핵심 요약: 파기 미이행과 국외이전 근거 미비는 사건이 없는 상태형 위반이라, 실사에서 자료를 직접 받아 대조하지 않으면 발견되지 않습니다. 무엇을 받을지는 법이 이미 정해 두었습니다. 개인정보 보호법 제30조 제1항 제3호의2의 처리방침 기재(파기절차·방법, 보존근거·보존항목)와 제28조의8 제1항의 이전 근거별 문서(동의·공개·통지·인증·인정)가 그것입니다. 다만 두 위반의 무게는 달라서, 파기 미이행은 3천만원 이하 과태료(제75조 제2항 제4호), 국외이전 근거 미비는 전체 매출액 3% 이내 과징금(제64조의2 제1항 제7호)과 이전 중지 명령(제28조의9)의 영역입니다.

인수 실사의 자료요청 목록에서 개인정보는 흔히 “관련 법령을 준수하고 있다"는 진술 한 줄로 지나갑니다. 그 한 줄이 클로징 뒤에 하는 일은 진술보증 조항을 다룬 글에서 살펴봤습니다. 그 글이 공표된 처분 이력을 확인하는 축이라면, 이 글은 드러나지 않은 위반 상태 자체를 찾는 축입니다.

개인정보 위반에는 유출처럼 사건이 터지는 사고형과, 사건 없이 이어지는 상태형이 있습니다. 실무에서 반복적으로 마주치는 상태형의 대표가 파기 미이행과 국외이전 근거 미비입니다.

상태형 위반은 왜 실사에서만 잡히나

사고형에는 시점이 있습니다. 유출이 나면 통지와 신고, 처분으로 흔적이 남으므로 인수하는 쪽이 밖에서도 확인할 수 있습니다.

상태형은 다릅니다. 지웠어야 할 데이터가 남아 있는 상태, 근거 없이 해외에서 데이터가 조회되는 상태는 뉴스에도 처분 이력에도 잡히지 않습니다. 대상회사의 자료를 직접 받아 보는 것 말고는 발견할 방법이 없습니다.

그렇다고 요청 목록을 새로 설계할 필요는 없습니다. 법이 이미 만들어 두고 밖에 알리라고 정한 문서가 곧 실사 요청 목록입니다.

파기 미이행은 무엇을 받아 보면 알 수 있나

출발점은 개인정보 처리방침입니다. 개인정보 보호법 제30조 제1항 제3호의2는 처리방침에 파기절차와 파기방법을 적게 하고, 법령상 보존 사유로 파기하지 않는 정보가 있으면 그 보존근거와 보존항목까지 적게 합니다. 회사가 스스로 공개해 둔 이 기재가 곧 대조표입니다.

다음은 실제 데이터와의 대조입니다. 제21조 제1항은 불필요해진 개인정보를 지체 없이 파기하되 다른 법령상 보존 의무가 있으면 예외로 두고, 제3항은 그렇게 보존하는 정보를 다른 개인정보와 분리하여 저장·관리하게 합니다. 파기 의무와 법정 보존기간이 충돌할 때의 기준은 따로 정리한 글이 있습니다.

주의할 점이 하나 있습니다. 민간 기업에 “파기 대장"을 만들라는 법정 의무는 없으므로, 대장을 요구하는 것은 근거가 없습니다. 처리방침의 보존근거·보존항목과 실제 남은 데이터를 대조하고, 전자 파일이 복원 불가능한 방법으로 삭제되는지(시행령 제16조 제1항)를 확인하는 것이 법이 만들어 둔 경로입니다.

국외이전은 근거마다 확인할 자료가 다르다

제28조의8 제1항은 국외이전을 원칙적으로 금지하고 다섯 가지 근거를 예외로 둡니다. 그래서 첫 질문은 회사가 어느 근거로 이전하고 있는지를 스스로 특정하게 하는 것입니다. 근거마다 확인할 자료가 다르기 때문입니다.

