The European Commission has published its first review of the adequacy decision for the Republic of Korea, concluding that Korea continues to ensure an adequate level of protection for personal data transferred from the EU. The review, published on 24 July 2026, finds that amendments to Korea's Personal Information Protection Act (PIPA) in March 2023 and April 2025 have strengthened safeguards and brought the framework closer to the EU's General Data Protection Regulation (GDPR).

The adequacy decision was originally adopted on 17 December 2021, allowing free data flows between the EU and Korea without additional safeguards. The review meeting took place on 17 October 2025, with input from Korean authorities (the Personal Information Protection Commission and the Korea Internet & Security Agency) and four representatives from the European Data Protection Board (Italy, France, Finland, Germany). No information was received from EU Member States under Articles 2 and 3(2)-(3) of the decision.

The 2023 PIPA amendments extended the law's scope to previously excluded sectors, including Statistics Act data processed by public institutions and processing for urgent public safety, security, and health purposes. Special rules for information and communication service providers were deleted, applying general PIPA rules instead. Legal bases for processing were broadened: Article 15(1)(4) removed the "unavoidable" requirement for contract performance, and Article 15(1)(7) added urgent public safety, security, and health grounds. Data subject rights were strengthened, including a general right to withdraw consent (Article 37(1)) and a right to object to and obtain explanations for automated decision-making (Article 37-2), with guidance issued by the PIPC in September 2024. Rules on pseudonymised data were tightened: Article 28-7 now limits transparency and rights exceptions to statistical, research, or archiving purposes, and Article 21 destruction obligations now apply. Supreme Court rulings in 2019 and 2024 clarified re-identification risks and suspension rights.

The 2025 amendment expanded domestic agent appointment requirements (Article 31-2) to all controllers, not just information and communication service providers. The Supplementary Rules (Annex I) remain functional, though some overlaps with amended PIPA may make certain rules redundant.

The review confirms that Korea's data protection framework remains adequate for EU transfers, with the 2023 and 2025 amendments significantly strengthening protections, rights, and convergence with the GDPR. This provides legal certainty for EU businesses transferring personal data to Korea, while ensuring strong protections for EU data subjects. The Commission will continue to monitor developments in Korea's data protection landscape.

← Atlas › News › Digital & Communication