[Photo: Shutterstock]

[DigitalToday reporter Chi-kyu Hwang (황치규)] A personal data transfer demand system that was already put up for legislative notice in June last year and then announced for implementation in February this year, followed by a grace period of more than six months, has emerged as an issue as the grace period nears its end.

An amendment to the Personal Information Protection Act imposes an obligation on personal data handlers above a certain size to transmit personal information to the data subject or an authorised representative upon request. Ahead of the rollout, talk spread that transfers via scraping, which had been allowed so far, would be blocked, fuelling controversy mainly in the fintech industry.

The dispute spread further after the Supreme Court announced it would fully block unauthorised scraping of court servers, including by financial institutions, from websites starting on the 20th.

Scraping refers to a technique in which a computer program automatically extracts and collects needed data from a website or another system. It is used to quickly and accurately retrieve large amounts of information through software without a person manually copying and pasting with a mouse.

It involves a representative logging into an institution's system using a user's ID and password or authentication information and retrieving the data, and it has been used in a range of fields. It has the advantage of enabling convenient and fast service development, but it has also drawn criticism for security risks, such as entrusting authentication information to a third party or potentially accessing personal data beyond what is needed.

Because it has been used so widely, notices that websites would block scraping triggered a significant reaction in the industry. The court has since said it would temporarily postpone the proposed measure.

According to the Personal Information Protection Commission, the personal data transfer demand right system is not designed to block scraping at its source. Its focus is not on blocking scraping but on requiring prior consultation with the party that must transmit the data if a firm wants to use scraping, and on shifting in the mid to long term from scraping to an API method that is safer from a security standpoint.

To obtain user information via scraping, service providers must first consult with the institution holding the information from Aug. 20 for public agencies and from Feb. 20 next year for private companies. The commission is pursuing a phased transition that can temporarily allow existing scraping in an agreed form when prior consultation has been completed, considering the reality that it is difficult to build public-agency APIs immediately.

The commission says the core of the system is not to uniformly prohibit scraping but to make the process of moving personal data safer.

It says that when requesting the transfer of personal information from public agencies or private companies on behalf of users, if automated tools such as scraping are used, transfers must follow the method agreed in advance, and that this does not mean scraping itself is being blocked.

Prior consultations include the scope of transfer items, how to verify whether a requester is a representative, how automated tools access systems and the level of authentication, and protective measures by the representative.

According to the commission, scraping through prior consultation is step 1 under the personal data demand policy. It says it adopted scraping with prior consultation to reduce market confusion, but has stressed that it ultimately aims to build an environment in which personal data transfers are carried out not through scraping but through an API-based method that is safer from a security standpoint. It has said an unrestricted scraping practice carries high risks of information leakage and misuse, including excessive data collection, and that a transition is needed for safe use of information, with APIs the alternative.

According to the commission, personal data transfer is similar to a process in which, on the assumption that an apartment management office is responsible for the security and protection of items inside a household, items stored in an apartment (a public agency) are delivered through a courier (a representative).

Existing scraping can be likened to a courier entering a unit directly using the unit password (authentication information) provided by the head of the household and taking the parcel to be sent. The courier could intentionally or inadvertently take other items from the home, and there is also a risk that the password could be leaked to a third party. Another security weakness is that the apartment management office does not know the fact of the courier's visit, its purpose or the contents.

Agreed scraping through prior consultation is an administratively managed method tailored to each apartment's circumstances. Examples include allowing entry into a household after verifying a courier's identity, or designating a specific common area to support temporary storage of items.

An API can be compared to creating unattended parcel lockers for each household to use, while the management office focuses on maintaining and managing the facilities.

The commission says it has repeatedly stressed the need for prior consultation with public agencies to overhaul indiscriminate scraping practices over about a year around the period of the legislative notice. It says it has informed companies and institutions across sectors of methods and procedures for representative transfer demands through public briefings for all fields, field-by-field and sector-by-sector meetings, and individual meetings. In June it also distributed a guide to the all-field MyData personal data transfer demand right system.

To address entry barriers from companies having to consult individually with public agencies, the commission also ran a pilot programme twice from June 25 to the end of July to support prior consultations between public agencies and representatives. In the first round, about 150 cases were submitted by about 70 institutions, and in the second round about 550 cases were submitted. For institutions that applied for prior consultation, a grace measure applies allowing them to maintain the current method until consultation is completed.

Even so, it is said that not a few companies that obtained user information from public agencies via scraping did not go through prior consultation. The commission is said to have notified the changes in its own way, but there were also many that remained unaware and did nothing.

Against that backdrop, the implementation of the system for public agencies on the 20th is approaching, and the court also issued a notice that it would block scraping on court websites, spreading controversy among companies. The commission decided to accept third-round applications from the 11th to the 31st to support prior consultation for representatives under the personal transfer demand system.

Taken together, the personal data transfer demand right system is in a transitional period. It appears it will take considerable time for the commission's final goal of API-based transfers to take hold. For public agencies, building an API is not mandatory, so if demand is not confirmed, they could be reluctant to build an API environment proactively. The commission says it expects more public agencies to move to build API systems if prior consultations indicate strong demand for personal data transfers.

Keyword

#Personal Information Protection Commission #scraping #API #Supreme Court #Personal Information Protection Act
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.