이용약관 및 개인정보보호방침 / Terms of Use and Privacy Policy
IT Service Partner
EN
한국어 (KO)
繁體中文 (TW)
简体中文 (ZH)
日本語 (JA)
Español (ES)
Português (PT)
Login
Menu
Solutions
Portfolio
Partner Program
Managed Infra
Workspace
Insights
Solutions
Portfolio
Partner Program
Managed Infra
Workspace
Insights
This service is available to members only.
OK
Terms of Use
Chapter 1 General Provisions Article 1 (Purpose) The purpose of these Terms and Conditions is to stipulate the rights, obligations and responsibilities between the Company and users in relation to the use of digital content (hereinafter referred to as "Content") and various services provided online by the Company. Article 2 (Definition) The definitions of terms used in these Terms and Conditions are as follows. 1. "Company" refers to a person who engages in economic activities related to the "content" industry and provides content and related services. 2. "User" refers to members and non-members who access the "Company" site and use the "Content" and various services provided by the "Company" in accordance with these Terms and Conditions. 3. "Member" refers to a "user" who has entered into a service agreement with the "Company" and has been given a "User" ID, who continuously receives information from the "Company" and can continuously use the services provided by the "Company." 4. "Non-member" refers to a person who is not a "member" but uses the services provided by the "Company." 5. "Content" refers to data or information expressed in codes, letters, voices, sounds, images or videos used in information and communications networks pursuant to the provisions of Article 2, Paragraph 1, Item 1 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc., and is produced or processed in electronic form to increase the utility in preservation and use. 6. "ID" refers to a combination of letters or numbers determined by the "Member" and approved by the "Company" for the purpose of identifying the "Member" and using the service. 7. "PASSWORD" refers to a combination of letters or numbers determined by the "member" to confirm that the "member" matches the "ID" given to the "member" and to protect confidentiality. Article 3 (Provision of identity information, etc.) The "Company" posts the contents of these terms and conditions, company name, name of representative, address of business location (including address of place where consumer complaints can be handled), phone number, facsimile number, e-mail address, business registration number, mail-order business report number, personal information manager, etc. on the initial screen of the online service so that users can easily see them. However, the terms and conditions can be viewed by users through the connection screen. Article 4 (Posting of Terms and Conditions, etc.) ① The "Company" takes technical measures to ensure that "Members" can print these Terms and Conditions in their entirety and check the contents of these Terms and Conditions during the transaction process. ② The "Company" installs technical devices to enable "Users" to ask and respond to questions regarding the "Company" and the contents of these Terms and Conditions. ③ Before the "User" agrees to the Terms and Conditions, the "Company" seeks confirmation from the "User" by providing a separate connection screen or pop-up screen so that the User can easily understand important contents such as subscription withdrawal and refund conditions among the contents stipulated in the Terms and Conditions. Article 5 (Revision of Terms and Conditions, etc.) ① The "Company" may revise these Terms and Conditions to the extent that they do not violate relevant laws, such as the Online Digital Content Industry Development Act, the Act on Consumer Protection in Electronic Commerce, etc., and the Act on the Regulation of Terms and Conditions. ② When the "Company" revises the Terms and Conditions, it specifies the date of application and the reason for revision and announces them on the service initial screen along with the current Terms and Conditions from 7 days before the date of application for a considerable period of time after the date of application, and sends the revised Terms and Conditions to existing members via e-mail address. ③ When the "Company" revises the Terms and Conditions, it confirms whether the "User" agrees to the application of the revised Terms and Conditions after announcing the revised Terms and Conditions. If the "User" does not agree to the application of the revised terms and conditions, the "Company" or "User" may terminate the content use agreement. At this time, the "Company" will compensate for the damages suffered by the "User" due to termination of the contract. Article 6 (Interpretation of Terms and Conditions) Matters not specified in these Terms and Conditions and the interpretation of these Terms and Conditions shall be subject to the Online Digital Content Industry Development Act, the Act on Consumer Protection in Electronic Commerce, etc., the Act on the Regulation of Terms and Conditions, the Digital Content User Protection Guidelines established by the Minister of Culture, Sports and Tourism, and other related laws and regulations or commercial practices. Chapter 2 Membership Registration Article 7 (Membership Registration) ① Membership registration is concluded when the "User" agrees to the terms and conditions and applies for membership and the "Company" approves the application. ② The following information must be entered in the membership application form. Matters 1 to 3 are required, and other matters are optional. 1. Name and resident registration number of the "member" or personal identification number on the Internet 2. "ID" and "Password" 3. Email address 4. Type of "content" you want to use 5. Other matters deemed necessary by the "Company" ③ In principle, the "Company" approves the membership application for the above-mentioned "User". However, the "Company" may not approve applications that fall under any of the following items. 1. If the applicant has previously lost membership in accordance with these Terms and Conditions 2. If it is not your real name or someone else's name is used 3. If false information is provided or information provided by the company is not provided. 4. If approval is not possible due to reasons attributable to the user or the application is made in violation of all other stipulated matters. ④ The "Company" may withhold approval if there is no room for service-related facilities or if there are technical or business problems. ⑤ If the membership application is not approved or is postponed pursuant to paragraphs 3 and 4, the "Company" must notify the applicant. An exception is made in cases where the applicant cannot be notified due to reasons not attributable to the "Company." ⑥ The membership contract is established when the approval of the "Company" reaches the "User". Article 8 (Special rules regarding membership of minors) ① "Users" under the age of 14 must fully understand the purpose of collection and use of personal information and obtain consent from their parents or other legal representatives before applying for membership and providing their personal information. ② The company cancels or disallows membership for users under the age of 14 who have not gone through the confirmation process for consent from their parents or other legal representatives. ③ Legal representatives, such as parents, of "users" under the age of 14 may request to view, correct, or update the child's personal information or withdraw consent to membership, and in such cases, the "Company" must take necessary measures without delay. Article 9 (Change of member information) ① "Members" can view and modify their personal information at any time through the personal information management screen. ② If there are any changes to the information provided when applying for membership, the "Member" must make changes online or notify the "Company" of the changes by e-mail or other means. ③ The "Company" is not responsible for any disadvantages arising from failure to notify the "Company" of changes in Paragraph 2. Article 10 (Obligation to manage "Member's" "ID" and "Password") ① Responsibility for managing the "Member's" "ID" and "Password" lies with the "Member" and must not be allowed to be used by a third party. ② If a "member" becomes aware that their "ID" and "password" have been stolen or are being used by a third party, they must immediately notify the "Company" and follow the "Company's" instructions. ③ In the case of paragraph 2, the "Company" is not responsible for any disadvantages arising from the "Member" not notifying the fact to the "Company" or not following the instructions of the "Company" even if notified. Article 11 (Notice to "Members") ① When the "Company" notifies the "Member," it may do so to the e-mail address designated by the "Member." ② In the case of notification to all "members," the "Company" may replace the notice in Paragraph 1 by posting the notice on the "Company" bulletin board for more than 7 days. However, for matters that have a significant impact on the "Member's" transactions, notification is provided in accordance with Paragraph 1. Article 12 (Withdrawal of membership, loss of qualification, etc.) ① "Members" may request withdrawal from the "Company" at any time, and the "Company" will immediately process membership withdrawal. ② If a "member" falls under any of the following reasons, the "Company" may restrict or suspend membership. 1. If false information is registered when applying for membership 2. When the "Company" service fee or other debts borne by the member related to the "Company" service use are not paid on the due date. 3. In case of threatening the order of e-commerce, such as interfering with other people's use of the "Company" services or stealing information. 4. When using the "Company" to commit an act prohibited by the law or these Terms and Conditions or contrary to public order and morals. ③ After the "Company" restricts or suspends membership, if the same act is repeated more than twice or the reason is not corrected within 30 days, the "Company" may revoke membership. ④ If the "Company" revokes membership, membership registration will be canceled. In this case, the "member" will be notified of this and given an opportunity to explain at least 30 days before cancellation of membership registration. Chapter 3 Content Use Agreement Article 13 (Posting of "contents", etc.) ① The "Company" displays the following information on the initial screen of the "Content" or its packaging so that the "User" can easily understand it. 1. Name or title of "Content" 2. Date of production and display of "Content" 3. Name (if a corporation, the name of the corporation), address, and phone number of the "content" creator. 4. "Content" contents, method of use, usage fee and other terms of use ② The "Company" provides "Users" with information regarding devices available for each "Content" and the minimum technical specifications required for use during the contract conclusion process. Article 14 (Establishment of service agreement, etc.) ① "Users" apply for use through the following or similar procedures provided by the "Company." Before concluding a contract, the "Company" provides information regarding each item so that the "User" can accurately understand and transact without mistakes or mistakes. 1. Browse and select the "Content" list 2. Enter your name, address, phone number (or mobile phone number), e-mail address, etc. 3. Confirmation of the contents of the terms and conditions and the actions taken by the "Company" regarding "contents" for which cancellation of subscription is not possible. 4. Indication of agreement to these terms and conditions and confirmation or rejection of the matters in item 3 above (e.g., mouse click) 5. Confirmation of application for use of "content" or consent to confirmation by "Company" 6. Selection of payment method ② The "Company" may not approve or withhold approval if the "User"'s application for use falls under any of the following items. 1. If it is not your real name or someone else's name is used 2. If false information is provided or information provided by the "Company" is not provided. 