별도 동의(1호)라면 동의 화면에 제2항의 다섯 가지 고지 항목, 특히 거부하는 방법과 효과까지 담겼는지 봅니다. 계약 이행을 위한 처리위탁·보관(3호)이라면 처리방침 공개 또는 서면등의 통지 기록(시행령 제29조의7), 인증(4호)은 인증 사실과 부수 조치, 동등성 인정(5호)은 관보 고시(시행령 제29조의9 제6항)입니다. 동등성 인정의 구조는 EU 동등성 인정을 다룬 글에서 썼습니다.

계약서도 요청 목록에 넣습니다. 제28조의8 제4항과 시행령 제29조의10 제2항이 안전조치와 고충처리·분쟁해결 조치를 이전받는 자와 미리 협의해 계약에 반영하게 하므로, 그 반영 여부가 계약서에서 확인됩니다. 그리고 법문이 제공에 “조회되는 경우를 포함한다"고 적고 있어, 해외 본사가 한국 서버의 데이터를 열람만 해도 국외이전입니다.

두 위반의 값은 왜 다른가

파기 미이행은 과태료의 영역입니다. 제21조 제1항 위반은 3천만원 이하(제75조 제2항 제4호), 분리 저장·관리 위반은 1천만원 이하(제75조 제4항 제2호)입니다.

국외이전 근거 미비는 다른 층에 있습니다. 제64조의2 제1항 제7호가 이를 전체 매출액의 3%를 초과하지 않는 범위의 과징금 대상으로 열거하고, 제28조의9 제1항은 이전 중지 명령을 따로 둡니다. 제28조의11에 따라 이전받은 자가 제3국으로 재이전하는 구간에도 같은 규율이 준용됩니다.

결정적인 대비는 제64조의2 제1항의 열거 항목에 제21조 파기 위반이 없다는 점입니다. 체크리스트에서는 둘 다 한 줄이지만 조문이 매긴 무게는 같지 않습니다. 다만 파기되지 않고 남은 데이터는 유출 사고가 났을 때 같은 항 제9호가 적용되는 사고의 규모 자체를 키웁니다.

실사에서 못 찾으면 그다음은 어떻게 되나

상태형 위반은 클로징으로 끝나지 않고 인수 뒤에도 이어집니다. 그리고 법 제64조의2 제4항 제2호는 과징금을 부과할 때 위반행위의 기간과 횟수를 고려하게 합니다.

금액을 가늠할 때 시행령 제60조의2 제1항은 정확히 읽어야 합니다. 이 조항이 위반행위가 있었던 사업연도로 잡는 것은 기준 시점일 뿐이고, 3%가 걸리는 전체 매출액 자체는 사업 개시 3년 이상인 회사의 경우 직전 사업연도 매출액과 직전 3개 사업연도 연평균 매출액 중 큰 금액입니다. 대상회사의 매출이 최근에 뛰었다면 익스포저는 최신 숫자가 아니라 이 기준으로 잡힙니다.

실사에서 발견하고도 시정하지 않은 기간이 어느 쪽에 귀속되는지는 계약과 사안에 따라 다투어질 자리입니다. 위반 상태가 클로징 전후에 걸칠 때 구간이 어디서 끊기는지는 클로징 전 원인을 다룬 글에서 이어집니다.

본 글은 일반적인 정보 제공을 위한 것으로 법률자문이 아닙니다. 구체적 사안은 개별 검토가 필요합니다.

자주 묻는 질문

실사에서 파기 대장을 요구하면 되나요?

민간 기업에 파기 대장을 만들라는 법정 의무는 없습니다. 시행령이 대장을 정한 것은 공공기관이 목적 외로 이용·제공하는 경우이고, 파기 대장이 아닙니다. 근거 있는 경로는 처리방침에 적힌 보존근거·보존항목(법 제30조 제1항 제3호의2)과 실제로 남아 있는 데이터를 대조하는 것입니다.

해외 클라우드에 데이터를 두지 않고 본사에서 조회만 하는데도 국외이전인가요?

