When using a generative AI service, it may appear that you simply type a question or upload materials and receive an answer.
In reality, however, the information you enter is transmitted to the service provider's systems, where it may be stored as chat history or system logs for a certain period or potentially used for service improvement, depending on the provider.
Some AI services allow users to disable the use of input data for AI training, delete chat history, or manage data retention periods.
Before entering work-related materials into a generative AI service, you should confirm the following:
- Whether your input data may be used for AI training
- How long conversations and uploaded files are retained
- Whether chat history and uploaded data can be deleted
- In which country the data is processed and stored
- What access permissions are granted to external applications or internal systems
The Personal Information Protection Commission (PIPC) of Korea also recommends checking whether user inputs are used for AI training, reviewing chat history storage and deletion settings, and granting only the minimum necessary permissions when connecting external services.
Simply deleting a client's name or contact information from a contract does not necessarily mean that the document no longer contains personal information.
Under Korean privacy law, personal information includes not only information that directly identifies an individual but also information that can identify a specific individual when combined with other available information.
For example, even if names are removed, an individual may still be identifiable if the document contains:
- A company name together with a specific job title
- The contract date and transaction amount
- Department information and performance evaluations
- Detailed consultation history and family relationships
- Case numbers and the location of a dispute
Accordingly, rather than removing only names, businesses should eliminate unnecessary identifying information wherever possible and replace actual names of individuals and companies with fictitious or placeholder names.
Entering client information into a generative AI service does not automatically constitute a violation of the Personal Information Protection Act (PIPA).
However, personal information collected by a company may only be used within the scope of the original purpose of collection and the applicable legal basis for processing.
Another important question is whether the AI service processes the information on behalf of the company (data processing/outsourcing) or whether the AI provider uses the information for its own purposes (third-party provision).
It is also necessary to determine whether personal information is transferred to servers located outside Korea, as the PIPA establishes different legal requirements for:
- Collection and use of personal information
- Provision to third parties
- Entrusted processing
- Cross-border transfer of personal information
In other words, the mere fact that information was entered into an AI service does not determine which legal rules apply. The applicable legal framework depends on the contractual arrangement and the actual data processing structure.
Contracts and client consultation materials often contain far more than personal information.
They may also include confidential business information such as pricing terms, commercial strategies, technical information, and litigation or dispute response strategies.
Entering such materials into an external generative AI service may create risks including:
- Breach of contractual confidentiality obligations
- Disclosure of trade secrets or confidential business information
- Violation of confidentiality agreements with clients
- Breach of internal corporate policies
- External transmission of materials prepared for litigation or regulatory investigations
Accordingly, a company's generative AI policy should address not only personal information but also trade secrets and other confidential business materials.
If employees are left to decide independently how to use generative AI, companies may have little visibility into what information has been entered into external AI services.
Rather than simply instructing employees not to enter personal information, organizations should establish practical internal policies.
For example, a company may define:
- Approved generative AI services and authorized accounts
- Categories of prohibited personal information and confidential business information
- Approval procedures for high-risk documents such as contracts and HR materials
- Standards for removing or replacing identifying information, including names, contact details, and company names
- Required settings regarding AI training and chat history retention
- Internal reporting procedures for accidental disclosure or erroneous input
Instead of uploading an entire contract, employees should submit only the relevant provisions after replacing actual client information with fictional or anonymized information whenever possible.
Generative AI can significantly improve efficiency in contract review and document drafting.
However, businesses should not use AI services without first understanding where client information and internal business data are stored and how they may be processed or used.
Companies should establish practical governance frameworks tailored to their operations, including approved AI services, prohibited categories of information, anonymization standards, and incident response procedures.
The Corporate Practice Team at Decent Law Firm provides comprehensive legal reviews of companies' generative AI usage, including the structure of personal information processing, AI service terms of use, cross-border data transfers, and internal AI governance policies.

 1.png)

