Skip to menu Skip to content

Korean e-government homepage mark This site is the official e-Government website of the Republic of Korea.

zoom
100%

Notice / Press Release

Notice Detail
Title The PIPC Actively Supports Public AX Trusted by the Korean People with Privacy Protection
Department Date 2026.07.30
Attachment press release The PIPC Actively Supports Public AX Trusted by the Korean People with Privacy Protection.pdf
Page URL https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=3153
Contents

Press Release

The PIPC Actively Supports Public AX Trusted by the Korean People with Privacy Protection 

- The PIPC unveils its Guidelines on Privacy Protection for Public AI Transformation (AX) 

- The Guidelines explain practical privacy measures and real-world use cases for the public sector

 

July 23, 2026

(This is an unofficial translation of a press release, originally prepared in Korean.)

 

As artificial intelligence transformation (AX) has kicked off across the public sector, comprehensive guidance on privacy protection for public AX has been released.

 

On July 23, 2026, the Personal Information Protection Commission (PIPC) unveiled its Guidelines on Privacy Protection for Public AX at the 11th ministerial meeting on science and technology.

 

The Guidelines are put together to help the public sector preemptively identify and address privacy issues that might arise from personal data processing over the course of public AX.

 

Public institutions, including state-owned enterprises, provide administrative services closely connected to people’s daily lives and process vast amounts of data across sectors, such as welfare, public health, safety, and civil complaints. In this context, ensuring the safety of public AX is essential to gaining public trust in government policies and administrative services. 

 

Some public institutions, however, face difficulties in understanding AI’s data processing mechanisms and designing detailed safeguards due to a lack of AI and privacy experts. In this regard, the PIPC systematically incorporates legal criteria and standards, as well as safeguards, into the guidelines informed by real-world use cases from its policy schemes, including fact-finding reviews, prior adequacy reviews of AI-related services and products. It aims to reduce implementation challenges on the ground and facilitate the expansion of public AX.

 

The following explains the details of the Guidelines.

 

 

1. 10 Key Things to Examine in Three Phases for Working-Level Staff

 

The Guidelines categorize the public AX lifecycle into three phases: Pre-Design Phase, Development Phase, and Application and Management Phase.

 

 

In the Pre-Design Phase, the guidance material explains the need to establish a foundation for complying with privacy principles, including purpose limitation and data minimization, by clearly setting the purposes and targets to be processed during AX. It also advises that data controllers in the public sector should identify particular-specific lawful bases for the collection, use, and provision of personal information. When choosing which AI systems to develop and deploy, data controllers are advised to consider system performance and characteristics of personal information to be processed, as well as potential privacy risks.

 

During the Development Phase, the guidelines advise data controllers to implement data processing point-specific safeguards, including the use of training data, entering inputs, integrating retrieval-augmented generation, generating outputs and others. As for safeguards that can be considered at the working level, the guidelines introduce the application of pseudonymization, anonymization, differential privacy and other privacy enhancing technologies (PETs), input and output filtering, and access authority management.

 

In the System Application and Management Phase, data controllers are advised to continuously keep an eye on potential privacy breaches or exposures, including through safety testing before and after deployment, and to establish monitoring and incident response systems. In addition, the guidelines suggest that data controllers should establish a procedure for data subjects to exercise rights to access, rectification, erasure, and suspension of processing, as required under the Personal Information Protection Act (PIPA). In addition, institutions are encouraged to enhance transparency by clearly explaining their data processing practices through a privacy policy and other channels.

 

 

2. Differentiated Safeguards Tailored and Proportionate to Public AX Usage and Risk Levels

 

The guidelines divide public AX into three types: i) assisting simple workstreams ii) information integration, analysis, and recommendations iii) selection and decision-making. It advises data controllers to flexibly review context-specific necessities required for AI systems rather than implementing one-size-fits-all measures.

 

 

As for Assisting Simple Workstreams, including data processing, summarization using large language models (LLMs), and chatbot consultations, the guidelines focus on baseline safeguards. The guidelines clarify permissible and prohibited use cases to help data controllers in the public sector guide and train users, and establish a management framework for input and output data filtering and others.

 

In terms of Information Integration, Analysis, and Recommendation that enable the integration of data bases with systems to analyze and recommend targeted information, the guidelines advise data controllers to focus on out-of-purpose uses and excessive privacy inference risks. The guidelines also suggest that data controllers should check whether they fail to identify a lawful basis for processing when integrating with databases outside the organization, and apply the purpose limitation principle to analyzed or inferenced data to minimize privacy infringements. Moreover, data controllers are advised to implement enhanced management frameworks by granting differentiated access authority or putting access controls in place for integrated data bases and systems.

 

For Selection and Decision-Making that is utilized for decision-making in the public sector, such as selection of beneficiaries and risk detection, the guidelines call for data controllers to closely review the need, effectiveness, and lawful bases for AX and personal data processing. In order to prevent privacy infringements on data subjects’ rights caused by AI biases, and a lack of accuracy and robustness, the guidelines advise data controllers to continuously overhaul and improve data accuracy, representation, and system performance. At the same time, the guidelines require that data controllers establish a response framework in which data subjects can effectively exercise their rights to object, request an explanation, and review, among others, when it comes to AI-based automated decision making (ADM).

 

 

3. Roles Required for Public Institutions and the PIPC for AX

 

Each public institution is advised to recognize privacy protections as one of core elements of AX, focusing on Chief Privacy Officers (CPOs) and Chief AI Officers (CAIOs), to establish an inter-department cooperation network that connects privacy and AX departments. Moreover, each public institution is required to advance its internal management plans in light of its AI operations and environments. 

 

The PIPC is operating a “Public AX Privacy Help Desk” to provide close support and address difficulties for public institutions on an occasional basis. The Help Desk is a comprehensive window for connecting public institutions with relevant support schemes, including legal interpretation, prior adequacy review, and pseudonymization support, and regulatory sandbox programs, based on inquires and project characteristics. 

*Public AX Privacy Help Desk Contact: +82-2100-3072, 3169

 

PIPC Chairperson Kyung Hee Song said, “Public AX is a key enabler for government-led innovation that aims to offer faster and convenient services and enable public officials to work efficiently.” She added, “The PIPC will provide concrete criteria and practical solutions to public institutions to pursue AX without having to worry about privacy uncertainties and actively support public AX to expand in a reliable and trusted manner.”

 

* A PDF file, formatted for better readability, is attached.

 

 

Previous
The EU’s Adequacy Decision on the Republic of Korea Renewed
Next
no data found