- 기업 · 스타트업
- 국제법무
- 가상자산 (디지털자산)
- VC · 금융
- IP · 기술
- 스포츠
- Education
- 뉴욕대학교(NYU) 정치학과 인하대학교 법학전문대학원 포스텍 블록체인 전문가과정
- Experience
- 여성가족부 고문 변호사 법무법인 평안(기업소송, 가상자산, 형사, 개인정보) 주식회사 차이코퍼레이션(블록체인,핀테크,IT) 김앤장 법률사무소 실무 법무법인 율촌 실무 주식회사 대한항공 실무
- Licenses
- 변호사(대한민국) 마이데이터관리사 블록체인법학회 정회원
- Languages
- 한국어 영어
- CASES
-
-
[기업/스타트업]
기업형사, 대표이사의 배임, 횡령, 마약, 성범죄 사건 등 소송
국내외 중견기업 및 스타트업 손해배상 기업소송 및 자문
M&A, 법률실사, 투자계약, VC/PE 기업 법률 자문
스타트업 투자계약, 이용약관, 개인정보 법률 자문
기업 간 분쟁해결 및 민형사 소송
[국제법무]
다국적 국제 민사, 형사, IP 분쟁 해결 및 소송
싱가포르, BVI, 스위스 법인 설립 및 은행 계좌 개설
국제 전기차 T사와의 영문 공급 계약서 검토 및 자문
국제 음반사 W사의 영문 계약서 작성, 검토, 번역 등
핀테크 기업 K사의 영문 계약서 등 작성, 검토, 번역 등
[가상자산]
국내 최대 가상자산 투자사 H사의 종합 세무진단 자문
가상자산 발행 P2E 법인 P의 사업 구조 종합 컨설팅 자문
가상자산 발행 법인 B사의 ICO, SAFT, 거래소 인수 계약 진행
가상자산 및 NFT 발행 법인의 백서 검토 및 자문
가상자산 알고리즘 트레이딩 U사, B사의 세무조사 대응 자문
K법인의 NFT 거래 플랫폼 사업 모델 구조 검토 및 자문
-
Civil Litigation
Jeonse Deposit Return Lawsuit: Plaintiff Prevails Against New Owner After Property Transfer
Client Information Individual / Plaintiff Case Details The client entered into a jeonse, or lump-sum deposit lease, for a residential property. After paying the deposit, the ...
Judgment Fully in Favor of the Plaintiff -
Crypto Litigation
Fraud Allegations Involving a Crypto Trading Signal Room and Referral Program — Case Closed Without Referral to Prosecutors
Client Information Individual / Suspect Case Details The client worked for a company that provided cryptocurrency-related information and was responsible for assisting prospe...
Police Non-Referral Decision -
가상자산 (디지털자산) Litigation
코인리딩방·레퍼럴 사기 혐의, 역할과 자금 흐름 소명으로 불송치 결정
의뢰인 정보 개인 / 피의자 의뢰 내역 의뢰인은 가상자산 관련 정보를 제공하는 업체에서 회원 가입과 해외 거래소 이용 방법...
불송치 결정 -
기업 · 비즈니스 Advisory
유사투자자문업 전문가 근로계약서, 업무 범위와 책임 구조 정비 자문
의뢰인 정보 기업 / 당사자 의뢰 내역 의뢰인은 불특정 다수의 회원을 대상으로 투자정보 콘텐츠를 제공하는 유사투자자문업체로...