법 제28조의8 제1항은 국외 제공에 “조회되는 경우를 포함한다"고 명시하고 있습니다. 데이터가 한국 서버에 있어도 해외에서 조회된다면 이 조항의 이전에 해당하므로, 다섯 가지 근거 중 하나가 필요합니다.

국외이전 근거가 없는 상태를 실사에서 발견하면 금액으로는 무엇을 봐야 하나요?

조문에 놓인 항목은 세 가지입니다. 제64조의2 제1항 제7호의 전체 매출액 3% 이내 과징금(위반행위와 관련 없는 매출액은 제외, 같은 조 제2항), 제28조의9의 이전 중지 명령(이의는 7일 이내, 처리 통지는 30일 이내), 그리고 그 3%가 걸리는 전체 매출액이 얼마인가입니다. 시행령 제60조의2 제1항은 위반행위가 있었던 사업연도를 기준점으로만 삼고, 금액 자체는 사업을 개시한 지 3년 이상이면 직전 사업연도 매출액과 직전 3개 사업연도 연평균 매출액 중 큰 금액으로 잡습니다. 실제 부과 여부와 수준은 개별 사안의 판단 사항이므로 이 글에서 말할 수 없습니다.

For your deal team — English summary

투자심의위원회나 해외 인수인 측 법무에 그대로 전달할 수 있도록 아래 요약을 영문으로 붙여 둡니다.

Korean privacy diligence: the two violations that leave no trace, and the documents the statute already tells you to ask for

Incident-type privacy violations have a date. A breach in Korea produces notification, regulatory reporting and, often, a published enforcement decision, so a buyer can find it from outside the target. State-type violations produce none of that. Data that should have been destroyed but is still sitting in a table, and data that is transferred out of Korea without a lawful basis, generate no event and no record. They are found only by requesting documents from the target. The good news is that you do not need to design the request list: the statute already requires these documents to exist and, in part, to be published.

Failure to destroy: what to request. Start with the target’s privacy policy. PIPA Article 30(1)3-2 requires it to state the destruction procedure and method, and — where personal information is retained under the proviso to Article 21(1) because another statute requires retention — the retention basis and the categories of personal information retained. That published text is your reconciliation sheet. Against it, test the substance: Article 21(1) requires destruction without delay once the information is no longer necessary; Article 21(3) requires information retained under the proviso to be stored and managed separately from other personal information; and Enforcement Decree Article 16(1)1 requires electronic files to be permanently deleted by means from which they cannot be restored. One caution worth passing to whoever drafts the request list: there is no statutory obligation on a private company to maintain a destruction ledger. The ledger the Enforcement Decree prescribes applies to public institutions using or providing personal information for other purposes; it is not a destruction ledger, and asking a private target for one has no statutory basis.

Cross-border transfer: the document you need depends on which basis the target is relying on. Article 28-8(1) prohibits transfer out of Korea in principle, and defines the covered acts as provision, outsourcing of processing, and storage — with provision expressly stated to include the case where the information “is viewed” from outside Korea. Five exceptions follow: (1) separate consent from the data subject; (2) a special provision in a statute, or in a treaty or international agreement to which Korea is a party; (3) outsourcing or storage necessary to conclude and perform a contract with the data subject, where either (a) the Article 28-8(2) items are disclosed in the privacy policy or (b) they are notified to the data subject in writing or an equivalent form (Enforcement Decree Article 29-7); (4) certification of the transferee recognized by the Personal Information Protection Commission, where both accompanying measures under item 4 are in place; and (5) PIPC recognition that the destination country or international organization affords a level of protection substantially equivalent to PIPA, which is published in the Official Gazette (Enforcement Decree Article 29-9(6)). So the first question is not “do you transfer data abroad” but “under which of these five do you transfer it” — the answer determines what you ask for next. If the answer is consent, review the consent screen against the five items in Article 28-8(2), particularly item 5, the method, procedure and effect of refusing. Ask for the transfer contracts as well: Article 28-8(4), read with Enforcement Decree Article 29-10(1) and (2), requires safety measures and complaint-handling and dispute-resolution measures to be agreed in advance with the transferee and reflected in the contract, so their presence or absence is visible on the face of the document. Article 28-11 applies the same regime to onward transfer by the transferee to a third country.

