AvisSK Rent-a-Car

Privacy Policy

Privacy Policy Revision History

SK Rent-a-Car Co., Ltd. (hereinafter the “Company”) highly values personal information and personal location information (hereinafter the “personal information”) of customers using SK Rent-a-Car service (hereinafter the “Service”) provided by the Company and is dedicated to safeguarding customers’ personal information.

The Company complies with all laws and regulations related to personal information protection, including the Personal Information Protection Act, the Credit Information Use And Protection Act, and the Act On The Protection And Use Of Location Information, while separately establishing and complying with the Company’s Privacy Policy, to protect the personal information of its members. In addition, the Company discloses its Privacy Policy on the first page of its website to allow its members to view it easily at any time. Any modification to the Company’s Privacy Policy will be notified on the website.

The Company’s Privacy Policy contains the following:

  • 01. Collected Personal Information, Purpose of Processing, and Period of Retention and Use
  • 02. Personal Information Processing for Children Under 14 Years of Age
  • 03. Provision of Personal Information to a Third Party
  • 04. Consignment of Personal Information Handling
  • 05. Destruction Procedures and Methods of Personal Information
  • 06. Rights and Obligations of Data Subject and Legal Representatives, and How to Exercise Them
  • 07. Measures to Ensure the Security of Personal Information
  • 08. Installation, Operation, and Rejection of Tools Collecting Personal Information Automatically
  • 09. Collection, Use, Provision, and Rejection of Behavioral Information
  • 10. Chief Personal Information Protection Officer and Personal Information Access Request
  • 11. Remedies for Violation of Rights and Interests of Data Subjects
  • 12. Installation and Operation of Visual Data Processing Devices
  • 13. Amendments to the Privacy Policy

01. Collected Personal Information, Purpose of Processing, and Period of Retention and Use

① The Company processes the personal information of data subjects as follows:

Collected Personal Information, Purpose of Processing, and Period of Retention and Use table
CategoryRequired / OptionalItems CollectedPurpose of UseRetention Period
ServiceChannel
MembershipSK Rental for foreignersOnlineRequiredName, ID, password, mobile phone number, nationality, passport number, email address(verification upon membership sign-up), date of birthTo verify membership and provide membership servicesUntil withdrawal of membership
OptionalMobile phone number, service usage history (search history etc.), Driver’s license number, license type
  • 1. To notify services/products offered by SK Rent-a-Car or services/products affiliated with/connected to services provided by a third party.
  • 2. To notify event information/benefits and how to participate
  • 1 year after the termination of the contractual business relationship or until the withdrawal of consent
  • (However, until the withdrawal of membership in the case of a website member)
Driver’s License RegistrationOnlineOptionalDriver’s license number, license type, driver license classificationTo verify vehicle rental qualificationsUntil withdrawal of membership or deletion of license information
Short-term ContractOnlineRequiredName, date of birth, email address, passport number
  • 1. For identification procedures for service use
  • 2. For identify verification for financial transactions and other debt collection
  • 3. To claim damages and process insurance in case of accidents
5 years after the termination of the contractual business relationship
Driver’s license number, license type, license expiry date, license issue date, date of birthTo verify vehicle rental qualifications
Card payment information (card issuer, card type, card number, expiration date, date of birth, first 2 digits of password)To settle fees based on the fulfillment of the purchase contract and provision of service
(In case of using affiliate services)
(SKT) T Membership number, Point Password
(KT) Membership number
(LG U+) Membership number, Date of birth
(Korean Air, Asiana Airlines)
Name, airline membership/mileage number
  • 1. To accumulate/settle mileage points
  • 2. To verify membership
DeviceRequired(Collected only in case of vehicle theft or non-return)
Vehicle location information (GPS)
  • 1. To confirm theft or loss and retrieve rental vehicles
  • 2. To respond to the renter’s refusal of return without prior notice
Until the vehicle is retrieved
BranchOfflineRequiredName, gender, date of birth, mobile phone number, email address, nationality
  • 1. For identification procedures for service use
  • 2. For identify verification for financial transactions and other debt collection
  • 3. To claim damages and process insurance in case of accidents
5 years after the termination of the contractual business relationship
Driver’s license number, license type
(Foreigner) Passport number, copy of passport
Copy of (International) Driving Permit
To verify vehicle rental qualifications
Card issuer, last 4 digits of the card numberTo settle fees based on the fulfillment of the purchase contract and provision of service
AddressTo send bills in the event of penalties or debts
(Additional Driver) Name, date of birth, mobile phone numberTo register additional driver2 years after the termination of the contractual business relationship
(for foreign passports and driver’s license - 10 years after the termination of the contractual business relationship)
(Additional Driver) Driver’s license number, license type, license issue date, license expiry date, date of birth
(Foreigner) Passport number, copy of passport Copy of
(International) Driving Permit
To verify vehicle rental qualifications
DeviceRequired(Collected only in case of vehicle theft or non-return)
Vehicle location information (GPS)
  • 1. To confirm theft or loss and retrieve rental vehicles
  • 2. To respond to the renter’s refusal of return without prior notice
Until the vehicle is retrieved
OfflineRequired(Keyed-in credit card transaction agreement for foreigners)
Credit card number, expiration date, owner, contact number, address, relationship with the renter, email address
To process keyed-in transactions for additional costs incurred during vehicle rental6 months after the termination of the contractual business relationship

