Korea PIPA Articles 28-8 + 28-9 cross-border transfer regime (substantially overhauled 2023 amendment). Article 28-8 cross-border transfer of personal information requires one of: (1) data subject separate consent + specified destination + safeguards; (2) law or treaty; (3) PIPC certification of recipient or recipient jurisdiction (similar to GDPR adequacy decisions); (4) PIPC-approved Standard Contractual Clauses (similar to GDPR SCCs) + Binding Corporate Rules equivalents; (5) ISMS-P certification of recipient. Article 28-9 PIPC suspension order against ongoing cross-border transfers found to risk Korean data subjects (jurisdictional protective measure). EU adequacy decision granted 17 December 2021 for personal information protection under PIPA - first East Asian country with EU adequacy + 4-year review (renewed 2025) + paired CBPR Cross-Border Privacy Rules (APEC + Global). Korea-Japan privacy cooperation arrangement + Korea-Singapore CBPR + APEC CBPR System. Recognition of recipient jurisdictions: EU + EEA + UK (post-Brexit) + adequacy pending Japan + Singapore.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.