Database

Browse Database

KOREA

Since March 2001, as amended in May 2010, last amended in July 2022
Since August 2017

Pillar Technical standards applied to ICT goods and online services  |  Sub-pillar Restrictions on encryption standards
Electronic Government Act (전자정부법)

Encryption Modules Implementation Guideline (암호모듈 구현 지침)
If software systems or hardware equipment such as virtual private network and firewall systems deal with non-confidential yet important information and are to be used in the government, they must pass verification for appropriate encryption modules under the auspices of National Intelligence Service (NIS). Appropriate encryption standards are ones developed in Korea such as ARIA, SEED, LEA, and Hight. The suppliers need to submit the source code of their products to receive the verification test. The same encryption standards also apply to certain network equipment such as VPN and SW USB series.
Coverage Software, network equipment, and other hardware equipment

KOREA

Last visited in 2021

Pillar Technical standards applied to ICT goods and online services  |  Sub-pillar Self-certification for product safety
Electrical Appliances Safety Control Act (전기용품 및 생활용품 안전관리법)
The Electrical Appliances Safety Control Act authorizes the Korean Agency for Technology and Standards to develop safety certification schemes for the import of electronic appliances. The agency has created three certification schemes: KC Safety Certification, KC Safety Confirmation, and SDoC.
The requirements are the following:
- Type 1 products must go through certification procedure that includes factory inspection (initial and regular) with mandatory product testing every two years in order to get KC Certification. Type 1 products include electric wire, cords, switches for electrical appliances, motor-oriented electric tools, breakers, insulated transformers, and lighting appliances;
- Type 2 products, which are considered less dangerous, must overcome certification procedure that includes safety testing without factory inspection. Type 2 products include electric switch, electric appliances, audio and video electronic apparatus, lighting appliances, insulated transformers, and information technology equipment;
- Type 3 products are qualified to be clear of mandatory certification procedures with a showing of SDoC. Except for products that qualify for SDoC, the other two procedures that include local testing could be burdensome. Type 3 products include fluorescent lamps starter, DC power supplies, and electric charger connected to the electric appliances as well as some electric appliances, audio and video electronic apparatus, and information technology equipment.
Coverage Electrical appliances

KOREA

Since 2010

Pillar Technical standards applied to ICT goods and online services  |  Sub-pillar Self-certification for product safety
Radio Wave Act (전파법)
The Ministry of Science, ICT & Future Planning (MSIP) is an authority that conducts EMC and wireless communication certification. KC certification is issued by Korea’s National Radio Research Agency (RRA) and requires testing at an RRA-approved laboratory. There are three mandatory certification mechanisms for imported broadcasting and communications equipment to test the safety of radio waves (Article 58-2):
- Certain equipment must receive certification of conformity from the Ministry of Science, ICT and Future Planning after undergoing a test by a designated third-party laboratory. Such equipment includes wireless telephone alarm automatic receiver, radar equipment for ships, telephone, and modem;
- Equipment that is not subject to this certification may come in only with a showing of confirmation that verifies the compatibility after undergoing a test either by a designated third-party testing body or self-tests. The equipment that falls in this category includes Computing device and peripheral, broadcasting set-top box, measuring instrument, industrial device, and connector.
- Equipment that is not subject to neither of these schemes must have interim of conformity after passing a test showing conformity with domestic or international standards. Equipment that is newly development but whose conformity assessment criteria have not been developed fall in this category.
Korea has entered into a mutual recognition arrangement with the United States, Canada, EU, Vietnam, and Chile. However, except for Canada, the import of broadcasting and communications equipment from the other countries must still receive certification of conformity from the South Korean government even if a conformity test has been conducted in the exporting countries.
Coverage Broadcasting and communications equipment

KOREA

Since December 1986, as amended in December 2008, last amended in June 2022

Pillar Quantitative trade restrictions for ICT goods and online services  |  Sub-pillar Export restrictions on ICT goods or online services
Foreign Trade Act (대외무역법)
Since 2008, the Foreign Trade Act has required a license prior to export of strategic items. These items include dual-use items. Among them, electronics (category 3), computers (category 4), telecommunications and information security (category 5), and sensors and lasers (category 6) are relevant to digital goods. These categories are controlled by the Ministry of Trade, Investment, and Energy.
Coverage Strategic items

KOREA

Since January 2005

Pillar Content access  |  Sub-pillar Licensing schemes for digital services and applications
Location Information Use and Protection Act (위치정보의보호및이용등에관한법률)
Per Art. 5 of the Location Information Use and Protection Act, any person who intends to engage in location information business shall obtain permission from the Korea Communications Commission. According to Art. 18 of the Act, even if permitted to do such business, location information providers or location-based service providers cannot collect location information of individuals without individuals' consent. It is reported that, although a supplier may export location information once acquiring a permit, Korea has never approved such a permit despite numerous applications by foreign suppliers over the past decade.
Coverage Location-based services

