Data Protection Within the AI Context in Korea
摘要
The Republic of Korea (hereinafter “Korea”) has designated artificial intelligence (AI) as a key pillar for national economic growth, with both government and industry striving to secure a leading global position in AI technology. In pursuing this goal, Korea’s AI governance is based on a dual-track approach, balancing the Basic Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness (hereinafter “AI Basic Act”) aimed at promoting the AI industry with the Personal Information Protection Act (PIPA) dedicated to safeguarding data subject rights. The PIPA underwent a major revision in 2020 to address the challenges of the Fourth Industrial Revolution, followed by another significant amendment in 2023 to include provisions on fully automated processing systems, including AI systems. Despite these efforts, there remains a perspective that the PIPA still does not fully address the complexities of the AI age. Consequently, the Personal Information Protection Commission (PIPC) has adopted a pragmatic approach as discussed below: interpreting PIPA provisions more proactively and flexibly to promote data utilization, while simultaneously introducing new mechanisms like the Prior Adequacy Review Mechanism (PARM) to vet potential administrative risks in advance. Acknowledging the insufficiency of the existing legal framework for AI, the PIPC also announced a major policy agenda on January 13, 2025, committing to innovate Korea’s personal data governance framework to suit the AI era (PIPC, “PIPC’s Policy Vision and Tasks for 2025: Trustworthy AI Era Backed by Safe Use of Personal Information”, Press Release, January. 13, 2025). With several PIPA amendment bills pending in the National Assembly, the PIPA is anticipated to shift towards focusing on utilization of personal information rather than traditional strict protection. This chapter analyzes the current state of Korea’s data protection rules in the context of AI. It particularly discusses the enforcement of automated decision clauses under the PIPA, and the initiatives of the PIPC such as the PARM. Ultimately, this analysis evaluates how Korea’s data protection legislation is gradually transitioning from a protection-centric to a utilization-oriented paradigm.