Home / Privacy Policy

Personal Information Policy

The Korea Information and Communications Technology Association (TTA)

The Korea Information and Communications Technology Association (hereinafter referred to as “TTA”) processes and securely manages personal information in compliance with the Personal Information Protection Act and other applicable laws and regulations in order to safeguard the freedoms and rights of data subjects. Pursuant to Article 30 of the Personal Information Protection Act, TTA has established and published this Personal Information Policy to provide data subjects with information on the procedures and standards governing the processing of personal information and to ensure the prompt and effective resolution of related complaints and grievances.

Article 1. Purposes, Categories, and Retention and Use Periods for Personal Information

① TTA collects and uses personal information only to the extent necessary to provide its services, in accordance with the Personal Information Protection Act.

② With the consent of the data subject, TTA processes the following categories of personal information pursuant to Article 15(1)(1) and Article 22(1)(7) of the Personal Information Protection Act.

Personal information processed — number, category, purpose of collection, required items, optional items, retention and use period
No.CategoryPurpose of CollectionRequired ItemsOptional ItemsRetention and Use Period
1Information on the person submitting the registration applicationEvent pre-notificationCountry, full name, job title, position, affiliation, email address, attendance information by dateContact information (cell phone number)September 7, 2026 – December 31, 2026
2Event participation informationPrize shipments to winners of pre-registration event, social media event, and on-site eventEvent participation information, contact information (cell phone number)Contact information (cell phone number)September 7, 2026 – December 31, 2026

Article 2. Procedures and Methods for the Destruction of Personal Information

① TTA shall destroy personal information without delay when the data subject requests its deletion, the applicable retention period expires, or it is no longer necessary such as when the purpose for which the information was processed has been fulfilled.

② Where personal information is required to be retained pursuant to other laws and regulations even after the retention period consented to by the data subject has expired or the purpose of processing has been fulfilled, such personal information shall be transferred to a separate database (DB) or stored separately in a different location.

③ The procedures and methods for destroying personal information are as follows.

1) Destruction Procedure

TTA shall establish a personal information destruction plan for information subject to destruction and carry out the destruction accordingly. TTA shall identify personal information for which the grounds for destruction have arisen and destroy such information upon obtaining approval from the Chief Personal Information Protection Officer and the departmental privacy protection officers.

2) Methods of Destruction

  • Electronic files: Permanently delete electronic files using a method that prevents their recovery.
  • Records, printed materials, written documents, and other storage media: Destroy by shredding or incineration.

Article 3. Provision of Personal Information to Third Parties

① TTA processes the personal information of data subjects only within the scope necessary to achieve the purposes for which such information was collected and provides personal information to third parties only in cases permitted under Articles 17 and 18 of the Personal Information Protection Act, including where the data subject has given consent or where disclosure is specifically authorized or required by law. Otherwise, TTA does not provide personal information to third parties.

Article 4. Entrustment of Personal Information Processing

① To facilitate the efficient processing of personal information, TTA entrusts the following personal information processing activities to the contractors listed below.

Entrustment of personal information processing — contractor, entrusted tasks, retention period
ContractorEntrusted TasksRetention Period
CP Partners Co., Ltd.Email dispatch, data storage, and system managementDecember 31, 2026
CelebStarsEmail dispatch, data storage, and website managementDecember 31, 2026
BizconMobile gift certificate dispatchDecember 31, 2026
PpurioEmail dispatch, Notification talk, and SMS delivery servicesDecember 31, 2026

② When entering into an entrustment agreement, TTA specifies in the agreement or other relevant documents the prohibition against processing personal information for purposes other than the performance of the entrusted tasks, security measures, restrictions on sub-entrustment, management and supervision of the contractor, and liability for damages and other matters regarding accountability, in accordance with Article 26 of the Personal Information Protection Act, and supervises the contractor to ensure the secure processing of personal information.

③ Pursuant to Article 26(6) of the Personal Information Protection Act, if a trustee sub-entrusts personal information processing tasks, such sub-entrustment shall be subject to TTA's prior consent, and details regarding the sub-trustees and their delegated tasks are disclosed through this Personal Information Policy.

