메뉴 열기
메뉴 닫기
메뉴 닫기

新着情報

|
|
2026.05.04
Lee & Ko Enters Strategic Alliance with Palo Alto Networks
On April 23, 2026, Lee & Ko entered into a strategic collaboration agreement (the Alliance Agreement) with Palo Alto Networks (Netherlands) B.V. (Palo Alto Networks), a global AI cybersecurity leader. Palo Alto Networks (NASDAQ: PANW) offers a comprehensive portfolio of solutions and platforms across Network, Cloud, Security Operations, AI, and Identity, serving over 70,000 customers worldwide. The company is backed by Unit 42, its renowned threat intelligence and incident response team, and maintains a significant presence across both enterprise and public-sector clients in Korea. The Alliance Agreement, signed by Sanggon Kim, Managing Partner of Lee & Ko, and Sangkyu Park, the representative of Palo Alto Networks Korea, establishes a framework for ongoing cooperation between the two organizations in cybersecurity advisory, threat intelligence sharing, and joint client-facing initiatives. Korea’s Cybersecurity Landscape: Recent Incidents and Legislative Response The Alliance Agreement comes at a time when cybersecurity has emerged as a critical concern across all sectors of the Korean economy. In 2025, Korea experienced a series of high-profile cyber incidents—most notably the SK Telecom and Coupang incidents. Large-scale breaches also affected major credit card companies, online gaming platforms, and financial institutions throughout the year. In direct response to these developments, the Korean legislature moved swiftly to overhaul the country’s data protection and cybersecurity framework through a series of amendments enacted in early 2026: Amendments to the Personal Information Protection Act (PIPA)—passed February 12, 2026. The amendments establish the CEO as the ultimate responsible person for data protection, strengthen the role and independence of the Chief Privacy Officer (CPO)—including mandatory board-level appointment and reporting for entities meeting prescribed thresholds—and introduce punitive administrative penalties of up to 10% of total revenue (in addition to the existing 3% general cap) for repeated or large-scale violations involving willful misconduct or gross negligence. In addition, the scope of breach notification obligations has been expanded to cover not only confirmed breaches but also situations where there is a recognized possibility of a breach, and ISMS-P certification has been made mandatory for certain categories of data processors (effective July 1, 2027). Amendments to the Network Act—passed March 12, 2026. The amendments require the designation of an executive-level CISO with expanded responsibilities (including personnel and budget oversight and board reporting), mandate the establishment of information security committees for entities meeting prescribed thresholds, and introduce annual information security level assessments by the Ministry of Science and ICT (MSIT). Incident reporting timelines have been tightened to 24 hours from awareness, and a new Incident Investigation Review Committee has been established with authority to initiate investigations based on suspected—not only confirmed—incidents. For repeated incidents caused by willful misconduct or gross negligence (two or more within five years), administrative penalties of up to 3% of relevant revenue may be imposed, supplemented by daily penalty payments of up to 0.03% of average daily revenue for non-compliance with corrective orders. Both sets of amendments will generally take effect six months after promulgation. In a regulatory environment that now demands 24-hour incident reporting, mandatory board-level cybersecurity governance, and revenue-based punitive sanctions, the ability to mobilize integrated legal and technical resources rapidly has become essential. By combining Lee & Ko’s established strengths in data privacy regulation, enforcement defense, and cybersecurity litigation with Palo Alto Networks’ technical forensics and threat intelligence capabilities, the Alliance Agreement is designed to enable a more comprehensive and timely advisory service for clients navigating this landscape. Lee & Ko’s Cybersecurity Track Record Lee & Ko has been at the forefront of cybersecurity incident response in Korea and has successfully handled a series of landmark cases, including large-scale data breaches involving major credit card companies, leading online gaming platforms, and e-commerce operators. Most recently, the firm was engaged from the earliest stages of the investigation into the SK Telecom data breach in 2025—one of the most significant cybersecurity incidents in Korea’s history. Drawing on this extensive track record, Lee & Ko has established a dedicated Cyber Incident Response Team staffed with legal specialists across data privacy, IT/security, financial regulation, criminal defense, and litigation, as well as former officials from the Personal Information Protection Commission (PIPC), the MSIT, the Financial Supervisory Service (FSS), the National Intelligence Service, and the Prosecutor’s Office. The team operates a 24-hour rapid response hotline and works in close coordination with leading cybersecurity researchers and technical experts to provide real-time support during regulatory on-site inspections and law enforcement investigations. Together with Lee & Ko’s broader Data Privacy & Cybersecurity Practice Group—comprising more than 50 professionals—the team delivers end-to-end legal services across every phase of a cybersecurity incident: from golden-hour crisis advisory and regulatory investigation response to legislative engagement, statutory interpretation, and related civil, criminal, and administrative proceedings, including class-action defense arising from large-scale data breaches. For inquiries regarding the Alliance Agreement or its implications for your operations in Korea, please contact Lee & Ko’s Data Privacy & Cybersecurity Practice Group.  
