Facts
Scatter Lab ran two apps, Science of Love and TextAt, which analysed KakaoTalk conversations uploaded by users and offered relationship advice. Between February 2020 and January 2021 the company used around 9.4 billion sentences from roughly 600,000 users of those apps to develop and operate Iruda, a chatbot offered to Facebook users. Names, mobile numbers and addresses in the conversations were neither deleted nor encrypted. From October 2019 to January 2021 the company also posted an AI model on GitHub together with 1,431 conversation sentences containing names and locations. The investigation further found that data of users under 14 had been collected without a guardian's consent.
Question
The central question was whether conversations collected for one service could be used, without notice or fresh consent, to build a different AI product. The PIPC also examined whether processing the chats without stripping identifiers could be reconciled with the rules on pseudonymised data in the Personal Information Protection Act (PIPA), whether releasing the model and sample sentences in a public repository was lawful, and whether the company had met the requirement of guardian consent for users under 14. The case was one of the first in which a chatbot's training data was reviewed under data protection law.
Decision
At its plenary meeting on 28 April 2021 the PIPC found eight breaches of PIPA. It imposed a penalty surcharge of KRW 55.5 million and administrative fines of KRW 47.8 million, KRW 103.3 million in total, together with corrective orders. In its view the conversations had been used beyond the purpose for which they were collected, and users had not been adequately informed. Because the sentences posted on GitHub contained information capable of identifying individuals, their release also breached the rule on pseudonymised data. Chair Yoon Jong-in said the decision made clear that information collected for a particular service may not be used indiscriminately in other services.
Why it matters
The decision is regarded as the first time a Korean authority sanctioned an AI company for indiscriminate processing of personal data. It applied purpose limitation, transparency and the pseudonymisation rules to conversational data used to train a chatbot, on concrete facts. Questions about where training data comes from and what users were told about it became, from this point, part of the legal assessment of AI development in Korea.
Related stages
In a damages action brought by users, the Seoul Eastern District Court in 2025 awarded compensation for non-pecuniary harm to some plaintiffs; Scatter Lab appealed.