South Korea Retains EU Data Adequacy in First Post-Schrems II Periodic Test
The European Commission confirmed on July 23, 2026, that South Korea continues to provide a level of personal data protection equivalent to the EU’s own standards — and in doing so quietly answered a question that privacy practitioners across dozens of countries have been waiting nearly six years to see resolved. For companies moving data between EU markets and Korean partners, the immediate outcome is simple: nothing changes. Personal data can continue to flow freely between the EU and the European Economic Area and South Korea without Standard Contractual Clauses, Binding Corporate Rules, or any other supplementary legal mechanism, as confirmed on the EU Commission’s official adequacy decisions page.
What is less simple — and more important — is what the review represents as a procedural event. This was the first periodic re-examination of a GDPR-era adequacy decision to be completed in the post-Schrems II legal environment, as required under GDPR Article 45(3). Since the Court of Justice of the European Union invalidated the EU-US Privacy Shield in July 2020 in Case C-311/18, compliance teams worldwide have known that adequacy decisions can be struck down instantly and without transition periods. What they did not know — until now — is what a periodic review of a surviving adequacy decision actually looks like in practice. The Korea review gives them the first data point: a “confirm plus recommend” outcome that makes clear that adequacy is no longer binary but iterative, with the Commission retaining a continuing supervisory role rather than simply issuing a permanent stamp.
That structural shift will shape the compliance calculus for every jurisdiction currently holding or seeking an EU adequacy decision — including the UK (renewed December 2025), Japan (which completed its first formal periodic review in 2023 and held follow-on scope-expansion talks most recently in April 2025), and the United States Data Privacy Framework, which faces an active legal challenge from civil liberties organizations. The Korea outcome is now the benchmark they will all be measured against.
What Korea Passed — and Why the Grade Is Not Perfect
The Commission’s review did not simply confirm adequacy and move on. The report published alongside the decision includes targeted recommendations, specifically around two areas: the safeguards governing onward transfers — what happens when EU personal data received by a Korean entity is then sent on to a third country — and the enforcement capacity of Korea’s data protection authority, the Personal Information Protection Commission (PIPC).
These are not trivial footnotes. The onward-transfer gap has been a consistent point of friction in EU adequacy discussions since Schrems II, which turned precisely on the question of what happens to data once it leaves the protected zone. The Commission’s willingness to name it publicly in the review report signals that Korea will be expected to close it before the next review.
The enforcement-capacity recommendation echoes concerns that the EDPB raised in its September 2021 opinion on the original adequacy draft, when the Board called for attentive monitoring of Korea’s supplementary rules in practice and asked the Commission to clarify substantive requirements — including the burden of proof — for EU individuals seeking redress through the PIPC. The fact that these two threads are still unresolved four-plus years after the original decision is precisely what makes the “confirm plus recommend” model useful: it documents the gaps without withdrawing the finding.
How Korea’s 2023 PIPA Overhaul Drove Convergence
A key driver of the Commission’s positive finding was South Korea’s own domestic legislative momentum in the years since the original 2021 decision. South Korea’s National Assembly passed a major overhaul of the Personal Information Protection Act (PIPA) on February 27, 2023, which entered into force on September 15, 2023. The amendments introduced rights that brought Korean law considerably closer to the GDPR.
The most structurally significant change was the introduction of two GDPR-equivalent data subject rights. First, the right to data portability — the ability to receive personal data held by an organization in a transferable format — became enforceable as of March 13, 2025. Second, the right to opt out of automated decision-making — covering decisions made by fully automated systems, including artificial intelligence systems, that substantially affect a data subject’s rights or obligations — took effect on September 15, 2024.
On breach notification, the 2023 amendment eliminated a two-track system that had previously required online service providers to report breaches within 24 hours and offline controllers within five days. All personal information controllers are now subject to a uniform 72-hour notification requirement — mirroring GDPR Article 33’s own 72-hour clock almost precisely. The amendment also streamlined dispute mediation, harmonized compliance standards for online and offline data processing, and replaced criminal sanctions with administrative fines — a shift that the Commission has explicitly welcomed as consistent with how enforcement operates under the GDPR.
