Personal Information Protection Checklist for External Transmission of Retirement Pension Training Participants
When transmitting the list of retirement pension training participants externally
Privacy Protection Checklist
When outsourcing retirement pension training, the participant list must contain only the minimum information necessary for the operation. The key is to first distinguish whether the transmission is for the outsourcing of training duties or for third-party provision used by the external organization for its own purposes, and to transmit only after verifying the recipients, items, retention period, and deletion method.
First, check 'why it is needed, who uses it, and when it is deleted.'
📌 Key points to check first
Employers who have established a Defined Benefit (DB) or Defined Contribution (DC) retirement pension plan must provide education to participants at least once a year. Even if this education is entrusted to a retirement pension provider or a specialized agency, this does not mean that the company may provide any list of employees it possesses. You must select only the people and topics necessary for the actual training.
The first thing to verify is the role of the external organization. If they perform only training guidance, course registration management, and responding to completion results at the company's direction, review whether this constitutes the outsourcing of personal information processing tasks. Conversely, if the external organization uses the list for its own marketing, product solicitation, or separate customer management purposes, do not group it under the same training duties; instead, verify whether the information was provided to a third party and the basis for separate processing.
Therefore, the practical sequence is not 'creating the file first,' but rather ① determining the training target ② verifying the role of external organizations ③ determining necessary items ④ verifying the contract and guidance ⑤ secure transmission ⑥ verifying the retrieval and deletion of results.
🧭 Step 1: Distinguishing between outsourcing and third-party provision
Even if the list is sent to the same retirement pension provider, the judgment may differ depending on the purpose of use. It is important not to mix the scope of conducting training on behalf of others with the scope of use for financial product guidance and sales under a single file and consent. Check who actually determines the purpose and processing method rather than the title of the contract.
| Verification status | Direction of review | HR Checklist |
|---|---|---|
| Performing only training guidance and course management for designated candidates | Review of whether to outsource personal information processing tasks | Conditions for purpose, scope, protective measures, re-entrustment, and supervision of entrustment |
| The organization uses the list for its own product information or sales. | Review of provision to third parties or separate collection and use | Legal basis, necessity of notification and consent, impact of refusal |
| The institution directly educates using existing subscriber information | Confirmation of existing contract and scope of processing purpose | Need for the company to send a new list and whether there are duplicates |
| The education platform operator is using a text messaging company again. | Confirmation of subcontracting structure | Sub-trustee, Processing Item, Overseas Processing Status, Delete After Termination |
If you are unsure, do not proceed with file transfer first; instead, it is safer to verify the contract and actual processing flow with the Chief Privacy Officer or the in-house legal and privacy officer.
🗂️ Step 2: Determine only the minimum items necessary for training
The Personal Information Protection Act mandates the collection of only the minimum amount of personal information necessary for the intended purpose. Externally transmitted files must be reviewed from the same perspective. 'Information already existing within the company' is not the same as 'information required for the operation of external training.' Instead of copying the entire HR ledger, a separate file must be created for the trainees.
| item | Inclusion judgment | Verification points |
|---|---|---|
| Name or employee number | Prioritize a single criterion required for target identification | Check if it is necessary to distinguish between people with the same name. |
| Company email or business contact | Review only when the institution provides direct guidance. | Exclusion is possible if provided internally within the company. |
| Membership/Affiliation System (DB/DC) | Include when necessary for training assignment or material classification | Detailed job titles and evaluation grades are excluded. |
| Registration/Education Status | Check if it is necessary to distinguish between supplementary education and new subscribers. | Review whether the target identifier is sufficient instead of the exact date. |
| Resident Registration Number, Salary, Account Number, Accumulated Funds | In principle, excluded from the training subject file | Review whether it is directly related to verification of training completion |
If an external agency already possesses subscriber information, the company also checks whether it needs to resend the same list. Unnecessary duplicate transmissions can be reduced by first transmitting only the number of subjects per operator and securely comparing the subscriber list held by the agency with the company's reference date list.
📝 Step 3: Check the Agreement and Privacy Policy
If you entrust educational operations to the processing of personal information, verify that the documentation reflects necessary details such as the prohibition of processing for purposes other than the intended purpose, safety measures, restrictions on sub-entrustment, and management, supervision, and responsibility. It is more important to be able to identify the actual processing items and workflow than to have a single line stating "compliance with personal information protection" in the contract.
Items to look for in the contract
The Company also verifies whether the entrusted tasks and trustee information required to be disclosed in the Privacy Policy align with the current contract structure. In cases involving sub-entrustment, such as educational platforms, text messaging, and email sending, the Company does not stop at verifying only the initial contract counterparty.
