The Korean authority publishes a guide to support privacy protection in the transformation of public artificial intelligence
The South Korean Personal Information Protection Commission (PIPC) has published a guide aimed at framing the transformation by artificial intelligence (AI) in the public sector while ensuring privacy protection.
This guide aims to help public bodies anticipate issues related to the processing of personal data. It structures the approach into three phases: prior design, development and construction, then application and management, defining ten essential control points. The requirements notably concern verifying legal bases, choosing appropriate technologies according to risks, applying security measures such as pseudonymization and data filtering, as well as implementing continuous testing and procedures to guarantee the rights of data subjects.
The document proposes a differentiated approach to protection measures according to three types of AI uses: assistance with basic tasks, interconnection and information analysis, and selection or judgment for decision-making. For each type, controls are adapted to specific risks, such as misuse, excessive inference of personal information, or biases and lack of robustness of systems that may affect individuals' rights, especially in cases of automated decision-making.
Finally, the guide highlights the role of public bodies, which must integrate data protection at the core of their AI strategy under the leadership of their management, their Chief Privacy Officer (CPO), and their Chief Artificial Intelligence Officer (CAIO). For its part, the PIPC is setting up a permanent assistance service, the "privacy assistance service for AI transformation in the public sector," to provide comprehensive support to the entities concerned, including legal interpretation and access to mechanisms such as the regulatory sandbox.
This guide aims to help public bodies anticipate issues related to the processing of personal data. It structures the approach into three phases: prior design, development and construction, then application and management, defining ten essential control points. The requirements notably concern verifying legal bases, choosing appropriate technologies according to risks, applying security measures such as pseudonymization and data filtering, as well as implementing continuous testing and procedures to guarantee the rights of data subjects.
The document proposes a differentiated approach to protection measures according to three types of AI uses: assistance with basic tasks, interconnection and information analysis, and selection or judgment for decision-making. For each type, controls are adapted to specific risks, such as misuse, excessive inference of personal information, or biases and lack of robustness of systems that may affect individuals' rights, especially in cases of automated decision-making.
Finally, the guide highlights the role of public bodies, which must integrate data protection at the core of their AI strategy under the leadership of their management, their Chief Privacy Officer (CPO), and their Chief Artificial Intelligence Officer (CAIO). For its part, the PIPC is setting up a permanent assistance service, the "privacy assistance service for AI transformation in the public sector," to provide comprehensive support to the entities concerned, including legal interpretation and access to mechanisms such as the regulatory sandbox.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire