- What Counts as an “Overseas Transfer” Under Korean Law
- Disclosure Obligations That Apply Regardless of Which Basis You Use
- The Regulator’s Power to Suspend a Transfer
- Extraterritorial Reach: This Applies Even Without a Korean Entity
- What’s at Stake for Non-Compliance
- Practical Steps Before Moving Korean Customer Data Overseas
Most companies that store Korean customer data on regional or global cloud infrastructure — AWS’s Singapore or Tokyo region, a US-based CRM, a global data warehouse — don’t think of that as a legal decision. It’s treated as an IT architecture choice: pick the region with the best latency or cost, and move on. Korean law doesn’t see it that way. Moving personal data of Korean data subjects outside Korea — even just to store it, even within the same corporate group, even where no third party ever looks at it — is treated as a distinct legal event under the Personal Information Protection Act (PIPA), governed by its own chapter with its own conditions, disclosure obligations, and penalties.
This matters most for foreign headquarters running a Korean subsidiary or serving Korean customers directly: the decision about where customer data physically sits is frequently made by a global IT or engineering team with no visibility into Korean law, while the compliance exposure sits with the Korean-facing entity.
- What Counts as an “Overseas Transfer” Under Korean Law
- The Legal Bases That Allow an Overseas Transfer
- Separate, Specific Consent
- The Contract-Performance Carve-Out for Cloud Processing
- Adequacy Recognition
- Certification of the Recipient
- Another Statutory Basis
- Disclosure Obligations That Apply Regardless of Which Basis You Use
- The Regulator’s Power to Suspend a Transfer
- PIPC’s Suspension Order Authority
- Extraterritorial Reach: This Applies Even Without a Korean Entity
- Foreign Companies Processing Korean Residents’ Data
- The Domestic Representative Requirement
- What’s at Stake for Non-Compliance
- Practical Steps Before Moving Korean Customer Data Overseas
What Counts as an “Overseas Transfer” Under Korean Law
PIPA’s 2023 amendment (effective March 2024) consolidated what used to be scattered across separate rules on third-party provision, outsourcing, and storage into a single regime for overseas transfer — under Article 28-8. Under this framework, it no longer matters whether the arrangement is labeled as providing data to an overseas third party, outsourcing processing to an overseas vendor, or simply storing data on a server located abroad: if personal information of a Korean data subject crosses the border, in any of these forms, the same set of conditions applies.
This also means the analysis doesn’t turn on corporate structure. Moving data to your own company’s server in another country is treated the same way as moving it to an unrelated vendor — “it’s staying within our group” is not, by itself, an exception.
The Legal Bases That Allow an Overseas Transfer
Article 28-8 sets out several distinct routes to a lawful overseas transfer. A company needs to be able to point to one of them for each transfer it makes — not simply assume that using a well-known cloud provider is automatically fine.
Separate, Specific Consent
The traditional route is obtaining consent from the data subject that is separate and distinct from general privacy-policy consent — specifically informing them of the items being transferred, the destination country, the identity and contact details of the recipient, the purpose and retention period of the processing, and how to refuse. A generic “I agree to the privacy policy” checkbox does not satisfy this.
The Contract-Performance Carve-Out for Cloud Processing
The 2023 amendment added meaningful relief here: where the overseas transfer is necessary to perform a contract with the data subject (the classic case being use of overseas cloud infrastructure to deliver the service the customer signed up for) and the company properly discloses the transfer in its privacy policy — recipient, items transferred, purpose, retention period, and complaint channel — separate consent is not required. This is the provision that lets companies use standard global cloud regions without collecting a new consent for every customer, provided the disclosure is done correctly and up front.
Adequacy Recognition
Where Korea’s Personal Information Protection Commission (PIPC) has formally recognized a destination country or region as providing an equivalent level of protection (적정성 결정), transfers to that jurisdiction can proceed without needing consent or certification on a case-by-case basis. The EU/EEA-Korea mutual adequacy arrangement is the most cited example of this mechanism in practice.
