klri logo klt logo

2-column view

ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION

2-column view table
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.21445 20260911
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.21305 20260707
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.21066 20251001
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20678 20250722
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20534 20250604
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20260 20240814
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20069 20240724
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.18871 20221211
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.18201 20211209
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.17358 20200910
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.17354 20201210
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.17348 20201210
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.17347 20200609
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.17344 20201210
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.16955 20200805
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.16825 20200611
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.16021 20190325
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.16019 20190625
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.15751 20190319
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.15628 20181213
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.14839 20170726
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.14580 20170314
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.14080 20160923
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13520 20160602
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13344 20151223
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13343 20151223
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13280 20150327
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13014 20150421
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.12844 20141119
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.12681 20140528
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.11690 20130323
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.11322 20120818
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.10560 20110706
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.10465 20110930
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.10166 20100923
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.10165 20100923
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.10138 20100317
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.9637 20090723
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.9119 20081214
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8867 20080322
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8852 20080322
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8778 20080322
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8486 20080526
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8289 20070727
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8031 20061004
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.8030 20070105
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.7917 20060625
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.7812 20060331
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.7796 20060701
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.7262 20050331
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.7142 20040730
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.7139 20040129
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.6797 20030119
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.6585 20020401
ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.6360 20010701
ACT ON PROMOTION OF UTILIZATION OF INFORMATION AND COMMUNICATIONS NETWORK No.5986 19990701
ACT ON PROMOTION OF UTILIZATION OF INFORMATION AND COMMUNICATIONS NETWORK No.5835 19990701
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.5219 19970131
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.4998 19960307
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.4969 19960101
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.4528 19930609
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.4439 19911214
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.4393 19911211
ACT ON EXPANSION OF DISSEMINATION AND PROMOTION OF UTILIZATION OF INFORMATION SYSTEM No.3848 19870101
CHAPTER I GENERAL PROVISIONS
법령 이단보기
Article 1 (Purpose)
The purpose of this Act is to contribute to improving citizens’ lives and enhancing public welfare by facilitating utilization of information and communications networks, protecting people using information and communications services, and developing an environment in which people can utilize information and communications networks in a healthier and safer way. <Amended on Feb. 4, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 2 (Definitions)
(1) The terms used in this Act are defined as follows: <Amended on Jan. 29, 2004; Jan. 26, 2007; Dec. 21, 2007; Jun. 13, 2008; Mar. 22, 2010; May 28, 2014; Jun. 9, 2020>
1. The term "information and communications network" means an information and communications system for collecting, processing, storing, searching, transmitting, or receiving information by using telecommunications equipment defined in subparagraph 2 of Article 2 of the Telecommunications Business Act or telecommunications equipment, computers and applied computer technology;
2. The term "information and communications services" means telecommunications services defined in subparagraph 6 of Article 2 of the Telecommunications Business Act and services providing information or intermediating the provision of information by using such telecommunications services;
3. The term "provider of information and communications services" means a telecommunications business operator defined in subparagraph 8 of Article 2 of the Telecommunications Business Act and any other person who provides information or intermediates to provide information commercially by utilizing services provided by a telecommunications business operator;
4. The term "user" means a person who uses information and communications services rendered by providers of information and communications services;
5. The term "electronic document" means data prepared and transmitted, received, or stored electronically in a standardized document by a device capable of processing information, such as a computer;
6. Deleted; <Feb. 4, 2020>
7. The term "cyber security incident" means an event resulting from an attack on an information and communications network or an information system related to such network by any of the following:
(a) Means of hacking, computer virus, logic bomb, electronic mail bomb, denial of service, high-power electromagnetic wave, etc.;
(b) Means of installing, in an information and communications network or an information system related thereto, a program, technical device, etc. that enables to circumvent the normal protection and authentication processes of the information and communications network and makes access thereto possible;
8. Deleted; <Jun. 22, 2015>
9. The term "message board" means, regardless of its name, a computer program or a technical device with which users can publish information in the form of a code, letters, voice, sound, image, motion picture, or any other form purposely to disclose the information to the public by using an information and communications network;
10. The term "telecommunications billing services" means information and communications services to perform the following business activities:
(a) Business activities charging and collecting prices for goods or services sold or provided by a third person (hereinafter referred to as "goods or services") together with charges for the telecommunications services provided;
(b) Business activities transmitting and receiving information on transactions electronically so that prices for goods or services sold or provided by a third person can be billed or collected together with charges for the telecommunications services provided by under item (a), or settling, on behalf of another person, or intermediating payments for such prices;
11. The term "provider of telecommunications billing services" means a person who provides telecommunications billing services after being registered under Article 53;
12. The term "user of telecommunications billing services" means a person who purchases or uses goods or services by using telecommunications billing services rendered by a provider of telecommunications billing services;
13. The term "electronic transmission medium" means a medium transmitting codes, letters, voices, images, or motion pictures to addressees in an electronic form, such as an electronic document, via information and communications networks.
(2) Except as provided in paragraph (1), definitions of the terms used in this Act shall be governed by the Framework Act on Intelligent Informatization. <Amended on Jun. 13, 2008; Mar. 23, 2013; Jun. 9, 2020>
법령 이단보기
Article 3 (Responsibilities of providers and users of information and communications services)
(1) Every provider of information and communications services shall contribute to protection of rights and interests of users and enhancement of users’ abilities to use information by protecting users and providing information and communications services in a healthier and safer way. <Amended on Feb. 4, 2020>
(2) Every user shall make efforts to help to establish a healthier information society.
(3) The Government may provide support to organizations composed of providers or users of information and communications services in their activities for protecting information and protecting youths in information and communications networks. <Amended on Feb. 4, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 4 (Formulating policy on promotion of utilization of information and communications networks and protection of information)
(1) The Minister of Science and ICT or the Korea Media and Communications Commission shall formulate policy measures to lay the foundations for an information society through the promotion of utilization of information and communications networks, the stable management and operation of such networks, the protection of users, and other related activities (hereinafter referred to as "promotion of utilization of information and communications networks, the protection of information, and other related matters"). <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(2) The policy measures under paragraph (1) shall contain descriptions of the following: <Amended on Dec. 24, 2018; Jun. 9, 2020>
1. Development and dissemination of technology related to information and communications networks;
2. Standardization of information and communications networks;
3. Promotion of utilization of information and communications networks, including the development of contents of information and applied service for information and communications networks under Article 11;
4. Facilitation of sharing information through information and communications networks;
5. Promotion of use of the Internet;
6. Deleted; <Feb. 4, 2020>
6-2. Deleted; <Feb. 4, 2020>
7. Protection of youths in information and communications networks;
7-2. Development and dissemination of technologies that identify false sounds, visions, pictorial images, etc., made using artificial intelligence technology, among information circulated through information and communications networks;
8. Enhancement of safety and reliability of information and communications networks;
9. Other matters necessary for the promotion of utilization of information and communications networks, the protection of information, and other related matters.
(3) When preparing the policy measures under paragraph (1), the Minister of Science and ICT or the Korea Media and Communications Commission shall ensure that the policy measures are linked to the comprehensive plan for the intelligent information society under Article 6 of the Framework Act on Intelligent Informatization. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020; Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 4-2 (Policy measures to prevent harm caused by synthesized videos, etc.)
(1) The Minister of Science and ICT and the Korea Media and Communications Commission shall establish policy measures to prevent harm, such as sexual crimes, defamation, or fraud, caused by the indiscriminate distribution of information (hereinafter referred to as "synthesized videos, etc." in this Article) that has been edited, synthesized, or processed against the will of a person by using artificial intelligence technology on the person's face, body, or voice in photographs, videos, or audio recordings. <Amended on Oct. 1, 2025>
(2) The policy measures under paragraph (1) shall include the following:
1. Identify the actual state of harm caused by synthesized videos, etc.;
2. Identify the circulation status of synthesized videos, etc.;
3. Identify domestic and international technology trends related to synthesized videos, etc.;
4. Promote technology development to prevent the indiscriminate circulation of synthesized videos, etc.;
5. Education and public relations for preventing the indiscriminate circulation of synthesized videos, etc. and preventing harm;
6. Other matters necessary for preventing the indiscriminate circulation of synthesized videos, etc. and preventing harm;
[This Article Added on Dec. 3, 2024]
법령 이단보기
Article 5 (Relationship to other statutes)
Except as otherwise provided in any other statute, the promotion of utilization of information and communications networks, the protection of information, and other related matters shall be governed by this Act; provided, in the event of a conflict between this Act and the Electronic Financial Transactions Act with respect to telecommunications billing services under Chapter VII, this Act shall prevail. <Amended on Jun. 12, 2018; Feb. 4, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 5-2 (Application to acts done overseas)
This Act shall apply to any act done overseas if such conduct affects the domestic market or users in the market.
[This Article Added on Jun. 9, 2020]
CHAPTER II PROMOTION OF UTILIZATION OF INFORMATION AND COMMUNICATIONS NETWORKS
법령 이단보기
Article 6 (Development of technology)
(1) The Minister of Science and ICT may engage the relevant research institute, as prescribed by Presidential Decree, to implement a project for research and development, technical cooperation, transfer of technology, technical guidance, or similar, in order to effectively promote the development of technology and devices related to information and communications networks. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Government may provide financial support to a research institute that implements a project for research and development or similar in accordance with paragraph (1) for all or part of the expenses incurred in conducting such project.
(3) Matters necessary for the disbursement and management of the expenses under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 7 (Management and dissemination of technology-related information)
(1) The Minister of Science and ICT shall manage, systematically and comprehensively, the information pertaining to technology and devices related to information and communications networks (hereafter in this Article referred to as "technology-related information"). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) If necessary for managing technology-related information systematically and comprehensively, the Minister of Science and ICT may request data relevant to technology-related information from the relevant administrative agency and a national or public research institute. Upon such request, the head of such agency or institute shall comply therewith, unless there is a special reason not to do so. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) The Minister of Science and ICT shall perform projects for dissemination of technology-related information, so that technology-related information can be used promptly and easily. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(4) Matters necessary for the scope of technology and devices related to information and communications networks which are to be disseminated pursuant to paragraph (3), shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 8 (Standardization and certification of information and communications networks)
(1) The Minister of Science and ICT shall establish and give public notice of the standards for information and communications networks in order to promote the utilization of information and communications networks, and may recommend providers of information and communications services or persons who manufacture or supply products related to information and communications networks to comply with the standards; provided, the matters for which the Korean Industrial Standards under Article 12 of the Industrial Standardization Act have already been established shall comply with such standards. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) A person who manufactures or supplies a product related to information communications in conformity with the standards publicly notified pursuant to paragraph (1) may put on the product a mark stating that the product conforms to the standards, subject to the prior certification of the certification body under Article 9 (1).
(3) Where a product falls under the proviso of paragraph (1) and the certification under Article 15 of the Industrial Standardization Act has been already given to the product, the product shall be deemed to have been certified pursuant to paragraph (2).
(4) No person other than a person who holds the certification under paragraph (2) may put a mark verifying that his or her product conforms to the standards or put any similar mark, nor may he or she sell a product with any similar mark or display such product for the purpose of sale.
(5) The Minister of Science and ICT may order a person who sells a product or displays such product for the purpose of sale in violation of paragraph (4), to collect and recall the product or to obtain certification to put such mark; or may take any other corrective measure as necessary. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(6) Matters regarding the subject matters of the standardization, the methods and procedures for such standardization, and a mark of certification under paragraphs (1) through (3), and the collection, recall, corrective measures, etc. under paragraph (5) shall be prescribed by Decree of the Ministry of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 9 (Designation of certification bodies)
(1) The Minister of Science and ICT may designate an organization to certify that products related to information and communications networks (hereinafter referred to as "certification body"), which are manufactured or supplied by a person, conform to the standards publicly notified pursuant to the main clause of Article 8 (1). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) If a certification body falls under any of the following, the Minister of Science and ICT may revoke the designation of such body or give an order of business suspension for a specified period not exceeding 6 months; provided, the Minister of Science and ICT shall revoke such designation, if it falls under subparagraph 1: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. If the body is designated by fraud or other improper means;
2. If the body has not continued its certification services for at least 1 year without good cause;
3. If the body fails to meet the standards for designation under paragraph (3).
(3) Matters regarding the standards and procedures for designation under paragraph (1), and the criteria for revocation of designation and for business suspension of a certification body under paragraph (2), and other related matters shall be prescribed by Decree of the Ministry of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 10 (Support for development of contents of information)
With an aim of securing national competitiveness and enhancing the public interest, the Government may provide financial and technical support, or otherwise, to persons who develop relevant contents of information that can be distributed through information and communications networks.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 11 (Acceleration of development of applied services for information and communications networks)
(1) The Government may provide financial and technical support or other necessary support to any national agency, local government, or public institution that develops and operates applied services for improving efficiency in processing its business affairs or automatizing or upgrading its business process by utilizing information and communications networks (hereinafter referred to as "applied services for information and communications networks").
(2) The Government may provide financial and technical support or other necessary support to the private sector with an aim of facilitating the development of applied services for information and communications networks by the private sector; and shall prepare the following policy measures for nurturing technical human resources necessary to develop applied services for information and communications networks:
1. Support for Internet education conducted by schools at different levels and other educational institutions;
2. Extension of Internet education for citizens;
3. Support for projects to cultivate technical human resources specializing in information and communications networks;
4. Establishment of and support for institutions to cultivate technical human resources specializing in information and communications networks;
5. Support for development and dissemination of educational programs for utilizing information and communications networks;
6. Support for establishment of the technical qualification system related to information and communications networks and support for supply of technical human resources specializing in information and communications networks on demand;
7. Other matters necessary to cultivate technical human resources related to information and communications networks.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 12 (Establishment of system for sharing information)
(1) The Government may encourage the development of a system for sharing information through linked operation and standardization of information and communications networks or in any other way so that the networks can be made efficient use of.
(2) The Government may provide financial and technical support or other necessary support to any person who develops a system for sharing information under paragraph (1).
(3) Matters necessary for the encouragement and support under paragraphs (1) and (2) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 13 (Projects for promoting utilization of information and communications networks)
(1) The Minister of Science and ICT may implement projects designed to promote efficient utilization and dissemination of technology, devices, and applied services related to information and communications networks, as prescribed by Presidential Decree, in order to promote the utilization of information and communications networks in various areas of public service, local communities, industry, life, and social welfare and to eliminate gaps in accessibility to information. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Government may provide financial and technical support or other necessary support to persons who participate in the projects under paragraph (1).
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 14 (Proliferation of the Internet)
The Government shall formulate and implement policy measures to induce the public and private sectors to use Internet facilities available in the public and private sectors so that the Internet can be widely used; to form the basis for using the Internet through education and public relations activities on the Internet; and to eliminate gaps in accessibility to the Internet between localities, genders, and ages.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 15 (Improvement of quality of internet services)
(1) The Minister of Science and ICT shall formulate and implement policy measures to protect rights and interests of users of Internet services and to ensure improvement of quality of Internet services and stable availability of Internet services. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) If deemed necessary for implementing the policy measures under paragraph (1), the Minister of Science and ICT may prescribe and give public notice of the standards for measuring and assessing the quality of Internet services, hearing opinions of organizations of providers and users of information and communications services and others. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) Every provider of information and communications services may voluntarily assess the current status of quality of his or her own Internet services in accordance with the standards under paragraph (2) and may notify the results thereof to users.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 16 Deleted. <Jan. 29, 2004>
법령 이단보기
Article 17 Deleted. <Jan. 29, 2004>
CHAPTER III Deleted.
법령 이단보기
Article 18 Deleted. <Jun. 22, 2015>
법령 이단보기
Article 19 Deleted. <Jun. 22, 2015>
법령 이단보기
Article 20 Deleted. <Jun. 22, 2015>
법령 이단보기
Article 21 Deleted. <Jun. 22, 2015>
CHAPTER IV CREATION OF SAFE ENVIRONMENT FOR USE OF INFORMATION AND COMMUNICATIONS SERVICES
SECTION 1 Deleted
법령 이단보기
Article 22 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 22-2 (Consent to access authority)
(1) Where a provider of information and communications services needs authority to access (hereinafter referred to as "access authority") information stored and functions installed in mobile devices of users in order to provide the relevant services, the provider shall inform users of the following so that users may clearly recognize such matters, and shall obtain consent of users:
1. In the case of access authority certainly necessary to provide the relevant services:
(a) Items of the information and functions for which access authority is necessary;
(b) Grounds that access authority is necessary;
2. In the case of access authority not certainly necessary to provide the relevant services:
(a) Items of the information and functions for which access authority is necessary;
(b) Grounds that access authority is necessary;
(c) Fact that users may give no consent to the permission for access authority.
(2) No provider of information and communications services shall refuse to provide the relevant services to users on the ground that the users give no consent to the establishment of access authority not certainly necessary to provide the relevant services.
(3) Persons manufacturing and providing a basic operating system (referring to an operating environment in which software installed in mobile devices can be run) of mobile devices, manufacturers of mobile devices, and persons manufacturing and providing a software for mobile devices shall take measures necessary for protecting user information, such as devising methods for users to give or revoke consent to access authority where the provider of information and communications services intends to access the information stored and functions installed in mobile devices.
(4) The Korea Media and Communications Commission may conduct compliance inspections to ascertain that access authority is set for relevant services in accordance with paragraphs (1) through (3). <Added on Jun. 12, 2018; Oct. 1, 2025>
(5) The scope of, and methods for consenting to, access authority referred to in paragraph (1), the measures necessary for protecting user information referred to in paragraph (3), and other necessary matters shall be prescribed by Presidential Decree. <Amended on Jun. 12, 2018>
[This Article Added on Mar. 22, 2016]
법령 이단보기
Article 23 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 23-2 (Restrictions on use of resident registration numbers)
(1) Except in any of the following cases, no provider of information and communications services may collect or use users’ resident registration numbers: <Amended on Feb. 4, 2020>
1. Where the provider is designated as an identity verification agency pursuant to Article 23-3;
2. Deleted; <Feb. 4, 2020>
3. Where a telecommunications business operator, who resells a mobile communications service and the like provided by a facilities-based telecommunications business operator under Article 38 (1) of the Telecommunications Business Act, collects or uses resident registration numbers of users in relation to performing the identity verification service of a mobile telecommunications business operator designated as an identity verification agency under Article 23-3.
(2) Even where the collection and use of users’ resident registration numbers is authorized pursuant to paragraph (1) 3, an identification method without using the users’ resident registration numbers (hereinafter referred to as "alternative means") shall be provided. <Amended on Feb. 4, 2020>
[This Article Wholly Amended on Feb. 17, 2012]
법령 이단보기
Article 23-3 (Designation of identification service agencies)
(1) The Korea Media and Communications Commission may, after reviewing the following, designate a person as an identity verification agency who is deemed competent to safely and reliably perform the affairs of development, provision, and administration of the alternative means (hereinafter referred to as "identity verification service"): <Amended on Oct. 1, 2025>
1. A plan for physical, technological, and administrative measures in order to secure safety of the identity verification service;
2. Technological and financial capability necessary for performing the identity verification service;
3. Appropriateness of the scale of facilities relevant to the identity verification service.
(2) When an identity verification agency intends to discontinue the identity verification service temporarily, it shall determine and notify a discontinuation period to the users by not later than 30 days prior to the intended date of discontinuation and shall report the same to the Korea Media and Communications Commission. In such cases, the discontinuation period shall not exceed 6 months. <Amended on Oct. 1, 2025>
(3) When an identity verification agency intends to discontinue the identity verification service, it shall notify the intention to the users not later than 60 days prior to the intended date of discontinuation and shall report the same to the Korea Media and Communications Commission. <Amended on Oct. 1, 2025>
(4) Matters necessary for detailed review criteria for each item subject to review, designation procedures, temporary or permanent discontinuation, and other matters under paragraphs (1) through (3) shall be prescribed by Presidential Decree.
[This Article Added on Apr. 5, 2011]
법령 이단보기
Article 23-4 (Suspension of identity verification services and revocation of designation of identification service agencies)
(1) When an identity verification agency falls under any of the following, the Korea Media and Communications Commission may order full or partial suspension of its identity verification service for a specified period of up to 6 months or revoke the designation of the identity verification agency; provided, in cases falling under subparagraph 1 or 2, the Korea Media and Communications Commission shall revoke the designation of the identity verification agency: <Amended on Oct. 1, 2025>
1. Where the identity verification agency is designated by fraud or other improper means;
2. Where a person who has received an order to suspend the identity verification service fails to suspend such service in violation of the order;
3. Where a person fails to start the identity verification service within 6 months from the date of designation, or has temporarily discontinued the service for at least 6 consecutive months;
4. Where the identification service agency no longer meets the standards for designation pursuant to Article 23-3 (4).
(2) Standards and procedures for disposition granted under paragraph (1) and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Apr. 5, 2011]
법령 이단보기
Article 23-5 (Creation and processing of connecting information)
(1) An identity verification agency shall not create, provide, use, compare, link irreversibly encrypted form of any user's resident registration number (hereinafter referred to as "connecting information") or perform other similar acts (hereinafter referred to as "processing") for the purpose of interlinking the services of a provider of information and communication services, except in cases falling under any of the following subparagraphs: <Amended on Oct. 1, 2025>
1. Where providing services to safely identify and authenticate users using information entered by the users;
2. Where administrative agencies and public institutions (hereinafter referred to as "administrative agencies, etc.") holding uniquely identifiable information under Article 24 of the Personal Information Protection Act (hereinafter in this Article referred to as "uniquely identifiable information") utilize connecting information to provide electronic government service defined in subparagraph 5 of Article 2 of the Electronic Government Act, in any of the following cases:
(a) Where the head of a central agency responsible for administrative affairs under subparagraph 4 of Article 2 of the Electronic Government Act requests for the creation and processing of connecting information in order to provide integral support to administrative agencies, etc. for the identification of users;
(b) Where an administrative agency, etc. inevitably requests the creation and processing of connecting information without obtaining the user's consent within the scope of the purpose of processing uniquely identifiable information;
3. Where a person holding uniquely identifiable information requests the creation and processing of connecting information of a data subject who has requested the transmission of personal information in order to fulfill the obligation to transmit personal information pursuant to Article 35-2 of the Personal Information Protection Act;
4. Where the processing of resident registration numbers is permitted under the subparagraphs of Article 24-2 (1) of the Personal Information Protection Act, and the identity verification agency and the relevant provider of information and communications services together have obtained approval from the Korea Media and Communications Commission for providing information and communication services prescribed by the Presidential Decree for which it is inevitable to create and process connecting information without obtaining the consent of the user.
(2) Where the Korea Media and Communications Commission intends to approve the creation and processing of connecting information under paragraph (1) 4, the Commission shall comprehensively examine the following matters: <Amended on Oct. 1, 2025>
1. Appropriateness and innovativeness of the realization of services to be provided:
2. Adequacy of procedures for creating and processing connecting information;
3. Plans for physical, technical, and administrative measures to ensure safety in creating and processing connecting information;
4. Adequacy of measures to protect the rights of users:
5. Impacts and effects on relevant markets and user benefits:
(3) The Korea Media and Communications Commission may revoke approval for the creation and processing of connecting information under paragraph (1) 4 in any of the following; provided, in the case of subparagraph 1, the approval shall be revoked: <Amended on Oct. 1, 2025>
1. Where they have obtained approval for the creation and processing of connecting information under paragraph (1) 4 by fraud or in any other improper means;
2. Where they fail to comply with the matters examined under each subparagraph of paragraph (2);
3. Where they violate the obligation to take physical, technical, or administrative measures under Article 23-6 (1);
4. Where they violate a statute or regulation related to the protection of personal information and the reason for such violation is material.
(4) A person who is provided with connecting information from an identity verification agency (hereinafter referred to as a "entity using connecting information") for the services under the subparagraphs of paragraph (1) may process the connecting information within the scope of purposes for which the person has been provided; provided, if the data subject separately consents, the connecting information may be processed within the scope of the consented purpose.
(5) Matters necessary for approval procedures for creating and processing connecting information under paragraphs (1) through (4), detailed examination criteria for each approval, criteria for revoking approval, and other matters shall be prescribed by Presidential Decree.
[This Article Added on Jan. 23, 2024]
법령 이단보기
Article 23-6 (Obligation to take safety measures for connecting information)
(1) Where an identity verification agency creates and processes connecting information, it shall take physical, technical and administrative measures to ensure safety for creating and processing the connecting information in addition to the measures under Article 29 of the Personal Information Protection Act.
(2) Where an entity using connecting information provides services under the subparagraphs of Article 23-5 (1), in addition to measures pursuant to Article 29 of the Personal Information Protection Act, the entity shall store and manage the connecting information separately from resident registration numbers and take measures to ensure that the connecting information is not lost, stolen, leaked, falsified, altered, or damaged (hereinafter referred to as "safety measures").
(3) The Korea Media and Communications Commission may inspect the operation and management of physical, technical and administrative measures taken by an identity verification agency that meets the standards prescribed by the Presidential Decree, including the scale and turnover of connecting information created and processed, and safety measures taken by the entity using the connecting information. <Amended on Oct. 1, 2025>
(4) The Korea Media and Communications Commission may entrust the affairs regarding inspection under paragraph (3) to a specialized organization prescribed by Presidential Decree. <Amended on Oct. 1, 2025>
(5) Matters necessary for the physical, technical and administrative measures under paragraph (1) and the safety measures under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Added on Jan. 23, 2024]
법령 이단보기
Article 24 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 24-2 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 25 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 26 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 26-2 Deleted. <Feb. 4, 2020>
SECTION 2 Deleted
법령 이단보기
Article 27 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 27-2 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 27-3 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 28 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 28-2 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 29 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 29-2 Deleted. <Feb. 4, 2020>
SECTION 3 Deleted
법령 이단보기
Article 30 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 30-2 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 31 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 32 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 32-2 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 32-3 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 32-4 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 32-5 (Designation of domestic agents)
(1) A person who meets the criteria prescribed by Presidential Decree, based upon considerations such as the number of users and sales, from among providers of information and communications services or similar with no domicile or place of business in the Republic of Korea, shall designate, in writing, an agent to act on his or her behalf with respect to the following (hereinafter referred to as "domestic agent"):
1. Deleted; <Feb. 4, 2020>
2. Deleted; <Feb. 4, 2020>
3. Submission of related articles, documents, etc. under Article 64 (1).
(2) A domestic agent shall be a person who has a domicile or place of business in the Republic of Korea.
(3) In designating a domestic agent pursuant to paragraph (1), all the following matters shall be disclosed on its website and the like: <Amended on Feb. 4, 2020>
1. The domestic agent's name (if the domestic agent is a corporation, referring to the name of the corporation and the name of its representative);
2. The domestic agent's domicile (if the domestic agent is a corporation, referring to the address of its place of business), and his or her telephone number and electronic mail address.
(4) If a domestic agent violates this Act in relation to the subparagraphs of paragraph (1), such violation shall be deemed to have been committed by the relevant provider of information and communications services or similar.
[This Article Added on Sep. 18, 2018]
SECTION 4 Deleted
법령 이단보기
Article 33 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 33-2 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 34 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 35 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 36 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 37 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 38 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 39 Deleted. <Mar. 29, 2011>
법령 이단보기
Article 40 Deleted. <Mar. 29, 2011>
CHAPTER V PROTECTION OF USERS IN INFORMATION AND COMMUNICATIONS NETWORKS
법령 이단보기
Article 41 (Preparation of policy on protection of youths)
(1) The Korea Media and Communications Commission shall prepare a policy on the following measures to protect youths from information harmful to youth, such as information of obscenities and violence, circulated through information and communications networks (hereinafter referred to as "information harmful to youth"): <Amended on Oct. 1, 2025>
1. Development and dissemination of content-screening software;
2. Development and dissemination of technology for protection of youths;
3. Education and public relations activities for protection of youths;
4. Other matters prescribed by Presidential Decree for protection of youths.
(2) The Korea Media and Communications Commission may, in an effort to implement the policy under paragraph (1), support activities conducted by the Korea Communications Standards Commission under Article 18 of the Act on the Establishment and Operation of Korea Media and Communications Commission (hereinafter referred to as the "Communications Standards Commission"), organizations of providers or users of information and communications services, and other relevant specialized institutions for protection of youths. <Amended on Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 42 (Labeling of media products harmful to youths)
A person who provides information to the general public purposely to make it public through telecommunications services rendered by a telecommunications business operator (hereinafter referred to as "information provider") and who intends to provide any media product harmful to youths defined in subparagraph 3 of Article 2 of the Youth Protection Act among the media products referred to in subparagraph 2 (e) of Article 2 of that Act, shall put a label indicating that the information is a media product harmful to youths by the labeling method prescribed by Presidential Decree. <Amended on Sep. 15, 2011>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 42-2 (Prohibition on advertisement of media products harmful to youths)
No one may transmit, to a youth defined in subparagraph 1 of Article 2 of the Youth Protection Act, any information containing an advertisement of a media product harmful to youths defined in subparagraph 3 of Article 2 of that Act among the media products referred to in subparagraph 2 (e) of Article 2 of that Act in the form of code, letter, voice, sound, image, or motion picture through an information and communications network or display such information to the general public without taking any measure to restrict access by a youth. <Amended on Sep. 15, 2011>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 42-3 (Designation of persons responsible for protection of youths)
(1) A provider of information and communications services who meets the criteria prescribed by Presidential Decree, such as the average number of daily users and sales, shall designate a person responsible for protection of youths to keep youths from information harmful to youths in the information and communication network.
(2) The person responsible for protection of youths shall be chosen from among executive officers of the relevant business operator or the persons in a position equivalent to the head of a department responsible for business affairs related to protection of youths.
(3) The person responsible for protection of youths shall block and control information harmful to youths in the information and communications network and shall perform business affairs for protection of youths, including establishment of a plan for protection of youths from information harmful to youths.
(4) Matters necessary for designating a person responsible for protection of youths under paragraph (1) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 43 (Duty of providers of visual or sound Information to keep information)
(1) An information provider prescribed by Presidential Decree from among those who engage in business providing media products harmful to youths defined in subparagraph 3 of Article 2 of the Youth Protection Act among the media products referred to in subparagraph 2 (e) of Article 2 of that Act in a way to make it impossible to save or record the harmful media products in a user's computer shall keep relevant information. <Amended on Sep. 15, 2011>
(2) The period during which an information provider under paragraph (1) is obligated to keep relevant information shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 44 (Protection of rights in information and communications networks)
(1) No user may circulate any information in violation of other person's rights, including invasion of privacy and defamation, through an information and communications network.
(2) Every provider of information and communications services shall make efforts to prevent any information under paragraph (1) from being circulated through the information and communications network operated and managed by the provider.
