년 - 년
개정 개인정보보호법과 GDPR의 투명성원칙 및 동의절차에 관한 비교법적 연구 - 구글의 GDPR 위반 사건과 홈플러스 사건 비교를 중심으로 - KCI 등재 KCI 등재후보
원광대학교 법학연구소 원광법학 제36집 제4호 2020.12 pp.53-82
유럽연합은 2018. 5. 부터 개인정보보호법(GDPR; General Data Protection Regulation, 이하 ‘GDPR’)을 전면 시행하고 있다. GDPR이 제정된 직후 유럽의 개인정보보호단체 들은 글로벌 기업들에 대하여 GDPR을 위반을 근거로 각종 진정을 제기하였다. 이 중 주목할 만한 사건은 프랑스의 프라이버시 보호협회인 None Of Your Business(NOYB) 와 La Quadrature du Net이 프랑스의 정보와 자유에 관한 국가위원회인 CNIL(Commission nationale de l'informatique et des libertés)에 구글의 프라이버시 정 책과 개인맞춤형 광고 문제를 진정한 것이다. 2019. 1. 21. 경 CNIL은 구글이 개인정보보호원칙 중 투명성의 원칙과 개인 맞춤 형 광고 동의 절차를 위반하였음을 인정하여 5000만 유로(한화 약 642억원)의 과징 금을 부과하였다. 구글은 불복하여 항소하였으나, 프랑스 항소법원은 2020. 6. 20. 경 구글의 항소를 기각하였다. 개정 개인정보보호법을 입법하는 과정에서 가장 많이 논의된 규정은 유럽의 개인 정보보호법(GDPR; General Data Protection Regulation) 이다. 이 때문에 GDPR이 개 정 개인정보보호법에 주는 영향에 관한 연구는 활발하다. 그러나 실제 GDPR이 적용 된 결정문을 꼼꼼히 살펴 GDPR에서 말하는 개인정보처리원칙과 동의절차의 적법성 이 실제로 어떻게 적용되는지에 관한 연구는 찾기 어렵다. 본고는 이러한 문제의식을 토대로 CNIL이 2019. 1. 21. 구글에 과징금 5000만 유 로를 부과한 케이스를 집중적으로 분석하여 GDPR의 개인정보처리원칙 중 투명성의 원칙을 중심으로 개인정보를 수집할 때의 동의절차에 대한 판단의 기준을 밝히고자 한다. 이를 바탕으로 GDPR의 투명성 원칙 및 동의절차에 관한 기준이 개인정보보호 법의 법률해석에 어떻게 적용될 수 있는지 우리나라의 홈플러스 사건과 비교하여 살 핀다. 두 판결의 비교를 통하여 개정 개인정보보호법 시행 이후 투명성의 원칙 및 동의절차의 적법성을 확립하는 기준을 정립하고, 개인정보처리자가 정보주체에게 제 시하는 개인정보 수집 및 이용항목의 내용과 동의하는 방식이 투명성의 원칙에 입각 하여 이루어져야 함을 주장하고자 한다. 위 연구목적을 달성하기 위하여 던지는 연구 질문은 다음과 같다. 첫째, 개정 개인정보보호법은 GDPR의 개인정보보호원칙 중 투명성의 원칙과 어 떻게 상응하고 있는가? 둘째, 개정 개인정보보호법 및 GDPR의 개인정보처리의 동의절차는 적법성을 어 떻게 확보하는가? 셋째, 구글 GDPR 위반 과징금 사건와 홈플러스 사건의 비교가 우리에게 주는 시 사점은 무엇인가? 연구의 범위는 개정 데이터 3법 중 개정 개인정보보호법에 한정하였다. 개인정보 보호법이 우리나라 개인정보보호법제의 가장 중심이기도 하고, 개정 데이터 3법 중 정보통신망 이용촉진 및 정보보호 등에 관한 법률 중 일부는 개정 개인정보보호법에 흡수되는 방향으로 정립되었으며, 신용정보의 이용 및 보호에 관한 법률 또한 개인 정보보호에 관한 해석의 기준을 개인정보보호법에서 정하는 바에 따르기 때문이다 그리고 개인정보처리원칙 중에서도 개인정보보호법 제3조 제1항에 상응하는 GDPR 의 투명성의 원칙을 중점적으로 살핀다. 구글 GDPR 위반 케이스는 투명성의 원칙을 바탕으로 판단하였고, 비교 대상이 되는 홈플러스 사건 또한 투명성의 원칙을 적용 한 판시를 보여주고 있기 때문이다.
The European Union has enforced the General Data Protection Regulation (GDPR) from May 2018. After the GDPR was enacted, European privacy organizations have filed various complaints against global companies for violating the GDPR. Privacy protection associations such as None Of Your Business (NOYB) and La Quadrature du Net complained to Commission nationale de l'informatique et des libertés(CNIL) about Google's privacy policy and personalized advertising issues. In January 21, 2019, France’s data protection regulator, CNIL, has issued Google a 50 million euros fine for failing to comply with its GDPR obligations. Google has filed appeal to a higher court, but France’s top court has dismissed Google’s appeal on June 20, 2020. The most widely-discussed regulation in the process of enacting the revised privacy law is the European General Data Protection Regulation(GDPR). For this reason, research on the impact of the GDPR on the revised Personal Information Protection Act has been actively discussed. However, there is a little study on personal information processing and legality of consent procedures that are discussed in GDPR are applied in real cases. This paper focuses on analyzing CNIL imposing a penalty of 50million Euros on Google cases on January 21, 2019. With this study, the research will clarify the criteria for judgement on the procedure for privacy data collectiong consent based on GDPR’s transparency policy. Furthermore, by comparing the Google case with the legal case of Homeplus in Korea, it further examines a possible way that the GDPR's transparency principles and procedure for consent can be affected to legal interpretation of the Personal Information Protection Act. With this comparative study results, this paper will not only set the criteria for the principle of transparency and procedure for consent after the enforcement of the revised Personal Information Protection Act, but also argue that the data controller should collect and use personal information based on the principle of transparency. The research will focus on following research questions in below: First, how does the revised Personal Information Protection Act correspond to the GDPR's transparency principles? Second, how does the revised Personal Information Protection Act and GDPR's procedure for consent ensure the legality? Third, what are the implications of the comparison between the Google case and the legal case of Homeplus in Korea? The scope of the study was limited to the revised Personal Information Protection Act among the Three Data Acts. In addition, among the principles of personal information processing, the study focuses on the GDPR's transparency principles. This is because the Google case is judged based on the GDPR's transparency principles, and the legal case of Homeplus in Korea also shows a judgment that applies the transparency principles.
GDPR원칙을 고려한 PbD 적용 방안에 관한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제22권 제4호 2022.10 pp.109-118
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
전 세계 국가들이 개인정보보호의 중요성을 인식하고 법률, 가이드라인, 지침 등의 다양한 형태로 정보주체의 권리 보호에 대해 논의해왔다. 개인정보보호를 위한 사전 예방적 차원에서 공통적으로 강조하고 있는 개념 중 하나가 PbD(P rivacy by Design)이며 정보주체의 프라이버시 보호를 위해 필수적인 요소로 주목받기 시작하였다. 그러나 시스템 개발 이나 서비스 운영에 있어서 사전에 개인의 프라이버시를 최우선적으로 고려하자는 PbD 개념이 아직은 선언적 차원에 만 머물고 있어서 이를 실제로 구현하기 위한 구체적 방법에 대한 논의는 상대적으로 부족하다. 이에 본 연구에서는 G DPR의 기본 원칙과 정보주체의 권리를 기준으로 어떠한 원칙과 권리가 우선적으로 고려되어 PbD가 구현되어야 하는 지를 논의하였다. 이를 통해 국내 환경에서 시스템이나 서비스 개발 시 우선 시 해야 할 프라이버시 고려사항을 제시하 여 PbD의 적용을 위한 방안을 제시했다는 점에서 본 연구의 의의가 있다.
Countries around the world have recognized the importance of personal information protection and have discussed protecting the rights of data subjects in various forms such as laws, regulations, and guidelines. PbD (Privacy by Design) is one of the concepts that are commonly emphasized as a precautionary measure for the protection of personal information, and it is starting to attract attention as an essential element for protecting the privacy of information subjects. However, the concept of PbD to prioritize individual privacy in system development or service operation in advance is still only at the declarative level, so there is relatively little discussion on specific methods to implement it. Therefore, this study discusses which principles and rights should be prioritized to implement PbD based on the basic principles of GDPR and the rights of data subjects. This study is meaningful in that it suggests a plan for the practical implementation of PbD by presenting the privacy considerations that should be prioritized when developing systems or services in the domestic environment.
GDPR에서의 스마트그리드 분야 영향분석 연구 : 스마트미터링 환경 중심으로
한국정보통신설비학회 한국정보통신설비학회 학술대회 2018년도 정보통신설비 학술대회 2018.08 pp.27-29
※ 기관로그인 시 무료 이용이 가능합니다.
