Use Policies on the Public Data Portal

Usage Policies

Public Data Usage Policy

All public sector organizations ensure that anyone can conveniently reuse public data through public data portals, and are striving for universal expansion of use rights. (Article 1, Article 3 of the Public Data Act)

What is Public Data Provision?

It refers to a public institution allowing users to access public data in a machine-readable form or delivering it in various ways.

How to use Public Data

Public Data provided through the public data portal can be used without a separate application procedure, and the list of provided public data can also be checked on the website of each public institution.
Data that is not provided by the public data portal can be used through application for provision. However, if the information subject to exclusion under Article 17 of the Public Data Act is included, provision may be denied, and in this case, you may apply for mediation to Open Data Mediation Committee.

※ For more information on how to use public data, please refer to Application Support> 「Public Data Reuse Guide」.

Scope of permission to use public data

Public data containing copyrights or other third-party rights must secure the legitimate permission of the rights holder.
When providing public data containing copyrighted works, the Public Domain label must be attached in accordance with the Copyright Act and other relevant laws.

[Reference] Public Data Management Guidelines, Article 8
- Article 8 (Management of Public Data Containing Copyrighted Works)
① When managing public data containing copyrighted works, the head of a public institution must clearly identify the ownership of the rights and the scope of the rights holder's permission to use the data to avoid infringement of third-party rights. In such cases, the rights holder's permission must be obtained in writing or other explicit means to confirm the intent.
② When providing public data containing copyrighted works, the head of a public institution must attach the Public Domain label in accordance with the Copyright Act and other relevant laws to indicate the scope of the permission to use the public data. In this case, even if the public data under their jurisdiction contains third-party rights, the data must be provided so that users can freely use the copyrighted work if the rights holder permits it.
③ In cases where the head of a public institution holds all copyrights to works included in public data under their jurisdiction, except in cases falling under any of the provisions of Article 24-2, Paragraph 1 of the Copyright Act, they shall provide such works so that users may use them freely without separate permission.

[Reference] Guide to Public Domain Types (https://www.kogl.or.kr/info/license.do)

KOGL License Type Guide

Provides license types, markers, and scope of use

Type of permission to use Marker Scope of Use
[Type 0]
Free use
No attribution required
Available for commercial and non-commercial use
Secondary works such as modifications can be created
[Type 1]
Source
Source
Available for commercial and non-commercial use
Secondary works such as modifications can be created
[Type 2]
Attribution + No Commercial Use
Source
Non-commercial use only
Secondary works such as modifications can be created
[Type 3]
Attribution + No Derivatives
Source
Available for commercial and non-commercial use
Prohibition on creation of secondary works such as modifications
[Type 4]
Attribution + No Commercial Use + No Derivatives
Source
Non-commercial use only
Prohibition on creation of secondary works such as modifications
[AI Type]
For artificial intelligence learning
No attribution required
Available for commercial and non-commercial use
Secondary works such as modifications can be created

Reference
National Law Information Center - Public Data Law
National Law Information Center – Enforcement Decree
National Law Information Center - Enforcement Rules

Terms and Services

Chapter 1: General Provisions

  • These Terms and Conditions are intended to stipulate the terms and conditions of use, the rights, duties and responsibilities of members and operating institutions, and other necessary matters in relation to the use of services provided by the Public Data portal (hereinafter referred to as the 'portal').

  • The terms used in these Terms and Conditions are defined as follows.

