년 - 년
A Legal Expression of the Limited Holding Right of Corporate Data Resources KCI 등재
중국지역학회 중국지역연구 제12권 제4호 통권37호 2025.11 pp.363-388
※ 기관로그인 시 무료 이용이 가능합니다.
6,400원
기업은 합법적으로 가공 및 수집한 기업 데이터를 보유할 수 있으나, 현행 법률은 기업이 합법적으로 보유한 데이터에 대해 가지는 권리의 성격을 명확히 규정하지 않고 있다. 기업에 고도로 배타적인 재산권을 부여할 경우 기업과 개인 간의 이익 균형을 이루기 어렵고, 기업 의 데이터에 대한 기존 권리가 분산된 권리 묶음일 경우 기업 데이터 권리 행사에도 불리하 다. 따라서 기업은 합법적 보유 및 데이터 통제를 기반으로 데이터에 대해 제한적 배타성을 지닌 단일 권리, 즉 기업 데이터 자원 제한적 보유권을 행사해야 한다. 보유권의 핵심 권한은 기업이 권한 범위 내에서 데이터 재산 가치 전환을 실현하는 데 있다. 한계성은 개인이 「개인정보 보호법」 제45조 '휴대권'을 통해 재산적 권익을 양도하고 인격적 이 익을 보존함으로써 이익 균형을 실현할 수 있으며, 데이터 거래 자유 보장, 합리적 데이 터 크롤링 및 데이터 독점 방지를 위해 다른 기업의 합리적 데이터 크롤링 행위를 당연 히 「부정경쟁방지법」 제2조의 부정경쟁 행위로 간주해서는 안 되며, 크롤링 데이터의 행위, 범위 및 활용 효과와 사회적 가치를 종합적으로 검토해야 한다는 점에 있다.
Enterprises may lawfully hold the data they collect and process; however, current legislation does not clearly define the legal nature of the rights that enterprises enjoy over such lawfully held data. If enterprises were granted highly exclusive property rights, the balance between corporate and individual interests could not be maintained; conversely, if enterprise rights were confined to a fragmented “bundle of rights,” the effective exercise of data rights would be undermined. Accordingly, enterprises should be recognized as possessing a singular yet non-absolute entitlement grounded in lawful holding and control—namely, the Limited Holding Right in Corporate Data Resources. The core function of this holding right lies in enabling enterprises to realize the economic value of data within the scope of lawful authorization. Its “limited” nature operates on two dimensions. First, under the Personal Information Protection Law (PIPL), Article 45, individuals may exercise the right to data portability to transfer their economic interests while retaining personality interests, thereby achieving a balance between dignity and property. Second, within the corporate market order, data transaction freedom must be safeguarded, reasonable data scraping must be tolerated, and monopolistic practices must be prevented. Consequently, reasonable scraping by other enterprises should not automatically be deemed “unfair competition” under the Anti-Unfair Competition Law (AUCL), Article 2, but should instead be evaluated comprehensively in light of the scraping conduct, scope, utilization outcomes, and social value.
企业合法持有其加工、收集的企业数据,但现行法律没有明确企业对其合法持有的数 据享有的权利性质。如果配置企业以高度排他性的财产权,则不能平衡企业与个人之间 的利益,若企业对数据现有的权利为分散的权利束,也不利于对企业数据权利的行使。 因此,企业应当以合法持有、控制数据为基础,对数据享有有限排他的单一权利,即企 业数据资源有限持有权。持有权核心权能体现在,企业在授权范围内实现数据财产价值 转化。有限性在于个人可通过《个人信息保护法》第四十五条“携带权”转让财产性权益 保留人格利益以实现利益平衡,以及为保障数据交易自由、合理数据爬取并防止数据垄 断,其他企业合理的数据爬取行为不能当然认定是《反不正当竞争法》第二条中的不正 当竞争行为,应根据抓取数据的行为、范围以及利用效果与社会价值进行综合审查。
EU의 GDPR 제20조에 전송요구권 도입 이후 우리나라 개인정보보호법 개정 안에도 전송요구권이 포함되어 논의되고 있다. 개인정보 전송요구권은 마이데이 터를 구현하기 위해 필요한 정보주체의 핵심적인 권리 중 하나이다. 이 연구는 의료분야 마이데이터를 실현하기 위해 의료정보에 대한 전송요구권의 도입가능성에 대한 것이다. 의료정보 전송요구권 구현을 위해 개인정보보호법 개정안을 포함한 개인정보보호법제와 보건의료법제의 제한점과 한계에 대하여 검토하였 고, 이후 이를 극복하기 위해 필요한 입법정책적 제안을 하고자 하였다. 개인정 보보호법은 개정안을 포함하여 전송 대상 정보의 개념과 기술적인 전송형식, 이 행의무자 규모의 문제가 있고, 그 입법취지 역시 의료 마이데이터를 구현하기 위한 그것과는 차이가 있다. 또한 보건의료법제 하에서 기록열람과 진료기록의 송부와 관련된 의료법 규정, 진료정보교류 관련 법제 역시 아직까지는 주체, 대 상이 매우 한정적이라는 한계가 있다. 이에 의료정보와 의료 분야의 특수성을 고려해 개인정보보호 법제 하에서는 전송요구권의 최소한의 기본을 규정하고 이후 보건의료 분야 개별 법률에서 추가적 규율하는 것을 제안한다.
Two bills have recently been proposed at the Korean National Assembly to introduce data portability provisions to the Personal Information Protection Act. The two bills were largely modeled on Article 20 Right to Data Portability of European Union’s General Data Protection Regulation (“GDPR”). We argue that the proposed “one-size-fits-all” provisions are ill-suited to health data portability for a few reasons. First and foremost, the bills stop short of mandating interoperability of data being transferred, in a manner similar to the GDPR. Unlike in some other sectors, however, interoperability is critical in achieving ease of data transmission in health care, because health IT is highly fragmented with numerous vendors, each with their own data format. Secondly, the two bills exempt inferred data and derived data from data portability, also in a manner similar to the GDPR. While such exemption may be striking a balance between the interest of individuals and the interest of data controllers, it renders data portability almost valueless in the context of health care, where important data are usually inferred data and derived data created by health providers. Lastly, an exemption from data portability for small businesses will be at odds with health care, in which primary care clinics are inevitably “small businesses”. These limitations found in the data portability bills are not surprising, in light of the core objective of their model, Article 20 of the GDPR, which was to promote competition by helping users retrieve their data held by dominant service providers. Hence, we argue that a better approach to health data portability is to amend the Medical Service Act that already includes basic measures to facilitate data exchange between health providers. Although the Medical Service Act too has to be amended to implement health data portability in the scale already being implemented in other countries, it will not be limited by the need for universal applicability across different industries that the general, Personal Information Protection Act faces. Instead, more nuanced and sophisticated health data portability can be designed in the Medical Service Act that provides more clarity to complex legal issues unique to health data, such as interoperability, data scope, health information exchange and secondary use, to name a few.
8,700원
21세기, 우리는 AI에 근거한 데이터 활용 시스템을 가능하게 하고, 데이터의 생성과 소멸까지를 통제할 수 있는 데이터 기본권 논의를 제시 해야만 한다. 이를 위하여 구체적으로 정보은행 인증제도, 마이데이터 사업의 인증 시스템, AI에 의해 프로파일링된 자동의사결정에 통제, 신용정보법, 개인정보보호법, 관련 데이터 기구 구성 논의에 까지 헌법에 근거한 데이터 통제권론에 근거한 뉴노멀 시스템을 연구한다. 디지털 전 환의 지능정보화 사회에서 각종 데이터와 개인정보의 합리적 보호와 활용은 헌법상으로도 중요한 가치이다. 세계는 2010년대부터 도입이 논의 된 마이데이터 시스템과 EU의 GDPR에서 인정된 데이터 이동권(right to data portability)을 인정하게 되었다. 이러한 때, 대한민국 헌법학에서도 개인데이터의 보호와 활용의 양자 의 조화를 꽤하면서도 데이터의 생성과 소멸에 걸치는 권한을 정보주체 에게 합리적으로 보장하기 위한 논의를 제시해야만 하는 상황이다. 특히 마이데이터에 의해 새로운 데이터의 처리에 종래 개인정보자기결정권 개 념과는 조화되는 않는 점이 있다. 반면, 데이터의 이동권을 인정하고 개 인정보의 통제권을 인정하는 EU, 미국(right to access 정보접근권), 일 본의 국가는 이러한 새로운 데이터 상황을 각자 유연하게 대처하고 있다. 따라서 대한민국도 헌법상 개인정보자기결정권 논의를 21세기에 적합하게 데이터 통제권으로 변화하여 데이터 이동권, 마이데이터 시스템, 핀테크, 기타 AI에 근거한 데이터 활용 시스템을 가능하게 하면서, 데이 터의 생성·거래·유통·소멸까지의 개인정보 자기통제권을 인정하는 논의 로 전환해야한다. 이를 통하여 구체적으로 정보은행 인증제도, 마이데이 터 사업의 인증 시스템, AI에 의해 프로파일링된 자동의사결정에 통제, 신용정보법, 개인정보보호법, 관련 데이터 기구 구성 논의에 까지 헌법 제10조, 제17조, 제18조에 근거한 개인정보통제권에 근거한 뉴노멀 시스템의 구현을 구체화해야 한다.
