년 - 년
전자상거래 활성화에 따른 유럽의 개인정보보호에 관한 연구 - 유럽연합 개인정보 보호규정(GDPR)을 중심으로 - KCI 등재
부경대학교 인문사회과학연구소 인문사회과학연구 제26권 제1호 2025.02 pp.561-595
※ 기관로그인 시 무료 이용이 가능합니다.
7,800원
정보화 사회의 발전으로 인해 정보의 유통이 확산되고 전사상거래 산업이 급속히 확 대됨에 따라 소비자와 기업 간 대면 방식의 산업유통구조의 체계가 비대면 방식으로 빠 르게 전개되고 있다. 개인들의 일상생활도 빅데이터의 활용・클라우드 컴퓨팅・원격교 육・IT 기술 등 디지털 서비스에 의존되고 집중화되는 경향이 있으며, 소비성향도 변화하 여 시간적・공간적 제약이 비교적 덜한 전자상거래를 통한 거래가 활발해지고 있고 이러 한 추세는 자국의 산업만이 아니라 글로벌 시장을 통해 확산되는 추세이다. 이처럼 디지 털화된 산업 환경 하에서 기업들은 엄청난 양의 디지털 데이터를 수집・분석하여 기업 활 동을 위한 디지털 플랫폼을 구축하고 있고, 글로벌화 된 산업생태계 속에서 이런 정보들 의 국경 간 이동 역시 다양한 형태로 발생하고 있다. 이런 점에서 본 논문은 전자상거래 의 소비자 개인정보보호 현황의 관점에서 개인정보의 개념 및 의의를 살펴보고, 개인정 보보호를 위한 기술적 접근방법과 규범적 접근방법을 고찰하고 있다. 기술적 정보보호 방식으로 활용되고 있는 차등 개인정보보호 방식과 K-평균 클러스팅 알고리즘 방식으 로 기존의 익명화나 가명화 방식의 단점을 보완할 수는 있지만, 끊임없이 유통되고 수집 되는 개인정보의 활용에서 발생하는 문제점과 유통되는 정보 중에서 식별 가능한 개인 정보의 보호에는 일정한 한계가 존재한다. 그래서 각 국가들이 개인정보보호 규율을 위 한 규제방식을 강구하고 있으며, 특히 미국은 불공정하고 기만적인 기업의 관행 규제를 통해 부문별 개인정보보호 제도인 소극적 방식을 취하지만 유럽연합은 개인정보보호에 구체적 법적 권한을 부여하는 명령과 통제라는 일괄적 규제방식으로 개인정보보호를 시 행하고 있다. 이를 위해 포괄적 개인정보보호 규범인 GDPR을 시행으로 유럽연합 내 개 인의 데이터 수집에 관한 규정을 통합 및 강화하고 있고, 개인 데이터에 대한 완전한 통 제권을 부여하고 있다. 또한 데이터 처리, 투명성, 문서화 및 사용자 동의에 대한 절차를 명시하여 전자상거래 기업에 대한 통제와 개인정보의 역외이동에도 상당한 규제를 취하 고 규정 위반에 대한 일정한 제재의 부과로 기업에 상당한 장애물로 작용할 가능성이 있 어 경쟁우위 확보를 위한 주의가 요구된다.
As the use of personal information spreads and the e-commerce industry rapidly expands, the face-to-face industrial structure between consumers and companies is rapidly developing into a non-face-to-face system. In this digitalized industrial environment, companies are collecting and analyzing a huge amount of digital data of individuals to build digital platforms for business activities, and the cross-border movement of such information is also occurring in various forms in the globalized industrial environment. This paper examines the concept and meaning of personal information from the perspective of the current state of consumer privacy in e-commerce, and considers technical and normative approaches to protecting personal information. Although differential privacy and K-means clustering algorithm, which are used as technical information protection methods, can compensate for the shortcomings of anonymization and pseudonymization methods, there are certain limitations in the use of personal information that is constantly spread and collected, and in the protection of identifiable personal information among collected personal information. Therefore each country is establishing normative frameworks to regulate personal data protection, especially while the United States takes a passive approach by regulating unfair and deceptive business practices the European Union is enforcing personal data protection through a command-and-control approach that gives specific legal authority to personal data protection. The European Union has implemented the GDPR, a comprehensive data privacy regulation that unifies and strengthens the rules governing the collection of data from individuals in the EU gives individuals full control over their personal data. In addition, the GDPR specifies procedures for data processing, transparency, documentation, and user consent to control e-commerce companies, and the cross-border movement of personal data is also significantly regulated, and certain sanctions for non-compliance are likely to act as significant obstacles for e-commerce companies.
