Facts
In the Worldcoin project a device called the Orb photographs a person's iris and generates an iris code from the image. The Worldcoin Foundation acted as controller and Tools for Humanity (TFH) carried out the processing. As of 6 September 2024, 29,991 of the 93,463 people in Korea who had downloaded the app had completed iris verification. The data were transferred abroad, to Germany among other countries. The Personal Information Protection Commission (PIPC), treating iris data as sensitive information, examined collection, notice, consent, cross-border transfer and deletion. It also reviewed how age was checked when users signed up to the World app operated by TFH.
Question
The main question was whether a biometric identifier such as the iris had been collected in line with the separate-consent and notice requirements that the Personal Information Protection Act (PIPA) sets for sensitive information. The PIPC also considered whether data subjects had been told which country the data went to and who received it, whether users had a way to request deletion of their iris code or suspension of its processing, and whether an age-verification step kept children under 14 out of the service. These questions went to the limits Korean law places on biometric identity services.
Decision
On 25 September 2024 the PIPC found that the Worldcoin Foundation had not properly told data subjects why iris data was collected or how long it would be kept, nor obtained separate consent for sensitive information. The data had gone to Germany and elsewhere without disclosure of the destination country or the recipient's name and contact details, and iris codes could not be deleted on request. TFH's age checks for children under 14 were inadequate. The PIPC imposed penalty surcharges of KRW 725 million on the Foundation and KRW 379 million on TFH, KRW 1.104 billion in total, and ordered proper notice and consent, guaranteed deletion and no use beyond the original purpose.
Why it matters
The decision showed that identity-verification services built on biometric identifiers such as the iris fall under Korea's sensitive-information regime, which requires separate consent, clear notice and a working right to deletion. It also spelled out that cross-border transfers must disclose the destination country and the recipient. The same project drew scrutiny from data protection authorities in other countries, and the Korean decision is one of those that ended in a monetary penalty.