근로계약서 검토
Related News
-
BlogsEU AI법(AI Act) 제50조 표시의무와 한국 기업의 대응 방안
생성형 AI로 광고 이미지나 홍보 영상을 제작하고, AI가 작성한 글을 홈페이지에 게시하는 한국 기업이 늘고 있습니다. EU 시장을 대상으로 하는 콘텐츠라면, 하단에 짧은 문구 하나를 추가하는 것만으로 의무를 다했다고 보기 어려운 경우가 있습니다. EU 「인공지능법(AI Act)」 제50조의 표시의무는 2026년 8월 2일부터 적용됩니다. 유럽집행위원회는 2026년 7월 20일 해당 조문의 적용 범위와 예외를 구체화한 최종 가이드라인을 채택했습니다. 1. 제공자와 배포자의 의무 구분 EU AI법은 기업이 AI 가치사슬에서 어떤 역할을 담당하는지에 따라 적용되는 의무를 다르게 규정합니다. AI 시스템 제공자는 AI 시스템을 개발하거나 개발을 의뢰한 뒤, 자신의 명칭이나 상표로 EU 시장에 공급하거나 업무에 투입하는 사업자를 말합니다. 생성형 AI 서비스나 이미지·영상 생성 솔루션을 자체 개발해 제공하는 기업이 대표적입니다. 다른 사업자의 AI 모델을 자사 서비스에 통합해 자신의 명칭으로 공급하는 경우에는, 단순 이용자가 아니라 제공자로 평가될 가능성도 함께 검토해야 합니다. AI 시스템 배포자는 자신의 권한 아래 AI 시스템을 업무 목적으로 이용하는 기업이나 기관입니다. 생성형 AI로 광고 이미지나 홍보 영상을 만들거나, AI가 작성한 글을 홈페이지에 게시하는 경우가 여기에 해당할 수 있습니다. 직원이 회사 지시에 따라 AI를 사용했다면 직원 개인이 아니라 회사가 배포자로 평가됩니다. 반면 자연인이 순수하게 개인적·비직업적 목적으로 AI를 이용하는 경우에는 배포자 의무가 적용되지 않습니다. 구분 제공자 의무 배포자 의무 표시 대상 AI 생성물 자체 딥페이크, 공익 관련 AI 텍스트 표시 방식 기계 판독 가능한 메타데이터 이용자가 인식 가능한 문구·아이콘·음성 안내 확인 주체 시스템·플랫폼 사람 2. 제공자의 기계 판독 가능한 표식 의무 합성 음성·이미지·영상·텍스트를 생성하는 AI 시스템의 제공자는 결과물이 AI에 의해 생성되거나 조작됐다는 사실을 기술적으로 탐지할 수 있도록 해야 합니다. 여기서 말하는 표식은 사람이 화면에서 직접 확인하는 문구와는 다릅니다. 메타데이터, 콘텐츠 출처 정보 등 기계 판독 가능한 방식을 결과물에 적용해야 하며, 콘텐츠 특성과 기술 수준을 고려해 효과적이고 상호운용 가능하며 견고하고 신뢰할 수 있어야 합니다. 다음과 같은 결과물은 표시 의무가 적용되지 않거나 제한적으로만 적용될 수 있습니다. ▪️ 짧은 숫자·기호·문자열: 표시 대상으로서 실익이 크지 않은 짧은 결과물 ▪️ 소스코드: 프로그래밍 언어로 작성된 결과물 ▪️ 시스템 간 자동 처리 결과물: 사람에게 노출되지 않고 시스템 간에만 자동으로 처리되는 결과물 ▪️ 폐쇄된 제작 환경의 중간 산출물: 최종 결과물이 아닌 제작 과정상의 중간 산출물 ▪️ 원본의 의미를 실질적으로 변경하지 않는 편집 기능: 맞춤법 교정 등 보조적 편집 기능의 결과물 다만 기업 간 거래나 산업 환경에서만 쓰이는 결과물이라 해도 가이드라인이 정한 조건을 충족하지 못하면 예외가 인정되지 않을 수 있습니다. 모든 B2B용 AI 결과물이 일률적으로 표시 의무에서 제외되는 것은 아니므로 개별 결과물의 성격에 따른 판단이 필요합니다. 3. 배포자의 공개 의무: 딥페이크와 공익 텍스트 제공자가 기술적 표식을 적용했다고 해서, AI를 이용하는 기업이 모든 결과물에 사람이 볼 수 있는 표시 문구를 붙여야 하는 것은 아닙니다. 배포자의 공개 의무가 발생하는 대표적인 대상은 딥페이크와 공익 관련 AI 텍스트입니다. 딥페이크란 AI로 생성하거나 조작한 이미지·음성·영상이 실제 인물, 사물, 장소, 단체 또는 사건과 유사하고, 사람에게 진짜이거나 사실인 것처럼 보일 수 있는 콘텐츠를 말합니다. 단순히 AI로 제작됐다는 사실만으로 모든 이미지·영상이 딥페이크에 해당하는 것은 아니며, 실제 대상과의 유사성, 콘텐츠가 전달하는 실질적인 메시지, 콘텐츠가 게시되는 환경, 예상 이용자가 진짜라고 받아들일 가능성을 함께 고려해 판단합니다. 예를 들어 실제 대표자의 얼굴과 음성을 합성해 마치 대표자가 직접 말한 것처럼 만든 홍보 영상은 딥페이크 표시 대상이 될 가능성이 높습니다. 반면 이용자가 처음부터 허구나 연출임을 명확히 인식할 수 있는 콘텐츠는 판단이 달라질 수 있습니다. 예술·창작·풍자·허구 작품에 딥페이크가 포함된 경우에도 공개 의무가 완전히 사라지지는 않으며, 작품의 전시나 감상을 방해하지 않는 적절한 방식으로 표시할 수 있습니다. 결국 딥페이크 여부는 AI로 만들었는지 여부보다, 실제처럼 보여 이용자를 속일 가능성이 있는지를 기준으로 판단됩니다. 4. 공익 관련 AI 텍스트의 표시 범위 AI가 생성하거나 조작한 텍스트를 공익에 관한 정보를 대중에게 제공할 목적으로 게시하는 경우에도 표시 의무가 발생할 수 있습니다. 다음과 같은 분야가 대표적입니다. ▪️ 정치와 민주적 절차 ▪️ 행정과 공공서비스 ▪️ 사법제도와 법 집행 ▪️ 기본권과 공공안전 ▪️ 공중보건과 환경 ▪️ 소비자 안전 ▪️ 경제·금융·과학·문화 관련 주요 현안 AI가 작성한 뉴스 기사, 정책 설명, 금융시장 분석, 법률·행정 정보를 사람의 검토 없이 자동 게시한다면 표시 대상이 될 수 있습니다. 다만 상품 설명, 일반적인 홍보 문구, 개인적인 게시물 등 모든 AI 생성 텍스트가 자동으로 공익 관련 텍스트에 해당하는 것은 아니며, 게시 목적과 내용, 예상 독자를 구체적으로 살펴야 합니다. 5. 사람의 실질적 검토와 예외 요건 공익에 관한 AI 생성 텍스트라도 다음 요건을 충족하면 별도의 표시 의무가 적용되지 않을 수 있습니다. 첫째, 콘텐츠가 사람의 실질적인 검토 또는 편집 통제를 거쳐야 합니다. 둘째, 자연인이나 법인이 해당 콘텐츠 게시에 대한 편집 책임을 부담해야 합니다. 다만 담당자가 맞춤법이나 문법만 확인하는 형식적인 검수는 실질적 검토로 인정되지 않습니다. 최종 가이드라인 역시 단순한 맞춤법 검사나 절차적 확인만으로는 사람의 검토·편집 통제로 보기 어렵다고 설명하고 있습니다. 