Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER IV-2 SPECIAL CASES CONCERNING PROCESSING OF PSEUDONYMIZED INFORMATION

Enforcement Decree of the Personal Information Protection Act — Article 29-5 (Measures to ensure safety of pseudonymized information)

개인정보 보호법 시행령 제29조의5

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) A personal information controller shall implement the following safety measures for pseudonymized information and additional information to restore pseudonymized information to the original state (hereinafter in this Article referred to as "additional information") in accordance with Article 28-4 (1) of the Act: <Amended on Feb. 2, 2021; Sep. 12, 2023>

1. Measures to ensure safety under Article 30;

2. Separate storage of pseudonymized information and additional information; provided, any unnecessary additional information shall be destroyed;

3. Separation of access rights to pseudonymized information and additional information; provided, if the personal information controller finds it difficult to separate access rights due to good reason such as the personal information controller being a micro enterprise defined in Article 2 of the Framework Act on Micro Enterprises which cannot afford an additional employee to handle pseudonymized information, it shall manage and control access rights by granting the minimum degree of access necessary to do the work and recording the status of access rights granted.

(2) "Matters prescribed by Presidential Decree" in Article 28-4 (3) of the Act mean any of the following: <Amended on Sep. 12, 2023>

1. Purpose of processing pseudonymized information;

2. Items of pseudonymized personal information;

3. Use history of pseudonymized information;

4. Recipient of pseudonymized information provided by a third party;

5. Processing period of pseudonymized information (limited to where the processing period of pseudonymized information is separately determined pursuant to Article 28-4 (2) of the Act);

6. Other matters determined and publicly notified by the Protection Commission as deemed necessary for the management of the processing of pseudonymized information.[This Article Added on Aug. 4, 2020]

‹ Article 29-4All articlesArticle 29-6 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law