formalities in a font size of 1mm.<\/li>\n\n\n\n<li>On May 3, 2019, the Seoul High Court ruled that <strong>provision of sensitive personal information to third parties without consent was a violation of the PIPA<\/strong>. The high court noted that if the data was to be de-identified in a way that made it impossible to identify specific individuals, the provision would not be considered a violation of the PIPA.<\/li>\n\n\n\n<li>The National Assembly in South Korea passed <strong>several amendments to the PIPA Korea<\/strong>&nbsp;on February 4, 2020.<\/li>\n\n\n\n<li>These amendments, which included revised definitions for pseudonymous and anonymous processing, restrictions and penalties and associated requirements, <strong>entered into effect on august 5 2020.<\/strong><\/li>\n\n\n\n<li>On March 30, 2021, <strong>adequacy talks were concluded between South Korea and the EU<\/strong>, with the effect being that personal data could potentially flow from the EU (And Norway, Liechtenstein and Iceland) to South Korea without any further safeguard being necessary. In other words, <strong>transfers to South Korea will be assimilated to intra-EU transmissions of data if passed.<\/strong><\/li>\n\n\n\n<li>\u2022 In June 2021 the EU launched the process towards <strong>adoption of the South Korea adequacy decision<\/strong>. The process will cover transfers of personal data to South Korea\u2019s commercial operators as well as public authorities.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_21_2964\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the draft South Korea adequacy decision by the European Commission<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Scan your website for free to see all cookies and trackers in use<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP free for 14 days \u2013 or forever if you have a small website.<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipa-in-korea-quick-breakdown\">PIPA in Korea - quick breakdown<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>South Korea\u2019s PIPA has like many other major data privacy laws the purpose of <strong>protecting the privacy rights of the data subject.<\/strong><\/li>\n\n\n\n<li>South Korea\u2019s PIPA <strong>applies to most organisations, including government entities<\/strong>, consequently making it very comprehensive.<\/li>\n\n\n\n<li>The penalties for breaking the PIPA are being enforced enthusiastically. They include everything from fines to imprisonment.<\/li>\n\n\n\n<li>The law consists of <strong>a general law accompanied with several special laws<\/strong>&nbsp;which pertain to specific industry sectors.<\/li>\n\n\n\n<li>The PIPA specifies very regulatory and detailed obligations throughout the lifecycle of the handling of personal data. This includes obligations like prior notification, opt-in consent and heavy sanctions prescribed by law. This among other things makes it <strong>one of the strictest data protection laws in the world.<\/strong><\/li>\n\n\n\n<li><strong>The PIPA is applicable to a data handler<\/strong>. A data handler in the South Korean PIPA is a person that by itself or through a third party handles personal data with the purpose of making use of any operation on a personal data file in the course of its business activities. The PIPA does not distinguish between the person being a public agency, organisation, an individual or juridical person.<\/li>\n\n\n\n<li>Personal data means <strong>data that is systematically organised pursuant to certain rules<\/strong>&nbsp;for easy search or use of such personal data.<\/li>\n\n\n\n<li><strong>The PIPA does not demand explicit written consent<\/strong>, like the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>&nbsp;for example. Instead, it varies between some personal information needing consent and other not requiring consent. However, consent is not explicitly defined in the PIPA.<\/li>\n\n\n\n<li><strong>Territorial scope is not specified in the law<\/strong>, but the standard for enforcement of South Korean law is similar to the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>, meaning that companies established in South Korea are subject to the law.<\/li>\n\n\n\n<li><strong>Extra territorial scope is also not specified in the law<\/strong>, but foreign companies that target South Korean users are likely to be affected by the law.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"\/\">Scan your website to discover what cookies and trackers are in use on your website<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot consent management platform (CMP) for free<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipa-south-korea-compliance-with-cookiebot-cmp\">PIPA South Korea compliance with Cookiebot CMP<\/h2>\n\n\n\n<p><a href=\"\/\">Cookiebot consent management platform (CMP<\/a>) is a world-leading solution that <strong>helps you provide transparency and control over all the cookies \u2013 and similar tracking \u2013 on your website.<\/strong><\/p>\n\n\n\n<p>This guarantees you that your website complies with all the main data privacy laws around the world. This includes <strong>South Korea\u2019s PIPA<\/strong>, <a href=\"\/en\/thailand-pdpa\/\">Thailand\u2019s PDPA<\/a>, <a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>, <a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>, <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>, <a href=\"\/en\/uk-gdpr\/\">UK\u2019s GDPR<\/a>&nbsp;and <a href=\"\/en\/ccpa\/\">California\u2019s CCPA<\/a>.<\/p>\n\n\n\n<p>The PIPA in Korea will, like many laws before it, require <strong>consent from the users in South Korea, before you can use cookies and trackers as an integral part of your website.<\/strong><\/p>\n\n\n\n<p>Even though the <strong>South Korean PIPA<\/strong>&nbsp;does not ask for a consent as explicit as other data privacy laws ask for from its\u2019 users, it is still a good idea to make sure that your users know what they consent to.<\/p>\n\n\n\n<p>Our unrivaled website scanner detects all cookies and trackers while delivering an exhaustive report on all personal data processing on your website.<\/p>\n\n\n\n<p>For that reason, among others, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is considered an optimal solution, for making your domain fully compliant without the need for you to get into any complicated technical implementation.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4197\/petals-consent.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustration of cookie consent banner with petals around it - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">Consent is not an explicit requirement under the South Korean PIPA, but Cookiebot CMP will provide you with an optimal solution for making your website compliant<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-is-cookiebot-cmp\">What is Cookiebot CMP?<\/h3>\n\n\n\n<p>You might wonder, what is <a href=\"\/\">Cookiebot CMP<\/a>? Simply put, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is a plug-and-play compliance solution that helps automate the complete PIPA compliance procedure. This includes everything, from automatically detecting all the cookies on your website and thereby controlling them, to actually collecting consents from end-users.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;offers you a detailed scan report including details about your website\u2019s cookies such as purpose, provider, duration and what third parties it shared end-user data with.<\/p>\n\n\n\n<p>Finally, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;helps you to safely store all end-user consents, and to renew them on a regular basis.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;works to make end-user privacy protection an integrated part of each individual website, and by offering you a comprehensive overview of all cookies on your website, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;ensures compliance with the PIPA in South Korea along with many other data privacy regulations around the world.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to discover what cookies and trackers are in use on your website<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP for PIPA compliance in South Korea<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-default\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4333\/consent_en.png?width=500&amp;\" alt=\"Cookieboot Pop Up Banner - Cookiebot\" width=\"770\" height=\"449\"\/><figcaption class=\"wp-element-caption\">Consent banner by Cookiebot CMP for PIPA compliance in South Korea<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-pipa-south-korea-s-personal-information-protection-act-in-detail\">PIPA - South Korea\u2019s Personal Information Protection Act, in detail<\/h2>\n\n\n\n<p>Hopefully you\u2019ve now gotten a quick overview of the South Korean PIPA, and what it means to you and your website.<\/p>\n\n\n\n<p>If you\u2019re looking for a more detailed breakdown, read on as we go look up close at South Korea\u2019s data privacy law\u2019s key characteristics.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-scope-of-application-of-the-pipa-in-korea\">Scope of application of the PIPA in Korea<\/h3>\n\n\n\n<p>When it comes to the scope of application, the PIPA in South Korea is applicable to a data handler.<\/p>\n\n\n\n<p>In South Korea\u2019s PIPA, a data handler is considered to be <strong>a person that by itself or through a third party handles personal data<\/strong>&nbsp;to make use of any operation on a personal data file in the course of its business activities.<\/p>\n\n\n\n<p>South Korea\u2019s PIPA does not differentiate between the data handler being an individual, a public agency, a juridical person or an organisation.<\/p>\n\n\n\n<p>You might wonder, what is a personal data file? And what does it mean \u2018to handle personal data\u2019?<\/p>\n\n\n\n<p>First of all, a personal data file is <strong>a collection of data that has systematically been organised in accordance with certain rules to make it easily accessible<\/strong>, either if you are searching for it or using it (personal data will be explained more thoroughly later on in the blog post).<\/p>\n\n\n\n<p>Handling of personal data, on the other hand, is defined in South Korea\u2019s PIPA as \u201c<em>processing, storage, retention, search, outputting, restoration, rectification, use, collection, generation, recording, provision, disclosure or destruction of personal data or any other action similar to any of the foregoing<\/em>\u201d.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4193\/data-handler.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustration of a hand placing a file into a filing cabinet - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">The South Korean PIPA is applicable to a data handler.