KOREA
Since October 2006, entry into force in April 2007, last amended in 2025
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Export restrictions on ICT goods or online services
Act on Prevention of Divulgence and Protection of Industrial Technology (산업기술의 유출방지 및 보호에 관한 법률)
Art. 11 of the "Act on the Prevention of Divulgence and Protection of Industrial Technology" provides that when a target institution holding national core technology developed with government research and development subsidies intends to export such technology to a foreign enterprise or any other external entity, whether through sale, transfer or another means, it must obtain prior approval from the Minister of Trade, Industry and Energy. In reviewing an application for approval, the Minister may grant approval after assessing the potential effects of the export on national security, the national economy and other relevant interests, consulting with the head of the competent central governmental administrative authority, and obtaining deliberation by the Committee. Where a target institution holding and managing national core technology that is not subject to this approval requirement seeks to export such technology, it must submit a prior report to the Minister of Trade, Industry and Energy. Upon receiving this report, the Minister shall examine the likely impact of the proposed export on national security and any other pertinent factors, and shall accept the report if the export is deemed not to pose a serious risk to national security and to comply with the Act. The term national core technology refers to technology designated under Art. 9, the overseas divulgence of which could have a materially adverse effect on national security or on the development of the national economy, owing to its significant technological and economic value in domestic and international markets or its capacity to generate substantial growth in related industries.
Coverage National core technology
KOREA
Since December 1986, as amended in December 2008, last amended in June 2022
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Export restrictions on ICT goods or online services
Foreign Trade Act (대외무역법)
Since 2008, the Foreign Trade Act has required a license prior to the export of strategic goods. These items include dual-use items. Among them, electronics (category 3), computers (category 4), telecommunications and information security (category 5), and sensors and lasers (category 6) are relevant to digital goods. These categories are controlled by the Ministry of Trade, Investment, and Energy.
Coverage Strategic goods
KOREA
Reported in 2022
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Export restrictions on ICT goods or online services
Export ban to Russia on strategic goods
On 28 February 2022, the South Korean Ministry of Economy and Finance (MOEF) introduced export bans on "strategic goods" to Russia. These strategic goods are classified into two categories: "dual-use" and "military use." Among the dual-use items are ICT goods such as machines and apparatus primarily used for the manufacture of semiconductor boules or wafers, semiconductor devices, and electronic integrated circuits. Other items included in the ban are telephone sets, including those for cellular networks or other wireless networks, among others.
Coverage Strategic goods
KOREA
N/A
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
Electrical Appliances Safety Control Act (전기용품 및 생활용품 안전관리법)
The Electrical Appliances Safety Control Act authorises the Korean Agency for Technology and Standards to develop safety certification schemes for the import of electronic appliances. The agency has created three certification schemes: KC Safety Certification, KC Safety Confirmation, and SDoC.
The requirements are the following:
- Type 1 products must go through a certification procedure that includes factory inspection (initial and regular) with mandatory product testing every two years in order to get KC Certification. Type 1 products include electric wire, cords, switches for electrical appliances, motor-oriented electric tools, breakers, insulated transformers, and lighting appliances;
- Type 2 products, which are considered less dangerous, must overcome certification procedures that include safety testing without factory inspection. Type 2 products include electric switches, electric appliances, audio and video electronic apparatus, lighting appliances, insulated transformers, and information technology equipment;
- Type 3 products are qualified to be clear of mandatory certification procedures with a showing of SDoC. Except for products that qualify for SDoC, the other two methods, which include local testing, could be burdensome. Type 3 products include fluorescent lamp starters, DC power supplies, and electric chargers connected to the electric appliances, as well as some electric appliances, audio and video electronic apparatus, and information technology equipment.
The requirements are the following:
- Type 1 products must go through a certification procedure that includes factory inspection (initial and regular) with mandatory product testing every two years in order to get KC Certification. Type 1 products include electric wire, cords, switches for electrical appliances, motor-oriented electric tools, breakers, insulated transformers, and lighting appliances;
- Type 2 products, which are considered less dangerous, must overcome certification procedures that include safety testing without factory inspection. Type 2 products include electric switches, electric appliances, audio and video electronic apparatus, lighting appliances, insulated transformers, and information technology equipment;
- Type 3 products are qualified to be clear of mandatory certification procedures with a showing of SDoC. Except for products that qualify for SDoC, the other two methods, which include local testing, could be burdensome. Type 3 products include fluorescent lamp starters, DC power supplies, and electric chargers connected to the electric appliances, as well as some electric appliances, audio and video electronic apparatus, and information technology equipment.
