(2) The Privacy Impact Assessment shall cover the matters of the following Subparagraphs: 1. The number of personal information being processed; 2. Whether the personal information is provided to a third party or not; 3. The probability to violate the rights of data subjects and the degree of such risk; and 4. The other matters as stated by the Presidential Decree. (3) The Minister of Public Administration and Security may provide its opinion subject to the deliberation and resolution of the Commission upon receiving the PIA result as stated in Paragraph (1). (4) The head of the public institution shall register the personal information files in accordance with Article 32(1), for which the Privacy Impact Assessment has been conducted pursuant to Paragraph (1), with the PIA result attached thereto. (5) The Minister of Public Administration and Security shall work out necessary measures, such as fostering relevant specialists, and developing and disseminating PIA criteria, so as to activate the Privacy Impact Assessment. (6) Necessary matters in relation to the Privacy Impact Assessment, such as the designation criteria and designation revocation of the PIA institution, assessment criteria, method and procedure, etc. pursuant to Paragraph (1) shall be provided by the Presidential Decree. (7) The Privacy Impact Assessment conducted by the National Assembly, the Court, the Constitutional Court and the National Election Commission (including their affiliated entities) shall be provided by the respective rules of the National Assembly, the Court, the Constitutional Court and the National Election Commission. (8) The personal information processor other than the public institution shall make efforts in a positive way to conduct the Privacy Impact Assessment if the violation of personal information of data subjects is highly probable in operating the personal information files. Article 34 (Data Breach Notification, etc.) (1) The personal information processor shall notify the aggrieved data subjects without delay of the fact in the following Subparagraphs when it becomes to know that personal information is leaked: 1. What kind of personal information was leaked; 2. When and how personal information was leaked; 3. Any information how data subject can do to minimize probable damage suffered from personal information leakage; 4. Countermeasures of the personal information processor and remedial procedure; and 5. Help desk of the personal information processor and contact points for data subjects to report sufferings. (2) The personal information processor shall prepare countermeasures to minimize the damage in case of personal information leakage, and take necessary measures. - 18 -

Select target paragraph3