Republic of Korea Adequacy Decision, Commission Implementing Decision (EU) 2022/254
Commission Implementing Decision (EU) 2022/254
In force since .
A cross border transfer rule binding public and private bodies.
- Criminal exposure
- No
- Private right of action
- No
- Obligation class
- Transfer
- Audit expectation
- periodic
- Who audits it
- Regulator
As of .
What it requires
- A transfer of personal data from the European Union to an entity in the Republic of Korea subject to the Personal Information Protection Act as complemented by the additional safeguards in Annex I may take place on the basis of Article 1(1) of the Decision, without any specific authorization (Article 45(1) of Regulation (EU) 2016/679).
- The finding does not cover a transfer to a religious organization, to the extent it processes the data for its missionary activities, to a political party, to the extent it processes the data in the context of the nomination of candidates, or to an entity subject to oversight by the Financial Services Commission for the processing of personal credit information pursuant to the Credit Information Act, to the extent it processes such information (Article 1(2)).
Who enforces it
Enforcement body
The competent authorities of the Member States, which exercise their powers under Article 58 of Regulation (EU) 2016/679 over transfers within the scope of Article 1 and inform the Commission (Article 2), and the Commission, which monitors the application of the legal framework and may suspend, amend or repeal the Decision (Article 3).
What this law does
Article 1(1) provides that, for the purpose of Article 45 of Regulation (EU) 2016/679, the Republic of Korea ensures an adequate level of protection for personal data transferred from the European Union to entities in the Republic of Korea subject to the Personal Information Protection Act as complemented by the additional safeguards set out in Annex I, together with the official representations, assurances and commitments contained in Annex II.
Article 1(2) provides that the Decision does not cover personal data transferred to religious organizations processing it for their missionary activities, political parties processing it in the context of the nomination of candidates, or entities subject to oversight by the Financial Services Commission for the processing of personal credit information pursuant to the Credit Information Act, to the extent they process such information.
Article 2 requires a Member State whose competent authorities exercise their powers under Article 58 of Regulation (EU) 2016/679 over data transfers within the scope of Article 1 to inform the Commission without delay.
Article 3(4) requires the Commission, after three years from the date of the notification of the Decision to the Member States and subsequently at least every four years, to evaluate the finding in Article 1(1) on the basis of all available information, including the information received as part of the review carried out together with the relevant Korean authorities.
Article 3(5) provides that, where the Commission has indications that an adequate level of protection is no longer ensured, it informs the competent Korean authorities and, if necessary, may decide to suspend, amend or repeal the Decision, or limit its scope, in accordance with Article 45(5) of Regulation (EU) 2016/679. Article 4 provides that the Decision is addressed to the Member States.
The Commission announced on that it had concluded its first review of the Decision and found that the Republic of Korea continues to provide an adequate level of protection of personal data.
When LexLint raises it
When your app profile says your app crawls the web, trains models, deploys a chatbot, sends automated outreach, processes voice recordings or processes biometric data.