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-pipc-s-responsibilities\">The PIPC\u2019s responsibilities<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.pipc.go.kr\/cmt\/main\/english.do\" target=\"_blank\" rel=\"noreferrer noopener\">The Personal Information Protection Commission (PIPC)<\/a>&nbsp;is in their own words the central administrative body with the primary task of protecting and supervising personal information.<\/p>\n\n\n\n<p>In their mission statement they present three primary tasks, which include:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Solid protection of personal information<\/li>\n\n\n\n<li>Safe use of personal information while increasing its value<\/li>\n\n\n\n<li>Fair balance between protection and use.<\/li>\n<\/ol>\n\n\n\n<p>The PIPC is accompanied by the KCC, the FSC and the Korea Internet &amp; Security Agency. The PIPC, however, are the ones in charge of enforcing South Korea\u2019s PIPA, which is why we will only focus on them at this point.<\/p>\n\n\n\n<p>The main powers of the PIPC include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enforcing the PIPA in South Korea<\/li>\n\n\n\n<li>Shaping data protection policy<\/li>\n\n\n\n<li>Evaluating the improvement of laws and the associated administrative measures relating to protecting the personal information<\/li>\n\n\n\n<li>Addressing matters regarding formal clarifications, and<\/li>\n\n\n\n<li>Imposing administrative fines, penalties, corrective orders and other administrative sanctions, when needed.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"\/\">Scan your website to discover what cookies and trackers are in use on your website<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP free for 14 days \u2013 or forever if you have a small website<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pipa-south-korea-key-definitions\">PIPA South Korea - key definitions<\/h3>\n\n\n\n<p>South Korea\u2019s Personal Information Protection Act (PIPA) operates with a set of key definitions, like many of the data privacy laws around the world that it resembles. They are important to familiarize yourself with to get the full understanding of the PIPA.<\/p>\n\n\n\n<p>The five key definitions of South Korea\u2019s PIPA are \u2013<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Personal Data<\/li>\n\n\n\n<li>Sensitive data<\/li>\n\n\n\n<li>Data controller<\/li>\n\n\n\n<li>Data processor<\/li>\n\n\n\n<li>Anonymized information<\/li>\n<\/ol>\n\n\n\n<p><strong>Personal Data<\/strong>&nbsp;is defined in South Korea\u2019s PIPA as data that can be related to a living natural person. Its definition of personal data is very broad, resulting in three subcategories of personal data:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data that identifies a particular individual by their name, image or resident registration number.<\/li>\n\n\n\n<li>Data that might not by itself identify a particular individual but can easily be combined with other information to identify the particular individual. To consider whether or not the information can be classified as \u2018easily combined\u2019 you need to consider the cost, technology and time it takes to identify the individual.<\/li>\n\n\n\n<li>Data that is information as mentioned above which can be pseudonymized and thereby become unqualified of recognizing a particular individual without the use or combination of extra information for reinstatement to its original state.<\/li>\n<\/ul>\n\n\n\n<p><strong>Sensitive data<\/strong>&nbsp;is personal information regarding an individual\u2019s faith, health, sexual orientation, genetic information, criminal records, political views, ideology and so on. It is information that could potentially cause a material breach of privacy.<\/p>\n\n\n\n<p><strong>A Data controller<\/strong>, or data handler, is a \u2018public institution, corporate body, organization or individual, who handles the data by, collecting, generating, connecting, interlocking, recording, storing, retaining, processing, editing, searching, outputting, correcting, restoring, using, providing, disclosing, destroying or otherwise handling personal data\u2019. The concept of a data controller under the PIPA is very similar to the concept under the GDPR.<\/p>\n\n\n\n<p><strong>A Data processor<\/strong>&nbsp;is someone who process personal data and personal information. The data processor is often a third party, since the data controller often outsource this job.<\/p>\n\n\n\n<p><strong>Anonymized information<\/strong>&nbsp;is any information which cannot be used to identify a specific individual. This includes instances where the information is combined with other information and is not subject to the PIPA.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4196\/personal-files.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustration of a hand placing a file into a filing cabinet - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">Data can come in many forms and shapes, but the PIPA South Korea has them alle covered<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-rights-and-responsibilities\">Rights and responsibilities<\/h3>\n\n\n\n<p>As mentioned above, we differentiate between a data processor and a data controller. The responsibilities they have and the rights they possess will be explained in detail here.