Skip to menu Skip to content

Korean e-government homepage mark This site is the official e-Government website of the Republic of Korea.

zoom
100%

Notice / Press Release

Notice Detail
Title The PIPC Holds a Briefing Session on Cross-Border Data Transfers for Businesses
Department Date 2026.09.16
Attachment press release The PIPC Holds a Briefing Session on Cross-Border Data Transfers for Businesses.pdf
Page URL https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=3164
Contents

Press Release 

The PIPC Holds a Briefing Session on Cross-Border Data Transfers for Businesses 

- The session aims to seek feedback from business-side practitioners on ways to identifying means for safe cross-border data transfers 

- The PIPC also introduces changes to the Global Cross-Border Privacy Rules (CBPR) Certification System

 

September 14, 2026

(This is an unofficial translation of a press release, originally prepared in Korean.)

 

The Personal Information Protection Commission (PIPC) and the Korean Internet & Security Agency (KISA) will hold a briefing session on the Cross-Border Data Transfer System on September 14, 2026, to hear from businesses about challenges they face in transferring personal information across borders and discuss ways to improve the system.

 

As digitalization, including the use of artificial intelligence (AI) and cloud services, and international joint research continue to proliferate, cross-border transfers of personal information have become commonplace in business operations and research environments. Accordingly, there is a growing need for more diverse means of cross-border data transfers that both safeguard personal information and facilitate the use of data by businesses and research institutions. Cross-border data transfers include the provision, the entrustment of personal data processing, and the retention of personal information outside of the jurisdiction.

 

Against this backdrop, the PIPC is pursuing the introduction of Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs) to provide clearer and more diverse options for cross-border data transfers while ensuring that data subjects’ rights are adequately protected. At the briefing session, the PIPC will present its plan to introduce these data transfer mechanisms and gather feedback from business practitioners. 

 

Starting from the briefing session, the PIPC will continue to engage with businesses experiencing difficulties in transferring personal information to other jurisdictions and seek the reviews of a wide range of stakeholders, including experts from industry, academia, and the legal sector. The PIPC will also conduct a comprehensive review of the operational status of cross-border data transfer systems and their operations in other countries to develop a system that strikes a balance between the protection of data subjects’ rights and the use of personal information.

 

In line with a notification on ‘Operational Guidance on the Cross-Border Privacy Rules (CBPR) System’, the Briefing Session also covers the operational details of the updated Global CBPR certification and the application procedures for a new certification.

 

The CBPR is an international certification framework developed to facilitate cross-border data transfers while safeguarding personal data. Global CBPR-certified companies can enjoy benefits, including enhanced business credibility worldwide. Moreover, they can receive personal data from Japan, Singapore, and other countries that have adopted the Global CBPR certification as a means of cross-border data transfers without unnecessary legal or procedural barriers.

 

The briefing session will also feature a presentation by the Korea- EU Privacy & Data Protection Cooperation Center on regulatory trends in the EU and corresponding response plans. In addition, legal experts will provide one-on-one consultations on privacy compliance requirements across different jurisdictions.

 

Director-General of the Planning & Coordination Bureau Jung-A Suh said, “We are at an important crossroads where we need to lay a foundation for protecting the rights of data subjects as well as helping businesses leverage data on the global stage.” She added, “This briefing session will allow us to attentively listen to practitioners’ voices to establish a reasonable cross-border data transfer system that harmonizes the protection and use of personal information.” 

 

* A PDF file, formatted for better readability, is attached.

Previous
The PIPC’s Privacy Protection Framework Reform is Open to Public Consultation for the Era of AI
Next
The PIPA Amendment Bill for AI Development Passed at the National Assembly Plenary Meeting