Case Studies
[IT Litigation] 7 Contract Conditions to Reduce Disputes When Drafting Software Service Contracts
Software is utilized for various purposes, including internal system construction, customer service automation, and development of data analysis tools. Consequently, the demand for software service contracts outsourced to external development companies has rapidly increased. However, despite the frequent execution of these contracts, disputes often arise. This is because, when contract conditions are unclear or vaguely stated, various issues such as development delays, defects, and intellectual property rights attribution can lead to disputes. Unlike typical product sales, software service contracts vary in development scope and deliverables for each project, and there is significant uncertainty in the development process. Therefore, to prevent disputes and ensure the successful completion of projects, it is essential to clearly define contract conditions. In particular, when development schedules are delayed, responsibility, compensation for defects in deliverables, ownership of development results, and the scope of maintenance must be specifically agreed upon in advance to avoid subsequent legal disputes. It is crucial to detail these aspects in the contract. Contract conditions that must be included in software service contracts Software development contracts should at least include the following items in detail. 1. Scope of Work Definition If the scope of work is not specifically defined in a software service contract, disputes may arise when additional development requests occur. Therefore, the contract should explicitly state the software’s functionality and requirements to be developed, and should avoid broad expressions such as “website construction” or “ERP system development.” Instead, it should be specified by screen and function unit, along with the technical stack and development methods. It is also advisable to define the submission method for intermediate deliverables and step-by-step results. 2. Development Schedule and Delay Responsibility Because development schedules are often delayed, it is important to clarify the development period and responsibility for delays. The project schedule (start date, milestones, expected completion date) should be specified, and the content of responsibility (penalty, etc.) when a schedule delay occurs, the scope within which a delay may be recognized, and regulations to hold responsibility for delays due to development delays should be defined. 3. Deliverable Inspection and Delivery Method If the inspection criteria for deliverables are not clear, disputes may arise regarding the quality of the results provided by the development company. The form (source code, technical documentation, etc.), delivery method, and inspection procedure for deliverables should be specified, the inspection deadline and completion criteria should be set, and the obligation and method for revision should be defined if the inspection fails. 4. Defect Liability Period and Maintenance Scope After software development is completed, bug fixes and maintenance may be required for a certain period. Therefore, contract conditions for defect liability and maintenance must be clearly stated in the contract. The scope, method, and period of defect liability should be defined, the scope and cost calculation criteria for maintenance should be determined, and procedures for responding to emergency maintenance should be established. 5. Intellectual Property Rights Attribution Intellectual property rights attribution is an important factor in software service contracts. When a contract is concluded, the ownership of the software’s source code and copyright must be clarified. The owner of the copyright of the development results should be specified, the provision of source code and usage restrictions should be determined, and the application of open-source licenses should be confirmed. 6. Confidentiality Obligation Because sensitive information may be shared during the software development process, a confidentiality clause should be included to prevent information leaks. The confidentiality obligation of the parties to the contract should be specified, the scope and protection period for confidential information should be set, and regulations for compensation in case of breach of confidentiality obligations should be established. 7. Contract Termination or Cancellation Clause If the conditions for termination and cancellation of the contract are not clarified, disputes may be difficult to resolve. The reasons and procedures for contract termination should be specified, the regulations for costs and penalties arising from termination should be determined, and the obligations of both parties after termination should be organized. Applicable Law for Software Service Contracts Software service contracts are not simple service contracts, but complex contracts that can be interpreted in various ways from a legal perspective. The Supreme Court, while explaining the nature of a manufacturing supply contract, found that it was a mixture of a commissioned work aspect and a sales aspect (Supreme Court Decision of June 28, 1996, 94da42976). In particular, in the case of software development tailored to a specific customer’s request, there is a high probability that the development results will be a substitute for only that customer, which means that it has the nature of a commissioned work contract. In this case, the provisions of the Civil Code regarding commissioned work shall apply, which may lead to differences in interpretation regarding defect liability, responsibility for non-performance, and conditions for contract cancellation. Law firm Veat, certified by the Korea Bar Association, includes partner attorneys Baek Seung-cheol and An Il-woon, as well as attorneys from engineering backgrounds, and provides specialized legal services in IT and software fields. They have experience advising numerous startups, development companies, and platform companies. They provide in-depth understanding of legal issues throughout the IT industry, such as software service contracts, license agreements, open-source compliance, Personal Information Protection Act, and Information and Communications Network Act, and provide practical solutions. From defining the scope of work during the development stage to responding to disputes after delivery, protecting against technology leakage and intellectual property rights, they provide customized advice on complex issues where technology and law intersect, minimizing business risks for clients. If you require legal advice regarding IT and software, please do not hesitate to contact Law firm Veat. Thank you. Law firm Veat
Reputation checks without consent are a violation of the law – Risks that hiring professionals must know.
