Data Protection in South Korea

Security in South Korea

Under the PIPA, every personal data controller must, when it processes personal information of a data subject, take the following technical and administrative measures in accordance with the guidelines prescribed by the Presidential Decree to prevent loss, theft, leakage, alteration, or destruction of personal information:

  • establishment and implementation of an internal control plan for handling personal information in a safe way;
  • installation and operation of an access control device, such as a system for blocking intrusion to cut off illegal access to personal information;
  • measures for preventing fabrication and alteration of access / log records;
  • measures for security including encryption technology and other methods for safe storage and transmission of personal information; and
  • measures for preventing intrusion of computer viruses, including installation and operation of vaccine software, and other protective measures necessary for securing the safety of personal information.

The PIPA provides detailed measures to be taken by the personal data controller in its subordinate regulations. On October 31, 2024, the PIPC released the updated Guidelines on Standards for Measures to Ensure Security of Personal Information (the “Guidelines”).

Continue reading

  • no results

Previous topic
Back to top