Complete Guide to the Pseudonymized Information Combination Application Process (2026 Practice): From Application to Export Review
"We have the data but can't combine it" — the real bottleneck isn't technology
When you try to launch a new data-combination business, you hit a peculiar wall. You have your company's data, the other organization's data you want to combine, even the analysis model ready — and everything stops at "how do we legally put them together?" What actually holds you back is usually not analytics capability but insufficient understanding of the regulatory process.
This problem is especially hard because English-language materials are almost useless. Pseudonymized information combination is a Korea-specific regime grounded in Korea's Personal Information Protection Act and the Notification on the Combination and Export of Pseudonymized Information (PIPC Notification). Knowing GDPR inside out still will not fill in the application form you submit to a combination specialist institution.
So this article is organized around what to submit, where, and how, from the practitioner's point of view. The goal is to let you write the application and plan the timeline without a consultant.
⚠️ Designated combination specialist institutions and detailed processing times can change, so always check Personal Information Protection Commission (PIPC) notices and the relevant combination specialist institution's website before applying.
Pseudonymized vs. anonymized information: what to use, and when
Start with the concepts. Many practitioners ask, "Can't we just anonymize it?" To combine data, it must be pseudonymized information. Anonymized information cannot be restored, so it cannot be linked with a combination key in the first place.
| Category | Pseudonymized information | Anonymized information |
|---|---|---|
| Definition | Processed so a specific individual cannot be identified without additional information | Processed so restoration is impossible given time, cost, and technology |
| Re-identification risk | Possible if combined with additional information (must be stored separately) | Effectively impossible |
| Legal character | Constitutes personal information (PIPA applies) | Not personal information |
| Data-subject consent | Not required when limited to specified purposes | Consent is irrelevant by nature |
| Scope of use | Statistical production, scientific research, public-interest record preservation | No restriction |
| Use in combination | Allowed | Not allowed (key linkage itself is impossible) |
The purposes for which you may use pseudonymized information without consent are limited by law to exactly three:
- Statistical production (including commercial purposes such as market research)
- Scientific research (including industrial R&D)
- Public-interest record preservation
Combining multiple companies' data in pseudonymized form for analysis usually falls under 1 or 2. MyData linkage and building datasets for AI training are also designed within this scope.
Pre-application prep: from combination keys to the application form
Combination is not a single submit-button click. The overall flow looks like this.
[Applicant companies]
│ ① Pseudonymization + prepare combination-key fields
▼
[Combination Key Management Institution (KISA)]
│ ② Generate and match combination keys (serial numbers)
▼
[Combination specialist institution]
│ ③ Perform combination (combine pseudonymized information)
│ ④ Export review + pseudonymization adequacy assessment
▼
[Applicant company] ⑤ Use in analysis environment or exportThere are two core institutions. The Combination Key Management Institution (KISA) generates and manages combination keys (serial numbers) so that the same individuals across different companies can be matched safely, and the combination specialist institution actually performs the combination and conducts the export review.
What applicant companies must finish in advance:
- Combination application form: state the combination purpose, target information, and period of use
- Pseudonymization results: a specification of the processing method per field (deletion, generalization, masking, etc.)
- Purpose and field specification: which data you are combining and why
- Security safeguards plan: access control, encryption, access-log retention, and other data-protection measures
- Combination-key linkage information: one-way hashed values of identifying fields (resident registration number, etc.) to send to KISA
The most common mistake is rushing pseudonymization right before you apply. Teams confuse fields meant for the combination key with fields meant for analysis, leave identifiers in place, or apply different generalization rules across datasets so that the combined data loses analytical value. Best practice is for both sides to align on a field specification before writing the application.