(3) The Korea Media and Communications Commission may prepare policy measures on technological development, education, public relations activities, and other activities to prevent violation of other persons' rights by information circulated through information and communications networks, including invasion of privacy and defamation and may recommend providers of information and communications services to adopt the policy measures. <Amended on Mar. 23, 2013; May 28, 2014; Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 44-2 (Request for deletion of information)
(1) Where information provided through an information and communications network purposely to be made public intrudes on other persons' privacy, defames other persons, or violates other persons' right otherwise, the victim of such violation may request the provider of information and communications services who managed the information to delete the information or publish a rebuttable statement (hereinafter referred to as "deletion or rebuttal"), presenting explanatory materials supporting the alleged violation. In such cases, a person who requesting deletion or rebuttal (hereafter in this Article referred to as "applicant") may designate a means to be notified of the progress and results of such processing, such as a text message or e-mail, and a person who has posted the relevant information (hereafter in this Article referred to as "person who posted information") may designate in advance the means to be notified of the fact of taking measures under paragraph (2), such as text messages or e-mails. <Amended on Mar. 22, 2016; Jan. 3, 2023>
(2) Upon receipt of a request for deletion or rebuttal of the information under paragraph (1), a provider of information and communications services shall delete the information or take a temporary or any other necessary measure and shall notify the applicant and the publisher of the information without delay. In such cases, the provider of information and communications services shall make it known to users that he or she has taken necessary measures by posting a public notification on the relevant message board or in any other way.
(3) If there is any media product harmful to youths published in violation of the labeling method under Article 42 in the information and communications network operated and managed by a provider of information and communications services or if a content advertising any media product harmful to youths is displayed in such network without any measures to restrict access by youths under Article 42-2, the provider shall delete such content without delay.
(4) Notwithstanding a request for deletion of the information under paragraph (1), if it is impracticable to judge whether information violates any right or it is anticipated that there will probably be a dispute between interested parties, a provider of information and communications services may take a measure to block access to the information temporarily (hereinafter referred to as "temporary measures"). In such cases, the period for the temporary measure shall not exceed 30 days.
(5) Every provider of information and communications services shall clearly state in advance the details, procedures, and other matters regarding necessary measures in the terms and conditions.
(6) If a provider of information and communications services takes necessary measures under paragraph (2) for the information circulated through the information and communications network operated and managed by himself or herself, the provider may have his or her liability to indemnify loss incurred by such information mitigated or discharged.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 44-3 (Discretionary temporary measures)
(1) If a provider of information and communications services finds that information circulated through the information and communications network which he or she operates and manages, intrudes on someone's privacy, defames someone, or violates someone's rights, the provider may take temporary measures at his or her discretion.
(2) The latter part of Article 44-2 (2), the latter part of Article 44-2 (4), and Article 44-2 (5) shall apply mutatis mutandis to the temporary measures under paragraph (1).
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 44-4 (Self-regulation)
(1) An organization of providers of information and communications services may establish and implement a code of conduct applicable to providers of information and communications services with an objective to protect users and render information and communications services more safely and reliably. <Amended on Dec. 24, 2018>
(2) An organization of providers of information and communications services may establish and enforce self-regulating guidelines for monitoring, etc. so as to prevent any of the following information from being circulated in information and communications networks: <Added on Dec. 24, 2018>
1. Information harmful to youth;
2. Unlawful information under Article 44-7.
(3) The Government may recommend organizations of providers of information and communications services to improve and supplement self-regulation guidelines, if necessary to effectively prevent the circulation of information specified in any subparagraph of paragraph (2). <Added on Dec. 3, 2024>
(4) The Government may support self-regulating activities by organizations of providers of information and communications services under paragraphs (1) and (2). <Added on Dec. 24, 2018; Dec. 3, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 44-5 (Identity verification of users of message boards)
(1) If any of the following persons intends to install and operate a message board, he or she shall take necessary measures, as prescribed by Presidential Decree (hereinafter referred to as "measures for identity verification"), including preparation of methods and procedures for verifying identity of users of the message board:
1. A national agency, local government, public enterprise, or quasi-government agency under Article 5 (3) of the Act on the Management of Public Institutions, or a local government-invested public corporation or a local government public corporation under the Local Public Enterprises Act (hereinafter referred to as "public institution, etc.");
2. Deleted. <May 28, 2014>
(2) Deleted. <May 28, 2014>
(3) The Government shall prepare policy measures to develop a safer and more reliable system to verify identity of users under paragraph (1).
(4) A public institution, etc. may have its liability for damages caused by fraudulent use of a user's identity by a third party mitigated or discharged, if it has taken the measures for identity verification under paragraph (1) with care as a good manager. <Amended on May 28, 2014>
[This Article Wholly Amended on Jun. 13, 2008]
[Paragraph (1) 2 of this Article was deleted by Act No. 12681 on May 28, 2014, following the decision of unconstitutionality by the Constitutional Court made on Aug. 23, 2012].
법령 이단보기
Article 44-6 (Claim to furnish user information)
(1) A person who alleges that information published or circulated by a specific user has intruded on his or her privacy, defamed him or her, or violated his or her rights, may file a claim with the defamation dispute conciliation division under Article 44-10 to demand the relevant provider of information and communications services to furnish the information the provider possesses about the alleged offender (referring to the minimum information prescribed by Presidential Decree, including the name and address, necessary for filing a civil or criminal complaint), along with materials supporting his or her allegation of the violation, in order to file a civil or criminal complaint against the alleged offender.
(2) Upon receipt of a claim under paragraph (1), the defamation dispute conciliation division shall make a decision on whether to furnish information, hearing the opinion of the relevant user, unless it is impossible to contact the relevant user or there is any particular reason otherwise.
(3) A person who receives information about the relevant user under paragraph (1) shall not use the information for any purpose other than the purpose of filing a civil or criminal complaint.
(4) Other necessary matters regarding the content of a claim to furnish user information and the procedures therefor shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 44-7 (Prohibition on circulation of unlawful information)
(1) No one may circulate any of the following information through an information and communications network: <Amended on Sep. 15, 2011; Mar. 22, 2016; Jun. 12, 2018; Jan. 21, 2025>
1. Information with obscene content distributed, sold, rented, or displayed openly in the form of code, words, sound, images, or motion picture;
2. Information with content that defames other persons by divulging a fact or false information, openly and with intent to disparage the person's reputation;
3. Information with content that arouses fear or apprehension by reaching other persons repeatedly in the form of code, words, sound, image, or motion picture;
4. Information with content that damages, destroys, alters, or forges an information and communications system, data, a program, or similar or that interferes with the operation of such system, data, program, or similar without good cause;
5. Information with content that amounts to a media product harmful to youths under the Youth Protection Act and that is provided for profit without fulfilling the duties and obligations under the relevant statutes and regulations, including the duty to verify the subject's age and the duty of labeling;
6. Information with content that amounts to speculative activities prohibited by statutes and regulations;
6-2. Information with content of transactions of personal information in violation of this Act or any other statute or regulation regarding the protection of personal information;
6-3. Information regarding methods, drawings, etc. for manufacturing guns or explosives (including things with a yield that may expose people to risk of life or bodily injury);
6-4. Information with content of the use, manufacture, sale, or mediation of the sale of narcotics prohibited by the Narcotic Drugs Control Act;
7. Information with content that divulges a State secret, including secrets classified under statutes and regulations;
8. Information with content that violates the National Security Act;
9. Other information with content that attempts to commit, aids, or abets a crime.
(2) The Korea Media and Communications Commission may order a provider of information and communications services or a manager or an operator of a message board to reject, suspend, or restrict management of information under paragraph (1) 1 through 6, 6-2 through 6-4, subject to deliberation by the Communications Standards Commission; provided, if the information falls under paragraph (1) 2 or 3, the Commission shall not issue an order to reject, suspend, or restrict such management against the intention specifically manifested by the victim of the relevant information. <Amended on Mar. 22, 2016; Jun. 12, 2018; Jan. 21, 2025; Oct. 1, 2025>
(3) The Korea Media and Communications Commission shall order a provider of information and communications services or a manager or an operator of a message board to reject, suspend, or restrict management of information under paragraph (1) 7 through 9, if the information falls under all of the following: <Amended on Mar. 22, 2016; Dec. 24, 2018; Dec. 3, 2024; Oct. 1, 2025>
1. A request shall have been made by the head of the relevant central administrative agency [including requests from the head of an investigative agency for photographs and videos, compilations, composites, processed products, or their duplicates (including duplicates of duplicates) under Articles 14 and 14-2 of the Special Act on the Punishment of Sexual Crimes, and for child or youth sexual exploitation materials under subparagraph 5 of Article 2 of the Act on the Protection of Children and Youth against Sex Offenses];
2. A demand for correction was made pursuant to subparagraph 4 of Article 22 of the Act on the Establishment and Operation of Korea Media and Communications Commission after deliberation by the Communications Standards Commission within 7 days from the date the request under subparagraph 1 had been received;
3. The provider of information and communications services or the manager or operator of the message board has not complied with the demand for correction.
(4) The Korea Media and Communications Commission shall provide an opportunity to the provider of information and communications services or the manager, operator, or relevant user of the message board to whom an order is to be issued pursuant to paragraph (2) or (3) to present his or her opinion in advance; provided, the Commission need not provide an opportunity to present an opinion in any of the following cases: <Amended on Oct. 1, 2025>
1. Where it is necessary to make an urgent disposition for public safety or welfare;
2. Where there is a ground prescribed by Presidential Decree to believe that it is obviously impracticable or evidently unnecessary to hear an opinion;
3. Where a person concerned clearly manifests his or her intent to give up the opportunity to present his or her opinion.
(5) An information and communication service provider that installs and operates a domestic server for temporary storage of data and meets the criteria prescribed by the Presidential Decree for the type and scale of business shall take the following technical and administrative measures to prevent the distribution of information falling under the subparagraphs of paragraph (1): <Added on Jan. 23, 2024>
1. Measures to identify whether the information described in each of the subparagraphs of paragraph (1) is stored on the server and to promptly restrict access to it, subject to deliberation by the Communications Standards Commission in accordance with paragraphs 2 and 3;
2. Measures to request the person who posted the information identified under subparagraph 1 to prohibit the distribution of the relevant information;
3. Measures to have the actual status of the operation and management of the measures under subparagraph 1 recorded automatically in the system, and to keep it for the period prescribed by Presidential Decree;
4. Other measures prescribed by Presidential Decree as necessary to prevent the distribution of information falling under the subparagraphs of paragraph (1).
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Articles 44-8 (Protection of children in interactive information and communications services)
When a provider of information and communications services provides children under 14 years of age with information and communications services based on a system that processes information by engaging in a conversation with a human user through text messages or voice chat, it shall endeavor not to provide information containing inappropriate content to such children.
[This Article Added on Dec. 24, 2018]
법령 이단보기
Article 44-9 (Persons responsible for preventing circulation of illegally filmed materials or the like)
(1) A provider of information and communications services who meets the criteria prescribed by Presidential Decree, such as the average number of daily users, sales, and types of business, shall designate a person (hereinafter referred to as a "person responsible for preventing the circulation of illegally filmed materials or the like") responsible for preventing the circulation of the following information (hereinafter referred to as "illegally filmed materials or the like") available to the public through the information and communications network the provider operates or manages:
1. A photograph or video or copies thereof (including copies of such copies) Article 14 of the Act on Special Cases concerning the Punishment of Sexual Crimes;
2. Compilations, composites, processed products, or their duplicates (including duplicates of duplicates) under Article 14-2 of the Act on Special Cases concerning the Punishment of Sexual Crimes;
3. Child or youth sexual exploitation materials defined in subparagraph 5 of Article 2 of the Act on the Protection of Children and Youth against Sex Offenses.
(2) Persons responsible for preventing the circulation of illegally filmed materials or the like shall take measures necessary to prevent the circulation thereof, such as deleting them and blocking access thereto, pursuant to Article 22-5 (1) of Telecommunications Business Act.
(3) Necessary matters regarding the number of persons responsible for preventing the circulation of illegally filmed materials or the like, qualification requirements, training, and other matters shall be prescribed by Presidential Decree.
[This Article Added on Jun. 9, 2020]
법령 이단보기
Article 44-10 (Defamation dispute conciliation division)
(1) The Communications Standards Commission shall have a defamation dispute conciliation division comprised of 5 members or fewer for efficient conciliation of disputes arising in connection with information that intrudes other persons' privacy, defames other persons, or violates other persons' rights, including a member or more holding the qualification of attorney-at-law. <Amended on Jun. 9, 2020>
(2) The members of the defamation dispute conciliation division shall be commissioned by the chairperson of the Communications Standards Commission with consent of the Communications Standards Commission.
(3) Articles 33-2 (2) and 35 through 39 shall apply mutatis mutandis to the procedures for conciliation of disputes by the defamation dispute conciliation division. In such cases, "Dispute Mediation Committee" shall be construed as "Communications Standards Commission", and "disputes over personal information" as "disputes arising in connection with information that intrudes other persons' privacy, defames other persons, or violates other persons' rights among information circulated through information and communications networks".
(4) Matters necessary for the installation and operation of the defamation dispute conciliation division and the conciliation of disputes, and other related matters shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
CHAPTER VI SECURING OF STABILITY OF INFORMATION AND COMMUNICATIONS NETWORKS
법령 이단보기
Article 45 (Securing of stability of information and communications networks)
(1) Any of the following persons shall take protective measures to secure the reliability of the information and ensure the stability of the information and communications networks used to provide information and communications services: <Amended on Jun. 9, 2020>
1. A provider of information and communications services;
2. A person who manufactures or imports devices, equipment, and facilities prescribed by Presidential Decree, among devices, equipment, and facilities which can transmit or receive information by being connected to an information and communications network (hereinafter referred to as "devices and the like connected to an information and communications network").
(2) The Minister of Science and ICT may determine and give public notice of guidelines for protective measures for information (hereinafter referred to as "information protection guidelines"), specifying details of the protective measures under paragraph (1) and may recommend any of the persons falling under paragraph (1) to observe the guidelines. <Amended on Feb. 17, 2012; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
(3) The information protection guidelines shall contain descriptions of the following: <Amended on Mar. 22, 2016; Jun. 9, 2020>
1. Technical and physical protective measures, including installation and operation of an information security system, to prevent or counteract access to or invasion upon an information and communications network by a person with no due authorization;
2. Technical protective measures for preventing unlawful leakage, forgery, alteration, or deletion of information;
3. Technical and physical protective measures for securing the state of enabling continuous use of information and communications networks;
4. Administrative protective measures for stabilization of information and communications networks and protection of information, including securing human resources, organization, and expenses and establishing related plans;
5. Technical protective measures for information security of devices and the like connected to an information and communications network.
(4) The Minister of Science and ICT may request the heads of relevant central administrative agencies to reflect the content of the information security guidelines in standards for testing, inspection, certification, etc. related to devices and the like connected to information and communications networks with regard to the substantive areas under their jurisdictions. <Added on Jun. 9, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 45-2 (Information security pre-inspection)
(1) If a provider of information and communications services intends to newly establish an information and communications network or to provide information and communications services, he or she shall take the matters regarding information security into account in planning or designing thereof.
(2) The Minister of Science and ICT may recommend a person who intends to operate the information and communications services or the telecommunications business falling under any of the following to take protective measures in accordance with the information security pre-inspection standards as prescribed by Presidential Decree: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. The information and communications services or telecommunications business prescribed by Presidential Decree, for which authorization or permission by the Minister of Science and ICT should be obtained or registration with or report to the Minister pursuant to this Act or other statutes and regulations;
2. The information and communications services or telecommunications business prescribed by Presidential Decree and fully or partially financed by the Minister of Science and ICT for the business expenses thereof.
(3) Standards, methods, procedures, fees for the information security pre-inspection standards under paragraph (2) and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Feb. 17, 2012]
법령 이단보기
Article 45-3 (Designation of chief information security officers)
(1) A provider of information and communications services shall designate an executive officer or employee meeting the standards prescribed by Presidential Decree as a chief information security officer and shall file a report thereon to the Minister of Science and ICT, in order to ensure the security of information and communications systems, etc. and safe management of information; provided, a provider of information and communications services whose total assets, turnover, and the like meet the criteria prescribed by Presidential Decree need not file a report on such chief information security officer. <Amended on May 28, 2014; Jul. 26, 2017; Jun. 12, 2018; Jun. 8, 2021>
(2) Methods and procedures for reporting under paragraph (1) and other matters shall be prescribed by Presidential Decree. <Added on May 28, 2014>
(3) No chief information security officer designated and reported under the main clause of paragraph (1) (limited to where a provider of information and communications services whose total assets, turnover, and the like meet the criteria prescribed by Presidential Decree) may hold another office concurrently, other than perform duties referred to in paragraph (4). <Added on Jun. 12, 2018>
(4) A chief information security officer shall perform the following duties: <Amended on Jun. 8 2021>
1. The chief information security officer shall be responsible for the following duties:
(a) To formulate, implement, and improve information protection plans;
(b) To conduct regular audit and improve the actual conditions and practices of information protection;
(c) To identify and evaluate risks relating to information protection and develop countermeasures for information protection;
(d) To formulate and implement plans for information protection education and simulation training;
2. The chief information security officer may hold another office concurrently to perform the following:
(a) Duties of providing information security disclosure under Article 13 of the Act on the Promotion of Information Security Industry;
(b) Duties of chief information security officers under Article 5 (5) of the Act on the Protection of Information and Communications Infrastructure;
(c) Duties of chief information security officers under Article 21-2 (4) of the Electronic Financial Transactions Act;
(d) Duties of privacy officers under Article 31 (2) of the Personal Information Protection Act;
(e) Taking other measure necessary for information protection in accordance with this Act or any other relevant statute or regulation.
(5) A provider of information and communications services may establish and operate a council of chief information security officers comprised of chief information security officers prescribed in paragraph (1) in order to jointly prevent and respond to a cyber security incident, share necessary information, and implement other joint programs prescribed by Presidential Decree. <Amended on May 28, 2014; Jun. 12, 2018>
(6) The Government may fully or partially provide support to the Council of Information Security Officers under paragraph (5) for expenses incurred in conducting its activities. <Amended on May 28, 2014; Jun. 22, 2015; Jun. 12, 2018>
(7) Necessary matters regarding qualifications, etc. of chief information security officers shall be prescribed by Presidential Decree. <Added on Jun. 12, 2018>
[This Article Added on Feb. 17, 2012]
법령 이단보기
Article 46 (Protection of integrated information and communication facilities)
(1) Among the following information and communications service providers who meet the standards prescribed by Presidential Decree in terms of the scale, etc. of information and communications facilities (hereinafter referred to as "integrated information and communication facility operator, etc.") shall take protective measures, as prescribed by Presidential Decree, in order to operate information and communications facilities in a stable manner: <Amended on Jun. 9, 2020; Jan. 3, 2023>
1. A person who operates and manages integrated information and communications facilities to provide information and communications services for others (hereinafter referred to as "integrated information and communication facility operator");
2. A person who operates and manages integrated information and communication facilities directly to provide his or her own information and communications services.
(2) Every integrated information and communication facility operator shall purchase insurance policies as prescribed by Presidential Decree to cover damages that may be caused by destruction or damage of integrated information and communication facilities or any other trouble in operation.
(3) The Minister of Science and ICT may regularly inspect whether protective measures under paragraph (1) have been implemented and may order the integrated information and communication facility operator, etc. to take corrective measures with respect to matters requiring supplementation; provided, in cases of matters for which inspection under Article 36-2 (2) of the Framework Act on Broadcasting Communications Development has been conducted with respect to an integrated information and communication facility operator, etc. such matters shall be excluded from the inspection on whether protective measures under paragraph (1) have been implemented. <Added on Jan. 3, 2023>
(4) The Minister of Science and ICT may request providers of information and communications services falling under any subparagraph of paragraph (1), the heads of relevant central administrative agencies, the heads of local governments, and the heads of institutions designated as public institutions pursuant to Article 4 of the Act on the Management of Public Institutions to submit materials in order to verify whether they fall under the category of integrated information and communication facility operators and to conduct an inspection under paragraph (3). Upon receipt of a request for submission of materials in such cases, a person in receipt of such request shall comply therewith, in the absence of good cause, and Article 64 (6) and (9) through (11) shall apply mutatis mutandis to the procedures, methods, etc. for requesting submission of materials. <Added on Jan. 3, 2023>
(5) Article 64-2 shall apply mutatis mutandis to the protection and destruction of materials submitted pursuant to paragraph (4). <Added on Jan. 3, 2023>
(6) Where the provision of information and communications services has been interrupted during the period prescribed by Presidential Decree due to a disaster, calamity, or other physical or functional defects, an integrated information and communication facility operator shall report to the Minister of Science and ICT without delay the current status of interruption, causes of such interruption, emergency measures, and recovery measures. In such cases, the Minister of Science and ICT may provide technical support necessary for the recovery and protection of integrated information and communications facilities. <Added on Jan. 3, 2023>
(7) A provider of information and communications services who has leased an integrated information and communications facility provided by an integrated information and communication facility operator shall actively cooperate with the integrated information and communication facility operator in implementing protective measures under paragraph (1), and if exclusively operating and managing the leased facility, including directly installing and operating facilities necessary for protective measures under paragraph (1) or controlling access to such facilities, he or she shall take measures prescribed by Presidential Decree, such as implementing protective measures and reporting service interruption due to a disaster, etc. <Added on Jan. 3, 2023>
(8) The Minister of Science and ICT may entrust affairs regarding the inspection under paragraph (3) and technical support under paragraph (6) to a specialized organization prescribed by Presidential Decree. <Added on Jan. 3, 2023>
(9) The frequency and method of inspection under paragraph (3), the method of reporting under paragraph (6), and other necessary matters shall be prescribed by Presidential Decree. <Added on Jan. 3, 2023>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 46-2 (Emergency countermeasures of integrated information and communication facility operators)
(1) In any of the following cases, an integrated information and communication facility operator may fully or partially interrupt the provision of relevant services, as stipulated in the terms and conditions of use: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
1. If it is anticipated that an abnormality found in the information system of a person using an integrated information and communication facility (hereinafter referred to as "facility user") may cause serious disruption to the information and communications network of other facility users or the information and communication network of the integrated information and communication facility;
2. If it is anticipated that an external cyber security incident will probably cause serious disruption to the integrated information and communication facility;
3. If there occurs a serious cyber security incident and the Minister of Science and ICT or the Korea Internet and Security Agency requests the interruption of the services.
(2) When the integrated information and communication facility operator interrupts his or her services in accordance with paragraph (1), he or she immediately notify users of the integrated information and communication facility the interruption of services, specifically stating the reasons for the interruption, the date, time, period, and details of the interruption, and other related matters.
(3) Once the event that caused the interruption of services ceases to exist, the integrated information and communication facility operator shall resume his or her services immediately.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 46-3 Deleted. <Feb. 17, 2012>
법령 이단보기
Article 47 (Certification of information security management systems)
(1) With respect to a person who establishes and operates a comprehensive management system, including administrative, technical, and physical protective measures, for ensuring stability and reliability of an information and communications network (hereinafter referred to as "information security management system"), the Minister of Science and ICT may certify as to whether such person meets the standards under paragraph (4). <Amended on Feb. 17, 2012; Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>
(2) A telecommunications business operator under subparagraph 8 of Article 2 of the Telecommunications Business Act, or any of the following persons who provides or intermediates the provision of information by using telecommunications services of any telecommunications business operator, shall receive the certification under paragraph (1): <Added on Feb. 17, 2012; Dec. 1, 2015; Dec. 24, 2018; Jun. 9, 2020; Jan. 23, 2024>
1. A person who renders information and communications network services, as prescribed by Presidential Decree, as a person registered pursuant to Article 6 (1) of the Telecommunications Business Act (hereinafter referred to as a "major provider of information and communications services");
2. A integrated information and communication facility operator;
3. A person meeting the standards prescribed by Presidential Decree, whose sales, tax revenue, or any similar for the previous year is at least 150 billion won, whose sales in the information and communications service sector for the previous year is at least 10 billion won, or whose average daily users for the previous year is at least 1 million.
(3) Where a person required to be certified in accordance with paragraph (2) is certified for conformity with international standards for information protection or takes measures for information protection, as prescribed by Decree of the Ministry of Science and ICT, the Minister of Science and ICT may omit part of certification examination under paragraph (1). In such cases, the detailed scope of omitted certification examination shall be determined and publicly notified by the Minister of Science and ICT. <Added on Dec. 1, 2015; Jul. 26, 2017>
(4) For the purpose of certification of an information security management system under paragraph (1), the Minister of Science and ICT may determine and publicly notify certification standards, etc. including countermeasures for administrative, technical, and physical protection and other necessary matters. <Amended on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
(5) The period of validity of the certification of an information security management system under paragraph (1) shall be 3 years; provided, upon receipt of any information security management gradein accordance with Article 47-5 (1), the certification under paragraph (1) shall be deemed effective during the period of validity of such rating. <Added on Feb. 17, 2012; Dec. 1, 2015>
(6) The Minister of Science and ICT may have the Korea Internet and Security Agency or any institution designated by the Minister of Science and ICT (hereinafter referred to as "certification body for information security management systems") perform the following affairs related to the certification under paragraphs (1) and (2): <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Examination to verify whether the information security management system established by an applicant for certification meets the certification standards under paragraph (4) (hereinafter referred to as "examination for certification");
2. Review on the results of examination for certification;
3. Issuance and management of written certifications;
4. Follow-up management of granted certifications;
5. Fosterage and qualification management of the certification examiners of information security management systems;
6. Other affairs regarding the certification of information security management systems.
(7) If necessary for the efficient conduct of affairs related to certification, the Minister of Science and ICT may designate an institution that performs affairs related to examination for certification (hereinafter referred to as "examination institution for information security management systems"). <Added on Dec. 1, 2015; Jul. 26, 2017>
(8) The Korea Internet and Security Agency, a certification body for information security management systems, and an examination institution for information security management systems shall, in order to enhance the efficiency of information security management systems, perform follow-up management at least once a year and notify the Minister of Science and ICT of the results thereof. <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
(9) A person who has received the certification of an information security management system in accordance with paragraphs (1) and (2) may indicate or publicize the content of the certification, as prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>
(10) The Minister of Science and ICT may revoke the certification where any of the following grounds is found; provided, in cases falling under subparagraph 1, the Minister of Science and ICT shall revoke the certification: <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Having received the certification of an information security management system by fraud or other improper means;
2. Falling short of the certification standards under paragraph (4);
3. Refusing or obstructing the follow-up management under paragraph (8).
(11) Methods and procedures for, and scope and fees of, certification under paragraphs (1) and (2), methods and procedures for follow-up management under paragraph (8), methods and procedures for revoking certification under paragraph (10), and other necessary matters shall be prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>
(12) Standards and procedures for, and period of validity of, the designation of a certification body for information security management systems and an examination institution for information security management systems, and other necessary matters shall be prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 47-2 (Revocation of designation of certification body for information security management systems or examination institution for information security management systems)
(1) If a corporation or organization designated as a certification body for information security management systems or an examination institution for information security management systems pursuant to Article 47 falls under any of the following cases, the Minister of Science and ICT may revoke the designation or order it to fully or partially suspend the relevant business for a specified period not exceeding 1 year; provided, in cases falling under subparagraph 1 or 2, the Minister of Science and ICT shall revoke the designation: <Amended on Feb. 17, 2012; Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Where it has obtained the designation of a certification body for information security management systems or an examination institution for information security management systems by fraud or other improper means;
2. Where it has performed certification or examination for certification during a business suspension period;
3. Where it has not performed certification or examination for certification without good cause;
4. Where it has performed certification or examination for certification, in violation of Article 47 (11);
5. Where it no longer meets the standards for designation under Article 47 (12).
(2) Matters necessary for the revocation of designation and suspension of business under paragraph (1) and other related matters shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
[Title Amended on Dec. 1, 2015]
법령 이단보기
Article 47-3 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 47-4 (Protection of users' information)
(1) The Government may prescribe guidelines necessary for protection of information of users to recommend users to observe the guidelines and may take measures necessary for preventing cyber security incidents and precluding spread thereof, such as inspection of vulnerabilities and technical support.
(2) The Government may entrust affairs regarding measures taken under paragraph (1) to the Korea Internet and Security Agency or a specialized organization prescribed by Presidential Decree. <Added on Jun. 9, 2020>
(3) If a major provider of information and communications services foresees that a serious problem is likely to occur in the information system of a user who uses the services, the information and communications network, or similar provided by such provider because of an occurrence of a serious cyber security incident on the information and communications network, the provider may request the user to take necessary protective measures as stipulated by the terms and conditions of use and may place a temporary restriction on access to the relevant information and communications network if the user does not perform as requested. <Amended on Jun. 9, 2020>
(4) When a software business operator defined in Article 2 of the Software Promotion Act has produced a program that can address security vulnerabilities, he or she shall notify the Korea Internet and Security Agency of such production and shall notify users of the software of the production at least twice within 1 month from the date of production. <Amended on Apr. 22, 2009; Jun. 9, 2020>
(5) Specific details that shall be stipulated by the terms and conditions of use with respect to the request for protective measures under paragraph (3) and other related matters shall be prescribed by Presidential Decree. <Amended on Jun. 9, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
[This Article Moved from Article 47-3 <Feb. 17, 2012>]
법령 이단보기
Article 47-5 (Assignment of rating for information security management grade)
(1) A person who has obtained the certification of an information security management system pursuant to Article 47 is entitled to receive a information security management grade from the Minister of Science and ICT in order to enhance the level of a corporate's management of its comprehensive information security and to secure users' reliability on information security services. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Minister of Science and ICT may authorize the Korea Internet and Security Agency to perform the affairs of assigning ratings under paragraph (1). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) A person who has obtained an information security management grade pursuant to paragraph (1) may indicate the obtained grade or advertise the details of such grade as prescribed by Presidential Decree.
(4) Where the Minister of Science and ICT finds any of the following cases, he or she may revoke the granted rating; provided, in the cases falling under subparagraph 1, the Minister of Science and ICT shall revoke the granted rating: <Amended on Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Where a person has obtained a information security management grade by fraud or other improper means;
2. Where a person falls short of the standards for assigning grades pursuant to paragraph (5).
(5) Standards for review in assigning ratings pursuant to paragraph (1); the methods and procedures for and fees of assigning ratings; the effective term of ratings; the methods and procedures for revocation of ratings pursuant to paragraph (4); and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Feb. 17, 2012]
법령 이단보기
Article 47-6 (Giving monetary award to person reporting information security vulnerability)
(1) The Government may pay a monetary award, within the budget, to a person who has reported any information security vulnerability relating to information communications services, devices and the like connected to information and communications networks, or software (hereinafter referred to as "information security vulnerability") to prevent cyber security incidents and stop damage from spreading.
(2) Persons eligible for monetary awards under paragraph (1), the standards and procedures for the payment of such monetary awards, and other relevant matters shall be prescribed by Presidential Decree.
(3) The Government may entrust affairs regarding the payment of monetary awards under paragraph (1) to the Korea Internet and Security Agency.
[This Article Added on Jun. 10, 2022]
법령 이단보기
Article 47-7 (Special cases concerning certification of information security management system)
(1) The Minister of Science and ICT may relax and apply the certification standards and procedures under Article 47 to persons who fall under any of the following subparagraphs among persons seeking certification pursuant to Article 47 (1) and (2):
1. A small enterprise under Article 2 (2) of the Framework Act on Small and Medium Enterprises;
2. Any other person who meets the criteria prescribed by the Presidential Decree according to the scale and characteristics of information and communication services.
(2) The Minister of Science and ICT may provide necessary support, including costs and technology related to paragraph (1), to ensure the stability and reliability of the information and communication network.
