(1) A credit information company, etc. shall formulate and implement technological, physical, and administrative security measures, as prescribed by Presidential Decree, with respect to the unlawful access by a third party to the credit information computer system (including the common computer network for credit information under Article 25(6); hereinafter the same shall apply) and alteration, compromise and destruction or any other danger in relation to the information entered. <Amended on Mar. 11, 2015>
(2) Where a credit information provider or user exchanges credit information with another credit information provider or user or any personal credit rating company, sole proprietor credit rating company, or corporate credit inquiry company, such credit information provider or user shall enter into an agreement containing measures concerning the management of credit information security, as determined and publicly notified by the Financial Services Commission. <Amended on Feb. 4, 2020>