3. When a minor wishes to use "content" that is prohibited under the Youth Protection Act. 4. If there is no room for service-related facilities or there are technical or business problems. ③ The contract is deemed to have been established when the "Company's" approval reaches the "User" in the form of a receipt confirmation notice under Article 16, Paragraph 1. ④ The "Company's" expression of intent includes confirmation of the "User's" application for use, availability of services, and information on correction/cancellation of the application for use. Article 15 (Special rules regarding use contracts for minors) If a minor user under the age of 20 wishes to use a paid service, the "Company" takes steps to notify the minor user or his/her legal representative before concluding the contract that the consent of his or her legal representative, such as a parent, may be canceled if the minor user or his/her legal representative does not obtain ratification after conclusion of the contract. Article 16 (Reception confirmation notification, change and cancellation of application for use) ① If a "User" submits an application for use, the "Company" will notify the "User" of receipt. ② If there is a discrepancy in the expression of intent, etc., the "User" who has received the receipt confirmation notice may request change or cancellation of the application for use immediately after receiving the receipt confirmation notice, and if there is a request from the "User" before service provision, the "Company" must process the request without delay. However, if the payment has already been made, the provisions of Article 27 regarding cancellation of subscription, etc. shall apply. Article 17 (Obligations of "Company") ① The "Company" must faithfully exercise the rights and fulfill the obligations stipulated by the law and these Terms and Conditions in good faith. ② The "Company" must have a security system to protect personal information (including credit information) so that "Users" can use "Content" safely, and shall disclose and comply with the personal information protection policy. ③ The "Company" takes measures to ensure that "Users" can check the content usage and payment details at any time. ④ If the "Company" deems that opinions or complaints raised by "users" in relation to the use of content are justified, it will process them without delay. Regarding opinions or complaints raised by users, the processing process and results are communicated through the bulletin board or e-mail. ⑤ The "Company" compensates for damages suffered by the "User" due to violation of obligations set forth in these Terms and Conditions. Article 18 (Obligations of "User") ① "Users" must not engage in the following acts. 1. Entering false information when applying or changing 2. Stealing other people's information 3. Changes to information posted on "Company" 4. Transmission or posting of information (computer programs, etc.) prohibited by the "Company" 5. Infringement of intellectual property rights, such as copyrights, of the "Company" and other third parties. 6. Actions that damage the reputation of the "Company" and other third parties or interfere with their work. 7. Disclosing or posting obscene or violent words, writings, images, sounds, or other information that is against public order and morals on the "Company" site. 8. Other illegal or unfair actions ② "Users" must comply with relevant laws and regulations, the provisions of these Terms and Conditions, instructions for use, notices announced in relation to "Contents," matters notified by the "Company," etc., and must not engage in any other actions that interfere with the business of the "Company." Article 19 (Payment Method) Payment for the use of "Contents" can be made by any of the following methods. However, the "Company" does not collect any additional fees for the "User's" payment method. 1. Various account transfers such as phone banking, internet banking, and email banking 2. Various card payments such as prepaid cards, debit cards, credit cards, etc. 3. Online bank transfer 4. Payment by electronic money 5. Payment based on points paid by the "Company," such as mileage 6. Payment by gift certificate entered into a contract with the "Company" or recognized by the "Company" 7. Payment using phone or mobile phone 8. Payment by other electronic payment methods, etc. Article 20 (Provision and suspension of content services) ① In principle, content services are provided 24 hours a day, 365 days a year. ② The "Company" may temporarily suspend the provision of content services in the event of maintenance inspection, replacement or breakdown of information and communication equipment such as computers, communication interruption, or significant operational reasons. In this case, the "Company" will notify the "User" in the manner specified in Article 11 [Notice to "Members"]. However, if there are unavoidable reasons why the "Company" cannot notify in advance, notification may be made after the fact. ③ The "Company" compensates for damages suffered by the "User" due to temporary suspension of the provision of content services without any reasonable cause. However, this does not apply if the "Company" proves that there was no intention or negligence. ④ The "Company" may conduct regular inspections when necessary for the provision of content services, and the regular inspection time is as announced on the service provision screen. ⑤ In the event that content services cannot be provided due to reasons such as conversion of business type, abandonment of business, or integration between companies, the "Company" will notify the "User" in the manner prescribed in Article 11 [Notice to "Members"] and compensate the "User" according to the conditions originally presented by the "Company." However, if the "Company" does not notify the compensation standards, etc., or if the notified compensation standards are not appropriate, the mileage or accumulated points, etc. of the "Users" will be paid to the "Users" in kind or in cash. Article 21 (Changes in Content Services) ① If there is a reasonable reason, the "Company" may change the content service it provides according to operational and technical needs. ② When the "Company" changes the content, method of use, or usage time of the content service, it posts the reason for the change, the content of the content service to be changed, the date of provision, etc. on the initial screen of the content for at least 7 days prior to the change. ③ In the case of Paragraph 2, if the changed content is significant or unfavorable to the "User", the "Company" will notify the "User" who receives the relevant content service in the manner prescribed in Article 11 [Notice to "Members"] and obtain consent. At this time, the "Company" provides the service before the change to the "User" who refuses consent. However, if it is impossible to provide such services, the contract may be terminated. ④ The "Company" shall change the service pursuant to Paragraph 1 and pursuant to Paragraph 3. Damage suffered by the "User" due to termination of the contract will be compensated. Article 22 (Provision of information and posting of advertisements) ① The "Company" may provide "Members" with notices that are necessary to perform the contract or operate the service, including security, outage, and payment information, through notices or email. ② Before sending commercial advertising information through email or another electronic channel, the "Company" obtains the "Member's" explicit prior consent as required by applicable law. Marketing consent is not required to register for or use the service. ③ Marketing information may include information about IT7 services, partner programs, benefits, and events. A "Member" may withdraw consent at any time through Account info or the unsubscribe method included in a marketing email, and the "Company" will apply the request without delay. ④ The "Company" may display advertisements on its website and content screens. Article 23 (Deletion of posts) ① If any material harmful to youth that violates the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. is posted on the bulletin board, the "Company" will delete it without delay. However, an exception is made for bulletin boards that can only be used by "users" who are 19 years of age or older. ② Any person whose legal interests have been infringed by information posted on bulletin boards operated by the "Company" may request the "Company" to delete the information or post a rebuttal. In this case, the "Company" will take necessary measures without delay and immediately notify the applicant. Article 24 (Attribution of copyright, etc.) ① Copyrights and other intellectual property rights for works created by the "Company" belong to the "Company." ② Among the services provided by the "Company," copyrights and other intellectual property rights for works provided under an affiliate agreement belong to the relevant provider. ③ "Users" must not use, or allow a third party to use, information obtained by using the services provided by the "Company" for commercial purposes by copying, transmitting, publishing, distributing, broadcasting or other methods without the prior consent of the "Company" or the provider, information whose intellectual property rights belong to the "Company" or the provider. ④ When the "Company" uses the copyrighted work of a "User" in accordance with the agreement, it obtains permission from the "User" in question. Article 25 (Personal Information Protection) ① The "Company" may collect the minimum information necessary for the "User" to use the content in addition to the application information in Article 7, Paragraph 2. For this purpose, the "User" must faithfully notify the truth regarding matters inquired by the "Company." ② When the "Company" collects "personal information" that can personally identify a "User," it obtains the consent of the "User." ③ The "Company" cannot use the information provided by the "User" in the application for use, etc. and the information collected pursuant to Paragraph 1 for purposes other than the purpose or provide it to a third party without the consent of the "User". In case of violation, the "Company" assumes all responsibility. However, exceptions are made in the following cases. 1. When information is provided in a form that does not identify a specific individual as necessary for statistical compilation, academic research, or market research 2. When necessary to settle fees for providing "content" 3. When identity verification is necessary to prevent theft 4. When there is an unavoidable reason necessary according to the provisions of the Terms and Conditions or the law. ④ In cases where the "Company" must obtain the consent of the "user" pursuant to paragraphs 2 and 3, the identity of the person responsible for managing "personal information" (affiliation, name, phone number and other contact information), the purpose of collection and use of information, matters related to the provision of information to third parties (recipient of information, purpose of provision and content of information to be provided), etc., Article 22 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. The matters stipulated in Paragraph 2 must be specified and notified. ⑤ "Users" may withdraw their consent under Paragraph 3 at any time. ⑥ "Users" may request to view and correct errors in their "personal information" held by the "Company" at any time, and the "Company" has the obligation to take necessary measures without delay. If the "User" requests correction of an error, the "Company" will not use the "Personal Information" until the error is corrected. ⑦ In order to protect personal information, the "Company" limits the number of administrators and minimizes the number, and is responsible for any damages suffered by the "User" due to loss, theft, leakage, alteration, etc. of the "User's" "Personal Information," including credit cards, bank accounts, etc. ⑧ The "Company" or anyone who has received "personal information" from it may use the "personal information" within the scope agreed upon by the "user," and when the purpose has been achieved, the "personal information" is destroyed without delay. ⑨ The "Company" strives to protect the "personal information" of "users" in accordance with relevant laws and regulations, such as the Act on Promotion of Information and Communications Network Utilization and Information Protection. The protection and use of "personal information" is subject to relevant laws and the "Company's" personal information protection policy. Chapter 4 Withdrawal of subscription, contract cancellation/termination, and restriction of use of content use agreement Article 26 (Withdrawal of subscription by "User" and cancellation/termination of contract) ① "Users" who have entered into a contract with the "Company" regarding the use of "Contents" may withdraw their subscription within 7 days from the date of receiving the confirmation of receipt. However, if the "Company" takes one of the following actions, the "User's" right to cancel the subscription may be restricted. 1. When the information regarding "content" that cannot be withdrawn from subscription is included in the information 2. When a trial product is provided 3. When temporary or partial use is provided. ② If any of the following reasons exist, the "User" may cancel or terminate the Content Use Agreement within 3 months from the date the "Content" was supplied or within 30 days from the date the fact was known or could have been known. 