※ Online: Website (Web/Mobile Web), Mobile app.

※ Offline: Phone call, branch

※ External: Consignee, affiliate

※ Device: A device (Smart Link) is installed in a rental vehicle to collect vehicle location information. (Requests are made to SK Telecom to determine the location information.)


② In the process of using the service, the following personal (location) information items may be automatically generated and collected:
- IP address, cookies, MAC address, mobile device OS information, service usage history, visit history, call logs during consultation, etc.


※ Even after the purpose of collecting and using personal information is achieved, records that must be retained according to relevant laws, including the Act On The Consumer Protection In Electronic Commerce, are retained for a certain period before destruction.

  • • Records on contracts or withdrawal of subscription: 5 years
  • • Records on payment and supply of goods: 5 years
  • • Records on handling member complaints and disputes: 3 years
  • • Commercial ledgers and important documents related to business: 10 years
  • • Communication confirmation data (login record): 3 months

02. Personal Information Processing for Children Under 14 Years of Age

The Company does not collect personal information of children under 14 years old, and their membership registration is not allowed.

03. Provision of Personal Information to a Third Party

① The Company processes the data subject's personal information only within the scope specified for the purpose of processing the personal information. Personal information is provided to third parties only when it falls under Articles 17 and 18 of the Personal Information Protection Act, such as the consent of the data subject and special provisions in other statute; otherwise, the Company does not provide the personal information of the data subject to third parties.


② The company provides personal information to third parties as follows:

Provision of Personal Information to a Third Party table
ServiceRecipientItems ProvidedRecipient’s Purpose of UseRetention and Use Period
Short-term Contract(In case of using affiliate services)
Korean Air, Asiana Airlines
Name, affiliate member number / mileage number, rental periodTo verify data to accumulate/settle mileage pointsUntil affiliate service termination
(In case of using affiliate services)
Jin Air
Name, vehicle number, date and time of departure, date and time of arrivalTo verify data for affiliate service settlement
(In case of using affiliate services)
SKT, KT, LG U+
(Common) Membership number
(SKT) Point password
(LG U+) Date of birth
To verify membership

③ In the event of emergencies, such as disaster, infectious disease, incident or accident causing urgent life or bodily harm, and imminent property loss, the Company may provide personal information to the relevant organizations. For more information, please click here (link to the Personal Information Handling and Protection Rules in Emergency Situations, jointly announced by the relevant government departments in October 2021).
※ In this case, the Company will provide only the minimum necessary personal information based on applicable laws and will not provide information for purposes other than those specified.

