Fourth, it is necessary to review the terms of service, privacy policies, and security policies of generative AI services in order to understand factors such as data retention periods; whether data entered through prompts is used for AI training; compliance with relevant laws, including personal data protection laws; security measures such as encryption; and differences in security levels across pricing plans. In the case of some overseas generative AI services, compliance with Korea’s Personal Information Protection Act may be insufficient, meaning that users may not receive the protections afforded under domestic law. Levels of personal data protection may also vary depending on the pricing plan. Many providers—particularly when services are offered free of charge, or even when paid services are used under individual user plans— use data shared through prompts for AI training purposes. Some providers offer users an opt-out option, while others do not. Where an AI provider offers an opt-out option (i.e., the choice not to have user data used as training data), that option should be selected. Alternatively, for stronger security, organizations may choose pricing plans under which uploaded data is not used for AI training. Such options, however, may impose additional financial burdens on the organization. In any case, it should be recognized that the security of data stored on AI providers’ servers can never be absolutely guaranteed. For example, as of November 2025, major generative AI services available in the Republic of Korea operate under the following policies. In the case of OpenAI’s ChatGPT Free and the individual paid plan ChatGPT Plus, data entered by users is, by default, used Generative AI Guide for Civil Society

Select target paragraph3