EAP Outsourcing Contract Personal Information Clause Checklist
EAP Outsourcing Contract Personal Information Clause Checklist
HR, Purchasing, and Legal Practice Standards for Separating Consultation Application Information, Consultation Records, and Corporate Reporting Data at the Contract Stage
๐ Why Privacy Clauses Are Particularly Important in EAP Contracts
Unlike general welfare services, the application process for EAP may generate basic information such as contact details, affiliation, and usage dates, along with information regarding psychological and health status. The fact that the company bears the costs does not mean that individual counseling topics or statements can be obtained. Article 83 of the Framework Act on Workers' Welfare stipulates that anonymity must be guaranteed to prevent the infringement of workers' secrets during the operation of employee support programs, and Article 23 of the Personal Information Protection Act restricts the processing of sensitive information, such as health data.
Therefore, the key to the contract is not a declaration that "the trustee will store the information securely," but rather to craft verifiable statements detailing what information the company and the EAP agency process, why, and at what point they delete it. It must be possible to make judgments based on the same standards even if the actual operational manager changes.
๐ Information flow to map before signing a contract
| step | Possible information | Main processing entity | Company Provided Principles |
|---|---|---|---|
| User Guide | Scope of eligible participants, company name, certification criteria | Company/EAP Agency | Minimum scope required for service usage |
| Request consultation | Name or identifier, contact information, preferred time, consultation type | EAP agencies | In principle, information regarding individual applications is not provided to the company. |
| Consultation in progress | Presenting problem, assessment/counseling records, counselor notes | Counseling agencies and counselors | Personal identification counseling content is excluded from operational reports. |
| Cost settlement | Number of uses, session, billed amount | EAP agencies/companies | Remove unnecessary consultation details for settlement |
| Operational report | Usage count by period, categorized topics, satisfaction | EAP agencies | Aggregated information reviewing the risk of minority group re-identification |
| Crisis Response | Minimum information regarding risks to life and body | EAP Agency/Designated Personnel | The minimum necessary scope in accordance with laws, prior notice, and internal procedures |
Do not combine 'Consultation Records' and 'Service Operation Records' into a single category. This is because the access rights, retention periods, and destruction methods for reception, reservation, and settlement data may differ from those of the professional records written by counselors.
๐งพ 12 Contract Clauses You Must Check
| number | clauses | Key points to write in the contract | Review Questions |
|---|---|---|---|
| 1 | Purpose and Scope of Entrustment | List specific tasks such as consultation reception, provision, settlement, and statistics. | Isn't the scope excessively broad, like 'overall EAP operations'? |
| 2 | Processing items | Step-by-step mandatory and optional items and whether sensitive information is included | Do they unnecessarily request employee IDs or resident registration numbers for consultations? |
| 3 | Basis for processing and notification | Consent or Legal Basis, Notification Responsibility and Forms | Is consent for sensitive information distinguished from other consents? |
| 4 | Prohibition of use for purposes other than intended | Unauthorized use for marketing, model training, product development, etc. is prohibited. | Is secondary use not permitted under the broad phrase "service improvement"? |
| 5 | Access permissions | Minimum privileges by role, account revocation, log checks | Are the permissions of counselors, operators, and developers separated? |
| 6 | Subcontracting | Prior approval or notice, the same obligation as the list of trustees | Have you also identified the reservation platform, cloud, and call center? |
| 7 | Overseas processing | Whether transferred or stored abroad, and the country, business operator, and protective measures | Did you check whether overseas SaaS would be used before signing the contract? |
| 8 | Storage and destruction | Period by information type, return/deletion upon contract termination, proof of destruction | Are backup copies and logs also included in the scope of destruction? |
| 9 | Safety measures | Encryption, transmission security, access logs, vulnerability management, education | Are there any verifiable criteria other than 'compliance with relevant laws'? |
| 10 | Incident Response | Notification deadline, initial reporting items, investigation cooperation and prevention of recurrence | Have night and holiday contact networks and the person responsible for initial reporting been designated? |
| 11 | Supervision and inspection | Submission of data, regular inspections, requests for improvement, and verification of implementation | Can the trustee perform the legal duty of supervision? |
| 12 | Responsibility/Termination | Liability for breach, damages, data transfer/disposal, account termination | Is access rights revoked immediately after the contract ends? |
๐ Reports a company can accept and reports it should not accept
Principle 1: Only aggregated information necessary for operational purposes
The company may receive data necessary for contract management and system improvement, such as usage volume, usage status by channel, satisfaction levels, and the proportion of major issues. However, if the number of users in a specific department is very low, individuals may be estimated based solely on statistics combining department, gender, and job title. A minimum aggregation unit must be specified in the contract, and data below this threshold should be combined with the parent organization or marked as "insufficient sample."
