PIPA Article 17 — Statutory framework for overseas provision of personal information
South Korea's cross-border data transfer regime is governed by Article 17 of the Personal Information Protection Act (PIPA), enacted in 2011 and substantially amended in 2020 when the Personal Information Protection Commission (PIPC) was elevated to central administrative-agency status. The PIPC is the supervisory authority responsible for enforcement.
Article 17 uses the term "provision to a third party in a foreign country" rather than "transfer" — the same conceptual framework as domestic third-party disclosure under Article 17, but with heightened consent and transparency requirements when the recipient is located outside South Korea. A cross-border provision occurs when a personal information controller (정보처리자) transfers personal information to any natural or legal person located in a foreign jurisdiction, whether that recipient acts as an independent controller or as a processor on behalf of the Korean controller.
Consent-based transfers — Article 17(1) and (2)
Article 17(1) permits overseas provision only when the data subject has been separately informed of specific details and has given consent. The required disclosure elements under Article 17(2) are:
- The recipient and contact details of the person receiving the information in the foreign country;
- The country to which the information will be transferred;
- The purpose for which the recipient will use the information;
- The items of personal information to be provided;
- The period during which the recipient will retain and use the information; and
- The fact that the data subject has the right to refuse consent, and any disadvantages that may result from refusal.
This consent obligation is separate from and in addition to the general consent requirements under Articles 15 and 22 for collection and third-party provision. In practice, a Korean controller must layer consents: initial collection consent under Article 15, domestic third-party provision consent under Article 17 (if applicable), and then the heightened overseas-provision consent under Article 17(1)–(2).
Exceptions under Article 17(3)
Article 17(3) creates narrow exceptions mirroring those in Article 17(1) for domestic third-party disclosure, including where overseas provision is necessary for performance of a contract to which the data subject is party, or where required by statute or treaty obligation. These exceptions are construed strictly by the PIPC — contractual necessity is read functionally (the specific data element must be objectively required for contract performance), not as a blanket waiver.
No adequacy framework or standard contractual clauses
Unlike the GDPR Chapter V regime, PIPA does not recognize adequacy decisions or pre-approved standard contractual clauses (SCCs) as standalone transfer mechanisms. Every cross-border provision to a non-adequate jurisdiction requires individualized data-subject consent under Article 17(1)–(2) unless a statutory exception applies. Korea is a member of the APEC Cross-Border Privacy Rules (CBPR) system, but CBPR certification does not substitute for Article 17 compliance — it is a supplementary accountability signal, not a legal basis.
The Enforcement Decree of PIPA (Presidential Decree) implements Article 17 by specifying recordkeeping obligations and security safeguards for overseas provision, codified in Articles 48-10 and related provisions. Controllers must document each cross-border transfer, the legal basis, and the safeguards applied, similar to GDPR Article 30 records of processing activity (ROPA) but focused specifically on outbound transfers.
The PIPC enforces Article 17 through administrative fines up to 3% of revenue or KRW 300 million (approximately USD 220,000) under Article 34-2 of PIPA, and criminal penalties under Article 71 for egregious or intentional violations. Leading enforcement actions have targeted e-commerce platforms and cloud-service providers that embedded overseas data flows in general terms of service without the Article 17(2)-compliant layered disclosures.
Source: Personal Information Protection Act (Act No. 16930, as amended), Article 17
PIPA Article 17(3) — Adequacy recognition and PIPC certification as consent alternatives (2023 amendment)
The March 2023 amendment to PIPA (Act No. 19234, effective September 15, 2023) introduced two new pathways for cross-border personal-information transfers that do not require individualized data-subject consent under Article 17(1)–(2): adequacy recognition for countries with equivalent data-protection regimes, and PIPC certification for individual foreign recipients that meet prescribed standards. These mechanisms represent Korea's first movement toward a transfer framework resembling GDPR Chapter V, though consent remains the default and most widely used legal basis.
Adequacy recognition — Article 17(3), subparagraph 1
Article 17(3), subparagraph 1 permits transfers to a foreign country or international organization that the PIPC has formally recognized as maintaining "an equivalent level of data protection to that required under [PIPA]." This provision is modeled on GDPR adequacy decisions under Article 45, but as of May 2026 the PIPC has not published any adequacy determinations or the procedural framework for assessment.
The statutory text does not define "equivalent level." Secondary PIPC guidance (when published) is expected to evaluate foreign jurisdictions on criteria including: comprehensive data-protection statute with controller/processor obligations and data-subject rights; independent supervisory authority with enforcement powers; restrictions on onward transfers to third countries; and effective judicial remedies for data subjects. The analysis mirrors the European Commission's adequacy-decision framework under Recital 104 and Article 45(2) GDPR, adapted to PIPA's terminology (e.g., "personal information controller" rather than "data controller").
A cross-border provision to a recognized-adequate jurisdiction requires no separate consent under Article 17(1), but the controller must still satisfy the general third-party-provision notice requirements under Article 17 (domestic provision) and document the adequacy determination in its records of processing activity. The controller remains subject to PIPA security obligations under Article 29 and must verify that the recipient's jurisdiction remains on the PIPC adequacy list at the time of transfer.
PIPC certification of foreign recipients — Article 17(3), subparagraph 2
Article 17(3), subparagraph 2 permits transfers to a foreign natural or legal person that "has been certified by the [PIPC]" as meeting prescribed data-protection standards. This mechanism is conceptual equivalent to Binding Corporate Rules (BCRs) under GDPR Article 47 or to an entity-level certification scheme, but the implementing regulations specifying the certification criteria, application procedure, audit standards, and renewal cycle have not yet been promulgated by the PIPC.
The statutory text authorizes the PIPC to issue certifications to foreign recipients — whether acting as independent controllers or as processors on behalf of Korean controllers — on a case-by-case basis. The certification is expected to verify that the foreign recipient implements technical, administrative, and physical security measures equivalent to those required of Korean controllers under PIPA Article 29 and the Enforcement Decree, and that the recipient grants data subjects enforceable rights (access, rectification, erasure, objection) equivalent to Articles 35–38 of PIPA.
Once certified, the foreign recipient may receive personal information from any Korean controller without requiring Article 17(1)–(2) consent, provided the controller documents the certification number and validity period in its records and verifies that the certification remains in force. The PIPC retains authority under Article 17(4) to suspend or revoke the certification if the foreign recipient fails to maintain the prescribed safeguards or violates PIPA obligations, and to order the suspension of ongoing cross-border transfers to that recipient.
Practical status and limitations (May 2026)
As of May 2026, neither adequacy nor certification pathway is operationalized. The PIPC has not published:
- A list of adequate jurisdictions (no country has been recognized);
- Application forms, fees, or procedural timelines for entity certification;
- Audit standards or security benchmarks for certification eligibility; or
- Guidance on evidentiary requirements for demonstrating "equivalent" protection.
In practice, Article 17(1)–(2) individualized consent remains the predominant legal basis for cross-border transfers from Korea. Controllers relying on the contractual-necessity exception under Article 17(3), subparagraph 5 (mirroring the general exception in Article 15(1) subparagraph 2) must apply strict functional necessity — the specific data element must be objectively required for contract performance, not merely convenient. The PIPC enforces this narrowly: embedding a cross-border data flow in general terms of service does not satisfy the exception.
Korea is a member of the APEC Cross-Border Privacy Rules (CBPR) system, but CBPR certification is not recognized as a standalone legal basis under Article 17(3). A foreign recipient holding APEC CBPR certification must still either (a) obtain individualized data-subject consent under Article 17(1)–(2), (b) qualify for a statutory exception under Article 17(3), or (c) wait for the PIPC to operationalize the certification pathway and issue a Korea-specific certification.
The Enforcement Decree (Presidential Decree No. 35343, as amended February 25, 2025) implements Article 17 by requiring controllers to document each cross-border transfer in records of processing activity (Article 48-10), but does not yet contain the delegated rulemaking for adequacy or certification procedures. Controllers should monitor PIPC notices and enforcement-decree amendments for operationalization of these mechanisms.
The PIPC enforces Article 17 violations through administrative fines up to 3% of revenue or KRW 300 million (approximately USD 220,000) under Article 34-2, and criminal penalties under Article 71 for intentional or egregious violations. The PIPC's authority to suspend cross-border transfers under Article 17(4) applies to all transfer mechanisms, including adequacy and certification pathways once operational — if the PIPC determines that the foreign recipient or jurisdiction no longer satisfies the prescribed safeguards, it may order immediate suspension of ongoing transfers pending remediation or revocation.
Source: Personal Information Protection Act, Article 17(3) (Act No. 19234, effective September 15, 2023)
Article 30 PIPA — Privacy policy disclosure obligations for cross-border transfers
South Korean controllers transferring personal information to foreign jurisdictions must meet heightened transparency and disclosure obligations under Article 30 of the Personal Information Protection Act (PIPA) and the PIPC's Guidelines on Applying the Personal Information Protection Act to Foreign Business Operators (issued April 4, 2024). These requirements layer onto the separate-consent framework under Article 17 (renumbered Article 28-8 in some amendments), ensuring that data subjects can locate and understand cross-border transfer details before consenting.
