South Korea's three telecom operators are elevating the strengthening of their personal data protection systems to a core management task. They agreed to reflect data protection from the design stage of telecom AI services and to build an accountability system directly managed by chief executives and boards.
The Personal Information Protection Commission on Sept. 28 held a policy communication meeting with the CEOs of the three telecom operators, including SK Telecom, KT and LG Uplus, at the Korea Press Center in Jung-gu, Seoul. It was the first time Chairperson Song Kyung-hee (송경희) had met the three CEOs in one place since taking office.
Last year, the telecom sector saw a series of personal data leak issues, including an SKT USIM hacking incident, an unauthorised small-payment billing incident at KT and suspicions of a server hacking at LG Uplus. The PIPC and the three telecom operators on the day focused discussions on measures to strengthen internal controls under the revised Personal Information Protection Act, accident-prevention systems and improvements to rules on using personal data in the AI development process.
In opening remarks, Song stressed the need to shift data protection systems from responding after an accident to a prevention-focused approach. "Protecting personal data in the telecom sector is about safeguarding people's daily lives and trust in a digital society," she said. "The recent series of data leak accidents is something both the government and companies must take seriously," she said.
She added that the system must shift to a prevention-focused framework that finds risks in advance and responds proactively before accidents occur. "Personal data protection should not be the task of only the responsible department. It must become a core management task that the CEO directly oversees and the entire company shares responsibility for," she said.
CEO and boards to directly oversee data protection in joint declaration by three telecom operators
The three telecom operators issued a joint declaration titled "Joint Declaration for an AI and Digital Society Trusted by the People" and stressed they would place personal data protection as a core value of corporate management. The declaration includes building accountability governance under which CEOs and boards constantly manage and check the status of data protection, and expanding investment and specialist personnel for data protection. The PIPC said the declaration aims to check and publicise telecom operators' efforts to protect personal data.
The three telecom operators will also build a proactive safety management system to prevent breach incidents. They agreed to apply "privacy by design" across the entire process from service planning to development and operation, to reduce the risk of privacy infringements in advance.
The PIPC and the three telecom operators also exchanged views on the recently revised Personal Information Protection Act. The revised law, which took effect on Sept. 11, specifies the CEO's ultimate responsibility for personal data protection and strengthens the role of the chief privacy officer.
The CEOs of the three companies expressed their intention at the meeting to actively participate in the government's policy direction. They stressed they are running privacy protection work under company-wide accountability governance. They shared difficulties related to training information security personnel and also requested cooperation at the government level. The three telecom operators said they will expand investment in personal data protection and continue strengthening internal management systems in line with the AI era.
Jung Jae-heon, CEO of SKT, said, "Personal data protection is a trust infrastructure that supports the AI industry to grow even further." He said, "As a people's livelihood infrastructure company spanning telecommunications and AI, SKT will fulfil its responsibility by protecting personal data safely while ensuring the public can fully enjoy the benefits of AI."
Park Yoon-young, CEO of KT, said, "We will expand the scope of ISMS-P certification to networks and media infrastructure and reflect personal data protection throughout the entire lifecycle from service planning to development and operation." He added, "We will accelerate the shift to a prevention-focused system rather than a post-incident response."
Hong Beom-sik, CEO of LG Uplus, said, "Based on responsibility and trust, we will raise transparency and accountability and work to guarantee users' rights." He added, "For a safe AI ecosystem, we will expand public-private cooperation and continue cooperating on advancing standards and systems to share field experience and best practices in the industry."
The PIPC urged the telecom operators to strengthen self-inspections and training for personal data handlers by the end of the year. It ordered the three telecom operators to strengthen management and supervision across their distribution networks, saying personal data management could be vulnerable at frontline retailers because the telecom industry has a complex distribution structure that runs from telecom operators to agencies and retail stores.
Lee Sang-min (이상민), director general of the PIPC's Personal Information Policy Bureau, said, "We have confirmed that the three telecom operators are now making personal data protection the top management value." He added, "We will further strengthen our communication efforts using today's meeting as an opportunity."
PIPC to prepare agentic AI guidance this year as it overhauls rules on AI data use
How to overhaul regulations on the use of data for AI development was also discussed as a key agenda item. The revised Personal Information Protection Act set to take effect in March next year includes an AI special provision. Under the provision, if certain requirements are met for AI technology development, a personal information processor may use personal information lawfully collected through review and resolution by the PIPC for purposes other than the original collection purpose.
The telecom industry presented opinions calling for clearer grounds in current personal information processing, including public information, pseudonymised information and legitimate interests, in the AI development process. Calls were also raised for separate standards for processing personal information that reflect the characteristics of AI agents.
The PIPC will prepare an improvement plan for related systems and draft an "Agentic AI Personal Information Processing Guidance" within this year. On the AI special provision system, it plans to continue improving related systems by detailing enforcement decrees and notices. It will build a pre-consultation system with industry and prepare operational measures that can be used in actual AI research and development fields.
The three telecom operators also requested building an always-on communication channel on pending personal information issues. The PIPC plans to reduce unreasonable regulations and institutional uncertainty in the industrial field through a public-private cooperation system and support corporate AI innovation.
Song said, "The joint declaration to make the people's personal information the top management value and establish a CEO-centred accountability governance system is a meaningful starting point for change." She added, "The PIPC will also support corporate efforts by presenting clear standards and incentives for preventive investment."