    1. "Portal" refers to the integrated public data provision system established and managed by the Ministry of the Interior and Safety for the efficient provision of public data pursuant to Article 21 of the Public Data Act.
    2. "List Registration Management System" refers to the public data business system established and operated by the Ministry of the Interior and Safety for the systematic management of public data pursuant to Article 18 of the Public Data Act.
    3. "Member" refers to all of the following: "General Member," "Corporate Member," and "Institutional Member."
    4. "General Member" refers to an individual or corporation that has agreed to the Terms of Use and completed registration through the Portal's membership registration process, and is eligible to use the services provided by the Portal.
    5. "Corporate Member" refers to a corporation or organization whose employee has agreed to the Terms of Use and completed registration on behalf of the corporation or organization through the Portal's membership registration process, and is eligible to use the services provided by the Portal.
    6. "Institutional Member" refers to a public institution that has completed an application for conversion from a "General Member" to an "Institutional Member" or a "Corporate Member" or whose employee has agreed to the Terms of Use and completed registration on behalf of a "Public Institution" through the membership registration process in the "List Registration Management System." This person is eligible to use the services provided by the "Portal."
    7. "Public Institution" refers to a public institution as defined in Article 2, Paragraph 1 of the Public Data Act.
    8. "Provider" refers to a "Public Institution" providing public data through the "Portal."
    9. "Center" refers to the Public Data Utilization Support Center established at the Korea National Information Society Agency (NIA), which performs public data-related tasks, including the construction, management, and utilization promotion of the "Portal," as defined in Article 13 of the Public Data Act.
    10. Terms not defined in these Terms and Conditions shall be defined in relevant laws and service guidelines or in general terms.
    1. The Center will post the contents of these Terms and Conditions on the portal or otherwise notify members so that they are easily accessible. These Terms and Conditions will apply to all members who agree to them.
    2. The Center may amend these Terms and Conditions as necessary, provided that they do not violate applicable laws and regulations. If changes are made to these Terms and Conditions, the Center will post a notice on the portal at least seven days prior to the effective date, specifying the changes, and notify members via the email address they provided upon registration. However, changes to correct minor typos or obvious errors are exempt from this provision.
    3. If a member does not agree to the amended Terms and Conditions after being notified of the changes, they may terminate their service agreement (cancel their membership). If a member does not explicitly express their objection to the changes, they will be deemed to have agreed to the amended Terms and Conditions.
  • Matters not stipulated in these Terms and Conditions shall be governed by the Public Data Act, Personal Information Protection Act, Copyright Act, Terms and Conditions Regulation Act, Information and Communications Network Act, and other relevant laws and regulations, as well as the Personal Information Processing Policy and guidelines separately established by the Ministry of the Interior and Safety. In the absence of provisions in laws and guidelines, general practices shall apply.

Chapter 2 Terms of Use and Procedure

    1. This Service Agreement is established when a user wishing to become a member (hereinafter referred to as the "Applicant") agrees to these Terms and Conditions and the collection and use of personal information by filling out the required information in the membership application form provided online by the portal, and the Center approves the Applicant's membership application.
    2. When registering as a member, the Applicant is deemed to have fully read and agreed to these Terms and Conditions by clicking the "Agree" button on each registration screen after understanding the registration procedures for general, corporate, and institutional members.
    3. Public institutions under Article 2, Paragraph 7 of these Terms and Conditions may register as corporations and then transition to service providers under Article 2, Paragraph 8 of these Terms and Conditions.
    4. The Center may not approve or terminate membership applications that fall under any of the following clauses.
      • 1) When applying using another person's name
      • 2) When false information is provided in the membership application form, false information is submitted, or other application requirements set by the Center are not met
      • 3) When using the portal to engage in acts prohibited by law or these Terms and Conditions, or when applying for the purpose of disrupting public order or morals
      • 4) When interfering with another person's use of the portal service or stealing information
      • 5) When a member has withdrawn from membership to avoid sanctions for misuse of the service before such sanctions are imposed
      • 6) When a member whose membership agreement was terminated due to the Center's fault, such as a violation of these Terms and Conditions, applies for re-registration
      • 7) For corporate members, when the affiliated company or the person in charge cannot be confirmed or has resigned
      • 8) When the sharing policy and work processing standards of the provider set by the Center are violated
    5. If any of the facts listed in Paragraph 4 above are discovered after membership registration, the Center may terminate the membership agreement, delete the member ID, or forcibly withdraw the member. In such cases, legal procedures for criminal punishment or administrative sanctions may be initiated in accordance with relevant laws and regulations
    6. The Center may withhold approval of membership applications until the reasons for such suspension are resolved in the following cases
      • 1) Service interruption due to technical issues
      • 2) When a telecommunications service provider suspends telecommunications services pursuant to the Telecommunications Business Act
      • 3) When a national emergency such as war, incident, natural disaster, or similar event occurs or is likely to occur
      • 4) When emergency equipment failure, service overload, or other reasons impede service provision
    7. If a member wishes to terminate the service agreement (membership withdrawal), the member may apply for membership withdrawal through the portal, and the Center will immediately process the withdrawal. The member is responsible for any disadvantages arising from membership withdrawal.
    1. Members' personal information is protected by relevant laws such as the Personal Information Protection Act.
    2. Member information is used, managed, and protected as follows.
      1. 1) Use of Personal Information: The Center will not use or provide members' personal information to third parties without their consent. However, exceptions may be made when permitted by relevant laws.
      2. 2) Management of personal information: Members can modify or delete personal information from time to time through the personal information management function of the portal service to protect and manage personal information.
      3. 3) Protection of personal information: Members' personal information is managed entirely by the member's ID and password, and only members can view, modify and delete. Therefore, you must not disclose the member's ID and password to others, and you must close the connection at the end of use.
      4. 4) Disposal of personal information: Upon membership withdrawal, the operating institution immediately discards the member information registered in the portal.
    1. From the moment a member completes the portal membership registration process, they are responsible for safely managing their ID, password, and other related information. They must not disclose their information or account (ID, password, etc.) to others. They are responsible for all consequences arising from their failure to fulfill this responsibility.
    2. If a member discovers that their ID or password has been used illegally, they must immediately report it to the Center. They are responsible for all consequences arising from their failure to report.
    3. The Center is not responsible for any legal issues, including any damages, arising from third parties accessing their information due to a member's failure to properly terminate the portal service.
    1. Portal service hours are, in principle, 24 hours a day, 365 days a year, unless there are special operational or technical difficulties at the Center.
    2. Notwithstanding the operating hours stipulated in Paragraph 1, the Center may restrict service access after prior notice on the portal if it deems it necessary for the smooth operation of the portal, such as for regular maintenance.
    1. The Center may temporarily or permanently suspend the Portal Service if it determines that the smooth provision of the Portal Service is difficult due to a national emergency, power outage, equipment failure, or other force majeure; if improvements to business procedures or systems are required pursuant to relevant laws and regulations; or if the continued provision of the Portal Service is otherwise difficult. In the event of a permanent suspension, members must be notified three months in advance.
    2. The Center may temporarily modify, change, or suspend the Service after prior notice if it deems it necessary for the smooth operation of the Portal Service.
  • To ensure smooth operation of the portal, the Center may delete any information (hereinafter referred to as "Posts") posted by members, including text, photos, videos, various files, and links, without prior notice in the following cases

