South Korea PIPA
Korea PIPA - CPO - Privacy Officer - PIA - Personal Information Impact Assessment - ISMS-P Certification - Articles 31-33

South Korea PIPA PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33: Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Korea PIPA Articles 28 + 31 + 33 governance regime. Article 28 obligations of personal information handlers including security measures + training + supervision of processors. Article 31 mandatory designation of Chief Privacy Officer (CPO equivalent of DPO) for all controllers + minimum qualifications + independence + reporting + role obligations. CPO has direct reporting to CEO + executive officer designation requirement for large processors after 2023 amendment. Article 32 registration with PIPC (largely repealed 2023 amendment for private sector). Article 32-2 Personal Information Protection Certification (ISMS-P - Information Security and Privacy Management System integrated certification + voluntary but standard market signal). Article 33 mandatory Personal Information Impact Assessment (PIA) for public agencies processing certain high-risk personal information categories (RRN + biometric + 1M+ records) + recommended for private sector + ENISA-style methodology + PIPC reporting. Article 33-2 mandatory PIA for AI processing automated decisions (added 2023).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 523 controls across 178 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 7 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

BSI IT-Grundschutz · 6 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

NIST SP 800-53 Rev 5 · 6 controls

API 1164 · 5 controls

IEC 62443 · 5 controls

ISO 27017 · 5 controls

ISO 27018 · 5 controls

ISO 27019 · 5 controls

ISO/IEC 23894:2023 · 5 controls

MTCS (Singapore) · 5 controls

NIST SP 1800-32 · 5 controls

NIST SP 800-190 · 5 controls

  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 5 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data
  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight
  • PDPASG-8 Data Breach Notification, Incident Response, and Enforcement

PDPA Thailand · 5 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-6 Cross-Border Transfer and Processor Engagement
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 5 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-7 Notifiable Privacy Breach Scheme
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
  • FFIEC-08 Application security controls
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

ISO 13485 · 4 controls

ISO 27799 · 4 controls

ISO/IEC 27400:2022 · 4 controls

Mauritius DPA · 4 controls

Mexico LFPDPPP · 4 controls

NIST SP 800-122 · 4 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-6 PII Breach Response and Incident Handling
  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 4 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs

PCI P2PE · 4 controls

PCI PIN Security · 4 controls

PCI SSF · 4 controls

  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Peru DPL · 4 controls

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions
  • PERU-4 Children's Data, Privacy Impact, Sensitive Categories
  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance

APPI · 3 controls

  • APPI-A31 Provision of Personally Referable Information
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing

FISMA · 3 controls

GDPR · 3 controls

ISO 22320:2018 · 3 controls

ISO 27005 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

LGPD · 3 controls

Liechtenstein DPA · 3 controls

MARS-E · 3 controls

Malaysia PDPA 2010 · 3 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-145 · 3 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 3 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-30 · 3 controls

  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

Open Banking Security · 3 controls

  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO

South Korea ISMS-P · 3 controls

  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-13 Board Accountability for Operational Risk Management

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.4.7 Emergency and Incident Response
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management

IEEE 1686 · 2 controls

ISO/IEC 27003:2017 · 2 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 29147:2018 · 2 controls

ISO/IEC 30111:2019 · 2 controls

MDS2 (Medical Device) · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4

NERC CIP · 2 controls

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security

NIST SP 800-37 · 2 controls

  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection

NIST SP 800-66 · 2 controls

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • ORSA-S2 ORSA Manual Section 2: Insurer's Assessment of Risk Exposure
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

Turkey KVKK · 2 controls

  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation

Vietnam PDPD · 2 controls

  • CA-12 Deploys Through Policies and Procedures
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FDA 21 CFR Part 11 · 1 control

  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP Rev 5 · 1 control

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 20000-1 · 1 control

ISO 22000 · 1 control

ISO 26000:2010 · 1 control

ISO 45001 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27031:2011 · 1 control

ITIL 4 · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

NIST SP 800-39 · 1 control

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning
  • PSPF24-1 Security Culture, Governance, Risk Management
  • RUSPD-4 Special Categories, Biometric Data
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 523 it maps to, and the evidence behind each claim, over MCP and REST.