Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER VI PROTECTION OF CREDIT DATA SUBJECT

Credit Information Use and Protection Act — Article 40-2 (Rules of conduct regarding pseudonymization and anonymization)

신용정보의 이용 및 보호에 관한 법률 제40조의2

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) A credit information company, etc. shall retain or erase additional information used for pseudonymization after separating it by means prescribed by Presidential Decree.

(2) A credit information company, etc. shall formulate and implement technical, physical, and managerial security measures, such as formulating an internal management plan and retaining access records, to protect pseudonymized personal credit information to protect such information from illegal access by a third party, change, damage, or destruction of entered data, and other risks, as prescribed by Presidential Decree.

(3) A credit information company, etc. may request the Financial Services Commission to examine whether the personal credit information is properly anonymized.

(4) Where the Financial Services Commission deems that the personal credit information is properly anonymized according to the results of an examination under paragraph (3), it shall be presumed that the relevant personal credit information is one that no longer uniquely identifies the relevant credit data subject.

(5) The Financial Services Commission may entrust the duty of examination under paragraph (3) and recognition under paragraph (4) to a data agency under Article 26-4, as prescribed by Presidential Decree.

(6) No credit information company, etc. shall process pseudonymized information to uniquely identify an individual for profit-making or improper purposes.

(7) Where it becomes possible to uniquely identify an individual in the process of using pseudonymized information, a credit information company, etc. shall immediately cease the processing of the information, and shall immediately erase the information that can uniquely identify an individual.

(8) Where a credit information company, etc. pseudonymizes or anonymizes personal credit information, it shall retain the records of measures for three years according to the following classifications:

1. Where it pseudonymizes personal credit information:a. Date of pseudonymization;b. Items of pseudonymized information;c. Reasons and grounds for the pseudonymization;

2. Where it anonymized personal credit information:a. Date of anonymization;b. Items of anonymized information;c. Reasons and grounds for anonymization.[This Article Added on Feb. 4, 2020]

‹ Article 40All articlesArticle 40-3 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law