The Korea Communications Standards Commission (KCSC) urged 12 foreign companies on September 13 to strengthen safeguards for sensitive information attached to content-removal requests. The move followed an alleged exposure involving information submitted to remove digital sex-crime content from Google.

That distinction matters: the issue concerns the data included with a removal request, not necessarily the content targeted for removal. The KCSC also sought removal of the exposed material and related Google search results.

A separate privacy investigation

South Korea’s Personal Information Protection Commission (PIPC) said on September 11 that it had requested records from Google on September 7 and begun investigating the reported disclosure of data from digital-sex-crime content-removal requests.

The investigation covers what information was shared, when and how it was shared, the basis for processing it, consent and possible violations. The PIPC’s investigation is separate from the KCSC’s safeguard requests.

The companies named in the KCSC action are Google, Meta Korea, X Korea, and TikTok Korea. The action covered 12 foreign companies in total, but eight additional companies were not identified.

Cloudflare and four international organizations

The KCSC addressed Cloudflare separately, urging stronger controls against the external sharing, redistribution or disclosure of sensitive information contained in regulatory requests. Cloudflare was not identified as one of the 12 companies in the KCSC request.

The regulator also shared the case with four international organizations: the International Association of Internet Hotlines, the Global Online Safety Regulators Network, the International Institute of Communications, and the US National Center for Missing & Exploited Children.

Those actions widen the focus beyond removing harmful material itself. They put the handling and onward distribution of the information attached to a removal request at the center of South Korea’s response.