년 - 년
한국정보통신설비학회 한국정보통신설비학회 학술대회 2013년도 정보통신설비 학술대회 2013.08 pp.255-258
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
컴퓨터의 개발과 통신(유선통신부터 유선통신까지)기술의 발전으로 인해 인간의 자료 습득, 저장, 처리 방법은 획기적으로 발전되어져 왔다. 컴퓨터 유선통신을 시작으로 발전된 기술은 개인용 휴대장치를 통화 무선통신으로 까지 발전되어지고 있다. 그중에서도 최근 음성 통화와 컴퓨터상의 많은 응용을 가능하게 하는 스마트폰이 개발되었으며 이제는 남 녀노소를 불문하고 스마트폰 사용자가 아니라면 문맹 에 가까운 취급을 받는다. 아직 상품으로 출시가 되지는 않았지만 구글 글라스는 강력한 검색 기능을 가진 착용형 스마트폰 형태로 구분 지을 수 있다. 하지만 스마트 기기의 보급에 따라 생성되는 프라이버시 또는 개인정 보의 보호라는 하찮게 느끼지만 매우 큰 영향력을 갖 는 관점에 대해 크게 다루어지는 않는 경향이 있다. 본 연구에서는 구글 글라스 체험 버전을 기준으로 프라이버시 침해요인을 예측해 보고 그에 대한 기술적, 관리적 방안을 모색한다.
Development of Personal Information Protection Model using a Mobile Agent
[Kisti 연계] 한국정보처리학회 Journal of information processing systems Vol.6 No.2 2010 pp.185-196
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper proposes a personal information protection model that allows a user to regulate his or her own personal information and privacy protection policies to receive services provided by a service provider without having to reveal personal information in a way that the user is opposed to. When the user needs to receive a service that requires personal information, the user will only reveal personal information that they find acceptable and for uses that they agree with. Users receive desired services from the service provider only when there is agreement between the user's and the service provider's security policies. Moreover, the proposed model utilizes a mobile agent that is transmitted from the user's personal space, providing the user with complete control over their privacy protection. In addition, the mobile agent is itself a self-destructing program that eliminates the possibility of personal information being leaked. The mobile agent described in this paper allows users to truly control access to their personal information.
한국경영정보학회 Asia Pacific Journal of Information Systems 제35권 제2호 2025.06 pp.459-486
※ 기관로그인 시 무료 이용이 가능합니다.
6,700원
With the growing adoption of electronic financial payment services across both wired and wireless environments, the importance of managing personal information in FinTech has become increasingly critical. Incidents such as hacking and phishing within the FinTech ecosystem have caused significant harm to users, making personal information protection a paramount concern. This study presents a research framework based on Protection Motivation Theory (PMT) to analyze the psychological responses of FinTech payment services users. Specifically, it examines the impact how prior experiences of privacy invasion influence users’ emotional concerns (i.e., threat appraisals), perceived security (i.e., coping appraisals), and compliance intentions regarding personal information protection. Data were collected through an online survey of FinTech users with relevant experience. The empirical results show that privacy invasion experiences increase emotional concerns and reduce perceived security, although they do not affect FinTech-related knowledge. Additionally, while FinTech knowledge does not influence emotional concerns, it has a positive effect on perceived security and compliance intentions. Perceived security was found to alleviate emotional concerns and enhance compliance intentions. These findings provide valuable insights for FinTech services providers seeking to strengthen user behavior concerning personal information protection.
Personal Information Protection Crisis Management in Big Data KCI 등재
위기관리 이론과 실천 한국위기관리논집 제17권 제11호 2021.11 pp.95-108
※ 기관로그인 시 무료 이용이 가능합니다.
4,600원
ICT의 비약적인 발달로 인하여 4차 산업시대의 총아인 빅데이터 시대가 도래하였지만 개인정보보 호법상 개인정보수집최소의 원칙과 일치되지 않는 빅데이터 수집과 생성 및 활용의 최대의 시대적 요청과 상충되지만 산업의 발전과 개인의 정보보호를 위하여 조화할 필요가 있다. 첫째, 정보주체에 관한 개인 정보 보호 면에서 빅데이터 산업의 효율과 경영을 저해하지 않는 범위에서 빅데이터에서 의 개인정보에 관한 자기정보통제권을 최대한 보장하여야 한다. 둘째, 정보처리자의 관련된 개인정 보보호에서 정보주체의 동의를 필요로 하지만 정보처리자의 일방적인 결정에 좌우되며 새로운 프라 이버시 침해가 제기된다. 개정 개인정보보호법은 빅데이터에서의 개인정보의 보호를 위하여 익명 내지 가명정보처리규정을 신설하여 빅데이터수집⋅생성과 개인정보보호의 조화를 모색하고 있으 나 개인정보보호법상 공익적 목적이 아닌 이의 적용여부가 명확하지 않다. 셋째, 빅데이터의 조작가 능성은 존재한다. 빅데이터가 자신의 의도대로 유도하기 위하여 사용되는 경우 관련된 이해당사자 들에게 심각한 폐해를 초래한다. 현행 통계법상 규정이외의 빅데이터를 조작하는 경우 이를 금지 규정이 없다는 점에서 이의 규제가 요구된다.
Due to rapidly-rising development of ICT the era of Big Data comes in modern lives and Big Data are deeply located at our everyday lives. Personal informations are integrated, used widely at the many aspects including public and private sectors. Big Data including personal informations in itself become giant industries in modern business nowadays. Big Data that personal informations have been integrated may cause serious infringements of personal informations. According to Personal Information Protection Act in the cases one collects or uses personal informations one has to obtain consent by concerned party of personal information. But it is not easy to obtain consent that is necessary to collect and use Big Data creating massively and automatically by ICT instruments. In the aspect of management of Big Data, to protect personal informations throughly, pseudonymisation, anonymisation of personal information have to be permitted in the Big Data collections and uses. And possibility of fake manipulation about Big Data may always exists.
Applications of Medical Big Data and Personal Information Protection KCI 등재
원광대학교 법학연구소 의생명과학과 법 제31권 2024.06 pp.233-262
현재의 정보사회라는 환경에서 의료빅데이터의 생성 및 활용은 모든 시민의 개인정보보호와 직결되며, 특히, 의료빅데이터의 활용은 개인정보보호와 밀접한 관련이 있다. 의료기술의 지속적인 발전과 함께 의료빅데이터의 활용은 점점 더 광범위해지고 있으며, 한편으로 의료빅데이터의 활용은 의료기술의 발전을 촉진 할 뿐만 아니라, 약물 개발, 의료 개인화 및 정밀 치료의 발전에 많은 기여를 하고 있다. 한편, 의료빅데이터는 국민의 개인정보보호의 중요한 부분인 개인정 보와 관련이 있으며, 실제로 현행법 상 의료빅데이터의 활용과 개개인의 정보이 익 보호 간에 법적 모순이 없다고 할 수 없다. 의료빅데이터의 관점에서 국민의 개인정보, 의료건강정보, 의료빅데이터 정보의 범위가 교차하는 부분이 있음에 도 법률규정이 다른 부분이 있다. 또한, 현행법 상 개인정보의 제공 과정에서 정보의 사용 등에 대해 ‘고지-동 의’의 규정에만 의존하는 것은 개인정보를 종합적으로 보호할 수 없으며, 의료 빅데이터의 활용과 발전을 보장하기 어렵다. 이에 본 연구에서는 중국의 의료빅 데이터와 관련한 개인정보보호 문제를 분석하고, 현행법상 구체적으로 발생하는 문제들을 지적하고, 그 해결방안을 제시한다. 이를 통해 의료데이터 개방의 합 법화 추진에 입법근거를 마련할 수 있는 토대가 될 것이라 본다.