FILE download
2026.03.27
Amendments to the Network Act Passed by the National Assembly
Following the passage of amendments to the Personal Information Protection Act (PIPA) by the National Assembly on February 12, 2026, the National Assembly also approved amendments to the Act on Promotion of Information and Communications Network Utilization and Information Protection (Network Act) on March 12, 2026. In recent months, cybersecurity incidents—or suspected incidents—affecting major telecommunications carriers and financial institutions have underscored the need to strengthen information security management and incident response frameworks. Against this backdrop, multiple amendment bills were proposed, and a consolidated bill prepared by the National Assembly's Science, ICT, Broadcasting and Communications Committee has now been enacted. The amendments focus on enhancing incident prevention and response mechanisms, strengthening corporate information security governance, and tightening regulation of illegal spam. Key measures—including the expansion of the Chief Information Security Officer's (CISO) role, mandatory establishment of information security committees, introduction of information security level assessments, enhanced certification standards for high-risk entities, and the implementation of incident response manuals and enforcement mechanisms—are expected to have a meaningful impact on corporate information security practices. The amended Network Act will generally take effect six months after promulgation, except for provisions relating to the information security level assessment system, which will take effect one year after promulgation. This newsletter outlines the key amendments and their practical implications. 1. Key Amendments     1) Strengthening Information Security Governance         The amendments enhance corporate governance frameworks to promote more structured and effective information security management.         In particular, major information and communications service providers are now required to endeavor to secure personnel with relevant expertise and sufficient budget for information security (Article 45(5)).         In addition, service providers (other than small and medium-sized enterprises) must designate an executive officer as the CISO. The CISO's responsibilities have been expanded to include (i) oversight of personnel and budgeting for information security, and (ii) reporting on information security status and key matters to the board of directors (Article 45-3).         Further, certain service providers meeting prescribed thresholds must establish and operate an information security committee to deliberate on information security matters, with the CISO serving as chair (Article 45-4).         The Ministry of Science and ICT (MSIT) is also authorized to conduct annual information security level assessments for designated entities and to disclose the results or issue recommendations for improvement (Article 45-5).     2) Enhancements to the Information Security Management System (ISMS) Certification Regime         Building on the comprehensive reform plan announced on December 6, 2025 to enhance the effectiveness of ISMS and ISMS-P certifications, the amended Network Act further strengthens the ISMS certification framework.         Under the amendments, entities that process large volumes of data or whose services have significant societal impact may be subject to enhanced certification standards and procedures (Article 47-7(2)). In addition, ISMS certification may be revoked in cases of material violations of applicable information security laws (Article 47(10)(4)).     3) Strengthening Incident Response and Investigation Frameworks         The amendments refine reporting, notification, and analysis requirements to enable more prompt and systematic responses to cybersecurity incidents.         Service providers are now required to report incidents—including the timing and response status—within 24 hours of becoming aware of the incident (Article 48-3(1)).         Where certain incidents prescribed by Presidential Decree occur, service providers must promptly notify affected users (Article 48-3(4)).         The scope of incident analysis has been expanded from focusing solely on the "cause" to covering both the "occurrence and cause" of incidents (Article 48-4).         An Incident Investigation Review Committee will be established under the MSIT to deliberate on matters such as the need for investigation and the formation of joint public-private investigation teams (Article 48-2(7)).         In addition, designated entities operating information and communications networks must prepare and submit incident response manuals tailored to the scale and nature of their services, in accordance with standard guidelines issued by the Ministry. The Ministry is also authorized to review the implementation of such manuals (Article 48-9).     