Unknown User4
Case Study: Managing PIPA Training Across Regional Shared Service Centers
2026.08.31 10:00
Privacy · Retirement Pension
Case Study: Managing PIPA Training
Across Regional Shared Service Centers
A shared service centre is a trustee, and training its people is your duty, not theirs.
📌 Key takeaways
- Korea's Personal Information Protection Act does not set a training frequency. Article 28(2) says "regularly"; Article 26(4) says the entrusting party shall educate the trustee. Neither the Act, the Enforcement Decree, nor the safety-measures Public Notice contains a number. The "at least once a year" that every vendor quotes comes from administrative guidance and from your own internal management plan not from the statute.
- The one place a legal instrument does say "at least once a year" is a different duty entirely: Article 4(4) of the Standards for Ensuring the Safety of Personal Information requires the Chief Privacy Officer to review implementation of the internal management plan annually. Confusing the two is the most common structural error we see in foreign-invested entities.
- A shared service centre is a trustee , and training its people is your duty, not theirs. Article 26(4) puts the education and supervision obligation on the Korean entity that entrusted the work. The SSC's own global privacy training does not discharge it, and Article 26(7) treats the trustee as your own employee for damages purposes.
- If the SSC passes work down the chain, you have to agree to it. Article 26(6), added in the 2023 amendment, requires the entrusting party's consent to sub-entrustment. A regional SSC that quietly moves payroll onto a global vendor without your sign-off has created a defect in your compliance position, not in theirs.
- Korean employee data reaching an offshore SSC is a cross-border transfer under Article 28-8. There is a workable route that does not require separate consent but it runs through your privacy policy, and the EU/EEA equivalence recognition of 16 September 2025 does not help you if the SSC is in Kuala Lumpur, Manila or Bangalore, and does not cover resident registration numbers anywhere.
🧩 The scenario
Set out a composite that will be familiar to anyone running HR for a foreign-invested group in Korea.
A European manufacturing group operates a Korean subsidiary with 180 employees a sales organisation, a technical service team and a small corporate function. HR administration was centralised three years ago. Payroll input, benefits administration, onboarding and leaver processing are performed by a regional shared service centre in Kuala Lumpur. The group HRIS is hosted in the EU. IT service desk tickets, which routinely contain employee identifiers, are handled from Bangalore. A specialist payroll vendor, contracted by the SSC rather than by the Korean entity, produces the Korean payroll file.
Privacy training is run globally: a single English-language e-learning module, assigned annually to everyone in the group with an HR system login, with completion tracked in the group LMS. The group is GDPR-mature. The Data Protection Officer sits in Amsterdam. The Korean HR manager has been told, more than once, that Korea is covered.
Nothing in that description is unusual, and most of it is sound practice. But four separate Korean obligations are unaddressed in it, and none of them is fixed by adding a Korean-language version of the same module.
🔎 Question 1 — who is the personal information controller here?
Start with the entity, because everything else follows from it.
The Korean subsidiary employs the Korean employees. It determines why and how their personal information is processed for employment purposes. It is therefore the security the personal information controller for that data, and every duty discussed below attaches to it rather than to the parent, to the regional HR organisation, or to the group DPO.
The shared service centre is a receiver a trustee, roughly the analogue of a GDPR processor. So is the Bangalore service desk, to the extent it handles Korean employee data. So is the payroll vendor, though as we come to below, its position in the chain is the problem rather than its status.
This is not the same allocation a GDPR-trained team expects. Under GDPR, a controller must ensure its processor's staff are bound by confidentiality, but the duty to train them sits with the processor as their employer. Korean law does not split it that way. Article 26(4) obliges the entrusting party to educate the trustee and to supervise it, including by checking how it is handling the personal information. The obligation is yours, discharged by you, evidenced by you.
Article 26(7) then closes the loop from the other end: where the trustee causes damage in the course of performing the entrusted work, the trustee is regarded as an employee of the entrusting party for the purposes of liability. A Korean entity that has outsourced HR administration to a regional centre has not outsourced the consequences.
🕒 Question 2 — does the annual global module satisfy Korean law?
Here is where the analysis usually goes wrong in both directions at once.
What the law actually says.
Article 28(1) requires the controller to exercise appropriate control and supervision over personal information handlers expressly including officers and employees, dispatched workers and part-time workers. Article 28(2) requires the controller to regularly provide those handlers with necessary training. There is no number.