1. When the "content" agreed upon in the service agreement is not provided 2. If the "content" provided is different or significantly different from display, advertisement, etc. 3. When normal use is significantly impossible due to other defects in the "Content" ③ Withdrawal of subscription under Paragraph 1 and cancellation/termination of contract under Paragraph 2 become effective when the "User" expresses his/her intention to the "Company" by phone, e-mail or facsimile. ④ After receiving the "User"'s intention to withdraw subscription or cancel or terminate the contract pursuant to Paragraph 3, the "Company" will reply to the "User" without delay. ⑤ "Users" may request complete "contents" or cure of defects in service use within a reasonable period of time before expressing their intention to cancel or terminate the contract for the reasons set forth in paragraph 2. Article 27 (Effect of withdrawal of subscription by "user" and cancellation/termination of contract) ① The "Company" must refund the amount using the same method as the payment within 3 business days from the date the "User" expressed his/her intention to withdraw the contract or from the date the "User" responded to the "User's" expression of intention to cancel or terminate the contract. If a refund is not possible through the same method, the "Company" must notify the user in advance. In this case, when the "Company" delays refund to the "User," the delay interest calculated by multiplying the delay period by the delay interest rate determined and announced by the Fair Trade Commission will be paid. ② When the "Company" makes a refund in accordance with Paragraph 1, the "User" may deduct the amount equivalent to the profit obtained from the use of the service and make the refund. ③ In refunding the above amount, if the "User" has paid for the goods, etc. using a payment method such as a credit card or electronic money, the "Company" will request the business operator who provided the payment method to suspend or cancel the billing for the goods, etc. without delay. However, this may not apply if the amount deduction under Paragraph 2 is necessary. ④ In cases where the "Company," "the person who received payment for content, etc.," or "the person who entered into a content use agreement with the user" are not the same person, each person is jointly and severally liable for the performance of obligations related to payment refund due to cancellation of subscription or cancellation or termination of contract. ⑤ The "Company" will not claim a penalty or compensation for damages from the "User" due to cancellation of subscription. However, this does not affect the "User's" claim for compensation for cancellation or termination of the contract. Article 28 (Company's contract cancellation/termination and use restrictions) ① If a "User" commits an act stipulated in Article 12, Paragraph 2, the "Company" may cancel or terminate the contract without prior notice or restrict the use of the service for a set period of time. ② Cancellation/termination under Paragraph 1 takes effect when the "Company" expresses its intention to the "User" in accordance with the notification method determined by the "Company." ③ Cancellation/termination and use restrictions of the "Company" "Users" may file an objection in accordance with the procedures set by the "Company." At this time, if the "Company" acknowledges that the objection is justified, the "Company" will immediately resume use of the service. Article 29 (Effect of company contract cancellation/termination) Article 27 applies mutatis mutandis to the effect of cancellation or termination of the service agreement due to reasons attributable to the "user." However, the "Company" will refund the amount in the same manner as the payment within 7 business days from the date of the "User's" expression of intention to cancel or terminate the contract. Chapter 5 Overpayment, compensation for damages, etc. Article 30 (Overpayment) ① If an overpayment occurs, the "Company" must refund the entire overpayment amount using the same method as payment of the usage fee. However, if a refund is not possible through the same method, we will notify you in advance. ② If an overpayment occurs due to a reason attributable to the "Company," the "Company" will refund the entire overpayment amount regardless of contract costs, commissions, etc. However, if an overpayment occurs due to a reason attributable to the "User", the costs incurred by the "Company" to refund the overpayment must be borne by the "User" within a reasonable range. ③ If the company refuses to refund the overpayment claimed by the "user," it is responsible for proving that the usage fee was properly charged. ④ The "Company" handles refund procedures for overpayments in accordance with the Digital Content User Protection Guidelines. Article 31 (Compensation for user damage due to content defects, etc.) The "Company" handles matters related to the standards, scope, methods and procedures of compensation for user damage caused by content defects, etc. in accordance with the Digital Content User Protection Guidelines. Article 32 (Disclaimer) ① If the "Company" is unable to provide the "Content" due to a natural disaster or other force majeure, the "Company" is exempted from liability for the provision of the "Content." ② The "Company" is not responsible for any disruption in the use of content due to reasons attributable to the "User." ③ The "Company" is not responsible for the reliability and accuracy of information, data, and facts posted by "Members" in relation to "Content." ④ The "Company" is not responsible for disputes that arise between "Users" or between "Users" and third parties through "Contents." Article 33 (Resolution of disputes) If a dispute arises, the "Company" takes appropriate and prompt action by reflecting the legitimate opinions or complaints raised by the "User." However, in cases where prompt processing is difficult, the "Company" will notify the "User" of the reason and processing schedule.
Privacy Policy
Chapter 1 General Provisions Article 1 (Purpose) The purpose of these guidelines is to stipulate detailed information on standards for processing personal information, types of personal information infringements, and preventive measures in accordance with Article 12 (1) of the Personal Information Protection Act (hereinafter referred to as the "Act"). Article 2 (Definition of terms) The meanings of terms used in these guidelines are as follows. 1. "Personal information processing" refers to collecting, creating, linking, linking, recording, storing, retaining, processing, editing, searching, printing, correcting, recovering, using, providing, disclosing, destroying, and other similar actions of personal information. 2. "Personal information processor" refers to all public institutions, for-profit business operators, non-profit organizations such as associations and alumni associations, individuals, etc. that process personal information in order to operate personal information files pursuant to Article 2, Paragraph 4 of the Act for business purposes. 3. "Public institution" means an institution pursuant to Article 2, Paragraph 6 of the Act and Article 2 of the Enforcement Decree of the Personal Information Protection Act (hereinafter referred to as the "Decree"). 4. "Friendship group" refers to various gatherings such as alumni associations, clubs, local associations, neighborhood associations, clubs, etc., which are made up of schools, regions, companies, internet communities, etc., and are intended to promote friendship among people with common interests or goals such as volunteer work, hobbies, politics, religion, etc. 5. "Personal information protection officer" refers to a person who is responsible for overall management of personal information processing of the personal information processor and falls under Article 32 (2) of the Decree. 6. "Personal information handler" refers to a person in charge of processing personal information under the direction and supervision of the personal information processor, including executives and employees, dispatched workers, and part-time workers. 7. "Personal information processing system" refers to an application system systematically configured to process personal information, such as a database system. 8. "Video information processing device" refers to any device that is continuously installed in a certain space to capture images of people or objects or transmit them through wired or wireless networks, including closed-circuit televisions and network cameras under Article 3 of the Decree. 9. "Personal video information" refers to video related to an individual's portrait, behavior, etc., among video information captured and processed by a video information processing device, and information that can identify the individual. 10. "Video information processing device operator" means a person who installs and operates video information processing devices in accordance with each subparagraph of Article 25 (1) of the Act. 11. "Public place" refers to a place where there are no restrictions on access or passage by an unspecified number of people, such as parks, roads, subways, inside shopping malls, parking lots, etc. Article 3 (Scope of Application) These guidelines apply to personal information processors who operate personal information files in all forms, including electronic files, printed materials, and written documents. Article 4 (Personal Information Protection Principles) ① Personal information processors must clarify the purpose of processing personal information and legally and justly collect only the minimum amount of personal information necessary for that purpose. ② Personal information processors must process personal information appropriately to the extent necessary for the purpose of processing personal information, and must not use it for purposes other than that purpose. ③ Personal information processors must maintain the accuracy and up-to-dateness of personal information to the extent necessary for the purpose of processing personal information, and must ensure that personal information is not unduly altered or damaged in the process of processing personal information, either intentionally or through negligence. ④ Personal information processors must safely manage personal information through appropriate managerial, technical, and physical protection measures, taking into account the possibility and degree of risk that the information subject's rights may be violated depending on the processing method and type of personal information. ⑤ The personal information processor must disclose matters related to the processing of personal information, such as the personal information processing policy, and must establish reasonable procedures and methods to ensure the rights of the information subject, such as the right to request access, are guaranteed. ⑥ Personal information processors must process personal information in a way that minimizes infringement on the privacy of the information subject, even when processing personal information lawfully to the extent necessary for the purpose of processing personal information. ⑦ Even when personal information is collected legally, the personal information processor must ensure that personal information can be processed anonymously if the business purpose can be achieved anonymously. ⑧ Personal information processors must strive to gain the trust of information subjects by complying with and practicing the responsibilities and obligations stipulated in relevant laws and regulations. Article 5 (Relationship with other guidelines) When the head of a central administrative agency establishes personal information protection guidelines related to the processing of personal information in the field under his/her jurisdiction, he/she must ensure that these guidelines are complied with. Chapter 2 Personal information processing standards Section 1 Processing of Personal Information Article 6 (Collection and use of personal information) ① "Collection" of personal information refers to not only receiving personal information such as name, address, and phone number directly from the information subject, but also acquiring all forms of personal information about the information subject. ② The personal information processor may collect personal information in the following cases and use it within the scope of the purpose of collection. 1. When prior consent has been obtained from the information subject 2. When the law specifically states or permits the collection and use of personal information. 3. When the law imposes specific obligations on the personal information processor, and it is impossible or significantly difficult for the personal information processor to fulfill that obligation without collecting and using personal information. 