Personal Information Handling Policy

KEB Hana Bank protects the personal information and rights of its customers in accordance with Article 30 of the Personal Information Protection Act and Article 27, Section 2 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, and the following policies have been established to process customer complaints with respect to personal information.

Article 1 (Purpose of Use of Personal Information)

※ KEB Hana Bank processes personal information for the purposes prescribed in the following paragraphs. Processed personal information is not used for any purpose other than those prescribed, and KEB Hana Bank shall seek consent for any changes to the purpose of use.

(Financial) Transaction Relationship

  • Personal information is processed in relation to (financial) transactions for the purposes of inquiring about personal credit information held by credit information agencies or public credit registries; determining whether (financial) transaction relationships have been set; setting, maintaining, implementing, and managing (financial) transaction relationships; financial incident investigations; dispute resolutions; complaint handling; and statutory obligations.
  • The term 'transaction' refers to any (financial) transactions related to banking (loan, deposit, currency exchange, etc.), cross-ownership (fund, trust, derivative product, bancassurance, credit card, etc.), and ancillary (factoring, guarantee, collection/payment agency, safe deposit box, sales commission vouchers, etc.) services.

Product and Service Marketing and Solicitation

  • Personal information is processed for statistical purposes in relation to the usage of services by customers including developing new services and providing personalized services through customer satisfaction surveys; providing services and advertising according to demographic characteristics; verifying the effectiveness of services; awarding of prizes; providing appreciation and promotional events; and identifying frequency of service access.

Membership Registration and Management

  • Personal information is processed for the purposes of membership registration; usage of membership-based services; limited identification of persons; personal identification; prevention of fraudulent and unauthorized use; confirmation of registration intent; verification of consent by a legal representative for customers under the age of fourteen (14); identification of legal representatives; incident investigation; dispute resolution; complaint handling; and delivery of notices.

Online Transaction-Related Purposes

  • Personal information is processed for the purposes of tracking and retrieving electronic financial transaction information and utilizing statistics for establishing security policies in accordance with Articles 21 and 22 of the Electronic Financial Transactions Act.

Article 2 (Processing and Retention Period of Personal Information)

※ Personal (credit) information related to (financial) transactions shall be retained and used for the above purposes from the date of consent for the collection and use of information until the final date of financial transaction. After the final date of financial transaction, the information shall only be retained and used for the purposes of financial incident investigation, dispute resolution, complaint handling, statutory obligations, and risk management of KEB Hana Bank.

※ Personal (credit) information collected for the purpose of inquiring such information shall be retained and used from the date of consent for the collection and use of information until the duration specified in the respective agreement. Upon expiration of any such agreement, the information shall only be retained and used for the purposes of financial incident investigation, dispute resolution, complaint handling, and statutory obligations.

※ Personal (credit) information related to the promotion and solicitation of products and services shall be retained and used from the date of consent for the collection and use of information until the withdrawal of consent. Upon withdrawal of consent, the information shall only be retained and used for the purposes of financial incident investigation, dispute resolution, complaint handling, and statutory obligations as prescribed in Article 1.

※ Personal (credit) information collected for the purposes of membership registration and management shall be retained and used from the date of registration until termination of membership. Upon termination, the information shall only be retained and used for the purposes of financial incident investigation, dispute resolution, complaint handling, and statutory obligations as prescribed in Article 1.

※ Personal (credit) information related to online transactions shall be retained and used for the period prescribed under Article 12 of the Enforcement Decree of the Electronic Financial Transactions Act.

Article 3 (Provision of Personal Information to Third Parties)

※ KEB Hana Bank shall only process the personal information of customers within the scope specified in Article 1 and shall not provide said information to third parties or process the information beyond the specified scope without the customer's prior consent. However, KEB Hana Bank may provide personal information to third parties or use the information for purposes other than those specified except when such actions are likely to unduly infringe upon the interests of the customers or third parties.

  • If a customer has agreed in advance to the disclosure and provision of information to third parties.
  • If there are special provisions in other laws and/or regulations.
  • If a customer or his/her legal representative is incapable of clearly declaring his/her will; or consent cannot be obtained due to an unknown address; or if deemed obviously necessary for the immediate interests of a customer or a third party's life, health, or assets.
  • If providing personal information in an aggregated form for purposes such as the creation of statistics or a scientific study.

※ KEB Hana Bank provides personal information as prescribed in the following paragraphs. For more information, visit the KEB Hana Bank website > Personal Information Processing (Handling) Policy > Status of Provision of Personal (Credit) Information.