(3) The Minister of Science and ICT may determine and publicly notify the certification standards and procedures under paragraph (1) and other necessary matters.
[This Article Added on Jan. 23, 2024]
법령 이단보기
Article 48 (Prohibition on intrusive acts on information and communications networks)
(1) No one shall intrude on an information and communications network without a rightful authority for access or beyond a permitted authority for access.
(2) No one shall damage, destroy, alter, or forge an information and communications system, data, program, or similar without good cause, nor shall he or she convey or spread a program that is likely to interrupt operation of such system, data, program, or similar (hereinafter referred to as "malicious program").
(3) No one shall cause a trouble to an information and communications network to interfere with stable operation of the information and communications network by sending a large amount of signals or data, letting the network process an illegitimate order, or doing the similar actions.
(4) No person shall install a program or technical device that enables access to the information and communication network circumventing the normal protection and authentication procedures of the information and communication network without good cause on the information and communication network or the information system related to the information and communication network, or deliver or distribute it. < Added on Jan. 23, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 48-2 (Countermeasures against cyber security incidents)
(1) The Minister of Science and ICT shall perform the following business affairs to take proper countermeasures against cyber security incidents and may have the Korea Internet and Security Agency fully or partially perform the business affairs, if necessary to do so: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
1. Collection and spread of information about cyber security incidents;
2. Precaution and warning of computer security incidents;
3. Emergency measures against cyber security incidents;
4. Other countermeasures against cyber security incidents prescribed by Presidential Decree.
(2) Any of the following persons shall furnish the Minister of Science and ICT or the Korea Internet and Security Agency with the information related to cyber security incidents, including statistics by type of cyber security incidents, statistics of traffic of the relevant information and communications network, and statistics of use by access channel, as prescribed by Presidential Decree: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
1. A major provider of information and communications services;
2. A integrated information and communication facility operator;
3. Other persons prescribed by Presidential Decree from among those who operate an information and communications network.
(3) The Korea Internet and Security Agency shall analyze the information under paragraph (2) and report it to the Minister of Science and ICT. <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017; Jul. 26, 2017>
(4) If a business operator obligated to furnish the information in accordance with paragraph (2) refuses to do so without good cause or furnishes false information, the Minister of Science and ICT may order the business operator to make a correction within a reasonable period. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(5) The Minister of Science and ICT or the Korea Internet and Security Agency shall use the information furnished in accordance with paragraph (2) properly within the extent necessary for taking countermeasures against a cyber security incident. <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
(6) If necessary to take countermeasures against a cyber security incident, the Minister of Science and ICT or the Korea Internet and Security Agency may request a person falling under any subparagraph of paragraph (2) to provide human resources for assistance. <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 48-3 (Report on cyber security incidents)
(1) If a cyber security incident occurs, a provider of information and communications services shall immediately report it to the Minister of Science and ICT or the Korea Internet and Security Agency; in such cases, if a provider of information and communications services has already notified or reported a cyber security incident in accordance with another statute, such report mandated under the former part shall be deemed to have been made: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022>
1. Deleted; <Jun. 10, 2022>
2. Deleted. <Jun. 10, 2022>
(2) Upon receipt of a report on a cyber security incident under paragraph (1) or becoming aware of a cyber security incident, the Minister of Science and ICT or the Korea Internet and Security Agency shall take necessary measures under the subparagraphs of Article 48-2 (1). <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
(3) Upon receipt of a notice of or report on a cyber security incident under the latter part of paragraph (1), the head of a related agency shall share relevant information with the Minister of Science and ICT or the Korea Internet and Security Agency without delay. <Added on Jun. 10, 2022>
(4) Matters necessary for the time, method, and procedures for reporting under paragraph (1) shall be prescribed by Presidential Decree. <Added on Feb. 13, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 48-4 (Analysis of causes of cyber security incidents)
(1) If a cyber security incident occurs, a person who operates an information and communications network, including a provider of information and communications services, shall analyze the causes of the cyber security incident; respond thereto, based on the results of analysis, for stopping damage from spreading; and take measures necessary to recover from the damage and prevent a recurrence of such cyber security incident. <Amended on Jun. 10, 2022>
(2) If a cyber security incident occurs in an information and communications network operated by a provider of information and communications services, the Minister of Science and ICT may analyze the causes of the cyber security incident and develop countermeasures to stop damage from spreading, to respond to such incident, to recover from damage, and to prevent a recurrence of such incident; and may order the provider of information and communications services (excluding public institutions) to implement necessary measures. <Added on Jun. 10, 2022; Feb. 13, 2024>
(3) The Minister of Science and ICT may inspect whether measures under paragraph (2) have been implemented and order the provider of information and communications services to make a correction for matters requiring supplementation. <Added on Feb. 13, 2024>
(4) Where a serious cyber security incident occurs in an information and communications network operated by a provider of information and communications services, the Minister of Science and ICT may organize a private-public joint investigation team having expertise in the protection of information and analyze the causes of such cyber security incident if necessary for analyzing such causes and developing countermeasures pursuant to paragraph (2). <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(5) If deemed necessary for analyzing the causes of a cyber security incident and developing countermeasures pursuant to paragraph (2), the Minister of Science and ICT may order the relevant provider of information and communications services to preserve relevant data, such as records on access to the relevant information and communications network. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(6) The Minister of Science and ICT may demand a provider of information and communications services to submit data related to a cyber security incident, if deemed necessary for analyzing the causes of such cyber security incident and developing countermeasures pursuant to paragraph (2); and in the case of a serious cyber security incident, the Minister may require public officials under his or her jurisdiction or a private-public joint investigation team under paragraph (4) to enter the place of business of the relevant person and to investigate the causes of the incident; provided, data corresponding to the communication confirmation data defined in subparagraph 11 of Article 2 of the Protection of Communications Secrets Act shall be submitted in the manner prescribed by that Act. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(7) The Minister of Science and ICT or the private-public joint investigation team shall not use the information learned through the data submitted and the investigation conducted in accordance with paragraph (6) for any purpose other than the analysis of the causes of the cyber security incident and development of countermeasures and shall destroy it immediately after the analysis of the causes is completed. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(8) Matters necessary for the methods and procedures for inspection under paragraph (3), the organization and operation of a private-public joint investigation team under paragraph (4), the protection of data submitted pursuant to paragraph (6), the methods and procedures for investigations, etc. shall be prescribed by Presidential Decree. <Amended on Jun. 10, 2022; Feb. 13, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 48-5 (Countermeasures against cyber security incidents related to devices and the like connected to information and communications networks)
(1) Where a computer security incident related to devices and the like connected to an information and communications network occurs, the Minister of Science and ICT may analyze the cause of the relevant computer security incident in cooperation with the heads of relevant central administrative agencies.
(2) Where there occurs a computer security incident related to devices and the like connected to an information and communications network, which is likely to cause any danger to the lives, bodies, or property of citizens, the Minister of Science and ICT may request the heads of relevant central administrative agencies to take the following measures:
1. Measures, such as the inspection of vulnerabilities and technical support under Article 47-4 (1);
2. Measures necessary for precluding the spread of damage;
3. Improvement of other systems for the information security of devices and the like connected to an information and communications network.
(3) Where there occurs a cyber security incident related to devices and the like connected to an information and communications network, the Minister of Science and ICT may recommend a person who manufactures or imports the relevant devices and the like connected to an information and communications network to take measures, such as improving vulnerabilities thereof, for preventing an expansion or recurrence of the cyber security incident.
(4) The Minister of Science and ICT may provide support to a specialized organization prescribed by Presidential Decree for expenses incurred in conducting the following business activities:
1. Research to formulate guidelines for information security related to devices and the like connected to information and communications networks;
2. Research for improving standards for testing, inspection, authentication, etc. related to devices or the like connected to information and communications networks.
[This Article Added on Jun. 9, 2020]
법령 이단보기
Article 48-6 (Certification of devices and the like connected to information and communications networks)
(1) Where devices and the like connected to an information and communications network meet the certification standards under paragraph (2) as a result of an examination conducted by a testing agency for certification under paragraph (4), the Minister of Science and ICT may grant information security certification.
(2) The Minister of Science and ICT may determine and publicly notify certification standards for ensuring the stability of information and communications networks and securing the reliability of information, with regard to the information security certification under paragraph (1) (hereinafter referred to as "information security certification").
(3) Where a person who has obtained information security certification falls under any of the following subparagraphs, the Minister of Science and ICT may revoke such certification; provided, in cases falling under subparagraph 1, such certification shall be revoked:
1. Where he or she has obtained information security certification by fraud or other improper means;
2. Where he or she fails to meet the certification standards provided for in paragraph (2).
(4) In order to efficiently conduct tests verifying whether devices and the like connected to an information and communications network meet the certification standards referred to in paragraph (2), the Minister of Science and ICT may, if necessary, designate, as a testing agency for certification, an institution satisfying the designation standards prescribed by Presidential Decree.
(5) Where a testing agency for certification designated pursuant to paragraph (4) (hereinafter referred to as a "testing agency for certification") falls under any of the following cases, the Minister of Science and ICT may revoke such designation; provided, in cases falling under subparagraph 1, such certification shall be revoked:
1. Where it has obtained the designation by fraud or other improper means;
2. If it fails to meet the criteria for designation under paragraph (4).
(6) The Minister of Science and ICT may entrust affairs related to information security certification and the revocation thereof to the Korea Internet and Security Agency.
(7) Necessary matters regarding procedures, etc. for information security certification and cancellation of such certification and procedures, etc. for designation of testing agencies for certification and cancellation of such designation shall be prescribed by Presidential Decree.
[This Article Added on Jun. 9, 2020]
법령 이단보기
Article 49 (Protection of secrets)
No one shall damage another person's information processed, stored, or transmitted through an information and communications network, nor shall he or she infringe, misappropriate, or divulge another person's secret.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 49-2 (Prohibition on collection of information by deception)
(1) No one shall collect another person's information or entice another person to furnish information through an information and communications network by deception.
(2) Whenever a provider of information and communications services discovers a violation of paragraph (1), he or she immediately report it to the Minister of Science and ICT or the Korea Internet and Security Agency. <Amended on Apr. 22, 2009; Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020>
(3) Upon receipt of a report under paragraph (2) or becoming aware of a violation of paragraph (1), the Minister of Science and ICT or the Korea Internet and Security Agency shall take the following measures as necessary: <Amended on Apr. 22, 2009; Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020; Jun. 10, 2022>
1. Collection and diffusion of the information related to the violation;
2. Precaution and warning of similar damage;
3. Emergency measures for preventing damage and spread thereof, including requesting a provider of information and communications services to conduct all or some of the following:
(a) Blockage of access paths;
(b) Suspension of the provision of information and communications services for telephone numbers used for a violation described in paragraph (1);
(c) Notification to relevant users of the fact that they have been exposed to a violation described in paragraph (1).
(4) To take measures referred to in paragraph (3) 3, the Minister of Science and ICT may order providers of information and communications services to take necessary measures, such as sharing among themselves information regarding deception through information and communications networks. <Added on Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020>
(5) Upon receipt of a request made under paragraph (3) 3, a provider of information and communications services may take the relevant measures in the manner prescribed by relevant terms and conditions of use. <Added on Jun. 10, 2022>
(6) Details to be stipulated by the terms and conditions of use under paragraph (5) shall be prescribed by Presidential Decree. <Added on Jun. 10, 2022>
[This Article Wholly Amended on Jun. 13, 2008]
[Title Amended on Feb. 4, 2020]
법령 이단보기
Article 49-3 (Suspension of provision of telecommunications services for telephone numbers used as means of deception)
(1) When a person prescribed by Presidential Decree, including the Commissioner General of the National Police Agency, the Prosecutor General, and the Governor of the Financial Supervisory Service, has verified telephone numbers used as means of deception described in Article 49-2 (1), the person may request the Minister of Science and ICT to suspend the provision of telecommunications services for the relevant telephone numbers.
(2) A user whose telecommunication services have been suspended due to a request made paragraph (1) may file an objection with the agency that has requested the suspension.
(3) Matters necessary for procedures, etc. for filing an objection under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Added on Jun. 10, 2022]
법령 이단보기
Article 50 (Restrictions on transmission of advertising information for profit-making purpose)
(1) If any person intends to transmit advertising information for profit-making purpose by using an electronic transmission medium, he or she shall obtain express prior consent from an addressee of such information; provided, he or she need not obtain prior consent in any of the following cases: <Amended on Mar. 22, 2016; Jun. 9, 2020>
1. Where a person who has directly collected contact details from the addressee in his or her dealings of goods, etc. intends to transmit advertising information for profit-making purpose on the same kinds of goods, etc. as those he or she manages and has dealt with the addressee within a period prescribed by Presidential Decree;
2. Where a telemarketer under the Act on Door-to-Door Sales informs prospective customers of the collection source of their personal information by voice, and solicits them to buy products or services by means of a telephone call.
(2) Notwithstanding paragraph (1), where an addressee expresses his or her intention to refuse to receive information or revokes his or her prior consent, no person who intends to transmit advertising information for profit-making purpose by using an electronic transmission medium shall transmit advertising information for profit-making purpose.
(3) Notwithstanding paragraph (1), a person who intends to transmit advertising information for profit-making purpose by using an electronic transmission medium during the time between 9:00 pm and 8:00 am of the following day shall obtain express prior consent from the addressee of such information; provided, the forgoing shall not apply to media prescribed by Presidential Decree.
(4) A person who transmits advertising information for profit-making purpose by using an electronic transmission medium shall specify the following matters in advertising information, as prescribed by Presidential Decree:
1. The name and contact details of a sender;
2. Matters regarding measures and methods by which an addressee can readily express his or her intention to refuse to receive information or to revoke his or her consent to receive information.
(5) A person who transmits advertising information for profit-making purpose by using an electronic transmission medium shall not engage in any of the following acts: <Amended on Jan. 23, 2024>
1. Act of evading or preventing addressees from opting out or withdrawing their consent to receive advertising information;
2. Act of automatically generating an addressee's contact information, such as a telephone number and e-mail address, using a combination of numbers, symbols, or letters;
3. Act of automatically registering a telephone number or e-mail address for the purpose of transmitting advertising information for profit-making purpose;
4. Various acts to conceal the identity of the sender of advertising information or the source of the transmission of the advertisement;
5. Various acts to deceive an addressee into responding for the purpose of transmitting advertising information for profit-making purpose.
(6) A person who transmits advertising information for profit-making purpose by using an electronic transmission medium shall take necessary measures so that an addressee does not incur any cost, such as telephone charges, when the addressee refuses to receive or revokes his or her consent to receive such information, as prescribed by Presidential Decree.
(7) A person who intends to transmit advertising information for profit-making purpose using an electronic transmission medium shall, when an addressee expresses his or her intention to consent to the receipt of such information under paragraphs (1) and (3) refuse to receive, or revoke his or her consent to receive, advertising information under paragraph (2), inform the relevant addressee of the outcomes of measures taken in relation to consent to receive, refusal to receive, or revocation of consent to receive, advertising information, as prescribed by Presidential Decree. <Amended on Jan. 23, 2024>
(8) A person who obtains consent to receive advertising information pursuant to paragraph (1) or (3) shall regularly verify whether an addressee of advertising information consents to receive such information, as prescribed by Presidential Decree.
[This Article Wholly Amended on May 28, 2014]
법령 이단보기
Article 50-2 Deleted. <May 28, 2014>
법령 이단보기
Article 50-3 (Entrustment of transmission of advertising information for profit-making purpose)
(1) A person who has entrusted the transmission of advertising information for profit-making purpose to a third party shall control and oversee the third party to ensure that the third party does not violate Article 50. <Amended on May 28, 2014>
(2) A person entrusted with the transmission of advertising information for profit-making purpose under paragraph (1) shall be deemed an employee of a person who has entrusted the transmission of information in determining liability for damages caused by a violation of a statute related to such business affair. <Amended on Jun. 9, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 50-4 (Restrictions on rendering information transmission services)
(1) A provider of information and communications services may take measures to refuse rendering corresponding services in any of the following cases:
1. If transmission or reception of advertising information hinders or is likely to hinder rendering the services;
2. If a user does not want to receive advertising information;
3. Deleted. <May 28, 2014>
(2) If a provider of information and communications services intends to take any measure for refusal under paragraph (1) or (4), he or she shall include matters regarding the refusal of the relevant services in the terms and conditions of a contract for use of information and communications services for which he or she concludes with the user of such services. <Amended on May 28, 2014>
(3) A provider of information and communications services shall inform interested persons, such as users to whom such services are provided, of the fact that he or she has taken measures for refusal under paragraph (1) or (4); provided, where it is impracticable to inform them of the fact in advance, he or she shall inform them of the fact without delay after he or she has taken measures for refusal. <Amended on May 28, 2014>
(4) Where services which a provider of information and communications services provides to users under a contract for use are used for transmitting advertising information for profit-making purpose, in violation of Article 50 or 50-8, the relevant provider of information and communications services shall formulate necessary measures, such as refusal to provide the relevant services or redressing problems of information and communications networks or services. <Added on May 28, 2014>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 50-5 (Installation of advertising programs for profit-making purpose)
When a provider of information and communications services intends to install a program designed to display advertising information or collect personal information in a user's computer or any other information processing device prescribed by Presidential Decree, he or she shall obtain consent from the user. In such cases, the provider shall notify the purpose of use of the program and the method of deletion.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 50-6 (Distribution of software designed to block transmission of advertising information for profit-making purpose)
(1) The Korea Media and Communications Commission may develop and distribute software or computer programs designed for addressees to conveniently block or report any advertising information for profit-making purpose when it is transmitted in violation of Article 50. <Amended on Oct. 1, 2025>
(2) The Korea Media and Communications Commission may provide necessary support to related public agencies, corporations, organizations, or similar for facilitating the development and distribution of software or computer programs for blocking or reporting transmission under paragraph (1). <Amended on Oct. 1, 2025>
(3) If telecommunications services rendered by a provider of information and communications services are used in transmitting advertising information for profit-making purpose in violation of Article 50, the Korea Media and Communications Commission may recommend the provider of information and communications services to take necessary measures, such as development of technology, education, and public relations activities to protect addressees. <Amended on Oct. 1, 2025>
(4) The method of the development and distribution under paragraph (1) and the matters necessary for the support under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 50-7 (Restrictions on posting of advertising information for profit-making purpose)
(1) Where any person intends to post advertising information for profit-making purpose on a website, he or she shall obtain prior consent from the operator or the manager of a website; provided, in cases of a message board to which any person can have easy access without special authority and on which any person can post his or her message, he or she need not obtain prior consent.
(2) Notwithstanding paragraph (1), where the operator or the manager of a website explicitly expresses his or her intention to refuse to post a notice or to revoke his or her prior consent, no person who intends to post advertising information for profit-making purpose shall post advertising information for profit-making purpose.
(3) The operator or the manager of a website may take measures, such as deletion of advertising information for profit-making purpose posted in violation of paragraph (1) or (2).
[This Article Wholly Amended on May 28, 2014]
법령 이단보기
Article 50-8 (Prohibition on transmission of advertising information for unlawful acts)
No person shall use a telecommunications network to transmit any advertising information about any goods or services whose use, sale, offering, distribution, or other similar conduct is prohibited by this Act or any other statute. <Amended on Jan. 23, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 51 (Restrictions to prevent overseas leakage of important information)
(1) The Government may authorize providers or users of information and communications services to take necessary measures to prevent overseas leakage of any important information about industry, economy, science, technology, etc. of this county through information and communications networks.
(2) The scope of the important information under paragraph (1) shall be as follows:
1. Information related to the national security and major policies;
2. Information about details of cutting-edge science and technology or devices developed within this country.
(3) The Government may authorize the providers of information and communications services that manage the information under the subparagraphs of paragraph (2) to take the following measures: <Amended on Mar. 22, 2016>
1. Installation of a systematic or technical device for preventing unlawful use of information and communications networks;
2. Systematic and technical measures for preventing unlawful destruction or manipulation of information;
3. Measures for preventing leakage of important information that providers of information and communications services have learned while managing the information.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 52 (Korea Internet and Security Agency)
(1) The Government shall establish the Korea Internet and Security Agency (hereinafter referred to as the "Internet and Security Agency") to upgrade information and communications networks (excluding matters regarding establishment, improvement, and management of information and telecommunications networks), encourage the safe use thereof, and promote the international cooperation and advancement into the overseas market in relation to broadcasting and communications. <Amended on Apr. 22, 2009; Jun. 9, 2020>
(2) The Internet and Security Agency shall be a corporation. <Amended on Apr. 22, 2009>
(3) The Internet and Security Agency shall perform the following business affairs: <Amended on Apr. 22, 2009; Feb. 17, 2012; Mar. 23, 2013; Nov. 19, 2014; Jun. 22, 2015; Jul. 26, 2017; Feb. 4, 2020; Jun. 9, 2020; Jun. 8, 2021; Jun. 10, 2022; Jan. 23, 2024; Oct. 1, 2025>
1. Survey and research of laws, policies, and systems for the use and protection of information and telecommunications networks, promotion of the international cooperation and advancement into the overseas market in relation to broadcasting and communications, etc.;
2. Survey and analysis of statistics regarding the use and protection of information and telecommunications networks;
3. Analysis of negative effects arising from the use of information and telecommunications networks and research on countermeasures;
4. Public relations activities, education, and training for using and protecting information and telecommunications networks;
5. Information protection for information and telecommunications networks, development of technologies regarding the Internet address resources and standardization thereof;
6. Support for policies for the information security industry, development of relevant technology, and fostering of human resources;
7. Implementation of certification and evaluation of information security, such as certification of information security management systems, certification and evaluation of information security systems, certification of information security of devices and the like connected to information and communications networks, and software development security assessment; and the provision of support therefor;
8. Research of countermeasures for protecting personal information, and support for development and dissemination of protective technologies under the Personal Information Protection Act;
9. Operation of a personal information infringement call center under the Personal Information Protection Act;
10. Consultation on and processing of complaints related to transmission of advertising information and online advertisements;
11. Management of cyber security incidents in information and communications networks, analysis of causes thereof, operation of systems for responding thereto; and promotion of chief information security officers' activities to prevent and respond to such incidents and to cooperate each other;
12. Support for policies on electronic signature certification under Article 21 of the Electronic Signature Act;
13. Support for an efficient operation of the Internet and encouragement of wider use thereof;
14. Support for the protection of stored information of the Internet users;
15. Support for service policies pertaining to the Internet;
16. Protection of users and support for the dissemination of sound information on the Internet;
17. Affairs related to the management of Internet address resources under the Internet Address Resources Act;
18. Support for the operation of the Internet Address Dispute Resolution Committee under Article 16 of the Internet Address Resources Act;
19. Support for operation of the conciliation committee under Article 25 (7) of the Act on the Promotion of Information Security Industry;
20. Support for such international cooperation, overseas expansion, and overseas publicity activities as are regarding broadcasting and communications;
21. Support for policies related to identity verification services and to the creation and processing of connecting information;
22. Any other business incidental to the business referred to in subparagraphs 1 through 21;
23. Other business determined to fall under the affairs of, or entrusted to, the Internet and Security Agency in accordance with this Act, or any other statute or regulation, or other business entrusted by the Minister of Science and ICT, the Minister of the Interior and Safety, the Korea Media and Communications Commission, or the head of any other administrative agency.
(4) Expenses necessary for the business affairs of the Internet and Security Agency shall be funded by the following financial resources: <Amended on Mar. 22, 2016>
1. Government’s contributions;
2. Revenues accrued from the business referred to in each subparagraph of paragraph (3);
3. Other revenues accrued from operating the Internet and Security Agency.
(5) Except as provided in this Act, the provisions governing incorporated foundations under the Civil Act shall apply mutatis mutandis to matters regarding the Internet and Security Agency. <Amended on Apr. 22, 2009>
(6) No person, other than the Internet and Security Agency, shall use the name "Korea Internet and Security Agency". <Amended on Apr. 22, 2009>
(7) Matters necessary for the operation of the Internet and Security Agency and performance of its business affairs shall be prescribed by Presidential Decree. <Amended on Apr. 22, 2009>
[This Article Wholly Amended on Jun. 13, 2008]
[Title Amended on Apr. 22, 2009]
CHAPTER VII TELECOMMUNICATIONS BILLING SERVICES
법령 이단보기
Article 53 (Registration of providers of telecommunications billing services)
(1) A person who intends to render telecommunications billing services shall meet the following requirements and file for registration with the Minister of Science and ICT, as prescribed by Presidential Decree: <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017>
1. Financial soundness;
2. A plan for protection of users of telecommunications billing services;
3. Human resources and physical facilities required for conducting the business;
4. A business plan.
(2) A person eligible for the registration under paragraph (1) shall be either a company under Article 170 of the Commercial Act or a corporation under Article 32 of the Civil Act; and the total amount of its capital, contributions, or fundamental property shall be at least the amount prescribed by Presidential Decree, not less than 500 million won.
(3) Notwithstanding Article 22 of the Telecommunications Business Act, a provider of telecommunications billing services need not file a report of a value-added telecommunications business operator. <Amended on Mar. 22, 2010>
(4) Articles 23 through 26 of the Telecommunications Business Act shall apply mutatis mutandis to the modification of registered matters of a provider of telecommunications billing services, the transfer of business or acquisition by transfer of business, or the merger or inheritance of business, the succession to business, and the temporary closure, permanent closure, dissolution, or similar of business of a provider of telecommunications billing services. In such cases, "special telecommunications business operator" shall be construed as "provider of telecommunications billing services", and "special telecommunications business" as "telecommunications billing services". <Amended on Mar. 22, 2010; Jun. 9, 2020>
(5) Detailed requirements and procedures for the registration under paragraph (1) and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Dec. 21, 2007]
[Previous Article 53 moved to Article 62 <Dec. 21, 2007>]
법령 이단보기
Article 54 (Disqualification from filing for registration)
Any of the following persons shall be disqualified from filing for registration under Article 53: <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
1. A corporation for which 1 year has not elapsed since its business was permanently closed pursuant to Article 53 (4) or a person who was a majority shareholder (referring to an investor prescribed by Presidential Decree; hereinafter the same shall apply) of such corporation as at the time its business was permanently closed, if 1 year has not elapsed since the date of permanent closure of its business;
2. A corporation for which 3 years have not elapsed since its registration was revoked pursuant to Article 55 (1) or a person who was a majority shareholder of such corporation as at the time its registration was revoked, if 3 years have not elapsed since the date of revocation;
3. A corporation that is still under rehabilitation proceedings under the Debtor Rehabilitation and Bankruptcy Act or a majority shareholder of such corporation;
4. A person who did not perform his or her obligations within an agreed time limit in conducting a banking transaction or any other commercial transaction and who is prescribed by the Minister of Science and ICT;
5. A corporation any of whose majority shareholders falls under subparagraphs 1 through 4.
[This Article Added on Dec. 21, 2007]
[Previous Article 54 Moved to Article 63 <Dec. 21, 2007>]
법령 이단보기
Article 55 (Orders to revoke registration)
(1) Where a provider of telecommunications billing services files for registration by fraud or other improper means, the Minister of Science and ICT shall revoke the registration. <Amended on Jun. 22, 2015; Jul. 26, 2017>
(2) The procedures for the disposition under paragraph (1) and other necessary matters shall be prescribed by Presidential Decree. <Amended on Jun. 22, 2015>
[This Article Added on Dec. 21, 2007]
[Title Amended on Jun. 22, 2015]
[Previous Article 55 moved to Article 64 <Dec. 21, 2007>]
법령 이단보기
Article 56 (Reporting on terms and conditions)
(1) Every provider of telecommunications billing services shall prepare terms and conditions on telecommunications billing services and report it to the Minister of Science and ICT (including reporting on a revision thereto). <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017>
(2) If it is found that the terms and conditions under paragraph (1) are likely to undermine interests of users of telecommunications billing services, the Minister of Science and ICT may recommend the relevant provider of telecommunications billing services to revise the terms and conditions. <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Dec. 21, 2007]
[Previous Article 56 moved to Article 65 <Dec. 21, 2007>]
법령 이단보기
Article 57 (Securing safety in telecommunications billing services)
(1) Every provider of telecommunications billing services shall perform his or her duty to pay attention as a good manager so that telecommunications billing services may be provided in a safe manner. <Amended on May 28, 2014>
(2) Every provider of telecommunications billing services shall take administrative measures, including formulation of guidelines for work process and classification of accounts, and technical measures, including establishment of an information security system, to secure safety and reliability of transactions through telecommunications billing services, as prescribed by Presidential Decree.
[This Article Added on Dec. 21, 2007]
[Previous Article 57 moved to Article 66 <Dec. 21, 2007>]
법령 이단보기
Article 58 (Rights of users of telecommunications billing services)
(1) When the price for goods, etc. sold or provided must be paid, or a provider of telecommunications billing services charges the price therefor; such provider shall notify the users of telecommunications billing services of the following: <Amended on Apr. 5, 2011; May 28, 2014>
1. Date and time telecommunications billing services are used;
2. Trade name and contact information of the other party with respect to purchasing or using any good or service through telecommunications billing services (referring to a person who sells or provides any good or service in a transaction through telecommunications billing services; hereinafter referred to as "other party to a transaction");
3. Amount purchased or used through telecommunications billing services and details thereof;
4. Methods for raising an objection and contact information.
(2) A provider of telecommunications billing services shall provide users of telecommunications billing services with a method by which users can verify the details of purchase and use and shall also furnish a user, upon request, with a written statement on the details of purchase and use (including an electronic document; hereinafter the same shall apply) within 2 weeks from the date of the request.
(3) A user of telecommunications billing services discovers that the telecommunications billing services have been rendered against his or her will, the user may request the provider of telecommunications billing services to make corrections (excluding where there is an intentional act or negligence on the part of the user of the telecommunications billing services), and where the provider of telecommunications billing services finds that the user's request for correction is reasonable, the provider shall withhold the payment of the price for use to a seller and shall notify the user of the results thereof within 2 weeks from the date of the request for correction. <Amended on May 28, 2014>
(4) Every provider of telecommunications billing services shall preserve records of telecommunications billing services during the period, within 5 years, prescribed by Presidential Decree.
(5) Where a provider of telecommunications billing services (referring to a person who provides services under Article 2 (1) 10 (a)) provides telecommunications billing services or increases the upper limits of use, he or she shall obtain consent from a user of the relevant telecommunications billing services in advance. <Added on May 28, 2014>
(6) When a provider of telecommunications billing services (referring to a person who provides services under Article 2 (1) 10 (a)) amends the terms and conditions, he or she shall notify users of the amendment thereof 1 month prior to the effective date of the amended terms and conditions. In such cases, a user who has an objection to the amended terms and conditions may terminate the contract for telecommunications billing services. <Added on May 28, 2014>
(7) The period, types, and scope of the details of purchase and use that a provider of telecommunications billing services should provide pursuant to paragraph (2); the types of records that a provider of telecommunications billing services should preserve pursuant to paragraph (4) and the methods for preserving such records; the methods for notifying amendment to the terms and conditions pursuant to paragraph (6); and matters necessary for terminating the contract, such as the period and procedures for raising an objection; shall be prescribed by Presidential Decree. <Amended on May 28, 2014>
(8) The Minister of Science and ICT shall prescribe and provide public notice of matters necessary for methods for giving consent, etc. under paragraph (5). <Added on May 28, 2014; Jul. 26, 2017>
(9) The Minister of Science and ICT may prescribe and provide public notice of detailed matters regarding the methods for settling accounts, etc. so that telecommunications billing services are not provided against the will of users of telecommunications billing services. <Added on May 28, 2014; Jul. 26, 2017>
[This Article Added on Dec. 21, 2007]
[Previous Article 58 Moved to Article 67 <Dec. 21, 2007>]
법령 이단보기
Article 58-2 (Request for providing information about purchasers)
(1) Any user of telecommunications billing services may request the counter-party to a transaction to provide information about the name and date of birth of a person who purchased or used goods, etc. (hereinafter referred to as "purchaser information") if necessary to ascertain that telecommunications billing services have been provided according to his or her intention. In such cases, the counter-party so requested to provide purchaser information shall provide such information within 3 days from the date of the request without good cause.
