Jurisdiction
South Korea
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Korea has both a comprehensive data protection statute and a comprehensive AI statute in force. The Personal Information Protection Act is enforced by the Personal Information Protection Commission, and gives data subjects a right to refuse or object to decisions made by fully automated systems, including systems applying AI. The AI Framework Act has applied since 22 January 2026, with an Enforcement Decree and a Ministry of Science and ICT policy of at least a year’s grace on investigations and fines. PIPA is amended twice more in the near term.
- Region
- North Asia
- ISO code
- KR
- Privacy framework
- Personal Information Protection Act (개인정보 보호법). The version in force is Act No. 20897, effective 2 October 2025. It sets consent and alternative bases, purpose limitation, retention limits, security duties, breach notification and cross-border rules, and since March 2023 has carried Article 37-2, the right of a data subject to object to or refuse a decision made by a completely automated system — expressly including systems applying artificial intelligence — where that decision significantly affects their rights or duties. An amendment promulgated on 10 March 2026 takes effect on 11 September 2026.
- AI-specific rules
- The Framework Act on the Development of Artificial Intelligence and Establishment of a Basis for Trust has applied since 22 January 2026; the current consolidated version took effect on 21 July 2026. It carries obligations tied to high-impact AI and to generative AI, with the Enforcement Decree setting thresholds — the Ministry of Science and ICT has stated that AI used in the areas the Act names is assessed on the seriousness of the risk, and that a human in the final decision loop takes a system outside the high-impact category. The Ministry has also said it will defer enforcement for at least a year, running a guidance period for fact-finding investigations and administrative fines. That is enforcement policy, not a change to the law. Alongside it, the PIPC has published guidance on processing publicly available personal information for AI, on data subjects’ rights over automated decisions, and on generative AI development and use.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
PIPA permits cross-border provision on defined bases including consent, a statutory or treaty basis, certification, and an adequacy-style recognition by the Commission, and the PIPC may order a transfer to stop where protection in the destination is inadequate. The European Commission’s adequacy decision for Korea remains in place, which matters when the deployment also touches the EU. As everywhere, the practical work is establishing which hop is the transfer: the model API call, the log store, or the support tooling.
Regulators
Primary sources
- Legislation개인정보 보호법 — 국가법령정보센터 (version in force, effective 2025-10-02)
- Legislation개인정보 보호법 — 국가법령정보센터 (promulgated, effective 2026-09-11)
- Legislation인공지능 발전과 신뢰 기반 조성 등에 관한 기본법 — 국가법령정보센터
- Regulator guidance개인정보보호위원회 — 인공지능(AI) 개발·서비스를 위한 공개된 개인정보 처리 안내서
- Regulator guidance개인정보보호위원회 — 자동화된 결정에 대한 정보주체의 권리 안내서
- Regulator guidance개인정보보호위원회 — 생성형 인공지능(AI) 개발·활용을 위한 개인정보 처리 안내서
- Official faq대한민국 정책브리핑 — 인공지능기본법 시행 (규제 유예 방침)
02Regulations and guidance
| Instrument | Status |
|---|---|
| PIPC Generative AI GuidePIPC guidance organising personal-data issues by generative AI lifecycle stage and setting out the legal standards and safeguards for each. Non-binding, and a workable structure for an internal assessment of a RAG or fine-tuning project. | In force |
| PIPC Public Data AI GuidePIPC guidance offering an interpretive standard for processing publicly available personal information to develop AI, covering the legal basis, safety measures, data subject rights and the role of AI companies. The guide states on its own cover that it has no legal binding force. | In force |
| AI Framework ActKorea’s comprehensive AI statute, in force since 22 January 2026. Sets duties around high-impact AI and generative AI and creates a national AI governance structure. An amendment promulgated two days before commencement deferred a handful of provisions to 21 July 2026; the Act as a whole was not delayed. | In force |
| PIPC Automated Decision GuidePIPC guidance on what a controller must do when a data subject exercises rights over an automated decision, and on disclosing the scope, criteria and procedure of such decisions. It is the operative guidance for PIPA Article 37-2. | In force |
| MSIT AI Act Grace PeriodA government policy briefing recording that the Ministry of Science and ICT will defer regulation for at least a year to give firms time to prepare, running a guidance period for fact-finding investigations and administrative fines, with investigations reserved for exceptional cases such as loss of life or serious harm to rights. | In force |
| PIPAKorea’s data protection statute. Sets bases for processing, purpose limitation, retention limits, security duties, breach notification and cross-border rules, and gives a data subject the right to object to or refuse a decision made by a completely automated system, including one applying artificial intelligence, where it significantly affects their rights or duties. | In force |
| PIPA 2026 AmendmentA promulgated amendment to PIPA that takes effect on 11 September 2026, six months after promulgation, with two provisions deferred to 1 July 2027. The law information centre publishes it as a pending version alongside the text in force. | Adopted, not yet applicable |
| PIPA AI Special ProvisionAn amendment creating a special provision allowing lawfully collected personal data to be used for AI development where pseudonymised or anonymised data is insufficient, where public or social benefit is recognised, and subject to enhanced safeguards and Commission deliberation. It passed the National Assembly on 20 August 2026 and takes effect six months after promulgation, which has not yet occurred. | Proposed |
03Common enterprise issues
Automated decision-making
Article 37-2 names AI explicitly
Where a completely automated system — expressly including one applying AI — makes a decision that significantly affects a person’s rights or duties, that person can object to it. The design consequence is that the objection route and the explanation have to exist before launch.
High-risk AI
Whether the deployment is high-impact AI
The AI Framework Act attaches its heavier duties to high-impact AI. The assessment turns on the area of use and the seriousness of the risk, and a genuine human decision in the loop is treated as taking the system out of the category.
Model training
Training data and publicly available information
The PIPC has published a legal-interpretation guide on using publicly available personal information for AI development. It is not binding, but it is the standard the regulator will apply, and a further statutory special provision for AI training has passed the National Assembly.
Transparency
Generative AI guidance covers the whole lifecycle
The PIPC’s August 2025 guide organises personal-data issues by lifecycle stage rather than by feature, which maps well onto a RAG or fine-tuning project and is a useful structure for an internal assessment.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.