<\/p>\n\n\n\n<p><strong>The data controlle<\/strong>r has a number of obligations under the PIPA in South Korea. These obligations include handling personal data in a way that minimizes any potential infringement upon the privacy of data subjects and anonymizing or pseudonymizing the data before processing.<\/p>\n\n\n\n<p>More specifically, <strong>data controllers must maintain the security of personal data<\/strong>, while taking into account the risk of a breach of the data subjects\u2019 privacy.<\/p>\n\n\n\n<p>Data controllers are required to take the technical, physical and administrative actions required to ensure the security of personal data.<\/p>\n\n\n\n<p>Data controllers also need to <strong>provide notice whenever they process personal data<\/strong>. The consent for a provision must be obtained separately from the consent for the collection and use of personal data, while consent for sensitive data must be obtained separately from each other as well.<\/p>\n\n\n\n<p>There are only a few exceptions to the above-mentioned requirements under South Korean law, but in accordance with the <a href=\"https:\/\/www.kimchang.com\/en\/insights\/detail.kc?sch_section=4&amp;idx=20726\" target=\"_blank\" rel=\"noreferrer noopener\">2020 amendments<\/a>, personal data may be used without the data subject\u2019s consent.<\/p>\n\n\n\n<p>This only applies when it is within the scope reasonably related to the original purpose of the collection. These are some of the things <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;can help you take care of.<\/p>\n\n\n\n<p>Since <strong>data processors<\/strong>&nbsp;regularly are treated in the same way as data controllers, they will, commonly, be subject to the same legal responsibilities as those related to data handlers.<\/p>\n\n\n\n<p>In a case where an outsourced service provider function as a data processor and violates the PIPA in South Korea, the data processor will be deemed as an employee of the data controller. In that case, the data controller will have vicarious liability, meaning they are being held partly responsible for the unlawful actions of the outsources service provider.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-subjects\">Data subjects<\/h3>\n\n\n\n<p>The data subjects have some rights. They can exercise their rights of access, correction, suspension of use and removal of their personal data.<\/p>\n\n\n\n<p>Regarding this, the PIPA also possesses prescriptive rules for the procedure with the purpose of ensuring data subject\u2019s exercise of the before mentioned rights.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sanctions\">Sanctions<\/h3>\n\n\n\n<p>The penalties for breaching South Korea\u2019s Personal Information Protection Act (PIPA) vary.<\/p>\n\n\n\n<p>You could face various administrative sanctions such as corrective orders, fines and penalty surcharges. Also, public prosecutors may investigate any violations which are also subject to criminal punishment. Finally, data handlers could potentially become civilly liable to data subjects who suffer damages as a result of the violations of the data handler.<\/p>\n\n\n\n<p><a href=\"\/\">Scan your website to discover what cookies and trackers are in use on your website<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP for PIPA compliance in South Korea<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-south-korea-s-pipa-vs-gdpr\">South Korea\u2019s PIPA vs GDPR<\/h2>\n\n\n\n<p>South Korea\u2019s Personal Information Protection Act (PIPA) and the <a href=\"\/en\/gdpr\/\">EU\u2019s General Data Protection Regulation (GDPR)<\/a>&nbsp;are similar and different in a number of ways, e.g. key requirements and how they view data privacy.<\/p>\n\n\n\n<p>This section of the blog post will primarily focus on the differences between the two laws, but if you want to know more about the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>&nbsp;you can read about it <a href=\"\/en\/gdpr-cookies\/\">here<\/a>.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Under South Korea\u2019s PIPA, employers are required to appoint a data protection officer (DPO) among the employees that are authorized to be one. This could be executives or company representatives. The EU\u2019s GDPR on the other hand allows for external DPOs or joint DPOs.<\/li>\n\n\n\n<li>\u2022 South Korea\u2019s PIPA guarantees data subjects the right of access, right to deletion and right to correction. The EU\u2019s GDPR also gives the data subject those rights, but in addition to it, it prescribes the right to limit personal information processing, the right to be deleted from storage, the right to refuse profiling and lastly, the right to transfer personal information to other companies.<\/li>\n\n\n\n<li>\u2022 South Korea\u2019s PIPA requires a company to obtain agreement from data subject before it is allowed to transfer personal information to a location outside of its legal jurisdiction. The EU\u2019s GDPR is not that strict, as it allows for the transfer of personal data to an overseas country without the data subject\u2019s approval, if there is an adequacy decision or appropriate safeguards. However, personal data processing always needs explicit end-user consent.<\/li>\n\n\n\n<li>Regarding detailed procedures, PIPA in South Korea requires only public institutions to get an impact assessment, while the EU\u2019s GDPR also requires you to get private companies that handle large-scale information an impact assessment as well.