Can employee criminal record checks be performed? There has been increasing legal controversy recently regarding 'reputation checks (reference , reference check)' in the recruitment market. In particular, informal reputation check practices, without the consent of job applicants, still exist, especially in the IT and startup industries, and there is increasing concern about whether this constitutes a violation of the Personal Information Protection Act. According to related reports, some companies are continuing to confirm reasons for leaving and work attitude through former colleagues or industry contacts, which could lead to legal disputes such as violations of the Personal Information Protection Act or criminal liability, requiring special caution. (Related article: “What do you think of this friend?” Job applicant reputation check... “Illegal act” vs “Necessary process”, World Ilbo 2025.03.17.) Under these circumstances, Law firm Veat received a legal consultation request from a client about to hire employees regarding whether obtaining criminal record data of the recruitment candidates carries the risk of violating the Personal Information Protection Act. In this post, we would like to introduce the main legal issues related to criminal record checks and reputation checks, and practical points for companies to pay attention to in the recruitment process, based on this consultation case.
What is the responsibility of the principal company when canceling a subcontracting agreement? Key issues based on practical advice.
Law firm Veat received a request for legal advice regarding the termination of a subcontract agreement from a KOSPI-listed IT company (hereinafter referred to as "client"). This case involved a request for a comprehensive review of whether the client would bear legal responsibility for termination based on the situation where subsequent subcontract agreements also had to be terminated as some of the main contract concluded by the client was terminated. Article 1,537 (Principle of Burden of Risk of Default) When the performance of an obligation of one of the parties to a reciprocal contract becomes impossible due to a cause not attributable to the fault of either party, the obligee shall not be entitled to request performance. Law firm Veat first reviewed the applicability of Article 1,537 to review the legal feasibility of whether the subcontract agreement would continue or not, as the main contract was partially terminated unexpectedly and the subcontract agreement was dependent on it. The provision stipulates the principle that legal responsibility is exempted when the inability to perform a contract arises due to a cause not attributable to the fault of both contracting parties. In this case, as the subcontract agreement was concluded on the premise that the main contract was valid, there was a high possibility that the purpose of the subcontract agreement itself would become impossible to achieve as the main contract was terminated. We explained that the legality of the contract termination could be secured based on the grounds that performance was impossible due to a cause not attributable to the fault of both parties. Article 1,8 (Prohibition of Unreasonable Cancellation of Entrustment, etc.) ① A principal shall not engage in any of the following acts if there is no reason to attribute the responsibility for the reason to the subcontractor after entrusting manufacturing or other work. However, this shall not apply to service entrustment involving the supply of services. get advice on proactive measures to avoid unnecessary risks is recommended. Law firm Veat has strengths in presenting optimal solutions tailored to the characteristics of each case, based on abundant practical experience in handling various subcontract disputes. In particular, we have established effective legal strategies considering the balanced interests of both the principal and the subcontractor in relation to contract termination and the Subcontract Act and the Civil Code, and we have reviewed legal issues that may arise throughout the entire process from contract negotiation to termination and regulatory response. Also, we have extensive experience in responding to investigations and sanctions procedures of regulatory agencies including the Fair Trade Commission, and can provide rapid and professional responses to administrative risks related to violations of the Subcontract Act. Like this, Law firm Veat provides practical legal advice from the client’s perspective, covering all stages from proactive risk prevention to regulatory agency response and dispute resolution. If you need legal advice regarding unfair subcontract transactions and
[Forest of Innovation] Partner Attorney An Il-woon, Article Contribution on Data Crawling in the AI Era, Legal Issues
Law firm Veat's partner attorney An Il-un published a column on the key legal issues related to data crawling in light of the AI era on the startup growth analysis platform ‘Innovation Forest’. AI and Data Crawling: The Boundary of Innovation and the Law Data crawling plays a crucial role in collecting vast amounts of information from the web to utilize for AI learning, and its importance is further emphasized with the remarkable advancement of generative AI technology. However, the act of automatically collecting information or data from other people's websites may conflict with various laws, such as the Copyright Act, the Act on Prevention of Unfair Competition, and the Act on Information and Communications Networks, making legal review essential. Partner attorney An Il-un analyzed in depth in this column the cases where data crawling can be legally problematic based on precedents, and the matters to be considered for legitimate crawling. In particular, he organized various issues such as the possibility of violating the terms of service