Personal Data Processing Outsourcing Agreements: Why the Contract Alone Is Not Enough

A company outsources customer support to an external vendor. A personal data processing outsourcing agreement is signed. Does that mean the company has finished dealing with personal data compliance? No. When a business outsources CRM operations, customer support, e-commerce administration, messaging, delivery, logistics, cloud services, or similar work, the outside vendor may also gain access to customer personal information.
The Agreement Must Match the Actual Data Flow
The agreement is only one part of the structure. The more important question is whether the documentation matches the way personal data is actually handled. Five elements should be compared side by side:
- the outsourcing agreement
- the privacy policy
- the disclosed processor information
- the work the vendor actually performs
- the access rights configured in the system If the agreement says that the vendor only handles customer inquiries, but the vendor's employees can download full purchase histories, the contract and the system are telling different stories. If the privacy policy still lists a former processor while a different company is actually handling the data, the disclosure and the real arrangement do not match. The same issue arises when the contract requires deletion at the end of the engagement but copies remain on employee PCs, external drives, backup systems, or test environments. For personal data processing outsourcing, the practical question is not simply whether an agreement exists. It is whether the agreement reflects the actual flow of personal information.
447 Personal Data Breach Reports in 2025
According to a May 2026 analysis released by Korea's Personal Information Protection Commission, 447 personal data breach reports were filed in 2025. That was a 45.6% increase from 307 reports in 2024. Hacking accounted for 276 cases, or 62% of the total. During the same year, the Commission conducted 227 investigations and dispositions. Among 150 private-sector dispositions, 75 involved small and medium-sized enterprises, representing 50%. The Commission also identified chain-type breaches involving processors as an area requiring stronger management and supervision. Source: Personal Information Protection Commission, "Analysis of Personal Data Breach Reports and Investigation/Disposition Cases in 2025" (May 15, 2026) The important point for a business is not merely that hacking incidents increased. Outsourcing the work does not automatically outsource the controller's responsibility to supervise how personal information is handled.
Processing Outsourcing or Third-Party Provision?
Not every transfer of customer information to an outside company is treated as outsourced processing. A distinction must be made between processing outsourcing and third-party provision. The Supreme Court of Korea addressed this distinction in Supreme Court Decision 2016Do13263, decided on April 7, 2017. The Court explained that the classification should be determined by considering factors such as:
- the purpose and method by which the recipient obtains the information
- whether consideration is paid
- whether the transferring party exercises substantive management and supervision
- the effect on the protection of the data subject
- who actually needs to use the personal information Consider an online retailer that gives a delivery company the recipient's name, phone number, and address for the purpose of delivering an order. If the delivery company uses the information only to perform the retailer's delivery work and remains subject to the retailer's management and supervision, the arrangement may be structured as processing outsourcing. But the analysis changes if the delivery company can use the information independently for its own advertising or sales activities. The same issue can arise with a CRM provider. A company may believe that it has outsourced customer support, but if the CRM provider is also permitted to use customer data for its own product development, analytics, or marketing, the arrangement may not remain a simple outsourcing relationship. The title of the agreement does not determine the legal character of the data transfer. The actual structure should be examined first. Ask:
- Is the vendor performing only the work instructed by the company?
- Who determines the purpose for which the personal information is used?
- Can the vendor use the information for its own sales, analytics, or product development?
