New System to Separate CI and Resident Registration Numbers to Prevent Data Leaks Starting January

By PARK, JONG-HO Posted : September 18, 2026, 18:16 Updated : September 18, 2026, 18:16

A new system to separate the management of linked information (CI) and resident registration numbers will be implemented in January. This measure aims to reduce the risk of personal data breaches, as the simultaneous exposure of both types of information increases the likelihood of individual identification.

On September 18, the Broadcast Media Commission (BMC) announced the approval of a revised guideline concerning the generation and processing of linked information. The BMC stated, "We are promoting this revision to enhance security and prevent the possibility of simultaneous exposure of resident registration numbers and linked information."

CI is a unique identifier used to recognize individuals online. It was introduced to prevent the direct exposure and misuse of resident registration numbers. When a user verifies their identity, a verification agency generates a CI and provides it to businesses and institutions.

However, the existing structure of CI issuance has been problematic, as once issued, it cannot be changed. While CI alone does not enable hackers to conduct financial transactions or steal accounts, issues arise when it is combined with personal information such as names and birthdates. The repeated incidents of data breaches have heightened calls for the separation and secure storage of CI and resident registration numbers.

Last year, Lotte Card exposed logs containing linked information and resident registration numbers in plaintext while operating its mobile and online payment service. Approximately 1.29 million CIs were included in the leaked data, with 450,000 of them also having their resident registration numbers exposed.

This year, the online video platform Tving reported that accounts holding CIs experienced an average of 11.1 data items leaked, significantly higher than the average of 4.6 items for accounts without CIs.

Experts have acknowledged that separating CI and resident registration numbers is a necessary step, but they emphasize the need for a robust post-incident response system. Professor Hwang Seok-jin from Dongguk University’s Graduate School of International Information Security stated, "While the separation and secure storage of CI and resident registration numbers is essential to mitigate the severity of personal data breaches, it is equally important to implement encryption, access controls, and monitoring of access logs."

Currently, the BMC is discussing options for invalidating or replacing leaked CIs. Professor Hwang suggested that, given the need to overhaul databases and authentication systems, it is crucial to approach this transition gradually through ongoing discussions rather than implementing a uniform change in a short period.




* This article has been translated by AI.

Copyright ⓒ Aju Press All rights reserved.