CONTENTS
- 1. Violation of the Personal Information Protection Act, a Case Involving Breach of the Cross-Border Transfer Provisions

- - K, Which Provided the Personal Information of All Users Without Consent
- - A, Which Failed to Disclose the Entrustment of Personal Information Processing and the Cross-Border Transfer
- 2. Penalty Surcharges for a Violation of the Personal Information Protection Act

- - K Rebuts, Arguing That the Transfer Was a Lawful Entrustment of Processing
- 3. Violation of the Personal Information Protection Act, Daeryun's Strategy?

1. Violation of the Personal Information Protection Act, a Case Involving Breach of the Cross-Border Transfer Provisions

K and A received penalty surcharges of approximately KRW 8.3 billion and corrective orders for a violation of the Personal Information Protection Act.
On January 22, the Personal Information Protection Commission (hereinafter the Commission) imposed a penalty surcharge of KRW 5,968,000,000 on K, a domestic fintech service company that violated the cross-border transfer provisions under the Personal Information Protection Act, and a penalty surcharge of KRW 2,405,000,000 on A, a global big tech company, along with an administrative fine of KRW 2,200,000.
Following media reports that K and A had transferred personal information to the Chinese company A without customer consent, the Commission commenced an investigation and announced the following findings of legal violations and the contents of its dispositions.
K, Which Provided the Personal Information of All Users Without Consent
K was transmitting payment information and other data to A through the relay network of China A Pay, which provides an integrated payment system service within A.
In the course of processing payments, A entrusted China A Pay with personal information processing tasks, including the calculation of users' NSF scores (a score used to predict the likelihood of insufficient funds in a user's account).
In this process, so that China A Pay, A's entrusted party, could build an NSF score calculation model, K transmitted the personal information of all of its users to China A Pay on a total of three occasions beginning in 2018, without user consent.
In addition, every day from June 27, 2019, to May 21, 2024, K continuously transmitted the personal information of approximately 40 million of its users to China A Pay, without separate consent, so that China A Pay could calculate each user's NSF score.
The transmitted information was found to include encrypted mobile phone numbers, email addresses, charged balances, and the number of payments, charges, and remittances over the preceding week.
A, Which Failed to Disclose the Entrustment of Personal Information Processing and the Cross-Border Transfer
A, a global big tech company, entrusted system integration tasks (NSF), such as the development of a communications API for linking payment methods, to China A Pay, having it process the transmission of K users' payment information and the personal information used to calculate NSF scores.
However, in its privacy policy and elsewhere, A did not disclose to users the fact of this entrustment of personal information processing and the cross-border transfer.
2. Penalty Surcharges for a Violation of the Personal Information Protection Act
For the violation of the Personal Information Protection Act, the Commission imposed penalty surcharges and corrective orders on K and A.
The Commission determined that providing the personal information of all users without consent in order to build the NSF model and calculate scores constituted a cross-border transfer without a lawful basis for processing.
Accordingly, it imposed a penalty surcharge of KRW 5,968,000,000 on K and issued a corrective order requiring it to satisfy the legal requirements for cross-border transfers.
In addition, for A's conduct of entrusting the processing of personal information abroad without disclosing or notifying the data subjects of the overseas entrusted party through its privacy policy or otherwise, the Commission imposed a penalty surcharge of KRW 2,405,000,000, and for the conduct of failing to disclose the fact of entrustment, it imposed an administrative fine of KRW 2,200,000.
K Rebuts, Arguing That the Transfer Was a Lawful Entrustment of Processing
However, at the hearing on the application for a stay of execution of the penalty surcharge held on April 18, K argued that “the transfer of the personal information at issue was a lawful entrustment of processing.”
K contended that it was a lawful entrustment of processing and a procedure necessary to carry out its business, and that a system to prevent fraudulent payments was needed in order to enhance the convenience and security of the payment service.
K argued that, under Supreme Court precedent, whether something is provision to a third party or an entrustment of processing must be determined on the basis of “whose business processing and benefit it serves” and who holds the right to control and manage the personal information, and that, because ownership of the personal information rests with K and China A Pay is designated as the entrusted party, the cross-border transfer of personal information constitutes an entrustment of processing.
The Commission, by contrast, takes the position that the automatic transmission of information itself constitutes provision to a third party, so the consent of the data subject is required for the cross-border transfer of user information.
3. Violation of the Personal Information Protection Act, Daeryun's Strategy?
This case, in which penalty surcharges totaling KRW 8.3 billion were imposed for a violation of the Personal Information Protection Act, is a meaningful case in that, as the cross-border transfer of personal information increases with the spread of global platform services, it reaffirms the need to clarify the scope of cross-border transfers and to ensure that businesses comply with the legal requirements when transferring data abroad.
When a business provides a service that involves the cross-border transfer of personal information, it must obtain separate consent from the data subject, and when it entrusts the processing of personal information to an overseas entrusted party, it must clearly disclose, through its privacy policy or otherwise, the fact that the personal information is transferred across the border.
When personal information processing tasks are entrusted to an external party, the entrusting party bears responsibility toward the data subject. Where personal information is transferred beyond the entrusting party's scope of responsibility into the area of responsibility of a third party, this constitutes "provision to a third party," so a legal basis, such as the consent of the data subject, must be in place.
Because the Personal Information Protection Act contains many provisions, and the concepts and requirements of cross-border transfer, provision to a third party, and entrusted processing are intricately interrelated, it is advisable to seek the assistance of an attorney experienced in these matters to prevent risk.
At Daeryun Law Firm LLP, attorneys experienced in this area work as a team on matters such as the following: ▲consulting on violations of the Personal Information Protection Act, ▲advice regarding cross-border transfers and provision to third parties, ▲advance review of legal risks, ▲responding to investigations and administrative proceedings, and ▲responding to personal information breach incidents.