유럽연합 GDPR의 동의제도 분석 및 우리 개인정보보호법제에 주는 시사점 KCI 등재
아주대학교 법학연구소 아주법학 제13권 제3호 2019.11 pp.157-192
※ 기관로그인 시 무료 이용이 가능합니다.
7,900원
우리의 개인정보보호법제는 정보처리에 앞서 정보주체의 동의를 받아야 하는 사전 동의의 원칙에 따라 설계되었다. 아울러 사전동의를 받는 방식으로 수집·이용·제공 에 대한 포괄동의를 금지하고 각 동의사항을 분리해서 별도로 받도록 하는 동의방식 (‘개별적 동의방식’)과 처리목적에 필요한 최소정보만을 수집하게 하면서 최소정보 외 에는 ‘선택’으로 동의를 받도록 하는 동의방식(‘선택적 동의방식’)에 의하도록 하고 있 다. 이러한 강력한 동의체계는 오히려 정보주체를 제대로 보호하지 못하고, 동의를 형 식화하면서, 빅데이터 산업 등 관련 산업의 발전에 장애 요소가 되고 있다. 유럽연합(EU)의 「일반개인정보보호규칙」(GDPR; General Data Protection Regulation; 이하 ‘GDPR’)은 우리의 동의제도 개선에 있어서 여러 시사점을 제시한다. 우선, 정보 주체의 동의를 개인정보 처리의 6가지 합법성 요건 중 하나로 규정함으로써 정보주체 의 동의 없이도 데이터를 처리할 수 있는 길을 열어놓고 있다. 특히 정보처리자나 제공 을 받는 제3자의 ‘정당한 이익’을 위해서 데이터를 처리할 수 있다. 둘째로, GDPR은 처리 목적 중심의 동의를 받도록 하고 있다. 처리 목적이 변경되거나 추가되면 새로운 동의를 받아야 하지만, 그 외에는 규제가 없다. 우리와 같이 하나의 처리 목적을 위해 서도 모든 항목을 구분하여 받을 필요가 없으므로 보다 단순하고 명료한 동의서식을 제시하는 것이 가능하다. 셋째로, 정보처리자의 정당한 이익을 위하여 정보를 처리하 는 경우, 정보주체가 이에 대한 거부권(제21조)을 행사하면 정보처리자는 더이상 그 정보를 처리할 수 없다. 이를 사후거부권(opt-out)이라고 하는데, 정보처리자의 정당한 이익을 위하여 정보를 처리할 수 있는 가능성을 배제한 우리 법제 하에서는 사실상 이러한 옵트아웃 방식이 들어설 자리는 없다. 그러나 정보주체의 동의 이외에도 데이 터 처리가 가능한 다른 합법성 요건을 규정하게 될 때에는 이와 같은 사후거부권의 도입을 함께 고려해야 할 것이다. 넷째, GDPR에서는, 공공기관의 경우 원칙적으로 정 보주체의 동의에 근거한 데이터 처리를 할 수 없고 예외적인 경우에만 가능하다. 동의 가 유효하기 위한 4가지 요건 중 첫 번째, 자유로운 상태에서 이루어진 동의(freely given)의 요건을 충족하지 못한다고 보기 때문이다. 우리의 경우, 공공기관 역시 동의 제도를 만연히 이용하고 있는데, 이는 법률유보원칙과도 조화될 수 없다. 법제도적으 로나 관행적으로나 개선을 요한다. 다섯째, GDPR은 유효한 동의이기 위한 네 가지 요건과 특별히 명시적 동의가 요구되는 경우를 별도로 규정하고 있다. 우리 법제에는 이와 같은 규정이 없는데, 정보주체에게 불리한 상황에서 이루어진 동의도 유효한 동 의가 되거나 민감정보와 아닌 정보를 구분 없이 동일한 방식으로 동의를 받게 하므로 문제가 될 수 있다. 마지막으로, 유럽과 같이 가이드라인이 수범자에게 보다 확실한 지침이 될 수 있게끔 내용적인 면에서 충실한 개선이 필요하다. 나아가 동의제도의 수정은 개인정보자기결정권, 즉 개인정보보호권의 강화가 함께 수반되어야 한다. 정보주체에게 실질적이고 효과적인 통제권을 부여함으로써 개인정 보의 처리로 발생할 수 있는 실체적 권리가 침해될 위험을 예방하고 감소시켜나가는 것이 최종 목표가 되어야 할 것이다.
