Korean Law in English
Laws › Credit Information Use and Protection Act › SECTION 2 MyData Business

Credit Information Use and Protection Act — Article 22-9 (Code of conduct for MyData companies)

신용정보의 이용 및 보호에 관한 법률 제22조의9

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) No MyData company shall engage in any of the following conducts:

1. Forcing an individual credit data subject to transmit his or her personal credit information or improperly inducing him or her to transmit such information;

2. Other activities prescribed by Presidential Decree, which are likely to undermine the protection of credit data subjects or sound credit order.

(2) A MyData company shall prepare internal control standards to prevent conflicts of interest that may arise between an individual credit data subject and a MyData company in the course of performing the business affairs provided in Articles 11(6) and 11-2(6)3.

(3) No MyData company shall collect credit information to be provided to a credit data subject by using or retaining any of the following means in a manner prescribed by Presidential Decree:

1. A means of access defined in subparagraph 10 of Article 2 of the Electronic Financial Transactions Act, which is a means regarding a credit data subject, selected and used or managed by a credit information provider or user prescribed by Presidential Decree, a public institution prescribed by Presidential Decree under the Personal Information Protection Act (hereafter in this Article and Article 33-2 referred to as "credit information provider or user, etc."), or a MyData company;

2. Means prescribed by Presidential Decree, including the presentation of identification verifying the person in question or the use of a telephone or website as a means to verify the identity of the person in question.

(4) Where an individual credit data subject requests the transmission of his or her personal credit information to a MyData company, the credit information provider or user, etc. shall transmit the personal credit information of the individual credit data subject directly to such company by any method prescribed by Presidential Decree, which can ensure the safety and reliability of the provision of information.

(5) Notwithstanding paragraph (4), a credit information provider or user, etc. may transmit personal credit information to a MyData company through an intermediary agency prescribed by Presidential Decree, in cases prescribed by Presidential Decree in consideration of the size of the credit information provider or user, the frequency of commercial transactions, including financial transactions, etc.

(6) Where a credit information provider or user, etc. regularly transmits personal credit information pursuant to Article 33-2(4), he or she may have the MyData company bear the minimum necessary expenses.

(7) The procedures and methods for transmission under paragraphs (4) and (5) and the standards for the calculation of expenses under paragraph (6) shall be prescribed by Presidential Decree.[This Article Added on Feb. 4, 2020]

‹ Article 22-8All articlesArticle 23 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law