Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER VI PROTECTION OF CREDIT DATA SUBJECT

Credit Information Use and Protection Act — Article 39-4 (Notification of divulgence of personal credit information)

신용정보의 이용 및 보호에 관한 법률 제39조의4

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) Where a credit information company, etc. becomes aware that personal credit information has been divulged for purposes other than business purposes, it shall notify the relevant credit data subject without delay. In this case, the matters to be notified shall apply mutatis mutandis the matters prescribed in each subparagraph of Article 34(1) of the Personal Information Protection Act: <Amended on Feb. 4, 2020>

1. Deleted; <Feb. 4, 2020>

2. Deleted. <Feb. 4, 2020>

3. Deleted. <Feb. 4, 2020>

4. Deleted. <Feb. 4, 2020>

5. Deleted. <Feb. 4, 2020>

(2) A credit information company, etc. shall prepare countermeasures to minimize the damage in the event that personal credit information is disclosed and take necessary measures. <Amended on Feb. 4, 2020>

(3) A credit information company, etc. shall report without delay to the Financial Services Commission or an institution prescribed by Presidential Decree (hereinafter referred to as the "Financial Services Commission, etc." in this Article) the notification under paragraph (1) and the results of measures taken under paragraph (2) when personal credit information of a scale prescribed by Presidential Decree or more has been divulged. In such cases, the Financial Services Commission, etc. may provide technical support for preventing the spread of damage and restoring the damage. <Amended on Feb. 4, 2020>

(4) Notwithstanding paragraph (3), commercial enterprises and corporations under Article 45-3(1) shall report to the Protection Commission or an institution prescribed by Presidential Decree (hereinafter referred to as "Protection Commission, etc." in this Article). <Added on Feb. 4, 2020>

(5) When the Financial Services Commission, etc. receives a report pursuant to paragraph (3), it shall notify the Personal Information Protection Commission thereof. <Amended on Jul. 26, 2017, Feb. 4, 2020>

(6) The Financial Services Commission or the Protection Commission may investigate the measures taken by a credit information company, etc. pursuant to paragraph (2), and if it is determined that such measures are inadequate, the Financial Services Commission or the Protection Commission may request correction. <Amended on Feb. 4, 2020>

(7) Matters necessary for the timing, methods, and procedures of notification under paragraph (1) shall be prescribed by Presidential Decree. <Amended on Feb. 4, 2020>[This Article Added on Mar. 11, 2015][Title Amended on Feb. 4, 2020][Moved from Article 39-2 <Feb. 4, 2020>]

‹ Article 39-3All articlesArticle 40 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law