We Resolve Legal Matters
How can we assist you?
Blogs
More-
Commercial Lease and Change of Use in Korea: Can the Lease Be Terminated If Business Operations Are Not Permitted?
A tenant may sign a commercial lease intending to operate a restaurant, café, convenience store, academy, or other specific business, only to later discover that the premises cannot legally be used for that purpose. This may occur because the building’s registered use does not permit the intended business, the required change of use cannot be approved, or separate business licensing requirements cannot be satisfied. In such cases, the landlord is not automatically liable simply because the change of use is unsuccessful. Whether the tenant may terminate the lease, recover the security deposit, or claim damages depends on factors such as the agreed purpose of the lease, the reason the intended business cannot operate, any contractual allocation of responsibility for permits and change-of-use procedures, and the representations made by the landlord before the lease was signed. Contents When a Change of Use Is Required What to Check Before Signing a Commercial Lease Landlord Liability When a Change of Use Is Not Possible Lease Termination and Return of the Security Deposit Damages for Interior and Business Preparation Costs Recommended Commercial Lease Clauses Frequently Asked Questions Key Takeaways on Commercial Leases and Change of Use 1. When Is a Change of Use Required for Commercial Premises? If the current registered use of a building differs from the tenant’s intended use, it is necessary to determine whether a change-of-use procedure is required under the Korean Building Act. Article 19 of the Building Act requires a building whose use is changed to comply with the building standards applicable to the intended new use. Depending on the type of change, approval, reporting, or an application to amend the building register may be required. [Article 19 of the Building Act – Change of Use] However, a change of use under the Building Act and a business-specific license or registration are separate legal issues. Even if the registered building use can be changed, the premises may still fail to satisfy requirements applicable to a restaurant, academy, or other regulated business. A prospective tenant should therefore confirm not only the current use shown on the building register but also whether the intended business can legally operate at the premises. 2. What Should Be Checked Before Signing a Commercial Lease? Before signing a commercial lease, the tenant should verify the registered use of the premises, whether the intended business can operate there, and who will bear responsibility for any change of use or licensing process. 🔹Key Checks Before Signing a Commercial Lease Item What to Check Building Register Current registered use of the premises Intended Business The specific business to be operated Change of Use Whether the required change can legally be made Building Standards Parking, fire safety, structural, and other requirements Business Licenses Whether permits, registrations, or reports required for the business are available Lease Agreement Who is responsible for permits, change of use, and related costs Special Clauses What happens if the tenant cannot obtain the required approval or operate the intended business Where a tenant is leasing premises for a specific business, it is generally preferable to state that purpose expressly rather than describing the premises only as a “commercial unit” or “store.” The purpose stated in the agreement may become an important factor if a dispute later arises over whether the premises were suitable for the intended use. 3. Is the Landlord Liable If the Change of Use Is Not Possible? If the premises cannot be used for the purpose agreed under the lease, the landlord’s contractual obligation to enable the tenant to use and benefit from the premises may become an issue. Article 623 of the Korean Civil Act requires a landlord to deliver the leased property and maintain it in a condition necessary for the tenant’s use and enjoyment during the lease term. [Article 623 of the Civil Act – Obligations of the Lessor] In Supreme Court Decision 2021Da202309, dated April 29, 2021, the lease expressly stated that the premises would be used as a convenience store, but issues relating to the building’s registered use interfered with normal business operations. The Supreme Court held that the condition in which leased premises must be provided should be determined in light of the agreed purpose and terms of the lease, and that the landlord’s obligation to maintain the premises in a usable condition does not automatically disappear merely because the landlord was unaware of the relevant defect. [Supreme Court Decision 2021Da202309, April 29, 2021] However, the landlord is not automatically liable whenever a change of use is denied. Relevant factors may include: the business purpose stated in the lease; whether the landlord knew the tenant’s intended business; whether the landlord represented that the business could operate at the premises; whether the problem arises from the building itself; and whether responsibility for permits or change-of-use procedures was allocated to a particular party. The central issue is whether the premises were leased for a specifically agreed business purpose and why that purpose became impossible to achieve. 4. Can the Lease Be Terminated If the Change of Use Is Not Permitted? If the inability to change the building use prevents the tenant from carrying out the business contemplated by the lease, termination of the lease may be considered. Where the tenant has already taken possession and used the premises, however, Korean law may treat the issue as termination with prospective effect rather than cancellation that retroactively unwinds the entire contractual relationship. In Supreme Court Decision 93Da61321, dated November 22, 1994, the tenant had taken possession of the premises but could not achieve the purpose of the lease because a legal restriction prevented the necessary change of use. The Supreme Court considered the continuing nature of the lease relationship and addressed the matter as one of termination rather than retroactive cancellation. [Supreme Court Decision 93Da61321, November 22, 1994] If the lease is validly terminated, the tenant may also seek the return of the lease security deposit upon returning the premises. Disputes may nevertheless arise over unpaid rent, restoration costs, or other amounts the landlord claims should be deducted from the deposit. 5. Can the Tenant Claim Interior and Business Preparation Costs as Damages? Where the landlord has breached a contractual obligation and the required elements for liability are satisfied, the tenant may consider claiming damages for losses such as interior construction costs. Article 390 of the Civil Act provides for damages where a party fails to perform its contractual obligations in accordance with the terms of the contract. [Article 390 of the Civil Act – Damages for Non-performance] Potential losses in a commercial lease dispute may include: interior construction costs; fixtures and equipment; demolition and restoration expenses; and expenses actually incurred in preparing permits or business registrations. However, not every expense incurred by the tenant will automatically be recoverable. The tenant must generally establish the connection between the landlord’s breach and the claimed loss, as well as the amount actually incurred. Construction agreements, tax invoices, bank transfer records, receipts, and similar documentation may therefore become important evidence. Claims for anticipated profits or lost business revenue generally require additional proof and should be considered separately from actual out-of-pocket expenses. 