Coverage Electrical appliances
Sources
- https://web.archive.org/web/20221130003017/https://www.kats.go.kr/content.do?cmsid=44
- https://web.archive.org/web/20241213214311/https://www.law.go.kr/lsInfoP.do?lsiSeq=200901&urlMode=engLsInfoR&viewCls=engLsInfoR#0000
- https://web.archive.org/web/20241213214412/https://elaw.klri.re.kr/kor_mobile/viewer.do?hseq=45624&type=sogan&key=13
- https://web.archive.org/web/20201130011413/https://www.gma.trade/single-post/2019/05/09/south-korea-market-access-for-electrical-and-rtt-products
- Show more...
KOREA
Since March 2011, last amended in 2025
Pillar Domestic data policies |
Indicator Framework for data protection
Personal Information Protection Act No. 10465 (개인정보 보호법)
The Personal Information Protection Act provides a comprehensive framework for data protection in Korea.
Coverage Horizontal
KOREA
Since 1994
Pillar Domestic data policies |
Indicator Minimum period for data retention
Enforcement Decree of Protection of Communications Secrets Act (통신비밀보호법 시행령)
Per Art. 41 of the Enforcement Decree of Protection of Communications Secrets Act, telecoms or internet infrastructure operators should retain for 12 months the following:
- the date of the telecommunication, the commencement time and end time of the telecommunication, the communications number of outgoing and incoming calls, the frequency of use, and the location data for 12 months (six months in case of long-distance calls and local call services); and
- the log records of users and the location data for three months.
This requirement has been in place since the Act's enactment in 1994.
- the date of the telecommunication, the commencement time and end time of the telecommunication, the communications number of outgoing and incoming calls, the frequency of use, and the location data for 12 months (six months in case of long-distance calls and local call services); and
- the log records of users and the location data for three months.
This requirement has been in place since the Act's enactment in 1994.
Coverage Telecommunications services
Sources
- https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%ED%86%B5%EC%8B%A0%EB%B9%84%EB%B0%80%EB%B3%B4%ED%98%B8%EB%B2%95%20%EC%8B%9C%ED%96%89%EB%A0%B9
- https://web.archive.org/web/20220305191230/https://elaw.klri.re.kr/eng_mobile/viewer.do?hseq=33283&type=part&key=43
- https://web.archive.org/web/20211024082047/https://iclg.com/practice-areas/telecoms-media-and-internet-laws-and-regulations/korea
- Show more...
KOREA
Since March 2011, last amended in March 2023
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Personal Information Protection Act No. 10465 (개인정보 보호법)
Under the Personal Information Protection Act, data controllers must appoint a privacy officer who comprehensively takes charge of personal information processing (Art. 31). The requirement has been in place since its enactment in 2011.
Coverage Horizontal
KOREA
Since January 1957, as amended in 2006, last amended in December 2022
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Copyright Act (저작권법)
The Copyright Act, since its 2006 amendment, has established a safe harbour regime for intermediaries, exempting Internet Service Providers (ISPs) from liability for copyright infringement when acting as mere conduits, caching, hosting, or searching information (Art. 102). ISPs are also not liable for users' infringing acts if it is technically impossible for them to take preventive measures.
Coverage Internet intermediaries
Sources
- https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A0%80%EC%9E%91%EA%B6%8C%EB%B2%95
- https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A0%95%EB%B3%B4%ED%86%B5%EC%8B%A0%EB%A7%9D%EC%9D%B4%EC%9A%A9%EC%B4%89%EC%A7%84%EB%B0%8F%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EB%93%B1%EC%97%90%EA%B4%80%ED%95...
- http://elaw.klri.re.kr/kor_service/lawView.do?hseq=25455&lang=ENG
- https://elaw.klri.re.kr/kor_mobile/viewer.do?hseq=42587&type=part&key=43
- https://web.archive.org/web/20210125001209/https://www.kcopa.or.kr/eng/lay1/S1T10C222/contents.do?lnbCd=2
- Show more...