3,000원
The General Data Privacy Regulation (GDPR) was adopted on 14 April 2016, and became enforceable beginning 25 May 2018. GDPR is compared with existing Data Protection Directive, stronger and uniform regulations are possible. In particular, it is expected to have a impact on Smart Grid industry, which uses vast amounts of data. This paper examines how the GDPR affects the smart grid industry and describes its economic impact using the Gordon & Lob model.
대규모 언어 모델(LLM)의 기술적 특성과 GDPR 원칙 간 충돌에 관한 개인정보 리터러시 교육 효과 실증 분석 KCI 등재
한국융합보안학회 융합보안논문지 제26권 제3호 2026.06 pp.177-185
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 대규모 언어 모델(LLM)의 기술적 특성과 GDPR 원칙 간 충돌에 관한 개인정보 리터러시 교육 효과를 실증적으로 분석하였다. 이를 위해 인공지능 및 정보보호 전공 대학원생 31명을 대상으로 단일 집단 사전-사후 검사 설계를 적용하여 5가지 기술적 요인(대규모 데이터 사용, 모델 경직성, 데이터 편향성, 블랙박스, 새로운 보안 위협)에 따른 인식 변화를 측정하였다. 분석 결과, 교육 후 ‘모델 경직성’과 ‘데이터 편향성’ 요인에서는 위험 인식이 유의미하게 강화된 반면, ‘블랙박스’와 ‘대규모 데이터 사용’ 관련 항목에서는 기술적 이해도 향상에 따라 막연한 불안감이 합리적으로 조정되는 경향이 나타났다.
This study provides an empirical analysis of the impact of privacy literacy education on the tension between the technical features of Large Language Models (LLMs) and GDPR principles. Utilizing a single-group pre- and post-test design with 31 graduate students in AI and information security, we evaluated perceptual changes based on five technical domains: large-scale data use, model rigidity, data bias, the black box phenomenon, and new security threats. The results indicate that while risk perception was significantly heightened regarding ‘model rigidity’ and ‘data bias,’ arbitrary anxiety surrounding ‘black box’ issues and ‘large-scale data use’ was rationally mitigated through enhanced technical comprehension.
개인정보보호법제 관점에서 본 블록체인의 법적 쟁점 GDPR 및 국내 개인정보보호법을 바탕으로
한국정보기술응용학회 JITAM Vol.25 No.2 2018.06 pp.133-146
※ 기관로그인 시 무료 이용이 가능합니다.
4,600원
The technical definition of Blockchain is commonly known ‘distributed ledger’, however, there is no legal definition for being accepted in worldwide. Therefore, unless legal definitions and concepts of Blockchain are presented, there is a possibility that various legal disputes will occur in the future in Blockchain environment. The purpose of this study is to derive legal issues related to personal information protection that can be conflicted in Blockchain environment based on domestic Privacy Act and GDPR. The outcomes of this study can prevent various legal disputes and provide solutions that may occur due to the spread of Blockchain. It also suggests the foundation for the improvement of Privacy Act. Finally, it contributes to activate of Blockchain, industry, in Korea.
중국과 EU의 개인정보보호 규정 비교와 시사점 KCI 등재
중국지역학회 중국지역연구 제8권 제4호 통권21호 2021.11 pp.215-239
※ 기관로그인 시 무료 이용이 가능합니다.
6,300원
중국 개인정보 보호제도에 있어 기본법이라고 할 수 있는 개인정보보호법이 2021년 8월 20일 제13차 전인대 상무위원회에서 통과된 후 2021년 11월 1일부로 정식 시행된 다. 이법은 중국 민법전, 네트워크보안법, 데이터안전법 등 여러 법령에 산재되어 있는 개인정보보호와 관련된 내용을 통합하여 체계적으로 정리가 되었을 뿐만 아니라, 이들 법안을 중심으로 사이버 정보관리, 데이터 및 일반 개인정보 보호와 관련된 기본적인 법규체제가 완비되었다는 의미를 가지고 있다. EU의 신 개인정보보호법이이라고 할 수 있는 GDPR이 2018년 5월25일부로 정식 발 효가 되었다. GDPR과 비교하여 중국 개인정보보호법은 개인정보의 정의와 적용범위, 개인정보 처리 원칙, 개인정보 주체의 권리 보장, 개인정보처리 동의 및 철회 조항, 개인 정보의 국외이전, 신기술 응용 개인정보의 보호, 위반시 처벌 조항 등에 있어 대부분 유사한 면을 보이고 있지만, 민감 개인정보의 범위가 더 넓고, 공공안전 사건 발생시 사전 고지없이 개인정보 처리가 가능하다는 점, 법규 위반시의 제재 조항은 GDPR 대비 더욱 엄격하고 광범위하다는 차이점도 내포하고 있다. 4차 산업혁명 시대를 맞아 디지털 경제의 발전이 가속화되는 현재 개인정보 처리 및 이전관련 이슈가 앞으로 더욱 늘어날 것이기 때문에 우리 기업들로서는 사전 중국 개인정보보호법에 대한 이해와 대응노력이 필요하다.
The Personal Information Protection Law, which can be said to be the basic law of China's personal information protection system, was passed by the Standing Committee of the 13th Chinese National People's Congress on August 20, 2021, and will be officially entered into force on November 1, 2021. It has the significance that the China’s basic legal system related to cyber information, data management and protection of personal information has been completely organized by integrating the contents related to personal information protection scattered in various laws such as the Chinese Civil Code, the Network Security Law, the Information Safety Law, etc. EU's new version of personal information protection law, GDPR, came into effect formally starting from May 25, 2018. Compared to GDPR, China’s Personal Information Protection Law is mostly similar to the former in many respects such as definition and application of personal information, principles of personal information processing, guarantee of the rights of the subject of personal information, provision regarding consent and withdrawal of personal information processing, international transfer of personal information, protection of personal information through application of new technology, penalty provisions for violation, etc. The Chinese law, however, differs from EU in the following points: the scope of sensitive personal information is wider, personal information processing is possible without prior notice in case of public safety incidents, and sanctions for violation of laws are stricter and broader than GDPR. As the digital economy is accelerating in the era of the 4th industrial revolution, and the issues related to personal information processing and transfer are expected to increase in the future, Korean companies need efforts to understand and respond to the China's Personal Information Protection Law in advance.
생성형 AI의 기술적 특성에 따른 개인정보 보호 체계 재설계 : 모델 경직성과 프라이버시 환각 대응을 중심으로 KCI 등재
한국융합보안학회 융합보안논문지 제25권 제5호 2025.12 pp.89-96
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 생성형 인공지능(GAI)의 모델 경직성 및 확률적 생성이라는 기술적 특성이 GDPR의 7대 기본 원칙과의 구조적 충돌을 분석한다. 전문가 인터뷰 및 문헌 분석 결과, GAI가 야기하는 프라이버시 환각 현상은 기존의 정적인 데이터 처리에 근거한 정확성 원칙의 준수를 어렵게 만들고 있으며, 보유기간 제한 및 책무성 원칙 역시 원칙의 준수를 어렵게 만든다는 점 을 확인하였다. 이에 본 연구는 실현 가능성을 담보하는 규범적 재설계 방향을 제시한다. 구체적으로 머신 언러닝 기반의 삭 제권 대체 보장, 프라이버시 환각 대응을 위한 출력 중심의 정확성 관리, 개발자-운영자 간의 공유 책임 체계 법제화를 제안 한다. 본 연구는 GAI 시대 개인정보 보호 법제의 기술-규제 간극 해소를 위한 기초 분석틀을 제공했다는 점에서 의의가 있다.
This study analyzes the structural conflicts between the seven fundamental principles of the GDPR and the inherent technical characteristics of Generative AI (GAI), namely Model Rigidity and Probabilistic Generation. Findings from expert interviews and literature review confirm that the phenomenon of Privacy Hallucination caused by GAI fundamentally impedes compliance with the Accuracy Principle, which presupposes the processing of static data. Furthermore, practical adherence to the principles of Storage Limitation and Accountability is also found to be challenging. Consequently, this research proposes a direction for normative redesign that ensures technical feasibility, specifically recommending the guarantee of the right to erasure based on Machine Unlearning, the introduction of an output-centric accuracy management duty to counter Privacy Hallucination, and the formalization of a Shared Responsibility Model between developers and operators. This study is significant as it provides a foundational analytical framework for resolving the technology-regulation gap in personal data protection law in the GAI era.
4차산업환경에서 개인정보 처리 동의의 자발성에 관한 연구 KCI 등재
전북대학교 동북아법연구소 동북아법연구 제19권 제2호 2025.10 pp.583-605
※ 기관로그인 시 무료 이용이 가능합니다.