Data Protection Act in Korea was designed in accordance with the principle of prior consent(Opt-in), which requires consent of the data subject prior to data processing. In addition, the Act prescribes two things in a manner of consent, one is the consent method, which prohibits comprehensive consent on the processing of personal information and requires each to be consented to separately, and the other is the consent method, which allows the collection of only the minimum information required for processing purposes and provides an option of consent except for the minimum information. Such a strong system of consent has not adequately protected the data subject and has been a barrier to the development of related industries, such as big data industries, while formalizing consent. 「General Data Protection Regulation(GDPR)」 in European Union offers a number of implications for improving our consent system. First of all, by defining the consent of the data subject as one of the six legal requirements for the processing of personal data, data processing is possible without the consent of the data subject. In particular, data can be processed for the ‘legitimate interests’ of the data controller or third party receiving the data. Second, the GDPR requires consent for each processing purpose. If the purpose of the process is changed or added, new consent is required, but there are no other restrictions. It is possible to present a simple and clear consent form, because there is no need to separate consent for a purpose like us. Third, while data is processed for the legitimate interest of the data controller, the data controller can no longer process the data if the data subject exercises the right to object(Article 21). There is virtually no place for such an opt-out method under our legislation, which excludes the possibility of processing data for the legitimate interests of data controller. However, the introduction of the right to object should be considered also if other legal requirements for data processing are prescribed in addition to the consent of data subject. Fourth, in the GDPR, public authorities cannot, in principle, process data based on the consent of the data subject, but only in exceptional cases. This is because, among the four requirements for the consent to be valid, it is not considered to meet the first requirements of ‘freely given’. In our case, public authorities also mainly use the consent system, which cannot be harmonized with the rule of law. With the revision of the law, the practice should also be improved. Fifth, the GDPR specifies four requirements for valid consent and when explicit consent is required. There are no such provisions in our legislation, which can be problematic because consents made in circumstances that are disadvantageous to the data subject are either valid consent and consent is given to sensitive and non-sensitive data in the same way. Finally, like Europe Union, it is necessary to enrich the contents of the guidelines to help the data controller to understand the Act. Furthermore, the revision of the consent system should be accompanied by the enhancement of the right to the protection of personal data. The ultimate goal is to prevent and reduce the risk of infringing on the substantive rights that may arise from the processing of personal data, by giving the data subject substantial and effective control rights.
중국과 EU의 개인정보보호 규정 비교와 시사점 KCI 등재
중국지역학회 중국지역연구 제8권 제4호 통권21호 2021.11 pp.215-239
※ 기관로그인 시 무료 이용이 가능합니다.
6,300원
중국 개인정보 보호제도에 있어 기본법이라고 할 수 있는 개인정보보호법이 2021년 8월 20일 제13차 전인대 상무위원회에서 통과된 후 2021년 11월 1일부로 정식 시행된 다. 이법은 중국 민법전, 네트워크보안법, 데이터안전법 등 여러 법령에 산재되어 있는 개인정보보호와 관련된 내용을 통합하여 체계적으로 정리가 되었을 뿐만 아니라, 이들 법안을 중심으로 사이버 정보관리, 데이터 및 일반 개인정보 보호와 관련된 기본적인 법규체제가 완비되었다는 의미를 가지고 있다. EU의 신 개인정보보호법이이라고 할 수 있는 GDPR이 2018년 5월25일부로 정식 발 효가 되었다. GDPR과 비교하여 중국 개인정보보호법은 개인정보의 정의와 적용범위, 개인정보 처리 원칙, 개인정보 주체의 권리 보장, 개인정보처리 동의 및 철회 조항, 개인 정보의 국외이전, 신기술 응용 개인정보의 보호, 위반시 처벌 조항 등에 있어 대부분 유사한 면을 보이고 있지만, 민감 개인정보의 범위가 더 넓고, 공공안전 사건 발생시 사전 고지없이 개인정보 처리가 가능하다는 점, 법규 위반시의 제재 조항은 GDPR 대비 더욱 엄격하고 광범위하다는 차이점도 내포하고 있다. 4차 산업혁명 시대를 맞아 디지털 경제의 발전이 가속화되는 현재 개인정보 처리 및 이전관련 이슈가 앞으로 더욱 늘어날 것이기 때문에 우리 기업들로서는 사전 중국 개인정보보호법에 대한 이해와 대응노력이 필요하다.
