Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER IV-3 Cross-Border Transfer of Personal Information

Enforcement Decree of the Personal Information Protection Act — Article 29-10 (Protective measures in cases of cross-border transfers of personal information)

개인정보 보호법 시행령 제29조의10

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) Where a personal information controller makes a cross-border transfer of personal information under the proviso, with the exception of the subparagraphs, of Article 28-8 (1) of the Act, he or she shall take the following protective measures under Article 28-8 (4) of the Act:

1. Measures to ensure safety for protecting personal information under Article 30 (1);

2. Measures to handle grievances and resolve disputes with respect to personal information breach;

3. Other measures necessary to protect the personal information of data subjects.

(2) Where a personal information controller makes a cross-border transfer of personal information under the proviso, with the exception of the subparagraphs, of Article 28-8 (1) of the Act, it shall have a prior consultation with the recipient of the personal information on the matters specified in the subparagraphs of paragraph (1) and shall reflect the results of such consultation in the details of a contract, etc.[This Article Added on Sep. 12, 2023]

‹ Article 29-9All articlesArticle 29-11 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law