South Korea has deferred the enforcement of the Credit Information Act on cryptocurrency exchanges until 1 December 2025, providing a grace period during which penalties will not be imposed unless violations involve intent or gross negligence. The Act mandates that crypto exchanges treat user transaction records as sensitive credit information, aligning them with traditional financial institutions in terms of data handling and protection.

This postponement allows exchanges additional time to adapt their systems and processes to comply with the stringent requirements of the Act. The Financial Services Commission has indicated that during this grace period, it will focus on guiding exchanges towards compliance rather than penalising them, unless there is clear evidence of deliberate or grossly negligent misconduct.

The Credit Information Act's application to the crypto sector is part of South Korea's broader initiative to regulate digital assets more comprehensively. The Act's provisions require exchanges to implement robust data protection measures, including the secure storage of user data and the establishment of protocols to prevent data breaches. These measures are intended to enhance user trust and align the crypto industry's practices with those of the traditional financial sector.

In the interim, the Virtual Asset User Protection Act, which came into effect on 19 July 2024, continues to govern the crypto industry. This Act mandates that exchanges store at least 80% of user deposits in cold storage, separate from their own funds, and entrust users' cash deposits to licensed local banks. Additionally, exchanges are required to maintain cryptocurrency reserves matching customer deposits and to have insurance or reserve funds to cover potential losses from hacks or liquidity issues.

