The organization must ensure that the collection and processing of credit data comply with legal and regulatory requirements of the relevant authorities.
Appropriate organizational, technical, and administrative measures must be in place to protect credit data from unauthorized access, misuse, or disclosure.
When processing credit data based on consent, the organization must:
- Obtain explicit and informed consent from the data subject before processing or disclosing their credit data.
- Clearly separate the consent request from other terms to ensure transparency and understanding.
- Allow data subjects to withdraw consent easily and at any time, ensuring that withdrawal is as simple as giving consent.
- Notify data subjects promptly of any authorized request to disclose their credit data in line with the Credit Information Law and applicable regulations.
All consent records and disclosure notifications must be documented and reviewed to demonstrate compliance with the Credit Information Law and related supervisory requirements.