Personal Information Protection Checklist for External Transmission of Retirement Pension Training Participants

Personal Information · Retirement Pension

When transmitting the list of retirement pension training participants externally
Privacy Protection Checklist

When outsourcing retirement pension training, the participant list must contain only the minimum information necessary for the operation. The key is to first distinguish whether the transmission is for the outsourcing of training duties or for third-party provision used by the external organization for its own purposes, and to transmit only after verifying the recipients, items, retention period, and deletion method.

Before sending the list
First, check 'why it is needed, who uses it, and when it is deleted.'

📌 Key points to check first

Employers who have established a Defined Benefit (DB) or Defined Contribution (DC) retirement pension plan must provide education to participants at least once a year. Even if this education is entrusted to a retirement pension provider or a specialized agency, this does not mean that the company may provide any list of employees it possesses. You must select only the people and topics necessary for the actual training.

The first thing to verify is the role of the external organization. If they perform only training guidance, course registration management, and responding to completion results at the company's direction, review whether this constitutes the outsourcing of personal information processing tasks. Conversely, if the external organization uses the list for its own marketing, product solicitation, or separate customer management purposes, do not group it under the same training duties; instead, verify whether the information was provided to a third party and the basis for separate processing.

Therefore, the practical sequence is not 'creating the file first,' but rather ① determining the training target ② verifying the role of external organizations ③ determining necessary items ④ verifying the contract and guidance ⑤ secure transmission ⑥ verifying the retrieval and deletion of results.

🧭 Step 1: Distinguishing between outsourcing and third-party provision

Even if the list is sent to the same retirement pension provider, the judgment may differ depending on the purpose of use. It is important not to mix the scope of conducting training on behalf of others with the scope of use for financial product guidance and sales under a single file and consent. Check who actually determines the purpose and processing method rather than the title of the contract.

Verification status Direction of review HR Checklist
Performing only training guidance and course management for designated candidates Review of whether to outsource personal information processing tasks Conditions for purpose, scope, protective measures, re-entrustment, and supervision of entrustment
The organization uses the list for its own product information or sales. Review of provision to third parties or separate collection and use Legal basis, necessity of notification and consent, impact of refusal
The institution directly educates using existing subscriber information Confirmation of existing contract and scope of processing purpose Need for the company to send a new list and whether there are duplicates
The education platform operator is using a text messaging company again. Confirmation of subcontracting structure Sub-trustee, Processing Item, Overseas Processing Status, Delete After Termination

If you are unsure, do not proceed with file transfer first; instead, it is safer to verify the contract and actual processing flow with the Chief Privacy Officer or the in-house legal and privacy officer.

🗂️ Step 2: Determine only the minimum items necessary for training

The Personal Information Protection Act mandates the collection of only the minimum amount of personal information necessary for the intended purpose. Externally transmitted files must be reviewed from the same perspective. 'Information already existing within the company' is not the same as 'information required for the operation of external training.' Instead of copying the entire HR ledger, a separate file must be created for the trainees.

item Inclusion judgment Verification points
Name or employee number Prioritize a single criterion required for target identification Check if it is necessary to distinguish between people with the same name.
Company email or business contact Review only when the institution provides direct guidance. Exclusion is possible if provided internally within the company.
Membership/Affiliation System (DB/DC) Include when necessary for training assignment or material classification Detailed job titles and evaluation grades are excluded.
Registration/Education Status Check if it is necessary to distinguish between supplementary education and new subscribers. Review whether the target identifier is sufficient instead of the exact date.
Resident Registration Number, Salary, Account Number, Accumulated Funds In principle, excluded from the training subject file Review whether it is directly related to verification of training completion

If an external agency already possesses subscriber information, the company also checks whether it needs to resend the same list. Unnecessary duplicate transmissions can be reduced by first transmitting only the number of subjects per operator and securely comparing the subscriber list held by the agency with the company's reference date list.

📝 Step 3: Check the Agreement and Privacy Policy

If you entrust educational operations to the processing of personal information, verify that the documentation reflects necessary details such as the prohibition of processing for purposes other than the intended purpose, safety measures, restrictions on sub-entrustment, and management, supervision, and responsibility. It is more important to be able to identify the actual processing items and workflow than to have a single line stating "compliance with personal information protection" in the contract.

