(1) The Protection Commission may designate a corporation that satisfies all of the following requirements as a privacy impact assessment institution (hereinafter referred to as "assessment institution") pursuant to Article 33 (2) of the Act: <Amended on Mar. 23, 2013; Nov. 19, 2014; Dec. 22, 2015; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>
1. A corporation whose total revenue derived from any of the following work is 200 million won or more during the last five years:(a) Privacy impact assessments or work similar thereto;(b) Data protection consulting (which means the analysis and assessment of information systems and the provision of corresponding countermeasures against electronic infringement incidents; hereinafter the same shall apply) among the work related to establishing information systems, as defined in subparagraph 13 of Article 2 of the Electronic Government Act (including the information protection system);(c) Data protection consulting among the work related to monitoring information systems, as defined in subparagraph 14 of Article 2 of the Electronic Government Act;(d) Data protection consulting among the work related to the information security industry defined in Article 2 (1) 2 of the Act on the Promotion of the Information Security Industry;(e) Work prescribed in Article 23 (1) 1 and 2 of the Act on the Promotion of the Information Security Industry;
2. A corporation that employs at least 10 full-time experts who meet the qualification requirements determined and publicly notified by the Protection Commission, including work experience in the field related to privacy impact assessment;
3. A corporation with the following offices and facilities:(a) An office with facilities for identification and access control;(b) Facilities for the safe management of records and materials.
(2) A person who intends to be designated as an assessment institution shall file an application for designation as an assessment institution, in the form determined and publicly notified by the Protection Commission, with the Protection Commission, along with the following documents (including electronic documents; hereinafter the same shall apply): <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
1. The articles of incorporation;
2. The representative’s name;
3. Documents verifying the qualifications of the experts referred to in paragraph (1) 2;
4. Other documents determined and publicly notified by the Protection Commission.
(3) Upon receipt of an application for designation as an assessment institution filed under paragraph (2), the Protection Commission shall verify the following documents through administrative data matching pursuant to Article 36 (1) of the Electronic Government Act; provided, where the applicant does not give consent to the verification of subparagraph 2, the Protection Commission shall require the applicant to submit the relevant document: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
1. The corporation registration certificate;
2. The certificate of alien registration issued under Article 88 (2) of the Immigration Act (applicable only to aliens).
(4) Upon designating an assessment institution pursuant to paragraph (1), the Protection Commission shall, without delay, issue a written designation to the relevant applicant, and make a public notice thereof in the Official Gazette. The same shall also apply to any modification of the matters publicly notified: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
1. The name, address, and telephone number of the assessment institution, and the name of its representative;
2. Terms and conditions attached to the designation, if any.
(5) "Cases that fall under any ground prescribed by Presidential Decree" in Article 33 (7) 5 of the Act means any of the following cases: <Amended on Sep. 12, 2023>
1. Where an assessment institution fails to comply with the obligation to submit a report under paragraph (6);
2. Where an assessment institution has no records of privacy impact assessment for two consecutive years from the date of obtaining designation without good cause;
3. Where an assessment institution divulges any information that it has obtained in the course of conducting privacy impact assessments, such as a privacy impact assessment report under the provisions, with the exception of the subparagraphs, of Article 38 (2);
4. Other cases where an assessment institution breaches the duties under the Act or this Decree.
(6) An assessment institution designated under paragraph (1) shall, upon occurrence of any of the following events after designation, submit a report to the Protection Commission, as determined and publicly notified by the Protection Commission, within 14 days from the date of occurrence; provided, it shall submit a report to the Protection Commission within 60 days from the date of occurrence in cases falling under subparagraph 3: <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Oct. 17, 2017; Aug. 4, 2020>
1. Where any matter referred to in paragraph (1) is changed;
2. Where any matter referred to in paragraph (4) 1 is changed;
3. Where the transfer, acquisition, or merger of the assessment institution, or similar event occurs.
(7) Deleted. <Sep. 12, 2023>[Moved from Article 37; previous Article 36 moved to Article 37 <Sep. 12, 2023>]