Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER V SAFEGUARD OF PERSONAL INFORMATION

Enforcement Decree of the Personal Information Protection Act — Article 35 (Object of privacy impact assessment)

개인정보 보호법 시행령 제35조

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

"Personal information files meeting the criteria prescribed by Presidential Decree" in Article 33 (1) of the Act means any of the following personal information files that can be processed electronically: <Amended on Sep. 29, 2016>

1. Personal information files that will be established, operated, or modified, and contain sensitive information or personally identifiable information of at least 50 thousand data subjects for processing;

2. Personal information files that is established and operated, and will be matched with other personal information files being established and operated inside or outside the relevant public institution, and, as a result of matching, will contain the personal information of at least 500 thousand data subjects;

3. Personal information files that will be established, operated, or modified, and contain the personal information of at least one million data subjects;

4. Personal information files whose operating system, including the data retrieval system, will be changed after the privacy impact assessment under Article 33 (1) of the Act (hereinafter referred to as "privacy impact assessment"). In such cases, the privacy impact assessment shall be limited to the changed system.

‹ Article 34-8All articlesArticle 36 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law