The Personal Information Protection Law, which can be said to be the basic law of China's personal information protection system, was passed by the Standing Committee of the 13th Chinese National People's Congress on August 20, 2021, and will be officially entered into force on November 1, 2021. It has the significance that the China’s basic legal system related to cyber information, data management and protection of personal information has been completely organized by integrating the contents related to personal information protection scattered in various laws such as the Chinese Civil Code, the Network Security Law, the Information Safety Law, etc. EU's new version of personal information protection law, GDPR, came into effect formally starting from May 25, 2018. Compared to GDPR, China’s Personal Information Protection Law is mostly similar to the former in many respects such as definition and application of personal information, principles of personal information processing, guarantee of the rights of the subject of personal information, provision regarding consent and withdrawal of personal information processing, international transfer of personal information, protection of personal information through application of new technology, penalty provisions for violation, etc. The Chinese law, however, differs from EU in the following points: the scope of sensitive personal information is wider, personal information processing is possible without prior notice in case of public safety incidents, and sanctions for violation of laws are stricter and broader than GDPR. As the digital economy is accelerating in the era of the 4th industrial revolution, and the issues related to personal information processing and transfer are expected to increase in the future, Korean companies need efforts to understand and respond to the China's Personal Information Protection Law in advance.
세이프하버협정 무효판결 이후 EU 일반개인정보보호규정(GDPR)의 내용과 우리 개인정보보호법제상 시사점- 개인정보의 국외이전에 관한 비교법적 연구를 중심으로 -
[NRF 연계] 한양대학교 법학연구소 법학논총 Vol.36 No.1 2019.03 pp.211-249
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
EU사법재판소(Court of Justice of the EU, CJEU)는 2015년 10월 6일 막스 슈렘스 사건(Maximillian Schrems Case)에서 EU집행위원회가 미국과 체결한 세이프 하버(safe-harbor) 협정은 무효라고 판결을 내렸다. 이 판결 이후, 유럽위원회와 미국 상무부는 세이프하버협정에 갈음하여, 2016년 7월 12일 EU와 미국의 ‘개인정보보호 쉴드’(EU-US Privacy Shield) 협정을 새로 체결하고, 2016년 8월 1일부터 시행하고 있다. 또 유럽연합은 2016년 5월 24일 EU의 ‘일반개인정보보호규정’(GDPR)을 제정하였고, 2년 후 2018년 5월 25일부터 시행하고 있다(GDPR 제99조). EU역외에서 제3국으로 개인데이터를 이전하기 위하여 채택할 수 있는 선택지로서는 다음과 같이 6가지가 있다. 즉 ① 제3국의 적정성(adequacy) 결정, ②표준계약조항을 포함한 계약의 체결, ③ 구속적 기업규칙의 설정, ④인증제도(認證制度), ⑤행동규약, ⑥정보주체의 동의 등의 예외가 있다. 위 각 제도는 EU역내 개인정보주체의 데이터를 역외로 이전하는 경우 데이터와 함께 그 정보주체의 보호도 함께 이동하는 것을 확보하는 데에 주된 목적이 있다는 점을 염두에 두어야 한다. 이런 EU GDPR의 규정에 비추어 우리 개인정보보호법제에서도 동의 이외에도 개인정보를 국외이전하는 방식을 명문으로 입법화 할 필요가 있다. 요컨대 막스 슈렘스 사건 판결의 영향을 받은 EU GDPR의 내용 및 EU와 미국 사이의 개인정보보호 쉴드 협정 등에서 시사점을 도출하면, 우리의 개인정보보호법제상 관련규정이 오로지 사전 동의만에 의한 개인정보 국외이전을 합법화 하고 있어서 입법적 개선이 필요하다고 본다. 따라서 글로벌 수준의 개인정보 국외이전제도로서 실효성을 갖추기 위해서는 예외적 허용기준을 확대하여 입법화하는 방향으로 개선할 필요가 있다. 나아가 EU와 역외 제3국 정부 사이에 ‘적정성(adequacy) 결정’이 바로 EU의 GDPR에 대응하는 모든 문제를 해결하는 것은 아니다. 가까운 장래로 예견되지만 유럽위원회가 한국에 대해 개인정보보호의 적정성(adequacy) 결정을 하는 효과는 EEA내에서 한국으로의 개인데이터 이전만이 적법하게 될 뿐이다. 결국 유럽연합에서 비즈니스를 하는 한국기업 등은 역외이전 이외의 쟁점에 대해서도 GDPR에 여전히 대응할 필요가 있다.
