Juye ”Elizabeth” Han
A elizabeth@decentlaw.ioElizabeth has gained hands-on experience at the Legislative Office of the Ministry of Government Legislation and the Legislation and Judiciary Committee of the National Assembly. She has extensive experience ranging from corporate and startup advisory to overseas corporate establishment and international contract review.
- Corporate · Startups
- Cross-border · Dispute Resolution
- Crypto
- VC · Financial Advisory
- IP Litigation
- Administrative
We navigate complex interests to deliver practical solutions for our clients. ”
- 학력
- Seoul National University B.A., English Language and Literature / Political Economy & Philosophy Hanyang University School of Law J.D.
- 경력
- Legislative Office, Ministry of Government Legislation Legislation and Judiciary Committee, National Assembly
- 자격
- Attorney, Korea
- 언어
- Korean English
- 업무사례
-
-
[Corporate / Startups]
- Drafting and reviewing investment agreements, terms of service, and privacy policies
- Corporate establishment and related tax advisory
- Dispute resolution between companies and related civil and criminal litigation
- Legal advisory on partnership agreements in Thailand for instant photo booth brand P
- Representing overseas creditors in bankruptcy claim filings for CFi platform H
- Reviewing MOUs for fintech company B’s partnership expansion in Indonesia
- Legal advisory on publishing contracts between a Korean author and overseas publisher M
- Legal advisory on terms of service and privacy policy for referral service provider G
- Drafting and reviewing crypto asset account rental agreements for media content creator C
- Drafting and reviewing professional trader appointment contracts for referral service provider P
- Reviewing and drafting legal opinions for the Ministry of Gender Equality and Family
[Cross-border / Dispute Resolution]
[Crypto]
[Administrative]
성공사례
-
Crypto 자문사례
USDT Sponsorship Agreement Review and Successful Contract Execution with an Overseas Participant
Client Information Corporate / Business Entity Case Details The client was preparing a digital asset industry event in Korea and planned to enter into booth operation and ...
Delivery of the Final English Sponsorship Agreement -
Corporate & Biz 자문사례
Partnership NDA Review and Confidentiality Clause Design Advisory
Client Information Corporate / Business Entity Case Details The client was preparing to enter into a business partnership agreement and needed to disclose commercially sen...
Completion of NDA Clause Design -
Corporate & Biz 자문사례
Fintech Business Partnership Agreement Risk Review and Contract Revision Advisory
Client Information Corporate / Business Entity Case Details A Korea-based fintech startup was preparing to expand its services overseas and planned to enter into an agreem...
Delivery of Revised Agreement -
Crypto 자문사례
Legal Review of a Virtual Asset Automation Program and Terms of Use Revision Advisory Completed
Client Information Corporate / Business Entity Case Details The client was a company developing and providing an automation program for users of a blockchain-based platfor...