6,000원
본 논문은 인공지능과 빅데이터 등 4차 산업혁명 기술이 일상화된 디지털 환경에서, 개인정보처 리자가 정보주체의 동의를 얻어 개인정보를 처리하는 현행 법제하에서 동의의 자발성이 실질적으 로 보장되고 있는지를 비판적으로 검토한다. 현행 개인정보 보호법은 정보주체의 동의를 개인정보 처리의 필수 요건으로 규정하고 있으나, 디지털 플랫폼 생태계의 정보 비대칭, 다크 패턴, 자동화된 알고리즘 등으로 인해 동의가 형식화되고 정보주체의 실질적 선택권이 제한되는 문제가 있다. 본 논문은 동의의 자발성 개념과 법적 성격, 관련 조항 간의 관계를 분석하고, 유럽연합의 일반 개인정보보호규정(GDPR)과 일본, 미국 등 해외 입법례를 검토하여 자발성 판단기준과 국내 입법 시사점을 도출한다. 또한 정보통신기술 구조상 개인정보 처리 과정에서 정보주체의 자발성이 침 해되는 사례를 분석하고, 이에 대한 법적·정책적·기술적 대응의 필요성을 살펴본다. 국내 입법 제안으로서, 동의의 자발성을 개인정보 보호법에 명시적으로 규정하고, 비자발적 동 의의 무효 조항을 도입하며, 동의 절차의 세분화와 정기적 갱신 절차의 의무화를 제안한다. 아울러 이용자 대상의 교육·홍보 강화와 개인정보보호위원회의 정책적 가이드라인 제시가 필요함을 제 언한다. 요컨대 동의의 자발성은 개인정보 자기결정권 실현의 핵심 요소이며, 4차 산업혁명 기술 환경에 서 동의 제도의 실효성 있는 접근 방안을 모색해야 할 시점이다.
This study critically examines whether the voluntariness of consent for personal data processing is effectively guaranteed under the current legal framework in the digital environment shaped by technologies of the Fourth Industrial Revolution, such as artificial intelligence and big data. Although the Personal Information Protection Act (PIPA) requires consent from data subjects as a prerequisite for processing personal data, the realities of the digital ecosystem—characterized by information asymmetry, dark patterns, and automated algorithms—have rendered such consent largely formal and coercive. The paper analyzes the conceptual and legal characteristics of voluntariness in consent, reviews relevant provisions under Korean law, and compares them with the General Data Protection Regulation (GDPR) of the European Union as well as legislative examples from Japan and the United States. Based on this analysis, it identifies critical shortcomings in ensuring voluntariness and proposes legislative, policy, and technological improvements. Specifically, the study suggests explicitly stipulating voluntariness in the PIPA, introducing a provision invalidating non-voluntary consent, and mandating regular renewal of consent procedures. These measures are intended to secure the substantive autonomy of data subjects and enhance the effectiveness of the consent system in the age of AI and big data.
페이스북의 데이터 수집(사용)과 남용에 대한 법적 쟁점 검토 - 페이스북에 대한 2018년 미 상원의 청문회 내용을 중심으로 -
동국대학교 비교법문화연구원 비교법연구 제25권 2호 2025.08 pp.325-385
※ 기관로그인 시 무료 이용이 가능합니다.
11,700원
본 논문은 페이스북(Meta Platforms Inc.)의 ‘케임브리지 애널리티카 데이터 유출 사건’을 계기로 2018. 4. 미국 상원이 페이스북의 최고 경영자 마크 저커버그(Mark Zuckerberg)를 상대로 진행한 청 문절차에서 페이스북의 개인정보 유출에 따른 개인정보와 프라이버시 (Privacy) 보호를 비롯한 SNS 플랫폼의 제반 문제에 대하여 논의된 다양한 법적 쟁점과 향후 개인정보 법제의 규제 방향에 대하여 살펴보 았다. 먼저, 데이터 유출에 따른 개인정보 및 프라이버시 침해는 연방거래 위원회(FTC)의 Consent Order 2011 위반으로서 FTC의 법적제재 및 규제강화 논의, EU GDPR(General Data Protection Regulation)의 미국 적용 논의, 데이터 유출 시 통지제도, 사전 동의 (Opt-in) 적용 강화 및 이를 제도화하는 ‘Consent Act(Customer Online Notification for Stopping Edge-provider Network Transgressions Act)’ 법안, 온라인 정치 광고의 투명성과 책임성을 강화한 ‘Honest Ads Act(정직한 광고법)’ 법안, 그리고 ‘어린이 온라 인 사생활보호법(the Children’s Online Privacy Protection Act, COPPA)’ 등에 대하여 검토하였다. 또한, SNS에서 다양한 디지털 상호작용을 추적하는 Tracking에 관하여, Shadow Profiles, API 정책, 안드로이드 폰의 통화기록과 SMS 데이터 수집에 관한 문제, 디지털 환경에서 Tracking 방지의 기술적 한계에 따른 데이터 소유권 법제화, 통제권 강화, 이의제기 절 차 및 콘텐츠 관리정책 등의 문제를 살펴보고, 미래 개인정보 법제의 규제 방향으로서 규제강화 요구와 반론, 인공지능을 활용한 개인정보 및 프라이버시 보호에 대하여 검토하였다. 비록 개인정보 유출로 인한 피해는 막대했지만, 청문회를 통하여 SNS를 주도하는 글로벌 빅테크 산업의 다양한 문제점을 공론화함으 로써, 페이스북과 Tech 산업 전반, 정부와 민간, 사회 각계에서 개인 정보와 프라이버시에 관한 인식의 전환과 확대, 기술혁신의 긍정적이 고 발전적인 효과를 일으킨 점을 주목할 필요가 있다. 한국도 예외가 아니며, 개인정보보호에 관한 사회적 인식의 제고, 법 집행 기관의 국내외 산업을 구분하지 않는 적극적인 법집행으로 효 과적인 개인정보 보호와 관련 법제의 발전을 기대할 수 있을 것이다. 그러나 청문회 이후에도 문제의 미해결 영역은 많이 존재하고, 이는 우리가 해결해야 할 사안이기에 청문절차에 나타난 주장들은 여전히 유효하다. 다만 본 논문은 종국적인 해결을 제시하기보다는 연구 능력 의 부족으로 인해 개인정보 및 프라이버시에 대한 기술적 침해 수단 및 방법, 그 미비점들을 제시하는데 연구의 주된 목적이 있으므로 깊 이 있는 논의 및 대안 제시에 이르지 못하였다. 향후 페이스북을 비롯한 SNS 플랫폼 Tech 기업의 데이터 수집과 사용에 따른 개인정보 보호와 프라이버시 보호 문제는 AI의 기술 발 전에 따른 역할 확대, 데이터 소유권과 통제권의 법제화 쟁점과 함께 규제와 혁신을 동시에 보장할 수 있는 합리적이고 발전적인 논의가 적 극적으로 이뤄져야 할 것이다.
This paper aims to examine various legal issues and future directions of personal data regulation that were discussed during the U.S. Senate hearing held in April 2018, following the Facebook–Cambridge Analytica data breach. The hearing was convened to question Mark Zuckerberg, CEO of Facebook (now Meta Platforms Inc.), regarding the company’s handling of user data, the ensuing privacy violations, and broader systemic issues related to social networking platforms. First, the data breach and resulting infringements on personal information and privacy constituted a violation of the 2011 Consent Order issued by the Federal Trade Commission (FTC). Accordingly, this paper reviews the FTC’s legal sanctions and calls for stronger regulation, discussions on the potential applicability of the EU General Data Protection Regulation (GDPR) to U.S. entities, data breach notification requirements, the reinforcement of opt-in consent mechanisms as proposed in the “Consent Act” (Customer Online Notification for Stopping Edge-provider Network Transgressions Act), the “Honest Ads Act” aimed at enhancing transparency and accountability in online political advertisements, and the Children’s Online Privacy Protection Act (COPPA). Additionally, the paper explores issues surrounding tracking technologies used on social networking services (SNS), such as shadow profiles, API policies, the collection of call and SMS data from Android phones, and the technical limitations of preventing tracking in digital environments. It addresses related concerns such as the legal codification of data ownership, the enhancement of user control rights, procedures for contesting content moderation decisions, and Facebook’s content governance policies. Furthermore, the study discusses regulatory trends, demands for stricter controls, opposing arguments, and the use of artificial intelligence in protecting privacy and personal data. Although the harm caused by the data breach was substantial, the hearing played a crucial role in bringing public attention to the structural issues of global big tech industries leading SNS platforms. It also sparked a shift in awareness across Facebook, the broader tech sector, governments, private sectors, and civil society regarding data privacy, ultimately encouraging constructive technological innovation. South Korea is no exception. The growing public awareness of personal data protection, coupled with proactive enforcement by regulatory authorities that do not distinguish between domestic and foreign industries, is expected to contribute to more effective safeguards for personal information and the further development of relevant legal frameworks. However, many unresolved issues remain even after the hearing. These issues continue to pose challenges that demand attention, and the arguments raised during the hearing are still valid. This paper does not attempt to offer conclusive solutions to these challenges. Rather, due to limitations in research capacity, its primary aim is to present the methods and shortcomings of technological intrusions into privacy and personal data, rather than to propose in-depth alternatives. Looking ahead, the issues of personal data collection and use by SNS platform tech companies such as Facebook must be addressed through active discussions on how to simultaneously ensure both regulation and innovation. These efforts must consider the expanding role of AI, the legislative issues concerning whether data ownership and user control rights should be legally established, and the need for a balanced and forward-looking regulatory framework.
EU의 데이터 이용 관련 법제와 우리 법에의 시사점 – 독일의 최근 사례를 중심으로 - KCI 등재
전북대학교 동북아법연구소 동북아법연구 제17권 제3호 2023.10 pp.143-177
※ 기관로그인 시 무료 이용이 가능합니다.
7,800원
흔히 데이터 주도 경제로 표현되는 최근의 디지털 산업화가 몇몇의 데이터 독점 기업을 통해 주도 되어지면서 결과적으로 상업적 이용가치를 가지는 데이터가 포함하고 있는 이용자 개인정보가 심각하게 누출될 수 있다는 점이 최근에 부각되기 시작하였다. 데이터의 경제성과 소비자프라이버시(Privacy) 보호라는 두 가지 목적을 동시에 달성하기 위해서는 개인정보 수집 및 활용에 있어 정보주체인 이용자의 권리를 보호하면서 동시에 이를 정당하게 활용하기 위한 동의 획득 방안을 구체화하여야 하여야 한다. 우리 개인정보보호법과 GDPR에서 정하고 있는 동의 절차의 측면에서 가장 크게 차이가 나는 부분은 우리 법이 동의라는 요소를 개인정보처리의 필수적인 사항으로 규정하고 있음에 반해 GDPR은 동의를 개인정보처리의 합법성 요건 즉 정보주체의 동의, 계약의 체결과 이행, 법적의무의 이행, 정보주체 혹은 다른 자연인의 중대한 이익의 보호, 공익을 위한 업무의 처리 또는 공적 권한의 행사, 정보처리자 또는 제3자의 정당한 이익의 달성 중에서 하나로만 정하고 있다는 점이다. 그렇지만 양자의 절차상의 실제적인 부분은 유사한 점이 많다. 양자의 차이란 결국 실제 법 적용의 정도와 범위의 차이를 의미하는 것으로 해석할 수 있다. 거대 온라인 플랫폼의 영업방식 즉 포괄적 동의를 통한 개인정보 처리 방식은 GDPR의 투명성 원칙의 위반이자 동의 절차 규정의 위반임은 명백하며 이와 더불어 근래에는 독일 연방카르텔청 개입과 법원의 결정을 통하여 대규모 온라인 플랫폼의 독점력을 약화시킬 경쟁법적 규제 수단으로서의 데이터 보호라는 의미가 중요성을 가지게 되었다. 특히 독일의 Facebook 사건을 시작으로 EU의 DMA 제정의 일련의 과정에서 만들어진 새로운 규제 방식 즉 시장지배적 사업자가 개인정보 보호법을 위반하거나 기타의 방법으로 개인정보 자기결정권을 침해하는 내용의 약관에 형식적 동의를 통해 적법하게 개인정보를 영업활동에 사용하는 행위를 금지하는 점은 우리 법제에도 시사하는 바가 적지 않다. 특히 2023년 현재 생성형 인공지능의 진화를 통해 새로운 단계로 진입한 대규모 온라인 플랫폼의 개인정보 수집의 정당성의 문제는 결과적으로 기존의 동의의 실질성 여부를 어떻게 적용할 것인가라는 논의로 발전되고 있으며 이는 여전히 소극적인 입장을 보이고 있는 우리 법제의 입장에서도 좀더 깊이 있는 고민이 필요할 것으로 보인다.
As the recent digital industrialization, often described as a data-driven economy, has been driven by a few data monopolies, it has recently been highlighted that there may be serious leakage of users’ personal information, including data with commercial use value. The main difference between the Korean Personal Information Protection Act and the GDPR in terms of the consent process is that the Korean Act stipulates consent as an essential element of personal information processing, while the GDPR only establishes consent as one of the requirements for the legality of personal information processing, namely, the consent of the data subject, the conclusion and performance of a contract, the fulfillment of a legal obligation, the protection of the vital interests of the data subject or other natural persons, the processing of tasks in the public interest or the exercise of public authority, and the achievement of the legitimate interests of the data processor or a third party. However, there are many similarities in the practical aspects of the two procedures. The differences can be interpreted as differences in the extent and scope of the actual application of the law. It is clear that the practice of large online platforms, i.e., processing personal information through blanket consent, is a violation of the transparency principle of the GDPR and a violation of the consent procedure regulation, and in recent years, through the intervention of the German Federal Cartel Office and court decisions, the meaning of data protection as a means of competition law regulation to weaken the monopoly power of large online platforms has gained importance. In particular, the new regulatory approach created in the course of the EU’s DMA enactment, starting with the Facebook case in Germany, which prohibits market-dominant operators from using personal information for business activities through formal consent to terms and conditions that violate privacy laws or otherwise infringe on the right to self-determination of personal information, has implications for our legal system. In particular, the issue of the legitimacy of personal information collection by large-scale online platforms that have entered a new stage through the evolution of generative artificial intelligence in 2023 is consequently developing into a discussion on how to apply the substantiality of existing consent, which is likely to require more in-depth consideration from the position of our legal system, which is still showing a passive stance.
5,800원
빅 데이터 시대, 사람들은 인터넷이 가져다 주는 각종 편리함을 즐기고 있다. 예를 들어,모바일 결제, 인터넷 쇼핑, 전자 정무(政務) 등이다. 반면에 사람들 의 생활을 매우 편리하게 하는 동시에, 인터넷은 사람들과 사회에 매우 큰 복병 을 가져왔다. 사람들은 웹 서핑이나 인터넷 쇼핑, 앱을 이용할 때 여러벙법 개 인정보를 남긴다. 이러한 인터넷상에 남겨진 개인정보는 불법 분자에 의해 수 집 판매되어 전신 사기(電信詐騙)를 일으키거나 사생활이 노출될 수 있다. 또 한 사람들이 인터넷에 남긴 개인정보、데이터는 개인에 대한 평가를 할 수 있 는 근거가 되기도 한다. 그러나 그 정보들이 당시에는 정확했겠지만 시간이 흐 를수록 정확성을 잃어가고, 심지어 요즘 사람들에게 부정적인 평가와 차별적 영향을 미칠 수 있다. 이 문제를 해결하기 위해서는 개인정보를 더 잘 관리하고 통제함으로써 개인정보의 오남용을 막을 수 있다. 그리고 이렇게 하면 정보 주 체의 인격 존엄을 보호하고 인격 이익도 보호할 수 있다. 이 때문에 EU에서는 「일반 정보보호조례」(General Data Protection Regulation, GDPR)를 확립하였 다. 이후에도 상당수 국가가 자국(自國)에 맞는 “삭제권” 설치를 검토하게 되었 다. 중국에서는 2021년 8월 「개인정보보호법」을 통과시켜 11월 1일부터 시행 한다. 이 법의 47조는 삭제권에 대해 비교적 상세하게 규정하고 있다. 그러나 이 새로운 법이 제대로 시행될 수 있을지에 대해서는 삭제권 제도의 기본 개요 를 검토하여 삭제권 설정의 필요성을 명확히 하고, 삭제권 시행 과정의 현실적 장애물을 분석하여 개선 방안을 제시하였다. 또한 이를 바탕으로 “잊혀질 권리” 와 “삭제권”의 명칭 논란 및 정의에 대해 비교적 상세하게 설명하고 “삭제권”이 라는 명칭과 정의를 위한 강력한 뒷받침을 제공함과 동시에 중국의 「개인정보 보호법」, 「네트워크안전법」, 「민법전」 등의 법률은 이미 개인을 정당한 이익을 전제로 인터넷이나 부정적인 정보의 불이익으로부터 충분히 보호할 수 있기 때문에 별도로 잊혀질 권리를 규정할 필요가 없다고 생각한다.
