| Title | The PIPC Takes its First Step to Shift Toward an Ex-Ante Approach to Privacy Protection, Starting with the Public Sector | ||
|---|---|---|---|
| Department | Date | 2026.02.26 | |
| Attachment | press release The PIPC Takes its First Step to Shift Toward an Ex-Ante Approach to Privacy Protection, Starting with the Public Sector.pdf | ||
| Page URL | https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=3001 | ||
| Contents |
Press Release The PIPC Takes its First Step to Shift Toward an Ex-Ante Approach to Privacy Protection, Starting with the Public Sector - The PIPC will unlock the potential of an ex-ante approach to privacy protection by taking risk-based, outcome-linked and voluntary improvement principles - The PIPC aims at establishing a sustainable privacy protection framework by conducting status examinations, providing consulting and support services, sharing guidelines and best practices, and continuous monitoring
February 12, 2026 (This is an unofficial translation of a press release, originally prepared in Korean.)
1. Designation of More Intensive Management Systems in the Public Sector ● The amount of personal information held, the number of personal data processors, processing, and mapping of sensitive or uniquely identifiable information (pursuant to Article 30-2 of the Enforcement Decree of the Personal Information Protection Act) ● 382 systems in 57 entities (2024) → 387 systems in 58 entities (2026) 2. Status Examinations of Major Public-Sector Systems ● Status examinations focusing on key vulnerabilities identified in recent massive data breaches ● Encourage effective improvements by mandating the submission of improvement plans and taking an outcome-linked approach
The Personal Information Protection Commission (PIPC) will laser-focus on taking an ex-ante approach to privacy protection, starting with the public sector that processes personal information or people, such as resident registration numbers (RRNs). To this end, the Commission will establish three key principles to pursue its prevention-oriented mandates as follows:
i) Risk-based; ii) Evidence-based review; and iii) Voluntary improvement by outcome-linked incentives.
The measures taken by the PIPC are designed to address the higher risk of data breaches and leaks, as the processing of vast amounts of personal information has become commonplace due to the proliferation of AI and cloud systems and the shift toward the platform economy.
As for public institutions, they process vast amounts of personal information in accordance with relevant laws and regulations, regardless of whether they obtain consent from data subjects. In this sense, such processing carries higher risks, but ex-post sanctions, such as imposing administrative fines for violations, have not been effective. Against this backdrop, the PIPC decided to prioritize conducting status examinations and establishing a safe management system in the public sector.
Status of Data Breaches in the Public Sector as of 2025 ▪ Breach reports: 23 cases (2022) → 41 cases (2023) → 104 cases (2024) → 128 cases (2025) ▪ Causes: Human errors (64%), hacks (32%) ▪ Violation types: Safeguards (64%), limitations on the collection of RRNs (8%)
1. Designation of More Intensive Management Systems in the Public Sector
The pool of intensive management systems in the public sector has been expanded according to the following criteria, and the list of intensive management systems is available on the PIPC’s website:
i) Public institutions that hold personal information of more than 1 million data subjects; ii) More than 200 personal data handlers; iii) Project budgets worth KRW 1 million; iv) Processing data in mapping with RRNs; and Processing sensitive data
First, the PIPC newly designated eight systems that process vast amounts of personal information as intensive management systems in the public sector, including the Korea Red Cross’s Blood Information Management System, and excluded the Korea Disease Control and Prevention Agency (KDCA)’s Epidemiological Investigation Support System, which was temporarily used during the COVID-19 pandemic. Furthermore, the three systems already designated involving the Worknet have been integrated into Work24 (under the Korea Employment Information Service), so the PIPC has reflected the status and newly designated Work24 as subject to intensive management systems in the public sector.
Accordingly, the number has increased from 382 systems across 57 entities to 387 systems across 58 entities. Once designated, public-sector entities should implement stronger safeguards when granting authority to personal data handlers for human resources data and incorporate automated analysis features for access logs.
2. Status Examinations of Major Public-Sector Systems
By March this year, the PIPC will conduct urgent status examinations of the aforementioned intensive management systems and systems processing RRNs for one million or more data subjects.
These status examinations are designed to examine key vulnerabilities identified in recent data breaches and take appropriate measures.
As for intensive management systems, the Commission focuses on the following areas: ● Whether they put the recently released security patches; ● Whether they apply safe authentication methods when personal data handlers have access to the system, such as authentication certificates and one-time passwords; ● Whether they take de-identification measures, such as removing or masking RRNs and other personal information in access logs.
For systems processing RRNs for one million or more data subjects, the PIPC will examine whether they use safe encryption algorithms and how they manage encryption keys.
After examinations, any identified areas for improvement should be taken care of without delay, and the Commission will ensure the effectiveness of examinations by providing consultations proportionate to risk levels.
3. Overhaul of Status Examinations of Uniquely Identifiable Information
Under the Personal Information Protection Act (PIPA), the PIPC should conduct fact-finding surveys on entities that process RRNs and other uniquely identifiable information (UII) above certain thresholds. Up until now, such fact-finding surveys have remained perfunctory, as entities have submitted their self-examination results in writing, and these surveys are not mandated. As a result, such mechanisms have been criticized for relying heavily on each processor's voluntary will.
To align with the initial intention of status examinations of UII management, the PIPC will select target entities in both the public and private sectors based on risk findings. To this end, the PIPC will update the list of personal information files within the first half of this year.
Also, the Commission will review core areas in depth by overhauling the existing twenty- six items to be examined as follows: ● The status of granting authority to personal data handlers who can access UII; ● De-identification measures, such as partial masking, when personal data handlers get access to UII; and ● The status of management of encryption keys
To increase the effectiveness of such reviews, the PIPC will require such entities to submit concrete evidence of their RRN processing status.
The Commission also mandates the submission of remedial plans when any room for improvement is identified. Entities demonstrating exemplary practices in processing UII will be exempt from reviews for a certain period and receive incentives.
The PIPC Chairperson, Kyung Hee Song, stated, “Public institutions process vast amounts of people’s personal information without obtaining consent under applicable law and regulations, requiring more focused and ex-ante approaches to privacy protection.” She added, “Starting with the public sector, the PIPC will actively pursue its ex-ante approaches to privacy protection to have a prevention-oriented privacy protection framework firmly established across society.”
* A PDF file, formatted for better readability, is attached.
|
||