Privacy Policy

1. General Provisions

The Seoul Design Foundation, the host organization of the World Design Congress, values the personal information of users in connection with the official World Design Congress website (hereinafter the “Site”) and the pre-registration and event participation application process, and complies with the Personal Information Protection Act and other relevant laws and regulations. This Privacy Policy has been prepared to explain what personal information the Congress processes, for what purposes, and how.

In the event the Congress transfers or is transferred all or part of its business, or undergoes a merger, and there is a party receiving the personal information, the Congress will notify this fact in advance through the Site and public notices, obtain the consent of data subjects, and carry out other necessary procedures.

  • Effective date of this Privacy Policy: [2026.09.01]
  • Date of most recent revision: [2026.09.01]

2. Purposes of Processing Personal Information

The Congress processes personal information for the following purposes, and where a purpose changes, will take necessary measures such as obtaining separate consent.

1. Pre-registration and notices for the World Design Congress 2027 Seoul Preview event (14 October 2026)

  • Confirmation of application/receipt, sending event notices (venue, time, changes, etc.), management of the participant list, on-site check-in

2. Notices related to the 35th World Design Congress (where separate consent is given)

  • Sending emails regarding key Congress news, notices of future registration openings, etc.

3. Responding to inquiries

  • Confirming contact details in order to reply to inquiries received

4. Prevention of fraudulent use and Site security

  • Detecting abnormal access, preventing fraudulent registration/abuse, and responding to security incidents

5. Improvement of service quality

  • Improving content and features through analysis of Site usage statistics

6. Fulfilment of legal obligations

  • Complying with retention and reporting obligations under relevant laws and regulations

3. Items of Personal Information Processed and Collection Methods

a. Items Collected (Preview Event Pre-Registration — via Naver Form or Catch Form)

CategoryItemRequired/Optional
RequiredNameRequired
RequiredEmail addressRequired
RequiredMobile phone numberRequired
OptionalAffiliation (organization/company name), positionOptional
OptionalNumber of attendees, areas of interestOptional
Automatically collectedDate/time of registration, IP address, browser/device information

b. Collection Methods

  • Pre-registration: Data subjects enter information directly when applying online through the Naver Form/Catch Form accessed via the link posted on the Site
  • Inquiries: Information entered through the inquiry channel on the Site (email, etc.)
  • Automatic collection: Collected through automated means such as cookies when visiting the Site (see Article 12)

4. Period of Processing and Retention of Personal Information

  • Pre-registration information: Retained until [3 months after the event ends] from the date of collection, then destroyed

(e.g., “Destroyed within 3 months of the end of the Preview event. However, where separate consent has been obtained for the purpose of managing participants in preparation for the official World Design Congress, information will be retained until [2027]”)

  • Newsletter subscribers: Destroyed immediately upon request to unsubscribe
  • Where retention is required under relevant laws and regulations, information will be separately stored for the applicable period before destruction (e.g., records of consumer complaint/dispute handling under the Act on Consumer Protection in Electronic Commerce — generally not applicable where there is no payment or transaction)

5. Outsourcing of Personal Information Processing ★ (Key clause when using Naver Form or Catch Form)

The Congress outsources personal information processing tasks as set out below to ensure the smooth handling of pre-registration, and specifies in the outsourcing agreement, in accordance with relevant laws and regulations, matters such as the prohibition on processing for purposes other than the outsourced task, technical and administrative protection measures, and supervision of the outsourced service provider.

Outsourced PartyDetails of Outsourced TaskPeriod of Retention/Use of Personal Information
NAVER Corporation (Naver Form)Receipt and storage of pre-registration form submissionsUntil termination of the outsourcing agreement or until the purpose is achieved
ONEPEOPLE Co., Ltd. (Catchsecu/Catch Form)Receipt and storage of pre-registration form submissionsUntil termination of the outsourcing agreement or until the purpose is achieved

6. Provision of Personal Information to Third Parties

The Congress processes data subjects’ personal information only within the scope specified in Article 2 (Purposes of Processing), and does not provide personal information to third parties except where separate consent has been obtained from the data subject or where specifically required by law.

