ARTICLE
10 January 2022

European Commission Adopts Korean Adequacy Decision

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
The European Commission recently adopted an adequacy decision regarding the Republic of Korea's data protection laws.
Worldwide Privacy

The European Commission recently adopted an adequacy decision regarding the Republic of Korea's data protection laws. As a result of this decision, personal data can freely flow between the EEA and South Korea without the need for additional transfer mechanisms.

Without such a finding of adequacy, EU law prohibits the transfer of data out of the EU without certain measures being in place. These include, for example, the transferring entity and the recipient entering into Standard Contractual Clauses, or the recipient having Binding Corporate Rules in place. South Korea now joins 13 other countries that are able to freely transfer data from the EEA. This list includes Andorra, Argentina, Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, United Kingdom, and Uruguay.

This decision follows the EDPB's September opinion on the Commission's draft Korea adequacy decision. The decision covers transfers of data to both commercial operators and public authorities. A list of common Q&As can be found here. Whether the UK will grant South Korea this same adequacy status remains to be seen. Unlike the recent UK adequacy decision, which contains a sunset provision, the conclusion about the adequacy of South Korea's data privacy laws is not time-limited. Instead, the decision will be subject to a regular review every three to four years. The decision will continue so long as the level of data protection remains.

Putting it Into Practice: Companies who regularly engage in cross-border data transfers will not need additional measures -like SCCs- if the data transfers are from the EU to Korea.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More