Pangyo: Software companies clustered in this district south of Seoul sell cloud services, games and enterprise platforms into Europe, and their lawyers have spent the summer reading a treaty that nobody can yet invoke.
Maros Sefcovic and Yeo Han-koo signed the digital trade agreement in Brussels on 10 June 2026, at the eleventh summit between the Union and the Republic of Korea. The text guarantees cross-border data flows, recognises electronic contracts and signatures, bars forced data localisation and forbids either side from demanding source code as a condition of market access.
Signature does not switch any of that on. The European Parliament must consent, the Council must then formally conclude the agreement, and both parties must exchange written notifications confirming their internal procedures. No entry-into-force date exists. Firms on both sides operate today under the 2011 free trade agreement and the 2021 adequacy decision, neither of which covers source code or localisation.
The economics behind the treaty are substantial. Goods trade between the two partners passed 124 billion euros in 2025, with European imports at 69.7 billion and exports at 54.5 billion, which makes Korea the Union’s eighth largest goods partner. Services and data move alongside those goods and, until now, without dedicated rules.
Negotiators also launched a competitiveness partnership covering investment, supply chains, advanced technologies, energy and innovation, and set up a high-level economic dialogue for economic security and industrial policy. The digital trade agreement functions as the legally binding core of that wider architecture.
Data flows dominated the coverage, and data flows were the easiest chapter to agree. Both jurisdictions already run comprehensive privacy laws, Korea holds a European adequacy finding, and neither side had much appetite for a fight over transfers it had already settled.
The harder questions sit in procurement and certification. Korea’s cloud security assurance programme governs which providers may serve public institutions, and European vendors have long argued that its requirements favour domestic operators. Network usage fee proposals aimed at large content providers have moved through the Korean assembly for years. Neither issue disappears because a treaty prohibits source code transfer.
The agreement also carries the standard carve-outs. Prudential measures, public policy objectives and national security exceptions remain available to both parties. Those clauses give governments room to regulate, and they give lawyers room to argue about where regulation ends and restriction begins.
Brussels has a further motive that has little to do with Seoul. The Commission wants a reusable template for digital chapters with other partners in the region, and a ratified Korean text would give it one. A text stuck awaiting parliamentary consent gives it nothing.
Members of the European Parliament will scrutinise the data protection safeguards closely, as they did with earlier digital provisions. Their consent is likely rather than certain, and the timetable depends on committee scheduling as much as on substance.
Until the notifications cross, the Pangyo lawyers keep advising clients on the law that exists rather than the law that was signed.





