The CEOs and Boards of the Three Telecom Carriers to Directly Oversee Personal Data Protection
- Input
- 2026-09-28 15:30:00
- Updated
- 2026-09-28 15:30:00

Song Kyung-hee Holds First CEO Meeting Since Taking Office, Urges Self-Inspections and Training by Year-End
Song Kyung-hee, chairperson of the PIPC, held a meeting with the CEOs of the three telecom carriers at the Korea Press Center in Jung-gu, Seoul, on the 28th. They discussed measures to prevent recurring personal data breaches and ensure the safe use of data in AI services.
This was the first official meeting Song Kyung-hee had held with corporate CEOs since taking office in October 2025.
In her opening remarks, Song Kyung-hee stressed, "The recent series of personal data breaches is something that both the government and businesses must take very seriously. Personal data protection is not the responsibility of a single department. CEOs must oversee it directly, and it must become a core management priority for which the entire company shares responsibility."
Three Telecom Carriers Issue Joint Declaration for an AI and Digital Society Where People Feel Secure
Before the meeting, the three telecom carriers issued a joint declaration titled 'Joint Declaration for an AI and Digital Society Trusted by the Public.' The declaration calls for setting personal data protection as the top management priority; establishing a responsibility system centered on CEOs and boards; increasing investment in personal data protection and expanding the pool of specialists; ensuring privacy protection, transparency and accountability throughout the development and operation of AI services; and expanding the development of privacy-enhancing technologies (PETs).
The CEOs of the three carriers emphasized, "We will create a digital telecommunications environment in which people feel secure. By working continuously with the government, we will help South Korea lead the way in personal data protection and AI and digital innovation."
The meeting also addressed ways to improve internal management systems to prevent data breaches. The agenda included personal data management across the telecommunications distribution network, which extends to dealers and retail outlets, the training of specialists, and the establishment of a public-private cooperation system to respond to personal data-related issues.
The PIPC explained that, under the revised Personal Information Protection Act that took effect on the 11th, the CEO's ultimate responsibility for personal data protection is now explicitly established and the authority of the chief privacy officer (CPO) has been strengthened. Companies above a certain size must obtain board approval when appointing, replacing or dismissing a CPO and report the decision to the PIPC.
The PIPC noted that personal data management at retail outlets may be vulnerable because of the distribution structure extending from telecom carriers to dealers and retail outlets. It asked the carriers to strengthen management and supervision across the entire distribution network.
The three telecom carriers agreed to cooperate with the government in developing PETs and cultivating specialists in personal data protection and cybersecurity, including by recruiting talent through contract-based academic departments.
Industry Calls for "Standards on the Use of Personal Data in AI Development"
The three telecom carriers asked the government to clarify the standards for legally using personal data during AI development. They called for clearer criteria for applying existing legal grounds for personal data processing, including publicly available information, pseudonymized information and legitimate interests, as well as guidelines tailored to the way AI agents process personal data.
In response, the PIPC said, "We are preparing to improve the relevant system and plan to prepare, by the end of this year, a guide tentatively titled 'Guidelines on the Processing of Personal Information in Agentic Artificial Intelligence.'"
Regarding the special provisions for AI scheduled to take effect next March, participants said a system was needed to allow companies to consult with the authorities before using the provisions. The PIPC responded that it would establish operating measures to support data-based research and continue to gather opinions during the implementation process.
The telecom industry also proposed a public-private communication channel for responding quickly to personal data-related issues.
Song Kyung-hee, chairperson of the PIPC, said, "I hope the joint declaration by the representatives of the three telecom carriers today will lead to meaningful changes and improvements in the field. I ask you to implement it responsibly so that it can further raise the level of personal data protection in the telecommunications sector and serve as an opportunity to restore public trust."
[email protected] Yoon Hong-jip Reporter