In the 21st century, we should present a discussion of the fundamental rights of data that enables data utilization systems based on AI, the right to control data from creation to destruction. For this end, I research the right to control data theory based on the Constitution related with the information bank authentication system, the authentication system of the My Data business, control over automatic decision-making profiled by AI, the Credit Information Act, the Personal Information Protection Act, etc. In the intelligent information society of digital transformation, rational protection and utilization of various data is an important constitutional value. The world recognizes the MyData system, which has been discussed since the 2010s, and the right to data portability recognized by the EU's GDPR Article 20. At this time, even in the case of constitutional studies of the Republic of Korea, it is necessary to present a discussion for rationally correcting the authority over the creation and destruction of data to the data subject while maintaining a good balance between the protection and use of personal data. In particular, there is a point that does not harmonize with the conventional concept of the right to self-determination of personal information in the processing of new data by My Data. On the other hand, countries such as the EU, the US (right to access information) and Japan, which recognize the right to transfer data and control the right to personal information, are flexibly responding to this new data situation. Therefore, by changing the discussion on the right to selfdetermination of personal information in Constitution to the right to control data suitable for the 21st century, the right to data transfer, my data system, fintech, and other AI-based data utilization systems are possible. We should turn to a discussion that recognizes the right to control data up to the creation, transaction, distribution and destruction. Through this, the information bank authentication system, my data business authentication system, control over automatic decision-making profiled by AI, the Credit Information Act, the Personal Information Protection Act, and the constitution of related data organizations are discussed in Articles 10 and 17 of the Constitution. The implementation of a new normal system based on data control rights based on Articles 18 and 18 should be specified.
Under the background of digital economy, data, as a new factor of production, plays an extremely important role in resource allocation. The collection, storage and transfer of personal data are gradually normalized, and personal data has become an important resource for public management, social services and business competition. However, the problem also emerges. How to realize the free flow of data while protecting the rights of data subjects to their personal data, and create a win-win situation between the protection of personal data rights and the development of digital economy is a major problem facing the world. The emergence of the portability right of personal data undoubtedly provides ideas for the solution of this problem. In the exercise of this right, the data subject can independently control the flow of personal data among different data controllers, which has the dual effect of enhancing the self-determination right of the data subject and promoting the competition in the data market. At present, the European Union, some states of the United States, Brazil and other countries and regions are formulating laws to raise the right of data portable as a personal data right, and there are also relevant provisions in China's Personal Information Protection Law. As a response to the protection of personal information in the digital age, the right to data portability has a far-reaching significance in protecting the data control rights of users and the barrier-free data transmission. Major countries in the world are already building localized specific specifications for the right to carry personal data, and it will reach more countries and regions in the future. The right to carry personal data is not only related to personal interests, but also an important means to develop the digital economy and realize the marketization of data elements. Therefore, China should also timely build a specific system for the right to carry personal data with Chinese characteristics according to its national conditions. Based on the normative interpretation of China's Personal Information Protection Law, the practical needs of data subjects to realize the right of personal information, and the useful reference of the judicial practice of countries outside the region, the data portable right has further applicable legal logic. The portability of personal data is an extension of the rights and interests of personal information in the Civil Code of China. The establishment of this right can effectively strengthen the individuals' possession and effective control of data, which can not only enable individuals to gain personality independence in the digital economy, but also become a beneficiary of data contribution and reuse. The study of the right to data portability is conducive to improving the personal data protection system, and further clarifying the data ownership and transfer between individuals and enterprises, and between enterprises and enterprises. Unfortunately, there are still disputes between the property right and the personality right in the legal property of the current data portable right, and the fuzzy exercise rules and the confusion of the scope of application lead to its unsatisfactory effect. In view of the problems of the right to data portability, China build personal data carrying system can draw lessons from the European Union and other countries mode and system specification, but not copy, it is in the practice of carrying data at home and abroad and mode analysis and research under the premise of, conform to China's national conditions and the development status of the specific design. Firstly, the dual attribute of “property right + personality right” should be clarified. It not only fully reflects the personal characteristics and rights of the data subject, but also highlights the economic value created by the personal data for the data subject. Secondly, the right structure of data carrying right should be refined. Determine the natural person as the right subject of personal data carrying rights; identify the subject with important decision function of data as the obligation subject of personal data carrying rights; regulate the regulation of the object of rights and the scope of rights object from the perspective of adaptation scope and exclusion scope; and for the purpose of preventing the abuse of data carrying rights, add restrictive clauses to exercise the right within the appropriate scope. Finally, Establish a supporting mechanism for the right of personal data, improve the relief channels for the right of personal data, and at the same time, establish a perfect data protection supervision system from the three aspects of the country, industry and enterprises.
数字经济背景下,数据作为新的生产要素,在资源配置中发挥了极其重要的作用。 个人数据的收集、存储与转移逐步常态化,个人数据成为公共管理、社会服务和商业 竞争的一项重要资源。但问题也随之显现出来,如何在保护数据主体对其个人数据的 权利的同时实现数据的自由流动,打造个人数据权利保护与数字经济发展共赢局面是 全球面临的重大难题。个人数据可携权的出现无疑为这一问题的解决提供了思路,在 该权利的行使中,数据主体可以自主控制个人数据在不同数据控制者之间流转,具有 增强数据主体自决权与促进数据市场竞争的双重效果。目前,欧盟、美国部分州、巴 西等国家和地区都在制定法层面将数据可携权上升为一项个人数据权利,中国《个人 信息保护法》中亦有可携权的相关规定。作为数字时代下个人信息保护的回应,个人 数据可携带权在保障用户主体数据控制权益,以及数据无障碍传输方面意义深远。世 界主要国家已经在构建本土化的个人数据可携带权具体规范,而且未来将会遍及更多 的国家和地区。个人数据可携带权不仅关系个人利益,更是发展数字经济,实现数据 要素市场化的重要手段。因此,中国也应根据国情和实践,建设具有中国特色的个人 数据可携带权的具体制度规范。基于中国《个人信息保护法》的规范解读、数据主体实现个人信息权利的现实需要以 及其他域外国家司法实践的有益参考,个人数据可携带权具有进一步适用的法理逻 辑,个人数据可携权是中国《民法典》关于个人信息权益的延伸,该权利的确立可以有 效强化个人对于数据的占有和有效控制,既可以使个人在数字经济中获得人格的独 立,也可以成为数据贡献和再利用的受益者。研究个人数据可携带权有利于完善个人 数据保护体系,进一步厘清个人与企业、企业与企业之间的数据归属和转移问题。 遗憾的是,当前个人数据可携带权的法权属性仍存在财产权与人格权的争议,同时 行权规则的模糊以及适用范围的混乱导致其效果差强人意。针对个人数据可携带权存 在的问题,中国构建个人数据可携带权制度可以借鉴欧盟等国家的模式和制度规范, 但并非照搬照抄,而是在对中国个人数据可携带权的实践状况和模式进行分析和研究 的前提下,提出符合中国国情和数据发展现状的具体设计。首先,明确个人数据可携 带权“财产权+人格权”的双重属性,不仅充分体现数据主体的个人特征和权利,也突 出个人数据为数据主体创造的经济价值。其次,细化数据可携带权的权利结构,将自 然人确定为个人数据可携带权的权利主体;将对数据的处理与利用有重要决策作用的 主体确定为个人数据可携带权的义务主体;对权利客体的规制与权利分配关系密切, 因此从适应范围和排除范围的视角出发,以类型化的方法对权利客体的范围进行规 制;出于防止数据可携带权的滥用的目的,增添限制性条款,使权利在合适的范围内 得到行使。最后,构建个人数据可携带权的配套机制,完善数据主体对其个人数据可 携带权的救济途径,同时从国家、行业和企业三个方面建立完善的数据保护监管体 系。
[NRF 연계] 경상국립대학교 법학연구소 법학연구 Vol.32 No.3 2024.07 pp.51-78
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
생성형 인공지능은 기존 데이터 경제에 많은 변화를 불러왔고, 데이터로서의 개인정보에 관한 법제들도 이 변화에 있어 예외는 아니다. 과거 개인정보는 산업 부가가치 창출을 위한 진흥의 대상이기보다는 규제를 통해 보호해야 할 대상으로 인식되었다. 그리고 관련 법제들도 개인정보의 유출·오용·남용 등의 침해로부터 국민의 사생활의 비밀을 보호하고, 개인정보에 대한 정보주체의 권리와 이익을 보장하려는 목적으로 개인정보를 포함하는 데이터의 유통을 통제하는 방식으로 입법되었다. 이처럼 기존의 관련 법제에서 개인정보는 보호와 통제의 대상으로 규제되는 경향이 강했다. 그러나 생성형 인공지능이 범용인공지능으로 사회 전반에 실질적 영향력을 미치게 된 현재에는 데이터를 재산권적 관념으로 인식하려는 움직임이 시작되고 있으며, 개인정보의 유통으로 인해 얻을 수 있는 부가가치를 정보주체에게 환원하여 데이터의 실체적 활용을 활성화하기 위한 다양한 법제의 개발로 관심이 전환되고 있다. 인공지능 기술은 제2의 겨울을 극복하고 딥러닝, 생성형 인공지능 등 기술적 진화를 거듭하고 있다. 과거 이세돌 구단과의 바둑 대국에서 알파고의 우승은 인공지능 기술의 발전을 단편적으로 보여주었고 많은 국민들의 이목을 집중시켰지만, 알파고가 바둑 대국에서 승리했다고 해서 이러한 바둑기술이 경제적 이윤 창출로 직결되는 것은 아니었다. 이 대국을 통해 구글은 딥러닝 기술의 발전을 보여주었고 세계가 놀라움에 휩싸였지만, 이 기술이 어떤 상품으로 개발되고 판매되어 경제적인 부가가치를 창출하여 구글에게 이윤을 제공한 것은 아니었기 때문이다. 그러나 생성형 인공지능의 등장과 함께 다양한 산업분야에서 인공지능 기술을 활용한 상품이 개발되고 상용화되어 실체적인 경제적 부가가치를 창출하기 시작했다. 쳇GPT로 대표되는 생성형 인공지능이 범용인공지능으로 상용화됨에 따라 인공지능 기술이 산업분야에서 실체적인 경제적 부가가치를 창출할 수 있는 새로운 국면 전환이 일어나고 있다. 결국 산업혁명 시대의 석유에 비견되는 양질의 데이터의 확보와 유통이 신산업분야의 실체적인 성공의 핵심 요건으로 인식되면서, 개인정보 보호를 위해 출발했던 정보주체의 개인정보자기결정권의 개념이 양질의 데이터 유통과 이를 통한 산업 데이터의 확보라는 개념으로 확장되어 새롭게 조명 받고 있다. 개인정보를 포함하는 데이터를 통해 얻어진 부가가치의 환원에 있어서도 주요한 개념인 개인정보자기결정권은 데이터 경제가 본격화됨에 따라 개인정보를 포함하는 데이터가 상업적·행정적으로 활용되면서 개인정보 보호의 필요성에서 개인을 자기정보에 대한 독자적인 결정권을 가진 법적 정보주체로 인식하기 위해 개념화되었다. 개인정보자기결정권은 개인정보 보호를 목적으로 논의가 시작되었지만 데이터가 산업 부가가치 생산에 있어 주요 자원으로 인식되면서, 데이터 독점을 해소하고 개인에게 데이터 유통을 통해 생산한 부가가치를 환원하여 양질의 데이터가 산업 전반에 보다 적극적으로 활용될 수 있도록 하기 위한 진흥의 관점으로 인식의 전화을 맞이하고 있다. 따라서 개인정보 보호를 목적으로 시작된 개인정보자기결정권의 개념을 데이터의 재산권적 의의를 인식할 수 있는 개념으로 확장하여 인식함으로써 개인정보의 유통 및 활용을 통 ...
