information—including personal data—can be memorized within model parameters and extracted under specific conditions. As a result, when retrained AI systems are deployed, there is a risk that an organization’s personal data or confidential information may be exposed through outputs generated for other users. To address these security risks, the following safeguards are necessary. First, personal data must not be entered into prompts. This includes personal identification numbers (such as resident registration numbers, passport numbers, and driver’s license numbers), credit card numbers, passwords, and sensitive personal data (such as biometric data or information about sexual orientation). Under Korea’s Personal Information Protection Act (PIPA), the following categories are defined as sensitive personal data. However, there are types of information—such as location data—that may not be classified as sensitive personal data under the Act but nonetheless pose a high risk of privacy infringement. Moreover, what is considered sensitive personal data may differ across jurisdictions. From the perspective of civil society organizations, it is therefore advisable to adopt a broad and precautionary approach to protecting information that could reasonably be regarded as sensitive. Sensitive personal data under the Personal Information Protection Act (Article 23): Information concerning ideology or beliefs; membership in or withdrawal from labor unions or political parties; political opinions; health; sex Generative AI Guide for Civil Society

Select target paragraph3