Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER III COLLECTION AND PROCESSING OF CREDIT INFORMATION

Credit Information Use and Protection Act — Article 17 (Entrustment of processing)

신용정보의 이용 및 보호에 관한 법률 제17조

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) A credit information company, etc. may entrust a third party with the business affairs of processing credit information. In such cases, Article 26(1) through (3) of the Personal Information Protection Act shall apply mutatis mutandis to the entrusted processing of personal credit information. <Amended on Feb. 4, 2020>

(2) A credit information company, etc. may entrust the processing of credit information; and Articles 19 through 21, 22-4 through 22-7, 22-9, 40, 43, 43-2, 45, 45-2, and 45-3 (including penalty provisions and provisions regarding administrative fines in relation to such Articles) shall apply mutatis mutandis to the processing of entrusted business affairs by the entrusted person (hereinafter referred to as "trustee"). <Amended on Mar. 11, 2015; Feb. 4, 2020>

(3) A credit information company, etc. prescribed by Presidential Decree, which intends to entrust the processing of credit information under paragraph (2), shall notify the Financial Services Commission of the scope of the credit information provided, etc., as prescribed by Presidential Decree.

(4) In providing any personal credit information to an agent in order to entrust the processing of credit information under paragraph (2), a credit information company, etc. shall take measures to protect information that can uniquely identify an individual, such as encryption, as prescribed by Presidential Decree. <Added on Mar. 11, 2015>

(5) Where a credit information company, etc. has provided any credit information to a trustee, it shall educate the trustee as prescribed by Presidential Decree to prevent the credit information from being lost, stolen, disclosed, altered, or compromised and reflect matters for the safe processing of credit information by the trustee in the entrustment contract. <Added on Mar. 11, 2015; Feb. 4, 2020>

(6) Where the trustee uses personal credit information or provides it to a third party, Article 26(5) of the Personal Information Protection Act shall apply. <Amended on Feb. 4, 2020>

(7) No agent shall further outsource any of the duties under paragraph (2) to any third party; provided, this shall not apply where the Financial Services Commission acknowledges within the scope not compromising the protection and safe processing of credit information. <Added on Mar. 11, 2015>[Title Amended on Feb. 4, 2020]

‹ Article 16All articlesArticle 17-2 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law