"Guidelines for the Processing of Personal Information for Generative AI Development and Use"
Lawful Handling of Personal Information for Specific Purposes
Urging the Establishment of In-House AI Privacy Governance Systems

As artificial intelligence (AI) services become increasingly widespread, concerns over personal information leaks and privacy violations are growing. In response, the Personal Information Protection Commission has released the "Guidelines for the Processing of Personal Information for the Development and Use of Generative AI." These guidelines are expected to resolve uncertainties for AI companies when launching services and to enable ongoing innovative management.

Koh Haksoo, Chairperson of the Personal Information Protection Commission, is delivering a greeting at the 'Generative Artificial Intelligence and Privacy' open seminar held on the afternoon of the 6th at Jeongdong 1928 Art Center in Jung-gu, Seoul.

Koh Haksoo, Chairperson of the Personal Information Protection Commission, is delivering a greeting at the 'Generative Artificial Intelligence and Privacy' open seminar held on the afternoon of the 6th at Jeongdong 1928 Art Center in Jung-gu, Seoul.

View original image

On August 6, the Personal Information Protection Commission held a seminar on generative AI and privacy at the Jeongdong 1928 Art Center in Jung-gu, Seoul, where it announced these guidelines. The guidelines are expected to be useful for businesses that utilize commercial large language model (LLM) services such as ChatGPT or develop and provide services by fine-tuning open-source LLMs.


Since the beginning of this year, the Commission has prepared a draft of the guidelines through internal review and consultation with external experts, and finalized the public version last month after discussions with the public-private policy council and a plenary meeting.


The main contents of the guidelines require first setting a specific purpose to be achieved through generative AI technology. Since data used for training may include personal information, the Commission emphasized that the purpose for processing personal information must be specific, clear, and set in a lawful manner.


The Commission also stated that even if personal information is publicly available, indiscriminate scraping could infringe on rights, so attention must be paid to ensuring legality and safety.


Personal information collected based on user consent, contracts, or legitimate interests can be used to improve and advance AI services.

AI Companies Urged to Reduce Personal Data Risks... Personal Information Commission Releases Guidelines View original image

However, the Commission noted the need to systematically address issues such as data poisoning, which maliciously corrupts data, as well as data bias and inaccuracy. In particular, it stressed that resident registration numbers, other unique identification numbers, account numbers, and credit card numbers should be deleted or pseudonymized/anonymized before being used for AI training.


Addressing adversarial attacks aimed at extracting personal information contained in training data from generative AI models was also identified as a critical task.


Lastly, the Commission urged companies to establish an AI privacy governance system by maintaining close cooperation among the Chief Privacy Officer (CPO), AI officers, and information security officers. If a significant vulnerability is discovered, it recommended reporting to the highest decision-making body within the organization, such as the board of directors, and promptly sharing information with relevant government ministries.


Hot Picks Today


Koh Haksoo, Chairperson of the Personal Information Protection Commission, said, "We expect that the clear guidelines will resolve legal uncertainties in the field and enable the systematic incorporation of privacy protection into the development and use of generative AI. Going forward, the Commission will continue to establish a policy foundation so that both 'privacy' and 'innovation' can coexist."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily(www.asiae.co.kr). All rights reserved.

Today’s Briefing