You Can Now Ask a Company to Send Your Personal Data Somewhere Else — Who Qualifies for the Transfer-Request Right, and How to Apply
Diplomas, employment certificates, license copies -- every job season means requesting the same documents all over again and handing them to a new employer. But Article 35-2 of Korea's Personal Information Protection Act, the "transfer-request right," is being rolled out in stages, and it lets you tell an organization holding your data, "send this information directly to that other company," instead of collecting paperwork yourself. It isn't universal yet, so it's worth checking now who's covered and how the process works.

The Paperwork You Used to Chase for Every Job Change Can Now Be Sent Directly
What the Transfer-Request Right Actually Is -- Different from Access or Deletion
You already had the right to view, correct, delete, or suspend processing of your personal data. The transfer-request right goes a step further: it lets you demand that your information be sent directly to another organization or service you designate. Until now this only worked in a few sectors, such as hospital medical records or telecom usage history, but the Personal Information Protection Commission has been pushing a decree revision to extend it to every sector.
Coverage Still Starts With Large Organizations -- the Line Is Roughly $130M in Revenue or 1 Million Users
Not every company owes you this obligation yet. The revised decree applies first to large-scale data processors with average annual revenue above about 180 billion won (roughly $130 million) and at least 1 million data subjects on file (or 50,000, for sensitive or unique-ID information). A neighborhood clinic or a small online shop isn't on the hook right away -- the first targets are large hospitals, telecoms, and retail platforms with millions of users. The rollout is staggered, too: public agencies and third-party transfer providers get a six-month grace period from the announcement date, while large private companies above the revenue threshold get a full year, with phased application starting August 2026.

Healthcare, Telecom, and Retail Came First -- Education and Employment Data Are Next
The sectors that launched first were healthcare, telecom, and retail -- think sending medical records from one hospital to another, or telecom usage history to a rival carrier, to compare insurance premiums or rate plans. On July 6, 2026, the Personal Information Protection Commission pre-announced a decree revision adding academic records, grades, degrees, licenses, and completion certificates (education) and hiring, employment, career, and job-duty records (employment) to the list of transferable data. The idea is to let universities, lifelong-education institutes, and vocational training centers -- along with a person's previous employer -- send verified records straight to the next applicant with a single consent, no paperwork run required. A working group is also looking at extending the right to energy and culture/leisure data, so how job-seekers submit career proof could change again within 2026.
How to Apply -- Download It Yourself, or Route It Through a Licensed Intermediary
There are two paths. One is to download the data yourself from the holding organization's website or app and submit it wherever it's needed. The other runs through a licensed "personal data management institution" designated by the Commission, which can gather information scattered across multiple organizations into one place and manage or transfer it on your behalf. That designation is valid for three years, and applicants must submit a business plan and a data-management plan to qualify.
Who Pays the Fee -- the Receiving Party, Not You
The cost of the transfer itself isn't billed to the data subject, meaning you. The law sets a fee structure based on infrastructure and operating costs and the nature of the information being sent, allowing the sender to charge the party receiving the data. For hospitals or telecoms that have to build new systems, the expense can grow with every request they process, which is part of why going through a licensed intermediary that batches multiple requests is described as more cost-efficient. The actual fee schedule hasn't been finalized industry by industry, so it's worth confirming the specific institution's notice before you apply.

Don't Confuse This With Similarly Named Rules
Around the same time, an amended Personal Information Protection Act took effect on September 11, 2026, raising breach penalties to up to 10% of revenue and expanding the responsibilities of Chief Privacy Officers -- but that's a separate set of provisions covering breach incidents and CPO duties. The transfer-request expansion runs on its own timeline, tied to a separate consultation process for converting legacy data-scraping services into secure transfer methods and to the decree-revision procedure itself. If you've already looked into how to request access or deletion of your data, keep in mind the transfer-request right is a distinct entitlement from that one.
It's also worth separating this from the MyData auto-filing used for interest-rate reduction requests, which is broadly a form of data portability too, but one that took root in banking first under the Credit Information Act. This transfer-request right is grounded in the Personal Information Protection Act instead, and it's a government-wide MyData policy that reaches beyond finance into healthcare, telecom, retail, and soon education and employment. Even where the same CI identifier is involved, this is a separate matter from the policy separating CI from resident registration numbers -- when you get an application notice, check which law it's citing before you get the two confused.
Step by Step
1) Check whether the organization holding the data you want moved (school, previous employer, hospital, etc.) meets the size threshold for mandatory transfer. 2) Decide whether to download it yourself or route it through a licensed data-management institution. 3) Verify your identity on the organization's site or app and submit the transfer request. 4) Since the fee is, in principle, billed to the receiver, confirm in writing whether you'll be charged anything. 5) Education and employment data are still at the pre-announcement stage, so if it isn't available yet, check back with the Personal Information Protection Commission's notices for the 2026 rollout.
This article is based on Articles 35-2, 35-3, and 35-4 of Korea's Personal Information Protection Act and the related decree revision (pre-announced July 6, 2026), along with the Personal Information Protection Commission's published guide to the transfer-request system (confirmed September 2026). Implementation timing and coverage thresholds may still change through decree review and cabinet approval, and this article does not substitute for legal advice. Check with the Personal Information Protection Commission or the relevant organization for your specific situation. Until the system is fully in place, it's safer to keep preparing documents the old way as a backup.
All content is fact-checked under our editorial standards.