년 - 년
동국대학교 비교법문화연구원 DONGGUK LAW REVIEW Volume 14 2020.12 pp.59-89
※ 기관로그인 시 무료 이용이 가능합니다.
7,200원
Anyone who collects and uses other people’s data must meet legal requirements such as prior consent from the data subject. Data controllers who can legally process other people’s data must comply with the corresponding rules. In this context, controllers also disclose and inform all matters related to the processing of such data subject. After the OECD adopted the privacy principle of transparent and fair processing, most countries have accepted it, including the EU and Korea. The data subject must know who, for what purpose, and how their data is processed in order to control their data. The data subject’s right to basic information on data processing is the prerequisite for exercising their rights to rectification, erasure, etc. However, this basic principle has been mitigated as Korea revised the Personal Information Protection Act in February 2020. The PIPA introduced an exceptional case of data processing, pseudonymization. When data controllers process pseudonymized personal data, they can process it without prior consent from the data subject and without notifying the data subject of relevant information related to the processing. Korea publicly announced it would revise the PIPA by referring to European Union’s General Data Protection Regulation. Still, GDPR does not eliminate the data controller’s obligation to notify when pseudonymized processing. Only consent is exempted if the data initially collected is pseudonymized for compatible purposes such as statistical, scientific research, or archiving purposes in the public interest. This inconsistency appears because the systems of both laws do not match perfectly even though they are much similar. This paper suggests how the PIPA guarantees the data subject’s right to basic information when processing by a comparative study between Korea’s PIPA and the EU’s GDPR. Notification of data processing is crucial in ensuring the right to informational self-determination that the PIPA should accomplish as the ultimate goal.
A Study on the Optimal Allocation of Subsampling for Categorical Data Subject to Misclassification
고려대학교 통계연구소 응용통계 제11권 1996.12 pp.91-107
4,000원
The service reference model is a classification system for service producers who provide services worthy of service to the consumer. Therefore, independence between service producers is the most fundamental attribute of the service reference model. In this paper, to develop a service reference model, a method has been proposed to identify a service consumer using a business reference model, and to analyze the cohesiveness between business functions and subject data to identify mutually independent service producers. The service reference model development methodology of this study has been applied to the Botswana Government Enterprise Architecture project, and its effectiveness and practicality have been verified. The methodology will help countries that are trying to establish a new government EA.
[NRF 연계] 한국도서관·정보학회 한국도서관·정보학회지 Vol.46 No.4 2015.12 pp.379-402
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
이 연구에서는 지금까지 국내 자료조직 연구에서 거의 다루어지지 않았던 주제명 데이터의 ‘품질’에 관해 논의하였다. 구체적으로, 우리나라 대표도서관으로서 주제명표목표의 개발과 이를 이용한 주제명 데이터의 구축을 주도해 온 국립중앙도서관의 실체를 있는 그대로 드러내 보이면서 과연 현재와 같은 품질을 유지하는 것이 바람직한지에 대해 폭넓게논의해 보고자 하였다. 이러한 목적을 위해 이 연구에서는 먼저, 주제명 데이터에 반영되어야 할 ‘주제’의 의미와 속성에대해 살펴보고, 이어 국립중앙도서관에서 구축한 주제명 데이터의 품질을 절대적 품질과 상대적 품질로 나누어 분석하였다. 절대적 품질 분석을 위해서는 ‘대중자료’와 ‘학술자료’ 중 샘플자료를 임의로 추출하여 이들 자료에 반영된 주제명데이터를 분석하였으며, 상대적 품질 분석을 위해서는 미의회도서관(이하 LC)과 국내의 A대학도서관에서 구축한 주제명 데이터와의 비교를 시도하였다.
This study intends to make a comprehensive inquiry into the quality of subject data in library catalogs. On the basis of National Library Subject Headings (NLSH) developed in 2002, National Library of Korea (NLK) has input the subject data into cataloging records since 2003. However a serious question could arise regarding whether the data are appropriate and desirable as a subject of the work. Under these circumstances, this study examined as follows: First, the meanings and attributes of the ‘subject’ were examined with a comprehensive literature survey. Second, a experimental analysis was carried out to measure the quality of the subject data. Sample records were selected from NLK, LC and A university library in Korea, and absolute and relative quality were compared. Finally, the substantial and realistic strategies for improving the quality of subject data were discussed.
미술치료에서 단일대상연구 자료의 효과크기 분석 방법 KCI 등재후보
한국아동발달지원연구소 임상미술심리연구 제8권 제3호 통권 16호 2018.12 pp.1-26
※ 기관로그인 시 무료 이용이 가능합니다.
6,400원
본 연구는 단일대상연구의 결과 분석방법을 간략하게 소개하고, 효과크기 계산의 유형과 개념을 중점적으로 탐구하는데 목적이 있다. 이를 위해 단일대상연구 자료의 분석 방법 유형과 단일대상연구 자료의 비중복 방법을 탐구한다. 단일대상연구의 분석방법에는 시각적 분석방법, 비중복 분석방법, 통계적 분석방법이 있다. 비중복 분석방법 가운데 비교적 빈번하게 언급되는 9가지 방법을 탐구하였다. 이 방법들을 검토한 결과 다음과 같은 결론을 얻을 수 있었다. 첫째, 단일대상연구에서 빈번하게 사용되는 비중복 분석방법은 비중복 자료 백분율이다. 둘째, 모든 쌍의 비중복과 Tau-U는 상대적으로 복잡한 통계적 절차를 거쳐야 하지만, 나머지 방법은 비교적 간단하게 효과크기를 계산할 수 있다. 셋째, 대부분의 방법은 정적 기초선 경향을 통제할 수 없지만, 확장된 변속선과 Tau-U는 기초선 경향을 통제한다. 넷째, 확장된 변속선과 중앙치 초과 자료 백분율은 자료가 집중경향을 보이는 경우에 적절하다. 그러나 자료의 형태가 쌍봉, 극단적 편포, 집중경향치의 부족, 중앙치에 의존하는 자료는 결과를 왜곡할 수 있다. 다른 비중복 분석방법은 집중 경향치에 의존하지 않기 때문에 보다 유연하게 적용할 수 있다. 다섯째, 확장된 변속선과 중앙치 초과 자료 백분율은 통계적 검증력이 매우 낮고, 다음으로 통계적 검증력이 높은 것이 향상율 차이이다. 모든 쌍의 비중복과 Tau-U는 통계적 검증력이 매우 높다. 여섯째, 확장된 변속선은 중앙치 경향 초과 자료 백분율과 동일하고, 중앙치 초과 자료 백분율은 확장된 변속선에 포함된다. 그리고 2×2 분할표에서 계산이 되는 전체 비중복 자료 백분율, 향상율 차이는 매우 유사하다는 것이다.