Personal information may exceptionally be provided where required by relevant laws and regulations, such as where a court, investigative agency, or similar body makes a request through lawful procedures based on applicable law.

7. Overseas Transfer of Personal Information

[This section was listed in the table of contents of the source draft but its content had not yet been drafted at the time of translation. Please supply the relevant details — e.g., whether personal information is transferred outside Korea (such as to overseas servers used by Naver Form/Catch Form or analytics providers), the recipient, items transferred, purpose, retention period, and method of transfer — so this section can be completed.]

8. Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercise

Data subjects may exercise the following personal-information-related rights against the Congress at any time.

1. Request to access personal information

2. Request for correction in the event of errors

3. Request for deletion

4. Request to suspend processing

Rights may be exercised in writing, by email, or by other means, addressed to [Department Email/Contact Information], and the Congress will take action without delay.

  • Requests for access: Access will be provided within 10 days of receipt of the request (Article 35 of the Personal Information Protection Act).
  • Requests for correction/deletion: Except where other laws specifically designate the information as subject to separate collection requirements, the Congress will notify the result of processing within 10 days of receipt of the request (Article 36 of the Personal Information Protection Act).
  • Requests to suspend processing: Processing will be suspended without delay (Article 37 of the Personal Information Protection Act).

The Congress may verify the identity of the data subject in order to process such requests. Where the data subject is a child under the age of 14, the child’s legal representative may exercise these rights on the child’s behalf.

9. Protection of Children’s Personal Information

As a general principle, the Congress operates pre-registration and event participation for adults (aged 14 and older).

Where it is necessary to process the personal information of a child under the age of 14, the Congress obtains the consent of the child’s legal representative in accordance with Article 22-2 of the Personal Information Protection Act, and may collect the minimum information necessary to confirm that such consent has been given.

A legal representative may request that the Congress provide access to, correct or delete, or suspend the processing of, a child’s personal information, and the Congress will take the necessary action without delay in such cases.

10. Procedures and Methods for Destruction of Personal Information

  • Destruction procedure: Personal information for which grounds for destruction have arisen — such as the expiry of the retention period or achievement of the processing purpose — is transferred to a separate database (or, in the case of paper records, a separate filing cabinet) and is stored for a set period, or destroyed immediately, in accordance with internal policy and relevant laws and regulations.
  • Destruction method: Personal information recorded and stored in electronic file form is deleted using technical methods that render the records unrecoverable; personal information recorded and stored on paper is destroyed by shredding or incineration.
  • Upon request from a data subject, the Congress can confirm that destruction of their personal information has been completed.

11. Measures to Ensure the Security of Personal Information

The Congress takes the following measures to ensure the security of personal information.

1. Administrative measures: Establishment and implementation of an internal management plan; minimization of personnel with access and regular training

2. Technical measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of personal information during storage and transmission (where applicable), and installation and updating of security programs

3. Physical measures: Access control over the storage of materials

12. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices (Cookies, etc.)

The Site may use cookies and similar technologies to provide customized services to users and to analyze access statistics.

  • Purpose of using cookies: Analysis of access frequency and time spent, etc. (e.g., where analytics tools such as Google Analytics are used)
  • Third-party cookies: Third-party services embedded in the Site, such as social media share buttons or map embeds (Kakao/Google Maps), may independently install their own cookies, and the relevant third party’s privacy policy will apply in such cases.
  • Refusing the installation and operation of cookies: Users may refuse to allow cookies to be stored through their web browser settings, in which case they may experience difficulty using the service.

13. Links to Other Sites

The Site may include links to other websites that are not owned or operated by the Congress, such as those of sponsors, partner organizations, or ticketing providers.

The Congress is not responsible for the personal information practices of such other sites, and users are advised to review the privacy policy of any site they access through such links. This Privacy Policy applies only to personal information collected on the World Design Congress Site.

