More

South Korea’s Robot Vacuum Privacy Inspection: Findings and Fixes

South Korea’s Robot Vacuum Privacy Inspection: Findings and Fixes

On September 14, 2026, South Korea’s Personal Information Protection Commission (PIPC) announced the results of its privacy inspection of robot vacuums from five major brands: Roborock, Samsung Electronics, LG Electronics, Ecovacs, and Xiaomi. The inspection covered each brand’s latest models as of March 2025.

The inspection was conducted under the preliminary fact-finding inspection (사전 실태점검) framework in Article 63-2 of South Korea’s Personal Information Protection Act (개인정보 보호법), which aims to identify weaknesses in personal information protection before incidents occur. The announcement described how robot vacuums, apps, and servers process video, audio, and other information, and identified shortcomings in companies’ compliance with their legal obligations.

I. Personal Information Processing

Robot vacuums use cameras, microphones, and sensors to provide remote control, obstacle recognition, video viewing, and voice-command features. These functions may collect and use video and audio from inside the home, photographs of obstacles, and mapping information showing the layout of the home.

The PIPC focused on how this information is collected, transmitted, stored, and used on robot vacuums, apps, and servers. The announcement described the processing of four categories of information and noted that details may vary by brand.

Information typeTransmission and processing
VideoWhen users view live camera footage through the app, the robot vacuum transmits encrypted video to the user’s app. The footage is not retained on the company’s servers.
AudioAfter a user gives a command such as “clean the room,” the audio is processed on the device or sent to a server for conversion into text. For server-side processing, the original audio is deleted immediately after conversion, and users can delete the resulting text.
PhotographsPhotographs of obstacles taken during cleaning are temporarily stored on the device or a server and subsequently deleted. Retention periods vary by brand: for example, until the next cleaning session, until the user views the photograph, or for 24 hours.
Mapping informationMaps are generated from information such as the home’s layout to improve cleaning efficiency. They are stored on the robot vacuum, not on the user’s phone; some products also store maps on a server.

The PIPC stated that its inspection found no particular risk of privacy infringement in the collection, transmission, and storage of video, audio, photographs, and mapping information by the robot vacuums. However, some companies still needed to improve how they explain personal information processing to users and fulfill their legal obligations.

II. Findings and Remediation Requirements

1. Distinguish the legal bases for processing personal information

Some companies’ privacy policies described processing that does not require consent, such as processing for entering into or performing a contract, together with processing that requires user consent, without distinguishing their respective legal bases.

The PIPC required companies to improve their privacy policies, clearly distinguish the legal bases for processing personal information, and explain them in language users can understand.

2. Let users decide whether to consent to the use of personal information for service improvement

Some companies collected and used personal information for purposes such as improving their services without users making a separate choice. The PIPC required improvements so that users could decide in advance whether to consent.

Companies need to let users choose whether to consent before they start collecting or using the relevant information. Simply stating “for service improvement” in a privacy policy is insufficient.

3. Clearly explain overseas transfers and retention periods

Some companies used overseas data centers or similar facilities or services without explaining overseas transfers of personal information in their privacy policies. Others described retention periods only in broad terms, such as “until the purpose is achieved.” The PIPC required more specific explanations.

To inform users accurately, companies first need to establish which information is transferred overseas, which information is stored on servers, how long each category is retained, and when it is deleted, and then describe their actual practices in their privacy policies.

4. Appoint a domestic representative in South Korea as required and disclose the relevant information

Some overseas companies had not appointed a domestic representative in South Korea, or had appointed a representative that was not a legal entity established in South Korea.

The PIPC required the relevant companies to appoint a domestic representative in accordance with the Personal Information Protection Act and clearly list the representative’s name, address, contact details, and other relevant information in their privacy policies.

5. Improve access-rights management, access controls, and encryption in transit

The PIPC examined how companies grant, modify, and revoke access rights for staff handling personal information, as well as how they manage access logs, and prompted improvements. Specific remedial measures listed in the announcement included extending the retention period for access-rights grant records from 200 days to three years, and for access logs from 90 days to at least two years.

Some companies also had shortcomings in robot vacuum access controls and encryption of personal information in transit. The relevant latest models had been remediated, while remediation of other models was ongoing.

The inspection shows that the PIPC considers both how products actually process personal information and whether companies adequately inform users, protect their ability to choose, and implement the relevant management measures.

During the inspection, the PIPC guided companies to undertake remediation themselves. Most issues had been addressed or were being addressed. At its 19th plenary meeting on September 9, the PIPC decided to issue corrective recommendations for outstanding issues.

The PIPC will continue to verify remediation results and plans to inspect new features in the latest models on sale in the second half of 2026.

References

PIPC press release of September 14, 2026 and attachments: https://www.korea.kr/briefing/pressReleaseView.do?newsId=156781496; Article 63-2 of South Korea’s Personal Information Protection Act: https://www.law.go.kr/lsLinkCommonInfo.do?chrClsCd=010202&lsJoLnkSeq=1029334695.

Related reading

Kaamel
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2026 Kaamel Inc. All rights reserved.