The purpose of this study is to briefly introduce the results analysis method of a single-subject study and to focus on the type and concept of effect size calculation. There are visual analysis methods, non-overlapping analysis methods, and statistical analysis methods for the analysis of a single subject research. This study investigated 9 methods which are relatively frequently mentioned among non-overlapping methods. After reviewing these methods, the following conclusions were obtained. First, the non-overlapping analysis method that is frequently used in a single-subject research is the PND. Second, NAP and Tau-U must go through a relatively complicated statistical procedure, but the remaining methods can calculate the effect size relatively simply. Third, most methods can not control the positive baseline trend, but ECL and Tau-U control baseline trends. Fourth, ECL and PEM are appropriate when data tend to be concentrated. However, data types that are bimodal, extreme bias, lack of central tendency, and median dependent data may distort the results. Other non-overlap methods can be applied more flexibly since they do not depend on the central tendency. Fifth, ECL and PEM are very low statistical power, followed by IRD. NAP and Tau-U has highly statistical power. Sixth, ECL is equal to PEM-T, and PEM is included in ECL. In addition, PAND and IRD calculated in the 2×2 partition table are very similar. Furthermore, NAP and Tau-U are similar in terms of calculating in the same way.
삶의 만족감에 영향을 주는 요인에 관한연구 : 집계적 자료와 비집계적 자료의 비교분석 KCI 등재
한국지역개발학회 한국지역개발학회지 28권 1호 2016.03 pp.89-104
※ 기관로그인 시 무료 이용이 가능합니다.
4,900원
삶의 만족감에 영향을 미치는 요인들에 대한 관심은 지역적 수준과 더불어 개인적 수준에서의 연구 모두를 포함하고 있다. 두 수준에서의 연구 모두, 궁극적으로는 삶의 만족도 증대를 위해 국가‧지역 혹은 개인 차원에서 어떠한 노력을 기울여야 하는지를 실증하기 위함이라는 공통점이 있다. 그러나, 두 수준의 삶의 만족감 연구를 진행하는 과정에서 국가나 지역 수준에서의 분석 결과를 바탕으로 개인의 삶에 적용하거나 반대로 개인 수준의 결과를 국가·지역수준으로 적용하려는 시도가 종종 있어왔다. 따라서 본 연구는 한국노동패널조사 자료와 통계청 자료를 바탕으로 하여, 집계적 자료를 통한 실증분석의 결과와 비집계적 자료를 통한 결과가 서로 상이할 수 있음을 논증하려 했다. 본 연구의 실증분석에서 얻은 주요 결과를 정리하면 다음과 같다. 집계적 자료에서는 고학력자 비율과 조이혼율이 높을수록 지역민의 삶의 만족감이 높음을 보였고, 기초수급자비율이 높을수록, 소득이 높을수록 전반적으로 삶의 만족도가 높은 지역으로 나타났으며, 지역 내 소득 격차가 큰 곳일수록 삶의 만족도는 낮은 경향을 보였다. 반면에 비집계적 자료에서는 집계적 자료보다 다양한 요인들이 통계적 유의성을 보이고 있었다. 특히 집계적 자료에서 나타났던 이혼관련 변수와 기초수급관련변수는 상반된 영향력을 보여주었다. 결론적으로 본 연구의 실증분석 결과는 지역적 수준에서 삶의 만족감에 영향을 주는 요인과 개인적 수준에서 삶의 만족감에 영향을 주는 요인들 간에 큰 차이가 있다는 것을 확인할 수 있었다. 본 논문의 결과는, 집계적 수준의 만족도 연구를 통한 결론을 개인에게 적용하거나, 혹은 반대로 개인 수준의 분석에서 얻은 결론을 국가‧지역의 전반적인 삶의 만족감을 증진시키는 방안으로 고려할 때, 보다 신중한 해석이 필요함을 강조하고 있다.
There have been many studies arguing that inferences about the characteristics of individuals cannot be deduced from inference for the group to which those individuals are belonging to. This kind of ecological inference fallacy, however, has been ignored in the field of life satisfaction studies. The main purpose of this study is to identify whether the findings obtained from the aggregate data analyses are different from those from the disaggregate data analyses. The Korean Labor and Income Panel Data was used to examine the factors affecting both individual- and regional- level of life satisfaction. The main findings of this study showed that any inferences obtained from the aggregate data analyses may not be substantiated by analyses of individual level data. This implies that a careful interpretation is needed when the findings from analyses of regional level data are applied to policies aimed to improve the level of individual life satisfaction.
낙동강유역 지류에서의 장기 수질모니터링 자료를 이용한 관리 대상물질 분석 연구 KCI 등재
한국습지학회 한국습지학회지 제25권 제4호 2023.11 pp.326-334
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 낙동강수계 지류에서의 장기 수질모니터링 자료를 이용하여 수질의 목표수질 초과율, 증가 추세를 검토하 여 지류에서 문제 되는 물질이 무엇인지 파악하는 것이 목적이다. 낙동강수계에서는 중점 관리가 필요한 38개 지류 에 대하여 월 1회 모니터링이 수행되고 있으며 이 자료를 이용하여 지점별 목표수질 초과 및 증가 경향을 분석하였 다. 분석 항목은 하천 수질 기준으로 평가가 가능한 DO, BOD, COD, TOC, SS, 총인, 분원성 대장균군, 총대장균 군 8개 항목이다. 분석 결과, 목표수질 초과율이 50% 이상이며 증가추세인 항목은 TOC, 분원성 대장균과 총대장 균수로 나타났으며 초과율이 50% 이하이나 증가 경향을 가진 항목은 SS로 나타났다. TOC는 난분해성 물질의 증가 로 인한 원인으로 판단되며 대장균의 지속적인 증가는 향후 하수처리시설에서의 방류수질 중 대장균의 관리가 필요 할 것으로 판단된다.
The purpose of this study is to use long-term water quality monitoring data from tributaries of the Nakdong River system to identify problematic substances in tributaries by examining the rate of exceedance and increase in water quality targets. In the Nakdong River system, monitoring is conducted once a month for 38 tributaries that require intensive management, and this data was used to analyze trends in exceeding and increasing target water quality at each point. The analysis items are eight items that can be evaluated based on river water quality standards: DO, BOD, COD, TOC, SS, total phosphorus, fecal coliform, and total coliform. As a result of the analysis, the target water quality exceedance rate was more than 50%, and the items with an increasing trend were TOC, fecal coliform and total E. coli counts, and the items with an exceedance rate of less than 50% but an increasing trend were SS. TOC is believed to be caused by an increase in non-degradable substances, and the continued increase in Total Coliform will require management of Total ColiformTotal Coliform in effluent water from sewage treatment facilities in the future.
