# PIPA Amendment Would Let Companies Reuse Existing Personal Data for AI Development — Subject to PIPC Review
A consolidated amendment (대안) to the Personal Information Protection Act was transferred to the government for promulgation on 8 September 2026. It adds new Articles 28-12, 28-13, and 28-14, creating a legal basis for personal-information controllers to reuse personal data they already lawfully collected — for the purpose of AI technology development — where anonymized or pseudonymized processing is not workable. No effective date has been set yet; the bill is currently at the promulgation stage, not in force.
What the amendment does
- New use case for existing data (Art. 28-12(1)). A controller may use previously, lawfully collected personal data for AI development only if all of the following are met: (1) anonymization or pseudonymization is genuinely difficult for the AI development in question; (2) the controller has put in place safety measures for secure processing; and (3) the purpose serves the public interest or social benefit, with a markedly low risk of unjustly harming the data subject's or a third party's interests.
- PIPC deliberation and resolution required. Even where all three conditions are met, use is conditioned on going through the Personal Information Protection Commission's (PIPC) deliberation-and-resolution process. There is no self-assessment path.
- Prior risk assessment for higher-risk cases (Art. 28-12(3), (6)). Where criteria to be set by presidential decree are met — factors include whether sensitive information or unique identifiers are processed, and the degree of impact/risk to data subjects — a risk assessment must be completed *before* the PIPC deliberation, and the main content of that assessment must be publicly disclosed.
- Simplified review for repeat cases (Art. 28-12(4)). Where an AI technology or service is substantially the same as or similar to one that already went through deliberation and resolution, the PIPC may simplify the review procedure for it.
- Ongoing supervision and a processing restriction (Art. 28-13, 28-14). The PIPC will periodically check compliance with matters it approved. If a controller obtained approval by fraud or false means, or fails to continue meeting the qualifying conditions, its processing under this special provision can be restricted.
What this means for you
- If you plan to reuse Korean user data you already hold for AI model or feature development, this is the provision to track — it is the mechanism that would let you do so without full anonymization or pseudonymization, but only through PIPC deliberation, not by internal decision.
- Do not treat this as available yet. The bill has been transferred for promulgation but has no confirmed effective date, and the presidential-decree criteria (which determine when a prior risk assessment is required) have not been issued.
- Prepare your safety-measure documentation now. "Safety measures for secure processing" is a stated precondition — if you intend to use this route once it takes effect, start building the record you would need to show it.
- Watch for the presidential decree. It will define which cases (sensitive information, unique identifiers, risk level) trigger the mandatory prior risk assessment and public disclosure — this is where your specific data set and use case will be sorted into standard or heightened review.
- Note the downside risk. Obtaining approval through false or fraudulent means, or later failing to meet the qualifying conditions, exposes you to a processing restriction — plan for the possibility of losing the basis for use, not just for obtaining it.
Source: 2220246_2220246_의사국 의안과_의안원문.pdf