Article 4(2) of the Standards for Ensuring the Safety of Personal Information (Personal Information Protection Commission Public Notice No. 2023-6) is more specific about shape and still silent about frequency. It requires the controller to set the training purpose and audience, content, schedule and method, and to deliver training to the Chief Privacy Officer and to personal information handlers, differentiated according to business scale, volume of personal information held, and the nature of the work, on a regular basis.
Read that clause against the scenario and the mismatch is obvious. One module, one language, one audience, delivered identically to a payroll analyst in Kuala Lumpur who handles Korean resident registration numbers and to a marketing coordinator in Seoul who does not, is the opposite of differentiated.
Where "once a year" comes from.
It is not fabricated it is simply not statutory. Administrative guidance from the Personal Information Protection Commission, including its HR and labour-management privacy guidance, recommends at least annually for ordinary businesses. Beyond that, the number in force at your company is generally the number written into your own internal management plan under Article 4(1) of the Public Notice, which is a document you drafted and are then measured against.
That distinction matters practically. A commitment of "quarterly" in your internal management plan, delivered annually, is a failure to implement your own plan. A commitment of "annually", delivered annually, is not.
| Source | What it actually says about frequency | Legal character | ||
|---|---|---|---|---|
| PIPA Art. 28(2) handler training | "Regularly" no figure | Statute; binding | ||
| PIPA Art. 26(4) trustee education | No figure | Statute; binding | ||
| Public Notice 2023-6 Art. 4(2) | "Regularly", differentiated by scale, volume and nature of work | Public Notice; binding as a safety measure | ||
| Public Notice 2023-6 Art. 4(4) | "At least once a year" but this is the CPO's review of internal management plan implementation, not training | Public Notice; binding | ||
| PIPC administrative guidance | At least once a year recommended | Guidance; not a penalty provision | ||
| Your internal management plan | Whatever you wrote | Binding on you, in practice |
One more thing the law does not do
: there is no free-standing penalty for failing to run the training itself. That is a poor reason to relax. Training is how you evidence the supervision duty under Articles 26(4) and 28(1), and those are what an investigator examines after an incident.
👥 Question 3 — who trains the shared service centre?
You do. This is the single obligation most often missing from an otherwise well-run global privacy programme, because nothing in the GDPR structure prompts it and nothing in the SSC's own compliance file fills it. The SSC will show you its ISO 27001 certificate, its annual group privacy module, its confidentiality undertakings. All of that is real, and none of it is the Korean entity discharging Article 26(4).
What Article 26(4) contemplates, in the shape practitioners and public-sector guidance describe, is a two-track cycle:
Education
— plan, deliver, report. The Korean entity may deliver classroom or online training itself, engage a third-party specialist, or accept the trustee's own training. The last option is permitted. What is not permitted is not knowing whether it happened, what it covered, or who attended.
Supervision
— plan the check, perform it, report the result. Requesting documentation, site visits and remote assessment are all recognised methods. The subject is whether the trustee is complying with the safety measures, not whether it is generally a competent organisation.
For an offshore SSC there is an additional layer the domestic guidance does not have to spell out. The Korean-specific content is precisely the content a global module omits: the resident registration number rules, the retention periods that Korean employment and tax law impose, the notification obligations if something goes wrong, and the fact that Korean employees have data subject rights they will exercise in Korean, to an SSC that may not read Korean.
The written instrument sits underneath all of it. Entrustment must be documented, and between Article 26(1) and Article 28(1) of the Enforcement Decree the document must cover seven items.
| # | Mandatory item in the entrustment document | Where it bites in an SSC arrangement | ||
|---|---|---|---|---|
| 1 | Prohibition on processing personal information beyond the purpose of the entrusted work | Analytics, benchmarking and group reporting built on Korean HR data | ||
| 2 | Technical and managerial protective measures | Whether group standards actually map to the Korean safety measures | ||
| 3 | Purpose and scope of the entrusted work | Scope creep as the SSC absorbs new processes | ||
| 4 | Restriction on sub-entrustment | The payroll vendor the SSC contracted directly | ||
| 5 | Safety measures including access restriction | SSC agents with standing access to all countries' records | ||
| 6 | Supervision, including inspection of the management status of personal information | Your right to actually perform the Article 26(4) check | ||
| 7 | Liability, including damages, where the trustee breaches its obligations | Meaningless if the intra-group agreement excludes it |
Two further duties follow from the entrustment and are easy to forget in a group context. The content of the entrusted work and the identity of the trustee must be disclosed and since the 2023 amendment, the disclosure reaches down the chain to sub-trustees. In practice this lives in the Korean entity's privacy policy, and for employee data in the employee-facing privacy notice.