The Max Schrems case led the Court of Justice of the European Union on October 6, 2015, to invalidate the Safe Harbor arrangement, which governed data transfers between the EU and the US. And replacing Safe Harbor arrangement, the ‘EU-US Privacy Shield’ agreement has applied from 1. August, 2016. Furthermore, The General Data Protection Regulation (GDPR) of the EU has enacted in 24. May, 2016, and It has applied since 25. May, 2018. There are six options that can be adopted to transfer personal data from outside the EU to third countries: (1) Acquisition of adequacy recognition of third countries, (2) Contracts including standard contract provisions(SCC), (3) formulation of binding corporate rules (BCR), (4) the approved certification mechanism, (5) the approved code of conduct, and (6) the consent of the data subject, etc. In this paper, it is suggested that our Personal Information Protection Act needs legislative improvement in order to expand the exceptional acceptance standards in order to be effective as the transfer system of personal information abroad. Because our Personal Information Protection Act concerning the transfer of personal information to foreign countries are regulated mainly on the transfer of personal information based on prior consent.
EU의 2016년 일반정보보호규칙(GDPR)의 제정과 그 시사점
[NRF 연계] 전남대학교 법학연구소 법학논총 Vol.36 No.3 2016.09 pp.411-453
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
2016년 5월에 EU 일반정보보호규칙(이하 ‘2016년 규칙’이라 한다.)이 제정되었다. 동 규칙은 EU의 개인정보보호법제에서 일반법적 지위를 누리던 1995년 정보보호지침을 대체하는 것으로서, 2012년 1월에 EU의 집행기관인 유럽위원회가 일반정보보호규칙(안)을 EU의 입법기관인 유럽의회와 이사회에 제출한 이래 4년여만에 성립된 것이다. 이러한 2016년 규칙의 제정배경으로는 1995년 지침이 그 목적과 원칙에 관한 한 여전히 유효하지만, 그 법형식이 ‘지침’이라는 점 때문에 동 지침이 가이드라인적인 역할을 한다고 하더라도 각 회원국별로 구체적인 개인정보보호법제도가 다르기 때문에 개인정보 보호에서의 EU 전체의 집행이라는 점에서는 단편화와 법적 불확실성이 존재하게 되었다는 점이 들어진다. 그로 인하여, 보다 강력하고 통일적인 EU개인정보보호제도를 시행할 필요가 있으며, 이에 의하여 EU역내시장에서 디지털경제가 발전할 수 있게 되고, 개인들은 자기의 개인정보를 통제할 수 있으며, 사업자들과 공적 기관들에게는 법적·실무적 확실성을 확보할 수 있게 된다는 것이다. 따라서, 본고에서는 이러한 EU의 2016년 규칙을 대상으로 하여, 그 제정경위를 살펴본 후(Ⅱ), 그 주요내용으로서 입법목적, 정보주체의 동의와 권리, 정보보호영향평가와 사전협의, 행동강령과 인증, 개인정보의 제3국이나 국제조직으로의 이전, 독립적 감독기관과 유럽정보보호위원회, 권리구제, 책임 및 벌칙, 특별한 정보처리상황과의 관련, 최종규정을 살펴보고(Ⅲ), 개인정보의 제3국으로의 이전과 관련한 EU사법재판소의 판례인 Maximillian Schrems Case를 고찰한 것(Ⅳ)을 토대로 하여, 우리에게 던져주는 시사점(Ⅴ)을 제시하였다.
EU has enacted its 2016 General Data Protection Regulation(GDPR) in May 2016 and 2016 GDPR replaced the 1995 Data Protection Directive. This article consists of 5 chapters. Chapter 1 is prelude, and chapter 2 is the enactment process of 2016 GDPR, and chapter 3 is the main contents of 2016 GDPR, which is as follows ; legislative objectives, consent and rights of the data subject, data protection impact assessment and prior consultation, codes of conduct and certification, transfers of personal data to third countries or international organisations, independent supervisory authorities and European Data Protection Board, remedies, liability and penalties, provisions relating to specific processing situations, and final provisions. Thereafter, it is treating the case related with transfers of personal data to third countries, which is cited as Maximillian Schrems Case. Lastly, this article is suggesting the implications on the basis of the research.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.