In the current social environment, the generation and application of medical big data is closely related to the personal information security of every citizen. With the continuous development of medical technology, the application of medical big data has become increasingly widespread. On one hand, it can promote the development of medical technology, including drug development, personalized medicine, and precision treatment. On the other hand, medical big data also concerns the private information of citizens, which is a crucial part of personal information protection. However, in practice, there often exists a contradiction between medical big data and the protection of citizens' personal information rights. From the perspective of medical big data, there are overlaps and differences among citizens' personal information, privacy information, medical health information, and medical big data information. Relying solely on the “informed consent” rule for personal information cannot effectively protect personal information comprehensively or guarantee the application and development of medical big data. This article analyzes the issues surrounding Chinese medical big data in terms of personal information from a legal perspective, and proposes corresponding solutions to these issues. It is hoped that this research can contribute to advancing the legalization of medical data openness, re-examining patients' personal information in the context of medical big data, and balancing the conflicts between individual privacy interests, public interests, and economic benefits of medical data, thus better protecting individuals' personal information interests under social and private benefits.
在当前的社会环境下,医疗大数据的产生和应用,关系到每个公民的个人信息安 全,医疗大数据的应用与个人信息保护紧密相关。随着医疗技术的不断发展,医疗 大数据的应用越来越广泛,一方面,医疗大数据的应用能够推动医疗技术的发展, 促进药物开发、医疗个性化、精准治疗等方面的发展。另一方面,医疗大数据同时 也关系到公民个人隐私信息,是个人信息保护的重要组成部分,在实践中,医疗大 数据与公民个人的信息权益保护方面往往存在矛盾。在医疗大数据的视角下,公民 个人信息、隐私信息、医疗健康信息、医疗大数据信息存在着范围的交叉和重叠, 相互之间又存在差别。单纯依靠个人信息的“知情-同意”规则,并不能很好地对个人 信息进行全方位的保护,也不能很好保障医疗大数据的应用和发展。本文从法律角 度分析中国医疗大数据在个人信息方面存在的问题,并针对这些问题提出来相对应 的解决措施,期望本文的研究能够对推动医疗数据开放的法制化程度向前发展起到 些许作用。以重新审视医疗大数据背景下的患者个人信息,平衡个体隐私利益、公 共利益以及医疗数据经济利益之间的冲突,从而在社会效益和私人效益之下更好的 保护个体的个人信息利益。
4,000원
공공정보화분야 유지관리 사업에서 개인정보의 고의 또는 관리 부재로 인한 유출 및 파괴, 변조 등 외부 불법사 용자의 공격이 증가되고 있다. 이러한 보안 사고를 사전에 예방하고자 SLA 지표를 개발하여 정량적으로 관리하는 것이 필요하다. 본 연구는 개인정보보호 SLA 지표를 개발하여 개인정보보호 SLA 지표 정보수집 방법, 시기 등의 구체적인 안을 제시하였다. 특히, 전문가 그룹을 중심으로 온라인 설문조사를 실시한 결과 개인정보 파기 준수율, 개인정보보호 시스템 접근통제 준수율의 경우 그 중요성과 타당성 측면에서 실제 공공정보화 사업에 SLA 신규 및 개정 시 적용하여 관리하는 것이 효과가 클 것이라는 의견을 받았다. 향후, 이러한 개인정보보호를 위한 SLA 지표를 공공정보화 유지관 리에 기준으로 활용함으로서 SW품질을 높이고 안전성 확보에 기여할 것이다.
In the field of public informatization maintenance business, the attacks of external illegal users such as unauthorized leakage, destruction, and alteration due to intentional or inadequate management of personal information are increasing. In order to prevent such security incidents in advance, it is necessary to develop and quantitatively manage SLA indicators. This study presents the privacy SLA indicators and suggests specific methods such as information collection method and timing of the privacy SLA indicators. In order to confirm the validity and reliability of the proposed SLA indicators, an online survey was conducted with a group of experts. As a result, it was evaluated that compliance rate of personal information destruction and compliance rate of personal information protection system would be effective when applied to new and revised SLA indicators in terms of importance and validity. In the future, using SLA indicators for personal information protection as a standard for public information maintenance will contribute to improving SW quality and securing safety.
생성형 인공지능 모델의 개인정보 라이프 사이클에 따른 국내 개인정보 보호법 개선 고려 요소 : GDPR과 개인정보 보호법의 비교·분석 KCI 등재
한국융합보안학회 융합보안논문지 제24권 제3호 2024.09 pp.81-93
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
본 논문은 기존에 개발된 개인정보 라이프 사이클 모델을 정리 및 분석 후 이러한 개인정보 라이프 사이클 모델이 인공지능 학습에 적용 가능한지를 살펴보았다. 검토 결과 기존의 개인정보 라이프 사이클은 인공지능 학습의 적용에 일 부 한계가 있음을 발견했다. 따라서 본 논문에서는 인공지능 학습에 적합한 개인정보 라이프 사이클을 제시했다. 새로 운 개인정보 라이프 사이클은 수집-학습-보유-생성·추론-차단·재학습·삭제 단계로 구성했다. 새로운 모델 제시에 따라 현행 개인정보 보호법 조항과 일치 여부를 검토 후 향후 법령 개정 방향을 제시했다. 본 논문은 인공지능 학습과 개인 정보 보호의 영역에서의 체계적 접근 가능성을 높였다는 측면에서 의의가 있다.
The purpose of this paper is to derive considerations when improving the Personal Information Protection Act ba sed on the personal information protection life cycle of the generative artificial intelligence model as generative artifi cial intelligence models are introduced and used in Korea a lot. Through the study, the necessity of using open infor mation in the collection stage, using personal information preservation technology in the learning stage, and preparin g the basis for the development of protection technology in the holding stage was derived. It also revealed the nece ssity of managing the generated information in the generation and inference stage, re-learning in the limitation and destruction stage, and preparing a filtering basis. It is expected that the results of this study can be used to revise the Personal Information Protection Act and make policies in the future.
