South Korea — Personal Information Protection Act (개인정보 보호법)
Korea's omnibus privacy law, heavily amended in 2020 (absorbing the Network Act's privacy chapter) and 2023. It applies to public institutions (schools included) and private processors alike. Curated here: the lawful-basis catalogue and the children's provision.
Statute text is Korean (the authentic language); this README is curation.
Applicability to EdTech
- Child consent age is 14 (제22조의2): processing a child under 만 14세 requires legal-representative consent, and the processor must verify it (제1항); minimal data may be collected from the child solely to obtain that consent (제2항); notices to under-14s must use plain, easily understood language (제3항).
- Lawful bases (제15조): consent, statute, public-institution duties, contract necessity, vital interests, and a legitimate-interest ground that must "clearly override" the data subject's rights — narrower than GDPR Art. 6(1)(f).
- Korea holds an EU adequacy decision (2021), so EEA→KR transfers within a school group are covered; the reverse (KR student data processed by us) sits under PIPA's own cross-border rules (제28조의8, not extracted — add on demand).
- Fines: PIPA's 2023 amendment moved to turnover-based penalty surcharges (과징금, up to 3% of related turnover) — README-level note; extract 제64조의2 on demand.
Contents
| Document | Covers |
|---|---|
| SUJIP-GWA-ADONG.md | 제15조 (수집·이용의 근거), 제22조의2 (아동의 개인정보 보호) |
Enforcement
개인정보보호위원회 (Personal Information Protection Commission, PIPC, pipc.go.kr).
Related
- KR 초·중등교육법 — student records & NEIS
- KR 교육기본법 — student-information principles
- KR Network Act — commercial-message opt-in
Sources
Meta
Statute text in SUJIP-GWA-ADONG.md is reproduced verbatim in Korean from the official 국가법령정보센터 DRF API by tools/law-go-kr/build_kr.py; verify re-resolves the current MST by exact 법령명 and fails as soon as an amendment lands.