Items to look for in the contract

Purpose of use and items of the list of training participants · Responsible personnel with access · Storage location and period · Status of re-entrustment · Access control management · Protective measures during transmission and storage · Incident notification procedures · Return/destruction upon contract termination or achievement of purpose · Company inspection methods

The Company also verifies whether the entrusted tasks and trustee information required to be disclosed in the Privacy Policy align with the current contract structure. In cases involving sub-entrustment, such as educational platforms, text messaging, and email sending, the Company does not stop at verifying only the initial contract counterparty.

🔐 Step 4: Apply protection measures before transferring files

While sending lists as Excel attachments is convenient, it is prone to misrecipients, redeliveries, and saving to personal devices. If possible, set recipient access permissions and expiration dates in a company-approved collaboration space or training management system, and use a method to verify who has downloaded the file.

Before transmission When transmitting After transmission
Remove resignees, non-members, and duplicate rows Reconfirm recipient address and contact person Check availability for receiving and viewing
Delete unnecessary columns, hidden sheets, and memos Use an approved secure link or encryption method Immediately revoke authority upon incorrect reception
Minimize sensitive expressions in filenames Information on Purpose, Re-delivery Prohibition, and Usage Period Check for the existence of the original after receiving the completion results

If a password has been set, do not rely on the practice of including the password in the same email body; instead, apply the separate delivery procedures established by the company. Do not send to the person in charge's personal email, private messenger, or public link, and if delivering to multiple retirement pension providers, separate the recipients by provider.

✉️ Step 5: Send a recipient notice along with it

If you send only the file, external personnel may misunderstand the scope of use and the timing of deletion. Please include the training name, target criteria date, purpose of use, permitted processing scope, result reply date, and the time of deletion or return in a short notice.

💬 Ready-to-use messaging

The attached materials are provided for the purpose of assigning participants and verifying completion of the 2026 retirement pension subscriber training. Please use the list only for the operation of the training and for responding to results; do not use it for other product announcements or separate promotional purposes, nor forward it to unauthorized personnel. Please verify any training assignment errors by September 18. After the training concludes, please return or destroy the list in accordance with the procedures stipulated in the contract and report the processing results. If corrections to the participants are necessary, please do not keep the existing files separately; instead, please check the latest files via the designated secure channel.

Please modify the dates and scope of processing to match your actual contract and training schedule.

🔄 Step 6: Manage corrections and retransmissions as a single 'latest version'

Files may be exchanged multiple times if the list changes due to hiring, resignation, leave of absence, return to work, enrollment in a retirement pension plan, or a change in the system. In such cases, if files are stacked with names like 'Final', 'Final 2', or 'Really Final', past subjects will continue to be exposed, making it difficult to verify which version was used for training.

Set a reference date and version number, and terminate the previous sharing link or replace the existing file when uploading a new list. It is practical to separately store a change history indicating only deleted individuals, newly added individuals, and those whose system types have changed, while showing external agencies only the latest status necessary for their work.

Recommended filename examples
2026_RetirementPensionEducation_Eligible_ 기준일20260908_v1.xlsx

🧾 Step 7: Separating Completion Results and Deletion Confirmation

After the training is completed, the completion results are received to update the company's training records. We distinguish between data that the company needs to verify—such as the list of completers, reasons for non-completion, completion dates, and whether retraining is required—and the processing status of the original participant files remaining at external institutions.

A reply stating that "the training is finished" does not mean that the list has been deleted. We verify how operational accounts, responsible personnel PCs, downloaded files, backups, and data held by subcontractors are handled in accordance with the retention period and destruction method stipulated in the contract. If there are records that must be preserved under laws or the contract, we identify the basis, items, and periods, and manage other unnecessary materials to ensure they are destroyed without delay.

✅ Confirm termination items

division Confirmation details check
Receive results Check completers, non-completers, error targets, and reference dates
Terminate permissions Revoke access rights for external personnel and temporary accounts
File processing Confirmation of return or destruction of original, corrected, or downloaded files
Confirmation of re-entrustment Confirmation of processing of re-trustee holdings, such as sending text messages or emails

🚨 If it was sent to the wrong person, here's how to respond

If you discover a false message, first stop the shared link or lock the account, and confirm with the recipient whether they viewed, downloaded, or forwarded the message, as well as whether they deleted it. Do not simply send a 'request to delete email' and stop there; identify the items included, the target audience, the recipients, the time of access, and whether the message was actually viewed.