Principle 2: Exceptions requiring personal verification are handled through a separate procedure.
Exceptional situations, such as imminent danger to life or body, should not be mixed with general monthly reports. Crisis assessment criteria, details to be notified to employees in advance, internal contacts, minimum information to be conveyed, and records and access rights after delivery must be managed through a separate procedure document. Broad clauses implying that all high-risk appeals are immediately subject to company notification may undermine trust in confidentiality.
๐ค How to divide roles between a company and an EAP agency
| work | company | EAP agencies |
|---|---|---|
| Information for Eligible Participants | Notice regarding welfare eligibility and channels, and guidelines on prohibiting disadvantages | Explanation of processing policy, confidentiality, and exceptions upon application |
| Consultation Information | Individual counseling details are not required | Access to counseling records is restricted to personnel for counseling purposes. |
| Operational report | Define the purpose and necessary indicators in advance | Review re-identification risk and aggregate/de-identify reporting |
| Data subject request | Information on reception counters and liability | Cooperate with requests for access, correction, and deletion within the contractual timeframe. |
| Incident Response | Decision on legal filing and notification, and external response | Immediate notification, scope verification, preservation/blocking, investigation cooperation |
๐ 5 Steps to Reviewing Contract Clause
1. We interview the actual operational process.
Do not just look at the draft contract; verify who uses which system throughout the entire process, from receipt and assignment to consultation, settlement, reporting, and closure. If the contract wording differs from the actual processing flow, inspections and incident response will not function.
2. Classify information items into required, optional, and unnecessary.
We ask whether an employee ID is mandatory for company verification and whether a department name is required for consultation assignment. We review whether items collected for convenience can be reduced using alternative identifiers or one-time authentication methods.
3. Attach the report sample to the contract annex.
If you only write 'Provide statistics,' the scope of operations can easily become broad. By specifying allowed items, minimum sample size, and criteria for hiding decimal values โโin monthly and quarterly report samples, you can maintain these standards even when the person in charge changes.
4. Check the sub-outsourcing/cloud list.
We verify whether the affiliate center to which the counselor belongs, the reservation solution, the SMS sender, the video consultation tool, and the cloud operator are involved in the actual processing of information. We also define the method of approval and notification for any changes made after the contract is signed.
5. Complete the termination test.
We check whether only the account is simply closed on the contract expiration date, whether operational data and backups are also deleted, and whether a deletion confirmation can be obtained. We distinguish between data to be transferred to another vendor and data to be destroyed.
๐ Examples of ready-to-use operational records
| Inspection day | Inspection targets | Verification materials | result | Improvement measures/deadlines |
|---|---|---|---|---|
| 2026-09-03 | Status of re-entrustment | List of sub-trustees, scope of work, storage location | Missing annex to the text messaging company contract | Reflection in Annex / September 10 |
| 2026-09-03 | Operational report | Previous month report sample | Small department figures can be exposed | Apply minimum aggregation criteria / Immediately |
| 2026-09-03 | Authority for retirees and transferees | Account list, login history | Recovery completed | Quarterly review |
Inspection results should not be limited to just 'appropriate/inappropriate'; supporting documents, the person in charge, the deadline, and the date of confirmation of implementation must also be recorded. Since the consignor must supervise the trustee's safe processing in accordance with Article 26 of the Personal Information Protection Act, the proof of operation is weakened if there are no actual inspection records, even if the contract includes inspection authority.