Generative AI has brought about many changes to the existing data economy, and laws regarding personal information as data are no exception to this change. In the past, personal information was recognized as a subject to be protected through regulation rather than a subject to be promoted for the purpose of creating industrial added value. In addition, related laws were legislated in a way that controlled the distribution of data containing personal information in order to protect the privacy of citizens from infringements such as leakage, misuse, and abuse of personal information, and to guarantee the rights and interests of information subjects regarding personal information. In this way, personal information tended to be regulated as a subject of protection and control in existing related laws. However, now that generative AI has had a real impact on society as a general-purpose AI, a movement to recognize data as a property right is beginning, and interest is shifting to the development of various laws to return the added value obtained from the distribution of personal information to the information subjects and activate the actual use of data. Artificial intelligence technology is overcoming the second winter and undergoing technological evolution such as deep learning and generative AI. AlphaGo's victory in the past Go match against Lee Sedol briefly demonstrated the development of artificial intelligence technology and attracted the attention of many people, but AlphaGo's victory in the Go match did not directly lead to economic profit generation. Through this match, Google demonstrated the development of deep learning technology, and the world was amazed, but this technology was not developed into a product or sold to create economic added value and provide profits to Google. However, with the emergence of generative artificial intelligence, products utilizing artificial intelligence technology in various industries have been developed and commercialized, creating tangible economic added value. As generative artificial intelligence represented by ChetGPT is commercialized as general-purpose artificial intelligence, a new phase of transition is occurring in which artificial intelligence technology can create tangible economic added value in the industrial sector. Eventually, as the acquisition and distribution of high-quality data, comparable to oil in the Industrial Revolution era, became recognized as key requirements for the actual success of new industries, the concept of the information subject's right to self-determination of personal information, which started out as a means of protecting personal information, expanded into the concept of distributing high-quality data and securing industrial data through it, and is now receiving renewed attention. The right to self-determination of personal information, which is also a key concept in the return of added value obtained through data containing personal information, was conceptualized to recognize individuals as legal information subjects with independent decision-making rights over their own information in response to the need for personal information protection as data containing personal information was utilized commercially and administratively as the data economy began in earnest. The right to self-determination of personal information was first discussed for the purpose of protecting personal information, but as data became recognized as a key resource in the production of industrial added value, it is now receiving recognition as a promotion perspective to eliminate data monopolies and return the added value produced through data distribution to individuals so that high-quality data can be utilized more actively throughout the industry. Thus, it is necessary to establish a return system in which the added value obtained through the distribution and use of personal information can be returned to the information subject by expanding the concept of the ...
GDPR시행에 따른 데이터 주권강화를 위한 개인정보 이동권에 관한 연구
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2018 pp.300-303
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
유럽연합(EU)의 GPDR(개인정보보호일반규정)시행에 따라 개인정보를 활용하는 사업자 입장에서는 개인정보 보호도 중요하지만 활용측면에 더 많은 관심을 보이고 있다. 개인정보 보호와 활용에 따른 균형점을 찾는 제도적 정착을 위해 개인정보 이동권에 대한 요구가 생겼다. 국내 개인정보 관련 법률에는 아직 근거가 없으며 개인정보처리자의 독립적 데이터 보유에 따른 책임 강화와 정보주체가 자신의 데이터를 관리하는 권리를 가지고 데이터 활용을 할 수 있는 개인정보 자기결정권이 더 요구된다. 이에 따라 본 논문에서는 GDPR의 개인정보 이동권에 대한 현황 및 준수사항을 알아보고 각 나라별 개인정보 이동(data portability)에 따른 개인정보 활용방안과 고려사항을 제시하고자 한다. 개인정보이동에 한 형태로 국내 마이데이터 시범 사업이 정착하기 위한 법칙, 기술적 대응사항을 제시하고자 한다.
GDPR시행에 따른 데이터 주권강화를 위한 개인정보 이동권에 관한 연구
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2018 pp.300-303
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
유럽연합(EU)의 GPDR(개인정보보호일반규정)시행에 따라 개인정보를 활용하는 사업자 입장에서는 개인정보 보호도 중요하지만 활용측면에 더 많은 관심을 보이고 있다. 개인정보 보호와 활용에 따른 균형점을 찾는 제도적 정착을 위해 개인정보 이동권에 대한 요구가 생겼다. 국내 개인정보 관련 법률에는 아직 근거가 없으며 개인정보처리자의 독립적 데이터 보유에 따른 책임 강화와 정보주체가 자신의 데이터를 관리하는 권리를 가지고 데이터 활용을 할 수 있는 개인정보 자기결정권이 더 요구된다. 이에 따라 본 논문에서는 GDPR의 개인정보 이동권에 대한 현황 및 준수사항을 알아보고 각 나라별 개인정보 이동(data portability)에 따른 개인정보 활용방안과 고려사항을 제시하고자 한다. 개인정보이동에 한 형태로 국내 마이데이터 시범 사업이 정착하기 위한 법칙, 기술적 대응사항을 제시하고자 한다.
정보이동권의 국내 도입 방안 - EU GDPR의 관련 규정을 중심으로 -
[NRF 연계] 경희대학교 법학연구소 경희법학 Vol.52 No.3 2017.09 pp.211-232
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
EU에서는 정보이동권이 GDPR에 포함되어 2018년 5월부터 시행될 예정이다. 이동권이란 우리나라에서도 2004년부터 이동전화의 번호이동성제가, 또 2015년에는 계좌이동 서비스가 시행되고 있어 우리나라에서도 그리 생소한 개념은 아니다. GDPR에 따르면 정보이동권이란 정보주체의 동의나 계약에 의하여 개인정보를 수집・처리・보관하는 정보처리자에 대하여 정보주체가 그에 관한 정보를 보내주거나 다른 정보처리자에게 직접 전송할 것을 요구하는 것을 말한다. 2012년 초 GDPR 초안이 공개되었을 때부터 정보이동권에 대하여는 찬반 양론이 많았다. 그러나 정보처리자에게 추가적인 부담을 지우지 않고 비용 문제만 해결될 수 있다면 정보이동권은 IT산업의 경쟁을 촉진하고 소비자들에게도 이익이 된다는 견지에서 바람직하다는 것으로 의견이 모아졌다. GDPR의 시행을 앞두고 EU 집행위 실무작업반에서는 정보이동권에 관한 가이드라인을 공표한 바 있다. 유럽에서는 구글, 페이스북, 애플, 아마존 등 미국의 IT기업들이 플랫폼을 장악하고 정보유통 시장을 지배하는 것에 대한 경계심이 고조되었다. 그 결과 외국의 IT 플랫폼 기업에 대한 데이터 시장 탈환의 무기로 정보이동권을 들고 나온 것이다. 우리나라에 정보이동권을 도입할 것인가의 문제는 거대 IT기업의 정보유통 시장 지배에 대한 경계 못지않게 정보이용 서비스에 대한 유・무형의 규제의 탈피라는 관점에서 살펴볼 필요가 있다. 정보이동권의 도입 취지에 비추어 일차 SNS를 통해 유・불리가 명백히 드러나는 클라우드형 전자우편이나 금융거래정보가 이전의 대상이 될 공산이 크다. 아예 소셜네트워크 서비스 자체를 이전을 요구할 수도 있다. 그 다음에는 IoT를 도입한 커넥티드 카나 네트 가전으로 확장될 것이다. 나아가 헬스케어・의료 분야에서의 이용 가능성은 거의 무한할 것으로 전망된다. 우리나라가 정보이동권제를 도입하기 위해서는 정보통신망법 및 신용정보법에 근거규정을 마련해 놓고 업계의 준비상황을 보아 시행시기를 정하는 것이 좋을 것이다.