대학생의 개인정보보호 인식이 정보보안 태도 미치는 영향연구 : 정보보안, 개인정보침해, 개인적 경험, 정보보안 의도 다중매개효과분석 KCI 등재
한국디지털정책학회 디지털융복합연구 제19권 제12호 2021.12 pp.125-132
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 대학생의 개인정보보호 인식이 정보보안 태도와의 관계에서 정보보안, 개인정보침해, 개인적 경험, 정보보안의도의 다중매개효과를 실증분석 하였다. 이를 위해 G대학교 221명을 대상으로 설문 조사를 하였다. 수집된 자료는 Process macro를 활용하여 매개효과를 실증분석 하였다. 본 연구결과 첫째, 개인정보보호와 정보보안 태도 사이에서 정보보안, 개인정보 침해, 정보보안 의식은 단순매개효과가 있었다. 둘째, 개인정보보호와 정보보안 태도 사이 에서 정보보안, 개인정보침해, 개인적 경험, 정보보안 의식이 병렬 다중매개효과가 있었다. 셋째, 개인정보보호와 정보보 안 태도 사이에서 개인정보침해와 정보보안 의식은 병렬 다중매개 상태에서 단순매개효과가 있었다. 넷째, 개인정보보 호와 정보보안 상태에서 정보보안은 단순매개효과가 있지만, 병렬 다중매개상태에서는 단순매개효과가 없는 것으로 나 타났다. 본 연구는 단순매개효과와 다중매개효과를 실증 비교하였으며, 매개변수를 다중으로 투입하여 연구의 다변화를 시도하였다는 의의가 있다.
This study analyzed the multi-mediating effects of information security, personal information infringement, personal experience, and information security intention in the relationship between personal information protection and information security attitude. For this purpose, a survey was conducted on 221 students from G University. First, information security, personal information infringement, and information security awareness had a simple mediating effect. Second, information security, personal information infringement, personal experience, and information security consciousness had parallel multi- mediation effects. Third, personal information infringement and information security awareness had a simple mediating effect in the parallel multiple mediation state. Fourth, information security had a simple mediating effect, but it was found that there was no simple mediating effect in the parallel multiple mediation state. This study is meaningful in that it empirically compared the simple and multi-mediation effects.
인공지능 서비스 제공과정에서의 개인정보관리 개선방안 - 개인정보 침해요소와 개인정보 보호요소 연계를 중심으로 - KCI 등재
한국사회안전범죄정보학회 한국범죄정보연구 제8권 제2호 통권 제16호 2022.12 pp.107-133
※ 기관로그인 시 무료 이용이 가능합니다.
6,600원
지능정보사회에서는 AI를 활용한 서비스의 수요가 증가하고 있으며, AI를 활용한 생활의 편리성 및 국가경쟁력의 향상이 이루어지고 있다. 그러나, AI서비스를 위한 다양한 데이터의 수집 및 결합과정에서 개인정보의 오남용 및 악용으로 인한 개인정보 침해사고가 발생하고 있다. 이에 따라 본 연구의 목적은 AI서비스제공과정에서의 개인정보 침해요소(3개 과정, 9개 단계 58개 요소)와 개인정보 보호요소(3개 과정, 9개 단계 27개 요소)를 도출하고, 상호 연계하여 개인정보보호를 위한 개선방안을 제시하고자 하였다. 이를 위해 각 요소에 대한 중요도는 관계 전문가 94명을 대상으로 한 설문조사 결과를 활용하였으 며, 두 요소의 각 과정에 대해서는 상관관계분석, 회귀분석, 경로분석 등을 통해 타당성을 검증하였다. 그 결과, 개인정보 침해요소와 개인정보 보호요소간의 상관성이 높았으며, 개인정보 침해요소가 우려될 경우 개인정보 보호요소를 적절히 활용하여 대응할 수 있도록 3개 과정 및 9개 단계를 연계하여 준수사항을 이행하여야 한다. 이처럼 개인정보 침해요소를 해소하기 위해 세부적인 관리방안을 마련한다면, 향후 개인정보보호를 위한 정책과제를 도출할 수 있도록 세부적인 방향을 제시할 수 있으리라 본다.
In the intelligent information society, the demand for AI services is increasing, and the convenience of life and improvement of national competitiveness due to AI are be improved. However, increases, However, in the process of collecting and combining various data for AI services, personal information infringement accidents are occurring due to misuse and abuse of personal information. Accordingly, the purpose of this study is to derive personal information infringement elements (3 processes, 9 steps, 58 elements) and personal information protection elements (3 processes, 9 steps, 27 elements) in the AI service provision process, In connection with each other, the study tried to suggest improvement measures for personal information protection. To this end, the importance of each factor was determined using the results of a survey of 94 related experts, and the validity of each process of the two factors was verified through correlation analysis, regression analysis, and path analysis. As a result, the correlation between the personal information infringement element and the personal information protection element was high, and if it is concerned about the personal information infringement element, the compliance matters must be implemented by linking the 3 process and 9 steps used and responded the personal information protection element. If detailed standards are prepared to resolve the elements of personal information infringement, it is expected that detailed management measures can be presented so that policy tasks for personal information protection can be derived in the future.
디지털시대의 개인정보보호 - 새로운 개인정보보호법을 중심으로 KCI 등재
한국디지털정책학회 디지털융복합연구 제9권 제6호 2011.12 pp.81-90
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
오늘날 인터넷을 통한 전자상거래의 확대추세에 따라 인터넷을 기업의 마케팅수단으로 활용하는 기업이 급속도로 증가하고 있으며, 소비자도 인터넷을 물품구매의 일상화된 생활수단으로 이용하고 있다. 즉, 인터넷을 통한 전자상거래는 시․공간적으로 접근성에 제한이 없다는 장점이 있어 일반 소비자들뿐만 아니라 불특정 다수가 인터넷을 통하여 물품을 구매하거나 거래하는 전자상거래가 본격화되고 있으며 그 내용도 광고, 계약, 대금결제, 클레임처리 등 거래행위 전반으로 확대되고 있는 것이 현실이다. 정보화시대에 정보통신기술의 발전으로 인한 개인정보 침해문제는 모든 국가가 직면하고 있는 가장 큰 문제 중의 하나이다. 따라서 개인정보보호법은 정보인권을 보호하는 기본적인 법률 중의 하나로써 개인정보보호법은 정보화시대에 없어서는 안 될 법률인 것이다. 그런 의미에서 새로운 개인정보보호법은 개인정보 유출로 인한 국민의 피해를 최소화하고 정보사회에서 개인정보자기결정권을 보호하기 위한 다양한 내용들을 담고 있는 진일보한 법이라 할 것이다. 이러한 법제정을 통하여 끊임없이 발생하는 개인정보 유출사고가 줄어들어 국민의 개인정보 보호수준이 월등히 높아지고, 개인정보 관련 산업발전에도 크게 기여할 것으로 전망된다. 그러나 합리적인 개인정보 이용 및 보호 문화의 정착을 위한 사회구성원 모두의 적극적인 참여와 인식개선이 선행되어야 할 것이다. 개인정보보호법의 목적이 개인정보의 수집․유출․오용․남용으로부터 사생활의 비밀 등을 보호함으로써 국민의 권익을 증진하고 개인의 존엄과 가치를 보호할 수 있지만, 사생활의 비밀보호와 정보의 자유로운 흐름을 조화하는 역할도 수행하여야 하기 때문이다.
