Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER IV DISTRIBUTION AND MANAGEMENT OF CREDIT INFORMATION

Credit Information Use and Protection Act — Article 20 (Clarification of accountability of credit information management and archiving of business processing records)

신용정보의 이용 및 보호에 관한 법률 제20조

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) A credit information company, etc. shall comply with the standards for management of credit information determined by the Financial Services Commission with regard to collection, processing, use, protection, etc. of credit information. <Amended on Mar. 11, 2015>

(2) A credit information company, etc. shall retain the records concerning the following matters for three years according to the following classifications: <Amended on Feb. 4, 2020>

1. Where it collects or uses personal credit information:a. The date of collection and use;b. Items of information collected and used;c. Reasons and grounds for collection and use;

2. Where it provides or is provided with personal credit information:a. The date of provision or receipt;b. Items of information it provides or is provided with;c. Reasons and grounds for provision and receipt;

3. Where it destroys personal credit information:a. The date of destruction;b. Items of information destroyed;c. Reasons and grounds for destruction;

4. Other matters prescribed by Presidential Decree.

(3) A credit information company, a MyData company, a claims collection agency, a credit information collection agency, and a credit information provider or user prescribed by Presidential Decree shall appoint at least one credit information administrator or guardian to perform the tasks prescribed in paragraph (4); provided, a person prescribed by Presidential Decree in consideration of total assets, the number of employees, etc. shall appoint a credit information administrator or guardian as his or her executive officer (including persons who hold a position that has general supervision and control of the management and protection of credit information, as prescribed by Presidential Decree). <Amended on Mar. 11, 2015; Feb. 4, 2020>

(4) A credit information administrator or guardian under paragraph (3) shall perform the following duties: <Added on Mar. 11, 2015; Feb. 4, 2020; Mar. 14, 2023; Mar. 10, 2026>

1. The following duties in cases of personal credit information:A. Business affairs under Article 31(4)1 and 4 through 7 of the Personal Information Protection Act;b. Inspection for compliance with the statutes and regulations related to the protection of credit information by its executive officers and employees, exclusive solicitors, etc.;c. Other duties prescribed by Presidential Decree to manage and protect credit information;

2. Regular inspection and improvement of the status and practice of the management of credit information, such as the collection, keeping, provision, and deletion thereof;a. Formulation and implementation of plans for the management and protection of credit information, such as the collection, keeping, provision, and deletion thereof;b. Regular inspection and improvement of the status and practice of the management of credit information, such as the collection, keeping, provision, and deletion thereof;c. Exercise of rights of credit data subjects, such as the access to and the request for correction of credit information, and damage relief;d. Establishment and operation of internal control system to prevent disclosure, etc. of credit information;e. Formulation and execution of a plan to protect credit information for its executive officers and employees, exclusive solicitors, etc.;f. Inspection for compliance with the statutes and regulations related to the protection of credit information by its executive officers and employees, exclusive solicitors, etc.;g. Other duties prescribed by Presidential Decree to manage and protect credit information;

3. Deleted. <Feb. 4, 2020>

4. Deleted. <Feb. 4, 2020>

5. Deleted. <Feb. 4, 2020>

6. Deleted; <Feb. 4, 2020>

7. Deleted; <Feb. 4, 2020>

(5) Article 31(5) and (7) of the Personal Information Protection Act shall apply mutatis mutandis to the performance of the duties of a credit information administrator or guardian. <Amended on Feb. 4, 2020; Mar. 14, 2023; Mar. 10, 2026>

(6) A credit information administrator or guardian of a credit information company, etc. shall regularly inspect the status of the management and protection of personal credit information processed by the credit information company, etc. in accordance with the procedures and methods prescribed by Presidential Decree and shall report the inspection results to the Financial Services Commission. <Added on Feb. 4, 2020>

(7) Qualifications for credit information administrators or guardians and other matters necessary for designation under paragraph (3) and methods of submission under paragraph (6) shall be prescribed by Presidential Decree. <Amended on Mar. 11, 2015; Feb. 4, 2020>

(8) Where a customer information officer appointed in accordance with Article 48-2(6) of the Financial Holding Companies Act, meets the qualifications set forth in paragraph (6), he or she shall be deemed a credit information administrator or guardian designated under paragraph (3). <Amended on Mar. 11, 2015; Feb. 4, 2020>

‹ Article 19All articlesArticle 20-2 ›

Korean original (law.go.kr) · Get articles as JSON via API