생성형 인공지능 모델의 개인정보 라이프 사이클에 따른 국내 개인정보 보호법 개선 고려 요소 : GDPR과 개인정보 보호법의 비교·분석
Considerations for the Improving Domestic Personal Information Protection Act in accordance with The Life Cycle of Personal Information In Generative Artificial Intelligence Model : Comparative analysis of GDPR and Personal Information Protection Act of Korea
The purpose of this paper is to derive considerations when improving the Personal Information Protection Act ba sed on the personal information protection life cycle of the generative artificial intelligence model as generative artifi cial intelligence models are introduced and used in Korea a lot. Through the study, the necessity of using open infor mation in the collection stage, using personal information preservation technology in the learning stage, and preparin g the basis for the development of protection technology in the holding stage was derived. It also revealed the nece ssity of managing the generated information in the generation and inference stage, re-learning in the limitation and destruction stage, and preparing a filtering basis. It is expected that the results of this study can be used to revise the Personal Information Protection Act and make policies in the future.
한국어
본 논문은 기존에 개발된 개인정보 라이프 사이클 모델을 정리 및 분석 후 이러한 개인정보 라이프 사이클 모델이 인공지능 학습에 적용 가능한지를 살펴보았다. 검토 결과 기존의 개인정보 라이프 사이클은 인공지능 학습의 적용에 일 부 한계가 있음을 발견했다. 따라서 본 논문에서는 인공지능 학습에 적합한 개인정보 라이프 사이클을 제시했다. 새로 운 개인정보 라이프 사이클은 수집-학습-보유-생성·추론-차단·재학습·삭제 단계로 구성했다. 새로운 모델 제시에 따라 현행 개인정보 보호법 조항과 일치 여부를 검토 후 향후 법령 개정 방향을 제시했다. 본 논문은 인공지능 학습과 개인 정보 보호의 영역에서의 체계적 접근 가능성을 높였다는 측면에서 의의가 있다.
목차
요약 ABSTRACT 1. 서론 2. 인공지능 관련 규제 현황 2.1 유럽 일반 개인정보 보호법 - 프로파일링 2.2 개인정보 보호법 - 자동화된 결정 2.3 GDPR과 개인정보 보호법 관련 규정 비교 3. 생성형 인공지능의 라이프 사이클단계별 개인정보 보호 법령 검토 3.1. 개인정보 보호 라이프 사이클 모델 3.2 수집 3.3 보유 3.4 학습 3.5 이용 3.6 파기·정지 4. 보호법 근거 조항 마련 시 라이프 사이클 단계별 고려 요소 4.1 단계별 고려 요소 4.2 요약 5. 결론 참고문헌