South Korea Cloud Security Assurance Program (CSAP)
Data Protection and Privacy

South Korea Cloud Security Assurance Program (CSAP) CSAP-PRIV-20: Privacy and personal information protection

Where certified services process personal information of Korean data subjects, the provider shall comply with PIPA obligations on lawful basis, data minimisation, retention limits, data subject rights, and cross-border transfer restrictions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Data Protection and Privacy

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.