GDPR과 CCPA상 정보주체 권리에 관한 비교법적 연구 KCI 등재
언론중재위원회 미디어와 인격권 제6권 제1호 2020.06 pp.71-106
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
인터넷을 통한 쇼핑은 현대 사회에서 보다 쉽고 편리한 보편적 거래 수단으로 자리 잡았다. 그러나 이를 가능하게 만들어준 정보통신기술(ICT)은 개인정보 수집과 공유를 통해 프라이버시 침해 가능성도 높이고 있다. 이에 대한 우려로 유럽연합은 2018년 5월 일반개인정보보호법(GDPR)을 시행하였으며 미국도 2018년 6월 캘리포니아 소비자 프라이버시법(CCPA)이 제정되었다. 정보주체에게 보장되는 권리로서, 일반개인정보보호법은 정보를 제공받을 권리, 정보주체의 열람권, 정정권, 삭제권(잊힐 권리), 처리제한권, 데이터이동권, 반대권, 프로파일링을 포함한 자동화된 의사결정의 대상이 되지 않을 권리를 보장한다. 한편, 캘리포니아 소비자 프라이버시법은 정보를 제공받을 권리, 삭제권, 거부권, 열람권, 소비자가 CCPA에 따른 권리행사로 인해 차별을 받지 않을 권리를 보장한다. 양 법이 보호하는 권리 간에는 유사점과 차이점이 존재한다. 이상의 두 법은 역외 적용가능성이 있으므로 우리나라 기업도 준수하게 될 가능성이 있으며 디지털 단일시장을 형성해 가는 추세 속에 국내법을 정비할 필요성이 있다. 본고는 두 법을 통해 옵트아웃의 메커니즘, 법의 적용범위, 정보주체의 권리, 준수의무자 배려에 있어 시사점을 발견한다.
In modern society, Internet shopping has been made easier and more convenient, now becoming the universal transaction method. However, the information and communications technology (ICT) that made this possible also increases the possibility of privacy infringement through the collection and sharing of personal information. With this concern, the European Union enacted the General Data Protection Regulation (GDPR), which came into force in May 2018. Similarly, the California Consumer Privacy Act (CCPA) was established in June 2018 in the United States. To protect the privacy of the data subject, GDPR includes the right to be informed, right of access by the data subject, right to rectification, right to erasure (“right to be forgotten”), right to restriction of processing, right to data portability, right to object, and right not to be subject to automated individual decision-making including profiling. Meanwhile, the CCPA guarantees the right to be informed, right to deletion, right to opt out, right of access, and right not to be subject to discrimination for the exercise of rights. Although with some differences, both laws share similarities as well in terms of the rights protected. Given that both laws are applicable offshore, compliance from Korean companies is possible. Amid the trend of forming a single digital market, however, there remains a need to revise domestic laws. This paper gives implications for the areas of the opt-out mechanism, the scope of the law, the rights of the data subject, and the consideration of the obligator through the two laws.
Designing ICT Curriculum for Data Science Education based on Subject Convergence
국제인공지능학회(구 한국인터넷방송통신학회) International Journal of Internet, Broadcasting and Communication Vol.17 No.2 2025.06 pp.239-247
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The necessity of data science education that experiences the problem-solving process by combining information discovered from data with varied expertise is necessary to develop digital talents with the knowledge and capabilities required by the 21st-century society. This study examines a creative teachinglearning strategy that connects data science to ICT main programs and suggests an efficient data science education plan within the industrial framework of intelligent information technology. An extended data science education system that makes use of convergent problem-solving skills in the ICT curriculum was described in this research along with the implications of data-based science education. We proposed a strategy to implement and activate the design of data science education policies based on statistics and mathematics in order to enhance the effective insight of data. And also, we suggested the continuous data education management system was diagnosed, and new approaches, to improve the management of academic accomplishment in data-based science. With out research results, we would certainly boost national scientific and technology competitiveness as well as academic excellence in data science.
Subject Hierarchy Structure Modeling in Data Warehouse SCOPUS
보안공학연구지원센터(IJDTA) International Journal of Database Theory and Application Vol.8 No.4 2015.08 pp.265-272
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Data warehouse is subject-oriented organized. However, when data warehousing, the hierarchy structure of subject is currently only decided by decision makers’ intuition. Faced with complicated business data mining cases, it is hard to establish hierarchy structure of subject just according to intuition. Thus a method based on ISM is present to make subject level structure establishment more measurable and illustrative. In this article, the "Subject" level structure establishment process is presented firstly. Then the method is put forward. Finally, the rationality and validity of this method are verified by a case on university financial data warehouse’s subject level establishment.
[Kisti 연계] 한국통계학회 Communications for statistical applications and methods Vol.9 No.3 2002 pp.853-864
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In the analysis of categorical data subject to misclassification errors, the observed cell proportions are adjusted by a misclassification probabilities and estimates of variances are adjusted accordingly. In this case, it is important to determine the extent to which misclassification probabilities are homogeneous within a population. This paper considers methods to evaluate the power of chi-squared tests for homogeneity with complex survey data subject to misclassification errors. Two cases are considered: adjustment with homogeneous misclassification probabilities; adjustment with heterogeneous misclassification probabilities. To estimate misclassification probabilities, logistic regression method is considered.
On Best Precedence Test when Data are subject to Unequal Patterns of Censorship
[Kisti 연계] 한국품질경영학회 Journal of the Korean Society for Quality Management Vol.22 No.1 1994 pp.169-178
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Nonparametric tests for comparing two treatments when data are subject to unequal patterns of censorship are discussed. Best precedence test proposed by Slud can be viewed as a nice alternative test comparing with weighted log-rank tests, not to mention the advantage of short experimental period. This research revises some missing parts of Slud's test and examines the asymptotic power of it under the nonproportional hazard alternatives through the simulation. The simulation studies show best precedence test has reasonable power in the sense of robustness under nonproportional hazard alternatives and could be recommended at such situation.