In Korea, users have got familiar with the mobile number portability since 2004 and the bank account switching since 2015. They are also curious about the data portability stated in the General Data Protection Regulation (GDPR), which enters into force on May 25, 2018. Article 20 of GDPR creates a new right to data portability. It allows for data subjects to receive the personal data that they have provided to a controller, in a structured, commonly used and machine-readable format, and to transmit those data to another data controller if technically feasible. In this context, data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his/her consent or the processing is necessary for the performance of a contract. The purpose of this new right is to empower the data subject and give him/her more control over the personal data concerning him/her. Since it allows the direct transmission of personal data from one data controller to another, the right to data portability is also an important tool that will support the free flow of personal data in the EU and foster competition between controllers. It will facilitate switching between different service providers, and will therefore foster the development of new services in the context of the European digital single market strategy. In consequence, the right to data portability is similar and closely related to the right of access, rectification, cancellation and objection (ARCO). Since the draft GDPR was disclosed in the early 2012, there have been pros and cons in relation to the new right. If it does not prove to be burdensome technically and fiscally to controllers, and the cost sharing could be settled in a reasonable way, the right to data portability will be conducive to consumers. So the Article 29 Working Party Guidelines on the data portability have advised data controllers to start developing the means that will contribute to answer data portability requests, and recommend industry stakeholders and trade associations to work together on a common set of interoperable standards and formats through codes of conduct. In Europe, Digital Giants such as Google, Facebook, Apple and Amazon (collectively called “GFAA”) have aroused concern that they dominate business platforms to make their own data distribution market. Against these backdrops, it is believed that EU has armed itself with a weapon of data portability to recapture the European data markets. In Korea, however, does it make sense to adopt the right to data portability as stated in the forthcoming GDPR? Which factor matters: market dominance, regulation of information services, competition between ISPs? In view of the strategic advantage of data portability, it is advisable to institute the right to data portability in the area of social networking services(SNS), Cloud e-mail correspondence and the IoT-based connected cars or home networked appliances. Further, it will be extended to the vast market of health care and medical services. At last, the right to data portability will make it necessary to establish a statutory ground in the Information and Communications Network Act and/or the Credit Information Act, and to coordinate the timing of such amendment to the existing Acts in line with the preparedness of the relevant industries.
디지털 플랫폼에서의 데이터 이동성에 대한 선호 실증분석
[NRF 연계] 정보통신정책학회 정보통신정책연구 Vol.28 No.3 2021.09 pp.65-85
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구에서는 거대 플랫폼의 데이터 집중을 해결하기 위한 대안으로 최근 활발히 논의되고 있는 데이터 이동성에 대한 이용자의 선호를 이산선택모형을 이용하여 실증분석하였다. 디지털 플랫폼의 다양한 특성을 반영하기 위해 분석 대상으로 검색서비스, 소셜네트워크서비스, 그리고 데이터 기반 맞춤형 모바일 금융 서비스의 세 가지 서비스를 포함하였다. 분석 결과 데이터 이동성에 대해 소비자는 긍정적 선호를 보이는 것으로 나타났고, 특히 소셜네트워크 서비스에서 데이터의 이동에 대한 지불의사가 큰 것으로 나타났으며, 생성 데이터와 추론 데이터가 모두 이동되는 경우를 더 선호하는 것으로 나타났다. 개인특성에 따른 영향을 살펴본 결과, 서비스의 이용시간이나 이용기간은 데이터 이동성 속성에 유의한 영향을 미치지 않았으나 이용집중도는 검색서비스를 제외한 두 디지털 플랫폼 서비스에서 데이터 이동에 부정적 영향을 미치는 것으로 나타났다. 즉, 특정 서비스에 고착된 이용자일 경우 데이터 이동에 대한 선호가 낮게 나타났다.
This study evaluates empirically consumer preferences for data portability, arising as a solution to data concentration on a few large-scale digital platforms. A discrete choice model accounting for individuals' characteristics is used to study preferences for data portability across platforms such as search engines, social networking services and online banking platforms. The results show that users have positive attitudes toward data portability and prefer to be able to transport both observed and inferred data. Among digital platforms, users showed a higher willingness to pay for data portability at social networking services, which are subject to network effects. Users thus have higher preferences for data portability on digital platforms with higher network effects. The frequency and duration of platform use do not affect users' preference for portability significantly. However, users with a higher concentration of usage on fewer search service and online banking platforms (eg. all digital platforms except search engines) ? that is, users locked in for a few specific services ? have a lower preference for data portability.
유럽연합과 미국에서의 개인정보이동권 논의와 한국에의 시사점
[NRF 연계] 중앙법학회 중앙법학 Vol.21 No.4 2019.12 pp.271-310
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
유럽연합(EU)은 일반개인정보보호규칙(GDPR)에서 정보주체의 새로운 권리로 개인정보이동권(right to data portability)을 도입하였다. 그리하여 소비자인 정보주체의 ‘통제 하에’ 개인데이터의 ‘자유로운 이전’ 내지는 ‘재사용’을 촉진시켜 소비자가 새로운 플랫폼을 용이하게 선택할 수 있도록 하여 힘의 불균형을 시정하고 경쟁을 촉진함으로써 데이터 기반의 혁신(data-driven innovation)을 끌어내고자 하는 것이다. 그러나 GDPR의 개인정보이동권 도입에 관해서는 찬반양론이 팽팽히 대립하고 있다. 게임 체인저(game changer)로 기능할 것이라는 긍정적인 평가가 있는 반면에, 상충하는 권리와 이익의 충돌 문제를 해결하는 뚜렷한 기준을 찾아내기 쉽지 않고, 개인정보이동권을 기술적으로 구현해내는 것이 기업 등의 개인정보처리자에게 부담과 비용을 초래하며, 또 개인데이터가 이동하는 과정에서 오히려 보안침해 문제가 더 쉽게 발생할 수 있다는 등의 우려가 표출되고 있다. 한편, 미국은 2011년부터 연방정부의 주도 하에 ‘스마트 공개 정책’(Smart Disclosure Policy)을 민관협력체계를 통해 시행함으로써 소비자의 개인정보이동성(data portability)을 구현해 오고 있다. 이제 데이터경제체제에서 개인데이터의 자유로운 이동을 기반으로 한 혁신을 끌어내고, 개인정보에 대한 정보주체의 통제권을 강화하여 소비자(정보주체)와 사업자(개인정보처리자) 간의 힘의 불균형을 재조정함과 아울러 소비자의 서비스 선택권을 강화하여 경쟁을 촉진해야 하는 정책목표는 누구도 부인하기 어렵게 되었다. 이러한 정책목표를 달성하는 수단으로 개인정보이동권을 인정하고 도입하는 것이 불가피하게 되었다. 다만, 개인정보이동권의 도입에는 몇 가지 측면에서 제약요인들이 있기 때문에, 당장 전면적이고 일반적인 개인정보보호권을 도입하는 것은 정책적으로 부담이 클 것으로 판단된다. 따라서 일반법인 「개인정보 보호법」에 도입하는 것은 보다 신중할 필요가 있다. 도입의 필요성이 크다면, 면밀한 입법조사와 논의를 거쳐 우선적으로 금융 분야나 의료 분야 등에 잠정적으로 도입하는 것을 고려할 수 있을 것으로 생각된다. 또한 미국 연방정부가 주도적으로 추진해 온 민관협력체계 방식의 접근방법은 현재 시점에서 가장 적절하고 필요해 보인다.
