스팸 수신거부 제도의 역설적 효과와 사이버범죄 피해 확대 - 양끝단 원칙의 관점에서 본 제도 개선 방향 -
Paradoxical Effects of the Anti-Spam Opt-Out Regime and Cybercrime Victimization - Institutional Reform in Light of the End-to-End Principle -
This study analyzes how Korea's anti-spam opt-out system under Article 50 of the Information and Communications Network Act, originally designed to protect users from unsolicited advertising, may paradoxically transform recipients' opt-out responses into a secondary form of personal information — namely, “active number” status — that can be incorporated as a preparatory resource in voice phishing and smishing operations. Rather than serving purely as a protective device, the opt-out system inadvertently certifies which phone numbers are presently in active use and reachable, generating data that may subsequently circulate in informal markets. The study borrows the four-dimensional analytical framework — regulatory effectiveness, scope of application, rights of the data subject, and scope of protection — that Park (2017) used in his critical review of the Korea Communications Commission's Online Behavioral Advertising Personal Information Protection Guidelines, and extends its application to the opt-out regime. Despite the formal coherence of the prior-consent / opt-out / no-retransmission sequence, the regime is shown to operate at a level of merely formal compliance. The active number information generated by opt-out responses constitutes secondary processed personal information yet remains absent from the statutory protection scope; the Korea Internet & Security Agency's “personal information illicit distribution reporting system” documents the general existence of an informal personal-data market without specifying active numbers as such. The study designates this configuration as “the paradox of active object verification” and introduces the concept of an “institutional legitimacy cue” as a hypothetical operational mode distinct from but adjacent to Kim & Suh's (2021) confirming factor, formalizing how a lawful procedural record may persist as a weak basis for legitimacy inference at the evaluation stage of subsequent contact. Drawing on the end-to-end principle (Saltzer, Reed, & Clark, 1984) as a heuristic resource for diagnosing the inefficiency of diffused responsibility — and grounding the normative attribution itself in Korean tort-law causation doctrine and Calabresi's cheapest cost avoider principle — the study argues that responsibility, currently blurred across intermediary nodes, can be restored to the endpoints (advertiser and data subject) through institutional redesign. A comparative review of the U.S. Telephone Consumer Protection Act (TCPA) and the EU General Data Protection Regulation (GDPR) yields two convergent reform implications: distributed enforcement through statutory damages and class actions, and a multi-layered structure of data-subject claim rights. On this basis, the study proposes three institutional reform directions: (i) introduction of a “transmission-path disclosure claim right,” (ii) substantive expansion of the no-retransmission rule with permanent effect across delegated processors and third-party recipients, and (iii) construction of a distributed enforcement mechanism combining statutory damages, private rights of action, and class action procedures. To our knowledge, this study is among the earliest attempts to analyze the paradox of the opt-out system from a criminological perspective, connecting two previously separate research areas — anti-spam regulation studies and criminological research on voice phishing and smishing — through cross-analysis. By reframing the opt-out system as a structural component embedded within crime causation rather than a mere consumer protection device, the study aims to offer a starting point for subsequent empirical and policy research.
한국어
본 연구는 정보통신망법 제50조의 수신거부 제도가 광고성 정보로부터 이용자를 보호하려는 입법의도와 달리, 수신자의 거부 응답을 ‘활성 번호’라는 2차 개인정보로 가공하여 보이스피싱·스미싱 범죄의 준비 단계에 편입될 가능성을 메커니즘 가설로 정식화한다. 본 연구는 박성용(2017)이 방송통신위원회 「온라인 맞춤형광고 개인정보보호 가이드라인」을 비판할 때 사용한 네 측면의 분석틀인 규제 실효성, 적용대상, 정보주체 권리, 보호대상을 수신거부 제도 영역에 확장 적용하여 결함 구조를 해부한다. 분석결과 수신거부 제도는 사전 동의 — 수신거부 — 재전송 금지의 정합적 외관에도 불구하고 형식적 이행에머물며, 수신거부 응답을 통해 확인된 활성 번호가 광고주의 2차 가공 개인정보로서 보호 대상에서 누락된 채 장외 시장에서 거래되어 보이스피싱·스미싱 범죄의 준비 자원으로 전환될 수 있는 구조를 가진것으로 나타난다. 본 연구는 이를 ‘활성화 객체 증명의 역설’로 명명하고, 김경진·서준배(2021)의 컨빈서(confirming factor) 개념과 구별되는 별개의 작용 양상을 ‘제도적 정당성 단서(institutional legitimacycue)’로 잠정 명명하여 합법 제도가 후속 연락의 평가 단계에서 정당성 추정의 약한 근거로 잔존할 가설적 작용을 정식화한다. 이론적으로 양끝단 원칙(Saltzer et al. 1984)·간접성에 의한 책임 희석 명제(Lessig 2006)·신뢰의 역설(O'Neill 2002)·범죄경제학적 억지 모형(Becker 1968)을 책임 분산 구조의비효율성을 진단하는 발견론적 자원으로 활용하고, 책임 귀속의 규범적 정당성은 한국 불법행위법의인과관계 법리와 Calabresi의 최적 억지자 원리에서 도출하여, 미국 TCPA와 EU GDPR의 비교법적 검토를 거쳐 경로 공개 청구권의 도입, 재발송 금지의 실질화, 분산형 집행 메커니즘의 구축이라는 세 가지제도 개선 방향을 제안한다. 본 연구는 수신거부 제도의 역설을 범죄학적 관점에서 분석하여, 스팸 규제연구와 보이스피싱·스미싱 범죄학 연구로 분리되어 있던 두 연구 영역을 교차 분석하여 연결하는 데기여한다.
목차
요약 Ⅰ. 서론 Ⅱ. 현행 수신거부 제도의 법적 구조 Ⅲ. 수신거부 제도의 역설적 효과 Ⅳ. 이론적 재구성 Ⅴ. 비교법적 검토 Ⅵ. 제도 개선 방향 Ⅶ. 결론 <참고문헌>