6. What Clauses Should Be Included in a Commercial Lease? Where the premises are being leased for a specific business, the lease should clearly address what happens if the required change of use or business license cannot be obtained. Relevant provisions may address: the specific business to be operated; whether a change of use is required; which party will handle the change-of-use procedure; allocation of related costs; the landlord’s obligation to provide documents or cooperation; termination rights if approvals are not obtained within a specified period; return of the deposit or other payments; and treatment of interior construction and restoration obligations. In particular, a general provision stating that “all permits and licenses are the tenant’s responsibility” may not adequately distinguish between regulatory issues relating to the tenant’s individual business and legal restrictions arising from the building itself. Where the ability to operate the intended business remains uncertain, the parties may consider expressly addressing termination and payment-return arrangements if the necessary approvals cannot be obtained. 7. Frequently Asked Questions Q1. If the lease says the premises will be used as a restaurant, must restaurant operations necessarily be permitted? The stated business purpose is an important factor, but it does not by itself determine liability. It is also necessary to consider whether the landlord knew the intended use, why the business cannot legally operate, and how the lease allocated responsibility for regulatory approvals. Q2. Is the landlord free from liability if the landlord did not know that the change of use was impossible? Not necessarily. A landlord’s lack of knowledge does not automatically eliminate the obligation to maintain the leased premises in a condition suitable for the agreed use. Whether damages may also be claimed requires a separate review of the requirements for contractual liability. Q3. What happens if neither the landlord nor the tenant is responsible for the inability to operate the business? If the contractual purpose becomes impossible to achieve for reasons attributable to neither party, Korean rules on risk allocation in bilateral contracts may become relevant. The result will depend on why the business became impossible and on the specific terms of the lease. Q4. What should a tenant do if interior construction has already been completed but the business license cannot be obtained? Before incurring additional expenses, the tenant should determine the exact reason the license cannot be issued and whether the problem can be corrected. The tenant should also preserve the building register, lease agreement, licensing documents, interior construction agreements, invoices, receipts, and communications with the landlord before assessing termination, deposit recovery, or damages. 8. Commercial Lease and Change of Use: Key Takeaways In a Korean commercial lease dispute involving a change of use, the registered use of the building is only one part of the analysis. The business purpose agreed between the landlord and tenant is also critical. If the parties entered into the lease for a specific business but a problem inherent in the building prevents that business from operating, issues such as lease termination, return of the security deposit, and damages may arise. However, the landlord is not automatically liable simply because a change of use cannot be completed. The lease agreement, special provisions, building register, reason for the licensing failure, representations made before signing, and records of actual expenditure should be reviewed together.
-
When Does Crypto Trading Violate Korea's Specified Financial Transaction Information Act? Standards and Penalties Explained
Trading virtual assets frequently, or trading large amounts, does not by itself mean that someone has violated Korea's Specified Financial Transaction Information Act (특금법). What matters most is whether a person carried out virtual asset buying, selling, exchanging, transferring, storing, or brokering as a business for other people — and whether that person, as a Virtual Asset Service Provider (VASP), failed to file the required report with Korea's Financial Intelligence Unit (FIU). The Supreme Court of Korea has held that whether someone qualifies as a VASP must be judged comprehensively, taking into account the purpose and type of the transactions, their scale and frequency, the period and method of trading, and other relevant circumstances. Table of Contents What Is a Violation of the Specified Financial Transaction Information Act? Which Types of Violations Arise in Virtual Asset Trading? How Is Personal Coin Trading Distinguished From Operating a Virtual Asset Business? Can OTC, P2P, or USDT Trading Also Violate the Act? What Are the Penalties for Violating the Act? What Should You Check If You Are Being Investigated for a Suspected Violation? Frequently Asked Questions Summary and Points to Note 1. What Is a Violation of the Specified Financial Transaction Information Act? A violation of the Act refers to a breach of the reporting, notification, or customer due diligence obligations set out in the Act on Reporting and Using Specified Financial Transaction Information (특정 금융거래정보의 보고 및 이용 등에 관한 법률). The Act imposes certain obligations on financial companies and Virtual Asset Service Providers (VASPs) in order to prevent money laundering and the financing of illegal activities. In the virtual asset sector, the issue that most commonly arises for individuals and unregistered operators is operating a virtual asset trading business — while qualifying as a VASP — without filing the required report with the FIU. Accordingly, what matters is not simply the fact that coins were traded, but rather for whose benefit and through what structure the trading was carried out, and whether it was conducted continuously and repeatedly as a business. [Related Legislation] Act on Reporting and Using Specified Financial Transaction Information — Korea Law Information Center 2. Which Types of Violations Arise in Virtual Asset Trading? In the virtual asset sector, issues can arise not only from operating without registration, but also from failing to file required notifications or changes of registration, and from breaching anti-money laundering obligations. These can generally be divided into the following categories. Unregistered virtual asset business This refers to operating a virtual asset trading business — while qualifying as a VASP — without filing the required report with the FIU. Depending on the actual structure of the trades, even individual-to-individual OTC or P2P transactions may be found to constitute an unregistered virtual asset business. Failure to file required notifications or changes of registration Even a VASP that has already filed a report must file a notification of change, following the procedure set out in the Act, whenever the details of its original filing change. In particular, from August 20, 2026, the amended Act and its subordinate regulations take effect, tightening VASP registration requirements. Under the amended system, the scope of screening expands to cover the legal violation history, financial status, and social credibility of controlling shareholders, and a VASP's organizational structure, personnel, IT systems, and internal control system also become substantive elements of the registration review. In addition, notifications relating to controlling shareholders and the compliance system will shift from after-the-fact filing within 14 days of the change to advance filing 30 days before the change takes place. If a matter subject to advance filing is carried out before