Legal Opinion and Terms of Use Revision Advisory
관련소식
-
법률정보Generative AI and Personal Data: What Businesses Should Check Before Uploading Customer Information or Contracts
Businesses are increasingly using generative AI to review contracts, summarize meetings, respond to customer inquiries, and draft documents. However, when contracts or other materials entered into an AI service contain personal data relating to customers or employees, the issue extends beyond operational efficiency. It may raise concerns regarding personal data processing, confidentiality, and the management of internal business information. Businesses should therefore understand how an AI service stores and uses input data and establish internal rules that reflect how generative AI is actually used within the organization. How Is Information Entered into Generative AI Processed? From the user’s perspective, generative AI appears to involve simply entering a question and receiving a response. In practice, however, prompts and uploaded files are transmitted to the service provider’s systems. Depending on the service policy and account type, they may be retained as conversation records or system logs and may also be used to improve the service. Before entering business materials, companies should check: ▪️ Whether input data may be used to train the AI model ▪️ How long conversations and uploaded files are retained ▪️ Whether conversations and uploaded materials can be deleted ▪️ In which country and on which servers the data is processed ▪️ What access permissions are granted when the AI is connected to external applications or internal systems Using a paid or enterprise account does not automatically resolve every data protection issue. The relevant contractual terms and actual data-processing arrangements must also be reviewed. Is Information No Longer Personal Data Once the Name Is Removed? Removing a customer’s name or contact information from a contract does not necessarily mean that the remaining information is no longer personal data. Personal data includes not only information that directly identifies an individual, such as a name, but also information that may identify a person when combined with other readily available information. Even after a name has been removed, an individual may still be identifiable through a combination of information such as: ▪️ The company name and a specific job title ▪️ The contract date and transaction amount ▪️ The employee’s department and performance evaluation ▪️ Detailed consultation history and family relationships ▪️ A case number and the location of a dispute A company name alone is generally information about a legal entity. However, when combined with a specific position, transaction details, or other contextual information, it may make an individual employee or representative identifiable. Businesses should therefore remove information that is unnecessary for the intended task rather than deleting names alone. Actual names, contact details, company names, and similar identifiers may also need to be replaced with fictional or generic information. Does Entering Customer Information Automatically Violate Korea’s Personal Information Protection Act? Entering customer information into a generative AI service does not automatically constitute a violation of Korea’s Personal Information Protection Act, commonly referred to as the PIPA. However, a business may generally use personal data only within the scope of the original purpose of collection and an appropriate legal basis. It is therefore necessary to assess whether the intended AI use is related to the original processing purpose and whether additional consent or another legal basis is required. The relationship between the business and the AI service provider must also be reviewed. The applicable legal framework may differ depending on whether the provider processes data solely on the company’s instructions or also uses the input data for its own purposes, such as model training or service improvement. Depending on the actual arrangement, the use of the service may involve outsourced processing, third-party provision, or other forms of data processing. If personal data is transferred to servers or service providers located outside Korea, the requirements governing overseas transfers must also be considered. The applicable rules cannot be determined solely from the fact that customer information was entered into an AI service. Businesses should review the actual contractual structure and data flow, including: ▪️ The legal basis for using personal data in the relevant AI task ▪️ The purposes for which the service provider uses input data ▪️ Whether the data is used for training or service improvement ▪️ The data-retention period and deletion procedures ▪️ The server locations and countries to which data is transferred ▪️ The involvement of subprocessors or downstream service providers ▪️ How input data is handled after the service contract ends Contracts and Consultation Records Raise More Than Personal Data Issues Contracts and customer consultation records may contain confidential business information in addition to personal data. Examples include: ▪️ Transaction terms and supply prices ▪️ Sales strategies and business plans ▪️ Technical materials and development information ▪️ Confidentiality obligations