4. When it is impossible or significantly difficult for a public institution to perform its duties prescribed by laws and regulations without collecting and using personal information. 5. When it is impossible or significantly difficult to conclude a contract with the information subject and perform obligations according to the contents of the concluded contract without collecting and using personal information. 6. In cases where the information subject or his/her legal representative is unable to express his/her intention or cannot obtain prior consent due to unknown address, etc., it is clearly deemed necessary for the urgent benefit of life, body, and property of the information subject or a third party (referring to all other persons excluding the information subject). 7. When it is necessary for the personal information processor to achieve legitimate interests pursuant to laws or contracts with the information subject, and clearly takes precedence over the rights of the information subject. However, in this case, the collection and use of personal information is limited to cases where it is significantly related to the legitimate interests of the personal information processor and does not exceed a reasonable scope. ③ If the personal information processor collects personal information by receiving a business card or similar media (hereinafter referred to as "business card, etc.") directly from the information subject, it may be used only to the extent that it is recognized that there was an intention to consent based on social norms, considering the circumstances of providing the business card, etc. ④ When personal information processors collect personal information from public media or locations such as Internet homepages (hereinafter referred to as "Internet homepages, etc."), personal information may be used only to the extent that the information subject's intent to consent is clearly indicated or the intent to consent is recognized based on social norms based on the content displayed on the Internet homepage, etc. ⑤ When the information subject, who is the other party to a contract, etc., performs legal acts or expresses his/her intention through an agent, the personal information processor may collect and use the agent's personal information only for the purpose of confirming the agent's authority to represent the agent. ⑥ When a worker and an employer enter into a labor contract, personal information may be collected and used without the worker's consent for the purpose of payment of wages, training, issuance of certificates, and provision of worker welfare in accordance with the Labor Standards Act. Article 7 (Provision of personal information) ① "Provision" of personal information refers to any act that results in the transfer or joint use of personal information, such as physically transferring personal information storage media or printouts or booklets containing personal information, transmitting personal information through a network, granting a third party access to personal information, or sharing personal information between the personal information processor and a third party. ② "Third party" in Article 17 of the Act means all persons excluding the information subject and the personal information processor who collects and holds personal information regarding the information subject, and excludes the information subject's agent (limited to those clearly within the scope of representation) and trustee under Article 26 (2) of the Act (hereinafter the same shall apply). ③ When the personal information processor informs the information subject of the person receiving personal information pursuant to Article 17, Paragraph 2, Item 1 of the Act, the name (if it is a corporation or organization, its name) and contact information must be notified as well. Article 8 (Use/Provision of Personal Information for Other Purposes) ① If the personal information processor provides personal information to a third party for a purpose other than the purpose pursuant to Article 18 (2) of the Act, the purpose of use, method of use, and use of personal information will be provided to the person receiving the personal information. A request must be made in writing (including electronic documents; hereinafter the same shall apply) to limit the period, form of use, etc., or to prepare specific measures necessary to ensure the safety of personal information. In this case, the person who received the request must take action accordingly and notify the personal information processor who provided the personal information of the fact in writing. ② Pursuant to Article 18, Paragraph 2 of the Act, a person who provides personal information to a third party for purposes other than the intended purpose must clarify the relationship of responsibility for measures to ensure the safety of personal information with the person receiving the personal information. ③ When the personal information processor informs the information subject of the person receiving personal information pursuant to Article 18, Paragraph 3, Item 1 of the Act, the name (if it is a corporation or organization, its name) and contact information must also be notified. ④ When a personal information processor provides personal information to a third party pursuant to Article 18, Paragraph 2, Item 4 of the Act, it must be provided in a form that does not identify a specific individual even when combined with other information. Article 9 (Notice of personal information collection sources, etc.) ① When a personal information processor processes personal information collected from people other than the information subject, he/she must inform the information subject of all matters stipulated in each subparagraph of Article 20 (1) of the Act within 3 days from the date of the information subject's request, unless there is a justifiable reason. However, this does not apply in any of the following cases. 1. If the personal information subject to notification request is included in a personal information file falling under any of the subparagraphs of Article 32 (2) of the Act. 2. If there is a risk that the life or body of another person may be harmed due to the notice, or there is a risk of unfairly infringing on another person's property or other interests. ② If the personal information manager refuses the information subject's request pursuant to the preamble to paragraph (1) pursuant to the proviso to paragraph (1), he/she shall notify the information subject of the basis and reason for such refusal within three days from the date of the information subject's request, unless there is a justifiable reason. Article 10 (Methods and procedures for destroying personal information) ① The personal information manager must destroy the personal information within 5 days when the personal information retention period has expired or the personal information has become unnecessary, such as the achievement of the purpose of processing the personal information, abolition of the relevant service, or termination of the business, unless there is a justifiable reason. ② 'Method of making restoration impossible' in Article 16, Paragraph 1, Item 1 of the Decree means a method of taking measures to make it impossible to restore destroyed personal information at a reasonable cost in accordance with social norms at the current level of technology. ③ Personal information processors must record and manage matters related to destruction of personal information. ④ The person in charge of personal information protection must confirm the results of destruction of personal information after implementation. ⑤ Articles 55 and 56 shall apply to the destruction of personal information files by public institutions among personal information processors. Article 11 (Preservation of personal information in accordance with laws) ① If the personal information processor must preserve personal information rather than destroy it based on the law in accordance with the proviso to Article 21, Paragraph 1 of the Act, the personal information must be stored and managed separately by physical or technical means. ② When personal information is stored and managed separately pursuant to paragraph 1, the information subject must be made aware that the personal information or personal information file is stored and managed in accordance with laws and regulations through the personal information processing policy, etc. Article 12 (Method of obtaining consent) ① When a personal information processor receives the consent of the information subject for the processing of personal information, he or she must distinguish between personal information that can be processed without the consent of the information subject and personal information that requires the consent of the information subject, and the consent of the information subject is limited to personal information that requires consent. In this case, the burden of proving that personal information can be processed without consent is borne by the personal information processor. ② If any of the following cases applies, the personal information manager must inform the information subject of the matters stipulated in each subparagraph of Article 18 (3) of the Act and obtain consent. 1. In cases where personal information is intended to be collected and used and does not fall under Article 15 (1) 2 to 6 of the Act 2. If you wish to use or provide personal information for purposes other than the purpose of collection pursuant to Article 18 (2) of the Act. 3. When it falls under Article 22 (3) of the Act and seeks to promote or recommend the sale of goods or services to the information subject. 4. Cases where processing of unique identification information other than resident registration number is necessary and there is no basis for processing unique identification information in the law. 5. If you wish to process sensitive information and there is no basis for processing sensitive information in the law. ③ If a personal information processor wishes to process personal information that falls under any of the provisions of paragraph 2, he/she must explicitly inform the information subject that he/she can choose to consent or refuse consent. ④ If personal information is collected without the consent of the information subject pursuant to Article 15, Paragraph 1, Items 2 to 6 of the Act, the personal information processor shall endeavor to inform the information subject of the legal basis for collecting personal information. ⑤ When a personal information manager records a call in relation to consent by telephone pursuant to the provisions of Article 17 (1) 2 of the Decree, he/she shall notify the information subject of the recording. ⑤-2 If a member gives optional consent, IT7 uses the member's name and email address to provide information about IT7 services, partner programs, benefits, and events. Consent is not required to use the service and may be withdrawn at any time through Account info or an email's unsubscribe function. Consent status and change history are retained until withdrawal or account deletion and thereafter only for the period required by applicable law. ⑥ If a personal information processor collects personal information that falls under any of the following items in order to operate a social organization, the personal information may be collected and used without the consent of the information subject. 