(2) A user of telecommunications billing services shall use the purchaser information provided pursuant to paragraph (1) only for the purpose of identifying the relevant purchaser or submitting such information to an investigative agency in filing a criminal complaint or report.
(3) Other matters necessary relating to the content of, and the procedures for, requests for purchaser information shall be prescribed by Presidential Decree.
[This Article Added on Jun. 12, 2018]
법령 이단보기
Article 59 (Mediation in and resolution of disputes)
(1) Any provider of telecommunications billing services may establish and operate an institution or organization to autonomously mediate, resolve, or otherwise address disputes to protect rights and interests of users of telecommunications billing services. <Amended on Jun. 12, 2018; Jun. 9, 2020>
(2) If deemed necessary for mediating, resolving, or otherwise addressing disputes, an organization or institution authorized to mediate and resolve disputes under paragraph (1) may request purchaser information on behalf of a user of telecommunications billing services with consent of the user. In such cases, Article 58-2 shall apply mutatis mutandis to the request for purchaser information, etc. <Added on Jun. 12, 2018>
(3) Every provider of telecommunications billing services shall prepare a procedure for raising an objection by users of telecommunications billing services in connection with the services and redressing damages to their rights, as prescribed by Presidential Decree, and where the provider enters into a contract for telecommunications billing services, the provider shall stipulate such procedure in the terms and conditions of use. <Amended on May 28, 2014; Jun. 12, 2018>
[This Article Added on Dec. 21, 2007]
[Title Amended on Jul. 12, 2018]
[Previous Article 59 Moved to Article 68 <Dec. 21, 2007>]
법령 이단보기
Article 60 (Liability for damages)
(1) A provider of telecommunications billing services shall be liable for damages caused to a user of the telecommunications billing services while rendering the services; provided, the same shall not apply where the damages were caused by intention or gross negligence on the part of the user of the telecommunications billing services. <Amended on Jun. 9, 2020>
(2) A provider of telecommunications billing services shall negotiate with the claimant to damages for agreement on compensation for the damages under paragraph (1). <Amended on Jun. 9, 2020>
(3) If parties fail to or are unable to reach an agreement on compensation for damages under paragraph (2), either party may file an application for decision with the Korea Media and Communications Commission. <Amended on Feb. 29, 2008; Oct. 1, 2025>
[This Article Added on Dec. 21, 2007]
[Previous Article 60 moved to Article 69 <Dec. 21, 2007>]
법령 이단보기
Article 61 (Restrictions on use of telecommunications billing services)
The Minister of Science and ICT may order a provider of telecommunications billing services to deny, suspend, or place a restriction on, the services against any of the following persons: <Amended on Feb. 29, 2008; Sep. 15, 2011; Mar. 23, 2013; Jul. 26, 2017>
1. A person who sells, lends, or provides any media product harmful to youths to a youth in violation of Article 16 of the Youth Protection Act;
2. A person who undermines interests of users of telecommunications billing services seriously by enticing the users to purchase or use goods or services in any of the following means:
(a) Transmitting any advertising information for profit-making purpose in violation of Article 50;
(b) Deceiving or enticing users of telecommunications billing services wrongfully;
3. A person who sells or renders goods or services prohibited by this Act or any other statute.
[This Article Added on Dec. 21, 2007]
[Previous Article 61 Moved to Article 70 <Dec. 21, 2007>]
CHAPTER VIII INTERNATIONAL COOPERATION
법령 이단보기
Article 62 (International cooperation)
The Government shall cooperate reciprocally with other nations or international organizations in performing the following affairs:
1. Deleted; <Feb. 4, 2020>
2. Affairs for the protection of youths in information and communications networks;
3. Affairs for the prevention of acts that undermine safety of information and communications networks;
4. Other affairs for the facilitation of sounder and safer use of information and communications services.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 63 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 63-2 Deleted. <Feb. 4, 2020>
CHAPTER IX SUPPLEMENTARY PROVISIONS
법령 이단보기
Article 64 (Submission of data)
(1) The Minister of Science and ICT or the Korea Media and Communications Commission may require a provider of information and communications services (including a domestic agent; hereafter in this Article the same shall apply) to submit related articles, documents, and others in any of the following cases: <Amended on Mar. 29, 2011; Feb. 17, 2012; Mar. 23, 2013; Jul. 26, 2017; Sep. 18, 2018; Feb. 4, 2020; Oct. 1, 2025>
1. Where the Minister or the Commission becomes aware of a violation or suspected violation of this Act;
2. Where the Minister or the Commission receives a report or petition on a violation of this Act;
2-2. Where an event, accident, or similar occurs or is likely to occur that noticeably damages safety and reliability of user information;
3. Where there is any other ground prescribed by Presidential Decree to believe that it is necessary for the protection of users.
(2) When the Korea Media and Communications Commission intends to take the following measures against a person who transmitted any advertising information for profit-making purpose in violation of this Act, it may request a provider of information and communications services to let it peruse or to submit data of the person who transmitted the advertising information, such as the name, address, and resident registration number of the person and the period for access: <Amended on Feb. 4, 2020; Oct. 1, 2025>
1. Corrective measures under paragraph (4);
2. Imposition of administrative fines under Article 76;
3. Any similar measures.
(3) If a provider of information and communications services fails to submit data under paragraph (1) or (2) or if it is found that a provider of information and communications services has violated this Act, the Minister of Science and ICT or the Korea Media and Communications Commission may assign public officials under his, her, or its control to enter the place of business of the person concerned related to such violation of this Act, including the provider of information and communications services, for inspecting the current status of business, account books, documents, and others. <Amended on Mar. 29, 2011; Mar. 23, 2013; Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(4) The Minister of Science and ICT or the Korea Media and Communications Commission may order a provider of information and communications services who has violated this Act to take corrective measures as necessary to stop or correct the violation and may also require a provider of information and communications services who has been ordered to take corrective measures to announce to the public the fact that he or she received the order to take such corrective measures. In such cases, the matters necessary for the methods, guidelines, and procedures for the public announcement and other related matters shall be prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(5) In cases of issuing an order to take corrective measures as necessary pursuant to paragraph (4), the Minister of Science and ICT or the Korea Media and Communications Commission may disclose to the public the issuance of the order to take corrective measures. In such cases, the matters necessary for the methods, guidelines, and procedures for the public disclosure and other related matters shall be prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(6) When demanding submission or perusal of data or other materials pursuant to paragraph (1) or (2), the Minister of Science and ICT or the Korea Media and Communications Commission shall give a written notice (including an electronic document), specifically stating the reasons and legal authority for such demand, the time limit for submission or the date and time for perusal, the details of data subject to the submission or perusal, and other related matters. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(7) When an inspection under paragraph (3) is to be conducted, the plan for the inspection, including the date and time of, and the reasons for and details of, the inspection, shall be notified to the relevant provider of information and communications services not later than 7 days before the commencement of the inspection; provided, the plan for such inspection shall not be notified in an emergency case or if it is deemed impossible to accomplish the purposes of the inspection because of anticipated destruction of evidence or any other factor if a prior notice is given. <Amended on Feb. 4, 2020>
(8) The public officials who conduct an inspection pursuant to paragraph (3) shall carry an identification indicating their authority with them to present it to people concerned, and shall deliver to the people concerned a document stating their names, the time and purposes of access, and other related matters, whenever they access to a place of business.
(9) In cases of receiving, perusing, or inspecting data or any other material submitted pursuant to paragraphs (1) through (3), the Minister of Science and ICT or the Korea Media and Communications Commission shall notify the relevant provider of information and communications services of the results thereof (including the details of disposition, in cases of intending to make a disposition, such as an order to take corrective measures, as a result of the inspection) in writing. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(10) The Minister of Science and ICT or the Korea Media and Communications Commission may ask technical advice or any other support of the head of the Internet and Security Agency as necessary in demanding submission of data or conducting an inspection pursuant to paragraphs (1) through (4). <Amended on Apr. 22, 2009; Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(11) Demand for submission of data or any other material, and perusal and inspection thereof under paragraphs (1) through (3) shall be limited to the least extent necessary for the enforcement of this Act and shall be not abused for any other purpose.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 64-2 (Protection and destruction of data)
(1) If asked by a provider of information and communications services to protect documents, data, or any other material submitted or collected pursuant to Article 64, the Minister of Science and ICT or the Korea Media and Communications Commission shall not furnish them to a third party or disclose them to the general public. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(2) In cases of receiving data submitted through an information and communications network or converting collected data or any other material into an electronic format, the Minister of Science and ICT or the Korea Media and Communications Commission shall take systematic and technical measures for security to protect personal information, trade secret, or similar from being leaked. <Amended on Mar 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(3) If any of the following events occurs, the Minister of Science and ICT or the Korea Media and Communications Commission shall immediately destroy documents, data, or any other material submitted or collected pursuant to Article 64, except as otherwise provided in any other statute. The same shall apply to a person to whom the authority of the Minister of Science and ICT or the Korea Media and Communications Commission has been fully or partially delegated or entrusted under Article 65: <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
1. If the objectives of demanding submission of data, conducting a field inspection, or issuing an order to take corrective measures pursuant to Article 64 have been achieved;
2. If an administrative trial or administrative litigation is filed against an order issued to take corrective measures pursuant to Article 64 (4), when proceedings of such administrative trial are completed;
3. If a disposition is made to impose an administrative fine under Article 76 (4) and there is no objection to it, when the period to raise an objection under paragraph (5) of that Article ends;
4. If there is an objection filed against disposition of an administrative fine under Article 76 (4), when the non-contentious case procedures are closed at the competent court.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 64-3 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 64-4 (Hearings)
The Minister of Science and ICT or the Korea Media and Communications Commission shall hold a hearing in any of the following cases: <Amended on Jul. 26, 2017; Feb. 4, 2020; Jun. 9, 2020; Oct. 1, 2025>
1. Where intending to revoke the designation of a certification body in accordance with Article 9 (2);
2. Where intending to revoke the designation of an identity verification agency in accordance with Article 23-4 (1);
3. Where intending to revoke certification of an information security management system in accordance with Article 47 (10);
4. Where intending to revoke the designation of a certification body for information security management systems in accordance with Article 47-2 (1);
5. Where intending to revoke any information security management grade in accordance with Article 47-5 (4);
5-2. Where intending to revoke information security certification under Article 48-6 (3);
5-3. Where intending to revoke the designation of a testing agency for certification under Article 48-6 (5);
6. Where intending to revoke the registration in accordance with Article 55 (1).
[This Article Added on Dec. 1, 2015]
법령 이단보기
Article 64-5 (Obligation to submit transparency reports)
(1) A provider of information and communications services who meet the criteria prescribed Presidential Decree, such as the average number of daily users, sales, and types of business, shall prepare an annual report stating the following (hereinafter referred to as "transparency report") with regard to the disposition of illegally filmed materials or the like circulated through information and communications services rendered by the provider and shall submit the report to the Korea Media and Communications Commission by January 31 of the following year: <Amended on Oct. 1, 2025>
1. Matters concerning the general efforts made by the provider of information and communications services to prevent the circulation of illegally filmed materials or the like;
2. Matters concerning the number, details, criteria for processing, results of examination, and results of processing of reports on illegally filmed materials or the like and requests for deletion, etc. of such materials under Article 22-5 (1) of the Telecommunications Business Act;
3. Matters concerning the preparation and operation of procedures necessary for preventing circulation, such as deleting illegally filmed materials or the like and blocking access thereto, under Article 22-5 (1) of the Telecommunications Business Act;
4. Matters concerning the placement of persons responsible for preventing the circulation of illegally filmed materials or the like;
5. Matters concerning the provision of internal training and support for preventing the circulation of illegally filmed materials or the like.
(2) The Korea Media and Communications Commission shall disclose transparency reports through the information and communications network operated and managed by it. <Amended on Oct. 1, 2025>
(3) The Korea Media and Communications Commission may request a provider of information and communications services to submit data to ascertain the facts of a transparency report or ascertain the authenticity of the submitted data. <Amended on Oct. 1, 2025>
[This Article Added on Jun. 9, 2020]
법령 이단보기
Article 65 (Delegation and entrustment of authority)
(1) The Minister of Science and ICT or the Korea Media and Communications Commission may delegate or entrust part of his or her authority under this Act to the heads of affiliated agencies or the presidents of the regional Korea posts, as prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(2) The Minister of Science and ICT may entrust projects under Article 13 for facilitating the use of information and communications networks to the National Information Society Agency under Article 12 of the Framework Act on Intelligent Informatization, as prescribed by Presidential Decree. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
(3) The Minister of Science and ICT or the Korea Media and Communications Commission may entrust the Internet and Security Agency with business affairs related to demanding submission of data and conducting inspections pursuant to Article 64 (1) and (2), as prescribed by Presidential Decree. <Amended on Apr. 22, 2009; Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(4) Article 64 (8) shall apply mutatis mutandis to employees of the Internet and Security Agency under paragraph (3). <Amended on Apr. 22, 2009>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 65-2 Deleted. <Dec. 30, 2005>
법령 이단보기
Article 66 (Confidentiality)
A person who is or was engaged in a job related to any of the following business affairs shall not divulge to another person any secret that he or she has learned while performing his or her duties, nor does he or she use it for any purpose other than performance of his or her duties; provided, the same shall not apply if any other statute provides otherwise: <Amended on Feb. 17, 2012; Jun. 9, 2020>
1. Deleted; <Mar. 29, 2011>
2. Certification of an information security management system under Article 47;
2-2. Deleted; <Feb. 4, 2020>
3. Evaluation of information security systems under Article 52 (3) 4;
4. Deleted; <Feb. 17, 2012>
5. Conciliation of disputes by the defamation dispute conciliation division under Article 44-10.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 67 Deleted. <Feb. 4, 2020>
법령 이단보기
Article 68 Deleted. <Mar. 22, 2010>
법령 이단보기
Article 68-2 Deleted. <Jun. 22, 2015>
법령 이단보기
Article 69 (Legal fiction as public officials in application of penalty provisions)
Executive officers and employees of the National Information Society Agency and the Internet and Security Agency who engage in the business affairs entrusted by the Minister of Science and ICT or the Korea Media and Communications Commission pursuant to Article 65 (2) or (3) shall be deemed public officials in applying Articles 129 through 132 of the Criminal Act. <Amended on Apr. 22, 2009; Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 69-2 Deleted. <Feb. 4, 2020>
CHAPTER X PENALTY PROVISIONS
법령 이단보기
Article 70 (Penalty provisions)
(1) A person who commits defamation of another person by disclosing a fact to the public through an information and communications network purposely to disparage the reputation of such person, shall be punished by imprisonment with labor for up to 3 years or by a fine not exceeding 30 million won. <Amended on May 28, 2014>
(2) A person who commits defamation of another person by disclosing a false fact to the public through an information and communications network purposely to disparage the reputation of such person, shall be punished by imprisonment with labor for up to 7 years, by suspension of qualification for up to 10 years, or by a fine not exceeding 50 million won.
(3) The prosecution may not prosecute a person who committed a crime under paragraph (1) or (2) against the victim's will explicitly manifested.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 70-2 (Penalty provisions)
A person who conveys or spread a malicious program in violation of Article 48 (2) shall be punished by imprisonment with labor for up to 7 years or by a fine not exceeding 70 million won.
[This Article Added on Mar. 22, 2016]
법령 이단보기
Article 71 (Penalty provisions)
(1) Any of the following persons shall be punished by imprisonment with labor for up to 5 years or by a fine not exceeding 50 million won: <Amended on Mar. 22, 2016; Dec. 24, 2018; Jan. 23, 2024>
1. Deleted; <Feb. 4, 2020>
2. Deleted; <Feb. 4, 2020>
3. Deleted; <Feb. 4, 2020>
4. Deleted; <Feb. 4, 2020>
5. Deleted; <Feb. 4, 2020>
6. Deleted; <Feb. 4, 2020>
7. Deleted; <Feb. 4, 2020>
8. Deleted; <Feb. 4, 2020>
9. A person who creates and processes connecting information, in violation of Article 23-5 (1);
10. A person who processes connecting information beyond the scope of purposes under Article 23-5 (4);
11. A person who intrudes into the information and communication network, in violation of Article 48 (1);
12. A person who causes a trouble to the information and communication network, in violation of Article 48 (3);
13. A person who installs a program, technical device, etc. in the information and communications network or an information system related thereto, or transmits or disseminates it, in violation of Article 48 (4);
14. A person damages the information of others or infringes, misappropriates, or divulges the secrets of others, in violation of Article 49.
(2) Any attempt referred to in paragraph (1) 11 shall be punished. < Added on Mar. 22, 2016; Jan. 23, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 72 (Penalty provisions)
(1) Any of the following persons shall be punished by imprisonment with labor for up to 3 years or by a fine not exceeding 30 million won: <Amended on Jan. 20, 2015; Mar. 27, 2015; Feb. 4, 2020; Jan. 23, 2024>
1. Deleted; <Mar. 22, 2016>
1-2. A person who transmits to a youth any information containing advertisement of a media product harmful to youths or displays such information openly without taking any measures to restrict access by youths, in violation of Article 42-2;
2. A person who collects another person's information in violation of Article 49-2 (1);
2-2. A person who transmits any advertising information, in violation of Article 50-8;
3. A person who conducts affairs without filing for registration under Article 53 (1);
4. A person who lends a loan to someone, or offers, intermediates, recommends, or advertise such loan by committing any of the following acts:
(a) Conducting, or engaging someone to conduct vicariously, a transaction through telecommunications billing services by pretending sale or supply of goods or services or billing more than an actual selling price;
(b) Engaging a user of telecommunications billing services to purchase or use certain goods or services through telecommunications billing services and then purchasing, at a discount, the goods or services purchased or used by the user of telecommunications billing services;
5. A person who divulges to another person any secret he or she has learned while performing his or her duties or uses such secret for any purpose other than performance of his or her duties, in violation of Article 66.
(3) Deleted. <Feb. 22, 2016>
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 73 (Penalty provisions)
Any of the following persons shall be punished by imprisonment with labor for not more than 2 years or by a fine not exceeding 20 million won: <Amended on May 28, 2014; Mar. 22, 2016; Jun. 12, 2018; Feb. 4, 2020; Jun. 10, 2022; Feb. 13, 2024; Oct. 1, 2025>
1. Deleted; <Feb. 4, 2020>
1-2. Deleted; <Feb. 4, 2020>
2. A person who provides a media product harmful to youths for profit without labeling it as such in violation of Article 42;
3. Deleted; <Jan. 23, 2024>
4. A person who uses user's information for any purpose other than filing a civil or criminal lawsuit, in violation of Article 44-6 (3);
5. A person who fails to comply with an order issued by the Korea Media and Communications Commission under Article 44-7 (2) or (3);
6. A person who fails to preserve relevant data, in violation of an order issued pursuant to Article 48-4 (5);
7. A person who entices another person to provide him or her with information in violation of Article 49-2 (1);
7-2. A person who uses provided information for any purpose other than identifying a purchaser or submitting the information to an investigative agency in filing a criminal complaint or report, in violation of Article 58-2 (including where that Article shall apply mutatis mutandis under Article 59 (2));
8. A person who fails to comply with an order issued pursuant to Article 61.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 74 (Penalty provisions)
(1) Any of the following persons shall be punished by imprisonment with labor for up to 1 year or by a fine not exceeding 10 million won: <Amended on Feb. 17, 2012; May 28, 2014>
1. A person who puts any similar label on a product or sells a product bearing any similar label, or who displays such product with intent to sell it, in violation of Article 8 (4);
2. A person who distributes, sells, lends, or openly displays any obscene codes, letters, sound, images, or motion pictures in violation of Article 44-7 (1) 1;
3. A person who makes any codes, letters, sound, images, or motion pictures arousing fear or apprehension reach another person repeatedly in violation of Article 44-7 (1) 3;
4. A person who takes measures, in violation of Article 50 (5);
5. Deleted; <May 28, 2014>
6. Deleted; <Jan. 23, 2024>
7. A person who fails to file for any modification of registered matters, or who fails to file a report on transfer, acquisition by transfer, merger, or inheritance of business, in violation of Article 53 (4).
(2) The prosecution may not prosecute a person who committed a crime under paragraph (1) 3 against the victim's will explicitly manifested.
[This Article Wholly Amended on Jun. 13, 2008]
법령 이단보기
Article 75 (Joint penalty provisions)
If the representative of a corporation, or an agent or employee of, or any other person employed by, a corporation or individual commits any violation referred to in Articles 71 through 73 or Article 74 (1) in conducting the business affairs of the corporation or individual, the corporation or the individual shall, in addition to punishing the violator accordingly, be punished by a fine prescribed in the relevant Article; provided, this shall not apply where such corporation or individual has not been negligent in giving due attention and supervision regarding the relevant business affairs to prevent such violation.
[This Article Wholly Amended on Mar. 17, 2010]
법령 이단보기
Article 75-2 (Confiscation and punitive collection)
Money and goods or other profits received by a person committing any crime referred to in Article 72 (1) 2 and subparagraph 7 of Article 73 with respect to the relevant violation may be confiscated, and if it is impossible to confiscate such money and goods or other profits, the value thereof may be punitively collected. In such cases, the penalty of confiscation or punitive collection may be imposed in addition to any other penalty. <Amended on Feb. 4, 2020>
[This Article Added on Mar. 22, 2016]
법령 이단보기
Article 76 (Administrative fines)
(1) Any of the following persons and any of the following persons who commit an act falling under any of subparagraphs 7 through 11 shall be subject to an administrative fine not exceeding 30 million won: <Amended on Mar. 29, 2011; Feb. 17, 2012; Mar. 23, 2013; May 28, 2014; Jun. 22, 2015; Dec. 1, 2015; Mar. 22, 2016; Jul. 26, 2017; Sep. 18, 2018; Feb. 4, 2020; Jun. 8, 2021; Jan. 3, 2023; Jan. 23, 2024; Feb. 13, 2024; Oct. 1, 2025>
1. A person who refuses to provide services, in violation of Article 22-2 (2);
1-2. A person who fails to take measures necessary to protect user information such as devising methods for users to give or revoke consent to access authority, in violation of Article 22-2 (3);
2. A person who collects or uses resident registration numbers in violation of Article 23-2 (1) or fails to take necessary measures in violation of Article 23-2 (2);
2-2. Deleted; <Feb. 4, 2020>
2-3. Deleted; <Feb. 4, 2020>
2-4. Deleted; <Feb. 4, 2020>
2-5. A person who fails to take physical, technical or administrative measures under Article 23-6 (1);
2-6. A person who fails to take safety measures in accordance with Article 23-6 (2);
3. Deleted; <Feb. 4, 2020>
4. Deleted; <Feb. 4, 2020>
5. Deleted; <Feb. 4, 2020>
5-2. Deleted; <Feb. 4, 2020>
6. Deleted; <May 28, 2014>
6-2. A person who fails to designate an executive officer or employee meeting the standards prescribed by Presidential Decree as a chief information security officer, or fails to report the designation of a chief information security officer, in violation of Article 45-3 (1);
6-3. A person who requires a chief information security officer to hold another office concurrently other than to perform duties prescribed in Article 45-3 (4), in violation of paragraph (3) of that Article;
6-4. A person who fails to comply with a corrective order issued under Article 46 (3);
6-5. A person who fails to have an information security management system certified, in violation of Article 47 (2);
6-6. A person who fails to report a cyber security incident, in violation of Article 48-3 (1);
6-7. A person who fails to comply with a corrective order issued under Article 48-4 (3);
7. A person who transmits any advertising information for profit, in violation of Article 50 (1) through (3);
8. A person who fails to state the matters required to be stated, or who states false information on such matters, when transmitting any advertising information, in violation of Article 50 (4);
9. A person who imposes the burden of any expense on an addressee, in violation of Article 50 (6);
9-2. A person who fails to verify whether an addressee consents to receiving advertising information, in violation of Article 50 (8);
9-3. A person who fails to take necessary measures, in violation of Article 50-4 (4);
10. A person who installs a program without consent of the relevant user, in violation of Article 50-5;
11. A person who posts any advertising information for profit-making purpose on a website, in violation of Article 50-7 (1) or (2);
11-2. Deleted; <Feb. 4, 2020>
12. A person who fails to comply with an order issued, for violation of this Act, by the Minister of Science and ICT or the Korea Media and Communications Commission pursuant to Article 64 (4).
(2) Any of the following persons shall be subject to an administrative fine not exceeding 20 million won: <Amended on Mar. 22, 2016; Jun 12, 2018; Sep. 18, 2018; Feb. 4, 2020; Jun. 9, 2020>
1. Deleted; <Feb. 4, 2020>
1-2. Deleted; <Feb. 4, 2020>
2. Deleted; <Feb. 4, 2020>
3. Deleted; <Feb. 4, 2020>
4. Deleted; <Feb. 4, 2020>
4-2. A person who fails to take out insurance, in violation of Article 46 (2);
4-3. A person who fails to designate a domestic agent, in violation of Article 32-5 (1);
4-4. A person who fails to designate a person responsible for preventing the circulation of illegally filmed materials or the like, in violation of Article 44-9 (1);
5. Deleted. <Feb. 4, 2020>
(3) Any of the following persons shall be subject to an administrative fine not exceeding 10 million won: <Amended on Apr. 22, 2009; Apr. 5, 2011; Feb. 17, 2012; May 28, 2014; Jun. 22, 2015; Dec. 1, 2015; Mar. 22, 2016; Jul. 26, 2017; Jun. 12, 2018; Jun. 12, 2018; Feb. 4, 2020; Jun. 9, 2020; Jun. 10, 2022; Jan. 3, 2023; Jan. 23, 2024; Feb. 13, 2024; Oct. 1, 2025>
1. Deleted; <Jun. 22, 2015>
2. Deleted; <Jun. 22, 2015>
2-2. A person who engages in the identity verification service without being designated as an identity verification agency, in violation of Article 23-3 (1);
2-3. A person who fails to notify as to the temporary discontinuation of the identity verification service under Article 23-3 (2) or as to the permanent discontinuation of the identity verification service under Article 23-3 (3) to users or who fails to report the same to the Korea Media and Communications Commission;
2-4. A person who continuously engages in the identity verification service notwithstanding a disposition for suspension of the identity verification service and revocation of the designation as an identity verification agency under Article 23-4 (1);
2-5. Deleted; <Feb. 4, 2020>
3. A person who fails to designate a person responsible for protection of youths in violation of Article 42-3 (1);
4. A person who fails to preserve information, in violation of Article 43;
4-2. A person who fails to take technical and administrative measures, in violation of Article 44-7 (5);
4-3. A person who fails to comply without good cause with a request to submit data under Article 46 (4) of the Act; provided, the foregoing shall not apply to the heads of relevant central administrative agencies (including their affiliated agencies) shall be excluded;
4-4. A person who fails to file a report or files a false report, in violation of Article 46 (6);
5. Deleted; <Jun. 12, 2018>
6. Deleted; <Dec. 1, 2015>
7. A person who advertises false details of the certification he or she has obtained, in violation of Articles 47 (9);
8. Deleted; <Feb. 17, 2012>
9. Deleted; <Feb. 17, 2012>
10. A person who fails to give notice to users of software, in violation of Article 47-4 (4);
11. A person who fails to comply with an order issued pursuant to Article 48-2 (4) to take corrective measures;
11-2. Deleted; <Feb. 13, 2024>
11-3. A person who fails to submit data demanded under Article 48-4 (6) or submits false data;
12. A person who obstructs, refuses, or evades access to a place of business to conduct an investigation under Article 48-4 (6);
12-2. A person who fails to comply with an order issued by the Minister of Science and ICT or the Korea Media and Communications Commission, in violation of Article 49-2 (4);
12-3. A person who fails to inform the results of handling consent to receive, refusal to receive, or revocation of consent to receive, advertising information, in violation of Article 50 (7);
12-4. Deleted; <Jan. 23, 2024>
13. A person who uses the name of the Korea Internet and Security Agency, in violation of Article 52 (6);
14. A person who fails to file a report on temporary closure, permanent closure, or dissolution of business, in violation of Article 53 (4);
15. A person who fails to report terms and conditions, in violation of Article 56 (1);
16. A person who fails to take administrative or technical measures, in violation of Article 57 (2);
17. A person who fails to notify a user of telecommunications billing services of the date and time of using the aforementioned services and other necessary matters, in violation of Article 58 (1);
18. A person who fails to provide a user of telecommunications billing services with the method by which the user can verify the details of purchase or use, or who fails to respond to a request by a user of telecommunications billing services for the provision of such method, in violation of Article 58 (2);
19. A person who fails to withhold payment of the price though a request to correct a telecommunications bill he or she has received from a user of telecommunications billing services is reasonable or who fails to notify the user of telecommunications billing services of the results of the measures taken in response to a request of the user, in violation of Article 58 (3);
20. A person who fails to preserve records of telecommunications billing services, in violation of Article 58 (4);
20-2. A person who provides telecommunications billing services or increases the maximum use without obtaining consent from a user of telecommunications billing services, in violation of Article 58 (5);
20-3. A person who fails to give notice regarding amendment to the terms and conditions of telecommunications billing services, in violation of Article 58 (6);
20-4. A person who fails to comply with a request by a user of telecommunications billing services for information, in violation of Article 58-2 (including where that Article shall apply mutatis mutandis under Article 59 (2));
21. A person who fails to prepare the procedures for raising an objection by users of telecommunications billing services and redressing their infringed rights or who fails to stipulate such procedures when he or she enters into a contract for telecommunications billing services, in violation of Article 59 (3);
22. A person who fails to submit, or who falsely submitted, goods, documents, or any other material under Article 64 (1);
23. A person who fails to respond to a request for perusal or submission of data under Article 64 (2);
24. A person who refuses, obstructs or evades access and inspection under Article 64 (3);
25. A person who fails to submit rules, etc. in violation of Article 64-5 (1).
(4) The administrative fines prescribed in paragraphs (1) through (3) shall be imposed and collected by the Minister of Science and ICT or the Korea Media and Communications Commission, as prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(5) Deleted. <Mar. 14, 2017>
(6) Deleted. <Mar. 14, 2017>
(7) Deleted. <Mar. 14, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
ADDENDA <Act No. 6360, Jan. 16, 2001>
Article 1 (Enforcement date)
This Act shall enter into force on July 1, 2001.