agreed with customers or business partners ▪️ Strategies for litigation, investigations, or other disputes ▪️ Non-public financial information and internal decision-making materials Entering such information into an external generative AI service may raise issues under the PIPA, but it may also create risks involving contractual confidentiality obligations, trade secret protection, customer security agreements, and internal company policies. A corporate generative AI policy should therefore cover not only personal data but also trade secrets, contractual information, technical materials, and dispute-related documents. Internal Rules Businesses Should Establish for Generative AI Use When employees are left to decide individually how generative AI should be used, the company may be unable to identify what information has been entered into which external service. Rather than issuing a general instruction not to enter personal data, businesses should establish practical and specific rules that employees can follow in their day-to-day work. 1. Approved Services and Accounts The company should designate the generative AI services and account types that employees are permitted to use. Employees should also be prohibited from entering business materials through personal accounts or unapproved services. 2. Prohibited Input Data The company should clearly define the information that must not be entered into generative AI services. This may include resident registration numbers, bank account information, health information, other sensitive or high-risk personal data, trade secrets, non-public contractual terms, and materials relating to litigation or criminal investigations. 3. Approval Procedures for High-Risk Documents High-risk materials, such as contracts, human resources documents, and customer consultation records, may be made subject to prior review or approval by the responsible department. 4. Standards for Removing or Replacing Identifying Information Businesses should establish standards for removing or replacing information that could identify an individual or a transaction party, including names, contact details, company names, and transaction amounts. Rather than uploading an entire contract, employees should extract only the clauses required for the relevant task. Actual customer information may also be replaced with fictional names or sample data. 5. Conversation History and Model-Training Settings The company should determine whether the service allows input data to be excluded from model training, whether conversation history can be disabled, and how deletion features operate. 6. Internal Reporting and Incident Response Employees should be required to report promptly if personal data or confidential business information is entered into an AI service by mistake. The company should also establish procedures for deleting records, disabling external integrations, requesting deletion from the service provider, and taking any other necessary measures. What Should a Business Do If Customer Information Has Already Been Entered? If an employee mistakenly enters customer information or an internal document into a generative AI service, the company should first stop any further sharing or use of the resulting output. The following matters should then be reviewed: ▪️ Which account and AI service were used ▪️ What personal data or confidential information was entered ▪️ Whether the conversation and uploaded files can be deleted ▪️ Whether the service was connected to any external applications ▪️ Whether the information may have been used for training or service improvement ▪️ Whether a third party may have gained access to the information Where necessary, the company should delete the conversation history and uploaded files, revoke external access permissions, and request that the service provider stop processing or delete the relevant information. Whether the incident requires a personal data breach report or notification to affected individuals should be determined by considering the type and volume of information involved, the possibility of third-party access, whether the data has been deleted, and the potential harm to the individuals concerned. Effective Generative AI Use Requires Governance, Not Just Prohibition Generative AI can improve efficiency in contract review, document drafting, and customer communications. However, when its use is left entirely to individual employees, a business may have little control over where customer information and internal documents are transmitted or how they are subsequently used. Businesses should establish specific rules regarding approved services, prohibited data, the removal or replacement of identifying information, approval procedures for high-risk documents, and incident response. Decent Law Firm advises businesses on the legal use of generative AI, including compliance with Korean personal data protection requirements, review of service terms and data-processing agreements, overseas data transfers, trade secret protection, and the preparation of internal AI-use policies. This content is provided for general informational purposes only and does not constitute legal advice regarding any specific matter or business.
2026-07-24 -
법률정보Virtual Asset “Hwanchigi” in Korea: Penalties and Key Changes Under the 2026 Foreign Exchange Transactions Act