Certification of the Recipient
Alternatively, a transfer can proceed where the overseas recipient has obtained PIPC certification that its protective measures meet the standard required under Korean law, or where the transfer is structured using PIPC’s standard contract framework for cross-border transfers (a mechanism functionally similar to the EU’s standard contractual clauses).
Another Statutory Basis
Less commonly, a transfer permitted or required under another statute or an international treaty can independently justify the transfer.
Disclosure Obligations That Apply Regardless of Which Basis You Use
Separately from which legal basis is relied on, Article 28-8(2) requires the transferring company to make available to data subjects — typically through the privacy policy — the specific items of personal information being transferred, the destination country, the recipient’s identity and contact information, the purpose and retention period of the overseas processing, and the method by which a data subject can refuse the transfer. This disclosure obligation is not optional even where consent isn’t required under the contract-performance carve-out; if anything, it becomes more important there, since disclosure is doing the work that consent would otherwise do.
The Regulator’s Power to Suspend a Transfer
PIPC’s Suspension Order Authority
Article 28-9 gives PIPC authority to order a company to suspend an overseas transfer — one already underway or one that’s planned — where the transfer violates PIPA, or where the level of protection in the destination country is inadequate and the resulting risk to data subjects is serious enough that other remedies aren’t sufficient. This is a meaningful operational risk distinct from a fine: a suspension order can force a company to stop using a given overseas processing arrangement on short notice, which is disruptive in a way that a later financial penalty is not.
Extraterritorial Reach: This Applies Even Without a Korean Entity
Foreign Companies Processing Korean Residents’ Data
PIPA’s extraterritorial application provisions mean a foreign company with no Korean subsidiary and no physical presence in Korea can still be subject to the Act if it offers goods or services to people located in Korea, or profiles their behavior, and processes their personal information in doing so. “We have no Korean entity, so Korean privacy law doesn’t apply to us” is not a reliable position where the company is knowingly serving Korean customers.
The Domestic Representative Requirement
For foreign businesses that meet certain thresholds (generally tied to scale of processing or revenue from Korean users), Article 31-2 requires appointing a domestic representative in Korea — a person or entity that PIPC and Korean data subjects can actually reach for compliance purposes, rather than having to pursue a claim against an entity with no presence in the jurisdiction.
What’s at Stake for Non-Compliance
Violations of the overseas transfer rules can result in administrative fines under Article 64-2, calculated by reference to relevant revenue rather than a fixed amount — historically up to a percentage of the revenue tied to the violation, a structure introduced specifically to make penalties meaningful for large multinational processors rather than only small domestic operators. Certain violations, such as unauthorized provision of personal information to a third party, also carry potential criminal liability. And as noted above, a suspension order can create an operational disruption independent of any monetary penalty.
Practical Steps Before Moving Korean Customer Data Overseas
Before treating a choice of server region or vendor as a settled IT matter, it’s worth mapping exactly what Korean customer data actually leaves Korea, in what form, and to which recipients — including data flowing through subprocessors a primary vendor uses. From there, the company needs to identify which Article 28-8 basis actually applies to each flow, rather than assuming the contract-performance carve-out covers everything by default. The required disclosures should be built into the privacy policy at the point data collection begins, not added retroactively after a transfer is already underway. Where a destination benefits from PIPC’s adequacy recognition, that can meaningfully simplify the analysis; where it doesn’t, certification or a standard contract mechanism becomes the more realistic path. And for global platforms serving Korean users without a Korean entity, it’s worth checking early whether the domestic representative threshold applies, since that obligation is easy to miss precisely because it doesn’t depend on having Korean incorporation at all.
This is general information about how PIPA’s overseas transfer rules operate, not an assessment of any specific company’s data flows or vendor arrangements — which legal basis fits, what disclosures are required, and whether the domestic representative obligation applies all depend on the actual processing setup. Mapping the real data flows with counsel before finalizing infrastructure decisions is the step that avoids discovering a gap after the fact.