🔐 Step 4: Apply protection measures before transferring files
While sending lists as Excel attachments is convenient, it is prone to misrecipients, redeliveries, and saving to personal devices. If possible, set recipient access permissions and expiration dates in a company-approved collaboration space or training management system, and use a method to verify who has downloaded the file.
| Before transmission | When transmitting | After transmission |
|---|---|---|
| Remove resignees, non-members, and duplicate rows | Reconfirm recipient address and contact person | Check availability for receiving and viewing |
| Delete unnecessary columns, hidden sheets, and memos | Use an approved secure link or encryption method | Immediately revoke authority upon incorrect reception |
| Minimize sensitive expressions in filenames | Information on Purpose, Re-delivery Prohibition, and Usage Period | Check for the existence of the original after receiving the completion results |
If a password has been set, do not rely on the practice of including the password in the same email body; instead, apply the separate delivery procedures established by the company. Do not send to the person in charge's personal email, private messenger, or public link, and if delivering to multiple retirement pension providers, separate the recipients by provider.
✉️ Step 5: Send a recipient notice along with it
If you send only the file, external personnel may misunderstand the scope of use and the timing of deletion. Please include the training name, target criteria date, purpose of use, permitted processing scope, result reply date, and the time of deletion or return in a short notice.
💬 Ready-to-use messaging
Please modify the dates and scope of processing to match your actual contract and training schedule.
🔄 Step 6: Manage corrections and retransmissions as a single 'latest version'
Files may be exchanged multiple times if the list changes due to hiring, resignation, leave of absence, return to work, enrollment in a retirement pension plan, or a change in the system. In such cases, if files are stacked with names like 'Final', 'Final 2', or 'Really Final', past subjects will continue to be exposed, making it difficult to verify which version was used for training.
Set a reference date and version number, and terminate the previous sharing link or replace the existing file when uploading a new list. It is practical to separately store a change history indicating only deleted individuals, newly added individuals, and those whose system types have changed, while showing external agencies only the latest status necessary for their work.
2026_RetirementPensionEducation_Eligible_ 기준일20260908_v1.xlsx
🧾 Step 7: Separating Completion Results and Deletion Confirmation
After the training is completed, the completion results are received to update the company's training records. We distinguish between data that the company needs to verify—such as the list of completers, reasons for non-completion, completion dates, and whether retraining is required—and the processing status of the original participant files remaining at external institutions.
A reply stating that "the training is finished" does not mean that the list has been deleted. We verify how operational accounts, responsible personnel PCs, downloaded files, backups, and data held by subcontractors are handled in accordance with the retention period and destruction method stipulated in the contract. If there are records that must be preserved under laws or the contract, we identify the basis, items, and periods, and manage other unnecessary materials to ensure they are destroyed without delay.
✅ Confirm termination items
| division | Confirmation details | check |
|---|---|---|
| Receive results | Check completers, non-completers, error targets, and reference dates | □ |
| Terminate permissions | Revoke access rights for external personnel and temporary accounts | □ |
| File processing | Confirmation of return or destruction of original, corrected, or downloaded files | □ |
| Confirmation of re-entrustment | Confirmation of processing of re-trustee holdings, such as sending text messages or emails | □ |
🚨 If it was sent to the wrong person, here's how to respond
If you discover a false message, first stop the shared link or lock the account, and confirm with the recipient whether they viewed, downloaded, or forwarded the message, as well as whether they deleted it. Do not simply send a 'request to delete email' and stop there; identify the items included, the target audience, the recipients, the time of access, and whether the message was actually viewed.
Next, in accordance with the internal personal information infringement response procedures, report to the Chief Privacy Officer and review whether a data breach occurred and the necessary follow-up measures. Separate from resolving the incident, fix the causes—such as autocomplete URLs, default sharing link permissions, hidden sheets within files, and recipient double-checking procedures—to prevent the same thing from happening again.
✅ Final Checklist Before Shipment
□ We reviewed whether the role of the external agency was outsourcing or providing to a third party.
□ The contract, personal information processing policy, and subcontracting structure are consistent with actual operations.
□ Deleted columns and hidden data that were not needed for educational operations.
□ Separated the recipients by business operator and re-verified the receiving addresses.
□ Set the company-approved secure transmission method and access expiration date.
The purpose, prohibition of redelivery, method of correction, and date of response were provided together.
After the training ended, a person in charge was appointed to verify the revocation of authority and its return or destruction.
🔗 Recommended articles to check out
❓ Frequently Asked Questions
Q1. Are all lists sent to retirement pension providers considered third-party provision?
Q2. May I send my personal mobile phone number for training information?
Q3. Is it safe to send a password-protected Excel file via email?
Q4. Do I need to delete all completion records from external institutions as well once the training is finished?
Q5. If I sent the list incorrectly and the other party says they didn't open it, is that the end of it?
You must connect the entire process—from participant selection and outsourcing to guidance, completion verification, and data organization—to reduce both repetitive transmissions and omissions.
👉 Go to Nudge EAP Implementation Consultation →📚 Source and Information
• National Law Information Center, Article 16 of the Personal Information Protection Act
• National Law Information Center, Article 26 of the Personal Information Protection Act
• National Law Information Center, Article 29 of the Personal Information Protection Act
• Ministry of Employment and Labor, Key Questions Regarding Specialized Education Institutions for Retirement Pension Subscribers