    1. Posts that violate these Terms of Service or are deemed commercial, illegal, obscene, or vulgar
    2. Posts that defame or slander other members or third parties
    3. Posts that violate public order and morals
    4. Posts that are deemed to be linked to criminal activity
    5. Posts that infringe on the copyrights or other rights of third parties
    6. Posts that violate other relevant laws and regulations
    1. If the information provided by a member is found to be false or there are reasonable grounds to suspect such information, the Center may suspend part or all of the member's use of the service. The Center shall not be liable for any disadvantages incurred by the member or any third party as a result thereof, unless such suspension is due to the Center's intentional or gross negligence.
    2. The Center may restrict the member's use of the service if it determines that the member has violated these Terms and Conditions, and shall not be liable for any damages resulting from such restriction.

Chapter 3 rights, duties and responsibilities

    1. Members retain the copyright and other legally protected rights to posts they create while using the portal service.
    2. Members must be careful not to include any information that violates other people's copyrights or other relevant laws when creating posts. Members are responsible for any civil or criminal liability arising from such postings.
    3. Members must accurately enter the information requested upon registration. Members must also maintain and update any previously provided information to ensure it is accurate.
    4. Members must not engage in any of the following acts in connection with their use of the portal service
      1. 1) Allowing a third party to use your ID and password or illegally using another member's ID
      2. 2) Falsely altering member information or information posted on the portal
      3. 3) Acts intended for criminal activity or related to other criminal activities
      4. 4) Acts that harm public morals or other social order
      5. 5) Acts that defame or insult others
      6. 6) Acts that infringe upon the intellectual property rights of others
      7. 7) Acts that execute hacking or similar programs or interfere with normal operation (e.g., hacking, virus distribution, DDoS attacks, etc.)
      8. 8) Continuously posting information unrelated to the portal service, such as advertising information
      9. 9) Any other actions that disrupt or are likely to disrupt the stable operation of the service
      1. The Center may take the following actions against members who commit acts falling under Paragraph 4 of this Article. However, the actions the Center may take are not limited to the following, and the member's actions against which the Company may take action are not limited to those falling under Paragraph 4 of this Article.
      2. 1) Restrictions on use of certain services
      3. 2) Termination of service agreement
      4. 3) Claim for damages
    1. The Center must legally perform its duties in accordance with the Public Data Act and other applicable laws governing portal services, and is obligated to provide continuous and stable services.
    2. The Center will not use or provide members' personal information to third parties without their consent. However, exceptions may be made when permitted by the Personal Information Protection Act or other relevant laws.
    3. The Center must protect members' personal information to ensure that members can safely use the portal service.
    4. The Center is not responsible for any service disruptions caused by a member's fault.
    1. If the public data it holds and manages falls under the scope of provision under Article 17 of the Public Data Act, the provider must register a provision list and upload the relevant data to the portal in accordance with relevant procedures.
    2. If a member requests provision of public data not listed on the provision list pursuant to Article 27 of the Public Data Act, the provider must decide whether to provide the data in compliance with the procedures and standards prescribed by law. Upon deciding whether to provide the data, the provider must promptly notify the member of the decision.
    3. The provider must update the public data provided on the portal and take action on any omissions, errors, or inconveniences reported by members.
    4. The provider may suspend the provision of public data in the following cases.
      1. 1) When a user violates the usage requirements announced at the time of providing public data, potentially causing significant disruption to the public institution's original business operations
      2. 2) When the use of public data significantly infringes on the rights of a third party
      3. 3) When public data is misused for illegal activities such as crime
      4. 4) When the provider requests the Minister of the Interior and Safety to exclude the data from the list of public data pursuant to Article 20 of the Public Data Act
      5. 5) In other cases determined by the Public Data Dispute Mediation Committee pursuant to Article 29 of the Public Data Act
    5. With regard to the use of public data provided via open APIs, the provider may restrict service use if a specific member's usage pattern disrupts the provider's business or causes problems such as reduced performance of the provision system.

