(1) Where a financial company or an electronic financial business entity concludes or alters a contract with its subsidiary electronic financial business entity for affiliation, entrustment or outside orders (hereafter referred to as "outside order, etc." in this Article) in relation to electronic financial transactions (including where a subsidiary electronic financial business entity concludes or alters a contract with another subsidiary electronic financial business entity for outside orders, etc.), the entity shall meet the standards determined by the Financial Services Commission to ensure the safety and reliability of electronic financial transactions and the soundness of the financial company and electronic financial business entity. <Amended on Feb. 29, 2008; May 22, 2013>
(2) Where the contents of a contract under paragraph (1) are deemed likely to undermine the operational soundness of a financial company or an electronic financial business entity and the rights and interests of users, the Financial Services Commission may direct the financial company or electronic financial business entity to correct or supplement the relevant contents of the contract. <Amended on Feb. 29, 2008; May 22, 2013>
(3) When the Governor of the Financial Supervisory Service conducts an inspection of a financial company or an electronic financial business entity in relation to outside orders, etc. under paragraph (1), he or she may request its subsidiary electronic financial business entity to submit data pursuant to the standards determined by the Financial Services Commission. <Amended on Feb. 29. 2008; May 22, 2013>
(4) When a subsidiary electronic financial business entity fails to submit data under paragraph (3) or submit insufficient data, the Governor of the Financial Supervisory Service may investigate the relevant subsidiary electronic financial business entity. <Added on May 22, 2013>
(5) The Governor of the Financial Supervisory Service may request the following from a subsidiary electronic financial business entity, if deemed necessary for conducting an investigation under paragraph (4): <Added on May 22, 2013>
1. Submitting a written statement relating to matters subject to such investigation;
2. Submitting a ledger, document or other articles necessary for such investigation;
3. Attendance of a relevant person.
(6) A subsidiary electronic financial business entity entrusted with any duties related to the data protection of the information technology sector shall not re-entrust such duties to a third party; provided, this shall not apply to cases recognized by the Financial Services Commission within the extent not impairing the protection and safe processing of electronic financial transaction information. <Added on Oct. 15, 2014>
(7) Article 39 (4) shall apply mutatis mutandis to investigations conducted under paragraph (4). <Added on May 22, 2013; Oct. 15, 2014>[Title Amended on May 22, 2013]