it has been accepted by the authorities, criminal penalties or administrative sanctions may follow — so VASPs planning changes to their governance structure or compliance system should check the filing timeline well in advance. [Related Source] Financial Services Commission & Korea Financial Intelligence Unit, "Comprehensive Revision of the VASP Registration Manual in Line With Strengthened VASP Registration Requirements" (Aug. 13, 2026) 3. How Is Personal Coin Trading Distinguished From Operating a Virtual Asset Business? Whether someone qualifies as a VASP is not determined by transaction amount or frequency alone. The Supreme Court has held that the following factors must be considered together: The purpose and type of the transactions The scale and frequency of the transactions The period over which the trading continued The specific method of trading Whether the trading was carried out for another person's benefit Whether consideration was received for the trading The Court found that an ordinary user who buys, sells, or exchanges virtual assets on an exchange solely for their own benefit and on their own account is, absent special circumstances, unlikely to be treated as a VASP. On the other hand, a person who continuously and repeatedly trades virtual assets for an indefinite number of customers or users, and receives consideration for doing so, may in principle qualify as a VASP. Criteria for distinguishing personal trading from a virtual asset business Category Personal Virtual Asset Trading Trading Likely to Be Treated as a Virtual Asset Business Purpose of trading Personal investment or asset management Providing trading convenience to another person Counterparty Self-directed trading through an exchange Customers or an indefinite number of users Source of funds Mainly the trader's own funds Involvement of customer or third-party funds Profit Capital gains from investment Fees, spreads, or other trading consideration Method of trading Based on the trader's own judgment At another party's request Continuity Depends on investment circumstances Continuous and repeated in a set manner A large trading volume does not, on its own, make trading a virtual asset business if it was conducted with the trader's own funds. Conversely, even a relatively small trading volume may require a review of VASP registration obligations, if the trader repeatedly bought and sold coins at the request of multiple people and received consideration for doing so. [Related Case Law] Supreme Court, Judgment of Dec. 12, 2024, Case No. 2024Do10710 4. Can OTC, P2P, or USDT Trading Also Violate the Act? Trading virtual assets through OTC or P2P methods does not, by itself, make the trading illegal. What matters is the actual structure of the transactions. If a person purchases USDT with their own funds and trades it on their own account, this is likely closer to ordinary investment activity. On the other hand, the following types of trading warrant a review of whether they constitute an unregistered virtual asset business: Repeatedly buying and selling USDT or other assets at the request of multiple people Receiving Korean won and sending the corresponding virtual asset to the other party's wallet Continuing to trade while receiving fees or spreads Brokering or carrying out another person's virtual asset trading, exchange, or transfer on their behalf Accordingly, what matters is not simply the trading volume, but whose funds were used, how the counterparties were found, and what consideration was received. 5. What Are the Penalties for Violating the Act? The severity of the penalty depends on which reporting obligation was breached. Criminal penalties for violations of the Act Type of Violation Penalty Operating a virtual asset business without filing a report with the FIU Imprisonment for up to 5 years, or a fine of up to KRW 50 million Filing a report through false or fraudulent means and operating a business Imprisonment for up to 5 years, or a fine of up to KRW 50 million Failing to file a required notification of change Imprisonment for up to 3 years, or a fine of up to KRW 30 million Filing a notification of change through false or fraudulent means Imprisonment for up to 3 years, or a fine of up to KRW 30 million These statutory penalty ranges remain unchanged under the amended Act, which takes effect on August 20, 2026. That said, actual cases also take into account the period and scale of trading, the profit obtained, and each party's role and degree of involvement. Depending on the trading method used, it is also necessary to separately review whether charges such as violation of the Foreign Exchange Transactions Act, fraud, or offenses related to proceeds of crime may also apply. 6. What Should You Check If You Are Being Investigated for a Suspected Violation? The first step is to organize all trading activity into transactions made for your own investment and transactions made on behalf of others. A large volume of account deposits and withdrawals or virtual asset transactions does not, on its own, reveal the true nature of the trading. Before an investigation, it is worth reviewing the following materials: Trading and transfer records from exchanges and personal wallets Deposit and withdrawal records for accounts used in the trading KakaoTalk, Telegram, or other messages exchanged with counterparties The actual profit structure, such as fees or spreads received How each counterparty was found, and the role each participant played In particular, if funds were repeatedly received in Korean won from multiple people and virtual assets were sent in return, it is essential to first trace the flow of funds and determine which deposit corresponds to which virtual asset transaction. Based on this, you should be able to explain whether you were an investor trading on your own account, or someone who continuously and repeatedly carried out virtual asset trading on behalf of others. 7. Frequently Asked Questions Q1. Does trading coins frequently automatically mean I have violated the Act? Frequent trading alone does not constitute a violation. If the trading was carried out for your own benefit and on your own account, it may qualify as ordinary virtual asset investment. However, if you repeatedly traded at another person's request and received consideration for doing so, this requires separate review. Q2. If I buy USDT low and sell it high, do I need to file a report? Earning a profit from the price difference alone does not make someone a VASP. The determination depends on whether the profit came from personal investment, or from repeatedly supplying USDT to customers while receiving fees or spreads. Q3. Is it a problem if I bought coins on behalf of an acquaintance as a favor? A one-off favor and continuous, repeated conduct of this kind must be distinguished. Relevant factors include the number and period of the transactions, whether consideration was received, and how far the range of counterparties expanded. 8. Summary and Points to Note Whether a violation of the Act has occurred is not determined by the amount or frequency of virtual asset trading alone. The key factor in distinguishing personal investment from an unregistered virtual asset business is whose funds were used, for whose benefit the trading was carried out, and what consideration was received. In addition, from August 20, 2026, the registration review and certain notification-of-change procedures for VASPs will be strengthened, so existing operators should also confirm the requirements and filing deadlines under the revised registration manual. Decent Law Firm reviews VASP status, violation risk under the Act, and investigation response strategy based on the structure of virtual asset transactions and the flow of funds involved.
