Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER V SAFEGUARD OF PERSONAL INFORMATION

Enforcement Decree of the Personal Information Protection Act — Article 38 (Criteria for privacy impact assessment)

개인정보 보호법 시행령 제38조

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) The criteria for privacy impact assessments (hereinafter referred to as "assessment criteria") under Article 33 (9) of the Act shall be as follows: <Amended on Jul. 22, 2016; Sep. 12, 2023>

1. The type and nature of personal information contained in the relevant personal information files, the number of data subjects, and the possibility of subsequent personal information breach;

2. The level of measures to ensure safety taken under Articles 23 (2), 24 (3), 24-2 (2), 25 (6) (including cases applied mutatis mutandis in Article 25-2 (4)), and 29 of the Act, and the subsequent possibility of personal information breach;

3. Countermeasures against risk factors of personal information breach, if any;

4. Other necessary measures subject to the Act or this Decree, or any factor affecting breach of duties.

(2) An assessment institution requested to conduct a privacy impact assessment under Article 33 (2) of the Act shall, in accordance with the assessment criteria, analyze and assess the risk factors of personal information breaches that result from the operation of personal information files, and shall prepare a privacy impact assessment report based on the results of the evaluation that includes the following and send such report to the head of the relevant public institution, who shall submit the report to the Protection Commission before operating and changing personal information files falling under the subparagraphs of Article 35: <Amended on Sep. 12, 2023>

1. Those subject to the privacy impact assessment and the scope thereof;

2. Fields and items of the evaluation;

3. Analysis and assessment of the risk factors of personal information breaches in accordance with the assessment criteria;

4. The details of measures taken based on the results of the analysis and evaluation under subparagraph 3 and a plan for improvement;

5. The results of the privacy impact assessment;

6. A summary of the matters prescribed in subparagraphs 1 through 5.

(3) The Protection Commission or the head of a public institution may disclose the details of a summary of a privacy impact assessment report prescribed in paragraph (2) 6. <Added on Sep. 12, 2023>

(4) Except as provided in the Act and this Decree, the Protection Commission may determine and publicly notify the detailed standards for designating assessment institutions, procedures for privacy impact assessments, etc. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020; Sep. 12, 2023>

‹ Article 37All articlesArticle 39 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law