4) Introduction of Sanctions and User Protection Measures         To strengthen accountability, the amendments introduce new enforcement tools in relation to cybersecurity incidents.         Penalty surcharges may be imposed for failure to comply with corrective orders, refusal to submit materials, or obstruction of investigations (Article 48-7).         Further, where incidents occur repeatedly (two or more times within five years) due to willful misconduct or gross negligence, administrative fines of up to 3% of relevant revenue may be imposed (Article 48-8), subject to certain exceptions under the PIPA.         The amendments also introduce user protection provisions requiring service providers to take necessary measures to prevent the spread of harm and to facilitate prompt remedies, and to report such measures to the Ministry (Article 48-10).     5) Strengthening Regulation of Illegal Spam         The amendments also tighten regulation of illegal spam, particularly in relation to bulk messaging services.         Where a party outsources the transmission of commercial advertising messages, such outsourcing must be made only to entities certified under the Telecommunications Business Act (Article 50-3).         Where a service is used for unlawful transmission of advertising messages, the service provider must take prescribed measures, including (i) immediate suspension of such transmissions, (ii) denial of service or termination of contracts, (iii) inspection and remediation of security vulnerabilities, (iv) improvement of terms of service, and (v) implementation of recurrence prevention measures (Article 50-4(4)).         In addition, violations of advertising message transmission regulations may result in administrative fines of up to 6% of related revenue, significantly strengthening enforcement. 2. Key Implications     1) Need to Strengthen Information Security Governance         As with the recent amendments to the PIPA, the amended Network Act places significant emphasis on strengthening corporate information security governance. Companies should therefore review and enhance their internal governance structures, including the expanded role of the CISO, the requirement to establish information security committees, and the introduction of information security level assessments.         In addition, as enhanced ISMS certification standards may apply to high-risk entities, such companies should proactively upgrade their security management systems. Given that certification may be revoked in cases of material legal violations, ongoing compliance and post-certification management will also become increasingly important.     2) Need to Review Incident Response Processes and Internal Policies         The amendments introduce significant changes to incident response and investigation frameworks, including new user notification obligations and the establishment of the Incident Investigation Review Committee. Companies should comprehensively review their existing incident response processes in light of the expanded scope of investigation and analysis and the introduction of mandatory incident response manuals.         In particular, incident response manuals, reporting timelines, and notification procedures will play a critical role in practice. Companies are therefore advised to update relevant internal policies and systems in advance of the amendments taking effect.         Moreover, given that repeated incidents caused by willful misconduct or gross negligence may result in administrative fines of up to 3% of revenue, post-incident remediation measures, security investments, and internal controls are likely to be key factors in determining enforcement outcomes.     3) Need to Strengthen Spam Compliance         With the introduction of administrative fines of up to 6% of relevant revenue for violations relating to advertising messages, the importance of internal controls and compliance frameworks in this area will increase significantly.         In addition, as outsourcing of advertising message transmission is restricted to certified entities, companies utilizing messaging services should review their vendor selection processes and contractual arrangements accordingly. Lee & Ko's Data Privacy & Cybersecurity Practice Group comprises more than 50 professionals, including specialized privacy lawyers, former regulators, and security technology experts, and maintains close collaboration with external IT and security specialists. The group provides comprehensive, one-stop advisory services across all areas of data protection and information security, including governance design, incident response, and ISMS/ISMS-P certification support. If you require advice in relation to the amended Network Act or other data protection and cybersecurity matters, please feel free to contact Lee & Ko's Data Privacy & Cybersecurity Practice Group.