of the target service, copyright infringement of individual works and infringement of the rights of the database creator, and unfair competition, and you can check the details through the content below. Data Crawling in the AI Era: What are the Legal Issues? (Innovation Forest) AI companies and developers should carefully examine whether the data being crawled is legally protected information, and whether its collection and utilization infringes on the rights of the rights holder. Furthermore, it is important to move beyond the practice of collecting data simply because it is technically possible, and to arrange clear relationships and responsibilities in advance through legal consultation. Law firm Veat provides specialized legal services in cutting-edge technology fields such as AI, big data, blockchain, and metaverse, and has established itself as a reliable legal partner for numerous technology-based startups and IT companies, based on its expertise in proactively analyzing and responding to complex legal issues facing new industries. In particular, An Il-un partner attorney, an IT specialist and external contributor to the startup growth analysis platform Innovation Forest, provides in-depth legal advice across the AI, data, and IT industries, supporting the growth of technology companies legally. In particular, he provides practical interpretations and solutions for data rights issues, algorithm transparency and accountability issues, and IP risk response strategies that are highlighted by the spread of generative AI technology, and proposes a balance between technological advancement and legal safety. Thank you. Law firm Veat
Data breach, it cannot be dismissed as a simple ‘risk’ – legal review is essential.
As digital transformation accelerates, the value and importance of personal information is increasing. Customer information handled by companies is no longer just data, but a core asset directly linked to trust. However, personal information leakage incidents are also occurring, which can lead to significant legal and financial risks for companies. For example, A Card Company was fined approximately 1.34 billion won due to inadequate internal controls and misuse of personal information for purposes other than those stated, and B Travel Agency received administrative sanctions worth hundreds of millions of won due to a hacking attack that leaked 3.06 million pieces of personal information. These cases demonstrate that personal information leakage can go beyond a simple security incident, resulting in substantial legal and financial damage to companies. “Personal Information Protection Law” prevention is the best response The process by which companies collect and process personal information is subject to the strict regulations of the Personal Information Protection Law. Personal information processors must take various technical and administrative measures to ensure the security of personal information, and failure to do so can result in administrative sanctions such as fines, public announcements, and corrective orders. Specifically, Article 64-2(1)(9) of the Personal Information Protection Law stipulates that personal information processors who fail to take security measures and cause personal information to be leaked may be subject to fines. This means that preventative measures play a crucial role in reducing a company’s legal responsibility. For example, the procedure of checking whether sensitive personal information such as resident registration numbers and financial information is included before uploading documents to bulletin boards or websites is the most basic preventive measure. It is also important to set individual recipients when sending emails and apply file encryption and device locking functions to work devices. Considering that many leakage incidents have stemmed from basic errors such as email recipient errors and posting files on bulletin boards, these measures are simple but highly effective preventative measures. Despite all precautions, personal information leakage incidents can occur at any time. According to the ‘2024 Personal Information Leakage Reporting Trends and Prevention Methods’ report released by the Personal Information Protection Committee, a total of 307 personal information leakage reports were received only in 2024. Of these 307, hacking accounted for the largest proportion at 56%, followed by work-related errors (30%) and system errors (7%). This indicates that internal negligence and inadequate system management are also major causes. When a personal information leakage incident occurs, companies must respond quickly and transparently. According to Article 39(1) of the Enforcement Decree of the Personal Information Protection Law, companies must notify the information subject within 72 hours from the time they become aware of the incident, and provide detailed information on the items of leaked information, the time of occurrence, and the countermeasures. This is not just a formality, but a minimum measure to minimize secondary damage to the information subject and maintain trust in the company. Hiding the incident or reporting it late can lead to legal responsibility and damage to the company’s image that is difficult to recover. Legal advice should be a 'proactive strategy,' not a post-incident response. Recent cases show that risks are also significant due to the absence of internal security regulations, neglected access controls, and unauthorized use of personal information, not just system hacking. In fact, in industries that handle large amounts of personal information, such as finance, healthcare, education, and travel, personal information protection levels are acting as important evaluation criteria in the partner selection and investment attraction processes. In this trend, proactively checking legal risks and establishing systematic response manuals is not just about avoiding legal violations, but about enhancing a company’s credibility as a ‘strategic choice.’ Law firm Veat, led by partners Jo Eun-byeol and Baek Seung-cheol, has high expertise and extensive practical experience in the Personal Information Protection Law field and provides customized consulting to support personal information protection measures and rapid and practical legal responses in the event of a leakage incident. Law firm Veat's partner Jo Eun-byeol has been recognized and awarded as an excellent legal advisor by the Personal Information Protection Committee and has strengths in legal interpretation, regulatory response, and policy consultation related to personal information. She is also actively contributing to system improvement through her involvement in various public advisory bodies such as the Information Disclosure Deliberation Committee, the Proactive Administration Committee, and the Personal Information Dispute Resolution Committee. Partner Baek Seung-cheol is active as a member of the Personal Information Processing Policy Evaluation Committee and other personal information-related deliberation and advisory committees, and as a personal information and PIPL (Personal Information Protection Law) certified auditor with the Korean Bar Association’s IT Personal Information Protection Advisory Lawyer, and actively conducts personal information protection education for public organizations and educational institutions. Based on the experience of providing customized legal advice to various companies in the field of personal information protection, Law firm Veat can provide specialized advice tailored to your specific situation. Please feel free to contact [Law firm Veat Personal Information Center] for any inquiries related to the Personal Information Protection Law. Thank you. Law firm Veat
AI (Artificial Intelligence) Regulation: Domestic and International Latest Legal Trends_Law firm Veat Academy On-site Sketch
Technology advances, and the law follows. Artificial intelligence (AI) technology is rapidly changing our daily lives and industries, and as a result, countries around the world are successively working on legal arrangements to keep pace. Now, the law is not merely a means of control, but is performing the role of a ‘design tool’ that presents direction for technology to function safely and sustainably within society. Amidst this flow of change, Law firm Veat continuously contemplates issues arising at the intersection of the technology industry and the law, and through the ‘Veat Academy’, is systematically studying the latest legal trends and regulatory issues and reflecting them in practical application.. VEAT ACADEMY: ‘AI (Artificial Intelligence) Regulation, Global Trends and Implications’ This Veat Academy centered on ‘AI (Artificial Intelligence) Regulation’, and also examined the AI legislation and policy trends of major countries. We explored the reasons why AI has become a central regulatory issue, outlined the international discussion flow surrounding the new legal challenges brought about by AI technology, and surveyed the international discussion flow surrounding the new legal challenges brought about by AI technology. Given that AI is evolving into a ‘decision-making tool’ influencing social structures and human lives, we were able to build consensus on the need for regulation and how legislative discussions are formed. Furthermore, we focused on understanding the current global regulatory landscape by comparing major documents that function as international standards, such as the EU’s AI Act and the OECD’s AI policy recommendations, examining the differences in regulatory philosophy, design methods, and levels. In addition, we juxtaposed the legislation and policy directions of major countries such as the EU, the United States, and China, and also viewed the differences in their perspectives on AI and regulatory approaches. The discussion did not stop at a simple comparison, but also analyzed the flow of regulatory design in depth, focusing on core elements that make up the actual regulation, such as technical classification criteria, regulatory scope, and application methods. Within this international trend, discussions were also actively held on what kind of institutional response Korea should take. Amidst increasingly intense global regulatory competition, practical perspectives were shared on the strategic challenges and legislative directions that the domestic industry and policy authorities should consider. This Veat Academy reaffirmed the need to not only understand institutional aspects but also to anticipate actual legal and practical challenges that companies will face and jointly explore response strategies. Law firm Veat, leading global and domestic AI regulation responses Law firm Veat has continuously provided specialized legal services for industries centered on AI technology. However, this expertise is not simply explained by past consulting experience. Veat seeks to provide practical advice to companies at the intersection of technology and regulation through continuous learning and reality-based contemplation. The Veat Academy is an internal program symbolizing this effort, where members regularly study the latest legal systems and consider how to apply them in practice. Through this constant learning and contemplation, Veat is evolving into a rare and specialized firm capable of performing both proactive analysis of global AI regulatory changes and precise responses to domestic institutional changes. Moving forward, we will continue to provide practical solutions based on internal capabilities, and strive to grow together as a trusted partner. Thank you. Law firm Veat
Corporate Card Misuse Revealed Internal Illegal Acts, Cases of Corporate Response for Breach of Trust and Embezzlement.