04. Consignment of Personal Information Handling

① In order to facilitate personal information processing, the Company entrusts personal information processing as follows:

Consignment of Personal Information Handling table
CategoryConsigneeDescription of Tasks Entrusted
Vehicle RentalContract / Customer ManagementSales partners who signed a car rental brokerage contract with SK Rent-a-Car Co., Ltd.
  • 1. Brokerage/maintenance of concluding car rental contracts and related supplementary tasks (providing explanations and guidance on car rental contracts, terms and conditions, and rental vehicles)
  • 2. Any and all tasks closely related to car rental brokerage, including various sales activities to attract new customers
Car Life Service Co.,LtdCustomer center operation, TM on the Company’s products and services (TMs are limited to cases where prior consent is obtained.)
Companies that signed a business outsourcing contract for sales offices/customer centers, etc.
Processing sales office/customer center tasks, customer consultation, and contracts
Short-term Rental/Insurance Car RentalCompanies that signed a business outsourcing contract related to short-term rentals and insurance car rentals
Providing insurance car rental services
DeliverySongin Co., Ltd., Car life Service Co., Ltd., Taewo Logistics Co., Ltd. , HK Logistics Co., Ltd., CJ Logistics Corporation, Hi Auto Members Co., Ltd., Sangwon Logistics Co., Ltd., Motor man Co., Ltd.Rental vehicle delivery
Vehicle ManagementSupplies DeliverySERVEONEVehicle supplies delivery, after-sales service
Visit InspectionCar Life Service Co.,LtdVisit inspection
RepairSamsung Fire Service Claim Adjustment Co., Ltd.Rental vehicle repair (Anycar Land)
Master Co., Ltd.Rental vehicle repair
GS Mbiz Co., Ltd.Rental vehicle repair (Auto Oasis)
Companies that signed a business outsourcing contract related to vehicle repair
Rental vehicle repair (cooperative maintenance)
InspectionSS-Car, Asta Networks Co., Ltd., Open Mile, CarforyouRental vehicle inspection agency
Emergency ServiceSK Speedmate Co., Ltd.Emergency roadside assistance service for rental vehicle
Visit InspectionCar123-JasperVisit inspection
TotalAJ Maintenance PartnersGeneral rental vehicle repair, accident handling agency, rental vehicle inspection agency, emergency roadside assistance in case of accidents, visit inspection
SystemOperation / Development
(Maintenance)
SK AXInformation system development and maintenance/management, infrastructure and DB operation
Sk shieldusInformation protection system operation
Summit CorporationMobile rent-a-car service development and operation
NetpathyeDM sending system maintenance
SK Networks Co., Ltd.Consultation system (CSS) development, operation and maintenance
SK M&ServiceComputerized information processing and maintenance / management
TA9Information system development and maintenance/management
In / outbound systemDaou TechnologyProviding SMS/MMS sending service
BiztalkProviding AlimTalk/SMS/MMS sending service
HumusOnProviding push message-sending service
SPECTRAProviding chat consultation solution
Quve17, EarlyslothSupplying a happy call system
Sejong Telecom, Narae Internet, LG UplusProviding 080 opt-out service
TA9Collecting and providing personal location information (mobile phone location)
AutobeginsProviding vehicle information inquiry service
Grayboxproviding online customized advertising and service provision solutions
Identity VerificationSCI Information ServiceIdentity verification via mobile phone
Credit InquiryNICE Information ServicePerforming credit rating inquiry for confirmation of long-term car rental
PaymentFIRST DATAProviding a credit card payment system
Hyosung FMSDirect debit service
NICE Payments, Korea Payment NetworksProviding payment system
KG InicisProviding a payment system (payment of usage fees and charging fees)
CloudMicrosoft, AmazonProviding Cloud service (Azure-Seoul Region, AWS-Seoul Region)
OtherDebt CollectionF&U Credit Information, MG Credit Information Service, KS Credit InformationDelegation of debt collection
Duksung DMSending notification and billing of overdue payments, termination notices, and other contract-related postal mails (including proof of contents)
EventsNHN ADCollection and use of personal information of consumers participating in various events
eMFORCE
No Move No Works
SK Rent-a-Car official SNS channel managements & event management
SK Rent-a-Car coupon delivery and benefit information
11st StreetSending gifticons
SurveyNAVERUse of survey platform
DeliveryKorea PostCourier delivery
EV LinkSoftberry Co., Ltd.EV Link service outsourcing

