Binding law — in force AI-adjacent law
Controllers must explain fully automated (including AI) decisions on request and publish their criteria and procedures (South Korea PIPA)
A data subject may ask for an explanation of a decision a controller made by a fully automated system, including AI (Art. 37-2(2)); the controller must, absent justifiable grounds, provide the explanation (Art. 37-2(3)), and must publish the criteria and procedure of its automated decisions and how personal information is processed so data subjects can easily check them (Art. 37-2(4)). Under the Enforcement Decree, an explanation must be concise and meaningful and give the result, the main types of personal information used, the main criteria including how those types affected the decision, and the procedure (Art. 44-3(2)); a request to have added information considered must be reviewed and answered (Art. 44-3(3)); both within 30 days (Art. 44-3(5)); and the controller must publish on its website that it makes automated decisions with their purpose and the data subjects covered, the main personal-information types and how they relate to the decision, what the process considers and how the data is processed, the purpose and items where sensitive data or a child under 14's data is processed, and how to refuse or request an explanation, in standardised terms (Art. 44-4). Detect an automated-decision service with no published criteria or no explanation handler.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 15 Mar 2024
- Official source
- 개인정보 보호법 제37조의2 (Art. 37-2, rights over automated decisions) · captured 2 Oct 2026 · anchor hash (SHA-256)
a307bb64789d…· 10 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Who it applies to
- Duty falls on: controller
- Systems covered: automated decision
- Personal information controllers whose fully automated system (including AI) makes decisions that significantly affect a data subject's rights or obligations. Art. 37-2 applies from 2024-03-15 (Addenda of Law No. 19234, Art. 1 item 1: one year after promulgation on 2023-03-14). AI-adjacent (D-9, D-13).
- Not covered:
- Automatic dispositions by administrative agencies under Art. 20 of the Framework Act on Administration (Art. 37-2(1))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path.
At decision time, write a decision-log row with the purpose, the key factors or reason codes, the model output, how the output was used, the human's role, and the model version. Provide an access-request path (privacy portal endpoint or DSAR export job) that verifies the requester and assembles a plain-language response from those rows using a template that explains the purpose, the logic, the outcome, and the person's other rights. Without decision-time records the access response cannot be reconstructed later, so the logging belongs in the decision service, not in the privacy team's tooling.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Explain on request, concisely and meaningfully: the result, the main personal-information types used, the main criteria and their effect, and the procedure; answer within 30 days (Decree Art. 44-3(2), (5)).
- Publish on the website, in standardised terms, the Decree Art. 44-4(1) items: the fact, purpose and covered data subjects; main data types and their relation to the decision; considerations and processing steps; sensitive or under-14 data and why; and how to refuse or request an explanation.
Example (Python + scikit-learn), before:
score = model.predict_proba([features])[0][1]
applications.update(app_id, status='approved' if score >= 0.6 else 'denied')After:
score = model.predict_proba([features])[0][1]
status = 'approved' if score >= 0.6 else 'denied'
decision_log.insert({'consumer_id': cid, 'purpose': 'credit line eligibility',
'key_factors': reason_codes(features), 'model_output': score,
'how_used': 'scores of 0.6 or more approve; lower scores deny',
'human_role': 'underwriter reviews appeals', 'model_version': MODEL_VERSION})
applications.update(app_id, status=status)Control: Significant-decision ADMT without consumer access explanation. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
Rule id kr-pipa-adm.explanation-and-published-criteria · review status: primary source derived