/보안/Entrustment vs. Third-Party Provision of Personal Information: Consent Requirements and Case Comparisons
Security개인정보위탁제3자제공

Entrustment vs. Third-Party Provision of Personal Information: Consent Requirements and Case Comparisons

Distinguish personal information entrustment from third-party provision by purpose and role. This post compares legal bases other than consent, entrustment contracts, disclosure and supervision, and what to check for cross-border transfers

Entrustment vs. Third-Party Provision of Personal Information: Consent Requirements and Case Comparisons

Start by distinguishing personal information entrustment from third-party provision based on whose business and purpose the receiving company processes the information for. If they process our work on our instructions, it may be entrustment. If the receiving company uses the information for its own purposes, you should review it as third-party provision. Do not decide based on the contract title alone.

The consent question comes after that. Third-party provision also has statutory bases other than consent, and entrustment still carries contract, disclosure, and supervision duties. This article explains the general distinction under the Personal Information Protection Act. Whether a given contract is lawful must be confirmed against the actual data flow and the applicable law.

Entrustment vs. third-party provision comparison table

Assessment itemEntrustment of personal information processingThird-party provision of personal information
Purpose / workProcessing the entrustor's work on their behalfReview whether the recipient uses it for its own purposes
Key provisionPersonal Information Protection Act Article 26Personal Information Protection Act Article 17
ConsentDistinct from a structure that collects third-party provision consent merely because of the entrustment itselfConsent is required, or the requirements of a statutory non-consent basis must be met
Operational checksEntrustment documentation, disclosure of work and trustee, training and supervision, sub-entrustment managementConfirm the legal basis for provision, the scope of provision, and the recipient's purpose of use
ExampleDelivery or customer support performed on instructionsA partner using customer information to market its own products

Article 17(1) distinguishes provision based on consent from provision based on certain legal grounds, and paragraph (4) sets requirements for provision within a scope reasonably related to the original collection purpose. Therefore, it is inaccurate to conclude that “third-party provision always requires separate consent with no exceptions.” Personal Information Protection Act Article 17

Five questions to ask before contracting

  1. What work is being entrusted? Do not write it broadly as “processing customer information.” Specify order delivery, inquiry handling, and so on.
  2. Does the receiving company use the data independently? Check both the terms and actual operations for use in its own advertising, building a separate customer DB, or training a general-purpose model.
  3. Is it subject to our instructions and supervision? Confirm the processing scope, access rights, and return/destruction procedures. Do not classify based solely on whether a fee is paid.
  4. Are there a legal basis and procedures that match the classification? For provision, confirm consent or an applicable legal basis. For entrustment, confirm documentation, disclosure, and supervision under Article 26.
  5. Does it include a cross-border transfer? Check not only overseas storage but also overseas access and processing entrustment.

If it is entrustment, is disclosure enough?

No. Article 26 requires documentation covering prohibition of processing beyond the purpose and protective measures, disclosure of the entrusted work and the trustee, and training and supervision of the trustee. If the trustee sub-entrusts the work, the entrustor's consent is required. For entrustment of promotional or sales solicitation work, also check the rules on notifying data subjects of the work and the trustee. Personal Information Protection Act Article 26

The following is a practical checklist for reviewing both the contract and operations together. It is not a table that oversimplifies the statutory mandatory items into a fixed count.

Material to reviewWhat to check
Scope of work and data listAre only necessary items transferred?
Contract and service termsIs there use beyond the purpose, or use for the provider's own training or advertising?
Protective measures and access recordsWho accesses which data?
Sub-entrustment listCan prior consent and change management be handled?
Termination proceduresAre the scope of return/deletion and a method to confirm completion in place?
Public documents and inspection recordsDo the actual trustee list and operating status match?

Set training and inspection cycles according to data risk and applicable rules. Do not assume that “once a year is enough” for every business.

Under Article 17(2), you must inform them of the recipient, the purpose of use, the items provided, the retention and use period, the right to refuse consent, and any disadvantage from refusal if there is one. Listing only a company name in a privacy policy without confirming a legal basis cannot substitute for provision consent. Article 17(2) notice items

How should you assess cloud, SaaS, and LLM APIs?

Do not classify them solely by service type. Separate the parts that store and process data on our behalf from the parts the provider uses for its own purposes. In particular, compare training-use terms, retention periods, the countries from which support staff access data, and sub-entrusted vendors against the contract materials.

If there is a cross-border transfer, separately confirm the basis under Article 28-8. For example, processing entrustment or storage necessary to conclude or perform a contract may be handled by meeting that article’s disclosure or notice requirements, but not every overseas service is permitted merely by disclosing it in a privacy policy. Personal Information Protection Act Article 28-8

Distinguishing with practical cases

  • A delivery company only fulfills order delivery: Review whether it is entrustment and the contract, disclosure, and supervision framework.
  • A partner uses a customer list to promote its own products: Confirm the basis for third-party provision and the scope of provision.
  • An affiliate only operates a shared system: Do not treat it as an exception just because it is “the same group”; confirm the actual role.
  • An AI provider uses inputs to improve its own model: Separately review whether there is a purpose of use other than simple processing on your behalf.

Do not leave only an “entrustment / provision” conclusion. Record the purpose of the work, the items transferred, who uses the data, the applicable legal basis, and how data is handled at termination together.

확인 정보
✦ ✦ ✦
편집 검토 · Editorial Review

Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.

편집 책임 · Nodelog 기술 편집팀·발행 · ·업데이트 ·

Comments

Be the first to comment.