Law firm Veat was commissioned by a platform service company based on big data artificial intelligence (AI) to handle criminal prosecution procedures for employees who misused the company’s corporate card for personal use, resulting in a formal indictment and guilty verdict. In this case, the employee repeatedly made obviously personal consumption expenditures, such as shopping and travel, using the corporate card issued in the company’s name. Furthermore, an internal audit revealed that these uses were made secretly over a long period without the company’s approval. The client company determined that this matter was not a simple internal problem but a serious case requiring criminal action and commissioned Law firm Veat for advice on specific response measures. This case was not merely a civil damages issue but a serious matter involving criminal responsibility, requiring thorough preliminary preparation and strategic planning. Law firm Veat prepared a persuasive indictment based on legal grounds and relevant precedents, and systematically compiled supporting evidence such as corporate card usage receipts, internal emails, and approval records, and submitted them to the investigating authorities. In particular, the employee’s actions were ▲not a simple deviation but repeated over a long period▲, and the usage records were obviously for personal consumption, yet they exhibited an attitude of avoiding responsibility, and ▲there was a growing concern about the recurrence of similar cases. Consequently, considering the client company's situation, which necessitated strict punishment to restore the organization's discipline and prevent recurrence, Law firm Veat drafted and submitted a petition for strict punishment faithfully reflecting the company’s position. Through this series of responses, the employee was formally indicted and received a guilty verdict through trial. 「Criminal Code」 Article 355 (Embezzlement and Breach of Trust) ① A person who is in possession of another’s property and embezzles it or refuses to return it shall be sentenced to imprisonment for not more than 5 years or a fine of not more than 15 million won. ② A person who processes another’s affairs and acquires property for himself or for a third party by an act contrary to his duties, thereby causing damage to the principal, shall be subject to the punishment of the previous paragraph. Article 356 (Embezzlement and Breach of Trust in the Performance of Official Duties) A person who commits the offense of Article 355 by acting contrary to the performance of his duties shall be sentenced to imprisonment for not more than 10 years or a fine of not more than 30 million won. Under the Criminal Code, embezzlement and breach of trust are crimes that occur when a person manages or holds another’s property and violates their trust to use the property for their own benefit. In particular, a company’s corporate card is considered part of the company’s assets, and any misuse of it without proper procedure is clearly an act of embezzlement subject to punishment. This case is a precedent where the court clearly stated that corporate cards should only be used for business purposes and rendered a guilty verdict, demonstrating that any act of using company assets for personal use cannot be taken lightly. Furthermore, it has significance in that it has raised awareness of ethical violations within the organization and produced a preventive effect beyond simple punishment. For a company to achieve sustainable growth, internal trust and transparent accounting management are essential. In particular, acts by employees to misappropriate company assets can lead to serious criminal offenses of ‘breach of trust’ and ‘embezzlement’ beyond simple ethical deviations. However, many companies, even when aware of such misappropriation, are reluctant to press criminal charges due to concerns about organizational reputation, external image, or emotional burdens. Such neglect will ultimately encourage the recurrence of similar acts and long-term increase in the company’s legal risks. Conversely, as in this case, actively responding to legal issues regarding internal illegal acts can restore organizational trust and prevent recurrence. Law firm Veat helps companies maintain a healthy organizational culture and minimize legal risks by establishing and reviewing internal control regulations, providing legal advice on the scope of employee responsibility, and conducting legal diagnostics of high-risk areas. We provide assistance in operating compliance systems. In particular, we protect the company’s interests by providing rapid and professional responses based on preliminary reviews when problems arise. If you require legal advice on issues such as breach of trust, embezzlement, and protecting company assets, please consider seeking legal support with corporate attorney Law firm Veat. This case study can also be found on the Law firm Veat blog. - Internal Illegal Acts Revealed by Corporate Card Misuse, Case of Corporate Response for Embezzlement and Breach of Trust Thank you. Law firm Veat
[IT Litigation] Is the application of the legitimate interest provision possible when AI learning uses publicly disclosed personal information?