14. Personal Information Protection Officer and Department in Charge

CategoryDetails
Personal Information Protection OfficerName: [Jeonghoon Cho] / Title: [Senior Manager]
Department in Charge[Universal Design Team, Seoul Design Foundation]
ContactEmail: [jhcho@seouldesign.or.kr] / Phone: [+82-2-2096-0123]

Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising in connection with their use of the Congress’s services to the department in charge listed above. The World Design Congress will respond to and process such inquiries without delay.

15. Remedies for Infringement of Data Subjects’ Rights

Data subjects may report or seek consultation regarding infringements of their personal information rights with the following organizations.

  • Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
  • Supreme Prosecutors’ Office: 1301 (no area code) (www.spo.go.kr)
  • National Police Agency: 182 (no area code) (ecrm.cyber.go.kr)

16. Changes to This Privacy Policy

This Privacy Policy applies from its effective date. Where any addition, deletion, or correction is made pursuant to relevant laws and regulations or internal policy, notice will be given through the notice board at least 7 days prior to the effective date of the change.

개인정보처리방침

1. 총칙

세계디자인총회 주최기관인 서울디자인재단은 세계디자인총회 공식 웹사이트(이하 “사이트”) 및 사전등록·행사 참가 신청 과정에서 이용자의 개인정보를 소중히 다루며, 「개인정보보호법」 등 관계 법령을 준수합니다. 본 개인정보처리방침은 총회가 어떤 개인정보를, 어떤 목적으로, 어떻게 처리하는지 안내하기 위해 작성되었습니다.

총회가 사업의 전부 또는 일부를 양도·양수하거나 합병하는 경우, 개인정보를 이전받는 자가 있을 때에는 사전에 그 사실을 사이트 및 공지사항을 통해 고지하고 정보주체의 동의를 받는 등 필요한 절차를 이행합니다.

  • 처리방침 시행일자: [2026.09.01]
  • 최종 개정일자: [2026.09.01]

2. 개인정보의 처리 목적

총회는 다음 목적을 위해 개인정보를 처리하며, 목적이 변경되는 경우 별도 동의를 받는 등 필요한 조치를 이행합니다.

1. World Design Congress 2027 Seoul Preview 행사(2026.10.14) 사전등록 및 안내

  • 참가 신청·접수 확인, 행사 안내(장소·시간·변경사항 등) 발송, 참가자 명단 관리, 현장 체크인

2. 제35회 세계디자인총회 관련 소식 안내 (선택 동의 시)

  • 세계디자인총회 주요 소식, 추후 등록 오픈 안내 등 이메일 발송

3. 문의 응대

  • 문의 접수 시 회신을 위한 연락처 확인

4. 부정 이용 방지 및 사이트 보안

  • 비정상 접속 탐지, 부정 등록·어뷰징 방지, 보안 사고 대응

5. 서비스 품질 개선

  • 사이트 이용 통계 분석을 통한 콘텐츠·기능 개선

6. 법령상 의무 이행

  • 관계 법령에 따른 보관·제출 의무 준수

3. 처리하는 개인정보의 항목 및 수집방법

가. 수집 항목 (프리뷰 행사 사전등록 — 네이버폼 or 캐치폼 이용)

구분항목필수/선택
필수성명필수
필수이메일필수
필수휴대전화번호필수
선택소속(기관/회사명), 직위선택
선택참석 인원 수, 관심 분야선택
자동수집등록일시, 접속 IP, 브라우저·기기 정보

나. 수집 방법

  • 사전등록: 사이트에 게시된 링크를 통해 접속하는 네이버폼/캐치폼을 통한 온라인 신청 시 정보주체가 직접 입력
  • 문의: 사이트 내 문의 채널(이메일 등)을 통한 입력
  • 자동수집: 사이트 방문 시 쿠키 등 자동화된 수단을 통한 수집 (제12조 참조)

4. 개인정보의 처리 및 보유기간

  • 사전등록 정보: 수집일로부터 [행사 종료 후 3개월]까지 보유 후 파기

(예: “프리뷰 행사 종료일로부터 3개월 이내 파기. 단, 세계디자인총회 정식 행사 준비를 위한 참가자 관리 목적으로 별도 동의를 받은 경우 [2027년까지] 보유”)