<\/li>\n\n\n\n<li>When it comes to personal information data breaches, South Korea\u2019s PIPA requires a company to inform data subjects about the leakage before you notify the relevant authority. Under the EU\u2019s GDPR it is the other way around; a company needs to notify the relevant authority first and then notify the data subjects.<\/li>\n\n\n\n<li>Lastly, under South Korea\u2019s PIPA a company can be fined up to about 40.000 euros, while the EU\u2019s GDPR can fine you up to 20 million euro.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"\/\">Scan your website to see all cookies and trackers in use<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP free for 14 days \u2013 or forever if you have a small website.<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4198\/korea-eu-adequacy.jpeg?width=450&amp;;mode=max\" alt=\"Illustration of a person pasting the South Korean flag on a billboard - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">EU and South Korea share a lot of similarities, but also differ in a number of ways<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-south-korea-s-eu-adequacy-decision\">South Korea\u2019s EU adequacy decision<\/h3>\n\n\n\n<p>As mentioned in the section above, the EU\u2019s GDPR allows for transfer of personal information to an overseas country without the data subject\u2019s approval, if there is an adequacy decision or appropriate safeguards.<\/p>\n\n\n\n<p><em>Adequacy<\/em>&nbsp;means, under the GDPR, that a non-EU country ensures a level of personal data protection equivalent to that of the EU itself.<\/p>\n\n\n\n<p>In January 2017, the EU launched a dialogue with South Korea with the goal of reaching an adequacy decision, ensuring a free flow of data between the two. Such a decision would complement <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/ALL\/?uri=OJ%3AL%3A2011%3A127%3ATOC\" target=\"_blank\" rel=\"noreferrer noopener\">the Free Trade Agreement<\/a>&nbsp;in place since July 2011.<\/p>\n\n\n\n<p>In March 2021, the EU and South Korea concluded the adequacy talks with the two parties showing a high degree of convergence in the area of data protection. The amendments to South Korea\u2019s PIPA and the strengthening of the powers of the <a href=\"https:\/\/www.pipc.go.kr\/cmt\/main\/english.do\" target=\"_blank\" rel=\"noreferrer noopener\">Personal Information Protection Commission<\/a>&nbsp;greatly influenced the outcome.<\/p>\n\n\n\n<p>In June 2021, the EU <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_21_2964\/\" target=\"_blank\" rel=\"noreferrer noopener\">launched the process<\/a>&nbsp;towards adoption of the adequacy decision. The process will cover transfers of personal data to South Korea\u2019s commercial operators as well as public authorities.<\/p>\n\n\n\n<p>The benefits of this adequacy decision, if adopted, is that it would provide Europeans with a strong protection of their personal data when transferred to South Korea, while at the same time boosting cooperation between the two leading digital powers.<\/p>\n\n\n\n<p><a href=\"https:\/\/ec.europa.eu\/info\/index_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">The European Commission<\/a>&nbsp;is currently awaiting the opinion of <a href=\"https:\/\/edpb.europa.eu\/edpb_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">the European Data Protection Board (EDPB)<\/a>, while seeking approval from a committee composed of representatives of the EU member states. Once these two steps have been completed, the EU can proceed to adopt South Korea\u2019s adequacy decision.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-summary-of-pipa-south-korea-s-personal-information-protection-act-pipa\">Summary of PIPA, South Korea\u2019s Personal Information Protection Act (PIPA)<\/h2>\n\n\n\n<p>South Korea\u2019s Personal Information Protection Act (PIPA) is one of the world\u2019s many data privacy laws. Not unlike many other data privacy laws its purpose is to protect the privacy rights of the data subject, while at the same making sure that entities like companies or organisations do not abuse the data they receive about their users.<\/p>\n\n\n\n<p>South Korea\u2019s PIPA was first approved in March 2011, went into effect in September 2011 and has since been amended. In 2021 talks about adequacy with the EU\u2019s GDPR concluded and are currently awaiting adoption.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;enables compliance with most of the world\u2019s major data privacy laws, including South Korea\u2019s PIPA.<\/p>\n\n\n\n<p><a href=\"https:\/\/admin.cookiebot.com\/signup\">Try Cookiebot CMP for PIPA compliance<\/a><\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>PIPA in South Korea, quick summary Personal Information Protection Act Korea, condensed South Korea\u2019s Personal Information Protection Act&nbsp;(PIPA) was passed in September 2011 and became one of the strictest data privacy laws in the world. Just like it is the case with many other data privacy laws, the purpose of the PIPA in South Korea [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":758,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2021\/11\/flag_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=733"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/733\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/758"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}