HomeTech

보안·프라이버시

If You Ask a Company to Delete Your Personal Data, It Has 10 Days to Answer — Access, Deletion and Suspension Requests, and When They Can Refuse

A shopping site you left years ago starts texting you ads again. A company you used once still has your number. Most people call customer service, say "please delete it," and leave it there. But Korea's Personal Information Protection Act treats this as a right, not a favour, and it puts a 10-day clock on the company that receives the request. There is a prescribed form, and there is a defined place to go when you are refused. It is a procedure only the people who know about it actually use, so here it is.

KD
Kim Do-hyun Tech Editor·2026.08.15·15 min read·128 views

A person working at an office desk in front of a monitor

The rights split into four

The Act gives the data subject, meaning the person the information belongs to, four separate rights of demand. They sound alike enough to be lumped together, but the requirements and the effects are different for each.

  • Access (Article 35) — show me what you hold about me
  • Correction (Article 36) — fix what is wrong
  • Deletion (Article 36) — erase it
  • Suspension of processing (Article 37) — keep it if you must, but stop using it

The sequence matters. If you do not know what they hold, you cannot decide what to ask them to erase. In practice you file for access first, and move to deletion or suspension once the response comes back.

Access requests — the company has 10 days

When a controller receives an access request, it must make the information available for inspection within 10 days. If there is a legitimate reason it cannot meet that window, it may defer after notifying you of the reason, but even then it must let you inspect without delay once the reason has passed.

The scope is broader than a list of stored fields. It includes the purpose of collection and use, the retention and use period, the record of provision to third parties, and the fact and content of any consent you gave. That third-party record is the channel for finding out where your data went. It is the part people actually use when tracing where marketing calls started.

For personal information files held by public institutions, you can file directly with the institution or use the unified channel on the Privacy Portal run by the Personal Information Protection Commission.

Deletion — the law defines when it fails

Deletion also has to be acted on within 10 days, with the outcome sent to you as a written result notice. But there is an exception in the proviso to Article 36(1). Where another statute expressly names that information as something to be collected, you cannot demand its deletion.

That clause is behind most "why won't they delete it" disputes. Contract and withdrawal records, payment records and consumer complaint records under e-commerce law, and transaction records at telecoms and financial firms, are information the law orders kept for a set period. The company could not erase it even if it wanted to. When a firm replies "statutory retention obligation," that is usually a fact rather than a refusal.

Blue document binders lined up neatly on a shelf

Suspension of processing is the card that works when deletion fails

When deletion is blocked by statute, what remains is suspension of processing (Article 37). It says keep the record, but stop using it and stop passing it on. This too must be acted on within 10 days, with the outcome notified.

This is the one that actually stops the marketing texts. The transaction record may have to stay because of the retention duty, but use for marketing and provision to third parties can be suspended. That is why so many people who only ever said "please delete it" got turned down. Change the name of the request and the outcome changes.

There is a prescribed form

A phone call is valid, but writing preserves the clock and the record. The Enforcement Rules of the Act contain a "Request for Access to / Correction, Deletion of / Suspension of Processing of Personal Information" form, and most organisations post the same layout at the bottom of their privacy policy. You tick a box for which right you are exercising, then state the items and the reason.

An agent filing on your behalf needs a power of attorney, and for a child under 14 the legal guardian files. Because proof of receipt matters, use a method that leaves a date, such as email or registered post. The 10-day clock runs from the date of receipt.

If you are refused: objection, then 60-day mediation

A controller cannot simply decline. It must tell you the reason for refusal together with how to object. If the notice is missing either of those, that omission is itself a problem.

Two routes follow. There is a privacy infringement report (dial 118), and there is personal information dispute mediation for recovering loss. The Dispute Mediation Committee must draft a mediation proposal within 60 days of receiving an application, and a controller notified of mediation must respond absent special circumstances. That is the part that changed from the era when a company could simply ignore it. It costs nothing and moves faster than litigation.

If your data leaked: three million won, with a caveat added in December 2025

Once a leak has already happened, a different provision applies. Article 39-2, statutory damages, lets you claim compensation of up to three million won where personal data has been lost, stolen, leaked, forged, altered or damaged, and the controller cannot escape liability unless it proves for itself that it acted without intent or negligence. It exists for individuals who cannot document their actual loss.

The threshold for that provision was recently clarified. In its ruling of 4 December 2025, case 2023Da311184, the Supreme Court held that statutory damages require that there was a leak caused by the controller's intent or negligence, that there was harm of a kind that does not ordinarily arise, and that there is a causal link between the leak and that harm. It added that intervening circumstances, such as a third party's wrongdoing or the user's own carelessness, are weighed as well.

In practical terms it reads like this. Receiving a breach notification does not by itself produce an automatic three million won. What matters far more is documenting what actually happened afterwards, such as an attempted account opening or a specific line of fraudulent contact.

The order to work in

  • 1. File for access first to obtain the stored items, purpose of use and third-party provision record (10 days)
  • 2. Read the response, decide what to erase and what to fix, then file for deletion or correction (10 days)
  • 3. If deletion is refused on statutory retention grounds, refile as suspension of processing (10 days)
  • 4. Use the form in the Enforcement Rules, sent by a method that leaves a date such as email or registered post
  • 5. Check that the refusal notice states the reason and the route to object
  • 6. If it goes nowhere, file a 118 report or apply for dispute mediation (proposal within 60 days)
  • 7. In a breach case, keep notices, texts and attempt records filed by date

To first find out whether your data is already circulating, start with checking whether your information has leaked, and if a phone has gone missing, the first 30 minutes come first. Filter the bait messages that follow a leak with how to spot smishing, and the surest way to protect the account itself is two-factor authentication.

Hands leafing through a printed document in front of a monitor

This article summarises Articles 35 to 37 and Article 39-2 of the Personal Information Protection Act, its Enforcement Decree and the prescribed form in its Enforcement Rules, the Personal Information Protection Commission's Privacy Portal guidance on requests for access and related rights, guidance from the Personal Information Dispute Mediation Committee, and Supreme Court judgment of 4 December 2025, case 2023Da311184 (case digest), as confirmed in August 2026. In any individual case, the scope of a valid request and the legitimacy of a refusal are determined by the controller and by the Dispute Mediation Committee or the courts, and this article is not a substitute for legal advice.

KD
Kim Do-hyun · Tech Editor

All content is fact-checked under our editorial standards.

Back to list