With the advent of the data economy with the recent development of information technology, personal data has become a key resource for economic development and social growth. As a result, the value of personal information or personal data increases day by day, with some large platform companies holding the majority of such critical resources, resulting in a power imbalance issue between platform companies and consumers, and this imbalance is difficult to correct under the existing consent system. Against this backdrop, the European Union (EU) introduced the right to data portability as a new right for information subjects in the General Data Protection Regulation (GPPR). Thus, by facilitating the 'free movement' and 'reuse' of the personal data of consumers, data-driven innovation is sought by correcting power imbalances and promoting competition by facilitating a consumer's choice of a new platform. However, there is a strong disagreement between the two sides regarding the introduction of the GDPR's right to personal information. While there is a positive assessment that it will function as a game changer, concerns are being expressed such as that it is not easy to find clear criteria for resolving conflicts between conflicting rights and interests, and that the technical implementation of the right to move personal information creates burdens and costs for private data processors such as companies, and that security breaches can occur more easily in the process of moving personal data. Meanwhile, the U.S. has implemented 'Smart Disclosure Policy' through a public-private partnership system since 2011 under the initiative of the federal government to implement data mobility for consumers. In other words, the personal data of consumers held by public agencies and private companies is standardized and provided to consumers in a format that can be read by computers. These smart releases are empowering consumers to make rational choices and pushing forward policy goals to increase market transparency. It is now difficult for anyone to deny policy goals that should promote competition by enhancing consumer service choices, as well as readjusting the power imbalance between consumers (information entities) and operators (personal information processors) by drawing innovation based on the free movement of personal data in the data economy system and strengthening control of the information subjects. It has become inevitable to recognize and introduce the right to move personal information as a means of achieving these policy goals. However, since there are some constraints on the introduction of the right to move personal information, it is deemed that the introduction of the right to protect personal information in full and general immediately will be a big policy burden. Therefore, it is necessary to be more prudent to introduce the law on personal information protection for general corporations. If there is a great need for introduction, it is thought that we can consider introducing it temporarily in the financial and medical sectors first after careful legislative investigation and discussion. In addition, the public-private partnership approach, which has been pursued by the U.S. federal government, seems most appropriate and necessary at this point.
데이터 이동권 관련 경쟁법적 문제 - 비교법적 방법으로 -
[NRF 연계] 한국외국어대학교 법학연구소 외법논집 Vol.48 No.4 2024.11 pp.91-115
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
개인정보 또는 데이터는 디지털 플랫폼 생태계(digital platform ecosystem)의 사업모델 설계에서 중요한 내용이 된다. 플랫폼 사업자는 최종이용자(end user)의 개인정보를 수집⋅활용하여 수익창출에 집중하는 것이 일반적이다. 그런데 이러한 사업모델은 다양한 법적 문제를 가져올 수 있다. 우선, 최종 이용자 또는 정보주체가 자신의 개인정보를 통제할 수 없게 되어 권리를 보장받을 수 없는 상황이 발생할 수 있다. 또한 만약 특정 분야의 데이터가 필수설비의 성격을 갖는다고 가정한다면, 규모가 작은 이용사업자(business user)가 해당 데이터에 접근이 어려워 시장에 진입할 수 없거나 시장에서 퇴출될 수도 있다. 이러한 문제는 최종이용자의 데이터 이동권 혹은 개인정보 전송요구권의 보장으로 어느 정 도 해결될 수 있을 것이다. 다만, 데이터 이동권 자체가 제3자의 개인정보 침해로 이어지거나 기존 플랫폼(incumbent platform)의 데이터 독점을 오히려 강화하는 역효과를 발생시킬 수 있다. 따라서 데이터 이동권이 추구하는 목적을 달성할 수 있는 정책의 설계와 법집행의 방향을 고민하는 것은 향후 개 인정보 보호법과 경쟁법의 중복과 충돌을 방지하는 데 필요할 것이다. 이 연구는 개인정보 보호법상 효과적인 데이터 이동권의 보장이 경쟁법이 추구하는 목적에 합치되는 지에 대해서 살펴보고, 데이터 이동권과 관련하여 경쟁법의 역할에 대해서 논의하는 것을 목적으로 한다.
Personal information or data has become one of the most important elements in designing business models of digital platform ecosystems. Digital platforms usually focus on collecting and processing personal data of end users, thereby to improve value creation and value capture (monetization). However, it is possible that an end user or a data subject faces harms from certain platforms’ conducts when she or he cannot control her or his personal data, which is essential in ensuring fundamental rights. In addition, if we presume certain types of data in specific fields have characteristics of essential facility, a small size enterprise or business user cannot easily access to the data in concern. This may cause a problem of entry barrier or exclusion from the market. The problems above can be solved through a guarantee of the right to data portability. Nevertheless, data portability itself may bring another legal or policy issue. For example, excessive allowance of data portability may lead to harms to the third party when it involves infringement of data protection of others. Moreover, data portability may lead to economic concentration of incumbent monopolies. Therefore, it is necessary to examine the legal framework and enforcement of data portability to avoid any possible conflict or overlap between data protection law and competition law. This article aims to assess whether the implementation of legal provisions on data portability within the data protection act can satisfy the objective of competition law. In particular, it examines whether competition law can supplement data protection law through enforcing certain provisions and imposing remedies related to data portability.
[NRF 연계] 한국상사판례학회 상사판례연구 Vol.34 No.3 2021.09 pp.331-360
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
최근 4차 산업혁명 시기가 도래함에 따라 데이터 공유가 창출할 수 있는 사회적 가치의 증대를 경험하면서 금융분야에서는 오픈뱅킹, 마이데이터 서비스 등 정보의 이동을 촉진하는 제도가 활성화되고 있다. 금융분야 정보 이동의 법적 근거는 개정 신용정보법의 개인신용정보 전송요구권 규정에 마련되었다. 또한 시행령 개정을 통하여 주문내역정보가 전송요구권의 대상으로 포함된 점에 대해 신용정보 범위의 과대한 확대라는 우려가 있다. 그러나 사회관계망 정보, 디지털 이력 등 다양한 비금융 정보를 바탕으로 새로운 신용평가 분석 기법이 발굴되고 있고 금융이력부족자의 금융접근성을 높여나갈 수 있다는 점에 비추어 봤을 때 주문내역정보는 신용정보주체의 거래내용을 판단할 수 있는 신용정보에 포함된다고 봄이 타당하다. 개정 신용정보법상 전송요구권을 행사할 수 있는 대상자는 전자금융업자로 한정되어 있어 신용정보주체의 전송요구권의 행사에 제약이 발생하게 된다. 정보 유통의 활성화와 신용정보주체의 편의성 강화를 위하여 전송요구권의 행사 대상자를 「전자상거래법」의 통신판매업자 또는 통신판매중개업자로 확대하여 나가는 것이 타당하다. 더 나아가 「신용정보법」 외 「개인정보보호법」 등 개인정보 관련 일반 법률에 개인정보 이동권을 도입하여 정보 이동의 구역을 확장해나가는 것이 정보의 활용도 제고와 적극적인 개인정보자기결정권 실현에 유용할 것이다. 전송요구권 행사와 관련한 법적 쟁점으로는 신용정보주체의 이익과 관련한 정보 보호, 정보 보유자의 이익과 관련한 데이터 소유권 및 지적재산권, 정보 집중에 따른 경쟁법적 이슈로 나누어 볼 수 있다. 정보 보호와 관련하여, 전송된 개인신용정보의 이용 목적을 명확히 하도록 정보 이용 동의서 등을 개선해 나가야 할 것이다. 데이터 소유권 및 지적재산권과 관련하여, 데이터는 물건의 성질을 가질 수 없어 소유권의 대상이 될 수 없고 개별 데이터는 '창작성'이 인정될 수 없으므로 저작권의 대상이 될 수 없다. 특히, 전송요구권의 대상인 개인신용정보는 신용정보주체로부터 수집하거나 제공받은 정보만을 대상으로 하기에 그러한 개별 데이터에 보유자의 권리를 인정할 필요는 없을 것이다. 경쟁법적 이슈와 관련하여, 전송요구권 행사를 통해 정보를 집중하는 본인신용정보관리 산업에 불공정거래행위나 시장지배적 지위 남용에 해당하는 경쟁 저해 행위가 나타날 수 있음을 유의해야 할 것이다.
With the recent arrival of the Fourth Industrial Revolution, financial services that promote the movement of information such as open banking and mydata services is being activated in the financial sector as it aims to increase the social value that data sharing can create. The legal basis for the movement of information in the financial sector was established in the amended Credit Information Use and Protection Act on the introduction of right to request to transmit personal credit information. There is also concern that the amendment to the Enforcement Decree would significantly broaden the scope of credit information by including details about order as the object of the right to request transmission of information. However, given that new credit evaluation analysis techniques are being developed based on various non-financial information such as social network information and digital history, and that it can improve financial access for people with insufficient financial history, It is reasonable to assume that details about order should be included in credit information. Under the revised Credit Information Use and Protection Act, information receivers by requtransmission request are limited to electronic financial companies, which will impose restrictions on the exercise of the right to request transmission. In order to revitalize information circulation and enhance the convenience of credit information subjects, it is reasonable to expand the scope of information receivers by the transmission request to the telecommunication vendor or the telecommunication broker of Act on the Consumer protection in E-commerce. Furthermore, it would be useful in enhancing information utilization and realizing the right to self-determination of personal information to introduce ‘right to data portability’ into Personal Information Protection Use and Protection Act. Legal issues related to the exercise of transmission requirements can be divided into information protection related to the interests of credit information subjects, data ownership and intellectual property rights related to the interests of information holders, and competitive legal issues based on information concentration. With regard to information protection, the consent procedures for the use of information should be improved to clarify the purpose of the transmission of personal credit information. With respect to data ownership and intellectual property rights, data cannot be subject to ownership because it cannot have the nature of object and individual data cannot be subject to copyright because 'creativity' cannot be recognised. So it is not necessary to recognise the rights of the data holders. With regard to competitive legal issues, it should be noted that the exercise of the right to request transmission may result in competitive inhibitions such as unfair trading or abuse of market-dominant status in personal credit information management industry.