Companies using internet as a kind of marketing means are increasing rapidly according to the expansion trend of e-commerce through internet and consumers also use internet as the common means of purchasing necessary articles. E-commerce using internet has advantages without limitation to temporal and spatial accessibility and general consumers and unspecified individuals also use internet to purchase their goods as well as general transactions such as advertisement, contract, payment and claim settlement. In the age of information, invasion of personal information resulted from the development of information and communication technology is one of the greatest problems all the countries in the world face. Therefore, Personal information protection Act is one of basic laws to protect personal information and rights and it is also an essential law in the age of information. In that sense, new Personal information protection Act is the advanced act containing various items to minimize the national damages from the leaking of private information and protect right to informational self-determination in the information society. It is expected that this legislation contributes to reduce the leaking of private information, enhance the level of privacy protection and develop privacy related industries. However, active participation of all members of our society and improvement of their recognition should be preceded for the rational and legal use of private information and the settlement of its protection culture. While the purpose of Personal information protection Act can protect privacy from collection, leaking, misuse and abuse of private information and enhance national interests and protect personal dignity and value, it also must perform the roles of balancing privacy protection with liberal information flow.
온라인에서의 아동의 개인정보보호에 관한 연구 - 미국 및 EU에서 아동의 개인정보보호동향을 중심으로 - KCI 등재
유럽헌법학회 유럽헌법연구 제13호 2013.06 pp.221-262
※ 기관로그인 시 무료 이용이 가능합니다.
8,800원
최근 미국 및 유럽연합에서는 온라인상의 아동 프라이버시의 보호에 관한 논의가 활발해지고 있다. 미국에서는 1998년 아동온라인프라이버시보호법(Children's Online Privacy Protection Act, COPPA)에 근거하여 연방통상위원회규칙의 개정제안이 검토되고 있고, 그 과정에서 ‘개인정보’의 범위 등의 COPPA의 개정상의 문제 외에 Safe Harbor Program의 실효성의 확보 등 규제의 합리화 및 실효성의 확보에 대해 논의되고 있다. EU에서는 2012년 1월 25일 유럽위원회에서 1995년의 데이터보호지침을 개정한 “일반데이터보호규칙안(General Data Protection Regulation)”이 공표되어, 당 규칙안에서 온라인상 아동의 프라이버시를 보호하기 위한 규정을 포함하고 있다. 아동이 각종 단말기를 통하여 쉽게 인터넷상의 서비스를 이용하는 요즘에 온라인상의 아동의 프라이버시보호가 중요한 것에는 이론은 없다. 특히, 최근에는 스마트폰으로 대표되는 모바일단말기가 급속하게 보급되고 인터넷상의 여러 서비스를 언제나, 누구나, 어디서나 이용할 수 있도록 되고 있어 생활을 보다 편리하게 하는 한편, 이러한 현상은 인터넷상에서 취득한 이용자의 개인정보를 포함한 다양한 정보가 점점 많아져가는 것을 의미한다. 이러한 상황에 비추어 최근에는 미국 및 EU에서 종래의 규칙을 정보통신기술의 발전을 근거로 재검토 및 온라인상의 아동 프라이버시 보호에 관한 새로운 규칙을 정하는 움직임이 있다. 먼저 주목해야 하는 것은 미국에서는 2010년 4월 이후, 1998년에 책정된 온라인상의 아동 프라이버시보호를 확보하기 위해 연방법에 근거하여 규칙이 개정되려고 하고 있는 것이다. 또한, EU에서는 2012년 1월 25일 유럽위원회에서 1995년에 책정된 데이터보호지령을 개정하고 가맹국에의 구속력이 보다 강하게 “규칙”으로 하는 새로운 개인정보보호의 구조가 공표되어, 그 안에 온라인상의 아동의 프라이버시보호를 확보하기 위한 규정이 포함되어 있다. 아동이 휴대전화등에서 쉽게 인터넷상의 서비스를 이용하는 것이 일반화된 현재, 판단능력이 불충분한 아동의 프라이버시보호가 중요하다는 것에는 국제적으로 이론은 거의 없으며, 2012년 2월에 OECD는 “온라인상의 아동의 보호에 관한 이사회권고”를 채택하고 정부에 대해서 프라이버시보호를 포함한 온라인상의 아동을 보호하는 정책을 정해야한다는 권고를 하였다. 우리나라에서는 2010년 1월 방송통신위원회가 「SNS 사업자ㆍ이용자 개인정보보호 수칙」을 발표하였다. 이는 SNS사업자 및 이용자에 대하여 개인정보보호를 위하여 각각 10가지 수칙으로 구성되어 있는데, 이 중에서 아동의 개인정보보호와 관련하여 SNS사업자에 대한 수칙에서는 “미성년자의 개인정보를 보호하기 위해 서비스 제한 등 적절한 보호수단을 마련하고 이행한다. SNS사업자는 개인정보보호에 대한 인식이 상대적으로 취약한 아동ㆍ청소년 등 미성년자를 보호하기 위해 미성년자의 서비스 이용범위 제한 및 아동의 서비스 가입 금지, 미성년자 전용의 서비스 제공 등 적절한 보호조치를 강구하여 시행하도록 한다”라고 되어 있다. 또한, 이용자에 대하여는 “미성년자인 자녀가 SNS를 이용하는 경우 SNS에 대해 충분히 이해시키고 무분별하게 자신이나 타인의 개인정보를 공개하지 않도록 지도해야 한다. 일부 사이트에서는 미성년자의 SNS 가입이 제한되어 있으므로 부모님(법정대리인 포함)과 선생님의 주의 깊은 감독이 필요하며, 아울러 성인들을 대상으로 하는 콘텐츠나 서비스에 자녀들이 노출되지 않도록 부모님의 지속적인 관심이 필요하다”라는 내용이다. 그러나, 외국에서는 아동의 개인정보보호를 위해 법률의 레벨에서 규정하고 있는것에 비하여 우리나라의 상기와 같은 지침에서의 규정을 강제성이 없고 실효성 또한 확보되지 못하고 있는 실정이다. 아동의 인터넷상의 서비스 이용은 앞으로도 높은 증가율을 보일 것으로 예상되므로 우리나라에서도 이러한 국제동향을 참조하여 아동ㆍ청소년에 대한 개인정보보호 수준에 대한 일관적인 법정책 및 이에 대한 지속적인 관리ㆍ감독이 가능한 정책이 나와야 할 것이며, 개인정보보호를 위한 정책적 대응 뿐만 아니라 인터넷 관련 기업에서도 자율적으로 이에 맞는 기업 나름의 자율규제의 룰을 가지는 것이 필요하다.