개인정보보호법에서의 정보주체의 동의와 기본권 보장에 관한 연구
[NRF 연계] 한국법학회 법학연구 Vol.18 No.1 2018.03 pp.321-346
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
정보통신 기술의 고도화로 정보가 IoE시대의 자원으로 급부상하며, 제4차 산업혁명시대의 가장 중요한 요소가 되고 있다. 이 중 개인정보는 이러한 IoE시대의 원활한 사회운영을 위한 필수요소 중 하나다. IoE시대에 개인정보가 개인에게는 하나의 인격적 표상이자 재산권과 직・간접적으로 연결된 주요수단이지만, 기업에게는 이윤획득의 수단이자 국가 및 사회에게는 국가 및 사회운영에 필요한 필수요소로 작용하고 있다는 점에서, 개인정보에 대한 보다 신중하고 각별한 관리와 원활한 유용을 위한 능동적이며 효율적 접근이 필요하다. 이를 위해 국민의 기본권인 개인정보자기결정권을 보장하고, 기업과 국가 및 사회의 원활한 운용에 이바지할 적절한 개인정보의 처리를 담보할 방안이 모색되어야 함은 자명하다. 그리고 이러한 방안 모색의 기초가 되는 것이 정보주체의 동의이다. 상황이 이렇다보니, 개인정보처리자의 수집・이용・제공 등 그 처리에 관한 국가의 관리․감독의 필요성이 높아지게 되었다. 그 중 개인정보처리자의 개인정보 처리의 단초가 되는 정보주체의 동의에 있어, 무분별하고 관행적인 동의수집 절차의 진행으로 인해, 정보주체의 개인정보자기결정권을 과도하게 침해 또는 제한하는 결과를 야기하고 있다. 개인정보처리자에 의한 개인정보의 처리는 일반적으로 정보주체의 동의에 의해 이뤄진다는 점에서 정보주체의 권리를 보장하고, 제4차 산업혁명 시대에 효과적으로 대응하기 위한 정보주체의 동의절차에 대한 효율적 대응방안 모색이 필요하다. EU와 일본 및 미국의 경우 제4차 산업혁명 시대라 불리는 정보통신 사회로 진입함에 따라 개인정보의 효율적이며 공정하고 체계적인 처리와 그에 따른 안전한 관리를 위해, 다양한 입법방침을 시행 또는 시행 예정에 있다. 이에 현행 개인정보보호법제 및 실제 공공기관 및 민간 기업 등에서 운용하고 있는 정보주체의 동의 절차 및 서식 등에 관한 사항을 고찰해 보고, 문제점을 파악한 후 해외 입법례의 비교․분석을 통해 정보주체의 개인정보자기결정권을 보장하고, 정보통신 기술의 발달에 효과적으로 대응할 수 있는 개인정보의 동의절차에 관한 개선 방안을 모색해 보고자 한다.
With the advancement of information and communication technologies, personal information has become an essential element of social management. However, due to the advancement of information and communication technology, personal data is a personal representation to individuals, but it is a means of earning profits for companies and an essential element for national and social administration for countries and society. And the need for the management and supervision of the state on the treatment of such problems has increased. Personal information self-determination right which is basic human rights should be guaranteed by the government. We need to find an efficient way to respond to the procedures for consent by data subject. As the EU, Japan and the United States enter the information society that is called the fourth industrial revolution era, various legislative policies are planned or enforced for efficient, fair and systematic processing of personal information and safe management accordingly. In this paper, I examine issues related to consent procedures and forms of information entities, identify problems, and compare and analyze overseas legislation to ensure the right of self - determination of information subjects and to respond effectively to the development of information and communication technologies. This will try to find ways to improve the personal information agreement form.
영국의 개인정보보호법 -일반원칙 및 정보주체의 권리를 중심으로-
[NRF 연계] 한국정보법학회 정보법학 Vol.13 No.1 2009.04 pp.211-236
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
영국의 1998년 정보보호법은 개인정보보호에 관한 일반원칙 및 그 구체적인 실행 요건과 절차들을 규정하였다. 즉, 공정하고 적합한 처리의 원칙, 목적제한의 원칙, 목적적합성의 원칙, 정확성의 원칙, 보존필요성의 원칙, 정보주체의 권리 원칙, 안전보호조치의 원칙, 역외이전제한의 원칙 등이다. 또한 동법은 개인정보보호의 실효성을 확보하기 위하여 개인정보에 관한 개인의 권리를 구체적으로 규정하였다. 즉, 개인정보 접근권, 침해 예방 청구권, 직접 마케팅을 위한 처리를 방지할 권리, 자동화된 결정과 관련된 권리, 위반에 대한 보상받을 권리, 개인정보통제권 등이다. 이러한 일반원칙과 개인의 권리에 관한 규정은 이미 UN 개인정보지침, OECD 가이 드라인이나 EU 개인정보보호지침에서 천명하였던 각종 원칙들이 수용되어 구체화된 것이라고 할 수 있다. 영국의 1998년 정보보호법은 8개의 정보보호원칙을 천명함으로써 개인정보의 보호 를 위한 추상적․일반적 규범을 제시하고 있는데, 우리나라의 공공기관개인정보법은 OECD 가이드라인을 수용하여 목적명확화의 원칙, 수집제한의 원칙, 목적적합성의 원칙, 정보정확성․최신성의 원칙, 안전보호의 원칙, 책임명확화의 원칙, 공개의 원칙, 개인참여의 원칙을 규정함으로써 원칙 규정에 있어서는 영국의 정보보호법과 큰 차이가 없다. 반면, 우리나라의 정보통신망법은 정보통신망에서의 개인정보에 관한 일반법으로서의 성격을 가지고 있지만 개인정보보호에 관한 일반원칙의 천명 없이 개별적․구체적인 보호 요건 및 절차만을 규정하고 있다. 이러한 일반원칙의 부재로 인한 문제점은 개별적․구체적 요건․절차가 미비한 경우에 문제해결을 위한 기준이 없게 된다는 점이다. 따라서 정보통신망법을 개정하거나 개인정보에 관한 통합법률을 새로이 제정하는 경우에 일반원칙을 규정할 필요가 있다. 개인정보와 관련한 개인의 권리에 대하여 영국의 1998년 정보보호법은 6가지 권리 를 규정하였는데, 공공기관 개인정보법은 처리정보의 열람, 처리정보의 열람제한, 처리정보의 정정 및 삭제만을 규정하고 있으며, 정보통신망법도 동의철회권, 열람 및 정정 청구권, 손해배상청구권이 규정되어 있어서 영국법보다 상대적으로 규정된 범위 가 좁다. 개인정보와 관련한 권리를 반드시 명시적으로 규정하여야만 해당 개인의 권리가 보호되는 것은 아니지만, 구체적인 권리를 개인정보와 관련한 법률에서 명시적으로 규정함으로써 선언적으로 뿐만 아니라 실질적으로도 개인의 권리 보호가 효과적으로 이루어질 수 있기 때문에 우리의 경우에도 향후 관련법규의 제개정 시에 보다 구체적인 권리유형을 명시하여 규정할 필요가 있다. 그러나 여기에서 주의할 점은 우리의 개인정보의 처리환경이 영국과는 다르며, 개 인정보의 유통환경도 다르다는 점을 인식하여 일반원칙을 명문으로 규정하거나 추가적인 권리를 규정하는 경우에 우리나라에 적합한 내용으로 변형하여 받아들여야 한다는 점이다.
