Callstrike
Compliance

Voice phishing simulations in South Korea

Phone numbers in South KoreaProvisioned by Callstrike after approval

South Korea does have a balancing ground, so a voice phishing simulation here never turns on whether your staff agreed to it. It turns on two other things. Acquiring personal data by false or wrongful means is a crime carrying up to three years, which puts the script rather than the paperwork at the centre of the design. And above thirty workers the training plan needs a labour-management council to pass a resolution, not to give an opinion.

Phone numbers

Supplied by Callstrike

Local numbers in South Korea, after a one-time approval.

Running a simulation

Permitted, with a criminal line in the script

Acquiring data by false means carries three years, and binds your supplier too.

Consent

A ground exists, so this is evidence

The balancing ground is harder than Europe's and the regulator anchors it in the contract.

Getting a phone number in South Korea

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Korean onboarding turns on one choice you make when you sign the carrier's own order form, and it is worth making deliberately because it decides which proof of authority you then have to produce. If the form carries your company's corporate seal, a corporation seal verification certificate has to come with it. If your chief executive signs it personally instead, their government-issued identity document is what goes in the same slot. One document either way, but the wrong pairing is the commonest reason a Korean filing comes back.

The rest of the table below is a business registration certificate, obtainable from the National Tax Service, doing double duty as proof of who you are, and proof that your address falls inside the locality covered by the number's own prefix, which will also take a utility bill, a tax notice, a rent receipt or a title deed. A post office box is not accepted. Alongside the uploads the console form asks you to type your business registration number, your website and the authorised representative's name and work email.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in South Korea is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of local addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable.Business registration certificate, Utility bill, Tax notice, Rent receipt, Title deed
Proof of authorityIf the SK Corporate Service Application Form is stamped with the corporate seal, a Corporation Seal Verification Certificate is required. If it is signed by the CEO, the CEO's Government ID must be provided instead.Corporation seal verification certificate, CEO's government issued ID
Proof of business identityThe Business Registration Certificate (사업자등록증) can be obtained from the National Tax Service (NTS) in South KoreaBusiness registration certificate
SK corporate service application formA copy of the order form is located here. Please complete the form and upload it with your bundle application. Must show company's corporate seal otherwise, must show CEO signature if CEO is the applicant.Completed carrier form

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in South Korea?

The position in short, before your counsel reads the detail below.

Yes, and the first thing to correct is an assumption people arrive with. Korea is routinely described as offering no balancing ground, and it does offer one: collection and use are permitted where necessary to achieve the controller's legitimate interests and those interests manifestly override the rights of the data subject, limited to what is substantially related to them and within a reasonable scope. That ground survived the 2023 amendment. It is textually harder than the European provision it resembles, because manifestly overriding is a higher bar than not overridden by, and the regulator then narrows it again in a binding notice to an interest arising from statute or from a contract with the person. For an employer that anchors the whole analysis in the employment contract.

The constraint that decides the design is criminal and has nothing to do with your ground. A person who processes personal data must not acquire it, or obtain agreement to its processing, by false or other wrongful means or methods, and breach carries imprisonment of up to three years or a fine of up to thirty million won. That provision is about the act of acquisition under a false identity, which is precisely what a pretext call is, and a separate article applies it to a processor, so it binds Callstrike directly rather than only through the contract. The line it draws is workable: a call that induces an employee to hand over personal data under a false identity is on the wrong side of it, and a call that measures whether they would have, without capturing anything, is not.

Recording is settled by the statutory definition here rather than by academic consensus, which is unusual in this region. Interception is defined as acquiring the content of a telecommunication without the consent of a party, and the companion limb bites on a conversation between other persons. Someone on the call is neither. What makes this worth an explicit architectural decision rather than a default is the sentence: not up to ten years but not less than one and not more than ten, joined with a suspension of qualifications for up to five, so there is no fine-only outcome on the face of the provision. A silent third leg bridged in for monitoring is the exact shape the prohibition is drafted against.