Collecting Agencies

Provision of Information to Public Credit Registries and Credit Information Companies

  • Public Credit Registries: [Korea Federation of Banks; The Credit Finance Association; etc.]
  • Credit Information Companies: [Seoul Credit Rating and Information, Inc.; Korea Credit Bureau; NICE Information Service; etc.]

Provision to Affiliates

Affiliates: [SK Telecom; LG U+; etc.]

Purpose of Information Use by Collecting Agencies

Provision of Information to Public Credit Registries and Credit Information Companies

  • Used as data for determining a customer's credit standing or used as data for policy by a public institution.

Provision to Affiliates

Marketing and solicitation of partner products and services.

Types of Personal Information Provided

Provision of Information to Public Credit Registries and Credit Information Companies

  • Personally identifiable information (PII), credit transaction information, creditworthiness information, and information for determining credit rating.

Provision to Affiliates

Personally identifiable information (PII); (financial) transaction information; information described in a transaction application other than PII; or information provided by the customer.

※ Includes personal (credit) information collected prior to providing consent.

Personal Information Retention Period

Personal (credit) information shall be retained and used from the date of provision until the withdrawal of consent or achievement of the given objectives. Upon withdrawal of consent or achievement of the given objectives, the information shall only be retained and used for the purposes of financial incident investigation, dispute resolution, complaint handling, and statutory obligations with respect to the above purposes.

Article 4 (Consignment of Personal Information Processing)

※ KEB Hana Bank consigns the processing of personal information as prescribed in the following paragraphs upon a customer's consent. For detailed information, go to the KEB Hana Bank website > Personal Information Processing (Handling) Policy > Consignment of Personal (Credit) Information.

Trust Company

Affiliates that establish, maintain, implement, and manage (financial) transactions: [Mirae Credit Information Services Corp.; Seoul Credit Rating and Information; Doore Seeing; Korea Employment Information Service; IB Career; etc.]

Research firms that perform compliance telemarketing, customer service calls, and customer satisfaction surveys: [Korea Employment Information Service, etc.]

The Purpose of a Trust

Performance of tasks consigned for the purposes of establishing, maintaining, implementing, and managing (financial) transactions.

Performance of tasks consigned as necessary for the purposes of promoting and soliciting products and services, appreciation events, and customer satisfaction surveys.

Types of Personal Information Provided

Personally Identifiable Information (PII): Identification and contact information including name, Resident Registration Number, nationality, occupation, address, email address, phone number, etc.

(Financial) Transaction Information: Product type, transaction conditions (interest rate, maturity, collateral, etc.), date/time of transaction, amount, and other transaction details.

Information described in a transaction application other than personally identifiable information (PII); or information provided by the customer.

  • Residence and family information, length of residence, family composition, marital status, etc.
  • ※ Includes personal (credit) information collected prior to providing consent.

※ Terms such as compliance with laws protecting personal information, restrictions on the provision of personal information to third parties, and liabilities are clearly defined at the time of agreement for the consignment of personal information, and the relevant agreement details are stored in the form of written and electronic documents.

Article 5 (Customer Rights/Obligations and the Exercising Thereof)

※ A credit information principal or the legal representative of a customer under the age of fourteen (14) may request the provision or viewing of his/her credit information held and processed by KEB Hana Bank.

※ A credit information principal may request KEB Hana Bank to correct incorrect information or delete indeterminable information. However, certain information may not be deleted if said information is the target of collection passed to other relevant laws or regulations.

※ Customers may request that KEB Hana Bank suspend handling of their personal information.

However, KEB Hana Bank may refuse such requests for any of the reasons prescribed in the following paragraphs after notifying the customer of the reason.

  • If specified by special laws or regulations or if unavoidable for compliance with statutory obligations.
  • If there is concern about causing harm to a person's life or health or there is risk of unduly infringing upon the assets or interests of another person.
  • If an agreement is unable to be implemented without processing of personal information and thus resulting in the inability to fulfill said agreement, but the customer does not explicitly express the desire to terminate the agreement.

Article 6 (Types of Personal Information Processed)

KEB Hana Bank collects required and optional information as prescribed in the following paragraphs for the purposes of establishing, maintaining, implementing, and managing (financial) transactions as well as the provision of products and services.

Required Information

※ Personally Identifiable Information (PII): Identification and contact information including name, Resident Registration Number, nationality, address, phone number, etc.

