What companies should check first on AI services and personal data protection
Hello, this is Legal Agent.
For companies that provide AI services and those that use them internally, the Act on the Protection of Personal Information (APPI) is unavoidable, since generative AI handles text, audio and images that can include personal data. What matters is not just what the technology can do but whether the company can explain which data it handles, for what purpose, and under whose responsibility.
The APPI is reviewed roughly every three years, and a 2026 amendment bill introducing an administrative fine system, among other changes, is before the Diet as of this writing; practical requirements may change depending on how it proceeds.
Start by mapping the data flow
Before drafting anything, map which screen collects which information, whether it is stored on the company's own servers, sent to an external AI service, kept as logs, or used for training. Writing a privacy policy without this drifts from what actually happens, and where an external generative AI API is used, input data goes to an outside provider, so its terms and log retention need checking. Getting this as a diagram from the development team, rather than a verbal account, avoids errors in the outsourcing/third-party-provision distinction below.
Writing the purpose of use
AI services tend toward vague purposes such as "to provide the service," which do not explain what actually happens. State the real processing instead: summarising text a user enters, drafting reply candidates, or improving features from usage logs. Using personal data for model training carries different risk from ordinary provision, so whether data is used for training, treated as anonymised information, and how that is explained, all need care.
Separating outsourcing, third-party provision and cross-border transfer
AI services often rely on external cloud and generative AI APIs, which under the APPI need to be classified as outsourcing or third-party provision. Where a provider is overseas, cross-border transfer disclosures can become an issue. In a B2B service, a corporate customer may input its own personal data, making the company a processor entrusted by that customer, so obligations around re-entrustment need checking too.
AI output, not just input
Where AI evaluates, classifies or summarises information about a person, that output can disadvantage the individual, and areas such as hiring and credit assessment need human review rather than using an AI judgment as-is. An AI's inference is not always accurate, and storing or acting on inaccurate personal information can create problems beyond privacy compliance.
A privacy policy alone is not enough
Privacy protection for an AI service also requires internal data management, review of external service contracts, and incident response. Enterprise customers often send a security questionnaire, and how well the company can explain data flow and deletion affects how the deal proceeds. LegalAgent treats AI privacy compliance as a matter of service design and contract practice, not just drafting a policy.