In the era of Internet-based big data, people enjoy a more convenient life than ever before. A smartphone takes over the world, and people use various payment platforms to complete various transactions. In the network platform ”shopping malls” shopping, entertainment, office...... While people enjoy these conveniences, they also leave traces everywhere. People's own privacy and personal information is memorized by the Internet. This is the security problem brought by the era of big data.Criminals may use the information left over from the Internet for telecom fraud or resale, and even people's privacy will be snooped on. Moreover, the browsing history or message left on the Internet may become the ”basis” for others to evaluate themselves. Although some comments or left information were accurate at that time, people's thoughts will also change with the change of times, so the left information on the network may have a negative evaluation and differential impact on people today. The basic idea to solve this problem is to better manage and control the storage, transmission and deletion of personal information, so as to better protect personal information. China adopted the ”Personal Information Protection Law” in August 2021, which came into effect on November 1. Article 47 of this law provides more detailed provisions on the ”right to delete”. However, as to whether the new law can be implemented smoothly, this paper, through the study of the basic overview of the right to delete system, makes clear the necessity of establishing the right to delete, and also analyzes the realistic obstacles in the implementation of the right to delete, and gives the improvement plan. On this basis, it gives a detailed explanation of the name dispute and definition of ”right to be forgotten” and ”right to delete”, and provides a strong support for the name and definition of ”right to delete”. At the same time, it believes that China's ”Personal Information Protection Law”, ”network Security Law”, ”Civil Code” and other laws are enough to protect individuals under the premise of legitimate interests. It is not adversely affected by the Internet or negative information, so there is no need to stipulate the right to be forgotten separately.
在以互联网为基础的大数据时代,人们享受了比以往任何时候都更加便 利的生活. 一部智能手机 “走天下”,人们通过各种支付平台完成各种交易. 在网络平台“逛商场”购物,娱乐,办公……在人们尽情享受这些便利的同 时,也处处留下了痕迹. 这就是大数据时代带给人们的安全问题. 不法分 子可能会利用网络遗留的信息进行电信诈骗或者转卖,甚至人们的隐私 都会被窥探. 并且,网络上遗留的浏览记录或者留言,有可能成为别人评 价自己的“依据”. 虽然有些留言或者遗留信息在当时是准确的,但是随着 时代的变迁,人们的思想也会发证变化,那么网络上的遗留信息可能会 对当今的人们产生负面的评价和差异化影响. 能够解决这一问题的基本思 路就是要更好的管理、控制个人信息的储存、传输和删除,从而可以更 完善的保护个人信息. 中国于2021年8月通过「个人信息保护法」,11月1日 开始实施. 这部法律的第47条对“删除权”做了较为详细的规定. 但是关于 这一新法是否能顺利实施,本文通过研究删除权制度的基本概况,明确 了删除权主要内容,同时也对删除权实施过程中的现实障碍进行分析, 并给予了改善方案. 在此基础上,对“被遗忘权”与“删除权”的名称争议及 定义进行了较为详尽的阐释,并为“删除权”这一名称与定义提供了有力的 支撑,同时认为中国的「个人信息保护法」,「网络安全法」,「民法典」等 法律已经足够保护个人在正当利益的前提下,不受网络或者负面信息的 不利影响,因此不需要在单独规定被遗忘权.
5,800원
빅 데이터 시대, 사람들은 인터넷이 가져다 주는 각종 편리함을 즐기고 있다. 예를 들어,모바일 결제, 인터넷 쇼핑, 전자 정무(政務) 등이다. 반면에 사람들 의 생활을 매우 편리하게 하는 동시에, 인터넷은 사람들과 사회에 매우 큰 복병 을 가져왔다. 사람들은 웹 서핑이나 인터넷 쇼핑, 앱을 이용할 때 여러벙법 개 인정보를 남긴다. 이러한 인터넷상에 남겨진 개인정보는 불법 분자에 의해 수 집 판매되어 전신 사기(電信詐騙)를 일으키거나 사생활이 노출될 수 있다. 또 한 사람들이 인터넷에 남긴 개인정보、데이터는 개인에 대한 평가를 할 수 있 는 근거가 되기도 한다. 그러나 그 정보들이 당시에는 정확했겠지만 시간이 흐 를수록 정확성을 잃어가고, 심지어 요즘 사람들에게 부정적인 평가와 차별적 영향을 미칠 수 있다. 이 문제를 해결하기 위해서는 개인정보를 더 잘 관리하고 통제함으로써 개인정보의 오남용을 막을 수 있다. 그리고 이렇게 하면 정보 주 체의 인격 존엄을 보호하고 인격 이익도 보호할 수 있다. 이 때문에 EU에서는 「일반 정보보호조례」(General Data Protection Regulation, GDPR)를 확립하였 다. 이후에도 상당수 국가가 자국(自國)에 맞는 “삭제권” 설치를 검토하게 되었 다. 중국에서는 2021년 8월 「개인정보보호법」을 통과시켜 11월 1일부터 시행 한다. 이 법의 47조는 삭제권에 대해 비교적 상세하게 규정하고 있다. 그러나 이 새로운 법이 제대로 시행될 수 있을지에 대해서는 삭제권 제도의 기본 개요 를 검토하여 삭제권 설정의 필요성을 명확히 하고, 삭제권 시행 과정의 현실적 장애물을 분석하여 개선 방안을 제시하였다. 또한 이를 바탕으로 “잊혀질 권리” 와 “삭제권”의 명칭 논란 및 정의에 대해 비교적 상세하게 설명하고 “삭제권”이 라는 명칭과 정의를 위한 강력한 뒷받침을 제공함과 동시에 중국의 「개인정보 보호법」, 「네트워크안전법」, 「민법전」 등의 법률은 이미 개인을 정당한 이익을 전제로 인터넷이나 부정적인 정보의 불이익으로부터 충분히 보호할 수 있기 때문에 별도로 잊혀질 권리를 규정할 필요가 없다고 생각한다.
In the era of Internet-based big data, people enjoy a more convenient life than ever before. A smartphone takes over the world, and people use various payment platforms to complete various transactions. In the network platform ”shopping malls” shopping, entertainment, office...... While people enjoy these conveniences, they also leave traces everywhere. People's own privacy and personal information is memorized by the Internet. This is the security problem brought by the era of big data.Criminals may use the information left over from the Internet for telecom fraud or resale, and even people's privacy will be snooped on. Moreover, the browsing history or message left on the Internet may become the ”basis” for others to evaluate themselves. Although some comments or left information were accurate at that time, people's thoughts will also change with the change of times, so the left information on the network may have a negative evaluation and differential impact on people today. The basic idea to solve this problem is to better manage and control the storage, transmission and deletion of personal information, so as to better protect personal information. China adopted the ”Personal Information Protection Law” in August 2021, which came into effect on November 1. Article 47 of this law provides more detailed provisions on the ”right to delete”. However, as to whether the new law can be implemented smoothly, this paper, through the study of the basic overview of the right to delete system, makes clear the necessity of establishing the right to delete, and also analyzes the realistic obstacles in the implementation of the right to delete, and gives the improvement plan. On this basis, it gives a detailed explanation of the name dispute and definition of ”right to be forgotten” and ”right to delete”, and provides a strong support for the name and definition of ”right to delete”. At the same time, it believes that China's ”Personal Information Protection Law”, ”network Security Law”, ”Civil Code” and other laws are enough to protect individuals under the premise of legitimate interests. It is not adversely affected by the Internet or negative information, so there is no need to stipulate the right to be forgotten separately.
在以互联网为基础的大数据时代,人们享受了比以往任何时候都更加便 利的生活. 一部智能手机 “走天下”,人们通过各种支付平台完成各种交易. 在网络平台“逛商场”购物,娱乐,办公……在人们尽情享受这些便利的同 时,也处处留下了痕迹. 这就是大数据时代带给人们的安全问题. 不法分 子可能会利用网络遗留的信息进行电信诈骗或者转卖,甚至人们的隐私 都会被窥探. 并且,网络上遗留的浏览记录或者留言,有可能成为别人评 价自己的“依据”. 虽然有些留言或者遗留信息在当时是准确的,但是随着 时代的变迁,人们的思想也会发证变化,那么网络上的遗留信息可能会 对当今的人们产生负面的评价和差异化影响. 能够解决这一问题的基本思 路就是要更好的管理、控制个人信息的储存、传输和删除,从而可以更 完善的保护个人信息. 中国于2021年8月通过「个人信息保护法」,11月1日 开始实施. 这部法律的第47条对“删除权”做了较为详细的规定. 但是关于 这一新法是否能顺利实施,本文通过研究删除权制度的基本概况,明确 了删除权主要内容,同时也对删除权实施过程中的现实障碍进行分析, 并给予了改善方案. 在此基础上,对“被遗忘权”与“删除权”的名称争议及 定义进行了较为详尽的阐释,并为“删除权”这一名称与定义提供了有力的 支撑,同时认为中国的「个人信息保护法」,「网络安全法」,「民法典」等 法律已经足够保护个人在正当利益的前提下,不受网络或者负面信息的 不利影响,因此不需要在单独规定被遗忘权.
