Key points. Article 28-8(1)(iv) of Korea's Personal Information Protection Act ("PIPA") accepts certification as a ground for a cross-border transfer, on conditions that are easy to miss. The certification must be one that the Personal Information Protection Commission ("PIPC") has designated by notice, the party that holds it must be the recipient of the data, and the protective measures the subparagraph lists must also be in place. The designated list is Annex 2 to PIPC Notice No. 2023-11. As of 5 October 2026 it has one entry, ISMS-P. ISO/IEC 27701, Binding Corporate Rules, APEC CBPR and Global CBPR are not on it. A headquarters certificate under one of those unlisted schemes is therefore not a transfer ground in Korea as of that date, although it remains useful as supporting material for the safeguards Korean law asks for.
A common exchange in the design phase of a group data flow goes like this. The Korean entity asks headquarters what the legal basis is for sending Korean personal data to the group's systems. Headquarters answers that it holds ISO/IEC 27701 certification, or approved Binding Corporate Rules, or a CBPR certification, and that most jurisdictions accept one of these.
Korean law does have a certification ground, so the answer is not unreasonable on its face. However the ground is tied to a published list, and the list can be read in full in under a minute. This note sets out what the statute requires, what the list contains as of 5 October 2026, and where to check both.
What does article 28-8(1)(iv) actually require?
Article 28-8(1) of PIPA prohibits cross-border transfers in principle and then permits them in five enumerated cases. "Transfer" here covers provision of personal data abroad (including making it available for access), entrustment of processing, and storage. Certification is the fourth of the five cases.
Subparagraph (iv) applies where the party receiving the personal data has obtained the personal information protection certification under article 32-2 of the Act, or another certification that the PIPC designates by notice, and where both of the following have been done:
- (a) the security measures necessary to protect the personal data and the measures necessary to guarantee data subjects' rights; and
- (b) the measures necessary to implement the certified matters in the country to which the personal data is transferred.
(The wording above is our paraphrase of the Korean text, not an official translation.)
Three requirements come out of that sentence. First, the certification must be the article 32-2 certification or another certification the PIPC has designated by notice. Second, the party that holds the certification must be the recipient. Third, the measures in items (a) and (b) must both be in place.
The second requirement is the one that is most easily missed. Where a Korean subsidiary sends personal data to its overseas parent, the recipient is the parent. A certificate held by the Korean subsidiary is a certificate held by the sender, which is not the position the provision describes.
What is on the list?
The Act does not name the designated certifications, apart from the article 32-2 certification it gives as an example. Article 29-8 of the Enforcement Decree sets the procedure for designating a certification by notice, and the designation itself is made in the PIPC's notice on the operation of cross-border transfers (PIPC Notice No. 2023-11, made and in force on 16 October 2023). The Notice refers to its Annex 2 for the designated certifications.
Annex 2 consists of one row.
| Certification | Period of validity | Remarks |
|---|---|---|
| ISMS-P | Not applicable | The personal information protection certification under article 32-2 of the Act |
In other words the only certification on the list is the one the statute already names as its example. The words "or another certification" in subparagraph (iv) leave room for further schemes, but as of 5 October 2026 nothing else has been entered. On that date the Notice was shown as current, in its original 2023 form, in the Ministry of Government Legislation's database, and a search of the official gazette by title from 17 October 2023 to 5 October 2026 did not find an amendment to it.
That is a statement about a date, and the position can change. Article 28 of the Notice requires the PIPC to review the Notice every three years, and the first review point fell on 14 September 2026. A review deadline does not guarantee that anything will be added or when. For that reason it is worth checking Annex 2 itself before relying on any summary of it, including this one. The Korean text is available at the National Law Information Center.
| Certification a group typically holds | On Annex 2 as of 5 October 2026? |
|---|---|
| ISMS-P (Korea) | Yes |
| ISO/IEC 27701 | No |
| Binding Corporate Rules | No |
| APEC CBPR | No |
| Global CBPR | No |
How does a certification get onto the list?
A company cannot add its certification to Annex 2 by submitting a certificate. What the procedure evaluates is the certification scheme itself, not an individual company that holds a certificate under it.
Article 29-8(1) of the Enforcement Decree requires three steps, in order, before the PIPC may designate a certification:
- an evaluation by a personal information protection certification body;
- an evaluation by the PIPC's expert committee on cross-border transfers; and
- consultation with the policy council.
Articles 11 to 14 of the Notice then set out those steps and add the PIPC's own deliberation and resolution as the final one. Annex 1 to the Notice gives the evaluation criteria under ten headings: lawful basis for processing, minimal processing, data subjects' rights, transparency, accountability, security, processing of personal data requiring special protection, breach prevention and response, cross-border transfers, and operation of the certification scheme.
Listing is also not permanent by design. Article 29-8(2) of the Enforcement Decree allows the PIPC to attach a period of validity of up to five years when it designates a certification, and article 17 of the Notice provides a procedure for removing a certification from Annex 2 where its level of protection falls short.
