What's changed: Initial version
4.3Security-related Laws
Learn the Act on the Protection of Personal Information, which governs proper handling of personal data; the Unauthorized Computer Access Prohibition Act; the Act on Countermeasures for Information Distribution Platforms (formerly the Provider Liability Limitation Act), which addresses rights-infringing information online; the Basic Act on Cybersecurity, setting national cybersecurity policy; the Unfair Competition Prevention Act, protecting trade secrets; the Electronic Signature Act, preventing impersonation; and the Penal Code offense of obstructing business by damaging a computer.
SG tests not just the technical correctness of a control but also responses grounded in relevant law. Laws in this area are frequently revised, so it is important to remember current names and requirements accurately—in particular, note that the name once known as the Provider Liability Limitation Act has changed.
4.3.1The Personal Information Protection Act and the Unauthorized Access Prohibition Act
- The Act on the Protection of Personal Information requires businesses that handle personal information to specify and notify the purpose of use, implement safety-control measures, and restrict provision to third parties, among other obligations. If a breach of personal data occurs, under certain conditions the business is obligated to report it to the Personal Information Protection Commission and notify the affected individuals. When outsourcing the handling of personal data to a supplier, the outsourcing party is obligated to exercise necessary and appropriate supervision over the supplier.
- The Unauthorized Computer Access Prohibition Act bans unauthorized access—logging into an access-controlled system by using someone else's ID/password without authorization—as well as acts that facilitate it, such as illegally acquiring, storing, or providing to a third party an ID/password. Importantly, the act is illegal at the point access control is bypassed and login succeeds, even if no actual damage has occurred yet.
4.3.2The Act on Countermeasures for Information Distribution Platforms and the Basic Act on Cybersecurity
- The Act on Countermeasures for Information Distribution Platforms is designed to make it easier for victims of online rights infringement (defamation, etc.) to request removal of a post and disclosure of the sender's identifying information from large-scale platform operators such as SNS providers; it was formerly called the Provider Liability Limitation Act. A feature of the current law is the strengthened obligation for large platform operators to respond promptly and disclose their operational status.
- The Basic Act on Cybersecurity sets out the basic principles for the nation's overall cybersecurity measures, clarifies the responsibilities of the national government, local governments, critical infrastructure operators, and others, and establishes the framework for formulating a cybersecurity strategy. Unlike laws that define specific prohibited acts (such as the Unauthorized Computer Access Prohibition Act), it should be understood as a basic law defining the nation's overall structure and policy.
4.3.3The Unfair Competition Prevention Act, the Electronic Signature Act, and the Penal Code
- The Unfair Competition Prevention Act prohibits the unauthorized acquisition, use, or disclosure of a company's trade secrets (information meeting the three requirements of secrecy management, usefulness, and non-public knowledge), and lets the victimized company seek an injunction and damages. It comes up in cases such as a departing employee taking a customer list or technical information—information exfiltration by an insider.
- The Electronic Signature Act grants electronic signatures meeting certain requirements the same legal effect as a handwritten signature or seal (a presumption of authentic formation), providing the legal basis for preventing impersonation and tampering when digitizing contracts. The Penal Code offense of obstructing business by damaging a computer punishes destroying or tampering with a computer or its data in a way that obstructs business. System destruction via malware infection or business obstruction through data tampering can fall under this Penal Code provision in addition to the Unauthorized Computer Access Prohibition Act.
The staples: the Provider Liability Limitation Act is now called the Act on Countermeasures for Information Distribution Platforms; unauthorized access is illegal the moment access control is bypassed, regardless of actual damage; the three requirements of a trade secret (secrecy management, usefulness, non-public knowledge); and the Basic Act on Cybersecurity sets the nation's basic principles and structure, not individual prohibited acts. You are expected to judge by the current law's content even if a question uses an old name.
Consider a compound incident at mid-size chemical maker E to organize how these laws apply. Shortly before leaving the company, a former researcher at E copied manufacturing-process data meeting the requirements of secrecy management, usefulness, and non-public knowledge (a trade secret) onto a personal USB drive without authorization, taking it to a new employer and using it there. E judged this to fall under trade-secret infringement under the Unfair Competition Prevention Act and considered seeking an injunction and damages against both the former researcher and the new employer. During the investigation, it also emerged that after leaving, the former researcher had used a former colleague's ID and password without authorization to log into E's internal system multiple times. Although the researcher had only viewed data without tampering with it, the moment access control was bypassed and login succeeded, a violation of the Unauthorized Computer Access Prohibition Act was established. Furthermore, this incident spread on social media in posts containing defamatory claims that "Company E is careless with information management"; for the factually false, defamatory portion, E requested the relevant SNS operator to remove the post and disclose the sender's identifying information under the Act on Countermeasures for Information Distribution Platforms. Meanwhile, throughout this response, E's IT department also participated in measures under the Basic Act on Cybersecurity, the nation's cross-industry cybersecurity policy framework (such as information-sharing arrangements for critical infrastructure operators), giving it a concrete sense of how individual incident response (the Unfair Competition Prevention Act, the Unauthorized Computer Access Prohibition Act, the Act on Countermeasures for Information Distribution Platforms) and the nation's overall basic policy (the Basic Act on Cybersecurity) function in parallel as distinct layers of law.
| Law | What it protects/regulates | Key point |
|---|---|---|
| Act on the Protection of Personal Information | Personal information/data | Breach requires reporting to the commission and notifying individuals |
| Unauthorized Computer Access Prohibition Act | Access-controlled systems | Illegal the moment login succeeds, even without damage |
| Act on Countermeasures for Information Distribution Platforms | Rights-infringing information online | Formerly the Provider Liability Limitation Act; removal/disclosure requests |
| Unfair Competition Prevention Act | Trade secrets | Three requirements: secrecy management/usefulness/non-public knowledge |
Trap: the name "Provider Liability Limitation Act" has been renamed to the Act on Countermeasures for Information Distribution Platforms under the current syllabus, so choosing the old name alone as the correct answer is wrong. Also, "the Unauthorized Computer Access Prohibition Act only becomes applicable once data has actually been stolen or tampered with" is wrong—it is already illegal the moment access control is bypassed and login succeeds. Furthermore, "the Basic Act on Cybersecurity directly punishes individual acts of unauthorized access" is wrong—individual prohibition/punishment provisions belong to the Unauthorized Computer Access Prohibition Act and the Penal Code, while the Basic Act on Cybersecurity defines the nation's overall basic principles and structure.
4.3.4Section summary
- "Provider Liability Limitation Act" -> now the Act on Countermeasures for Information Distribution Platforms. The Unauthorized Computer Access Prohibition Act applies the moment login succeeds, even without damage
- Unauthorized acquisition/use of information meeting the three trade secret requirements (secrecy management/usefulness/non-public knowledge) violates the Unfair Competition Prevention Act
- The Basic Act on Cybersecurity defines the nation's overall basic principles and structure, a role distinct from laws defining individual prohibited acts
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Under the current syllabus, which law provides the basis for a victim of anonymous online defamation to request an SNS operator to remove a post and disclose the sender's identifying information?
Q2. A departed employee used another person's ID and password without authorization to log into the internal system, only viewing data without tampering with it. Which statement about this act is most accurate?
Q3. An employee about to leave the company took process data meeting the requirements of secrecy management, usefulness, and non-public knowledge without authorization and used it at a new employer. Which law provides the basis for the victimized company to seek an injunction and damages?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