② In order to facilitate personal information processing, the Company re-entrusts personal information processing as follows:

personal information processing as follows table
ConsigneeRe-consigneePurpose of Reconsignment
SK AXSoulbit I-TechOperation of car rental sales support system and B2C system
C&ThothDBA and middleware tasks, operation of network / server / storage / backup systems toktok server operation and management (messenger), operation of car rental sales support system
SK BroadbandTransmission of information to provide SMS service within NateOnBiz
Able ComH/W and S/W operation for car rental consultants
ec-BankTax invoice (RTax) system operation
EPIENCERTok payment and My Service operation
ToBeWayComputerized Biztalk information processing, maintenance / management
NETS Co., Ltd.Group portal’s integrated account management
SK ShieldusIssuance / renewal / revocation of toktok access authentication certificate, Group portal’s integrated account management
SK AX(Beijing) Co., Ltd. Shenyang BranchInfra DBA and middleware tasks, operation of server / storage / backup systems, toktok server operation and management (integrated account management / messenger / email / portal), issuance / renewal / revocation of toktok access authentication certificate
Okta Inc.Providing user authentication service for toktok access
UWSCloud system operation (Azure)
Nix VisionOnSpace system operation
DituelVisit management system operation
Hasung CNIPurchase management system (Buyone) operation
P&P ConsultingRDAP system operation
etecusM365 operation
eMFORCECoop MarketingGift delivery agency
SK M&ServiceHuevertechNetwork maintenance
SK telecomSK M&ServiceCounseling center operation
TA9GLIMEV Link system strategic planning

③ When entering into a consignment contract, the Company complies with Article 26 of the Personal Information Protection Act, specifying in documents responsibilities, including prevention of personal information processing for other purposes than performing the entrusted work, technical and managerial safeguards of personal information, restriction on reconsignment, management and supervision of consignees, and compensation for damages. The Company supervises whether consignees process personal information safely.

④ In case any change is made to the content of the consigned tasks and consignees, the Company will promptly disclose it through this Privacy Policy.

05. Destruction Procedures and Methods of Personal Information

① When the retention period expires, or the purpose of processing is achieved for personal information, which thereby becomes no longer necessary, the Company shall destroy such personal information without delay. The procedure, deadline, and method of destruction are as follows:

Destruction Procedures and Methods of Personal Information table
CategoryDescription
Destruction procedurePersonal information for which a reason for destruction has occurred, such as an expired retention period or achieved purpose of processing, is selected and destroyed.
Destruction DeadlineEnd of the retention periodWithin 5 days from the end date
Achieved the purpose of processing Service abolition Termination of businessWithin 5 days from the date when processing personal information is deemed unnecessary
Destruction MethodInformation in the form of electronic files is destroyed using technical methods that do not allow the reproduction of records. Personal information printed on paper is destroyed by shredding or incineration.

② If the personal information collected upon the data subject’s consent must be preserved under different laws despite the retention period having expired, and the purpose of processing has been achieved, the Company transfers the personal information to a separate database (DB) or preserves it in a different storage location.

③ When the Company achieves the purpose of collection, use, or provision of the collected personal location information, it shall destroy the personal location information without delay unless the information must be recorded and preserved to verify the collection, use, and provision of location information in accordance with Article 16 Paragraph 2 of the Act On The Protection And Use Of Location Information.
However, the Company shall immediately destroy the information after using it within the scope of the purpose agreed to by the customer in accordance with Article 23 of the Act On The Protection And Use Of Location Information.
In this case, when destroying the personal location information or data verifying the collection of location information, the Company uses technically irreversible methods to delete, shred, or incinerate the record.

06. Rights and Obligations of Data Subject and Legal Representatives, and How to Exercise Them

Users, as the data subject, may recognize the following obligations and exercise their rights at any time according to the procedures with respect to the Company.