Chapter 4 Others

    1. In principle, intellectual property rights for portal services belong to the Center. However, this does not apply if otherwise stipulated in a contract or other agreement.
    2. Information posted in the Portal Data Room menu is not based on public data provision decisions and may contain intellectual property belonging to public institutions and third parties. Therefore, care must be taken to avoid infringement of relevant rights when using the information.
    3. Members must not use or allow third parties to use intellectual property related to portal services without the Center's express prior approval.
    1. The provider shall not be liable for any damages suffered by users or third parties due to reasons stipulated in Article 36 of the Public Data Act, such as the quality of public data or the suspension of public data provision, in connection with the provision of public data.
    2. Pursuant to Article 36, Paragraph 3 of the Public Data Act, users shall not be liable for damages suffered by the true rights holder even if they use public data that contains third-party rights. However, this does not apply if the user used the data with the knowledge that third-party rights were included.
    3. The Center shall not be liable for any damages suffered by members or third parties in connection with the use of the portal service due to reasons such as service suspension pursuant to Article 9. However, this does not apply if such damages are caused by the Center's intentional or gross negligence, criminal acts, or other causes.
    1. Disputes arising between the portal and its members regarding the use of services shall be governed by the laws of the Republic of Korea. Any lawsuit arising from such disputes shall be filed in the competent court under the Civil Procedure Act.

Supplementary provisions

  1. These Terms and Conditions are effective as of June 8, 2023.
    1. * Revised: June 8, 2023

Ministry of the Interior and Safety <Public Data Portal> Personal Information Processing Policy

The Ministry of the Interior and Safety (http://www.data.go.kr, hereinafter referred to as the "Public Data Portal") protects the freedom and rights of data subjects by lawfully processing and safely managing personal information in compliance with the Personal Information Protection Act and related laws and regulations. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Ministry of the Interior and Safety establishes and discloses the following personal information processing policy to provide data subjects with information on the procedures and standards for personal information processing and to promptly and smoothly address any complaints related to this process.
Labeling of key personal information processing
Index

The “Personal Information Processing Policy” consists of the following contents.

※ Clicking on the table of contents will take you to the corresponding article.