🔗 Question 4 — the link in the chain you did not sign
Return to the payroll vendor contracted by the SSC rather than by the Korean entity.
Article 26(6), introduced by the amendment effective 15 September 2023, requires the consent of the entrusting party before the trustee may sub-entrust the work. Sub-entrustment is not prohibited; proceeding without your agreement is.
This is a real divergence from the framework a European group will have internalised. GDPR Article 28 permits a processor to engage sub-processors under a general written authorisation, subject to notice and an opportunity to object. Korean law is built the other way round: the default is that the trustee may not, and your consent is the thing that changes it.
The operational consequence for a regional SSC model is specific and unwelcome. Regional centres are designed to standardise, and standardising usually means selecting one vendor for a process across all countries in the region. Where that decision is made regionally a new payroll engine, a new ticketing platform, a new document repository, an offshore team taking over first-line HR queries the Korean entity's consent is a step in the process, and in most groups it is not.
The fix is procedural rather than legal: the Korean entity needs to be a named approver in the SSC's vendor-onboarding workflow for anything touching Korean employee data, with the approval recorded. It costs very little to build and cannot be reconstructed afterwards.
🌐 Question 5 — the data is leaving Korea, and consent is not the only route
Sending Korean employee data to Kuala Lumpur is a transfer abroad. Article 28-8(1) prohibits transferring personal information overseas — including by provision, entrustment of processing, storage, and access from abroad — unless one of five grounds applies.
| Ground (Art. 28-8(1))Available in this scenario? | |
|---|---|
| 1. Separate consent from the data subject to the overseas transfer<br> | Available, but consent from employees is a weak foundation given the imbalance in the relationship |
| 2. Special provision in a statute or a treaty to which Korea is a party | Not applicable |
| 3. Entrustment or storage necessary for concluding and performing a contract with the data subject, where the Art. 28-8(2) items are disclosed in the privacy policy or notified by email or similar means | The workable route |
| 4. The recipient holds a certification designated by the Commission | Situational |
| 5. The Commission recognises the receiving country or international organisation as offering an equivalent level of protection | EU/EEA only — see below |
Ground 3 is the one that fits an HR shared service arrangement, and it is worth being precise about what it requires. The transfer must be an entrustment or storage that is necessary for concluding and performing the contract with the data subject for employee data, the employment contract. And the items in Article 28-8(2) must either be disclosed in the privacy policy under Article 30 or notified to the data subject by email or another prescribed method.
Those items are the transfer disclosure most global privacy notices are missing:
- the categories of personal information transferred;
- the country to which it is transferred, and the timing and method of transfer;
- the name of the recipient, or for a legal person its name and contact details;
- the recipient's purpose of use and the period of retention and use; and
- the method and procedure for refusing the overseas transfer, and the effect of refusal.
The EU equivalence recognition, and its limits. On 16 September 2025 the Personal Information Protection Commission recognised the 27 EU member states and the three EEA states Norway, Liechtenstein and Iceland as offering an equivalent level of protection under Article 28-8(1)5. This is the first such recognition, and for a European group it is genuinely useful: the EU-hosted group HRIS no longer needs a separate transfer ground.
It does not solve the case in front of us. The SSC is in Malaysia. The service desk is in India. Neither is covered, and a group that hears "Korea has recognised the EU" and concludes that its global architecture is cleared has drawn a conclusion three jurisdictions wider than the decision.
There is also a carve-out that lands squarely on payroll. Resident registration numbers and personal credit information cannot be transferred on the basis of the equivalence recognition. The resident registration number is the identifier Korean payroll and year-end tax settlement actually run on. Where an offshore SSC touches it, that element of the processing needs its own analysis under Article 24-2, which restricts resident registration number processing to specific legal bases regardless of where it happens, as well as under the transfer rules.
📝 Question 6 — language, evidence, and the part nobody owns
Two loose ends remain, and they are the ones that decide how the file looks eighteen months later.
Language.
