South Korea Opens a New Route to Personal Data for AI Development
Key Takeaways
- South Korea Creates a New Legal Path for AI Data Use: The PIPA amendment would allow lawfully collected personal information to be used for AI development beyond the law’s existing legal bases in specified circumstances.
- The Exception Is Narrowly Conditioned: Personal information may be used when relying only on pseudonymized or anonymized data would make AI development difficult or substantially limited, or when its use is necessary for AI development in the public interest.
- PIPC Oversight Remains Central: Use of personal information under the new provisions will require enhanced privacy safeguards and be subject to the PIPC’s deliberation and oversight.
- Higher-Risk Processing Brings Additional Obligations: Controllers processing sensitive data or uniquely identifiable information that could significantly affect data subjects’ rights will need to conduct risk assessments and develop plans to mitigate identified risks.
Deep Dive
For South Korean AI developers, some useful data has come with an awkward choice. Get fresh consent from the people behind it, strip away enough identifying information to satisfy privacy requirements, or find another legal basis for using information that may have been collected for an entirely different reason. None is especially convenient when the object is to train an AI model on large and varied datasets.
South Korea’s National Assembly has now decided that the country’s privacy law needs another answer. Lawmakers passed an amendment to the Personal Information Protection Act, or PIPA, creating special provisions for the use of personal information in AI development. The legislation would allow certain personal information that was lawfully collected to be used beyond the existing legal bases under PIPA, provided specific conditions are met and the Personal Information Protection Commission approves the arrangement.
It is a fairly consequential change disguised in the language of an exception. Under the current framework, personal information collected with an individual’s consent or for the performance of a contract generally needs another lawful basis or separate consent before it can be put to a different use. Developers can turn to pseudonymized or anonymized information, but the PIPC acknowledges the practical problem with that solution: sometimes removing the identifying characteristics of data also removes part of what makes the data useful.
The amendment recognizes two circumstances in which developers could go further. Personal information could be used when developing an AI system would be difficult or substantially limited using only pseudonymized or anonymized data, or when the use of personal information is necessary for AI development in the public interest.
Neither amounts to a general permission slip. Use under the new provisions would require enhanced privacy safeguards and would be subject to deliberation and oversight by the PIPC.
That structure matters because South Korea has already been allowing some experimentation with personal data through its regulatory sandbox system. AI-based voice-phishing prevention and self-driving robots are among the services that have been permitted to use video or voice data containing personal information under sandbox arrangements. Tentative approvals have gone to businesses and other entities deemed to have reviewed and implemented privacy safeguards over periods of two to four years.
The sandbox solved one problem while leaving another behind. It offered a way to test technologies that did not fit comfortably within existing rules, but the exemptions came through regulatory frameworks designed to promote particular industries. Personal information is a different sort of regulatory object. Its use bears directly on individual rights, and the PIPC concluded that the legal foundation for overseeing it belonged inside PIPA itself.
The result is a law that gives AI developers more room while making the conditions for using that room part of the privacy regime rather than an exception sitting outside it.
Some of those conditions are substantial. A data controller processing sensitive data or uniquely identifiable information that could significantly affect the exercise of a data subject’s rights would have to conduct a risk assessment. Where risks are identified, the controller would also have to develop an improvement plan to mitigate them.
Organizations relying on the AI provisions would have to say so publicly, disclosing the relevant processing practices in their privacy policies or statements. The PIPC would face its own transparency obligation, with the regulator required to disclose the operational status of the special provisions.
There is also an attempt to keep the approval machinery from becoming its own obstacle. The PIPC plans to streamline reviews for AI technologies or services that are technically identical or similar to cases it has already considered. Rather than putting substantially the same technology through substantially the same process each time, the regulator wants previous decisions to shorten the path for later applicants.
That could prove important. A legal route to using personal information is of limited value to developers if approval takes longer than the technology does to change. The legislation itself is the product of two lawmakers’ drafts that were integrated and adjusted by the National Assembly’s Policy Committee. It was subsequently reviewed by the Legislation and Judiciary Committee before passing the plenary meeting on Aug. 20.
There are still several steps before companies can use it. The bill must be submitted for deliberation by the Cabinet and then promulgated. It will take effect six months after promulgation.
That interval will determine much of what the amendment means in practice. The PIPC plans to gather input from experts and practitioners as it develops implementation plans and subordinate legislation. The statute establishes the route, but regulators will still have to give practical meaning to questions that are likely to decide how wide it becomes, including when pseudonymized or anonymized information is genuinely insufficient and what safeguards will satisfy the new regime.
PIPC Chairperson Kyung Hee Song said the special provisions are intended to provide a “reasonable framework” for making greater use of personal information as AI becomes more important to national competitiveness, while allowing government and businesses to develop supervision and management arrangements together.
For developers, the immediate significance is simpler. South Korea has accepted that its existing choices for handling personal information do not fit every legitimate use of data in AI development. Instead of leaving those cases to a patchwork of sandboxes, it is writing an additional path into the privacy law itself.
That does not settle the tension between access to data and the rights of the people represented in it. It gives the PIPC a new way to referee it. How permissive that system becomes will depend less on the principle lawmakers approved on Aug. 20 than on the rules the regulator writes next.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

