MIC Guidelines - Mandatory Secure Server (SSL) Implementation; SSL has been applied to anjpat.com.
MIC (Ministry of Information and Communication) Guidelines - Mandatory Secure Server (SSL) Implementation
Sites Required to Implement a Secure Server
- All websites that handle personal information are required to implement a secure server.
- Even if a website does not collect personal information through membership registration, if it has users enter personal information during payment, bulletin board use, ordering, or consultation, that website must implement a secure server.
Regulations Concerning Encryption When Transmitting Personal Information
1. Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.
- Article 28 (Protective Measures for Personal Information) When handling users' personal information, an information and communications service provider, etc. shall take the technical and managerial measures necessary to ensure safety, as prescribed by Ordinance of the MIC, so that personal information is not lost, stolen, leaked, altered, or damaged.
- Article 67 (Administrative Fines) A person falling under any of the following shall be subject to an administrative fine not exceeding 10 million won.
Item 8-2. A person who fails to take the technical and managerial measures in violation of Article 28.
2. Enforcement Rule of the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.
- Article 3-2 (Protective Measures for Personal Information) The technical and managerial measures necessary to ensure the safety of personal information under Article 28 shall be as follows. (Portion omitted)
4. Security measures using encryption technology, etc. that can safely store and transmit personal information (remainder omitted)
3. Standards for Technical and Managerial Protective Measures for Personal Information
- Article 5 (Encryption of Personal Information) When an information and communications service provider, etc. transmits a resident registration number, password, or personal information that the user has not consented to disclose, outside the information and communications network protected under Article 3(4), or stores it on a PC, it shall encrypt such information.
—————————–
Following the enforcement of mandatory secure server implementation and the amendment of the relevant laws, administrative fines will be imposed for violations!!
As incidents of personal information leakage continue to occur, the relevant laws and government investigations are being strengthened.
In particular, the implementation of a secure server is now legally mandatory for websites that handle personal information, such as those with membership registration and login. After the amended enforcement on August 18 of this year, a fine of up to 30 million won will be imposed without prior warning on websites that have not implemented a secure server, so we ask all customers to take action promptly.
Targets for Secure Server Certificate (SSL) Implementation
SSL must be applied to all websites that handle personal information.
Most people recognize only resident registration numbers as personal information, but if email addresses and mobile phone numbers are also handled during payment, bulletin board use, ordering, and consultation, the site becomes subject to mandatory SSL installation and inspection, so an SSL certificate must be installed.
Relevant Statutes
http://www.law.go.kr/lsInfoP.do?lsiSeq=123210&efYd=20120818#0000