Home / Privacy Policy
Personal Information Policy
The Korea Information and Communications Technology Association (TTA)
The Korea Information and Communications Technology Association (hereinafter referred to as “TTA”) processes and securely manages personal information in compliance with the Personal Information Protection Act and other applicable laws and regulations in order to safeguard the freedoms and rights of data subjects. Pursuant to Article 30 of the Personal Information Protection Act, TTA has established and published this Personal Information Policy to provide data subjects with information on the procedures and standards governing the processing of personal information and to ensure the prompt and effective resolution of related complaints and grievances.
Article 1. Purposes, Categories, and Retention and Use Periods for Personal Information
① TTA collects and uses personal information only to the extent necessary to provide its services, in accordance with the Personal Information Protection Act.
② With the consent of the data subject, TTA processes the following categories of personal information pursuant to Article 15(1)(1) and Article 22(1)(7) of the Personal Information Protection Act.
| No. | Category | Purpose of Collection | Required Items | Optional Items | Retention and Use Period |
|---|---|---|---|---|---|
| 1 | Information on the person submitting the registration application | Event pre-notification | Country, full name, job title, position, affiliation, email address, attendance information by date | Contact information (cell phone number) | September 7, 2026 – December 31, 2026 |
| 2 | Event participation information | Prize shipments to winners of pre-registration event, social media event, and on-site event | Event participation information, contact information (cell phone number) | Contact information (cell phone number) | September 7, 2026 – December 31, 2026 |
Article 2. Procedures and Methods for the Destruction of Personal Information
① TTA shall destroy personal information without delay when the data subject requests its deletion, the applicable retention period expires, or it is no longer necessary such as when the purpose for which the information was processed has been fulfilled.
② Where personal information is required to be retained pursuant to other laws and regulations even after the retention period consented to by the data subject has expired or the purpose of processing has been fulfilled, such personal information shall be transferred to a separate database (DB) or stored separately in a different location.
③ The procedures and methods for destroying personal information are as follows.
1) Destruction Procedure
TTA shall establish a personal information destruction plan for information subject to destruction and carry out the destruction accordingly. TTA shall identify personal information for which the grounds for destruction have arisen and destroy such information upon obtaining approval from the Chief Personal Information Protection Officer and the departmental privacy protection officers.
2) Methods of Destruction
- Electronic files: Permanently delete electronic files using a method that prevents their recovery.
- Records, printed materials, written documents, and other storage media: Destroy by shredding or incineration.
Article 3. Provision of Personal Information to Third Parties
① TTA processes the personal information of data subjects only within the scope necessary to achieve the purposes for which such information was collected and provides personal information to third parties only in cases permitted under Articles 17 and 18 of the Personal Information Protection Act, including where the data subject has given consent or where disclosure is specifically authorized or required by law. Otherwise, TTA does not provide personal information to third parties.
Article 4. Entrustment of Personal Information Processing
① To facilitate the efficient processing of personal information, TTA entrusts the following personal information processing activities to the contractors listed below.
| Contractor | Entrusted Tasks | Retention Period |
|---|---|---|
| CP Partners Co., Ltd. | Email dispatch, data storage, and system management | December 31, 2026 |
| CelebStars | Email dispatch, data storage, and website management | December 31, 2026 |
| Bizcon | Mobile gift certificate dispatch | December 31, 2026 |
| Ppurio | Email dispatch, Notification talk, and SMS delivery services | December 31, 2026 |
② When entering into an entrustment agreement, TTA specifies in the agreement or other relevant documents the prohibition against processing personal information for purposes other than the performance of the entrusted tasks, security measures, restrictions on sub-entrustment, management and supervision of the contractor, and liability for damages and other matters regarding accountability, in accordance with Article 26 of the Personal Information Protection Act, and supervises the contractor to ensure the secure processing of personal information.
③ Pursuant to Article 26(6) of the Personal Information Protection Act, if a trustee sub-entrusts personal information processing tasks, such sub-entrustment shall be subject to TTA's prior consent, and details regarding the sub-trustees and their delegated tasks are disclosed through this Personal Information Policy.