Privacy policy — Article 30(1) general obligation
Article 30(1) of PIPA requires every personal information controller to "establish and publicly disclose a privacy policy" that informs data subjects of how their personal information is collected, used, and provided to third parties. For cross-border transfers, the privacy policy must include the specific elements mandated by Article 17(2) (or Article 28-8, depending on the statutory version in force):
- The recipient's identity and contact details — the name of the foreign natural or legal person receiving the personal information, plus a contact address or email where the data subject can reach that recipient directly;
- The destination country — the name of the foreign jurisdiction to which the information will be transferred (e.g., "United States," "Singapore");
- Purpose of use by the recipient — the specific processing purposes for which the foreign recipient will use the information (general statements such as "business operations" are insufficient; the PIPC expects functional specificity, e.g., "cloud storage and backup," "customer-support ticket processing");
- Items of personal information — an enumeration of the data elements being transferred (name, email, payment-card number, IP address, etc.);
- Retention period — how long the foreign recipient will retain and use the information; and
- Right to refuse consent and consequences — a statement that the data subject has the right to refuse consent for the overseas provision, and a disclosure of any disadvantages that may result from refusal (e.g., inability to use a particular service feature).
These six elements are mandatory for every cross-border transfer that relies on data-subject consent under Article 17(1)–(2). Controllers that fail to include them in the privacy policy—or that bury them in general terms of service without clear labeling—face administrative fines under Article 34-2 of PIPA (up to 3% of revenue or KRW 300 million, approximately USD 220,000).
PIPC Guidelines on Foreign Business Operators — April 2024 clarifications
The PIPC's April 2024 Guidelines impose additional specificity for foreign controllers operating in or targeting Korea:
- Korean-language disclosure: The privacy policy must be written in Korean and "specifically formulated to comply with PIPA." A global privacy policy written in English and merely translated does not satisfy this standard if it omits Korea-specific transfer details or uses GDPR terminology (e.g., "adequacy," "SCCs") without explaining the PIPA legal basis.
- Separate cross-border section: The Guidelines recommend that cross-border transfer details be disclosed in a separate, clearly labeled section of the privacy policy—labeled "Overseas Provision of Personal Information" (개인정보의 국외 이전) or similar—rather than folded into a general "third-party provision" clause. This separation ensures data subjects can locate transfer-specific information without reading the entire policy.
- Consolidation on a single page: If the controller discloses additional Korea-specific provisions beyond the global policy (e.g., PIPC certification status, Korea-only retention periods), those provisions should be consolidated on one web page accessible via the main privacy-policy link, not scattered across multiple sub-pages or annexes.
- Prior-version accessibility and change-highlighting: The privacy policy must remain accessible in its prior versions, and substantive changes (including new cross-border transfer destinations or recipients) must be highlighted for easy identification by returning users. The PIPC enforces this through its "transparency and accessibility" principle—data subjects must be able to see what has changed since their last consent.
Article 30 vs. Article 17 consent layer
The Article 30 privacy-policy disclosure is not a substitute for the Article 17(1)–(2) individualized consent. Article 30 imposes a passive transparency obligation—the controller must publish the transfer details in a publicly accessible document. Article 17 imposes an active consent obligation—the controller must affirmatively inform the data subject of the six elements at the point of transfer and obtain separate opt-in consent.
In practice, controllers typically satisfy both obligations by:
- Publishing the cross-border transfer details in the Article 30 privacy policy (general transparency);
- Displaying a layered consent interface at the point of collection or transfer that reproduces the Article 17(2) elements in a checkbox or modal dialog and requires the data subject to opt in before the transfer occurs; and
- Logging the consent event (timestamp, IP address, consent string) in a records-of-processing-activity (ROPA) system that can be produced during a PIPC audit.
Enforcement focus — e-commerce and cloud-service providers
The PIPC has prioritized enforcement against e-commerce platforms and cloud-service providers that embed cross-border data flows in general terms of service without the Article 17(2)-compliant layered disclosures. Leading enforcement actions have targeted controllers that:
- Listed "global partners" in the privacy policy without naming the specific foreign recipients or destination countries;
- Used boilerplate language such as "we may transfer your information to our affiliates worldwide" without enumerating which countries or entities;
- Pre-checked a consent box for overseas provision, or bundled overseas-provision consent with general terms-of-service acceptance, violating the separate-consent requirement; or
- Failed to disclose the retention period or the consequences of refusal.
Penalties in these cases have included administrative fines, mandatory corrective orders (requiring the controller to re-obtain compliant consent from all affected data subjects), and public disclosure of the violation on the PIPC website.
Recordkeeping and audit obligations
Controllers must document each cross-border transfer in their internal records of processing activity, as required by Article 48-10 of the Enforcement Decree of PIPA (Presidential Decree No. 35343, as amended February 25, 2025). The records must include:
- The legal basis for the transfer (Article 17(1) consent, Article 17(3) exception, or—once operational—adequacy or PIPC certification);
- The date and time of the transfer;
- The identity of the foreign recipient and the destination country;
- The data categories transferred; and
- Evidence of the data subject's consent (for Article 17(1) transfers) or documentation of the applicable exception (for Article 17(3) transfers).
The PIPC audits these records during inspections and can impose fines for inadequate documentation even if the underlying transfer was lawful. Controllers should retain transfer records for at least three years from the date of the transfer, consistent with general PIPA recordkeeping standards, though sector-specific regulations (e.g., financial services, telecommunications) may impose longer retention periods.
Interplay with APEC CBPR and adequacy
Korea is a member of the APEC Cross-Border Privacy Rules (CBPR) system, but CBPR certification of a foreign recipient does not reduce the Article 30 disclosure obligations or the Article 17(1) separate-consent requirement. A controller transferring personal information to a CBPR-certified processor in Singapore must still:
- Disclose the processor's identity, Singapore as the destination country, the purpose, the data items, and the retention period in the Article 30 privacy policy; and
- Obtain individualized data-subject consent under Article 17(1)–(2).
CBPR certification is a supplementary accountability signal that may inform the controller's due-diligence assessment of the foreign recipient, but it is not recognized by PIPA as a standalone legal basis for transfer.
Similarly, when the PIPC operationalizes the adequacy recognition pathway under the March 2023 amendment (Article 17(3), subparagraph 1), transfers to recognized-adequate jurisdictions will still require Article 30 privacy-policy disclosure of the recipient, destination country, purpose, data items, and retention period—consent under Article 17(1) will no longer be required, but transparency under Article 30 remains mandatory.
Practical compliance steps
To satisfy Article 30 and the April 2024 PIPC Guidelines, controllers should:
- Audit existing privacy policies for completeness of the six Article 17(2) elements for every cross-border transfer relationship;
- Create a dedicated "Overseas Provision" section in the Korean-language privacy policy, listing each foreign recipient by name, destination country, purpose, data items, and retention period in a table or enumerated list;
- Implement layered consent at the point of transfer, reproducing the six elements in a modal dialog or checkbox interface separate from general terms-of-service acceptance;
- Log consent events with timestamp, IP address, and consent string, and retain logs for at least three years;
- Update the privacy policy whenever a new cross-border transfer relationship is established, and highlight the change prominently on the policy page; and
- Train compliance personnel on the distinction between Article 30 transparency (passive, policy-based) and Article 17 consent (active, opt-in).
Failure to meet these disclosure and transparency obligations is a leading cause of PIPC enforcement actions, even when the underlying transfer is otherwise lawful and secured by contract.
Source: Personal Information Protection Act, Article 30 (Act No. 19234, effective September 15, 2023)
Article 28-11 PIPA — Onward-transfer restrictions when foreign recipients re-transfer to third countries
When a foreign recipient of Korean personal information subsequently transfers that data to a third country (an "onward transfer" or "sub-transfer"), South Korean law applies the same cross-border transfer safeguards to the second-leg transfer as it did to the initial outbound transfer from Korea. This onward-transfer rule is codified in Article 28-11 of the Personal Information Protection Act (PIPA), enacted in the March 2023 amendment (Act No. 19234, effective September 15, 2023), and ensures that Korean data subjects' rights travel with their data regardless of how many jurisdictions it crosses after leaving Korea.
Article 28-11 statutory text and scope
Article 28-11 PIPA states:
> "When a recipient of personal information in a foreign country further provides such personal information to a third country or international organization, the provisions of this Act relating to cross-border transfers of personal information shall apply accordingly."
The provision imposes a chain-of-custody obligation: each subsequent transfer in the chain must comply with PIPA's cross-border transfer rules (Articles 28-8 through 28-10) as if the sub-recipient were receiving the data directly from the original Korean controller. This means:
- Consent or statutory exception required for each onward leg — If the initial transfer from Korea to Country A was authorized by data-subject consent under Article 28-8(1)(1) (the separate-consent pathway with the six disclosure elements under Article 28-8(2)), the onward transfer from Country A to Country B must also be authorized by either:
- Fresh data-subject consent under Article 28-8(1)(1) and (2), disclosing the Country B recipient's identity, destination, purpose, data items, retention period, and right to refuse; or
- One of the Article 28-8(1) exceptions (contractual necessity under subparagraph 2, PIPC certification under subparagraph 3, adequacy recognition under subparagraph 5, or treaty/law under subparagraph 6).
- Security safeguards under Article 48-10 of the Enforcement Decree — Each onward transfer must implement the security measures, complaint-handling mechanisms, and data-subject rights guarantees prescribed by Article 48-10 of the Enforcement Decree (Presidential Decree No. 35343, as amended February 25, 2025). The European Commission's adequacy decision for Korea (Commission Implementing Decision (EU) 2022/254, February 17, 2022) describes this obligation: "For each transfer, specific safeguards must be put in place with respect to security, the handling of complaints and disputes, as well as other measures necessary to protect users' information" (Recital 113).