[NRF 연계] 서울대학교 법학연구소 경제규제와 법 Vol.13 No.2 2020.11 pp.92-107
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
4차 산업혁명 시대에 세계 각 국은 수단과 정책의 차이는 있지만, 개인정보 주체의 권리를 강화하고 데이터 활용도를높이기 위한 전략을 추진하고 있다. 우리나라도 2020년 2월 데이터3법 개정에 따라 「신용정보법」에 개인신용정보 전송요구권을 신설하고 마이데이터 사업을 추진 중에 있다. 본 연구에서는 유럽연합, 미국, 일본의 개인정보 이동권 관련 법제도와 마이데이터 산업 관련 정책을 살펴보고 이를 통해 우리나라의 데이터 산업 관련 시사점을 도출하고자 하였다. 또한 우리나라 개인정보 이동권과 마이데이터 산업 현황을 살펴보고 관련 쟁점을 도출하고 이를 통해 향후 나아가야 할 방향을 제시하고자 한다. 각 국의 개인정보 이동권 및 마이데이터사업 관련한 정책에는 차이가 있으나 개인정보의 유통과 관련한 관리체계를 강화하려는 점에서 공통적이다. 개인정보 이동권에 대해 유럽연합처럼 법에 규정하고 있거나 일본과 같이 규정 마련을 준비 중에 있는 등 상황은 다르지만, 정보주체의 권한을 강화하고 있는 추세이다. 또한 데이터 유통 산업 관련하여 유럽과 일본은 오랫동안 시범사업과 연구 등을 통해 준비해오고 있었다. 한편 마이데이터 산업에서 개인이 실질적인 정보주체로서의 권한을 행사하기 위해 유럽은 자기정보관리가 가능한 시스템이 존재한다. 일본은 정보은행에서 계약을 통한 신탁으로 개인 정보를 관리하고 있다. 미국의 스마트 공개의 버튼도 정부홈페이지에 정보주체가 개인정보를 검색할 수 있는 기능을 제공하고 있다. 우리나라의 경우 2016년 K-Mydata 정책을 발표하였다. 이후 금융위원회는 개인신용정보 전송요구권을 기반으로 금융산업의 발전과 소비자 편의 증진 측면에 초점을 맞추어 마이데이터 산업 육성을 추진 중이다. 과학기술정보통신부는 개인정보 이동권 기반은 아니지만 사전 동의를 바탕으로 한 마이데이터 플랫폼 관련 체계를 정비 중이고, 행정안전부도 공공부문 마이데이터 포털을 추진 중이다. 향후 마이데이터 정책이 데이터 유통 산업 발전과 함께 개인의 권리를 보장하기 위해서는, 개인정보자기관리체계 구축 및 구체적 동의권 보장, 마이데이터 대상 정보에 대한 사회적 합의 도출, 「개인정보 보호법」과 「신용정보법」상의 종합적인 법체계 정비 등이 이루어져야 할 것이다.
In the era of the Fourth Industrial Revolution, countries around the world are pursuing strategies to strengthen the rights of personal information subjects and increase data utilization, although there are differences in means and policies. In accordance with the revision of so called 3 Data Act in February 2020, Korea also established the right to request the transmission of personal credit information in the 「Credit Information Act」 and is promoting the Mydata business. In this study, the legal system related to the right to data portability in the European Union, the United States, and Japan and policies related to Mydata industry were examined, and through this, the implications of Korea's data industry were drawn. In addition, it will examine the current status of the right to data portability and the Mydata industry in Korea, derive related issues, and present the direction to be taken in the future. Although there are differences in policies related to the right to data portability and Mydata business in each country, they are common in that they intend to strengthen the management system related to the distribution of personal information. Although the situation is different, such as the European Union stipulating the right to data portability or preparing regulations like Japan, the authority of the data subject is strengthening. Also, regarding the data distribution industry, Europe and Japan have been preparing for a long time through pilot projects and research. On the other hand, in Mydata industry, in order for individuals to exercise their authority as a real information subject, there is a system that enables self-information management in Europe. In Japan, information banks manage personal information through contractual trusts. The button of the Smart Disclosure Policy in the United States is also provided with a function that allows the information subject to search for personal information on the information homepage. In the case of Korea, the 2016 K-Mydata policy was announced. Since then, the Financial Services Commission is promoting the development of the Mydata industry, focusing on the development of the financial industry and enhancement of consumer convenience based on the right to request transmission of personal credit information. The Ministry of Science, Technology and ICT is not based on the right to data portability, but has been promoting a system related to the Mydata platform based on prior consent, and the Ministry of Public Administration and Security has been also promoting the Mydata policy in terms of opening public data. However, in order for Mydata policy to achieve both personal rights and data distribution industry development in the future, ① PIMS for personal information establishment and guaranteed specific right to consent, ② social consensus on information subject to Mydata, ③ the readjustment of the legal system between the Personal Information Protection Act and Credit Information Act should be done.
EU개인정보보호규정 상 정보이동권의 실효성과 중국 및 한국에서의 전망
[NRF 연계] 한국토지공법학회 토지공법연구 Vol.86 2019.05 pp.345-375
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In recent years, with the rapid development of new generation information technologies(IT) on a global scale, the development of cyberspace has risen to an unprecedented stage. The European Union introduced the “right to data portability” system in the “General Data Protection Regulations”, which came into effect on May 25, 2018. Aiming at enhancing the individuals' control of data and promoting the free flow of data, the right to data portability itself involves largely two perceptions: right to receive personal data and right to transmit personal data. First of all, the “data” itself, as the object of “right to data portability”, implicates personal characteristics, honors and privacy, which makes it possible to say that it possesses "personality attributes". When it comes to the implementation process, this right specifically involves the legal source of data, the subject relevance of data, technical feasibility and the harmlessness of power exercise. At the same time, although this right has been sought after in the introduction process, it has also caused doubts from all parties, especially its rationality and feasibility is still mired in great controversy. In Europe US IT companies, such as Google, Facebook, Apple and Amazon have become increasingly vigilant about dominating the platform and dominating the information distribution market. As a result, it seems that the rules on the information movement have been designed to regain the distribution market of information that these US IT companies have dominated. Moreover, in addition to the EU region, other countries are actively exploring whether they can and how to refer to this system. All in all, the application prospect of this data migration right remains to be seen. As far as China and South Korea are concerned, in spite that this system is not suitable for indiscriminate introduction, it can still be applied in appropriate areas, such as the above mentioned telephone number transfer system. As long as the system can be localized, its effectiveness is likely to get maximized.
[NRF 연계] 한남대학교 과학기술법연구원 과학기술법연구 Vol.24 No.3 2018.10 pp.207-242
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
유럽연합이 2016년 채택한 GDPR 제20조는 정보주체가 정보처리자에게 제공한 개인정보를 그로부터 구조화되고, 일반적으로 이용되며, 기계가 읽을 수 있는 형식으로 제공받고 이를 다른 정보처리자에게 방해 없이 이전할 수 있는 권리를 도입하였다. 이를 “데이터이동성에 대한 권리”, 약칭하여 “데이터이동권”이라 한다. 이어서 2017년 유럽연합 집행위원회는 「비개인정보 자유유통을 위한 골격규칙」을 제안하였다. 그 배경에는 클라우드 컴퓨팅, 빅 데이터, 사물인터넷, 인공지능과 같은 4차 산업혁명이 있다. 이와 같은 신산업을 촉진하기 위해서는 데이터의 수집, 분석, 유통, 활용이 활발하게 이루어져야 하지만 현실에 있어서는 데이터의 자유 이동에 여러 가지 제약이 존재하는 것이다. ‘데이터 현지화 요건’과 국내 기관에 의한 설비인증 요건은 국가차원에서 부과하는 데이터 이동에의 장애요인이다. 사적인 서비스이용계약상 데이터의 이동을 제약하는 조건도 이용자의 자유로운 선택을 제약하므로 불공정성이 없는지 검토되어야 한다. 규제당국은 기업의 정보가 외국에 저장되어 있는 경우에도 필요한 경우에는 이에 접근하여 감사를 실시할 수 있는 권한을 확보하면서도 이용자들이 거래하는 데이터센터를 어려움 없이 바꾸고 자신의 데이터를 이동할 수 있도록 보장하여야 한다. EU는 데이터 이동성 입법에서 시장에서의 경쟁 활성화와 소비자 권익보호, 업계의 자율성 보장간의 균형을 중시하고 있다. 하지만 GDPR과 신 규칙의 조화로운 적용, 데이터 이동성 행동규약의 채택 등 적지 않은 과제가 남아있다.
Article 20 of the General Data Protection Regulation of the European Union introduced right to data portability, under which the data subject has the right to receive the personal data concerning him, which he has provided to a controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided. The European Commission also proposed a Regulation on a framework for the free flow of non-personal data in the European Union in 2017. The EU purports to promote the 4th industrial revolution in the area of cloud computing, big data, IoT and artificial intelligence, which requires free flow of data as essential input. The proposal aims to curb data localization requirements of member governments and other barriers to data movement. It also tries to accommodate national interests for public authorities to access data concerning public security and provide room for self-regulation of the industry to develop details for the data portability. In June 2018, the European Parliament, the Council and the Commission reached a political consensus on the proposed regulation. The data portability in the GDPR and the proposed regulation complement each other in that one deals with personal data and the other deals with non-personal data. Both regulations are keen on balancing public interests in user protection and promotion of competition against industry self-regulation. The two, however, differs in conditions of data portability, which makes the harmonious application a complex mission.