For groups with a Korean subsidiary, note the “is viewed” language. Because Article 28-8(1) counts viewing as provision, headquarters read-access to data resident on Korean servers is a cross-border transfer requiring one of the five bases. Architectures built specifically to keep data in Korea do not, by themselves, take the arrangement outside the provision.

The two findings are not priced the same, and the diligence checklist should not treat them as one line. Failure to destroy under Article 21(1) carries an administrative fine of up to KRW 30 million (Article 75(2)4); failure to store retained data separately under Article 21(3), up to KRW 10 million (Article 75(4)2). Transfer without a lawful basis sits in a different tier: Article 64-2(1)7 makes it subject to a surcharge of up to 3% of total sales — up to KRW 2 billion where there are no sales or sales cannot be calculated — with sales unrelated to the violation excluded from the base (Article 64-2(2)). Failure to comply with a suspension order is separately enumerated at Article 64-2(1)8, and the PIPC may order suspension of the transfer under Article 28-9(1), with objection due within 7 days (Article 28-9(2), Enforcement Decree Article 29-12(1)) and written notice of the outcome within 30 days (Enforcement Decree Article 29-12(2)). The decisive contrast is what is absent: none of the nine items in Article 64-2(1) refers to Article 21. Failure to destroy is not surcharge territory. What it does do is enlarge a later breach, to which Article 64-2(1)9 does apply.

Sizing the exposure: “total sales” is not the violation year’s revenue. Enforcement Decree Article 60-2(1)1 uses the business year in which the violation occurred only as the reference point. For a target that has been in business for three years or more as of the first day of that year, total sales is the greater of the preceding business year’s sales or the annual average sales of the preceding three business years; items 2 through 4 set separate formulas for shorter operating histories. For a fast-growing target this is the difference between two materially different numbers, and the statute does not use the most recent one. Article 64-2(4) also requires the PIPC to consider the period and frequency of the violation, which is why a state-type violation identified in diligence and left uncorrected keeps accruing after closing. How that post-closing period is allocated between the parties is a matter for the agreement and the facts, not something the statute settles.

Which English text to cite — and which to avoid. Statutory terms above follow the English translation of PIPA published by the Korea Ministry of Government Legislation: Act No. 20897, in force 2 October 2025, at law.go.kr. Two cautions if your team looks these provisions up independently:

  • The Enforcement Decree provisions cited above have no English translation. The decree in force is Presidential Decree No. 36340 (19 May 2026), and law.go.kr does not carry an English text for it. Searching an English decree for Articles 16, 29-7, 29-9, 29-10, 29-12 or 60-2 as cited here will not return the current wording.
  • Avoid the copy hosted at elaw.klri.re.kr. It ranks well in search, but the version served there is Act No. 16930 of 2020, which does not contain Article 28-8 at all — the provision that governs cross-border transfer and carries the 3% surcharge. Under that older text, overseas provision reads as a consent-only regime, which is no longer the law.

All English translations of Korean statutes are unofficial and carry no legal effect; the Korean text governs.

Written by Hyunsub Lee, partner at SEUM Law (Seoul). Principal practice areas: IT, personal information and data, and startup advisory. This summary is general information on Korean law and is not legal advice; conclusions depend on the facts of each case. Full article in Korean: datalaw.kr.

참고 자료

  • 개인정보 보호법(법률 제20897호, 시행 2025. 10. 2.) 제21조, 제28조의8, 제28조의9, 제28조의11, 제30조 제1항, 제64조의2, 제75조
  • 개인정보 보호법 시행령(대통령령 제36340호, 2026. 5. 19.) 제16조, 제29조의7, 제29조의9, 제29조의10, 제29조의12, 제60조의2