Nothing in PIPA prescribes Korean-language delivery. But the training obligation is to provide necessary training, differentiated by the nature of the work, and the supervision obligation is to establish that the trustee is complying. A Korean personal information handler who has completed an English module about GDPR concepts has not been trained on resident registration number handling, Korean retention periods, or the Korean breach notification route. The question is not whether an English module is permitted; it is whether it is the necessary training for that person's actual work.
The mirror image applies offshore. SSC agents processing Korean employee records need the Korean-specific content in a language they work in which is generally English. Bilingual delivery in a shared service model usually means two different modules for two different populations, not one module in two languages.
Evidence.
The Korean entity is the party that must be able to show what was delivered, to whom, when, and what the supervision check found. Where the LMS belongs to the group and the SSC's records belong to the SSC, the Korean entity frequently holds nothing at all. A quarterly extract of Korean-relevant completion records into the Korean entity's own files is a small piece of housekeeping that changes the entity's position materially.
Two adjacent items belong in the same file. The Chief Privacy Officer must be designated by the Korean entity the group DPO in Amsterdam is not a substitute and where the entity meets the thresholds for the specialist CPO regime that took effect on 15 March 2024, the appointee must hold four years of combined privacy, information security and IT experience including at least two years in privacy. That regime applies to controllers with annual revenue of KRW 150 billion or more that process the personal information of one million or more people, or sensitive or unique identifying information of 50,000 or more people, among other categories. And the CPO's annual review of internal management plan implementation under Article 4(4) of the Public Notice is the "once a year" obligation that genuinely exists which, in a group where the CPO is a Korean HR or finance manager with a day job, is worth diarising.
🆕 What changes on 11 September 2026
One development is close enough to plan around rather than watch.
The amended Personal Information Protection Act was promulgated on 10 March 2026 and takes effect on 11 September 2026. Three elements matter to the arrangement described here.
Administrative fines rise for aggravated cases.
The general ceiling stays at 3 per cent of total revenue under Article 64-2. The amendment adds a 10 per cent ceiling where the violation is a repeat violation, where intent or gross negligence caused large-scale harm, or where a corrective order was not complied with. A reduction of up to 40 per cent is introduced for demonstrated investment in, and operation of, a protection framework which gives the documentation discussed above a second use.
The domestic representative regime tightens further.
Separately, since 2 October 2025 a controller that has established a Korean legal entity must designate its domestic representative from among those entities, closing the practice of appointing a nominal local agent; the correction deadline for existing designations was 2 April 2026. From 11 September 2026 the scope of the representative's functions widens. For a group whose foreign parent is itself a controller of Korean data not merely a recipient this needs checking rather than assuming.
⚠️ Common mistakes
- Treating "at least once a year" as a statutory requirement. It is guidance and internal policy. What binds you is "regularly", "differentiated", and whatever your own internal management plan says.
- Confusing the CPO's annual internal-management-plan review with the training obligation. Only the former carries the annual figure.
- Assuming the shared service centre trains its own people for Korean purposes. Article 26(4) puts the education and supervision duty on the Korean entity that entrusted the work.
- Running the SSC relationship on an intra-group agreement that never addresses the seven mandatory entrustment items, on the basis that it is internal to the group.
- Letting the SSC appoint a sub-vendor for a Korean process without the Korean entity's consent. Korean law does not have GDPR's general written authorisation.
- Delivering one English-language global module to both Korean handlers and offshore SSC agents and treating that as differentiated training.
- Reading the September 2025 EU equivalence recognition as covering the group's whole processing footprint. It covers the EU and EEA, and it does not cover resident registration numbers.
- Relying on employee consent as the transfer ground when the entrustment route under Article 28-8(1)3 is available and does not depend on consent that employees may withdraw.
- Leaving all training and supervision records in group systems, so that the Korean entity holds none of them.
- Designating the group DPO as the Korean Chief Privacy Officer.
- Disclosing the trustee in the privacy policy but not the sub-trustees the SSC engaged.
💬 How EAP supports employees and HR
There is a reason this topic belongs on a board about employee wellbeing rather than only in a compliance manual, and it is not a general one.
An employee assistance programme processes some of the most sensitive personal information an employer will ever be adjacent to health and mental health information, in the terms of the Act sensitive information within the meaning of Article 23. In a group that has centralised HR into a regional shared service centre, the EAP is very often procured regionally too, run on a regional platform, with a regional case management system and a hotline that may route outside Korea. Every question in this article applies to it, with the sensitivity dialled up: who is the controller, who is the trustee, was there consent to sub-entrustment, is the transfer ground correct, and has anyone trained the people handling the records.