실질적인 검토로 인정받으려면 담당자가 다음과 같은 권한과 책임을 실제로 행사해야 합니다. ▪️ 내용의 수정·승인 또는 게시 거절 권한 ▪️ 사실관계와 출처 확인 ▪️ 법률·정책적 내용의 적정성 검토 ▪️ 최종 게시 여부 결정 ▪️ 게시된 내용에 대한 편집상·법률상 책임 부담 기업은 내부 지침에 담당자가 검수한다고 기재하는 데 그치지 않고, 누가 어떤 기준으로 검토하고 승인했는지 기록이 남도록 운영할 필요가 있습니다. 6. 표시 위치·방식과 EU 아이콘 딥페이크나 공익 관련 AI 텍스트에 공개 의무가 적용된다면, 이용자가 콘텐츠에 처음 노출되는 시점에 AI 생성 또는 조작 사실을 확인할 수 있어야 합니다. 표시는 다른 정보와 구분돼야 하고, 명확하고 인식 가능한 방식으로 제공해야 하며, 장애가 있는 이용자를 위한 접근성 요건도 고려해야 합니다. 실무적으로는 이미지 주변에 AI 생성·수정 문구를 표시하거나, 영상 시작 부분이나 화면에 표시 문구를 삽입하거나, 합성 음성 재생 전 음성 안내를 제공하거나, AI 생성 텍스트 상단이나 제목 주변에 표시하는 방식이 활용될 수 있습니다. EU는 AI 생성·조작 콘텐츠 표시에 활용할 수 있는 아이콘을 「AI 생성 콘텐츠 투명성 행동규범」을 통해 공개했습니다. AI가 제작에 관여한 콘텐츠, AI로 전부 생성된 콘텐츠, AI로 일부 수정된 콘텐츠를 구분하는 형태입니다. 다만 EU 아이콘 사용은 의무가 아니라 선택사항입니다. 아이콘을 쓰지 않아도 법이 요구하는 수준으로 명확하게 표시하면 되고, 반대로 아이콘을 사용했다는 사실만으로 표시 의무를 모두 이행했다고 인정되는 것도 아닙니다. 제공자가 콘텐츠 내부에 기계 판독 가능한 메타데이터를 넣었다는 사실만으로 배포자의 공개 의무까지 자동으로 이행되는 것은 아닙니다. 제공자는 기술적으로 탐지 가능한 표식을, 배포자는 이용자가 실제로 알아볼 수 있는 공개를 각각 책임집니다. 7. 시행 전 콘텐츠의 소급 적용 여부 AI법 제50조는 2026년 8월 2일부터 적용되며, 소급 적용 여부는 콘텐츠 유형에 따라 기준이 다릅니다. 이미지·음성·영상 딥페이크의 경우, 2026년 8월 2일 전에 생성 또는 조작된 결과물은 그 이후 게시되더라도 소급하여 표시할 의무가 없습니다. 기준 시점은 생성일자입니다. 반면 공익 관련 AI 텍스트는 기준 시점이 게시일자입니다. 시행일 전에 작성됐더라도 2026년 8월 2일 이후 처음 게시된다면 표시 대상이 될 수 있으며, 사람의 실질적 검토·편집 책임 요건을 충족하는 경우에만 예외가 인정됩니다. 시행 전에 게시했던 콘텐츠를 시행일 이후 새로운 광고나 게시물에 다시 활용하는 경우, 단순 보관과 새로운 배포를 구분해 판단해야 하며 사안별 검토가 필요합니다. 8. 전환기간(Digital Omnibus)의 확정 현황 원칙적으로 제50조 대상 AI 시스템은 시장 출시 시점과 관계없이 2026년 8월 2일부터 표시 의무를 준수해야 합니다. 다만 EU가 추진해 온 AI 규제 간소화 규정(Digital Omnibus)에 따라, 2026년 8월 2일 전에 시장에 공급되거나 사용된 생성형 AI 시스템의 기계 판독 가능한 표식 의무(제50조 제2항)에 한해 2026년 12월 2일까지 전환기간이 부여될 예정입니다. 해당 개정 규정은 유럽의회와 이사회의 채택 절차를 마쳤으나, 관보(Official Journal) 게재를 통한 정식 발효는 아직 완료되지 않은 상태입니다. 따라서 기업은 2026년 12월까지 무조건 유예된다고 전제해서는 안 되며, 최종 발효 여부와 시행일을 별도로 확인하되 원칙적으로는 2026년 8월 2일 적용을 기준으로 준비하는 것이 안전합니다. 9. 한국 기업의 역외 적용 가능성 EU AI법은 EU에 설립된 기업에만 적용되는 법률이 아닙니다. EU 외부의 사업자라도 EU 시장에 AI 시스템이나 범용 AI 모델을 공급하는 경우, EU에서 AI 시스템을 사용하도록 제공하는 경우, EU 외부 제공자·배포자의 AI 결과물이 EU에서 사용되는 경우에는 적용 대상이 될 수 있습니다. 한국 기업이 EU 이용자를 대상으로 AI 서비스를 제공하거나, 한국에서 생성한 AI 콘텐츠를 EU 법인·고객·플랫폼을 통해 사용하는 경우에는 적용 가능성을 검토해야 합니다. 다만 EU 거래처가 있거나 홈페이지가 EU에서 접속 가능하다는 사정만으로 모든 기업에 제50조가 적용된다고 단정할 수는 없으며, AI 시스템·결과물이 EU 시장에서 어떤 방식으로 공급·사용되는지를 중심으로 판단해야 합니다. 10. 위반 시 과징금 규모 AI법 제50조를 포함한 일반적인 의무를 위반하면 최대 1,500만 유로 또는 직전 회계연도 전 세계 연간 총매출액의 3% 중 더 높은 금액까지 행정상 과징금이 부과될 수 있습니다. 기업이 중소기업(SME)에 해당한다면 정액 기준과 매출액 비율 기준 중 더 낮은 금액이 상한으로 적용됩니다. 실제 과징금은 위반의 성격과 기간, 피해 규모, 고의·과실 여부, 기업 규모, 시정조치와 감독기관에 대한 협조 여부 등을 고려해 결정됩니다. 디센트 법률사무소 국제법무팀 조력 EU AI 생성물 표시 의무는 모든 AI 콘텐츠에 일률적으로 'AI 생성' 문구를 붙이는 제도가 아닙니다. AI 시스템 제공자는 기술적 표식 적용 여부를 확인해야 하고, AI로 콘텐츠를 게시하는 기업은 해당 콘텐츠가 딥페이크 또는 공익 관련 텍스트에 해당하는지부터 판단해야 합니다. 특히 사람의 검토를 이유로 예외를 적용하려면 실질적인 검토·편집 통제와 함께 게시물에 대한 편집 책임이 함께 존재해야 합니다. 결국 이 문제는 표시 문구 하나를 붙이는 문제가 아니라, 콘텐츠 분류 기준과 검토 절차를 갖추는 운영 체계의 문제라고 볼 수 있습니다. 디센트 법률사무소 국제법무팀은 EU 시장을 대상으로 AI 서비스·콘텐츠를 제공하는 한국 기업을 위해 다음과 같은 실무 대응을 지원합니다. ▪️ AI 콘텐츠 이용 현황 진단 및 제공자·배포자 지위 판단 ▪️ 딥페이크·공익 텍스트 표시 대상 콘텐츠 분류 기준 수립 ▪️ 사람의 실질적 검토·편집 책임 체계 설계 및 내부 문서화 지원 ▪️ AI 솔루션·외주업체 계약서 검토 및 표시 책임 조항 정비 ▪️ EU AI법 역외 적용 가능성 검토 및 대응 전략 자문 2026년 8월 2일 시행을 앞두고 AI 콘텐츠 게시 현황을 점검하고 싶으시다면, 국제법무팀과 먼저 논의해 보시기 바랍니다. 본 콘텐츠는 일반적인 법률 정보 제공을 목적으로 하며, 개별 사건에 대한 법률 조언을 구성하지 않습니다.