- Controller liability and supervision obligations — Article 28-11 does not relieve the original Korean controller of its Article 26 supervision and education obligations over the foreign recipient. If the foreign recipient onward-transfers to a sub-recipient without satisfying Article 28-11, the Korean controller remains vicariously liable under Article 26(6) PIPA, which deems the foreign recipient (and any sub-recipient in the onward-transfer chain) to be employees of the Korean controller for purposes of compensation liability under Article 39.
Practical application — multi-hop cross-border data flows
Article 28-11 is triggered in three common scenarios:
A. Cloud subprocessors and nested entrustment
A Korean e-commerce platform (Controller) transfers customer data to a US cloud-infrastructure provider (Recipient 1, acting as processor) under the Article 28-8(1)(2) contractual-necessity exception (entrustment or storage necessary for contract performance, disclosed in the privacy policy). Recipient 1 uses a subprocessor in Singapore (Recipient 2) for database replication.
- The Korea → US transfer is lawful under Article 28-8(1)(2) if the platform disclosed the US provider's identity, destination (United States), purpose, data items, and retention period in its privacy policy or via email to data subjects, and the transfer is objectively necessary for performance of the customer's service contract.
- The US → Singapore onward transfer triggers Article 28-11. Under Article 28-11, the US provider must ensure that the Singapore subprocessor transfer complies with Article 28-8. Because the original legal basis was Article 28-8(1)(2) (contractual necessity), the onward transfer to Singapore must also be necessary for contract performance and disclosed to the data subjects. If the Singapore subprocessor is not necessary for the customer's contract (e.g., it is purely a cost optimization by the US provider), the onward transfer fails Article 28-11 and the Korean controller is liable.
- The Korean controller must document the entire chain (US → Singapore) in its records of processing activity under Article 48-10 of the Enforcement Decree, including the legal basis for each hop and the security safeguards applied by both the US provider and the Singapore subprocessor.
B. Corporate group data-sharing and adequacy bridges
A Korean subsidiary (Controller) transfers employee HR data to its German parent company (Recipient 1) under Article 28-8(1)(5) (adequacy recognition — the EU was formally recognized by the PIPC on September 16, 2025, as having equivalent protection under Article 28-8(1)(5), per PIPC Notice). The German parent subsequently transfers the data to a subsidiary in India (Recipient 2) for payroll processing.
- The Korea → Germany transfer is lawful under Article 28-8(1)(5) because Germany is in the EU/EEA adequacy zone recognized by the PIPC. No separate data-subject consent is required under Article 28-8(1)(1).
- The Germany → India onward transfer triggers Article 28-11. India is not recognized as adequate by the PIPC (as of June 2026, only the EU/EEA has been recognized). Therefore, the German parent must either:
- Obtain fresh data-subject consent from the Korean employees under Article 28-8(1)(1) and (2), disclosing the India recipient, or
- Rely on another Article 28-8(1) exception (e.g., contractual necessity under subparagraph 2 if the India payroll processing is necessary for the employees' employment contracts and disclosed in the privacy policy).
- If the German parent onward-transfers to India without satisfying Article 28-11, the Korean subsidiary is liable under Article 26(6) even though the violation occurred in Germany, because the German parent was acting as a "trustee" (processor/recipient) in the onward-transfer chain.
C. Cross-border M&A and change-of-control transfers
A Korean fintech startup (Controller) transfers customer financial data to a US SaaS provider (Recipient 1, processor) under Article 28-8(1)(1) consent. The US provider is acquired by a Chinese technology company (Recipient 2), and the data is migrated to servers in China as part of the acquisition.
- The Korea → US transfer was lawful under Article 28-8(1)(1) consent initially.
- The US → China onward transfer (triggered by the acquisition) is a new cross-border transfer under Article 28-11. The Korean fintech must ensure that the China recipient complies with Article 28-8. Because China is not recognized as adequate by the PIPC (and does not hold a PIPC certification as of June 2026), the fintech must:
- Obtain fresh consent from each Korean customer under Article 28-8(1)(1) and (2), disclosing the China recipient's identity, the People's Republic of China as the destination, the purpose, data items, retention period, and right to refuse; or
- Cease the onward transfer to China and migrate the data back to a jurisdiction for which it holds a valid legal basis.
- Failure to obtain fresh consent before the China migration constitutes an Article 28-11 violation, exposing the Korean fintech to PIPC administrative fines under Article 64-2 (up to 3% of revenue or KRW 300 million, approximately USD 220,000) and potential criminal liability under Article 71 for intentional violations.
Interaction with EU adequacy bridge and mutual recognition
The PIPC and the European Commission formally recognized each other's frameworks as equivalent in 2025 (EU adequacy decision for Korea adopted February 17, 2022, as Commission Implementing Decision (EU) 2022/254; Korea adequacy recognition for EU/EEA adopted September 16, 2025, per PIPC Notice). Both adequacy decisions incorporate onward-transfer safeguards to maintain continuity of protection.
Under the EU-Korea adequacy bridge:
- A transfer from Korea to Germany (EU member state) under Article 28-8(1)(5) adequacy is lawful without consent.
- A subsequent transfer from Germany to the United States (a third country outside the EU/EEA adequacy zone) must comply with both GDPR Chapter V (the EU controller in Germany must use SCCs, BCRs, or another GDPR transfer mechanism) and PIPA Article 28-11 (the Korean controller must ensure the US recipient satisfies Article 28-8).
- The EU adequacy decision for Korea explicitly contemplates this dual compliance: "To maintain continuity in personal data protection during onward transfers, the PIPC and the European Commission have agreed to mutually inform each other of developments concerning the operation of their respective cross-border transfer systems, including new recognitions of equivalence or adequacy decisions" (Commission Implementing Decision (EU) 2022/254, Recital 24, as cited in secondary sources).
PIPC enforcement and suspension authority under Article 28-9
The PIPC has statutory authority under Article 28-9 PIPA to order the suspension of cross-border transfers, including onward transfers under Article 28-11, if:
- The transfer violates Article 28-8 (e.g., no valid legal basis, insufficient disclosure, coerced consent); or
- The foreign recipient or sub-recipient fails to implement the prescribed security safeguards under Article 48-10 of the Enforcement Decree.
The Enforcement Decree (Article 29-14) specifies that the PIPC must consider factors including the severity of the violation, the volume and sensitivity of the data, the harm to data subjects, and whether the controller/recipient has taken corrective action. The controller may object to a suspension order within seven days of receipt, and the PIPC must respond within 30 days (Enforcement Decree Article 29-14(3)).
Once a suspension order is issued, the Korean controller must immediately cease the onward-transfer relationship and either:
- Migrate the data back to Korea or to a jurisdiction for which it holds a valid Article 28-8 legal basis;
- Obtain fresh data-subject consent or PIPC certification to re-authorize the transfer; or
- Delete the data under Article 21 PIPA if continued processing is no longer lawful.
Failure to comply with a suspension order is a separate violation under Article 75(3) PIPA, punishable by imprisonment of up to two years or a fine of up to KRW 20 million (approximately USD 15,000).
Recordkeeping and documentation obligations
Controllers must document the entire onward-transfer chain in their records of processing activity under Article 48-10 of the Enforcement Decree. The records must include, for each hop in the chain:
- The identity and contact details of the foreign recipient and each sub-recipient;
- The destination country for each transfer;
- The purpose, data categories, and retention period at each stage;
- The legal basis under Article 28-8(1) for each transfer (consent, contractual necessity, certification, adequacy, treaty);
- Evidence of data-subject consent (timestamp, IP, consent string) if Article 28-8(1)(1) was the basis;
- Documentation of the security safeguards, complaint-handling procedures, and data-subject rights mechanisms implemented by each recipient in the chain; and
- Contracts with each foreign recipient and sub-recipient specifying the Article 26 supervision, education, and vicarious-liability obligations.
These records must be retained for at least three years from the date of the last transfer and must be produced to the PIPC upon request during an audit or investigation. Controllers that fail to maintain adequate onward-transfer documentation face administrative fines under Article 75(2) PIPA even if the underlying transfers were lawful.
Cross-border controller-to-controller onward transfers
Article 28-11 applies not only to processor-to-subprocessor transfers (entrustment chains under Article 26) but also to controller-to-controller onward transfers. If the foreign recipient acts as an independent controller (e.g., a data broker, marketing platform, or analytics provider that uses the data for its own business purposes), and that foreign controller subsequently shares the data with a third controller in another jurisdiction, Article 28-11 requires the original Korean controller to ensure that the second-leg transfer complies with Article 28-8.
In practice, this imposes a contractual due-diligence obligation: the Korean controller must include a clause in the data-transfer agreement requiring the foreign controller to:
- Notify the Korean controller of any planned onward transfers to third countries before they occur;
- Obtain the Korean controller's prior written approval for each onward transfer;
- Ensure that the third-country recipient satisfies Article 28-8 (consent, contractual necessity, certification, adequacy, or treaty); and
- Flow down the same onward-transfer restrictions to the third-country recipient in a written contract.
If the foreign controller onward-transfers without the Korean controller's approval or in violation of Article 28-11, the Korean controller is jointly and severally liable with the foreign controller under Article 39 PIPA for any damages to the data subjects, unless the Korean controller proves it exercised reasonable supervision and had no knowledge of the violation.
