The PIPC published a privacy guide for public sector AI adoption built around ten checkpoints and three use types

Korea PIPC Guide for Public Sector AI Privacy Checks. The Leveraged Years regulation briefing card.

The interesting move is not the checklist. It is that the PIPC graded its expectations by what the system is used for, and said plainly that identical controls for every AI system are not what it wants.

The short version

Bottom line: Not binding. This is a guide, not a regulation or an enforcement action. It states the PIPC's expectations and points to existing duties under the Personal Information Protection Act. It creates no new obligation of its own.

Who this affects: Chief privacy officers, chief AI officers and agency heads in Korean public bodies, and the vendors and system integrators building AI into government services.

Issue date: Posted by the PIPC on 22 July 2026, under a 23 July 2026 10:00 release marking. The guide was disclosed at the 11th Science and Technology Related Ministers Meeting held on Thursday 23 July.

What changed: Public bodies now have a written PIPC position mapping ten checkpoints onto three project stages, three graded use types, and a named standing helpdesk on 02-2100-3072 and 3169.

Analysis: The guide refuses uniformity. It says that requiring the same measures of every AI system is not the goal, and instead pushes agencies to scale controls to the use type. That is a proportionality position from a regulator, and it cuts both ways.

Primary sources: PIPC press release and guide

Instrument (EN)
Public AX Privacy Protection Guide
Authority
Personal Information Protection Commission, AI Privacy Team
Jurisdiction
South Korea, public sector
Status
Published guide
Bindingness
Not binding. Guidance material describing legal standards and safeguards, drawn from prior inspections and adequacy reviews.
Issue date / next deadline
Posted 22 July 2026, released 23 July 2026. No deadline stated.
Support channel
Public AX Privacy Helpdesk, 02-2100-3072 and 02-2100-3169, operated on a standing basis
Underlying law
Personal Information Protection Act, including data subject rights over automated decisions
Primary source
https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12307

Why the PIPC wrote it

The stated problem is capacity. On the PIPC's account, frontline public bodies often lack enough specialist staff in privacy and AI to understand complex AI data processing and design concrete protective measures.

The commission's answer was to assemble the guide from actual cases: prior fact finding inspections on AI and results of the prior adequacy review scheme, organised into legal standards and safeguards. It also frames the stakes in trust terms, noting that public bodies process large volumes of data across welfare, health, safety and civil complaints, so the safety of public AI adoption connects directly to trust in government services.

Ten checkpoints across three stages

The guide splits an AX project into prior design, development and build, and system application and management.

At the design stage, agencies are told to make the purpose and the processing target explicit so that purpose limitation and minimal collection can be respected, and to confirm the lawful basis for collection, use and provision item by item. When choosing how to develop or build, the guide says to weigh not only system performance but also the character of the personal data processed and the expected privacy risk.

At the development and build stage, safeguards are to be applied at each point where personal data is processed: training data use, prompt input, retrieval augmented generation linkage, and output. Measures listed include pseudonymisation or anonymisation of training data, privacy enhancing technologies such as differential privacy, filtering of personal data on input and output, and access rights management.

At the application and management stage, agencies are to keep testing before and after deployment for possible leakage or exposure, stand up monitoring and incident response, establish procedures for data subject rights including access, correction, deletion and suspension of processing, and disclose processing matters transparently through the privacy policy.

Three use types, graded expectations

The guide sorts public AI into basic work assistance, information linkage, analysis and recommendation, and screening or judgement, and says explicitly that rather than demanding identical measures of every AI system, agencies should be able to review flexibly what is needed in the specific context.

Basic work assistance covers large language model use for processing, summarising and searching materials, and chatbot consultation. Here the emphasis is a safe usage environment and basic safeguards: clarify permitted and prohibited uses, train the main users, and build a management system for AI input and output data.

The linkage and analysis type, where databases and systems are joined to analyse or recommend tailored information, gets a sharper focus on use beyond the original purpose and on excessive inference. Agencies are told to check that a processing basis exists before linking an external database, to limit analysed and inferred information to what the purpose needs, and to implement differentiated access rights and access control across the linked systems.

Screening and judgement, meaning direct use in public decisions such as selecting benefit recipients or detecting risk, draws the heaviest treatment. Necessity, effectiveness and legal basis are to be examined more closely. Data accuracy and representativeness and system performance are to be continuously checked and improved so that bias, or shortfalls in accuracy and resilience, do not injure data subject rights. Where the case amounts to an automated decision, the guide says the rights guaranteed by the Protection Act, including the right to refuse and the right to demand explanation and review, must be made real through a response system.

Who owns it inside the agency

The guide names the agency head, the chief privacy officer and the chief AI officer as the people who should treat personal data protection as a core element of AX, and calls for a cooperation structure between the privacy function and the operating departments running the project. It also says internal management plans should be upgraded to reflect the AI operating environment.

On its own side, the PIPC committed to a standing Public AX Privacy Helpdesk as a single window routing questions into legal interpretation, the prior adequacy review scheme, pseudonymised data processing support, or the regulatory sandbox, depending on the query and the nature of the project.

What we did not verify

We opened the PIPC press release page in full and read its account of the guide, including the three stages, the ten checkpoint framing, the three use types, the named roles and the helpdesk numbers.

We did not open the attached PDF of the guide itself, so the ten checkpoints are described only at the level the press release states them, and the two diagrams referenced on the page were not read. We did not open the Personal Information Protection Act or the prior adequacy review scheme documents.

We do not claim the guide creates any obligation, that it changes the automated decision provisions of the Protection Act, or that non compliance carries consequences. We also cannot confirm the official English spelling of the chairperson's name, which the page does not give.

Key compliance takeaway

If you build or buy AI for a Korean public body, the risk tier the PIPC will apply is set by what the system does, not by how large the model is. Screening and judgement uses attract the automated decision rights, so the refusal and explanation pathway has to exist before deployment, not after a complaint. Vendors should expect access basis questions for every external database they link.

Source File

https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12307

Open the PIPC press release, confirm the posting date of 2026-07-22 and the AI Privacy Team as author, and check the three stage split, the three use types and the helpdesk numbers 02-2100-3072 and 3169 against the third attachment.

공공 AX는 국민에게 더 빠르고 편리한 서비스를 제공하고, 공무원이 보다 효율적으로 일할 수 있도록 하는 정부 혁신의 핵심 수단 · PIPC Chairperson, PIPC press release, 22 July 2026

FAQ

Is the guide binding on public bodies?

No. It is guidance. The obligations it points to come from the Personal Information Protection Act, not from the guide.

What are the three use types?

Basic work assistance, information linkage and analysis and recommendation, and screening or judgement. Expected safeguards rise across those three.

Does it address automated decisions?

Yes, within the screening and judgement type. Where a case is an automated decision, the guide says the statutory rights to refuse and to demand explanation and review must be operationalised.

Is there a way to ask questions?

The PIPC operates a standing Public AX Privacy Helpdesk on 02-2100-3072 and 02-2100-3169, which routes queries to legal interpretation, prior adequacy review, pseudonymised data support or the regulatory sandbox.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}