TwinEthos homeRequest access

Law

South Korea PIPA Art. 37-2 (automated decisions)

Personal Information Protection Commission (PIPC) · South Korea (KR) · 2 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.law.go.kr.

Trust and provenance 2 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Controllers must explain fully automated (including AI) decisions on request and publish their criteria and procedures (South Korea PIPA)

개인정보 보호법 제37조의2 (Art. 37-2, rights over automated decisions) · official text · In force: applies since 15 Mar 2024 · South Korea (KR)

A data subject may ask for an explanation of a decision a controller made by a fully automated system, including AI (Art. 37-2(2)); the controller must, absent justifiable grounds, provide the explanation (Art. 37-2(3)), and must publish the criteria and procedure of its automated decisions and how personal information is processed so data subjects can easily check them (Art. 37-2(4)). Under the Enforcement Decree, an explanation must be concise and meaningful and give the result, the main types of personal information used, the main criteria including how those types affected the decision, and the procedure (Art. 44-3(2)); a request to have added information considered must be reviewed and answered (Art. 44-3(3)); both within 30 days (Art. 44-3(5)); and the controller must publish on its website that it makes automated decisions with their purpose and the data subjects covered, the main personal-information types and how they relate to the decision, what the process considers and how the data is processed, the purpose and items where sensitive data or a child under 14's data is processed, and how to refuse or request an explanation, in standardised terms (Art. 44-4). Detect an automated-decision service with no published criteria or no explanation handler.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Mar 2024
Official source
개인정보 보호법 제37조의2 (Art. 37-2, rights over automated decisions) · captured 2 Oct 2026 · anchor hash (SHA-256) a307bb64789d… · 10 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Personal information controllers whose fully automated system (including AI) makes decisions that significantly affect a data subject's rights or obligations. Art. 37-2 applies from 2024-03-15 (Addenda of Law No. 19234, Art. 1 item 1: one year after promulgation on 2023-03-14). AI-adjacent (D-9, D-13).
  • Not covered:
    • Automatic dispositions by administrative agencies under Art. 20 of the Framework Act on Administration (Art. 37-2(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path.

At decision time, write a decision-log row with the purpose, the key factors or reason codes, the model output, how the output was used, the human's role, and the model version. Provide an access-request path (privacy portal endpoint or DSAR export job) that verifies the requester and assembles a plain-language response from those rows using a template that explains the purpose, the logic, the outcome, and the person's other rights. Without decision-time records the access response cannot be reconstructed later, so the logging belongs in the decision service, not in the privacy team's tooling.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Explain on request, concisely and meaningfully: the result, the main personal-information types used, the main criteria and their effect, and the procedure; answer within 30 days (Decree Art. 44-3(2), (5)).
  • Publish on the website, in standardised terms, the Decree Art. 44-4(1) items: the fact, purpose and covered data subjects; main data types and their relation to the decision; considerations and processing steps; sensitive or under-14 data and why; and how to refuse or request an explanation.

Example (Python + scikit-learn), before:

score = model.predict_proba([features])[0][1]
applications.update(app_id, status='approved' if score >= 0.6 else 'denied')

After:

score = model.predict_proba([features])[0][1]
status = 'approved' if score >= 0.6 else 'denied'
decision_log.insert({'consumer_id': cid, 'purpose': 'credit line eligibility',
                     'key_factors': reason_codes(features), 'model_output': score,
                     'how_used': 'scores of 0.6 or more approve; lower scores deny',
                     'human_role': 'underwriter reviews appeals', 'model_version': MODEL_VERSION})
applications.update(app_id, status=status)

Control: Significant-decision ADMT without consumer access explanation. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere

Rule id kr-pipa-adm.explanation-and-published-criteria · review status: primary source derived

Binding law — in force AI-adjacent law

People may refuse significant fully automated (including AI) decisions; the controller must stop them or re-process with a human (South Korea PIPA)

개인정보 보호법 제37조의2 (Art. 37-2, rights over automated decisions) · official text · In force: applies since 15 Mar 2024 · South Korea (KR)

A data subject may refuse a decision made by processing personal information with a fully automated system, including a system applying AI technology, where it significantly affects their rights or obligations, unless the decision rests on consent, a legal duty or a contract (Art. 15(1)1, 2, 4) (Art. 37-2(1)). On a refusal the controller must, absent justifiable grounds, stop applying the automated decision or re-process it with human involvement (Art. 37-2(3)). The Enforcement Decree requires refusals to follow the method the controller publishes (Art. 44-2(1)), the controller to take one of those measures and tell the data subject the result (Art. 44-3(1)), to give written reasons when it rejects a request on justifiable grounds (Art. 44-3(4)), and to act within 30 days, extendable twice by 30 days with notice (Art. 44-3(5)). Detect model output that becomes a decision about a person with no refusal route or human re-processing.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 15 Mar 2024
Official source
개인정보 보호법 제37조의2 (Art. 37-2, rights over automated decisions) · captured 2 Oct 2026 · anchor hash (SHA-256) a307bb64789d… · 10 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • The refusal right does not apply where the decision rests on consent, a legal duty or a contract with the data subject (Art. 15(1)1, 2, 4); the explanation right still does. Whether the effect is significant is a human…

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Personal information controllers whose fully automated system (including AI) makes decisions that significantly affect a data subject's rights or obligations. Art. 37-2 applies from 2024-03-15 (Addenda of Law No. 19234, Art. 1 item 1: one year after promulgation on 2023-03-14). AI-adjacent (D-9, D-13).
  • Not covered:
    • Automatic dispositions by administrative agencies under Art. 20 of the Framework Act on Administration (Art. 37-2(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.

Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.

What this provision adds:

  • Act on a refusal within 30 days (extendable twice by 30 days with notice), by stopping the automated decision or re-processing with human involvement, and tell the data subject the result in writing (Decree Art. 44-3(1), (5)).
  • Give written reasons without delay when declining a request on justifiable grounds (Decree Art. 44-3(4)).

Example (Python + OpenAI SDK), before:

verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
    deny(applicant)
    send_decision_email(applicant, 'Your application was not approved.')

After:

out = client.chat.completions.create(model=MODEL, messages=msgs,
                                     response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
    if requires_human_review('credit'):                 # a person decides
        review_queue.enqueue(applicant.id, proposal=result)
    else:                                               # solely automated, recorded basis
        deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
        send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
            reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))

Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 15 items with binding law in 15 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id kr-pipa-adm.refuse-or-human-reprocessing · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.