Tech for People
We leverage proprietary technology to securely protect personal data and
provide stable, accessible services for everyone
provide stable, accessible services for everyone
Tech for People
Data Privacy
- Environment
- Communication
- Certification
- Research
Environment, Communication, Certification, Research
NAVER safeguards user privacy and data across the full service lifecycle, from design to retirement, and upholds the highest standards of compliance.
Privacy Report
-
Personal Information Protection ReportA report on our activities and initiatives to protect user privacy and personal data새창 열림
-
Privacy WhitepaperPresents the findings of our specialized research into advancing user privacy protection새창 열림
-
Transparency ReportDiscloses user data statistics and includes external audits of our privacy protection compliance새창 열림
Privacy Enhancement Rewards (PER)
Personal Information Protection
Initiatives
Initiatives
Information Security
NAVER protects user information through a comprehensive and multi-layered security framework.

NAVER Security Whitepaper
An annual whitepaper transparently disclosing NAVER's key security activities and issues

NAVER Bug Bounty program
A bug bounty program to proactively identify and fix vulnerabilities before security incidents occur

DevSecOps
Toothless & NShiftkey
Our DevSecOps platform that automates code security reviews and vulnerability checks across development cycle

User protection
NAVER Safe Browsing
NAVER Safe Browsing system has protected all users from phishing and online threats since 2019
Information Security
Certifications
NAVER holds globally recognized certifications that validate our security practices and demonstrate our commitment.

Information Security and Personal Information Protection Management System Certification
ISMS-P
Obtained for comprehensive measures in information security & personal data protection confirmed to be compliant with certification standards
-
ScopeOperational management of NAVER services (including Customer Center and Business services, and e-Documents) and the handling of B2C and B2B user data
-
Validity periodOctober 5, 2022 - October 4, 2025

Information Security Management System Certification
ISMS
Obtained for a series of measures and activities in information security confirmed to be compliant with certification standards
-
ScopeOperation of NAVER Data Center (GAK)
-
Validity periodOctober 16, 2024 ~ October 15, 2027
Global Personal Information Protection Management System Certification
APEC CBPR
In December 2022, NAVER became the first Korean company to obtain the APEC Cross-Border Privacy Rules (CBPR) certification
-
ScopeOverall privacy policy and management across 79 NAVER services, including NAVER Portal, NAVER Business Partner Service, and Band
-
Validity periodMarch 21, 2025 ~ March 20, 2026


International Information Security Management System Certification
ISO / IEC 27000 series
NAVER is certified under ISO/IEC international standards for its information security. In 2007, NAVER was the world's first to receive the ISO 27001 certification for personal information and has since expanded to include ISO 27017, 27018, and 27701.
-
ScopeDevelopment, maintenance, and operation of all NAVER Corp. services, including all security activities for protecting user personal information
-
Validity periodSeptember 10, 2024 ~ September 9, 2027

Service and Organization Controls
SOC
A framework where an independent auditor verifies that our data and privacy protection controls are designed and operating effectively
-
NAVER was the first company in Korea to obtain SOC 2 and SOC 3 certifications in FY2012 and has maintained them ever since

