The Korean authority recommends corrections on the management of certain obligations related to personal data of robot vacuum cleaners following several investigations

The South Korean authority has concluded its sectoral investigation into the practices of five major robot vacuum manufacturers, highlighting an overall secure management of data but identifying shortcomings in formal compliance, notably regarding user information and data transfers.

Facts and context

The South Korean data protection authority, the Personal Information Protection Commission (PIPC), today published a decision issuing compliance recommendations against five major robot vacuum manufacturers for breaches related to several obligations under the local data protection law.

This case originates from an ex officio sectoral inspection, provided for by Article 63-2 of the South Korean Personal Information Protection Act, aimed at verifying data processing practices (video, sound, mapping) of the latest models marketed by Roborock, Samsung Electronics, LG Electronics, Ecovacs, and Xiaomi.

Reasons for the decision

The investigation revealed that while data collection and transmission were overall well secured, several compliance failures were identified. The authority noted that most manufacturers made voluntary corrections during the investigation but formalized recommendations for the remaining points.

  • Information and consent collection obligation: The authority noted deficiencies in the methods of collecting and using personal data, as well as in the procedures for obtaining user consent, which were not always compliant with legal requirements.
  • Information obligation on data transfers outside the country: It was found that information and notifications related to the transfer of personal data outside the national territory were incomplete or missing for certain services.
  • Obligation to designate a local representative: Some foreign manufacturers had not designated a representative in South Korea, making it more difficult for users and the authority to exercise their prerogatives.
  • Obligation to ensure data security: Although overall security was deemed satisfactory, specific weaknesses in the implementation of certain technical and organizational security measures were identified.

Authority's decision

Consequently, the authority issued compliance recommendations to the companies concerned for points not yet voluntarily corrected during the investigation.

Lessons learned

This decision reminds that:

  • The collection of sensitive data within the home (videos, sounds, room mappings) by connected objects requires particular vigilance regarding the clarity of information provided to users and the validity of consent mechanisms.
  • Manufacturers marketing their equipment internationally must comply with local obligations, notably regarding transparency on cross-border data flows and the designation of a legal representative in the concerned country.
  • Robust technical security alone is not sufficient to guarantee compliance; formal aspects such as informing data subjects, managing consent, and representation obligations are equally essential and scrutinized by authorities.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire