(2) The Privacy Impact Assessment shall cover the matters of the following Subparagraphs:
1. The number of personal information being processed;
2. Whether the personal information is provided to a third party or not;
3. The probability to violate the rights of data subjects and the degree of such risk; and
4. The other matters as stated by the Presidential Decree.
(3) The Minister of Public Administration and Security may provide its opinion subject to
the deliberation and resolution of the Commission upon receiving the PIA result as stated
in Paragraph (1).
(4) The head of the public institution shall register the personal information files in
accordance with Article 32(1), for which the Privacy Impact Assessment has been
conducted pursuant to Paragraph (1), with the PIA result attached thereto.
(5) The Minister of Public Administration and Security shall work out necessary measures,
such as fostering relevant specialists, and developing and disseminating PIA criteria, so as
to activate the Privacy Impact Assessment.
(6) Necessary matters in relation to the Privacy Impact Assessment, such as the designation
criteria and designation revocation of the PIA institution, assessment criteria, method and
procedure, etc. pursuant to Paragraph (1) shall be provided by the Presidential Decree.
(7) The Privacy Impact Assessment conducted by the National Assembly, the Court, the
Constitutional Court and the National Election Commission (including their affiliated
entities) shall be provided by the respective rules of the National Assembly, the Court, the
Constitutional Court and the National Election Commission.
(8) The personal information processor other than the public institution shall make efforts in
a positive way to conduct the Privacy Impact Assessment if the violation of personal
information of data subjects is highly probable in operating the personal information files.
Article 34 (Data Breach Notification, etc.)
(1) The personal information processor shall notify the aggrieved data subjects without delay
of the fact in the following Subparagraphs when it becomes to know that personal
information is leaked:
1. What kind of personal information was leaked;
2. When and how personal information was leaked;
3. Any information how data subject can do to minimize probable damage suffered from
personal information leakage;
4. Countermeasures of the personal information processor and remedial procedure; and
5. Help desk of the personal information processor and contact points for data subjects to
report sufferings.
(2) The personal information processor shall prepare countermeasures to minimize the damage
in case of personal information leakage, and take necessary measures.
- 18 -