Korea regulates financial personal data twice: once through PIPA like everything else, and again through a sector statute old enough to predate the privacy era, the Credit Information Use and Protection Act. The 2020 “Data 3 Act” reform turned the CIA from a defensive secrecy law into the legal chassis for two experiments the rest of the world watches: consent-free analytics on pseudonymized financial data, and MyData, portability operated as a licensed industry rather than an individual right exercised one request at a time.
| Regulation | Credit Information Use and Protection Act (2020 reform) |
|---|---|
| Max penalty | 3% of related revenue (surcharge); 10 years (criminal) |
| Supervisors | FSC / FSS, with the PIPC |
| Landmark event | 2014 card-issuer breaches (~20M people) drove the modern security rules |
What the CIA covers
Credit information spans identification data, transaction records, creditworthiness assessments, credit-capacity data, and public-record information (judgments, defaults) processed by financial companies, credit rating and inquiry firms, collection agencies, and MyData licensees. Duties include purpose-bound collection, consent for provision with financial-grade specificity, technical and physical security per FSC notice standards (network separation, access control, encryption), retention limits after transactions end (personal credit information must be deleted within three months to five years depending on category), and accuracy obligations feeding the credit-rating system.
The two 2020 innovations
Pseudonymized data. Financial institutions may process pseudonymized credit information without consent for statistical, research, and archiving purposes, commercial statistics included. Re-identification is criminal (up to 5 years), dataset combination happens only inside government-designated combination agencies, and adequacy of pseudonymization follows FSC standards. This is the legal foundation of Korea’s credit-data analytics market.
MyData. Individuals direct institutions to transmit their financial data to a licensed aggregator through mandated APIs, screen scraping was banned once APIs matured. The FSC licenses providers (capital, security, governance requirements), audits them, and specifies the data scope, which has expanded steadily since 2021 launch. For global readers: this is what GDPR Article 20 portability looks like when a regulator builds the pipes and polices the participants.
Compliance posture for financial players
Foreign financial institutions and fintechs in Korea inherit the full stack: CIA credit-information rules under FSC/FSS supervision, PIPA for everything else, overseas-transfer constraints tightened by financial cloud and outsourcing rules, and MyData API obligations if they hold licensable data. Sequence it as: classify data (credit vs general), map each class to its supervisor and rulebook, then build security to the stricter FSC notice standard, it exceeds PIPA’s baseline. For the regional picture, see the Korea-Japan-EU comparison.