Rights and Obligations of Data Subject and Legal Representatives, and How to Exercise Them table
CategoryDescription
ObligationsThe data subject has the obligation to protect their personal information. The Company shall not be liable for problems arising from the leakage of personal information without any reason attributable to the Company due to the following reasons: data subject’s negligence, such as transfer, rental, or loss of ID, password, access media, etc., and vacating while logged in; or, problems on the Internet that the Company cannot control despite its considerable care, such as hacking using methods or technologies that cannot be blocked by security measures under relevant laws.

1) The data subject must keep their personal information up-to-date, and any problems arising from inaccurate information input are the data subject's responsibility.
2) Registering membership using another person’s personal information or processing payment using another person’s ID may result in disqualification as a data subject and punishment in accordance with relevant laws.
3) The data subject is responsible for maintaining the security of ID, password, etc., and may not transfer or lend them to third parties. The data subject has the obligation to cooperate with periodic password changes for security according to the Company’s Privacy Policy.
4) The data subject must log out of the account and close the web browser program after using the Company’s services.
5) The data subject must comply with the Act On Promotion Of Information And Communications Network Utilization And Information Protection, the Personal Information Protection Act, the Resident Registration Act, and other laws regarding personal information.
RightsThe data subject may exercise their rights related to personal information with respect to the Company at any time, and the rights are as follows:

1) Request for access to personal information
2) Request for correction in case of errors
3) Request for deletion
4) Request for suspension of processing

The Company shall verify whether the person requesting access, correction, deletion, or suspension of processing by the rights of the data subject is the data subject or a legitimate representative.

The data subject’s rights may be restricted in case of requests for access to personal information and suspension of processing in accordance with Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.

Requests for correction and deletion of personal information cannot be made if the personal information is specifically included in items to be collected under other laws.
How to Exercise the Rights
(Procedure)
The data subject’s rights with respect to the Company can be exercised in writing, email, or facsimile (FAX) under Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act.

Rights can also be exercised through an agent, such as the data subject’s legal representative or a person authorized to do so. In this case, a power of attorney according to the format specified in Annex 11 of the Guidelines on Personal Information Processing Methods.

※ If the data subject requests correction or deletion of personal information, the Company will not use or provide such personal information until the correction or deletion is completed.

07. Measures to Ensure the Security of Personal Information

The Company takes technical/managerial and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act.

Measures to Ensure the Security of Personal Information table
CategoryMeasuresDescription
Managerial MeasuresMinimization of personal information processing personnelThe Company minimizes the authority of personal information processors to protect personal information.
Regular training for personal information processing personnelThe Company provides regular annual training to raise awareness of personal information protection.
Regular internal inspectionsThe Company conducts regular in-house inspections to ensure the stability of personal information processing.
Establishment and implementation of internal management plansThe Company has established and implemented internal management plans to process and manage personal information safely.
Technical MeasuresEncryption of personal informationUsers’ personal information and passwords are encrypted for storage/management. Separate security features are used during transmission for safe management.
Technical measures against hacking, etc.Security programs are installed for regular update/inspection to prevent leakage and damage of personal information due to hacking, computer viruses, etc. Systems are installed in areas with controlled access from outside to monitor and block access technically and physically.
Access restrictions on personal informationNecessary measures are taken to control access to personal information by granting, changing, or revoking access rights to the database system that processes personal information. An intrusion prevention system is used to control unauthorized access from outside.
Access recordkeeping and prevention of forgery and alterationAccess records to the personal information processing/handling system are stored and managed for at least two years, and security features are used to prevent forgery, alteration, theft, and loss of access records.
Physical MeasuresUse of locking devices for document securityDocuments and auxiliary storage media containing personal information are stored in a safe place with locking devices.
Access control for unauthorized individualsA separate physical storage location is designated for storing personal information, and access control procedures are established and operated accordingly.
Safety measures for disasters and catastrophesCrisis response procedures, such as risk response manuals, are established and inspected in preparation for disasters and catastrophes, including natural disasters.