2026-07-24 -
Blogs성범죄피해자대리, 신고하면 끝나는 일이 아닙니다.
성범죄피해자대리, 법적으로는 어떤 의미일까요 성범죄피해자대리는 성범죄 피해자가 형사 절차 전반에서 변호사를 통해 자신의 권리를 행사하도록 하는 제도를 의미합니다. 관련 법령 규정에 따라 피해자 국선변호사 제도를 통한 지원 가능 경찰·검찰 조사 동석, 증거 수집 조력, 합의 및 손해배상 협상까지 전 과정 지원 가해자 측 변호인의 부당한 압박이나 회유로부터 피해자의 절차상 권리 및 권익 보호 이처럼 성범죄피해자대리는 단순히 조사에 동행하는 것을 넘어, 피해자가 2차 피해 없이 절차를 마칠 수 있도록 돕는 실질적인 법률 조력입니다. 신고부터 재판까지, 어떤 절차로 진행되나요 성범죄피해자대리를 통해 진행되는 사건은 통상 다음과 같은 절차를 거칩니다. 신고 및 고소장 접수 - 경찰서 등에 피해 사실 신고 및 고소장 제출 피해자 조사 - 대리인 동석 하에 진술 및 증거 제출 수사기관의 수사 - 가해자 조사, 증거 감정, 참고인 조사 진행 사건 송치 및 기소 여부 결정 - 경찰의 송치 후 검사의 기소 또는 불기소 처분 공판 진행 및 배상명령 신청 - 재판 참여, 형사조정, 요건 충족 시 배상명령 신청을 통한 피해 회복 이 과정에서 초기 진술의 일관성과 증거 보전이 사건 결과에 결정적인 영향을 미치기 때문에, 신고 직후부터 법률적 조력을 받는 것이 매우 중요합니다. 실제 사례로 보는 성범죄피해자대리 [실제 사례] 20대 여성 B씨는 직장 내 성추행 피해를 입고 신고를 망설이다 뒤늦게 고소장을 제출했습니다. 이에 시간이 지나 증거가 부족한 상황이었지만, 디센트 법률사무소의 도움을 받아 정황 증거를 체계적으로 정리하고 조사 과정에서 2차 가해성 질문에 적절히 대응한 끝에 가해자에 대한 기소 처분을 이끌어낼 수 있었습니다. 이처럼 성범죄피해자대리 사건은 초기 대응과 증거 정리 여부에 따라 결과가 크게 달라질 수 있습니다. 변호인의 역할, 그리고 디센트와 함께해야 하는 이유 성범죄피해자대리 사건은 다음과 같은 전문적인 대응이 요구되는 분야입니다. 조사 동석을 통한 2차 가해 방지 및 심리적 안정 지원 증거 수집 및 진술 조력을 통한 사건 입증력 강화 합의, 손해배상, 형사조정 등 후속 절차 전략 수립 디센트 법률사무소는 다수의 성범죄 피해자 대리 사건을 다뤄온 경험을 바탕으로 의뢰인의 상황을 면밀히 분석하고, 신고 초기 단계부터 재판, 배상까지 체계적인 지원 전략을 수립합니다. 피해로 인해 심리적으로 위축되어 있는 의뢰인이 절차 안에서 또다시 상처받지 않도록, 처음부터 끝까지 곁에서 함께합니다. 성범죄피해자대리는 시간이 지날수록 증거 확보와 대응이 어려워지는 대표적인 사건 유형입니다. 이미 피해를 입었거나 신고를 앞두고 있다면, 혼자 판단하기보다 성범죄 사건 경험이 풍부한 변호인과 먼저 상담하시길 권해드립니다. 디센트 법률사무소는 언제든 신속하고 정확한 법률 상담으로 여러분의 상황에 맞는 최선의 방향을 함께 찾아드리겠습니다.
2026-07-24 -
BlogsGenerative AI and Personal Data: What Businesses Should Check Before Uploading Customer Information or Contracts
Businesses are increasingly using generative AI to review contracts, summarize meetings, respond to customer inquiries, and draft documents. However, when contracts or other materials entered into an AI service contain personal data relating to customers or employees, the issue extends beyond operational efficiency. It may raise concerns regarding personal data processing, confidentiality, and the management of internal business information. Businesses should therefore understand how an AI service stores and uses input data and establish internal rules that reflect how generative AI is actually used within the organization. How Is Information Entered into Generative AI Processed? From the user’s perspective, generative AI appears to involve simply entering a question and receiving a response. In practice, however, prompts and uploaded files are transmitted to the service provider’s systems. Depending on the service policy and account type, they may be retained as conversation records or system logs and may also be used to improve the service. Before entering business materials, companies should check: ▪️ Whether input data may be used to train the AI model ▪️ How long conversations and uploaded files are retained ▪️ Whether conversations and uploaded materials can be deleted ▪️ In which country and on which servers the data