Hyeonsu “Elliot” Jin
MP elliot@decentlaw.ioElliot served as a corporate lawyer at Pyeongan Lawfirm and as in-house counsel for Chai Corporation, providing diverse corporate advisory services.
- Corporate · Startups
- Cross-border · Dispute Resolution
- Crypto
- VC · Financial Advisory
- IP Litigation
- Sports
- 학력
- New York University B.A., Political Science Inha University School of Law J.D. Postech Blockchain Expert Program
- 경력
- Legal Advisor to Ministry of Gender Equality and Family Pyeongan Lawfirm (Corporate, Crypto, Criminal, Data) Chai Corporation (Legal Counsel) Kim & Chang (Intern) Yulchon (Intern) Korean Air (Intern)
- 자격
- Attorney, Korea My Data Manager Regular Member of the Blockchain Law Society
- 언어
- English Korean
- 업무사례
-
-
[Corporate/Startups]
- Corporate criminal cases involving embezzlement, misappropriation by CEOs, drug-related offenses, and sexual crimes litigation.
- Domestic and international mid-sized company and startup litigation and advisory on corporate damages and lawsuits.
- M&A, legal due diligence, investment agreements, VC/PE corporate legal advisory.
- Startup investment agreements, terms of service, personal data legal advisory.
- Inter-corporate dispute resolution and civil/criminal litigation.기업형사, 대표이사의 배임, 횡령, 마약, 성범죄 사건 등 소송
- Multinational civil, criminal, IP dispute resolution and litigation.
- Establishment of corporations and bank account openings in Singapore, BVI, Switzerland.
- English supply contract review and advisory with international electric vehicle company T.
- English contract drafting, review, translation, etc., with international record label W.
- English contract drafting, review, translation, etc., for fintech company K.
- Comprehensive tax audit advisory for Korea's largest virtual asset investment company, H.
- Business structure comprehensive consulting advisory for virtual asset issuance P2E company P.
- Progression of ICO, SAFT, and exchange acquisition contracts for virtual asset issuance corporation B.
- Review and advisory of white papers for virtual asset and NFT issuance corporations.
- Tax investigation response advisory for algorithmic trading companies U and B.
- Business model structure review and advisory for NFT trading platform operations of corporation K.
[Cross-border / Dispute Resolution]
[Crypto]
성공사례
-
Crypto 소송사례
Fraud Allegations Involving a Crypto Trading Signal Room and Referral Program — Case Closed Without Referral to Prosecutors
Client Information Individual / Suspect Case Details The client worked for a company that provided cryptocurrency-related information and was responsible for assisting prospe...
Police Non-Referral Decision -
Corporate & Biz 자문사례
Employment Agreement for a Quasi-Investment Advisory Expert: Clarifying the Scope of Duties and Allocation of Liability
Client Information Corporate / Business Entity Case Details The client operates a quasi-investment advisory business in Korea, providing investment-related content to an u...
Employment Agreement Review Completed -
Crypto 자문사례
USDT Sponsorship Agreement Review and Successful Contract Execution with an Overseas Participant
Client Information Corporate / Business Entity Case Details The client was preparing a digital asset industry event in Korea and planned to enter into booth operation and ...
Delivery of the Final English Sponsorship Agreement -
Criminal 소송사례
Conditional Deferred Prosecution in a Sexual Exploitation Communication Case under Korea’s Youth Protection Law
Client Information Individual / Suspect Case Details The client was a career service member in his early twenties with no prior criminal record or history of police investiga...
