Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER V SAFEGUARD OF PERSONAL INFORMATION

Enforcement Decree of the Personal Information Protection Act — Article 32 (Work of privacy officer and requirements for designation)

개인정보 보호법 시행령 제32조

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) "Personal information controller whose number of employees, turnover, etc. meet the criteria prescribed by Presidential Decree" in terms of the number of employees, sales, etc. in the proviso of Article 31 (1) of the Act means a personal information controller who is a micro enterprise defined in Article 2 (1) of the Framework Act on Micro Enterprises. <Added on Mar. 12, 2024>

(2) "Work prescribed by Presidential Decree" in Article 31 (3) 7 of the Act shall be as follows: <Amended on Mar. 12, 2024>

1. To establish, modify, and implement the Privacy Policy pursuant to Article 30 of the Act;

2. Management of human and physical resources and information related to personal information processing;

3. To destroy personal information whose purpose of processing is attained or retention period expires.

(3) Where a personal information controller intends to designate a person in charge of personal information protection pursuant to Article 31 (1) of the Act, he or she shall designate the person according to the following classifications: <Amended on Jul. 22, 2016; Mar. 12, 2024>

1. Public institutions: Public officials, etc. who satisfy the below standards:(a) The administrative bodies of the National Assembly, the Court, the Constitutional Court, and the National Election Commission; and central administrative agencies: A member of the Senior Executive Service (hereinafter referred to as "senior executive") or equivalent public official;(b) Other national agencies than item (a), headed by a public official in political service: A public official of Grade III or higher (including a senior executive) or equivalent thereto;(c) Other national agencies than items (a) and (b), headed by a senior executive, a Grade III or higher public official, or an equivalent public official: A public official of Grade IV or higher or equivalent thereto;(d) Other national agencies than items (a) through (c) (including their affiliated bodies): The head of a department in charge of the work related to personal information processing in the relevant agency;(e) City/Do, City/Do Offices of Education: A public official of Grade III or higher or equivalent thereto;(f) Si/Gun/autonomous Gu: A public official of Grade IV or higher or a public official equivalent thereto;(g) Schools of various levels under subparagraph 5 of Article 2: A person who exercises overall control over the administrative affairs of the relevant school; provided, in cases falling under paragraph (4) 2, it means teachers and staff;(h) Other public institutions than items (a) through (g): The head of a department in charge of the work related to personal information processing in the relevant institution; provided,, where the heads of at least two departments are in charge of the work related to personal information processing, the head of the relevant institution shall designate the privacy officer from among them;

2. An institution other than public institutions: Any of the following persons:(a) The business owner or representative;(b) An executive officer (or the head of a department in charge of the work related to personal information processing, if no executive officer exists).

(4) Any of the following personal information controllers (limited to cases falling under subparagraphs 2 through 5 of Article 2 in cases of public institutions) shall designate a person who meets the requirements prescribed in Appendix 1, from among persons classified in the subparagraphs of paragraph (3), as a person in charge of protecting personal information: <Amended on Mar. 12, 2024>

1. Any of the following persons (excluding schools of various levels defined in subparagraph 5 of Article 2 and medical institutions defined in Article 3 of the Medical Service Act) whose annual sales, etc. are at least 150 billion won:(a) A person who processes sensitive information or personally identifiable information concerning at least 50,000 data subjects;(b) A person who processes personal information of at least one million data subjects;

2. The School under Article 2 of the Higher Education Act, the number of enrolled students (including the number of enrolled students at a graduate school) of which is at least 20,000 as of Dec. 31 of the immediately preceding year;

3. High-tier general care hospitals under Article 3-4 of the Medical Service Act;

4. Institutions operating public systems.

(5) The Protection Commission may provide support, such as the establishment and operation of educational courses for persons in charge of personal information protection so that the person in charge of personal information protection can smoothly perform the duties prescribed in Article 31 (3) of the Act. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Mar. 12, 2024>

(6) A personal information controller (excluding where a business owner or representative becomes a person in charge of protection of personal information pursuant to Article 31 (2) of the Act) shall comply with the following to ensure the independence of the person in charge of personal information protection under Article 31 (6) of the Act: <Added on Mar. 12, 2024>

1. Protecting personal information protection officer's access to information related to personal information processing;

2. Establishment of a system in which a person in charge of personal information protection may regularly report the establishment and implementation of a personal information protection plan and the results thereof to the representative or the board of directors on a regular basis;

3. Preparation of an organizational system suitable for persons in charge of personal information protection to perform their duties and provision of human and material resources.

‹ Article 31-2All articlesArticle 32-2 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law