It also matters for a reason that has nothing to do with penalties. Employees use an EAP when they believe it is confidential, and they stop using it the moment they suspect their manager or their HR team can see who called. An EAP that cannot describe its data flows clearly, in Korean, to a Korean employee is an EAP with low utilisation, which means the organisation loses the early signal it was built to provide.
International frameworks put that signal at the centre rather than at the edge. WHO guidance on mental health at work is explicit that organisational conditions workload, control, job security, and the way change is managed drive worker mental health outcomes, and recommends manager training alongside worker-directed support. ISO 45003 places psychosocial risk inside the occupational health and safety management system rather than beside it. Under the EAPA Core Technology, confidential problem identification and assessment for employees whose personal concerns affect work performance, and consultation with managers and organisations on employee and organisational issues, are core EAP functions and the confidentiality is not a service feature layered on top, it is what makes the identification function work at all.
Centralisation into a shared service centre is itself one of those organisational conditions. HR administration moving offshore removes the person a Korean employee used to walk over to, and often removes it at the same time as a restructuring. The transition period is exactly when confidential support is most used and least available.
Three things follow for a Korean entity in this position. Handle the EAP as a named entrustment with its own documented data flow, in the same file as the HRIS and the payroll vendor rather than as a benefit outside the compliance perimeter. Insist that the confidential channel operates in Korean, staffed by people who can hold the conversation, whatever the regional platform behind it looks like. And give managers somewhere to take a concern about a team member, since in a shared service model the HR generalist who used to take that call is now a ticket queue in another country.
🔗 Related guides
❓ FAQ
Q1. Our global privacy e-learning runs once a year in English and everyone in Korea completes it. Is that compliant?
It is not automatically non-compliant, and it is not automatically sufficient. The Act requires training "regularly" without setting a number, and the safety-measures Public Notice requires it to be differentiated by business scale, volume of personal information and the nature of the work. A single module delivered identically to everyone fails the differentiation requirement rather than the frequency requirement. The practical fix is usually to keep the global module as a baseline and add a short Korean-specific component for the people who actually handle personal information covering resident registration numbers, Korean retention periods, and how a data subject request or an incident is escalated. Check separately what frequency your own internal management plan commits to, because that is the number you will be measured against.
Q2. The shared service centre has its own privacy training and ISO certification. Do we still have to train them?
Yes, in the sense that the obligation is yours. Article 26(4) requires the entrusting party to educate the trustee and to supervise it, including checking how it is handling the personal information. You may accept the trustee's own training as the delivery mechanism that is a recognised approach but you have to know what it covered, who completed it, and whether it addressed the Korean-specific content, and you have to be able to show the supervision check you performed. A certificate is evidence that the SSC has a management system. It is not evidence that you supervised it.
Q3. Our SSC selected a regional payroll vendor for the whole region, including Korea. Is that a problem?
It needs your consent, and it needs to be documented. Article 26(6), effective since 15 September 2023, requires the entrusting party's consent before the trustee sub-entrusts the work. This differs from GDPR Article 28, which allows a processor to engage sub-processors under a general written authorisation with a right to object so a European group's standard clause will often not meet the Korean requirement. Two things to put in place: consent for the arrangements already running, and the Korean entity as a named approver in the SSC's vendor-onboarding process going forward. Remember also that the sub-trustee has to appear in your disclosure of entrusted processing.
Q4. Korea recognised the EU in September 2025. Does that cover our transfers?
Only to the EU and EEA. The recognition of 16 September 2025 under Article 28-8(1)5 covers the 27 EU member states and Norway, Liechtenstein and Iceland, and it means personal information can be transferred there without separate consent to the overseas transfer. It does not extend to a shared service centre or service desk elsewhere in Asia, and it expressly does not cover resident registration numbers or personal credit information. For an offshore SSC, the route that usually works is Article 28-8(1)3 entrustment or storage necessary to perform the contract with the data subject, with the prescribed items disclosed in your privacy policy or notified directly. Note that consent to the collection and use of the data is a separate question and is still required on its own terms.
Q5. Can our group Data Protection Officer act as the Korean Chief Privacy Officer?
