The label in the contract is not the position under Korean law

When a group data processing agreement arrives naming the Korean entity a processor, the first thing to establish is that Korean law has no slot that corresponds to it.

The Personal Information Protection Act works with two different relationships. Entrustment of processing under article 26, where one company has another carry out processing for it. Provision to a third party under article 17, where the recipient processes for its own purposes. Which one applies is decided by who determines the purpose and means and who exercises control — not by the word the contract uses.

This matters because the two carry different duties, different disclosure obligations and, where the data leaves Korea, different transfer bases. A privacy policy that files every vendor under "entrustment" because the group DPA said processor will be wrong somewhere, and the error surfaces where it is most expensive: in the cross-border transfer basis.

Physical location does not settle it either. Equipment sitting at a customer’s premises is still operated by whoever holds the authentication and access control.

Where the liability sits while the contract runs

While the contract is live, the centre of gravity is the company that entrusted the work. Articles 26(4) and 26(7), with article 64-2(1)5, build that structure. The vendor is not without duties of its own — the two layers overlap — but a foreign group that assumes its Korean vendor carries the exposure has the direction wrong.

What the published decisions show is narrower than the theory suggests, and it cuts both ways.

Of the decisions in which the Commission found a breach of article 26, there are 69. Of those, 40 ended in an administrative fine, and 49 turned on article 26 alone with no other provision engaged — things visible on the face of the documents, such as failing to disclose that processing was entrusted, or a contract missing a mandatory term.

So far this reads like a paperwork risk. The part that is usually missed is the rest of it: 9 of those decisions carried a penalty surcharge rather than an administrative fine, and 5 of those rested on article 26 alone. Failure to supervise an entrustee can produce a surcharge without any other violation being found.

After the contract ends, the direction reverses

This is the part that catches vendors.

Where the parties agreed that data would be destroyed at the end of the contract, the data was not destroyed, and a breach followed, the sanction has landed on the vendor rather than the customer. Article 26(8) applies the duties of destruction, safeguards and notification to the entrustee, and the administrative fine provisions say so expressly.

Two practical consequences. A destruction clause in the contract and a record that destruction actually happened are different things, and only the second is a defence. And the confirmation step at termination protects both sides, which is why it is worth insisting on even when the commercial relationship has soured.

Paying first does not mean recovering in full

Where one side has compensated data subjects and seeks recovery from the other, the route is open but the amount is not the whole of what was paid. What moved the split in the decided cases was the state in which the data was handed over — not how much supervision the paying party could evidence.

What changed on 11 September 2026

The amendment added three administrative fine provisions on the chief privacy officer, and all three are applied to entrustees through article 26(8).

A company that only processes personal data on another company’s instruction now carries, in its own name, the duty to designate a chief privacy officer, to have the designation resolved by the board where that applies, and to file it. A group that treats its Korean vendors as an extension of its own compliance perimeter will not have planned for that.

What to do with this

  • Work out the position under Korean law before the group DPA’s terminology is copied into the Korean privacy policy and the local contract.
  • Split the vendor list by article — entrustment under article 26, provision under article 17 — and check the cross-border basis against that split, not against the group’s labels.
  • Treat termination as a documented step, not a clause.
  • If your Korean entity or vendor only processes on instruction, check the chief privacy officer position again against the September 2026 changes.

Frequently asked questions

Q. Is a processor under a group DPA an entrustee under Korean law?

Not by virtue of the label. Korean law has no position that corresponds one-to-one with a processor. The Personal Information Protection Act works with entrustment of processing under article 26 and provision to a third party under article 17, and which one applies turns on who decides the purpose and means and who exercises control — not on what the contract calls the parties. Copying the group DPA’s terminology into the Korean privacy policy and contracts before working out the position is the usual source of the problem.

Q. Who is sanctioned when a vendor’s employee causes a breach in Korea?

While the contract is running the weight sits with the company that entrusted the work, under article 26(4) and (7) and article 64-2(1)5. That does not mean the vendor has no duties of its own; the two layers overlap. Once the contract has ended the direction reverses, because article 26(8) applies the duties of destruction, safeguards and notification to the entrustee, and there are decisions in which the vendor itself was sanctioned.

Q. Do vendors in Korea have to appoint a chief privacy officer?

Since 11 September 2026 the three new administrative fine provisions on the chief privacy officer are applied to entrustees through article 26(8). A company that only processes personal data on another company’s instruction now carries the designation, board resolution and filing duties in its own name.


This page is general information on Korean law and is not legal advice; whether a particular arrangement is entrustment or provision depends on its facts. Korean is the governing language of the statutes cited — the English renderings here are unofficial. The counts are read from the decisions the Commission has published and change as more are published.