Skip Navigation
Menu
Newsletters

Korea Media and Communications Commission Launches 2026 Inspection of Service Providers Using Connecting Information (“CI”)

2026.07.24

The Korea Media and Communications Commission (“KMCC”) is conducting its 2026 periodic inspection of service providers that use Connecting Information (“CI”) under the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. (the “Network Act”).
 
CI is a unique identifier used as a substitute for a resident registration number of Korea. It is generated by a designated identity verification agency when users complete an authentication process, such as mobile phone or i-PIN.
 
Regardless of industry or service classification, any business operating a website or mobile application that receives CI from an identity verification agency for user registration, account creation, or user verification is deemed an “entity using CI.”
 

1.

Inspection of Service Providers Using CI
 

Following the amendments to the Network Act establishing requirements relating to the generation, processing, and security of CI, the KMCC has been conducting inspections to assess whether service providers using CI comply with the applicable statutory requirements.
 
The current inspection is conducted pursuant to Article 23-6(3) of the Network Act, which authorizes the KMCC to inspect whether service providers using CI have implemented the security measures required for the safe processing of CI.
 
The inspection will initially be conducted through written responses to a questionnaire. Service providers subject to the inspection must submit their responses to the KMCC’s inspection questionnaire, together with supporting documents, by August 14, 2026. The KMCC may subsequently conduct an on-site inspection of service providers whose written submissions did not sufficiently demonstrate compliance or were otherwise insufficient.
 
Pursuant to Article 14 of the Enforcement Decree of the Network Act, the inspection in principle applies to service providers that use 1,000 or more CI records. Accordingly, if your company operates a website or mobile application and has received and processed 1,000 or more CI records from an identity verification agency for user registration or verification, it is advisable to confirm whether it has received an inspection notice from the KMCC.
 

2.

Key Security Obligations Applicable to Service Providers Using CI
 

Under the Network Act, a service provider using CI must implement technical and administrative measures to prevent the loss, theft, leakage, forgery, falsification, or damage of CI.
 
The principal security measures applicable to service providers using CI may include the following:
 

  • Designate a person responsible for overseeing CI security measures;

  • Establish and implement internal policies governing the handling and management of CI;

  • Restrict the scope of personnel permitted to access, review, or otherwise process CI on a need-to-know basis;

  • Provide regular security training to personnel handling CI;

  • Conduct internal reviews at least once a year to confirm that CI is processed securely and in accordance with internal policies;

  • Apply appropriate encryption when transmitting CI through information and communications networks;

  • Encrypt stored CI where required based on the volume of CI held or other applicable criteria;

  • Separately store and manage CI and resident registration numbers when resident registration numbers are also processed;

  • Conduct vulnerability assessments to prevent the leakage, theft, or other compromise of CI;

  • Establish and implement response plans for CI security breach incidents; and

  • Maintain records regarding the source, timing, purpose, and scope of CI collection, together with supporting documentation.
     

Failure to implement security measures required under the Network Act may result in an administrative fine of up to KRW 30 million pursuant to Article 76(1) of the Network Act.

Accordingly, before submitting written responses to the KMCC’s inspection questionnaire, the service provider should review whether each item in the inspection questionnaire has been implemented in practice along with adequate supporting documentation and remedy any identified deficiencies.

 

[Korean Version]

Share

Close

Professionals

CLose

Professionals

CLose