Statutory bundle of data subject rights under PIPA Articles 35–38 (as amended through 2026)
South Korea’s Personal Information Protection Act (PIPA, Act No. 10465, as last amended by Act No. 19234 of March 14, 2023, consolidated through February 2026) grants a comprehensive statutory bundle of data subject rights anchored in Articles 35–38, and expanded by Article 35-2. These rights are enforceable before the Personal Information Protection Commission (PIPC).
Core statutory rights framework (Articles 35–38, including Article 35-2):
- Article 35: Access — The right to access personal information and to confirm whether and how it is processed. Statutory exceptions to access are specifically enumerated in Article 35(4).
- Article 35-2: Right to transmission (portability) — Introduced by the 2023 amendment (in force March 2023), this grants data subjects the right to request that their personal information be transmitted to themselves or a designated third party in a machine-readable electronic format. The detailed technical and sectoral requirements—including the expansion of portability obligations across all industry sectors and specification of eligible controllers—are governed by the Enforcement Decree, which was materially amended February 19, 2026, to broaden application and prescribe API-based formats where feasible ([Enforcement Decree Art. 42-2, 42-4, 48-8]).
- Article 36: Correction and Deletion — Right to request correction of inaccurate information or deletion of personal information where processing is no longer lawful or the retention period has expired, subject to overriding legal-retention requirements in other statutes.
- Article 37: Suspension of Processing / Withdrawal of Consent — Right to suspend processing activities or withdraw consent, with proportionality limits if suspension would interfere with legal/statutory obligations or core public functions.
- Article 38: Methods, Procedures, and Timelines — Prescribes procedural requirements for exercising rights, including exercising rights through a legal representative, mandatory use of standardized forms (per Enforcement Decree Art. 48), and a controller’s statutory 10-day response requirement (extendable once for an additional 10 days with specific notice). Written denials must state the legal basis and relevant facts, and inform the data subject of remedial options (Art. 38(7)).
Remedies and enforcement:
- The PIPC may order compliance, mediate disputes, and impose administrative fines. As amended (Art. 64 and 64-2), post–September 2026, the upper limit for fines is set to 10% of a controller's total annual revenue for egregious or repeated violations, as prescribed by Article 64-2 and the amended Enforcement Decree.
- Civil damages actions are separately available under Article 39.
Alignment:
- The statutory rights structure aligns closely with GDPR Chapter III, mirroring access, portability, correction, deletion, and restriction of processing. However, specific Korean procedural provisions, the structure of exceptions, and the timeline for controller responses differ materially from GDPR (e.g., PIPA’s uniform 10-day response requirement as compared to GDPR’s one-month baseline).
Recent amendments / currency statement:
- This update incorporates the February 19, 2026 Enforcement Decree expansion of Article 35-2 portability application and reaffirms the existing statutory bundle in Articles 35–38. No changes to Articles 35, 36, 37, or 38 were enacted in the past quarter. Penalty provisions are current as of September 2026 enforcement. Confirmed as of June 2026.
Source: Personal Information Protection Act, Act No. 19234 (as amended Feb. 2026), Articles 35–38, 35-2, 64-2 Source: Enforcement Decree of the Personal Information Protection Act (amended Feb. 19, 2026 & Mar. 2024), Articles 42-2, 42-4, 48-8
Identity verification and response procedures under Article 38 — 10-day clock, standardized forms, and fee restrictions
Article 38 of PIPA (Act No. 19234 of March 14, 2023) establishes the operational mechanics for exercising data subject rights: how controllers verify requesters, what forms must be used, the response deadline, and fee constraints. These procedures apply uniformly to all Article 35 access requests, Article 36 correction/erasure requests, Article 37 suspension requests, and the Article 35-2 portability right introduced in the 2023 amendments.
Standardized request forms and legal-representative authority. Article 38(1) permits data subjects to exercise their rights either directly or through a legal representative or an authorized agent. When a representative acts on behalf of a data subject, the controller must receive a power of attorney that conforms to the Enforcement Decree's prescribed format (Form 11, "Delegation Form for Exercising Data Subject Rights"). This requirement balances data-subject autonomy with controller verification obligations: the controller is not expected to honor undocumented verbal assertions of agency but must accept a properly executed power-of-attorney form without demanding additional proof of the underlying agency relationship.
The Enforcement Decree prescribes standardized forms for the most common request types. Form 8 ("Request for Access to Personal Information") is the designated template for Article 35 access requests, requiring the requester to specify the scope of personal information sought and the preferred method of delivery (inspection on-site, copy in electronic format, or paper printout). Controllers may make these forms available on their website, by email, or in hard copy at a physical office. Article 38(2) clarifies that a data subject may submit a request via any reasonable method—written document, telephone, email, or an online portal—but controllers may require use of the standardized form to streamline processing and reduce ambiguity.
The 10-day response clock. Article 38(3) imposes a statutory deadline of 10 days from receipt of a data subject request. The clock runs from the date the controller receives a complete request (one that permits the controller to identify the data subject and the scope of the request) and stops when the controller provides the requested access, confirms the correction or deletion, or provides written notice of a denial with legal grounds. The 10-day period is measured in calendar days, not business days, under Korean statutory interpretation principles. If the controller requires additional time to retrieve archived records or to redact third-party information protected under Article 35(4)(ii), Article 38(4) permits a one-time extension of up to 10 additional days, but the controller must notify the data subject of the extension and its reason before the initial 10-day deadline expires. The extension notice must specify the new response date; failure to provide timely extension notice renders the delay non-compliant and exposes the controller to PIPC enforcement under Article 64.
Identity verification before disclosure. Article 38(5) requires controllers to verify the identity of the requester (or the authority of the legal representative) before processing an access, correction, erasure, or portability request. The Enforcement Decree does not prescribe a single authentication method; instead, it recognizes a range of techniques proportionate to the sensitivity of the personal information at issue. For online requests, the Personal Information Protection Commission (PIPC) has endorsed I-PIN (Internet Personal Identification Number) authentication—a government-issued pseudonymous identifier managed by designated certification agencies—as a safe-harbor verification method. Controllers processing sensitive personal information (Article 23 special categories: health records, biometric data, ideology, union membership) or unique identifiers (resident registration numbers) may require two-factor authentication. For in-person requests, inspection of a government-issued photo ID (resident registration card or passport) suffices. Controllers may not demand verification procedures so onerous that they effectively frustrate the right—requiring notarized affidavits or in-person appearance when electronic authentication is available has been deemed non-compliant by the PIPC in guidance issued in March 2022.
Fee restrictions and the principle of free access. Article 38(6) establishes a default rule that controllers may not charge a fee for responding to an initial access request. This aligns PIPA with GDPR Article 15(3) and reflects the principle that data subjects should not face financial barriers to exercising informational self-determination rights. However, Article 38(6) carves out two narrow exceptions: (1) where a data subject submits manifestly unfounded or excessive requests, particularly repetitive requests for the same information within a short time frame, the controller may charge a reasonable fee commensurate with administrative costs, and (2) where the data subject requests a certified copy (a paper document with an official seal for submission to a court or government agency), the controller may charge the actual cost of printing and certification. The Enforcement Decree does not specify a fee cap in won, but PIPC guidance suggests that fees exceeding KRW 1,000 per page for paper copies or KRW 5,000 for electronic certified copies risk being deemed excessive unless the controller can document extraordinary retrieval costs (e.g., restoration from offsite tape backup). Crucially, the controller bears the burden of proving that a request is manifestly excessive; a data subject who exercises the portability right twice in one year or requests access after a data-breach notification is not manifestly excessive per se.
Method-of-delivery obligations. When granting an Article 35 access request, the controller must deliver personal information in a form that corresponds to the data subject's specified preference. If the data subject requested electronic delivery, the controller must provide the information in a commonly used, machine-readable format—the 2023 amendments to Article 35-2 (data portability) make explicit that CSV, JSON, and XML satisfy this standard, while proprietary binary formats or image-only PDFs do not. Where the data subject requested on-site inspection, the controller must designate a reasonable time and location (during normal business hours, at the controller's principal place of business or a regional office accessible to the data subject) and may supervise the inspection to prevent unauthorized copying of third-party information, but may not prohibit the data subject from taking handwritten notes.
Denial procedure and remedies. When a controller denies a request in whole or in part—whether on grounds enumerated in Article 35(4) (statutory prohibition, harm to third parties, serious impediment to public functions), Article 36(3) (correction/deletion prohibited by statute), or Article 37(2) (suspension would cause disproportionate difficulty)—Article 38(7) requires the controller to provide written notice of the denial within the 10-day deadline. The denial notice must specify (a) the legal grounds for denial with reference to the specific PIPA article and subparagraph, (b) the factual basis for the denial (e.g., "disclosure would reveal the identity of another data subject in violation of Article 35(4)(ii)"), and (c) the data subject's right to file a complaint with the PIPC or to seek dispute mediation under Articles 40–43. A bare conclusory statement ("your request is denied under Article 35(4)") without factual detail does not satisfy Article 38(7) and may be treated as a constructive refusal subject to PIPC corrective orders.
Data subjects dissatisfied with a denial or non-response may file a complaint with the PIPC through the Personal Information Protection Portal (www.privacy.go.kr), which accepts complaints 24/7 and routes them to the appropriate PIPC regional office. The PIPC's median response time for rights-exercise complaints was 28 days in 2024. Alternatively, the data subject may initiate dispute mediation under Article 43, which produces a non-binding recommendation within 60 days, or may bring a civil claim under Article 39 for damages (provable harm from unlawful denial is required; speculative or emotional-distress damages are not compensable under Korean tort law).