Recently the discussion on the protection of children’s privacy becomes active in U.S.A and European Union. In U.S.A, amendment proposal for the rules of Federal Trade Commission is being reviewed based on Children's Online Privacy Protection Act (COPPA) of 1998, and in the process, discussions are being made on the rationalization of the regulations and securing of effectiveness such as securing of effectiveness of safe harbor system, besides the matters of assessment by COPPA, such as the range of ‘personal information’. In EU, General Data Protection Regulation came forth on Jan. 25, 2012 by European Commission, which includes provisions to protect children’s online privacy, revising the Data Protection Guideline of 1995. It is unarguably important to protect children’s online privacy in these days when children use internet services quite easily. Recently mobile terminals represented by smart phone have come into wide use, and anyone may use a variety of internet services at any time and at any places. This makes our lives very convenient, whereas it means that a variety of information obtained on internet, including personal information of internet users, keeps increasing. Recently in U.S.A and EU, there are some movements to have a new understanding of the existing regulations according to the development of information and communication technology or to establish new regulations for protecting children’s online privacy. We should first pay attention to the plan in U.S.A to revise the rules established to protect children’s online privacy in 1998, based on federal laws, after April 2010. Furthermore in EU, European Commission published a new personal information protection structure on Jan. 25, 2012, amending the Data Protection Order established in 1995 into a “regulation” to strengthen the binding force to the member countries, which comprises provisions to secure children’s online privacy. It is not arguably important across the world to protect privacy of children, who lack the ability of perception, in these days when children may easily use internet services on mobile phones and other devices. In Feb. 2012, OECD adopted “a recommendation of the Council for protection of children online”, an gave an advice to the government to establish policies to protect children online including the protection of privacy. In our country, Korea Communications Commission announced 「Personal Information Protection Regulations to SNS service providersㆍ users」 in Jan. 2010. It consists of 10 regulations to each of SNS service providers and users, among which, following provisions are contained for protecting personal information of children and adolescents. The regulations to SNS service providers say, “Proper measures of protection, such as restriction of services, should be taken and implemented to protect personal information of minors. SNS service providers shall figure out and implement proper protection measures, such as restriction of service range for minors, prohibition of service subscription of children and provision of services for exclusive use of minors, to protect minors including children and adolescents, who have relatively low recognition of the importance of personal information protection.” And also, the regulations to users say, “Users should make their children of minors understood sufficiently on SNS in using the service and should guide them not to disclose the personal information of themselves and others thoughtlessly. As the subscription of SNS by minors is restricted on some sites, parents (including a legal representative) and teachers need to supervise them carefully, and in addition, parents need to constantly pay attention to prevent their children from being exposed to the contents or services for adults.” As it is expected that the use of internet service by children keeps increasing at high rate from now on, we need to establish consistent legal policy on the level of personal information protection for children and adolescents and constant control and supervision policy for it in our country, on reference to the international trend, and also, each internet service company needs to set up its own voluntary rules to keep pace with this trend, besides the political countermeasures for personal information protection.
농어촌지역 고령층의 개인정보 보호 실천에 미치는 영향 : 괸당문화와 개인정보 보호 교육 중심으로 KCI 등재후보
제주대학교 융합과학기술사회연구소 융합과학기술사회연구 제3권 1호 2024.06 pp.1-9
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 연구는 제주 고유의 공동체 문화인 괸당문화와 개인정보 보호 교육이 농어촌 지역 고령층의 개인정보 보호 실천에 미치는 영향을 규명하는 것을 목적으로 한다. 연구모형은 ‘괸당문화 - 개인정보 보호 교육 - 개인정보 보 호 실천’으로 설계되었으며, 서귀포시 A읍의 61세 이상 노인을 대상으로 조사하였다. 연구 결과, 괸당문화의 핵심 요소인 신뢰, 규범, 네트워크, 협력 수준이 높을수록 개인정보 보호 교육의 효과가 높아졌으며, 참여형 협동 교육 이 전통적 교육 방식보다 개인정보 보호 실천에 더 큰 영향을 미쳤다. 그러나, 괸당문화 단독으로는 개인정보 보 호 실천을 높이는 데 한계가 있는 것으로 나타났으며, 괸당문화와 개인정보 보호 교육이 함께 이루어질 때 개인 정보 보호 실천이 향상되는 긍정적인 효과가 있는 것으로 확인되었다. 본 연구는 지역 협력 공동체 문화를 활용 한 개인정보 보호 교육이 농어촌 지역 고령층의 개인정보 보호 인식과 실천을 효과적으로 향상시킬 수 있음을 밝 힌 데 의의가 있다.
This study investigates the impact of Jeju's Goendang culture and personal information protection education on the personal information protection practices of the elderly in rural areas. The model ‘Goendang culture - Personal information protection education - Personal information protection practices’ was analyzed with seniors in A-eup, Seogwipo City. The results show that higher levels of Goendang culture increase the effectiveness of personal information protection education, with participatory education being more effective than traditional methods. While Goendang culture alone has its limitations, combining it with education significantly enhances personal information protection practices. This study emphasizes that integrating communal culture into personal information protection education can effectively improve the personal information protection practices of the elderly in rural areas.
중국 개인정보 보호체계에 관한 연구 - 신(新)개인정보보호법의 주요내용 - KCI 등재
한중법학회 중국법연구 제45집 2021.03 pp.333-361
※ 기관로그인 시 무료 이용이 가능합니다.
6,900원
중국은 그동안 개인정보 보호를 통합적으로 다루는 일반법을 제정하지 않았 고, 개인정보 보호와 관련된 법률규정은 여러 법률에 분산되어 있었다. 이와 같은 상황에서 체계적인 입법을 추진해야 한다는 의견이 꾸준히 제기되어왔다. 중국의 상설입법기구인 전국인민대표대회 상무위원회는 2020년 10월 21일 「개 인정보보호법(초안)」을 공개하고 2020년 11월 19일까지 수렴된 의견에 관한 심의절차를 진행하고 있다. 총 8장, 70개 조항으로 구성된 「개인정보보호법(초 안)」은 개인정보 보호에 대한 전반적인 규율 내용을 담고 있는 일반법으로서 인공지능(AI)·빅데이터 기반의 4차 산업혁명 시대에서의 개인정보 보호에 역점 을 둠과 동시에, 데이터 경제의 건강한 발전을 추구하고 있다. 「개인정보보호법 (초안)」을 공개함에 따라, 2017년 6월 1일부터 시행하고 있는 「네트워크안전법」 과 2020년 7월 3일에 공개한 「데이터안전법(초안)」과 함께 체계적인 개인정보 보호 및 데이터 안전에 관련한 법체제를 구축해 나아갈 것으로 예상한다. 이와 함께 2021년 1월 1일부터 시행 중인 중국 최초의 「민법전」은 전통적 인격권인 ’생명권·성명권·초상권‘과 함께 ’프라이버시와 개인정보의 보호‘를 별도로 규 정하는 ’장(章)‘을 신설하였는바, 중국 내 개인정보의 보호와 관련한 커다란 변화 가 있을 것으로 전망된다. 2018년 5월 25일부터 시행 중인 「GDPR」의 주요 내용을 적극적으로 반영한 「개인정보보호법(초안)」은 국제적 수준의 선진화된 개인정보 보호 규정과의 정합성과 강화된 개인정보 보호 법체계 기반 위에 개인 정보의 활용을 촉진하여 데이터 경제 활성화에 이바지하기 위한 토대를 마련하 려는 것으로 풀이된다. 본고에서는 현재 중국 개인정보 보호 관련 법률 체계를 분석하고, 공개된 「개인정보보호법(초안)」 규정의 주요 특징을 「GDPR」과 같은 국제 기준의 개인정보 보호 규정과 비교해봄으로써, 향후 우리나라 개인정보 보호 법제에의 시사점과 기업이 유의해야 할 점을 도출하고자 한다.
