Part of the AI Regulation News hub.
The PIPC set up a privacy system reform task force and opened a national call for proposals to rework PIPA for AI
A regulator asking the public what is wrong with its own statute is unusual. The four worked examples it published are the real signal about where PIPA is expected to move.
Bottom line: Not binding, and not a draft bill. This is an agenda setting exercise: a task force plus an open intake of proposals. Nothing in it changes the Personal Information Protection Act.
Who this affects: Privacy counsel, data protection officers and AI product leads at companies operating in Korea, plus academics, research institutions and civil society groups that want a say before drafting begins.
Issue date: The press release is dated 5 August 2026 with a 6 August 10:00 release marking. The task force was constituted on 30 July 2026. Proposals were open from 6 August to 31 August 2026.
What changed: Nothing legally. Procedurally, the PIPC moved the starting point of policy formation from stakeholder and expert consultation to open public intake, through the privacy portal and the government's Sotong 24 channel.
Analysis: The four examples the PIPC chose are all consent failures. Read together they point at the same target: the step by step, consent per stage architecture that has been the core of Korean privacy law since 2011.
Primary sources: PIPC press release · Privacy portal proposal window · Sotong 24 innovation proposal channel
- Instrument (EN)
- Personal information system innovation, designed together with the public
- Authority
- Personal Information Protection Commission, Personal Information Protection Policy Division
- Jurisdiction
- South Korea
- Status
- Task force constituted, public proposal intake completed
- Bindingness
- Not binding. No draft amendment, no obligation, no deadline for regulated entities.
- Issue date / next deadline
- Press release 5 August 2026, task force formed 30 July 2026, proposals open 6 to 31 August 2026, direction to be announced within the year.
- Channels
- Privacy portal policy proposal window at privacy.go.kr, including by email, and the Innovation Proposal Talk on sotong.go.kr after login
- Next step stated
- Selection of policy tasks from the proposals, then open debates and seminars, then an announced reform direction
- Primary source
- https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12361
What the PIPC set in motion
The commission constituted a Personal Information System Innovation Task Force on 30 July 2026 and then opened a public intake for proposals running from 6 to 31 August 2026. Anyone can file: individuals, companies, research institutions, academia and civil society.
Five prompts were published. Fields and tasks where the privacy protection framework needs improving for the AI era; difficulties experienced by the public and industry in operating the current law; measures to make safe use of personal data workable; protection principles that need revising to reflect the AI environment; and any innovation ideas the public wants to propose.
The PIPC said it would select policy tasks including the strongest proposals, hold open debates and seminars with the public, business and experts, and then announce a direction for privacy system reform for the AI era within the year. A commendation from the chairperson was offered for outstanding proposals.
The commission's own diagnosis
The framing is historical. Korea's privacy law began in the mid 1990s in the public sector and in telecommunications and finance separately, reached the Personal Information Protection Act in 2011, and consolidated the provisions scattered across individual statutes in 2020. What survived every step was an architecture built for a 1990s digital environment: individual consent as the organising idea, with a legal basis required at each stage of collection, use and provision.
The commission then describes what has changed underneath that architecture. Data has moved from structured information about the user to unstructured data including information about third parties. In an AI environment varied data accumulates and is learned from, multiple institutions link and use data together, and AI agents perform tasks on the user's behalf.
Its conclusion, stated as a persistent criticism rather than a finding, is that consent centred regulation struggles to guarantee real protection and causes inconvenience in AI services and data processing.
Four examples worth reading closely
The first is consent that has become a formality. Lawful bases beyond consent have expanded, yet the practice persists: people press the consent button rather than read a long form, and the PIPC notes the criticism that consent based processing may actually weaken the real level of protection and control.
The second is pseudonymised data in international joint research. Current law permits pseudonymised data for scientific research including medical research, but cross border transfer requires the data subject's consent, and re obtaining consent is practically impossible once individuals cannot be identified. International collaboration is limited as a result.
The third is AI agent services. Agents increasingly judge for themselves, look up and use varied information, and perform tasks. Where several agents cooperate or link to external services and tools, fresh consent may be needed each time, which raises both the limits of consent based processing and the question of how to allocate responsibility.
The fourth is new privacy issues from physical AI. Robots, drones and smart glasses are spreading as data collecting and processing devices, and the commission says issues arise that the existing legal framework struggles to capture, raising the need to design protection principles, safeguards and rights mechanisms for the new technical environment.
How to read this if you operate in Korea
Nothing here changes an obligation. What it does is tell you which arguments the regulator is currently willing to hear, and the four examples are effectively an invitation on four specific topics: consent fatigue, cross border research transfers, agentic AI, and ambient data capture devices.
The commission described the method itself as the point, contrasting it with designing policy around stakeholders or experts and then publishing it. Whether the resulting proposals survive drafting is a separate question, and the press release promises only a direction, announced within the year.
What we did not verify
We opened the PIPC press release in full, including the dates, the two submission channels, the five prompts and the four illustrative problems.
We did not open the attached PDF or HWPX file, and we did not open the privacy.go.kr or sotong.go.kr submission pages to confirm the intake forms are live or now closed. We did not open the Personal Information Protection Act or any draft amendment, because none is referenced.
We do not claim that PIPA will be amended, that consent will be replaced, or that any specific proposal will be adopted. The commission promises a direction announced within the year and nothing more. The chairperson's name is transliterated by us, as the page gives no English spelling.
Treat this as the earliest visible stage of a Korean privacy overhaul, not as a change in the law. If cross border pseudonymised research, agent to agent data flows or device based capture sit in your roadmap, the commission has published exactly those four as open questions. The output promised is a direction within the year, which is the point at which drafting risk becomes real.
Source File
https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12361
Open the PIPC press release, confirm the posting date of 2026-08-05 and the 30 July 2026 task force date in the first paragraph, then check the 6 to 31 August intake window and the four numbered example cases.
인공지능 시대 개인정보가 안전하게 보호되면서도 국민과 사회에 도움이 되는 방향으로 데이터가 책임 있게 활용될 수 있도록 새로운 균형을 만들어 가는 것이 개인정보위의 역할 · PIPC Chairperson, PIPC press release, 5 August 2026
FAQ
Is this a draft amendment to PIPA?
No. It is a task force plus an open call for proposals. The commission promises only to announce a reform direction within the year.
When was the task force formed?
30 July 2026, according to the press release, which is dated 5 August 2026 with a 6 August release marking.
Who could submit proposals?
Anyone. The commission named the public, companies, research institutions, academia and civil society, through privacy.go.kr or sotong.go.kr, between 6 and 31 August 2026.
What problems did the commission single out?
Formalised repeat consent, cross border transfer consent blocking pseudonymised international research, repeated consent demands in AI agent services, and privacy issues from robots, drones and smart glasses.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.