APEC CBPR and Article 28-11 compliance
Korea is a member of the APEC Cross-Border Privacy Rules (CBPR) system, but CBPR certification of a foreign recipient or sub-recipient does not satisfy Article 28-11 as a standalone legal basis. A Korean controller transferring data to a CBPR-certified processor in Japan must still:
- Rely on one of the Article 28-8(1) legal bases (consent, contractual necessity, etc.); and
- Ensure that any onward transfer by the Japanese processor to a sub-recipient in another APEC economy (e.g., Singapore) complies with Article 28-11.
CBPR certification is a supplementary accountability signal that may inform the controller's due-diligence assessment of the foreign processor's data-protection capabilities, but it does not substitute for the Article 28-8 legal-basis requirement or the Article 48-10 security-safeguard obligations. The PIPC has not published guidance recognizing CBPR as a substitute for PIPC certification under Article 28-8(1)(3), and controllers should not rely on CBPR alone to authorize onward transfers.
Comparison to GDPR onward-transfer regime
Article 28-11's onward-transfer framework resembles GDPR Article 44 (general principle that all Chapter V transfer rules apply to onward transfers from a third country) but is more restrictive in practice because:
- PIPA does not recognize standard contractual clauses (SCCs) as a standalone transfer mechanism — every onward transfer requires either individualized consent, contractual necessity (narrowly construed), PIPC certification (not yet operationalized as of June 2026), or adequacy (only EU/EEA recognized).
- GDPR permits onward transfers from an adequate third country (e.g., UK → US) using SCCs or BCRs without returning to the original EU controller for fresh consent; PIPA Article 28-11 requires the Korean controller to document and verify that each onward leg satisfies Article 28-8, even if the first-leg recipient is in an adequate jurisdiction.
- PIPA's vicarious liability rule under Article 26(6) makes the Korean controller strictly liable for onward-transfer violations by any recipient in the chain, whereas GDPR liability is more nuanced and depends on the controller-processor relationship and the adequacy of the contract.
Controllers accustomed to GDPR compliance should not assume that a GDPR-compliant onward-transfer chain (e.g., EU SCC → UK Addendum → US SCC) automatically satisfies PIPA Article 28-11. Each onward leg must be separately analyzed under Korean law, and the Korean controller must retain documentation demonstrating compliance.
Source: Personal Information Protection Act, Article 28-11 (Act No. 19234, effective September 15, 2023)
Article 48-10 Enforcement Decree — Security safeguards and contractual measures for cross-border transfers
South Korean controllers transferring personal information to foreign jurisdictions must implement specific technical, organizational, and contractual safeguards prescribed by Article 48-10 of the Enforcement Decree of PIPA (Presidential Decree No. 35343, as amended February 25, 2025). These requirements go beyond the Article 28-8 legal-basis determination (consent, contractual necessity, adequacy, or certification) and impose affirmative obligations on the controller to secure the data, handle complaints, and guarantee data-subject rights throughout the transfer relationship. Article 48-10 is the operational backbone of cross-border transfer compliance — satisfying the legal basis is necessary but not sufficient; controllers must also document and maintain the prescribed safeguards for each transfer.
Article 48-10 statutory mandate and scope
Article 48-10 of the Enforcement Decree states that for each cross-border transfer of personal information, the controller must put in place specific safeguards with respect to:
- Security measures to protect the data during transmission, storage, and processing by the foreign recipient;
- Complaint-handling and dispute-resolution mechanisms that allow Korean data subjects to lodge complaints and obtain remedies for violations; and
- Other measures necessary to protect users' information, including ongoing supervision of the foreign recipient and contractual obligations that flow down PIPA requirements.
This obligation applies to every cross-border transfer, regardless of the legal basis. A transfer authorized by data-subject consent under Article 28-8(1)(1), a transfer relying on the contractual-necessity exception under Article 28-8(1)(2), a transfer to an adequate jurisdiction under Article 28-8(1)(5), and a transfer to a PIPC-certified recipient under Article 28-8(1)(3) (once operationalized) all trigger the Article 48-10 safeguard requirement. The only distinction is evidentiary: transfers relying on consent or contractual necessity require the controller to document the safeguards proactively and produce them during a PIPC audit, whereas transfers to adequate jurisdictions or certified recipients benefit from a rebuttable presumption that the safeguards are in place (because adequacy and certification assessments incorporate Article 48-10 compliance as a condition).
The European Commission's adequacy decision for Korea (Commission Implementing Decision (EU) 2022/254, adopted February 17, 2022) describes the Article 48-10 obligation as follows: "For each transfer, specific safeguards must be put in place with respect to security, the handling of complaints and disputes, as well as other measures necessary to protect users' information" (Recital 113). The adequacy decision recognizes Article 48-10 as a core element of Korea's transfer framework, ensuring continuity of protection when personal information leaves Korean territory.
Security measures — technical and organizational safeguards
The security component of Article 48-10 requires controllers to implement and verify that the foreign recipient maintains technical and organizational measures equivalent to those prescribed for domestic processing under Article 29 PIPA and Article 48-2 of the Enforcement Decree. These include:
- Encryption of personal information during transmission (TLS 1.2 or higher for data in transit) and at rest (AES-256 or equivalent for databases and backups storing personal information);
- Access controls limiting the number of employees and systems that can access the personal information, with role-based access control (RBAC) and logging of all access events;
- Intrusion detection and malware protection using software and network monitoring to detect and block unauthorized access attempts;
- Physical security for data centers and server rooms, including restricted access, surveillance, and environmental controls;
- Secure deletion and destruction protocols when the retention period expires or the legal basis for processing ends, with documented destruction logs; and
- Internal management plans specifying the controller's and foreign recipient's respective security responsibilities, the technical measures in place, and the audit schedule.
The controller must document these safeguards in writing, typically through a data processing agreement (DPA) or data transfer addendum with the foreign recipient. The DPA should enumerate the specific security measures the foreign recipient has implemented, including certifications (ISO/IEC 27001, ISMS-P, SOC 2 Type II), the encryption algorithms in use, the access-control policies, and the frequency of security audits. The controller retains ongoing supervision obligations under Article 26 PIPA (trustee supervision), meaning the controller must periodically verify that the foreign recipient continues to maintain the prescribed safeguards — annual or biannual audits, security questionnaires, or third-party attestations are common evidence.
Complaint-handling and dispute-resolution mechanisms
Article 48-10 requires the controller to establish accessible mechanisms for Korean data subjects to lodge complaints about the foreign recipient's processing of their personal information and to obtain remedies. This obligation ensures that cross-border transfers do not dilute data subjects' rights — the fact that the data is in a foreign jurisdiction must not prevent the data subject from exercising the rights guaranteed by PIPA (access, rectification, erasure, objection under Articles 35–38).
In practice, controllers satisfy the complaint-handling requirement through contractual clauses in the DPA requiring the foreign recipient to:
- Accept complaints directly from Korean data subjects in Korean language (or provide translation services) via email, web form, or mail;
- Respond to complaints within the timelines prescribed by PIPA — typically within 10 business days for acknowledgment and 30 days for substantive response, consistent with the Article 35 access-request timeline;
- Cooperate with the Korean controller in investigating and resolving the complaint, including producing records of processing activity, access logs, and consent documentation;
- Escalate unresolved disputes to the Korean controller for final resolution, or to the Personal Information Dispute Mediation Committee under Article 43 PIPA if the data subject elects statutory mediation; and
- Indemnify the Korean controller for damages awarded to the data subject under Article 39 PIPA if the violation was caused by the foreign recipient's failure to comply with PIPA obligations.
The DPA should also specify the governing law and jurisdiction for disputes. While the foreign recipient may be subject to the laws of its home jurisdiction for general commercial disputes, the DPA should explicitly state that PIPA governs the processing of Korean personal information and that the Korean controller (or the data subject) may bring enforcement actions in Korean courts or before the PIPC. This ensures that Korean data subjects retain access to Korean remedies even when the recipient is abroad.
Some controllers implement a centralized complaint portal on their Korean-language website where data subjects can submit complaints about any recipient in the cross-border transfer chain. The controller then routes the complaint to the responsible foreign recipient and monitors resolution. This model satisfies the Article 48-10 complaint-handling requirement and simplifies the data subject's experience, but it increases the controller's operational burden and vicarious liability exposure under Article 26(6).
Contractual measures — data processing agreements and flow-down obligations
The "other measures necessary to protect users' information" language in Article 48-10 is a catch-all requiring controllers to impose contractual obligations on foreign recipients that mirror the controller's own PIPA obligations. The contractual measures must address:
A. Scope and purpose limitation
The DPA must specify the categories of personal information being transferred, the processing purposes authorized, and the prohibition on use for any other purpose. The foreign recipient may not repurpose the data for its own business objectives (e.g., marketing, analytics, AI training) unless it obtains separate data-subject consent or qualifies for a PIPA exception. This mirrors the Article 15 purpose-limitation principle.
B. Retention and deletion obligations
The DPA must state the retention period for the personal information — the maximum duration the foreign recipient may retain the data before it must be securely deleted or returned to the Korean controller. The retention period must align with the period disclosed to the data subject under Article 28-8(2)(5) (the sixth element of the cross-border transfer consent disclosure). Once the retention period expires, the foreign recipient must delete the data within a specified timeframe (commonly 30 or 60 days) and provide a written certification of deletion to the Korean controller.
