Every personal information controller shall take such technical, managerial, and physical measures as establishing an internal management plan and preserving access records, etc. that are necessary to ensure safety as prescribed by Presidential Decree so that the personal information may not be lost, stolen, divulged, forged, altered, or damaged. <Amended on Jul. 24, 2015>
Laws › Personal Information Protection Act › CHAPTER IV SAFEGUARD OF PERSONAL INFORMATION
Personal Information Protection Act — Article 29 (Duty of safeguards)
개인정보 보호법 제29조
This English translation is based on the Korean text effective 2025-10-02. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.
For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool:
https://mcp.apify.com?tools=kr-data/korea-law