Korean Law in English
Laws › Credit Information Use and Protection Act › CHAPTER VIII SUPPLEMENTARY PROVISIONS

Credit Information Use and Protection Act — Article 45-3 (Request for submission of data and investigation by Protection Commission)

신용정보의 이용 및 보호에 관한 법률 제45조의3

This English translation is based on the Korean text effective 2026-08-13. The Korean law has since been amended (current version effective 2026-09-11) — check the Korean original.

(1) In any of the following cases, the Protection Commission may request a credit information provider or user (hereinafter referred to as "enterprise or corporation involved in commercial transactions") exempt from supervision by the Financial Services Commission to submit data, including relevant articles and documents, pursuant to Article 45:

1. Where an enterprise or corporation involved in commercial transactions becomes aware of any violation, or suspicion of violation, of any of the following regulations (hereinafter referred to as "regulations for protecting information in commercial transactions"):a. Articles 15 and 17;b. Articles 19 and 20-2;c. Articles 32, 33, 34, 36, 37, 38, 38-3, 39-4, 40-2, and 42;

2. Where the Protection Commission receives a report or petition about a violation of the regulations for protecting information in commercial transactions by an enterprise or corporation involved in commercial transactions;

3. Other cases prescribed by Presidential Decree as necessary for protecting personal credit information.

(2) If an enterprise or corporation involved in commercial transactions fails to submit data required under paragraph (1) or if it is deemed to have violated the regulations for protecting information in commercial transactions, the Protection Commission may require public officials of the Protection Commission to enter the office or place of business of the enterprise or corporation or a person related to such violation, and to investigate the current status of business affairs, books, documents, etc. In such cases, a public official who conducts an inspection shall carry identification indicating his or her authority and present it to relevant persons.

(3) The Protection Commission shall not provide any third party with the documents, data, etc. furnished or collected pursuant to paragraph (1), nor disclose them to the general public, except as provided in this Act.

(4) Where the Protection Commission receives data via information and communications networks or digitalizes the collected data, etc., it shall take systematic and technical security measures to prevent any leakage of personal information, trade secrets, etc.[This Article Added on Feb. 4, 2020]

‹ Article 45-2All articlesArticle 45-4 ›

Korean original (law.go.kr) · Get articles as JSON via API

For AI agents and developers — get this article as JSON, with the English and current Korean effective dates and an outdated-translation flag, from the korea-law API or as an MCP tool: https://mcp.apify.com?tools=kr-data/korea-law