Recently, the pace of artificial intelligence (AI) development has accelerated, leading to an increase in instances where personal information is processed during the development and provision of AI models and services. In particular, large-scale data containing publicly exposed personal information is often included in the learning process of AI models, which may lead to potential legal issues. Therefore, AI development companies and service providers need to identify and manage legal issues related to personal information processing in advance. Meaning and Examples of Publicly Exposed Personal Information Publicly exposed personal information refers to data that is legally accessible by anyone on the internet, such as Common Crawl, Wikipedia, blogs, and websites. AI companies utilize these publicly available data by employing methods such as web scraping to acquire data needed for AI model training. Constitutional self-determination of personal information means the right of an individual to decide the processing and methods concerning their personal information. Even if personal information already exists on a public platform, in principle, unauthorized collection or use by a third party is not permitted. For example, accessing a specific website without proper access privileges to collect personal information for AI learning may violate the Act on Promotion of Information and Communication Network Utilization and Information Protection and the Personal Information Protection Act.
Order app era, customized terms of service and privacy policy for F&B franchises.
Law firm Veat received a request from F&B franchise company A (hereinafter referred to as "the client") and drafted Terms of Use and Privacy Policy for a delivery-only application and a proprietary brand ordering application. As digital transformation accelerates, companies are expanding their offline customer touchpoints to online platforms, and particularly in the F&B (food and beverage) industry, they are strengthening their connections with consumers through delivery-only apps or proprietary ordering apps. Accordingly, legal infrastructure for platform operation, especially the 「Act on Regulation of Standard Contract Terms」(hereinafter referred to as "Standard Contract Act"), the Personal Information Protection Act, and the 「Act on the Protection and Use of Location Information」(hereinafter referred to as "Location Information Act"), are becoming increasingly important. Law firm Veat focused on establishing a Terms of Use system that realistically operates by reflecting the client's actual operating methods, in addition to the conventional clauses of the Terms of Use and Privacy Policy. In particular, it focused on drafting clauses related to point accumulation and usage structure, whether delivery riders are outsourced, the possibility of product disposal, the use of location information, and personal information processing outsourcing. Drafting Terms of Use based on the Standard Contract Act The Terms of Use of an ordering app is a key document that defines the rights and obligations between the client and the platform, and should reflect the main provisions of the Standard Contract Act, which focuses on consumer rights protection in the e-commerce environment, to ensure fairness and transparency. Law firm Veat, in addition to the general Terms of Use items, also incorporated the following elements into the Terms of Use, considering the client's unique service structure. ※ Clauses related to point accumulation and usage When adopting a structure of accumulating points upon ordering and using them as a discount, specific and clear provisions regarding point accumulation conditions, validity period, expiry conditions, and whether a cash refund is possible must be included in the Terms of Use. These matters serve as a key criterion for judging the fairness of the Terms of Use and the fulfillment of the obligation to provide prior notice in the event of consumer disputes, and also play an important role in consumer protection. ※ Clauses related to employment of delivery riders and service outsourcing When directly providing delivery services or operating a dualized system through a third-party delivery agency, clear clauses must be drafted in the Terms of Use regarding the scope of responsibility for providing services, obligations to notify consumers, and the party responsible in the event of an accident during the delivery process. This goes beyond simple civil liability for damages and can also be linked to issues of joint or several liability under the Consumer Protection Act and the Personal Information Protection Act, making it important to take proactive measures to reduce legal risks. ※ Clauses related to order changes/cancellation and receipt confirmation In the case of a food delivery service, where products may be discarded if a certain amount of time has passed after ordering, it is necessary to clearly define in the Terms of Use receipt confirmation notices, the time during which order changes and cancellations are possible, the disposal procedure if the consumer does not receive the order, and the conditions under which a refund is not possible. These clauses are directly related to the establishment and termination/cancellation requirements of contracts under the Electronic Commerce Act and act as a key element to protect the rights of users in the process of electronic contract conclusion