(1) Any of the following persons (in cases falling under subparagraph 10, including persons who issue prepaid electronic payment means to which the relevant provisions apply mutatis mutandis under the proviso of Article 28 (4)) shall be subject to an administrative fine not exceeding 50 million won: <Amended on Oct. 15, 2014; Apr. 18, 2017; Sep. 14, 2023; Dec. 16, 2025>
1. A person who fails to either perform his or her duties with the due care of a good manager or comply with the standards determined by the Financial Services Commission, in violation of Article 21 (1) or (2);
2. A person who fails to separately manage prepaid recharge funds, in violation of Article 25-2 (1);
3. A person who transfers separately managed prepaid recharge funds or provides it as security, in violation of Article 25-2 (6);
4. A person who fails to externally manage funds subject to settlement, in violation of Article 25-4 (1);
5. A person who transfers funds subject to settlement or provides such funds as collateral, in violation of Article 25-4 (5);
6. A person who fails to obtain permission for change or file for registration of a change, in violation of Article 33-3;
7. A person who uses the name "electronic currency", in violation of Article 36;
8. A person who grants economic benefits, such as issuance at a discount or payment of accumulated points for prepaid electronic payment means, in violation of subparagraph 1 of Article 36-2;
9. A person who grants economic benefits and fails to separately manage the corresponding amount, in violation of subparagraph 2 of Article 36-2;
10. A person who fails to notify the relevant fact within the period, in violation of subparagraph 3 of Article 36-2;
11. A person who commits an act likely to impede user protection or sound transaction order, in violation of subparagraph 4 of Article 36-2;
12. A person who fails to comply with an order for corrective action under Article 36-3(2);
13. A person who fails to comply with Article 37(5);
14. A person who refuses, interferes with, or evades an inspection, submission of materials, demand for attendance, or investigation under Article 39(3) (including cases applied mutatis mutandis under Article 29(2)) or Article 40(3) or (4);
15. A person who fails to submit a report or submits a false report, in violation of Article 42(1).
(2) An administrative fine not exceeding 20 million won shall be imposed on a person who falls under any of the following subparagraphs: <Amended on Oct. 15, 2014; Apr. 18, 2017; Dec. 16, 2025>
1. A person who fails to have the payment of electronic funds transfer take effect, in violation of Article 13 (2);
2. A person who fails to appoint the chief information security officer or appoint an executive officer as the chief information security officer, in violation of Article 21-2 (1) or (2);
3. A person who has the chief information security officer concurrently perform duties in the information technology sector other than those under Article 21-2 (4) or himself or herself concurrently performs duties in such sector, in violation of paragraph (3) of that Article;
4. A person who fails to analyze and assess the vulnerabilities of the electronic financial infrastructure, in violation of Article 21-3 (1);
5. A person who fails to formulate and implement a plan for complying with complementary measures, in violation Article 21-3 (2);
6. A person who fails to destroy any record of electronic financial transactions, in violation of Article 22 (2);
7. A person who makes a re-entrustment to a third party, in violation of Article 40 (6).
8. A person who fails to publicly disclose matters necessary for the protection of users, etc., in violation of Article 42-2 (2).
(3) Any of the following persons (including any person issuing a prepaid electronic payment means applicable mutatis mutandis pursuant to Article 28 (4), in cases falling under subparagraphs 1, 6 through 8, and 10) shall be punished by an administrative fine not exceeding 10 million won: <Amended on Apr. 18, 2017>
1. Any person who fails to deliver a document stating the details of a transaction, in violation of Article 7 (2);
2. Any person who fails to inform the relevant user of the causes of an error and results of correction, in violation of Article 8 (2) and (3);
3. Any person who transfers a prepaid electronic payment means or electronic currency to a third party or provides it as a security, in violation of Article 18 (2);
4. Any person who fails to submit a plan for the information technology sector, in violation of Article 21 (4);
5. Any person who fails to report the findings from analysis and assessment of vulnerability in electronic financial infrastructure, in violation of Article 21-3 (1);
6. Any person who fails to inform the Financial Services Commission of an infringement incident, in violation of Article 21-5 (1);
7. Any person who fails to create or keep records in violation of Article 22 (1) (including where it is applicable mutatis mutandis under Article 29 (2));
8. Any person who fails to clarify, explain, deliver, publish or notify the terms and conditions, in violation of Article 24 (1) or (3);
9. Any person who fails to report to the Financial Services Commission, in violation of Article 25 (1);
10. Any person who fails to prepare the procedures for the settlement of disputes, in violation of Article 27 (1);
11. Deleted; <Apr. 18, 2017>
12. Any person who fails to keep separate accounts by the category of business provided for in Article 28 (1) and (2), in violation of Article 42 (1).
(5) Administrative fines under paragraphs (1) through (4) shall be imposed and collected by the Financial Services Commission, as prescribed by Presidential Decree. <Amended on Apr. 18, 2017>[This Article Wholly Amended on May 22, 2013]