Example of a data list to include in a contract annex
In the data list, do not simply list item names; instead, link the collection time, mandatory status, purpose of use, job function accessing the data, storage location, retention period, and destruction method in a single row. For example, mobile phone numbers are accessible only to the receptionist and assigned counselor for the purpose of notifying consultation schedules, and are destroyed in accordance with the operating system and backup policy once the contractually defined period expires. Department names should only be collected when absolutely necessary for aggregate reporting, and can be replaced with workplace-unit codes if there is a high risk of re-identifying a small number of departments.
Consultation topics are also aggregated into broad categories agreed upon in advance, rather than submitting the original free-form text to the company. Since overly detailed categories could lead to the estimation of individuals over a short period of time, the monthly sample size, items permitted for cross-analysis, and criteria for hiding values โโare also specified. To prevent report writers from arbitrarily including detailed examples, provisions may be established to prohibit the citation of specific cases or to set separate approval procedures.
Examples of due diligence questions for a new trustee
- What is the system used and the storage location from the counseling application to the conclusion?
- How do the screens and permissions differ for counselors, operators, developers, and client representatives?
- Who handles the revocation of authority upon retirement, contract termination, or role change, and when?
- Do the same security and confidentiality obligations apply to affiliated counseling centers and individual counselors?
- Does the text, email, video consultation, and recording function retain separate personal information?
- On which channel and within how many hours does the person who first becomes aware of the suspected leak report it?
- How is the destruction of the operational DB, file storage, backups, and test data proven after the termination of the contract?
Change management must also be included in the contract.
After the service is introduced, the flow of information changes if app features, authentication methods, cloud services, partner consulting agencies, or report items are modified. The contract stipulates that for changes that could increase riskโsuch as new data collection, changes to subcontractors, overseas processing, the introduction of AI features, or consultation recordingโthe company must be notified and reviewed before implementation. Differentiating between minor changes and those requiring prior approval can also reduce the inefficiency of processing all updates through the same procedure.
At quarterly operational meetings, do not rely solely on usage rates; instead, verify the results of access control checks, changes in re-entrustment, requests from data subjects, security incidents or misdeliveries, destruction records, and the implementation rate of corrective measures. Even reports stating that no incidents occurred should not be limited to verbal confirmation; recording the inspection date and the person in charge serves as objective evaluation data for the next contract renewal.
โ ๏ธ Common Contract Review Mistakes
- Summarize the status of the company and the EAP agency in one sentence: You must distinguish the roles and responsibilities for each processing activity.
- Include consent to provide consultation details in employment documents all at once: We need to re-examine whether free choice and separate notification are possible.
- Report items to be discussed later: Detailed statistics with potential for individual estimation may be added as a matter of practice.
- List the retention period as 'in accordance with relevant laws' only: You must determine the actual period and starting point for each data type.
- Understanding subcontracting solely as an IT company: Local counseling centers, freelance counselors, and reservation, text, and video tools are also subject to verification.
- Crisis response defined as 'notify the company if necessary': There is a risk of over-sharing due to the lack of judgment criteria and minimum provision scope.
โ Final Checklist Before Signing the Contract
- The purpose and scope of the outsourcing align with the actual operational flow.
- Basic personal information and sensitive information related to health and psychology were distinguished.
- We determined the aggregate indicators and minimum sample standards provided to the company.
- Individual usage status and consultation details were excluded from the general report.
- We verified the subcontractor, overseas processing, and cloud location.
