CONTENTS
- 1. A Case in Which a Violation of the Personal Information Protection Act Was at Issue

- 2. The Court's Determination Regarding the Personal Information Protection Act

- - The Genuineness of Consent to the Collection and Use of Personal Information
- - Whether the Data Constituted Pseudonymized or Anonymized Information
- - The Discrepancy Between the Collection Purpose and the Actual Purpose of Use
- - Violation of the Obligation to Destroy Personal Information
- - The Need for Separate Consent to the Processing of Sensitive Information
- 3. The Significance of the Judgment Regarding the Personal Information Protection Act

- - Daeryun's Strategy in a Personal Information Infringement Case
1. A Case in Which a Violation of the Personal Information Protection Act Was at Issue

This was a case in which whether the Personal Information Protection Act had been violated was the central issue.
The defendant company operated an app providing analysis of romantic relationships, and it collected KakaoTalk conversation sentences between users and their counterparts through a method in which users uploaded those sentences directly.
Thereafter, in the course of developing a separate AI chatbot service provided by the same company, the defendant transferred a portion of the personal information and conversation sentences stored in the existing app service's database to a separate training database and used them for model training, and on that basis the defendant launched the AI chatbot service.
However, the victims claimed damages, as several matters became contested, including the discrepancy between the processing purpose disclosed at the personal information collection stage and the actual purpose of use, whether the consent to personal information processing was genuine, and whether the requirements for processing pseudonymized or anonymized information were satisfied.
2. The Court's Determination Regarding the Personal Information Protection Act
The court made the following determinations regarding this matter.
The Genuineness of Consent to the Collection and Use of Personal Information
The court determined that a merely formal and blanket consent procedure cannot be regarded as satisfying the obligation of genuine consent required by the Personal Information Protection Act.
The court found that obtaining consent through a checkbox stating only "I agree to the terms and the privacy policy" and then providing access to the privacy policy by way of a link does not make it possible to conclude that users clearly recognized how their personal information would be used and consented to it.
In doing so, the court set out a standard that consent must be disclosed with its content and scope clearly distinguished and must be explained in a manner that allows users to recognize it sufficiently.
Whether the Data Constituted Pseudonymized or Anonymized Information
The court determined that the data the defendant company used in the course of AI training did not meet the standards for anonymized or pseudonymized information under the Personal Information Protection Act.
Because the conversation sentences contained not only individually identifying information such as names, contact numbers, addresses, passwords, and account numbers, but also content from which social relationships and personal details could be inferred, the court found that the risk of identifying a specific individual was substantial if additional information were combined with it.
The court also determined that the measure of encrypting only part of the information while storing a substantial portion without de-identification did not satisfy the pseudonymization standard required by Article 28-2 of the Personal Information Protection Act.
The Discrepancy Between the Collection Purpose and the Actual Purpose of Use
The court found that the functions provided by the existing app service and the AI chatbot service were fundamentally different in purpose, character, function, and usage environment, so using the data as training data without consent constituted a use exceeding the scope of the collection purpose provided for in Articles 15 and 18 of the Personal Information Protection Act.
The court determined that the mere fact that the privacy policy stated "development of new services" cannot be assessed as showing that the data subjects anticipated or consented to the training of AI algorithms.
Violation of the Obligation to Destroy Personal Information
The court also found a violation with respect to the defendant's failure to comply with the legal obligation to separately store or destroy the personal information of long-term non-users and withdrawn members.
The court determined that this constituted a violation of Articles 21 and 39-6 of the Personal Information Protection Act.
The Need for Separate Consent to the Processing of Sensitive Information
On the ground that, although the conversation sentences contained content falling under the sensitive information set out in Article 23(1) of the Personal Information Protection Act, such as health information, content relating to sexual life, and ideologies and beliefs, no separate explicit consent had been obtained, the court found a violation of the laws relating to sensitive information.
Accordingly, the court, using the risk of harm and the degree of infringement as criteria, divided the victims into groups according to whether their personal information had been leaked, their sensitive information had been leaked, or both, and recognized differentiated consolation money of 100,000 won, 300,000 won, and 400,000 won.
3. The Significance of the Judgment Regarding the Personal Information Protection Act

This judgment is a case that made clear that, in order to use, for the separate purpose of AI development and training, personal information collected from an existing service in the course of applying AI technology, the data subject's clear prior consent is required.
In particular, the court set out a standard that, even if pseudonymized information is asserted to be usable without consent for the purpose of scientific research, pseudonymization must be carried out to a level at which the flow of personal information is technically and administratively controlled and the risk of identification is recognized as having been removed.
The court also confirmed that, even for a data-driven AI company, additional use of data beyond the scope foreseeable at the personal information collection stage is not permitted, and that the scope of data processing must be designed from the early stages of service development in a manner that satisfies legal standards.
Daeryun's Strategy in a Personal Information Infringement Case
Daeryun Law Firm LLP provides the following response services for platform service companies and AI service operators.
First, it provides compliance modeling that reviews in advance whether the Personal Information Protection Act is being complied with at the service-planning and early-development stages.
Second, it presents disclosure and consent procedures regarding the purposes of personal information collection and use, the retention period, and the scope of use, based on the standard of what users can understand.
Third, during service operation, it supports responses to investigations by supervisory authorities such as the Personal Information Protection Commission and the Korea Communications Commission, and the development of improvement measures.
Fourth, when a personal information leak or infringement incident occurs, it designs both the criminal response (filing complaints, responding to investigations, and strategies for a finding of no charge and for mitigation of punishment) and the civil response (strategies for defending against claims for damages) together.
Fifth, it provides risk-prevention systems, including training for officers and employees within companies and institutions, vulnerability management, and the analysis and collection of evidence through digital forensics when a violation of the Personal Information Protection Act occurs.
If you need legal advice regarding the Personal Information Protection Act, you are welcome to book a 🔗corporate attorney legal consultation at any time.











