Republic of Korea: Personal Information Protection Commission opened consultation on draft standards for cross-border privacy rules certification

Description

Personal Information Protection Commission opened consultation on draft standards for cross-border privacy rules certification

On 28 July 2025, the Personal Information Protection Commission (PIPC) opened a public consultation on the draft standards on Cross-Border Privacy Rules (CBPR) certification to support domestic companies in obtaining certification under the Global Cross-Border Privacy Rules (CBPR) Forum, until 16 August 2025. The standards apply to Korean companies engaged in cross-border data transfers, particularly those in digital services and data processing sectors. The draft sets out 50 certification criteria based on the Asia-Pacific Economic Cooperation (APEC) Privacy Framework’s nine privacy principles. It introduces obligations, including separating certification issuance and audit functions, requiring certification assessors to hold Information Security Management System - Personal Information Protection (ISMS-P) auditor qualifications. It also requires having at least 20 audit days within the past two years, and complete CBPR assessor training, and establishing a certification committee of qualified experts.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2025-07-28
in consultation

On 28 July 2025, the Personal Information Protection Commission (PIPC) opened a public consultation…

2025-08-16
processing consultation

On 16 August 2025, the Personal Information Protection Commission (PIPC) closes the public consulta…