Law / South Korea

Personal Information Protection Act, cross-border transfer restrictions

Act No. 10465 (as amended by Act No. 19234, 2023), Art. 28-8(1), Arts. 28-8 to 28-11

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 September 2023.

A cross border transfer rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • An app transferring the personal data of a Korean data subject to a recipient outside South Korea must obtain the data subject's separate consent, or rely on a qualifying treaty, PIPC certification, or PIPC adequacy recognition instead.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Art. 28-8 prohibits cross-border transfer of personal information unless a lawful basis applies, separate consent from the data subject first among them (Art. 17(3), the rule's pre-2023 home, was deleted by Act No. 19234), and bars a transfer contract that would violate the Act.

The 2023 amendment's Arts. 28-8 to 28-11 add alternative grounds: a treaty or international agreement, PIPC certification of the recipient's safeguards, or PIPC recognition that the destination country affords adequate protection, and arm the PIPC to order a transfer suspended for a serious or repeated violation. There is no data localization mandate.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official KLRI English translation of the current consolidated PIPA text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app