The Data Protection Act 1998 of U.K. provides the Data Protection Principles. According to the first principle, personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless at least one of the conditions in Schedule 2 is met, and in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met. Second, Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. Personal data shall be accurate and, where necessary, kept up to date. Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. Personal data shall be processed in accordance with the rights of data subjects under this Act. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data. The Act permits data subject and others to access to personal data, to prevent processing for purposes of direct marketing, at any time to require the data controller to ensure that no decision taken by or on behalf of the data controller which significantly affects that individual is based solely on the processing by automatic means of personal data in respect of which that individual is the data subject for the purpose of evaluating matters relating to him by notice in writing to any data controller, to compensation for failure to comply with certain requirements, and right of rectification, blocking, erasure and destruction On the other hand, our laws related to personal information protection partly provide such principle or rights of data subjects. To enhance protection of right to personal information and promote trafficking of personal information, more concrete and distinct standard are necessary to be provided in our new laws.
[NRF 연계] 충남대학교 법학연구소 법학연구 Vol.18 No.1 2010.04 pp.61-94
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
오늘날 개인정보처리에 대한 동의제도는 규범적, 민주적 차원에서 심각한 남용 양상을 보이고 있다. 이 글은 우선 정보주체의 동의권이 당면한 문제와 이를 극복하기 위한 법적 대책에 관하여 유럽연합, 영국, 미국, 캐나다, 한국의 최근 정책동향을 고찰한다. 하지만 국내외를 통틀어서 디지털충격에 대응하여 동의에 관한 개인정보보호 법제를 체계적으로 정비하고 일관된 관행으로 모범을 보여주고 있는 나라를 찾기 어렵다. 동의는 다른 개인정보처리 원칙을 대체하지는 못하나 분쟁의 발생억지, 유리한 해결에 요긴하게 쓰일 수 있으므로 개인정보처리자에 의하여 현실적으로 광범위하게 사용되고 있다. 동의제도가 효과 측면에서 정보주체보다 개인정보처리자에게 훨씬 큰 혜택을 주고 있으며 그 만큼 개인정보처리자는 동의획득을 위한 양자 간의 거래에 주도적이고 우월한 입장으로 임하고 있다. 대등한 당사자간의 거래가 아닌 점에서 기인하는 시장실패를 방지하기 위해서는 정부, 전문기관, 시민사회가 적극적인 참여로 공정한 개인정보처리의 시장 질서를 세울 필요가 있다. 빅 데이터는 기존의 개인정보보호 법제와 시장 간의 불협화음을 더욱 여실히 보여주고 있다. 일정범주에서 동의제도에 기초한 정보주체와 정보처리자간의 권리의무관계를 감독기관과 정보처리자간의 권리의무관계로 잠정적으로 대체하는 개인정보 이해당사자간 권리의무와 그 집행구조의 재조정을 포함한 개인정보보호법제의 전반적인 개정을 검토할 필요가 있다.
The mechanism of consent by data subject is currently abused severely. This article first surveys the policy approaches of the European Union, the United Kingdom, the United States, Canada, and Korea. The author finds that no country has ever showed a satisfactory solution to this problem. Although it cannot replace other principles of personal data protection, data processors widely used the consent mechanism as it can preempt the eruption of disputes and help to settle any dispute in a favorable way once it arises. As the consent mechanism gives more benefit to data processors than to data subject, data processors are more aggressive in obtaining consent by the data subject. The processors are dominant compared to the data subjects. Because it is not a transaction between the equals, efforts should be made by the government, agencies and the civil society to prevent a market failure and establish a fair market order in personal data processing. Big data exacerbates the serious conflicts between the existing legal system of personal data protection and the market development. An overall revision of the legal system should be contemplated including replacement of the legal relationship based on the consent mechanism by the legal relationship based on regulatory mechanism on a temporary and partial basis.
스마트도시 환경에서의 데이터 활용과 정보주체 보호의 조화 ― 지방자치단체의 개인정보 보호 역량 제고를 위한 법제 개선과 거버넌스 구축을 중심으로 ―
[NRF 연계] 서울시립대학교 법학연구소 서울법학 Vol.33 No.4 2026.02 pp.39-69
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구는 스마트도시 4.0 단계로의 진입에 따른 데이터 수집 체계의 근본적인 패러다임 변화를 분석하고, 이에 대응하는 지방자치단체의 법적 책임과 실효적인 개인정보 보호 거버넌스 구축 방안을 제시하는 데 그 목적이 있다. 현대의 스마트도시는 과거 1.0 및 2.0 단계의 정적 인프라 중심 체계에서 벗어나, 인공지능(AI), 디지털 트윈, 자율주행 기술이 유기적으로 결합된 동적 네트워크 체계로 진화하였다. 이 과정에서 발생하는 데이터는 수집의 ‘즉시성’, ‘대량성’, ‘비정형성’을 특징으로 하며, 이는 단순히 영상 정보의 수집을 넘어 개인의 이동 경로, 생활 양식, 바이오 정보까지 포함하는 정교한 프로파일링(Profiling)을 가능하게 함으로써 정보주체의 기본권에 전례 없는 위협을 가하고 있다. 특히 본 연구는 최근 대법원 판례(2024다210554)를 중심으로 가명정보 처리 특례와 정보주체의 자기결정권 사이의 법리적 충돌을 집중적으로 조명하였다. 대법원이 가명화 전 단계에서의 정보주체의 처리정지요구권을 인정함에 따라, 지자체가 공익적 통계나 과학적 연구를 목적으로 수행하던 데이터 가명처리 행정에 상당한 법적 제약이 발생하게 되었다. 이는 데이터 활용의 유연성을 확보하면서도 정보주체의 실질적인 통제권을 어떻게 보장할 것인가라는 해법을 지방자치단체에 요구하고 있다. 그러나 현재 대다수의 지자체는 전문 인력의 부족, 재정적 자립도 저하, 위탁 운영에 따른 책임 소재의 모호성 등 구조적 한계로 인해 이러한 급변하는 법적 환경에 적절히 대응하지 못하고 있는 실정이다. 이에 본 연구는 비교법적 고찰을 통해 EU GDPR의 ‘비재산적 손해배상(Non-material Damage)’ 법리와 미국 샌프란시스코 등 주요 도시의 ‘감시 기술 통제 조례’ 사례를 분석하였다. 이를 통해 도출된 지방자치단체의 역량 제고 방안은 다음과 같다. 첫째, 법제도적 차원에서 「스마트도시법」과 「개인정보 보호법」의 정합성을 재정비해야 한다. 지자체가 법적 불확실성 없이 혁신적인 서비스를 실증할 수 있도록 ‘지자체 특화형 규제 샌드박스’와 ‘개인정보 안심구역’에 대한 구체적인 입법 모델을 구축해야 한다. 둘째, 거버넌스 차원에서 시민 참여형 ‘리빙랩(Living Lab)’ 모델을 법적 통제 기제로 활용할 것을 제언한다. 시민이 기획 단계부터 참여하여 개인정보 영향평가를 공동 수행함으로써 기술 수용성을 높이고, 지자체 내부적으로는 독립적 권한을 가진 전담 개인정보 보호관(DPO)을 배치하여 민간 위탁 업체에 대한 실질적인 관리・감독권을 강화해야 한다. 셋째, 사후 구제 차원에서 정신적 고통이나 통제권 상실 등 비재산적 손해에 대한 위자료 산정 기준을 구체화해야 한다. 이는 지자체로 하여금 더욱 엄격한 데이터 관리 기준을 준수하게 만드는 법적 인센티브로 작용할 것이며, 시민들에게는 실질적인 권리 구제의 기반을 제공할 것이다. 결론적으로 본 연구는 지방자치단체가 단순한 기술 도입자에서 능동적인 ‘데이터 수탁자’로 거듭나야 함을 강조한다. 본 연구에서 제시한 법제 개선과 참여형 거버넌스 모델은 스마트도시가 감시와 통제의 공간이 아닌, 시민의 신뢰를 바탕으로 한 지능형 혁신 공간으로 지속 가능하게 하는 필수적인 전제 조건이 될 것이다.
