HomeTech

개인정보·보안

Why Separating CI From Resident Numbers Should Shrink Data-Breach Damage -- Korea Moves the Rollout Up to January 2027

On September 18, Korea's Broadcasting and Media Communications Commission voted to approve an amendment to the "Standards for Generating and Processing Linkage Information," moving the mandatory separation of Connecting Information (CI) from resident registration numbers up from May 1, 2027 to January 1, 2027. The later date had originally been set aside to give companies time to rebuild and test their technical infrastructure. But after a string of incidents this year -- including May's TVING data breach -- in which CI leaked together with resident numbers, regulators moved to close the gap sooner rather than wait for further damage.

HJ
Han Ji-woo Tech Editor·2026.09.19·10 min read·7 views

Storage drives packed tightly into a data center server rack

What happened -- the rollout date just got moved up by four months

What CI actually is -- why it's called an "online resident number"

Connecting Information is a value generated by encrypting a resident registration number in a specific way so that a person can be identified online. It's issued when you complete identity verification to sign up for a site, and it's what lets different services confirm "this is the same person" without directly exchanging your resident number. The catch is that once a CI is issued, it's essentially impossible to change -- it follows you for life just like your resident number does, yet in practice the two have often been stored together, making a single breach doubly damaging.

Multicolored fiber-optic cables densely connected to server equipment

What "separate storage" actually requires

What the revised notice demands is that CI and resident registration numbers be kept physically or logically separate. In plain terms, the two values can no longer sit side by side in the same database table or be reachable through the same access path. The core requirement is that access rights and storage locations be split up, so that if an unauthorized party breaches one part of a system, both pieces of information aren't exposed at once. Until now, many companies stored the two together, which meant a single intrusion could pull both out simultaneously.

When it takes effect, and who has to comply

The revised effective date is January 1, 2027, and it applies to what the Network Act (Article 23-6) calls "linkage information user institutions" -- essentially any website or app operator that issues and uses CI alongside resident numbers as part of an identity-verification service. Individual users don't need to file anything or change anything themselves; this is an internal system overhaul that falls on the operators. For ordinary users, it's enough to know roughly when things get safer.

Why a breach would do less damage once this is in place

The biggest change once separated storage takes hold is the scale of damage from any single breach. Under the current setup, if an attacker breaches one database, both the resident number and CI can be pulled out together, making it easier to identify the same person across other sites or attempt identity theft. Once the two are stored apart, breaching one system doesn't automatically expose the other, so the odds of a leak snowballing into secondary damage go down. That said, this only changes how companies store data going forward -- it doesn't erase information that has already leaked in the past, and that distinction matters.

What happens if a company doesn't comply -- fines and the burden on business

Companies that fail to keep CI and resident numbers separate after the effective date face administrative fines of up to 30 million won under Article 76(1) of the Network Act. Moving the deadline up by four months has raised concerns among some operators that their system-rebuild timelines are now tight, but that burden ultimately falls on the service providers to manage. As a user, if a service you rely on requires identity verification, whether that company is actually complying with this rule is directly tied to how safe your information is.

A fingertip tracing an inked fingerprint left on paper

What you can check for yourself right now

While the rule is being phased in, there are still things individuals can do. If you already know your resident number has leaked, it's worth checking whether someone has opened phone lines or accounts under your name before anything else, and if a service you've used recently sent you a breach notice, it's worth revisiting every site where you're still signed up and closing accounts you no longer use. In particular, the TVING breach, where CI leaked alongside resident numbers, was a direct trigger for this policy change -- if you were a TVING user, it's worth checking whether the compensation application window has already closed. And to get a sense of how much responsibility companies bear when a mass breach happens, the revenue-based penalty system is a useful reference point.

The bottom line

There are three things worth remembering from this change. First, the separation of CI and resident numbers takes effect on January 1, 2027, four months earlier than originally planned. Second, the rule applies to companies that issue and use CI -- individuals don't need to file anything separately. Third, once separated storage is in place, a single breach is less likely to expose both CI and resident numbers at the same time, which should shrink the scope of secondary damage. That said, this article can't cover every detail of the implementing guidelines or confirm whether any specific company is complying, so if you have questions about a service you use, it's best to check directly with the Broadcasting and Media Communications Commission or a lawyer who specializes in personal data protection.

HJ
Han Ji-woo · Tech Editor

All content is fact-checked under our editorial standards.

Back to list