-
Unregistered Virtual Asset Service Providers in Korea: Registration Requirements and Penalties
Frequent trading of virtual assets does not, by itself, mean that you are required to register as a Virtual Asset Service Provider (VASP) in Korea. However, if you repeatedly buy, sell, exchange, transfer, broker, arrange, or facilitate virtual asset transactions for others and receive compensation for doing so, you may be considered a VASP subject to registration requirements under Korea’s Act on Reporting and Using Specified Financial Transaction Information (the “Specified Financial Information Act”). 1. What Is an Unregistered Virtual Asset Service Provider in Korea? A person or entity may be treated as an unregistered VASP if it conducts regulated virtual asset activities as a business without completing the required registration with the Korea Financial Intelligence Unit (KoFIU). The Specified Financial Information Act regulates businesses engaged in activities involving virtual assets, including the purchase and sale of virtual assets, exchanges between virtual assets, certain transfers, custody or management, and the brokerage, arrangement, or agency of virtual asset transactions. Accordingly, the rules are not limited to large centralized exchanges. Depending on the actual structure of the business, an individual or smaller operator may also fall within the scope of a VASP. Specified Financial Information Act, Article 7 ↗ 2. How Is VASP Status Determined? The key issue is not simply whether virtual assets were traded, but whether the relevant activities were carried out “as a business.” The Supreme Court of Korea has held that VASP status should be determined by considering the circumstances as a whole, including: the purpose and type of the transactions; the scale and frequency of the transactions; the period over which the transactions were conducted; and the manner in which the transactions were carried out. In particular, an ordinary exchange user who repeatedly buys or exchanges virtual assets solely for his or her own account and benefit will generally not be regarded as a VASP, absent special circumstances. By contrast, a person who repeatedly conducts virtual asset transactions for the benefit of an unspecified number of customers or users and receives compensation in return may, in principle, be regarded as a VASP. Supreme Court Decision 2024Do10710, Dec. 12, 2024 ↗ 3. How Are Personal Crypto Trading and VASP Activities Distinguished? The amount or frequency of trading is not the decisive factor. What matters more is for whom the transactions are conducted and how the business operates. Factor More Likely to Be Personal Trading May Require VASP Review Purpose Personal investment or profit Providing transaction services to customers Funds Trader’s own funds Funds connected to customers or third parties Counterparty Trading through an exchange for one’s own account Transactions involving multiple customers Compensation No separate fee Fees, spreads, or other compensation received Transaction method Trading based on one’s own decisions Buying, selling, exchanging, or transferring at a customer’s request Continuity Trading as part of personal investment activity Activities performed repeatedly as a business A high transaction volume or a large number of trades does not automatically make a person an unregistered VASP. Conversely, even if transactions are conducted through a personal bank account or wallet, VASP status may need to be reviewed where the person repeatedly provides transaction services to customers and earns fees or other compensation. 4. Can OTC, P2P, or Crypto Transaction Services Require VASP Registration? Yes. OTC or P2P transactions are not automatically subject to VASP registration, but the actual business model may fall within the regulated scope. For example, VASP issues may arise where an operator repeatedly: receives Korean won from customers and transfers USDT or other virtual assets in return; buys, sells, or exchanges virtual assets at a customer’s request; earns fees or profits through transaction spreads; or solicits customers through Telegram, open chat rooms, or similar online channels. The absence of a formal exchange platform or physical business location does not, by itself, exclude the activity from VASP regulation. In June 2026, KoFIU specifically identified private exchange operators that buy and sell stablecoins and other virtual assets in exchange for fiat currency as a type of unregistered virtual asset business activity requiring regulatory attention. KoFIU / Financial Services Commission – Official Source ↗ 5. Can an Overseas Virtual Asset Business Be Required to Register in Korea? Yes. An overseas business may be subject to Korean VASP registration requirements if it conducts business activities targeting users in Korea. KoFIU considers various factors when assessing whether an overseas virtual asset business is conducting business in Korea, including: whether a Korean-language website or service is provided; whether payments in Korean won are supported; whether customer acquisition campaigns target Korean users; and whether marketing activities are directed at users in Korea. In June 2026, KoFIU announced that it had identified eight illegal OTC operators and four overseas exchanges conducting business in Korea, referred the cases to the police, and requested domestic access restrictions for the relevant websites and applications. Accordingly, the fact that a company is incorporated or headquartered outside Korea does not, by itself, exempt it from Korean VASP regulations. KoFIU / Financial Services Commission – Official Source ↗ 6. What Are the Consequences of Operating as an Unregistered VASP? Operating a virtual asset business without the required registration may result in criminal liability under the Specified Financial Information Act. Under Article 17(1) of the Act, a person who conducts virtual asset transactions as a business without filing the registration required under Article 7(1) may be subject to imprisonment for up to five years or a fine of up to KRW 50 million. Specified Financial Information Act, Article 17(1) ↗ In addition, amendments to the Specified Financial Information Act scheduled to take effect on August 20, 2026 will strengthen the entry and registration requirements applicable to VASPs. The amended framework expands the review of matters such as the financial condition and social credibility of the VASP and its major shareholders, as well as organizational, personnel, IT infrastructure, and internal control requirements. Financial Services Commission – Official Source ↗ KoFIU has also taken measures against unregistered operators, including referrals to investigative authorities, requests to restrict domestic access to websites and mobile applications, and restrictions involving transactions with registered VASPs. KoFIU / Financial Services Commission – Official Source ↗ If you have already conducted transactions that may fall within the scope of VASP activities, it is advisable to organize the relevant transaction records, bank account and wallet flows, communications with customers, fee or spread structures, and the specific role you performed before assessing the applicable regulatory and legal risks. 7. Frequently Asked Questions (FAQ) Q1. If I frequently buy and sell USDT, am I automatically considered a VASP? No. Frequent trading alone does not automatically make you a VASP. It is necessary to consider whether you were trading with your own funds for your own benefit or conducting transactions for customers in return for fees or other compensation. Q2. Do I need to register if I occasionally buy crypto on behalf of a friend? Not necessarily. An isolated transaction performed at the request of a friend does not, by itself, determine VASP status. The analysis may change depending on factors such as the number and range of counterparties, transaction frequency and duration, whether compensation was received, and whether the activity was carried out continuously or repeatedly. Q3. Am I outside the VASP rules if I do not have a registered business? No. The absence of a Korean business registration does not, by itself, determine whether you are a VASP under the Specified Financial Information Act. Even an individual operating through a personal account or wallet may need to consider VASP registration requirements if the person repeatedly provides virtual asset-related services to customers for profit. 8. Key Takeaways Whether a person or business constitutes an unregistered VASP in Korea depends not simply on the volume of crypto trading, but primarily on whether virtual asset-related services are repeatedly provided to customers as a business. For OTC, P2P, or transaction-facilitation arrangements in particular, the purpose of the transactions, counterparties, flow of funds, fee structure, and the operator’s actual role should be reviewed together. Decent Law Firm advises clients on whether their virtual asset business models fall within Korea’s VASP regulatory framework, including registration requirements under the Specified Financial Information Act and legal risks associated with unregistered operations.
