「ENFORCEMENT DECREE OF THE ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK
UTILIZATION AND INFORMATION PROTECTION」
1. Where the basic operating system of mobile devices (referring to the based environment
in which the software can be executed in mobile devices; hereinafter referred to as
"operating system") is an operating system in which the users can individually choose
whether to consent to the access authority: A method by which, after the provider of
information and communications services informs the users about the both access
authorities under Article 22-2 (1) 1 and 2 of the Act separately from each other, the users
choose whether to consent when for the first time they access any information or
function the access authority for which is set;
2. Where the operating system of mobile devices is one by which the users cannot
individually choose whether to consent to the access authority: A method by which, after
the provider of information and communications services only sets the access authority
under Article 22-2 (1) 1 of the Act and informs the users thereof, the users choose
whether to consent to the access authority when they install the software;
3. Where the method referred to in subparagraph 1 or 2 is impossible though the
operating system of mobile devices is one referred to in subparagraph 1 or 2: A method
similar to one referred to in subparagraph 1 or 2, by which the provider of information
and communications services informs the users of the content of consent so that they
can definitely acknowledge such content and choose whether to give consent.
(3) When determining whether a matter requiring consent of the users pursuant to Article
22-2 (1) of the Act falls under any access authority under subparagraph 1 or 2 of that
Article, the following shall be taken into consideration: The extent of information and
communications services as disclosed through the terms of service, the privacy policy
prescribed in Article 30 (1) of the Personal Information Protection Act, or any separate
guidelines; whether such information and communications services are actually provided;
the users’ reasonable foreseeability for the relevant information and communications
services; and technical relevance between the relevant information and communications
services and the access authority, and other factors. <Amended on Aug. 4, 2020>
(4) Persons manufacturing and supplying the operating system of mobile devices,
manufacturers of mobile devices, and persons manufacturing and supplying software of
mobile devices shall take necessary measures according to the following classifications in
order to protect information on the users referred to in Article 22-2 (3) of the Act:
법제처
4
국가법령정보센터