Conditional Deferred Prosecution
관련소식
-
법률정보Legal Representation for Sex Crime Victims: Reporting Is Not the End
What Does Legal Representation for Sex Crime Victims Mean? Legal representation for sex crime victims refers to a system that allows survivors of sexual offenses to exercise their rights throughout the criminal process through an attorney. Support is available through the court-appointed victim attorney system under relevant statutes Attorneys accompany victims during police and prosecutor investigations, assist in gathering evidence, and support settlement and damages negotiations through the entire process Attorneys protect the victim's procedural rights and interests from unfair pressure or inducement by the offender's defense counsel In this way, legal representation for sex crime victims goes beyond simply accompanying the investigation — it provides substantive legal support that helps victims complete the process without suffering secondary harm. From Reporting to Trial: What Is the Process? Cases handled through victim legal representation generally proceed through the following steps. Filing a report and complaint - Reporting the incident and submitting a criminal complaint to the police Victim interview - Providing statements and evidence with the attorney present Investigation by authorities - Investigation of the offender, forensic examination of evidence, and witness questioning Case referral and indictment decision - After police referral, the prosecutor decides whether to indict or not Trial and claim for a restitution order - Participation in trial, criminal mediation, and, if requirements are met, a restitution order to help restore the victim's losses Since the consistency of initial statements and the preservation of evidence during this process critically affect the outcome of the case, it is essential to receive legal assistance as soon as possible after reporting. A Real Case: Legal Representation for a Sex Crime Victim [Case We Handled] Ms. B, a woman in her twenties, hesitated to report workplace sexual harassment and filed her complaint only after considerable time had passed. Although evidence was scarce by then, with Decent Law Firm's help she systematically organized circumstantial evidence and responded appropriately to secondary-harm-inducing questions during the investigation, ultimately leading to the offender's indictment. As this shows, the outcome of a sex crime victim representation case can vary greatly depending on the initial response and how well the evidence is organized. The Attorney's Role, and Why You Should Work With Decent Sex crime victim representation cases require a professional approach that includes the following. Preventing secondary harm and supporting psychological stability by accompanying the victim during investigations Strengthening the case through evidence collection and assistance with statements Developing follow-up strategies for settlement, damages, and criminal mediation Decent Law Firm has extensive experience handling numerous sex crime victim representation cases, closely analyzing each client's situation and building a systematic support strategy from the initial report through trial and compensation. We stand by clients from beginning to end so that those who are already psychologically vulnerable from the harm they suffered are not hurt again during the process. Sex crime victim representation is a type of case where, as time passes, securing evidence and responding effectively become increasingly difficult. If you have already suffered harm or are considering filing a report, we recommend consulting first with an attorney experienced in sex crime cases rather than deciding on your own. Decent Law Firm is always ready to provide prompt and accurate legal consultation to help you find the best direction for your situation.
2026-07-24 -
법률정보Generative AI and Personal Data: What Businesses Should Check Before Uploading Customer Information or Contracts
Businesses are increasingly using generative AI to review contracts, summarize meetings, respond to customer inquiries, and draft documents. However, when contracts or other materials entered into an AI service contain personal data relating to customers or employees, the issue extends beyond operational efficiency. It may raise concerns regarding personal data processing, confidentiality, and the management of internal business information. Businesses should therefore understand how an AI service stores and uses input data and establish internal rules that reflect how generative AI is actually used within the organization. How Is Information Entered into Generative AI Processed? From the user’s perspective, generative AI appears to involve simply entering a question and receiving a response. In practice, however, prompts and uploaded files are transmitted to the service provider’s systems. Depending on the service policy and account type, they may be retained as conversation records or system logs and may also be used to improve the service. Before entering business materials, companies should check: ▪️ Whether input data may be used to train the AI model ▪️ How long conversations and uploaded files are retained ▪️ Whether conversations and uploaded materials can be deleted ▪️ In which country and on which servers the data is processed ▪️ What access permissions are granted when the AI is connected to external applications or internal systems Using a paid or enterprise account does not automatically resolve every data protection issue. The relevant contractual terms and actual data-processing arrangements must also be reviewed. Is Information No Longer Personal Data Once the Name Is Removed? Removing a customer’s name or contact information from a contract does not necessarily mean that the remaining information is no longer personal data. Personal data includes not only information that directly identifies an individual, such as a name, but also information that may identify a person when combined with other readily available information. Even after a name has been removed, an individual may still be identifiable through a combination of information such as: ▪️ The company name and a specific job title ▪️ The contract date and transaction amount ▪️ The employee’s department and performance evaluation ▪️ Detailed consultation history and family relationships ▪️ A case number and the location of a dispute A company name alone is generally information about a legal entity. However, when combined with a specific position, transaction details, or other contextual information, it may make an individual employee or representative identifiable. Businesses should therefore remove information that is unnecessary for the intended task rather than deleting names alone. Actual names, contact details, company names, and similar identifiers may also need to be replaced with fictional or generic information. Does Entering Customer Information Automatically Violate Korea’s Personal Information Protection Act? Entering customer information into a generative AI service does not automatically constitute a violation of Korea’s Personal Information Protection Act, commonly referred to as