Skip to main content Skip to global navigation Skip to footer content

Other

Privacy Policy

Privacy Policy of KoFIU

KoFIU abides by the Personal Information Protection Act (hereinafter referred to as the PIPA) and its relevant statutes to protect the freedom and rights of individuals and to manage personal information in a legitimate and secure manner. Pursuant to Article 30 of the PIPA, KoFIU informs the data subject of the process and standards for personal information management. For efficient and smooth information management and the handling of relevant matters, the privacy policy of KoFIU has been established and disclosed as follows.

  1. 1) Purpose of the Collection and Use of Personal Information
    KoFIU collects and uses personal information strictly for the purposes described below. The collected information will not used for any other purpose. If the purpose of collection is modified, necessary measures, including obtaining separate consent, will be taken pursuant to Article 18 of the PIPA.

    ㅇ Prevention of Illegal Financial Transactions and Money Laundering
    - KoFIU collects and analyzes Suspicious Transaction Reports (STR) and Currency Transaction Reports (CTR) pursuant to Articles 4 and 4-2 of the Act on Reporting and Using Specified Financial Transaction Information (hereinafter referred to as the FTRA), with a view to establishing a sound and transparent financial order and preventing related criminal activity that abuse financial transactions.

    ㅇ Dissemination of Information to Law Enforcement Agencies, etc.
    - Pursuant to Article 10 of the FTRA, KoFIU disseminates the results of the analysis of STRs and CTRs to the related law enforcement agencies, including the Public Prosecutors’ Office, the National Policy Agency, the National Tax Service, and Customs Service.
  2. 2) Period for Retaining and Using Personal Information

    1. Personal Information Processed without the Consent of a Data Subject


    Pursuant to Articles 10-2 and 12-2 of the FTRA, KoFIU retains and uses personal information during the period specified below.

    Pursuant to Articles 15-1(2) and (3) of the PIPA, KoFIU collects and uses personal information without the consent of the data subject.


    Period for Retaining and Using Personal Information
    Purpose Information collected Retention
    Period
    Matters related to Specified Financial Transactions Information referred to in Articles 4 (Report on Suspicious Transaction such as Illicit Property, etc.), 4-2 (Currency Transaction Report filed by Financial Institutions, etc.), and 11-1 (Information Exchange with Foreign FIUs) 25 years
    Information referred to in Article 5-3(2) (Provision of Wire Transfer Information), 9 (Notification of Foreign Exchange Transaction Data), and 13(1), (2), and (3) (Request for Provision of Data) 5 years
    Information referred to in Article 15(7) (Supervision and Inspection, etc. of Financial Institutions, etc.) 10 years
    Information referred to in Article 10-2(4) (Notification of Provision of Specified Financial Transaction Information), Connecting Information (CI) for providing an electronic notification service pursuant to Article 23-5(1) (Generation and Processing of Connecting Information, etc.) of the Network Act (Act on Promotion of Information and Communications Network Utilization and Information Protection) Until Close of Business

    2. Personal Information Processed upon the Consent of the Data Subject


    Period for Retaining and Using Personal Information
    Purpose Information collected Retention
    Period
    Sign up ID, Password, Name, Position, Date of Appointment, Phone Number, Mobile Number, Email Address (optional) Until Suspension of Operation

  3. 3) Registration of Personal Information Files
    KoFIU manages personal information files in a confidential and closed manner, pursuant to FTRA Article 12 (Confidentiality of Financial Transaction Information) and PIPA Article 32-2(5) (Registration and Disclosure of Personal Information File), and does not register any personal information files.
  4. 4) Destruction of Personal Information

    1. KoFIU destroys personal information without delay when the personal information becomes unnecessary owing to the expiry of the retention, the attainment of the purpose of information collection, etc., in accordance with the PIPA and FTRA.


    2. Despite the retention period having expired or the purpose of collection being completed, where it is necessary to preserve personal information pursuant to other laws and regulations, such personal information (or personal information file) is stored and managed in either a separate database or another place of storage.


    3. In compliance with Article 21 of the PIPA, the process and method for destroying personal information are as follows


    • ㅇ Destruction Process
      • - KoFIU identifies personal information that needs to be destroyed and destroys such personal information upon the approval of KoFIU’s Personal Information Officer.
    • ㅇ Destruction Method
      • - KoFIU takes appropriate measures to destroy electronically written or stored information to prevent the recovery and revival of such information, and destroys information written or stored in paper documents by shredding or burning.
  5. 5) Outsourcing of Collected Information Processing

    1. For the seamless management of personal information, KoFIU entrusts collected information to the following entities.


    Outsourced service Outsourcee
    Operation and Maintenance of KoFIU Information System KCC I&C
    ALLFORLAND
    Mobile/Electronic Notification Service KT
    Kakao

    2. Pursuant to Article 26 of the PIPA, KoFIU specifies obligations on (i) the prohibition of personal information processing for purposes other than the outsourced duties, (ii) technical and managerial safeguards, (iii) the restriction on re-outsourcing, (iv) management and supervision over the outsourcees, (v) liability for damages (such as compensation), etc., in written documents such as contracts, upon concluding agreements, and supervises outsourcees to ensure they safely manage personal information.