C. Subprocessor and onward-transfer restrictions
The DPA must require the foreign recipient to obtain the Korean controller's prior written approval before engaging a subprocessor or onward-transferring the data to a third country. This implements the Article 28-11 onward-transfer rule, which requires each subsequent transfer in the chain to satisfy Article 28-8. The DPA should specify the approval process (e.g., 30-day notice period, list of pre-approved subprocessors, right of the controller to object) and require the foreign recipient to impose equivalent contractual obligations on any subprocessor ("flow-down" clauses).
D. Data-subject rights support
The DPA must obligate the foreign recipient to assist the Korean controller in responding to data-subject rights requests (access, rectification, erasure, restriction, portability, objection under Articles 35–38). Because the data subject's contractual relationship is with the Korean controller, not the foreign recipient, the foreign recipient must provide the controller with the information and tools needed to satisfy the request. Common contractual provisions include:
- A commitment to respond to the controller's requests for data extracts, deletion confirmations, or processing logs within 10 business days;
- Technical integrations (APIs, data portability formats) that enable the controller to retrieve the data subject's information from the foreign recipient's systems; and
- A prohibition on charging fees to the controller for rights-support services (the foreign recipient may not monetize its PIPA compliance obligations).
E. Breach notification obligations
The DPA must require the foreign recipient to notify the Korean controller immediately (and in any event within 24 hours) of any personal-information breach affecting the transferred data. This enables the controller to meet its own 72-hour breach-notification obligation to the PIPC and affected data subjects under Article 34 PIPA. The DPA should specify the information the foreign recipient must include in the breach notice: the nature and scope of the breach, the categories and volume of affected data, the root cause, remediation steps, and whether the breach triggered notification obligations in the foreign recipient's jurisdiction.
F. Audit and inspection rights
The DPA must grant the Korean controller (or a third-party auditor designated by the controller) the right to audit the foreign recipient's security measures, complaint-handling procedures, and PIPA compliance documentation at reasonable intervals (annually or upon reasonable suspicion of a violation). The audit may be conducted remotely (document review, questionnaire) or on-site at the foreign recipient's data center. The foreign recipient must cooperate with the audit, produce requested records, and remediate any deficiencies identified by the auditor within a specified cure period (commonly 30 or 60 days).
G. Indemnification and liability allocation
The DPA should allocate liability for PIPA violations and data-subject damages. Under Article 26(6) PIPA, the Korean controller is vicariously liable for violations by the foreign recipient (the recipient is deemed an "employee" of the controller for purposes of Article 39 compensation liability). The DPA typically includes an indemnification clause requiring the foreign recipient to indemnify and hold harmless the Korean controller for any damages, fines, or penalties arising from the recipient's breach of PIPA obligations. This does not eliminate the controller's primary liability to the data subject or the PIPC, but it allows the controller to seek reimbursement from the foreign recipient after satisfying the claim.
Recordkeeping and production during PIPC audits
Controllers must retain written evidence of the Article 48-10 safeguards for at least three years from the date of the transfer, consistent with the general PIPA recordkeeping standard. The records must be produced to the PIPC upon request during an audit or investigation. Required documentation includes:
- The executed DPA or data transfer addendum with the foreign recipient, including all amendments and addenda;
- Evidence of the foreign recipient's security certifications (ISO 27001 certificate, ISMS-P certification, SOC 2 Type II report) current at the time of the transfer;
- Records of ongoing supervision activities: audit reports, security questionnaires, breach notifications, and remediation logs;
- Complaint logs showing data-subject complaints about the foreign recipient's processing and the resolution;
- Deletion certificates or return-of-data confirmations when the retention period expires;
- Documentation of the legal basis for each transfer (consent records, contractual-necessity analysis, adequacy determination, PIPC certification number); and
- Internal management plans specifying the roles and responsibilities of the controller and the foreign recipient for maintaining the Article 48-10 safeguards.
Failure to maintain adequate records is a separate violation under Article 75(2) PIPA, punishable by administrative fines, even if the underlying transfers were lawful and secured.
PIPC enforcement focus — AliExpress and contractual-safeguard failures
The PIPC has prioritized enforcement of Article 48-10 safeguards in recent years, particularly against cross-border e-commerce platforms and cloud-service providers that transfer Korean customer data abroad without implementing the prescribed contractual and security measures. A leading enforcement action involved AliExpress, a China-based online marketplace, which the PIPC sanctioned in July 2024 for multiple violations including:
- Unlawful cross-border data practices — transferring Korean customer data to China without adequate safeguards under Article 48-10;
- Transparency failures — failing to disclose the transfer details (recipient, destination country, purpose, retention period) in the privacy policy as required by Article 30;
- Missing contract clauses — no DPA with the Chinese data processors specifying security measures, complaint-handling, or data-subject rights support; and
- Barriers to user rights — an English-only account-deletion page that hindered Korean data subjects from exercising their Article 36 erasure right.
The PIPC imposed administrative fines and issued a corrective order requiring AliExpress to implement Article 48-10-compliant DPAs with all Chinese recipients, establish a Korean-language complaint portal, and re-obtain consent from all affected Korean users with the required Article 28-8(2) disclosures. The enforcement action underscores that contractual safeguards are not optional — the PIPC views the absence of a compliant DPA as a per se violation of Article 48-10, regardless of whether the foreign recipient's actual security practices are adequate.
Interaction with adequacy and PIPC certification
When the PIPC operationalizes the adequacy recognition pathway under Article 28-8(1)(5) (EU/EEA recognized in September 2025), transfers to adequate jurisdictions will still require Article 48-10 safeguards, but the evidentiary burden shifts. The adequacy determination itself incorporates an assessment of whether the foreign jurisdiction's legal framework ensures security, complaint-handling, and data-subject rights equivalent to PIPA. Therefore, a controller transferring data to an adequate jurisdiction satisfies Article 48-10 by documenting the adequacy determination and implementing a baseline DPA that references the foreign jurisdiction's data-protection law (e.g., GDPR for EU transfers) as the governing safeguard framework.
Similarly, when the PIPC issues entity-level certifications under Article 28-8(1)(3), the certification will verify that the foreign recipient has implemented Article 48-10-compliant security measures, complaint-handling procedures, and data-subject rights mechanisms. A controller transferring data to a PIPC-certified recipient may rely on the certification as evidence of Article 48-10 compliance, but the controller must still execute a DPA specifying the scope, purpose, retention period, and onward-transfer restrictions, and must verify that the certification remains in force at the time of each transfer.
Cross-border controller-to-controller vs. controller-to-processor safeguards
Article 48-10 applies to both controller-to-processor transfers (entrustment under Article 26) and controller-to-controller transfers (third-party provision under Article 17). The required safeguards differ slightly:
- For processor relationships (cloud storage, payroll processing, customer-support outsourcing), the DPA focuses on processing instructions, security measures, subprocessor controls, and return-or-deletion obligations. The Korean controller retains full control over the processing purposes and means; the foreign processor acts solely on the controller's documented instructions.
- For controller-to-controller transfers (data sharing with affiliates, marketing platforms, analytics providers), the DPA must specify the independent processing purposes of the foreign controller, obtain data-subject consent for those purposes (or rely on another Article 28-8 exception), and impose onward-transfer restrictions. The Korean controller has less supervisory authority but retains joint liability under Article 39 for violations by the foreign controller.
In both cases, the security, complaint-handling, and contractual measures prescribed by Article 48-10 apply in full.
Practical compliance checklist
To satisfy Article 48-10 for cross-border transfers, controllers should:
- Execute a written DPA or data transfer addendum with every foreign recipient before the first transfer occurs, covering security measures, complaint-handling, data-subject rights support, breach notification, audit rights, and indemnification.
- Document the foreign recipient's security posture — obtain current copies of ISO 27001, ISMS-P, SOC 2, or equivalent certifications, and enumerate the encryption standards, access controls, and physical safeguards in the DPA.
- Establish a Korean-language complaint channel on the privacy-policy page or customer-support portal, with clear instructions for data subjects to lodge complaints about foreign recipients' processing.
- Implement ongoing supervision — schedule annual security questionnaires, third-party audits, or on-site inspections of foreign recipients, and document the results in compliance logs.
- Track retention periods and deletion deadlines — maintain a calendar of when each transfer's retention period expires, and obtain written deletion certificates from foreign recipients within 60 days of expiry.
- Train privacy personnel on the distinction between legal basis (Article 28-8) and safeguards (Article 48-10), and ensure that both are documented for every cross-border transfer in the records of processing activity.
- Prepare for PIPC audits — consolidate all DPAs, security certifications, audit reports, complaint logs, deletion certificates, and consent records in a centralized compliance repository accessible during an investigation.
Failure to implement Article 48-10 safeguards exposes the controller to administrative fines under Article 64-2 (up to 3% of revenue or KRW 300 million, approximately USD 220,000), corrective orders requiring suspension of the transfer relationship until safeguards are implemented, and vicarious liability under Article 39 for any damages caused to data subjects by the foreign recipient's violations.