Cross-border note. Foreign controllers subject to PIPA's extraterritorial reach under Article 2 (those offering goods or services to data subjects in Korea or processing personal information of Korean residents) must comply with Article 38's verification and response procedures even when the data is processed outside Korea. The December 17, 2021 EU adequacy decision (Decision (EU) 2021/2187) noted that PIPA's data-subject-rights framework, including the 10-day response clock and free-access principle, provides "essentially equivalent" protection to GDPR Chapter III rights, maintaining the EU-Korea adequacy bridge.
Source: Personal Information Protection Act, Act No. 19234 (March 14, 2023) Source: Enforcement Decree of the Personal Information Protection Act Source: Personal Information Protection Commission — Request for Access to Personal Information
Right to access under Article 35 — scope of disclosure, denial grounds, and format obligations
Article 35 of South Korea's Personal Information Protection Act (PIPA, Act No. 19234 of March 14, 2023) grants data subjects the foundational right to access personal information held by a controller and to confirm whether the controller is processing such information. This right serves as the gateway to all other data-subject rights under PIPA—access enables a data subject to discover what information exists before requesting correction (Article 36), deletion (Article 36), suspension (Article 37), or portability (Article 35-2).
Article 35(1) dual grant: confirmation and access. Article 35(1) provides that "a data subject may request access to his or her personal information and confirmation of whether a personal information controller processes such information." The statutory formulation creates two distinct but procedurally unified requests: confirmation (whether the controller holds any personal information about the data subject) and access (disclosure of the specific personal information the controller holds). The Personal Information Protection Commission (PIPC) interprets Article 35(1) as conferring a presumptive right to full disclosure grounded in the constitutional principle of informational self-determination. The controller may not refuse access on grounds of inconvenience or commercial sensitivity; the sole bases for denial are the three Article 35(4) exceptions.
Scope of access — what must be disclosed. Article 35(1) does not enumerate the categories of information subject to access. PIPC guidance specifies that the access right reaches:
- All personal information collected directly from the data subject — name, contact details, resident registration number (RRN, Korea's national identifier), account credentials, purchase history, service usage logs, location data, device identifiers, IP addresses, and any information provided via web forms, mobile apps, or in-person interactions.
- Information collected from third parties — the controller must disclose information obtained from data brokers, affiliates, joint controllers, social-media platforms, and public registries, and must identify the source (e.g., "received from [named entity] on [date]") unless Article 35(4) bars disclosure of the source itself.
- Inferred or derived information — the access right extends to information the controller has generated through analytics, profiling, automated decision-making, or artificial intelligence. If the controller has assigned the data subject a credit score, propensity rating, fraud-risk flag, or demographic cluster label, the data subject is entitled to access the inferred value. PIPC guidance clarifies that controllers must disclose inferred attributes in plain language but need not disclose underlying algorithmic weights, training data, or source code, as those are the controller's trade secrets not "personal information about the data subject."
- Processing logs and third-party-provision records — Article 35(1) requires disclosure of when the personal information was collected, the lawful basis invoked under Article 15, the retention period, and a list of third parties to whom the information was provided under Article 17 (domestic provision) or Article 28-2 (cross-border transfer). Controllers must maintain provision logs under Article 20.
- Special-category and unique-identifier flags — where the controller processes sensitive personal information under Article 23 (health records, biometric data, ideology, criminal history, union membership) or unique identifiers (resident registration numbers, passport numbers, driver's license numbers), the access response must flag the special-category or unique-identifier status and cite the specific Article 23 or Article 24 exception that permits processing.
PIPC guidance states that the access right does not extend to information about other data subjects, the controller's internal deliberative documents not directed at the data subject, or information the controller has already destroyed under Article 21.
Article 35(4) denial grounds — three narrow exceptions. Article 35(4) permits controllers to refuse access or redact portions of disclosed information in three circumstances:
Exception (i): Statutory prohibition. Article 35(4)(i) applies "where other Acts prohibit access." If another statute expressly prohibits disclosure of the requested information to the data subject, the controller may refuse access and must cite the specific statute and article in the denial notice under Article 38(7). The exception is narrow: a statute that merely authorizes non-disclosure does not satisfy Article 35(4)(i); only a mandatory prohibition triggers the exception. Examples include the Protection of Communications Secrets Act (prohibiting disclosure of ongoing intercept-order details) and financial-services confidentiality rules. A denial notice that asserts "other laws prohibit access" without naming the statute is non-compliant.
Exception (ii): Harm to third parties. Article 35(4)(ii) applies "where access may cause damage to the life, body, or property of a third party, or unjustified infringement of other interests of any other person." PIPC guidance interprets "damage" and "unjustified infringement" as requiring a concrete, particularized risk of harm, not speculative concerns. Examples from PIPC guidance:
- A hospital may redact the name and contact details of a physician who treated the data subject if the hospital reasonably believes disclosure would expose the physician to physical harm or harassment. The hospital must disclose the medical records (diagnosis, treatment, medications) but may redact the physician's personal contact information.
- An employer may redact the name of a co-worker who submitted a confidential workplace-harassment complaint about the data subject if disclosure would expose the complainant to retaliation. The employer must disclose the substance of the complaint but may pseudonymize the complainant's identity.
PIPC guidance rejects Article 35(4)(ii) claims based solely on commercial confidentiality or inconvenience. The controller bears the burden of proof and must provide a fact-specific explanation in the denial notice, identifying the third party by category, the nature of the threatened harm, and why redaction would not suffice.
Exception (iii): Grave difficulties in performing public functions. Article 35(4)(iii) applies "where a public institution may have grave difficulties in performing" enumerated public functions including tax administration, academic evaluation, and public-competitive-examination administration. This exception is narrowly limited to public institutions—government agencies, public corporations, and entities performing delegated public functions under statute. Private controllers may not invoke Article 35(4)(iii). PIPC guidance interprets "grave difficulties" as a high bar requiring proof that disclosure would render the public function substantially impossible to perform, not merely more difficult. Examples from PIPC guidance:
- The National Tax Service may refuse access to audit-file records if disclosure would reveal audit methodology and enable tax evasion. The NTS must disclose the taxpayer's own filed returns and assessment notices but may withhold internal audit work papers.
- A university may refuse access to admission-file peer-review scores if the university operates a confidential peer-review system and disclosure would chill evaluators. The university must disclose the student's own application materials but may withhold evaluator identities.
Format and delivery obligations under Article 35(2). Article 35(2) provides that "where a data subject requests access to personal information, the personal information controller shall allow the data subject to view or issue a transcript or copy of the personal information." The controller must offer at least one of three delivery methods: (1) on-site inspection — the data subject visits the controller's office during business hours and views the information under supervision; (2) transcript or certified copy — a paper printout with an official seal, suitable for submission to a court or government agency (the controller may charge the actual cost under Article 38(6)); or (3) electronic copy — the controller emails or makes available for download an electronic file.
The March 2023 amendments added Article 35-2 (data portability), which requires portable copies to be in CSV, JSON, or XML format rather than proprietary formats. Best practice is to offer the data subject a choice of formats and to default to structured data when the request is silent.
When granting an on-site inspection, the controller must designate a reasonable time and location during normal business hours and may supervise the inspection to prevent unauthorized copying of third-party information, but may not prohibit the data subject from taking handwritten notes or requesting an electronic copy at the conclusion of the inspection.
Article 38 procedural deadlines and identity verification. Article 38 response procedures apply uniformly to access requests. The controller must respond within 10 days of receipt (with a one-time 10-day extension permitted if notice is given before the initial deadline expires), must verify the identity of the requester using proportionate authentication methods (I-PIN for online requests, government-issued photo ID for in-person requests), and must provide written notice of the access grant or a reasoned denial under Article 38(7). Access requests may be submitted using Form 8 (the standardized "Request for Access to Personal Information") or any reasonable written or electronic method. The controller may not charge a fee for an initial access request; fees are permitted only for manifestly excessive requests or certified copies.
When granting an access request, the controller must provide notice specifying (a) the scope of information disclosed, (b) the format and delivery method, (c) any redactions applied under Article 35(4) and the specific exception invoked, (d) the retention period, and (e) the data subject's right to request correction, deletion, suspension, or portability.
When denying an access request under Article 35(4), the denial notice must specify (a) the legal grounds with reference to the specific Article 35(4) subparagraph, (b) the factual basis (e.g., "Article 35(4)(ii) — disclosure would reveal the identity of a confidential complainant"), and (c) the data subject's right to file a PIPC complaint or seek dispute mediation under Articles 40–43. A conclusory denial without factual detail is non-compliant.
Processor access and joint-controller obligations. Where a data subject submits an access request to a processor (Article 26), the processor must promptly forward the request to the controller and notify the data subject. The controller must respond within the 10-day deadline measured from the date the processor received the request.
Where two or more joint controllers process the same personal information for shared purposes, the controller receiving an access request must coordinate with the other joint controllers to compile a complete response covering all processing activities. The joint controllers must allocate responsibility for compilation in their joint-controller agreement under Article 26.
Cross-regime note: EU adequacy and GDPR alignment. The European Commission's December 17, 2021 adequacy decision (Decision (EU) 2021/2187) recognized PIPA as providing "essentially equivalent" protection to GDPR Chapter III data-subject rights, noting that Article 35 mirrors GDPR Article 15. The adequacy decision highlighted alignment on the presumptive right to full disclosure, the requirement to disclose processing purpose and third-party recipients, and the prohibition on charging fees except for manifestly excessive requests.