is processed ▪️ What access permissions are granted when the AI is connected to external applications or internal systems Using a paid or enterprise account does not automatically resolve every data protection issue. The relevant contractual terms and actual data-processing arrangements must also be reviewed. Is Information No Longer Personal Data Once the Name Is Removed? Removing a customer’s name or contact information from a contract does not necessarily mean that the remaining information is no longer personal data. Personal data includes not only information that directly identifies an individual, such as a name, but also information that may identify a person when combined with other readily available information. Even after a name has been removed, an individual may still be identifiable through a combination of information such as: ▪️ The company name and a specific job title ▪️ The contract date and transaction amount ▪️ The employee’s department and performance evaluation ▪️ Detailed consultation history and family relationships ▪️ A case number and the location of a dispute A company name alone is generally information about a legal entity. However, when combined with a specific position, transaction details, or other contextual information, it may make an individual employee or representative identifiable. Businesses should therefore remove information that is unnecessary for the intended task rather than deleting names alone. Actual names, contact details, company names, and similar identifiers may also need to be replaced with fictional or generic information. Does Entering Customer Information Automatically Violate Korea’s Personal Information Protection Act? Entering customer information into a generative AI service does not automatically constitute a violation of Korea’s Personal Information Protection Act, commonly referred to as the PIPA. However, a business may generally use personal data only within the scope of the original purpose of collection and an appropriate legal basis. It is therefore necessary to assess whether the intended AI use is related to the original processing purpose and whether additional consent or another legal basis is required. The relationship between the business and the AI service provider must also be reviewed. The applicable legal framework may differ depending on whether the provider processes data solely on the company’s instructions or also uses the input data for its own purposes, such as model training or service improvement. Depending on the actual arrangement, the use of the service may involve outsourced processing, third-party provision, or other forms of data processing. If personal data is transferred to servers or service providers located outside Korea, the requirements governing overseas transfers must also be considered. The applicable rules cannot be determined solely from the fact that customer information was entered into an AI service. Businesses should review the actual contractual structure and data flow, including: ▪️ The legal basis for using personal data in the relevant AI task ▪️ The purposes for which the service provider uses input data ▪️ Whether the data is used for training or service improvement ▪️ The data-retention period and deletion procedures ▪️ The server locations and countries to which data is transferred ▪️ The involvement of subprocessors or downstream service providers ▪️ How input data is handled after the service contract ends Contracts and Consultation Records Raise More Than Personal Data Issues Contracts and customer consultation records may contain confidential business information in addition to personal data. Examples include: ▪️ Transaction terms and supply prices ▪️ Sales strategies and business plans ▪️ Technical materials and development information ▪️ Confidentiality obligations agreed with customers or business partners ▪️ Strategies for litigation, investigations, or other disputes ▪️ Non-public financial information and internal decision-making materials Entering such information into an external generative AI service may raise issues under the PIPA, but it may also create risks involving contractual confidentiality obligations, trade secret protection, customer security agreements, and internal company policies. A corporate generative AI policy should therefore cover not only personal data but also trade secrets, contractual information, technical materials, and dispute-related documents. Internal Rules Businesses Should Establish for Generative AI Use When employees are left to decide individually how generative AI should be used, the company may be unable to identify what information has been entered into which external service. Rather than issuing a general instruction not to enter personal data, businesses should establish practical and specific rules that employees can follow in their day-to-day work. 1. Approved Services and Accounts The company should designate the generative AI services and account types that employees are permitted to use. Employees should also be prohibited from entering business materials through personal accounts or unapproved services. 2. Prohibited Input Data The company should clearly define the information that must not be entered into generative AI services. This may include resident registration numbers, bank account information, health information, other sensitive or high-risk personal data, trade secrets, non-public contractual terms, and materials relating to litigation or criminal investigations. 3. Approval Procedures for High-Risk Documents High-risk materials, such as contracts, human resources documents, and customer consultation records, may be made subject to prior review or approval by the responsible department. 