(1) Where an identity verification agency creates and processes connecting information, it shall take physical, technical and administrative measures to ensure safety for creating and processing the connecting information in addition to the measures under Article 29 of the Personal Information Protection Act.
(2) Where an entity using connecting information provides services under the subparagraphs of Article 23-5 (1), in addition to measures pursuant to Article 29 of the Personal Information Protection Act, the entity shall store and manage the connecting information separately from resident registration numbers and take measures to ensure that the connecting information is not lost, stolen, leaked, falsified, altered, or damaged (hereinafter referred to as "safety measures").
(3) The Korea Media and Communications Commission may inspect the operation and management of physical, technical and administrative measures taken by an identity verification agency that meets the standards prescribed by the Presidential Decree, including the scale and turnover of connecting information created and processed, and safety measures taken by the entity using the connecting information. <Amended on Oct. 1, 2025>
(4) The Korea Media and Communications Commission may entrust the affairs regarding inspection under paragraph (3) to a specialized organization prescribed by Presidential Decree. <Amended on Oct. 1, 2025>
(5) Matters necessary for the physical, technical and administrative measures under paragraph (1) and the safety measures under paragraph (2) shall be prescribed by Presidential Decree.[This Article Added on Jan. 23, 2024]