Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER VI PROTECTION OF CREDIT DATA SUBJECT

Credit Information Use and Protection Act — Article 33-2 (Request for transmission of personal credit information)

신용정보의 이용 및 보호에 관한 법률 제33조의2

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) An individual credit data subject may request a credit information provider or user, etc. to transmit personal credit information on himself or herself in its possession to any of the following persons:

1. The credit data subject himself or herself2. MyData companies;

3. A credit information provider or user prescribed by Presidential Decree;

4. A personal credit rating company;

5. Such other persons similar to those provided in subparagraphs 1 through 4 as prescribed by Presidential Decree.

(2) The scope of personal credit information to be transmitted by an individual credit data subject pursuant to paragraph (1) shall be prescribed by Presidential Decree, in consideration of all the following factors:

1. It shall be credit information processed between the relevant credit data subject (including persons who process credit information on the credit data subject under statutes or regulations, etc.; hereafter in this subparagraph this shall apply) and a credit information provider or user, etc., and shall fall under any of the following items:a. Information collected by a credit information provider or user from a credit data subject;b. Information provided by a credit data subject to a credit information provider or user, etc.;c. Information generated from the relationship of rights and obligations between a credit data subject and a credit information provider or user, etc.;

2. It shall be credit information processed by a computer or other information processing device;

3. It shall not be credit information separately generated or processed by a credit information provider or user based on personal credit information.

(3) A credit information provider or user, etc. in receipt of a request to transmit personal credit information from the credit data subject in accordance with paragraph (1), shall without delay transmit the personal credit information about the credit data subject in a form that makes it possible for him or her to process it with a computer or any other information processing device, notwithstanding Article 32 and the related provisions of any of the following Acts:

1. Article 4 of the Act on Real Name Financial Transactions and Confidentiality;

2. Article 81-13 of the Framework Act on National Taxes;

3. Article 86 of the Framework Act on Local Taxes;

4. Article 18 of the Personal Information Protection Act;

5. Other relevant provisions prescribed by Presidential Decree which are similar to those referred to in subparagraphs 1 through 4.

(4) Where a credit data subject requests the transmission of his or her personal credit information pursuant to paragraph (1), he or she may request a credit information provider or user, etc. to regularly transmit his or her personal credit information in the same details so as to ensure the accuracy and up-to-dateness of the relevant personal credit information.

(5) Where an individual credit data subject makes a request for transmission under paragraph (1) to a person falling under any subparagraph of paragraph (1), he or she shall do so in the form of an electronic document or any other method ensuring safety and reliability by specifying all the following matters:

1. A credit information provider or user, etc. who receives a request for transmission;

2. Personal credit information requested to be transmitted;

3. A person who receives personal credit information upon a request for transmission;

4. Whether such information is requested on a regular basis, and the frequency of such transmission;

5. Matters similar to those prescribed in subparagraphs 1 through 4, which are prescribed by Presidential Decree.

(6) A credit information provider or user, etc. who has provided personal credit information under paragraph (3) need not notify the relevant credit data subject of the fact that personal credit information has been transmitted, notwithstanding Article 32(7) and provisions of the following statutes:

1. Article 4-2 of the Act on Real Name Financial Transactions and Confidentiality;

2. Other provisions of statutes prescribed by Presidential Decree regarding the processing of personal credit information.

(7) An individual credit data subject may withdraw a request for transmission made under paragraph (1).

(8) A credit information provider or user, etc. in receipt of a request to transmit personal credit information from a credit data subject under paragraph (1) may refuse to comply with the request for transmission or may cease or suspend the transmission in cases prescribed by Presidential Decree, including where the identity of the credit data subject is not authenticated.

(9) The methods of requesting transmission under paragraphs (1) and (4), the deadline and methods of transmission under paragraph (3), the methods of withdrawing request for transmission under paragraph (7), and the methods of refusal, cessation, and suspension under paragraph (8) shall be prescribed by Presidential Decree.[This Article Added on Feb. 4, 2020]

‹ Article 33All articlesArticle 34 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law