China has not enacted a general law dealing with the protection of personal information in an integrated manner, law and regulation related to the protection of personal information were scattered across various laws. Under this circumstance, a variety of opinions have been constantly raised that systematic legislation related to the protection of personal information should be promoted. On October 21, 2020 the Standing Committee of the National People's Congress, a permanent legislative organization in China, published for public comment the first draft of the Personal Information Protection Law(hereinafter referred to as “draft PIPL”), and is undergoing deliberation procedures on opinions received until November 19. The draft PIPL, consisting of a total of 8 chapters and 70 articles, is a general law that contains the overall rules for the data privacy and protection of personal information. While focusing on personal information protection in the era of the 4th industrial revolution based on artificial intelligence and big data, it is pursuing the healthy development of the data economy. As the draft PIPL published, it is expected to establish a legal system related to systematic personal information protection and data safety along with the Cybersecurity Law went into effect on June 1, 2017, and a draft Data Security Law published on July 3, 2020. In addition, China's first Civil Code went into effect on January 1, 2021 established ‘a chapter’ that separately regulates ‘right of privacy and personal information protection’ along with ‘right of life, name, and portrait’, which are traditional personal rights. It is expected that there will be significant changes in the legal system of the protection of personal information in China. The draft PIPL, which actively reflects the main contents of the General Data Protection Regulation (EU) 2016/679(hereinafter referred to as “GDPR”) went into force on May 25, 2018, tried to match the international level of advanced personal information protection regulations. In addition, the draft PIPL intends to contribute to the vitalization of the data economy by promoting the use of personal information on the basis of a strengthened personal information protection legal system. In the article, we would like to analyze the current legal system related to personal information protection in China, and then by comparing the main features of the published provisions of the draft PIPL with the GDPR, which is the international level of advanced personal information protection regulation, we would also like to derive implications related to Korea‘s personal information protection legislation.
개정 개인정보보호법과 GDPR의 투명성원칙 및 동의절차에 관한 비교법적 연구 - 구글의 GDPR 위반 사건과 홈플러스 사건 비교를 중심으로 - KCI 등재 KCI 등재후보
원광대학교 법학연구소 원광법학 제36집 제4호 2020.12 pp.53-82
유럽연합은 2018. 5. 부터 개인정보보호법(GDPR; General Data Protection Regulation, 이하 ‘GDPR’)을 전면 시행하고 있다. GDPR이 제정된 직후 유럽의 개인정보보호단체 들은 글로벌 기업들에 대하여 GDPR을 위반을 근거로 각종 진정을 제기하였다. 이 중 주목할 만한 사건은 프랑스의 프라이버시 보호협회인 None Of Your Business(NOYB) 와 La Quadrature du Net이 프랑스의 정보와 자유에 관한 국가위원회인 CNIL(Commission nationale de l'informatique et des libertés)에 구글의 프라이버시 정 책과 개인맞춤형 광고 문제를 진정한 것이다. 2019. 1. 21. 경 CNIL은 구글이 개인정보보호원칙 중 투명성의 원칙과 개인 맞춤 형 광고 동의 절차를 위반하였음을 인정하여 5000만 유로(한화 약 642억원)의 과징 금을 부과하였다. 구글은 불복하여 항소하였으나, 프랑스 항소법원은 2020. 6. 20. 경 구글의 항소를 기각하였다. 개정 개인정보보호법을 입법하는 과정에서 가장 많이 논의된 규정은 유럽의 개인 정보보호법(GDPR; General Data Protection Regulation) 이다. 이 때문에 GDPR이 개 정 개인정보보호법에 주는 영향에 관한 연구는 활발하다. 그러나 실제 GDPR이 적용 된 결정문을 꼼꼼히 살펴 GDPR에서 말하는 개인정보처리원칙과 동의절차의 적법성 이 실제로 어떻게 적용되는지에 관한 연구는 찾기 어렵다. 본고는 이러한 문제의식을 토대로 CNIL이 2019. 1. 21. 구글에 과징금 5000만 유 로를 부과한 케이스를 집중적으로 분석하여 GDPR의 개인정보처리원칙 중 투명성의 원칙을 중심으로 개인정보를 수집할 때의 동의절차에 대한 판단의 기준을 밝히고자 한다. 이를 바탕으로 GDPR의 투명성 원칙 및 동의절차에 관한 기준이 개인정보보호 법의 법률해석에 어떻게 적용될 수 있는지 우리나라의 홈플러스 사건과 비교하여 살 핀다. 두 판결의 비교를 통하여 개정 개인정보보호법 시행 이후 투명성의 원칙 및 동의절차의 적법성을 확립하는 기준을 정립하고, 개인정보처리자가 정보주체에게 제 시하는 개인정보 수집 및 이용항목의 내용과 동의하는 방식이 투명성의 원칙에 입각 하여 이루어져야 함을 주장하고자 한다. 위 연구목적을 달성하기 위하여 던지는 연구 질문은 다음과 같다. 첫째, 개정 개인정보보호법은 GDPR의 개인정보보호원칙 중 투명성의 원칙과 어 떻게 상응하고 있는가? 둘째, 개정 개인정보보호법 및 GDPR의 개인정보처리의 동의절차는 적법성을 어 떻게 확보하는가? 셋째, 구글 GDPR 위반 과징금 사건와 홈플러스 사건의 비교가 우리에게 주는 시 사점은 무엇인가? 연구의 범위는 개정 데이터 3법 중 개정 개인정보보호법에 한정하였다. 개인정보 보호법이 우리나라 개인정보보호법제의 가장 중심이기도 하고, 개정 데이터 3법 중 정보통신망 이용촉진 및 정보보호 등에 관한 법률 중 일부는 개정 개인정보보호법에 흡수되는 방향으로 정립되었으며, 신용정보의 이용 및 보호에 관한 법률 또한 개인 정보보호에 관한 해석의 기준을 개인정보보호법에서 정하는 바에 따르기 때문이다 그리고 개인정보처리원칙 중에서도 개인정보보호법 제3조 제1항에 상응하는 GDPR 의 투명성의 원칙을 중점적으로 살핀다. 구글 GDPR 위반 케이스는 투명성의 원칙을 바탕으로 판단하였고, 비교 대상이 되는 홈플러스 사건 또한 투명성의 원칙을 적용 한 판시를 보여주고 있기 때문이다.