- Does the company actually control and supervise the scope of processing? Only after those questions are answered should the agreement be drafted around the real arrangement. Source: Supreme Court of Korea, Decision 2016Do13263 (April 7, 2017)
Write the Actual Work into the Agreement
Article 26 of Korea's Personal Information Protection Act (개인정보 보호법) and Article 28 of its Enforcement Decree specify matters that should be documented when personal information processing is outsourced. These include matters such as:
- the purpose and scope of the outsourced work
- prohibition on processing personal information beyond the outsourced purpose
- technical and managerial safeguards
- restrictions on sub-processing
- measures such as restrictions on access to personal information
- supervision, including inspection of the status of personal information management
- liability for damages in the event of a violation A practical problem arises when an agreement simply copies general statutory language. For example:
The processor shall safely handle personal information in compliance with applicable laws and regulations. The direction is not necessarily wrong. But the clause does not tell the company who may access the information, which data may be viewed, whether the information may be downloaded, or what happens to copies after the engagement ends. If that is what the parties have actually agreed, the clause can be made more specific. The processor may access only the customer's name, contact information, order number, and order information necessary to perform customer support services. Access rights shall be limited to personnel responsible for customer support, and records of the granting, modification, and termination of such rights shall be maintained. The processor shall not use personal information for purposes outside the outsourced work or provide it to a third party. Upon termination of the agreement, the processor shall return or delete the personal information and copies in accordance with the controller's procedures and provide materials confirming the result. This is not a statutory model clause. The actual wording should reflect the company's workflow, applicable retention obligations, data categories, and system architecture. The goal is for the agreement to show who can access which information, for what purpose, and what happens when the work ends.
When the Agreement and System Permissions Do Not Match
A 2025 enforcement action involving Seoul CC and Hanyang CC provides a useful example. Seoul CC had outsourced personal information processing to Hanyang CC. According to the Personal Information Protection Commission's investigation, the websites and golf-course operating systems of the two entities were not adequately separated and were managed using the same web server, database, and administrator account. An attacker used previously obtained administrator credentials to access the system. Spam messages were then sent to 70,166 Seoul CC members and 17,757 Hanyang CC members, for a total of 87,923 members. The Commission imposed approximately KRW 148 million in administrative surcharges and KRW 12.3 million in administrative fines on Hanyang CC, the processor. Seoul CC, the controller, was also subject to approximately KRW 53.1 million in administrative surcharges and KRW 9.9 million in administrative fines, including for inadequate management and supervision of the processor. The investigation also addressed whether the processing arrangement had been properly reflected in the relevant documentation and privacy policy. Source: Personal Information Protection Commission, "PIPC Imposes Administrative Surcharges on Both Controller and Processor Following Personal Data Breach" (October 23, 2025) From a contract review perspective, this leads to several practical questions:
- Does the agreement identify the actual processor?
- Does the privacy policy identify the same processor?
- If access is restricted in the agreement, is the system configured accordingly?
- Are user accounts separated appropriately?
- Are shared administrator accounts being used in practice? The documentation and the system should describe the same arrangement.
Supervision Begins after the Agreement Is Signed
Signing an outsourcing agreement is not the end of the controller's work. Article 26(4) of the Personal Information Protection Act requires the controller to supervise the processor, including through education and inspections of the processor's handling of personal information. A 2026 enforcement action involving Boram Sangjo illustrates why this matters. Boram Sangjo Development received outsourced CRM-related work, including online customer support, from six affiliated companies and managed personal information on an integrated basis. The Personal Information Protection Commission found deficiencies in safeguards, including access control. A hacker used an SQL injection attack to access a database and obtain personal information including names, mobile phone numbers, and email addresses. The Commission imposed an administrative surcharge of KRW 531 million and an administrative fine of KRW 11.4 million on Boram Sangjo Development. The six affiliated companies that had outsourced the work were also subject to administrative surcharges totaling KRW 11.5 million for deficiencies in processor management and supervision. Source: Personal Information Protection Commission, Decisions No. 2026-009-057 through 2026-009-063 (May 13, 2026); "PIPC Sanctions Boram Sangjo Following Personal Data Breach" (May 14, 2026) A clause stating that the processor must protect personal information does not eliminate the controller's supervision obligation. The company should be able to show what it actually reviewed. Depending on the volume and risk of processing, this may include:
- current access rights
- removal of access for former or reassigned personnel
- where personal information is stored
- whether sub-processors have changed
- whether security incidents have occurred
- records showing that processor supervision was actually performed If the contract says that inspections will be performed but no inspection record exists, there is still a gap between the document and the operation.