Article 26 PIPA — Security safeguards and mandatory contractual clauses for cross-border entrustment
Material update (effective September 11, 2026):
The statutory text of Article 26 of South Korea’s Personal Information Protection Act (PIPA) was amended by Law No. 21445 (promulgated March 10, 2026; effective September 11, 2026). The main substantive changes relevant to cross-border entrustment are:
- Terminology update in security obligations: Article 26(4) and related references throughout the Act were amended to replace the list of adverse events ("loss, theft, leakage, forgery, alteration, or damage") with the consolidated term “유출등” ("leakage, etc."). The intent is to modernize and streamline the statutory language concerning adverse security incidents for entrusted personal information, including cross-border transfers. All contracts and internal documentation should update the referenced statutory citations and language for compliance with the revised Act.
- Expanded reference to new security and reporting articles: Article 26(8) was amended to incorporate explicit references to newly added Article 30-2 (Measures in Case of Leakage, etc., of Personal Information) and Article 30-3, strengthening the linkage between trustee (processor) obligations and breach remediation/reporting rules in the event of a data incident. Controllers must ensure their entrustment contracts and operational protocols address these new obligations starting September 2026.
All other core requirements for cross-border entrustment under Article 26 and Article 28 of the Enforcement Decree remain in effect:
- Controllers must continue to supervise foreign entrusted processors, require all eight mandatory clauses in entrustment contracts (per Article 28 of the Enforcement Decree), and impose technical, organizational, and contractual safeguards at least equivalent to those specified in PIPA and the Enforcement Decree.
- The controller’s non-delegable supervision, the requirement of prior written consent for subprocessing, strict vicarious liability, and the need for prompt data return/destruction and notification—all remain unchanged, except that cited statutory language and references must be updated to reflect the 2026 amendments.
Controllers should review all cross-border entrustment and data processing agreements to update contract language, templates, and compliance protocols in advance of the September 11, 2026 effective date, and ensure that breach notification and incident-handling processes now specifically address references to Articles 30-2 and 30-3, alongside the revised wording for "leakage, etc."
Source: Personal Information Protection Act, Article 26 (Law No. 21445, effective September 11, 2026) Source: Enforcement Decree of the Personal Information Protection Act, Article 28 (Presidential Decree No. 35343, February 25, 2025)
PIPA Articles 35–38 — Data subject rights and redress for cross-border personal-information transfers
South Korean data subjects retain a robust set of statutory rights under Articles 35–38 of the Personal Information Protection Act (PIPA) after their personal information has been transferred abroad. These rights include: access (Article 35), rectification and erasure (Article 36), suspension of processing (Article 37), and redress procedures (Article 38). Controllers must generally respond to requests within 10 days (see Enforcement Decree Article 41(1)), and must provide clear, Korean-language channels for rights requests even when data is held by an overseas recipient. Controllers are also contractually required to ensure overseas recipients cooperate with rights requests as far as technically possible.
Material update — Expanded right to data portability (Article 35-2; Enforcement Decree Article 42-2, eff. Feb. 2026):
In addition to the traditional rights, the 2023 statutory amendment—effective from September 15, 2023—introduced Article 35-2, granting data subjects the right to request a copy of their personal information in a portable, machine-readable format and/or direct its transmission to a third party, including across borders. The scope and compliance mechanism for this right were significantly expanded by amendment to the Enforcement Decree, effective February 19, 2026 (Presidential Decree No. 35343, Article 42-2). This amendment clarifies which controllers are “Data Portability Obligors” and the process by which requests must be handled. The obligations apply broadly to any controller processing personal information at scale, including those engaging in international data transfers. Controllers must enable the exercise of the data portability right in all cases where the data subject requests it, including onward transfer to a third country.
Strict liability and redress: Korean controllers remain strictly and vicariously liable for all actions of their overseas recipients (Article 26(6)), including compliance with data subject rights requests. Data subjects denied their rights may seek redress through the Personal Information Protection Commission (PIPC) or the Personal Information Dispute Mediation Committee. Controllers that fail to comply may face administrative fines (Article 64-2 PIPA).
Procedural note: As of June 2026, the statutory and regulatory framework for data subject rights and redress in cross-border personal information transfers—now including data portability—is fully in force. Controllers should review and update compliance programs, contracts, and request-handling workflows to reflect both the expanded scope and procedural requirements of the 2026 Enforcement Decree amendment.
Source: Personal Information Protection Act (Act No. 19234, as amended September 15, 2023), Articles 26(6), 35-38, 35-2, 39, 43, 64-2 Source: Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 35343, as amended February 25, 2025 & February 19, 2026), Articles 41, 42-2, 48-10
PIPC suspension orders and enforcement — Article 28-9 and cross-border transfer prohibitions
PIPC suspension of cross-border personal-information transfers — Article 28-9
The Personal Information Protection Commission (PIPC) has express statutory authority under Article 28-9 of the Personal Information Protection Act (PIPA) to suspend or prohibit cross-border transfers of personal information. This power may be exercised at any point—either preemptively or after a breach—where the PIPC determines that a recipient abroad (or the circumstances of the transfer) fail to provide an "adequate level of protection" or violate PIPA requirements.
Grounds for suspension Under Article 28-9(1), the PIPC may order the suspension of cross-border provision if:
- The overseas provision or onward transfer is in violation of Articles 28-8 or 28-11 (e.g., no valid legal basis, insufficient consent or exception, failure to meet safeguarding requirements); or
- The overseas recipient fails to implement required security safeguards or otherwise acts in breach of PIPA or the Enforcement Decree; or
- The overseas recipient’s country is found, on factual investigation, not to ensure an essentially equivalent or adequate level of protection for the data subject’s rights.
Article 28-9 is broad: it allows the PIPC to halt transfers where the foreign recipient is non-compliant even if the Korean controller’s own practices are compliant. Transfers can be suspended for an individual recipient, a group of recipients, or a whole jurisdiction.
Procedure and appeal rights Procedurally, when issuing a suspension order, the PIPC must take into account the severity and frequency of the violation, the sensitivity and volume of the data, and the remedial efforts of the controller or processor (Enforcement Decree, Article 29-14(1)). The PIPC must notify the controller in writing; the controller may submit an objection within 7 days. The PIPC must then re-examine the facts and issue a final decision within 30 days (Enforcement Decree, Article 29-14(3)).
Consequences and follow-up Upon a suspension order, the controller must immediately halt all further transfers to the affected recipient(s)/country. The controller must either repatriate data to Korea, delete affected data, or transfer only to recipients/countries for which a valid legal basis exists. Continued transfer in violation of a PIPC suspension order is subject to criminal sanctions under Article 75(3) (up to two years’ imprisonment or KRW 20 million fine).
Cross-reference: See also the section “onward-transfer-restrictions-article-28-11” for how PIPA applies to chains of onward transfers, and “security-safeguards-article-48-10” for safeguard obligations that, if breached, may trigger a suspension order.
Source: Personal Information Protection Act (Act No. 19234, effective September 15, 2023), Article 28-9 Source: Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 35343, February 25, 2025), Article 29-14
PIPA special-category (sensitive) personal information — cross-border transfer rules and heightened requirements
Definition and statutory treatment of special-category personal information in cross-border transfers
The Personal Information Protection Act (PIPA) classifies certain types of data as “sensitive information” (민감정보). Article 23(1) describes this as “information on ideology, beliefs, labor union or political party membership, political opinions, health, sexual life, genetic information, criminal records, and any other personal information prescribed by Presidential Decree,” with unique identification numbers explicitly included (see Enforcement Decree, Art. 19). These categories are subject to more stringent controls than general personal information for all lifecycle stages, including overseas provision.
Separate consent: the cumulative compliance hurdle
Cross-border transfers of sensitive information require cumulative consents and disclosures:
- Article 23(2) PIPA states: “No personal information controller shall collect, use, or provide sensitive information, unless the data subject gives separate consent... distinct from any other consents.” Korean practice and PIPC guidance (2026 currency) require that consent for handling sensitive information is explicit and not bundled with other provisions—even when general consent under Article 17 ("provision to a third party") or Article 28-8 (amended cross-border provision) is also being sought.
- Accordingly, for a controller seeking to transfer sensitive information abroad, three distinct layers are mandatory:
- Consent for collection/use of sensitive information (Article 23(2));
- Consent for third-party provision (Article 17 or 28-8, as amended);
- Consent for transfer overseas, with each of the Article 17(2) (“the recipient, country, purpose of use, items, retention period, right to refuse, and disadvantage for refusal”) or Article 28-8(2) elements disclosed at the point of transfer.
- Each consent must reference the specific information and cannot be given by pre-checked boxes or implied by broader terms acceptance (per PIPA and recent PIPC enforcement).
Additional security and procedural obligations
Article 23(4) requires that: “A personal information controller shall take necessary measures, as prescribed by Presidential Decree, to ensure the safety of sensitive information.” The Enforcement Decree (Art. 30–32) details these as:
- Implementing encryption on storage and transmission,
- Access/restriction controls to limit exposure,
- Logging and monitoring systems,
- Immediate destruction procedures for expired data,
- Physical security for equipment and storage.
Contracts for overseas processors/recipients must reflect these requirements and provide for both documentation and audit by the controller and, if requested, the PIPC. Article 48-10 additionally requires controllers to document and keep all records of cross-border transfers—including for sensitive data—for at least three years.
No exemption for adequacy or certification—statutory silence
As of June 2026, PIPA does not recognize any separate adequacy or certification regime exclusively for sensitive information. Article 17(3) and (4) allege general adequacy or certification pathways, but neither the statute nor Enforcement Decree creates “special” relief or exemption for high-risk categories; thus, all cumulative requirements for sensitive information apply in full, even where adequacy/certification is invoked for general data.