    3. Where an outsourcee re-outsources the personal information processing work, the outsourcee obtains approval from KoFIU pursuant to Article 26-6 of the PIPA, and discloses the details of the re-outsourced work and re-outsourcee(s) in this privacy policy.


    4. KoFIU will notify the data subject of any changes made to the outsourced work or the outsourcees without delay in this privacy policy.

  6. 6) Measures taken to Secure Personal Information Safety
    KoFIU is taking the following measures to ensure that the collected personal information is securely retained

    ㅇ Managerial Measures: Establishment and implementation of an internal control plan, regular staff training, and periodical self-inspections.
    ㅇ Technical Measures: Management of access to the personal information processing system, installation of an access control system, blocking of the internet network, encryption of personal information, storage and monitoring of access logs, and installation, operation, and update of security programs.
    ㅇ Physical Measures: Access control to computer/data centers and archives, storage of documents and auxiliary storage devices in a safe place with locks, weatherproofing measures against disasters and accidents, auxiliary storage device in/out control.
  7. 7) Installation, Operation, and Rejection of Automatic Information Collection System
    KoFIU does not run ‘cookies’ that store and uses user information.
  8. 8) Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise such Rights

    1. A data subject may exercise his or her rights at any time to request access to, correction, deletion of, suspension of processing, and withdrawal of personal information (hereinafter referred to as “exercise of a right”).


    2. The exercise of a right can be made through written documents, electronic mails, fax, etc., pursuant to Article 41-1 of the PIPA, and upon receiving a request, KoFIU will take appropriate measures without delay.


    3. Such rights may be exercised by a proxy such as a legal representative or an authorized person, on behalf of the data subject. To do so, the proxy must submit a power of attorney using the template in Appendix 11 of the “Notification on Personal Information Processing (No. 2025-5)”.


    4. Where other legislation stipulates that personal information is subject to collection, requests for the correction or deletion of such information shall not be made.


    5. KoFIU verifies the identity of the person who exercises such rights or the legitimacy of his or her legal representative.


    6. A data subject’s right to request access or suspension of processing may be limited in accordance with Articles 35-4 and 37-2 of the PIPA.

    Grounds for limiting or denying access (PIPA Article 35-4)
    • 1. Where access is prohibited or limited by statues
    • 2. Where access may cause damage to the life or body of a third party, or unjustified infringement of property and other interests of any other person
    • 3. Where a public institution has grave difficulties in performing any of the following duties
      • a. Imposition, collection or refund of taxes
      • b. Evaluation of academic achievements or admission affairs at the schools of each level established under the Elementary and Secondary Education Act and the Higher Education Act, lifelong educational facilities established under the Lifelong Education Act, and other higher educational institutions established under other statutes
      • c. Testing and qualification examination regarding academic competence, technical capability and employment
      • d. Ongoing evaluation or decision-making in relation to compensation or grant assessment
      • e. Ongoing audit and examination under other statues
    Grounds for Rejecting Suspension of Processing (PIPA Article 37-2)
    • 1. Where special provisions in other laws so require or it is inevitable to observe legal obligations
    • 2. Where access may cause damage to the life or body of a third party, or unjustified infringement of property and other interests of any other person
    • 3. Where the public institution cannot perform its work as prescribed by any Act without processing the personal information in question
    • 4. Where it is impracticable to perform a contract such as the provision of services as agreed upon with the said data subject without processing the personal information in question, and the data subject has not clearly expressed the desire to terminate the agreement.
  9. 9) Personal Information Officer and Competent Department

    1. To ensure the comprehensive accountability of personal information and to handle related complaints and damage remedies, KoFIU has designated a personal information officer as follows

    Personal Information Officer
    - Name :
     Jooyoung Park
    - Position :
     Director General
    - Contact :
     (Tel)  (Tel) 02-2100-1733
    Personal Information Department (in charge of responding to personal information access requests)
    - Office :
     Planning & Administration Office
    - Contact :
     (Tel) 02-2100-1758
     (E-mail) kofiuinfo@korea.kr
     (FAX) 02-2100-1738

    2. Any individual can make inquiries to the competent department or personal information officer regarding all matters related to personal information protection, complaints, remedies for damages, etc., which may arise from using KoFIU’s services. KoFIU will respond to and address your request without delay.

  10. 10) Remedies from Information Infringement

    1. A Data Subject may seek conflict resolution or counseling from the Personal Information Dispute Mediation Committee and the Personal Information Infringement Report Center of the Korea Internet & Security Agency (KISA) for redress. For other reports or counseling regarding privacy breaches, please contact the following agencies.



    2. Where anyone suffers an infringement of rights or interests owing to any disposition or omission by head officials of public agencies regarding requirements under PIPA Articles 35 (Access to Personal Information), 36 (Correction or Erasure of Personal Information), and 37 (Suspension of Processing of Personal Information), he or she may file an administrative appeal for remedies as prescribed by Administrative Appeals Act.


  11. 11) Revision of Privacy Policy
    • This privacy policy enters into effect from August 2026.
    • Previous privacy policies can be found below.
feedback

We are pleased to hear your feedback on this website.
How satisfied are you with the information provided from us?