FILE download
2026.03.09
PIPA Amendment Passes National Assembly Plenary Session
The amendment to the Personal Information Protection Act (the Amended PIPA) was passed at the plenary session of the National Assembly on February 12, 2026. Following a recent series of large-scale data breach incidents (i.e., incidents involving the loss, theft, or unauthorized disclosure of personal information) involving major telecommunications companies, financial institutions, and platform operators, public demand has grown for stronger preventive measures and enhanced corporate accountability. While this amendment is widely known for introducing administrative penalties of up to 10% of revenue for violations of the PIPA, including data breaches, its significance extends further in that it calls for substantial changes to corporate data protection governance frameworks and security incident response systems. In this newsletter, we review the specific details of the Amended PIPA and highlight its key implications. 1. Key Amendments     A. Increased cap on administrative penalties for repeated or serious personal information infringements and specification of data protection investments as grounds for mitigation         Administrative penalties may now be imposed at up to 10% of a data handler (a concept analogous to a data controller under the GDPR)'s total revenue (excluding any amounts unrelated to the violation at issue)—or up to KRW 5 billion if there is no revenue or if calculating revenue is difficult, as prescribed by the Enforcement Decree (a proposed amendment to which is expected to be publicly notified)—in the following circumstances (Article 64-2(2)):         (i) if a violation constituting grounds for an administrative penalty is committed within three (3) years from the date of receiving a previous administrative penalty, with intent or gross negligence;         (ii) if a violation constituting grounds for an administrative penalty is committed with intent or gross negligence, and the number of affected data subjects is 10 million or more; or         (iii) where a data breach occurs as a result of failure to comply with a corrective order.         Conversely, the Amended PIPA requires the reduction of administrative penalties if grounds prescribed by the Enforcement Decree are met, such as the investment in and operation of data protection budgets, personnel, facilities, and equipment (excluding cases where the violation was committed with intent or gross negligence) (Article 64-2(6)).     B. Expansion of the concept of data breach and obligations related to data breach notification         The scope of "data breach" under the PIPA has been expanded beyond the current statutory categories of "loss, theft, or unauthorized disclosure" of personal information to additionally include "forgery, alteration, or damage" (Articles 23(2) and 34(1)).         The PIPA requires that certain information be notified to the affected data subjects in the event of a data breach. Under the Amended PIPA, the scope of required notification items has been expanded to include the following (Article 34(1)(6)):         (i) information regarding the data subject's legal rights and methods of exercising such rights, including claims for compensatory and statutory damages arising from the data breach or similar incident and dispute resolution procedures; and         (ii) other matters prescribed by the Enforcement Decree.         In addition, even prior to confirmation of a data breach, where a data handler becomes aware of the possibility of a data breach as prescribed by the Enforcement Decree—taking into account the type of personal information involved, the impact on data subjects, and the level of risk—the data handler is now required to notify, without delay, all potentially affected data subjects of such possibility, including information necessary to minimize potential damages and other matters to be prescribed by the Enforcement Decree (Article 34(2)).     C. Mandatory ISMS-P certification for data handlers above a certain scale         The PIPA provides that the Personal Information Protection Committee may certify the level of personal data protection of a data handler. Data handlers may apply for such certification—i.e., Personal Information & Information Security Management System (ISMS-P) certification—and, under the current PIPA, obtaining ISMS-P certification is voluntary. Under the Amended PIPA, however, data handlers that meet certain criteria prescribed by the Enforcement Decree—based on factors such as annual revenue and the scale of personal information processed—will be required to obtain ISMS-P certification (Article 32-2(1), proviso).     D. Clarification of the representative's responsibility and strengthening of the CPO's role         The Amended PIPA expressly provides that the representative (e.g., CEO) or business owner bears ultimate responsibility for the secure processing of personal information and the protection of data subjects' rights, and must effectively implement comprehensive management measures, including the allocation of qualified personnel and sufficient budgetary support (Article 30-3).         