Medical data privacy by country
Medical data privacy in South Korea.
Korea's law sits close to Europe's, which is why the EU treats it as adequate. It governs the copy the clinic holds. Ask how long the clinic keeps records and where its systems are, and send only what the consultation needs.
General information, checked against the law on 23 September 2026. For your own case, ask a lawyer in South Korea.
What the law says
How South Korea treats your health data.
- The law
- Personal Information Protection Act (PIPA)[S84]
- The regulator
- Personal Information Protection Commission (PIPC)[S84]
- Health data
- Health information is sensitive information under Article 23. A clinic needs your separate consent to process it, given apart from any other consent you sign.[S84]
- Sending it abroad
- Article 28-8 lets personal information leave Korea on five bases: your separate consent, a law or treaty, outsourcing or storage needed for a contract with you, a certification recognised by the PIPC, or a PIPC adequacy decision.[S84]
- EU adequacy
- Yes. The EU adopted an adequacy decision for Korea in December 2021 and confirmed it in July 2026, so data can flow from the EU to Korea as it would within Europe.[S85][S77]
- If there is a breach
- Within 72 hours to the people affected, and to the PIPC or the Korea Internet and Security Agency for serious incidents, such as those involving sensitive data or 1,000 people or more.[S87]
Questions
South Korea: common questions.
Is it safe to email medical records to a clinic in South Korea?
Email is protected between mail servers only when both providers support TLS, and it stays readable on each server afterwards. Once your records reach a clinic in South Korea, local law applies: health information is sensitive information under Article 23. A clinic needs your separate consent to process it, given apart from any other consent you sign. For a full history, use a channel where you hold the key, such as a link that expires by itself.
How does South Korea protect health data?
Health information is sensitive information under Article 23. A clinic needs your separate consent to process it, given apart from any other consent you sign. Breaches must be reported within 72 hours to the people affected, and to the PIPC or the Korea Internet and Security Agency for serious incidents, such as those involving sensitive data or 1,000 people or more. The regulator is the Personal Information Protection Commission (PIPC).
Can a clinic in South Korea send my medical records abroad?
Article 28-8 lets personal information leave Korea on five bases: your separate consent, a law or treaty, outsourcing or storage needed for a contract with you, a certification recognised by the PIPC, or a PIPC adequacy decision.
Keep reading
More on South Korea, and elsewhere.
- Our South Korea report: care, clinics and indicative prices
- Is it safe to send your medical records to a clinic abroad?
- Medical data privacy in Turkey
- Medical data privacy in Thailand
- Medical data privacy in China
- Medical data privacy in Vietnam
- Medical data privacy in Indonesia
- Medical data privacy in United Kingdom
- Medical data privacy in Switzerland
- Medical data privacy in France
- Medical data privacy in Germany
- Medical data privacy in Spain
- Medical data privacy in Hungary
Sources are numbered in the text and listed in full in the reference list.