EU의 GDPR 제20조에 전송요구권 도입 이후 우리나라 개인정보보호법 개정 안에도 전송요구권이 포함되어 논의되고 있다. 개인정보 전송요구권은 마이데이 터를 구현하기 위해 필요한 정보주체의 핵심적인 권리 중 하나이다. 이 연구는 의료분야 마이데이터를 실현하기 위해 의료정보에 대한 전송요구권의 도입가능성에 대한 것이다. 의료정보 전송요구권 구현을 위해 개인정보보호법 개정안을 포함한 개인정보보호법제와 보건의료법제의 제한점과 한계에 대하여 검토하였 고, 이후 이를 극복하기 위해 필요한 입법정책적 제안을 하고자 하였다. 개인정 보보호법은 개정안을 포함하여 전송 대상 정보의 개념과 기술적인 전송형식, 이 행의무자 규모의 문제가 있고, 그 입법취지 역시 의료 마이데이터를 구현하기 위한 그것과는 차이가 있다. 또한 보건의료법제 하에서 기록열람과 진료기록의 송부와 관련된 의료법 규정, 진료정보교류 관련 법제 역시 아직까지는 주체, 대 상이 매우 한정적이라는 한계가 있다. 이에 의료정보와 의료 분야의 특수성을 고려해 개인정보보호 법제 하에서는 전송요구권의 최소한의 기본을 규정하고 이후 보건의료 분야 개별 법률에서 추가적 규율하는 것을 제안한다.
Two bills have recently been proposed at the Korean National Assembly to introduce data portability provisions to the Personal Information Protection Act. The two bills were largely modeled on Article 20 Right to Data Portability of European Union’s General Data Protection Regulation (“GDPR”). We argue that the proposed “one-size-fits-all” provisions are ill-suited to health data portability for a few reasons. First and foremost, the bills stop short of mandating interoperability of data being transferred, in a manner similar to the GDPR. Unlike in some other sectors, however, interoperability is critical in achieving ease of data transmission in health care, because health IT is highly fragmented with numerous vendors, each with their own data format. Secondly, the two bills exempt inferred data and derived data from data portability, also in a manner similar to the GDPR. While such exemption may be striking a balance between the interest of individuals and the interest of data controllers, it renders data portability almost valueless in the context of health care, where important data are usually inferred data and derived data created by health providers. Lastly, an exemption from data portability for small businesses will be at odds with health care, in which primary care clinics are inevitably “small businesses”. These limitations found in the data portability bills are not surprising, in light of the core objective of their model, Article 20 of the GDPR, which was to promote competition by helping users retrieve their data held by dominant service providers. Hence, we argue that a better approach to health data portability is to amend the Medical Service Act that already includes basic measures to facilitate data exchange between health providers. Although the Medical Service Act too has to be amended to implement health data portability in the scale already being implemented in other countries, it will not be limited by the need for universal applicability across different industries that the general, Personal Information Protection Act faces. Instead, more nuanced and sophisticated health data portability can be designed in the Medical Service Act that provides more clarity to complex legal issues unique to health data, such as interoperability, data scope, health information exchange and secondary use, to name a few.
A Study on Data Governance in Digital Trade KCI 등재
한국무역금융보험학회(구 한국무역보험학회) 무역금융보험연구(구 무역보험연구) 제22권 제5호 2021.10 pp.153-169
※ 기관로그인 시 무료 이용이 가능합니다.
5,100원
21세기에 접어들어 상품 및 서비스의 디지털화로 글로벌 무역은 데이터 무역을 포괄하는 디지 털 무역으로 점차 확대되고 있으며 국가 간 경쟁의 핵심 요소로 데이터를 기반으로 한 디지털 무역이 자리 잡을 것으로 전망된다. 글로벌 데이터 거버넌스 수립을 둘러싼 국가 간 이해관계 가 첨예하게 엇갈리고 있어 디지털 무역 활성화를 위해 연관된 데이터 거버넌스 연구가 필요 한 시점이다. 본 연구는 디지털 무역과 관련된 주요국의 쟁점과 양자 및 복수의 국가 간 국제통상규범의 형성 과정을 고찰하고 디지털 무역과 연관된 데이터 거버넌스를 분석한다. 미국, EU, 중국 및 기타의 디지털 무역정책 및 FTA 규정을 고찰한 결과, 전자적 전송의 무관세 원칙, 국경 간 데 이터 이전, 개인정보와 데이터 보호 및 디지털 세의 쟁점 관련 조항들이 공통으로 포함되어 있음을 확인하였고, 주요국 모두 디지털 통상협상에 적극적으로 대응하면서도 쟁점별로 각자 의 국익에 따라 다른 태도를 견지하고 있다. 우리나라의 경우 전자적 전송의 무관세 원칙, 국 경 간 데이터 이전 등과 개인정보, 데이터 보호 및 디지털 세와 관련하여 실제 무역협정에서는 아직 논의 중이다. 이러한 상황에서 기업들이 디지털 무역에서 새로운 비즈니스 기회 창출과 디지털 무역의 글로 벌 공급망에 안정적으로 참여할 수 있도록 미래지향적인 관점과 전략적으로 표준협력을 활용 하여 디지털 거버넌스 전략을 강화하는 방안을 모색하고 현재 선진국들 중심으로 재편되는 데이터 관련 제도, 나아가 디지털 무역 규범의 도입을 서둘러야 한다. 그리고 우리 기업들 또 한 글로벌 동향의 꾸준한 모니터링을 통해서 보다 유연하고, 실용적인 방안을 마련하는 것이 필요하다.
Purpose : In the 21st century, with the digitalization of goods and services, global trade is gradually expanding into digital trade that includes data trade, and data-based digital trade is expected to become a key element of competition between countries. As the interests of countries surrounding the establishment of global data governance are sharply diverging, the need for related data governance research is felt to vitalize digital trade. Research design, data, methodology : This study aims to analyze data governance related to digital trade by examining the issues of significant countries related to digital commerce and the formation of bilateral and multi-country international trade norms. Results : The results of examining digital trade policies and FTA regulations in the US, EU, China and other countries confirm that the provisions related to the duty-free principle of electronic transmission, cross-border data transfer, privacy and data protection, and digital tax issues are included in common. All major countries are actively responding to digital trade negotiations while maintaining different attitudes according to their national interests for each issue. In the case of Korea, while focusing on trade liberalization in the field of digital commerce, it is open to the duty-free principle of electronic transmission and cross-border data transfer. Conclusions : To summarize, this study seeks ways to strengthen digital governance strategies using a forward-looking perspective and strategically standard cooperation so that companies can create new business opportunities in digital trade and participate stably in the global supply chain of digital trade. The introduction of data-related systems reorganized centering on advanced countries, and furthermore, digital trade norms must be accelerated. And in the midst of the war to establish global data governance, including the United States, Europe and China, we are faced with the task of how to utilize and grow data in the future actively. it is necessary to do.
중국 개인정보 보호체계에 관한 연구 - 신(新)개인정보보호법의 주요내용 - KCI 등재
한중법학회 중국법연구 제45집 2021.03 pp.333-361
※ 기관로그인 시 무료 이용이 가능합니다.
6,900원
중국은 그동안 개인정보 보호를 통합적으로 다루는 일반법을 제정하지 않았 고, 개인정보 보호와 관련된 법률규정은 여러 법률에 분산되어 있었다. 이와 같은 상황에서 체계적인 입법을 추진해야 한다는 의견이 꾸준히 제기되어왔다. 중국의 상설입법기구인 전국인민대표대회 상무위원회는 2020년 10월 21일 「개 인정보보호법(초안)」을 공개하고 2020년 11월 19일까지 수렴된 의견에 관한 심의절차를 진행하고 있다. 총 8장, 70개 조항으로 구성된 「개인정보보호법(초 안)」은 개인정보 보호에 대한 전반적인 규율 내용을 담고 있는 일반법으로서 인공지능(AI)·빅데이터 기반의 4차 산업혁명 시대에서의 개인정보 보호에 역점 을 둠과 동시에, 데이터 경제의 건강한 발전을 추구하고 있다. 「개인정보보호법 (초안)」을 공개함에 따라, 2017년 6월 1일부터 시행하고 있는 「네트워크안전법」 과 2020년 7월 3일에 공개한 「데이터안전법(초안)」과 함께 체계적인 개인정보 보호 및 데이터 안전에 관련한 법체제를 구축해 나아갈 것으로 예상한다. 이와 함께 2021년 1월 1일부터 시행 중인 중국 최초의 「민법전」은 전통적 인격권인 ’생명권·성명권·초상권‘과 함께 ’프라이버시와 개인정보의 보호‘를 별도로 규 정하는 ’장(章)‘을 신설하였는바, 중국 내 개인정보의 보호와 관련한 커다란 변화 가 있을 것으로 전망된다. 2018년 5월 25일부터 시행 중인 「GDPR」의 주요 내용을 적극적으로 반영한 「개인정보보호법(초안)」은 국제적 수준의 선진화된 개인정보 보호 규정과의 정합성과 강화된 개인정보 보호 법체계 기반 위에 개인 정보의 활용을 촉진하여 데이터 경제 활성화에 이바지하기 위한 토대를 마련하 려는 것으로 풀이된다. 본고에서는 현재 중국 개인정보 보호 관련 법률 체계를 분석하고, 공개된 「개인정보보호법(초안)」 규정의 주요 특징을 「GDPR」과 같은 국제 기준의 개인정보 보호 규정과 비교해봄으로써, 향후 우리나라 개인정보 보호 법제에의 시사점과 기업이 유의해야 할 점을 도출하고자 한다.