  • 소식 수신 동의자: 수신 거부 요청 시 즉시 파기
  • 관계 법령에 따라 보존이 필요한 경우 해당 기간 동안 별도 보관 후 파기 (예: 전자상거래법상 소비자 불만·분쟁처리 기록 등 — 결제·거래가 없다면 통상 해당 없음)

5. 개인정보처리의 위탁 ★(네이버폼 or 캐치폼 이용 시 핵심 조항)

총회는 사전등록 접수 업무의 원활한 수행을 위해 아래와 같이 개인정보 처리업무를 위탁하고 있으며, 위탁계약 체결 시 관계 법령에 따라 위탁업무 목적 외 처리금지, 기술적·관리적 보호조치, 수탁자에 대한 관리·감독 등을 계약서에 명시합니다.

수탁업체위탁업무 내용개인정보 보유·이용 기간
네이버 주식회사 (네이버폼)사전등록 폼 접수·저장위탁계약 종료 시 또는 목적 달성 시까지
주식회사 오내피플 (캐치시큐/캐치폼)사전등록 폼 접수·저장위탁계약 종료 시 또는 목적 달성 시까지

6. 개인정보의 제3자 제공

총회는 정보주체의 개인정보를 제2조(처리 목적)에서 명시한 범위 내에서만 처리하며, 정보주체의 별도 동의, 법률의 특별한 규정 등이 있는 경우를 제외하고는 개인정보를 제3자에게 제공하지 않습니다.

법원, 수사기관 등으로부터 법령에 근거한 적법한 절차에 따른 요청이 있는 경우 등 관계 법령에 의해 요구되는 경우에는 예외적으로 개인정보를 제공할 수 있습니다.

7. 개인정보의 국외 이전

[본 항목은 원본 초안의 목차에는 포함되어 있으나, 번역 시점 기준 본문 내용이 아직 작성되지 않았습니다. 개인정보의 국외 이전 여부(예: 네이버폼/캐치폼 또는 분석 도구가 이용하는 해외 서버 등), 이전받는 자, 이전 항목, 이전 목적, 보유·이용 기간, 이전 방법 등을 포함하여 내용을 보완해 주시기 바랍니다.]

8. 정보주체와 법정대리인의 권리·의무 및 행사방법

정보주체는 총회에 대해 언제든지 다음 각 호의 개인정보 보호 관련 권리를 행사할 수 있습니다.

1. 개인정보 열람 요구

2. 오류 등이 있을 경우 정정 요구

3. 삭제 요구

4. 처리정지 요구

권리 행사는 [담당부서 이메일/연락처]로 서면, 전자우편 등을 통하여 하실 수 있으며, 총회는 이에 대해 지체 없이 조치합니다.

  • 열람 요구: 요구를 받은 날로부터 10일 이내에 열람하도록 조치합니다 (개인정보보호법 제35조).
  • 정정·삭제 요구: 다른 법령에서 별도로 수집 대상으로 명시하고 있는 경우를 제외하고는 요구를 받은 날로부터 10일 이내에 처리 결과를 통지합니다 (개인정보보호법 제36조).
  • 처리정지 요구: 지체 없이 처리를 정지합니다 (개인정보보호법 제37조).

요청을 처리하기 위해 정보주체 본인 여부를 확인할 수 있으며, 정보주체가 만 14세 미만 아동인 경우 법정대리인이 대신하여 권리를 행사할 수 있습니다.

9. 아동의 개인정보 보호

총회는 원칙적으로 사전등록 및 행사 참가 대상을 성인(만 14세 이상)으로 운영합니다.

만 14세 미만 아동의 개인정보를 처리해야 하는 경우, 「개인정보보호법」 제22조의2에 따라 법정대리인의 동의를 받으며, 법정대리인이 동의하였는지를 확인하기 위해 필요한 최소한의 정보를 수집할 수 있습니다.

법정대리인은 아동의 개인정보에 대한 열람, 정정·삭제, 처리정지를 총회에 요구할 수 있으며, 이 경우 지체 없이 필요한 조치를 취합니다.