As of 5 October 2026 no certification scheme operated outside Korea appears on Annex 2.
Korea runs a CBPR scheme. Is that not a designation?
This is where the two questions are most often merged, and the notices themselves keep them apart.
On 3 February 2026 the PIPC made a separate notice, Notice No. 2026-1, on the operation of the cross-border privacy rules certification scheme. That notice sets out how the Global CBPR Forum's certification is run in Korea. It names the Korea Internet & Security Agency as the certification body and provides for application, assessment, a certification committee, issuance of a certificate valid for one year, and revocation. It is a notice about operating a certification scheme. It is not the notice that designates certifications for the purposes of article 28-8(1)(iv), which remains Notice No. 2023-11 and its Annex 2.
The European Commission addressed the same point in its first periodic review of the Korea adequacy decision, concluded on 23 July 2026. Its report states: "The Commission invites the PIPC to clarify that the APEC CBPR and CBPR (Cross-Border Privacy Rules) certification schemes are not recognised as a mechanism for transfers of personal data under PIPA rules" (COM(2026) 384 final, p. 5, recommendation 2). Recommendation 3 of the same report adds that it is "important that the PIPC's website clearly displays the tools that are valid for international data transfers, in both English and Korean".
A company in Korea can therefore hold a CBPR certificate issued under a Korean notice and still need a different ground for its transfers.
What is a headquarters certificate good for in Korea?
It is not without value. The limit is on what it can be cited for.
ISO/IEC 27701 certification and Binding Corporate Rules are meaningful as material showing the measures that item (a) of subparagraph (iv) describes, namely security measures and measures guaranteeing data subjects' rights. A CBPR certification has value as a way of explaining a company's privacy programme to overseas partners.
What these certificates do not do is supply the ground itself. If a privacy policy or an internal transfer record names an unlisted certification as the legal basis, the certification does not supply a ground, and the transfer needs another ground under article 28-8(1) that actually applies. If consent or the required disclosures were skipped on the strength of the certificate, that other ground may not be there. The practical step is to move the certificate from the "legal basis" column to the "supporting evidence" column and to identify the ground separately.
Which grounds are used in practice?
With subparagraph (iv) confined to ISMS-P held by the recipient, the routes that remain for most group transfers are the following.
Subparagraph (i), separate consent. The data subject gives consent specifically to the cross-border transfer, separately from other consents.
Subparagraph (iii), entrustment or storage needed for a contract with the data subject. This ground applies where entrustment of processing or storage abroad is necessary to conclude and perform a contract with the data subject, and the matters listed in article 28-8(2) have either been published in the privacy policy or notified to the data subject. Those matters are the items transferred; the country, time and method of transfer; the recipient; the recipient's purpose of use and period of retention and use; and the method, procedure and effect of refusing the transfer. Readers who work mainly under the GDPR should note that this ground is narrower than it may first appear. Korean law has no general ground corresponding to standard contractual clauses, and subparagraph (iii) is tied to entrustment and storage that a contract with the data subject requires. Whether a given flow is entrustment at all is a separate question under Korean law, discussed in Your group DPA calls us a processor. Korean law has no such slot.
Subparagraph (v), recognition of a country or international organisation. This is a decision the PIPC makes about a destination, so it is not something a company can choose to obtain. The PIPC has recognised the EU under this subparagraph with effect from 16 September 2025 (PIPC Public Notice No. 2025-68). The recognition covers the 27 EU member states and the three other EEA states, the recipient must be a controller or processor subject to the GDPR, and it does not extend to resident registration numbers or personal credit information.
Subparagraph (ii), which covers special provisions in a statute or in a treaty or other international agreement to which Korea is a party, completes the five.
Whichever ground is relied on, the disclosure and contract steps that go with that ground still have to be carried out by the Korean entity. Which ground fits a particular flow depends on the data, the recipient's role and the contract with the data subject, and the answer can differ between flows inside the same group.
Does a valid ground finish the analysis?
No. Two further layers apply.
The first is inside subparagraph (iv) itself. Even where the recipient holds a listed certification, items (a) and (b) must both be satisfied, and item (b) requires measures to carry the certified matters into the destination country.
The second applies to every ground. Article 28-8(4) of the Act and article 29-10(1) of the Enforcement Decree require protective measures, including security safeguards and measures for handling grievances and resolving disputes. Article 29-10(2) requires those matters to be agreed with the recipient in advance and reflected in the contract. Article 28-8(5) prohibits entering into a transfer contract whose terms violate the Act. The contract layer is covered in Signing the group DPA is not the whole transfer analysis, and the continuing duties towards data subjects after the data has left Korea in Erasure requests do not follow the data abroad (both are English summaries within Korean articles).
The consequences follow that split. A transfer in breach of article 28-8(1), that is, without a valid ground, is listed in article 64-2(1)(vii) as a ground for a penalty surcharge within a ceiling of 3% of total turnover. Failure to take the protective measures under article 28-8(4) is subject instead to an administrative fine of up to KRW 30 million under article 75(2)(14). Separately, article 28-9(1) allows the PIPC to order suspension of a transfer where article 28-8(1), (4) or (5) has been violated, and article 28-9(2) gives seven days from receipt of the order to object.
