or external APIs, the scope of data transmitted shall be reviewed
to ensure that no unnecessary personal data or information are
transferred.
⑦ Work-related accounts and personal accounts shall be used
separately.
Data such as text entered into prompts by users or documents
uploaded to generative AI services are transmitted to and stored on
the servers of AI providers. In this process, various security threats
may arise. Security breaches may occur during data transmission;
AI providers may access stored data without authorization; or data
may be leaked if the provider’s servers are compromised through
hacking. The same security considerations that apply when storing
an organization’s data on cloud services such as Google Drive are
equally relevant in this context.
* The Digital Justice Network (formerly Korean Progressive Network
Jinbonet) published 〈2024 Digital Security Guide〉 and 〈Guide
to Ensuring the Security of Personal Data〉 in 2024. For general
security policies and data protection measures that civil society
organizations should follow, please refer to these guides.
There are additional security risks specific to generative AI.
Data transmitted to an AI provider’s servers may later be used as
training data in subsequent rounds of model retraining. Although
generative AI systems do not store training data verbatim or directly
reproduce it in their outputs, research has shown that certain
74
75