Choosing a combination specialist institution and stage-by-stage processing times
Combination specialist institutions are split by domain. Representative designated institutions as of 2026 are as follows (always confirm the latest status in PIPC notices).
| Domain | Representative combination specialist institutions | Selection criteria |
|---|---|---|
| Statistics / general | Statistics Korea, NIA-affiliated institutions | General-purpose statistical and research combination |
| Finance / credit | Financial Security Institute, Korea Credit Information Services | When financial or credit data is included |
| Healthcare / bio | Designated health-sector institutions | Combining health or clinical data |
| Public / general | General institutions designated by PIPC | Linking ministry or public data |
The selection rule is simple. Look at the nature of the data being combined. If even one financial record is mixed in, it is safer to go to a finance-sector specialist institution (Financial Security Institute or Korea Credit Information Services). For purely statistical or research purposes, a general institution such as Statistics Korea is a better fit.
Overall timeline (business-day estimates)
| Stage | What happens | Expected duration |
|---|---|---|
| 1. Application intake | Submit combination application and documents; supplements | 5–10 days |
| 2. Combination-key generation | KISA serial-number matching | 5–10 days |
| 3. Combination | Combination processing inside the specialist institution | 10–20 days |
| 4. Export review | Adequacy assessment and re-identification risk review | 10–20 days |
| 5. Export | Export of results or use in an analysis environment | Around 5 days |
Budget about 2–3 months from application to export. When you plan a new-business timeline, work backward from this window to set the pseudonymization completion date.
Export review and adequacy assessment pass checklist
Mapped to actual application items. Check each ✅ before you submit.
- The combination purpose clearly maps to one of statistics, research, or public-interest preservation
- Pseudonymization adequacy: direct identifiers deleted; quasi-identifiers generalized
- Re-identification risk assessment: risk level quantified with metrics such as k-anonymity
- Export data form: aggregated or pseudonymized so individuals cannot be identified
- Field minimization: fields not needed to achieve the purpose have been removed
- Security safeguards: access rights, encryption, and access logs (minimum 1 year) are specified
- Separate storage of additional information: keys used for pseudonymization are physically and administratively separated
Top 5 common rejection reasons and how to respond
The patterns that keep getting rejected in the field are almost fixed.
- Unclear purpose → Ban vague phrasing such as "marketing use." Be specific, e.g. "scientific research to develop a churn-prediction model."
- Insufficient pseudonymization → Names were removed, but date of birth + sex + residence remain, so identification is still possible. Generalize quasi-identifier combinations as well.
- Underestimated re-identification risk → Do not just write "low risk." Provide evidence such as k-anonymity values and equivalence-class sizes.
- Weak safeguards → Do not describe access control, encryption, and log retention abstractly; specify concrete controls per item.
- Too many fields requested → The habit of including everything "just in case" is the most common rejection reason. Keep only fields that map 1:1 to the purpose.
A word from the field
What raises the pass rate the most is pre-consultation. It is much faster to align once with the combination specialist institution's officer on purpose, fields, and export form at the draft stage than to submit a finished application, get rejected, and rewrite from scratch. Treat the process as a prior conversation, not a paperwork fight, and you can cut two months.
If you start today: a 4-week roadmap
- Week 1: Confirm the combination purpose + agree on a field specification with both sides
- Week 2: Perform pseudonymization + quantitative re-identification risk assessment
- Week 3: Security safeguards plan + application draft, pre-consult with the specialist institution
- Week 4: Final document check (checklist above), then formal filing
Frequently asked questions (FAQ)
Q. Is data-subject consent required for combining pseudonymized information? A. Not if the purpose is statistical production, scientific research, or public-interest record preservation. If the purpose falls outside that scope, combination itself is not allowed, so defining the purpose is the key.
Q. Can our company combine the data itself? A. No. Combining pseudonymized information across different organizations must be done only through a combination specialist institution designated by the Personal Information Protection Commission, and the results can leave only after passing export review.
Q. How long does it take from application to export? A. Including supplements and review, it is safest to budget 2–3 months. Pre-consultation can shorten this by reducing the number of supplement rounds.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.