South Korea Credit Information Act
Evidence request list. 25 controls, 25 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consent
Per CIA: lawful basis + consent for credit information including separate consent + purpose limitation.
- KR Credit Info evidence for KRCRED-2
- FSC + PIPC cooperation partial
Credit Information Act: Data Subject Rights and MyData
Data subjects have the right to access their credit information held by providers, request correction of inaccuracies, request deletion where retention is unlawful, and lodge disputes with credit inquiry companies and the FSC.
- Access request handling procedure with SLA
- Correction and deletion workflow
- Dispute log with resolution outcomes
- Communication templates in Korean
- Quarterly metrics on rights request volume and timeliness
- Identity verification overly burdensome
- Correction propagation to downstream users incomplete
- Dispute outcomes not communicated within deadline
Where personal credit information is used in automated decision making producing significant effects, data subjects have rights to explanation, contestation, and human review, and processors shall assess fairness and bias of models.
- Inventory of automated credit decisions
- Model documentation including features and methodology
- Bias and fairness assessment reports
- Customer notice on automated decisions and rights
- Human review process with SLA
- Vendor models without transparency into features
- No mechanism for customer contestation
- Bias assessments limited to protected attributes not proxies
Entities providing personal credit information transmission services (MyData) shall obtain FSC authorisation, integrate with the central API gateway, support data subject portability requests, and meet ongoing security, capital, and operational requirements.
- FSC MyData authorisation certificate
- API integration test reports with KCB or KFTC gateway
- Capital adequacy filings
- Customer authentication architecture using approved methods
- Quarterly MyData operational metrics report
- Authentication relying on deprecated certificates
- Withdrawal of consent not propagated to all providers
- Data minimisation not enforced per query
Credit Information Act: Governance and Accountability
Credit information processors shall provide regular training to employees and officers handling personal credit information, with content covering legal obligations, security practices, incident response, and data subject rights.
- Annual training plan
- Attendance and completion records
- Role specific modules for handlers, IT staff, and management
- Assessment of learning outcomes
- Refresher triggers based on regulatory updates
- Completion rates below 100 percent for required staff
- Outsourcees not in training scope
- Content not updated after FSC guidance changes
Credit information processors shall cooperate with FSC and Financial Supervisory Service inspections, providing requested records and explanations within prescribed timeframes, and shall implement corrective measures resulting from supervisory actions.
- Inspection response procedure
- Records of past inspections and findings
- Corrective action plans with status
- Communication log with FSC and FSS
- Internal audit linkage to supervisory findings
- Inspection response coordination ad hoc
- Corrective actions closed without independent verification
- Recurring findings indicate systemic gap
Each credit information company and major user shall designate a Credit Information Management and Protection Officer with authority and resources to oversee compliance, report to senior management, and serve as point of contact with the FSC.
- Officer appointment letter with delegated authority
- Annual compliance plan
- Quarterly report to board or senior management
- Officer training certificates
- FSC notification of designation
- Officer role combined with operational duties creating conflicts
- No direct reporting line to board
- FSC notification not updated after replacement
Credit information processors shall publicly disclose a credit information processing policy in Korean covering categories of information, purposes, retention periods, third party provision, outsourcing, data subject rights, and contact for inquiries.
- Published policy on website
- Version history with change logs
- Notification mechanism for material changes
- Accessibility check for Korean speakers and persons with disabilities
- Cross reference to broader privacy policy where applicable
- Policy buried behind login walls
- Updates not actively notified
- Outsourcees listed at aggregate level only
Major credit information processors shall conduct annual risk assessments specific to personal credit information, evaluating likelihood and impact of breach scenarios, and report results to senior management with risk treatment plans.
- Annual risk assessment report
- Threat scenarios specific to credit information
- Treatment plans with owners and deadlines
- Management acceptance of residual risk
- Linkage to enterprise risk framework
- Generic information security risk substituted for credit specific assessment
- Treatments lack milestones
- Senior management acknowledgement missing
Credit Information Act: Lawful Basis and Consent
Processing of personal credit information of persons under 14 years of age requires consent of a legal representative, with verification of the relationship, and additional safeguards on retention and marketing use.
- Age verification mechanism
- Legal representative verification flow
- Records of parental consent capture
- Marketing prohibitions enforced for minor accounts
- Transition workflow at age 14
- Verification reliant on self declared age
- Marketing exclusions not technically enforced
- Retention beyond minor status not separately reviewed
Provision or use of personal credit information for purposes beyond the original collection requires explicit informed consent from the data subject, with disclosure of recipient, purpose, items, and retention period, and consent retained for evidentiary purposes.
- Consent screens with all four disclosure elements
- Consent storage with proof of capture
- Notification records for material changes to processing
- Consent expiry and renewal workflow
- Audit trail linking consent to each use event
- Recipient names abbreviated or grouped
- Retention periods generic such as until purpose achieved
- Renewal not triggered before expiry
Credit information providers, users, and credit inquiry companies shall process personal credit information only on a lawful basis including data subject consent, statutory authorisation, contract necessity, or vital interests, with consent collected separately for each purpose.