Verify Deletion When the Contract Ends
The end of an outsourcing relationship is another point where problems can arise. In 2026, the Personal Information Protection Commission imposed sanctions involving the Rural Development Administration and processor Misotech. Misotech had received outsourced system maintenance and management work from the Rural Development Administration and affiliated institutions. The investigation found that Misotech had stored outsourced personal information on its own network-attached storage system from May 2020 through April 2025. The NAS contained approximately 575,000 personal information records and was accessible from external IP addresses. In April 2025, an attacker obtained the information and posted it on the dark web. The termination process is particularly relevant. The outsourcing institutions had obtained statements confirming that the vendor no longer retained the materials when the service engagements ended. However, the investigation found that the institutions had not adequately checked whether personal information remained on laptops, external storage devices, or other locations. The Commission imposed an administrative surcharge of KRW 82.5 million and an administrative fine of KRW 4.5 million on Misotech. The Rural Development Administration was also subject to an administrative surcharge of KRW 168 million for deficiencies in processor management and supervision. Source: Personal Information Protection Commission, "Five Institutions and Companies Sanctioned for Violations of Safeguard and Processor Supervision Obligations" (May 28, 2026) The practical lesson is straightforward. A clause stating that personal information will be deleted when the contract ends may not be enough. The company should determine where the data may actually remain, including:
- production servers
- employee PCs
- downloaded files
- external storage devices
- backup copies
- test data
- user accounts The method used to verify deletion should also be decided in advance. A deletion confirmation can document the result. It does not replace the process of verifying whether deletion actually occurred.
Follow the Data through Sub-Processors and Overseas Transfers
Many outsourced services involve more than one outside company. A business may contract with a single CRM provider, while the service itself uses a cloud provider, messaging vendor, customer support platform, or other downstream service provider. This creates a sub-processing issue. Under Article 26(6) of the Personal Information Protection Act, a processor that intends to outsource the entrusted personal information processing work again to a third party must obtain the controller's consent. The company should therefore look beyond a general clause saying that consent is required. It should identify who is actually involved in the processing. Questions may include:
- What work has been sub-outsourced?
- Which personal information can the sub-processor access?
- How will changes to the sub-processor list be communicated?
- Are equivalent personal information protection obligations imposed on the sub-processor? Cloud and SaaS arrangements may require another layer of review. If an overseas provider or overseas server participates in the processing or storage of personal information, the company may also need to review Korea's overseas transfer rules. Article 28-8 of the Personal Information Protection Act covers overseas transfers that may include processing outsourcing and storage outside Korea. A contract with a Korean vendor therefore does not necessarily mean that all personal information remains in Korea. The actual processing and storage locations should be identified.
Separate the Statutory Deadline from Internal Incident Reporting
Time becomes critical when a personal data incident occurs. Article 34 of the Personal Information Protection Act requires a personal information controller that becomes aware of a leak or similar incident to notify data subjects of the prescribed matters without delay. The Enforcement Decree requires notification and reporting within 72 hours in specified circumstances, subject to the conditions and exceptions provided by law. This creates a practical contract issue. If the processor's contractual reporting deadline is also written simply as "within 72 hours," the controller may receive the first report too late to investigate the incident and prepare its own legally required response. The statutory deadline and the processor's internal reporting obligation should therefore be treated as different concepts. The parties may, for example, require the processor to provide an initial report without delay after becoming aware of an incident or a potential leak, followed by updated information as the investigation develops. The initial report can be structured to include matters such as:
- when the incident occurred or was discovered
- the affected system
- the personal information categories currently known to be affected
- the approximate scope currently identified
- immediate containment measures
- whether relevant logs and evidence have been preserved It is easier to define the reporting path before an incident than to decide who must provide what information after an incident has already occurred.