1. Name, contact information for membership in a friendly organization, and personal information related to common interests or goals determined by the bylaws of the friendly organization 2. Matters concerning the payment status of expenses necessary for maintaining friendship, such as membership fees of friendly organizations 3. Matters pertaining to member attendance and activity details of social group activities 4. Matters related to birthdays, preferences, and family members' wishes that members wish to inform other members in order to promote friendship and harmony among members of other social organizations. ⑦ When a personal information processor writes a consent form to obtain consent from the information subject, he/she must comply with the "Guidelines for Writing a Consent Form for Personal Information Collection and Provision." Article 13 (Consent of legal representative) ① Pursuant to Article 17 (3) of the Decree, when a personal information manager collects the name and contact information of a legal representative, he/she must inform the child of his or her identity and contact information and the reason for collecting the name and contact information of the legal representative. ② The personal information processor must use the personal information of the legal representative collected pursuant to Article 22 (5) of the Act only for the purpose of obtaining the consent of the legal representative, and if the legal representative refuses to consent or the legal representative's intention to consent is not confirmed, the personal information must be destroyed within 5 days from the date of collection. Article 14 (Cases where prior consent of the information subject cannot be obtained) If a personal information processor collects, uses or provides personal information without the prior consent of the information subject pursuant to Article 15, Paragraph 1, Item 5 and Article 18, Paragraph 2, Item 3 of the Act, the processing of personal information shall be immediately stopped when the relevant reason has been resolved, and the information subject shall be notified of the fact that personal information has been collected, used or provided without prior consent, the reason for this, and the details of use. Article 15 (Supervision of personal information handlers) ① Personal information processors must keep the number of personal information handlers to a minimum within the extent necessary for business purposes, and limit the scope of personal information processing by personal information handlers to the minimum within the extent necessary for business purposes. ② The personal information processor must differentially grant access rights to the personal information processing system to the person in charge to the minimum extent necessary to perform the work, depending on the nature of the work, and take measures to manage the access rights. ③ The personal information processor must provide appropriate management and supervision, such as requiring the personal information handler to submit a security pledge, and if the personal information handler's duties change due to personnel changes, etc., the right to access personal information must be changed or canceled. Section 2 Entrustment of Personal Information Processing Article 16 (Things to consider when selecting a trustee) When selecting a person (hereinafter referred to as "trustee") who is entrusted with the processing of personal information, the personal information processor (hereinafter referred to as "consignor") entrusted with the processing of personal information shall comprehensively consider personal information processing and protection capabilities, including human resources and physical facilities, financial burden capacity, degree of technology, and responsibility capacity. Article 17 (Obligation to take personal information protection measures) In order to protect the entrusted personal information, the trustee must take administrative, technical and physical measures in accordance with the "Personal Information Safety Security Standard Notice". Section 3 Preparation of personal information processing policy Article 18 (Standards for writing personal information processing policy, etc.) ① When a personal information manager prepares a personal information processing policy, the matters stipulated in each subparagraph of Article 30 (1) of the Act and each subparagraph of Article 31 (1) of the Decree shall be explicitly distinguished, and shall be detailed and in easy-to-understand terms. It must be expressed clearly. ② The personal information processor must disclose that the personal information being processed is the minimum necessary for the purpose of processing the personal information. Article 19 (Statement of Personal Information Processing Policy) When a personal information manager prepares a personal information processing policy, he/she must include all of the following matters in accordance with Article 30 (1) of the Act. 1. Purpose of processing personal information 2. Items of personal information processed 3. Processing and retention period of personal information 4. Matters regarding provision of personal information to third parties (decided only in applicable cases) 5. Matters regarding destruction of personal information 6. Matters related to the entrustment of personal information processing, such as the contact information of the person in charge of the personal information processing trustee and the results of the management status inspection of the trustee (to be determined only in cases where applicable) 7. Matters concerning measures to ensure the safety of personal information pursuant to Article 30 (1) of the Decree 8. Matters pertaining to the rights and obligations of the information subject and how to exercise them, including the right to view, correct, delete, and suspend processing of personal information 9. Matters regarding changes to personal information processing policy 10. Matters regarding the person in charge of personal information protection 11. Department that receives and processes requests to view personal information 12. Remedy for infringement of rights and interests of information subjects Article 20 (Disclosure of personal information processing policy) ① If a personal information processor establishes a personal information processing policy pursuant to Article 30, Paragraph 2 of the Act, it must be continuously posted on the Internet homepage. In this case, the name "Personal Information Processing Policy" must be used, but the font size, color, etc. must be used to distinguish it from other notices so that the information subject can easily confirm it. ② If the personal information processor does not operate the Internet homepage or if there is a defect in the management of the Internet homepage, the personal information processing policy must be disclosed in one or more ways under each subparagraph of Article 31 (3) of the Decree. In this case as well, the name "Personal Information Processing Policy" must be used, but font size, color, etc. must be used to distinguish it from other notices so that information subjects can easily check it. ③ If the personal information processor discloses the personal information processing policy in the manner prescribed in Article 31, Paragraph 3, Item 3 of the Decree, it shall be continuously published in publications, newsletters, promotional materials, invoices, etc. whenever they are issued. Article 21 (Change in Personal Information Processing Policy) If the personal information processor changes the personal information processing policy, the timing of change and implementation and the changed content must be continuously disclosed, and the changed content must be disclosed by comparing before and after the change so that the information subject can easily confirm it. Section 4 Personal Information Protection Manager Article 22 (Disclosure of Personal Information Protection Manager) ① If the personal information manager designates or changes the personal information protection manager, the fact of designation and change of the personal information protection manager, name, department name, phone number, and other contact information must be disclosed. ② When disclosing the person in charge of personal information protection, the personal information manager must disclose the contact information where grievances and consultations related to personal information protection can actually be handled. In this case, the contact information, including the name, department name, and phone number of the person in charge of personal information protection and the person in charge of personal information protection work, may be disclosed. Article 23 (Training of Personal Information Protection Manager) The contents of the training for personal information protection officers that the Minister of Government Administration and Home Affairs may establish and operate pursuant to Article 32 (3) of the Decree are as follows. 1. Contents of laws and systems related to personal information protection 2. Matters necessary for performing duties under Article 31 (2) of the Act and Article 32 (1) of the Decree. 3. Other matters necessary to protect the personal information of the personal information processor. Article 24 (Establishment and implementation of education plan) ① At the beginning of each year, the Minister of Government Administration and Home Affairs establishes and implements a training plan for personal information protection officers for the current year. ② The Minister of Government Administration and Home Affairs may have organizations such as the Korea Personal Information Protection Council provide training for personal information protection officers in accordance with the training plan under paragraph (1). ③ The Minister of Government Administration and Home Affairs shall strive to create an environment in which the person responsible for personal information protection can receive training conveniently regardless of geographical or economic conditions. Section 5 Personal information leak notification and reporting, etc. Article 25 (Leakage of personal information) Leakage of personal information refers to any of the following cases in which the personal information processor loses control over the personal information of the information subject or allows access to an unauthorized person, not in accordance with laws or the personal information processor's free will. 1. When documents containing personal information, portable storage devices, portable computers, etc. are lost or stolen 2. When a person without normal authority accesses the personal information processing system, such as the database where personal information is stored. 3. If a file, paper document, or other storage medium containing personal information is incorrectly delivered to an unauthorized person due to the personal information processor's intention or negligence. 4. If personal information is passed on to an unauthorized person Article 26 (Time and items of leak notification) ① When the personal information manager becomes aware that personal information has been leaked, he/she must notify the information subject of the following matters within 5 days, unless there is a justifiable reason. However, in order to prevent the spread and further leakage of leaked personal information, if urgent measures such as blocking access paths, checking and supplementing vulnerabilities, or deleting leaked personal information are necessary, the information subject may be notified within 5 days after taking such measures. 1. Items of leaked personal information 2. When and how it was leaked 3. Information on methods the information subject can take to minimize damage that may occur due to leakage. 4. Personal information processor's response measures and damage relief procedures 5. Department in charge and contact information where reports, etc. can be received in case of damage to the information subject ② If it is difficult to confirm all of the matters in each subparagraph of Paragraph 1, the personal information manager may first inform the information subject of only the following facts and may notify the information subject as soon as they are later confirmed. 1. The fact that the information has been leaked to the subject 2. Confirmed matters among the notification items in Paragraph 1 ③ If the personal information manager is not aware of the personal information leakage incident and fails to notify the relevant information subject of the personal information leakage within 5 days from the time the personal information leakage incident occurred, the personal information manager must prove the point in time when he or she actually became aware of the personal information leakage incident. Article 27 (Leak notification method) ① When notifying the information subject of the matters stipulated in each subparagraph of Article 26, Paragraph 1, the personal information manager shall notify the information subject without delay through writing, e-mail, facsimile transmission, telephone, mobile phone text message, or similar methods. ② The personal information manager may disclose the matters specified in each subparagraph of Article 26, Paragraph 1 through the website, etc. at the same time as the notification method in Paragraph 1. Article 28 (Report of personal information leak, etc.) ① If the personal information of 10,000 or more information subjects is leaked, the personal information processor must report the notification to the information subjects and the results of the action to the Minister of Government Administration and Home Affairs or a specialized agency under Article 39 (2) of the Decree within 5 days. ② Reports under paragraph 1 must be made through the personal information leak report form in Annex Form No. 1. ③ If the personal information manager does not have time to report a leak through e-mail, fax, or the Internet site of a specialized organization pursuant to Article 39, Paragraph 2 of the Decree, or if there are other special circumstances, the personal information manager may first report the matters under Article 26, Paragraph 1 via telephone and then submit a personal information leak report in Form No. 1 of the attached document. ④ If the personal information of 10,000 or more information subjects is leaked, the personal information manager shall post the matters specified in each subparagraph of Article 26 (1) on the Internet homepage, etc. for at least 7 days along with the notice pursuant to Article 26 (1) so that the information subjects can easily recognize them. Article 29 (Personal Information Leak Incident Response Manual, etc.) ① Personal information controllers who fall under any of the following items must prepare a "Personal Information Leakage Accident Response Manual" to minimize damage through rapid response in the event of a leakage incident. 