South Korea PIPA
Korea PIPA - Cross-Border Transfer - Articles 28-8 - 28-9 - Adequacy - EU 2021 - SCCs - ISMS-P Certification

South Korea PIPA PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU: Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Korea PIPA Articles 28-8 + 28-9 cross-border transfer regime (substantially overhauled 2023 amendment). Article 28-8 cross-border transfer of personal information requires one of: (1) data subject separate consent + specified destination + safeguards; (2) law or treaty; (3) PIPC certification of recipient or recipient jurisdiction (similar to GDPR adequacy decisions); (4) PIPC-approved Standard Contractual Clauses (similar to GDPR SCCs) + Binding Corporate Rules equivalents; (5) ISMS-P certification of recipient. Article 28-9 PIPC suspension order against ongoing cross-border transfers found to risk Korean data subjects (jurisdictional protective measure). EU adequacy decision granted 17 December 2021 for personal information protection under PIPA - first East Asian country with EU adequacy + 4-year review (renewed 2025) + paired CBPR Cross-Border Privacy Rules (APEC + Global). Korea-Japan privacy cooperation arrangement + Korea-Singapore CBPR + APEC CBPR System. Recognition of recipient jurisdictions: EU + EEA + UK (post-Brexit) + adequacy pending Japan + Singapore.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 234 controls across 102 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 4 controls

  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • DSO-2 Data Security
  • DSO-3 Data Access Management

MARS-E · 4 controls

Mauritius DPA · 4 controls

Mexico LFPDPPP · 4 controls

NIST SP 800-122 · 4 controls

  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-6 International Transfers and Processor Agreements
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 4 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

ISO 13485 · 3 controls

ISO 27019 · 3 controls

ISO 27043 · 3 controls

ISO 27799 · 3 controls

ISO/SAE 21434 · 3 controls

LGPD · 3 controls

Liechtenstein DPA · 3 controls

MDS2 (Medical Device) · 3 controls

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 3 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data
  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 3 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-6 Cross-Border Transfer and Processor Engagement

South Korea ISMS-P · 3 controls

ISO/IEC 23894:2023 · 2 controls

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

MITRE ATT&CK · 2 controls

Malaysia PDPA 2010 · 2 controls

  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

Turkey KVKK · 2 controls

Vietnam PDPD · 2 controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • BB-DPA-17 Section 24 - Appropriate Safeguards

GDPR · 1 control

  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • ICP-25 Supervisory Cooperation and Coordination
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

ITIL 4 · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring
  • 3.10 Encrypt Sensitive Data in Transit

NIST SP 800-61 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PAKPDPB-6 Cross-Border Transfer and Data Localization

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • RUSPD-4 Special Categories, Biometric Data
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 234 it maps to, and the evidence behind each claim, over MCP and REST.