In addition, the statutory duties of the Chief Privacy Officer (CPO) have been expanded to include (Article 31(4)(2) and (3)):         (i) managing qualified personnel and securing the budget necessary for the protection of personal information; and         (ii) reporting to the representative and the board of directors on the status of personal information protection and other related matters of importance.         Furthermore, for data handlers meeting criteria prescribed by the Enforcement Decree—based on factors such as annual revenue and volume of personal information processed—are now subject to obligations to (Article 31(3)):         (i) obtain board approval when appointing, changing, or dismissing the CPO; and         (ii) report matters concerning the appointment, change, or dismissal of the CPO to the Personal Information Protection Commission in accordance with the Enforcement Decree.     E. Effective Date         The Amended PIPA will enter into force six (6) months after the date of its promulgation; provided, however, that the provisions mandating ISMS-P certification will take effect on July 1, 2027 (Addendum, Article 1). 2. Implications     A. Increased importance of establishing robust data protection governance and investment         The Amended PIPA introduces punitive administrative penalties, thereby significantly increasing the level of sanctions for data breaches and other infringements. At the same time, it strengthens not only the duties and role of the CPO but also the responsibilities of the representative and the board regarding data protection, while incentivizing corporate investment in data protection by providing additional grounds for mitigation of administrative penalties. Accordingly, before the Amended PIPA takes effect, businesses should establish or refine governance structures to ensure the effective implementation of data protection measures and proactively invest in adequate personnel, systems, and infrastructure. Regarding specific compliance measures, it will also be important to closely monitor how the provisions of the Amended PIPA are further specified through the forthcoming amendment to the Enforcement Decree.         In this context, the presence or absence of intent or gross negligence on the part of a data handler will serve as a key factor in determining the amount of an administrative penalty.         However, as the responsibilities of the representative and other directors with respect to data protection have now been expressly articulated—and as they are expected to participate in related decision-making—the propriety of the board's conduct, in addition to that of the CPO and personnel directly handling personal information, may also be considered in assessing intent or gross negligence. Therefore, guidance from legal experts may be necessary from the very beginning—such as when preparing guidelines for board reporting matters—to ensure compliance and mitigate potential liability risks.         In addition, with respect to ISMS-P certification, businesses should note that the certification review process is expected to become more rigorous, and that the Personal Information Protection Commission has indicated that it will actively revoke certifications in light of the seriousness of violations.     B. Need to strengthen monitoring systems and revise incident response processes         The scope of incidents subject to data breach notifications and the required notification items have been broadened, and notably, the notification obligation now extends to circumstances where only the possibility of a data breach or similar incident has been identified, even if no actual breach has been confirmed. Companies should therefore review and update their existing incident response processes. In particular, it has become increasingly important to enhance monitoring at pre-breach stages (e.g., upon detection of a security incident) and to establish corresponding response mechanisms at an earlier stage.         As these changes may necessitate amendments to internal regulations or policies, as well as adjustments to the roles of relevant departments, companies should begin preparations well in advance of the Amended PIPA's effective date. Lee & Ko's Data Privacy & Cybersecurity (DPC) Practice Group comprises more than 50 professionals—including dedicated privacy attorneys, former regulatory officials, and information security and technology experts—and maintains close collaborative relationships with external IT and cybersecurity specialists. Through this integrated network, we provide fast and accurate one-stop advisory services across the full spectrum of data protection and information security matters, including the establishment of information security governance frameworks, incident response relating to data breaches and similar leakage/infringement incidents, and assistance with ISMS and ISMS-P certification. Should you require advice regarding the Amended PIPA or any other data protection or information security matters, please do not hesitate to contact Lee & Ko's DPC Practice Group.  