No. The Korean controller designates its own CPO, and the role carries statutory functions under Korean law including establishing and implementing the privacy training plan, and reviewing implementation of the internal management plan at least once a year. Where the entity falls within the specialist CPO regime effective 15 March 2024 broadly, annual revenue of KRW 150 billion or more together with processing of one million or more people's personal information, or sensitive or unique identifying information of 50,000 or more people the appointee must also meet an experience requirement of four years across privacy, information security and IT, with at least two years in privacy. The group DPO can support the role; the designation has to be local. Separately, if the foreign parent is itself a controller of Korean personal information, check the domestic representative rules, which changed on 2 October 2025 and change again on 11 September 2026.
👉 Next step
Take the scenario apart for your own entity this quarter. Four documents, none of them long.
A data flow map for Korean employee data, naming every entity that touches it the SSC, the service desk, the HRIS host, the payroll vendor, the EAP provider with each one classified as controller, trustee or sub-trustee, and the transfer ground identified for each border it crosses.
An entrustment file
containing, for each trustee, a document that covers the seven mandatory items; evidence of consent to any sub-entrustment already in place; and the disclosure of entrusted processing and sub-processing as it appears in your privacy policy and employee privacy notice.
A training plan that differentiates.
Baseline for everyone, Korean-specific content for Korean personal information handlers, and Korea-specific content in working English for offshore SSC agents handling Korean records. Set a frequency, write it into the internal management plan, and then meet it.
A supervision record.
The Article 26(4) check you performed on each trustee, when, by what method, and what it found held in the Korean entity's own files, not only in a group system.
Then look at the calendar. The amended Act takes effect on 11 September 2026, and the documentation above is what a reduction for demonstrated protection measures would rest on. Have the entrustment documents and the transfer analysis reviewed by Korean counsel before then, particularly where resident registration numbers reach an offshore centre.
If your organization is centralizing HR into a regional shared service model and needs employee support that works in Korean, sits inside the Korean entity's compliance perimeter rather than outside it, and gives managers somewhere to take a concern, contact Nudge EAP to discuss an implementation model suited to your Korean workforce.