Article 2 (Transitional measures following change of basis for establishing the Korea Information Security Center and of its name)
(1) The Korea Information Security Center established pursuant to Article 14-2 of the Framework Act on Informatization Promotion as at the time this Act enters into force shall be deemed the Korea Information Security Agency established pursuant to Article 52 of this Act.
(2) Any act performed by and any legal relations maintained by the Korea Information Security Center as at the time this Act enters into force shall be deemed performed and maintained by the Korea Information Security Agency.
(3) The name of the Korea Information Security Center on the register book and other public registers as at the time this Act enters into force shall be deemed the name of the Korea Information Security Agency.
Article 3 (Transitional measures following change of name of the Korea Information and Communications Promotion Association)
(1) The Korea Information and Communications Promotion Association as at the time this Act enters into force shall be deemed the Korea Association of Information and Telecommunication.
(2) Any act performed and any legal relations maintained by the Korea Information and Communications Promotion Association as at the time this Act enters into force shall be deemed performed and maintained by the Association.
(3) The name of the Korea Information and Communications Promotion Association on the register book and other public registers as at the time this Act enters into force shall be deemed the name of the Korea Association of Information and Telecommunication.
Article 4 (Transitional measures concerning application of penalty provisions)
The application of penalty provisions to any act committed before this Act enters into force shall be governed by the previous provisions.
Article 5 Omitted.
Article 6 (Relationship to other statutes or regulations)
If other statutes or regulations cite the previous Act on Promotion of Utilization of Information System or the provisions thereof as at the time this Act enters into force and if there exist corresponding provisions thereto in this Act, this Act or the corresponding provisions in this Act shall be deemed cited.
ADDENDA <Act No. 6585, Dec. 31, 2001>
Article 1 (Enforcement date)
This Act shall enter into force on April 1, 2002.
Articles 2 through 4 Omitted.
ADDENDA <Act No. 6797, Dec. 18, 2002>
(1) (Enforcement date) This Act shall enter into force 1 month after the date of its promulgation; provided, the amended provisions of Articles 50 (2) and (5), 56 (3) and (4), 60, and 67 (1) (limited to subparagraphs 15-2 and 15-4) shall enter into force 6 months after the date of promulgation of this Act.
(2) (Transitional measures concerning imposition of administrative fines) The previous provisions of this Act shall apply to the imposition of administrative fines for violations committed before this Act enters into force.
ADDENDA <Act No. 7139, Jan. 29, 2004>
(1) (Enforcement date) This Act shall enter into force on the date of its promulgation; provided, the amended provisions of Articles 28, 45 (4), 46-3, 47-2 (4), and 48-4 (6) shall enter into force 6 months after the date of promulgation of this Act.
(2) (Transitional measures concerning imposition of administrative fines) The previous provisions of this Act shall apply to the imposition of administrative fines for violations committed before this Act enters into force.
ADDENDA <Act No. 7142, Jan. 29, 2004>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Articles 2 through 4 Omitted.
ADDENDUM <Act No. 7262, Dec. 30, 2004>
This Act shall enter into force 3 months on the date of its promulgation.
ADDENDA <Act No. 7796, Dec. 29, 2005>
Article 1 (Enforcement date)
This Act shall enter into force on July 1, 2006.
Articles 2 through 6 Omitted.
ADDENDUM <Act No. 7812, Dec. 30, 2005>
This Act shall enter into force 3 months after the date of its promulgation.
ADDENDA <Act No. 7917, Mar. 24, 2006>
(1) (Enforcement date) This Act shall enter into force 3 months after the date of its promulgation.
(2) (Transitional measures concerning safety check of information protection) Where a company specializing in information protection consulting under Article 17 of the Act on the Protection of Information and Communications Infrastructure has commenced the works of safety check of information protection before this Act enters into force, it may continue to perform the works of safety check of information protection pursuant to the previous provisions, notwithstanding the amended provisions of Article 46-3 (1).
ADDENDUM <Act No. 8030, Oct. 4, 2006>
This Act shall enter into force 3 months after the date of its promulgation.
ADDENDA <Act No. 8031, Oct. 4, 2006>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
ADDENDA <Act No. 8289, Jan. 26, 2007>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 (Transitional measures concerning prohibition on illegal communications)
The orders issued by the Minister of Information and Communication to reject, suspend, or restrict handling of telecommunications services pursuant to Article 53 of the Telecommunications Business Act before this Act enters into force shall be deemed to have been issued pursuant to the amended provisions of Article 44-7 of this Act.
Article 3 (Transitional measures following change in authority for establishment of the Information and Communications Ethics Committee)
(1) The Information and Communications Ethics Committee established pursuant to Article 53-2 of the previous Telecommunications Business Act as at the time this Act enters into force shall be deemed the Information and Communications Ethics Committee established pursuant to the amended provisions of Article 44-8 of this Act.
(2) The acts done by or against the Information and Communications Ethics Committee and other legal relationships with the Information and Communications Ethics Committee under the previous provisions before this Act enters into force shall be deemed the acts done by or against the Information and Communications Ethics Committee and other legal relationships with the Information and Communications Ethics Committee under the amended provisions of Article 44-8 of this Act.
Article 4 (Transitional measures concerning collection, use, and provision of personal information)
(1) Consent obtained from a user in relation to collection, use, provision, or similar of personal information in accordance with the previous provisions of Article 22, 23, 24, or 54 as at the time this Act enters into force shall be deemed consent obtained lawfully in accordance with the amended provisions of Article 22, 23, 24, 24-2, or 54.
(2) Handling of personal information, which has been entrusted lawfully in accordance with the previous provisions of Article 25 as at the time this Act enters into force shall be deemed to have been entrusted with consent obtained lawfully in accordance with the amended provisions of Article 25 (1).
(3) An act performed by a person who succeeded rights and obligations of a provider of information and communications services or similar in accordance with the previous provisions of Article 26 as at the time this Act enters into force to use or provide personal information, shall be deemed to have been performed with consent obtained lawfully in accordance with the amended provisions of Article 26 (3).
Article 5 (Transitional measures concerning application of penalty provisions)
The previous provisions of this Act shall apply to the imposition of penalties for acts committed before this Act enters into force.
Article 6 Omitted.
ADDENDA <Act No. 8486, May 25, 2007>
Article 1 (Enforcement date)
This Act shall enter into force 1 year after the date of its promulgation.
Articles 2 through 8 Omitted.
Article 9 Omitted.
Article 10 Omitted.
ADDENDA <Act No. 8778, Dec. 21, 2007>
Article 1 (Enforcement date)
This Act shall enter into force 3 months after the date of its promulgation.
Article 2 (Transitional measures concerning registration of providers of telecommunications billing services)
(1) A person who renders telecommunications billing services as at the time this Act enters into force shall complete the registration with the Minister of Information and Communication in accordance with the amended provisions of Article 53 (1) within 3 months from the date this Act enters into force.
(2) A provider of telecommunications billing services who is registered in accordance with Article 28 (2) of the Electronic Financial Transactions Act as at the time this Act enters into force shall submit a written statement certifying the registration to the Minister of Information and Communication within 3 months from the date this Act enters into force.
(3) A person who submits a written statement in accordance with paragraph (2) shall be deemed to have been registered in accordance with the amended provisions of Article 53 (1).
ADDENDA <Act No. 8852, Feb. 29, 2008>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation; provided, ... <omitted> among the statutes to be amended under Article 6 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
ADDENDA <Act No. 8867, Feb. 29, 2008>
Article 1 (Enforcement date and others)
This Act shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
Article 7 Omitted.
Articles 8 through 12 Omitted.
ADDENDA <Act No. 9119, Jun. 13, 2008>
(1) (Enforcement date) This Act shall enter into force 6 months after the date of its promulgation.
(2) (Transitional measures concerning application of penalty provisions and administrative fines) The previous provisions of this Act shall apply to the imposition of penalties and administrative fines for acts committed before this Act enters into force.
ADDENDA <Act No. 9637, Apr. 22, 2009>
Article 1 (Enforcement date)
This Act shall enter into force 3 months after the date of its promulgation.
Article 2 (Preparation for establishment of the Korea Internet and Security Agency)
(1) The Korea Communications Commission may perform preparatory activities to establish the Korea Internet and Security Agency by commissioning not more than 5 incorporators before this Act enters into force.
(2) The incorporators shall prepare the articles of incorporation of the Korea Internet and Security Agency and obtain approval from the Korea Communications Commission.
(3) Upon obtaining authorization under paragraph (2), the incorporators shall register the incorporation of the Korea Internet and Security Agency by joint signature and turn over the administrative responsibility to the President of Korea Internet and Security Agency.
(4) The incorporators shall be deemed decommissioned at the time the take-over of the administrative responsibility is complete pursuant to paragraph (3).
Article 3 (Transitional measures concerning succession of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency)
(1) The administrative responsibilities of the Korea Information Security Agency under Article 52 of the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter referred to as the "Korea Information Security Agency"), the Korea Internet and Security Agency under Article 9 of the Internet Address Resources Act (hereinafter referred to as the "Korea Internet and Security Agency"), and the Korea IT International Cooperation Agency under Article 24-2 of the Framework Act on Informatization Promotion (hereinafter referred to as the "Korea IT International Cooperation Agency"), which are governed by the previous provisions as at the time this Act enters into force, shall be comprehensively succeeded to the Korea Internet and Security Agency under this Act.
(2) The previous rights, obligations, properties of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency as at the time this Act enters into force shall be comprehensively succeeded to the Korea Internet and Security Agency under this Act.
(3) The previous employment relationship covering the employees of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency as at the time this Act enters into force shall be comprehensively succeeded to the Korea Internet and Security Agency under this Act.
(4) The previous activities performed by or in relation to the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency as at the time this Act enters into force shall be deemed to have been performed by or in relation to the Korea Internet and Security Agency under this Act.
(5) The names of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency indicated on the register as at the time this Act enters into force or other public books shall be deemed to be that of the Korea Internet and Security Agency under this Act.
Article 4 Omitted.
Article 5 (Relationship to other statutes or regulations)
Where the previous Act on Promotion of Information and Communications Network Utilization and Information Protection or the provisions thereof are cited in other statutes or regulations as at the time this Act enters into force, and provisions corresponding thereto are included in this Act, this Act or the corresponding provision of this Act shall be deemed cited in lieu of the previous provisions.
ADDENDUM <Act No. 10138, Mar. 17, 2010>
This Act shall enter into force on the date of its promulgation.
ADDENDA <Act No. 10165, Mar. 22, 2010>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
ADDENDA <Act No. 10166, Mar. 22, 2010>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Articles 2 through 6 Omitted.
Article 7 Omitted.
Articles 8 through 9 Omitted.
ADDENDA <Act No. 10465, Mar. 29, 2011>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
ADDENDA <Act No. 10560, Apr. 5, 2011>
Article 1 (Enforcement date)
This Act shall enter into force 3 months after the date of its promulgation.
Article 2 (General transitional measures)
Previous acts of the identity verification agency which developed and provided the previous identity verification service as at the time this Act enters into force shall be deemed to have been legitimately developed and provided only if the agency obtains the designation as an identity verification agency under this Act.
Article 3 (Transitional measures concerning designation of identity verification agency)
A person who was conducting the identity verification service as at the time this Act enters into force shall be designated, within 3 months from the date this Act enters into force, as an identity verification agency by the Korea Communications Commission pursuant to the amended provisions of Article 23-3 (1).
ADDENDA <Act No. 11048, Sep. 15, 2011>
Article 1 (Enforcement date)
This Act shall enter into force 1 year after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
ADDENDA <Act No. 11322, Feb. 17, 2012>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 45, 45-2, 45-3, 46-3, 47, 47-2, 47-3, 47-5, 52 (3) 7, 66, and 76 (3) 6 through 9 shall enter into force 1 year after the date of promulgation of this Act.
Article 2 (Transitional measures concerning restrictions on collection and use of resident registration numbers)
(1) A provider of information and communications services who provides methods of subscription for membership by using the subscriber's resident registration number as at the time this Act enters into force shall destroy all the resident registration numbers possessed by the provider within 2 years after this Act enters into force; provided, this shall not apply in the case of any subparagraph of Article 23-2 (1).
(2) Where a provider of information and communications services fails to destroy the resident registration numbers possessed by him or her within the period under paragraph (1), the amended provisions of Article 23-2 (1) shall be deemed violated.
Article 3 (Transitional measures concerning abolition of safety inspection on protection of information)
A business operator who received a safety inspection on the protection of information pursuant to the previous provisions as at the time this Act enters into force shall be deemed, during the relevant year in which he or she underwent the safety inspection on the protection of information, a business operator who received the certification of an information security management system pursuant to the amended provisions of Article 47 (2).
Article 4 (Transitional measures concerning certification of personal information management system)
A person who received the certification of a personal information management system from the Korea Internet and Security Agency as at the time this Act enters into force shall be deemed to have received the certification of a personal information management system pursuant to the amended provisions of Article 47-3.
Article 5 (Transitional measures concerning administrative fines)
The previous provisions of this Act shall apply to the imposition of penalties for violations committed before this Act enters into force.
ADDENDA <Act No. 11690, Mar. 23, 2013>
Article 1 (Enforcement date)
(1) This Act shall enter into force on the date of its promulgation.
(2) Omitted.
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
ADDENDA <Act No. 12681, May 28, 2014>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 44 (3), 44-5, and 76 (1) 6 shall enter into force on the date of promulgation of this Act.
Article 2 (Transitional measures concerning penalty surcharges and penalty provisions)
The previous provisions of this Act shall apply to the imposition of penalty surcharges and penalties for violations committed before this Act enters into force.
ADDENDA <Act No. 12844, Nov. 19, 2014>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation: provided, among the statutes to be amended under Article 6 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
ADDENDUM <Act No. 13014, Jan. 20, 2015>
This Act shall enter into force 3 months after the date of its promulgation.
ADDENDUM <Act No. 13280, Mar. 27, 2015>
This Act shall enter into force on the date of its promulgation.
ADDENDA <Act No. 13343, Jun. 22, 2015>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 Omitted.
Article 3 Omitted.
ADDENDA <Act No. 13344, Jun. 22, 2015>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 (Applicability concerning administrative dispositions)
The amended provisions of Article 55 (1) shall apply even where administrative dispositions are imposed against violations committed before this Act enters into force.
ADDENDA <Act No. 13520, Dec. 1, 2015>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Article 29 (2) and (3) shall enter into force on the date of its promulgation.
Article 2 (Applicability to destruction of personal information)
The amended provisions of Article 29 (2) and (3) shall apply even to the personal information collected or provided before the amended provisions enter into force.
Article 3 (Applicability to omission of examination for certification of information security management systems)
The amended provisions of Article 47 (3) shall apply even to persons who have made an application for the certification of an information security management system, procedures for which are in progress before this Act enters into force.
Article 4 (Transitional measures concerning certification of information security management systems)
A person who has not received the certification of an information security management system shall receive the certification within 6 months after this Act enters into force, in accordance with the amended provisions of Article 47 (2).
Article 5 (Transitional measures concerning administrative fines)
The previous provisions of this Act shall apply to the imposition of penalties for violations committed before this Act enters into force.
ADDENDA <Act No. 14080, Mar. 22, 2016>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 22-2 and 76 (1) 1 and 1-2 shall enter into force 1 year after the date of promulgation of this Act; the amended provisions of Articles 32 (2) and (3) and 32-2 (3) shall enter into force on July 25, 2016; and the amended provisions of Article 52 (4) shall enter into force on the date of promulgation of this Act.
Article 2 (Applicability to compensation for damage)
The amended provisions of Articles 32 (2) and (3) and 32-2 (3) shall begin to apply to claims made for compensation for damage against information lost, stolen, leaked, forged, altered, or damaged after said amended provisions enter into force.
Article 3 (Transitional measures concerning informing fact of exposure to violations)
A provider of information and communications services shall, not later than 6 months after this Act enters into force, establish equipment, by means of which informing messages can be sent to users pursuant to the amended provisions of Article 49-2 (3).
Article 4 (Transitional measures concerning penalty provisions)
The previous provisions of this Act shall apply to the imposition of penalties for acts committed before this Act enters into force.
Article 5 Omitted.
ADDENDUM <Act No. 14580, Mar. 14, 2017>
This Act shall enter into force on the date of its promulgation.
ADDENDA <Act No. 14839, Jul. 26, 2017>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation; provided, among the statutes to be amended under Article 5 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 4 Omitted.
Article 5 Omitted.
Article 6 Omitted.
ADDENDUM <Act No. 15628, Jun. 12, 2018>
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 32-3, 45-3, and 76 (2) 4-2 (limited to the part relevant to the amended provisions of Article 32-3) shall enter into force 1 year after the date of its promulgation.
ADDENDUM <Act No. 15751, Sep. 18, 2018>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDA <Act No. 16019, Dec. 24, 2018>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Article 2 Omitted.
Article 3 Omitted.
ADDENDUM <Act No. 16021, Dec. 24, 2018>
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 44-4 and 44-7 (3) 1 shall enter into force 3 months after the date of its promulgation.
ADDENDA <Act No. 16825, Dec. 10, 2019>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 (Applicability to additional payment on refund)
The amended provisions of Article 64-3 (7) and (8) shall begin to apply where penalty surcharges are refunded on such grounds as a court judgment after this Act enters into force.
ADDENDUM <Act No. 16955, Feb. 4, 2020>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDA <Act No. 17344, Jun. 9, 2020>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
Article 7 Omitted.
Article 8 Omitted.
ADDENDUM <Act No. 17347, Jun. 9, 2020>
This Act shall enter into force on the date of its promulgation.
ADDENDA <Act No. 17348, Jun. 9, 2020>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Articles 2 through 13 Omitted.
Article 14 Omitted.
Article 15 Omitted.
ADDENDA <Act No. 17354, Jun. 9, 2020>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
Article 7 Omitted.
Article 8 Omitted.
ADDENDUM <Act No. 17358, Jun. 9, 2020>
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Article 4 (2) 7-2 shall enter into force 3 months after the date of its promulgation.
ADDENDUM <Act No. 18201, Jun. 8, 2021>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDUM <Act No. 18871, Jun. 10, 2022>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDUM <Act No. 19154, Jan. 3, 2023>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDA <Act No. 20069, Jan. 23, 2024>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 48 (4) and 71 (1) 13 shall enter into force on the date of their promulgation, and the amended provisions of Article 23-5 (1) 3 shall enter into force on the enforcement date specified in subparagraph 2 of Article 1 of the Addenda of the Personal Information Protection Act (Act No. 19234).
Article 2 (Applicability to special cases concerning certification of information security management system)
The amended provisions of Article 47-7 (1) and (3) shall apply to persons seeking certification under Article 47 (1) and (2) after this Act enters into force.
Article 3 (Transitional measures for approval for creating and processing connecting information)
Identification service agencies and the providers of information and communication services that have received temporary permission or similar special designation for creating and processing connecting information pursuant to other statutes and regulations, including Article 37 of the former Act on the Promotion of Information and Communication and Convergence Activation at the time this Act enters into force, may create and process connecting information without obtaining approval from the Korea Communications Commission under Article 23-5 (1) 4 until 1 year from the date this Act enters into force, notwithstanding its amended provisions.
ADDENDUM <Act No. 20260, Feb. 23, 2024>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDUM <Act No. 20534, Dec. 3, 2024>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDUM <Act No. 20678, Jan. 21, 2025>
This Act shall enter into force 6 months after the date of its promulgation.
ADDENDA <Act No. 21066, Oct. 1, 2025>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation; provided, among the statutes to be amended under Article 7 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 6 Omitted.
Article 7 Omitted.
Article 8 Omitted.

ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION

2-column view table
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.36502 20260707
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.36220 20260324
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.35837 20251104
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.35810 20251001
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.35533 20250520
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.35172 20241231
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.34821 20240814
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.34723 20240724
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.34258 20240227
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.34024 20231226
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.33039 20221209
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.32868 20220809
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.32274 20211230
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.32179 20211209
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.31429 20210205
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.31380 20210105
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.31247 20201210
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.31221 20201210
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.30894 20200805
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.30691 20200611
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.30509 20200303
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.29886 20190625
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.29852 20190611
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.29633 20190319
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.29339 20181213
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.29192 20180928
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.29053 20180717
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.28919 20180528
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.28283 20170905
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.28210 20170726
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.27951 20170323
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.27751 20170101
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.27510 20160923
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.27188 20160602
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.25789 20141129
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.25751 20141119
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.25532 20140807
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.25050 20140401
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.24445 20130323
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.24102 20120916
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.24076 20120902
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.24047 20130218
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.23876 20120625
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.23169 20110930
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.23104 20110829
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22773 20110329
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22550 20101227
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22467 20101102
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22424 20101001
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22423 20101001
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22151 20100505
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.22003 20100201
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.21719 20131113
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.21692 20090823
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.21278 20090128
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20947 20090204
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20896 20080703
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20756 20080328
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20668 20080229
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.20199 20070727
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.19719 20061029
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.19424 20060331
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.18759 20050331
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.18505 20040730
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.18312 20040317
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.18100 20030915
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.17344 20010825
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.16883 20000701
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.16456 19990701
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.15282 19970222
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.14947 19960314
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.14847 19960101
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13674 19920630
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13558 19911231
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13413 19910708
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.13282 19910201
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.12680 19890404
ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION No.12049 19870101
CHAPTER I GENERAL PROVISIONS
법령 이단보기
Article 1 (Purpose)
The purpose of this Decree is to provide for matters delegated by the Act on Promotion of Information and Communications Network Utilization and Information Protection and matters necessary for enforcing said Act.
법령 이단보기
Article 2 (Code of Ethics)
(1) The providers of information and communications services, defined under Article 2 (1) 3 of the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter referred to as the “Act”), or an association of such providers may establish and enforce a code of ethics in order to protect users and to ensure soundness and safety in providing information and communications services. <Amended on Jan. 28, 2009; Aug. 4, 2020>
(2) An association of users defined under Article 2 (1) 4 of the Act may establish and enforce a users’ code of ethics for the establishment of a sound information society.
(3) The Government may provide assistance to activities for the establishment and enforcement of the code of ethics under paragraph (1) or (2).
법령 이단보기
Article 3 Deleted. <Aug. 4, 2020>
CHAPTER II PROMOTION OF UTILIZATION OF INFORMATION AND COMMUNICATIONS NETWORKS
법령 이단보기
Article 4 Deleted. <Aug. 18, 2009>
법령 이단보기
Article 5 Deleted. <Aug. 18, 2009>
법령 이단보기
Article 6 (Measures for Establishment of System for Sharing Information)
(1) Pursuant to Article 12 of the Act, the head of a central administrative agency may formulate and provide a public notice of a plan for sharing information about matters under his or her jurisdiction. <Amended on May 4, 2010>
(2) If the head of a central administrative agency deems it necessary to efficiently implement a plan for sharing information pursuant to paragraph (1), he or she may assist a person in conducting the following business activities:
1. Selection of information to be shared, among the information possessed and managed;
2. Establishment and operation of a system for interconnecting different information and communications networks;
3. Adjustment of expenses allotted to each agency in connection with the interconnection of different information and communications networks;
4. Other activities necessary for the establishment of the system for sharing information.
법령 이단보기
Article 7 (Implementation of Projects for Promoting Utilization of Information and Communications Networks)
Projects that the Minister of Science and Information Communications Technology (ICT) may implement pursuant to Article 13 (1) of the Act are as follows: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. Pilot projects for the establishment and operation of information and communications networks;
2. Pilot projects for the commercialization of new media;
3. Advanced application projects for nurturing the informatization industry and projects for supporting related research projects;
4. Projects to lay a foundation for the development of technologies for electronic transactions and the invigoration of electronic transactions;
5. Supportive projects for the improvement of statutes and systems for promoting the utilization of information and communications networks;
6. Other pilot projects for the efficient utilization and dissemination of technologies, equipment, and application services.
CHAPTER III Deleted.
법령 이단보기
Article 8 Deleted. <Dec. 22, 2015>
법령 이단보기
Article 9 Deleted. <Dec. 22, 2015>
CHAPTER IV CREATION OF SAFE ENVIRONMENT FOR USE OF INFORMATION AND COMMUNICATIONS
법령 이단보기
Article 9-2 (Extent of Access Authority)
(1) A case where a provider of information and communications services shall obtain consent from the users pursuant to Article 22-2 (1) of the Act means a case where such provider needs authority of access to the following information and functions (hereafter referred to as “access authority” in this Article) through the software of mobile devices: Provided That this shall not apply to the information and functions accessed by any software, which has been installed in mobile devices in the course of manufacturing and supplying them, to perform their intrinsic functions such as communications, photography, and audio and video replay:
1. Information stored by the users on their mobile devices such as contact points, schedules, videos, communications, biometric information (referring to information concerning physical or behavioral characteristics with which an individual can be identified, such as fingerprints, iris, voice, and handwriting; hereinafter the same shall apply);
2. Information automatically stored on mobile devices in the course of using them, such as location information, communication logs, authentication information, and physical activity records;
3. Unique information assigned to identify mobile devices, including unique international identification number under Article 60-2 (1) of the Telecommunications Business Act;
4. Input and output functions, such as photography, speech recognition, and biometric or health information detecting sensor.
(2) A provider of information and communications services shall, in the course in which the users install or run a software of mobile devices, inform the users of the matters referred to in each subparagraph of Article 22-2 (1) of the Act in a manner displaying such matters on a software’s guidance information screen or other separate screen and shall obtain consent of the users according to the following classifications in the same manner:
1. Where the basic operating system of mobile devices (referring to the based environment in which the software can be executed in mobile devices; hereinafter referred to as “operating system”) is an operating system in which the users can individually choose whether to consent to the access authority: A method by which, after the provider of information and communications services informs the users about the both access authorities under Article 22-2 (1) 1 and 2 of the Act separately from each other, the users choose whether to consent when for the first time they access any information or function the access authority for which is set;
2. Where the operating system of mobile devices is one by which the users cannot individually choose whether to consent to the access authority: A method by which, after the provider of information and communications services only sets the access authority under Article 22-2 (1) 1 of the Act and informs the users thereof, the users choose whether to consent to the access authority when they install the software;
3. Where the method referred to in subparagraph 1 or 2 is impossible though the operating system of mobile devices is one referred to in subparagraph 1 or 2: A method similar to one referred to in subparagraph 1 or 2, by which the provider of information and communications services informs the users of the content of consent so that they can definitely acknowledge such content and choose whether to give consent.
(3) When determining whether a matter requiring consent of the users pursuant to Article 22-2 (1) of the Act falls under any access authority under subparagraph 1 or 2 of that Article, the following shall be taken into consideration: The extent of information and communications services as disclosed through the terms of service, the privacy policy prescribed in Article 30 (1) of the Personal Information Protection Act, or any separate guidelines; whether such information and communications services are actually provided; the users’ reasonable foreseeability for the relevant information and communications services; and technical relevance between the relevant information and communications services and the access authority, and other factors. <Amended on Aug. 4, 2020>
(4) Persons manufacturing and supplying the operating system of mobile devices, manufacturers of mobile devices, and persons manufacturing and supplying software of mobile devices shall take necessary measures according to the following classifications in order to protect information on the users referred to in Article 22-2 (3) of the Act:
1. Persons manufacturing and supplying the operating system of mobile devices: They shall manufacture and provide the operating system in which there are embedded functions by which the providers of information and communications services can obtain the consent of the users by the methods classified in the subparagraphs of paragraph (2) and the users can revokes their consent, and they also shall prepare and disclose operating standards for the access authority set in the operating system so that the persons manufacturing and supplying the software of mobile devices can easily understand such standards;
2. Manufacturers of mobile devices: They shall install on mobile devices the operating system in which functions to give and revoke the consent under subparagraph 1 are embedded;
3. Persons manufacturing and providing software of mobile devices: They shall embed in the software the operating system for which the measures under subparagraphs 1 and 2 are taken and the methods for giving and revoking consent which are suitable for mobile devices.
[This Article Added on Mar. 22, 2017]
법령 이단보기
Article 9-3 (Criteria for Standard Subject to Review)
(1) Detailed examination criteria for each item of examination under Article 23-3 (1) of the Act shall be as follows: <Amended on Aug. 17, 2012; Aug. 4, 2020>
1. A plan for physical, technological, or administrative measures: A plan for measures concerning the following shall be formulated:
(a) The management and operation of equipment for identification services under Article 23-3 (1) of the Act (hereinafter referred to as “identification services”);
(b) The prevention of a breach on information and communications networks;
(c) The operation, security, and management of systems and networks;
(d) The protection of users and the settlement of complaints;
(e) The response to urgency and emergency;
(f) The formulation and enforcement of internal regulations on identification services;
(g) The securement of safety of an alternative means under Article 23-2 (2) of the Act (hereinafter referred to as “alternative means”);
(h) The prevention of fabrication and alteration of access records;
(i) Other matters specified and publicly notified by the Korea Communications Commission for identification services;
2. Technological capability: An identification service agency shall have at least eight persons who meet any of the following requirements:
(a) Each person shall hold a national technical qualification as an information and communications engineer, information processing engineer, or an engineer specializing in application of electronic computer systems or a qualification recognized by the Korea Communications Commission as equivalent to such qualification;
(b) Each person shall have work experience of at least two years in a field specified and publicly notified by the Korea Communications Commission as related to the protection of information or the operation and management of information and communication systems;
3. Financial capability: An identification service agency’s equity capital shall be at least eight billion won (excluding state agencies and local governments);
4. Appropriateness of the scale of facilities: An identification service agency shall possess the following facilities in a scale necessary for the proper provision of identification services:
(a) Facilities for the verification, management, and protection of users’ personal information (referring to personal information defined in subparagraph 1 of Article 2 of the Personal Information Protection Act; hereafter in Article 9-6 the same shall apply);
(b) Facilities for the generation, issuance, and management of alternative means;
(c) Security facilities for controlling and restricting access;
(d) Facilities for the protection of systems and networks;
(e) Facilities for the prevention of fire, flood, power failure, and other disasters.
(2) Matters necessary for guidelines and methods for the evaluation of criteria for each standard subject to the review under paragraph (1) shall be prescribed and publicly notified by the Korea Communications Commission.
[This Article Added on Aug. 29, 2011]
법령 이단보기
Article 9-4 (Procedures for Designation of Identification Service Agencies)
(1) A person who intends to be designated as an identification service agency under Article 23-3 (1) of the Act shall file an application for the designation of an identification service agency (including in electronic form) with the Korea Communications Commission, along with the following documents (including electronic documents):
1. A business plan describing the current conditions of its organization, human resources, facilities, etc.;
2. Documents certifying that criteria for each standard subject to the review under Article 9-3 are satisfied;
3. Articles of incorporation or bylaws of organization (applicable only if an applicant is a legal person or organization);
4. Other documents specified and publicly notified by the Korea Communications Commission as documents necessary for ascertaining the expertise in providing identification services, the soundness of the financial structure, etc.
(2) Upon receipt of an application for the designation of an identification service agency under paragraph (1), the Korea Communications Commission shall verify the relevant corporate registration (applicable only if an applicant is a corporation) by sharing administrative information under Article 36 (1) of the Electronic Government Act.
(3) If the Korea Communications Commission deems it necessary to review an application under paragraph (1), it may request an applicant to submit data or may hear the applicant’s opinions.