China has not enacted a general law dealing with the protection of personal information in an integrated manner, law and regulation related to the protection of personal information were scattered across various laws. Under this circumstance, a variety of opinions have been constantly raised that systematic legislation related to the protection of personal information should be promoted. On October 21, 2020 the Standing Committee of the National People's Congress, a permanent legislative organization in China, published for public comment the first draft of the Personal Information Protection Law(hereinafter referred to as “draft PIPL”), and is undergoing deliberation procedures on opinions received until November 19. The draft PIPL, consisting of a total of 8 chapters and 70 articles, is a general law that contains the overall rules for the data privacy and protection of personal information. While focusing on personal information protection in the era of the 4th industrial revolution based on artificial intelligence and big data, it is pursuing the healthy development of the data economy. As the draft PIPL published, it is expected to establish a legal system related to systematic personal information protection and data safety along with the Cybersecurity Law went into effect on June 1, 2017, and a draft Data Security Law published on July 3, 2020. In addition, China's first Civil Code went into effect on January 1, 2021 established ‘a chapter’ that separately regulates ‘right of privacy and personal information protection’ along with ‘right of life, name, and portrait’, which are traditional personal rights. It is expected that there will be significant changes in the legal system of the protection of personal information in China. The draft PIPL, which actively reflects the main contents of the General Data Protection Regulation (EU) 2016/679(hereinafter referred to as “GDPR”) went into force on May 25, 2018, tried to match the international level of advanced personal information protection regulations. In addition, the draft PIPL intends to contribute to the vitalization of the data economy by promoting the use of personal information on the basis of a strengthened personal information protection legal system. In the article, we would like to analyze the current legal system related to personal information protection in China, and then by comparing the main features of the published provisions of the draft PIPL with the GDPR, which is the international level of advanced personal information protection regulation, we would also like to derive implications related to Korea‘s personal information protection legislation.
가명정보 Life-Cycle에 대한 위험 분석을 통한 관리적/기술적 보호조치 방안에 대한 연구 KCI 등재
한국융합보안학회 융합보안논문지 제20권 제5호 2020.12 pp.53-63
※ 기관로그인 시 무료 이용이 가능합니다.
4,200원
개인정보보호법 등 데이터 3법 개정에 따라 통계작성, 과학적 연구, 공익적 기록보존 등을 위해서는 정보주체의 동의 없이 가명정보 처리가 가능하며 개인정보와 달리 개인정보 유출통지 및 개인정보 파기 등의 법적용 예외조항을 두고 있다. 가명정보는 국가별로 가명처리에 대한 기준이 상이하며 국내에서도 개인정보 비식별 조치 가이드라인에 비식별조 치와 익명화를 동일시하고 있다는 점에서 개정이 필요하다 할 것이다. 본 논문에서는 4차 산업혁명에 따라 개인정보의 활용에 초점을 두고 새롭게 도입된 가명정보의 안전한 활용을 위해 가명정보의 개념을 살펴보고 국내외 비식별조치 기 준과 가명정보의 생성/이용/제공/파기 단계에서 법 또는 시행령(안)의 주요내용 검토를 통해 향후 추진되는 관리적/기술 적 보호조치 방안에 대한 제언을 하고자 한다.
In accordance with the revision of the Data 3 Act, such as the Personal Information Protection Act, it is possible to process pseudonym information without the consent of the information subject for statistical creation, scientific research, and preservation of public records, and unlike personal information, it is legal for personal information leakage notification and personal information destruction There are exceptions. It is necessary to revise the pseudonym information in that the standard for the pseudonym processing differs by country and the identification guidelines and anonymization are identified in the guidelines for non-identification of personal information in Korea. In this paper, we focus on the use of personal information in accordance with the 4th Industrial Revolution, examine the concept of pseudonym information for safe use of newly introduced pseudonym information, and generate / use / provide / destroy domestic and foreign non-identification measures standards and pseudonym information. At this stage, through the review of the main contents of the law or the enforcement ordinance (draft), I would like to make suggestions on future management / technical protection measures.
4차산업혁명 시대에 이르러 IoT 의료서비스, 유전자정보를 활용한 정밀의료, AI에 의한 질병의 치료 및 진단이 가능해지면서 각국은 세계 의료시장의 주도권을 확보하기 위하여 전략적으로 보건 의료빅데이터 구축에 앞장서고 있다. 이러한 세계적 흐름에 동참하기 위하여 최근 우리 보건복지부 역시 건강보험공단·심사평가원·질병관리본부·국립암센터로 산재 되어있는 의료데이터를 연계하는 보건의료 빅데이터 활용 플랫폼 시범사업을 시작하였다. 그러나 아직 갈 길은 멀기만 하다. 보건의료 빅데이터의 활용 범위, 방법, 절차, 정보보호 조치 등에 관하여 규정하는 구체적인 법적 근거가 부재 한데다가 규제 완화라는 시대적 흐름에 역행하는 각종 과잉규제가 보건의료 빅데이터의 활용을 어렵거나 불가능하게 하고 있기 때문이다. 또한, 야심차게 시작한 보건의료 빅데이터 활용 플랫폼 시범사업 역시 연구자로 하여금 연구에 필요한 최소 수준의 데이터를 요구할 수 있도록 하고 과도하다고 판단되는 경우 데이터의 제공 자체를 반려하도록 함으로써 데이터 의존도가 높은 AI 딥러닝 알고리즘의 개발에 기여하지 못하는 반쪽자리 빅데이터에 머물고 있다. 데이터 제공 목적 역시 “정책연구, 정보보호기술, 보건의료기술연구, 건강 관련 학술연구” 등으로만 제한되어 있는데 사실상 민간이나 산업적 차원의 보건의료 빅데이터 활용 가능성 자체가 원천적으로 봉쇄됨으로써 빅데이터 활용을 통하여 헬스케어 분야의 혁신을 이루고 있는 선진국과 우리나라 간의 격차는 점점 벌어지고 있는 상황이다. 본 논문은 보건의료 빅데이터를 둘러싼 법적 사회적 쟁점을 살펴보고, 보건의료 빅데이터 활용의 선두주자인 핀란드의 개인보호 법제, 건강 및 사회적 정보의 2차 사용에 관한 법률, 핀젠 프로젝트의 사례를 중심으로 검토, 개선방안을 도출함으로써 향후 우리나라의 보건의료 빅데이터 활성화 방안에 관하여 제언하고자 한다.
In the era of the Fourth Industrial Revolution, it is possible to treat and diagnose diseases by IoT medical services, precise medical care using genetic information, and AI. In order to lead the initiative of the global medical market, Countries are striving to build health and medical big data. Recently, the Ministry of Health and Welfare has also started a pilot project for the use of healthcare big data, which links medical data scattered in the Health Insurance Corporation, Review and Assessment Service, Disease Control Headquarters and National Cancer Center. However, there is still a long way to go. This is because there is no specific legal basis for defining the scope, method, procedure, and information protection measures of health care big data. Also, various over regulations that are contrary to the trend of deregulation make it difficult or impossible to use health care big data. In addition, the health care big data platform pilot project does not provide meaningful information for the formation of AI deep learning algorithms by allowing researchers only extremely limited information. The gap between advanced countries and Korea, which are innovating, is widening. This study examines the current state of health care big data use in Korea and its legal and social issues, and suggests the direction for us to move forward for the activation of health care big data by examining the case of Finnish private protection legislation, the second use of health and social information, and the Finzen project.
개인정보 자기결정권 강화를 위한 논의 : 서비스 사용 중 수집 정보에 대한 자기정보 접근권을 중심으로
한국경영정보학회 한국경영정보학회 정기 학술대회 ICBM 기반 비즈니스 트랜스포메이션 2019.05 pp.496-517
※ 기관로그인 시 무료 이용이 가능합니다.