The European Union has enforced the General Data Protection Regulation (GDPR) from May 2018. After the GDPR was enacted, European privacy organizations have filed various complaints against global companies for violating the GDPR. Privacy protection associations such as None Of Your Business (NOYB) and La Quadrature du Net complained to Commission nationale de l'informatique et des libertés(CNIL) about Google's privacy policy and personalized advertising issues. In January 21, 2019, France’s data protection regulator, CNIL, has issued Google a 50 million euros fine for failing to comply with its GDPR obligations. Google has filed appeal to a higher court, but France’s top court has dismissed Google’s appeal on June 20, 2020. The most widely-discussed regulation in the process of enacting the revised privacy law is the European General Data Protection Regulation(GDPR). For this reason, research on the impact of the GDPR on the revised Personal Information Protection Act has been actively discussed. However, there is a little study on personal information processing and legality of consent procedures that are discussed in GDPR are applied in real cases. This paper focuses on analyzing CNIL imposing a penalty of 50million Euros on Google cases on January 21, 2019. With this study, the research will clarify the criteria for judgement on the procedure for privacy data collectiong consent based on GDPR’s transparency policy. Furthermore, by comparing the Google case with the legal case of Homeplus in Korea, it further examines a possible way that the GDPR's transparency principles and procedure for consent can be affected to legal interpretation of the Personal Information Protection Act. With this comparative study results, this paper will not only set the criteria for the principle of transparency and procedure for consent after the enforcement of the revised Personal Information Protection Act, but also argue that the data controller should collect and use personal information based on the principle of transparency. The research will focus on following research questions in below: First, how does the revised Personal Information Protection Act correspond to the GDPR's transparency principles? Second, how does the revised Personal Information Protection Act and GDPR's procedure for consent ensure the legality? Third, what are the implications of the comparison between the Google case and the legal case of Homeplus in Korea? The scope of the study was limited to the revised Personal Information Protection Act among the Three Data Acts. In addition, among the principles of personal information processing, the study focuses on the GDPR's transparency principles. This is because the Google case is judged based on the GDPR's transparency principles, and the legal case of Homeplus in Korea also shows a judgment that applies the transparency principles.
개인정보보호법제 관점에서 본 블록체인의 법적 쟁점 GDPR 및 국내 개인정보보호법을 바탕으로
한국정보기술응용학회 JITAM Vol.25 No.2 2018.06 pp.133-146
※ 기관로그인 시 무료 이용이 가능합니다.
4,600원
The technical definition of Blockchain is commonly known ‘distributed ledger’, however, there is no legal definition for being accepted in worldwide. Therefore, unless legal definitions and concepts of Blockchain are presented, there is a possibility that various legal disputes will occur in the future in Blockchain environment. The purpose of this study is to derive legal issues related to personal information protection that can be conflicted in Blockchain environment based on domestic Privacy Act and GDPR. The outcomes of this study can prevent various legal disputes and provide solutions that may occur due to the spread of Blockchain. It also suggests the foundation for the improvement of Privacy Act. Finally, it contributes to activate of Blockchain, industry, in Korea.
임상간호사의 개인정보보호 실천 영향요인: 개인정보보호법 지식, 옹호간호를 중심으로
[NRF 연계] 병원간호사회 임상간호연구 Vol.29 No.3 2023.12 pp.261-270
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
목적: 본 연구는 임상간호사의 개인정보보호법 지식, 옹호간호가 개인정보보호 실천에 미치는 영향을 파악하여 임상간호사의 환자 개인정보보호 실천도를 높이기 위한 기초자료를 제공하고자 시행되었다. 방법: 본 연구의 대상자는 상급종합병원과 종합병원의 병동에서 6개월 이상 근무하고 있는 140명의 임상간호사를 목표로 하였다. 2023년 2월 20일부터 3월 3일까지 설문을 진행하였으며, 최종적으로 130부의 설문지가 분석되었다. 결과: 본 연구 결과에서 임상간호사의 개인정보보호 실천에 영향을 미치는 요인은 옹호간호의 하위영역인 옹호자로서의 행동(β=.32, p=.004), 환경과 교육의 영향(β=.21, p=.040), 개인정보보호법 지식(β=.19, p=.013), 5년 이상 10년 미만의 총 임상경력(β=.17, p=.036)으로 나타났다. 본 회귀모형의 설명력 값은 34.0%로 확인되었다. 결론: 옹호간호의 하위영역 중 옹호자로서의 행동은 개인정보보호 실천에 가장 높은 영향을 미치는 것으로 나타났다. 임상간호사의 개인정보보호 실천을 높이기 위해 개인정보보호에 대한 교육과 옹호간호를 장려함이 필요하다.
Purpose: This study aimed to identify the influence of knowledge of personal information protection law andnursing patient advocacy on practice of personal information protection among nurses. Methods: The subjectswere 130 nurses who have worked for six months or more in the ward of the tertiary or general hospitals. Datawere collected from February 20 to March 3, 2023. Results: Factors influencing practice of personalinformation protection were acting as an advocate (β=.32, p=.004), environmental and educationalinfluences (β=.21, p=.040), knowledge of personal information protection law (β=.19, p=.013) and clinicalexperience for five years or more but less than ten years (β=.17, p=.036). The regression model showed anexplanatory power of 34.0%. Conclusion: Acting as an advocate has the most effect on practice of personalinformation protection. To promote practice of personal information protection for nurses, it is necessary toprovide education related to privacy protection and encourage nursing patient advocacy.
개인정보 오남용 예방을 위한 정보보호정책 개선에 관한 연구 : 금융회사의 개인정보 오남용 모니터링 결과 중심으로
[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.29 No.6 2019 pp.1437-1446
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
각종 개인정보 유출사고를 계기로 정부에서는 강화된 개인정보보호 대책을 시행하였고, 금융회사들은 정부 대책에 의거 개인정보 오남용 여부를 주기적으로 점검하는 등 노력을 기울이고 있지만 개인정보 오남용 문제는 여전히 개선되지 않고 있는 실정이다. 본 연구는 금융회사 직원을 대상으로 개인정보 오남용 모니터링 시스템을 이용한 현장실험 결과를 분석하여 오남용 문제 개선방안을 제시하고자 한다. 특별억제이론에 기반하여 오남용 행위자를 조치 하는 방법에 따른 오남용 방지 효과를 확인하고, 오남용 행위자들의 담당업무 및 근속연수와 오남용 행위 간의 관련성을 분석하였다. 분석결과를 바탕으로 제시하는 개선방안들이 실효성 있는 정책수립에 활용되기를 기대한다.