(4) Upon receipt of an application under paragraph (1), the Korea Communications Commission shall examine whether the application meets criteria for each standard subject to the review under Article 9-3 and shall notify the applicant of the outcomes of the review within 90 days from the date when such application is filed: Provided, That the period may be extended by up to 30 days in special circumstances by giving notice of the reasons therefor.
(5) When the Korea Communications Commission designates an identification service agency based on the result of the review under paragraph (4), it shall issue a letter of designation of an identification service agency to an applicant and shall provide a public notice of the details of designation, including the name and location of the identification service agency and the date of designation, through the Official Gazette.
(6) Matters necessary for procedures and methods for the application for designation and the review on the designation under the provisions of paragraphs (1) through (5) shall be prescribed and publicly notified by the Korea Communications Commission.
[This Article Added on Aug. 29, 2011]
법령 이단보기
Article 9-5 (Identification Service Agency’s Request for Verifying Electronic Data for Resident Registration)
When a person designated as an identification service agency under Article 23-3 (1) of the Act (hereinafter referred to as "identification service agency") needs to verify the identities of a child under 14 years of age and the legal representative of the child, it may request the Minister of the Interior and Safety to verify relevant electronic data for resident registration under Article 30 (1) of the Resident Registration Act.
[This Article Added on Jul. 17, 2018]
[Previous Article 9-5 moved to Article 9-6 <Jul. 17, 2018>]
법령 이단보기
Article 9-6 (Suspension or Discontinuation of Identification Services)
(1) When an identification service agency intends to suspend or discontinue its services as referred to in Article 23-3 (2) or (3) of the Act, it shall notify users of the following matters:
1. The reasons for suspension or discontinuation;
2. The date and time of suspension or discontinuation (including the date and time of resumption of services in cases of suspension);
3. Restrictions on the use of alternative means and personal information (applicable only to suspension);
4. The destruction of alternative means and personal information (applicable only to discontinuation).
(2) When an identification service agency reports the suspension or discontinuation of its identification services in accordance with Article 23-3 (2) or (3) of the Act, it shall file a report on the suspension or discontinuation of its identification services with the Korea Communications Commission, along with the following documents:
1. A notice of the matters under paragraph (1);
2. A document concerning a plan to restrict the use or to destroy alternative means and personal information;
3. A document concerning a plan for measures for the protection of users;
4. The letter of designation of an identification service agency (applicable only to discontinuation).
(3) Details regarding the procedures, guidelines, methods, etc. for the notification and reporting of suspension or discontinuation under paragraph (1) or (2) shall be prescribed and publicly notified by the Korea Communications Commission.
[This Article Added on Aug. 29, 2011]
[Moved from Article 9-5; previous Article 9-6 Is moved to Article 9-7 <Jul. 17, 2018>]
법령 이단보기
Article 9-7 (Suspension of Identification Services or Cancellation of Designation)
(1) Standards for the suspension of identification services or the cancellation of designation under Article 23-4 (1) of the Act are as prescribed in Appendix 1.
(2) When the Korea Communications Commission suspends identification services or cancels designation under paragraph (1), it shall publish notice thereof in the Official Gazette.
[This Article Added on Aug. 29, 2011]
[Moved from Article 9-6 <Jul. 17, 2018>]
법령 이단보기
Article 10 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 11 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 12 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 13 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 14 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 14-2 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 15 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 16 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 16-2 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 17 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 17-2 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 18 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 18-2 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 19 (Scope of Persons Required to Designate Domestic Agents)
(1) "Person who meets the criteria prescribed by Presidential Decree" in Article 32-5 (1) of the Act means any of the following persons: <Amended on Aug. 4, 2020>
1. A person whose sales for the preceding year (if the person is a corporation, referring to the preceding business year) reach or exceed one trillion won;
2. A person whose sales from information and telecommunications services for the preceding year (if the person is a corporation, referring to the preceding business year) reach or exceed 10 billion won;
3. Deleted; <Aug. 4, 2020>
4. A person who caused or is likely to cause an incident or accident significantly undermining security in using information and communication services in violation of this Act and has been consequently required by the Korea Communications Commission to submit relevant articles, documents, etc. under Article 64 (1) of the Act.
(2) Sales referred to in paragraphs (1) 1 and 2 shall be based on the amount determined by converting sales into Korean won at the average foreign exchange rate for the preceding year (if the person is a corporation, referring to the preceding business year).
[This Article Added on Mar. 19, 2019]
법령 이단보기
Article 20 Deleted. <Sep. 29, 2011>
법령 이단보기
Article 21 Deleted. <Sep. 29, 2011>
법령 이단보기
Article 22 Deleted. <Sep. 29, 2011>
CHAPTER V PROTECTION OF USERS IN INFORMATION AND COMMUNICATIONS NETWORKS
법령 이단보기
Article 23 (Policy on Protection of Youths)
“Matters prescribed by Presidential Decree” in Article 41 (1) 4 of the Act means the following measures: <Amended on Jan. 28, 2009; Aug. 29, 2011>
1. Promotion of the development and dissemination of information useful to youths;
2. Encouragement of and support for youths’ voluntary activities for protecting themselves from harmful information, such as information of obscenity or violence, circulated through information and communications networks;
3. Encouragement of and support for voluntary activities conducted by parents, teachers, or nongovernmental organizations for surveillance, counseling, and remedial measures for the protection of youths;
4. Assistance in the establishment of a system for the cooperation of providers of information and communications services for the protection of youths;
5. Other measures incidental to the implementation of policies under Article 41 (1) of the Act.
법령 이단보기
Article 24 (Labeling of Media Product Harmful to Youths)
(1) A person who provides a media product harmful to youths, as defined under Article 42 of the Act, shall label it with an easily noticeable audio, text, or video warning stating that no person under 19 years shall use the same.
(2) If a person who shall put a label required by paragraph (1) provides information through the Internet, he or she shall also put an electronic label warning that it is a media product harmful to youths with symbols, marks, letters, or numbers.
(3) The Korea Communications Commission shall prescribe specific methods for labeling under paragraphs (1) and (2), taking into consideration the categories of information, etc., and shall publish notice of the methods in the Official Gazette.
법령 이단보기
Article 25 (Scope of Persons Obliged to Designate Persons Responsible for Protection of Youths)
“Provider of information and communications services whose the average number of users per day, sales, and other related factors fall under the criteria prescribed by Presidential Decree” in Article 42-3 (1) of the Act means a person who meets all the following criteria: <Amended on Aug. 29, 2011; Sep. 14, 2012>
1. A person falling under either of the following:
(a) A person in whose case the average number of users per day during three months immediately before the end of the immediately preceding year is at least 100,000 persons;
(b) A person whose sales of information and communications services during the immediately preceding year (or the preceding business year, if the service provider is a corporation) is at least one billion won;
2. A person who provides a media product harmful to youths, as defined under subparagraph 3 of Article 2 of the Youth Protection Act or who acts as a broker or agent for a transaction of such medium.
법령 이단보기
Article 26 (Duties of Persons Responsible for Protection of Youths)
A person responsible for protection of youths under Article 42-3 (1) of the Act shall perform the following duties in order to protect youths from information harmful to youths on information and communications networks (hereinafter referred to as “harmful information”):
1. Formulation of a plan for protection of youths from harmful information;
2. Measures for restricting or controlling youths’ access to harmful information;
3. Education of persons engaged in information and communications services for the protection of youths from harmful information;
4. Counseling on damage inflicted by harmful information and the settlement of grievances;
5. Other matters necessary to protect youths from harmful information.
법령 이단보기
Article 27 (Deadline for Designation of Persons Responsible for Protection of Youths)
A person responsible for protection of youths under Article 42-3 (1) of the Act shall be designated by no later than the end of April each year.
법령 이단보기
Article 28 (Preservation of Video or Audio Information)
(1) “Information provider prescribed by Presidential Decree” in Article 43 (1) of the Act means a person who distributes information through telecommunications lines: Provided, That broadcasting business entities, CATV relay broadcasting business entities, and electronic signboard broadcasting business entities under subparagraphs 3, 6, and 12 of Article 2 of the Broadcasting Act, among persons who distribute information according to a certain program schedule, using the word “broadcasting”, “television” or “radio” in their names, shall be excluded herefrom. <Amended on Aug. 29, 2011>
(2) An information provider under Article 43 of the Act shall preserve relevant information for six months from the time when the information is provided for use.
법령 이단보기
Article 29 Deleted. <Nov. 28, 2014>
법령 이단보기
Article 30 Deleted. <Nov. 28, 2014>
법령 이단보기
Article 31 (Scope of User Information That May Be Requested)
“Minimum information prescribed by Presidential Decree” in Article 44-6 (1) of the Act means the following information: <Amended on Aug. 29, 2011>
1. Name;
2. Address;
3. Other information that the defamation dispute conciliation division under Article 44-10 of the Act (hereinafter referred to as “defamation dispute conciliation division”) deems necessary for filing a civil or criminal complaint, including the contact information of users involved.
법령 이단보기
Article 32 (Procedures for Requesting Provision of Information)
(1) A person who intends to request the provision of the information of users involved pursuant to Article 44-6 (1) of the Act (hereinafter referred to as “claimant”) may file a claim with the defamation dispute conciliation division, stating the following matters therein, along with supporting materials:
1. The claimant’s name, address, and contact information (referring to telephone numbers, e-mail addresses, etc.);
2. The category of the lawsuit to be filed and remedies sought;
3. The type of violated rights and specific facts relevant to the violation of rights by users involved.
(2) Where the defamation dispute conciliation division finds it necessary to make a decision on whether to provide information under Article 44-6 (2) of the Act, it may permit the claimant to present his or her arguments.
법령 이단보기
Article 33 (Procedures for Provision of Information)
(1) Upon receipt of a request from a claimant to provide information, the defamation dispute conciliation division shall make a decision on whether to provide the information of users involved and shall notify the claimant of its decision.
(2) When the defamation dispute conciliation division decides to provide information, it shall request the relevant provider of information and communications services to provide information under Article 31. In such cases, the provider of information and communications services shall comply with such request, unless there is a compelling reason not to do so. <Amended on Jan. 28, 2009>
(3) A provider of information and communications services shall notify the users involved of such provision of information under paragraph (2). <Amended on Jan. 28, 2009>
(4) The defamation dispute conciliation division shall keep documents relating to the provision of user information for five years.
법령 이단보기
Article 34 (Requests to Order Restrictions on Handling Unlawful Information)
(1) When the head of a related central administrative agency (including the head of an investigative agency with regard to a photograph or its duplicate (including duplicates of duplicates) under Article 14 of the Act on Special Cases concerning the Punishment of Sexual Crimes out of information provided in Article 44-7 (1) 9 of the Act; hereafter in this Article the same shall apply) intends to request the Korea Communications Commission pursuant to Article 44-7 (3) of the Act to order a provider of information and communications services or the manager or operator of a message board to refuse, suspend, or restrict the management of the information specified in Article 44-7 (1) 7 through 9 of the Act, he or she shall submit to the Korea Communications Commission a written request stating the following matters, along with evidentiary materials: <Amended on Jan. 28, 2009; Sep. 22, 2016; Jun. 11, 2019>
1. The purpose of and reasons for a request;
2. Relevant statutes or regulations and the details of violations;
3. A list of relevant information and a person by whom the relevant information is provided;
4. The titles or names and contact information, such as addresses, telephone numbers, and e-mail addresses, of the provider of information and communications services or the manager or operator of the message board and users involved.
(2) If the Korea Communications Commission finds any defect in the documents submitted pursuant to paragraph (1), it may request the head of a related central administrative agency to rectify the defect immediately. In such cases, at least five more days shall be given for rectification.
(3) If the head of a related central administrative agency fails to rectify a defect even until the end of a period given for the rectification requested under paragraph (2), the Korea Communications Commission may return the request and evidential materials submitted pursuant to paragraph (1) to the head of the related central administrative agency.
[Title Amended on Sep. 22, 2016]
법령 이단보기
Article 35 (Grounds for Exception from Submission of Opinions)
“Ground prescribed by Presidential Decree” in Article 44-7 (4) 2 of the Act means any of the following cases: <Amended on Aug. 29, 2011>
1. Where a user involved is not identifiable (limited to the submission of a user’s opinion);
2. Where the facts relevant to an order have already been proved objective by a final judgment of a court or by other decisions and thus issuing the order to hear an opinion is unnecessary.
법령 이단보기
Article 35-2 (Persons Responsible for Preventing Circulation of Illegally Filmed Materials)
(1) A provider of information and communications services obligated to designate a person responsible for preventing the circulation of illegally filmed materials, etc. pursuant to Article 44-9 (1) of the Act shall be the following persons:
1. A person who provides value-added telecommunications services defined in subparagraph 14 (a) of Article 2 of the Telecommunications Business Act among special value-added telecommunications business operators referred to in Article 22-3 (1) of that Act;
2. Any of the following persons, who has filed a report on the value-added telecommunications business under Article 22 (1) of the Telecommunications Business Act (including a person who falls under any of the subparagraphs of Article 22 (4) of that Act):
(a) A person who provides information and communication services under Appendix 1-2, posting at least 10 billion won in sales of information and communication services over the preceding year (referring to the preceding business year, in the case of a corporation);
(b) A person who has an average number of at least 100,000 users per day for three months immediately before the end of the preceding year and who provides information and telecommunications services specified in Appendix 1-2.
(2) A provider of information and communications services under the subparagraphs of paragraph (1) (hereinafter referred to as "person obligated to designate a person responsible for preventing the circulation of illegally filmed materials, etc.") shall designate at least one person responsible for preventing the circulation of illegally filmed materials (hereinafter referred to as "illegally filmed materials, etc.") under Article 44-9 (1) of the Act (hereinafter referred to as "person responsible for preventing the circulation of illegally filmed materials").
(3) Persons responsible for preventing the circulation of illegally filmed materials, etc. shall be any of the following persons:
1. Executive officers who belong to the person obligated to designate a person responsible for preventing the circulation of illegally filmed materials, etc.;
2. The head of a division responsible for preventing the circulation of illegally filmed materials, etc., who belongs to the person obligated to designate a person responsible for preventing the circulation of illegally filmed materials, etc.
(4) A person responsible for preventing the circulation of illegally filmed materials, etc. shall receive education (including remote education using information and communications networks) for at least two hours every year, including the following matters, which is delivered by the Korea Communications Commission in cooperation with relevant agencies and organizations:
1. Matters regarding systems and statutes and regulations relating to preventing the circulation of illegally filmed materials;
2. Matters regarding measures necessary to prevent circulation under Article 44-9 (2) of the Act;
3. Matters regarding the criteria for deliberation on illegally filmed materials, etc. by the Korea Communications Standards Commission under Article 18 of the Act on the Establishment and Operation of Korea Communications Commission (hereinafter referred to as the "Korea Communications Standards Commission");
4. Other matters deemed by the Korea Communications Commission as necessary for preventing the circulation of illegally filmed materials, etc.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 36 (Establishment and Management of Defamation Dispute Conciliation Division, and Conciliation of Disputes)
(1) A meeting of the defamation dispute conciliation division shall be convened by the head of the defamation dispute conciliation division.
(2) When the head of the defamation dispute conciliation division intends to hold a meeting of the division, he or she shall determine the date, time, and place of meeting and items on the agenda and shall notify the conciliators thereof by no later than seven days before the opening of the meeting, except in unavoidable circumstances.
(3) A majority of the conciliators of the defamation dispute conciliation division shall constitute a quorum, and any resolution thereof shall require the concurring votes of at least a majority of those present.
(4) The head of the defamation dispute conciliation division shall be appointed by the Chairman of the Korea Communications Standards Commission, from among conciliators. <Amended on Dec. 8, 2020>
(5) No meeting of the defamation dispute conciliation division shall be open to the public; provided,, if it is deemed necessary, the defamation dispute conciliation division may resolve to permit parties to a dispute or interested parties to sit in on a meeting.
(6) Deleted. <Sep. 29, 2011>
(7) Except as provided in this Decree, the establishment, organization, and management of the defamation dispute conciliation division and other matters necessary for the conciliation of disputes shall be determined by the resolution of the Korea Communications Standards Commission.
CHAPTER VI SECURING OF STABILITY OF INFORMATION AND COMMUNICATIONS NETWORKS
법령 이단보기
Article 36-2 (Scope of Equipment Connected to Information and Communications Networks)
"Devices, equipment, and facilities prescribed by Presidential Decree" in Article 45 (1) 2 of the Act means the following devices, equipment, and facilities (hereinafter referred to as "equipment connected to information and communications networks, etc.") in any field specified in Appendix 1-3:
1. Devices, equipment, and facilities that have caused or are likely to cause a computer security incident;
2. Devices, equipment, and facilities that pose a serious risk to ensuring the security of information and communications networks and the reliability of information, if a computer security accident occurs.
[This Article Added on Dec. 8, 2020]
[Previous Article 36-2 moved to Article 36-3 <Dec. 8, 2020>]
법령 이단보기
Article 36-3 (Preliminary Examination Standards on Protection of Information)
Preliminary examination standards on the protection of information under Article 45-2 (2) of the Act shall be determined and publicly notified by the Minister of Science and ICT, taking the following matters into consideration: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. The structure of the system for establishing an information and communications network or for providing information and communications services and the operating environment of such system;
2. Identification of assets to be protected, such as hardware, programs, and content for the operation of the system under subparagraph 1 and hazards in the protection of such assets;
3. Current status of the establishment and implementation of protective measures.
[This Article Added on Aug. 17, 2012]
[Moved from Article 36-2; Previous Article 36-3 moved to Article 36-4 <Dec. 8, 2020>]
법령 이단보기
Article 36-4 (Business Subject to Recommendation of Preliminary Examination on Protection of Information)
(1) “Information and communications services or telecommunications business determined by Presidential Decree” in Article 45-2 (2) 1 of the Act means the information and communications services or telecommunications businesses that require at least 500 million won (referring to an amount exclusive of costs incurred in merely purchasing hardware and software) for investment in information systems.
(2) “Information and communications services or telecommunications business determined by Presidential Decree” in Article 45-2 (2) 2 of the Act means the information and communications services or the telecommunications businesses that the Minister of Science and ICT fully or partially subsidizes projects for searching for and nurturing new information and communications services or the telecommunications businesses. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Aug. 17, 2012]
[Moved from Article 36-3; previous Article 36-4 moved to Article 36-5 <Dec. 8, 2020>]
법령 이단보기
Article 36-5 (Methods and Procedures for Preliminary Examinations on Protection of Information)
(1) The preliminary examination on the protection of information under Article 45-2 (2) of the Act shall be administered by a written examination, on-site examination, or remote examination (referring to an examination administered on matters related to security by accessing the system under subparagraph 1 of Article 36-3 from outside through an information and communications network). <Amended on Dec. 8, 2020>
(2) The preliminary examination on the protection of information under Article 45-2 (2) of the Act shall be administered according to the following order:
1. Preparation for the preliminary examination;
2. Review on designs;
3. Application of protective measures;
4. Inspection on the current status of implementation of protective measures;
5. Arrangement of results of the preliminary examination.
(3) Upon recommendation from the Minister of Science and ICT under Article 45-2 (2) of the Act, a person may administer the preliminary examination on the protection of information by himself or herself or request the Korea Internet and Security Agency under Article 52 of the Act (hereinafter referred to as the “Korea Internet and Security Agency”) or a specialized external agency to administer the preliminary examination on his or her behalf. In such cases, only persons who meet the standards for the qualification as technicians for the protection of information under Appendix 2 may administer the preliminary examination on the protection of information. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(4) Except as provided in paragraphs (1) through (3), details regarding the methods and procedures for preliminary examination on the protection of information shall be determined and publicly notified by the Minister of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Aug. 17, 2012]
[Moved from Article 36-4; previous Article 36-5 moved to Article 36-6 <Dec. 8, 2020>]
법령 이단보기
Article 36-6 (Fees for Preliminary Examinations on Protection of Information)
(1) When a person requests the Korea Internet and Security Agency or an external professional agency to administer the preliminary examination on the protection of information on his or her behalf, as recommended by the Minister of Science and ICT under Article 45-2 (2) of the Act, the person shall pay fees therefor to the Korea Internet and Security Agency or the specialized external agency. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Minister of Science and ICT shall determine and provide a public notice of guidelines for the determination of fees for the preliminary examination on the protection of information, taking the following factors into consideration: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. The scale of information and communications services or telecommunications businesses subject to the preliminary examination on the protection of information;
2. Expertise of persons participating in the preliminary examination on the protection of information;
3. The period required for the preliminary examination on the protection of information.
[This Article Added on Aug. 17, 2012]
[Moved from Article 36-5; previous Article 36-6 moved to Article 36-7 <Dec. 8, 2020>]
법령 이단보기
Article 36-7 (Designation of Chief Information Security Officers and Prohibition on Dual Office Holding)
(1) "Executive officers and employees meeting the criteria prescribed by Presidential Decree" in the main clause of Article 45-3 (1) of the Act means persons categorized as follows: <Added on Dec. 7, 2021>
1. Any of the following providers of information and telecommunications services: The business owner or its representative:
(a) A person whose capital does not exceed 100 million won;
(c) A medium enterprise defined in Article 2 (2) of the Framework Act on Small and Medium Enterprises, which does not fall under any of the following:
(i) A telecommunications business operator under the Telecommunications Business Act;
(ii) A person required to obtain certification of an information security management system pursuant to Article 47 (2) of the Act;
(iii) A personal information controller required to disclose its privacy policy under Article 30 (2) of the Personal Information Protection Act;
(iv) A mail order distributor required to file a report under Article 12 of the Act on the Consumer Protection in Electronic Commerce;
2. Any of the following providers of information and communications services: Directors (including persons under Article 401-2 (1) 3 of the Commercial Act and executive directors under Article 408-2 of that Act):
(a) A person whose total assets as of the end of the immediately preceding business year amount to at least five trillion won;
(b) A person whose total assets as of the end of the immediately preceding business year amount to at least 500 billion won, among those required to obtain certification of an information security management system under Article 47 (2) of the Act;
3. A provider of information and communications services who does not fall under subparagraph 1 or 2: Any of the following persons:
(a) The business owner or representative;
(b) Directors (including persons prescribed in Article 401-2 (1) 3 of the Commercial Act and executive directors prescribed in Article 408-2 of that Act);
(c) The head of a department that has general supervision and control of information security-related affairs.
(2) "Provider of information and communications services whose total assets, sales, and the like meet the criteria prescribed by Presidential Decree" in the proviso of Article 45-3 (1) of the Act means a person referred to in any item of paragraph (1) 1 as a provider of information and communications services. <Amended on Dec. 7, 2021>
(3) Where a person falling under the proviso of Article 45-3 (1) of the Act fails to report his or her chief information security officer, he or she shall be deemed to have designated the business owner or representative as the chief information security officer. <Added on Dec. 7, 2021>
(4) A chief information security officer required to be designated and reported by a provider of information and communications services pursuant to Article 45-3 (1) and (7) of the Act shall have any of the following qualifications. In such cases, a degree in the field of information security or information technology refers to the completion of and graduation from courses offered by departments provided in the items of subparagraph 1 of the remarks of Appendix 1 of the Enforcement Decree of the Electronic Financial Transactions Act at schools referred to in the subparagraphs of Article 2 of the Higher Education Act or other degrees recognized as equivalent to or higher than aforementioned degrees under other relevant statutes or regulations: <Amended on Dec. 7, 2021>
1. A person who has obtained at least a master’s degree in the field of information security or information technology in Korea or abroad;
2. A person who has at least three years of work experience in the field of information protection or information technology, after obtaining a bachelor’s degree in the field of information security or information technology in Korea or abroad;
3. A person who has at least five years of work experience in the field of information security or information technology, after obtaining an associate degree in the field of information security or information technology in Korea or abroad;
4. A person who has at least 10 years of work experience in the field of information security or information technology;
5. A person who has obtained the qualification of a certification examiner of information security management systems under Article 47 (6) 5;
6. A person who has at least one year of work experience as the head of a department in charge of the information security-related affairs of the relevant provider of information and communications services.
(5) "Provider of information and communications services whose total assets, sales, and the like meet the criteria prescribed by Presidential Decree" in Article 45-3 (3) of the Act means a person who falls under any item of paragraph (1) 2 as a provider of information and communications services. <Amended on Dec. 7, 2021>
(6) The chief information security officer required to be designated and reported by a provider of information and communications services under paragraph (5) shall be a full-time worker with qualifications prescribed in paragraph (4) together with any of the following qualifications. In such cases, the affairs in the field of information security or information technology mean the affairs under subparagraphs 3 and 4 of the remarks of Appendix 1 of the Enforcement Decree of the Electronic Financial Transactions Act: <Amended on Dec. 7, 2021>
1. A person who has at least four years of work experience in the field of information security;
2. A person who has at least five years of total combined work experience in the field of information security and information technology (at least two years of those work experience shall be from the field of information security).
[This Article Wholly Amended on Jun. 11, 2019]
[Moved from Article 36-6; previous Article 36-7 moved to Article 36-8 <Dec. 8, 2020>]
법령 이단보기
Article 36-8 (Methods and Procedures for Reporting on Chief Information Security Officers)
Any information and communications service provider obligated to designate and report a chief information security officer under the proviso of Article 45-3 (1) of the Act shall submit to the Minister of Science and ICT a report on the designation of the chief information security officer prescribed by Ministerial Decree of Science and ICT within 180 days from the date he or she becomes obligated to report such officer. <Amended on Jul. 26, 2017; Jun. 11, 2019; Dec. 7, 2021>
[This Article Added on Nov. 28, 2014]
[Moved from Article 36-7; previous Article 36-7 moved to Article 36-8 <Dec. 8, 2020>]
법령 이단보기
Article 36-9 (Scope of Programs of Council of Chief Information Security Officers)
“Joint programs prescribed by Presidential Decree” in Article 45-3 (5) of the Act means the following programs: <Amended on Nov. 28, 2014; Jun. 11, 2019>
1. Assistance in policy research, studies, and formulation to enable information and communications service providers to strengthen the protection of information;
2. Analysis on a computer security incident and the study of measures following the use of information and communications services;
3. Improvement of information and communications service providers' ability and expertise of the protection of information, including education of chief information security officers;
4. International exchange and cooperation in relation to information and communications services security;
5. Other programs necessary for the security of information and communications systems and the safe management of information.
[This Article Added on Aug. 17, 2012]
[Moved from Article 36-8 <Dec. 8, 2020>]
법령 이단보기
Article 37 (Protective Measures of Business Entities of Clustered Information and Communications Facilities)
(1) Pursuant to Article 46 (1) of the Act, a provider of information and communications services who operates and manages clustered information and communications facilities to provide information and communications services of other persons (hereinafter referred to as "business entity of clustered information and communications facilities") shall take the following protective measures to ensure the stable operation of information and communications facilities: <Amended on Jan. 28, 2009; Jun. 11, 2019; Dec. 7, 2021>
1. Technical and administrative measures for controlling and monitoring access by persons who have no authority to access information and communications facilities;
2. Physical and technical measures for uninterrupted and stable operation of information and communications facilities and for protecting information and communications facilities from various disasters and threats, such as fire, earthquake, flood, and terrorism;
3. Measures for selecting and placing personnel for the stable management of information and communications facilities;
4. Formulation and implementation of an internal control plan for the stable operation of information and communications facilities (including an emergency plan);
5. Preparation and implementation of technical and administrative measures to contain the spread of computer security incidents.
(2) The Minister of Science and ICT shall collect opinions from related business entities and determine and publicly notify detailed guidelines for protective measures under paragraph (1). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) If any duty carried out by another agency is involved in the course of inspecting implementation of protective measures under paragraph (1), the Minister of Science and ICT shall consult with the relevant agency thereon in advance. <Amended on Mar. 23, 2013; Jul. 26, 2017>
법령 이단보기
Article 38 (Insurance)
(1) Pursuant to Article 46 (2) of the Act, a business entities of clustered information and communications facilities shall buy a liability insurance policy simultaneously when he or she commences his or her business operation.
(2) The amount of liability insurance that a business entity is obligated to purchase under paragraph (1) shall be as specified in Appendix 3. <Amended on Aug. 29, 2011; Jun. 11, 2019; Dec. 8, 2020>
법령 이단보기
Article 39 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 40 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 41 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 42 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 43 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 44 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 45 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 46 Deleted. <Aug. 17, 2012>
법령 이단보기
Article 47 (Methods and Procedures for, and Scope of, Certification of Information Security Management Systems)
(1) A person who intends to have his or her information security management system certified under Article 47 (1) or (2) of the Act shall file an application for the certification of the information security management system (or an application in an electronic form) with the Korea Internet and Security Agency, an institution designated pursuant to Article 47 (6) of the Act (hereinafter referred to as “certification body of information security management system”), or an institution designated pursuant to Article 47 (7) of the Act (hereinafter referred to as “examination institution for information security systems”), along with a statement of the information security management system (or a statement in an electronic format) containing explanations about the following matters: <Amended on Mar. 23, 2013; May 31, 2016>
1. The scope of the information security management system;
2. A list of major information and communications facilities included in the information security management system and the system diagram;
3. The method and procedure for the establishment and operation of the information security management system;
4. A list of major documents related to the information security management system;
5. Details of domestic and foreign certifications obtained for the quality management system in connection with the information security management system.
(2) Where the Korea Internet and Security Agency, a certification body of information security systems, or an examination institution for information security systems in receipt of an application referred to in paragraph (1) conducts a certification examination referred to in Article 47 (6) 1 of the Act (hereinafter referred to as “certification examination”), it shall consult with the applicant about the scope, time schedule, etc. of certification on the basis of standards for certification, etc. determined and publicly notified by the Minister of Science and ICT for the certification of information security systems referred to in paragraph (4) of that Article (hereinafter referred to as “public notice of certification of security systems”), including countermeasures for managerial, technical and physical protection. <Amended on Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
(3) The Korea Internet and Security Agency, a certification institution for information protection and management systems, or an examination institution for information protection and management systems shall, in the case of conducting a certification examination, examine whether the information protection and management system established by the applicant for certification meets requirements for public notice of certification of management systems. In such cases, a certification examination shall be conducted by means of a written examination or on-site examination. <Amended on May 31, 2016>
(4) A certification examination may be administered only by a certification examiner under Article 53 (1) 1. <Amended on May 31, 2016>
(5) An examination institution for information protection and management systems shall submit the result of a certification examination to a certification institution for information protection and management systems. <Added on May 31, 2016>
(6) The Korea Internet and Security Agency or a certification institution for information protection and management systems shall establish and operate a certificate committee composed of members having abundant knowledge and experience in the information protection field to deliberate on the results of examinations of certification. <Amended on May 31, 2016>
(7) Where an information protection and management system is found to meet the requirements for public notification of certification of management systems as a result of the deliberation by the certificate committee under paragraph (6), the Korea Internet and Security Agency or a certification institution for information protection and management systems shall issue a certificate of the information protection and management system. <Amended on May 31, 2016>
(8) Except as provided in paragraphs (1) through (7), details regarding the application for certification, deliberation on certification, the establishment and operation of a certification committee, and the issuance of certificates shall be determined and publicly notified by the Minister of Science and ICT. <Amended on Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
[This Article Wholly Amended on Aug.17, 2012]
[Moved from Article 50; previous Article 47 moved to Article 53 <Aug. 17, 2012>]
법령 이단보기
Article 48 (Fees for Certification of Information Security Management Systems)
(1) A person who intends to apply for certification pursuant to Article 47 (1) shall pay fees to the Korea Internet and Security Agency, a certification institution of information protection and management systems, or an examination institution for information protection and management systems. <Amended on May 31, 2016>
(2) The Minister of Science and ICT shall determine and give a public notice of detailed guidelines for the determination of fees for the certification of information security management systems, taking into consideration the number of certification examiners assigned to a certification examination, the number of days required for the certification examination, etc. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Aug. 17, 2012]
[Previous Article 48 moved to Article 53-2 <Aug. 17, 2012>]
법령 이단보기
Article 49 (Scope of Persons Subject to Certification of Information Security Management Systems)
(1) “Person who renders information and communications services, as prescribed by Presidential Decree” in Article 47 (2) 1 of the Act means a person who provides information and communications network services in Seoul Special Metropolitan City or any Metropolitan City.