Two things then differ from Japan and should not be assumed across. Korea has a synthetic-voice disclosure duty in force since 22 January 2026: where an operator uses an AI system to produce output difficult to distinguish from the real thing, the output has to be notified or marked so the user can clearly recognise it was generated by one. An exemption for artificial intelligence used only for the operator's internal business purposes exists, but it lives in the Presidential Decree rather than in the Act, and no regulator decision or guidance applies it to a security test, so treat it as available and untested. And on caller identity the practical answer arrives before the legal one: carriers must block a call whose own user has arbitrarily altered the calling number, and calls from abroad presenting a number on the public-institution and financial list are blocked without delay.

What your company needs to do

8 items, in the order you will need them.

  • Settle whether the programme is an unfavourable change to the rules of employmentSouth Korea-specificThis is the Korean question and it cannot be deferred, because it decides what you have to obtain. Making or changing rules of employment normally requires you to hear the opinion of the majority union or of a majority of the workers; where the change is unfavourable to them, the proviso requires their agreement instead. No Korean source we found answers which side a simulation programme falls on, and breach of the procedure article is criminally penalised, so this is the item to take to Korean counsel before a campaign rather than after one.
  • File the rules of employment with the opinion or the agreement attachedSouth Korea-specificAt ten or more workers the rules go to the Minister of Employment and Labor, and the same applies to a change. The written opinion is attached to the filing, so the paperwork is the proof. The two limbs a programme most plausibly sits in are commendation and sanctions, and the catch-all for other matters applicable to all workers of the workplace.
  • At thirty workers, minute a council resolution rather than a discussionSouth Korea-specificA labour-management council is mandatory at that size and meets quarterly. Most matters go to it for consultation, including recruitment, placement, education and training, and the installation of worker-surveillance equipment by name. But the basic plan for workers' education, training and capability development needs a resolution: a majority of each side present and two-thirds of those present in favour. Failing to implement a resolution without justifiable cause carries up to ten million won.
  • Anchor the balancing ground in the employment contractThe regulator's binding guideline restates the ground as an interest arising from statute or from a contract with the person, so a free-floating assertion that security is in the company's interest is weaker here than reading the Act alone would suggest. Write the assessment against the contract, and do not import a European one.
  • Design so that nothing an employee says is actually harvestedThe three-year offence is built around acquisition, so the exercise has to measure whether someone would have disclosed rather than capture what they disclosed. This is a configuration decision taken before the campaign is built, not a caveat added to a report afterwards.
  • Publish who your processor is, and keep the arrangement documentedSouth Korea-specificRunning the exercise through an outside supplier is an entrustment. The arrangement has to be documented, you have to publish who the processor is so that data subjects can check at any time, and you have to educate and supervise them. The publication is the part companies forget, because it is a standing disclosure rather than a contract clause.
  • Decide how you meet the synthetic-voice dutySouth Korea-specificThe duty is in force and the internal-business-use exit is in the Decree and untested. Decide deliberately whether the campaign relies on that item or whether the voice is marked, and record which. Note the enforcement shape while you are there: the administrative fine attaches to the advance-notification duty, while the marking and synthetic-output duties are enforced through an investigation and a corrective order, with the fine attaching to ignoring the order.
  • Present a Korean number your organisation holds a right of use inThe offence aimed at callers is scoped to deceiving for gain or inflicting harm, so an authorised exercise is outside it, but the second limb catches anyone supplying the number-alteration capability for profit and the ministry's list of justifiable causes is a closed six that covers no private test. In practice the call fails at the network before any of that is argued.

The controls that do the work

How Callstrike is configured, and which provision in South Korea each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

This answers the sharpest provision on the page, and in Korea that provision is criminal. Acquiring personal data, or agreement to its processing, by false or wrongful means carries up to three years or thirty million won, and a separate article applies it to a processor so it reaches your supplier on its own terms. The offence is drafted around the acquisition rather than around the deception, so the call ending the instant an employee begins to give up a credential means the thing the statute punishes never happens. That is a stronger position than arguing about purpose after the event, and it is also the design the regulator's own line between measuring and capturing points to.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Worker education and training is a matter the labour-management council consults on, and the basic plan for it is the one matter that needs a resolution carried by two-thirds of those present. A second voice that breaks character as the call ends, with vishing training in writing the same day, is what turns the exercise from surveillance the council is being asked to tolerate into a training measure it is being asked to adopt, which is a materially easier vote to win and a materially easier minute to write.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Korea has a ground, so agreement is not what carries the processing, and the regulator points employers at statute and the contract instead. What this produces are the two dated artefacts the Korean file is actually assessed on: the record of the opinion or the agreement gathered before the rules of employment were filed, which is the step that is criminally penalised if it is skipped, and the standing publication of who your processor is, kept where data subjects can check it at any time rather than produced when somebody asks.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Korea's synthetic-voice duty is the reason this route reads differently here than anywhere else in the region. Callstrike's vishing simulator delivers the same deepfake voice through a web call the learner opens themselves after working through the module, and a module that says on its own face that the voice is generated needs no reliance on the untested internal-business-use item in the Decree. It also has no Korean calling number to be blocked and no altered number for a carrier to detect. The criminal acquisition rule is not a telephony rule and still governs whatever either route collects.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A balancing ground that exists, and a crime about how you ask