As cross-border transactions involving virtual assets and overseas payment services continue to increase, Korean regulators are paying closer attention to whether such transactions constitute unlicensed foreign exchange business or illegal remittance activities. The Korea Customs Service recently conducted targeted inspections of high-risk money exchange businesses and identified violations involving false transaction records, foreign currency sales exceeding statutory limits, and failures to report large cash transactions. The businesses selected for inspection also included entities suspected of using virtual assets for illegal cross-border remittances. A major regulatory change will take effect on December 3, 2026, when the amended Foreign Exchange Transactions Act comes into force. Under the amended Act, certain cross-border virtual asset transfer services will become subject to a separate registration requirement. Virtual asset service providers, payment companies, remittance operators, and businesses offering cross-border settlement services should review whether their current business models fall within the scope of the new registration regime. What Is “Hwanchigi” Under Korean Law? “Hwanchigi” is not a term expressly defined in the Foreign Exchange Transactions Act. It generally refers to an arrangement in which funds are transferred across borders without using a bank or another authorized foreign exchange institution. Instead, separate pools of funds or accounts in Korea and another country are used to produce the same economic effect as an international remittance. For example, a person in Korea may pay Korean won to a local operator, while the operator’s overseas partner pays an equivalent amount in foreign currency to the intended recipient abroad. The Korean won received in Korea is not physically transferred overseas. Nevertheless, because a corresponding payment is made abroad, the arrangement produces substantially the same result as an international remittance. Article 8 of the Foreign Exchange Transactions Act generally requires a person who engages in foreign exchange business as a commercial activity to obtain the necessary registration. A person may therefore be regarded as participating in foreign exchange business even if they did not personally send money overseas, provided that their role formed part of a broader structure designed to complete a cross-border payment. A Transaction May Be Regulated Even If No Foreign Currency Crosses the Border Under Korean foreign exchange law, the key issue is not whether the same cash or foreign currency physically crossed the border. What matters is whether payments made in Korea and abroad were connected in a manner that produced the same economic effect as a cross-border transfer. Common structures that may raise regulatory concerns include the following. ▪️ Korean Won Received in Korea and Foreign Currency Paid Overseas A Korean account receives the funds, while an overseas partner or local office pays foreign currency to the designated recipient abroad. ▪️ Funds Received Overseas and Korean Won Paid in Korea Foreign currency or local currency is received outside Korea, and Korean won is then paid into a designated Korean bank account. ▪️ Settlement Through Third-Party Accounts Funds are paid or received through accounts held by family members, employees, acquaintances, or unrelated business entities rather than the actual sender or recipient. ▪️ Offshore and Domestic Obligations Offset Against Each Other Amounts payable in Korea and abroad are offset, allowing the parties to settle without making a conventional international bank transfer. If these transactions are conducted repeatedly and the operator earns fees or profits from exchange-rate differences, the activity may be treated as unregistered foreign exchange business. Why the Supreme Court Treated Virtual Asset Arbitrage as Foreign Exchange Business In its September 4, 2025 decision, Supreme Court Case No. 2024Do16540, the Court confirmed that a transaction may constitute foreign exchange business even where no foreign currency was directly transferred across the border. In that case, the defendant received virtual assets from a non-resident located overseas, sold them through a Korean virtual asset exchange, and transferred the proceeds in Korean won to multiple domestic bank accounts designated by the non-resident. The defendant did not personally remit foreign currency overseas. Nevertheless, the Supreme Court upheld the lower court’s finding that the transaction performed substantially the same function as an inbound remittance service, in which a Korean foreign exchange bank pays Korean won to a domestic recipient based on payment instructions from a foreign bank. The relevant question was therefore not simply whether the defendant had directly sent funds abroad. The Court examined whether the overall transaction structure effectively facilitated payments between Korea and another country. However, the sale of virtual assets followed by a domestic Korean won transfer does not automatically constitute unregistered foreign exchange business in every case. The following factors should be considered together: ▪️ The purpose and background of the transaction ▪️ The size and frequency of the transactions ▪️ The duration and degree