South Korea's Personal Information Protection Commission (PIPC) used the July 3, 2026 Economic Ministers' Meeting to unveil its Third Basic Plan for Personal Information Protection, a statutory three-year blueprint required under the Personal Information Protection Act that will govern data policy from 2027 through 2029. The plan's headline move: personal data that was lawfully collected can now be used in its original, non-anonymized form to train AI systems, provided the use clears PIPC review and a risk assessment, rather than being masked or pseudonymized first.
From Uniform Masking to Case-by-Case Review
Until now, Korean privacy practice has leaned on anonymization and pseudonymization as prerequisites for reusing personal data, mirroring the EU's technique-first approach to lawful processing. The new plan abandons that uniformity. Video, voice, and image data collected under an existing lawful basis can move into AI training pipelines in raw form once the PIPC signs off, with implementation tied to a broader shift the commission is calling "risk-proportionate" regulation — protection calibrated to how sensitive the data and the use case actually are, not a flat rule applied to every dataset regardless of context. A new AI Transformation (AX) Safety Support Center is meant to walk companies through that review process and cut the legal uncertainty that PIPC officials say has been slowing AI development in Korea. Telecommunications, education, and employment are flagged as higher-risk sectors for tighter joint oversight between the PIPC and relevant ministries, while the commission expands cross-border transfer cooperation with the UK, Japan, and the US on top of its existing EU adequacy status. PIPC Chair Sung Kyung-hee framed the plan as redesigning "the personal data rulebook to fit the AI environment," according to ZDNet Korea's coverage of the July 3 briefing.
The Case Against Loosening the Rule
The strongest objection deserves to be stated plainly: anonymization exists because raw video, voice, and biometric data are unusually hard to de-identify and unusually revealing when they leak. A face in a training clip can reveal health status, political activity, or location history that a subject never consented to expose in that form, and Korea is legislating this shift months after a plan document that itself cites recurring large-scale personal data breaches as part of its justification. A regime that lets companies skip anonymization — even with commission sign-off — puts a lot of weight on the PIPC's review capacity holding up at scale, especially once every AI-adjacent firm in the country is routing raw-data requests through the same commission. If the AX Safety Support Center becomes a rubber stamp under industry pressure to keep training pipelines moving, the exemption could function as a de facto blanket permission with a paperwork step attached.
Why the Trade Is Still Worth Making
That risk is real, but the status quo it replaces was not actually protecting people better — it was just protecting them uniformly badly. Blanket anonymization mandates degrade exactly the signal AI training needs most: facial expressions, vocal inflection, and movement patterns that make computer vision and speech models useful are often the first casualties of masking. That's not a hypothetical trade-off; it's the specific complaint industry has made to regulators for years, and it's why the PIPC had already started down this road with revised Pseudonymized Information Processing Guidelines on March 31, 2026, which the IAPP has described as turning pseudonymization into "a gateway into a legal regime that permits certain types of processing without consent" rather than a safeguard layered on top of it. The Third Basic Plan extends that logic one step further, from pseudonymized to raw data, but keeps the gate: PIPC review plus a documented risk assessment, not an open door. A rule that says "low risk, cleared; high risk, controlled" is a better instrument than a rule that treats a hospital's patient-monitoring footage and a retailer's checkout-camera feed identically because both technically contain faces. The plan pairs the exemption with real teeth elsewhere — mandatory data lineage and provenance tracking, elevated Chief Privacy Officer accountability, and harsher sanctions for negligent handling — which is the correct sequencing: loosen the input rule only alongside tighter downstream accountability, not instead of it.
What to Watch
The test of this plan won't be the text released on July 3; it will be whether the PIPC's review process actually discriminates between low- and high-risk raw-data requests once approval volumes climb, and whether the AX Safety Support Center publishes enough about its decisions for outside scrutiny to be possible at all. A risk-proportionate system that never says no isn't proportionate — it's just slower blanket permission. Korea's bet is that a functioning commission gate beats a mandatory-anonymization rule that AI developers were already routing around. Getting that bet right depends entirely on the PIPC building review capacity as fast as it built the exemption.