Practice Areas
Our People
News & Resources
Book Consultation

2026-05-15

Following a recent incident in which an outsourced maintenance worker at a school in the Busan area illegally exported 220,000 files from faculty PCs to produce deepfake sexual exploitation material, there are growing calls for companies to comprehensively reexamine their systems for managing external personnel.
This incident is regarded as a case that goes beyond a mere individual crime, exposing the responsibility for supervising outsourcing firms and the loopholes in information protection systems. In particular, concerns are being raised that similar data leak incidents could occur in corporate environments where external personnel frequently come and go, such as IT (information and communications) maintenance and facility management.
According to the legal community on the 14th, Article 26 of the current Personal Information Protection Act stipulates that a company that has entrusted work must manage and supervise the trustee's personal information processing. The explanation is that if outsourced personnel access work PCs or cloud systems and leak information, the entrusting company will also find it difficult to escape liability.
Attorney Jang Ji-woon of Daeryun Law Firm explained, "The courts place great importance on how faithfully the duty of management and supervision over the trustee was carried out," adding, "If a company has not properly established a control system, there is a high possibility that even the trustee's illegal acts will be connected to corporate liability."
Attorney Jang expressed particular concern about the fact that a considerable number of companies conclude that they have fulfilled their legal obligations merely by drafting a non-disclosure agreement (NDA) during the outsourcing contract process. He pointed out, "An NDA can serve as a basis for assigning responsibility after an incident occurs, but it has limitations in proving that a management system was in place beforehand."
He added, "In many cases where the outsourcing firm is small in scale or lacks capital, subsequent claims for damages are realistically difficult," noting that "in the end, there is a high possibility that the company itself will bear the financial and legal burden."
Attorney Jang also emphasized that corporate security systems have recently been shifting from a "trust-based" approach to a "Zero-Trust" model. The explanation is that a structure is needed in which not only external personnel but also internal employees are systematically controlled and all records are retained.
He advised, "Companies should mandatorily establish automatic screen locks for in-house PCs, data loss prevention (DLP) systems, and storage-media control solutions," adding, "A log management system that can objectively verify whether external personnel work alone and their file access records is also necessary."
He further stated, "Rather than a simple damages clause, contracts should include a penalty clause that can be claimed without proving the actual amount of damage," and said, "Making it mandatory for outsourcing firms to subscribe to cyber-security liability insurance is also a realistic way to respond to the risk."
Attorney Jang emphasized, "This incident ultimately shows that information protection is impossible through trust in people alone," stressing that "corporate security must be operated around a control system that is verifiable and leaves records, not around individual ethics."
[Read Full Article]\n\n"Outsourced Worker Data Leak: Companies Also Bear Responsibility"…Busan Deepfake Case Sounds the Alarm (Go to Link) All fields At a glance
1/0
Visit Consultation Booking
If you have legal concerns, consult a Litigation Involving Foreign Nationals specialist at a nearby office.