A Relationship That Turned Fully Mutual in September 2025
The legal architecture connecting the EU and Korea is now bilateral in a way it was not at the original 2021 decision. In March 2023, the amended PIPA introduced a new mechanism called “equivalency recognition” — essentially the Korean domestic equivalent of the EU’s own adequacy decision system, introduced through the Kim & Chang-analyzed PIPA reforms. Under Article 28-8(1)(5) of the PIPA, the PIPC can formally recognize that a foreign jurisdiction’s data protection framework is substantially equivalent to Korea’s own, permitting data to flow to that jurisdiction without the usual consent-based transfer requirements.
On September 16, 2025, the PIPC became the first national data protection authority to use this mechanism, formally recognizing the European Union as an equivalent-standard jurisdiction. The recognition covers all 27 EU member states plus Norway, Liechtenstein, and Iceland. Together with the 2021 Commission adequacy decision, this created what a joint EU Commission and PIPC statement called “a comprehensive area of free and safe personal data flows” covering both the private and public sectors in both directions.
There are limits to the symmetry. The PIPC’s equivalency recognition does not extend to resident registration numbers or personal credit information — two categories of particularly sensitive data that remain subject to Korea’s more restrictive domestic transfer rules. And the PIPC has scheduled the first review of its own recognition decision for before December 15, 2028. How that review proceeds will tell the same story from the other direction: whether Korea’s “confirm plus recommend” model extends to its own assessments of foreign frameworks.
Where This Sits in the EU-Korea Digital Architecture
The adequacy arrangement does not exist in isolation. Mutual data flows between the EU and Korea support over 500 million people and underpin a trade relationship valued at more than €150 billion (approximately $171 billion USD) per year, according to the Commission. That relationship already had a legal foundation in the EU-Korea Free Trade Agreement, which has been in force since 2011.
The newest layer is the EU-Korea Digital Trade Agreement, signed on June 10, 2026, at the EU-Korea Summit in Brussels. The DTA establishes binding rules for digital commerce, recognizes electronic contracts and signatures, prohibits the mandatory transfer of source code to governments as a market access condition, and explicitly facilitates cross-border data flows — all while preserving each side’s regulatory space for data protection and privacy. In 2023, more than one-third of the total EU-Korea trade in services — approximately €11 billion (approximately $12.5 billion USD) — was digitally delivered. The DTA, signed but not yet ratified, still requires consent from the European Parliament before it enters into force.
The adequacy confirmation, the mutual equivalency recognition, and the Digital Trade Agreement together form a layered framework: adequacy provides the legal permission for data to move without additional instruments, the mutual equivalency provides the Korean-law mechanism for the same permission operating in reverse, and the DTA provides the commercial framework governing what that movement enables and what it cannot be forced to include.
What This Review Sets in Motion for Every Adequacy Decision That Follows
The geopolitical significance of this review extends well beyond the EU-Korea bilateral relationship. The GDPR Article 45(3) requirement for periodic reviews — at least every four years — had never been applied to a post-Schrems II adequacy decision before July 23, 2026. That meant the concept of a periodic review was, until now, entirely theoretical as a governance event: it was a rule with no executed instances and therefore no established meaning.
The Korea review gave it content. The “confirm plus recommend” structure — maintain the finding, publish specific recommendations, create accountability for the next review cycle — is now the operational model. It resolves a question that had been open since 2020: can an adequacy decision survive scrutiny in the post-Schrems II era? The answer, for Korea, is yes, with conditions.