개인정보 전송요구권의 이론과 실제- 보험업을 예로 하여 -
[NRF 연계] 한국경영법률학회 경영법률 Vol.36 No.2 2026.01 pp.233-279
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
개인정보 전송요구권이란 ① 정보주체가 ② 본인에 관한 정보를 보유한 자에게 ③ 본인 정보를 ④ 본인 또는 다른 제3자에게 ⑤ 전송(電送)하도록 요구할 수 있는 법적 권리를 의미한다. 개인정보 전송요구권은 헌법상의 권리의 내용이라기보다는, 법률에 의해 제정된 권리로 보는 것이 타당한데, 최근 국내에서는 이를 입법화하는 시도가 자주 발견된다. 이 글에서는 이러한 시도의 예로, 신용정보법에 의한 개인신용정보 전송요구권, 보험업법에 의한 서류 전송 요청권, 개인정보보호법에 의한 개인정보 전송요구권을 분석하였다. 이들 각 권리에 있어 보험회사는 개인정보를 전송해야 할 의무자의 위치에 서기도 하고(개인신용정보 전송요구권), 개인정보를 전송받는 자의 위치에 서기도 한다(서류 전송 요청권, 그리고 아마도 개인정보 전송요구권). 이러한 개인정보 전송요구권은 정보주체의 요구로 시작되고 사전에 정보를 전송해야 할 의무자와 전송을 받게 될 새로운 처리자 사이에서 충분한 협의를 통해 거버넌스가 구축되는, 세련된 방식의 정보 공유 방안이라고 생각되고, 특히 개인정보의 활용에 제약이 많았던 우리나라에서는 새로운 기회가 되리라고 기대된다. 보험업으로 관점을 좁히면, 보험회사가 개인정보를 전송할 의무를 지게 되는 경우도 있고 전송을 받을 수 있는 위치에 놓이기도 한다. 이 제도가 특정 산업에 반드시 유리하다, 불리하다고 단정할 것은 아니고 새로운 법적 수단을 적절하게 활용하여 소비자의 이익과 산업의 발전에 활용할 수 있는 지혜가 필요하리라 생각된다.
The right to data portability refers to the legal right of the data subject to request a person who holds information about the person to transmit his or her information to the person or another third party. It is reasonable to view the right to data portability as a right enacted by law rather than a constitutional right, and attempts to legislate this are often found in Korea. In this article, as examples of such attempts, the Credit Information Act, the Insurance Business Act, and the Personal Information Protection Act were analyzed. In each of these rights, the insurance company may stand in the position of the person obligated to transmit personal information (the Credit Information Act) or the position of the person receiving the personal information (the Insurance Business Act and possibly the Personal Information Protection Act). This right to data portability is considered a sophisticated method of information sharing, which begins at the request of the information subject and establishes governance through sufficient consultation between the person obligated to transmit the information in advance and the new processor to receive the transmission, and is expected to be a new opportunity, especially in Korea, where the use of personal information is strongly limited. When narrowing the perspective to the insurance industry, there are cases in which the insurance company is obligated to transmit personal information and is in a position to receive it. It is not necessarily concluded that this system is advantageous or unfavorable to a specific industry, but it is thought that the wisdom that can be used for the development of the consumer's interests and industry by appropriately utilizing new legal means is needed.
[NRF 연계] 한남대학교 과학기술법연구원 과학기술법연구 Vol.26 No.2 2020.05 pp.3-58
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
우리나라는 해외 주요국과 같이 개인정보에 대한 정보주체의 권리를 보장하고자 마이데이터 정책을 점차 확장하고 있다. 마이데이터는 정보주체 중심의 데이터 생태계를 형성하는 것을 목적으로 하고 있으며 데이터 이동에 대한 통제권을 정보주체에게 보장함으로써 이를 달성하고자 하였다. 데이터이동권을 처음으로 규정한 EU GDPR은 공정한 시장경쟁을 위한 것을 목적으로 하고 있으며 특히 데이터이동권은 정보주체가 특정 서비스에 락인(lock-in)되는 현상을 방지하여 다른 서비스로 이전할 수 있도록 보장하고자 한 권리이다. 실제 거대 IT기업들이 정보유통시장을 과점하는 것을 방지하려는 목적이 있었다. 동일한 이유로, 단일화되고 있는 디지털 시장에서 우리나라 기업의 유효경쟁을 보장하고 정보주체의 서비스 선택에 자율성을 보장하기 위해 데이터이동권을 보장하는 것이 필요하다. 우리나라에서 데이터이동권은 데이터 이동에 대한 정보주체의 통제권을 의미한다는 점에서 데이터를 받을 수 있는 권리, 동의를 결정할 권리, 데이터 제공을 요청할 권리라는 모든 경우에 해당될 수 있다. 하지만 데이터이동권을 처음으로 명시한 EU GDPR의 규정에 따르면 데이터이동권은 정보주체가 개인정보를 기계판독이 가능한 포맷으로 제공받을 권리이다. 기계판독이 가능한 포맷 또는 상호운용성 있는 포맷의 보장은 해당 데이터가 이전받은 컨트롤러에 의한 이용가능성을 보장하고자 하는 의도가 있다. 우리나라 데이터이동권의 권리범위도 데이터 활용을 보장하며 정보주체가 데이터의 제공을 적극적으로 요청할 수 있는 권리로 보는 것이 타당할 것이다. 개인정보 일반에 대하여는 해당 규정이 존재하지 않으므로 이를 보장하기 위해서는 규정의 신설이 필요하다. 구체적으로 데이터이동권 규정을 도입하기 위하여 권리제한사유, 데이터 제공자, 제공자의 의무, 대상 데이터의 범위, 정보제공방법, 데이터 이동 요청에 따른 처리기간, 처리비용에 대하여 해외 주요국의 규정과 비교검토해 본다.
Korea is gradually expanding its MyData policy to ensure the right of the data subject to personal data like major foreign countries. My Data aims to form a data ecosystem centered on the data subject, and aims to achieve this by ensuring control over data portability by the data subject. The EU GDPR, which first stipulated the right to data portability, aims to promote fair market competition. In particular, the right to data portability is intended to prevent data subjects from being locked in to a specific service and to be able to transfer to another service. Indeed, it generated to prevent IT giants from dominating the information distribution market. For the same reason, it is necessary to guarantee the right to data portability in order to ensure the effective competition of Korean companies in a single digital market and to ensure the autonomy in the choice of services by data subjects. In Korea, the right to data portability can refer to all cases of the right to receive data, the right to decide consent, and the right to request data in that it means the right to control the data subject. However, according to the EU GDPR, the right to data portability is the right of the data subject to receive personal data in a machine-readable format. The guarantee of a machine-readable format or an interoperable format is intended to guarantee the availability of the transferred data by a controller. It would be appropriate to view the right scope of data portability in Korea as the right to guarantee the utilization of data and to actively request the controller to provide the personal data. In Korea, there is no provision for the right to data portability, it is necessary to establish a new provision to ensure this. Specifically, this paper compares the reasons for restriction of the right, the data provider, the obligations of the providers, the scope of the target data, the method of providing data, and the processing period and the processing cost according to the request for data porting with the regulations of foreign countries to introduce the provision for the right to data portability.
[NRF 연계] 성균관대학교 법학연구원 성균관법학 Vol.32 No.2 2020.06 pp.69-112
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
EU GDPR은 새로운 정보주체의 권리로서 ‘데이터 이동권(Right to Data Portability)’을 창설하여 주목받고 있다. 구글, 페이스북 등 디지털 플랫폼 기업들이 데이터 사용 권한을 독점하고 있는 상황에서, 데이터 이동권은 정보주체의 선택권을 근거로 개인정보를 자유롭게 이전하여 시장 경쟁을 촉진할 것으로 기대하며 설계된 권리라 할 수 있다. 이러한 이동권의 법적 성격을 두고 여러 이견이 있을 수 있으나, 이를 인센티브 차원의 권리로 보기보다는 헌법상 개인정보자기결정권에 기인하는 것으로 보아야 한다. 이에 따라 개인의 자유의사 및 선택권을 최대한 보장하는 방향으로 제도를 설계할 필요가 있다. 국내에서도 본격적인 논의를 거쳐 데이터 이동성 확보를 위한 개정 신용정보법상 ‘전송요구권’이 도입되었다. 그러나 본 권리는 개인신용정보를 대상으로 하고 있어 개인정보 일반에 적용되는 포괄적 권리의 필요성에 대한 논의는 여전히 유효하다고 할 수 있다. 특히 금융 분야에 한정된 권리 부여만으로는 해외 플랫폼 사업자로의 쏠림 현상을 약화시키거나 경쟁을 촉진시키는 등의 기대효과를 달성하기 어렵다는 한계가 있기 때문이다. 이에 본 연구는 데이터 이동권의 도입에 따른 실익을 산업‧경제적·권리 보장적 관점 등 다양한 맥락에서 면밀히 검토하였다. 또한 주요국의 입법례를 비교법적 시각에서 분석한 바, 이동권을 전면적으로 보장하는 EU의 GDPR, 12개월 이내 2회 이내로 제한하는 미국의 CCPA, 산업 정책 차원에서 별도의 근거 법률을 두는 영국과 일본의 접근 방식이 각각 상이함을 파악하였다. 향후 국내에 이동권 도입 시 시장 환경을 충분히 고려하여 권리 범위를 명확하게 설정하여야 할 것이다. 가령 권리 범위가 지나치게 넓게 설정되면 기존 개인정보처리자들은 적법한 이익(legitimate interests) 즉, 사업자로서 정당한 절차적 수단과 상당한 비용 및 투자를 통해 취득한 산출물이라는 명분으로 수범주체에서 빠져 나오려 하여 제도적 실효성이 감소될 수 있다. 결론적으로 포괄적인 권리로서 데이터 이동권을 도입하되, 입법 초기에는 법률상 요건을 엄격하게 규정하여 제한적인 권리 형태로 수용하게 되면 그에 따른 수범자들의 법적 혼란을 최소화 할 수 있을 것으로 본다.