Transfer suspension and PIPC powers
If a controller fails to obtain all required layered consents or a recipient cannot meet security standards for sensitive information, the PIPC may suspend the transfer under Article 28-9. The threshold is the same as for general personal information but applied in practice with heightened scrutiny for sensitive data.
Compliance focus for practitioners
- Audit consent flows: ensure explicit, separate consents for both sensitive information and its cross-border transfer distinct from all other consents.
- Update privacy policy and transfer documentation to specify all Article 17(2)/28-8(2) elements for every cross-border sensitive data flow.
- Require foreign recipients to mirror Korean technical and administrative security standards in contract; ensure audit rights and documentation under Art. 48-10/32.
- Retain all documentation for at least three years and prepare to demonstrate compliance on demand during a PIPC inspection or enforcement action.
Source: Personal Information Protection Act (Act No. 19234, effective September 15, 2023), Articles 17, 23, 28-8 Source: Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 35343, February 25, 2025), Articles 19, 30–32, 48-10
Article 48-10 Enforcement Decree — Recordkeeping requirements for cross-border personal data transfers
Article 48-10 of the Enforcement Decree of the Personal Information Protection Act (PIPA) (Presidential Decree No. 35343, as amended February 25, 2025) imposes specific recordkeeping obligations on South Korean personal information controllers for every cross-border transfer of personal data. These records are crucial for regulatory oversight by the Personal Information Protection Commission (PIPC), and failure to maintain or produce them is itself a separate violation under Korean law.
Statutory recordkeeping requirements under Article 48-10
The Enforcement Decree mandates that controllers document the following for each cross-border transfer:
- The date and method of the transfer
- The recipient’s name and contact information (including the country)
- The legal grounds for the transfer (such as consent, contractual necessity, adequacy, or certification)
- The items of personal information transferred and the purpose of transfer
- Security measures implemented to protect the personal information at the recipient
These records must be retained for at least three years from the date of transfer. Article 48-10 does not mandate a specific format, but records must be sufficiently detailed to demonstrate compliance with the Decree if requested during a PIPC audit or investigation. Failure to provide adequate records can result in administrative fines under Article 75(2) of PIPA, even if the underlying transfer was otherwise lawful.
Article 48-10 does not explicitly require documentation of data subject consent or audit activities over recipients, nor does it specify requirements for language or sector-based retention periods. Any broader recordkeeping practices recommended in regulatory guidance or sector codes should be clearly distinguished from the baseline legal requirement in Article 48-10.
In practice, Korean controllers should ensure that these statutory elements are captured contemporaneously for every cross-border data flow—whether the transfer is based on consent, exception, or a future adequacy/certification mechanism. The PIPC’s focus in audits is the controller’s ability to produce the statutorily required facts for each transfer, not additional business processes or best practices, unless outlined by law.
Cross-border personal data transfers by public institutions under the Act on the Protection of Personal Information by Public Institutions (APPIPI)
Scope and relationship to PIPA
While the Personal Information Protection Act (PIPA) is the primary statute for most cross-border transfers, South Korean public institutions—including central and local government agencies, public schools, and designated public bodies—are additionally, and in some areas exclusively, governed by the Act on the Protection of Personal Information by Public Institutions (APPIPI, last amended March 28, 2023). APPIPI takes precedence over the general PIPA for these entities when rules differ (Art. 3(1) APPIPI; Art. 2(6) PIPA).
Legal basis for overseas provision—APPIPI Article 18
APPIPI does not contain a dedicated provision expressly for international transfers, but treats overseas provision as a form of third-party disclosure, governed by Article 18. A public institution may provide personal information to a third party (including an entity located abroad) only if the data subject has been informed of the purpose and provides prior consent (Art. 18(1)), or if a specific statutory exception applies, such as legal mandate, contract fulfillment for the benefit of the data subject, or other grounds listed by presidential decree (Art. 18(2)). APPIPI does not establish an adequacy regime, binding corporate rules, or alternative transfer mechanisms for public-sector international transfers, and the statute is silent on such frameworks as of June 2026. Unable to confirm existence of any operational public-sector adequacy recognition or mutual assistance regime for international transfers as of 2026-06-16.
Notice and recordkeeping requirements—Articles 15, 18(3), and 30
At the time of collection—or at the time of new intended disclosure—a public institution must inform the data subject of:
- The recipient (including overseas recipients),
- The country of transfer,
- The purpose of provision,
- The kind of information disclosed, and
- The retention or use period (Art. 15(1), 18(3)).
Written records must be maintained for all third-party provisions, including international disclosures: grounds for disclosure (consent or exception), details of the recipient and country, purpose, and the retention/use period. Records must be preserved for the data lifecycle and shown to data subjects or authorities upon request (Art. 30).
Administrative and regulatory developments (2026 update)
- A new Cross-Border Privacy Rules (CBPR) certification regime was launched by the PIPC with effect from February 3, 2026 (PIPC Administrative Notice 2026-1). While this is primarily aimed at private-sector actors under PIPA, public institutions should be aware of the emergence of data-reciprocity and accountability mechanisms in the Korean cross-border landscape.
- Separately, a major amendment to PIPA was promulgated March 10, 2026 (effective September 11, 2026), expanding penalties—including CEO-level liability for violations of cross-border obligations. While these changes do not directly amend APPIPI, they reflect a more severe enforcement environment for all entities engaged in personal data transfers abroad.
Enforcement and redress—Articles 65–67
Public institutions remain responsible for the rights of data subjects under APPIPI after transfer abroad. Data subjects may request access, correction, or deletion, and complaints may be made to the head of the institution or to oversight bodies under the statute (Art. 41–44). Administrative, disciplinary, and criminal penalties exist for violations (Arts. 65–67); the enforcement mechanism does not explicitly require the institution to guarantee the effectuation of such rights via contractual means with foreign recipients—APPIPI requires the public authority to maintain responsibility, but not how that must be done.
Material changes: None to APPIPI as of June 2026. CBPR/PIPA amendments are contextual, not statutory changes to APPIPI.
Source: Act on the Protection of Personal Information by Public Institutions (Act No. 19399, as amended March 28, 2023), Articles 3, 15, 18, 30, 41–44, 65–67 Source: Personal Information Protection Act (Act No. 21445, promulgated March 10, 2026; effective September 11, 2026) Source: PIPC Administrative Rule 2026-1 (CBPR Certification Scheme), effective February 3, 2026
Dual compliance: Cross-border personal data transfers subject to both PIPA and GDPR (Korean–EU data flows)
As of September 16, 2025, Korea and the European Union have established true mutual adequacy for personal data transfers under their respective regimes, following the joint adequacy decision by the Personal Information Protection Commission (PIPC) and the European Commission.
EU-to-Korea: Adequacy in force since 2022 Since February 17, 2022, the European Commission's adequacy decision (Commission Implementing Decision (EU) 2022/254) allows personal data to flow from the EU/EEA to Korea for most private-sector and specified public-sector data flows without the need for GDPR Chapter V transfer tools. This recognizes Korea's PIPA as providing essentially equivalent protection (GDPR Article 45 pathway).
Korea-to-EU: PIPC formal adequacy recognition (effective September 16, 2025) On September 16, 2025, the PIPC granted the EU/EEA bloc formal equivalence recognition under PIPA Article 28-8(1)(5). This enables personal information to be transferred from Korea to the EU/EEA without the need for individualized consent under PIPA, provided the transfer fits the scope of the adequacy determination. This is now functionally parallel to the GDPR adequacy process; controllers must still document adequacy as their transfer basis and fulfill the ordinary transparency, privacy notice, and safeguard requirements (PIPA Arts. 30, 48-10; GDPR Arts. 13–14, 30). For transfers outside the scope of adequacy (e.g., onward transfers to a non-EEA entity), the relevant additional Korean or EU mechanism must be applied.
Friction points and ongoing obligations
- Purpose compatibility: Both laws require that onward processing in the recipient jurisdiction remains tied to the original, disclosed purpose. Neither adequacy nor consent overrides the purpose limitation principle.
- Onward transfers: The Korean controller (and the EU controller, when the data returns) must perform independent analysis for any further transfers outside the adequacy-recognized area, as both PIPA Article 28-11 and GDPR Chapter V contain additional requirements for onward transfers.
- Vicarious liability: PIPA Article 26(6) continues to tie damages liability to the Korean controller for overseas recipients; the GDPR’s liability regime (Articles 82–83) is strict but structurally distinct.
- Data subject rights: Controllers must support all fundamental rights of access, rectification, erasure, and objection available under both frameworks, regardless of where data is physically processed.
Practical compliance checklist (primary sources cited)
- Document the transfer legal basis: adequacy for both legs (GDPR Art. 45; PIPA Art. 28-8(1)(5)); retain evidence of adequacy determination in the records of processing (GDPR Art. 30; PIPA Art. 48-10)
- Fulfill privacy notice and transparency requirements in both jurisdictions (GDPR Arts. 13/14; PIPA Art. 30), ensuring clear communication about cross-border flows
- Assess each onward transfer scenario separately: mutual adequacy reduces, but does not eliminate, analysis for each non-EU/EEA onward recipient
- Update DPAs, transfer contracts, and privacy policies to reference mutual adequacy and liability structure
- Monitor agency, regulatory, or legislative updates for any future changes to EU/EEA or Korea adequacy status or substantive requirements
Historical note: Before September 16, 2025, Korea had not formally recognized the EU/EEA as adequate under PIPA Article 28-8; individualized consent or a statutory exception was required for such transfers. That requirement is now superseded for the EU/EEA.