NOTE: This article is intended for general informational purposes only. Specific legal, medical, clinical, or employment-related matters may require review by an appropriately qualified professional. The scenario described is a composite and is not based on any particular organization. Administrative fine amounts under Article 75 of the Personal Information Protection Act are deliberately omitted because they could not be verified against the statutory text, and the amendments effective 11 September 2026 should be confirmed in their final form. Entrustment documentation, sub-entrustment consent and overseas transfer grounds should be confirmed with qualified Korean counsel before being relied on.
📚 Sources
- 개인정보 보호법 제26조(업무위탁에 따른 개인정보의 처리 제한) — 제1항 문서에 의한 위탁, 제2항 위탁업무 내용·수탁자 공개(2023년 개정으로 재수탁자 포함), 제4항 수탁자 교육 및 처리 현황 점검 등 감독, 제6항 재위탁 시 위탁자 동의(2023. 9. 15. 시행), 제7항 수탁자를 소속 직원으로 간주(손해배상), 강은성 「개인정보 처리 위탁에서 지켜야 할 것들」, CIO Korea — https://www.cio.com/article/3523308/
- 개인정보 처리 위·수탁 실무 — 위·수탁 계약서 필수 기재 7개 항목(법 제26조제1항 2개 + 시행령 제28조제1항 5개), 수탁자 교육(계획 수립 → 이행 → 결과 보고)과 점검(계획 수립 → 이행 → 결과 보고), 위탁 사실 개인정보처리방침 공개, 서울특별시교육청 개인정보보호 자료 — https://www.sen.go.kr/resources/www/data/infoprotect_3_03.pdf
- 개인정보 처리 위탁 시 위·수탁 계약서 필수 기재사항 7가지 — 캐치시큐 — https://www.catchsecu.com/archives/10756
- 개인정보 처리 위탁 책임과 관리·감독 — 재위탁 사전 동의, 수탁자 관리·감독 범위, 법무법인 스타트 — https://www.startlawfirm.com/blog/개인정보-처리-위탁-책임-관리감독/
- 개인정보보호 위한 수탁자 관리, 어떻게 하시나요? — 수탁자 점검 방법(자료제출 요구·현장방문·원격점검), 보안뉴스 — https://www.boannews.com/news/articleView.html?idxno=63793
- 개인정보 보호법 제28조(개인정보취급자에 대한 감독) — 제1항 임직원·파견근로자·시간제근로자 등 지휘·감독을 받아 개인정보를 처리하는 자에 대한 관리·감독, 제2항 정기적으로 필요한 교육 실시(주기 수치 없음), 아이듀어 — https://www.idure.com/new3/sub_5/5_1.php?mode=view&number=1176&b_name=information1&page=1
- South Korea Personal Information Protection Act (PIPA) — Article 28(1)·(2) 영문("must regularly provide personal information handlers with necessary educational programs"), Securiti — https://securiti.ai/south-korea-personal-information-protection-act/
- 개인정보보호 교육, 법정 횟수·시간 기준 — "교육 횟수나 시간 기준은 법에 명시되어 있지 않다", 행정 지침상 일반 사업장 연 1회 이상 권고, ZUZU — https://start.zuzu.network/resource/guide/personal-information-protection-training/
- 개인정보의 안전성 확보조치 기준(개인정보보호위원회 고시 제2023-6호, 2023. 9. 22. 발령·시행) — 제4조제1항 내부 관리계획 필수 포함사항(제4호 개인정보취급자 관리·감독 및 교육, 제14호 수탁자 관리·감독), 제4조제2항 교육("교육목적 및 대상, 교육 내용, 교육 일정 및 방법"을 정하여 사업규모·개인정보 보유 수·업무성격에 따라 차등화하여 정기적으로 실시), 제4조제4항 개인정보 보호책임자의 내부 관리계획 이행 실태 연 1회 이상 점검·관리, 제8조 접속기록 1년 이상(5만명 이상·고유식별정보·민감정보·기간통신사업자는 2년 이상), 고시 원문 PDF — https://hs.ac.kr/bbs/kor/2157/54638/download.do
- 개인정보의 안전성 확보조치 기준 안내서(2024. 10., 발간등록번호 11-1790365-000038-14) — 제4조 해설, 교육 "정기적으로 실시", 접속기록 보관기간, 개인정보보호위원회 — https://business.cch.com/CybersecurityPrivacy/KoreanGuidetotheStandardsforEnsuringtheSafetyofPersonalInformationOctober2024.pdf
- 개인정보의 안전성 확보조치 기준 개정(2025. 10. 31. 시행) — 인터넷망 차단조치 완화, 접속기록 월 1회 이상 점검 의무 폐지, 내부관리계획 항목 추가, 김·장 법률사무소 — https://www.kimchang.com/ko/insights/detail.kc?sch_section=4&idx=33291
- 개인정보의 안전성 확보조치 기준 개정 해설 — 법률신문 — https://www.lawtimes.co.kr/news/articleView.html?idxno=213530
- 개인정보 보호법 제28조의8(개인정보의 국외 이전) 제1항 각 호 조문 인용 — 제1호 별도 동의, 제2호 법률·조약, 제3호 계약 체결·이행을 위한 처리위탁·보관(가목 개인정보처리방침 공개 / 나목 전자우편 등 통지), 제4호 인증, 제5호 적정성 인정, 로톡 — https://www.lawtalk.co.kr/posts/86941
- 개인정보 국외이전 규정 개정 해설 — 제28조의8 신설 경로(인증·적정성 인정), 제28조의9 국외이전 중지명령 3요건, 시행일 2023. 9. 15., 법무법인(유한) 화우 — https://www.hwawoo.com/kor/insights/newsletter/13126