-
Settling a Sexual Offense Case in Korea: What Victims Should Check Before Agreeing
This article explains how settlement amounts are determined in sexual offense cases in Korea, what to review in a settlement agreement and a Statement of Non-Punishment, and whether a victim may decline a settlement offer. Attorney in Charge | Hong Pureun Is a victim required to agree to a settlement? No. A victim of a sexual offense is not legally required to accept a settlement offer from the suspect or defendant. Even when the other party apologizes or offers compensation, the victim may decline the proposal. The victim may also request different terms if the proposed settlement does not adequately reflect the harm suffered. A victim does not have to respond immediately simply because a settlement request was made. Nor is the victim required to decide within a deadline unilaterally set by the other party. In particular, discussing the incident shortly after it occurred can be emotionally difficult. Direct calls or meetings with the accused may also create pressure and lead the victim to accept terms without sufficient review. The decision should therefore be made after considering the status of the criminal case, the extent of the harm, the attitude of the accused, and the specific settlement terms being offered. Does a settlement end the criminal case? Not necessarily. Reaching a private settlement does not automatically terminate a criminal investigation or trial in Korea. Under the Korean Sentencing Commission’s sentencing guidelines for sexual offenses, a victim’s expressed wish not to pursue punishment may constitute a special mitigating factor, while substantial recovery of damages may constitute a general mitigating factor, depending on the type of offense. Similar considerations appear in the sentencing guidelines for digital sexual offenses. However, a settlement or Statement of Non-Punishment does not automatically determine the outcome of the case or the sentence. Investigative authorities and courts may consider a range of circumstances, including the nature and seriousness of the offense, whether the conduct was repeated, the extent of the harm, the accused’s conduct after the offense, and the degree of actual recovery provided to the victim. Before signing any document, the victim should understand how the settlement agreement and the Statement of Non-Punishment may affect the criminal proceedings against the accused. How is a settlement amount determined? Korean law does not prescribe a fixed settlement amount for sexual offense cases. Even where the same criminal charge applies, the appropriate amount may differ depending on the conduct involved and the harm suffered by the victim. Relevant considerations may include: ▪️ The nature and seriousness of the offense ▪️ Whether the conduct occurred repeatedly ▪️ The physical and psychological harm suffered by the victim ▪️ Medical expenses, counseling fees, and other actual costs ▪️ Disruption to employment, education, or family relationships ▪️ The accused’s apology and efforts to repair the harm ▪️ Continued contact, intimidation, or other forms of secondary harm In cases involving unlawful filming or the distribution of intimate images, additional considerations may include how widely the material was shared, whether it has been deleted, and whether further distribution remains possible. A victim should therefore avoid relying solely on settlement figures found in other cases online. The assessment should also take into account the victim’s individual circumstances and the legal rights that may be waived under the proposed agreement. The wording of the settlement agreement may be as important as the amount A settlement in a sexual offense case should be reviewed not only for the amount offered but also for the conditions contained in the agreement. A settlement agreement commonly addresses: ▪️ The settlement amount and payment method ▪️ The payment deadline ▪️ Whether the victim will express a wish not to pursue punishment ▪️ Whether the victim will waive a future civil damages claim ▪️ Restrictions on future contact or access ▪️ Confidentiality obligations ▪️ Consequences of non-payment or other breaches Particular care is required when the agreement contains broad language such as: “The victim will not raise any further civil or criminal claims or objections in connection with this matter.” Depending on its wording and scope, this provision may affect not only the victim’s position in the criminal case but also the ability to pursue a later civil claim for damages. Further dissemination of intimate material or other previously unknown harm may be discovered after the settlement is signed. The agreement should therefore clearly state whether it covers only the harm currently known or also extends to future or additional harm. Are a settlement agreement and a Statement of Non-Punishment the same document? They are related, but they serve different purposes. A settlement agreement records the compensation amount, payment terms, and the parties’ future legal rights and obligations. A Statement of Non-Punishment—commonly referred to in Korean as a cheobeol bulwonseo (처벌불원서)—communicates to the police, prosecution, or court that the victim does not wish the accused to be punished. The settlement terms and the non-punishment statement may be included in a single document or prepared separately. A victim may also agree on financial compensation while reserving a separate position regarding punishment. The appropriate structure will depend on the circumstances of the case and the terms agreed by the parties. Receiving compensation does not, by itself, automatically mean that the victim has agreed not to seek punishment. The documents should clearly state exactly what the victim has agreed to and which rights, if any, are being waived. Should a Statement of Non-Punishment be submitted before payment is received? The accused or their representative may ask the victim to submit the Statement of Non-Punishment first, promising to transfer the settlement amount afterward. This arrangement may expose the victim to unnecessary risk. Once the statement has been submitted, the accused may delay payment or fail to pay the agreed amount, leaving the victim to pursue payment separately. Unless there is a specific reason to proceed otherwise, it is generally safer to arrange for payment and delivery of the relevant documents to occur simultaneously. Where the settlement amount will be paid in installments, the agreement should specify: ▪️ Each payment date and amount ▪️ The bank account and payment method ▪️ The consequences of late payment ▪️ Whether the full remaining balance becomes immediately due after a missed payment ▪️ The date or stage at which the Statement of Non-Punishment will be submitted Payment terms should be recorded in writing rather than left as a verbal promise. Bank transfer records and other evidence confirming payment should also be retained. Can a victim refuse a settlement? Yes. A victim may