08. Installation, Operation, and Rejection of Tools Collecting Personal Information Automatically

Under Article 29 of the Personal Information Protection Act, the Company takes technical/managerial and physical measures to ensure safety as follows:

  • ① The Company uses cookies, storing and retrieving usage records, to provide individualized custom services to users.
  • ② Cookies are small blocks of data that a server (HTTP) used to run the website sends to the user’s computer browser and may be stored on the user’s PC hard drive.
  • ③ Purpose of using cookies
    Cookies are used to understand users' visit and use patterns, whether secured access is made, etc., for each service and website they visit to provide optimized information to users.
  • ④ Installation, operation, and rejection of cookies
    Users can reject storing cookies by setting the options in the web browser menu, as shown below.
setting the options in the web browser menu table
CategorySetup Instructions
Internet Explorer
  • 1) Select the Tools button in Internet Explorer and select Internet Options
  • 2) Select the Privacy tab, select Advanced under Settings, then select Block or Accept cookies.
Edge
  • 1) Click the top right ‘…’ symbol in Edge and click Settings.
  • 2) Click Privacy, search and services on the left of the Settings page, activate or deactivate Tracking prevention, and select the level of tracking prevention.
  • 3) Activate or deactivate “Always use “Strict” level of enhanced security when browsing InPrivate.”
  • 4) In the Privacy section below, activate or deactivate “Send “Do Not Track” requests.”
Chrome
  • 1) Click the top right '︙' symbol in Chrome (customized Chrome settings and controls) and click Settings.
  • 2) Click “Privacy and security” on the left of the Settings page and select “Cookies and Other site data” in the Privacy and Security section.
  • 3) Select “Block third-party cookies” in the General Settings section

※ However, rejecting cookie storage may prevent the use of some services that require login.

9. Collection, Use, Provision, and Rejection of Behavioral Information

① In the process of using the service, the company collects and uses behavioral information as follows to provide optimized customized services, benefits, and online customized advertisements.

setting the options in the web browser menu table
CategoryDetails
Behavioral information items collectedUser’s service visit/use history, search and product inquiry history, purchase history
How to collect behavioral informationAutomatically collected and transmitted when users visit our website or run our app
Purpose of collecting behavioral informationProduct/service development and user analysis including statistics and customer analysis, and provision of customized advertisements based on user behavior information
Period of retention and use of behavioral informationIt is retained/used for up to 1 year from the date of collection, and is deleted without delay at the end of the retention period.
Contact information for user damage relief methods, etc.Department in charge: Information Protection Center
Phone number: 02-6474-5796

② Users can block the collection of behavioral information at any time through the following methods.

[Web browser]
- Above '9. You can block the collection of behavioral information by following the methods provided in Article 4 of ‘Installation/Operation and Rejection of Devices that Automatically Collect Personal Information’.
[Smartphone]
- Android: Settings → Google → Advertising → Delete Advertising ID
- iOS: Settings → Privacy & Security → Tracking → Allow apps to request tracking OFF

10. Chief Personal Information Protection Officer and Personal Information Access Request

① The Company is responsible for the overall management of information processing and appoints a Chief Personal Information Officer, as described below, to address data subjects’ complaints and provide remedies related to personal information processing.

② The Information Agency may request access to personal information pursuant to Article 35 of the Personal Information Protection Act to the departments below. The company will strive to promptly process the information subject's request to view personal information.

Chief Personal Information Protection Officer table
Chief Personal Information Protection Officer
DepartmentData Privacy Center
Name / TitleKim-Jung Ho, Technical Advisor

Customer Personal Information Protection Manager table
Customer Personal Information Protection Manager
DepartmentSK Rent-a-Car Information Protection Center
Name / TitleJong-won Jeong, Manager
Phone Number+82-2-6474-5796

※ Data subjects may contact the Chief Personal Information Protection Officer for any matters related to personal information protection inquiries, complaint handling, damage relief, etc., arising from the use of the Company’s services (or businesses). The Company will respond to and handle inquiries from data subjects promptly.

11. Remedies for Violation of Rights and Interests of Data Subjects

① The Company seeks opinions from members regarding their personal information and has established procedures and methods to address complaints. If consultation is needed for other personal information, individuals may contact the Privacy Call Center (operated by the Korea Internet Security Agency), the Personal Information Dispute Mediation Committee, the Cybercrime Investigation Division of the Supreme Prosecutors’ Office, and the Cyber Bureau of the National Police Agency.