This study aims to analyze the fundamental paradigm shift in data collection systems resulting from the transition to the Smart City 4.0 era and to propose practical measures for local governments to establish robust personal information protection governance and legal accountability. Contemporary smart cities have evolved from the static, infrastructure- oriented systems of the 1.0 and 2.0 stages into dynamic network ecosystems where Artificial Intelligence (AI), Digital Twins, and autonomous technologies are organically integrated. Data generated in this process is characterized by its immediacy, massiveness, and unstructurability. Such characteristics enable sophisticated profiling that encompasses not only location tracking but also behavioral patterns and biometric recognition, thereby posing unprecedented threats to the fundamental rights of data subjects. A particular focus of this research is the legal conflict between the special provisions for pseudonymized data and the data subject's right to self-determination, centered on the recent Supreme Court precedent (2024Da210554). By recognizing the data subject's right to request the suspension of processing even at the pre-pseudonymization stage, the court has introduced significant legal constraints on administrative actions previously performed by local governments for public statistics or scientific research. This ruling necessitates a solution for local governments to ensure the substantial control of data subjects while maintaining the flexibility of data utilization. However, most local governments currently face structural limitations?such as a lack of professional expertise, low fiscal independence, and ambiguity in liability arising from private outsourcing?which hinder their ability to respond effectively to this rapidly changing legal landscape. Through a comparative legal analysis, this study examines the doctrine of “Non-material Damage” under the EU GDPR and the “Surveillance Technology Oversight Ordinances” of major cities like San Francisco. Based on these findings, the study suggests the following enhancement measures for local governments: First, the consistency between the “Smart City Act” and the “Personal Information Protection Act” must be restructured at the legislative level. To allow local governments to demonstrate innovative services without legal uncertainty, specific legislative models for “Local Government-Specific Regulatory Sandboxes” and “Data Safe Zones” must be established. Second, from a governance perspective, the “Living Lab” model should be elevated to a legal control mechanism. By involving citizens from the planning stage to co-perform privacy impact assessments, local governments can enhance social acceptance of technology. Internally, it is essential to appoint independent Data Protection Officers (DPOs) with specialized authority to strengthen supervision over private contractors. Third, as a matter of judicial remedy, criteria for calculating compensation for non-material damages?including psychological distress and the loss of data control?must be specified. This will serve as a strong legal incentive for local governments to adhere to stricter data management standards and provide a solid foundation for actual rights remediation for citizens. In conclusion, this study emphasizes that local governments must transcend their roles as mere technology adopters and emerge as proactive “Data Trustees.” The proposed legislative improvements and participatory governance models are essential prerequisites for ensuring that smart cities remain sustainable as innovative spaces built on citizen trust, rather than becoming spaces of surveillance and control.
데이터 프라이버시 보호를 위한 정보주체의 권리에 대한 고찰 - EU GDPR 법제도를 중심으로 -
[NRF 연계] 가천대학교 법학연구소 가천법학 Vol.17 No.2 2024.06 pp.3-42
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
2021년 이후 2년간 전 세계에서 모두 26억 건의 개인정보유출 피해가 발생했는데, 이는 10년 전인 2013년과 비교할 때 3배 이상 증가한 수치라고 한다. 우리나라 또한 2020년 8월 이후 3년 동안 유출된 개인정보 건수가 6,505만 2,2232건에 달할 정도로 개인정보의 침해 사례가 많이 발생하였다. 이로 인하여 기업들은 자신들의 책임문제가 대두되어 고객의 개인정보를 적극적으로 수집·분석하여 마케팅에 활용하지 못하고 있다. 이에 기업들은 관련 법률에 정보주체의 권리를 명확하게 설정하여 책임 범위를 예측하여 고객들의 개인정보를 적극적으로 활용할 수 있도록 해 줄 것을 요구하였으며, 고객들 또한 관련 법률에 그들의 권리를 명시하여 자신들의 개인정보를 보호받기를 원하고 있다. 물론 우리나라는 2011년 개인정보호법의 제정, 2020년 데이터3법의 개정 그리고 2023년 3월 14일 공포되어 2023년 9월 15일 시행하는 개인정보보호법의 개정을 통해 정보주체의 권리를 강화하기는 하였지만 여전히 미흡하다. 이에 이 논문에서는 2018년 5월부터 적용되는 EU의 일반 데이터 보호 규칙상 정보주체의 권리를 우리나라 개인정보보호법상 정보주체의 권리와 비교 검토를 통해 개선방안을 마련하고자 하였다. 그 결과 개인정보보호법상 개인정보 열람권, 개인정보 전송권, 개인정보의 정정·삭제권, 개인정보의 처리 제한권, 자동화된 결정에 대한 정보주체의 권리 및 이의제기권 관련하여 일부 규정을 도입할 필요가 있다고 보고 그에 대한 개선방안을 제시하였다.