That precedent travels directly to the reviews now in progress or approaching for the UK, Japan, and the EU-US Data Privacy Framework. None of those situations is identical to Korea’s. The UK has a sunset-clause adequacy renewal that already required a formal European Parliament process. Japan completed its first formal periodic review in 2023 and has been in ongoing talks on expanding its adequacy decision’s scope, with the Commission and Japan’s Personal Information Protection Commission meeting again in April 2025. The US DPF faces a pending legal challenge that the Korean precedent does not neutralize — the challenge turns on surveillance capabilities that the DPF’s critics argue remain disproportionate under EU law.
But for jurisdictions that have invested in genuine GDPR alignment — legislating comparable rights, establishing independent enforcement, and building reciprocal recognition mechanisms — the Korea outcome is the most instructive signal the Commission has sent since Schrems II itself.
Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, described the outcome in terms of convergence rather than compliance. In the Commission’s announcement, she said the review showed the two data protection frameworks are now closer than ever.
Commissioner Michael McGrath, responsible for Democracy, Justice, the Rule of Law, and Consumer Protection, framed it in terms of the relationship between privacy and commerce. He stated in the Commission’s announcement that trusted data flows are the lifeblood of the digital economy, and that strong data protection and open international trade are not competing objectives but reinforce one another.
The recommendations the Commission attached to that confirmation — on onward-transfer safeguards, on enforcement capacity — are the part of that statement that compliance practitioners should mark in their calendars. Adequacy is now something a jurisdiction maintains, not something it is granted. The Korea review made that concrete for the first time.
Frequently Asked Questions
Does this decision change anything for companies currently transferring data between the EU and South Korea?
No immediate change is required. The Commission’s review confirmed that adequacy status continues, meaning personal data can still move freely between the EU/EEA and South Korea without Standard Contractual Clauses or Binding Corporate Rules. However, compliance officers should note the Commission’s recommendations regarding onward-transfer safeguards — specifically, rules governing what Korean recipients can do with EU data if they need to send it on to a third country. Those gaps are flagged for resolution before the next review cycle, and organizations with complex data chains through Korea should monitor whether the PIPC introduces updated rules in response.
Why does this review matter beyond the EU-Korea relationship?
This was the first completed periodic review of a GDPR-era adequacy decision in the post-Schrems II environment — meaning it is the first empirical example of what GDPR Article 45(3) looks like in practice. The “confirm plus recommend” structure the Commission used establishes a governance template. Every other jurisdiction holding EU adequacy — the UK, Japan, the United States under the Data Privacy Framework — is now on notice that periodic reviews are genuine assessments that can produce public recommendations, not rubber stamps. For jurisdictions that have invested in GDPR alignment (as Korea has, through its 2023 PIPA reforms), the Korea outcome is the most favorable signal the Commission has issued since 2020.
What exactly did Korea’s 2023 PIPA amendment change, and why does it matter for EU data protection?
The 2023 amendment, which took effect September 15, 2023, introduced two GDPR-equivalent data subject rights that the original 2021 adequacy decision had predated: the right to data portability (effective March 13, 2025) and the right to opt out of automated decision-making by AI systems (effective September 15, 2024). It also unified Korea’s breach notification timeline at 72 hours, matching GDPR Article 33 almost precisely, and replaced criminal sanctions with administrative fines. These changes moved the PIPA substantially closer to the GDPR’s substantive standards — which is the primary reason the Commission’s review found that the two frameworks have converged further since 2021.
Can South Korean companies now send data to the EU without special consent, the way EU companies can send data to Korea?
Yes, as of September 16, 2025. That is when the PIPC’s formal recognition of the EU’s data protection framework as equivalent under Korea’s own PIPA took effect. Before that date, the adequacy arrangement operated in only one direction — EU to Korea. The mutual equivalency recognition means Korean companies and public authorities can now transfer personal data to EU-based entities without the standard consent-based transfer requirements that would otherwise apply under the PIPA. One limitation: the recognition does not cover resident registration numbers or personal credit information, which remain subject to Korea’s stricter domestic transfer rules regardless of the mutual arrangement.