[비즈한국] As laws and regulations regarding personal information are strengthened, government sanctions against companies that reveal weaknesses in managing customer data are becoming increasingly severe. Kakao035720, which was hit with the largest fine in South Korean history this past May for violating the Personal Information Protection Act, has once again found itself at the center of controversy. This follows the Financial Supervisory Service (FSS) initiating sanction procedures over findings that Kakao Pay377300 provided customer credit information to China's Alipay without authorization. While "slap-on-the-wrist" punishments for violations are trending toward improvement, critics point out that even companies whose core business relies on customer data are responding complacently to these regulatory changes.

"Normal Outsourced Business" vs. "Third-Party Provision Lacking Separate Consent"
The positions of the FSS and Kakao Pay are sharply divided over the fact that Kakao Pay provided personal credit information to Alipay for Apple App Store payment services without customer consent. While the FSS views this as a "third-party provision," Kakao Pay argues that it was an operational information transfer for which customer consent was unnecessary from the start.
During an on-site inspection conducted between May and July of this year, the FSS identified that from April 2018 for approximately six years, Kakao Pay provided 54.2 billion instances of personal credit information—including Kakao account IDs, phone numbers, email addresses, subscription history, and Kakao Pay transaction history (top-ups, withdrawals, payments, transfers, and balances) for a total of 40.45 million users—to Alipay.
When Kakao Pay claimed via an explanatory document that it was merely an "information transfer between a principal and a contractor," the FSS issued a press reference document to actively rebut the claim. The intense debate over logic stems from the fact that the contractual relationship between the two companies and the original purpose of the information provision are the core issues determining illegality. Under relevant laws, when information is transferred for outsourcing, customer consent is not required and can be substituted with notification; however, in the case of third-party provision, a separate customer consent procedure is mandatory. In an outsourcing relationship, the transferred information is used solely for the contractor (Alipay) to process tasks on behalf of the principal (Kakao Pay). If the information is used for the purposes of the recipient (Alipay), it is unrelated to the original purpose of collection and therefore requires separate consent.
FSS Claims No Evidence of "Credit Scoring Outsourcing Contract"
Some view the process of distinguishing between outsourcing and third-party provision in this case as relatively clear. Choi Kyung-jin, a professor of law at Gachon University, explained, "Outsourcing agreements follow a standardized tool. If the contract between Kakao Pay and Alipay is similar to other outsourcing contracts Kakao Pay has signed with domestic companies, it could be considered outsourcing. Conversely, if there are differences in the contract content, it contradicts Kakao Pay's claims."

Financial authorities have determined that Kakao Pay's unauthorized provision of customer credit information is evident based on the contracts between the two companies. The FSS stated, "After reviewing all nine contracts signed between Kakao Pay and Alipay, there is absolutely no content stating that Kakao Pay entrusted Alipay with 'NSF score (credit score) calculation and provision tasks.'" The facts that entry into the Apple App Store benefits both companies, that the information transfer serves the interests of both Kakao Pay and Alipay, and that Kakao Pay has never managed or supervised Alipay as a principal are also grounds for the FSS to view Kakao Pay’s handling of credit information as illegal.
In an outsourcing relationship, the principal has a duty to manage and supervise the contractor. However, in the case of third-party provision, the entity is only responsible for ensuring the information is provided through legal procedures, and the recipient bears the duty of management and supervision. Furthermore, even if an outsourcing contract exists, the issue could become even more complex if it is proven that Alipay processed the information for its own interests.
The appropriateness of the scope of information provided to Alipay is also a key issue. In its explanatory document, Kakao Pay drew a line, stating, "When providing information to Alipay, we applied an encryption method that changes it into random codes, effectively anonymizing it so that it cannot be used for any purpose other than fraud detection." As the investigation is currently ongoing, Kakao Pay has refrained from further responses after releasing its explanation and is focusing on providing clarifications to the authorities.
Despite Stricter Personal Information Sanctions, Companies Remain Stagnant
The information Kakao Pay transferred to Alipay is "pseudonymized information" that has been processed to prevent the identification of content. Pseudonymized information has low identifiability when complex encryption is applied, but it poses safety risks if the original data can be determined by combining multiple sets of information. In 2016, the "Personal Information De-identification Guidelines," which allowed for non-purpose provision if de-identified, became effectively obsolete after backlash from civic society. Subsequently, the country went through trial and error to establish concepts, such as the implementation of the "Data 3 Laws," which classify pseudonymized information as personal information. The pseudonymized information system, introduced in August 2020 to foster the data industry, defines such data as personal information subject to the Personal Information Protection Act and dictates different management and usage rules depending on whether it is considered outsourcing or third-party provision.

Considering the recent trend of increasing sanctions on private companies regarding personal information, it is predicted that Kakao Pay may face heavy fines. Financial authorities believe Kakao Pay violated both the Personal Information Protection Act and the Credit Information Act. Under the previous Credit Information Act, fines for violations were capped at "3% of related revenue" from the year the incident occurred. However, with the amended law implemented last September, the scale of fines was significantly expanded to a cap of "3% of total revenue" for that year. Previously, in May, Kakao was hit with a fine of 15.1496 billion won for violating safety obligations regarding user information in open chat rooms. Although the pre-amendment law was applied, it was the largest fine in history. As the arguments of both sides sharply conflict, even after the level of sanctions is determined, it could lead to legal battles. It is expected that a final conclusion may take several years.
Within and outside the industry, voices are criticizing the slow response of companies that fail to keep up with institutional changes. One expert pointed out, "When providing data to Alipay, 'overseas transfer' rules apply, requiring additional separate consent. In terms of public sentiment, there is a general aversion to information being transferred abroad—especially to companies in China—compared to processing by domestic companies. This pressure may have played a role." However, the expert added, "Since these are acts that could even lead to criminal punishment, I believe the possibility of intentional omission is low. It is a case that demonstrates a low level of awareness regarding personal information protection and handling."
Voices in civil society have also pointed out institutional limitations. The Citizens' Coalition for Consumer Sovereignty emphasized, "It is difficult to view Kakao Pay's personal credit information leakage as solely their problem," adding, "Despite endless personal information leakage incidents occurring in various fields recently, there are no clear measures to prevent recurrences or stern, warning-like sanctions." There is also a view that while sanctions for negligence in personal information management are being strengthened, the government's policy direction regarding personal information remains ambiguous. Oh Byung-il, representative of the Progressive Network Center, noted, "Companies try to minimize the scope of personal information and their obligations, and the government also tends to seek lenient interpretations while considering industrial aspects."