In accordance with Article 30 of the Personal Information Protection Act (「개인정보 보호법」), the Inter-Korean Exchange & Cooperation Center (the "Center") establishes and publishes the following privacy policy in order to protect the personal data of data subjects and to handle related grievances promptly and smoothly.
- 1. Purposes of processing personal data
- 2. Personal data items processed
- 3. Processing and retention periods
- 4. Provision of personal data to third parties
- 5. Outsourcing of personal data processing
- 6. Destruction of personal data
- 7. Rights and duties of data subjects and legal representatives, and how to exercise them
- 8. Measures to ensure the security of personal data
- 9. Automatic data collection devices: installation, operation and refusal
- 10. Personal Data Protection Officer
- 11. Remedies for infringement of rights
- 12. Changes to this policy
1. Purposes of processing personal data
The Center processes personal data for the purposes set out below. Where a purpose changes, the Center takes the necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
- Handling consultation requests — receiving requests for consultation on exchange and cooperation procedures, funding and participation in the Talent Network; verifying the enquirer's identity; replying; and follow-up contact
- Record keeping — checking the history of consultations and preventing duplicate enquiries
2. Personal data items processed
| Category | Items collected | Method of collection |
|---|---|---|
| Consultation request (required) | Name, organization (institution or group name), contact details (telephone number), subject of the consultation, content of the enquiry | Consultation request form on this website |
| Consultation request (optional) | Email address | Consultation request form on this website |
| Generated automatically | IP address, time of access, browser type | Access logs kept by the hosting service |
Please do not include sensitive data (such as ideology, beliefs or political opinions) or a resident registration number in your enquiry. If information that is not needed for the consultation is included, the Center deletes it rather than storing it separately.
3. Processing and retention periods
The Center processes and retains personal data within the retention and use period consented to at the time of collection from the data subject.
- Consultation request data — one year from the date the consultation is closed, then destroyed without delay
- Access logs — up to three months, in line with the hosting service's retention policy
- Where another statute imposes a retention obligation, for the period laid down by that statute
4. Provision of personal data to third parties
The Center processes personal data only within the scope of the purposes set out in Section 1 and does not provide it to third parties, except with the separate consent of the data subject or where specifically provided for by law. Where an enquiry needs to be taken up with a government body or a related organization, the Center advises the data subject to contact that body directly; the Center does not pass on personal data on their behalf.
5. Outsourcing of personal data processing
To provide its services smoothly, the Center outsources the processing of personal data as follows.
| Contractor | Outsourced work |
|---|---|
| Website hosting provider | Operating the website, transmitting consultation request forms, and retaining access logs |
| Email service provider | Receiving and storing consultation requests by email |
In accordance with Article 26 of the Personal Information Protection Act, the outsourcing contract sets out in writing the prohibition on processing for purposes other than performing the outsourced work, technical and administrative safeguards, restrictions on sub-contracting, liability for damages and related matters, and the Center supervises whether the contractor processes the data securely. Any change of contractor will be published in this policy.
6. Destruction of personal data
When personal data is no longer needed — because the retention period has expired or the purpose of processing has been achieved — the Center destroys it without delay.
- Procedure — the personal data for which grounds for destruction have arisen is identified and destroyed with the approval of the Personal Data Protection Officer
- Method — electronic files are permanently deleted so that they cannot be recovered; paper documents are shredded or incinerated
7. Rights and duties of data subjects and legal representatives, and how to exercise them
Data subjects may at any time exercise rights against the Center, including the right to access, correct, delete or suspend the processing of their personal data. These rights may be exercised in writing, by telephone or by email to the Personal Data Protection Officer named in Section 10, and the Center will act on the request without delay.
- The Center does not collect the personal data of children under the age of 14. Rights may also be exercised through the data subject's legal representative or an authorised agent, in which case a letter of authority must be submitted.
- A data subject's rights to access data and to demand suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.
- Where another statute expressly specifies the personal data as subject to collection, deletion cannot be demanded.
8. Measures to ensure the security of personal data
- Administrative measures — keeping the number of staff who handle personal data to a minimum, maintaining an internal management plan, and carrying out regular checks
- Technical measures — HTTPS encryption across the whole site, anti-automation checks on the consultation request form, access rights management, and security updates
- Physical measures — devices and documents holding consultation records are kept under lock and key
9. Automatic data collection devices: installation, operation and refusal
The Center's website does not currently use cookies and no visitor tracking tools are installed. If visitor analytics are introduced in future, their type, purpose and how to refuse them will be set out in this policy before they are put into use.
10. Personal Data Protection Officer
The Center has designated a Personal Data Protection Officer, as set out below, who takes overall responsibility for personal data processing and for handling complaints and providing redress for data subjects.
Telephone 1588-0303 (within Korea, Mon–Fri 09:00–18:00) · Email [email protected]
Address #1125, Mark One Avenue, 32 Guksecheong-ro, Sejong-si, Republic of Korea
Data subjects may raise with the Personal Data Protection Officer any enquiry, complaint or request for redress relating to personal data protection that arises while using the Center's services. Requests for access to data are received at the same contact details.
11. Remedies for infringement of rights
To obtain redress for an infringement of personal data rights, data subjects may apply to the bodies below for dispute resolution or advice.
- Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회) — 1833-6972 (no area code required), www.kopico.go.kr
- Privacy Center, Korea Internet & Security Agency / KISA (개인정보침해 신고센터, 한국인터넷진흥원) — 118 (no area code required), privacy.kisa.or.kr
- Cybercrime Investigation Division, Supreme Prosecutors' Office (대검찰청 사이버수사과) — 1301 (no area code required), www.spo.go.kr
- Cyber Investigation Bureau, Korean National Police Agency (경찰청 사이버수사국) — 182 (no area code required), ecrm.police.go.kr
12. Changes to this policy
This privacy policy applies from 3 June 2025. Where content is added, removed or amended because of changes in legislation, policy or security technology, notice will be given through the Notices section of this website at least seven days before the change takes effect.
- 3 June 2025 — first version (v1.0)