South Korea will significantly restrict the use of data scraping by financial companies and fintech firms from Aug. 20, requiring operators to complete pre-consultation with public institutions and gradually shift toward API-based data transmission instead of collecting records directly from public websites with customer credentials. The Personal Information Protection Commission said the move is tied to the revised Personal Information Protection Act and the broader Right to Request Personal Data Transmission, which will apply to private companies and institutions above a certain size from Feb. 20 next year. Scraping will not be banned outright, and firms that apply for consultation can keep current methods until the process is completed, with the commission seeking a grace period after the Supreme Court said it would fully block scraping of its registry and family relations registration systems. The change affects core digital finance services. Banks and fintech platforms have long used scraping, with customer consent, to pull income records, family relationship certificates and other documents from bodies such as the National Tax Service and the Supreme Court, cutting paperwork for loans and other remote services. Regulators say customers often cannot tell exactly what is being collected and that handing over authentication credentials raises leakage and misuse risks. The commission said it has received more than 150 cases from around 70 institutions in the first consultation round and about 550 in the second, while fintech groups including Toss Income and Samjjeomsam warn the added procedures could shrink services and make digital finance more cumbersome for users. Earlier warnings from banks, internet-only lenders and policy finance providers said abrupt restrictions could also disrupt branchless banking and housing finance.