Korean Law in English
Laws › Enforcement Decree of the Personal Information Protection Act › CHAPTER II PERSONAL INFORMATION PROTECTION COMMISSION

Enforcement Decree of the Personal Information Protection Act — Article 9-3 (Procedures for assessment of personal information breach incident factors)

개인정보 보호법 시행령 제9조의3

This English translation is based on the Korean text effective 2025-03-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) The head of a central administrative agency who intends to request an assessment of personal information breach incident factors pursuant to Article 8-2 (1) of the Act (hereinafter referred to as "assessment of personal information breach incident factors") shall submit to the Protection Commission a written request (or an electronic request form) for an assessment of personal information breach incident factors which contains the following matters:

1. The purposes and major contents of the policy and systems in need of personal information processing to be adopted or changed by the statutes or regulations (including the draft);

2. Self-analysis of personal information breach incident factors with respect to the matters prescribed in paragraph (2) following the adoption and change of the policy and system in need of personal information processing;

3. Measures to protect personal information following the adoption and change of the policy and system in need of personal information processing.

(2) Upon receipt of a written request under paragraph (1), the Protection Commission shall assess data breach incident factors taking into account the following matters, and shall notify the result thereof to the head of the related central administrative agency:

1. Necessity for processing personal information;

2. Appropriateness of guarantees for the rights of data subjects;

3. Safety in the management of personal information;

4. Other matters necessary to assess data breach incident factors.

(3) The head of a central administrative agency who has been advised as prescribed in Article 8-2 (2) of the Act shall endeavor to implement as advised, such as incorporating such advice in the relevant draft statute or regulation; provided, where it is impracticable to implement as advised by the Protection Commission, the reason therefor shall be notified to the Protection Commission.

(4) The Protection Commission may request materials necessary to assess data breach incident factors from the head of the related central administrative agency.

(5) The Protection Commission may establish guidelines necessary to assess data breach incident factors, including detailed criteria for and methods of the assessment of data breach incident factors; and shall notify the heads of central administrative agencies of the guidelines.

(6) The Protection Commission may seek counsel, etc. from relevant experts where necessary to assess data breach incident factors.[This Article Added on Jul. 22, 2016]

‹ Article 9-2All articlesArticle 10 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law