  • 제1조(개인정보의 처리 목적) Article 1 (Purpose of Personal Information Processing)
  • 제2조(개인정보파일 등록 현황) Article 2 (Status of Personal Information File Registration)
  • 제3조(14세 미만 아동의 개인정보 처리에 관한 사항) Article 3 (Matters concerning the processing of personal information of children under 14 years of age)
  • 제4조(개인정보의 처리 및 보유 기간) Article 4 (Processing and Retention Period of Personal Information)
  • 제5조(개인정보의 파기 절차 및 방법에 관한 사항) Article 5 (Matters concerning procedures and methods for destroying personal information)
  • 제6조(개인정보의 제3자 제공에 관한 사항) Article 6 (Matters regarding provision of personal information to third parties)
  • 제7조(추가적인 이용·제공이 지속적으로 발생 시 판단 기준) Article 7 (Judgment Criteria for Continuous Additional Use/Provision)
  • 제8조(개인정보 처리업무의 위탁에 관한 사항) Article 8 (Matters concerning entrustment of personal information processing tasks)
  • 제9조(개인정보의 안전성 확보조치에 관한 사항) Article 9 (Matters concerning measures to ensure the security of personal information)
  • 제10조(가명정보 처리에 관한 사항) Article 10 (Matters concerning processing of pseudonymized information)
  • 제11조(개인정보를 자동으로 수집하는 장치의 설치·운영 및 그 거부에 관한 사항) Article 11 (Matters concerning the installation and operation of devices that automatically collect personal information and their refusal)
  • 제12조(정보주체와 법정대리인의 권리·의무 및 행사방법에 관한 사항 의무) Article 12 (Matters concerning the rights, obligations, and exercise methods of data subjects and legal representatives)
  • 제13조(개인정보 보호(분야별)책임자의 성명 또는 개인정보 업무 담당부서 및 고충 사항을 처리하는 부서에 관한 사항 의무) 제13조(개인정보 보호(분야별)책임자의 성명 또는 개인정보 업무 담당부서 및 고충 사항을 처리하는 부서에 관한 사항 의무) Article 13 (Name of the Privacy Officer/Department in Charge of Personal Information or Department Responsible for Handling Grievances)
  • 제14조(정보주체의 권익침해에 대한구제방법) Article 14 (Methods of Remedy for Infringement of the Rights of Data Subjects)
  • 제15조(개인정보 보호수준 평가 결과) Article 15 (Results of Personal Information Protection Level Evaluation)
  • 제16조(개인정보 처리방침의 변경에 관한 사항) Article 16 (Matters regarding changes to personal information processing policy)
    • ① The Public Data Portal processes personal information for the following purposes. The personal information being processed will not be used for any purposes other than the following. If the purpose of use changes, necessary measures, such as obtaining separate consent, will be taken in accordance with Article 18 of the Personal Information Protection Act.
      • 1. Public Data Portal Member Information
        Public Data Portal member information collected through membership registration, identity verification, and membership confirmation procedures is processed for the purposes of managing the use of the Public Data Portal and public data utilization, reflecting public data policies, and evaluating the status of public data provision operations.
      • 2. Public Data Portal Data Provision Request Applicant Information
        Personal information included in the Public Data Portal data provision request applicant information is processed by the application reception and processing agencies for the purpose of processing public data provision applications pursuant to Article 27, Paragraph 1 of the Act on the Promotion of the Provision and Use of Public Data.
      • 3. Public Data Provision Dispute Mediation Applicant Information
        Personal information included in public data provision dispute mediation applicant information is processed by the dispute mediation application receiving and processing agencies for the purpose of processing public data dispute mediation applications pursuant to Article 31, Paragraph 2 of the Act on Promotion of Provision and Use of Public Data.
    • ① The Public Data Portal processes the personal information files registered and disclosed pursuant to Article 32 of the Personal Information Protection Act for the following purposes, retention periods, and items. Personal information is collected and used to the minimum extent necessary to provide the relevant business or service.
      • 1. The Public Data Portal processes the following personal information items with the consent of the data subject, and no personal information items are processed without the consent of the data subject.
    • Name of personal information file Operational basis/processing purpose Items of personal information recorded in the personal information file Retention period
      Public Data Portal
      Member Information
      Article 15, Paragraph 1, Item 1 of the Personal Information Protection Act
      (Consent of the data subject)
      Manage the use of public data portals and public data utilization, reflect public data policies, and conduct an evaluation of the operational status of public data provision.
      General member
      • Required : Name, ID, Password, Email, Mobile Phone
      • Optional : Phone Number
      Until Withdrawal
      Corporate Member
      • Required : Name, Company Name, ID, Password, Email, Mobile Phone Number, Company Representative Name
      • Optional : Phone Number
      Institutional Member
      • Required : Name, ID, Password, Email, Mobile Phone Number, Certificate Registration, User Organization/Industry Classification, Organization Name, Phone Number, Department Signature
      Public Data Portal Data Provision Request Applicant Information Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act
      (Consent of the Data Subject)
      • Required : Name, Date of Birth, Address, Phone Number, Email
      • Optional : Business (corporation, organization) registration number
      10 years
      Acceptance and processing of public data provision applications
      Public data provision dispute mediation applicant information Article 15, Paragraph 1, Item 1 of the Personal Information Protection Act
      (Consent of the data subject)
      • Required : Name, Date of Birth, Address, Phone Number, Email
      • Optional : Business (corporation, organization) registration number
      5 years
      Application and processing of dispute resolution related to the provision of public data, reflection of public data policy
    • ① When collecting personal information from children under the age of 14, the Public Data Portal obtains the consent of their legal guardians and collects the minimum amount of personal information necessary to perform the relevant service.
    • ② Additionally, when collecting personal information from children under the age of 14 for purposes of registering and managing membership on the Public Data Portal, separate consent is obtained from their legal guardians.
    • ③ When collecting personal information from children under the age of 14, the Public Data Portal may request the child to provide the minimum amount of information, such as the name and contact information of their legal guardian.
    • ① The Public Data Portal processes personal information within the retention and use period stipulated by law or agreed upon by the data subject at the time of collection.
    • ② The processing and retention periods for each piece of personal information are as follows.
      • 1. Public Data Portal member information: Until withdrawal from the Public Data Portal
      • 2. Information on applicants requesting data provision from the Public Data Portal: 10 years
      • 3. Information on applicants requesting mediation for public data provision disputes: 5 years
    • ① The Public Data Portal destroys personal information without delay when it becomes unnecessary, such as when the retention period expires or the processing purpose is achieved.
    • ② If the retention period agreed upon by the data subject expires or the processing purpose is achieved, but personal information must be retained in accordance with other laws and regulations, the personal information (or personal information file) will be transferred to a separate database (DB) or stored in a different location.
    • ③ The procedures and methods for destroying personal information are as follows
      • 1. Destruction Procedure : The Public Data Portal selects personal information (or personal information files) for which a reason for destruction has arisen and destroys the personal information (or personal information files) with the approval of the Public Data Portal's personal information field manager.
      • 2. Destruction Method : The Public Data Portal destroys personal information recorded and stored in electronic files so that the records cannot be restored. Personal information recorded and stored in paper documents will be shredded or incinerated.
    • ① The Public Data Portal processes the personal information of data subjects only within the scope specified in Article 1 (Purpose of Personal Information Processing). Personal information is provided to third parties only when required by the data subject's consent, special provisions of law, or in cases falling under Articles 17 and 18 of the Personal Information Protection Act.
    • ② The Public Data Portal provides personal information to third parties as follows.
    • Recipient Purpose of provision Provided items Retention and use period Related evidence
      Public institutions providing public data (List of institutions) Public data utilization processing, improvement/development, error reporting/correction, and inquiry response management Name (group name and representative name), ID, mobile phone number, email 2 years Article 26 of the Public Data Act
      Public institutions that receive and process applications for provision of public data Acceptance and processing of public data provision applications Name (organization name and representative name), date of birth, address, phone number, email, business (corporation, organization) registration number 10 years Article 27, Paragraph 1 of the Public Data Act, Article 21 of the Enforcement Decree of the same Act, and Form 9 of the Enforcement Rules of the same Act