KOREA
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringement
A basic legal framework on intermediary liability beyond copyright infringement is absent in Korea's law and jurisprudence.
Coverage Internet intermediaries
KOREA
Since April 2006, as amended in July 2011
Pillar Intermediary liability |
Indicator User identity requirement
Game Industry Promotion Act (게임산업진흥에 관한 법률)
Art. 12-3 of the Game Industry Promotion Act stipulates that a business entity engaged in the provision of game products, limited to persons who make such products accessible to the public through an information and communications network, is required to verify the real names and ages of users and to conduct self‑authentication procedures when users register as members.
Coverage Gaming sector
KOREA
Reported in 2021, last reported in 2025
Pillar Intermediary liability |
Indicator User identity requirement
Mandatory SIM card registration
It is reported that Korea imposes an identity requirement for SIM registration. Anyone wanting to purchase a SIM card has to provide their national ID card or a passport in case of foreigners to activate a new prepaid SIM card.
Coverage Telecommunications sector
Sources
KOREA
Since December 1984, as amended in April 2015, last amended in June 2022
Pillar Intermediary liability |
Indicator Monitoring requirement
Telecommunications Business Act (전기통신사업법)
The amendment of the Telecommunications Business Act by Act No. 12761 on 15 October 2014 included Art. 22-3. According to Art. 22-3, value-added telecommunication service providers, encompassing all online hosts of applications and content, must implement technical measures as outlined in the Presidential Decree to counteract the dissemination of explicit materials.
Coverage Internet hosting services
Sources
- https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A0%84%EA%B8%B0%ED%86%B5%EC%8B%A0%EC%82%AC%EC%97%85%EB%B2%95
- https://elaw.klri.re.kr/eng_service/lawView.do?hseq=50189&lang=ENG
- https://web.archive.org/web/20241213213057/https://wilmap.stanford.edu/entries/telecommunications-business-act-last-amended-act-no-12761-october-15-2014-english-version
- Show more...
KOREA
Reported in 2025
Pillar Content access |
Indicator Blocking or filtering of commercial web content
Reported blocking of AI application
It is reported that, in February 2025, Korea’s data protection authority blocked downloads of the application developed by the Chinese artificial intelligence firm DeepSeek. The application is said to have become accessible again two months later, following changes to the company’s privacy practices. It is also reported that, in February 2025, multiple Korean ministries blocked access to DeepSeek within their own organisations due to security concerns.
Coverage DeepSeek
KOREA
Since November 1987, as amended in December 2009, last amended in December 2021
Pillar Content access |
Indicator Licensing schemes for digital services and applications
Act on the Promotion of Newspapers, Etc. (신문 등의 진흥에 관한 법률)
Under Art. 13 of the Act on the Promotion of Newspapers, a person who is not a national of Korea shall not be qualified as a publisher or editor of an online newspaper or as a news article layout manager of an online news service. This requirement has been in place since 2009.
Coverage Online newspapers
KOREA
Since January 2005
Pillar Content access |
Indicator Licensing schemes for digital services and applications
Act on the Protection, Use, etc. of Location Information (Act No. 7372 of 27 January 2005) (위치정보의보호및이용등에관한법률)
Per Art. 5 of the Location Information Use and Protection Act, any person who intends to engage in location information business shall obtain permission from the Korea Communications Commission. According to Art. 18 of the Act, even if permitted to do such business, location information providers or location-based service providers cannot collect location information of individuals without individuals' consent. It is reported that, although a supplier may export location information once acquiring a permit, Korea has never approved such a permit despite numerous applications by foreign suppliers over the past decade.
Coverage Location-based services
Sources
- https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9C%84%EC%B9%98%EC%A0%95%EB%B3%B4%EC%9D%98%EB%B3%B4%ED%98%B8%EB%B0%8F%EC%9D%B4%EC%9A%A9%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EB%B2%95%EB%A5%A0
- https://elaw.klri.re.kr/eng_service/lawView.do?hseq=43349&lang=ENG
- https://web.archive.org/web/20240407155542/https://ustr.gov/sites/default/files/2020_National_Trade_Estimate_Report.pdf
- https://web.archive.org/web/20250826091802/https://ustr.gov/sites/default/files/files/Press/Reports/2025NTE.pdf
- Show more...