FILE download
2024.05.20
Concretizing Rights of Data Subjects in the AI Era
Following the amendment of the Personal Information Protection Act (promulgated on March 14, 2023, the Amended PIPA), the second amendment to its Enforcement Decree (the Second Amended Enforcement Decree) went into effect on March 15, 2024. This decree delineates the provisions of the Amended PIPA that take effect one (1) year after its promulgation. For information on the first amendment to the Enforcement Decree, which came into effect on September 15, 2023, please refer to the link here. The Second Amended Enforcement Decree specifies the rights of data subjects concerning automated decision-making, a response to the rising use of artificial intelligence (AI). It further details the criteria for appointing privacy officers, including their qualifications and independence, specifies additional elements to be included in privacy policies, relaxed standards for obtaining insurance or joining mutual aid societies to secure liability for damages, and an adjustment to the cycle of regular inspections on the management of unique identifiable information (for the Personal Information Protection Commission (PIPC)’s press release dated March 6, 2024, available only in Korean, please refer to the link here). However, the provision for data portability (Article 35-2 of the Amended PIPA) is not yet in effect and thus is not included in the Second Amended Enforcement Decree. This newsletter aims to introduce the key contents of the Second Amended Enforcement Decree. 1. Rights of Data Subjects Regarding Automated Decision-making Including AI     According to the newly established rights of data subjects regarding automated decision-making under the Amended PIPA (Article 37-2 of the Amended PIPA; for more details, please refer to the link here), when a decision is made through a “fully automated process” without any human intervention, such as by using AI, the data subject may request an explanation or review of the decision. If the decision significantly affects the data subject’s rights or obligations, the data subject may also refuse the decision. The Second Amended Enforcement Decree concretizes these matters, with the details as follows:     Definition of the “automated decision-making”       An “automated decision-making” refers to a case where two key elements are present: (i) a data controller making a final decision that affects the rights or obligations of the data subject after (ii) processing personal information using a fully automated system without human intervention.     Methods and Procedures for Data Subject’s Request       Data controllers are required to establish methods and procedures for data subjects to exercise their rights regarding automated decision-making. These methods and procedures and methods should be comparable to those used for requests to access data, and should not be more difficult than the methods and procedures used to collect personal information.     Obligation to Disclose Criteria for Automated Decision-making       Data controllers are required to disclose the following through an internet homepage or similar means:       i. the fact that automated decision-making is taking place, its purpose, the scope of affected data subjects;       ii. the types of personal information used and their relationship with automated decision-making;       iii. considerations in the automated decision-making process and the procedures involving the processing of key personal information;       iv. in cases where sensitive information or personal information of children under the age of 14 is used in the automated decision-making process, the purpose and the specific items of personal information being processed; and       v. the fact that data subjects can request refusal, explanation, etc. regarding the automated decision-making, and the methods and procedures for doing so.     Data Controllers’ Obligation Regarding Data Subjects’ Exercise of Rights       ■ (Refusal of Automated Decision-making) If a data subject refuses automated decision-making on the grounds that it significantly affects their rights or obligations, such as regarding life, body, or property, the data controller must, unless there are legitimate grounds, either (i) take measures not to apply the decision or (ii) if the data subject requests a re-processing involving human intervention, take measures accordingly and notify the data subject of the result. “Legitimate grounds” here refer to cases where there is a risk of unduly infringing on the life, body, property, or other interests of others.     ■ (Request for Explanation) Upon a data subject’s request for an explanation, the data controller must provide a concise and meaningful explanation that is easy to understand, including the outcome of the decision, the types of personal information used, and their impact. However, if the decision does not significantly affect the data subject’s rights or obligations, it may suffice only to disclose the criteria for the automated decision-making.     ■ (Objection) If a data controller refuses a data subject’s request for refusal or explanation as described above, they must establish and provide necessary procedures for the data subject to object (Article 38(5) of the Amended PIPA). Upon an objection, the data controller must take necessary actions considering the content of the objection and inform the data subject of the result.     ■ (Timeline for Taking Measures) In principle, the above measures must be taken within 30 days of receiving the data subject’s request, which may be extended by up to 60 days if there are legitimate grounds.     