Wednesday, September 16, 2026

FSC Moves to Refine Surcharge Calculation Framework Under Credit Information Act

Input
2026-09-16 11:00:00
Updated
2026-09-16 11:00:00
Provided by the Financial Services Commission (FSC)
[Financial News] The Financial Services Commission (FSC) is moving to further subdivide the surcharge assessment rates under the Credit Information Use and Protection Act, which are currently set at 100%, 75%, or 50% depending on the seriousness of the violation. Critics have continued to argue that the surcharge calculation criteria under the Act are excessive compared with those under the Personal Information Protection Act and similar systems overseas.
On the 16th, the FSC held a task force (TF) meeting at the Government Complex-Seoul of the Financial Services Commission to improve the surcharge calculation criteria under the Credit Information Use and Protection Act. The meeting was chaired by Yoo Young-jun, director of digital finance policy. Representatives from the Financial Supervisory Service, the Korea Federation of Banks (KFB), the Credit Finance Association, the Life Insurance Association of Korea, the General Insurance Association of Korea (GIAK), and the Korea Financial Investment Association attended to discuss the current system, its problems, and possible improvements.
Participants agreed on the need to improve the transparency and rationality of the criteria for calculating surcharges for violations of the Credit Information Use and Protection Act. They shared the view that assessments of the seriousness of violations should reflect the characteristics of the Act, including the nature and type of personal credit information, the number of data subjects, and the extent of damage. They also discussed subdividing the surcharge assessment rates so that penalties would be proportionate to the violations.
On the 9th, the FSC decided to impose a surcharge of approximately 7 billion won on Tongyang Life Insurance for violating the Credit Information Use and Protection Act. The decision represented a substantial reduction from the approximately 140 billion won surcharge calculated by the Financial Supervisory Service Sanctions Review Committee. In 2022, the Financial Supervisory Service found that Tongyang Life Insurance had provided customers’ personal credit information to its subsidiary general agency (GA) without their consent. The committee subsequently estimated the surcharge at around 140 billion won under the current provisions of the Act.
The FSC took into account that the information had been provided to a subsidiary GA rather than a third party, and excluded revenue unrelated to the case from the surcharge calculation. It also reflected the fact that the scale of the data exposure was not large compared with similar cases in the past.
An amendment to the Credit Information Use and Protection Act in February 2020 expanded the scope of surcharge violations from the leakage or disclosure of personal credit information to include improper provision, improper use, and the improper processing of pseudonymized information. The surcharge ceiling was also raised from 3% of relevant revenue to 3% of total revenue. However, critics have continued to point out that the current inspection and sanctions rules apply uniformly across all financial sectors and therefore fail to adequately reflect the characteristics of violations under the Act.
The inspection and sanctions rules focus mainly on general assessment factors, such as the motive and method of the violation, the amount of unjust gains, the scale of damage, the impact on the market, and the duration and frequency of the violation. By contrast, South Korea’s Personal Information Protection Act and the European Union (EU)’s General Data Protection Regulation (GDPR) incorporate various assessment factors that take into account the characteristics of personal information protection. This has led to criticism that the Credit Information Use and Protection Act is out of touch with reality because it imposes stricter surcharge calculations than the Personal Information Protection Act and similar European laws.
The Credit Information Use and Protection Act calculates surcharges based on total revenue and applies three surcharge assessment rates—50%, 75%, and 100%—uniformly, regardless of the size of the base amount. As a result, revenue not directly related to the violation may be included, making it difficult to calculate a surcharge proportionate to the violation. By comparison, the Personal Information Protection Act, the EU GDPR, and the Act on the Protection of Financial Consumers apply assessment rates of 1% to 30% or 0% to 10% for minor violations to ensure proportionality in sanctions.
The financial authorities stated, "To enhance the transparency and rationality of the surcharge calculation criteria under the Credit Information Use and Protection Act, we plan to promptly pursue amendments to the relevant regulations after gathering diverse opinions from the financial sectors and other stakeholders."

[email protected] Park Moon-soo Reporter