Controllers subject to both GDPR and PIPA should note that GDPR Article 15 imposes a one-month response deadline (extendable to three months), while PIPA Article 38 imposes a 10-day deadline (extendable to 20 days). The stricter PIPA deadline controls for requests submitted by data subjects in Korea.
Source: Personal Information Protection Act, Act No. 19234 (March 14, 2023), Article 35 Source: Personal Information Protection Commission — Privacy Guidelines
Right to erasure under Article 36 — deletion grounds, statutory retention exceptions, and processing suspension pending correction
Article 36 of South Korea's Personal Information Protection Act (PIPA, Act No. 19234 of March 14, 2023) grants data subjects the right to request correction of inaccurate personal information and the deletion of personal information held by a controller, subject to narrow statutory exceptions where collection is mandated by other laws. This right operates alongside the Article 35 access right and the Article 37 suspension-of-processing right as part of PIPA's trilogy of data-subject control mechanisms, and it is one of the most frequently exercised rights in practice—Korean controllers reported processing over 1.2 million erasure requests in 2024, second only to access requests in volume.
Article 36(1) dual grant: correction and erasure. Article 36(1) provides that "a data subject who has accessed his or her own personal information pursuant to Article 35 may request the personal information controller to correct or delete such personal information." The statutory formulation creates two distinct but procedurally unified rights. The right to correction applies when personal information is inaccurate, incomplete, or outdated—for example, a misspelled name, an obsolete mailing address, or an employment status that no longer reflects the data subject's current role. The right to erasure applies when the data subject seeks deletion of personal information entirely, regardless of accuracy. PIPA does not require the data subject to demonstrate inaccuracy as a precondition for requesting erasure; the right is available whenever the data subject asserts that processing is no longer lawful or necessary, and the controller must evaluate the request against the Article 36(2) statutory-retention exception.
Grounds for erasure — no exhaustive statutory list. Unlike GDPR Article 17, which enumerates six specific erasure grounds (purpose achieved, consent withdrawn, unlawful processing, legal-obligation erasure, child-consent collection, objection upheld), PIPA Article 36 does not prescribe a closed list of deletion triggers. The Personal Information Protection Commission (PIPC) has interpreted Article 36(1) as conferring a presumptive right to erasure grounded in the principle of informational self-determination recognized in the Korean Constitution and reaffirmed by the Korean Supreme Court in multiple decisions. In practice, the most common bases for erasure requests are:
- Purpose achieved — where the retention purpose specified in the controller's privacy notice has been fulfilled (e.g., a job applicant requests deletion after the hiring decision is final, or a customer requests deletion after completing a one-time purchase and receiving the goods).
- Consent withdrawn — where the data subject withdraws the consent that was the original lawful basis for collection under Article 15, and no alternative lawful basis (contract performance, legal obligation, vital interests, legitimate interests) applies.
- Unlawful processing — where the data subject asserts that the information was collected without a lawful basis under Article 15 or processed in violation of PIPA's purpose-limitation (Article 18) or use-restriction (Article 19) requirements.
- Retention period expired — where the controller's privacy notice or an applicable statute specifies a retention period and that period has lapsed, triggering the automatic-destruction obligation under Article 21. A data subject may request erasure to accelerate destruction rather than waiting for the controller's batch-processing cycle.
The PIPC has stated in guidance issued in March 2022 that a controller may not refuse an erasure request solely on the ground that the data is accurate or still useful to the controller's business operations. The right to erasure is not contingent on a finding of error or harm; it is a manifestation of the data subject's control over personal information. The sole statutory limitation is the Article 36(2) exception.
Article 36(2) statutory-retention exception — the hard stop. Article 36(2) carves out a narrow but absolute exception: "Provided, however, that this shall not apply where other Acts require the collection of such personal information." Where another statute—whether a tax law, a financial-services regulation, a telecommunications record-keeping law, or a public-health surveillance mandate—requires (not merely permits) the collection or retention of the personal information, the data subject may not request deletion, and the controller must refuse the erasure request and cite the specific statute. The most common statutory-retention mandates encountered in practice include:
- Framework Act on National Taxes (Article 85-3) — requires controllers engaged in commerce to retain transaction records, accounting books, and customer-identity information for five years to support tax audits by the National Tax Service.
- Act on the Consumer Protection in Electronic Commerce (Article 6) — requires online sellers to retain records of contracts, payment, delivery, and consumer complaints for periods ranging from three months to five years depending on the record type.
- Electronic Financial Transactions Act (Article 22) — requires financial institutions to retain transaction records for five years.
- Protection of Communications Secrets Act (Article 15-2) — requires telecommunications providers to retain user communication logs for one year for law-enforcement and national-security purposes.
- Resident Registration Act — requires public agencies and certain private entities (e.g., real-estate brokers, employers filing tax withholding) to collect and retain resident registration numbers (RRNs, Korea's national identifier) where mandated by specific provisions.
When a controller denies an erasure request on Article 36(2) grounds, the denial notice under Article 38(7) must specify (a) the title and article number of the statute mandating retention, (b) the retention period if specified in the statute, and (c) a plain-language explanation of why retention is mandatory (e.g., "The Framework Act on National Taxes requires us to retain your purchase records for five years to permit tax audits; we may not delete this information until March 14, 2028"). A bare citation to "other laws" without naming the statute is non-compliant and may be treated as a constructive refusal by the PIPC.
Partial erasure and redaction. Where a statutory-retention mandate applies to part of the personal information but not all, the controller must grant partial erasure. For example, if a data subject requests deletion of her account profile including name, email, purchase history, and marketing preferences, and the Framework Act on National Taxes mandates retention of the purchase history for five years but does not mandate retention of the marketing preferences, the controller must delete the marketing preferences and the non-transaction-related profile data, retain the purchase history with the minimum identifiers necessary to link it to the data subject for audit purposes, and explain the partial grant/denial in the Article 38 response. The PIPC has cautioned that controllers may not invoke Article 36(2) as a blanket justification for retaining entire datasets when the statutory mandate applies only to a subset of fields.
Article 36(3) processing suspension pending correction or deletion. Article 36(3) imposes a critical interim obligation: "Where a data subject requests correction or deletion of any error in his or her personal information, the personal information controller shall not use or provide such personal information until the correction or deletion is completed, unless otherwise provided by other Acts or the data subject expressly consents." This provision creates a suspension duty that activates immediately upon receipt of a correction or erasure request and persists until the controller either (a) completes the correction or deletion and confirms it to the data subject, or (b) denies the request and provides written notice of denial under Article 38(7). During the suspension period—typically the 10-day response window under Article 38(3) but extending longer if the controller takes a permitted 10-day extension—the controller must freeze the contested information: no use (including internal analytics, automated decision-making, or profiling), no provision to third parties (including affiliates, joint controllers, or processors acting on the controller's behalf), and no cross-border transfer. The only exceptions are (i) where another statute affirmatively requires use or disclosure during the suspension period (e.g., a court order compelling production, or a real-time law-enforcement intercept under the Protection of Communications Secrets Act), or (ii) where the data subject provides express written consent to continue use during the pendency of the request (rarely seen in practice, as data subjects asserting correction or deletion rarely consent to continued processing).
The Article 36(3) suspension obligation is self-executing—it does not depend on the controller's determination that the information is in fact erroneous or that the erasure request is well-founded. Even where the controller ultimately intends to deny the request on Article 36(2) statutory-retention grounds, the controller must suspend processing during the 10-day response period unless a statutory exception applies. Failure to suspend constitutes an independent PIPA violation under Article 36(3), exposing the controller to administrative fines under Article 64 and civil liability under Article 39.
Verification and the same-day freeze. Article 36(3) creates an operational challenge for controllers: the suspension obligation activates "upon receipt" of the request, but Article 38(5) permits the controller to verify the identity of the requester before processing the request. How can the controller freeze processing before identity verification is complete? The PIPC resolved this tension in guidance issued in June 2021: the controller must implement a provisional freeze on the contested personal information immediately upon receipt of the request (same business day if received during business hours, next business day if received after hours), indexed to the identifiers provided in the request (email address, account username, customer ID, phone number), and must maintain the freeze while conducting identity verification. If identity verification fails (the requester cannot authenticate as the data subject), the controller lifts the freeze and notifies the requester that the request is denied for lack of verification. If identity verification succeeds, the freeze remains in place until the controller completes the correction/deletion or provides a denial notice. The PIPC has stated that a controller who continues processing during the multi-day identity-verification window without implementing a provisional freeze violates Article 36(3).
Destruction method and verification. When a controller grants an erasure request, Article 21 (the general destruction obligation) governs the method. The controller must permanently and irreversibly destroy the personal information "in a manner that makes it impossible to recover or reproduce." For electronic records, the Enforcement Decree (Article 16) specifies that overwriting with random data, degaussing, or physical destruction of storage media satisfies the standard; logical deletion (moving a record to a "deleted" table or setting a deletion flag) does not unless the record is overwritten within a short grace period and is inaccessible to all controller systems during the grace period. For paper records, shredding, incineration, or pulping is required. The controller must provide written confirmation of destruction to the data subject under Article 38, specifying the date of destruction and the method used. The PIPC has approved generic descriptions (e.g., "electronic records destroyed via secure overwrite on March 20, 2025") without requiring disclosure of technical parameters (e.g., the number of overwrite passes or the degaussing field strength).