In the two years after 2021, a total of 2.6 billion personal information leakage damages occurred around the world. Compared to 2013, which corresponds to 10 years ago, the number of such damages has more than tripled. The same goes for Korea. As of August 2020, the number of personal information leaked over the past three years was about 65 million, with many cases of personal information infringement. As a result, companies are unable to collect and analyze customer's personal information and actively use it for marketing due to the issue of their responsibility. Accordingly, companies requested that the rights of the data subject be clearly set in the relevant laws. This is because they can predict the scope of their responsibility and actively utilize the personal information of customers. Customers who are data subjects are also requesting that their rights be specified in the relevant laws by protecting their personal information. Of course, Korea has strengthened the rights of data subjects through the enactment of the Personal Information Protection Act in 2011, the revision of the Data 3 Act in 2020, and the revision of the Personal Information Protection Act, which was promulgated on March 14, 2023, and takes effect on September 15, 2023, but it is still insufficient. Therefore, in this paper, I tried to prepare sseveral solutions to improve the rights of data subjects under the EU's general data protection rules(GDPR) through comparative review with the rights of data subjects in Korea's Personal Information Protection Act. As a result, under the Personal Information Protection Act, it was necessary to introduce some legal systems regarding the right to access personal information, the right to transmit personal information, the right to correct and delete personal information, the right to restrict the processing of personal information, the right of the data subject to automated decisions, and the right to object to them.
정보주체에 의하여 공개된 개인정보의 처리 요건 - 서울행정법원 2023. 10. 26. 선고 2021구합57117 판결에 대한 평석을 겸하여 -
[NRF 연계] 법조협회 법조 Vol.73 No.2 2024.04 pp.290-333
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
대상판결은 페이스북(‘원고’)이 Graph API V1을 통하여 제3자 앱에 가입하는 페이스북 이용자의 페이스북 친구의 개인정보를 정보주체의 동의를 받지 않고 제3자 앱 개발자에게 제공(‘이 사건 정보 이전’)하였다는 이유로 개인정보보호위원회가 내린 과징금 등 처분의 당부를 다루었다. 이 글에서는 ① 이 사건 정보 이전의 법적 성격이 무엇인지, ② 페이스북 친구의 정보가 온전히 페이스북 친구의 정보인지, ③ 페이스북 이용자가 스스로 페이스북에 게시하여 공개한 정보를 타인이 활용하고자 하는 경우에, 동의에 관한 구 정보통신망법의 규정을 얼마나 엄격하게 적용하여야 하는지를 중심으로 대상판결을 비판적으로 검토하였다. 페이스북 친구가 자신의 프로필 정보에 대하여 ‘전체공개’를 선택한 경우에는 이 사건 정보 이전에 관한 페이스북 친구의 묵시적 동의가 있었다고 보는 것이 합리적이다. 반면 페이스북 친구가 자신의 프로필 정보에 대하여 ‘친구만’ 공개를 선택한 경우에는 (i) 이 사건 정보 이전으로 인하여 페이스북 친구의 정보가 그의 ‘친구’ 범위를 벗어나 더욱 넓은 범위의 사람에게 공개되었는지, (ii) 제3자 앱의 정보 활용 방식이 당초 페이스북 친구의 정보 공개 목적과 관련성을 가지는지를 검토하여, 이 사건 정보 이전이 페이스북 친구의 묵시적 동의 범위 내에 있는지를 판단하여야 한다. 페이스북 친구의 묵시적 동의가 인정되지 않는 경우에도, 이익형량을 통하여 이 사건 정보 이전이 객관적으로 위법한 것인지를 판단할 필요가 있다.
Seoul Adminitrative Court Decision 2021gu-hob57117 dated October 26, 2023 (hereinafter “the decision”) dealt with the disposition of penalty order issued by the Personal Information Protection Commission on the grounds that Facebook (the plaintiff) provided the personal information of Facebook friends of Facebook users who signed up for a third-party app through Graph API V1 to a third-party app developer without obtaining the consent of the data subject. This article examines the decision, focusing on (1) the legal nature of the data transfer, (2) whether the information of the Facebook friends solely belongs to the Facebook friends, and (3) how strictly the provisions of the Information and Communications Network Act regarding consent should be applied when a Facebook user wants to utilize the information that he or she has posted on Facebook and disclosed to others. If the Facebook friend has selected "All", it is reasonable to assume that the Facebook friend has implied consent to the transfer of the profile information. If, on the other hand, the Facebook friend chose "Friends Only", the following factors should be considered: (i) whether the transfer of the profile information expanded the scope of disclosure beyond his "friends" and (ii) examining whether the third-party app's use of the information was related to the purpose for which the Facebook friend originally disclosed the information. Even if the Facebook friend's implied consent is not recognized, it is still necessary to determine whether the transfer was objectively unlawful through the balance of related interests test.
公開된 個人情報 處理의 違法性 - 대법원 2016. 8. 17. 선고 2014다235080 판결 -
[NRF 연계] 한국행정판례연구회 행정판례연구 Vol.22 No.2 2017.12 pp.31-59
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
정보통신서비스 제공자들이 그 이용자의 개인정보를 동의 없이 일반의제3자에게 제공함으로써 제기된 이 사건은 현대정보사회에서 흔히 발생할수 있는 사안의 하나라고 할 수 있을 것이다. 개인정보 보호의 필요성이인식되면서 그를 위한 법적 규율이 이루어지는 과정에서 문제되는 개별영역별 입법을 거쳐 일반법으로서의 개인정보 보호법이 제정 ‧ 시행되는 시기에 걸쳐서 발생한 이 사건은, 다음과 같이 크게 3가지 쟁점으로 정리할 수있다. 첫째로, 이 사건이 구 정보통신망법과 새로운 개인정보 보호법의 시행이 이루어지는 과정에서 발생함으로써 그 적용법률의 문제가 존재하였다. 당시의 개인정보 보호법이 명문의 규정으로 두었던 것처럼 구 정보통신망법은 그 특별법으로서의 지위를 가지고 있었다. 따라서, 이 사건에 있어서는 우선 구 정보통신망법이 적용되어야 했고, 동 법에 흠결이나 불명확한부분이 있는 경우에 보완적으로 개인정보 보호법이 적용되어야 했다. 그러나, 유사한 사항에 대해 서로 유사한 법적 규제를 함으로써 그 법적용상의혼란을 초래한 입법상의 불비를 먼저 지적하여야 할 것이며, 따라서, 이 부분에 대해서는 입법적 개선이 요구된다고 할 것이다. 즉, 특별법인 정보통신망법에서 정보통신망에서의 정보통신서비스 제공자가 그 이용자의 개인정보의 보호와 관련된 특별한 사항에 대해서만 규율하고, 개인정보 보호와관련된 그 밖의 사항은 개인정보 보호법에 맡겨서 법규제의 정합성과 법적용의 간명함을 확보하여야 할 것이다. 둘째로, 이 사건 대법원판결 등을 포함하여, 개인정보 보호와 관련된사안에 있어서 금과옥조와 같이 제시되어온 개인정보자기결정권은 현대정보사회에서 요청되는 개인정보의 보호와 유통의 조화를 위한 개념으로서는부적절함을 지적하였다. 개인정보자기결정권에 기반하여 도입된 동의제도는실질적으로 그 기능을 다하지 못하고, 새로운 정보통신산업의 발전에도 장애가 될 수 있음을 알 수 있었다. 그리고, 이에 대해서는 EU개인정보보호법제로부터 개인정보보호권이 개인정자기결정권에 대체될 수 있음을 살펴보았다. 셋째로, 이 사건 대법원판결은 개인정보자기결정권에 근거하면서도 원고 X의 개인정보가 공개된 것임을 이유로 충돌하는 법익간의 비교형량에의하여 피고의 개인정보 처리행위의 최종적인 위법성 여부를 판단하고 있으며, 또한 이미 공개된 개인정보를 정보주체의 동의가 있었다고 객관적으로 인정되는 범위 내에서 수집·이용·제공 등 처리를 할 때는 정보주체의 별도의 동의는 불필요하다고 보아야 하고, 별도의 동의를 받지 아니하였다고하여 개인정보 보호법 제15조나 제17조를 위반한 것으로 볼 수 없다고 판단하였다. 이러한 대법원의 판단은 현대정보사회에서 개인정보 보호입법과그 적용실제 간의 갭을 메우는 유연한 사고로서 적정한 것으로 평가되어야할 것이다.
