Personal Information
Overview
Personal information refers to information that can identify an individual, such as name, resident registration number, and images, and its value and risk are both increasing in the digital environment. The Republic of Korea regulates the entire process of collecting, using, providing, and destroying personal information through the Personal Information Protection Act, guaranteeing the data subject's right to self-determination. With the recent rise of AI and the data economy, discussions on balancing personal information protection and utilization are active.
Main Contents
Definition and Types of Personal Information
Article 2 of the Personal Information Protection Act defines personal information as "information relating to a living individual that makes it possible to identify the individual through name, resident registration number, image, etc." This includes information that, even if it cannot identify a specific individual on its own, can be easily combined with other information to identify the individual. Representative examples include name, date of birth, address, phone number, email, account number, health information, location information, biometric information, genetic information, and online identifiers (IP, cookies). In addition, pseudonymized information is also considered personal information depending on the possibility of combination.
Necessity of Personal Information Protection
Personal information reflects an individual's personality and private life, and if leaked, it can cause serious harm such as identity theft, financial fraud, stalking, defamation, and digital sex crimes. For example, in 2021, a leak of more than 30 million pieces of personal information occurred on a major domestic online platform. In addition, personal information has great economic value as it is used for corporate marketing and personalized services, but collection without consent and misuse lead to privacy infringement. The right to self-determination of personal information, based on Articles 17 and 10 of the Constitution, is recognized as the right of data subjects to control their own information.
Domestic and International Legal Frameworks
Korea enacted the Personal Information Protection Act in March 2011, establishing an integrated personal information protection system covering both the public and private sectors. The Act grants data subjects the right to request access, correction, deletion, and suspension of processing, and imposes obligations on processors, including △obtaining consent △purpose limitation △minimization of collection △ensuring security △designating a personal information protection officer. Through the 2023 amendment, provisions on pseudonymized information were newly established, and measures to make the consent system more realistic (customized consent, specific notice) were reflected. Internationally, the EU GDPR (2018) is the most powerful norm, imposing fines of up to 4% of annual global turnover or €20 million (whichever is greater). The United States lacks a comprehensive federal law, with state-level laws such as the CCPA (California) in effect.
Principles of Personal Information Processing
When processing personal information, the purpose should be clearly defined and only the minimum information necessary should be collected. Data subjects must be notified in advance of the purpose of collection and use, retention period, right to refuse consent, etc., and explicit consent must be obtained. Use beyond the original purpose is prohibited, and consent must be obtained again when providing information to third parties. For safe management, technical measures such as encryption, access control, and installation of security programs are required. After the retention period expires or the purpose is achieved, the information must be destroyed immediately, but if necessary for record preservation, it is managed separately.
Pseudonymized Information and Anonymous Information
Pseudonymized information is information in which personally identifiable elements are replaced with other values, making it impossible to identify an individual alone, but with the possibility of combination. It can be processed without the consent of the data subject for purposes such as statistical compilation, scientific research, and preservation of public interest records. On the other hand, anonymous information is information that cannot identify a specific individual even when combined with other information, and is excluded from the application of the Personal Information Protection Act. This is a key mechanism for balancing personal information protection and data utilization, contributing to the development of the data industry.
Violation Cases and Sanctions
Violations of the Personal Information Protection Act can result in imprisonment of up to 3 years or a fine of up to 30 million won (for most violations), and administrative fines up to 3% of revenue. A representative case is the 2014 leak of information from three card companies (information on approximately 100 million people), which resulted in fines of 267 billion won. Recently, companies that secretly collected personal information and used it for AI learning have been sanctioned, and leaks due to hacking continue to occur.
Recent Trends
AI and Personal Information
In 2024-2025, cases are increasing in which personal information included in the training data of artificial intelligence large language models (LLMs) is exposed through chatbots. Accordingly, the Korea Personal Information Protection Commission issued the 'Measures for the Protection-Based Utilization of Personal Information in Generative AI' in 2024, emphasizing the obligation to pseudonymize or de-identify data when collecting it. In addition, when processing personal information for AI training purposes, a strict interpretation of legitimate interests is being required.
MyData and Expansion of the Right to Data Portability
'MyData' services, which allow data subjects to directly control their personal information and request its transfer to various fields such as finance, healthcare, and education, have been expanding to all industries since 2024. This legally guarantees the right to personal information portability and enables individuals to become agents in the data economy.
International Regulatory Trends
Since 2025, the EU has been implementing the AI Act in stages, strengthening personal information impact assessments and data governance requirements for high-risk AI. In the United States, federal-level privacy legislation is under discussion, and globally, there is a trend toward strengthening data sovereignty and cross-border transfer regulations.
Related Topics
- [[Personal Information Protection Act]]
- [[GDPR]]
- [[Information Security]]
- [[Pseudonymized Information]]
- [[Data Privacy]]
- [[AI Ethics]]