1. Public institution under Article 2, Paragraph 6 of the Act 2. Other personal information processors who process personal information about 10,000 or more information subjects. ② The personal information leak incident response manual pursuant to paragraph 1 shall include leak notification and inquiry procedures, measures to respond to customer complaints such as expansion of branches and internet lines, measures to minimize on-site congestion, measures to relieve customer anxiety, and measures to provide relief to victims. ③ Personal information processors must strive to minimize the inconvenience and economic burden of information subjects when carrying out damage recovery measures due to personal information leaks. Article 30 (Processing of reports of personal information infringement, etc.) ① Processing of personal information by the personal information processor As a result, a person whose rights or interests regarding personal information have been infringed may report the infringement to the Personal Information Infringement Reporting Center under Article 62 (2) of the Act. ② The Personal Information Infringement Reporting Center under Paragraph 1 shall perform the following tasks. 1. Receipt and consultation of reports related to personal information processing 2. Investigating and confirming the facts regarding personal information infringement reports and listening to the opinions of relevant parties 3. Inform the personal information processor of personal information infringement and induce correction 4. If the fact-finding results determine that there is no violation of the rights or interests of the information subject, the report will be closed. 5. Support for resolving grievances through mediation guidance by the Personal Information Dispute Mediation Committee pursuant to Article 43 of the Act Section 6 Guaranteeing the rights of information subjects Article 31 (Extinction of reasons for delaying viewing of personal information) ① If the personal information manager postpones the inspection of personal information pursuant to the latter part of Article 35, Paragraph 3 of the Act and the reason for such delay ceases to exist, the personal information manager must allow inspection within 10 days from the date on which the reason disappears, unless there is a justifiable reason. ② The personal information processor who has received a request from the information subject to view the status of provision of personal information to a third party pursuant to Article 41, Paragraph 1, Item 4 of the Decree, shall provide the third party with an opinion regarding permission, restriction, or rejection of the request for access if it is a matter of importance to national security and causes significant disruption in performing duties under Article 35, Paragraph 4, Item 3 of the Act. You can check and decide. Article 32 (Correction/Deletion of Personal Information) ① When a personal information processor receives a request for correction or deletion of personal information pursuant to Article 36 (1) of the Act, unless there is a justifiable reason, the personal information processor shall investigate the personal information within 10 days from the date of receipt of the request, take necessary measures such as correction and deletion in accordance with the request of the information subject, and notify the information subject of the results. ② If the information subject's request for correction or deletion falls under the proviso to Article 36, Paragraph 1 of the Act, the information subject must be notified of the contents of the underlying law that cannot request deletion within 10 days from the date of receipt of the request, unless there is a justifiable reason. Article 33 (Suspension of processing of personal information) ① When a personal information processor is requested by the information subject to suspend personal information processing pursuant to Article 37 (1) of the Act, part or all of personal information processing shall be suspended within 10 days from the date of receipt of the request, unless there is a justifiable reason. However, in cases that fall under the proviso to Article 37 (2) of the Act, the information subject's request to suspend processing may be rejected. ② The personal information processor shall take measures corresponding to the request of the information subject, such as destroying the personal information, within 10 days from the date of receiving the request for suspension of personal information, unless there is a justifiable reason, and notify the information subject of the results. Article 34 (Methods and procedures for exercising rights) ① When a data subject makes a request for viewing, etc. pursuant to Article 38 (1) of the Act, the personal information processor must provide an easy method for the data subject to exercise the rights, such as a request for viewing, that is the same or easier than the method of collecting personal information, and cannot request supporting documents, etc. that were not required at the time of collecting personal information, or require additional procedures. ② The provisions of paragraph 1 shall apply mutatis mutandis to cases where a person wishes to confirm that he or she is a principal or a legitimate agent pursuant to Article 46 of the Decree and to settlement of fees and postage charges pursuant to Article 47 of the Decree. Chapter 3 Installation and operation of video information processing equipment Section 1 Installation of video information processing equipment Article 35 (Scope of Application) This chapter covers video information processing devices installed and operated by video information processing device operators in public locations and personal video information processed through these devices. Article 36 (Guidelines for operating and managing visual information processing devices) ① When establishing or changing guidelines for the operation and management of video information processing devices, they must be disclosed so that information subjects can easily confirm them. ② In cases where guidelines for the operation and management of video information processing devices are established, a personal information processing policy pursuant to Article 30 of the Act may not be established, or matters related to the installation and operation of video information processing devices may be included in the personal information processing policy pursuant to Article 30 of the Act. Article 37 (Designation of management manager) ① The operator of video information processing equipment must designate a manager responsible for overall management of work related to the processing of personal video information. ② The manager in charge of paragraph 1 shall perform the following duties in accordance with the duties of the personal information protection manager under Article 31 (2) of the Act. 1. Establishment and implementation of personal video information protection plan 2. Regular investigation and improvement of personal video information processing status and practices 3. Handling of complaints and relief for damage related to the processing of personal video information 4. Establishment of an internal control system to prevent leakage and misuse/abuse of personal video information 5. Establishment and implementation of personal video information protection education plan 6. Management and supervision of protection and destruction of personal video information files 7. Other tasks necessary to protect personal video information ③ If a personal information protection manager is designated pursuant to Article 31 of the Act, the personal information protection manager may perform the duties of the manager. Article 38 (Collection of prior opinions) Even in the case of additional installation due to a change in the purpose of installation of video information processing equipment, opinions from relevant experts and interested parties must be collected in accordance with Article 23 (1) of the Decree. Article 39 (Installation of information boards) ① The operator of a video information processing device shall take necessary measures, such as installing a signboard listing the following matters in accordance with the main text of Article 25 (4) of the Act, so that the information subject can easily recognize that the video information processing device is being installed and operated. 1. Purpose and location of installation 2. Shooting range and time 3. Name or position and contact information of the person in charge of management 4. When entrusting affairs related to the installation and operation of video information processing equipment, the name and contact information of the trustee ② The signboard pursuant to paragraph (1) shall be installed so that anyone can easily read it in a place easily recognized by the information subject within the shooting range, and within this range, the operator of the image information processing device may voluntarily determine the size and installation location of the signboard. ③ In cases where the head of a public institution installs and operates video information processing devices by physically and managerially integrated for each purpose and region for efficient management of video information processing devices and information linkage within the institution or between institutions (hereinafter referred to as 'integrated management'), information on integrated management, including the purpose of installation, shall be written on the information board pursuant to paragraph 1 so that information subjects can easily recognize them. Section 2 Processing of personal video information Article 40 (Restrictions on use of personal video information, provision to third parties, etc.) ① Video information processing device operators shall not use personal video information for purposes other than collection purposes or provide it to third parties, except in the following cases. However, items 5 through 9 are limited to public institutions. 1. When consent is obtained from the information subject 2. When there are special provisions in other laws 3. In cases where the information subject or his/her legal representative is unable to express his/her intention or cannot obtain prior consent due to unknown address, etc., it is clearly deemed necessary for the urgent benefit of the life, body, or property of the information subject or a third party. 4. When personal video information is provided in a form that does not identify a specific individual as necessary for purposes such as statistical compilation and academic research. 5. Cases in which personal image information is used for purposes other than its intended purpose or does not provide it to a third party, in which case it is impossible to perform duties prescribed by other laws and has been reviewed and resolved by the Protection Committee. 6. When necessary to provide information to foreign governments or international organizations for the implementation of treaties and other international agreements. 7. When necessary for investigation of crime and filing and maintenance of indictment 8. When necessary to carry out the court's judicial duties 9. When necessary for the execution of punishment, custody, and protective measures. Article 41 (Storage and Destruction) ① The video information processing device operator must destroy the collected personal video information without delay when the storage period specified in the video information processing device operation and management policy expires. However, this does not apply if there are special provisions in other laws and regulations. ② If it is difficult for the video information processing device operator to calculate the minimum period to achieve the purpose of retention depending on the circumstances, the storage period shall be within 30 days after collection of personal video information. ③ The method of destruction of personal video information is as follows: 1. Printouts (photos, etc.) containing personal video information are shredded or incinerated. 