      Respondent to the Public Data Provision Dispute Mediation (Public Institution) Public data provision dispute resolution application details and fact verification Name (organization name and representative name), date of birth, address, phone number, email, business (corporation, organization) registration number 5 years Article 31, Paragraph 2 of the Public Data Act, Article 10 of the Enforcement Decree of the same Act (Form No. 15 of the Appendix)
    • ① The Public Data Portal may additionally use and provide personal information without the consent of the data subject, taking into account the provisions of Article 14-2 of the Enforcement Decree of the Personal Information Protection Act, pursuant to Article 15, Paragraph 3 and Article 17, Paragraph 4 of the Personal Information Protection Act.
    • ② Accordingly, the Public Data Portal has considered the following factors in order to additionally use and provide personal information without the consent of the data subject
      1. ‣ Whether the purpose of additional use and provision of personal information is related to the original purpose of collection
      2. ‣ Whether the additional use and provision of personal information is predictable in light of the circumstances under which the personal information was collected or the processing practices
      3. ‣ Whether the additional use and provision of personal information unfairly infringes upon the interests of the data subject
      4. ‣ Whether necessary measures to ensure security, such as pseudonymization or encryption, have been taken
    • ① The Public Data Portal entrusts personal information processing tasks as follows to ensure smooth processing of personal information.
      • A. Entrusted Processing Agency (Trustee)
      • Name of the consignee Address Phone number Working hours Consignment work
        National Information Society Agency 53, Cheomdan-ro, Dong-gu, Daegu, Republic of Korea 053-230-1514, 1567 09:00~18:00 Public Data Portal Operation
      • B. Consignment processing company (subcontractor)
      • Name of the consignee Address Phone number Working hours Consignment work
        Prompt Technology Co., Ltd. 4F, 25, Insadong 5-gil, Jongno-gu, Seoul, Republic of Korea 1566-0025 09:00~18:00 Public Data Portal service development and monitoring, civil complaint response
        WISE iTech Co., Ltd. 11F, 117, Gwacheon-daero 12-gil, Gwacheon-si, Gyeonggi-do, Republic of Korea 02-6246-1400 09:00-18:00 Public Data Portal Operation Enhancement Task
    • ② When concluding a consignment contract, the Public Data Portal, in accordance with Article 26 of the Personal Information Protection Act, specifies in the contract or other documents matters related to the prohibition of processing personal information for purposes other than the consigned task, security measures, restrictions on re-consignment, management and supervision of the consignee, and liability for damages. Furthermore, the portal supervises the consignee to ensure the safe processing of personal information.
    • ③ Pursuant to Article 26, Paragraph 6 of the Personal Information Protection Act, if the consignee re-consigns our company's personal information processing, we obtain the consent of the Ministry of the Interior and Safety.
    • ④ If the details of the consignment or the consignee change, we will disclose such changes without delay through this Personal Information Processing Policy.
    • ① The Public Data Portal takes the following measures to ensure the security of personal information.
      • 1. Establishment and Implementation of an Internal Management Plan: We establish and implement an internal management plan to ensure the secure processing of personal information.
      • 2. Minimization and Training of Personal Information Handling Staff: We designate and manage only the necessary number of staff to handle personal information, and provide them with training on safe management.
      • 3. Regular In-house Guidance: We conduct an annual internal personal information protection management level assessment to ensure the security of personal information handling.
      • 4. Restriction of Access to Personal Information: We take necessary measures to control access to personal information by granting, modifying, and revoking access rights to the personal information processing system. We also use an intrusion prevention system to control unauthorized access from outside sources.
      • 5. Retention of Access Records: We retain and manage access records to the personal information processing system for at least one year. However, for personal information processing systems that process personal information of more than 50,000 data subjects or that process uniquely identifiable information or sensitive information, we retain and manage records for at least two years.
      • 6. Encryption of Personal Information: Personal information is securely stored and managed through encryption and other methods. Additionally, separate security features, such as encryption for important data during storage and transmission, are used.
      • 7. Technical Measures Against Hacking, etc.: The Ministry of the Interior and Safety ("Public Data Portal") installs security programs and regularly updates and inspects them to prevent personal information leakage and damage caused by hacking or computer viruses.
      • 8. Access Control for Unauthorized Personnel: The personal information processing system, which stores personal information, has a separate physical storage location and has established and operates access control procedures for this location.
    • We are not currently anonymizing personal information. If we do anonymize your information, we will provide you with information so that you can confirm the relevant information.
    • < Automatic Personal Information Collection Devices Installed and Operated >
    • ① The Public Data Portal uses "cookies" to store and periodically retrieve usage information to provide personalized services and convenience to users.
    • ② Cookies are small pieces of information sent by the server (http) used to operate the website to the user's browser and are stored on the user's PC or mobile device.
    • ③ Data subjects can configure their web browser options to allow or block cookies. However, refusing cookie storage may result in difficulties using customized services.
      1. ▶ Allow/Block Cookies in Web Browsers
      2. • Chrome: Web Browser Settings > Privacy & Security > Delete Browsing History
      3. • Edge: Web Browser Settings > Cookies and Site Permissions > Manage and Delete Cookies and Site Data
      4. ▶ Allow/Block Cookies in Mobile Browsers
      5. • Chrome: Mobile Browser Settings > Privacy & Security > Delete Browsing History
      6. • Safari: Mobile Device Settings > Safari > Advanced > Block All Cookies
      7. • Samsung Internet: Mobile Browser Settings > Browsing History > Delete Browsing History
    • < Matters Regarding the Collection, Use, Provision, and Refusal of Behavioral Information >
    • The Public Data Portal does not collect, use, or provide behavioral information.
    • ① Data subjects may exercise their rights at any time regarding the Public Data Portal, including requesting access to, correction of, deletion of, or suspension of processing of personal information, withdrawal of consent, and refusal or request for explanation of automated decisions.
      1. ※ Requests for access to personal information of children under the age of 14 must be made directly by their legal representative. Data subjects who are minors over the age of 14 may exercise their rights regarding their personal information either on their own or through their legal representative.
    • ② Rights may be exercised through the Public Data Portal in writing, by email, or by facsimile (fax), in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act. The Public Data Portal will take action without delay.
      1. - Data subjects may directly view, edit, or delete their personal information at any time by going to "My Page > Edit Member Information" on the website.
      2. - Data subjects may withdraw their consent to the collection and use of personal information at any time by clicking "Cancel Membership."
    • ③ Rights may be exercised through a proxy, such as the data subject's legal representative or authorized representative. In this case, a power of attorney in the format of Appendix 11 of the "Personal Information Processing Methods" must be submitted.
    • ④ The data subject's right to request access to and suspension of processing of personal information may be restricted by Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
    • ⑤ If personal information is specifically designated as a subject of collection under other laws and regulations, the deletion of such personal information may not be requested.
    • ⑥ If the data subject has consented to the fact that automated decisions will be made, has been notified in advance through a contract or other means, or is otherwise explicitly stipulated by law, refusal of automated decisions is not permitted; only requests for explanation and review are permitted.
      1. - Furthermore, requests for refusal or explanation of automated decisions may be rejected if there are legitimate grounds, such as concerns about unjustified infringement on the life, body, property, or other interests of another person.
    • ⑦ The Public Data Portal verifies whether the person making the request, including access to personal information, correction/deletion, processing suspension or withdrawal of consent, or refusal of automated decisions or explanations, is the data subject or a legitimate representative.
    • ⑧ The Public Data Portal allows requests for access to personal information to be submitted to the departments listed below. The Public Data Portal will strive to promptly process requests for access to personal information.
    • ▶ Department responsible for receiving and processing requests for access to personal information
    • Department in charge by field Person in charge Phone number Email Fax
      Public Data Policy Division Kim Gyu-han 044-205-2473 seesun0704@korea.kr 044-205-8926