of repetition ▪️ Whether fees or exchange-rate profits were earned ▪️ Whether the activity was conducted as a business Can Virtual Assets and Overseas Payment Services Be Treated as Hwanchigi? The use of virtual assets or overseas payment services does not, by itself, exclude a transaction from the application of Korean foreign exchange laws. ▪️ Receiving Korean Won and Sending Virtual Assets to an Overseas Wallet Where Korean won is received in Korea and Bitcoin, USDT, or another virtual asset is sent to an overseas recipient in return, the transaction may be treated as a cross-border payment service rather than a simple virtual asset sale. ▪️ Receiving Virtual Assets Overseas and Paying Korean Won in Korea A transaction may also be treated as cross-border payment activity where virtual assets received from overseas are sold in Korea and the proceeds are paid into domestic accounts designated by the overseas party. ▪️ Settling Funds Through WeChat Pay or Alipay Regulatory concerns may arise where Korean won is received in Korea and an overseas payment account is funded abroad, or where funds are received overseas and Korean won is paid to a recipient in Korea. These transactions are not automatically illegal. The authorities will generally examine: ▪️ Whether the domestic payment corresponded to an overseas payment ▪️ Whether third-party accounts were used ▪️ Whether the activity was repeated ▪️ Whether the operator earned fees or exchange-rate profits ▪️ Whether the transaction was conducted for a commercial purpose Key Changes Under the 2026 Amendment to the Foreign Exchange Transactions Act The amended Foreign Exchange Transactions Act was promulgated on June 2, 2026 and will take effect on December 3, 2026. The amendment introduces three major changes. ▪️ Registration Requirement for Cross-Border Virtual Asset Transfer Services A virtual asset service provider that uses virtual asset sales, purchases, or exchanges to transfer value between Korea and another country, or to produce substantially the same effect, will be required to register with the Minister of Economy and Finance. A virtual asset service provider registration under the Act on Reporting and Using Specified Financial Transaction Information may not be sufficient by itself. A separate registration under the Foreign Exchange Transactions Act may be required where the business provides cross-border virtual asset transfer services. ▪️ Stronger Administrative Sanctions for Operating Outside the Registered Scope A specialized foreign exchange business operator that conducts foreign exchange activities outside its registered scope may be subject to: ▪️ Cancellation of registration ▪️ Business restrictions ▪️ Suspension of business ▪️ Administrative surcharges imposed in place of certain suspension measures Businesses should therefore confirm that their actual services remain within the scope of their registration. ▪️ Criminal Penalties for Unregistered Business and Certain Payment Procedure Violations A person who conducts cross-border virtual asset transfer business without registration may be subject to: ▪️ Imprisonment for up to three years ▪️ A fine of up to KRW 300 million The amended Act also introduces criminal penalties of: ▪️ Imprisonment for up to one year ▪️ A fine of up to KRW 100 million These penalties may apply where a person violates prescribed payment procedures for the purpose of obtaining an improper financial benefit for themselves or another person. The amendment does more than simply clarify which businesses must register. It expressly brings cross-border virtual asset transfer services within the registration framework and clarifies the scope of criminal liability for unregistered activities and certain payment procedure violations. The Substance of the Fund Flow Matters More Than the Name of the Transaction Virtual asset-based hwanchigi and arbitrage cases are primarily governed by the Foreign Exchange Transactions Act. Depending on the transaction structure, the following laws may also apply: ▪️ The Act on Reporting and Using Specified Financial Transaction Information ▪️ The Virtual Asset User Protection Act ▪️ Other criminal and financial regulations related to money laundering, fraud, or unlawful fund transfers Businesses and individuals should review the entire flow of funds, including: ▪️ The roles of the parties ▪️ Domestic and overseas bank transactions ▪️ Wallet transfers and transaction records ▪️ Fee and exchange-rate arrangements ▪️ The frequency and commercial nature of the activity Decent Law Firm’s Virtual Asset Practice Group advises clients on investigations involving alleged violations of the Foreign Exchange Transactions Act and virtual asset-based remittance activities. We also assist virtual asset businesses, payment providers, and cross-border settlement operators in assessing whether their services are subject to registration under the amended Act. Where the Korea Customs Service or the police requests attendance or submission of documents, or where a business needs to determine whether its services fall within the amended regulatory framework, the transaction structure and supporting records should be reviewed before responding. This publication is provided for general informational purposes only and does not constitute legal advice for any specific matter.