Remedies for Violation of Rights and Interests of Data Subjects table
Privacy Call Center (operated by the Korea Internet & Security Agency)
ResponsibilitiesReport personal information infringement and apply for a consultation.
Websiteprivacy.kisa.or.kr
Phone number(no area code) 118
AddressPrivacy Call Center,(Postal Code 58324) 3F, 9, Jinheung-gil, Naju-si, Jeollanam-do,

Personal Information Dispute Mediation Committee table
Personal Information Dispute Mediation Committee
ResponsibilitiesApply for personal information dispute mediation and perform collective dispute mediation (resolution through civil proceedings)
Websitewww.kopico.go.kr
Phone number(no area code) 1833-6972
Address(Postal Code 03171) 4F, Government Complex Seoul, 209, Sejong-daero, Jongno-gu, Seoul

Cybercrime Investigation Division of the Supreme Prosecutors’ Office table
Cybercrime Investigation Division of the Supreme Prosecutors’ Office
Websitewww.spo.go.kr
Phone number(no area code) 1301

Cyber Bureau of the National Police Agency table
Cyber Bureau of the National Police Agency
Websiteecrm.police.go.kr
Phone number(no area code) 182

② The Company guarantees the data subjects’ right to self-determination of personal information and strives to provide consultation and damage relief related to personal information infringement. If reporting or consultation is necessary, individuals can contact the responsible department below.

Customer Consultation and Reporting Regarding Personal Information Protection table
Customer Consultation and Reporting Regarding Personal Information Protection
DepartmentSK Rent-a-Car Information Protection Center
Person in ChargeJong-won Jeong
Contact Number+82-2-6474-5796

12. Installation and Operation of Visual Data Processing Devices

① The Company installs and operates visual data processing devices as follows:
1. Grounds and purposes for installation of visual data processing devices
- Company facility safety and fire prevention
- Crime prevention for customer safety
- Prevention of vehicle theft and damage

2. Number of installations and locations: Number of installations by branch and branch locations

Installation and Operation of Visual Data Processing Devices table
Location of InstallationNumber of InstallationScope of FilmingVisual Data Officer
SK Rent-a-Car entrance on each floor20 unitsInsideGeneral Affairs PL
Jeju EV Park parking tower, maintenance workshop, office entrance, etc.77 unitsInside / OutsideJeju Contents Business Team Head
Jeju Billy Car parking lot, car wash building, desk entrance, etc.33 unitsInside / OutsideJeju Vehicle Management QC Team Head
Parking lots and office entrances at direct branches other than the headquarters10 unitsInside / OutsideRegionals Project Team Heads
Regional logistics center entrances and parking lots30 unitsInside / OutsideRegional Logistics Center Managers
Branch / CentersDiffers by branch / centerEach business operation’s title holders (Branch Heads, Center Managers, etc.)

3. Visual data officer, responsible department, and person with access to visual data: Each branch’s person in charge
4. Visual data filming hours, retention period, storage location, and processing method
- Filming hours: 24 hours
- Retention period: 30 days from the time of filming
- Storage location and processing method: stored and processed in each branch’s visual data processing device management system
5. Method and place for checking visual data: Request each branch’s person in charge
6. Measures in response to data subjects’ request to view visual data: An application must be made with a request for inspection/confirmation of the existence of the personal visual data, and access is allowed only when the data subject himself/herself is filmed, or when it is explicitly required for the benefit of the data subject’s life, body, and property.
7. Technical, managerial, and physical measures to protect visual data: Establishment of an internal management plan, access control and restriction of access rights, application of safe storage and transmission technology of visual data, storage of processing records and measures for preventing forgery or alteration, and provision of storage facilities and installation of locking devices.

13. Amendments to the Privacy Policy

① Any addition, deletion, and correction of the Privacy Policy made pursuant to changes in applicable laws, policies, or security technologies will be notified on the website at least seven (7) days prior to the enforcement date of such the amended Privacy Policy, including reasons and details of the changes.

② This Privacy Policy is effective from 29, May, 2025.