Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER VI GUARANTEE OF RIGHTS OF DATA SUBJECTS

Enforcement Decree of the Personal Information Protection Act — Article 42 (Limitation to, and postponement and denial of, access to personal information)

개인정보 보호법 시행령 제42조

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) Where any information to which a personal information controller receives a request for access pursuant to Article 41 (1) falls under Article 35 (4) of the Act, the personal information controller may limit access to such information; and shall allow the data subject to access other personal information than the restricted part.

(2) Where a personal information controller intends to postpone a data subject’s access to his or her own personal information pursuant to the latter part of Article 35 (3) of the Act, or to deny the access pursuant to Article 35 (4) of the Act, the personal information controller shall serve the data subject with the Access Postponement or Denial Notice, stating the grounds for postponement or denial and how to appeal, in the form determined and publicly notified by the Protection Commission within 10 days from the receipt of the access request. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>

‹ Article 41All articlesArticle 42-2 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law