Law note · South Korea
Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention)
What it asks of an app
- Do not access an information and communications network without authorization, or beyond the scope of granted authorization, to collect data.
- Do not build, install, or distribute a tool whose purpose is to bypass a network's normal access-control or authentication procedures.
- Scraping a public, unauthenticated page without defeating an access control has not itself been held to violate this article (Supreme Court, Yanolja Co. v. GC Company, 2021Do1533, May 12, 2022).
When LexLint raises it
crawls_web
What we found
Article 48(1) prohibits intruding into an information and communications network without legitimate access authority or beyond the scope of permitted authority. The Supreme Court held in Yanolja Co. v. GC Company (2021Do1533, 12 May 2022) that scraping publicly available data without defeating an authentication or access-control measure did not violate this provision as charged.
Paragraph (4), added January 23, 2024, separately prohibits installing, transmitting, or distributing a program or technical device whose purpose is to bypass a network's normal protection or authentication procedures, reaching a scraper's own circumvention tooling directly even though paragraph (1)'s basic prohibition predates it and remains the article's core text.