SOUTH KOREA Law and Practice Contributed by: Hwan Kyoung Ko, Tae Joo Kim, Jaeyoung Chang and Ji Hoon Kim, Lee & Ko
Disaster Recovery and Business Continuity Financial institutions and electronic financial business operators must establish and comply with business continuity measures designed to prevent service inter - ruption even in urgent circumstances such as system failures, disasters, strikes or terrorism. These meas - ures must include: • situation-specific response procedures; • disaster recovery plans leveraging backups or dis - aster recovery centres; and • the composition and operation of emergency response teams (Article 23 of the Regulations on the Supervision of Electronic Financial Transac - tions). Under the 2025 amendment, the scope of entities required to establish disaster recovery centres was expanded from banks, financial investment business operators, credit card companies and insurers to include certain credit-specialised financial companies and electronic financial business operators meeting specified thresholds (Article 23 (8) of the Regulations on the Supervision of Electronic Financial Transac - tions). Incident Management and Reporting Where an incident occurs in which electronic finan - cial infrastructure is disrupted or paralysed due to an electronic intrusion, a financial institution or electronic financial business operator must notify the FSC with - out delay (Article 21-5 of the EFTA). In addition, financial institutions and electronic finan - cial business operators must establish and operate procedures for incidents relating to the IT function and electronic finance, including incident type clas - sification, handling stages, remediation measures and methods for assessing impact and severity (Article 37-5 (1)(1) of the Regulations on the Supervision of Electronic Financial Transactions). Reportable inci - dents are specified in the Enforcement Rules of the Regulations on the Supervision of Electronic Financial Transactions. These include: • where a delay or interruption of electronic financial services lasts 30 minutes or more; or
• where a delay or interruption lasts ten minutes or more and the relevant electronic financial service has 10,000 or more subscribers (Article 7-4 (1)(i) of the Enforcement Rules). Reporting must be made to the FSS within 24 hours of becoming aware of the incident, through the elec - tronic financial accident response system (EFARS). 3.4 Operational Resilience Enforcement Inspection and Sanctioning Authority of the FSS The FSS has inspection authority over financial institutions and electronic financial business opera - tors pursuant to Article 39 of the EFTA. Based on inspection results, the FSC may impose sanctions for cybersecurity-related violations, including corrective orders, recommendations for the dismissal of officers, suspension of all or part of business operations and the imposition of administrative penalties (Articles 39 and 51 of the EFTA). Violations of the Regulations on the Supervision of Electronic Financial Transactions may result not only in institutional sanctions but also in personnel measures against relevant officers and employees. Recent Enforcement Trends and Outlook In recent years, financial authorities have strengthened information security inspections of financial institu - tions and have maintained an active enforcement posture, including imposing administrative penalties in the event of electronic financial incidents. Moreover, the FSC has indicated that, following the amendment to the Regulations on the Supervision of Electronic Financial Transactions (Phase I), it plans to pursue Phase II reforms through amendments to the EFTA to operationalise an administrative fine regime and strengthen accountability of the CEO, the board and business units, thereby establishing a “digital financial security” legal framework. Accordingly, enforcement of cybersecurity regulation in the financial sector is expected to become more robust going forward. 3.5 International Data Transfers Regulation of Cross-Border Transfers of Personal Information PIPA imposes separate legal requirements for cross- border transfers of personal information. “Cross- border transfer” includes not only the provision, or
313 CHAMBERS.COM
Powered by FlippingBook