clearly state that they do not wish to settle. A victim may initially consider a proposal and later decide not to proceed after reviewing the accused’s conduct or the terms offered. Where the accused, their family members, or other representatives continue contacting the victim after a refusal, the victim should preserve call logs, messages, emails, and other records of the contact. The situation may then be reported to the investigator in charge or discussed with the victim’s attorney. The victim’s wishes should remain the central consideration throughout the process. A victim does not need to make an unwanted decision merely to help reduce the accused’s punishment. A victim does not have to contact the accused directly A victim is not required to speak with or meet the suspect, defendant, their family members, or their attorney to negotiate a settlement. Under the sentencing guidelines for digital sexual offenses, conduct that causes additional harm to the victim during an attempted settlement may be treated as an aggravating consideration. A victim’s attorney may assist with: ▪️ Confirming the other party’s settlement proposal ▪️ Negotiating the amount and payment conditions ▪️ Communicating the victim’s requests ▪️ Reviewing the settlement agreement and Statement of Non-Punishment ▪️ Coordinating payment and document delivery ▪️ Including restrictions on future contact or access ▪️ Submitting relevant documents to investigators, prosecutors, or the court Depending on eligibility, victims of sexual violence in Korea may also apply for assistance from a state-appointed victim’s counsel. This system provides legal support from the early stages of the investigation through trial proceedings. Before accepting a settlement offer A settlement in a sexual offense case is not simply a decision about how much compensation to receive. It also determines the scope of the harm being resolved, the victim’s position regarding punishment, and which civil rights will remain available after the agreement is signed. Before signing a settlement agreement, the victim should confirm: ▪️ Which rights will be waived under the agreement ▪️ Whether the amount and payment terms are clearly stated ▪️ Whether the victim will submit a Statement of Non-Punishment ▪️ Whether future or newly discovered harm is included in the settlement ▪️ Whether payment and document delivery will occur in a secure order ▪️ Whether restrictions on future contact or access are necessary How Decent Law Firm assists victims Decent Law Firm represents victims of sexual offenses in settlement discussions with suspects and defendants. Our assistance may include confirming the other party’s proposal, negotiating the settlement amount and payment terms, reviewing the settlement agreement and Statement of Non-Punishment, and coordinating the submission of relevant documents. We may also serve as the victim’s point of contact so that the victim does not have to communicate directly with the accused. Each proposed agreement is reviewed in light of the rights that may be waived and the possibility of additional or newly discovered harm. Victims who have received a settlement proposal but are uncertain whether the terms are appropriate should consider obtaining legal advice before signing an agreement or submitting a Statement of Non-Punishment. Official References ▪️ Korean Sentencing Commission, Sentencing Guidelines for Sexual Offenses ▪️ Korean Sentencing Commission, Sentencing Guidelines for Digital Sexual Offenses ▪️ Ministry of Justice, State-Appointed Counsel for Crime Victims
-
Generative AI and Personal Data: What Businesses Should Check Before Uploading Customer Information or Contracts
Businesses are increasingly using generative AI to review contracts, summarize meetings, respond to customer inquiries, and draft documents. However, when contracts or other materials entered into an AI service contain personal data relating to customers or employees, the issue extends beyond operational efficiency. It may raise concerns regarding personal data processing, confidentiality, and the management of internal business information. Businesses should therefore understand how an AI service stores and uses input data and establish internal rules that reflect how generative AI is actually used within the organization. How Is Information Entered into Generative AI Processed? From the user’s perspective, generative AI appears to involve simply entering a question and receiving a response. In practice, however, prompts and uploaded files are transmitted to the service provider’s systems. Depending on the service policy and account type, they may be retained as conversation records or system logs and may also be used to improve the service. Before entering business materials, companies should check: ▪️ Whether input data may be used to train the AI model ▪️ How long conversations and uploaded files are retained ▪️ Whether conversations and uploaded materials can be deleted ▪️ In which country and on which servers the data is processed ▪️ What access permissions are granted when the AI is connected to external applications or internal systems Using a paid or enterprise account does not automatically resolve every data protection issue. The relevant contractual terms and actual data-processing arrangements must also be reviewed. Is Information No Longer Personal Data Once the Name Is Removed? Removing a customer’s name or contact information from a contract does not necessarily mean that the remaining information is no longer personal data. Personal data includes not only information that directly identifies an individual, such as a name, but also information that may identify a person when combined with other readily available information. Even after a name has been removed, an individual may still be identifiable through a combination of information such as: ▪️ The company name and a specific job title ▪️ The contract date and transaction amount ▪️ The employee’s department and performance evaluation ▪️ Detailed consultation history and family relationships ▪️ A case number and the location of a dispute A company name alone is generally information about a legal entity. However, when combined with a specific position, transaction details, or other contextual information, it may make an individual employee or representative identifiable. Businesses should therefore remove information that is unnecessary for the intended task rather than deleting names alone. Actual names, contact details, company names, and similar identifiers may also need to be replaced with fictional or generic information. Does Entering Customer Information Automatically Violate Korea’s Personal Information Protection Act? Entering customer information into a generative AI service does not automatically constitute a violation of Korea’s Personal Information Protection Act, commonly referred to as the PIPA. However, a business may generally use personal data only within the scope of the original purpose of collection and an appropriate legal