the PIPA. However, a business may generally use personal data only within the scope of the original purpose of collection and an appropriate legal basis. It is therefore necessary to assess whether the intended AI use is related to the original processing purpose and whether additional consent or another legal basis is required. The relationship between the business and the AI service provider must also be reviewed. The applicable legal framework may differ depending on whether the provider processes data solely on the company’s instructions or also uses the input data for its own purposes, such as model training or service improvement. Depending on the actual arrangement, the use of the service may involve outsourced processing, third-party provision, or other forms of data processing. If personal data is transferred to servers or service providers located outside Korea, the requirements governing overseas transfers must also be considered. The applicable rules cannot be determined solely from the fact that customer information was entered into an AI service. Businesses should review the actual contractual structure and data flow, including: ▪️ The legal basis for using personal data in the relevant AI task ▪️ The purposes for which the service provider uses input data ▪️ Whether the data is used for training or service improvement ▪️ The data-retention period and deletion procedures ▪️ The server locations and countries to which data is transferred ▪️ The involvement of subprocessors or downstream service providers ▪️ How input data is handled after the service contract ends Contracts and Consultation Records Raise More Than Personal Data Issues Contracts and customer consultation records may contain confidential business information in addition to personal data. Examples include: ▪️ Transaction terms and supply prices ▪️ Sales strategies and business plans ▪️ Technical materials and development information ▪️ Confidentiality obligations agreed with customers or business partners ▪️ Strategies for litigation, investigations, or other disputes ▪️ Non-public financial information and internal decision-making materials Entering such information into an external generative AI service may raise issues under the PIPA, but it may also create risks involving contractual confidentiality obligations, trade secret protection, customer security agreements, and internal company policies. A corporate generative AI policy should therefore cover not only personal data but also trade secrets, contractual information, technical materials, and dispute-related documents. Internal Rules Businesses Should Establish for Generative AI Use When employees are left to decide individually how generative AI should be used, the company may be unable to identify what information has been entered into which external service. Rather than issuing a general instruction not to enter personal data, businesses should establish practical and specific rules that employees can follow in their day-to-day work. 1. Approved Services and Accounts The company should designate the generative AI services and account types that employees are permitted to use. Employees should also be prohibited from entering business materials through personal accounts or unapproved services. 2. Prohibited Input Data The company should clearly define the information that must not be entered into generative AI services. This may include resident registration numbers, bank account information, health information, other sensitive or high-risk personal data, trade secrets, non-public contractual terms, and materials relating to litigation or criminal investigations. 3. Approval Procedures for High-Risk Documents High-risk materials, such as contracts, human resources documents, and customer consultation records, may be made subject to prior review or approval by the responsible department. 4. Standards for Removing or Replacing Identifying Information Businesses should establish standards for removing or replacing information that could identify an individual or a transaction party, including names, contact details, company names, and transaction amounts. Rather than uploading an entire contract, employees should extract only the clauses required for the relevant task. Actual customer information may also be replaced with fictional names or sample data. 5. Conversation History and Model-Training Settings The company should determine whether the service allows input data to be excluded from model training, whether conversation history can be disabled, and how deletion features operate. 6. Internal Reporting and Incident Response Employees should be required to report promptly if personal data or confidential business information is entered into an AI service by mistake. The company should also establish procedures for deleting records, disabling external integrations, requesting deletion from the service provider, and taking any other necessary measures. What Should a Business Do If Customer Information Has Already Been Entered? If an employee mistakenly enters customer information or an internal document into a generative AI service, the company should first stop any further sharing or use of the resulting output. The following matters should then be reviewed: ▪️ Which account and AI service were used ▪️ What personal data or confidential information was entered ▪️ Whether the conversation and uploaded files can be deleted ▪️ Whether the service was connected to any external applications ▪️ Whether the information may have been used for training or service improvement ▪️ Whether a third party may have gained access to the information Where necessary, the company should delete the conversation history and uploaded files, revoke external access permissions, and request that the service provider stop processing or delete the relevant information. Whether the incident requires a personal data breach report or notification to affected individuals should be determined by considering the type and volume of information involved, the possibility of third-party access, whether the data has been deleted, and the potential harm to the individuals concerned. Effective Generative AI Use Requires Governance, Not Just Prohibition Generative AI can improve efficiency in contract review, document drafting, and customer communications. However, when its use is left entirely to individual employees, a business may have little control over where customer information and internal documents are transmitted or how they are subsequently used. Businesses should establish specific rules regarding approved services, prohibited data, the removal or replacement of identifying information, approval procedures for high-risk documents, and incident response. Decent Law Firm advises businesses on the legal use of generative AI, including compliance with Korean personal data protection requirements, review of service terms and data-processing agreements, overseas data transfers, trade secret protection, and the preparation of internal AI-use policies. This content is provided for general informational purposes only and does not constitute legal advice regarding any specific matter or business.