2. Personal video information in the form of electromagnetic files is permanently deleted using a technical method that makes restoration impossible. Article 42 (Recording and management of use, provision to third parties, and destruction) ① The video information processing device operator has the purpose of collecting personal video information. When using it for any other purpose or providing it to a third party, the following matters must be recorded and managed. 1. Name of personal video information file 2. Name of the person using or receiving the provision (public institution or individual) 3. Purpose of use or provision 4. If there is a legal basis for use or provision, the basis thereof 5. If there is a fixed period of use or provision, that period 6. Form of use or provision ② If the video information processing device operator destroys personal video information, the following information must be recorded and managed. 1. Name of the personal video information file to be destroyed 2. Personal video information destruction date (in case of automatic deletion with a pre-determined destruction period, destruction cycle and confirmation period for automatic deletion) 3. Person in charge of destroying personal video information Article 43 (Entrustment of installation and management of video information processing equipment, etc.) ① If the video information processing device operator entrusts affairs related to the installation and operation of the video information processing device to a third party pursuant to Article 26 (1) of the Decree, the name of the trustee, etc. shall be disclosed on the information board under Article 24 of the Decree and the video information processing device operation and management policy under Article 27 of the Decree so that the information subject can easily check the contents at any time. ② If the operator of video information processing equipment entrusts affairs related to the installation and operation of video information processing devices to a third party pursuant to Article 26 (1) of the Decree, he/she shall manage and supervise whether the person entrusted with such affairs is handling personal video information safely. Section 3 Request for viewing, etc. of personal video information Article 44 (Request for inspection, etc. by information subject) ① The information subject may request the video information processing device operator to view or confirm the existence of personal video information processed by the video information processing device operator (hereinafter referred to as "view, etc."). In this case, the personal video information that the information subject may request to view is limited to personal video information filmed by the information subject and personal video information clearly necessary for the urgent benefit of the information subject's life, body, and property. ② If the operator of the video information processing device is a public institution, a request for viewing and existence of personal video information (including electronic documents) must be submitted to the head of the relevant organization in Form No. 2. ③ When the operator of video information processing equipment receives a request pursuant to paragraph (1), he/she shall take necessary measures without delay. At this time, the operator of the video information processing device must confirm whether the person making the request for viewing, etc. is the person himself or a legitimate agent by receiving identification documents such as a resident registration card, driver's license, or passport. ④ Notwithstanding the provisions of paragraph 3, in any of the following cases, the video information processing device operator may refuse the information subject's request to view personal video information, etc. In this case, the video information processing device operator must notify the data subject of the reason for rejection in writing, etc. within 10 days. 1. Cases that cause significant disruption to criminal investigation, maintenance of prosecution, and trial performance (limited to public institutions) 2. When personal video information is destroyed after its retention period has expired 3. If there is a justifiable reason to refuse the information subject's request for inspection, etc. ⑤ When taking measures pursuant to paragraphs 3 and 4, the operator of video information processing equipment shall record and manage the following matters. 1. Name and contact information of the information subject who requested viewing of personal video information, etc. 2. Name and contents of the personal video information file that the information subject has requested to view, etc. 3. Purpose of viewing personal video information, etc. 4. In case of refusal to view personal video information, etc., specific reasons for refusal 5. If a copy of personal video information is provided to the information subject, the content of the video information and the reason for providing it ⑥ When requesting the video information processing device operator to destroy the information subject's personal video information, the information subject may only request destruction of the personal video information that has been requested to be preserved pursuant to paragraph (1). If the video information processing device operator takes the relevant destruction action, the contents must be recorded and managed. Article 45 (Personal video information management ledger) For recording and management pursuant to Article 42 (1) and (2) and Article 44 (5) and (6), the 'Personal Video Information Management Ledger' according to Form No. 3 can be used. Article 46 (Protection of personal video information of persons other than information subject) When taking measures such as viewing pursuant to Article 44 (2), the operator of video information processing equipment must take protective measures to prevent personal video information from being recognized by persons other than the information subject if a person other than the information subject can be clearly identified or if there is a risk of infringement on the privacy of a person other than the information subject. Section 4 Personal video information protection measures Article 47 (Measures to ensure the safety of personal video information) The operator of video information processing equipment must take the following measures to ensure safety in accordance with Article 29 of the Act and Article 30 (1) of the Decree to prevent personal video information from being lost, stolen, leaked, altered or damaged. 1. Establishment and implementation of an internal management plan for the safe processing of personal video information. However, 'small business owners' pursuant to Article 2, Paragraph 4 of the "Notice on Standards for Ensuring the Safety of Personal Information" may not establish an internal management plan. 2. Measures to control access to personal video information and limit access rights 3. Application of technology to safely store and transmit personal video information (encryption measures for safe transmission in the case of network cameras, password settings when saving personal video information files, etc.) 4. Measures to store processing records and prevent forgery and alteration (recording and management measures such as creation date and time of personal video information, purpose of viewing, viewer, date and time of viewing, etc.) 5. Establishment of storage facilities or installation of locking devices for safe physical storage of personal video information. Article 48 (Inspection of installation and operation of personal video information processing devices) ① When the head of a public institution installs and operates a video information processing device, he/she must conduct a self-inspection on compliance with these guidelines, notify the Minister of Government Administration and Home Affairs of the results by March 31 of the following year, and register them in the system under Article 34 (3) of the Decree. In this case, the following matters must be considered: 1. Matters listed in the operation and management policy of video information processing equipment 2. Work performance status of the person in charge of management 3. Installation and operation status of video information processing equipment 4. Current status of personal video information collection, use, provision, and destruction 5. Status of management and supervision of consignment and trustee 6. Status of measures taken regarding the exercise of rights of information subjects 7. Status of technical, managerial and physical measures 8. Whether the need for installation and operation of image information processor continues, etc. ② After completing the self-inspection of the installation and operation of image information processing equipment pursuant to paragraphs 1 and 3, the head of a public institution shall disclose the results on its website, etc. ③ If there is a concern that the personal video information of the information subject may be infringed upon due to the installation and operation of the video information processing device, the operator of video information processing equipment other than a public institution shall make active efforts to prevent the infringement of personal video information, such as through self-inspection. Chapter 4 Registration and disclosure of personal information files of public institutions Section 1 General Provisions Article 49 (Applicability) This chapter applies to the following: 1. Central administrative agencies (including agencies affiliated with the President and agencies affiliated with the Prime Minister), their affiliated agencies, and local governments 2. National Human Rights Commission under the National Human Rights Commission Act 3. Public institutions under the 「Act on the Management of Public Institutions」 4. Local public corporations and local corporations under the Local Public Enterprises Act 5. Special corporation established by special law 6. Schools at each level established in accordance with the Elementary and Secondary Education Act, the Higher Education Act, and other laws. Article 50 (Exclusion from application) This Chapter does not apply to personal information files that fall under any of the following items. 1. Personal information files managed by the National Assembly, courts, Constitutional Court, and National Election Commission (including their affiliated organizations) 2. Personal information files of the following items excluded from application pursuant to Article 32 (2) of the Act go. Personal information file that records matters related to national security, diplomatic secrets, and other important national interests. me. A personal information file that records matters related to investigation of crimes, filing and maintenance of indictments, execution of sentences and confinement, correctional dispositions, protective dispositions, security observation dispositions, and immigration control. all. A personal information file that records matters related to the investigation of criminal acts under the Tax Offenders Punishment Act and the investigation of illegal acts under the Customs Act. la. Personal information files used only for internal business processing of public institutions mind. Personal information files classified as confidential under other laws and regulations 3. Personal information files of the following items excluded from application pursuant to Article 58 (1) of the Act: go. Personal information files collected in accordance with the "Statistics Act" among personal information processed by public institutions me. Personal information files collected or requested to be provided for the purpose of analyzing information related to national security all. public health, etc. Personal information files that are temporarily processed when urgently needed for safety and security 4. Personal video information files processed through video information processing devices 5. Personal information files collected for the sole purpose of sending data, goods or money, conducting one-time events, etc. and discarding them without storing or recording them. 6. Personal information files held by financial institutions to handle financial business in accordance with the Act on Real Name Financial Transactions and Confidentiality. Section 2 Registration subject and procedure of personal information file Article 51 (Personal information file registration entity) ① The personal information protection officer of a public institution that operates personal information files must register the current status with the Ministry of Government Administration and Home Affairs. ② Central administrative agencies, metropolitan governments, special self-governing cities and provinces, and basic self-governing organizations must register directly with the Ministry of Government Administration and Home Affairs. ③ Offices of education and schools at each level must register with the Ministry of Government Administration and Home Affairs through the Ministry of Education. ④ Central administrative agencies, local government agencies, and other public agencies must register with the Ministry of Government Administration and Home Affairs through higher management agencies. Article 52 (Application for registration and change of personal information file) ① Personal information handlers of public institutions that operate personal information files must apply for registration of personal information files to the personal information protection manager of the relevant public institution. ② The application details for personal information file registration are as follows. Applications can be made using the 'Personal Information File Registration/Change Registration Application' in the attached Form No. 2 in accordance with Article 3, Paragraph 2 of the Personal Information Protection Act Enforcement Rules (hereinafter referred to as the "Enforcement Rules"). 