5,800원
정보산업 발전과 개인정보 보호 강화의 세계적인 추세 속에서 EU 일반정보보호규정이 시행된데 이어 미국 캘리포니아에서는 소비자프라이버시법이 승인되어 시행을 앞두고 있고 세계 주요 기업들은 이에 발맞추어 적극적으로 대응해나가고 있다. 한편 한국에서는 수차례의 개인정보 유출 사건을 겪으며 개인정보 보호 규제가 강화되었고 그에 따라 기업의 정보 보호 수준도 상향되어 왔으나, 시대 흐름에 뒤쳐진 법규와 기업의 일방적 소통 방식으로 인해 개인의 자기정보 접근권이 적절히 보장되지 못하였고 이에 따라 개인정보의 자기결정권 보장도 부족하다. 특히 빅데이터 산업 발전에 힘입어 다양하게 활용되고 있는 ‘서비스 이용 중 수집정보’는 국내의 많은 기업들이 이미 그 수집과 활용을 시작하였음에도 국내법상에 그 내용이 반영되어 있지 않고 기업의 수집 정보 열람에 관한 안내도 미비하여 정보 접근권이 제대로 보장되지 못하고 있다. 반면에 해외에서는 GDPR과 CCPA에서 해당 정보의 유형을 명확히 정의하고 있고, 법 적용 대상인 다국적기업들은 웹/앱 상에 정보 열람 기능을 마련하는 등 적극적으로 정보 접근권을 보장하고 있다. 따라서 향후 국내법의 개정과 기업의 권리 보장 강화 조치에 있어서 이러한 사례들을 참고해 볼 수 있을 것이다.
온라인 트래킹에서 소비자 보호 관련 EU, 미국, 한국의 법제도 비교 고찰 KCI 등재
한국소비자정책교육학회 소비자정책교육연구 제14권 2호 2018.06 pp.75-103
※ 기관로그인 시 무료 이용이 가능합니다.
6,900원
본 연구는 온라인 트래킹과 관련하여 소비자를 보호할 수 있는 방안을 모색해보고자 소비자 관점에서 EU, 미국, 한국에서 이루어지고 있는 최근 법제도 논의를 고찰하고 비교 분석하였다. EU는 입법을 통해 온라인 트래킹으로부터 소비자의 개인정보를 보호하기 위한 노력을 하고 있어 주요 법률인 ‘개인정보보호 일반규정(General Data Protection Regulation ; GDPR)’과 ‘ePrivacy Regulation(안)’을 살펴보았다. 미국의 경우 포괄적인개인정보보호법을 제정하지 않고 소비자 프라이버시와 관련된 업무를 FTC가 담당하고 있어 FTC가 발표한 다양한 보고서들을 중심으로 법제도를 살펴보았다. 한국은 ‘정보통신망 이용촉진 및 정보보호 등에 관한 법률’, ‘개인정보보호법’ 에 근거하여 온라인 트래킹과 관련된 논의가 이루어지고 있어 위의 두 가지 법제도를 중심으로 살펴보았다. EU와 미국의 경우 온라인 트래킹에 대한 소비자 선호를 반영한 실질적인 동의와 소비자 친화적인 통제방안을마련하는데 초점을 두고 있고, 제품과 서비스의 개발부터 전 단계에 걸쳐 소비자의 개인정보를 보호하도록 기업의 의무를 강화시키고 있다. 반면 한국은 온라인 트래킹으로부터 소비자를 보호하기 위한 실질적인 통제방안이부족하고 정부 주도의 형식적인 자율규제가 이루어지고 있는 실정이다. 비교 고찰을 통해 본 연구에서 도출한 법제도 개선방안은 다음과 같다. 첫째, 온라인 트래킹과 관련하여 개인정보 범위 한정에 대한 접근보다 소비자 보호를 위한 복합적인 접근으로의 전환이 필요하다. 둘째, 빠르게 진화하는 온라인 트래킹 환경에서 소비자의 선호를 반영할 수 있는 실질적인 동의 방안과 소비자가 쉽고 편리하게 통제할 수 있는 방안 마련이 요구된다. 셋째, 기업주도의 자율규제에 대한 유인을 제공하고, 자율규제를 강화할 수있는 행동강령 마련이 요구된다. 마지막으로 온라인 트래킹으로 인한 피해가 발생한 경우 이를 엄격히 제재하고적절한 조치를 행할 수 있도록 구체적인 관리․감독 방안에 대한 논의가 요구되며, 실질적으로 온라인 트래킹으로부터 소비자를 보호할 수 있는 안전망 마련이 필요하다.
The purpose of this study is to examine how to protect consumers in relation to online tracking. In this paper, we review and discuss the recent legislative debates in the EU(‘General Data Protection Regulation; GDPR’ and ‘ePrivacy Regulation(proposal)’), the United States(a variety of reports published by the FTC, which is responsible for consumer privacy protection) and South Korea(‘personal information protection Act’ and ‘Act of Promotion of information and Communications Network Utilization and Information Protection, Etc’) from a consumer perspective. The Europe and the United States have begun to actively discuss guidelines and legislation from the consumer’s point of view on how to protect consumers from online tracking. They have attempted to give consumer-friendly control over their own privacy, which reflects their preferences so that can agree to and control their own privacy. In addition, it is strengthening the company's duty to design by privacy with emphasis on protecting consumers' personal information. In Korea, on the other hand, the problem is that consumers’ consent and controls are not effective and government guidelines are being developed. As a result, the following implications were derived. First, it is necessary to call for a complex approach to consumer protection, rather than approach to limiting the scope of personal information related to online tracking. Second, it is essential to consider how to strengthen consumer’s control mechanisms and practical agreement measures that reflects the consumers’ preferences. Third, new methods are needed to strengthen self– regulation and the government and consumers should provide incentives to strengthen self-regulation. Finally, it is necessary to discuss the establishment of a effective safety net for consumer protection and supervision system that can strictly prohibit misuse of online tracking and take appropriate measures when there is damage such as consumer privacy violations from online tracking.
유럽에서의 잊힐 권리의 전개와 한국에서의 법제 제도화의 방안 KCI 등재
유럽헌법학회 유럽헌법연구 제25호 2017.12 pp.53-78
※ 기관로그인 시 무료 이용이 가능합니다.
6,400원
인터넷상의 검색엔진의 발달은 과거의 사건이나 여러 곳에 흩어져 있던 정보를 쉽게 한 곳에서 찾을 수 있게 해 주었지만, 반대로 잊고 싶은 기억이 있는 정보까지도 쉽게 찾아주게 되었다. 이렇게 잊고 싶은 기억이 있는 정보를 삭제할 수 있는 권리가 바로 잊힐 권리이다. 잊힐 권리는 유럽사법재판소의 곤잘레스 판결(Gonzales judgment) 이후에 활발한 연구가 진행되었고, 한국에서의 도입에 대한 논의도 계속되고 있다. 하지만 잊힐 권리가 어디까지 삭제를 할 수 있는지에 대해서는 아직 명확히 정립되지 않아, 넓은 범위를 가지고 있는 것으로 판단된다. 잊힐 권리가 처음 인정된 곤잘레스 판결과 잊힐 권리를 처음 법규로 정립한 유럽연합 개인정보보호 일반규정(General Data Protection Regulation)의 정립과정을 종합해 보면, 잊힐 권리는 넓은 의미의 잊고 싶은 정보의 삭제로 보기보다는 검색엔진서비스에서 검색되지 않은 권리로 보는 것이 타당하다고 판단된다. 생각건대 잊힐 권리에 대한 유럽에서의 사례를 살펴보면 정보의 원본을 가지고 있는 정보처리자(controller)에 대한 직접적인 삭제는 언론의 자유의 손을 들어주어 불가능 하다고 판단되고, 단지, 검색엔진에서 검색되지 않도록 하는 권리만을 인정해 준 것으로 볼 수 있다. 즉, 잊힐 권리에 대한 문제가 발생된 이유는 검색엔진의 발달과 매우 밀접한 관련이 있다고 볼 수 있다. 이에 연구자는 잊힐 권리가 검색엔진에서 검색되는 링크의 삭제권으로 봐야 한다고 판단된다. 잊힐 권리를 링크 삭제권으로 봐야 한다는 입장에서 한국의 잊힐 권리 관련 법제의 제도화 방안을 마련하고자 한다.
The development of search engines in the internet has made it convenient to find the past and scattered information but on the other hand, it is also possible to find information that is not desired to be remembered. As such, the right to delete information containing memories that people want to forget, is called the “right to be forgotten”. There have been active researches on the right to be forgotten after the Gonzales judgment by Court of Justice of the European Union and its introduction is being discussed in Korea as well. However, there is no clear consensus on how far the information could be deleted thus the right to be forgotten has a wide range of definition. The aspects of Gonzales judgment when the right to be forgotten was recognized for the first time, and the General Data Protection Regulation by EU, that established the right to be forgotten as legislation, it is more reasonable to narrow down the definition of the right to be forgotten as the ‘right to be not searched by the search engines’ rather than ‘right to delete information that wants to be forgotten’. Previous European cases concerning the right to be forgotten have not accepted to directly delete the information controller, that contains the original information, due to freedom of speech but they have recognized the right to be not searched by the search engines. That is, the it is presumed that the reason for issue raising on the right to be forgotten is closely related to the roles of search engines. Therefore, I concluded that the right to be forgotten should be considered as the right to delete the link searched at the search engines. In this sense, this research intends to define the right to be forgotten and propose measures for legal institutionalization in Korea.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.