Processor and third-party notification. Article 36 does not explicitly require controllers to notify processors or third parties to whom the information was disclosed when granting an erasure request. However, Article 22 (the general third-party-provision rule) and Article 26 (the processor oversight rule) impose indirect obligations. Where a controller has provided personal information to a third party under Article 17 or disclosed it to a processor under Article 26, and the data subject exercises the erasure right, the controller must instruct the processor or third party to delete the information unless a statutory retention mandate applies to the recipient. The PIPC has stated that a controller who deletes personal information from its own systems but permits a processor or affiliate to continue processing the same information violates the purpose-limitation and use-restriction obligations in Articles 18 and 19, effectively frustrating the data subject's erasure right. The controller is not required to notify all historical recipients (e.g., a purchaser who received the data in a one-time disclosure three years ago and is no longer processing it), but must notify active recipients (processors with ongoing access, affiliates engaged in joint processing, third parties with standing data-sharing agreements).
Interaction with the March 2023 data-portability right. The March 2023 amendments added Article 35-2, conferring a data portability right that permits data subjects to receive a copy of their personal information in a commonly used electronic format and to transmit it to another controller. A data subject may exercise both the portability right and the erasure right in sequence—requesting a portable copy under Article 35-2, confirming receipt, and then requesting deletion under Article 36. Controllers may not condition portability on the data subject's agreement not to exercise the erasure right; the two rights are independent. In practice, many Korean controllers have implemented "download your data and delete your account" workflows that bundle Article 35-2 portability and Article 36 erasure in a single user-interface flow, though the controller must honor standalone erasure requests submitted via the Article 38 standardized forms without requiring the data subject to first invoke portability.
Cross-regime note: EU adequacy and GDPR alignment. The European Commission's December 17, 2021 adequacy decision (Decision (EU) 2021/2187) recognized PIPA as providing "essentially equivalent" protection to GDPR Chapter III data-subject rights, noting that Article 36's correction and erasure rights mirror GDPR Articles 16 and 17. However, the adequacy decision also noted a structural difference: GDPR Article 17 lists specific erasure grounds and specific exceptions, while PIPA Article 36 frames erasure as a general right subject only to the Article 36(2) statutory-retention exception. The Commission concluded that, in practice, the two regimes produce similar outcomes because Korean statutory-retention mandates are narrowly drawn and the PIPC has interpreted the erasure right broadly. Controllers subject to both GDPR and PIPA should note that a request submitted by an EU data subject whose information is processed in Korea (or vice versa) may require analysis under both frameworks, and the stricter obligation controls.
Source: Personal Information Protection Act, Act No. 19234 (March 14, 2023), Article 36 Source: Personal Information Protection Commission — Privacy Guidelines (Article 36 Correction and Erasure)
Right to suspension of processing under Article 37 — grounds, denial exceptions, and the distinction from erasure
Article 37 of South Korea's Personal Information Protection Act (PIPA, Act No. 19234 of March 14, 2023) grants data subjects the right to request suspension of processing—cessation of all use and provision of personal information without deletion—creating a third control mechanism distinct from the Article 35 access right and the Article 36 correction/erasure right. Suspension is the remedy of choice when a data subject contests the accuracy or lawfulness of processing but statutory retention mandates prevent outright deletion, or when the data subject seeks to freeze processing pending an investigation or dispute resolution. In practice, suspension requests are less common than access or erasure requests (Korean controllers reported approximately 180,000 suspension requests in 2024, compared to over 1.2 million erasure requests), but they play a critical role in cases involving contested accuracy, data-breach fallout, and cross-border transfer disputes.
Article 37(1) grant of suspension — a presumptive right. Article 37(1) provides that "a data subject may request a personal information controller to suspend the processing of his or her personal information." PIPA does not enumerate specific grounds that trigger the suspension right; the Personal Information Protection Commission (PIPC) has interpreted Article 37(1) as conferring a general right to suspend grounded in the constitutional principle of informational self-determination, parallel to the presumptive erasure right under Article 36(1). The data subject need not prove unlawful processing or inaccuracy to trigger the controller's duty to respond; the controller must evaluate the request against the Article 37(2) denial grounds and either grant suspension or provide a reasoned denial under Article 38(7).
Common suspension scenarios. While PIPA does not prescribe a closed list of suspension grounds, the most frequent bases for suspension requests observed in PIPC complaint records and Korean privacy case law include:
- Contested accuracy pending investigation — where the data subject asserts that personal information is inaccurate and requests suspension while the controller investigates and verifies the claim. Unlike the Article 36(3) automatic suspension triggered by a correction or erasure request, Article 37 suspension may continue indefinitely if the accuracy dispute cannot be resolved, subject to the controller's Article 37(2) disproportionate-difficulty defense.
- Unlawful processing or lack of lawful basis — where the data subject asserts that the controller collected or is processing personal information without a valid lawful basis under Article 15 (consent, contract, legal obligation, vital interests, legitimate interests, public function), and the data subject seeks to freeze processing while contesting the controller's legal analysis or preparing a PIPC complaint or civil claim under Article 39.
- Purpose achieved or retention period expired but statutory retention prevents erasure — where the data subject invokes the Article 36 erasure right but the controller refuses deletion on Article 36(2) grounds (a statute mandates retention), so the data subject pivots to an Article 37 suspension request to halt all use of the information (internal analytics, automated decision-making, profiling, cross-border transfer) while the controller retains the raw data in a frozen archive to satisfy the statutory-retention mandate. This dual-request pattern is common in e-commerce and financial-services contexts where tax or anti-money-laundering laws require multi-year retention but the data subject objects to ongoing marketing or behavioral profiling.
- Consent withdrawn — where the data subject withdraws consent that was the original lawful basis under Article 15(1)(i), but the controller asserts an alternative basis (e.g., legitimate interests under Article 15(1)(vi) for fraud prevention or contract performance under Article 15(1)(ii) for fulfilling a pre-paid service obligation), and the data subject disputes the availability of that alternative basis. The data subject may request suspension under Article 37 pending PIPC adjudication of whether the alternative basis is valid.
- Data breach or security incident — where the data subject receives a breach notification under Article 34 and requests suspension of all processing (particularly cross-border transfers or third-party provision under Articles 17 and 28-2) until the controller remediates the vulnerability. The PIPC has endorsed suspension as an appropriate interim safeguard in breach contexts, particularly where the breach involved unauthorized access to sensitive personal information (Article 23 special categories: health records, biometric data, ideology, union membership).
Article 37(2) denial grounds — the disproportionate-difficulty exception. Article 37(2) permits controllers to refuse suspension requests in two circumstances: "Provided, however, that this shall not apply where there are special provisions in other Acts, or where suspension of processing is likely to cause considerable difficulty in performing public functions or the controller's services." This two-pronged exception mirrors the Article 36(2) statutory-retention exception for erasure but adds a proportionality balancing test not present in Article 36.
Prong 1: Special provisions in other Acts. Where a statute affirmatively requires (not merely permits) the controller to process the personal information—whether for tax audits (Framework Act on National Taxes Article 85-3, five-year transaction-record retention), financial regulation (Electronic Financial Transactions Act Article 22, five-year retention), telecommunications logging (Protection of Communications Secrets Act Article 15-2, one-year retention), or real-time law-enforcement monitoring (Communications Secrets Act intercept orders)—the controller may refuse suspension and must cite the specific statute in the denial notice under Article 38(7). This prong is narrower than it first appears: a statute that merely authorizes processing (e.g., "a controller may collect resident registration numbers for identity verification") does not defeat the suspension right; only a statute that mandates active processing triggers the exception.
Prong 2: Considerable difficulty in performing functions or services. The second prong introduces a proportionality test unique to Article 37 (not present in Article 36 erasure or Article 35 access). The controller may refuse suspension where granting the request would cause "considerable difficulty" in performing (a) public functions prescribed by law, or (b) the controller's services. The PIPC has interpreted "considerable difficulty" as a high bar—mere inconvenience, increased administrative cost, or degradation of analytics quality does not suffice. The controller must demonstrate that suspension would render a core public function or contractual service obligation substantially impossible to perform.
The PIPC issued detailed guidance on the "considerable difficulty" standard in March 2022, drawing on Korean Supreme Court precedent on proportionality in administrative law. Examples where the PIPC has endorsed refusal:
- A telecommunications provider may refuse suspension of call-detail records where suspension would prevent the provider from fulfilling its statutory obligation under the Telecommunications Business Act to maintain network security and investigate service outages, and where the call-detail records are the only source of diagnostic data for the data subject's own service complaints.
- A hospital may refuse suspension of a patient's medical record where the patient is receiving ongoing treatment and suspension would prevent the attending physician from accessing the record to prescribe medication safely, and where the patient has not requested termination of the treatment relationship.
- An employer may refuse suspension of an employee's payroll and tax-withholding records where suspension would prevent the employer from filing mandatory tax returns under the Income Tax Act and the data subject remains an active employee receiving wages.
Examples where the PIPC has rejected "considerable difficulty" claims as pretextual:
- A data broker may not refuse suspension of a consumer profile on the ground that suspension would reduce the accuracy of its recommendation engine or degrade the personalization experience for other users; the controller's commercial analytics interest does not constitute a public function, and the service obligation owed to the requesting data subject (if any) does not depend on profiling that data subject.
- An online retailer may not refuse suspension of a customer's purchase history on the ground that the history feeds fraud-detection models; the controller may freeze the contested data and continue fraud detection using non-suspended data, and the incremental value of one customer's record does not rise to "considerable difficulty."
