Legal Review of Liability for Personal Information Protection Act Violations: Corporate and Employee Liability and Exemption Requirements
Case Overview
- Client Information
- Corporate / Business Entity
- Case Details
-
The client is a company that processes the personal information of customers and employees. It requested a legal review of how liability would be allocated between the company and its employees if a violation of Korea’s Personal Information Protection Act occurred during business operations.
The client specifically sought advice on the following issues:
▪️ The civil and criminal liability of the company, as the personal information controller, and its employees, as personal information handlers
▪️ The legal relationship between a personal information controller and a personal information handler
▪️ Whether the company could avoid or limit liability where an employee acted outside the scope of authority
▪️ Whether an employee could avoid or limit liability where the violation resulted primarily from the company’s inadequate management or supervision
Rather than requesting a lengthy formal legal opinion, the client asked for issue-specific legal conclusions and practical guidance.
Decent's Strategy
The analysis therefore distinguished between the employee’s intent or negligence and the company’s level of management and supervision.
1. Distinguishing Employee Civil and Criminal Liability
DECENT distinguished between criminal liability arising from the intentional disclosure or provision of personal information and civil liability arising from mistakes or negligence that caused damage.
We also explained that criminal liability may depend on whether the employee knowingly disclosed or provided personal information, rather than merely making an inadvertent mistake in the course of work.
2. Reviewing Corporate Liability and Exemption Requirements
DECENT reviewed the circumstances in which Korea’s dual-liability provisions may apply to a company where an employee commits a violation in connection with the company’s business.
We advised that, to reduce or avoid liability, the company should be able to demonstrate that it exercised appropriate care and supervision through measures such as:
▪️ Limiting access rights to the minimum necessary level
▪️ Providing regular privacy and security training
▪️ Establishing and implementing an internal management plan
▪️ Maintaining and reviewing access logs
▪️ Preserving evidence that compliance measures were actually implemented
3. Clarifying the Relationship Between the Controller and Handler
DECENT explained that the relationship between a personal information controller and a personal information handler should not automatically be classified as a principal-agent, mandator-mandatary, or contractor-subcontractor relationship under Korean civil law.
Because a personal information handler processes personal information under the direction and supervision of the controller, the relationship is generally most comparable to an employment or user-supervision relationship.
However, the category is not limited to formally employed staff. Dispatched workers and external personnel may also qualify as personal information handlers depending on the actual business structure and degree of supervision.
4. Advising on Employee Protection Where the Company Failed to Manage Properly
Where an incident was primarily caused by deficiencies in the company’s internal management system, DECENT advised that the employee should preserve evidence showing that they followed official instructions and ordinary business procedures.
Relevant materials may include:
▪️ Written work instructions
▪️ Internal approval records
▪️ Emails and internal communications
▪️ System access and processing records
▪️ Evidence of compliance with established procedures
These materials may assist in demonstrating that the employee did not act intentionally or negligently.
Results & Significance
Through this legal review, the client obtained a clearer framework for determining how civil and criminal liability may differ depending on the employee’s intent or negligence, the company’s security measures, and the adequacy of its management and supervision.
DECENT also clarified that a company is not automatically exempt from liability merely because an employee acted independently or contrary to internal policy. Evidence of actual training, access control, monitoring, and compliance implementation may be critical.
Conversely, where the company’s inadequate management was the primary cause of the incident, an employee may be able to explain or limit personal liability by showing that they followed company instructions and ordinary procedures.
Based on the review, the client was able to identify areas requiring improvement, including access control, employee training, internal management plans, system logging, and documentation of work instructions.
Legal Consultation
All consultations are conducted after a case review by the attorney in charge.
Providing the key details of your case in advance will help you receive more specific advice.