④ If there is any change in the scope of the entrusted tasks or the trustee, TTA will disclose such change without delay through this Personal Information Policy.
Article 5. Measures to Ensure the Security of Personal Information
① TTA implements the following measures to ensure the security of personal information.
1) Administrative Measures: Establishment and implementation of internal management plans and regular training for employees.
2) Technical Measures: Encryption (HTTPS) for the transmission of personal information; verification of consistency between email addresses and names during pre-registration checks; restrictions on the frequency of inquiry requests; minimization of the information provided in response to inquiries; operation of mechanisms to prevent automated submissions; and separate management of access information for the reception and processing system.
3) Physical Measures: Access control for facilities of cloud service providers operating personal information processing systems; secure storage of documents containing personal information in locations equipped with locks.
Article 6. Installation and Operation of Automatic Personal Information Collection Devices and the Right to Refuse Their Use
① TTA does not use “cookies,” which store information about users on its website and retrieve such information at any time.
Article 7. Rights and Responsibilities of Data Subjects and Legal Representatives and Methods for Exercising Them
① Data subjects may, at any time, request that TTA provide access to, transfer, correct, or delete their personal information, suspend the processing thereof, or withdraw their consent to the processing of their personal information (hereinafter collectively referred to as “exercise of rights”).
② Rights may be exercised by requesting to TTA via a written request, email or fax, or other applicable means in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and TTA shall take the necessary measures without delay upon receipt of such a request.
③ Rights may be exercised through a proxy, including the data subject's legal representative or an authorized agent. In such cases, the proxy shall submit a power of attorney in the form prescribed in Form No. 11 attached to the Notice on Methods for Processing Personal Information.
④ A data subject's right to request access to or suspension of the processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.
⑤ A data subject may not request the deletion of personal information where other laws and regulations expressly require such information to be collected.
⑥ TTA verifies whether the person exercising the rights is the data subject or a duly authorized proxy.
⑦ Data subjects may contact the department designated below to exercise their rights. TTA will respond within 10 days of receiving a request from a data subject to exercise such rights.
| Receiving and Processing Department | Position | Contact Person | Contact Information |
|---|---|---|---|
| Standard Innovation Division | Principal Researcher | Choi Go | 010-5110-1843 · gogochoi@tta.or.kr |
Article 8. Personal Information Protection Officer and Departments Responsible for Personal Information Protection and Complaints
① TTA has overall responsibility for matters relating to the processing of personal information and has designated privacy protection officers for each department as set forth below to handle complaints from data subjects and provide remedies for damages arising from the processing of personal information.
| Category | Department | Position | Name | Contact |
|---|---|---|---|---|
| Personal Information Protection Officer | Management Support Office | Chief | Jeon Deok-jung | 031-724-0020 |
| Departmental Personal Information Protection Officer | Standard Innovation Group | Director | Byeon Jeong-wook | 031-724-0080 |
| Departmental Personal Information Protection Manager | Standard Innovation Group | Principal Researcher | Oh Ji-hoon | 010-5110-6793 · ggrrzz@tta.or.kr |
② Data subjects may contact the relevant Personal Information Protection Department with any inquiries, complaints, or requests for redress concerning the protection of personal information that arise in connection with their use of TTA's services. The entrusted service provider shall respond to and handle such inquiries without delay.
Article 9. Remedies for Violations of the Rights and Interests of Data Subjects
① In the event of an infringement of personal information, data subjects may seek redress by applying for dispute mediation or consultation with the Personal Information Dispute Mediation Committee or the Personal Information Infringement Reporting Center of the Korea Internet & Security Agency (KISA). For other reports or consultations concerning personal information infringements, data subjects may contact the organizations listed below.
| Organization | Website | Contact Information |
|---|---|---|
| Personal Information Dispute Mediation Committee | www.kopico.go.kr | (No area code required) 1833-6972 |
| Personal Information Infringement Reporting Center | privacy.kisa.or.kr | (No area code required) 118 |
| National Police Agency | ecrm.police.go.kr | (No area code required) 182 |
Article 10. Amendments to the Personal Information Policy
This Personal Information Policy shall take effect on September 7, 2026.

