Sending Korean customer data to a foreign AI API: what PIPA Article 28-8 asks

한국 고객 데이터를 해외 AI API로 전송할 때: 개인정보 보호법 제28조의8 요건

4 min read2 primary sources

Sending Korean user personal information to foreign AI models constitutes a cross-border transfer under PIPA Article 28-8. The law bars overseas transfer unless you meet one of five statutory exemptions. How the contract execution path works, the five mandatory disclosures, and the Commission's suspension powers under Article 28-9.

A shared office floor with glass meeting rooms, desks and a corridor sign
On this page
  1. The five statutory grounds for cross-border transfer
  2. The five mandatory disclosures
  3. Safety measures and contract prohibitions
  4. The Commission suspension power

Flowchart of PIPA Article 28-8 showing the baseline prohibition on cross-border data transfer, five statutory legal grounds, and the Article 28-9 suspension order

Korea's data privacy statute governs how companies handle customer data. When a backend forwards user prompts containing personal information to overseas servers, Korean law treats that transmission as a cross-border data transfer.

Personal Information Protection Act Article 28-8 establishes the baseline rule. The statute bans overseas transfers by default. You cannot transfer Korean personal information across borders unless your processing falls under an explicit statutory exception.

The five statutory grounds for cross-border transfer

Article 28-8 paragraph 1 defines transfer broadly. It covers third-party provision, processing consignment, and overseas storage. It also explicitly includes foreign remote access where data is viewed from abroad.

To transfer data lawfully, you must qualify under one of five statutory grounds:

Statutory groundLegal basisCore requirementCommon application
Separate consentArt. 28-8(1)(1)Express user opt-in with five statutory disclosuresModel training, marketing, non-essential features
Statutory / treatyArt. 28-8(1)(2)Explicit authority in domestic statute or ratified treatyCross-border regulatory reporting
Contract executionArt. 28-8(1)(3)Necessary processing consignment disclosed in Privacy PolicyCore product AI features, cloud hosting
Certified recipientArt. 28-8(1)(4)Recipient holds PIPC-approved privacy certificationCertified multinational partners
Adequacy findingArt. 28-8(1)(5)PIPC recognizes destination country's data protection levelJurisdiction-level mutual recognition

Most AI software products rely on the third ground. If processing is necessary to execute your contract with the user, you do not need a separate consent checkbox.

The five mandatory disclosures

When you seek separate consent or publish your cross-border processing details, Article 28-8 paragraph 2 mandates five specific disclosures:

Disclosure itemStatutory descriptionWhat you must print
1. Data items이전되는 개인정보 항목Exact personal data fields sent in API calls
2. Destination개인정보가 이전되는 국가, 시기 및 방법Destination country, transfer timing, and network transmission method
3. Recipient개인정보를 이전받는 자의 성명 또는 명칭Corporate entity name and direct contact details
4. Purpose and retention이용목적 및 보유·이용 기간Recipient's exact usage purpose and data retention duration
5. Refusal rights이전을 거부하는 방법, 절차 및 거부의 효과How users decline and resulting service limitations

If any of these five details change, Article 28-8 paragraph 3 requires you to notify users and obtain consent again.

Safety measures and contract prohibitions

Article 28-8 paragraph 4 requires controllers transferring data abroad to take protective measures prescribed by Presidential Decree, and to comply with Articles 17 through 19 and Chapter 5. Domestic statutory safeguards apply to foreign processing.

Article 28-8 paragraph 5 also prohibits signing contracts that violate Korean privacy law. You cannot contract away statutory user rights. Your data processing agreement with the overseas vendor must protect user rights and ensure prompt responses to data subject requests.

The Commission suspension power

Article 28-9 gives the Personal Information Protection Commission direct enforcement authority. The Commission can order a company to halt cross-border transfers immediately.

The Commission issues a suspension order if a company breaches Article 28-8 rules or fails to protect personal information adequately. If the Commission issues an order, you have seven days to submit a formal objection under Article 28-9 paragraph 2.

Founders preparing application materials can test their business plan narratives against regulatory requirements in the PSST Assistant.

Related on KBridge: the PSST plan format.

Frequently asked questions

Does sending prompts to OpenAI or Anthropic count as a cross-border transfer under PIPA?
Yes. PIPA Article 28-8 defines cross-border transfer to include providing personal data, consignment for processing, and remote storage or access. Sending user personal information to an overseas AI server qualifies as an overseas transfer.
Do I need explicit user consent for every foreign AI API call?
No. Under Article 28-8(1)(3), you do not need separate consent if processing consignment is necessary to execute a contract with the user, provided you disclose the five statutory items in your Privacy Policy or notify users by email.
What five items must a company disclose for cross-border data transfer?
Article 28-8(2) requires: (1) personal data items transferred, (2) destination country, timing, and transfer method, (3) recipient name and contact information, (4) recipient purpose and retention period, and (5) refusal methods and consequences.
Can I use customer prompts to train my AI models under Article 28-8(1)(3)?
No. Article 28-8(1)(3) covers only transfers strictly necessary to execute a contract with the user. Using customer data for model training or secondary development requires separate, explicit consent under Article 28-8(1)(1).
What happens if a startup violates PIPA Article 28-8?
Under Article 28-9, the Personal Information Protection Commission can order the company to suspend cross-border data transfers immediately. The company has seven days from receipt of the order to raise an objection with the Commission.
What contracts does PIPA Article 28-8 forbid?
Article 28-8(5) explicitly prohibits entering into contracts that violate the Personal Information Protection Act. A startup cannot sign terms of service with a foreign vendor that waive Korean data subjects' statutory rights.

Sources

Everything above is the rule as published. See how it applies to your case.

Read next