(1) A credit information company, etc. may entrust a third party with the business affairs of processing credit information. In such cases, Article 26(1) through (3) of the Personal Information Protection Act shall apply mutatis mutandis to the entrusted processing of personal credit information. <Amended on Feb. 4, 2020>
(2) A credit information company, etc. may entrust the processing of credit information; and Articles 19 through 21, 22-4 through 22-7, 22-9, 40, 43, 43-2, 45, 45-2, and 45-3 (including penalty provisions and provisions regarding administrative fines in relation to such Articles) shall apply mutatis mutandis to the processing of entrusted business affairs by the entrusted person (hereinafter referred to as "trustee"). <Amended on Mar. 11, 2015; Feb. 4, 2020>
(3) A credit information company, etc. prescribed by Presidential Decree, which intends to entrust the processing of credit information under paragraph (2), shall notify the Financial Services Commission of the scope of the credit information provided, etc., as prescribed by Presidential Decree.
(4) In providing any personal credit information to an agent in order to entrust the processing of credit information under paragraph (2), a credit information company, etc. shall take measures to protect information that can uniquely identify an individual, such as encryption, as prescribed by Presidential Decree. <Added on Mar. 11, 2015>
(5) Where a credit information company, etc. has provided any credit information to a trustee, it shall educate the trustee as prescribed by Presidential Decree to prevent the credit information from being lost, stolen, disclosed, altered, or compromised and reflect matters for the safe processing of credit information by the trustee in the entrustment contract. <Added on Mar. 11, 2015; Feb. 4, 2020>
(6) Where the trustee uses personal credit information or provides it to a third party, Article 26(5) of the Personal Information Protection Act shall apply. <Amended on Feb. 4, 2020>
(7) No agent shall further outsource any of the duties under paragraph (2) to any third party; provided, this shall not apply where the Financial Services Commission acknowledges within the scope not compromising the protection and safe processing of credit information. <Added on Mar. 11, 2015>[Title Amended on Feb. 4, 2020]