Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER IV DISTRIBUTION AND MANAGEMENT OF CREDIT INFORMATION

Credit Information Use and Protection Act — Article 20-2 (Retention period for personal credit information)

신용정보의 이용 및 보호에 관한 법률 제20조의2

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) A credit information provider or user shall manage personal credit information of a credit data subject as prescribed by Presidential Decree, including ensuring the right to access thereto, in such a manner that the personal credit information of the relevant credit data subject can be safely protected from the date a commercial transaction relationship including financial transactions (excluding employment relationship; hereinafter the same shall apply) is terminated until the time limit determined and publicly notified by the Financial Services Commission.

(2) Notwithstanding Article 21(1) of the Personal Information Protection Act, a credit information provider or user shall delete personal credit information of the relevant credit data subject from the management list within a maximum five year period from the date a commercial transaction relationship including financial transactions is terminated (where the purpose of the collection, provision, etc. of information is achieved before the lapse of the relevant period, within three months from the date such purpose is achieved); provided, this shall not apply in any of the following cases: <Amended on Feb. 4, 2020>

1. Where it is essential for performing any obligation under this Act or any other statute;

2. Where deemed necessary for the exigent interests of an individual's life, body, or property;2-2. When a pseudonymized information is used and retained for a period prescribed by Presidential Decree in consideration of the purpose of use, technical features of pseudonymization, the attributes of information, etc.;

3. Any of the following cases, as prescribed by Presidential Decree:a. For the payment of deposits and insurance proceeds:b. For preventing insurance fraudsters from repurchasing insurance;c. Where it is necessary to retain personal credit information due to the characteristics of the technology used to process personal credit information;d. Cases similar to those provided in items a through c where it is necessary to retain personal credit information.

(3) Where a credit information provider or user keeps personal credit information without deletion under the proviso of paragraph (2), he or she shall manage it as prescribed by Presidential Decree, such as separating it from the personal credit information of credit data subjects with whom he or she currently deals.

(4) When a credit information provider or user utilizes any personal credit information he or she keeps separately under paragraph (3), he or she shall notify such fact to the credit data subject.

(5) Types of personal credit information, period of management, methods and procedures for deletion, the criterion of the date a commercial transaction relationship including financial transactions is terminated, etc. under paragraphs (1) and (2) shall be prescribed by Presidential Decree.[This Article Added on Mar. 11, 2015]

‹ Article 20All articlesArticle 21 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law