Home Europe European Commission Commission Implementing Decision (EU) 2022/254 of 17 Decembe...
Date: 2022-02-24 Category: Not Applicable State: Union Government Country: Europe

Commission Implementing Decision (EU) 2022/254 of 17 December 2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the Republic of Korea under the Personal Information Protection Act (notified under document C(2021) 9316) (Text with EEA relevance)

Issued by European Commission · Directorate-General for Justice and Consumers

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: The document concerns nonlegislative acts notified under C2021 9316, focusing on the Schrems II ruling and its implications for personal data protection. It addresses the definition of personal data and processing, controller and outsourcee responsibilities, and special provisions for information and communication service providers. The policy covers lawfulness, data accuracy, security, transparency, individual rights, onward transfers, and accountability, including enforcement and sanctions. Key Points / Main Content: General Data Protection Principles: * Defines personal data and processing activities. * Establishes responsibilities for personal information controllers and outsourcees. * Highlights the lawfulness and fairness of processing, purpose limitation, data accuracy and minimisation, storage limitation, data security, and transparency. * Addresses the processing of special categories of personal data. * Ensures individual rights and accountability. Specific Provisions and Exemptions: * Includes special provisions for information and communication service providers (lex specialis) and exemptions from certain provisions of PIPA. * Addresses onward transfers of data (mutatis mutandis). Oversight and Redress: * Outlines independent oversight mechanisms. * Details enforcement measures, including sanctions. * Covers legal bases, limitations, and safeguards for data processing. * Addresses further use of collected information and redress mechanisms. Communication Information and Security: * Concerns searches and seizures, collection of communication information, communication restricting measures, communication confirmation data, censorship, and wiretapping. * Addresses voluntary disclosure by telecommunications business operators. * Includes provisions related to national security, terrorism, and state secrets. Institutions and Rights: * Involves bodies like the Personal Information Protection Commission (PIPC) and the National Human Rights Commission (NHRC). * Enshrines the "right to self-determination of personal information." Impact Analysis: Commission Member of the Commission: * Impact: Involved in implementing and overseeing the policy. * Action Required: Ensure compliance with the policy and address any related issues. Information and Communication Service Providers: * Impact: Subject to specific regulations and potential exemptions under PIPA. * Action Required: Adhere to data protection principles, ensure compliance with special provisions, and be prepared for audits. Individuals/Citizens: * Impact: Their personal data is subject to the policy's protections and regulations. They have the right to control their personal information. * Action Required: Be aware of their rights and exercise them when necessary. Personal Information Protection Commission (PIPC): * Impact: Responsible for overseeing and enforcing the policy. * Action Required: Conduct audits, address complaints, and ensure compliance. National Human Rights Commission (NHRC): * Impact: Provides redress mechanisms for individuals whose rights have been violated. * Action Required: Investigate complaints and provide redress as appropriate. Telecommunications Business Operators: * Impact: Subject to regulations regarding voluntary disclosure of communications data. * Action Required: Comply with regulations regarding data disclosure and protect user privacy.

Key Entities Referenced

Schrems II: A legal case (Data Protection Commissioner v Facebook Ireland and Maximillian Schrems) concerning data transfers between the EU and the US. PIPA: Likely refers to the Personal Information Protection Act, potentially of South Korea, given the context of the document. Privacy International: A UK-based non-governmental organisation that defends privacy and promotes data protection. La Quadrature du Net: A French advocacy group promoting digital rights and freedoms. PIPCCPA: Likely refers to Personal Information Protection Compliance, potentially relevant to CPPA (California Privacy Protection Act) within the context of data privacy. CPPA: Likely refers to the California Privacy Protection Act. The Personal Information Protection Commission: A data protection authority, likely South Korea's, responsible for enforcing the PIPA. The National Human Rights Commission: A national human rights institution, likely South Korea's, involved in redress mechanisms related to privacy.
Official Source Record View Original Source →
See Full Document Text
(Non-legislative acts) (notified under document C(2021) 9316) ­ Schrems II­ ­ Schrems Schrems ­Definition of personal dataDefinition of processing ­ Personal information controller and ‘outsourcee’ mutatis mutandisSpecial provisions for information and communication service providers lex specialis Exemption from certain provisions of PIPA­­ Lawfulness and fairness of processing ­­­ practically legally ­Processing of special categories of personal data ­Purpose limitation Data accuracy and minimisationStorage limitation Data security­ Transparency­Individual rights­Onward transfers mutatis mutandisAccountability­ Special rules for the processing of personal credit informationIndependent oversight­Enforcement, including sanctions ­­­­ ­­ Schrems II Privacy International La Quadrature du Net and Others Schrems II Privacy International La Quadrature du Net and Others Schrems II Schrems II Schrems I Schrems II Schrems II­ ex postLegal bases, limitations and safeguardsin loco ­ ­ ­ ­­­ Further use of the information collected ­ Oversight­ ­­Redress­ Legal bases, limitations and safeguards­­ ­ ­­­ Further use of the information collected Oversight ­­ Redress­Schrems Schrems Schrems SchremsArticle 1 Article 2 Article 3Article 4 For the Commission Member of the CommissionANNEX I ­­ ­※­ ­ ­­­ANNEX IIgovernment access "the right to self-determination of personal information" flagrante delicto "citizens" the right to control one's own personal information is a right of the subject of the information to personally decide when, to whom or by whom, and to what extent his or her information will be disclosed or used. It is a basic right, although not specified in the Constitution, existing to protect the personal freedom of decision from the risk caused by the enlargement of state functions and info-communication technologyrights of human beings PIPA abuse and misuse of personal information, indiscrete surveillance and tracking, etc. and to enhance the dignity of human beings and individual privacy ­ ­ PIPCCPA CPPA TBA NIS Searches and seizuresCollection of communication information communication communication-restricting measures communication confirmation data censorship wire-tapping ­ data on the records of telecommunications transmission or reception of all kinds of sounds, words, symbols or images by wire, wireless, fibre cable or other electromagnetic system, including telephone, e-mail, membership information service, facsimile and radio paging opening mail without the consent of the party concerned or acquiring knowledge of, recording or withholding its contents through other means acquiring or recording the contents of telecommunications by listening to or communally reading the sounds, words, symbols or images of the communications through electronic and mechanical devices without the consent of the party concerned or interfering with their transmission and reception­emergency censorship/ wiretapping statement­ ­ ­Voluntary disclosure by telecommunications business operators communications data "communications data" ­Self-auditing ­ The Board of Audit and Inspection BAI BAI ActThe National Assembly The Personal Information Protection Commission PIPC ­ The National Human Rights Commission NHRC NHRC Act­ Redress mechanisms available under PIPARedress before the National Human Rights Commission Judicial redress ­are not significantly off-balanced between Korea and the other country are not generally stricter than those determined by Korea, having no material and substantive difference." ­NIS ActAnti-Terrorism Act Collection of communication information communication-restricting measures wire-tapping censorship communication confirmation data­­ Collection of information on terrorist suspects Terrorist suspect Terrorist group TerrorismVoluntary disclosure by telecommunications business operators ­The Human Rights Protection Officer ­ ­ The National AssemblyThe Board of Audit and Inspection The Personal Information Protection Commission The National Human Rights Commission Redress before the Human Rights Protection Officer ­ the facts, goods or knowledge classified as state secrets, the access to which is permitted to a limited scope of persons and which shall not be disclosed to any other country or organization, in order to avoid any serious disadvantage to the national safetyRedress mechanisms available under PIPA ­ Redress before the National Human Rights Commission Judicial redress

Continue your research