- 개인정보 국외이전 시 고지사항 — 제28조의8제2항 각 호(이전되는 개인정보 항목 / 이전되는 국가·시기·방법 / 이전받는 자의 명칭 및 연락처 / 이용목적 및 보유·이용 기간 / 거부 방법·절차 및 거부의 효과), 캐치시큐 — https://www.catchsecu.com/archives/12008
- 개인정보보호법 개정에 따른 국외이전 제도 정비 — 제28조의8 각 호 및 제28조의9 중지명령, 톰슨로이터/로앤비 리포트(2023. 6.) — https://www.thomsonreuters.co.kr/content/dam/ewp-m/documents/korea/ko/pdf/other/lawnb-report-jun-2023.pdf
- Data Protection Laws of the World — South Korea, Transfer — 제28조의8 각 호 영문 정리, 거부 방법·절차 고지, DLA Piper — https://www.dlapiperdataprotection.com/?t=transfer&c=KR
- 개인정보위, EU·EEA 30개국 개인정보 보호수준 동등성 인정(2025. 9. 16.) — 제28조의8제1항제5호 최초 적용, EU 27개국 + 노르웨이·리히텐슈타인·아이슬란드, 주민등록번호·개인신용정보는 적용 제외, 법률신문 — https://www.lawtimes.co.kr/news/articleView.html?idxno=211803
- 개인정보 보호법 제64조의2 과징금 — 전체 매출액의 100분의 3 이하, 위반행위와 관련 없는 매출액 제외의 입증책임 전환, 2023. 9. 15. 시행, 김·장 법률사무소 — https://www.kimchang.com/ko/insights/detail.kc?sch_section=4&idx=21101
- 2026년 개정 개인정보 보호법(법률 제21445호, 2026. 3. 10. 공포 / 2026. 9. 11. 시행) — 제64조의2제2항 가중 시 과징금 상한 전체 매출액의 100분의 10(재위반 / 고의·중과실에 의한 대규모 피해 / 시정조치 불이행), 보호체계 운영 수준에 따른 40% 범위 감경, 제31조제3항 및 제75조제2항 개인정보 보호책임자 관련 과태료 신설, 국내대리인 업무 범위 확대 — https://datalaw.kr/guides/pipa-2026-amendment/
- 개인정보위, 과징금 상한 상향 등 개정법 시행령 입법예고(2026. 6. 1.) — ZDNet Korea — https://zdnet.co.kr/view/?no=20260601171735
- 국내대리인 지정제도 개정(2025. 10. 2. 시행) — 국내 법인이 있는 경우 그 법인 중에서 지정, 기존 지정자 시정기한 2026. 4. 2., 김·장 법률사무소 — https://www.kimchang.com/ko/insights/detail.kc?sch_section=4&idx=33813
- 국내대리인 제도 개정 안내 — 법무법인(유한) 신&김 — https://www.shinkim.com/kor/media/newsletter/1003
- 개인정보 보호책임자(CPO) 제도 — 법 제31조제3항제5호 개인정보 보호 교육 계획의 수립 및 시행, 제31조 독립성 보장·불이익 금지, 2024. 3. 15. 시행, 강은성 「개인정보보호책임자(CPO)의 역할」, CIO Korea — https://www.cio.com/article/3523307/
- 개정 개인정보 보호법 시행령 시행(2024. 3. 15.) — CPO 자격요건 및 독립성 보장, 법무법인(유한) 신&김 — https://www.shinkim.com/kor/media/newsletter/2643
- 전문 CPO 제도 — 대상 기준(매출액 1,500억원 이상 + 100만명 이상 개인정보 또는 5만명 이상 민감정보·고유식별정보 처리 등), 자격요건(개인정보보호·정보보호·정보기술 경력 합산 4년 이상, 그중 개인정보보호 경력 2년 이상), 근거 법 제31조제9항·시행령 제32조제4항 별표1, 법무법인(유한) 화우 뉴스레터 — https://www.hwawoo.com/newsletter/2024_04_18/240418_k_t.pdf
- 개인정보보호 전문성 갖춘 CPO 지정 요건 — 디지털데일리 — https://m.ddaily.co.kr/page/view/2024021611043740338
- 개인정보 처리 가이드라인 통합 정비 — 위탁(수탁) 관련 가이드라인의 통합본 흡수, 2차·3차 수탁 관계 및 클라우드·HR 시스템 서비스 제공자 의무 포함, 법무법인(유한) 신&김 — https://www.shinkim.com/kor/media/newsletter/2680
- World Health Organization, Guidelines on Mental Health at Work (2022) — https://www.who.int/publications/i/item/9789240053052
- World Health Organization, Mental health at work fact sheet — https://www.who.int/news-room/fact-sheets/detail/mental-health-at-work
- ISO 45003:2021, Occupational health and safety management — Psychological health and safety at work — https://www.iso.org/standard/64283.html
- Employee Assistance Professionals Association, Definition and Core Technology of Employee Assistance Programs — https://eapassn.org/page/definitionandcoretechnology
- Personal Information Protection Commission, Laws and Regulations (English) — https://www.pipc.go.kr/eng/user/lgp/law/lawsRegulations.do
Comments5