Skip to Content
ANALYSISMEMBER

Trusting the regulator, not the rules: South Korea's AI data amendment

South Korea is poised to let controllers use personal data, original and non-pseudonymized, for AI development without the data subject's consent and beyond the original purpose of collection, subject to PIPC approval.

Published
Subscribe to IAPP newsletters

Contributors:

Kyoungsic Min

AIGP, CIPP/E, FIP

Country Leader, South Korea, IAPP; Privacy Counsel and Asia Regional Lead

VeraSafe

South Korea is one plenary vote away from rewriting the legal basis for artificial intelligence training data. A bill amending the Personal Information Protection Act, approved by the National Assembly's Political Affairs Committee on 14 May 2026 and cleared by the Legislation and Judiciary Committee on 29 July with bipartisan support, would for the first time let controllers use personal data, original and non-pseudonymized, for AI development without the data subject's consent and beyond the original purpose of collection, provided the Personal Information Protection Commission approves. Only the floor vote remains, expected as early as mid-August; the law takes effect six months after promulgation.

Supporters present the amendment as a pragmatic answer to Korea's training-data bottleneck, and it is that. But it is also more consequential: a structural decision about where trust resides in South Korea's data protection system. Rather than trusting accountable controllers within enforceable limits, the amendment relocates the decision itself to the regulator. That relocation revives a question data protection law exists to answer, not to provoke. Who supervises the supervisor?

What the amendment would do

The new special provisions, draft Articles 28-12 through 28-15, let lawfully collected personal data be used for AI development, performance improvement included, on a case-by-case PIPC resolution. Four conditions frame the discretion: Anonymization or pseudonymization must not suffice; safeguards must be in place; the purpose must include public interest, protection of data subjects or third parties, or social benefit; and the risk of unfair infringement must be markedly low. 

Contributors:

Kyoungsic Min

AIGP, CIPP/E, FIP

Country Leader, South Korea, IAPP; Privacy Counsel and Asia Regional Lead

VeraSafe

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership