루미르피부과
2026.08.02
We bring you the latest news and
essential information from Jamsil Lumir Dermatology Clinic.

Privacy Policy of Jamsil Lumir Dermatology Clinic
We would like to inform you about the Privacy Policy of Jamsil Lumir Dermatology Clinic.
All personal information handled by Jamsil Lumir Dermatology Clinic(hereinafter referred to as the “Clinic”) is collected, retained, and processed in compliance with the personal information protection regulations of relevant laws and regulations, such as the Personal Information Protection Act (hereinafter referred to as the “Act”). The Clinic has established the following privacy policy to protect users' personal information and rights and interests pursuant to the Act, and to promptly handle any grievances related to personal information. In addition, when we amend our Privacy Policy, we will make the changes public by comparing the pre-amendment and post-amendment versions so that data subjects can easily check the effective date and the modified contents.
1. Purpose of Processing Personal Information, Processing and Retention Period, and Items of Personal Information Processed
The Clinic registers and discloses the purpose of processing personal information, the processing and retention period, and the items of personal information processed to the Ministry of Administration and Security pursuant to Article 32 of the Act.
The status of personal information files can be checked on the Privacy Portal (www.privacy.go.kr) by searching the list of personal information files under Personal Information Civil Complaints > Request for Access to Personal Information, etc., and entering "Health Insurance Review and Assessment Service" as the institution name.
2. Matters Concerning Use Outside the Purpose and Provision to Third Parties
Status of Use Outside the Purpose and Provision to Third Parties of Personal Information: As a rule, the Clinic processes personal information within the scope specified for the purpose of collection and use, and does not process personal information beyond the original purpose or provide it to third parties without the prior consent of the data subject, except in the following cases:
○ When separate consent is obtained from the data subject
○ When there are special provisions in other laws
○ When the data subject or legal representative is in a state incapable of expressing consent or cannot obtain prior consent due to unknown addresses, etc., and it is recognized as urgently necessary for the obvious life, body, or property interests of the data subject or a third party
○ When personal information is provided in a form that does not allow a specific individual to be identified, for purposes such as statistical preparation and academic research
○ When personal information is not used for purposes other than its intended purpose or provided to third parties, and the relevant duties prescribed by other laws cannot be performed, following deliberation and resolution by the Personal Information Protection Commission
○ When necessary to provide information to foreign governments or international organizations to fulfill treaties or other international agreements
○ When necessary for criminal investigation and the initiation and maintenance of prosecution
○ When necessary to perform court trial duties
○ When necessary for the execution of sentences, custody, and protective dispositions
The Clinic may link and provide personal information to other institutions in accordance with the above. In this case, the Clinic shall make a written request to the institution intending to use or receive the personal information to limit the purpose of use, method of use, period of use, form of use, or to establish specific measures necessary to secure the safety of personal information, and the linked and provided personal information shall be minimized in accordance with the purpose of use and provision.
3. Entrustment of Personal Information Processing
Status of Entrustment of Personal Information Processing: When entrusting personal information processing tasks, the Clinic shall process them pursuant to Article 26 of the Act through documents containing the following contents:
○ Matters concerning the prohibition of processing personal information outside the purpose of performing the entrusted tasks
○ Matters concerning technical and administrative protective measures for personal information
○ Other matters concerning the safe management of personal information
○ Purpose and scope of entrusted tasks
○ Matters concerning restrictions on re-entrustment
○ Measures to secure safety, such as access restrictions to personal information
○ Matters concerning supervision, such as inspection of the management status of personal information held in relation to the entrusted tasks
○ Matters concerning liability such as damages when a person entrusted with personal information processing tasks (hereinafter referred to as the “Trustee”) violates obligations to be observed
○ The Clinic discloses the contents of the entrusted tasks and the Trustee on its website.
4. Matters Concerning Rights and Obligations of Data Subjects and Methods of Exercise Thereof
Data subjects may exercise the following rights, and the legal representative of a child under the age of 14 may request access, correction, deletion, or suspension of processing of the child's personal information.
A. Request for Access to Personal Information
Data subjects may request access to their personal information pursuant to Article 35 of the Act. However, access may be restricted or refused in the following cases:
○ When access is prohibited or restricted by law
○ When there is a risk of harming another person's life or body, or unfairly infringing upon another person's property and other interests
○ When public institutions cause serious disruption in performing duties corresponding to the following:
- Duties related to the imposition, collection, or refund of taxes
- Duties related to grade evaluation or student selection at schools of various levels under the Elementary and Secondary Education Act and the Higher Education Act, lifelong education facilities under the Lifelong Education Act, and higher education institutions established under other laws
- Duties related to examinations for academic background, skills, and employment, and qualification screening
- Duties related to ongoing evaluations or judgments regarding the calculation of compensation or benefits
- Duties related to audits and investigations proceeding under other laws
B. Request for Correction and Deletion of Personal Information
A data subject who has inspected their personal information may request correction and deletion pursuant to Article 36 of the Act. However, if the personal information is specified as the target of collection in other laws and regulations, deletion cannot be requested.