What to do with this
- Read the "legal basis" entry for each cross-border flow in the Korean privacy policy and in internal transfer records. Where it names a certification, check that certification against Annex 2 to Notice No. 2023-11.
- Check who holds the certificate. Subparagraph (iv) looks at the recipient, not the Korean sender.
- Where the named certification is not on Annex 2, identify the ground again from the other subparagraphs of article 28-8(1), in practice usually (i), (iii) or (v), and keep the certificate on file as supporting evidence of safeguards.
- Confirm that the article 29-10 measures were agreed with the recipient in advance and appear in the contract or its annexes.
- Date the check. Annex 2 is a list that can be amended, and a record of when it was last read is part of the answer.
Related
- Your group DPA calls us a processor. Korean law has no such slot: why entrustment and third-party provision carry different cross-border bases
- Appointing a Domestic Representative under Korea's PIPA: a separate obligation for overseas groups with Korean users
- Signing the group DPA is not the whole transfer analysis: the contract layer under article 28-8(4)
- Erasure requests do not follow the data abroad: who answers data subject requests after transfer
- Korean article on the certification list (Korean): the full version of this note, with the statutory text quoted in Korean
- English summaries: the index of English pages on this site
Frequently asked questions
Our headquarters holds ISO/IEC 27701, BCR approval or a CBPR certification. Can we rely on article 28-8(1)(iv)?
Not as the list stands. Article 28-8(1)(iv) of the Personal Information Protection Act covers only a certification that the Personal Information Protection Commission has designated by notice. The designated list is Annex 2 to PIPC Notice No. 2023-11, and as of 5 October 2026 it contains one entry, ISMS-P. ISO/IEC 27701, Binding Corporate Rules, APEC CBPR and Global CBPR are not on it. Those certificates can still serve as material showing the security measures and the measures protecting data subjects' rights that item (a) of the same subparagraph describes, but they do not themselves supply the transfer ground.
Our Korean subsidiary is ISMS-P certified. Does that cover its transfers to headquarters?
The wording of article 28-8(1)(iv) attaches the certification to the party receiving the personal data. Where the Korean subsidiary sends data to headquarters, the recipient is headquarters, so the subsidiary's own ISMS-P certificate does not sit in the position the provision describes. In that structure another ground has to be considered, such as separate consent under subparagraph (i) or the entrustment and storage route under subparagraph (iii).
Korea operates a CBPR certification scheme. Does that make CBPR a transfer ground?
The two are governed by different notices. PIPC Notice No. 2026-1, made on 3 February 2026, sets out how the Global CBPR Forum's certification scheme is operated in Korea, including the certification body and the application, assessment and issuance procedure. It does not designate that certification as a transfer ground under article 28-8(1)(iv). The designation is made in a separate notice, Notice No. 2023-11, and its Annex 2 lists only ISMS-P as of 5 October 2026.
If a listed certification is held by the recipient, is a contract still needed?
Yes. Subparagraph (iv) itself requires two further sets of measures, items (a) and (b), in addition to the certification. Separately, article 28-8(4) of the Act and article 29-10 of the Enforcement Decree require protective measures whichever ground is used, including security safeguards and measures for handling grievances and resolving disputes, and article 29-10(2) requires those matters to be agreed with the recipient in advance and reflected in the contract. Article 28-8(5) also prohibits entering into a transfer contract whose terms violate the Act.
Sources
- Personal Information Protection Act (Act No. 21445, in force 11 September 2026), articles 28-8, 28-9, 32-2, 64-2(1)(vii) and 75(2)(14): Korean text
- Enforcement Decree of the Personal Information Protection Act (Presidential Decree No. 36671, in force 11 September 2026), articles 29-8 and 29-10: Korean text
- PIPC Notice No. 2023-11 on the operation of cross-border transfers (made and in force 16 October 2023), articles 11 to 17 and 28, Annex 1 and Annex 2, read on 5 October 2026: Korean text
- PIPC Notice No. 2026-1 on the operation of the cross-border privacy rules certification scheme (made 3 February 2026)
- PIPC Public Notice No. 2025-68 (16 September 2025), recognition of the EU under article 28-8(1)(v)
- European Commission, report on the first periodic review of the Korea adequacy decision, COM(2026) 384 final (23 July 2026)
This note is a general summary of Korean law for readers outside Korea and is not legal advice; which transfer ground applies turns on the facts of a particular data flow and requires individual review. The contents of Annex 2 are stated as read on 5 October 2026 and may be amended after that date. All English renderings of Korean statutes and notices on this page are unofficial and carry no legal effect; the Korean text governs.
Written by Hyunsub Lee, a Korean-qualified lawyer at SEUM Law in Seoul (firm profile; the page opens in Korean, with an ENG switch at the top right). Questions about this page can be sent through the contact page.