(1) Where a provider of information and communications services needs authority to access (hereinafter referred to as "access authority") information stored and functions installed in mobile devices of users in order to provide the relevant services, the provider shall inform users of the following so that users may clearly recognize such matters, and shall obtain consent of users:
1. In the case of access authority certainly necessary to provide the relevant services:(a) Items of the information and functions for which access authority is necessary;(b) Grounds that access authority is necessary;
2. In the case of access authority not certainly necessary to provide the relevant services:(a) Items of the information and functions for which access authority is necessary;(b) Grounds that access authority is necessary;(c) Fact that users may give no consent to the permission for access authority.
(2) No provider of information and communications services shall refuse to provide the relevant services to users on the ground that the users give no consent to the establishment of access authority not certainly necessary to provide the relevant services.
(3) Persons manufacturing and providing a basic operating system (referring to an operating environment in which software installed in mobile devices can be run) of mobile devices, manufacturers of mobile devices, and persons manufacturing and providing a software for mobile devices shall take measures necessary for protecting user information, such as devising methods for users to give or revoke consent to access authority where the provider of information and communications services intends to access the information stored and functions installed in mobile devices.
(4) The Korea Media and Communications Commission may conduct compliance inspections to ascertain that access authority is set for relevant services in accordance with paragraphs (1) through (3). <Added on Jun. 12, 2018; Oct. 1, 2025>
(5) The scope of, and methods for consenting to, access authority referred to in paragraph (1), the measures necessary for protecting user information referred to in paragraph (3), and other necessary matters shall be prescribed by Presidential Decree. <Amended on Jun. 12, 2018>[This Article Added on Mar. 22, 2016]