Sending Korean customer data to a foreign AI API: what PIPA Article 28-8 asks
한국 고객 데이터를 해외 AI API로 전송할 때: 개인정보 보호법 제28조의8 요건
Sending Korean user personal information to foreign AI models constitutes a cross-border transfer under PIPA Article 28-8. The law bars overseas transfer unless you meet one of five statutory exemptions. How the contract execution path works, the five mandatory disclosures, and the Commission's suspension powers under Article 28-9.

On this page
Korea's data privacy statute governs how companies handle customer data. When a backend forwards user prompts containing personal information to overseas servers, Korean law treats that transmission as a cross-border data transfer.
Personal Information Protection Act Article 28-8 establishes the baseline rule. The statute bans overseas transfers by default. You cannot transfer Korean personal information across borders unless your processing falls under an explicit statutory exception.
The five statutory grounds for cross-border transfer
Article 28-8 paragraph 1 defines transfer broadly. It covers third-party provision, processing consignment, and overseas storage. It also explicitly includes foreign remote access where data is viewed from abroad.
To transfer data lawfully, you must qualify under one of five statutory grounds:
| Statutory ground | Legal basis | Core requirement | Common application |
|---|---|---|---|
| Separate consent | Art. 28-8(1)(1) | Express user opt-in with five statutory disclosures | Model training, marketing, non-essential features |
| Statutory / treaty | Art. 28-8(1)(2) | Explicit authority in domestic statute or ratified treaty | Cross-border regulatory reporting |
| Contract execution | Art. 28-8(1)(3) | Necessary processing consignment disclosed in Privacy Policy | Core product AI features, cloud hosting |
| Certified recipient | Art. 28-8(1)(4) | Recipient holds PIPC-approved privacy certification | Certified multinational partners |
| Adequacy finding | Art. 28-8(1)(5) | PIPC recognizes destination country's data protection level | Jurisdiction-level mutual recognition |
Most AI software products rely on the third ground. If processing is necessary to execute your contract with the user, you do not need a separate consent checkbox.
The five mandatory disclosures
When you seek separate consent or publish your cross-border processing details, Article 28-8 paragraph 2 mandates five specific disclosures:
| Disclosure item | Statutory description | What you must print |
|---|---|---|
| 1. Data items | 이전되는 개인정보 항목 | Exact personal data fields sent in API calls |
| 2. Destination | 개인정보가 이전되는 국가, 시기 및 방법 | Destination country, transfer timing, and network transmission method |
| 3. Recipient | 개인정보를 이전받는 자의 성명 또는 명칭 | Corporate entity name and direct contact details |
| 4. Purpose and retention | 이용목적 및 보유·이용 기간 | Recipient's exact usage purpose and data retention duration |
| 5. Refusal rights | 이전을 거부하는 방법, 절차 및 거부의 효과 | How users decline and resulting service limitations |
If any of these five details change, Article 28-8 paragraph 3 requires you to notify users and obtain consent again.
Safety measures and contract prohibitions
Article 28-8 paragraph 4 requires controllers transferring data abroad to take protective measures prescribed by Presidential Decree, and to comply with Articles 17 through 19 and Chapter 5. Domestic statutory safeguards apply to foreign processing.
Article 28-8 paragraph 5 also prohibits signing contracts that violate Korean privacy law. You cannot contract away statutory user rights. Your data processing agreement with the overseas vendor must protect user rights and ensure prompt responses to data subject requests.
The Commission suspension power
Article 28-9 gives the Personal Information Protection Commission direct enforcement authority. The Commission can order a company to halt cross-border transfers immediately.
The Commission issues a suspension order if a company breaches Article 28-8 rules or fails to protect personal information adequately. If the Commission issues an order, you have seven days to submit a formal objection under Article 28-9 paragraph 2.
Founders preparing application materials can test their business plan narratives against regulatory requirements in the PSST Assistant.
Related on KBridge: the PSST plan format.
Frequently asked questions
- Does sending prompts to OpenAI or Anthropic count as a cross-border transfer under PIPA?
- Yes. PIPA Article 28-8 defines cross-border transfer to include providing personal data, consignment for processing, and remote storage or access. Sending user personal information to an overseas AI server qualifies as an overseas transfer.
- Do I need explicit user consent for every foreign AI API call?
- No. Under Article 28-8(1)(3), you do not need separate consent if processing consignment is necessary to execute a contract with the user, provided you disclose the five statutory items in your Privacy Policy or notify users by email.
- What five items must a company disclose for cross-border data transfer?
- Article 28-8(2) requires: (1) personal data items transferred, (2) destination country, timing, and transfer method, (3) recipient name and contact information, (4) recipient purpose and retention period, and (5) refusal methods and consequences.
- Can I use customer prompts to train my AI models under Article 28-8(1)(3)?
- No. Article 28-8(1)(3) covers only transfers strictly necessary to execute a contract with the user. Using customer data for model training or secondary development requires separate, explicit consent under Article 28-8(1)(1).
- What happens if a startup violates PIPA Article 28-8?
- Under Article 28-9, the Personal Information Protection Commission can order the company to suspend cross-border data transfers immediately. The company has seven days from receipt of the order to raise an objection with the Commission.
- What contracts does PIPA Article 28-8 forbid?
- Article 28-8(5) explicitly prohibits entering into contracts that violate the Personal Information Protection Act. A startup cannot sign terms of service with a foreign vendor that waive Korean data subjects' statutory rights.
Sources
- National Law Information Center (law.go.kr) - Personal Information Protection Act (개인정보 보호법) Article 28-8 (개인정보의 국외 이전) statutory text on cross-border transfer prohibition and five exceptions — read 2026-09-16
- National Law Information Center (law.go.kr) - Personal Information Protection Act (개인정보 보호법) Article 28-9 (개인정보의 국외 이전 중지 명령) statutory text on PIPC transfer suspension orders and seven-day objection window — read 2026-09-16
Everything above is the rule as published. See how it applies to your case.
Read next
- FounderCraftThe Business Model Canvas, mapped onto what a Korean 사업계획서 actually has to prove
- FounderCraftY Combinator's application and a Korean programme's: two processes, and what actually transfers
- FounderCraftValidate before the 모집공고 closes: what the printed calendar actually gives you
- FounderCraftPSST, section by section: the nine numbered blocks of KISED's startup business plan