SERVICES

STRATEGY, PRIVACY
AND RISK

STRATEGY, PRIVACY AND RISK service 

Compliance Applicability Assessment for Business in Korea

(Description) We assess whether domestic and international companies operating in Korea are able to comply with domestic laws and regulations requiring cybersecurity, data protection, and other requirements, and provide the results.


(Consulting Period and Process) Based on an understanding of a company's products/services, we identify the laws the company must comply with and the laws required for potential customers to use those products/services. We also identify detailed requirements mandated by the laws and subordinate statutes. Based on the identified regulatory requirements, we assess the company's compliance with domestic and international regulations. We collaborate with our consultants, the company's compliance officer, and domestic engineers to document the applicability of each specific regulation and verify the relevant evidence.

This process can take from one to three months, depending on the applicable laws, the assessment method (e.g., interviews, due diligence), and the implementation period. This consultation does not include follow-up on the assessment results. The consulting process is as follows:

1) Basic consultation based on corporate inquiries (including understanding of products/services available in Korea)

2) Provision of a quotation and standardized contract (SOW) considering the scope of compliance assessment (e.g., Information and Communications Network Act, Cloud Computing Act, Personal Information Protection Act, etc.), assessment method (e.g., interview), and assessment period

3) Contract signing

4) Consulting (including at least three interview sessions)

- Assessment of legal requirements the company must comply with

- Assessment of legal requirements* that potential customers must comply with.

*Identification of laws and regulations by customer business area, including information and communications technology, healthcare, finance, public/education, manufacturing, and personal information processors

5) Provision of a report (in Korean and English, if necessary)

6) Contract termination


(Deliverables)

  • Compliance requirements to be met by the company and the results of the applicability assessment
  • Compliance requirements of customers who will use the company's products/services, and the results of the applicability assessment
  • Results report prepared for corporate leadership.
    This report includes a quantified list of risks and the corresponding regulatory difficulties, penalty levels, required resources, and response periods.

© 2023 Security Awareness Korea, Inc. All Rights Reserved