As a result of various personal information leakage incidents, the government implemented enhanced privacy protection measures, and financial companies are making efforts to periodically check whether personal information is misused according to government measures, but the problem of misuse of personal information is still not improved. The purpose of this study is to analyze the results of field experiments using the monitoring system for misuse of personal information and to suggest ways to improve the misuse problem. Based on the specific deterrence theory, this study examined the effects of misuse prevention according to the method of dealing with misusers, and analyzed the relationship between the duties of misusers and their years of service and misuse. It is expected that the analysis results of this study will be used for effective policy establishment.
메타버스 서비스에서의 개인정보 침해요인 도출 및 개인정보보호 개선방안 KCI 등재
한국사회안전범죄정보학회 한국범죄정보연구 제9권 제1호 통권 제17호 2023.06 pp.31-57
※ 기관로그인 시 무료 이용이 가능합니다.
6,600원
코로나19이후 전 세계가 비대면 서비스를 제공하는 메타버스 플랫폼에 관한 관심이 높아지고 있으며, 메타버스를 다양한 분야에 적용하여 관련분야의 산업 및 서비스를 성장시키고 있다. 그러나, 메타버스 플랫폼을 사용하는 이용자의 개인정보뿐만 아니라 가상인물의 개인정보까지 수집되면서 개인정보의 악 용, 위・변조, 훼손, 탈취 등과 같은 침해사고를 일으키고 있다. 따라서, 본 연구에서는 메타버스 플랫폼 및 가상생태계에서의 개인정보처리과정에서 발생할 수 있는 개인정보 침해요인을 도출하여, 개인정보보 호 개선방안으로 제시하고자 한다. 이를 위해 본 연구에서는 문헌연구를 중심으로 메타버스 서비스에서의 제도적 측면, 기술적 측면, 관리적 측면으로 구분하여 개인정보 침해요인을 도출하여 각 분야별 개인정보보호 개선방안을 제시하였 다. 먼저, 제도적 측면에서는 메타버스에서의 개인정보보호를 위한 정책 및 제도적 로드맵을 제안하였 다. 둘째, 기술적 측면에서는 메타버스에서의 보안요구사항, 보안수칙 등을 적용하고, 다중인증, 보안모델을 연결한 개인정보보호체계를 제안하였다. 셋째, 관리적 측면에서는 설계중심에서의 개인정보보호뿐 만 아니라 개인정보보호 점검기준 및 ISMS-P연계 관리체계를 정비하여야 한다고 제언하였다. 이러한 본 연구의 성과는 향후 메타버스 서비스에서의 개인정보보호 개선과제를 발굴하는데 필요한 연구기반이 될 것이다.
After COVID-19, the interest in the metaverse platform that provides non-face-to-face services is increasing around the world, and industries and services in related fields are growing by applying the metaverse to various fields. However, personal information of virtual characters, as well as personal information of users using the metaverse platform, are collected, and infringement accidents such as misuse, forgery, alteration, damage, and theft of personal information are occurring. Therefore, this study intended to derive personal information infringement factors that may occur in the process of personal information processing in the metaverse platform/virtual ecosystem and suggest measures to improve personal information protection. To this end, this study presented personal information protection improvement measures for each field by deriving personal information infringement factors by dividing them into institutional, technical, and managerial aspects in the metaverse service, focusing on literature research. First, in the institutional aspect, it was proposed a roadmap for policies and systems for personal information protection in the metaverse. Second, in the technical aspect, it was proposed a personal information protection system that applies security requirements and security rules and connects multiple authentication and security models in the metaverse. Third, in the managerial aspect, it should be established that not only personal information protection by design but also personal information protection inspection standards and a management system linked to ISMS-P. The results of the study will be the basis for research needed to suggest improvement tasks for personal information protection in the metaverse service in the future.
제4차 산업시대의 개인정보 관리수준 진단지표체계 개선방안 : 특정 IT기술연계 개인정보보호기준 적용을 중심으로 KCI 등재
중소기업융합학회 융합정보논문지(구 중소기업융합학회논문지) 제11권 제12호 2021.12 pp.1-13
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
개인정보보호위원회에서 공공기관을 대상으로 시행하고 있는 개인정보 관리수준 진단제도의 지표체계는 「개인정보 보호 법」의 법적 준수사항을 점검하지만, 새로운 IT기술의 도입에 따르는 개인정보보호사항을 기준으로 적용하는 데 한계가 있었다. 따라서, 본 연구에서는 제4차 산업혁명의 핵심기술인 빅데이터, 클라우드, 사물인터넷, 인공지능을 특정IT기술의 도입에 따라, 개인정보보호가 강화될 수 있도록 별도의 지표체계가 운영될 수 있도록 지표체계의 개선방안을 제안하고자 한다. 이를 위해서 선정한 특정IT기술의 개인정보보호사항에 관한 국내외 문헌조사를 통해 지표체계의 구성요소를 도출하고, 공공기관의 개인정보 보호담당자 대상으로 한 설문조사 및 개인정보보호 전문가대상으로 FGI/Delphi분석을 통해 진단지표로 선정하였다. 이렇게 선정한 지표체계는 먼저, 모든 특정IT기술의 기획 및 설계단계에서부터 개인정보보호원칙(PbD)과 가명정보처리 및 비식별 조치 에 관한 기준의 적용여부를 점검하는 공통지표를 선정하였다. 이외에 빅데이터에 관한 2개 점검항목, 클라우드에 관한 개인정보 처리방침 게재 사항 등 5개 점검항목, 사물인터넷관련 원칙적용, 로그기록 관리 등 5개 점검항목, 인공지능에 관한 원칙 적용 등 4개 점검항목을 선정하였다. 이처럼 본 연구는 개인정보 관리수준 진단제도의 발전을 위해 새로운 IT기술변화에 대응할 수 있도록 개인정보보호의 신속한 대응을 유도하는 진단제도가 되도록 제언하고자 하였다.
This study tried to suggest ways to improve the indicator system to strengthen the personal information protection. For this purpose, the components of indicator system are derived through domestic and foreign literature, and it was selected as main the diagnostic indicators through FGI/Delphi analysis for personal information protection experts and a survey for personal information protection officers of public institutions. As like this, this study was intended to derive an inspection standard that can be reflected as a separate index system for personal information protection, by classifying the specific IT technologies of the 4th industrial revolution, such as big data, cloud, Internet of Things, and artificial intelligence. As a result, from the planning and design stage of specific technologies, the check items for applying the PbD principle, pseudonymous information processing and de-identification measures were selected as 2 common indicators. And the checklists were consisted 2 items related Big data, 5 items related Cloud service, 5 items related IoT, and 4 items related AI. Accordingly, this study expects to be an institutional device to respond to new technological changes for the continuous development of the personal information management level diagnosis system in the future.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.