2026-07-13 -
법률정보Illegal Crypto OTC Trading in Korea: Investigation Risks for Users
In June 2026, the Financial Services Commission (FSC) and the Korea Financial Intelligence Unit (KoFIU) announced that 12 suspected illegal virtual asset operators had been referred to the police following a joint investigation by DAXA and registered virtual asset service providers. According to the announcement, the investigation identified 8 illegal over-the-counter (OTC) crypto dealers and 4 overseas exchanges suspected of conducting business targeting Korean users without proper registration. These operators allegedly attracted users through Telegram, websites, open chat rooms, Korean-language services, KRW payment support, and domestic marketing activities. The Korean financial authorities have also warned that users of unregistered virtual asset service providers may face unexpected disadvantages, including being subject to investigation during the process of verifying counterparties and the source of funds. This article explains the key legal risks that may apply to users of illegal crypto OTC channels in Korea and how investigative authorities may assess the user’s knowledge and intent. Key Laws That May Apply Under Korea’s Act on Reporting and Using Specified Financial Transaction Information, commonly referred to as the Specified Financial Information Act, virtual asset service providers must report to KoFIU before conducting business in Korea. An operator that conducts virtual asset business without proper reporting may be subject to criminal penalties under Article 17 of the Act, including imprisonment of up to 5 years or a fine of up to KRW 50 million. In principle, the direct target of punishment under this provision is the unregistered business operator. However, depending on the circumstances of the transaction, users may also be investigated under other laws. Category Key Issue Potential Penalty Article 3(1) of the Act on Regulation and Punishment of Criminal Proceeds Concealment Disguising the acquisition or disposition of criminal proceeds, disguising the origin of criminal proceeds, or concealing criminal proceeds Imprisonment of up to 5 years or a fine of up to KRW 30 million Article 4 of the Act on Regulation and Punishment of Criminal Proceeds Concealment Receiving criminal proceeds while aware of the relevant circumstances Imprisonment of up to 3 years or a fine of up to KRW 20 million Article 17 of the Specified Financial Information Act Operating an unregistered virtual asset business Imprisonment of up to 5 years or a fine of up to KRW 50 million For ordinary users, direct liability for violating AML obligations under the Specified Financial Information Act is generally limited. In actual investigations, however, authorities tend to focus more closely on the source of funds, the identity of the counterparty, the transaction pattern, and the reason for using an OTC channel instead of a registered exchange. Key Legal Issue: The User’s Knowledge Illegal crypto OTC channels are often considered high-risk because they can make fund flows difficult to trace. For this reason, they may be misused for converting or concealing funds related to crimes such as narcotics, illegal gambling, phishing, or other fraud. In these cases, the key issue is whether the user knew, or could reasonably be seen as having known, that the funds were criminal proceeds or that the transaction structure was abnormal. The Supreme Court of Korea has held that, for a violation of the Criminal Proceeds Concealment Act, it is sufficient for the person to recognize that the property in question constitutes criminal proceeds. The person does not necessarily need to know the exact type or details of the underlying crime. Supreme Court Decision 2006Do5288, January 11, 2007 In other words, even if the user did not know the specific crime involved, intent may still be recognized if the user was aware that the funds were illegal in nature. Therefore, simply saying that the user did not know the operator was unregistered may not be enough. The user must be able to explain, based on the transaction history and structure, why there was no reasonable basis to suspect illegality. Circumstances Investigators May Review When it is difficult to directly confirm a user’s intent, investigative authorities may infer the user’s knowledge from the surrounding circumstances. Common factors include: · Use of unofficial trading channels Trading through Telegram channels, open chat rooms, or private OTC groups instead of registered exchanges. · Repeated or continuous transactions Using the same method over a long period of time or conducting multiple transactions. · Unclear source of funds Difficulty identifying where the funds came from or who the true counterparty was. · Abnormal conditions compared to registered exchanges Using a structure that allows KRW payments, fast conversion, or trading without proper identity verification. Authorities usually do not rely on a single factor alone. Instead, they assess the overall transaction period, frequency, amount, channel characteristics, and fund flow to determine whether the user may have recognized the illegality of the transaction. Decent Law Firm Virtual Asset Practice Group Investigations involving users of illegal crypto OTC channels often involve multiple legal issues at the same time, including violations of the Specified Financial Information Act, the nature of the transaction funds, and whether the user had knowledge of criminal proceeds. Decent Law Firm’s Virtual Asset Practice Group has advised and represented clients in matters involving unregistered virtual asset service providers, OTC crypto transactions, and criminal proceeds concealment allegations from the early stages of investigation. If you have been contacted by the police or prosecutors in Korea, or if you are unsure about the nature of the allegations, it is important to review your transaction history and response strategy before attending any investigative interview. Source: Financial Services Commission, Press Release on Caution Against Using and Trading with Illegal Virtual Asset Operators, June 24, 2026 This content is provided for general informational purposes only and does not constitute legal advice for any specific case.
2026-06-26