4. Standards for Removing or Replacing Identifying Information Businesses should establish standards for removing or replacing information that could identify an individual or a transaction party, including names, contact details, company names, and transaction amounts. Rather than uploading an entire contract, employees should extract only the clauses required for the relevant task. Actual customer information may also be replaced with fictional names or sample data. 5. Conversation History and Model-Training Settings The company should determine whether the service allows input data to be excluded from model training, whether conversation history can be disabled, and how deletion features operate. 6. Internal Reporting and Incident Response Employees should be required to report promptly if personal data or confidential business information is entered into an AI service by mistake. The company should also establish procedures for deleting records, disabling external integrations, requesting deletion from the service provider, and taking any other necessary measures. What Should a Business Do If Customer Information Has Already Been Entered? If an employee mistakenly enters customer information or an internal document into a generative AI service, the company should first stop any further sharing or use of the resulting output. The following matters should then be reviewed: ▪️ Which account and AI service were used ▪️ What personal data or confidential information was entered ▪️ Whether the conversation and uploaded files can be deleted ▪️ Whether the service was connected to any external applications ▪️ Whether the information may have been used for training or service improvement ▪️ Whether a third party may have gained access to the information Where necessary, the company should delete the conversation history and uploaded files, revoke external access permissions, and request that the service provider stop processing or delete the relevant information. Whether the incident requires a personal data breach report or notification to affected individuals should be determined by considering the type and volume of information involved, the possibility of third-party access, whether the data has been deleted, and the potential harm to the individuals concerned. Effective Generative AI Use Requires Governance, Not Just Prohibition Generative AI can improve efficiency in contract review, document drafting, and customer communications. However, when its use is left entirely to individual employees, a business may have little control over where customer information and internal documents are transmitted or how they are subsequently used. Businesses should establish specific rules regarding approved services, prohibited data, the removal or replacement of identifying information, approval procedures for high-risk documents, and incident response. Decent Law Firm advises businesses on the legal use of generative AI, including compliance with Korean personal data protection requirements, review of service terms and data-processing agreements, overseas data transfers, trade secret protection, and the preparation of internal AI-use policies. This content is provided for general informational purposes only and does not constitute legal advice regarding any specific matter or business.
2026-07-24