The expectation going in was that Korea would look like its neighbours and offer no balancing ground at all. That is wrong, and the correction matters because it changes which question a Korean programme has to answer.

The Personal Information Protection Act permits collection and use where it is necessary to achieve the legitimate interests of the controller and manifestly overrides the rights of the data subject, limited to what is substantially related to those interests and does not exceed a reasonable scope. That ground survived the 2023 amendment, and it is textually more demanding than the European provision it resembles: manifestly overriding is a higher bar than not overridden by, and the second sentence adds a relevance test and a scope test on top.

The regulator then narrows it further, in a binding notice rather than in the statute. Its standard guideline restates the ground as an interest arising from statute or from a contract with the data subject, or the like. For an employer that anchors the analysis in the employment contract, and a free-floating assertion that security is in the company's interest is weaker here than reading the Act alone would suggest.

The same guideline carries the nearest thing Korean data protection law has to an employment carve-out, and it is worth knowing because it names training expressly. Where a worker and an employer conclude a labour contract, personal data may be collected and used without the worker's agreement for wage payment, education, issuance of certificates and the provision of worker welfare under the Labor Standards Act. The list is closed and tied to that Act, and no regulator source we found applies the education limb to a security exercise. We report it as the nearest express provision, not as your answer.

Now the part that actually constrains the design. It is a criminal prohibition and it is not about your basis at all. A person who processes or has processed personal data must not acquire personal data, or obtain agreement to its processing, by false or other wrongful means or methods. Breach carries imprisonment for up to three years or a fine of up to thirty million won.

That provision is about the act of acquisition under a false identity, which is precisely what a pretext call is. The line it draws is a workable one and it should drive the script: a call that induces an employee to hand over personal data under a false identity is on the wrong side of it, while a call that measures whether they would have, without capturing the data, is not. Design the exercise so that nothing an employee would say is actually harvested.

If the exercise runs through an outside supplier, that is an entrustment. The arrangement has to be documented, the entrusting party has to publish who the processor is so that data subjects can check at any time, and it has to educate and supervise the processor. The prohibition just described is applied to the processor as well, so it binds your supplier on its own terms and not only through the contract.

The definition settles the participant question, and the sentence has a floor

Korea is one of the few jurisdictions in this portal where the participant question is answered by the statutory definition rather than by academic consensus, so it can be stated with a source instead of hedged.

The Protection of Communications Secrets Act prohibits any person, except as provided by that Act, the Criminal Procedure Act or the Military Court Act, from censoring mail, intercepting telecommunications, providing communication confirmation data, or recording or listening to a non-public conversation between other persons. A separate article repeats the conversation limb outside the telecommunications context.

Two phrases do all the work. Interception is defined in the Act itself as acquiring the content of a telecommunication, using an electronic or mechanical device, without the consent of a party. And the conversation limb bites on a conversation between other persons. A recording made by someone who is on the call is not made without the consent of a party, and the conversation is not one between other persons. Both limbs are drafted so that a participant falls outside them, and that is the text rather than an inference from it.

The penalty is the reason to get this right, because it is the strictest in our coverage and the two features that make it strict are exactly the ones a secondary summary drops. It is imprisonment for not less than one year and not more than ten, together with suspension of qualifications for up to five years. Not up to ten years: a statutory minimum of one. And the imprisonment and the suspension are joined rather than alternative, so there is no fine-only outcome on the face of the provision.