※ (Financial) Transaction Information: Product type, transaction conditions (interest rate, maturity, collateral, etc.), date/time of transaction, amount, and other transaction details.

Information for Determining Credit Rating (For credit transactions only)

  • Creditworthiness Information: Assets, liabilities, total income, tax payment records
  • Credit Determination Information: Delinquency, subrogation, proxy payments, bankruptcy, etc.

Information generated from consultations for establishing, maintaining, implementing, and managing (financial) transactions as well as managing credit.

Optional Information

Information contained in a transaction application or information provided by a customer in addition to personal identification information.

  • Residence and family information, length of residence, family composition, marital status, etc.

Information collected in accordance with the Electronic Financial Transactions Act. (Limited to online transactions)

Customer ID, date/time of access, IP address, HDD serial number, MAC address, personal firewall settings, operating system type, browser version, etc.

※ As a rule, KEB Hana Bank does not collect sensitive information that is likely to infringe upon the customer's privacy.

Collection Method

  • Collected directly from customers who visit a KEB Hana Bank branch.
  • Collected via website, written form, fax, phone, consultation forum, email, application history, and delivery request.
  • Collected via a generated-information-gathering tool.
  • Collected via Customer Service Center inquiries.

Article 7 (Destruction of Personal Information)

Except for cases in which one of the reasons prescribed in the following paragraphs apply, KEB Hana Bank shall destroy the personal information of customers for the following reasons within five business days of the date of determination if said information is deemed to be no longer required: The retention period has expired; the processing objectives of the information have been achieved; or the applicable service or business has been terminated.

  • If a public credit registry or a credit information company retains personal credit information for the purpose of centrally managing or utilizing credit information or to evaluate the credit ratings of individuals. (Limited to the retention period)
  • If a credit information company retains personal credit information for ongoing civil or criminal responsibilities or as evidence for disputes.
  • If information must be retained pass to Article 33 of the Commercial Act of South Korea or other relevant laws and regulations.
  • If there are other similar legitimate reasons.

Printed and written materials on which personal information is recorded shall be destroyed via shredding or incineration, and electronic files containing personal information shall be permanently deleted in a manner in which recovery is impossible.

Article 8 (Security Measures for Personal Information)

※ KEB Hana Bank shall implement technical, administrative, and physical measures as prescribed in the following paragraphs to ensure the security of information in accordance with Article 29 of the Personal Information Protection Act.

Personal Information Encryption

The personal information and passwords of customers shall be encrypted, stored, and managed, and the information shall be known only to the respective customers. Important files and transmitted data shall be encrypted or a file-locking feature shall be implemented for additional security.

Anti-Hacking Technical Measures

To prevent personal information leakage and damage due to hacking or computer viruses, KEB Hana Bank shall install and periodically check/update security programs. Systems shall be installed in areas with restricted access and shall be monitored/blocked via technological and physical means.

Training and Minimization of Sensitive Information-Handling Personnel

KEB Hana Bank shall designate and minimize the number of personnel required for the handling of personal information and implement measures to manage such information.

Article 9 (Changes in Personal Information Processing Policies)

※ If KEB Hana Bank changes any policies related to the handling of the personal information of customers, such changes and their respective effective dates shall be published and shall be made easily accessible to customers.

Article 10 (Remedies for the Infringement of Rights)

Customers who require reporting or consultation due to the infringement of personal information shall contact the following organizations.

  • Personal Information Dispute Mediation Committee (www.kopico.or.kr / 02-405-4710)
  • Korea Internet and Security Agency - Digital Certificate Report Center (www.1336.or.kr / 118 without area code)
  • Personal Information Protection Mark Accreditation Committee (www.eprivacy.or.kr / 02-550-9531~2)
  • Supreme Prosecutors' Office - High-Tech and Financial Crimes Investigation Division (www.spo.go.kr / 02-3480-2000)
  • Korean National Police Agency Cyber Terror Response Center (www.ctrc.go.kr / 02-392-0330)

Article 11 (Remedies for the Infringement of Rights)

The personal information protection officers of KEB Hana Bank are as follows passed to Article 31, Section 1 of the Personal Information Protection Act:

Type Personal Information Protection Officer Personal Information Department / Complaints Handling Center
Name/Title Yun-kyu Lee, Department Head Customer Information Protection Department / Customer Service Center
Phone/Fax Number Hana Bank Customer Service Center: 1588-1111 02-3709-6455~60 / 1588-1111