2026-07-24 -
법률정보Fraud Charges Under Korean Law: How You Could Become a Convict Overnight
What Are the Legal Requirements for Fraud Under Korean Law? Fraud under Korean law is defined by Article 347 of the Criminal Act, and all four of the following elements must be satisfied for a fraud charge to be established. Deceptive act — deceiving the other party (including not only affirmative lies but also omissions that conceal facts) Mistake and disposition of property — the deception causes the other party to fall into a mistaken belief and dispose of property Causation — a causal relationship must exist between the deceptive act and the disposition of property Intent to defraud — the intent to obtain property or a proprietary benefit through the deceptive act Simply failing to repay money does not, by itself, satisfy the legal requirements for fraud. The key question is whether the person lacked the intention or ability to repay at the time of the transaction. What Is the Process, From Investigation to Trial? Whether the legal requirements for fraud are met is typically determined through the following process. 1) Filing a criminal complaint — the investigation begins when the victim files a complaint 2) Questioning of the parties — the circumstances of the transaction, use of funds, and ability to repay are examined 3) Gathering evidence — contracts, text messages, and account records are used to prove intent 4) Referral to the prosecution and indictment decision — the key issue is whether intent to defraud is recognized 5) Trial proceedings — the court makes a final determination on whether the legal requirements for fraud are met Because the circumstances surrounding the transaction and the flow of funds at the time largely determine the outcome, anyone who has been accused should respond carefully from the very beginning. A Real Case: How the Elements of Fraud Were Assessed [Case We Handled] Mr. B, a small business owner, borrowed money from an acquaintance because he urgently needed business funds, but was unable to repay it after a sudden drop in sales and was accused of fraud. With the help of Decent Law Firm, however, he was able to demonstrate — through his business ledgers, records of legitimate transactions, and evidence of efforts to repay at the time of borrowing — that he never had the intent to defraud, and the case ultimately ended in a non-indictment decision. As this shows, if intent to defraud cannot be established, the matter remains a civil default and does not become subject to criminal punishment. The Role of Defense Counsel, and Why You Should Work With Decent Cases involving disputes over the legal requirements for fraud call for the following professional response. Legal analysis of the circumstances of the transaction and the flow of funds Gathering objective evidence to prove the absence of intent to defraud Developing a statement strategy for each stage of the investigation Drawing on its experience handling numerous fraud cases, Decent Law Firm closely analyzes each client's transaction history and builds a systematic defense strategy from the early stages of the investigation through trial. We stand by our clients from beginning to end, so that those wrongly accused of fraud are not unfairly disadvantaged. Whether the legal requirements for fraud are met can vary greatly depending on the facts and how the evidence is interpreted. If you have already been accused or are facing an investigation, we recommend consulting with an attorney experienced in criminal cases rather than trying to assess the situation on your own. Decent is always ready to provide prompt, accurate legal advice and help you find the best direction for your specific situation.
2026-07-22