The practical consequence is that the recording architecture is worth an explicit decision rather than a default. A recording captured by a party to the call sits outside both limbs. A recording captured by anything that is not a party to the call, including a silent third leg bridged in for monitoring, is the shape the prohibition is drafted against, and the sentence for getting that wrong starts at a year.

Outside the advertising rule, inside an AI rule with an untested exit

There are two Korean rules to clear here and they point in opposite directions, which is why they are worth separating.

The first is the restriction on transmitting advertising information for profit, and every operative paragraph of it is bounded by that purpose. Express prior agreement is required to transmit advertising information for profit by an electronic transmission medium; a separate agreement is required for the window between nine at night and eight the following morning; and a further paragraph prohibits acts concealing the identity of the sender or the source of the advertisement, and acts deceiving the recipient in order to induce a reply.

Those last two are the ones that read most like a description of a pretext call, and they are the reason to state the scoping explicitly rather than leave a reader to work it out. Both are inside an article about advertising information for profit. An authorised internal security exercise advertises nothing and pursues no commercial purpose, so neither reaches it, and nothing in the article turns on whether a person or a machine is speaking.

The second rule does reach a synthetic voice, and Korea is one of the countries in this portal that has such a duty in force rather than in prospect. Under the framework act on artificial intelligence, where an operator uses an AI system to provide output such as virtual sound, images or video that is difficult to distinguish from the real thing, it must notify or mark the output in a manner by which the user can clearly recognise that it was generated by an AI system. That has applied since 22 January 2026, and the Act reaches acts done outside Korea where they affect the domestic market or users.

Then the exemption, which is the part a reader of the Act alone would never find. It lives in the Presidential Decree, and it permits all or part of the transparency duties to be disapplied where the artificial intelligence is used only for the operator's internal business purposes. An employer running an exercise against its own staff is plausibly within that wording. We are not going to tell you that you are covered by it: no regulator decision, ministry guidance or court ruling we could find applies that item to a security test, and the honest position is that the exit exists and is untested.

The enforcement structure is worth one sentence because it is routinely reported wrong. The thirty million won administrative fine attaches to the advance-notification duty in the first paragraph only. The marking duty and the synthetic-output duty are enforced through a fact-finding investigation and a cessation or corrective order, and the fine then attaches to ignoring the order rather than to the original omission.

Two limbs, and the second one is aimed at your supplier

The article usually cited for Korean caller identity is the wrong one. The provision on a carrier telling the recipient who is calling is a different rule about a different thing. The offence sits in the article after it, and its two limbs are scoped so differently that they have to be read separately.

The first limb prohibits falsely displaying the sender's telephone number, including by alteration, when making a call, for the purpose of deceiving another to obtain a pecuniary benefit or of inflicting harm such as abusive language, threats or harassment. That is purpose-scoped, and an authorised, documented internal assurance exercise pursues neither of those purposes.

The second limb is where the commercial answer actually lies, and it does not point at the employer at all. It prohibits any person, for profit, from providing a service capable of falsely displaying the sender's number or from manufacturing, importing, distributing, selling or leasing a device capable of it. A supplier that sells that capability commercially is squarely inside the wording. Both limbs carry up to three years' imprisonment or a fine of up to one hundred million won.

The proviso to the second limb saves a justifiable cause, and the ministry notice that defines justifiable cause turns out to be an exhaustive list of six rather than a standard. Five of them are specific: the state, local government or a public institution acting for public services or its own duties; special numbers; a carrier prefixing an international identification number to a call from abroad; toll-free and representative-number services; and alteration between fixed-line services subscribed under one user's name. None describes a private employer's security test. The sixth is residual, but the applicant is the carrier rather than you, and the application requires the whole network and system diagram, the interconnection and call-processing flow, and the user identity-verification procedure.

There is also an operational answer that arrives before any of that, and it is the one worth planning around. The same notice requires a carrier to block a call where its own user has arbitrarily altered the calling number, and requires carriers to confirm whether their users on a private branch exchange are doing exactly that, building and running a system for the purpose. A separate list of state, public-institution and financial numbers is maintained by the Korea Internet and Security Agency, and calls arriving from abroad presenting a number on it must be blocked without delay.