basis. It is therefore necessary to assess whether the intended AI use is related to the original processing purpose and whether additional consent or another legal basis is required. The relationship between the business and the AI service provider must also be reviewed. The applicable legal framework may differ depending on whether the provider processes data solely on the company’s instructions or also uses the input data for its own purposes, such as model training or service improvement. Depending on the actual arrangement, the use of the service may involve outsourced processing, third-party provision, or other forms of data processing. If personal data is transferred to servers or service providers located outside Korea, the requirements governing overseas transfers must also be considered. The applicable rules cannot be determined solely from the fact that customer information was entered into an AI service. Businesses should review the actual contractual structure and data flow, including: ▪️ The legal basis for using personal data in the relevant AI task ▪️ The purposes for which the service provider uses input data ▪️ Whether the data is used for training or service improvement ▪️ The data-retention period and deletion procedures ▪️ The server locations and countries to which data is transferred ▪️ The involvement of subprocessors or downstream service providers ▪️ How input data is handled after the service contract ends Contracts and Consultation Records Raise More Than Personal Data Issues Contracts and customer consultation records may contain confidential business information in addition to personal data. Examples include: ▪️ Transaction terms and supply prices ▪️ Sales strategies and business plans ▪️ Technical materials and development information ▪️ Confidentiality obligations agreed with customers or business partners ▪️ Strategies for litigation, investigations, or other disputes ▪️ Non-public financial information and internal decision-making materials Entering such information into an external generative AI service may raise issues under the PIPA, but it may also create risks involving contractual confidentiality obligations, trade secret protection, customer security agreements, and internal company policies. A corporate generative AI policy should therefore cover not only personal data but also trade secrets, contractual information, technical materials, and dispute-related documents. Internal Rules Businesses Should Establish for Generative AI Use When employees are left to decide individually how generative AI should be used, the company may be unable to identify what information has been entered into which external service. Rather than issuing a general instruction not to enter personal data, businesses should establish practical and specific rules that employees can follow in their day-to-day work. 1. Approved Services and Accounts The company should designate the generative AI services and account types that employees are permitted to use. Employees should also be prohibited from entering business materials through personal accounts or unapproved services. 2. Prohibited Input Data The company should clearly define the information that must not be entered into generative AI services. This may include resident registration numbers, bank account information, health information, other sensitive or high-risk personal data, trade secrets, non-public contractual terms, and materials relating to litigation or criminal investigations. 3. Approval Procedures for High-Risk Documents High-risk materials, such as contracts, human resources documents, and customer consultation records, may be made subject to prior review or approval by the responsible department. 4. Standards for Removing or Replacing Identifying Information Businesses should establish standards for removing or replacing information that could identify an individual or a transaction party, including names, contact details, company names, and transaction amounts. Rather than uploading an entire contract, employees should extract only the clauses required for the relevant task. Actual customer information may also be replaced with fictional names or sample data. 5. Conversation History and Model-Training Settings The company should determine whether the service allows input data to be excluded from model training, whether conversation history can be disabled, and how deletion features operate. 6. Internal Reporting and Incident Response Employees should be required to report promptly if personal data or confidential business information is entered into an AI service by mistake. The company should also establish procedures for deleting records, disabling external integrations, requesting deletion from the service provider, and taking any other necessary measures. What Should a Business Do If Customer Information Has Already Been Entered? If an employee mistakenly enters customer information or an internal document into a generative AI service, the company should first stop any further sharing or use of the resulting output. The following matters should then be reviewed: ▪️ Which account and AI service were used ▪️ What personal data or confidential information was entered ▪️ Whether the conversation and uploaded files can be deleted ▪️ Whether the service was connected to any external applications ▪️ Whether the information may have been used for training or service improvement ▪️ Whether a third party may have gained access to the information Where necessary, the company should delete the conversation history and uploaded files, revoke external access permissions, and request that the service provider stop processing or delete the relevant information. Whether the incident requires a personal data breach report or notification to affected individuals should be determined by considering the type and volume of information involved, the possibility of third-party access, whether the data has been deleted, and the potential harm to the individuals concerned. Effective Generative AI Use Requires Governance, Not Just Prohibition Generative AI can improve efficiency in contract review, document drafting, and customer communications. However, when its use is left entirely to individual employees, a business may have little control over where customer information and internal documents are transmitted or how they are subsequently used. Businesses should establish specific rules regarding approved services, prohibited data, the removal or replacement of identifying information, approval procedures for high-risk documents, and incident response. Decent Law Firm advises businesses on the legal use of generative AI, including compliance with Korean personal data protection requirements, review of service terms and data-processing agreements, overseas data transfers, trade secret protection, and the preparation of internal AI-use policies. This content is provided for general informational purposes only and does not constitute legal advice regarding any specific matter or business.