      1. ※ In addition to the department receiving and processing requests for access, data subjects can also request access to their personal information through the ‘Personal Information Portal’ website (www.privacy.go.kr).
        • · Personal Information Portal → Civil Service → Exercise of Data Subject Rights → Request for Access to Personal Information, etc. (Identity verification required)
    • ① The Public Data Portal is responsible for overall management of personal information processing, and has designated a personal information protection officer (by field) as follows to handle complaints and provide remedies to data subjects related to personal information processing.
    • Position Department Name Contact Details
      Personal Information Protection Officer Policy Planning Director Lee Ji-seong ※ You will be connected to the relevant department.
      Phone number 044-205-2473
      Fax 044-205-8926
      Email seesun0704@korea.kr
      Personal Information Protection Manager Director of Public Data Policy Division Jeon Han-seong
      Personal information protection field manager Public Data Policy Division Kim Gyu-han
      Consignment processing agency Personal Information Protection Officer Vice President's Office Jang Kyung-mi ※ You will be connected to the relevant department.
      Phone number 053-230-1550
      Fax 053-230-1920
      Email sopal2@nia.or.kr
      Personal Information Protection Manager Public Intelligence Data Open Team Leader Geum Jong-hak
      Personal information protection field manager Public Intelligence Data Open Team Yoon So-yoon