Next, in accordance with the internal personal information infringement response procedures, report to the Chief Privacy Officer and review whether a data breach occurred and the necessary follow-up measures. Separate from resolving the incident, fix the causes—such as autocomplete URLs, default sharing link permissions, hidden sheets within files, and recipient double-checking procedures—to prevent the same thing from happening again.

✅ Final Checklist Before Shipment

The actual participants and cutoff date for this training have been finalized.
□ We reviewed whether the role of the external agency was outsourcing or providing to a third party.
□ The contract, personal information processing policy, and subcontracting structure are consistent with actual operations.
□ Deleted columns and hidden data that were not needed for educational operations.
□ Separated the recipients by business operator and re-verified the receiving addresses.
□ Set the company-approved secure transmission method and access expiration date.
The purpose, prohibition of redelivery, method of correction, and date of response were provided together.
After the training ended, a person in charge was appointed to verify the revocation of authority and its return or destruction.

❓ Frequently Asked Questions

Q1. Are all lists sent to retirement pension providers considered third-party provision?

It is difficult to make a uniform judgment based solely on the name of the organization. You must first verify the actual role and contractual structure to determine whether the list is processed within the scope of the educational duties entrusted by the company or if the organization also uses it for its own separate purposes.

Q2. May I send my personal mobile phone number for training information?

First, verify whether an external agency is required to send text notifications. If company email or internal announcements are sufficient, personal numbers may be excluded. If necessary, the basis for processing, the contract, the scope of recipients, and the timing of service termination must be reviewed together.

Q3. Is it safe to send a password-protected Excel file via email?

Setting a password alone is not sufficient. You must manage recipient addresses, minimum items, password delivery paths, storage after download, access termination, and handling false reception. If possible, prioritize reviewing secure shared spaces approved by the company.

Q4. Do I need to delete all completion records from external institutions as well once the training is finished?

You must distinguish between records that must be preserved in accordance with laws or contracts and original lists temporarily received for educational assignments. Verify the basis, items, and duration of retention, and manage unnecessary materials that have served their purpose by returning or destroying them in accordance with the methods specified in the contract.

Q5. If I sent the list incorrectly and the other party says they didn't open it, is that the end of it?

You must first block access rights and verify the actual possibility of viewing, downloading, or redistribution. Organize the included information, personnel, recipients, and exposure time, report it according to internal personal information incident response procedures, and review necessary measures.
Review education operations and personal information protection as a single flow.

You must connect the entire process—from participant selection and outsourcing to guidance, completion verification, and data organization—to reduce both repetitive transmissions and omissions.

👉 Go to Nudge EAP Implementation Consultation →
This content provides general information on retirement pension education operations and personal information protection. The relationship with external organizations regarding the processing of personal information, the basis for processing, disclosure, notification, and consent, retention periods, and the level of safety measures may vary depending on the actual contract structure, processing purpose, the latest laws, and the company's internal standards. Specific matters may require review by the Chief Privacy Officer, relevant authorities, or experts. Date of verification: September 8, 2026.
Comments5
  • Unknown User4
    외부 기관이 이미 퇴직연금 가입자 정보를 보유하고 있다면 회사가 같은 명단을 다시 보내지 않고 변경 대상자만 대조하는 방식도 가능할까요?
    Profile Image
    넛지EAP(관리자)
    Author
    안녕하세요, 넛지EAP 입니다☺️
    가능할 수 있으나, 외부 기관의 기존 정보 보유 목적·처리 근거와 회사의 제공 근거가 일치하는지 먼저 확인해야 합니다. 전체 명단 대신 사번 등 최소 식별값으로 변경 대상자만 대조하고, 위탁계약·접근권한·암호화·보관 및 파기 기준을 문서화한 뒤 개인정보보호 담당자나 노무·법률 전문가의 검토를 권합니다.
  • Unknown User3
    명단 정정 때 이전 파일의 권한을 종료하고 기준일과 버전번호를 관리하는 방식이 실무적으로 유용해 보입니다. 최종본이 여러 개 생기는 문제를 줄일 수 있을 것 같아요.
  • Unknown User2
    교육 대상자 파일에는 주민등록번호, 급여, 계좌번호처럼 교육 운영과 관계없는 정보를 제외하고 필요한 식별정보만 남기는 것이 중요하겠네요.
  • Unknown User1
    퇴직연금사업자에게 전달한다는 이유만으로 바로 보내지 않고 교육 위탁인지 별도 목적의 제3자 제공인지 먼저 구분해야 한다는 점이 도움이 됐습니다.