Korean Law in English
Laws › Personal Information Protection Act › CHAPTER IV SAFEGUARD OF PERSONAL INFORMATION

Personal Information Protection Act — Article 31 (Designation of privacy officers)

개인정보 보호법 제31조

This English translation is based on the Korean text effective 2025-10-02. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) A personal information controller shall designate a privacy officer who shall have general supervision and control of the work regarding personal information processing; provided, a personal information controller whose number of employees, turnover, etc. meet the criteria prescribed by Presidential Decree need not designate a privacy officer. <Amended on Mar. 14, 2023>

(2) Where a privacy officer is not designated under the proviso of paragraph (1), the business owner or representative of the personal information controller shall become the privacy officer. <Added on Mar. 14, 2023>

(3) A privacy officer shall perform the following work: <Amended on Mar. 14, 2023>

1. To establish and implement a personal information protection plan;

2. To conduct a regular survey of the status and practices of personal information processing, and to improve shortcomings;

3. To handle grievances and remedial compensation in relation to personal information processing;

4. To build the internal control system to prevent the divulgence, abuse, and misuse of personal information;

5. To prepare and implement an education program about personal information protection;

6. To protect, control, and manage the personal information files;

7. Other work prescribed by Presidential Decree for the appropriate processing of personal information.

(4) In performing the work provided in the subparagraphs of paragraph (3), a privacy officer may occasionally inspect the current status of personal information processing, processing systems, etc. if necessary, and may request a report thereon from the relevant parties. <Amended on Mar. 14, 2023>

(5) Where a privacy officer becomes aware of any violation of this Act or other relevant statutes or regulations in relation to the protection of personal information, he or she shall take corrective measures immediately, and shall report such corrective measures to the head of the institution or organization to which he or she belongs, if necessary. <Amended on Mar. 14, 2023>

(6) A personal information controller shall not allow the privacy officer to give or be subject to disadvantages without good cause while performing the affairs provided in the subparagraphs of paragraph (3), and shall guarantee the independent performance of work by the privacy officer. <Amended on Mar. 14, 2023>

(7) A personal information controller may organize and operate a council of privacy officers comprised of the privacy officers provided in paragraph (1) so as to safely process and protect personal information, exchange information, and conduct other joint projects prescribed by Presidential Decree. <Added on Mar. 14, 2023>

(8) The Protection Commission may provide support necessary for the activities of the council of privacy officers under paragraph (7). <Added on Mar. 14, 2023>

(9) Matters necessary for the qualification requirements for a privacy officer under paragraph (1), the work under paragraph (3), the guarantee of independence under paragraph (6), and other relevant matters, shall be prescribed by Presidential Decree, taking into consideration sales, the scale of personal information retained, etc. <Amended on Mar. 14, 2023>[Title Amended on Mar. 14, 2023]

‹ Article 30-2All articlesArticle 31-2 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law