So the practical Korean position on presenting a number you do not hold is not a question of argument. It fails on the wire before it becomes a legal question, and impersonating a bank or a government line is caught at network level as well. Present a number your own organisation holds a right of use in, and the whole area goes quiet.

One currency note we would rather give than suppress. The national register's record for the telecommunications business act is stamped with a commencement date that has not yet arrived, and overrides to serve the earlier text did not work. The first limb and the penalty carry no 2026 amendment marker, so their wording is the wording in force; the exact current form of the second limb's proviso is one we could not pin down as between its pre- and post-amendment states.

What the country matrix holds for South Korea

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Rules of employment, and a council that resolves rather than advises

Korea asks for more procedure than any other page in this portal, and it asks for it in three tiers rather than one. Which tier you are in depends on headcount and on whether the change is unfavourable, so it is worth working out before drafting anything.

An employer ordinarily using ten or more workers must draw up rules of employment covering an enumerated list of matters and file them with the Minister of Employment and Labor, and the same applies to a change. The two limbs a simulation programme most plausibly sits in are commendation and sanctions, and the catch-all for other matters applicable to all workers of the workplace. We flag that as a reading of the enumerated words rather than as settled authority: no ministry guidance or case law we found places a security exercise in either.

The procedure for making or changing those rules is the tier that catches people out. The employer must hear the opinion of the trade union where one organised by a majority of the workers exists, or of a majority of the workers where none does. But where the rules are changed unfavourably to the workers, the proviso requires their agreement rather than their opinion. That is a genuine agreement requirement, it is a labour-law one rather than a data protection ground, and it is criminally penalised: breach of the procedure article carries a fine of up to five million won, while failing to file at all is an administrative fine of the same ceiling. The written opinion is attached to the filing, so the paperwork is the proof.

Whether introducing a simulation programme is an unfavourable change is the question everybody will want answered, and no Korean source we found answers it. We are not going to answer it either way. It is the single item on this page most worth taking to Korean counsel before a campaign, because the tier it lands in changes what you have to obtain.

The third tier is one no European page in this portal has. At thirty or more workers a labour-management council is mandatory, meeting at least quarterly. Seventeen matters go to it for consultation, and three of those bear here: workers' recruitment, placement and education and training; the installation of worker-surveillance equipment within the workplace, which is on the list by name; and a catch-all for other matters of labour-management cooperation.

But a separate article lifts one matter above consultation altogether. The employer must go through a resolution of the council on the establishment of a basic plan for workers' education and training and capability development. A resolution needs a majority of the worker members and a majority of the employer members present and the affirmative vote of two-thirds of those present; both sides must then faithfully implement what was resolved, and failing to implement a resolution without justifiable cause carries a fine of up to ten million won. Refusing or obstructing the council's establishment carries the same ceiling, though on the wording it is the refusal that is penalised rather than the mere absence.

So the Korean file is: rules of employment covering the programme and filed, with the opinion or the agreement recorded depending on which tier the change falls in; a council consultation record where the workplace has thirty or more workers; and, where the programme forms part of the basic training plan, a minuted council resolution rather than a note of what was discussed.

One statute names simulated drills, and not one of them names phishing

Korea has more mandatory exercise language than most jurisdictions, which makes the negative finding here easy to get wrong in your favour. We counted terms across nine documents rather than relying on impressions, and the answer is that no Korean instrument requires a simulated attack against staff.

The provision closest to this activity was not on anybody's list. The information and communications network act makes establishing and implementing a plan for information-protection education and simulated drills a statutory duty of the chief information security officer, alongside the security plan, periodic auditing and risk identification. It is the only Korean statute that names simulated drills as a standing organisational duty. It does not say phishing, voice phishing or social engineering, and it prescribes no method.

In finance the statute delegates the substance. The electronic financial transactions act requires the due care of a good manager and compliance with standards set by the Financial Services Commission, and contains no training or drill obligation of its own. The supervisory regulation that carries the substance does mandate drills, and it is worth naming which: simulated drills within the business-continuity plan, an annual cut-over drill for firms running a disaster-recovery centre, an annual emergency-response drill whose result is reported to the Commission, and an annual incident-response and recovery drill plan submitted to the designated incident-response body. Its people-facing requirement is separate and is framed as education: the security officer establishes an annual education plan, the chief executive evaluates last year's results, and those results feed the next plan.