This case raised by the user of the information communication service whose personal data were collected by the information communication service providers and provided to the public third parties without consent can be said to be a common case in modern information society. The subject matter of this supreme court’s judgment is whether the conduct of the information communications service providers to collect personal data such as photographs, name, sex, birth year, occupation, workplace, educational background, career, etc. of the plaintiff X, who is a national university professor is illegal. This case can be summarized into three legal issues as follows. Firstly, this case occurred in the process of implementation of the new Personal Information Protection Act and the former Information and Communications Network Act, and there was a legal problem of the applicable law. The Personal Information Protection Act is a kind of general law, whereas the former Information and Communications Network Act is a special law. Therefore, in this case, the former Information and Communications Network Act had to be applied first, and in case of defective or unclear part of the Act, the Personal Information Protection Act had to be supplemented. Secondly, it is pointed out in matters with regard to the protection of personal data, including this Supreme Court decision, that the right to self-determination of personal data was inappropriate as a concept for harmonizing the protection and flow of personal data in modern information society. It was found that the consent system based on the right of self-determination of personal data could not fulfill its function effectively and could be a hindrance to the development of the information and communication industry. In this regard, we have seen that the right to protect personal data from the EU Personal Information Protection Act can be substituted for the right of self-determination of personal data. Thirdly, the Supreme Court finded whether the processing of the plaintiff’s personal data is ultimately illegal depending on the balancing between the conflicting legal interests. The Supreme Court 's judgment should be evaluated as a flexible thinking that fills the gap between privacy legislation and its application in modern information society.
정보주체의 동의 없는 개인정보 활용의 위법성 판단 방법 – 기본권 충돌의 관점에서 –
[NRF 연계] 한국헌법학회 헌법학연구 Vol.28 No.1 2022.03 pp.279-308
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
인간은 각자가 고유한 가치를 지니면서 공동체 내에서 타인과 교류하면서 살아간다. 즉 헌법은 고유한 가치를 지닌 인간이 타인 내지 공동체와 밀접한 관련을 맺고 살아갈 것을 전제하고 있는 것이다. 인격 주체성을 특징짓는 정보인 개인정보는 타인 내지 공동체와 관련성을 맺을 때, 고유한 가치를 가진 인간을 서로 구별하기 위해 필요하다. 따라서 헌법상 개인정보는 타인에 의한 활용이 예정된 것이며, 그 활용을 지나치게 제한하는 해석은 위헌적인 해석이 될 수 있다. 그러나 정보주체의 인간의 존엄과 가치를 훼손하는 개인정보 활용은 금지된다는 것 역시 헌법의 인간상으로부터 이끌어낼 수 있다. 정보주체의 동의 없는 개인정보 활용 역시 그 목적이 헌법적으로 정당하게 추구할 수 있는 것인 한, 헌법상 자유권에 의해 보호받는 행위이다. 따라서 정보주체의 동의 없는 개인정보 활용을 무조건 위법하다고 평가한다면, 개인정보를 활용하려는 자의 헌법상 보장된 자유권을 침해하게 될 여지가 있다. 결국 동의 없는 활용이라도 개인정보 보호법 제15조 제1항에 곧바로 위반된다고 할 것이 아니라 정보주체의 개인정보자기결정권과 개인정보를 활용하려는 자의 헌법상 자유권을 실제적 조화의 원칙에 의해 비교형량 하여야 한다. 이러한 비교형량이 바로 정보주체의 동의 없는 개인정보 활용의 위법성을 판단하는 방법이 될 것이다. 결국 개인정보 활용의 위법성을 판단하는 방법은 구체적 사건에서 정보주체의 개인정보자기결정권과 다른 주체의 자유권을 비교형량 하는 것이라고 본다.
Humans live by interacting with others within the community while each has its own value. In other words, the Constitution presupposes that humans with unique values should live closely related to others or communities. Personal information, which is information that characterizes personality subjectivity, is necessary to distinguish humans with unique values from each other when they are related to others or communities. Therefore, personal information under the Constitution is scheduled to be used by others, and an interpretation that excessively restricts its use can be an unconstitutional interpretation. However, the use of personal information that undermines the human dignity of the data subject is prohibited. The use of personal information without the consent of the data subject is also an act protected by the constitutional right of freedom as long as its purpose can be pursued properly. Therefore, it cannot be evaluated that the use of personal information without the consent of the data subject is unconditionally illegal. In the end, even if personal information is used without consent, it does not immediately violate Article 15 (1) of the Personal Information Protection Act. The right to self-determination over personal information of the data subject and the right to have freedom under the constitution of those who want to use personal information must be compared. This comparation will be a method of presenting the constitutional limitations of the use of personal information by other people. In the end, the method of setting the constitutional limitations of the use of personal information is to compare the data subject's right to self-determination of personal information and the other subject's right to freedom in specific cases.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.