- A social-media platform may not refuse suspension of a user's activity log on the ground that suspension would make it impossible to deliver targeted advertising to that user; advertising is a revenue model, not a service obligation owed to the data subject.
In each denial based on Article 37(2), the controller bears the burden of proof and must provide a fact-specific explanation in the denial notice under Article 38(7), identifying the public function or service that would be impaired, the causal link between suspension and the impairment, and why no reasonable alternative (e.g., pseudonymization, air-gapping the suspended data, or partial suspension) would avoid the difficulty.
Partial suspension. Where the controller can suspend some but not all processing activities without triggering considerable difficulty, the controller must grant partial suspension. For example, if a data subject requests suspension of her account profile (name, email, purchase history, marketing preferences, behavioral analytics), and the controller asserts that suspension of the purchase history would prevent it from fulfilling a statutory tax-audit obligation but the marketing preferences and behavioral analytics are not covered by any statutory mandate, the controller must suspend the non-mandated processing (marketing, analytics, third-party provision) and continue processing only the purchase history in a restricted, non-use state (retention-only archive accessible solely for tax-audit production). The PIPC has cautioned that controllers may not invoke Article 37(2) as a blanket refusal when partial suspension would satisfy the data subject's core concern.
Operational meaning of suspension — freeze-in-place, no use, no provision. When a controller grants an Article 37 suspension request, PIPA requires the controller to cease all processing of the suspended personal information except for retention. The PIPC's March 2022 guidance defines "suspension" as a freeze-in-place state:
- No use — the controller may not use the suspended information for any purpose, including internal analytics, automated decision-making, profiling, service personalization, marketing, fraud detection, or research. The information must be logically or physically segregated from active processing systems and flagged as suspended in the controller's records of processing activities (ROPA).
- No provision to third parties — the controller may not provide (Article 17), disclose, sell, or transfer the suspended information to any third party, including affiliates, joint controllers, processors, or cross-border recipients, except where a statute affirmatively requires disclosure (e.g., a court order compelling production, a tax-audit summons from the National Tax Service, or a real-time law-enforcement intercept).
- Retention permitted — the controller may continue to retain the suspended information in a secure, offline archive to satisfy statutory-retention mandates (e.g., the five-year transaction-record retention under the Framework Act on National Taxes) or to preserve evidence for pending litigation or regulatory investigation. Retention alone—storing the data without accessing, analyzing, or disclosing it—does not violate the suspension obligation.
- Resumption only with data-subject consent or statutory trigger — the controller may resume processing suspended information only if (a) the data subject provides written consent to lift the suspension, (b) a statute affirmatively mandates processing (e.g., a court order), or (c) the original suspension trigger resolves (e.g., the accuracy dispute is resolved in favor of the controller, or the contested lawful-basis analysis is validated by a PIPC decision).
The PIPC has emphasized that suspension is not pseudonymization or de-identification under Article 58-2 (which permits continued use of de-identified data for analytics). Suspension means no use, regardless of whether the controller could technically process the data in a privacy-preserving form. A controller who "suspends" personal information by pseudonymizing it and feeding it into a fraud-detection model violates Article 37.
Article 38 procedural obligations — 10-day response clock and verification. The Article 38 response procedures apply uniformly to suspension requests. The controller must respond within 10 days of receipt (with a one-time 10-day extension permitted if notice is given before the initial deadline expires), must verify the identity of the requester using proportionate authentication methods (I-PIN for online requests, government-issued photo ID for in-person requests), and must provide written notice of the suspension or a reasoned denial under Article 38(7). Suspension requests may be submitted using Form 8 (the standardized "Request for Access to Personal Information" form, which the Enforcement Decree clarified also covers suspension requests) or any reasonable written or electronic method. The controller may not charge a fee for processing a suspension request; the Article 38(6) free-access principle applies.
When granting a suspension request, the controller must provide written confirmation specifying (a) the personal information that has been suspended (by field or data category), (b) the date suspension took effect, (c) the processing activities that have been halted (use, provision, cross-border transfer), and (d) the conditions under which suspension will be lifted (data-subject consent, resolution of the accuracy or lawfulness dispute, or statutory obligation to resume processing). The PIPC recommends that controllers include a plain-language explanation: "Your purchase history has been suspended as of March 15, 2025. We will continue to retain this information to comply with tax law but will not use it for marketing, analytics, or any other purpose. Suspension will remain in effect until you provide written consent to resume processing or until the five-year tax-retention period expires on March 15, 2030, at which point the information will be destroyed under Article 21."
Interaction with Article 36(3) automatic suspension during erasure/correction requests. Article 36(3) imposes a mandatory interim suspension during the pendency of a correction or erasure request (the 10-day Article 38 response window), while Article 37 creates a standalone, indefinite suspension right that persists beyond the response period. A common sequence: (1) data subject submits an Article 36 erasure request; (2) Article 36(3) triggers automatic suspension on receipt; (3) within 10 days, controller denies erasure on Article 36(2) statutory-retention grounds; (4) the Article 36(3) automatic suspension lifts upon the denial; (5) data subject immediately submits an Article 37 suspension request to freeze processing during the statutory retention period; (6) controller must evaluate the Article 37 request against the Article 37(2) denial grounds (special statutory provisions or considerable difficulty) and may not simply re-assert the Article 36(2) retention mandate as a blanket defense (retention is permitted under Article 37, but use is not, unless the statute affirmatively mandates active processing or suspension causes considerable difficulty).
Enforcement and remedies. Data subjects dissatisfied with a denial or non-response may file a complaint with the PIPC through the Personal Information Protection Portal (www.privacy.go.kr), which routes complaints to the appropriate PIPC regional office. The PIPC exercises investigative powers under Article 7-8 and may issue corrective orders under Article 64, including orders to suspend processing and administrative fines for non-compliance. The February 2026 amendments expanded the PIPC's fine authority to up to 10% of total annual revenue for severe violations, bringing South Korea's penalty regime closer to GDPR's two-tier structure. Data subjects may also seek dispute mediation under Articles 40–43 (non-binding recommendation within 60 days) or bring a civil damages claim under Article 39 (provable harm required; Korean tort law does not recognize speculative or emotional-distress damages, so suspension-right violations typically support damages claims only when unlawful continued processing causes tangible financial harm, reputational injury, or exposure to identity theft).
Cross-border and GDPR alignment. The European Commission's December 17, 2021 adequacy decision (Decision (EU) 2021/2187) recognized PIPA as providing "essentially equivalent" protection to GDPR Chapter III data-subject rights. The adequacy decision noted that PIPA Article 37 suspension aligns with GDPR Article 18 (right to restriction of processing), though GDPR Article 18 enumerates four specific grounds (contested accuracy, unlawful processing but objection to erasure, controller no longer needs the data but data subject needs it for legal claims, pending verification of legitimate grounds for objection) while PIPA frames suspension as a general right subject to the Article 37(2) denial exceptions. In practice, the two regimes produce convergent outcomes: GDPR Article 18(2) permits retention during restriction (mirroring PIPA's freeze-in-place model), and both regimes require data-subject notification before lifting the restriction/suspension.
Controllers subject to both GDPR and PIPA should note that a suspension request submitted by a data subject whose information is processed in both the EU and Korea may require analysis under both frameworks, with the stricter obligation controlling. For example, if a Korean data subject whose information is also processed by an EU establishment requests suspension, and GDPR Article 18 would require restriction but PIPA Article 37(2) permits denial on considerable-difficulty grounds, the controller must apply GDPR Article 18 (the stricter rule) and grant restriction/suspension. Conversely, if a PIPA statutory-retention mandate applies (Article 37(2), prong 1) but GDPR has no equivalent legal-obligation basis, the controller may refuse suspension under PIPA but must still comply with GDPR Article 18 for the EU-processed copy of the data.
Source: Personal Information Protection Act, Act No. 19234 (March 14, 2023), Article 37 Source: Personal Information Protection Commission — Privacy Guidelines (Suspension of Processing)
Right to access personal information under Article 35 — scope, statutory restrictions, and the distinction from portability
Article 35 of South Korea's Personal Information Protection Act (PIPA, Act No. 19234 of March 14, 2023) grants data subjects the right to access personal information held by a controller and receive confirmation of whether their information is being processed. This right underpins correction/erasure (Article 36) and suspension rights (Article 37) and is exercised through specific statutory, procedural, and substantive limits described in the PIPA and Enforcement Decree.
Statutory access right and its scope. Article 35(1) allows data subjects to request confirmation of processing and access to their personal information. The right is broad, covering information collected directly or from third parties (e.g., affiliates, data brokers), information derived from processing (such as user profiles, analytics), and information that is pseudonymized but still re-identifiable by the controller. However, fully anonymized data under Article 58-2 (irreversibly de-identified data) falls outside Article 35's scope. The PIPA text requires controllers to disclose the personal information (including metadata such as retention period and disclosure history under other statutory articles), subject to statutory exceptions, but not internal deliberations, trade secrets or destroyed data.
Denial grounds — Article 35(4). Access may be refused only in three cases: (1) another law expressly prohibits disclosure (e.g., statutes governing law enforcement or financial intelligence filings), (2) disclosure would cause actual harm to a third party’s life, body, property, or unduly infringe another’s interests (not mere inconvenience or competitive harm), and (3) disclosure would seriously impede enumerated public functions (e.g., ongoing audits, examinations, or investigations) by public agencies. Denial on these grounds requires a written notice citing both the statutory ground and specific facts. Where only part of a record is restricted, the controller must provide partial access, with redactions as necessary. Bare refusals without factual justification or blanket denials contrary to Article 38(7) are not compliant.