PCI DSS
NAVER Pay complies with the Payment Card Industry Data Security Standard (PCI DSS), the global benchmark for payment card information protection
NAVER's AI Safety
Our AI ethics principles
NAVER will create cutting edge artificial intelligence ("AI") technology that can be easily and conveniently used as a daily tool by everyone. We wish to open new possibilities and opportunities by continuously striving to provide users with new experiences of connectivity. To this end, every one of us at NAVER will respect the following ethics principles in developing and using AI.
-
NAVER develops and uses AI as a daily tool for humanity. NAVER will prioritize human-centered values in developing and using AI.
We have developed technology with the purpose of improving the daily lives of our users. We are also advancing AI so it can be used as a daily tool by people. We recognize that while AI can make our lives convenient, it is also not infallible like all other technologies used today. We will continuously follow and improve our AI so that it can be used as a daily tool by humanity. -
In consideration of the value of diversity, NAVER will endeavor to develop and use AI that does not unjustly discriminate against anyone, including our users.
We have created technology and services that enable connections to carry greater meaning through diversity. Throughout this process, we have provided various new possibilities and opportunities for users and endeavored to prevent undue discrimination that cannot be reasonably justified. We will continue this commitment as it relates to our AI services by striving to prevent unjust discrimination and providing experience and opportunities in which diverse values coexist. -
NAVER will assist the convenient use of AI, while also fulfilling our responsibility to provide reasonable explanation to users when they interact with AI in their daily lives. NAVER acknowledges that the method and level of reasonable explainability for AI can vary, depending on the context in which the AI is used, and will take this into consideration as we endeavor to achieve this objective.
We do not view the AI we develop as a technology for technology's sake, but a tool that anyone should be capable of using with ease regardless of whether they have technical knowledge. While pursuing convenience in the service we provide, NAVER will also endeavor to explain our AI service in a manner that users can easily understand upon their request or when necessary. -
With safety in mind, NAVER will design AI services that do not cause harm to people at any stage of the service.
We will pay attention to safety during all stages of designing and testing our services, including after the service is deployed, to prevent a situation where AI as a daily tool threatens life or causes physical harm to people. -
In the process of developing and using AI, NAVER will endeavor to protect the privacy of users beyond the responsibility and obligation proscribed under law that protects personal information. In addition, NAVER will apply designs in consideration of data security during all stages of our AI service, including its development.
NAVER actively promotes the protection of users' privacy beyond what is required and obliged under the law protecting personal information. We also apply designs in consideration of data security during all stages of our services so that users do not have to be concerned about data breaches while using the services. NAVER will endeavor to allow users to freely utilize our AI services to make their lives more convenient without having to be concerned about their privacy and data security.
NAVER ASF 2.0
At NAVER, human-centered values are at the core of how we develop and use AI. We are advancing cutting-edge AI technology to make it an accessible, everyday tool for everyone.
Through “NAVER ASF 2.0”, we will continue to refine and advance our service-centered AI Safety governance, giving concrete shape to AI Safety across our On-Service AI.
Through “NAVER ASF 2.0”, we will continue to refine and advance our service-centered AI Safety governance, giving concrete shape to AI Safety across our On-Service AI.
-
The Evolving Landscape of AI Safety
ASF 2.0 is the service-centered AI Safety Framework we have established to respond to these shifts—the advancement of On-Service AI, the spread of multi-model environments, and changes in the policy and regulatory environment.
Overview of ASF 2.0
ASF 2.0 is built on three pillars—defining and classifying risk, identifying and assessing risk, and managing and mitigating risk—along with an operational structure that ensures these pillars work as intended in practice. -
Building on the misuse risks defined in “NAVER ASF Beta”, we have refined and classified them as risks that may arise within AI services. On this basis, we apply the AI Risk Taxonomy, which designates users, the public, and the AI service ecosystem as subjects of protection and defines a distinct protected value for each.
AI Risk Taxonomy
NAVER organizes the user-centered values articulated in the “NAVER AI Ethics Principles” into three protected values, and continuously strengthens safety through both pre-launch and post-launch impact assessments for AI Safety. -
NAVER identifies risks that may arise within a service by systematically organizing both the risks predefined through the AI Risk Taxonomy and those that emerge—or may emerge—during the planning, development, and operation of the service.
AI Impact Assessment Matrix
The AI Impact Assessment Matrix considers the entire lifecycle of an AI service. It first distinguishes whether the service falls within a special domain—corresponding to high-risk areas—or a general domain. Services in the general domain are then further divided by whether their scope of use is broad or narrow, and safety measures are determined based on the level of impact on subjects of protection and protected values. -
Safety Evaluation
After identifying both the risks predefined through the AI Risk Taxonomy and those that may arise during service operation, we conduct a safety evaluation.
User Communication
NAVER is committed to making AI convenient for everyone. Where AI is used in daily life, we fulfill our accountability to provide users with reasonable explanations. -
Consultation on Human-centered AI's Ethics and Safety Considerations 2.0 (CHEC 2.0)
In establishing ASF 2.0, we strengthened the safety of AI models and services as well as user communication regarding AI-generated content, and developed the “Consultation on Human-centered AI's Ethics and Safety Considerations 2.0 (CHEC 2.0)”, which addresses AI Safety alongside AI ethics.
CHEC 2.0 is a company-wide operational structure that provides guidance for individual service teams to implement AI Safety, while enabling collaboration between service teams and the AI Safety Center to meet the level of AI Safety expected by society. -
ASF 2.0 has advanced the existing AI Safety governance structure into a three-layer management and oversight system. Alongside this, we collaborate with academia, government bodies, and domestic and international AI safety networks, incorporating diverse external perspectives into NAVER ASF.
-
NAVER is committed to organizing our experience and know-how in AI Safety into various deliverables and sharing them with users and the broader public.
We will work to ensure that the experience accumulated through this process does not remain merely the asset of a single company, but becomes a shared asset for all of society. -
NAVER recognizes that while AI can make our lives more convenient, it is not perfect—like everything else in the world. We will continuously oversee and improve our AI so that it can serve as a daily tool for humanity.
User Protection and
Satisfaction
NAVER is committed to protecting users from harmful digital environments and fostering a safe, positive online space for everyone.
Blocking Harmful Content (Green-eye)
Our proprietary AI filtering system, developed in 2017, automatically detects and removes harmful content
Copyright Protection
Our copyright protection framework safeguards creators' rights with filtering systems and proactive measures to prevent unauthorized distribution
Malicious Comment Filtering (AI Cleanbot)
Launched in 2019 as an industry first, our AI Cleanbot automatically detects and filters malicious comments in real time
Auto Spam Content Detection System
Our AI-powered spam detection system operates 24/7 to automatically identify and remove spam content
User communication channel
Communication to establish a preemptive response process against risk factors infringing on the rights and interests of users
-
Customer Center24/7 support via ARS, chat, and AI-powered smartbotst to enhance user convenience새창 열림
-
Customer Center24/7 support via ARS, chat, and AI-powered smartbotst to enhance user convenience새창 열림
-
Post Reporting CenterA dedicated channel to report harmful content, including harmful Post, illegal footage, disinformation, and impersonation새창 열림
-
Green InternetA platform sharing NAVER's user protection initiatives and outcomes새창 열림
Service Stability and Reliability
NAVER is committed to maintaining service stability and ensuring business continuity, even in the event of natural disasters and other major disruptions.
24/7 Monitoring System
A 24/7 system that continuously monitors services and IT infrastructure for a rapid response to any disruption
Emergency response system
A robust emergency response framework with real-time monitoring ensures stable service access during national disasters and major events
Service and Infrastructure Redundancy
Our services and infrastructure are designed with redundancy for high availability and rapid recovery during emergencies
Digital Inclusion
We are committed to making our technology and services accessible to everyone, regardless of physical or environmental barriers.
NULI : A Platform for Digital Accessibility
A platform providing hands-on experiences, standards, guidelines, education, and development tools to improve accessibility for all
CLOVA CareCall
An AI conversational care service supporting the well-being of seniors and other vulnerable individuals
CLOVA Note
An AI service that transcribes voice to text from meetings or lectures and generates automatic summaries

