The old certificate mandates are gone. Foreign-card failure can still happen—but a rejected checkout is not proof that the repealed law is still operating.
The answer in 20 seconds
Korea removed the mandatory certificate for card checkout in 2014, removed the broader electronic-finance mandate in 2015, and abolished the state-accredited certificate system in 2020. What remains is a mixed stack of merchant policy, domestic identity and phone verification, payment-gateway design, issuer fraud checks, and legacy workflows.
Korean report with additional legal cases: /absurd-laws
FIRST, IDENTIFY WHAT ACTUALLY FAILED
STEP 1
Account creation
The service may require a Korean phone number, resident-linked identity check, or a locally supported age-verification method.
STEP 2
Merchant acceptance
The store or payment gateway may simply exclude overseas-issued cards even when the card network logo appears at checkout.
STEP 3
Payment authorization
The merchant accepts the card, but the issuer, 3-D Secure flow, address check, or fraud model declines the transaction.
AMS does not have a reliable market-wide statistic showing what share of Korean checkout pages reject foreign cards or still request a certificate. This page therefore explains the legal history and diagnostic layers instead of inventing a prevalence number.
THE REGULATORY TIMELINE
2012
The internet real-name rule was struck down
The Constitutional Court decision concerned identity verification for posting on large internet message boards. It did not outlaw every identity check used for contracts, finance, age gates, or regulated services.
2014
The certificate mandate for card checkout was removed
The Financial Services Commission removed the rule requiring an accredited certificate for online debit- and credit-card payments above ₩300,000.
2015
The broader technology mandate was removed
Financial regulators deleted the requirement to use an accredited certificate—or a method officially judged equivalent—for electronic financial transactions.
2020
The state “accredited certificate” status itself ended
The revised Electronic Signature Act abolished the government-designated accredited-certificate system and opened competition to different private electronic-signature methods.
WHY THE LEGACY MATTERS
Collecting more identity data also created a larger failure surface
In the 2014 card-company incident, prosecutors reported roughly 100 million leaked records. The Financial Supervisory Service later counted about 85 million compromised accounts after excluding some categories, while still including overlap among people holding multiple cards. Those are record and account counts—not 100 million unique Koreans.
DOES KOREA STILL IMPOSE TINY PRIVACY PENALTIES?
A blanket “Korea caps every privacy fine at 3% of related revenue” statement is now outdated. The current Personal Information Protection Act can calculate surcharges within 3% of total revenue, subject to statutory exclusions and the specific violation. Enforcement has also changed materially: in June 2026, the PIPC announced a ₩624.681 billion surcharge against Coupang. Older Google, Meta, EU, and U.S. penalties involve different conduct, statutes, revenue bases, and remedies, so lining them up as if they were the same case produces a misleading league table.
PRIMARY-SOURCE DESK
Open the exact decision, rule change, or enforcement release behind each claim.
Custom reports, datasets, Korea market or supplier research, and small, clearly scoped development. Describe what you need, the deliverable, timeline and budget — AMS reviews and replies on whether it can take it on.