④ If there is any change in the scope of the entrusted tasks or the trustee, TTA will disclose such change without delay through this Personal Information Policy.

Article 5. Measures to Ensure the Security of Personal Information

① TTA implements the following measures to ensure the security of personal information.

1) Administrative Measures: Establishment and implementation of internal management plans and regular training for employees.

2) Technical Measures: Encryption (HTTPS) for the transmission of personal information; verification of consistency between email addresses and names during pre-registration checks; restrictions on the frequency of inquiry requests; minimization of the information provided in response to inquiries; operation of mechanisms to prevent automated submissions; and separate management of access information for the reception and processing system.

3) Physical Measures: Access control for facilities of cloud service providers operating personal information processing systems; secure storage of documents containing personal information in locations equipped with locks.

Article 6. Installation and Operation of Automatic Personal Information Collection Devices and the Right to Refuse Their Use

① TTA does not use “cookies,” which store information about users on its website and retrieve such information at any time.

Article 7. Rights and Responsibilities of Data Subjects and Legal Representatives and Methods for Exercising Them

① Data subjects may, at any time, request that TTA provide access to, transfer, correct, or delete their personal information, suspend the processing thereof, or withdraw their consent to the processing of their personal information (hereinafter collectively referred to as “exercise of rights”).

② Rights may be exercised by requesting to TTA via a written request, email or fax, or other applicable means in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and TTA shall take the necessary measures without delay upon receipt of such a request.

③ Rights may be exercised through a proxy, including the data subject's legal representative or an authorized agent. In such cases, the proxy shall submit a power of attorney in the form prescribed in Form No. 11 attached to the Notice on Methods for Processing Personal Information.

④ A data subject's right to request access to or suspension of the processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.

⑤ A data subject may not request the deletion of personal information where other laws and regulations expressly require such information to be collected.

⑥ TTA verifies whether the person exercising the rights is the data subject or a duly authorized proxy.

⑦ Data subjects may contact the department designated below to exercise their rights. TTA will respond within 10 days of receiving a request from a data subject to exercise such rights.

Department receiving and processing requests to exercise rights
Receiving and Processing DepartmentPositionContact PersonContact Information
Standard Innovation DivisionPrincipal ResearcherChoi Go010-5110-1843 · gogochoi@tta.or.kr

Article 8. Personal Information Protection Officer and Departments Responsible for Personal Information Protection and Complaints

① TTA has overall responsibility for matters relating to the processing of personal information and has designated privacy protection officers for each department as set forth below to handle complaints from data subjects and provide remedies for damages arising from the processing of personal information.

Personal information protection officers and managers
CategoryDepartmentPositionNameContact
Personal Information Protection OfficerManagement Support OfficeChiefJeon Deok-jung031-724-0020
Departmental Personal Information Protection OfficerStandard Innovation GroupDirectorByeon Jeong-wook031-724-0080
Departmental Personal Information Protection ManagerStandard Innovation GroupPrincipal ResearcherOh Ji-hoon010-5110-6793 · ggrrzz@tta.or.kr

② Data subjects may contact the relevant Personal Information Protection Department with any inquiries, complaints, or requests for redress concerning the protection of personal information that arise in connection with their use of TTA's services. The entrusted service provider shall respond to and handle such inquiries without delay.

Article 9. Remedies for Violations of the Rights and Interests of Data Subjects

① In the event of an infringement of personal information, data subjects may seek redress by applying for dispute mediation or consultation with the Personal Information Dispute Mediation Committee or the Personal Information Infringement Reporting Center of the Korea Internet & Security Agency (KISA). For other reports or consultations concerning personal information infringements, data subjects may contact the organizations listed below.

Organizations for remedy of infringement — organization, website, contact information
OrganizationWebsiteContact Information
Personal Information Dispute Mediation Committeewww.kopico.go.kr(No area code required) 1833-6972
Personal Information Infringement Reporting Centerprivacy.kisa.or.kr(No area code required) 118
National Police Agencyecrm.police.go.kr(No area code required) 182

Article 10. Amendments to the Personal Information Policy

This Personal Information Policy shall take effect on September 7, 2026.