Fourth, it is necessary to review the terms of service, privacy
policies, and security policies of generative AI services in order to
understand factors such as data retention periods; whether data
entered through prompts is used for AI training; compliance with
relevant laws, including personal data protection laws; security
measures such as encryption; and differences in security levels
across pricing plans. In the case of some overseas generative AI
services, compliance with Korea’s Personal Information Protection
Act may be insufficient, meaning that users may not receive the
protections afforded under domestic law. Levels of personal data
protection may also vary depending on the pricing plan. Many
providers—particularly when services are offered free of charge,
or even when paid services are used under individual user plans—
use data shared through prompts for AI training purposes. Some
providers offer users an opt-out option, while others do not.
Where an AI provider offers an opt-out option (i.e., the choice not
to have user data used as training data), that option should be
selected. Alternatively, for stronger security, organizations may
choose pricing plans under which uploaded data is not used for AI
training. Such options, however, may impose additional financial
burdens on the organization. In any case, it should be recognized
that the security of data stored on AI providers’ servers can never be
absolutely guaranteed.
For example, as of November 2025, major generative AI services
available in the Republic of Korea operate under the following
policies. In the case of OpenAI’s ChatGPT Free and the individual
paid plan ChatGPT Plus, data entered by users is, by default, used
Generative AI Guide for Civil Society