Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER VI PROTECTION OF CREDIT DATA SUBJECT

Credit Information Use and Protection Act — Article 40 (Prohibitions for credit information company)

신용정보의 이용 및 보호에 관한 법률 제40조

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) No credit information company, etc. shall engage in any of the following acts: <Amended on Mar. 11, 2015; Feb. 4, 2020>

1. Deleted; <Feb. 4, 2020>

2. Deleted. <Feb. 4, 2020>

3. Deleted. <Feb. 4, 2020>

4. Finding out a certain person's whereabouts and contacts (hereinafter referred to as "whereabouts, etc.") or investigating his or her private life, other than commercial transaction relationships, including financial transactions; provided, where a credit information company permitted to engage in claims collection business finds out a certain person's whereabouts, etc. to conduct its business or it is allowed to find out a certain person's whereabouts, etc. pursuant to other statutes or regulations, this shall apply;

5. Using titles, including "intelligence service agent", "detective", or other titles similar thereto;

6. Deleted; <May 28, 2013>

7. Deleted; <Feb. 4, 2020>

(2) Where a credit information company, etc. transmits advertising information for profit-making purposes by using personal credit information or information necessary to identify an individual, Article 50 of the Act on Promotion of Information and Communications Network Utilization and Information Protection shall apply mutatis mutandis. <Added on Feb. 4, 2020>

‹ Article 39-4All articlesArticle 40-2 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law