South Korea's privacy regulator went through 220 banks, insurers, card issuers, savings banks and brokerages, and the resident registration numbers it found were being collected to do things like reset a password
Stock photo
Resetting a password should not cost you a national identity number. In South Korea it often did, and the regulator has now been through 220 financial companies taking those requests out.
The Personal Information Protection Commission published the result on Thursday morning in Seoul. It says it found resident registration numbers being processed with no basis in law, and that every case has been corrected. The account below is translated from the Korean release, and nothing in it is quoted directly for that reason.
What was checked, and where
The inspection ran from 1 April and covered six sectors: banks, life insurers, non-life insurers, credit card companies, savings banks and securities firms. Two hundred and twenty companies in total.
The commission was not looking at the transaction itself. Korean law requires financial firms to handle the number there, and the release names the Act on Real Name Financial Transactions and Confidentiality as the sort of legislation that does. What it went looking for was the habit that grew out of that requirement, in ordinary administration where no statute asks for anything.
Article 24-2 of the Personal Information Protection Act bans processing the number in principle, except where a law specifically allows it. The reason the commission gives is the obvious one and it is worth restating: the number identifies a person uniquely, it is hard to change, and a leak therefore does damage that lasts for years.
The three practices it names
None of them happen at a bank counter.
The first is a demand for the number when somebody signs up as a member for an online service that involves no financial transaction at all. The second is a demand for it in account administration, which the release illustrates with finding a lost identifier and resetting a password. The third is a demand for it when a customer registers or links a private digital certificate.
That third one comes with a footnote from the commission, and the footnote is the technical part of the story. Private certificates in Korea operate on connecting information, a per-service derived identifier, so the commission says it is hard to see the resident registration number as genuinely necessary to register or link one.
No fine, and that is the point of it
This was not an enforcement action. The instrument is a preventive inspection, under which a breach of the Act draws a corrective recommendation and a weakness short of a breach draws an improvement recommendation, and the commission states that where a company completed the necessary work itself, the file is closed with no separate disposition.
It follows something that was an enforcement action. On 11 March the commission sanctioned credit card companies for breaching the same article 24-2, and this sweep of the other five sectors was the follow-up to it.
The release names no company, in any of the six sectors, at any point. It was carried out jointly with the Korea Internet and Security Agency.