1. Name of public institution that operates personal information files 2. Name of personal information file 3. Basis and purpose of personal information file operation 4. Personal information items recorded in the personal information file 5. Number of information subjects whose personal information is held in personal information files 6. How personal information is processed 7. Retention period of personal information 8. If personal information is provided routinely or repeatedly, the recipient 9. Department in charge of personal information processing-related work at the relevant public institution 10. Department that receives and processes requests to view personal information 11. Among the personal information in the personal information file, the scope and reasons for restriction or refusal of personal information whose viewing can be restricted or refused pursuant to Article 35 (4) of the Act 12. In the case of a personal information file that has undergone a personal information impact assessment pursuant to Article 33 (1) of the Act, the results of the impact assessment ③ If the registered information is changed, the personal information handler must apply for change to the personal information protection manager using the 'Personal Information File Registration/Change Registration Application' in the attached Form No. 2 pursuant to Article 3, Paragraph 2 of the Enforcement Rules. Article 53 (Confirmation of personal information file registration and changes) ① The personal information protection manager who has received an application for registration or change of a personal information file must review the registration or change, determine its appropriateness, and then register it with the Ministry of Government Administration and Home Affairs. ② The person in charge of personal information protection at the Office of Education and schools at each level shall request the Ministry of Education to review and determine the appropriateness of registration and changes made pursuant to paragraph 1, and then receive confirmation from the Ministry of Education and register them with the Ministry of Government Administration and Home Affairs. ③ Central administrative agencies, local governments' affiliated organizations, and other public institutions shall request the higher management agency to review and determine the appropriateness of registration and changes made pursuant to paragraph (1) and then register with the Ministry of Government Administration and Home Affairs after receiving confirmation from the higher management agency. ④ Registration under paragraphs 1 through 3 must be made within 60 days. Article 54 (Registration and management of standard list of personal information files) ① Organizations that carry out a single common task nationwide, such as special local administrative agencies, local governments, and educational institutions (including schools), must register in accordance with the 'Personal Information File Standard List' provided by each central administrative agency. ② A standard list of personal information files related to a single common task nationwide must be registered and managed by the relevant central government agency. Article 55 (Destruction of personal information files) ① When a personal information file becomes unnecessary, such as when the retention period for the personal information file has expired or the purpose of processing has been achieved, a public institution must destroy the personal information file without delay. However, this does not apply in cases where it must be preserved in accordance with other laws and regulations. ② Public institutions must establish and implement a personal information destruction plan that reflects the retention period and processing purpose of personal information files. However, if an internal management plan has been established pursuant to Article 30, Paragraph 1, Item 1 of the Decree, a personal information destruction plan may be included in the internal management plan and implemented. ③ The personal information handler must select a personal information file for which there is a reason for destruction, such as expiration of the retention period or achievement of the purpose of processing, and destroy the personal information by entering the name and destruction method of the personal information file subject to destruction in the personal information file destruction request form in Appendix 4 and receiving approval from the personal information protection manager. ④ The person in charge of personal information protection must confirm the results of destruction of personal information after carrying out the destruction and prepare a personal information file destruction management ledger according to Form No. 5. Article 56 (Deletion of personal information file registration) ① If the personal information handler destroys the personal information file pursuant to Article 55, he/she must request the personal information protection manager to delete the registration of the personal information file pursuant to Article 32 of the Act. ② The personal information protection officer who has been requested to delete the personal information file registration confirms the fact, deletes the registration without delay, and then reports the fact to the Ministry of Government Administration and Home Affairs. Article 57 (Recommendations for improvement regarding registration and destruction) ① If the personal information protection manager of a public institution determines that the personal information file reviewed pursuant to Article 53 (1) is being excessively operated, he/she may recommend improvement. ② The personal information protection manager of the Office of Education, schools at each level, central administrative agencies and local governments, and other public institutions may recommend improvements if it is determined that the personal information files reviewed pursuant to Article 53 (2) and Article 53 (3) are being excessively operated, or if it is confirmed that there are unregistered files. ③ The Minister of Government Administration and Home Affairs may review the registration details and contents of the personal information file and, in any of the following cases, recommend improvements to the personal information protection manager of the relevant public institution pursuant to Article 32 (3) of the Act. 1. When it is judged that the personal information file is being used excessively 2. If there is an unregistered personal information file 3. If the personal information file is still retained despite the fact that the personal information file registration has been deleted 4. Even though you have a personal information file that has undergone a personal information impact assessment, the results are not included in the registration information. 5. If it is determined that there is a violation of registration and disclosure of personal information files pursuant to Article 32 of the Act. ④ If the Minister of Government Administration and Home Affairs recommends improvement pursuant to paragraph 3, the Minister of Government Administration and Home Affairs may announce the contents and results after deliberation and resolution by the Personal Information Protection Committee. ⑤ The Minister of Government Administration and Home Affairs may inspect the status of registration and destruction of personal information files of public institutions. Section 3 Management and disclosure of personal information files Article 58 (Preparation of personal information file ledger) Public institutions must create one personal information file ledger per personal information file. Article 59 (Management of use and provision of personal information files) In cases where a third party requests the use or provision of a personal information file pursuant to each subparagraph of Article 18 (2) of the Act, a public institution must check whether each use and provision is possible and record and manage it in the 'Ledger of Use and Provision of Personal Information for Other Purposes' in Form No. 6. Article 60 (Calculation of personal information file retention period) ① The retention period is the life cycle from collection to deletion of individual personal information, not entire personal information, and should be calculated as the minimum period that meets the retention purpose, and should be calculated according to the data retention period specified in individual laws and regulations. ② If a specific retention period is not specified in individual laws, it must be calculated through consultation with the person in charge of personal information protection and approval by the head of the institution. However, the retention period cannot exceed the standards presented in the personal information file retention period standard table in Annex 1 and the records management standard table pursuant to the Decree of the Public Records Management Act. ③ The external customer list for the purpose of publicity and public service of policy customers, website members, etc. may be kept continuously only if the data subject consents through the re-consent process every two years, except in special cases. Article 61 (Disclosure of personal information file status and methods) ① The person in charge of personal information protection at a public institution must periodically investigate the status of retention and destruction of personal information files and manage the results by including them in the personal information processing policy of the relevant public institution. ② The Minister of Government Administration and Home Affairs shall disclose the registration status of personal information files so that anyone can easily view them. ③ The Ministry of Government Administration and Home Affairs must compile and disclose the status of registration and deletion of personal information files of all public institutions every year. An information system can be established and operated to electronically process work related to status disclosure. Chapter 5 Supplementary Rules Article 62 (Exclusion of application of penalty provisions to social organizations) ① The penalty provisions of Article 75 (1) 1 of the Act, Article 75 (2) 1 of the Act, Article 75 (3) 7 and Article 75 (3) 8 of the Act shall not apply to personal information processors of social organizations. ② Penalty provisions, excluding those stipulated in paragraph 1, also apply to personal information processors of social organizations. Article 63 (Transitional measures regarding personal information being processed) ① If personal information is collected without any supporting laws and regulations before the enforcement of the Act, retention of such personal information shall be considered lawful processing. However, after the enforcement of this Act, in case of new processing of personal information, except for use within the scope of the existing collection purpose, the law, ordinance, enforcement regulations and these guidelines must be followed. ② Before the enforcement of the law, a personal information processor who receives personal information from a third party without the basis of law or the consent of the information subject and uses it for purposes other than the intended purpose must obtain the consent of the information subject. ③ Personal information processors who collected personal information before the enforcement of the Act may use the personal information collected before the enforcement of the Act for the purpose of obtaining new consent from the information subject in order to comply with the proviso to Paragraph 1 and Paragraph 2, notwithstanding the existing scope of collection purposes. Supplementary provisions Supplementary Provisions
This regulation comes into effect from the date of issuance.