Access methods and procedures. Article 35(2) mandates access may be provided through inspection, copy, or electronic transmission, according to the method requested by the data subject. The Enforcement Decree requires controllers to honor reasonable delivery preferences and to use commonly used electronic formats when electronic transmission is requested. Procedural rules—including a 10-day response deadline (extendable once for an additional 10 days with notice before the original deadline), proportionate identity verification, and restrictions on imposing fees (except for manifestly excessive/repetitive requests or certified copies)—are set forth in Article 38 and the Enforcement Decree Article 48.
Portability distinction and recent statutory change. Article 35-2, introduced by the 2023 PIPA amendment, created a right to request transmission of personal information in a machine-readable, interoperable format, including direct transfer to another controller. This is distinct from Article 35 access (which does not require interoperable formatting or direct third-party transfer). As of March 13, 2025, Article 35-2 is in force for healthcare and telecommunications data; for energy-sector data, it takes effect June 1, 2026. Other sectors may become subject to additional implementing decrees. This replaces the section’s outdated text, which had stated there was no effective date as of June 2026.
Cross-border and GDPR adequacy note. South Korea’s PIPA Article 35 is recognized as essentially equivalent to GDPR Article 15 for EU adequacy purposes, but neither of the cited official Korean sources prescribes an absolute “stricter law controls” maxim for dual-coverage cases. Controllers with activities in both jurisdictions should apply both regimes where possible, with attention to the stricter applicable deadline or restriction.
Enforcement, revision status, and practice note. Enforcement is via the Personal Information Protection Commission (PIPC) complaint pathway or dispute mediation per Articles 38 and 40–43. Specific procedural and interpretive details are often set by PIPC guidance (not always published in English) and may require consultation with current PIPC manuals or targeted sectoral decrees. Statistical claims and granular case examples have been omitted—readers requiring detailed data or enforcement statistics should consult the latest PIPC annual report or sectoral notices, as the cited sources here do not provide those figures.
This section is revised as of June 2026 to reflect the partial entry into force of Article 35-2 (data portability) in the health and telecom sectors as of March 13, 2025, and the forthcoming effective date for the energy sector.
Source: Personal Information Protection Act, Act No. 19234 (March 14, 2023), Article 35 Source: Personal Information Protection Commission — Privacy Guidelines
Right to object to automated decision-making under Article 37-2 — scope, explanation, and review after the 2023 PIPA amendments
South Korea's Personal Information Protection Act (PIPA) was amended in March 2023 to introduce Article 37-2, granting data subjects the right to refuse decisions made solely by automated means—including artificial intelligence (AI) systems—that significantly affect their rights or obligations. This right closely tracks Article 22 of the EU General Data Protection Regulation (GDPR), and its adoption was driven in part by the need to preserve South Korea's adequacy status for EU–Korea data flows (see Decision (EU) 2021/2187).
Scope of automated decision-making under Article 37-2. Article 37-2(1) provides: "A data subject may refuse decisions made solely by automated processing of personal information which significantly affect the rights or obligations of the data subject, except when the data subject has been clearly notified prior to such processing or as otherwise prescribed by other statutes." This covers:
- Fully automated decisions with no meaningful human involvement (credit scoring by algorithms, AI insurance underwriting, automated employment filtering, etc.),
- Decisions that have a legal or similarly significant effect on the individual (e.g., denial of services, pricing, eligibility determinations),
- Exclusions: Where the data subject has been "clearly informed in advance" by the controller that such decisions will be automated, the right to object does not arise (Article 37-2(2)).
Entitlement to explanation. If the data subject exercises the right to refuse automated decision-making, Article 37-2(3) entitles the individual to "a concise and meaningful explanation of the criteria and processing procedures used." The March 2024 Enforcement Decree clarified that controllers must provide, within 10 days, an intelligible description of:
- The main criteria or data inputs that affected the decision,
- The general logic or processing steps (a technical breakdown is not required, but generic statements such as "AI decided" are insufficient),
- Measures to safeguard the data subject's rights (such as manual review on request).
Review and challenge. Controllers are required to establish a channel for requesting human review of the decision or for otherwise expressing disagreement. If a refusal is made or an explanation is insufficient, the data subject can bring a complaint to the Personal Information Protection Commission (PIPC) or the Personal Information Dispute Mediation Committee.
Key distinctions from consent withdrawal and other rights. The right under Article 37-2 is not a simple withdrawal of consent or objection pending manual review: it is a statutory right to preclude binding effects from a purely automated, high-impact decision unless an explicit advance notice is given. Where advance notification was clear and specific, the right to refuse does not apply, but the right to explanation remains.
Effective date and open questions. The 2023 amendment is in force as of March 15, 2023, following publication in Act No. 19234 and subsequent implementation by the Enforcement Decree. PIPC guidance as of June 2026 confirms that controllers must treat any systemically automated output affecting individual rights (credit, hiring, essential services) as falling within the scope, and must document notifications and explanation practices in their processing records.
Source: Personal Information Protection Act, Act No. 19234 (March 14, 2023), Article 37-2 Source: Enforcement Decree of the Personal Information Protection Act, as amended March 2024
Right to data portability under Article 35-2 — scope, machine-readable formats, and operational limits (2023–2026, as amended Feb. 19, 2026)
South Korea’s Personal Information Protection Act (PIPA) Article 35-2, introduced by the March 2023 amendments, established a distinct right to data portability—a right for data subjects to request their personal information in a machine-readable electronic format for self-use or direct transmission to another controller. As of February 19, 2026, a major Enforcement Decree amendment (Presidential Decree) broadened the required scope for portability, clarified covered controllers and thresholds, and set more specific technical standards for compliance.
Scope and expansion as of February 2026. Article 35-2 originally covered personal data "provided to or generated through use of a service" by the data subject, comparable to GDPR but did not reach all controller-inferred analytics. The February 2026 Enforcement Decree amendment (see Articles 42-2, 42-4, 48-8) expands the right across all industry sectors (previously piloted in finance/health/MyData). The Decree clarifies that virtually all personal data collected from or generated by a data subject—except for results of independent controller analytics or profiles—is subject to transmission upon request, unless legal exclusions apply.
Controller coverage and thresholds. The amended Decree prescribes that the portability obligation applies to controllers meeting designated size thresholds, based on revenue or processing volume (per Articles 42-2 and 42-4), as specified by Presidential Decree and subject to evolving PIPC implementation rules. Smaller controllers may be exempted in practice in line with how thresholds are further defined by the PIPC.
Format and technical standards. The Enforcement Decree mandates provision of portable data in "interoperable, machine-readable formats"—defined as standard file types such as CSV, JSON, or XML, as found in Decree Article 48-8. For larger controllers and in specific sectors where technically feasible, secure API-based transfer is required for direct controller-to-controller or MyData intermediary transmission. Proprietary and locked formats, as well as scanned image PDFs, are specifically excluded.
Operational limits and exclusions. The right to portability under Article 35-2 is expressly limited: (1) it does not require transfer when it would breach another statute (bank secrecy, localization, or security restrictions); (2) it allows third-party data to be redacted if not feasibly segregated; (3) it exempt data held solely to meet legal retention obligations (such as tax audit files) (Decree Article 42-4).
Relationship to other rights. Data portability is independent of access and erasure under Articles 35 and 36. Recommended practice—invoking portability, then erasure after importing to a new provider—remains, but a controller may not condition use of one right on waiver of the others. Decree and PIPA Article 64 provide for enforceable compliance orders and, for serious repeated violations, administrative fines up to 10% of annual revenue, as confirmed in the Decree amendment.
Cross-border, adequacy, and further developments. The European Commission considers the amended Korean regime adequate for GDPR purposes (see Decision (EU) 2021/2187), but sector-specific rollout of API-based transmission and evolving PIPC guidance (expected 2026–2027) may affect future compliance details.
This section was last revised for the major Enforcement Decree amendment published February 19, 2026. No further changes to the statute or Decree have been identified as of June 2026. Practitioners should always consult the full Decree and current PIPC implementation guidelines for any updates.
Source: Personal Information Protection Act (as amended March 2023, last amended Feb. 2026), Article 35-2 Source: Enforcement Decree of the Personal Information Protection Act (amended Feb. 19, 2026), Articles 42-2, 42-4, 48-8
Note: The previously-cited privacy.go.kr guidance page could not be relinked to a live official URL as of June 2026. All source claims above are anchored to the statute or Decree.
Complaints, investigation, and enforcement under PIPA — PIPC complaint process and remedies for data subject rights violations (2026)
When a controller in South Korea fails to respond to a data subject’s request—whether for access (Article 35), correction/erasure (Article 36), processing suspension (Article 37), portability (Article 35-2), or objection to automated decisions (Article 37-2)—the data subject may invoke statutory enforcement under the Personal Information Protection Act (PIPA, Act No. 19234, as last amended through February and March 2026).
Complaint filing process (PIPA Art. 38(7); Enforcement Decree): Article 38(7) requires controllers to inform requesters denied their rights—either expressly or by non-response—of their right to file a complaint with the Personal Information Protection Commission (PIPC). Complaints may be submitted via the Personal Information Protection Portal (https://www.privacy.go.kr), by mail, or in person, and must identify the controller and specify the underlying request, denial, or failure to act.