10. 개인정보의 파기절차 및 방법

  • 파기절차: 보유기간 경과, 처리목적 달성 등 파기 사유가 발생한 개인정보는 별도의 DB(종이의 경우 별도 서류함)로 옮겨져 내부 방침 및 관련 법령에 따라 일정 기간 저장된 후 혹은 즉시 파기됩니다.
  • 파기방법: 전자적 파일 형태로 기록·저장된 개인정보는 기록을 재생할 수 없는 기술적 방법을 사용하여 삭제하며, 종이 문서에 기록·저장된 개인정보는 분쇄기로 분쇄하거나 소각하여 파기합니다.
  • 정보주체가 요청하는 경우, 개인정보 파기 완료 사실을 확인해 드릴 수 있습니다.

11. 개인정보의 안전성 확보조치

총회는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.

1. 관리적 조치: 내부관리계획 수립·시행, 담당자 최소화 및 정기 교육

2. 기술적 조치: 개인정보처리시스템 등 접근권한 관리, 접근통제시스템 설치, 개인정보의 저장 시 및 전송 시 암호화(해당하는 경우), 보안 프로그램 설치 및 갱신

3. 물리적 조치: 자료보관에 대한 접근통제

12. 개인정보 자동 수집 장치의 설치·운영 및 거부에 관한 사항 (쿠키 등)

사이트는 이용자에게 맞춤화된 서비스 제공 및 접속 통계 분석을 위해 쿠키(cookie) 등을 사용할 수 있습니다.

  • 쿠키 사용 목적: 접속 빈도 및 방문 시간 분석 등 (예: Google Analytics 등 분석도구 사용 시)
  • 제3자 쿠키: 소셜미디어 공유 버튼, 지도(Kakao/Google Maps) 임베드 등 사이트에 포함된 제3자 서비스가 자체적으로 쿠키를 설치할 수 있으며, 이는 해당 제3자의 개인정보처리방침이 적용됩니다.
  • 쿠키 설치·운영 거부: 웹브라우저 설정을 통해 쿠키 저장을 거부할 수 있으며, 이 경우 서비스 이용에 어려움이 있을 수 있습니다.

13. 타 사이트 링크

사이트는 스폰서·협력기관·티켓 예매처 등 총회가 소유·관리하지 않는 타 웹사이트로의 링크를 포함할 수 있습니다.

총회는 이러한 타 사이트의 개인정보 처리 관행에 대해 책임을 지지 않으며, 링크를 통해 타 사이트로 이동하는 경우 해당 사이트의 개인정보처리방침을 확인하시기 바랍니다. 본 개인정보처리방침은 세계디자인총회 사이트에서 수집한 개인정보에만 적용됩니다.

14. 개인정보 보호책임자 및 담당부서

구분내용
개인정보 보호책임자성명: [조정훈] / 직책: [선임]
담당부서[서울디자인재단 유니버설디자인팀]
연락처이메일: [jhcho@seouldesign.or.kr] / 전화: [02-2096-0123]

정보주체는 총회의 서비스를 이용하시면서 발생한 모든 개인정보 보호 관련 문의, 불만처리, 피해구제 등을 위 담당부서로 문의할 수 있습니다. 세계디자인총회는 정보주체의 문의에 대해 지체 없이 답변 및 처리해 드릴 것입니다.

15. 정보주체의 권익침해에 대한 구제방법

정보주체는 아래 기관에 개인정보 침해에 대한 신고나 상담을 할 수 있습니다.

  • 개인정보분쟁조정위원회: (국번없이) 1833-6972 (www.kopico.go.kr)
  • 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
  • 대검찰청: (국번없이) 1301 (www.spo.go.kr)
  • 경찰청: (국번없이) 182 (ecrm.cyber.go.kr)

16. 개인정보처리방침의 변경

이 개인정보처리방침은 시행일로부터 적용되며, 법령 및 방침에 따른 변경내용의 추가, 삭제 및 정정이 있는 경우에는 변경사항의 시행 7일 전부터 공지사항을 통하여 고지할 것입니다.