The EU General Data Protection Regulations(GDPR) is drawing attention by creating “The Right to Data Portability” as a new right. With digital platform companies such as Google and Facebook virtually monopolizing the right to use data, Right to Data Portability is a right designed to promote market competition by freely transferring personal information based on the information subject's choice. Afterwards, after full-fledged discussions in Korea, “The Right to Request Personal Credit Information Transmission" was introduced under the Credit Information Act as part of the revision of three laws about personal information. This right is intended only for personal credit information, so discussions on the need for Right to Data Portability that apply to all personal informations are still valid. In particular, the establishment of limited rights in the financial sector alone cannot achieve the effect of weakening the focus on overseas platform operators in the domestic market or promoting competition with them. In this study, the actual benefits of the domestic legislation of Right to Data Portability were closely examined from various perspectives, including industrial, economic, and rights-guaranteed aspects. In addition, each country's legislative cases were analyzed from a comparative legal perspective, and the EU GDPR, which fully guarantees the right to move data, the California Consumer Privacy Act(CCPA), which limits the right to move data within 12 months, and the UK and Japan's approaches, which have separate bases in terms of industrial policy, were different. If the scope of rights is set too wide when introducing the concept of Right to Data Portability in Korea, existing personal information controller can escape legitimate interests in the name of reducing the effectiveness of the system. Thus, in the early stages of legislation, it is necessary to define legal requirements rather strictly. In conclusion, the possibility of introducing data mobility rights will be left open to strengthening the rights of information subjects, but a cautious approach will be needed to observe changes in the MyData ecosystem in the financial sector and then draw specific directions.
개인정보의 개념의 차등화와 개인정보이동권의 대상에 관한 연구
[NRF 연계] 서울대학교 법학연구소 경제규제와 법 Vol.12 No.2 2019.11 pp.190-208
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
빅데이터, 인공지능(AI) 등 4차산업을 활용한 기술의 발 전에 따라 사업자는 개인정보를 용이하게 수집하고 이를 손 쉽게 가공하여 이용할 수 있게 되었고, 개별 이용자에 특화 된 서비스를 통해 이용자 편의를 극대화하는 다양한 상품이 출시되고 있다. 그러나 현행법은 동의를 비롯하여 개인정보 처리 시 각종 의무와 그 요건에 집중하면서, 개인정보의 이 용보다는 보호에 초점이 맞추어져 있다. 특히, ‘개인정보’라는 단일한 개념을 법 적용의 단위로 사 용함으로써 사업자의 입장에서 의무의 대상이 되는 정보의 범위가 어디까지인지 명확하지 않다는 점 이 개인정보의 이 용을 제한하는 사유가 되고 있다. 정보의 유형별로 규제 준 수를 위한 비용⋅인력 등이 다름에도 불구하고, 규제의 대 상을 모두 동일하게 해석할 경우, 사업자에게 과도한 부담 을 주거나 이행이 불가능한 의무를 강요하게 된다. 이에 개인정보 개념의 차등화 필요성에 대한 논의가 필요 하다. 이를 위해 먼저 개인정보 개념의 모호성과 관련해, 동 일한 개인정보의 개념에 대해 동일한 법령 내에서 그 범위 를 달리 해석하는 것이 가능한지를 살펴볼 필요가 있다. 더 불어 개인정보 규제의 적용 범위를 합리적인 범위로 한정하 기 위해서는 개인정보를 유형별로 분류하는 것이 필요하다. 특히, 개인정보의 개념을 모호하고 또한 광범위하게 만드는 핵심적인 요소인 식별 내지는 식별 가능성 기준에 따라 개 인식별정보와 개인을 식별할 수 없는 정보 외에 개인식별정 보와 결합되어 있는 상태의 개인식별가능정보와 개인식별정 보와 결합되지 않은 상태의 개인식별가능정보로 구분가능하 다. 그 외에 사업자가 제공받은 정보인지, 사업자가 생성, 가공한 정보인지, 사업자 내부적 목적인지, 외부적 목적인지 등도 기준이 될 수 있다. 이런 분류를 기준으로 법령상 각 규제별로 개인정보 자기 결정권과 영업의 자유의 비교형량을 통해 어느 정도의 개인 정보보호 수준이 적정한지를 볼 필요가 있다. 개인정보이동 권의 경우에도 마찬가지이다. 개인식별정보와 결합되지 않 은 상태의 개인식별가능정보 즉, 1인으로 귀속되는 정보에 해당하여 신원을 알 수 없는 특정한 1인으로 정보들을 귀속 시킬 수 있을 정도로만 식별가능성이 유지되어 있는 경우, 특정한 1인으로 귀속시키는 것조차 어렵도록 흩어져 있는 정보의 경우에는 제공대상에서 제외하는 것이 타당하다. 또 한 근무평가, 신용평가 등과 같이 개인정보처리자가 만들어 낸 정보의 경우에는 이를 내부적으로 활용하는 한 제공대상 이 아니라고 보아야 할 것이다. 개인정보 관련 규제의 적용 범위를 합리화하려는 시도가 축적되고 이것이 입법과 정부의 해석에 반영되어, 서비스 제 공자와 이용자 양측의 권리가 적절하게 수호되고, 향후 ICT 신산업 시대에 걸맞는 규제환경을 갖출 수 있어야 할 것이다.
With the development of technologies utilizing the 4th industry, such as big data and artificial intelligence (AI), operators can easily collect personal information, process it, and use it. Various products are released. However, the current law focuses on protection rather than use of personal information, focusing on various obligations and requirements when processing personal information, including consent. In particular, by using a single concept of 'personal information' as a unit of law application, it is not clear to what extent the scope of information subject to obligations from the operator's point of view. It has become a reason for limiting the use of personal information. Despite the different types of information and costs and manpower for regulatory compliance, interpreting all subjects of regulation equally imposes an excessive burden on the operator or imposes a duty that cannot be implemented. Therefore, it is necessary to discuss the necessity of differentiating the concept of personal information. To this end, it is necessary to first look at the ambiguity of the concept of personal information and see if it is possible to interpret the scope of the same concept of personal information within the same legislation. In addition, it is necessary to classify personal information by type in order to limit the scope of application of personal information regulation to a reasonable range. In particular, it is necessary to classify personal information in accordance with identification or identifiability criteria, which are key factors that obscure and broaden the concept of personal information. Personal identification information that is combined with personally identifiable information and personal identification information that is not combined with personally identifiable information can be distinguished in addition to personal identification information and non personal identification information In addition, the criteria may be whether the information provided by the operator, the information generated and processed by the operator, the operator's internal purpose, or the external purpose Based on this classification, it is necessary to see how appropriate the level of personal information protection is through a standard for balancing conflicting interests between personal information self-determination rights and freedom of operation for each regulation. The same applies to the right to data portability Personally identifiable information that is not combined with personal identification information, i.e., information that is attributed to one person, if the identifiability is maintained only to the extent that the information can be attributed to a specific person whose identity is unknown and information scattered so that it is difficult to attribute to specific person, should be excluded from the provision. In addition, information created by personal information processor such as work evaluation and credit evaluation should not be provided as long as it is used internally. As attempts to rationalize the scope of regulations related to personal information are accumulated and legislation and governmental interpretations are developed, the rights of both service providers and users should be adequately defended, and a regulatory environment suitable for the future ICT new industries should be established.
[Kisti 연계] 디지털산업정보학회 디지털산업정보학회논문지 Vol.8 No.1 2012 pp.221-229
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
A model for expressing meta data syntax in the eXtensible Markup Language(XML) was developed to increase the portability of the Arden Syntax in medical treatment. In this model that is Arden syntax uses two syntax checking mechanisms, first an XML validation process, and second, a syntax check using an XSL style sheet. Two hundred seventy-seven examples of MLMs were transformed into MLMs in ArdenML and validated against the schema and style sheet. Both the original MLMs and reverse-parsed MLMs in ArdenML were checked using a Arden Syntax checker. The textual versions of MLMs were successfully transformed into XML documents using the model, and the reverse-parse yielded the original text version of MLMs.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.