(2) “Person falling under the standards determined by Presidential Decree” in Article 47 (2) 3 of the Act means either of the following persons: <Amended on May 31, 2016>
1. A person falling under any of the following items whose annual sales or revenues are at least 150 billion won:
(a) A superior general hospital under Article 3-4 of the Medical Service Act;
(b) A school pursuant to Article 2 of the Higher School Act, the number of the enrolled students of which is at least 10,000 as of December 31, of the immediately preceding year;
2. A person whose sales of information and communication services during the preceding year (referring to the preceding business year, in the case of a corporation) are least 10 billion won: excluding, however, a financial company under subparagraph 3 of Article 2 of the Electronic Financial Transactions Act;
3. A person whose average daily number of users during three months immediately before the end of the preceding year is at least one million: Provided, That a financial company under subparagraph 3 of Article 2 of the Electronic Financial Transactions Act.
[This Article Added on Aug. 17, 2012]
[Previous Article 49 moved to Article 53-3 <Aug. 17, 2012>]
법령 이단보기
Article 50
[Moved to Article 47 <Aug. 17, 2012>]
법령 이단보기
Article 51 (Follow-Up Management of Certification)
(1) Follow-up management under Article 47 (8) of the Act shall be conducted by means of written examination or on-site examination. <Amended on May 31, 2016>
(2) Where as a result of conducting follow-up management pursuant to Article 47 (8) of the Act, an examination institution for information protection and management systems finds there is a ground referred to in any subparagraph of paragraph (10) of that Article, it shall immediately submit the result of the follow-up management so conducted to the Korea Internet and Security Agency or a certification institution for information protection and management systems. <Added on May 31, 2016>
(3) In cases falling under any of the following subparagraphs, the Korea Internet and Security Agency or a certification institution for information protection and management systems shall, after undergoing deliberation by the certification committee referred to Article 47 (6), notify the results thereof to the Minister of Science and ICT: <Amended on May 31, 2016; Jul. 26, 2017>
1. Where follow-up management conducted pursuant to Article 47 (8) of the Act finds grounds referred to in any subparagraph of paragraph (10) of that Article;
2. Where the Korea Internet and Security Agency or a certification institution for information protection and management systems receives the result of follow-up management from an examination institution for information protection and management systems pursuant to paragraph (2).
[This Article Wholly Amended on Aug.17, 2012]
[Moved from Article 52; Previous Article 51 Deleted]
법령 이단보기
Article 52 (Indication and Public Relation of Certification)
A person who obtains certification of his or her information security management system pursuant to Article 47 (1) or (2) of the Act may use a certification mark determined and publicly notified by the Minister of Science and ICT for the information security management system, when he or she indicates or promotes the certification in a document, invoice, or advertisement in accordance with Article 47 (9) of the Act. In such cases, the scope of certification and the effective period shall be indicated together with the mark. <Amended on Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
[This Article Wholly Amended on Aug.17, 2012]
[Moved from Article 53; previous Article 52 moved to Article 51 <Aug. 17, 2012>]
법령 이단보기
Article 53 (Criteria for Designation of Certification Institution for Information Protection and Management Systems and Examination Institution for Information Protection and Management Systems)
(1) The criteria for the designation of a certification institution for information protection and management systems and an examination institution for information protection and management systems shall be as follows: <Amended on Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
1. A certification institution shall have at least five persons who meet the requirements for the qualification determined and publicly notified by the Minister of Science and ICT (hereinafter referred to as “certification examiners”);
2. A certification institution shall be approved as competent in an examination administered by the Minister of Science and ICT on the requirements and competence for the performance of the duties.
(2) The Minister of Science and ICT shall determine and publicly notify detailed guidelines for the education of certification examiners, the management of qualification of certification examiners, and the examination on the requirements and competence for the performance of the duties under paragraph (1) 2. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Aug.17, 2012]
[Title Amended on May 31, 2016]
[Moved from Article 47; previous Article 53 moved to Article 52 <Aug. 17, 2012>]
법령 이단보기
Article 53-2 (Procedures for Designation of Certification Institution for Information Security Management Systems and Examination Institution for Information Protection and Management Systems)
(1) A person who intends to have his or her business designated as a certification institution for information protection and management systems or an examination institution for information protection and management systems pursuant to Article 47 (6) or (7) of the Act shall file an application (including in electronic form) for the designation of a certification institution for information protection and management systems or an examination institution for information protection and management systems with the Minister of Science and ICT, along with the following documents (or electronic documents): <Amended on Aug. 17, 2012; Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
1. Articles of incorporation, or bylaws of an association;
2. A statement of the current status of certification examiners employed and a document certifying the current status;
3. Documents determined and publicly notified by the Minister of Science and ICT as those necessary for the examination on the requirements and competence for the performance of duties, including work experience in performing duties for the protection of information and the level of expertise.
(2) Upon receipt of an application for the designation under paragraph (1), the Minister of Science and ICT shall verify the relevant corporate registration by sharing administrative information under Article 36 (1) of the Electronic Government Act, if the applicant is a corporation. <Amended on May 4, 2010; Nov. 2, 2010; Mar. 23, 2013; Jul. 26, 2017>
(3) Upon receipt of an application for the designation under paragraph (1), the Minister of Science and ICT shall examine whether the application meets the criteria for the designation under Article 53 (1), notify the applicant of the results thereof within three months from the date when the application is filed, and issue a certificate of designation of a certification institution for information protection and management systems or a certificate of designation of an examination institution for information protection and management systems to the applicant, if the applicant is designated as a certification institution for information protection and management systems or an examination institution for information protection and management systems. <Amended on Aug. 17, 2012; Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
(4) When the Minister of Science and ICT examines whether an application meets the criteria for the designation under paragraph (3), he or she may require the applicant to submit data or may conduct an on-site inspection. In such cases, a person who conducts an on-site inspection shall produce an identification badge certifying his or her authority to the applicant. <Amended on Aug. 17, 2012; Mar. 23, 2013; Jul. 26, 2017>
(5) Deleted. <Jun. 25, 2012>
[Title Amended on May 31, 2016]
[Moved from Article 48 <Aug. 17, 2012>]
법령 이단보기
Article 53-3 (Effective Period for Designation of Certification Institution for Information Protection and Management Systems and Examination Institution for Information Protection and Management Systems)
(1) The effective period for the designation of a certification institution for information protection and management systems or an examination institution for information protection and management systems under Article 53-2 shall be three years. <Amended on Aug. 17, 2012; May 31, 2016>
(2) A certification institution may file an application for re-designation during the period from six months before the end of the effective period under paragraph (1) to the expiry date. In such cases, the designation shall be deemed effective until the applicant for re-designation is notified of a decision on the application.
(3) Articles 53 and 53-2, and paragraph (1) shall apply mutatis mutandis to the re-designation under paragraph (2). <Amended on Aug. 17, 2012>
[Title Amended on May 31, 2016]
[Moved from Article 49 <Aug. 17, 2012>]
법령 이단보기
Article 53-4 (Follow-Up Management of Certification Institution for Information Protection and Management Systems and Examination Institution for Information Protection and Management Systems)
(1) A certification institution for information protection and management systems and an examination institution for information protection and management systems shall submit a report according to the following classification for the preceding year to the Minister of Science and ICT by no later than January 31 each year: <Amended on May 31, 2016; Jul. 26, 2017>
1. A certification institution for information protection and management systems: a report on the performances of certification for the preceding year;
2. An examination institution for information protection and management systems: a report on the performances of certification examination for the preceding year.
(2) If the Minister of Science and ICT deems it necessary to ascertain whether a certification institution for information protection and management systems or an examination institution for information protection and management systems falls under any subparagraph of Article 47-2 (1) of the Act, he or she may require the certification institution or the examination institution to submit data or may conduct an on-site inspection. <Amended on Mar. 23, 2013; May 31, 2016; Jul. 26, 2017>
[This Article Added on Aug. 17, 2012]
[Title Amended on May 31, 2016]
법령 이단보기
Article 54 (Guidelines for Revocation of Designation)
Guidelines for administrative dispositions rendered for the revocation of designation or the suspension of business under Article 47-2 of the Act are as prescribed in Appendix 4.
법령 이단보기
Article 54-2 (Measures to Prevent Computer Security Incidents and Preclude Dissemination Thereof)
(1) In order to prevent computer security incidents and precluding spread thereof under Article 47-4 (1) of the Act, the Government may pay a monetary award to a person who reports security vulnerability, within the budget.
(2) Standards, procedures, etc. for the payment of monetary awards under paragraph (1) shall be as listed in Appendix 4-2.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 54-3 (Entrustment of Affairs regarding Measures to Prevent Intrusion Incidents and Preclude Spread Thereof)
(1) The head of a central administrative agency may entrust affairs regarding measures under Article 47-4 (1) of the Act to the Korea Internet and Security Agency or any specialized institution related to the protection of users’ information, as determined by the head of the relevant central administrative agency in consultation with the Minister of Science and ICT.
(2) Where the head of a central administrative agency designates an entrusting agency pursuant to paragraph (1), he or she shall publicly notify an agency entrusted with the affairs and the details of such affairs entrusted.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 55 (Standard Agreements on Requests to Users for Protective Measures)
Matters that shall be stipulated in the terms of service with respect to a request to users for protective measures under Article 47-4 (3) of the Act shall be as follows: <Amended on Aug. 17, 2012; Dec. 8, 2020>
1. Grounds for requesting users to take protective measures and a method of making such request;
2. Details of protective measures that users shall take;
3. The period during which access to an information and communications network is restricted, if a user fails to take protective measures;
4. Procedures for filing a user’s objection and for compensation therefor, if a user’ access is unreasonably restricted on the grounds of the user’s failure to take protective measures.
법령 이단보기
Article 55-2 (Criteria for Examination for Rating Management of Information Protection)
(1) The criteria for management rating of information protection under Article 47-5 (1) of the Act shall be as follows:
1. The scope of the system established for the management of information protection and the period of operation;
2. An organization exclusively dedicated to information protection and the budget therefor;
3. Activities for the management of information protection and the level of protective measures.
(2) Matters necessary for the detailed criteria and methods for the evaluation according to the criteria for examination under paragraph (1) shall be determined and publicly notified by the Minister of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Aug. 17, 2012]
법령 이단보기
Article 55-3 (Methods and Procedures for Rating Management of Information Protection)
(1) A person who intends to be rated as qualified for the protection and management of information under Article 47-5 (1) of the Act shall file an application (including in electronic form) for rating the protection and management of information with the Korea Internet and Security Agency, along with a copy of the letter of certification of the information security management system.
(2) A written examination or an on-site examination shall be administered for the examination for rating the protection and management of information.
(3) Only certification examiners shall be able to conduct the examination under paragraph (2).
(4) If the results of an examination administered under paragraph (2) meet the criteria for examination under Article 55-2, the Korea Internet and Security Agency shall issue a certificate of the rating for the protection and management of information to the applicant for the rating qualified for management.
(5) Except as provided in paragraphs (1) through (4), further details necessary for the application and examination for rating the management of information protection and the issuance of certificates of the rating for the management of information protection shall be determined and publicly notified by the Minister of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Aug. 17, 2012]
법령 이단보기
Article 55-4 (Fees for Rating Management of Information Protection)
Articles 48 and 52 shall apply mutatis mutandis to fees for rating for the management of information protection and indication and publicity thereof.
[This Article Added on Aug. 17, 2012]
법령 이단보기
Article 55-5 (Effective Period of Rating for Management of Information Protection)
The effective period of the rating for the management of information protection under Article 55-3 shall be one year.
[This Article Added on Aug. 17, 2012]
법령 이단보기
Article 56 (Countermeasures against Computer Security Incidents)
“Other countermeasures against computer security incidents prescribed by Presidential Decree” in Article 48-2 (1) 4 of the Act means the following measures: <Amended on Jan. 28, 2009; Dec. 8, 2020>
1. Requesting a major provider of information and telecommunications services or a business entity who operates and manages clustered information and telecommunications facilities for other persons to provide information and telecommunications services under Article 46 (1) of the Act to cut off access channels (limited to access channels that have been used, or are likely to be used, for spreading computer security incidents);
2. Requesting a software business entity, defined under subparagraph 4 of Article 2 of the Software Promotion Act, who produced or distributed the software involved in a computer security incident, to produce and distribute a program by which the vulnerability in security of the software is cured and corrected (hereinafter referred to as “program for curing the vulnerability in security”) or requesting the provider of information and communications services to release the program for curing the vulnerability in security through information and communications networks;
3. Spreading forecasts and warnings of computer security incidents under Article 48-2 (1) 2 of the Act to mass media and providers of information and communications services;
4. Providing information about computer security incidents to the heads of related agencies, if necessary for the security of national information and communications networks.
법령 이단보기
Article 57 (Persons Providing Information about Computer Security Incidents)
“Persons prescribed by Presidential Decree from among those who operate an information and communications network” in Article 48-2 (2) 3 of the Act means any of the following persons among those who operate an information and communications network: <Amended on Mar. 28, 2008; Jan. 28, 2009; Oct. 1, 2010; Aug. 29, 2011; Mar. 23, 2013; Jul. 26, 2017>
1. An institution subject to a protection plan and protection guidelines on critical information and communications infrastructure, formulated and established by the Minister of Science and ICT pursuant to Articles 6 and 10 of the Act on the Protection of Information and Communications Infrastructure;
2. A person who observes the current status of operation of information and communications networks by providers of information and communications services and provides information on computer security incidents;
3. A person specified and publicly notified by the Minister of Science and ICT among private business entities who operate information and communications networks independently with Internet protocol addresses allocated by the Korea Internet and Security Agency under subparagraph 1 (a) of Article 2 of the Internet Address Resources Act;
4. A producer of antivirus software against computer viruses among persons who engage in the information protection industry.
법령 이단보기
Article 58 (Provision of Information on Computer Security Incidents)
A person who provides information on computer security incidents under Article 48-2 (2) of the Act shall comply with the following subparagraphs in providing information on computer security incidents: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. A method which a person applies to providing such information shall conform to a method determined by the Minister of Science and ICT, taking into consideration characteristics of information and communications networks, trends in computer security incidents, etc.;
2. The person shall take measures to prevent the destruction, obliteration, and alteration of information on computer security incidents;
3. The person shall adopt encryption techniques determined by the Minister of Science and ICT;
4. The person shall comply with other methods and procedures determined and publicly notified by the Minister of Science and ICT.
법령 이단보기
Article 59 (Organization of Private-Public Joint Investigation Team)
(1) The Minister of Science and ICT shall organize an investigation team with the following persons when he or she organizes a private-public joint investigation team pursuant to Article 48-4 (2) (hereinafter referred to as “investigation team”): <Amended on Oct. 1, 2010; Mar. 23, 2013; Jul. 26, 2017>
1. Public officials in charge of investigation of computer security incidents;
2. Persons who have expertise and experience in investigating computer security incidents;
3. Employees of the Korea Internet and Security Agency;
4. Other persons deemed necessary for the analysis of causes of computer security incidents.
(2) The organization of an investigation team under paragraph (1) may be adjusted according to the scale and type of each computer security incident.
법령 이단보기
Article 60 (Entry into Places of Business by Investigation Team)
(1) When an investigation team enters a place of business of a person involved under Article 48-4 (4) of the Act, the team members shall present identification badges indicating their authority to a person involved.
(2) The identification badges under paragraph (1) are as prescribed in Appendix 5.
법령 이단보기
Article 60-2 (Institutions Specialized in Countermeasures against Computer Security Incidents Related to Equipment Connected to Information and Communications Networks)
"Specialized institutions prescribed by Presidential Decree" in the provisions, with the exception of the subparagraphs, of Article 48-5 (4) of the Act means the following institutions:
1. The Korea Internet and Security Agency;
2. An institution determined through consultation between the Minister of Science and ICT and the heads of relevant central administrative agencies, which has expertise in dealing with computer security incidents related to equipment connected to information and communications networks, etc.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-3 (Procedures for Information Security Certification)
(1) A person who intends to obtain information security certification under Article 48-6 (1) of the Act (hereinafter referred to as "information security certification") shall submit an application for information security certification prescribed by Ministerial Decree of Science and ICT to the Minister of Science and ICT along with the following documents and shall produce equipment connected to information and communications networks, etc., subject to information security certification:
1. Documents proving that the certification standards under Article 48-6 (2) of the Act (hereinafter referred to as "information security certification standard") have been satisfied;
2. A user manual of equipment connected to information and communications networks, etc. subject to information security certification;
3. Other documents prescribed by Ministerial Decree of Science and ICT as necessary for information security certification.
(2) Upon receipt of an application for information security certification pursuant to paragraph (1), the Minister of Science and ICT shall request a testing agency for certification designated pursuant to Article 48-6 (4) of the Act (hereinafter referred to as "testing agency for certification") to conduct a test to confirm compliance with the certification standards under paragraph (2) of that Article (hereinafter referred to as "information security certification test").
(3) Where necessary for conducting an information security certification test, a testing agency for certification may conduct a test on the site where the relevant equipment connected to information and communications networks, etc. are installed.
(4) A testing agency for certification shall submit a report on the results of information security certification tests to the Minister of Science and ICT.
(5) The Minister of Science and ICT shall examine a report on the results of information security certification tests submitted pursuant to paragraph (4); and where the equipment connected to information and communications networks, etc. meet the information security certification standards, he or she shall issue an information security certification prescribed by Ministerial Decree of Science and ICT to a person who applies for information security certification pursuant to paragraph (1), and shall publicly announce such fact on the Ministry's website.
(6) The Minister of Science and ICT who has revoked information security certification pursuant to Article 48-6 (3) of the Act shall notify the relevant person of such fact and publicly announce it on the Ministry's website.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-4 (Effective Period of Information Security Certification)
(1) The effective period of information security certification shall be three years and may be extended only once by up to two years.
(2) A person who intends to extend the effective period of information security certification pursuant to paragraph (1) shall file an application for an extension of the effective period of information security certification with the Minister of Science and ICT no later than six months before the expiration of the effective period, as prescribed by Ministerial Decree of Science and ICT.
(3) Upon receipt of an application for extension of the effective period under paragraph (2), the Minister of Science and ICT may extend the effective period only where the sameness of the characteristics and configuration is recognized for the equipment connected to information and communications networks, etc. for which information security certification has been granted.
(4) The Minister of Science and ICT who extends the effective period under paragraph (3) shall issue information security certification reflecting the extended effective period as prescribed by Ministerial Decree of Science and ICT to the applicant for extension of the effective period, and shall publicly announce such fact on the Ministry's website.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-5 (Fees for Information Security Certification)
(1) A person who intends to apply for information security certification shall pay a fee.
(2) The criteria for calculating fees under paragraph (1) shall be determined and publicly notified by the Minister of Science and ICT.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-6 (Follow-Up Management of Information Security Certification)
(1) Where equipment connected to information and communications networks, etc. for which information security certification has been granted fail to meet the standards for information security certification due to discovery of vulnerabilities, the Minister of Science and ICT may request a person who has obtained the relevant information security certification to fix such vulnerabilities for a specified period.
(2) Details necessary for a request to fix vulnerabilities under paragraph (1) shall be determined and publicly notified by the Minister of Science and ICT.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-7 (Standards for Designating Testing Agencies for Certification)
(1) "Institution satisfying the designation standards prescribed by Presidential Decree" in Article 48-6 (4) of the Act means an institution meeting all of the following standards:
1. It shall be a corporation engaged in the affairs related to information security certification tests;
2. It shall have human resources (including two full-time workers) with technical capabilities, who are in charge of the affairs related to information security certification tests, and an organization dedicated to such affairs;
3. It shall have a test environment, such as facilities and laboratory spaces, to perform the affairs related to information security certification tests;
4. It shall have the operational ability to perform the affairs related to information security certification tests.
(2) A person seeking designation as a testing agency for certification shall file with the Minister of Science and ICT an application for such designation accompanied by documents evidencing that he or she meets the designation standards provided in paragraph (1).
(3) Upon receipt of an application under paragraph (2), the Minister of Science and ICT may designate a testing agency for certification after examining whether it satisfies the designation standards under paragraph (1).
(4) Upon designating a testing agency for certification under paragraph (3), the Minister of Science and ICT shall issue a certificate of designation prescribed by Ministerial Decree of Science and ICT to the relevant applicant, and shall publicly announce such fact in the Official Gazette and on the Ministry's website.
(5) The effective period of designation under paragraph (3) shall be determined by the Minister of Science and ICT for up to three years; and where it is intended to continue to conduct the affairs of a testing agency for certification after the effective period expires, an application for re-designation shall be filed from six months before the expiration date of the effective period until the expiration date of the effective period.
(6) The designation shall be deemed valid until the applicant is notified of the results of the examination of the application for re-designation under paragraph (5).
(7) Details regarding designation standards, designation procedures, re-designation, etc. of testing agencies for certification under paragraphs (1) through (6) shall be determined and publicly notified by the Minister of Science and ICT.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-8 (Follow-Up Management of Testing Agencies for Certification and Revocation of Designation)
(1) A testing agency for certification shall enter the results of certification tests for the preceding year in a report prescribed by Ministerial Decree of Science and ICT and submit it to the Minister of Science and ICT by January 31 of each year.
(2) The Minister of Science and ICT may request a testing agency for certification to submit data or visit the site to ascertain whether the designation standards under Article 48-6 (4) of the Act are met or whether the agency gives rise to grounds for revocation of designation under the subparagraphs of paragraph (5) of that Article.
(3) Upon revoking a designation as a testing agency for certification under Article 48-6 (5) of the Act, the Minister of Science and ICT shall notify the relevant institution of the revocation and publicly announce such revocation in the Official Gazette and on the Ministry’s website.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 60-9 (Entrustment of Information Security Certification Affairs)
Pursuant to Article 48-6 (6) of the Act, the Minister of Science and ICT shall entrust the following affairs to the Korea Internet and Security Agency:
1. Receiving applications for information security certification, requesting the implementation of information security certification tests, receiving reports on the results of information security certification tests, issuing information security certificates, and publicly announcing information security certification and revocation thereof, under Articles 60-3 (1), (2), and (4) through (6);
2. Receiving applications for extension of the effective period of information security certification, issuing an information security certificate, and publicly announcing information security certification pursuant to Article 60-4 (2) and (4);
3. Reviewing the fix of vulnerabilities of information security certification and supporting the delivery of requests to fix vulnerabilities under Article 60-6.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 61 (Guidelines for Transmission of Advertising Information for Profit)
(1) “Period prescribed by Presidential Decree” in Article 50 (1) 1 of the Act means six months from the date the trade of the relevant goods, etc. is concluded. <Amended on Nov. 28, 2014>
(2) “Media prescribed by Presidential Decree” in the proviso of Article 50 (3) of the Act means electronic mail. <Added on Nov. 28, 2014>
(3) Matters that a person who transmits advertising information for profit, using an electronic transmission medium pursuant to Article 50 (4) of the Act shall clearly state in the relevant information, and methods therefor shall be as specified in Appendix 6. <Amended on Nov. 28, 2014>
법령 이단보기
Article 62 (Provision of Free Telephone Services for Refusal of Reception or Withdrawal of Consent to Reception)
A person who transmits advertising information for profit, using an electronic transmission medium shall clearly state information about free telephone services, etc. for the refusal of reception or for the withdrawal of consent to reception, as prescribed in Appendix 6, and shall provide such services to addressees in accordance with Article 50 (6) of the Act. <Amended on Mar. 29, 2011; Nov. 28, 2014>
법령 이단보기
Article 62-2 (Notification of Results of Handling of Consent to Receive Messages)
A person who intends to transmit advertising information for profit, using an electronic transmission medium pursuant to Article 50 (7) of the Act shall notify an addressee of the following matters within 14 days from the date the relevant addressee expresses his or her consent to receipt of messages, refusal to receive messages or withdrawal of his or her consent to receive messages:
1. Name of a sender;
2. Fact that the addressee has consented to receive messages, refused to receive messages, or withdrawn his or her consent to receive messages, and the date he or she expresses the relevant intent;
3. Results of the handling thereof.
[This Article Added on Nov. 28, 2014]
법령 이단보기
Article 62-3 (Verification of Addressees' Consents to Receive Messages)
(1) A person who has obtained prior consent from an addressee pursuant to Article 50 (1) or (3) of the Act shall verify whether the relevant addressee gives consent to receive messages every two years from the date he or she obtains consent to receive messages from the addressee (referring to the day before every second year from the date he or she obtains consent to receive messages) pursuant to paragraph (8) of the aforesaid Article.
(2) A person who intends to verify whether an addressee gives his or her consent to receive messages pursuant to paragraph (1) shall advise the addressee of the following matters:
1. Name of a sender;
2. Fact that the addressee gives consent to receive messages, and the date he or she gives consent to receive messages;
3. Methods for expressing his or her intent to maintain or withdraw his or her consent to receive messages.
[This Article Added on Nov. 28, 2014]
법령 이단보기
Article 63 (Devices for Restricting Installation of Advertising Programs for Profits)
“Information processing device prescribed by Presidential Decree” in the former part of Article 50-5 of the Act means an information processing device with which information can be transmitted and received by connecting it to an information and communications network, such as mobile Internet and mobile telephones. <Amended on Aug. 29, 2011>
법령 이단보기
Article 64 (Subsidization for Development of Software Designed to Cut Off Transmission of Advertising Information for Profits)
(1) Pursuant to Article 50-6 of the Act, the Korea Communications Commission may fully or partially subsidize a project of a public institution, corporation, or organization that develops and distributes a piece of software or a computer program for conveniently blocking or reporting advertising information transmitted for profits in violation of Article 50 of the Act (hereinafter referred to as “software for blocking or reporting advertisements”), within the budget.
(2) The Korea Communications Commission may recommend providers of information and communications services and users to use the software for blocking or reporting advertisements developed in accordance with paragraph (1). <Amended on Jan. 28, 2009; Aug. 4, 2020>
법령 이단보기
Article 65 (Operation of the Korea Internet and Security Agency)
(1) The Minister of Science and ICT, the Minister of the Interior and Safety, the Korea Communications Commission, or the Personal Information Protection Commission may request the head of a related agency to dispatch public officials related to the affairs of the Korea Internet and Security Agency under the subparagraphs of Article 52 (3) of the Act. <Amended on Oct. 1, 2010; Mar. 23, 2013; Nov. 19, 2014; Jul. 26, 2017; Aug. 4, 2020>
(2) When the head of a related agency who dispatched a public official under paragraph (1) needs to have the public official returned during the period of dispatch service, he or she shall consult with the head of the agency that requested for such dispatch.
(3) The head of the Korea Internet and Security Agency may authorize a research institute related to information and communications to conduct part of the business affairs specified in Article 52 (3) 4 of the Act, with approval therefor from the Minister of Science and ICT, the Minister of the Interior and Safety or the Korea Communications Commission. <Amended on Oct. 1, 2010; Mar. 23, 2013; Nov. 28, 2014; Jul. 26, 2017>
(4) If a business affair that the head of the Korea Internet and Security Agency conducts in accordance with Article 52 (3) of the Act is related to the protection of a public institution’s information, he or she shall obtain approval therefor from the head of the related institution. <Amended on Oct. 1, 2010>
(5) The Korea Internet and Security Agency shall perform the following affairs to promote programs for transmitting advertising information under Article 52 (3) 10 and 21 of the Act: <Added on Aug. 4, 2020>
1. Settlement of grievances relating to the transmission of advertising information and counseling thereon;
2. Provision of technical advice under Article 64 (10) of the Act related to the transmission of advertising information and other necessary assistance;
3. Research on measures to prevent illegal transmission of advertising information;
4. Education and publicity for the prevention of illegal transmission of advertising information;
5. Affairs related to the duties under subparagraphs 1 through 4.
(6) If deemed necessary for requiring providers of information and communications services to submit relevant articles, documents, etc. or for efficiently conducting inspections under Article 64 (1) or (3) of the Act related to the transmission of advertising information, the Korea Communications Commission may dispatch its public officials to the Korea Internet and Security Agency pursuant to Article 32-4 of the State Public Officials Act. <Added on Aug. 4, 2020>
[Title Amended on Oct. 1, 2010]
법령 이단보기
Article 66 Deleted. <Aug. 4, 2020>
CHAPTER VI-2 TELECOMMUNICATIONS BILLING SERVICES
법령 이단보기
Article 66-2 (Requirements for Registration)
(1) A person who intends to be registered as a provider of telecommunications billing services under Article 53 of the Act shall meet all the following requirements: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. The ratio of the total liabilities to the equity capital, total contributions, or endowment shall not exceed a ratio determined and publicly notified by the Minister of Science and ICT, which shall not exceed 200/100. If the majority stockholder is a company that belongs to a conglomerate, defined under subparagraph 2 of Article 2 of the Monopoly Regulation and Fair Trade Act, (excluding conglomerates defined under Article 17 (1) 1 and 2 of the Enforcement Decree of the aforesaid Act) in such cases, the calculation of such ratio shall be based on the conglomerate, but companies that engage in financial business or insurance business, from among companies that belong to the conglomerate, shall be excluded from the calculation;
2. The person shall be fully equipped with the following human resources and physical facilities with which the person can conduct the business:
(a) At least five executive officers and employees who have work experience of at least two years in operating electronic computer systems;
(b) Electronic computer systems and various computer programs necessary for smoothly providing telecommunications billing services;
(c) An information protection system under Article 57 (2) of the Act;
3. The equity capital, total contributions, or endowment shall be at least an amount specified in paragraph (2).
(2) “Amount prescribed by Presidential Decree” in Article 53 (2) of the Act means one billion won.
[This Article Added on Mar. 28, 2008]
법령 이단보기
Article 66-3 (Procedures for Registration)
(1) A person who intends to be registered as a provider of telecommunications billing services under Article 53 of the Act shall file an application for registration, describing the following matters, with the Minister of Science and ICT: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. Trade name and the principal place of business;
2. The representative’s name;
3. Equity capital, total contributions, or endowment;
4. The names or titles of contributors (excluding small contributors specified and publicly notified by the Minister of Science and ICT) and their shares.
