Cross-Border Transfers of Personal Data Under the Personal Information Protection Act of the Republic of Korea
摘要
This chapter analyses the 2023 amendments to the Personal Information Protection Act (PIPA) of Korea on cross-border transfers of personal data, arguing that they mark a shift from a strictly consent-centric model to a multi-pillar, risk-based framework. Amended Article 28-8(1) now recognises five legal bases for transfer—separate consent, law or treaty, outsourcing/storage necessary for contract performance, PIPC-recognised certification and PIPC adequacy decisions—thereby offering controllers greater flexibility while seeking to maintain a high level of protection for data subjects. The article clarifies the boundary between PIPA’s extraterritorial application and its cross-border transfer regime, emphasising that direct collection by foreign platforms in Korea engages PIPA directly rather than the transfer rules, while subsequent disclosures abroad qualify as regulated cross-border transfers. It further shows that the distinction between third-party provision and outsourcing of processing is central: transfers to independent foreign recipients generally hinge on consent, whereas outsourcing to foreign processors may rely on the new contract-necessity ground, subject to transparency and safeguards. In comparative perspective, the article notes PIPA’s convergence with the GDPR through adequacy and certification mechanisms but stresses the absence of an ‘appropriate safeguards’ tier (SCCs/BCRs), leaving a structural gap between adequacy and last-resort bases such as consent. It also highlights post-transfer safeguards, onward transfer control and the PIPC’s new power to suspend transfers, illustrating through the AliExpress, Temu and Kakao Pay/Apple/Alipay cases that the amended regime is being enforced vigorously with substantial fines and corrective orders.