In addition to the above, further details, including the specific scope, content, and criteria for implementation, are expected to be specified in public notices issued under the authority delegated by the Enforcement Decree. 2. Designation of Privacy Officer     The Amended PIPA newly introduced a provision to ensure the independence of privacy officers in performing their duties (Article 31(6) of the Amended PIPA) and delegated the specification of the qualifications of the privacy officer to the Enforcement Decree (Article 31(9) of the Amended PIPA). The specifics of the qualifications under the Second Amended Enforcement Decree are as set forth below.       Firstly, the requirements for ensuring the independence of the privacy officers have been specified as follows:      ■ ensuring privacy officers’ access to information related to personal information processing;     ■ establishing a regular reporting system for privacy officers to report to the representative or board of directors directly; and     ■ establishing an organizational structure and providing human and material resources for privacy officers to perform their duties.     Secondly, the specific qualifications for privacy officers have been strengthened. Previously, the requirements under the Enforcement Decree for appointing a privacy officer were limited to “the business owner, the representative, or an executive (or the head of a department in charge of personal information processing in the absence of an executive).” However, the Second Amended Enforcement Decree now requires certain data controllers (i.e., those with an annual sales or income of at least KRW 150 billion and process either (i) sensitive or unique identifier information of more than 50,000 data subjects, or (ii) personal information of more than 1 million data subjects) to designate a person with at least four (4) years of combined experience in personal information, information security, and information technology, including at least two (2) years specifically in personal information protection, and specifies the criteria for recognizing such experience (for more information, only available in Korean, please refer to the link here).     Accordingly, when appointing privacy officers going forward, it will be necessary to ensure that they meet these requirements. However, if a privacy officer who does not meet these requirements was appointed at the time the Second Amended Enforcement Decree came into effect, the Second Amended Enforcement Decree provides a two-year grace period so that they can meet the qualification requirements by March 14, 2026, enabling a gradual transition (Article 2 of the Addendum to the Second Amended Enforcement Decree). 3. Content of Privacy Policy and Disclosure Methods     The Second Amended Enforcement Decree has added the following items that must be included in privacy policies:     ■ if collecting and processing personal information of domestic data subjects from overseas, the names of the countries where the processing takes place; and     ■ the legal basis for transferring personal information overseas and the statutory notification requirements for such cross-border transfers. 4. Securing Liability for Damages     Under the Amended PIPA, the obligation to secure liability for damages to data subjects, using means such as insurance policies and reserve funds, has been expanded from information communications service providers (ICSPs, such as online business operators) to include all data controllers, now covering both offline business operators and the public sector (Article 39-7 of the Amended PIPA). Correspondingly, the Second Amended Enforcement Decree has rationally adjusted the criteria for obligated entities and established exemptions from these obligations. Previously, ICSPs were required to meet these obligations only if they had more than 1,000 users and revenues exceeding KRW 50 million. However, the Second Amended Enforcement Decree has heightened these thresholds for entities with over 10,000 data subjects and revenues exceeding KRW 1 billion. Moreover, public institutions, public interest corporations, non-profit private organizations, and small business owners who have outsourced their operations to professional contractors insured for liability are specifically identified as exempt from these obligations. Lee & Ko has a Data Privacy & Cybersecurity Group composed of the largest team of experts in the fields of personal information protection and information security in Korea. Our comprehensive legal services encompass consultations, legal investigation responses, and litigation representation concerning personal information matters. If you require advice or assistance concerning the Amended PIPA and Second Amended Enforcement Decree, please feel free to contact us at your convenience.   For key revisions to the Personal Information Protection Act and details on the first amendment to the Enforcement Decree, please refer to the newsletter below.   Second Major Amendment to the Personal Information Protection Act Passed by National Assembly (I) [link here]   Second Major Amendment to the Personal Information Protection Act Passed by National Assembly (II) [link here]   Second Major Amendment to the Personal Information Protection Act Passed by National Assembly (III) [link here]   Amended Enforcement Decree of the Personal Information Protection Act of Korea [link here]    
FILE download
2024.05.02
Landmark Ruling: Supreme Court Overturns PIPC Sanctions Against E-commerce Platform Operators
