SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
Regulations on the Entrustment of Information Processing by Financial Companies Pursuant to the Regulations on the Entrustment of Information Processing by Financial Companies (an FSC Notification), when a financial institution executes an information processing entrustment contract, the agreement must explicitly incorporate the following clauses (Articles 4 and 5 of the Regulations): • strict data access controls; • the allocation of liability between the entrusting and entrusted entities regarding user damages resulting from IT accidents; • the entrusted company’s binding obligation to submit to supervision and inspection by regulatory authorities; and • the designated judicial jurisdiction for dispute resolution. Sub-entrustment (re-outsourcing) is legally permis - sible, provided it remains within the bounds of these compliance requirements. Crucially, the unique identification information of indi - vidual customers (eg, resident registration numbers, passport numbers) must be safeguarded through encryption or equivalent measures, and the cross- border transfer of such sensitive data is strictly pro - hibited (Article 5 (1)). Additionally, the specific safety measures implemented to protect the entrusted infor - mation must be transparently disclosed to the public via the company’s website. Regulations on Cloud Computing Usage When a financial company or electronic financial busi - ness intends to utilise cloud computing services, it must proactively evaluate the safety of the service and report its usage to the FSS pursuant to Article 14-2 of the Regulations on the Supervision of Electronic Financial Transactions. Safety evaluation of the cloud service provider (CSP) is conducted via the CSP Safety Evaluation Integrat - ed Support System operated by the FSI. The 2025 amendment to the Regulations on the Supervision of Electronic Financial Transactions streamlined this cloud usage reporting workflow, with specific pro - cedural details delegated to the Enforcement Rules
of the Regulations on the Supervision of Electronic Financial Transactions (Article 2-4 of the Enforcement Rules). For reference, if unique identification information or personal credit information is processed through a cloud computing service, regulatory restrictions man - date that the corresponding data processing systems must be physically localised within Korea. 3.3 Key Operational Resilience Obligations Governance Financial institutions and electronic financial busi - ness operators must designate a CISO and establish and implement an annual training plan to enhance employees’ information security capabilities (Article 8 (1) of the Regulations on the Supervision of Electronic Financial Transactions). Under the 2025 amendment, a new obligation was introduced under which the representative (eg, CEO) must evaluate the results of the prior year’s training plan implementation, and the CISO must reflect those results in the current year’s training plan (Article 8 (1)(4) of the Regulations on the Supervision of Electronic Financial Transactions). Financial institutions and electronic financial business operators must also establish and operate an Informa - tion Security Committee that deliberates and resolves key information security matters (Article 8-2 (1)). The CISO must report committee deliberations and reso - lutions to the representative and, further, must report directly to the board of directors on deliberations and resolutions that the CISO determines have a material impact on the safety and reliability of electronic finan - cial transactions (Article 8-2 (4) of the Regulations on the Supervision of Electronic Financial Transactions). Segregation of Duties To ensure robust internal controls within their IT departments, financial companies and electronic financial businesses must establish and operate strict standards for the segregation of duties (Article 8-3). Prior to the 2025 amendment, the tasks subject to segregation were enumerated in detail; following the amendment, the principle of segregation of duties is maintained, while the specific domains of segregation are left to each institution’s discretion.
312 CHAMBERS.COM
Powered by FlippingBook