Asia-Pacific South Korea

Korea's Credit Information Act: Financial Data and MyData

The Credit Information Use and Protection Act: how Korea regulates financial personal data, pseudonymized data for research, and the MyData portability industry.

Regulation

Credit Information Use and Protection Act (CIA), amended by the 2020 'Data 3 Act' reform

Max Penalty

Penalty surcharges up to 3% of related revenue; criminal penalties up to 10 years for unlawful credit-data disclosure

Enforcing Authority

Financial Services Commission (FSC) and Financial Supervisory Service (FSS), with the PIPC

Official Source

www.fsc.go.kr

Executive Summary

  • The Credit Information Act (CIA) is Korea's sector law for credit information: identification, transaction, creditworthiness, and public-record data handled by financial institutions and credit bureaus.
  • The January 2020 'Data 3 Act' amendments (CIA, PIPA, Network Act) legalized pseudonymized data use for statistics, research, and archiving without consent, and created the MyData (credit information management) industry.
  • MyData providers, licensed by the FSC, aggregate an individual's financial data across institutions via consent-driven APIs, the world's first mandated open-banking-style portability regime in privacy law.
  • Financial institutions face dual supervision: the FSC/FSS for CIA matters and the PIPC for general PIPA questions, with the CIA prevailing as lex specialis for credit information.
  • Sanctions include penalty surcharges up to 3% of related revenue and criminal terms up to 10 years for the gravest disclosure offenses.

Korea regulates financial personal data twice: once through PIPA like everything else, and again through a sector statute old enough to predate the privacy era, the Credit Information Use and Protection Act. The 2020 “Data 3 Act” reform turned the CIA from a defensive secrecy law into the legal chassis for two experiments the rest of the world watches: consent-free analytics on pseudonymized financial data, and MyData, portability operated as a licensed industry rather than an individual right exercised one request at a time.

RegulationCredit Information Use and Protection Act (2020 reform)
Max penalty3% of related revenue (surcharge); 10 years (criminal)
SupervisorsFSC / FSS, with the PIPC
Landmark event2014 card-issuer breaches (~20M people) drove the modern security rules

What the CIA covers

Credit information spans identification data, transaction records, creditworthiness assessments, credit-capacity data, and public-record information (judgments, defaults) processed by financial companies, credit rating and inquiry firms, collection agencies, and MyData licensees. Duties include purpose-bound collection, consent for provision with financial-grade specificity, technical and physical security per FSC notice standards (network separation, access control, encryption), retention limits after transactions end (personal credit information must be deleted within three months to five years depending on category), and accuracy obligations feeding the credit-rating system.

The two 2020 innovations

Pseudonymized data. Financial institutions may process pseudonymized credit information without consent for statistical, research, and archiving purposes, commercial statistics included. Re-identification is criminal (up to 5 years), dataset combination happens only inside government-designated combination agencies, and adequacy of pseudonymization follows FSC standards. This is the legal foundation of Korea’s credit-data analytics market.

MyData. Individuals direct institutions to transmit their financial data to a licensed aggregator through mandated APIs, screen scraping was banned once APIs matured. The FSC licenses providers (capital, security, governance requirements), audits them, and specifies the data scope, which has expanded steadily since 2021 launch. For global readers: this is what GDPR Article 20 portability looks like when a regulator builds the pipes and polices the participants.

Compliance posture for financial players

Foreign financial institutions and fintechs in Korea inherit the full stack: CIA credit-information rules under FSC/FSS supervision, PIPA for everything else, overseas-transfer constraints tightened by financial cloud and outsourcing rules, and MyData API obligations if they hold licensable data. Sequence it as: classify data (credit vs general), map each class to its supervisor and rulebook, then build security to the stricter FSC notice standard, it exceeds PIPA’s baseline. For the regional picture, see the Korea-Japan-EU comparison.

Frequently Asked Questions

How does the CIA relate to PIPA?

Lex specialis: where data qualifies as credit information handled by covered entities (financial companies, credit bureaus, MyData licensees), the CIA's rules govern; PIPA fills the gaps. In practice financial institutions run both: PIPA for employee and general customer data, CIA for the credit-information core, with the FSC/FSS as primary supervisor.

What is MyData in Korea?

A licensed 'credit information management business': with the customer's consent, a MyData provider pulls their account, card, loan, insurance, and investment data from institutions through standardized APIs and presents unified views plus advisory services. Licensing began in 2021; dozens of banks, fintechs, and big-tech subsidiaries operate under it. It is data portability run as a supervised industry.

What did the Data 3 Act change for analytics?

It legalized processing pseudonymized credit information without consent for statistics (including commercial), research (including industrial), and public-record archiving, with re-identification criminalized and combination of datasets restricted to designated specialist agencies. This opened Korean financial data science while keeping identity linkage under state-supervised control.

Can credit information leave Korea?

Outbound transfers of credit information face both CIA controls (outsourcing notifications and FSC oversight for offshore processing by financial institutions) and PIPA's overseas-transfer bases. Financial regulators additionally apply network-separation and cloud-usage rules, so financial-sector offshoring is materially harder than general commercial transfers.

What are the penalties for CIA violations?

Penalty surcharges reach 3% of related revenue for major violations (unlawful provision, security failures enabling leaks); criminal exposure reaches 10 years imprisonment for unlawfully divulging credit information; and the FSC layers on business suspension, executive sanctions, and corrective orders, tools it used broadly after the 2014 card-issuer breaches that exposed data of roughly 20 million people.

Regulatory Crosswalk

PIPAGDPR portabilityGLBA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.