(2) An application for registration under paragraph (1) shall be accompanied by the following documents:
1. Articles of incorporation;
2. Documents proving that an applicant meets the requirements for registration under Article 66-2;
3. A business plan for three years after the commencement of business (including estimated financial statements and a statement of estimated revenues and expenditures);
4. A plan for the protection of users of telecommunications billing services (including matters under Articles 66-7 through 66-9).
(3) Upon receipt of an application for registration under paragraph (1), the Minister of Science and ICT shall verify the relevant corporate registration by sharing administrative information under Article 36 (1) of the Electronic Government Act. <Amended on May 4, 2010; Nov. 2, 2010; Mar. 23, 2013; Jul. 26, 2017>
(4) If the Minister of Science and ICT finds any defect in a document submitted pursuant to paragraph (1) or (2), he or she may request the applicant to supplement and submit the document within 10 days from the date when such document is submitted. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(5) When the Minister of Science and ICT registers a provider of telecommunications billing services, he or she shall publish the details of the registration through in the Official Gazette and shall inform the general public thereof through the Internet, etc. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Mar. 28, 2008]
법령 이단보기
Article 66-4 (Grounds for Disqualification from Registration)
“Investor prescribed by Presidential Decree” in subparagraph 1 of Article 54 of the Act means any of the following persons: <Amended on Jul. 29, 2008; Sep. 5, 2017>
1. The principal who holds the largest number of outstanding voting stocks of, or shares in contributions to, the relevant corporation (hereafter referred to as “stocks or the like” in this Article), when the stocks held by the principal and those held by persons related to the principal, as defined under any subparagraph of Article 3 (1) of the Enforcement Decree of the Act on Corporate Governance of Financial Companies, on their own accounts respectively in whosever name are aggregated;
2. A person who holds at least 10/100 of stocks or the like of the relevant corporation on his or her account in whosever name or a stockholder who exercises the de facto control over important matters relating to the management of the corporation through appointment and dismissal of executive officers or by other means, who is a related person defined under any subparagraph of Article 3 (1) of the Enforcement Decree of the Act on Corporate Governance of Financial Companies.
[This Article Added on Mar. 28, 2008]
법령 이단보기
Article 66-5 (Administrative Dispositions)
(1) Deleted. <Dec. 22, 2015>
(2) When the Minister of Science and ICT intends to revoke the registration of a provider of telecommunications billing services under Article 55 of the Act, he or she shall hold a hearing. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) When the Minister of Science and ICT revokes the registration of a provider of telecommunications billing services under Article 55 of the Act, he or she shall publish the details thereof in the Official Gazette and shall notify the general public thereof through the Internet or by other means. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Mar. 28, 2008]
법령 이단보기
Article 66-6 (Measures Necessary for Securing Stability and Reliability of Telecommunications Billing Services)
Administrative and technical measures that a provider of telecommunications billing services shall take in accordance with Article 57 (2) of the Act in order to secure the stability and reliability of transactions through telecommunications billing services are as prescribed in Appendix 7.
[This Article Added on Mar. 28, 2008]
법령 이단보기
Article 66-7 (Period for Retention of Transaction Records and Methods for Changing Contractual Terms)
(1) Pursuant to Article 58 (4) and (7) of the Act, a provider of telecommunications billing services shall preserve records of the following matters for one year from the date on which each transaction is conducted: Provided, That the records of a transaction, the amount of which exceeds 10,000 won, shall be preserved for five years: <Amended on Aug. 29, 2011; Mar. 23, 2013; Nov. 28, 2014; Jul. 26, 2017; Dec. 11, 2018>
1. The type of a transaction conducted through telecommunications billing services;
2. The amount of a transaction;
3. The other party to a transaction of purchase or use through telecommunications billing services (referring to a person who sells goods or provides services in return for a price therefor through telecommunications billing services; hereinafter referred to as the “other party to a transaction”);
4. The date and time of a transaction;
5. The subscriber number of telecommunications services for which charges are billed and collected;
6. Matters regarding access to telecommunications services in connection with the relevant transaction;
7. Matters regarding an application for a transaction and amendment to terms and conditions;
8. Matters regarding approval for a transaction;
9. Other matters determined and publicly notified by the Minister of Science and ICT.
(2) Transaction records under paragraph (1) shall be preserved in paper, microfilms, discs, magnetic tapes, or other electronic information processing systems: Provided, That where such records are preserved in discs, magnetic tapes, or other electronic information processing systems, the requirements under Article 5 (1) of the Framework Act on Electronic Documents and Transactions shall be fully met. <Amended on Aug. 31, 2012>
(3) When a provider of telecommunications billing services (limited to a person who provides services under Article (2) (1) 10 (a)) changes contractual terms pursuant to Article 58 (6) of the Act, he or she shall notify users of telecommunications billing services by any means of e-mail, writing, facsimile, telephone or other means similar thereto. <Added on Nov. 28, 2014; Jan. 5, 2021>
(4) A user of telecommunications billing services may raise an objection to the changed contractual terms from the date he or she receives notification under paragraph (3) until the business day before the effective date of the changed contractual terms. <Added on Nov. 28, 2014>
[This Article Added on Mar. 28, 2008]
[Title Amended on Nov. 28, 2014]
[Moved from Article 66-8 <Dec. 11, 2018>]
법령 이단보기
Article 66-8 (Content of and Procedures for Requesting Information on Purchasers)
(1) Where a user of telecommunications billing services requests the other party to a transaction pursuant to the former part of Article 58-2 (1) of the Act for information about the name and date of birth of a person who purchased or used goods or service (hereinafter referred to as "purchaser information"), he or she shall submit a written request (including an electronic document) for purchaser information, stating the following information:
1. Personal data of the user of telecommunications billing services: Name, date of birth, and contact information (referring to a telephone number, electronic mail address, etc.);
2. Requested details of payment: The telephone number used for payment and the date, time, and amount of payment;
3. The statement that purchaser information needs to be written separately for each type of goods or services.
(2) Where any institution or organization authorized to mediate in and resolve disputes under Article 59 (2) of the Act requests for purchaser information on behalf of a user of telecommunications billing services, it shall submit a document (including an electronic document) confirming that the user of telecommunications billing services has given consent to requesting purchaser information on behalf of the user, along with the written request under paragraph (1).
[This Article Added on Dec. 11, 2018]
[Previous Article 66-8 moved to Article 66-7 <Dec. 11, 2018>]
법령 이단보기
Article 66-9 (Procedures for Filing Objections and Redressing Violations of Rights)
(1) A provider of telecommunications billing services shall designate a manager and an officer in charge of the protection of users of telecommunications billing services for filing objections and redressing violations of rights under Article 59 (3) of the Act and shall notify the contact information of such manager and officer (referring to telephone numbers, facsimile numbers, e-mail addresses, etc.) to users of telecommunications billing services through the Internet and by other means. <Amended on Dec. 11, 2018; Jan. 5, 2021>
(2) A user of telecommunications billing services may file an objection with regard to telecommunications billing services to the relevant provider of telecommunications billing services in writing (or by an electronic document), telephone, facsimile, or other similar means. <Amended on Jan. 5, 2021>
(3) Upon receipt of an objection under paragraph (2), the provider of telecommunications billing services shall notify the user of the results of the relevant investigation or decision within two weeks from the date when such objection is filed.
[This Article Added on Mar. 28, 2008]
CHAPTER VI-3 INTERNATIONAL COOPERATION
법령 이단보기
Article 67 Deleted. <Aug. 4, 2020>
CHAPTER VII SUPPLEMENTARY PROVISIONS
법령 이단보기
Article 68 (Submission of Data)
“Ground prescribed by Presidential Decree to believe that it is necessary for the protection of users” in Article 64 (1) 3 of the Act means either of the following cases: <Amended on Mar. 28, 2008; Aug. 29, 2011>
1. Where it is necessary to prepare measures for the protection of youths under Article 41 (1) of the Act;
2. Where it is necessary to ascertain whether a person responsible for the protection of youths under Article 42-3 (3) of the Act performs the duty of protecting youths;
3. Deleted. <Aug. 17, 2012>
법령 이단보기
Article 68-2 (Methods for Publication of Order of Corrective Measures)
(1) When the Minister of Science and ICT or the Korea Communications Commission orders a provider of information and communications services under Article 64 (4) of the Act to make a public publication of the fact that the service provider is ordered to take corrective measures, the Minister of Science and ICT or the Korea Communications Commission shall prescribe the details, number of times, and media of publication, the size of pages, etc. in issuing such order, taking the following factors into consideration: <Amended on Sep. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Aug. 4, 2020>
1. Details and severity of relevant violations;
2. The duration and number of times of relevant violations.
(2) When the Minister of Science and ICT or the Korea Communications Commission orders a provider of information and communications services under paragraph (1) to make a publication of the fact that the service provider is ordered to take corrective measures, the Minister of Science and ICT or the Korea Communications Commission may consult on the text of the publication with the provider of information and communications services. <Amended on Sep. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Aug. 4, 2020>
[This Article Added on Jan. 28, 2009]
법령 이단보기
Article 69 (Disclosure of Order to Take Corrective Measures)
(1) In either of the following cases, the fact that a provider of information and communications services is ordered to take corrective measures under Article 64 of the Act may be disclosed. In such cases, the Minister of Science and ICT or the Korea Communications Commission shall notify the relevant provider of information and communications services of the disclosure in advance: <Amended on Mar. 28, 2008; Jan. 28, 2009; Sep. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Aug. 4, 2020>
1. Where a provider of information and communications services is ordered to take corrective measures for an act specified in any provision of Articles 71 through 74 of the Act;
2. Where a provider of information and communications services has been ordered to take corrective measures at least twice a year.
(2) The disclosure of an order to take corrective measures under paragraph (1) shall be made by publishing it on Internet websites or general daily newspapers circulated nationwide under the Act on the Promotion of Newspapers. <Amended on Jan. 27, 2010>
법령 이단보기
Article 69-2 (Scope of Persons Required to Submit Transparency Reports)
"Person who meets the standards prescribed by Presidential Decree" in the provisions, with the exception of the subparagraphs, of Article 64-5 (1) of the Act means a person obligated to designate a person responsible for preventing the circulation of illegally filmed materials, etc.
[This Article Added on Dec. 8, 2020]
법령 이단보기
Article 69-3 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 69-4 Deleted. <Aug. 4, 2020>
법령 이단보기
Article 70 (Delegation of Authority and Entrustment of Affairs)
(1) Pursuant to Article 65 (1) of the Act, Minister of Science and ICT shall delegate the authority to impose administrative fines under Article 76 of the Act upon the following persons and to collect administrative fines from them to the Director General of the Central Radio Management Service: <Amended on Mar. 28, 2008; Jul. 3, 2008; Oct. 1, 2010; Mar. 23, 2013; Nov. 28, 2014; Jul. 26, 2017; Sep. 28, 2018; Jun. 11, 2019; Jun. 25, 2019>
1. A business operator not possessing line equipment under Article 22 (2) 2 of the Enforcement Decree of the Telecommunications Business Act;
2. A person required to designate and a chief information security officer, and report thereon pursuant to the proviso of Article 45-3 (1) of the Act;
2-2. A person required to ensure that the chief information security officer may not concurrently hold another office, other than the one performing duties prescribed in Article 45-3 (4) of the Act pursuant to Article 45-3 (3) of the Act;
3. A person who has registered as a provider of telecommunications billing services pursuant to Article 53 (1) of the Act.
(2) The Minister of Science and ICT shall delegate the following authority to the President of the Central Radio Management Service pursuant to Article 65 (1) of the Act: <Added on Aug. 4, 2020; Dec. 7, 2021>
1. Reporting on the designation of a chief information security officer under Article 45-3 (1) of the Act;
2. Registration of providers of telecommunications billing services under Article 53 (1) of the Act;
3. Registration of changes in providers of telecommunications billing services, the transfer or acquisition of business, or the merger or inheritance of business, succession to business and reporting on the suspension, closure or dissolution of business under Article 53 (4) of the Act;
4. Revocation of the registration of a provider of telecommunications billing services under Article 55 (1) of the Act;
5. Reporting on contractual terms (including reporting on changes in contractual terms) on telecommunications billing services under Article 56 (1) of the Act;
6. Recommending a provider of telecommunications billing services to change contractual terms under Article 56 (2) of the Act;
7. Issuing orders to refuse, suspend, or restrict the provision of telecommunications billing services under Article 61 of the Act;
8. Requesting the submission of data and conducting inspections under Article 64 (1) and (3) of the Act to verify facts of violations of Articles 45-3 and 53 through 61 of the Act;
9. Issuing an order to a person who has obtained registration as a provider of telecommunications billing services pursuant to Article 53 (1) of the Act to take corrective measures under Article 64 (4) of the Act.
(3) The Korea Communications Commission shall delegate the following authority to the President of the Broadcasting and Communications Office under Article 65 (1) of the Act: <Added on Aug. 4, 2020>
1. Issuance of orders to take corrective measures and orders for making a public announcement under Article 64 (4) of the Act for a person who has violated Articles 50, 50-3 (1), 50-4, 50-5, 50-7 and 50-8 of the Act;
2. Imposition and collection of administrative fines under Article 76 of the Act on and from persons who violate Articles 50, 50-4 (4), 50-5, and 50-7 (1) and (2) of the Act.
(4) Pursuant to Article 65 (3) of the Act, the Korea Communications Commission shall entrust the following affairs to the head of the Korea Internet and Security Agency: <Amended on Mar. 28, 2008; Oct. 1, 2010; Sep. 29, 2011; Nov. 28, 2014; Aug. 4, 2020>
1. Affairs relating to a request for the submission of data and inspections under Article 64 (1) and (3) of the Act (limited to grievances and counseling items filed with the Korea Internet and Security Agency for the protection of users) to verify whether a person violates Article 22-2, 23-2, or 23-3 of the Act or falls under any subparagraph of Article 23-4 (1);
2. Duties relating to a request for the submission of data and inspections under Article 64 (1) through (3) of the Act for ascertaining a violation of any provision of Articles 50, 50-3 through 50-5, 50-7, and 50-8 of the Act (limited to grievances filed with the Korea Internet and Security Agency for settlement or counseling in connection with the transmission of advertising information).
(5) Deleted. <Aug. 4, 2020>
[Title Amended on Dec. 7, 2021]
법령 이단보기
Article 70-2 (Processing of Personally Identifiable Information)
Where it is inevitable to conduct affairs regarding request for submission, perusal, inspection of data, etc. under Article 64 (1) through (3) of the Act, the Minister of Science and ICT or the Korea Communications Commission (including a person entrusted with the authority of the Korea Communications Commission pursuant to Article 70) may process resident registration numbers or foreigner registration numbers under subparagraph 1 or 4 of Article 19 of the Enforcement Decree of the Personal Information Protection Act: <Amended on Jul. 26, 2017; Aug. 4, 2020>
1. Deleted; <Aug. 4, 2020>
2. Deleted. <Aug. 4, 2020>
[This Article Added on Aug. 6, 2014]
법령 이단보기
Article 71 (Re-Examination of Regulation)
(1) Deleted. <Mar. 3, 2020>
(2) The Minister of Science and ICT shall examine the appropriateness of the following matters every three years (referring to the period ending on the date preceding every third anniversary from the base date), counting from each base date specified in the following, and take measures, such as making improvements: <Amended on Dec. 30, 2016; Jul. 26, 2017; Dec. 11, 2018; Jun. 11, 2019; Dec. 8, 2020; Dec. 7, 2021>
1. Qualifications of chief information security officers under Article 36-7 (4) and (6) and the scope of providers of information and communications services under paragraph (5) of that Article: January 1, 2020;
2. Protective measures taken by business entities operating and managing clustered information and telecommunications facilities under Article 37: January 1, 2017;
3. Obligations to purchase an insurance policy and the minimum amount of insurance coverage under Article 38: January 1, 2017;
4. Scope of persons subject to the certification of information protection and management systems under Article 49: January 1, 2014;
5. Follow-up management and notification on the certification of information protection and management systems under Article 51: January 1, 2017;
6. Guidelines for designating a certification institution for information protection and management systems under Article 53: January 1, 2017;
7. Procedures for designating a certification institution for information protection and management systems under Article 53-2: January 1, 2017;
8. Requirements for the registration of a provider of telecommunications billing services under Article 66-2: January 1, 2014;
9. Period and methods for preservation of transaction records under Article 66-7: January 1, 2014.
(3) Deleted. <Dec. 30, 2016>
(4) The Korea Communications Commission shall review the suitability of the following matters every three years (referring to the period ending on the date preceding every third anniversary from the base date), counting from each base date specified in the following, and take measures, such as making improvements: <Amended on Nov. 28, 2014; Dec. 30, 2016; Jun. 11, 2019>
1. Deleted; <Aug. 4, 2020>
2. Deleted; <Aug. 4, 2020>
3. Deleted; <Aug. 4, 2020>
4. Scope of persons liable to designate a person responsible for the protection of youths under Article 25: January 1, 2015;
5. Deadline for designation of a person responsible for the protection of youths under Article 27: January 1, 2015.
[This Article Added on Dec. 30, 2013]
법령 이단보기
Article 72 Deleted. <Dec. 27, 2010>
법령 이단보기
Article 73 Deleted. <Aug. 18, 2009>
법령 이단보기
Article 74 (Guidelines for Imposition of Administrative Fines)
Guidelines for the imposition of administrative fines under the provisions of Article 76 (1) through (3) of the Act are as prescribed in Appendix 9.
[This Article Wholly Amended on Oct. 1, 2010]
ADDENDA <Presidential Decree No. 20668, Feb. 29, 2008>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Article 2 (Relationship to Other Statutes or Regulations)
A citation of the previous Enforcement Decree of the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Enforcement Rule of the Act on Promotion of Information and Communications Network Utilization and Information Protection, or a provision of either of them by any other statutes or regulations in force as at the time this Decree enters into force shall be deemed a citation of this Decree or the relevant provision of this Decree in lieu of the previous provision, if this Decree prescribes such relevant provision.
ADDENDUM <Presidential Decree No. 20756, Mar. 28, 2008>
This Decree shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 20896, Jul. 3, 2008>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Article 2 Omitted.
ADDENDA <Presidential Decree No. 20947, Jul. 29, 2008>
Article 1 (Enforcement Date)
This Decree shall enter into force on February 4, 2009. (Proviso Omitted.)
Articles 2 through 28 Omitted.
ADDENDA <Presidential Decree No. 21278, Jan. 28, 2009>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation: Provided, That the amended provisions of Article 15 (4) 2 and 4 shall enter into force one year after the date of its promulgation.
Article 2 (Preparation for Public Notice)
Notwithstanding the proviso to Article 1 of the Addenda, the public notice under the amended provisions of Article 15 (6) may include the public notice of guidelines under the amended provisions of Article 15 (4) 2 and 4.
ADDENDA <Presidential Decree No. 21692, Aug. 18, 2009>
Article 1 (Enforcement Date)
This Decree shall enter into force on August 23, 2009.
Articles 2 through 6 Omitted.
ADDENDA <Presidential Decree No. 21719, Sep. 9, 2009>
Article 1 (Enforcement Date)
This Decree shall enter into force on September 10, 2009.
Articles 2 and 3 Omitted.
ADDENDA <Presidential Decree No. 22003, Jan. 27, 2010>
Article 1 (Enforcement Date)
This Decree shall enter into force on February 1, 2010.
Articles 2 through 5 Omitted.
ADDENDA <Presidential Decree No. 22151, May 4, 2010>
Article 1 (Enforcement Date)
This Decree shall enter into force on May 5, 2010.
Articles 2 through 4 Omitted.
ADDENDA <Presidential Decree No. 22423, Oct. 1, 2010>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Article 2 (Transitional Measures concerning Guidelines for Administrative Dispositions)
(1) Notwithstanding the amended provisions of Appendixs 4 and 8, the previous provisions shall apply to the application of guidelines for administrative dispositions (including guidelines for the imposition of penalty surcharges) against violations committed before this Decree enters into force.
(2) Administrative dispositions imposed for violations committed before this Decree enters into force shall be included in the computation of the number of violations under the amended provisions of Appendix 4.
Article 3 (Transitional Measures concerning Administrative Fines)
(1) Notwithstanding the amended provisions of Appendix 9, the previous practices shall apply to the imposition of administrative fines for violations committed before this Decree enters into force.
(2) Administrative fines imposed for violations committed before this Decree enters into force shall be included in the computation of the number of violations under the amended provisions of Appendix 9.
ADDENDA <Presidential Decree No. 22424, Oct. 1, 2010>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Articles 2 through 10 Omitted.
ADDENDUM <Presidential Decree No. 22467, Nov. 2, 2010>
This Decree shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 22550, Dec. 27, 2010>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
ADDENDUM <Presidential Decree No. 22773, Mar. 29, 2011>
This Decree shall enter into force on the date of its promulgation.
ADDENDUM <Presidential Decree No. 23104, Aug. 29, 2011>
This Decree shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 23169, Sep. 29, 2011>
Article 1 (Enforcement Date)
This Decree shall enter into force on September 30, 2011. (Proviso Omitted.)
Articles 2 through 8 Omitted.
ADDENDUM <Presidential Decree No. 23876, Jun. 25, 2012>
This Decree shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 24047, Aug. 17, 2012>
Article 1 (Enforcement Date)
This Decree shall enter into force on August 18, 2012: Provided, That the amended provisions of Articles 15 (2), 36-2 through 36-6, 39 through 49, 51 through 53, 53-2 through 53-4, 54-2, 55-2 through 55-5, Appendix 2, Appendix 3, paragraph 2 (v) and (w) of Appendix 9, and Article 3 of Addenda shall enter into force on February 18, 2013.
Article 2 (Applicability to Counting of Unused Period)
Counting a period under the amended provisions of Article 16 (1) shall begin where information and communications services are not used on and after August 18, 2012.
Article 3 Omitted.
ADDENDA <Presidential Decree No. 24076, Aug. 31, 2012>
Article 1 (Enforcement Date)
This Decree shall enter into force on September 2, 2012. (Proviso Omitted.)
Articles 2 through 4 Omitted.
ADDENDA <Presidential Decree No. 24102, Sep. 14, 2012>
Article 1 (Enforcement Date)
This Decree shall enter into force on September 16, 2012. (Proviso Omitted.)
Articles 2 through 4 Omitted.
ADDENDA <Presidential Decree No. 24445, Mar. 23, 2013>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Articles 2 through 4 Omitted.
ADDENDUM <Presidential Decree No. 25050, Dec. 30, 2013>
This Decree shall enter into force on January 1, 2014. (Proviso Omitted.)
ADDENDUM <Presidential Decree No. 25532, Aug. 6, 2014>
This Decree shall enter into force on August 7, 2014.
ADDENDA <Presidential Decree No. 25751, Nov. 19, 2014>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
ADDENDA <Presidential Decree No. 25789, Nov. 28, 2014>
Article 1 (Enforcement Date)
This Decree shall enter into force on November 29, 2014: Provided, That the
amended provision of the main sentence of Article 16 (1) shall enter into force on August 18, 2015.
Article 2 (Applicability to Destruction of Personal Information)
The amended provision of the main sentence of Article 16 (1) shall also apply to personal information collected or provided before August 18, 2015.
Article 3 (Applicability to Notification of Results of Handling of Consent to Receive Messages)
The amended provisions of Article 62-2 shall begin to apply to cases where an addressee expresses his or her consent to receive messages, refuse to receive messages or withdraw his or her consent to receive messages after this Decree enters into force.
Article 4 (Special Cases concerning Reporting on Chief Information Security Officers)
Notwithstanding the amended provisions of Article 36-7, an information and telecommunications service provider falling under any of the subparagraphs of the amended provisions of Article 36-6 as at the time this Decree enters into force shall submit a report on the designation of a chief information security officer to the Minister of Science, ICT and Future Planning within 90 days from the date this Decree enters into force.
Article 5 (Special Cases on Guidelines for Transmitting Advertising Information for Purposes of Generating Profits)
Where the amended provision of Article 61 (1) applies to cases where the sale of goods, etc. is concluded before this Decree enters into force, the enforcement date of this Decree shall be deemed the date the sale of the relevant goods, etc. is concluded.
Article 6 (Special Cases concerning Verification as to Whether Addressee Has Consented to Receive Messages)
Where the amended provisions of Article 62-3 (1) applies to cases where a person has obtained consent to receive messages from an addressee before this Decree enters into force, he or she shall be deemed to have obtained the relevant consent to receive messages on the date this Decree enters into force.
Article 7 (Transitional Measures concerning Measures to Protect Personal Information)
Where an information and telecommunications service provider has taken security measures under the previous provisions of Article 15 (4) 1 and 2 before this Decree enters into force, the previous provisions shall apply, notwithstanding the amended provisions of Article 15 (4) 1 and 2.
Article 8 (Transitional Measures concerning Guidelines for Calculating Penalty Surcharges)
When a penalty surcharge is imposed on any offense committed before this
Decree enters into force, notwithstanding the amended provisions of attached
Table 8, the previous provisions thereof shall apply.
Article 9 (Transitional Measures concerning Administrative Fines)
(1) When guidelines for imposing administrative fines apply to offenses committed before this Decree enters into force, notwithstanding the amended provisions of Appendix 9, the previous provisions thereof shall apply.
(2) A disposition of the imposition of an administrative fine due to an offense committed before this Act enters into force shall be included in the calculation of the number of times of offenses under the amended provisions of Appendix 9.
ADDENDA <Presidential Decree No. 26757, Dec. 22, 2015>
Article 1 (Enforcement Date)
This Decree shall enter into force on December 23, 2015.
Article 2 (Transitional Measures concerning Administrative Fines)
Administrative fines, imposed pursuant to the previous provisions of subparagraph 2 (n) of Appendix 9, for violations committed before this Decree enters into force, shall not be included in the count of violations under the amended provisions of subparagraph 2 (f) of Appendix 9.
ADDENDUM <Presidential Decree No. 27188, May 31, 2016>
This Decree shall enter into force on June 2, 2016: Provided, That the amended provisions of Article 16 shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 27510, Sep. 22, 2016>
Article 1 (Enforcement Date)
This Decree shall enter into force on September 23, 2016: Provided, That the amended provisions of the proviso to Article 16 (2) shall enter into force one year after this Decree enters into force.
Article 2 (Applicability to Separate Storage and Management of Personal Information)
The amended provisions of the proviso to Article 16 (2) shall also apply to the personal information collected or provided before the enforcement date referred to in the proviso to Article 1 of Addenda.
ADDENDA <Presidential Decree No. 27751, Dec. 30, 2016>
Article 1 (Enforcement Date)
This Decree shall enter into force on January 1, 2017. (Proviso Omitted.)
Articles 2 through 12 Omitted.
ADDENDA <Presidential Decree No. 27951, Mar. 22, 2017>
Article 1 (Enforcement Date)
This Decree shall enter into force on March 23, 2017.
Article 2 (Applicability to Consent to Access Authority)
The amended provisions of Article 9-2 (1) through (3) shall begin to apply from the first case where a provider of information and communications services needs access authority to provide the relevant services through such software (including software which have been manufactured before this Decree enters into force, but are provided thereafter, and software which have been provided before this Decree enters into force, but are supplied thereafter) of mobile devices as are supplied after this Decree enters into force.
Article 3 (Applicability to Measures Necessary for Protecting Information on Users)
The amended provisions of Article 9-2 (4) shall begin to apply from the first case of providing the operating system or software of mobile devices after this Decree enters into force (including a case of having manufactured the operating system or software before this Decree enters, but providing it thereafter and a case of having provided the operating system or software before this Decree enters into force, but upgrading either thereafter) and the first case of manufacturing mobile devices after this Decree enters into force (excluding a case where mobile devices are being manufactured as at the time this Decree enters into force, but the operating system has been installed in them therebefore).
ADDENDA <Presidential Decree No. 28210, Jul. 26, 2017>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Articles 2 through 6 Omitted.
ADDENDA <Presidential Decree No. 28283, Sep. 5, 2017>
Article 1 (Enforcement Date)
This Decree shall enter into force three months after the date of its promulgation: Provided, That ... <omitted> ... Article 6 of the Addenda shall enter into force on the date of its promulgation.
Articles 2 through 6 Omitted.
ADDENDUM <Presidential Decree No. 28919, May 28, 2018>
This Decree shall enter into force on the date of its promulgation. (Proviso Omitted.)
ADDENDUM <Presidential Decree No. 29053, Jul. 17, 2018>
This Decree shall enter into force on the date of its promulgation.
ADDENDA <Presidential Decree No. 29192, Sep. 28, 2018>
Article 1 (Enforcement Date)
This Decree shall enter into force on the date of its promulgation.
Articles 2 and 3 Omitted.
ADDENDUM <Presidential Decree No. 29339, Dec. 11, 2018>
This Decree shall enter into force on December 13, 2018.
ADDENDUM <Presidential Decree No. 29633, Mar. 19, 2019>
This Decree shall enter into force on March 19, 2019.
ADDENDA <Presidential Decree No. 29852, Jun. 11, 2019>
Article 1 (Enforcement Date)
This Act shall enter into force on June 13, 2019: Provided, That the amended provisions of Articles 34 (1) shall enter into force on the date of its promulgation, and the amended provisions of Articles 16-2 and 17-2 shall enter into force on June 25, 2019.
Article 2 (Applicability to Qualifications of Chief Information Security Officers)
The amended provisions of Article 36-6 (2) and (4) shall begin to apply to chief information security officers designated and reported after this Act enters into force.
Article 3 (Special Cases concerning Methods and Procedures for Reporting on Chief Information Security Officers)
Where a provider of information and communications services becomes obligated to report his or her chief information security officer pursuant to Article 45-3 (1) of the Act as at the time this Decree enters into force, the deadline for reporting on the chief information security officer under the amended provisions of Article 36-7 shall be counted from the date this Decree enters into force.
ADDENDA <Presidential Decree No. 29886, Jun. 25, 2019>
Article 1 (Enforcement Date)
This Decree shall enter into force on June 25, 2019.
Article 2 Omitted.
ADDENDUM <Presidential Decree No. 30509, Mar. 3, 2020>
This Decree shall enter into force on the date of its promulgation.
ADDENDUM <Presidential Decree No. 30691, May 19, 2020>
This Decree shall enter into force on June 11, 2020.
ADDENDUM <Presidential Decree No. 30894, Aug. 4, 2020>
This Decree shall enter into force on August 5, 2020.
ADDENDA <Presidential Decree No. 31221, Dec. 8, 2020>
Article 1 (Enforcement Date)
This Decree shall enter into force on December 10, 2020.
Articles 2 through 9 Omitted.
ADDENDUM <Presidential Decree No. 31247, Dec. 8, 2020>
This Decree shall enter into force on December 10, 2020: Provided, That the amended provisions of Article 35-2 (4) shall enter into force on January 1, 2021.
ADDENDUM <Presidential Decree No. 31380, Jan. 5, 2021>
This Decree shall enter into force on the date of its promulgation. (Proviso Omitted.)
ADDENDA <Presidential Decree No. 31429, Feb. 2, 2021>
Article 1 (Enforcement Date)
This Decree shall enter into force on February 5, 2021.
Articles 2 and 3 Omitted.
ADDENDUM <Presidential Decree No. 32179, Dec. 7, 2021>
This Decree shall enter into force on December 9, 2021.