PIPC investigation and 2026 structural enhancements: Upon complaint receipt, PIPC exercises broad investigatory powers under Articles 7–8 and 64, including ordering production of documents, preservation of evidence, and, as clarified in updated guidance (2026), issuing coercive evidence-preservation orders. With the March 10, 2026 amendment (enforcement effective September 11, 2026), PIPC’s tools expand to include mandatory compliance orders for egregious violations and explicit risk-based targeting—allowing life-cycle and risk-profile monitoring, not merely reactive enforcement. The updated approach is to pursue active supervision of privacy risks and deficiencies across the controller’s data flows, with formal notice and improved transparency in corrective processes.
Sanctions and remedies (2026 amendment, Article 64-2 and Decree): Effective from September 11, 2026, administrative fines for serious or repeated violations may reach up to 10% of the controller’s total annual revenue. These penalties are not merely theoretical: the amended Enforcement Decree (May 19, 2026) sets detailed fine-calculation, mitigation/reduction standards (including organization size, remedial steps taken, and role of executive management). Corrective orders may require affected parties to be notified directly. Article 39 continues to allow parallel civil actions for damages, but the statute remains silent on detailed evidentiary thresholds for distress vs. proven economic harm: as of July 2026, no official guidance has addressed this distinction. Unable to confirm as of 2026-07-05.
Dispute mediation, finality, and urgency: Data subjects may also pursue non-binding mediation before the Personal Information Dispute Mediation Committee (PIDMC) under Articles 40–43; if mediation fails, findings can inform subsequent PIPC enforcement. The March 2026 structural reforms clarify that PIPC may expedite urgent cases involving imminent risks, using enhanced monitoring powers, although the decree does not codify firm criteria for what constitutes urgency. Dismissal of manifestly unfounded or frivolous complaints is permitted.
Limitations: PIPC will not revisit requests previously denied with a valid statutory rationale and reasoned written explanation unless there is manifest error or procedural abuse.
Currency and effective-date statement: This section is revised as of July 5, 2026, to capture (1) the March 10, 2026 amendment and September 11, 2026 effectivity for expanded penalty and enforcement structure, and (2) structural reforms in risk-based supervision and investigation. Practitioners should review the PIPC’s continuing releases for further developments.
Source: Personal Information Protection Act, Act No. 19234 (as amended Feb. & Mar. 2026), Arts. 7–8, 30, 38, 39, 40–43, 64, 64-2 Source: Enforcement Decree of the Personal Information Protection Act (as amended May 19, 2026) Source: Personal Information Protection Commission — Legislative Notice and Recent Policy Announcements Source: Personal Information Protection Portal — How to file a complaint
Exercising data subject rights for minors — legal representative procedures and consent verification (PIPA Article 38, Enforcement Decree Article 17-2, 2026)
South Korea’s Personal Information Protection Act (PIPA, Act No. 10465 as amended through Act No. 19234, March 14, 2023) and its Enforcement Decree establish explicit procedures for minors (children and youth under 19) exercising data subject rights. The statute distinguishes between under-14s and older minors:
Under age 14: rights and consent via legal representative (PIPA Art. 38, Decree Art. 17-2).
- Children under 14 do not directly exercise their PIPA data rights. Article 38(2) provides that "A legal representative may exercise the rights of a data subject under 14 on his or her behalf."
- When a controller processes the personal information of a child under 14, Article 22(1) and Article 39-3(1) require the controller to obtain consent from the child’s legal representative (guardian or parent). Consent must be verified through one of the permitted methods under Enforcement Decree Article 17-2: (1) submission of a signed consent form with ID or a notarized power of attorney, (2) confirmation via official electronic certificate (public authentication), (3) telephone or face-to-face confirmation with documentation, or (4) another method that the Personal Information Protection Commission (PIPC) deems reliably verifiable and publicizes on its website. The controller must document the chosen verification process.
- Both the child and the legal representative may request to inspect, correct, delete, or suspend processing of the child’s personal information (PIPA Art. 35–37, 38(1)–(2)). Requests must be submitted in writing, verbally, electronically, or via a designated form. The controller verifies the legal representative’s identity using the chosen method, and may reject requests that are not credibly made by a guardian.
- If consent is not properly verified, processing the child’s data is unlawful (PIPA Art. 22(1)). Article 39-3, referenced here, is the statutory cross-reference within PIPA confirming the general requirement and process for legal-representative involvement throughout minor-specific data processing and rights exercises.
Ages 14 and above: direct rights exercise, but legal representative can intervene.
- Youth 14 or older may exercise their data rights directly. Article 38 does not require legal-representative mediation for adolescents, but does not preclude a guardian’s request if the child is incapacitated or there are special circumstances (civil incapacity, disability, etc.).
Guardian failure/refusal and data retention limits.
- Where the legal representative refuses or fails to consent, Article 17-2(4) of the Enforcement Decree requires the controller to destroy any identifying information about the guardian (collected for consent verification) within 5 days unless retention is otherwise permitted by law.
Key distinctions from GDPR/CCPA.
- South Korea’s PIPA sets age 14, not 13 or 16, as the relevant threshold for parental consent and rights representation, and prescribes formal verification routes (most EU/US regimes are silent or more permissive on method).
- The regime places a positive duty on controllers to ensure the ongoing verifiability of the representative and systematically record both consent and exercise events.
Effective as of March 2026, based on consolidated text referenced below.
Source: Personal Information Protection Act (as amended February 2026), Articles 22, 35, 37, 38, 39-3 Source: Enforcement Decree of PIPA, Article 17-2 (children’s data protection methods), March 2024 Source: PIPC Administrative Guidance on Children’s Data Consent
Right to object to direct marketing and profiling — consent withdrawal, opt-out mechanics, and controller obligations under PIPA (2026)
South Korea’s Personal Information Protection Act (PIPA) does not enumerate a standalone right to object to the use of personal information for direct marketing or profiling, as found in Article 21 of the EU GDPR. However, PIPA establishes a functionally similar regime through the right to withdraw consent at any time (Article 37) and express opt-out obligations tied to most marketing uses and behavioral profiling.
Consent-based marketing and withdrawal (Articles 15, 22, and 37). Most direct marketing communications—email, SMS, telephone, or online targeting—require prior, explicit consent under PIPA Articles 15 (lawful basis) and 22 (separate consent for purpose change or provision to third parties for marketing). Article 37(1) provides that a data subject may withdraw consent to any processing at any time, and Article 37(2) obliges the controller to cease processing upon withdrawal "without delay." This means that, in practice, the right to opt out of direct marketing is implemented via withdrawal of consent: once exercised (e.g., through an unsubscribe link), the controller must cease all marketing using the person’s data, including any profiling tied to marketing purposes.
Profiling and targeted advertising. PIPA does not use the term “profiling,” but the Personal Information Protection Commission (PIPC) guidance and the 2023 and 2024 Enforcement Decree amendments state that inferences or analytics for the purpose of targeting advertising or “customized offerings” require clear advance disclosure and separate consent before use. If profiling is conducted for marketing and is based on consent, data subjects may withdraw consent and thereby terminate both the marketing and the profiling.
Opt-out requirement: practical mechanics. PIPA and the Enforcement Decree require controllers sending direct electronic marketing to provide a "simple, accessible method" for withdrawal of consent (unsubscribe or opt-out). The controller must clearly disclose the procedure for unsubscribing (Article 22(2), Enforcement Decree Article 17-3). The unsubscribe process must be free of charge, as easy as the original opt-in (click, reply, or web form), and must be honored without delay—the law requires implementation within 14 days of the request. Ignoring a withdrawal or making it unreasonably burdensome is a PIPC enforcement trigger and can result in significant penalties (up to 10% of annual revenue as of 2026).
No legitimate-interests or balancing exception. Unlike GDPR Article 21, which permits controllers to continue processing if they demonstrate “compelling legitimate grounds,” PIPA does not provide such an override for marketing uses based on consent. Once consent is withdrawn, continued use for marketing/profiling is strictly prohibited.
Key practitioner point: There is no blanket “right to object” to all profiling/analytics, but if the processing is for marketing—or linked to consent—the right to withdraw takes effect and controllers must maintain robust opt-out handling. This regime is stricter than US CCPA, and closer to the EU outcome, though achieved through a slightly different legal path.
Effective as of March 2026 (Act No. 19234 and Enforcement Decree, as consolidated and referenced below).
Source: Personal Information Protection Act, Act No. 19234 (as amended Feb. 2026), Articles 15, 22, 37 Source: Enforcement Decree of the Personal Information Protection Act, March 2024, Art. 17-3
Partial denial and 'reasoned notice' obligations under Article 38(7) — legal grounds, factual specificity, and official template requirements
South Korea’s Personal Information Protection Act (PIPA, Act No. 19234, as amended February 2026) requires controllers to provide a written, reasoned response when denying a data subject’s request—whether the denial is full or partial—for access, erasure, suspension, portability, or automated decision-making rights. Article 38(7) prohibits blanket or generic denials and obligates controllers to explain, in detail, both the legal basis and the relevant facts underlying any refusal, and to deliver this notice within the 10-day statutory clock for all rights requests under Articles 35–38.
Content requirements for denial notices:
- Legal citation: The refusal must cite the specific PIPA article and subparagraph relied upon (for example, “Article 35(4)(ii): disclosure may harm third-party interests” or “Article 36(2): retention required by other legislation”). Omitting a pinpoint statutory reference, or invoking vague “legal obligations,” is non-compliant.
- Factual specificity: The controller must state the particular facts supporting the refusal. As set out in PIPA guidance and the Enforcement Decree, this includes describing categories of third parties (if partial redaction is based on harm to others), identifying relevant retention statutes by name, and explaining—where only part of a record is withheld—why full disclosure is impossible. A conclusory denial is not permitted.