    • ② Data subjects may inquire about all personal information protection-related matters, including inquiries, complaints, and damage relief, that arise while using the Public Data Portal, by contacting the relevant personal information department. The Public Data Portal will promptly respond and process inquiries from data subjects.
    • ① Data subjects may seek redress for personal information infringement by filing a complaint or requesting dispute resolution or consultation with the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency's Personal Information Infringement Report Center. For other inquiries or inquiries regarding personal information infringement, please contact the following organizations.
      • 1. Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)
      • 2. Personal Information Infringement Report Center: (without area code) 118 (privacy.kisa.or.kr)
      • 3. Supreme Prosecutors' Office: (without area code) 1301 (www.spo.go.kr)
      • 4. National Police Agency: (without area code) 182 (ecrm.cyber.go.kr)
    • ② The Public Data Portal guarantees the data subject's right to self-determination of personal information and strives to provide consultation and redress for damages resulting from personal information infringement. If you need to report or consult, please contact the relevant department below.
      1. ▶ Customer Consultation and Reporting Related to Personal Information Protection
    • Department in charge by field Person in charge Phone number Email Fax
      Public Data Policy Division Kim Gyu-han 044-205-2473 seesun0704@korea.kr 044-205-8926

    • ③ Any person whose rights or interests have been infringed upon by a disposition or inaction by the head of a public institution in response to a request pursuant to Article 35 (Access to Personal Information), Article 36 (Correction/Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may request an administrative appeal in accordance with the Administrative Appeals Act.
      1. ▶ Central Administrative Appeals Commission: (without area code) 110 (www.simpan.go.kr)
    • ① To ensure the safe management of personal information of data subjects, the Ministry of the Interior and Safety (MOIS) undergoes an annual "Personal Information Management Level Diagnosis of Public Institutions" conducted by the Personal Information Protection Commission, pursuant to Article 11-2 of the Personal Information Protection Act.
    • ② The MOIS received a "B" rating in the 2024 Personal Information Protection Level Assessment.
    • ③ Based on the assessment results, the MOIS is working to prevent personal information leaks by supplementing and improving personal information handling procedures.