- Lawful basis register per processing activity
- Consent forms with separated purpose tick boxes
- Consent withdrawal handling procedure
- Records of consent with timestamp
- Annual lawfulness review minutes
- Bundled consent across marketing and operations
- Withdrawal mechanism harder than collection
- Statutory basis not documented per article
Use of personal credit information for marketing purposes requires separate prior consent distinct from service consent, must offer opt-out at no cost, and direct marketing calls and messages must comply with electronic communications rules.
- Separate marketing consent capture
- Opt-out mechanism testing
- Marketing suppression list integration
- Channel specific consent (call, SMS, email)
- Audit log of marketing communications and basis
- Single consent covers all channels
- Opt-out propagation delayed across campaigns
- Marketing through outsourcees without confirming consent
Pseudonymised credit information may be processed without data subject consent for statistical, scientific research, or public interest record keeping purposes, subject to technical and organisational safeguards preventing re-identification.
- Pseudonymisation methodology documentation
- Additional information storage separation evidence
- Re-identification risk assessment per project
- Internal approval for pseudonymised processing projects
- Combination ledger when combining with other pseudonymised sets
- Direct identifiers retained adjacent to pseudonyms
- Re-identification risk not quantified
- Combination conducted outside specialised agencies
Credit Information Act: Outsourcing, Transfers and Licensing
Credit inquiry companies shall be licensed by the FSC, meet capital and personnel requirements, operate with prescribed governance including independent directors and audit committees, and submit periodic operational reports.
- FSC license documentation
- Capital adequacy filings
- Board composition and committee charters
- Annual operational report to FSC
- Conflict of interest policy
- Capital ratios calculated on stale data
- Independent director qualifications not documented
- Conflict declarations not refreshed annually
Outsourcing of personal credit information processing requires written contract with prescribed terms, prior data subject notification, FSC reporting where applicable, supervision of the outsourcee, and inclusion of outsourcing scope in regulatory filings.
- Outsourcing register
- Contracts with FSC required clauses
- Data subject notifications on outsourcing
- Audit and inspection records of outsourcees
- FSC outsourcing reports where applicable
- Sub-outsourcing not registered
- Inspection frequency below requirement
- Notification combined with privacy policy update rather than active notice
Transfer of personal credit information outside Korea requires data subject consent or alternative lawful basis, disclosure of recipient country and protection level, and contractual or organisational measures ensuring equivalent protection.
- Transfer impact assessment per destination
- Standard contractual clauses or binding intra group arrangements
- Consent capture for transfers requiring it
- Transfer register with countries and recipients
- Annual review of destination country protection levels
- Cloud provider sub-processors not in transfer register
- Transfer assessments lack legal opinion on destination law
- Withdrawal of consent does not stop ongoing transfers
Credit Information Act: Security, Retention and Logging
Where personal credit information is leaked, lost, falsified, altered, or destroyed, the credit information company shall notify affected data subjects without delay and report the incident to the FSC and the Financial Supervisory Service within prescribed timeframes.
- Incident response plan with credit information specific procedures
- Notification templates for individuals, FSC, FSS
- Breach register with timeline analysis
- Tabletop exercise reports
- Post incident remediation tracking
- Notification clock starts at confirmation rather than awareness
- Affected individuals identified slowly delaying notification
- FSC and FSS reports inconsistent in detail
Records of access to and provision of personal credit information shall be maintained for at least three years with prescribed details including identity of accessor, purpose, items accessed, and disclosure recipients, supporting investigation and audit.
- Logging design covering required fields
- Retention configuration meeting three year minimum
- Log integrity controls
- Periodic log review evidence
- Anomaly detection on access patterns
- Bulk export logs missing item-level detail
- Logs accessible to operators who could tamper
- Reviews automated only without human escalation
Personal credit information shall be retained only for the period necessary for the original purpose, with separate storage required for information retained beyond five years after termination of the commercial relationship, and destruction performed by approved methods.
- Retention schedule mapping article categories
- Separate storage architecture for legacy data
- Destruction logs with method and date
- Backup expiry alignment evidence
- Annual data minimisation audit
- Five year separation rule applied to live datastores
- Backups retained beyond primary destruction
- Destruction certificates lacking method detail
Credit information processors shall implement technical and physical safeguards including access control, encryption of personal credit information in transit and at rest, audit logging, malware protection, and intrusion detection, in accordance with FSC standards.
- Information security policy aligned to FSC standard
- Encryption inventory at rest and in transit
- Access log retention configuration meeting minimum periods
- Vulnerability scan reports
- Annual penetration test report
- Internal application traffic not encrypted
- Log retention shorter than required
- Privileged access logs not separately protected
Enforcement
Per CIA: FSC + PIPC cooperation + breach notification + sanctions including criminal penalties.
- KR Credit Info evidence for KRCRED-5
- FSC + PIPC cooperation partial
Rights
Per CIA: data subject rights including access + correction + restriction + automated decision review.
- KR Credit Info evidence for KRCRED-3
- FSC + PIPC cooperation partial
Scope
Per South Korea Credit Information Use and Protection Act: scope including credit information processing + financial sector + align with FSC + PIPC.
- KR Credit Info evidence for KRCRED-1
- FSC + PIPC cooperation partial
Security
Per CIA: security + cross-border restrictions + Duties of Data Processors + processor management.
- KR Credit Info evidence for KRCRED-4
- FSC + PIPC cooperation partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.