Korean Law in English
Laws › Personal Information Protection Act › CHAPTER IV SAFEGUARD OF PERSONAL INFORMATION

Personal Information Protection Act — Article 33 (Privacy impact assessment)

개인정보 보호법 제33조

This English translation is based on the Korean text effective 2025-10-02. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) Where there is a risk of a personal information breach of data subjects due to the operation of personal information files meeting the criteria prescribed by Presidential Decree, the head of a public institution shall conduct an assessment to analyze risk factors and to improve them (hereinafter referred to as "privacy impact assessment"), and submit the results thereof to the Protection Commission. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Feb. 4, 2020; Mar. 14, 2023>

(2) The Protection Commission may designate a person who satisfies the requirements prescribed by Presidential Decree such as human resources and facilities as an institution that performs a privacy impact assessment (hereinafter referred to as "assessment institution"), and the head of a public institution shall request the assessment institution to conduct the privacy impact assessment. <Added on Mar. 14, 2023>

(3) Privacy impact assessments shall take into account the following: <Amended on Mar. 14, 2023>

1. The number of personal information being processed;

2. Whether the personal information is provided to a third party;

3. The probability to violate the rights of the data subjects and the degree of risks;

4. Other matters prescribed by Presidential Decree.

(4) The Protection Commission may provide its opinion on the privacy impact assessment results submitted under paragraph (1). <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Feb. 4, 2020; Mar. 14, 2023>

(5) The head of a public institution shall register the personal information files in accordance with Article 32 (1), for which the privacy impact assessment has been conducted pursuant to paragraph (1), with the results of the privacy impact assessment attached thereto. <Amended on Mar. 14, 2023>

(6) The Protection Commission shall take necessary measures, such as fostering relevant specialists, and developing and disseminating criteria for the privacy impact assessment, to promote the privacy impact assessment. <Amended on Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Feb. 4, 2020; Mar. 14, 2023>

(7) The Protection Commission may revoke the designation of an assessment institution that has obtained designation under paragraph (2) in any of the following cases; provided, it shall revoke the designation in cases falling under subparagraph 1 or 2: <Added on Mar. 14, 2023>

1. Where the designated assessment institution has obtained its designation by fraud or other improper means;

2. Where the designated assessment institution wants revocation of such designation or has closed its business;

3. Where the designated assessment institution ceases to meet the requirements for designation provided in paragraph (2);

4. Where the designated assessment institution has poorly performed its work either by intention or gross negligence, and is deemed incapable of duly performing its affairs;

5. Other cases that fall under any ground prescribed by Presidential Decree.

(8) Where the Protection Commission revokes designation pursuant to paragraph (7), it shall hold a hearing in accordance with the Administrative Procedures Act. <Added on Mar. 14, 2023>

(9) Matters necessary for the criteria, methods, procedures, etc. for privacy impact assessments under paragraph (1) shall be prescribed by Presidential Decree. <Amended on Mar. 14, 2023>

(10) Matters regarding the privacy impact assessment conducted by the National Assembly, the Court, the Constitutional Court and the National Election Commission (including their affiliated entities) shall be prescribed by the National Assembly Regulations, the Supreme Court Regulations, the Constitutional Court Regulations, and the National Election Commission Regulations. <Amended on Mar. 14, 2023>

(11) A personal information controller other than public institutions shall proactively endeavor to conduct a privacy impact assessment, if there is a risk of a personal information beach of data subjects in operating the personal information files. <Amended on Mar. 14, 2023>

‹ Article 32-2All articlesArticle 34 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law