Skip to content
Is there an AI for this?

Jurisdiction

South Korea

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

Korea has both a comprehensive data protection statute and a comprehensive AI statute in force. The Personal Information Protection Act is enforced by the Personal Information Protection Commission, and gives data subjects a right to refuse or object to decisions made by fully automated systems, including systems applying AI. The AI Framework Act has applied since 22 January 2026, with an Enforcement Decree and a Ministry of Science and ICT policy of at least a year’s grace on investigations and fines. PIPA is amended twice more in the near term.

Region
North Asia
ISO code
KR
Privacy framework
Personal Information Protection Act (개인정보 보호법). The version in force is Act No. 20897, effective 2 October 2025. It sets consent and alternative bases, purpose limitation, retention limits, security duties, breach notification and cross-border rules, and since March 2023 has carried Article 37-2, the right of a data subject to object to or refuse a decision made by a completely automated system — expressly including systems applying artificial intelligence — where that decision significantly affects their rights or duties. An amendment promulgated on 10 March 2026 takes effect on 11 September 2026.
AI-specific rules
The Framework Act on the Development of Artificial Intelligence and Establishment of a Basis for Trust has applied since 22 January 2026; the current consolidated version took effect on 21 July 2026. It carries obligations tied to high-impact AI and to generative AI, with the Enforcement Decree setting thresholds — the Ministry of Science and ICT has stated that AI used in the areas the Act names is assessed on the seriousness of the risk, and that a human in the final decision loop takes a system outside the high-impact category. The Ministry has also said it will defer enforcement for at least a year, running a guidance period for fact-finding investigations and administrative fines. That is enforcement policy, not a change to the law. Alongside it, the PIPC has published guidance on processing publicly available personal information for AI, on data subjects’ rights over automated decisions, and on generative AI development and use.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

PIPA permits cross-border provision on defined bases including consent, a statutory or treaty basis, certification, and an adequacy-style recognition by the Commission, and the PIPC may order a transfer to stop where protection in the destination is inadequate. The European Commission’s adequacy decision for Korea remains in place, which matters when the deployment also touches the EU. As everywhere, the practical work is establishing which hop is the transfer: the model API call, the log store, or the support tooling.


02Regulations and guidance

8 instruments
InstrumentStatus
PIPC Generative AI GuidePIPC guidance organising personal-data issues by generative AI lifecycle stage and setting out the legal standards and safeguards for each. Non-binding, and a workable structure for an internal assessment of a RAG or fine-tuning project.In force
PIPC Public Data AI GuidePIPC guidance offering an interpretive standard for processing publicly available personal information to develop AI, covering the legal basis, safety measures, data subject rights and the role of AI companies. The guide states on its own cover that it has no legal binding force.In force
AI Framework ActKorea’s comprehensive AI statute, in force since 22 January 2026. Sets duties around high-impact AI and generative AI and creates a national AI governance structure. An amendment promulgated two days before commencement deferred a handful of provisions to 21 July 2026; the Act as a whole was not delayed.In force
PIPC Automated Decision GuidePIPC guidance on what a controller must do when a data subject exercises rights over an automated decision, and on disclosing the scope, criteria and procedure of such decisions. It is the operative guidance for PIPA Article 37-2.In force
MSIT AI Act Grace PeriodA government policy briefing recording that the Ministry of Science and ICT will defer regulation for at least a year to give firms time to prepare, running a guidance period for fact-finding investigations and administrative fines, with investigations reserved for exceptional cases such as loss of life or serious harm to rights.In force
PIPAKorea’s data protection statute. Sets bases for processing, purpose limitation, retention limits, security duties, breach notification and cross-border rules, and gives a data subject the right to object to or refuse a decision made by a completely automated system, including one applying artificial intelligence, where it significantly affects their rights or duties.In force
PIPA 2026 AmendmentA promulgated amendment to PIPA that takes effect on 11 September 2026, six months after promulgation, with two provisions deferred to 1 July 2027. The law information centre publishes it as a pending version alongside the text in force.Adopted, not yet applicable
PIPA AI Special ProvisionAn amendment creating a special provision allowing lawfully collected personal data to be used for AI development where pseudonymised or anonymised data is insufficient, where public or social benefit is recognised, and subject to enhanced safeguards and Commission deliberation. It passed the National Assembly on 20 August 2026 and takes effect six months after promulgation, which has not yet occurred.Proposed

03Common enterprise issues

4
  • Automated decision-making

    Article 37-2 names AI explicitly

    Where a completely automated system — expressly including one applying AI — makes a decision that significantly affects a person’s rights or duties, that person can object to it. The design consequence is that the objection route and the explanation have to exist before launch.

  • High-risk AI

    Whether the deployment is high-impact AI

    The AI Framework Act attaches its heavier duties to high-impact AI. The assessment turns on the area of use and the seriousness of the risk, and a genuine human decision in the loop is treated as taking the system out of the category.

  • Model training

    Training data and publicly available information

    The PIPC has published a legal-interpretation guide on using publicly available personal information for AI development. It is not binding, but it is the standard the regulator will apply, and a further statutory special provision for AI training has passed the National Assembly.

  • Transparency

    Generative AI guidance covers the whole lifecycle

    The PIPC’s August 2025 guide organises personal-data issues by lifecycle stage rather than by feature, which maps well onto a RAG or fine-tuning project and is a useful structure for an internal assessment.


04Vendor restrictions

0

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

No vendor restriction has been recorded for this jurisdiction.


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 8 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.