-
Korea’s AI Basic Act Six Months On: Disclosure and Labeling Duties for Generative AI Businesses
Korea’s AI Basic Act took effect on January 22, 2026. Under the Act, businesses that provide generative AI products or services are subject to transparency obligations. Compliance, however, does not end with adding a notice to a service screen. The applicable legal risks depend on the AI model used, the information entered by users, where that information is transferred, and how the generated output is used. Advance Disclosure and Output Labeling Are Separate Obligations Article 31 of the AI Basic Act divides transparency obligations into two categories. First, an AI business operator intending to provide a product or service based on generative AI must inform users of that fact in advance. Second, when generative AI or an AI-powered service produces content, the business must indicate that the output was generated using AI. For example, a chatbot or AI document-generation service may need to disclose its use of generative AI through its terms of service or user interface before the service is used. Separately, text, images, audio, or video generated by the service may require an AI-generated content label. Synthetic audio, images, and video that could easily be mistaken for real content require particularly clear disclosure. In practical terms: Before use: disclose that the product or service uses generative AI. After generation: indicate that the resulting content was generated using AI. AI-Generated Content Does Not Always Require a Visible Watermark The required label does not necessarily have to be a visible watermark. The Enforcement Decree permits both: ▪️ Human-readable labeling ▪️ Machine-readable labeling Where only a machine-readable method is used, users must still be informed at least once, through text, audio, or another accessible method, that the content was generated using AI. All or part of the disclosure and labeling requirements may not apply where: ▪️ The service name or interface already makes the use of AI obvious ▪️ The AI is used exclusively for the operator’s internal business purposes ▪️ A separately issued government notice recognizes an exception The internal-use exception should be applied carefully. Materials initially generated for internal use may fall outside the exception once they are included in advertisements, customer reports, consultation materials, or other externally distributed content. Businesses should therefore distinguish between outputs that remain within the service and outputs that can be downloaded, shared, or provided to customers. Businesses Using External AI APIs May Also Be Covered A business does not need to develop its own AI model to fall within the scope of the AI Basic Act. The Act also covers businesses that use AI developed by another provider to offer AI products or services. A company may therefore qualify as an AI business operator where it connects an external large language model through an API and provides services such as: ▪️ AI chatbots ▪️ Image-generation tools ▪️ Document drafting or summarization ▪️ Automated customer consultation The key question is not who developed the underlying model. What matters is whether the company uses AI to provide a product or service to users. Businesses using third-party APIs should therefore review whether they are subject to advance disclosure and AI-output labeling obligations. Disclosure Compliance Is Only One Part of the Legal Review Generative AI services commonly send user inputs to an external AI model and return generated outputs to the user. This process may raise data protection and copyright issues that are legally separate from the labeling requirements under the AI Basic Act. 1. Personal Data Entered into AI Services Where customers or employees enter names, consultation records, contracts, photographs, or internal documents into an external AI service, the business should verify: ▪️ Whether input data is stored or used for model training ▪️ The location and country of the servers processing the data ▪️ Applicable retention periods and deletion procedures ▪️ Whether the arrangement constitutes outsourcing, third-party provision, or overseas transfer ▪️ Whether the data is retransmitted to plug-ins or other external services The legal classification should be based on the actual data flow rather than the name of the agreement with the AI provider. A privacy policy should accurately reflect how personal data is collected, transferred, retained, and deleted throughout the AI service structure. 2. Copyright in AI-Generated Outputs A business does not automatically acquire exclusive copyright merely because an image, document, video, or source code was generated using AI. Relevant considerations include: ▪️ The degree of human creative involvement ▪️ Whether the source materials were lawfully used ▪️ Whether the AI provider’s terms permit commercial use ▪️ Whether the output is substantially similar to existing protected works AI-generated content may also infringe third-party copyrights, image rights, or other intellectual property rights. Businesses using generated outputs for advertising, websites, software, games, or commercial publications should retain records of the model used, prompts, initial outputs, and subsequent human edits. AI Used to Evaluate Individuals May Qualify as High-Impact AI Not every generative AI service is classified as high-impact AI. However, additional review may be required where AI is used beyond basic drafting or guidance and affects a person’s rights, opportunities, or access to essential services. Relevant examples include AI used in: ▪️ Recruitment and applicant evaluation ▪️ Lending, credit scoring, and insurance assessment ▪️ Medical diagnosis or treatment-related decision-making ▪️ Student admission, selection, or performance evaluation For instance, an AI tool that summarizes a résumé may present a different level of legal risk from one that calculates an applicant’s probability of being hired. The assessment depends on how the AI output is used in the actual decision-making process. Where a system qualifies as high-impact AI, the operator may need to implement: ▪️ Risk-management measures ▪️ Procedures for explaining major decision-making criteria ▪️ User-protection procedures ▪️ Human management and oversight ▪️ Preparation and retention of relevant records Documents to Review Before Launching a Generative AI Service Legal review should not begin by drafting a disclaimer in isolation. A business should first map: ▪️ The AI model being used ▪️ The information entered by users ▪️ The data-transfer route ▪️ How generated outputs are used ▪️ Where human review takes place The following documents should then be aligned with the actual service structure. AI Disclosure and Labeling Notices Separate advance disclosure before use from labeling of generated outputs. Terms of Service Define the permitted use of AI outputs and procedures for handling errors, rights infringement, and user complaints. Privacy Policy Reflect the actual collection, processing, storage, overseas transfer, and deletion of personal data involving external AI providers. AI Supply Agreements and API Terms Review provisions concerning data use, cybersecurity incidents, intellectual property, service interruptions, and liability allocation. Internal AI Use Policy Establish restrictions and approval procedures for entering customer data, contracts, source code, and confidential business information into AI tools. Legal Review Based on the Actual AI Service Structure Under Korea’s AI Basic Act, generative AI transparency obligations are divided into advance disclosure before use and labeling of AI-generated outputs. In practice, however, legal risk extends beyond how a notice is displayed. Businesses should also review the use of external AI models, personal data processing and overseas transfers, rights in generated content, potential classification as high-impact AI, and the allocation of liability with AI vendors. Decent Law Firm’s Corporate Practice Group advises AI and technology companies based on their actual service functions and data flows. Our review covers the applicability of the AI Basic Act, disclosure and labeling design, privacy and copyright issues, external AI model agreements, and the legal documentation required for launching and operating AI services in Korea. This content is provided for general informational purposes only and does not constitute legal advice for any individual matter.