C. Request for Suspension of Processing of Personal Information
Data subjects may request the suspension of processing of their personal information pursuant to Article 37 of the Act. However, requests for suspension of processing may be refused in the following cases:
○ When there are special provisions in laws or it is inevitable to comply with obligations under statutes
○ When there is a risk of harming another person's life or body, or unfairly infringing upon another person's property and other interests
○ When public institutions cannot perform their duties prescribed by other laws if they do not process personal information
○ When it is difficult to fulfill a contract, such as failing to provide the service promised with the data subject if personal information is not processed, and the data subject has not clearly expressed their intent to terminate the contract.
The exercise of rights pursuant to the above may be made in writing, via e-mail, or facsimile (FAX) in accordance with [Form No. 1] Request for Access, Correction, Deletion, and Suspension of Processing of Personal Information, and the Clinic will take action without delay.
In the case of exercising rights pursuant to the above, verification procedures must be gone through to prove that you are the data subject as follows:
- In the case of a data subject (self), submission of identification documents (resident registration card, driver's license, etc. certified by administrative agencies that cannot be easily forged or stolen)
- A legal representative or authorized agent of a data subject must submit a power of attorney according to [Form No. 2], along with identification documents such as the resident registration card of the principal and the agent.
- Verification through public certificate authentication procedures for websites or online.
5. Procedures and Methods for Destruction of Personal Information
As a rule, the Clinic destroys the personal information without delay when the retained personal information becomes unnecessary (expiration of the retention period, achievement of the processing purpose, etc.).
However, this does not apply if it must be preserved pursuant to other laws and regulations. The procedures, deadlines, and methods of destruction are as follows:
A. Destruction Procedure
Unnecessary personal information and personal information files are processed according to internal policies and statutory procedures under the responsibility of the Chief Privacy Officer.
B. Destruction Deadline
When the retention period has expired, the purpose of personal information processing has been achieved, or the relevant business has been abolished and the personal information becomes unnecessary, it shall be destroyed without delay.
C. Destruction Method
In the case of electronic files, records are permanently deleted using technical methods that cannot reproduce records, and personal information printed on paper is destroyed by shredding with a shredder or incineration.
6. Measures to Secure Safety of Personal Information
The Clinic takes the following measures to secure the safety of personal information:
A. Access Restriction to Personal Information
Necessary measures are taken to control access to personal information through the granting, modification, and cancellation of access rights to the database system processing personal information, and unauthorized access from the outside is controlled using an intrusion prevention system.
B. Retention of Access Logs
Records of access to the personal information processing system (web logs, summary information, etc.) are stored and managed for at least 6 months.
C. Encryption of Personal Information
Personal information is safely stored and managed through encryption, and important data uses separate security functions such as encryption during storage and transmission.
D. Minimization and Training of Employees Handling Personal Information
Employees handling personal information are designated and managed limited to necessary personnel, and training is conducted for handling employees for safe management.
E. Installation of Security Programs and Periodic Inspection and Renewal
Security programs are installed and periodically renewed and checked to prevent leakage and damage of personal information caused by hacking or computer viruses.
F. Access Control for Unauthorized Persons
A separate physical storage location for the personal information system storing personal information is established and operated with access control procedures.
7. Remedies for Infringement of Rights and Interests
Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, Personal Information Infringement Reporting Center, etc. to obtain relief for damages caused by personal information infringement.
Supplementary Data List:
- Personal Information Dispute Mediation Committee: 02-405-5150 (kopico.or.kr), 118 (privacy.kisa.or.kr)
- Personal Information Infringement Reporting Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Crime Investigation Division: 02-3480-3571 (cybercid@spo.go.kr)
- Korean National Police Agency Cyber Bureau: 182 (www.netan.go.kr)
In addition, anyone whose rights or interests have been infringed due to dispositions or omissions made by the Clinic in response to the data subject's request for access, correction, deletion, suspension of processing, etc., may file an objection with the Clinic and request administrative adjudication pursuant to the Administrative Appeals Act.
- Filing an objection: Submit an Application for Objection to Access, etc. of Personal Information according to [Form No. 3] to the Clinic.
- Request for administrative adjudication: Submit an application for administrative adjudication (2 copies) according to [Form No. 4] to the Administrative Appeals Commission or the Clinic.
* Administrative Appeals Commission: Refer to guidance at ☎110 (www.simpan.go.kr)
8. Chief Privacy Officer and Contact Information of Person in Charge
The Chief Privacy Officer and related personnel are as follows:
- Chief Privacy Officer: Cheon Seung-hyun
- Department and Person in Charge of Personal Information Protection: Cheon Seung-hyun
- Contact: 02-416-7778
9. Installation and Operation of Fixed Visual Data Processing Devices
Please refer to the [Operation and Management Policy for Fixed Visual Data Processing Devices].
- Self-inspection results of installation and operation of fixed visual data processing devices
10. Matters Concerning Changes to Privacy Policy
This policy was amended on August 14, 2026, and if additions, deletions, or modifications of contents are made according to changes in laws, policies, or security technologies, we will notify through the Clinic's homepage up to 7 days before enforcement.
- Announcement Date: August 14, 2026 / Enforcement Date: August 14, 2026
Jamsil Lumir Dermatology Clinic phone number.