For critical information and communications infrastructure the duty is to analyse and evaluate vulnerabilities periodically, and the statute says nothing about training or simulation at all. The ministry standard issued under it comes closest of anything in Korean law, and the gap in it is the finding: it requires simulated hacking against systems connected to the infrastructure, and it requires education and training for people whose effectiveness is measured and fed back, but it never asks for a simulated attack on the people.

The counts make the same point without adjectives. Across the nine instruments read, the terms for social engineering and voice phishing return zero every time. The word for phishing appears only as an incident-report classification, including a telebanking box for recording a fraud that has already happened, and once as a product category in an annex. What is mandatory is education for people and simulated hacking against systems. A vishing exercise is a reasonable way to discharge the education duty and to evidence that it worked; it is not itself required, and a Korean buyer should not be told it is.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in SOUTH KOREA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed through the rules of employment.

Verify or correct each proposition below against primary Korean sources, and tell me which consultation tier we are in:

1. PIPA 제15조제1항제6호 IS a legitimate-interests ground and survived the 2023 amendment, but requires the interest to 명백하게 override, to be 상당한 관련 and within a 합리적인 범위; 표준 개인정보 보호지침 제6조제2항제7호 narrows it to an interest arising 법령 또는 정보주체와의 계약 등에 따른.
2. ⚠⚠ PIPA 제59조제1호 (거짓이나 그 밖의 부정한 수단) is criminal under 제72조제2호 at 3 years or KRW 30m, and 제26조제8항 applies it to the 수탁자. Confirm both, and assess whether a call that captures nothing is outside it.
3. 통신비밀보호법 제2조제7호 defines 감청 as acquisition 당사자의 동의없이 and 제3조제1항/제14조 bite on 공개되지 아니한 타인간의 대화, so a party is outside both. ⚠ Confirm 제16조제1항 is 「1년 이상 10년 이하의 징역」 with a MINIMUM of one year, conjunctive (과) with 자격정지.
4. ⚠ THE CALLER-ID ARTICLE IS 전기통신사업법 제84조의2, NOT 제84조. Limb (1) is purpose-scoped to fraud or harm; limb (2) is scoped to 영리 and lands on the SUPPLIER, with 고시 제2026-48호 제3조's six 정당한 사유 covering no private security test.
5. 근기법 제94조 단서 requires 그 동의 for an UNFAVOURABLE change to the 취업규칙, penalised at 제114조. Is introducing a simulation programme an unfavourable change? This is our single most important question.
6. 근로자참여법 제21조제1호 requires the council's 의결 on 근로자의 교육훈련 및 능력개발 기본계획의 수립 at 30+ workers, distinct from the 제20조 consultation list.
7. ⚠ AI 기본법 제31조제3항 (시행 2026-01-22) imposes a synthetic-output disclosure duty, and the internal-business-use exemption is in 시행령 제23조제4항제2호 rather than in the Act. Is there ANY decision, guidance or ruling applying that item to an internal security test?

⚠ law.go.kr serves 전기통신사업법 at a 시행 2026-11-20 stamp that has not arrived; confirm the current form of 제84조의2제2항's proviso. Flag anything that has changed since September 2026.

Common questions

Does Korea have a legitimate interests ground, or not?
It does, and it survived the 2023 amendment. But the statutory test is harder than the European one it resembles, requiring the interest to manifestly override the worker's rights, and the regulator's binding guideline narrows it to an interest arising from statute or from the employment contract.
What is the criminal risk in a Korean pretext call?
Acquiring personal data by false or wrongful means is an offence carrying up to three years or thirty million won, and it applies to your supplier too. Design the exercise so the call measures whether an employee would have disclosed something, without actually capturing what they say.
Can we display a number we do not own in Korea?
In practice, no. The offence aimed at callers is scoped to fraud or harm, but the second limb catches suppliers of the capability for profit, the ministry list of justifiable causes covers no private test, and carriers must block altered numbers and monitor private branch exchanges for them.
Does the labour-management council just have to be consulted?
Not for the training plan. At thirty or more workers the employer must go through a council resolution on the basic plan for workers' education, training and capability development, carried by two-thirds of those present. Failing to implement a resolution without justifiable cause carries ten million won.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.