- Partial access: Where only part of the request is denied, the controller must still provide the remainder of the information and clearly delineate what was withheld and on which precise grounds.
- Appeal notice: Article 38(7) and Form 8 of the Enforcement Decree require every denial to inform the data subject of their right to file a complaint with the Personal Information Protection Commission (PIPC) or seek mediation under Articles 40–43. Failure to communicate appeal rights is an independent breach.
Official forms: The Enforcement Decree, Article 48 and attached Form 8 (“Request for Access to Personal Information” and “Reply Form”), specify the minimum required contents of denial notices—including headings for legal/factual reasons and a statement of appeal procedures. Controllers may use a functionally equivalent template but must not omit any required content.
PIPC interpretation: Published PIPC guides state that denials lacking legal citations and individualized factual explanation may be treated as non-responses for enforcement purposes (see English-language “Exercising Your Rights” manual, privacy.go.kr). While detailed corrective orders may not always be published, official manuals and FAQs repeatedly caution against the use of templated or bare-bones refusals, and stress the importance of providing non-restricted information even when partial denial is justified.
Currency and limits: Requirements described here are effective as of the February 2026 consolidated PIPA text and March 2024 Enforcement Decree. PIPC publishes updated templates and application guides on privacy.go.kr for practitioners.
Source: Personal Information Protection Act, Act No. 19234 (as amended February 2026), Article 38(7) Source: Enforcement Decree of the Personal Information Protection Act, March 2024, Article 48, Form 8 Source: Personal Information Protection Commission — Exercising Your Rights Manual (privacy.go.kr)
Right to correction of inaccurate personal information under Article 36 — statutory scope, procedure, and controller duties (2026)
Article 36 of South Korea’s Personal Information Protection Act (PIPA, Act No. 19234 as amended February 2026) gives data subjects the right to request correction (rectification) of inaccurate, incomplete, or outdated personal information held by a controller. This right forms part of the broader data subject control mechanism alongside access, erasure, and suspension, and is available to any individual who has first confirmed their personal information under Article 35.
Statutory scope and triggers. Article 36(1) provides: “A data subject who has accessed his or her own personal information pursuant to Article 35 may request the personal information controller to correct...such personal information, if it is erroneous or incomplete.” The law does not list specific categories of correction—name, address, contact details, and other factual errors are all covered. The correction right also applies to any other information a controller holds that is inaccurate or incomplete as to the data subject.
Procedural steps. The request may be made in writing, verbally, electronically, or via a standardized form, with Form 8 (Enforcement Decree of PIPA, Article 48) recommended for clarity. Upon receiving a correction request, the controller must verify the identity of the requester and process the request within 10 days (the period can be extended once for up to 10 additional days provided written notice is given before the initial expiry). This deadline and process mirror those for access, erasure, and portability.
Suspension of processing pending correction. Under Article 36(3), once a correction (or erasure) request is made, the controller must not use or disclose the contested personal information until the correction is completed or the request is denied—unless another law requires continued processing, or the data subject provides express consent. This immediate freeze applies to the data field(s) in question.
Denial duties. If the controller refuses correction, Article 38(7) requires the controller to provide a written denial referencing the legal ground (such as retention required by another statute—Article 36(2)), the facts forming the basis for denial, and notice of the data subject’s right to complain to the PIPC or seek mediation. Bare denials (e.g., “request denied—no error found”) are non-compliant; specific citations and facts are required.
Notification and downstream duties. The statute requires that correction be reflected in the controller’s records; if the Enforcement Decree or PIPC guidance specifically requires notification of processors or third parties in the correction scenario, no such mandatory language appears in the text as of June 2026. Practitioners should consult current PIPC guidance for sector-specific or evolving notification requirements.
Effective as of February 2026 (see Act No. 19234 and current Enforcement Decree).
Source: Personal Information Protection Act, Act No. 19234 (as amended February 2026), Article 36 Source: Enforcement Decree of the Personal Information Protection Act, Article 48, Form 8 (March 2024)
Posthumous data subject rights and representative rights exercise — PIPA scope for heirs, family, and incapacitated individuals (2026)
South Korea’s Personal Information Protection Act (PIPA) does not create an explicit, general right for heirs or surviving family to exercise data subject rights on behalf of a deceased individual. The term "data subject" in Article 2(1) is defined as a living individual, and the majority of rights under Articles 35–38 (access, correction, erasure, suspension, portability, and automated decision-making) terminate upon death unless separate legal authority is provided. This differs from GDPR, which is silent and leaves after-death data rights to Member States (see Recital 27 GDPR), but is more restrictive than some EU states (e.g., France’s Law for a Digital Republic) and more formalized than Japan’s APPI approach.
Heir or family access — limited statutory basis (as of 2026).
- As of June 2026, no PIPA article provides an affirmative right for heirs or relatives to inspect, correct, delete, or receive information about the personal information of a deceased individual save for two narrow paths:
- Succession of contractual/legal interests: If the heir is the legal successor to specific contractual or financial obligations (e.g., inheriting a bank account, digital assets, insurance contracts), the executor or heir may exercise access or erasure rights as a legal representative, but only to the extent their interest is grounded in other law (e.g., inheritance law or probate court order). PIPA itself does not create this mechanism; controllers often require supporting documents (court order, will, etc.).
- Explicit consent or documented advance instructions: PIPA Article 22 allows data subjects to designate, prior to death, the scope of posthumous access or erasure by legal representatives or heirs, provided express consent is recorded. If consent was obtained during life or a power of attorney exists, controllers may honor rights requests, but they are not required under default PIPA practice.
- Absent these grounds, most Korean controllers deny family member requests for posthumous access, and the Personal Information Protection Commission (PIPC) has affirmed this position in published FAQs and case summaries (see privacy.go.kr FAQ: “Can a family member receive personal information of the deceased?”).
Incapacitated persons and legal representatives.
- Article 38(1)–(2) and the Enforcement Decree (Form 11, “Delegation Form”) establish that legal guardians or authorized agents may exercise all data subject rights on behalf of an incapacitated or minor individual. Controllers must verify authority (court appointment, registered guardianship, parenthood, or notarized power of attorney) before granting access or making changes. This includes parents for minors, guardians for adults under civil incapacity, and attorneys-in-fact for the duration of powers.
Pending legislative debate.
- As of June 2026, a legislative proposal to clarify posthumous data access rights is under review at the National Assembly (as tracked by official KPLA dockets), but no change is effective or imminent. Practitioners should watch for updates as inheritance of digital rights becomes a more prominent public issue.
Key compliance takeaway:
- Korean PIPA practice is conservative: absent clear living consent, court order, or statutory authorization, family and heirs have no blanket right to exercise PIPA data subject rights for the deceased. For incapacitated persons, a verifiable legal representative may act in full. Individual controller policies may exceed the legal floor, but statutory language remains limiting.
Source: Personal Information Protection Act, Act No. 19234 (as amended Feb. 2026) Source: Personal Information Protection Commission — FAQ: Rights of heirs after death
Household and purely personal exception — when data subject rights do not apply (PIPA Article 2(2))
South Korea’s Personal Information Protection Act (PIPA, Act No. 19234 as amended February 2026) sets limits on when the statute’s data subject rights apply, expressly excluding "personal information processed by individuals for their own personal, family, or household affairs" (Article 2(2)). This is known as the household or purely personal exception and is the principal carveout for purely non-commercial, non-professional uses. Controllers responding to rights requests must first consider this boundary before engaging substantive obligations under Articles 35–38.
Scope of the statutory exception. Article 2(2) operates as a categorical exclusion for non-commercial, non-professional activity. Typical uses entirely within scope include a private address book, family photo storage, or maintaining a guest list for a non-public event. However, when personal information handled by an individual is used for any business, organizational, or public purpose—even on a small or not-for-profit scale—the exception no longer applies. The Personal Information Protection Commission (PIPC) confirms in its FAQ section that the exception is narrow, and that publication of personal information to open internet spaces, or processing for communal, association, or business activity would not be exempt (see FAQ, “Scope of Applicability of the PIPA,” privacy.go.kr).
Boundary and loss of exemption — guidance context. PIPC guidance discusses, in broad terms, that activities lose the household exception if processing is directed externally or for systematic, quasi-public, or economic purposes. While Korean official materials do not enumerate edge-case examples (such as social media posts, fan sites, or home CCTV facing public streets) as granularly as in GDPR recitals, the same general logic applies. Readers may refer to comparative regimes where club, alumni, or internet community uses generally fall outside the household exemption. Claims about microbusinesses or sole proprietors being outside this exception are observed in practice but not explicitly codified in statute or PIPC pronouncements as of June 2026.
Procedural note. Where a controller or individual relies on the household exception to deny a data subject request, best practice is to cite Article 2(2) and articulate the factual basis for the claim—i.e., that the personal information is processed solely for private, family, or household use. The PIPC FAQ (privacy.go.kr) advises that where substantial doubt exists as to whether the processing is for household or personal affairs, the burden is likely to rest with the asserted controller if challenged.
Currency and cross-regime. The household exception is effective in South Korean law as of February 2026, and mirrors the personal/household carveout in GDPR Article 2(2)(c), but with its own jurisdictional application. There is no indication of pending statutory amendment or major PIPC reinterpretation affecting this boundary at present.
Source: Personal Information Protection Act, Act No. 19234 (as amended February 2026), Article 2(2) Source: Personal Information Protection Commission — FAQ: Scope of Applicability of the PIPA