We are pleased to inform you of a landmark ruling by the Supreme Court of Korea which has significant implications for e-commerce platform operators within the country. In a recent case, the Supreme Court has overturned the sanctions imposed by the Personal Information Protection Commission (PIPC) against major online marketplaces, Naver (South Korea’s leading internet platform company) and Gmarket (formerly eBay Korea). This pivotal case clarified that sellers on e-commerce intermediary platforms (the E-commerce Seller) are not considered ‘personal information managers’ of the platforms providing intermediary sales services (the E-commerce Platform) under the Personal Information Protection Act (PIPA). This ruling marks a transformative moment for privacy law enforcement related to E-commerce Platforms in South Korea. In this newsletter, we will delve into the details of the Supreme Court’s decision and discuss its broader impact on the e-commerce landscape. 1. Overview of the Case     First, operators of the E-commerce Platform provide a service that enables members (including both sellers and buyers) to trade goods online. During the provision of this service, seller members utilize the personal information of buyer members, provided by the E-commerce Platform operators, to deliver products and carry out various sales-related tasks. In this context, the PIPC has interpreted that E-commerce Platform operators are ‘data controllers’ under PIPA, and that seller members are ‘personal information managers’ who process personal information under the direction and supervision of the E-commerce Platform operators. Based on this presumption, the PIPC found that E-commerce Platform operators breached the necessary safety measures required under PIPA by allowing seller members access to the seller system using only an ID and password, without employing additional secure authentication methods. As a result, the PIPC issued an order to seven (7) major platform operators to implement secure authentication methods and conduct regular training for their seller members (the PIPC Order). Among the E-commerce Platform operators subject to the PIPC Order, Naver and Gmarket filed lawsuit actions against the PIPC seeking to annul the PIPC Order. We, Lee & Ko, have represented Naver and Gmarket from the court of first instance to the final decision by the Supreme Court. 2. Summary of the Supreme Court’s Ruling     The main issue presented to the Supreme Court concerned whether E-commerce Sellers qualify as ‘personal information managers’ for E-commerce Platform operators under PIPA. This distinction was critical, as PIPA’s requirement for data controllers to implement secure authentication methods specifically applies to ‘personal information managers.’ Consequently, the legality of the PIPC Order depended on this determination.     In this regard, the Supreme Court annulled the PIPC Order for the following reasons, determining that E-commerce Sellers do not qualify as the ‘personal information managers’ of the E-commerce Platform operators:     ■ A ‘personal information manager’ is not limited to those who have an employment contract with a data controller. It includes any person who, under laws or contractual terms, acts under the direction and supervision of a data controller to carry out certain tasks.     ■ "Third parties," who receive personal information from data controllers and utilize it for their own business purposes and benefits, are distinct from and cannot coexist with personal information managers.     ■ The E-commerce Sellers receive personal information of buyer members from the E-commerce Platform operators and process that information according to their own discretion for their business operations. They are thus ‘data controllers’ and ‘third parties’ themselves rather than ‘personal information managers’ of the E-commerce Platform operators. 3. Significance of the Supreme Court’s Ruling     The significance of this case lies in the fact that it provided the first specific judicial interpretation of PIPA regarding the definition and scope of a ‘personal information manager,’ and the critical distinction between a ‘personal information manager’ and ‘third party.’ This ruling is pivotal not only for the e-commerce platform industry but also establishes a benchmark for future cases across various sectors involving the determination of who qualifies as a ‘personal information manager’ and who is subject to security measures requirements as per PIPA.     Prior to this ruling, the PIPC had used its guidelines as the legal basis to interpret E-commerce Sellers as ‘personal information managers’ for E-commerce Platform operators. However, this ruling clearly established that the PIPC’s guidelines cannot serve as grounds for enforcement actions. Nonetheless, it should be noted that independent of the Supreme Court’s decision, major E-commerce Platform operators such as Naver and Gmarket have proactively enhanced their security measures through self-regulatory efforts to safeguard the personal information of buyer members.     Furthermore, this ruling is also significant as it clearly delineates the responsibilities related to personal information processing between E-commerce Platform operators and their seller members. This provides critical guidance for E-commerce Platform operators on how to structure their compliance and governance frameworks to protect personal information effectively. This ruling marks the first decision issued by the PIPC that has been overturned since it became a central administrative agency in 2020. Lee & Ko features a Data Privacy & Cybersecurity Group comprised of the largest team of personal information protection and information security experts in Korea. Our comprehensive legal services encompass consultations, legal investigation responses, and litigation representation concerning personal information matters. If you require advice or assistance concerning privacy-related matters, please feel free to contact us at your convenience.
FILE download