With the advancement of the digital economy and the expansion of digital trade frameworks such as RCEP and DEPA, the regulation of cross-border transfers of personal information has emerged as a key issue closely related to national security and digital jurisdiction. In response to these developments, Korea established diversified transfer mechanisms aligned with global standards through the 2023 amendments to the Personal Information Protection Act (PIPA), while China, centered on the Personal Information Protection Law (PIPL), developed a risk-governance framework based on security assessments, personal information protection certification, and standard contractual mechanisms. However, differences in the legislative values and regulatory philosophies underlying the two legal systems have generated significant legal and institutional frictions. In particular, the structural divergence in the definition of sensitive personal information, as well as the lack of compatibility between Korea’s adequacy decision regime and China’s certification framework grounded in the state’s protective responsibilities, has increased compliance burdens for multinational enterprises operating across the two jurisdictions. To mitigate these regulatory frictions, this study argues that the expansion of rigid jurisdictional controls should be avoided and that a cooperative governance model based on the principle of functional equivalence should be pursued. Specifically, the paper proposes: (1) the establishment of a mutual recognition mechanism for cross-border certification standards through cooperation among private self-regulatory organizations; (2) the creation of a permanent dialogue channel between the regulatory authorities of the two countries (PIPC and CAC), together with procedural mutual recognition of the domestic representative system under the RCEP framework; and (3) the development of a cross-border data corridor through the linkage of data negative lists within the framework of the Korea–China FTA and the introduction of a cross-border regulatory sandbox in designated special zones. This study contributes to the comparative analysis of Korea’s and China’s regulatory frameworks governing cross-border transfers of personal information. It seeks to provide a positive-law-based approach for reducing regulatory frictions between the two systems while balancing data sovereignty and economic efficiency, and offers policy implications for the development of a digital trust infrastructure in the Asia-Pacific region.
한국어
디지털 경제의 고도화와 RCEP, DEPA 등 디지털 통상 규범의 확산에 따라 개인정보 국외 이전 규제는 국가 안보와 디지털 관할권 확보의 핵심 과제로 부상하였다. 이에 대응하여 한국은 2023년 「개인정보 보호법(PIPA)」 개정을 통해 글로벌 표준에 부합하는 다원화된 이전 경로를 확립하였고, 중국은 「개인정보보호법(PIPL)」을 중심으로 안전평가·인증·표준계약 체결을 주축으로 하는 리스크 거버넌스 체계를 구축하였다. 그러나 양국 법제가 표방하는 입법 가치와 규제 철학의 차이는 심층적인 법리적 교착 상태를 야기하고 있다. '민감개인정보' 정의의 구조적 불일치와 한국의 국가별 '적정성 결정' 제도 및 중국의 '국가 보호 의무' 중심 인증 체계 간의 호환성 결여는 역내 다국적 기업의 컴플라이언스 부담을 가중시키는 주요 원인이다. 이러한 규제 마찰을 완화하기 위해서는 경직된 관할권 확장을 지양하고, 법제 간 실질적 효과의 동질성을 인정하는 '기능적 동등성(Functional Equivalence)'에 기반한 협력적 거버넌스를 모색해야 한다. 이를 위한 구체적인 연계 방안으로 본 논문은 첫째, 민간 자율기구 간 협력을 통한 국경 간 인증 표준의 상호 인정 체계 구축, 둘째, 양국 규제 당국(PIPC-CAC) 간 상시 대화 채널 개설과 RCEP 프레임워크를 활용한 국내대리인 제도의 절차적 상호 인정, 셋째, 한·중 FTA 구조 및 특정 특구를 활용한 데이터 네거티브 리스트 연계와 '국경 간 규제 샌드박스' 도입을 통한 데이터 전용 회랑 구축을 제안한다. 본 연구는 한·중 양국의 개인정보 국외 이전 규제 체제 간의 마찰을 해소하고, 데이터 주권 확보와 산업적 효율성을 양립할 수 있는 법제적 기반과 아시아·태평양 지역의 디지털 신뢰 인프라 형성을 위한 실정법학적 대안을 제시하는 데 의의가 있다.
목차
요약 Ⅰ. 서언 Ⅱ. 한국 개인정보 국외 이전의 법적 규제 체계 Ⅲ. 중국 개인정보 국외 이전의 법적 규제 체계 Ⅳ. 한중 개인정보 국외 이전 규제 체계의 다차원적 비교 Ⅴ. 지역 디지털 거버넌스 배경하 한·중 개인정보 국외 이전 규칙 연계의 난제와 해법 Ⅵ. 결어 <참고문헌>
전북대학교 동북아법연구소 [Institute for North-East Asian Law]
설립연도
2007
분야
사회과학>법학
소개
전북대학교 동북아법연구소는 동북아법에 관한 국내외의 이론과 실제를 연구하고 교육하며, 그 결과를 발표하여 동북아법에 대한 이해의 증진과 동북아의 법률문화발전에 기여하기 위한 목적으로 2006년 7월 설립되었다.
서해안시대의 중심지역을 표방한 전라북도의 지리적 여건과 동북아시아의 여러 국가와의 인적 물적 교류가 확대되면서 그에 따른 여러 가지 법률문제가 발생됨에 따라 동북아시아의 지역적 특성을 고려한 법제도의 연구와 이들 국가와 거래하는 전북지역 자치단체와 기업에 대한 실질적 교육의 필요성이 대두되었다.
이러한 요청에 따라 법제도의 연구와 교육을 담당할 기관으로 전북지역 거점국립대학인 전북대학교가 동북아법연구소를 설립하게 되었고 전북 지방자치단체와 기업에 대한 교육과 자문프로그램을 운영하고 있다.