Start by distinguishing personal information entrustment from third-party provision based on whose business and purpose the receiving company processes the information for. If they process our work on our instructions, it may be entrustment. If the receiving company uses the information for its own purposes, you should review it as third-party provision. Do not decide based on the contract title alone.
The consent question comes after that. Third-party provision also has statutory bases other than consent, and entrustment still carries contract, disclosure, and supervision duties. This article explains the general distinction under the Personal Information Protection Act. Whether a given contract is lawful must be confirmed against the actual data flow and the applicable law.
Entrustment vs. third-party provision comparison table
| Assessment item | Entrustment of personal information processing | Third-party provision of personal information |
|---|---|---|
| Purpose / work | Processing the entrustor's work on their behalf | Review whether the recipient uses it for its own purposes |
| Key provision | Personal Information Protection Act Article 26 | Personal Information Protection Act Article 17 |
| Consent | Distinct from a structure that collects third-party provision consent merely because of the entrustment itself | Consent is required, or the requirements of a statutory non-consent basis must be met |
| Operational checks | Entrustment documentation, disclosure of work and trustee, training and supervision, sub-entrustment management | Confirm the legal basis for provision, the scope of provision, and the recipient's purpose of use |
| Example | Delivery or customer support performed on instructions | A partner using customer information to market its own products |
Article 17(1) distinguishes provision based on consent from provision based on certain legal grounds, and paragraph (4) sets requirements for provision within a scope reasonably related to the original collection purpose. Therefore, it is inaccurate to conclude that “third-party provision always requires separate consent with no exceptions.” Personal Information Protection Act Article 17
Five questions to ask before contracting
- What work is being entrusted? Do not write it broadly as “processing customer information.” Specify order delivery, inquiry handling, and so on.
- Does the receiving company use the data independently? Check both the terms and actual operations for use in its own advertising, building a separate customer DB, or training a general-purpose model.
- Is it subject to our instructions and supervision? Confirm the processing scope, access rights, and return/destruction procedures. Do not classify based solely on whether a fee is paid.
- Are there a legal basis and procedures that match the classification? For provision, confirm consent or an applicable legal basis. For entrustment, confirm documentation, disclosure, and supervision under Article 26.
- Does it include a cross-border transfer? Check not only overseas storage but also overseas access and processing entrustment.
If it is entrustment, is disclosure enough?
No. Article 26 requires documentation covering prohibition of processing beyond the purpose and protective measures, disclosure of the entrusted work and the trustee, and training and supervision of the trustee. If the trustee sub-entrusts the work, the entrustor's consent is required. For entrustment of promotional or sales solicitation work, also check the rules on notifying data subjects of the work and the trustee. Personal Information Protection Act Article 26
The following is a practical checklist for reviewing both the contract and operations together. It is not a table that oversimplifies the statutory mandatory items into a fixed count.
| Material to review | What to check |
|---|---|
| Scope of work and data list | Are only necessary items transferred? |
| Contract and service terms | Is there use beyond the purpose, or use for the provider's own training or advertising? |
| Protective measures and access records | Who accesses which data? |
| Sub-entrustment list | Can prior consent and change management be handled? |
| Termination procedures | Are the scope of return/deletion and a method to confirm completion in place? |
| Public documents and inspection records | Do the actual trustee list and operating status match? |
Set training and inspection cycles according to data risk and applicable rules. Do not assume that “once a year is enough” for every business.
If you obtain consent for third-party provision, what must you tell the data subject?
Under Article 17(2), you must inform them of the recipient, the purpose of use, the items provided, the retention and use period, the right to refuse consent, and any disadvantage from refusal if there is one. Listing only a company name in a privacy policy without confirming a legal basis cannot substitute for provision consent. Article 17(2) notice items
How should you assess cloud, SaaS, and LLM APIs?
Do not classify them solely by service type. Separate the parts that store and process data on our behalf from the parts the provider uses for its own purposes. In particular, compare training-use terms, retention periods, the countries from which support staff access data, and sub-entrusted vendors against the contract materials.
If there is a cross-border transfer, separately confirm the basis under Article 28-8. For example, processing entrustment or storage necessary to conclude or perform a contract may be handled by meeting that article’s disclosure or notice requirements, but not every overseas service is permitted merely by disclosing it in a privacy policy. Personal Information Protection Act Article 28-8
Distinguishing with practical cases
- A delivery company only fulfills order delivery: Review whether it is entrustment and the contract, disclosure, and supervision framework.
- A partner uses a customer list to promote its own products: Confirm the basis for third-party provision and the scope of provision.
- An affiliate only operates a shared system: Do not treat it as an exception just because it is “the same group”; confirm the actual role.
- An AI provider uses inputs to improve its own model: Separately review whether there is a purpose of use other than simple processing on your behalf.
Do not leave only an “entrustment / provision” conclusion. Record the purpose of the work, the items transferred, who uses the data, the applicable legal basis, and how data is handled at termination together.
Nodelog는 모든 콘텐츠의 내용과 출처를 공개 전에 검토합니다. 환경(OS·버전)에 따라 결과가 달라질 수 있는 기술 정보는 공식 문서와 함께 확인하며, 검토 기준과 정정 원칙은 편집 정책에서 안내합니다. 오류를 발견하시면 이메일로 제보해 주세요 — 확인 후 신속히 정정합니다.
Comments
Be the first to comment.