- I checked access rights, encryption, access logs, and account recovery criteria.
- The timing of accident notification, initial reporting items, and emergency contact network were determined.
- The retention period, destruction upon termination, deletion of backup copies, and proof methods were determined.
- A person responsible for data subject requests and crisis response was appointed.
- We established a schedule for regular inspections and a method to verify the implementation of improvement measures.
The fact that even one item in the check results is marked as 'Unconfirmed' does not mean that the contract will be terminated immediately. We determine the risk level of the unconfirmed items and divide the timelines into pre-contract supplementation, pre-service commencement supplementation, and supplementation within a set schedule after commencement. However, it is safer to clarify items that directly affect user rights, such as the scope of consultation content provision to the company, the basis for processing sensitive information, the sub-contracting structure, and accident notification and destruction, before the service commences.
When renewing, do not simply extend the original contract as is; instead, re-read the clauses based on actual operations during the past period. Check for items collected in larger quantities than initially anticipated, unused reporting indicators, newly added partners, repetitive inquiries, misdeliveries, and data with delayed destruction. If the wording in the User Guide, Privacy Policy, Consultation Request Screen, or Contract Annex differs, standardize the terminology and scope, and reflect the changes before the next announcement.
It is recommended to distinguish between the working-level manager and the decision-maker in the final approved version. HR verifies the purpose of the system and user guidelines; the Privacy Officer verifies the basis for processing and protective measures; Purchasing verifies subcontracting, liability, and termination conditions; Legal verifies clause consistency; and Information Security verifies system controls. Since the review is not automatically completed simply because one department has signed it, please record the verifiers and approval dates for each item in the attached checklist.
โ Frequently Asked Questions
Q1. Is it okay to only collect the number of uses per employee?
The number of uses can also reveal a specific individual's service usage. Even for settlement purposes, first review whether the company must receive personally identifiable information, and if possible, design the system using anonymous identifiers and aggregation methods.
Q2. Must the retention period for consultation records be the same as the company regulations?
It cannot be definitively concluded that they are necessarily the same. Periods should be determined by distinguishing the nature of the data, the purpose of processing, the legal basis, and professional record standards, and the structure in which the company retains original consultation records must be carefully reviewed.
Q3. If the contractor holds ISO certification, can the inspection be omitted?
Certification is for reference only and does not automatically replace the trustee's supervision. The actual scope of EAP work, access rights, sub-delegation, reports, and proof of destruction must be verified through the contract and periodic inspections.
Q4. Can I receive a list of individual promotion targets when the usage rate is low?
Selecting individuals based on EAP usage may lead to issues regarding confidentiality trust and personal information privacy. Improve guidance at the organizational or job/work environment level, and prioritize methods that enhance accessibility without requiring individual usage data.
๐ Useful Practical Materials to Check Out Together
- How to divide the roles of HR, healthcare, purchasing, and legal in the EAP implementation task force
- Comprehensive Guide to EAP Implementation and Operation
- Personal Information and Retirement Pension Education Guide
- Criteria for Sharing Job Stress Survey Results
If you need an implementation design tailored to your organization's size and counseling operational structure Inquiry regarding Nudge EAP implementation You can receive counseling at.
๐ Supporting Documents and Important Notes
- National Law Information Center, Article 26 (Outsourcing of Duties) of the Personal Information Protection Act
- National Law Information Center, Article 23 (Sensitive Information) of the Personal Information Protection Act
- National Law Information Center, Article 83 of the Framework Act on Labor Welfare (Worker Support Program)
Verification Date: September 3, 2026. This article provides information for general practical review and does not constitute legal advice regarding individual contracts. Before entering into an actual contract, please review it with the Chief Privacy Officer and Legal Officer based on the latest laws, the company's privacy policy, and the trustee's actual systems and processing flows.
EAP entrustment contract Privacy Protection Confidentiality of consultation HR Checklist