Until 2023, getting personal data out of Korea legally meant one thing: consent, itemized and separate. That made Korea the awkward corner of many global architectures, since consent is fragile at scale. The 2023 amendment rebuilt the outbound regime with four additional lanes and one new hazard: a PIPC power to order transfers suspended. Korea now interoperates with GDPR-style adequacy thinking and APEC CBPR certification, but polices the details, as AliExpress’s 2024 fine over seller-side provision shows.
| Regulation | PIPA Articles 28-8 to 28-11 (as amended 2023) |
|---|---|
| Bases | Consent / statute / contract necessity / certification / country recognition |
| Stop orders | PIPC may suspend non-compliant transfers |
| Regulator | PIPC |
The five lanes in practice
Consent. Still the default for marketing-driven and third-party provision transfers. Disclosure must itemize data, destination, recipient, purpose, and retention; consent must be separate from general processing consent. High UX cost, high validity risk, use it only where nothing else fits.
Statute or treaty. Narrow: tax treaties, financial reporting obligations, mutual legal assistance.
Contract necessity. The 2023 workhorse for outsourcing and storage abroad: offshore cloud, group shared services, SaaS processing. Requires disclosure through the privacy policy or notice rather than consent, plus processor supervision equivalent to domestic outsourcing rules.
Certification. Recipients holding PIPC-designated certifications, the CBPR-aligned route, can receive data if protective measures (safeguards, complaint handling) accompany the transfer. This is Korea’s bet on APEC CBPR interoperability.
Country recognition. The PIPC can designate countries or international organizations as providing PIPA-level protection, an adequacy mechanism in all but name.
The backstop. Whatever the lane, PIPA follows the data: recipients must uphold PIPA standards, retransfers inherit the rules, and the PIPC can order suspension when protection fails. Document each route the way you would a GDPR transfer assessment, mapping recipient, destination law, and safeguards.
Positioning regionally
Korea’s outbound regime now sits between Japan’s ongoing-monitoring model and China’s regulator-gated filings: more flexible than PIPL’s mechanisms, more supervised than APPI’s. The PIPA overview covers the domestic duty stack these transfers plug into, and the three-way comparison maps the full triangle.