Source: Commission Implementing Decision (EU) 2022/254 Source: Personal Information Protection Act (Act No. 19234, as amended), Article 28-8 Source: PIPC press release and joint statement on EU adequacy recognition, 2025-09-16
PIPC notification and prior approval requirements for cross-border personal information transfers under PIPA
Are Korean controllers required to notify or register cross-border personal information transfers with the Personal Information Protection Commission (PIPC) before or after outbound transmission?
As of July 2026, the Personal Information Protection Act (PIPA) and its Enforcement Decree do not impose a general statutory obligation on private-sector controllers to notify or pre-register routine cross-border transfers of personal information with the PIPC. The legal basis for a cross-border transfer—consent under Article 28-8(1)(1), contractual necessity, adequacy (once operationalized), or certification—must be established and documented, but no standard notice, registration, or prior approval process applies to each cross-border data flow.
Key regulatory sources and their implications:
- Article 28-8 PIPA (as amended) enumerates the lawful bases for cross-border provision but is silent on a PIPC notification or permit requirement except in cases subject to suspension orders (see Article 28-9) or corrective measures.
- Article 48-10 of the Enforcement Decree imposes detailed recordkeeping and documentation duties for every cross-border transfer, including identity of the overseas recipient, method, legal basis, and security measures, but does not require these records to be submitted to the PIPC unless specifically requested during an audit or investigation.
- Article 28-9 PIPA authorizes the PIPC to order the suspension or prohibition of transfers found to violate the statute or to lack equivalent protection. However, this mechanism is reactive, triggered by findings from investigations or specific notifications (such as a complaint or a breach report), not by advance notification of standard transfers.
- No provision in the PIPC’s official guidance (as of July 2026) imposes routine "prior approval" or "transfer registration" requirements for outbound transfers by private-sector controllers. For certain regulated industries (e.g., financial institutions or telecommunications), sector-specific statutes may prescribe additional notice or permit requirements not set by PIPA itself.
- Public institutions transferring personal information abroad must comply with APPIPI (see separate section), which contains its own recordkeeping and reporting requirements.
May 2026 PIPA amendment—pending new requirement: In May 2026, the National Assembly's policy committee approved a bill to amend PIPA by introducing a limited pre-approval requirement for cross-border transfers of certain categories of personal information. Under proposed Article 28-12(3) (not yet in force), controllers that intend to transfer sensitive information or unique identification information abroad would be required to conduct a risk assessment and submit it to the PIPC for review and approval prior to the transfer. The effective date and final text of this amendment are still pending; until implemented, the general no-notification rule remains in force.
Practical compliance:
- Korean controllers must implement and maintain internal records of all cross-border data transfers as prescribed by Article 48-10 and produce these records promptly on PIPC request during audits, inspections, or breach investigations.
- If the PIPC determines via audit, complaint resolution, or breach report that a cross-border transfer is non-compliant, it may impose suspension orders under Article 28-9, with post-facto registration or remedial obligations set out in the enforcement notice.
- Controllers initiating new or uniquely sensitive cross-border transfers are advised to monitor evolving PIPC guidance, especially regarding the progress and effective date of the 2026 PIPA amendment.
Bottom line: For ordinary business transfers of personal data abroad, Korean law (as amended to July 2026) requires robust recordkeeping and legal-basis documentation but does not require notice, registration, or advance approval from the PIPC for each transfer. However, a limited pre-approval regime for certain sensitive transfers is expected to take effect following the 2026 amendment; details and operational timing should be monitored.
Source: Personal Information Protection Act (Act No. 19234, effective September 15, 2023): Article 28-8, Article 28-9 Source: Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 35343, February 25, 2025), Article 48-10
Cross-border transfers of children’s personal information — parental consent and procedural safeguards
Children’s personal information and cross-border transfer restrictions under Korean law
South Korea’s Personal Information Protection Act (PIPA) establishes both baseline and heightened requirements for the collection, use, and overseas transfer of children’s personal information. The key statutory provision is PIPA Article 22(1), which requires that a personal information controller obtain consent from a legal representative (parent or guardian) before collecting, using, or providing the personal information of a child under fourteen. This requirement applies to all stages of processing, including cross-border transfers under Articles 17 and 28-8—controllers may not rely on the child’s own consent for overseas disclosures, and must secure verifiable parental consent specifically referencing the transfer.
Layered consent for cross-border provision
- Article 22(1): Requires parental/legal-representative consent for processing of personal information for children under 14 (the statutory age for minors).
- Articles 17(1) and 28-8(1): Impose an additional, cumulative requirement—information such as the foreign recipient, destination country, purpose, data items, retention period, and consequences of refusal must be disclosed at the point of cross-border provision. Consent for both processing and cross-border transfer must be obtained from the parent/guardian. Each layer of consent must be explicit, opt-in, and can’t be bundled or pre-checked.
- Article 39-9: Empowers the Personal Information Protection Commission (PIPC) to adopt further standards for the protection of children’s data, including technical and administrative measures, though as of June 2026, no separate cross-border-specific rules for minors have been enacted under Article 39-9.
Verification and documentation Korean law does not prescribe a fixed method for verifying the parental or guardian relationship but expects controllers to document and reasonably validate the authority of the consenting adult (e.g., identity verification via digital certificate, upload of proof, or phone/SMS authentication). Controllers must retain records of parental consent and the accompanying Article 17(2)/28-8(2) cross-border disclosures for at least three years (Enforcement Decree Article 48-10 on recordkeeping for each transfer).
No lower age or sectoral carve-outs Unlike regimes such as the GDPR (Art. 8, which allows Member States to set a child-consent threshold between 13 and 16), Korea’s PIPA applies a uniform threshold of 14 for all sectors—there are no lower ages or industry-specific exceptions as of June 2026. Online services directed at children or likely to collect children’s data are expected to implement parental-consent gating for any transfer abroad.
Enforcement risk Failure to obtain valid parental consent before a cross-border transfer, or inadequately documenting such consent, is subject to administrative fines under Article 64-2, and the controller remains vicariously liable for downstream recipient actions (Arts. 26(6), 39).
Source: Personal Information Protection Act (Act No. 19234, effective September 15, 2023): Articles 17, 22, 28-8, 39-9, 64-2 Source: Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 35343, February 25, 2025), Article 48-10
Step-by-step compliance checklist for cross-border personal data transfers from Korea (2026)
This section provides a practical compliance workflow for Korean controllers seeking to lawfully transfer personal information abroad as of June 2026, covering the main statutory and regulatory requirements under the Personal Information Protection Act (PIPA, Act No. 19234, last amended September 2023) and the Enforcement Decree (Presidential Decree No. 35343, as amended February 2025). Each step references the controlling provision or official government guidance.
1. Determine whether the transfer is a “provision to a third party in a foreign country.”
- Confirm that the operation constitutes an overseas provision under Article 17 (or Article 28-8, per recent amendments). Transfers to affiliates, processors (entrustment), or independent controllers are in-scope.
2. Identify lawful basis for transfer.
- Check if individualized, separate consent is required (default route: Article 17(1)/28-8(1)).
- Evaluate if a statutory exception applies (contractual necessity, legal obligation, public interest—Article 17(3)/28-8(1)).
- Assess if transfer is to a PIPC-recognized adequate jurisdiction or PIPC-certified recipient (Article 17(3), adequacy/certification);
note that as of June 2026, neither adequacy nor certification is in practical effect for most transfers.
3. Prepare and present layered disclosures for consent-based transfers.
- Disclose all six Article 17(2) elements (recipient identity and contact, destination country, purpose, data items, retention period, data subject’s right to refuse and consequences) at the point of consent.
- For sensitive or children’s data, secure layered, explicit consents as required by Articles 22 and 23. For continuous versus one-time transfers, refer to Decree/official guidance for any procedural nuance (if published).
4. Update privacy policy and document transfer in records of processing activity.
- Article 30 requires publication of the transfer details and all regulatory elements in a clear, Korean-language policy with a dedicated cross-border section.
- Article 48-10 of the Enforcement Decree mandates contemporaneous documentation of who, what, when, where, why, and how for every transfer—retain for at least three years.
5. Execute required contracts with the foreign recipient.
- For processors, draft a PIPA-compliant data processing/entrustment agreement with eight mandatory clauses as per Article 26 and Article 28 of the Enforcement Decree. For independent controllers, execute a transfer contract incorporating all safeguard and liability provisions per Article 48-10.
6. Implement technical and organizational safeguards; set up complaint/redress procedures.
- Article 48-10 requires security, complaint response, and ongoing supervision measures to be contractually imposed and properly documented.
7. Assess onward transfer risk and contractually require compliance for subsequent disclosures by the overseas recipient (Article 28-11).
8. Retain robust evidence of all steps as audit-ready documentation.
- Prepare to produce all consents, notices, contracts, and safeguard documentation to the PIPC on request (Articles 24, 41, 48-10).
This workflow distills the core legal requirements for outbound transfers and should be used together with section-specific guidance above for sectoral overlays and edge cases.
Source: Personal Information Protection Act (Act No. 19234, as amended Sep 15, 2023) Source: Enforcement Decree of PIPA (Presidential Decree No. 35343, as amended Feb 25, 2025)