KOREA

Since November 1987, as amended in December 2009, last amended in December 2021

Pillar Content access  |  Sub-pillar Licensing schemes for digital services and applications
Act on the Promotion of Newspapers, Etc. (신문 등의 진흥에 관한 법률)
Under Art. 13 of the Act on the Promotion of Newspapers, a person who is not a national of Korea shall not be qualified as a publisher or editor of an online newspaper, or as a news article layout manager of an online news service. This requirement has been in place since 2009.
Coverage Online newspapers

KOREA

Since December 1984, as amended in April 2015, last amended in June 2022

Pillar Intermediary liability  |  Sub-pillar Monitoring requirement
Telecommunications Business Act (전기통신사업법)
The amendment of the Telecommunications Business Act by Act no. 12761 on 15 October 2014, included Article 22-3. According to Art. 22-3, value-added telecommunication service providers, encompassing all online hosts of applications and content, must implement technical measures as outlined in the Presidential Decree to counteract the dissemination of explicit materials.
Coverage Internet hosting services

KOREA

Reported in 2021

Pillar Intermediary liability  |  Sub-pillar User identity requirement
Mandatory SIM card registration
It is reported that Korea imposes an identity requirement for SIM registration. Anyone wanting to purchase a SIM card has to provide their national ID card, or a passport in case of foreigners, to activate a new prepaid SIM card.
Coverage Telecommunications sector

KOREA

Since April 2006

Pillar Intermediary liability  |  Sub-pillar User identity requirement
Game Industry Promotion Act (게임산업진흥에 관한 법률)

Law No. 10879 (법률 제10879호)
According to Arts. 12-3 of the Game Industry Promotion Act, users are required to verify the real names and ages of users of game products when they join as members and self-authenticate. This requirement has been in place since 2011 within the amendment of the Game Industry Promotion Act through Law No. 10879 of July 2011.
Coverage Gaming industry

KOREA

Since January 1957, last amended in December 2022

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for copyright infringement
Copyright Act (저작권법)

Act on Promotion of Information and Communications Network Utilization and Information Protection etc (정보통신망 이용촉진 및 정보보호 등에 관한 법률)
Art. 122-2 of the Copyright Act lead to the establishment of the Korean Copyright Protection Agency (KCOPA) in 2016. According to Art. 133-3, in the event that KCOPA conducts an investigation into the information and communications network of an online service provider and detects the transmission of illegal reproductions, among others, the Protection Agency, upon deliberation of the Deliberation Committee, is empowered to apply the following corrective measures:
- Issue a warning to those who reproduce or transmit illegal copies, among others.
- Proceed with the suppression or suspension of the transmission of illegal copies, among others.
- Suspend the accounts of photocopiers and transmitters that continue to repeatedly transmit illegal copies, among others.
In addition, the agency is also empowered to file a request to block access to foreign websites that are infringing copyrights, based on Art. 44-7 of the Law on the Promotion of the Use of Information and Communications Networks and Information Protection.
Coverage Internet host services

KOREA

N/A

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place beyond copyright infringement
A basic legal framework on intermediary liability beyond copyright infringement is absent in Korea's law and jurisprudence.
Coverage Internet intermediaries

KOREA

Since January 1957, as amended in June 2006, last amended in December 2022

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for copyright infringement
Copyright Act (저작권법)
The Copyright Act establishes a safe harbour regime for intermediaries for copyright infringements since the amendment of the law in 2006. According to Art. 102 of the law, ISPs are not liable for copyright infringement as a result of being a mere conduit for caching, hosting, and searching information. Additionally, an Internet service provider will not be held liable for a user's infringing act of reproducing or transmitting a copyrighted work if it is technically impossible for the service providers to take measures as described in the listed requirements.
Coverage Internet and Internet host services

KOREA

Since 2011

Pillar Domestic data policies  |  Sub-pillar Requirement to perform an impact assessment (DPIA) or have a data protection officer (DPO)
Personal Information Protection Act (개인정보보호법)
Under the Personal Information Protection Act, data controllers must appoint a privacy officer who comprehensively takes charge of personal information processing (Art. 31). The requirement has been in place since its enactment in 2011.
Coverage Horizontal

KOREA

Since 2006

Pillar Domestic data policies  |  Sub-pillar Minimum period for data retention
Enforcement Decree of Electronic Financial Transactions Act (전자금융거래법 시행령)
Enforcement Decree of Electronic Financial Transactions Act provides under Art. 12 that a subsidiary electronic financial company such as payment gateway system that records and transmit electronic transaction information must keep the records at least for three years. This affects not only payment gateway services providers but also electronic commerce firms that utilize the services. This retention period requirement has been in place since its enactment in 2006.
Coverage Payment gateway services

KOREA

Since 1994

Pillar Domestic data policies  |  Sub-pillar Minimum period for data retention
Enforcement Decree of Protection of Communications Secrets Act (통신비밀보호법 시행령)
Per Art. 41 of Enforcement Decree of Protection of Communications Secrets Act, telecoms or internet infrastructure operators should retain for 12 months the following:
- the date of the telecommunication, the commencement time and end time of the telecommunication, the communications number of outgoing and incoming calls, the frequency of use, and the location data for 12 months (six months in case of long-distance calls and local call services); and
- the log records of users and the location data for three months.
This requirement has been place since the Act's enactment in 1994.
Coverage Telecommunications services

Report issue     Report new measure