Review the Actual Operation First
When reviewing an outsourcing agreement, it can be more effective to start with the real operation rather than the first clause of the contract. Determine whether the vendor handles customer support, delivery, messaging, CRM administration, or another function. List the personal information actually needed for each function. If a delivery vendor can view a customer's date of birth or complete purchase history, ask why that information is necessary for the delivery task. Identify which personnel at which company can view the data. Check whether they can modify or download it, whether shared accounts exist, and whether former employees still have access. Review whether the agreement's description of the work, data scope, purpose limitation, safeguards, sub-processing, supervision, return or deletion, and incident reporting matches the real operation. Confirm that the current processor and outsourced work match the actual contractual relationship. Look for records of access-right reviews, processor education or supervision, sub-processing approvals, account removal, and deletion after termination. This sequence makes it easier to answer a more useful question than whether the wording of the agreement looks sophisticated: Is the business actually operating in the way the agreement says it is?
What a Business Can Check Directly
A business can begin by identifying its current outside vendors. For each vendor, it can list:
- the work being outsourced
- the personal information provided or made accessible
- the processor information currently disclosed
- the accounts and access rights in the system
- whether information was deleted when a previous engagement ended This initial mapping can often reveal obvious inconsistencies. Individual review becomes more important when:
- a vendor also uses customer information for its own marketing or analytics
- sub-processing and overseas transfers are combined
- the agreement, privacy policy, and system access rights do not match
- there are already indications of unauthorized retention or a personal data breach
When Individual Review Becomes More Important
Under Article 2(1)2 of the Administrative Attorney Act (「행정사법」) and the relevant provision of its Enforcement Decree, an Administrative Attorney may, except where restricted by other laws, prepare documents concerning rights and obligations, including contracts, agreements, confirmations, and other transaction-related documents. Within that scope, an Administrative Attorney can review the factual business arrangement reflected by the parties and prepare transaction-related documents so that the outsourced work, personal information categories, outsourcing agreement, privacy policy, and processor disclosure describe the same structure. Legal determination of civil damages, criminal liability, or representation in litigation arising from a personal information incident falls into a different legal practice area and may require review by an attorney-at-law.
The Contract and the Operation Must Describe the Same Reality
The riskiest situation is not only one in which no outsourcing agreement exists. A company can also have a signed agreement while the real operation has moved in another direction. The agreement may say that the vendor only provides customer support, while the vendor actually performs additional analytics. The company may believe that its processor disclosure is current, while the privacy policy still identifies a former vendor. The parties may believe that the data was deleted when the contract ended, while copies remain on PCs, external storage devices, or backups. The enforcement cases discussed above show that contract terms, processor disclosure, access rights, supervision, and deletion are not separate issues. They are parts of the same processing structure. A practical review therefore compares:
- the outsourcing agreement
- the privacy policy
- the processor disclosure
- the actual outsourced work
- the system access rights Those five elements should describe the same reality.
Frequently Asked Questions
Is signing a personal data processing outsourcing agreement enough under Korean law?
No. The agreement should also match the actual outsourced work, processor disclosure, system access rights, supervision process, and deletion practices.
Is every transfer of customer information to an outside vendor considered processing outsourcing?
No. The arrangement must be distinguished from third-party provision by looking at the vendor's actual purpose, use of the information, and the controller's management and supervision, among other factors.
Is a deletion confirmation sufficient when an outsourcing agreement ends?
A deletion confirmation may serve as evidence, but it does not replace verification of whether personal information actually remains on PCs, external storage, backups, test systems, or active accounts. This article provides general information only. Specific responsibilities and response measures may differ depending on the facts of each case. For an initial free review, you may provide the personal data processing outsourcing agreement, the relevant privacy policy or processor disclosure, and the actual scope of outsourced work so that the classification, missing management items, and the issues that should be addressed first can be identified.