while reasonably adjusting the responsibilities of the business operator. Drafting Privacy Policy based on the Personal Information Protection Act and the Location Information Act The importance of personal information protection is increasingly emphasized, and in particular, online platforms require legal compliance throughout the entire process, including information collection and use based on user consent, third-party provision, processing outsourcing, and disposal procedures. Law firm Veat, based on the essential notice items under the Personal Information Protection Act (collection items, purpose of use, retention and usage period, etc.), supplemented the Privacy Policy with the following items to match the client’s service structure. ※ Specificity regarding collection and use of personal location information If the app allows users to directly set their delivery location or automatically recommends addresses based on real-time location, this may constitute collection and use of personal location information. At this time, the basis for collecting location information, the purpose of use, the retention period, and the procedure for withdrawing consent must be clearly explained in accordance with the Location Information Act and the Personal Information Protection Act. In particular, location information requires a higher level of protection equivalent to sensitive information, so it is important to write the consent method and notice content clearly. Legal and practical considerations are essential to provide users with sufficient information and obtain clear consent. ※ Specificity of personal information processing outsourcing Various operating functions, such as payment services, server operation, authentication, delivery agency, customer service, and order management, are often outsourced to external companies. In these cases, it is important to specifically mention in the Privacy Policy the content of each outsourcing task, the information of the outsourcee, and measures to ensure safety. This is a necessary procedure to fulfill the obligations of notice and consent when outsourcing under the Personal Information Protection Act, as well as the obligations to manage and supervise the outsourcee. ※ Clear distinction of collection items and retention periods The information collected during the ordering process is increasingly diversifying, including not only general order information such as name, contact information, and address, but also payment information, location information, and event participation history. Therefore, it is necessary to clearly distinguish the purpose of use and retention period for each item to guarantee the information subject’s right to know and secure the legal completeness of the Privacy Policy. Law firm Veat provides legal advice specializing in ICT convergence legal fields, such as Terms of Use, personal information, and platform regulations, based on its expertise. We can provide more specialized legal services for personal information protection and data-related laws through the LegalTune (Personal Information Center) on the Law firm Veat official website. This case study can also be viewed on the Law firm Veat blog. - Customized Terms of Use and Privacy Policy for F&B Franchises in the Ordering App Era Thank you. Law firm Veat
[Law firm Veat TIP] How far can the ‘similar transmission’ service be allowed? Digital voice transmission eligibility guideline
The Law firm Veat TIP(Technology Intellectual Property) team has contributed a column regarding the legal judgment of the '"similar transmission"' service and the guidelines for digital voice transmission eligibility to Platum, a specialized media platform for startups. As podcasting, webcasting, music streaming, and other various digital content services rapidly spread, whether these services are covered by "transmission" under copyright law, or "digital voice transmission," affects the permission methods of copyright holders and related rights holders. This column examines the "similar transmission" concept based on the controversy sparked by the streaming service "Milk" launched by Samsung Electronics in the domestic music market in 2014, and focuses on the "digital voice transmission eligibility" guidelines presented by the Korean Copyright Commission in 2015, specifically explaining the legal boundary between the two concepts and addressing what startups should consider when designing services. It also provides detailed explanations of the main contents of the digital voice transmission eligibility guidelines published by the Korean Copyright Commission. Detailed information can be found in the column published on Platum via the image or the link above. Content planners, music platform operators, startups, and other companies preparing digital content services are encouraged to use this column to gain practical insights to establish reasonable and safe guidelines and strategies. The Law firm Veat TIP team, specializing in intellectual property (IP), provides professional legal advice based on its accumulated experience in the digital content field, including legal classification reviews based on service type, negotiations with copyright holders and trust organizations, and establishment of dispute response strategies. If you need help with digital voice transmission, similar transmission, or other digital content services, please contact Law firm Veat. Thank you. Law firm Veat