Block Secret Data Collection, but Keep the Path to Innovation Open [Kim Hyun-ah’s “Reading the IT World”]
The Transition to MyData Is Inevitable, But...
We Must Not Stand in the Way of Startups’ Soft Landing
What’s More Important Than Abolishing Scraping
User Data Sovereignty and a Secure Data Ecosystem
[Edaily Reporter Kim Hyun-ah ] Few would readily oppose the proposition that “black-box scraping must be eliminated.”
Web scraping is a method whereby companies, with the user’s consent, automatically retrieve information scattered across various websites and display it in one place, so that users do not have to enter the information manually. A prime example is when tax refund or asset management services automatically retrieve information from the National Tax Service or financial institutions.
To date, scraping has served as the foundation for various innovative services, including fintech, tax services, and personalized healthcare. However, from the user’s perspective, it has also had the limitation of being an opaque form of data collection, making it difficult to know where, to whom, and to what extent their personal information is being shared. We cannot overlook a system where personal information is automatically collected without authorization and where security responsibilities remain unclear, simply in the name of “innovation.”
However, there is one point that must be clearly emphasized here. The problem lies not so much in the technology of scraping itself, but rather in the methods used to collect personal information without user control, or in the lack of transparency regarding the collection process and accountability.
Should We Eliminate Scraping—and Innovation Along With It? [IT World Insights byKim Hyun-ah]
The Shift Away from Scraping: “Eliminating the Technology” Is Not the Goal
Is the blanket exclusion of scraping truly the ultimate goal of the MyData policy?
Starting on the 20th, beginning with the public sector, the right to request the transfer of personal information—the so-called MyData system—will be fully implemented. This system allows users to request that their information be transferred directly to the company of their choice. Accordingly, the existing scraping method is expected to rapidly transition to the API (Application Programming Interface) method.
The shift to the API method is significant in enhancing transparency and control over the data provision and usage process. However, simply using APIs does not automatically resolve security issues. More important than the specific technology used is the process and standards by which personal information is collected and managed.
As anxiety grew among companies that had relied on scraping, the Personal Information Protection Commission (PIPC) established a safety net known as “prior consultation.” PIPC Chairwoman Song Kyung-hee emphasized, “This does not mean we intend to immediately ban scraping 100% as of August 20 and mandate the use of APIs exclusively.” The Commission has already conducted approximately 700 prior consultation cases, providing a temporary grace period for existing collection methods and allowing time for the transition to APIs.
The policy direction is sound. The issues are speed and feasibility.
[Edaily Reporter Lee Mi-na]
Large Corporations vs. Startups: Transition Costs Are “Worlds Apart”
The environments faced by
large corporations
and
startups
are vastly different. Major fintech companies like kakaopay and Toss can invest significant manpower and capital to navigate the transition to APIs relatively smoothly.
On the other hand, for startups that create innovative services with limited personnel and capital, building an API and establishing a sophisticated security system within a short period can pose a massive barrier that determines the very survival of their business.
If regulations intended to protect citizens’ personal information end up hindering the market entry and business continuity of innovative startups that have been providing useful services to the public, one cannot help but ask, “Who are these regulations really for?”
In fact, it is true that scraping was used as the foundation for innovative services during the growth of major domestic platforms and fintech companies such as Naver (NAVER(035420)), Kakao(035720), and Toss. If the gap in regulatory compliance costs widens between companies that have already entered the market and scaled up and latecomers who are just beginning to develop data-driven services, latecomer fintech or healthcare companies may perceive this as “kicking away the ladder.”
Of course, this is not an argument that “regulations should be relaxed just because they are startups.” It goes without saying that any company handling personal information must implement basic security measures, regardless of its size.
However, if strict accountability is demanded, it must be accompanied by realistic support that matches those expectations.
Balancing Personal Information Protection and Innovation: Catching Two Birds with One Stone
It is commendable that the
Personal Information
Protection Commission has established a channel for prior consultation. However, efforts must not stop there; more concrete support measures for startups must be developed. It is necessary to provide detailed technical guidelines for API migration and actively consider plans to support security consulting and development costs for small businesses.
In particular, a phased transition that takes into account company size and service characteristics is necessary. Rather than requiring all companies to transition to APIs using the same method and at the same pace, it is worth considering a plan that varies the transition period and level of support based on a comprehensive assessment of the scale of personal information processing, risk levels, and technical readiness.
Furthermore, we must move beyond the simplistic dichotomy that equates “scraping” with “absolute evil.” The root of the problem lies not in the technology itself, but in uncontrolled, unauthorized data collection and the lack of user control.
If only necessary data is safely collected with the user’s explicit consent, and the process and responsibilities are managed transparently, we should avoid an approach that judges right and wrong based solely on the technology used. Ultimately, what matters is not which technology is used, but how securely users can control their own data.
The Owners of MyData Are “Users,” Not Companies
The true owners of the MyData ecosystem are not the companies collecting the data, but the users who generated it. The success or failure of the system should also be evaluated not by the battle for data among companies, but by the extent to which citizens can safely and proactively control their own information.
Covert data scraping practices must be eradicated. However, in the process of eliminating outdated practices, we must not stifle the buds of new innovation. If small startups are forced to shut down their services due to significant transition costs, the ultimate burden will fall on the public, who stand to benefit from new data services and conveniences.
Regulation must be a decisive sword to correct an abnormal market. It must not become a tool that kicks away the very ladder needed to foster future innovation.
What the Personal Information Protection Commission must demonstrate during this MyData transition is not “how strictly it regulated.” What is more important is how skillfully it paved the way for startups to survive in the market and create new services while safely protecting personal information.
Personal data protection and industrial innovation are by no means a zero-sum game. The true success of the MyData system should not be judged by how quickly outdated technologies are phased out, but rather by how safely and dynamically a data ecosystem has been fostered while firmly safeguarding users’ data sovereignty.
Current Status of Production Outsourcing by Major Home Appliance Manufacturers. (Graphic by Lee Mi-na, E-Daily)
Most global home appliance companies are devising survival strategies that rely on C…
“Wheee-ing, clang, wheee-ing, clang.”On the 7th, I visited the Lotte Mart Zeta Smart Center in Busan. As I opened the thick steel door and stepped into the frozen food storage area, the frigid air at …
Few would readily oppose the proposition that “black-box scraping must be eliminated.”Web scraping is a method whereby companies, with the user’s consent, automatically retrieve information scattered …