Korea PIPA Articles 28-2 + 28-3 pseudonymisation regime (added 2020 amendment - one of Korea most innovative provisions). Article 28-2 pseudonymised information processing for statistical + scientific research + public interest purposes without consent (subject to safeguards). Article 28-3 controlled combining of pseudonymised information from different controllers via PIPC-designated specialised institutions. Article 28-4 prohibition on re-identification. Article 28-5 designation of expert combining agencies + technical + organisational safeguards. Articles 63-64 PIPC investigation + inspection powers + access to premises + records + data. Article 63 PIPC investigation including on-site + documentation + interviews + production orders. Article 64-2 administrative fines (surcharges) up to 3 percent of preceding-year turnover related to violation (raised from 1 percent in 2023 amendment - Korea now has GDPR-level financial penalties) + maximum 6 billion KRW absolute cap. Article 70-72 criminal penalties up to 10 years imprisonment + 100M KRW fine for unlawful collection + use + disclosure of sensitive or unique identifier information. Article 75 administrative fines for lesser violations. Article 39-4 punitive damages.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.