년 - 년
망분리 환경에서 민감정보를 안전하게 처리하기 위한 기술적 방안 KCI 등재
한국융합보안학회 융합보안논문지 제23권 제1호 2023.03 pp.125-137
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
공공기관을 필두로 민감정보를 취급하는 기업들은 사이버 공격 예방을 위하여 업무망과 인터넷망을 분리 구축하고, 강한 접근통제를 바탕으로 중요 데이터를 보호하고 있다. 그렇기에 업무망과 인터넷망이 연결되는 접점을 수반하는 시스템은 관리 적, 기술적으로 안전한 보안환경 구축이 필수적으로 요구되고 있다. 기관에서 사용하고자 하는 모바일 장치의 경우 기기를 통 제하기 위한 MDM(Mobile Device Management) 솔루션이 그 예라 할 수 있다. 이 시스템은 모바일 장치 정보, 사용자 정보 등의 민감정보를 인터넷망에서 취급하여 동작하므로 운영 시 각별한 보안대책이 요구된다. 본 연구에서 인터넷망에서 반드시 운영되어야 하는 시스템에서의 민감정보 데이터 처리를 내부망에서 관리할 수 있도록 모델을 제시하였으며, 이를 망연동 솔루 션을 기반으로 한 MDM 솔루션을 중심으로 기능 설계 및 구축하였다.
Companies that handle sensitive information, led by public institutions, establish separate networks for work and the Internet and protect important data through strong access control measures to prevent cyber attacks. Therefore, systems that involve the junction where the Intranet(internal LAN for work purposes only) and the Internet network are connected require the establishment of a safe security environment through both administrative and technical measures. Mobile Device Management(MDM) solutions to control mobile devices used by institutions are one such example. As this system operates by handling sensitive information such as mobile device information and user information on the Internet network, stringent security measures are required during operation. In this study, a model was proposed to manage sensitive information data processing in systems that must operate on the Internet network by managing it on the internal work network, and the function design and implementation were centered on an MDM solution based on a network interconnection solution.
[Kisti 연계] 한국디지털콘텐츠학회 디지털콘텐츠학회 논문지 Vol.9 No.1 2008 pp.7-15
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문은 사용자와의 대화를 통해 적합한 맛 집 정보를 제공하고, 사용자들에게 감성적으로 다가가는 프로그램인 감성형 모바일 정보 추천 에이전트에 관하여 기술하였다. 제안하는 에이전트는 단순히 음식점과 전화번호만을 소개하는 기존의 방식을 벗어나, 각각의 시간대에 적절한 질문 등을 함으로써 사용자와의 대화를 통한 흥미를 유발함과 동시에 현재의 상황에서 개개인에게 적합한 맛 집을 추천 해주는 프로그램이다. 사용자의 감성을 파악하기 위한 핵심 기술로, 불쾌지수와 감기지수를 측정하고 사용자의 바이오리듬을 계산하여 개개인에 적합한 맛 집을 추천한다. 뿐만 아니라 모바일 에이전트에 적합한 디자인을 제안하므로 에이전트를 더욱 효과적으로 설계하였다. 본 연구에서는 추천 서비스를 위한 모바일 환경과 데이타 관리를 위한 웹 환경을 사용한다. 서비스를 위한 서버환경은 Apache, PHP4, Mysql등을 사용하였으며, 모바일 페이지는 핸드폰의 접근을 위한 m-HTML로 구현되었다. 이때 모바일 서비스는 Mozilla-1.22, KUN-1.2.3 브라우저 버전에 최적화 하였다.
The paper proposes information system for providing proper well known delicious restaurants as interactions with users. The system calls 'Moloke', which is an agent for recommending sensitive information on mobile environment The proposing agent differs from existing ones that guide the telephone number and the name of the restaurant. The differences are as following goals. First, the agent gets existing from users as interactive communications on mobile devices through the proper requests on each time zone such as morning, afternoon, and evening. Second, the agent also can recommend a specific restaurant for current personal states such as parties, special community meetings, bio-rhythms and so on. Among them, specially the bio-rhythm is used for recommending proper restaurants to each user. In addition to through proposal suitable design for the mobile agent design more effectively. The research used mobile environment for recommendation service and web environment for data management. Server environment for service used Apache, PHP4, Mysql and mobile page was implemented m-html for approach. Mobile Service was optimized Mozilla-1.22, KUN-1.2.3 Browser
경찰용 웨어러블 기기 개발을 위한 생체정보 활용 방안 연구 KCI 등재
한국융합보안학회 융합보안논문지 제25권 제3호 2025.09 pp.153-160
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
디지털화 사회에서 웨어러블 기기에 기반한 빅데이터 정보는 개인화된 경험을 제공하고, 기업의 마케팅 효율을 높이는 하 나의 수단으로 활용되고 있다. 그러나, 그러한 과정에서 사용자의 프라이버시 침해에 대한 문제가 발생한다. 특히, 바이오 센 서에 기반한 디바이스의 사용자인 국내 소비자들은 바이오 정보의 형태사용에 관한 법률이 완벽하지 못하고, 상업적 시장에서 의 바이오 정보 사용도가 증가 가능성에 우려를 하고 있다. 이 연구의 목적은 디지털화가 가속화되는 사회에서 주요 구성원인 시민들의 민감정보 활용에 대한 문제점을 인식하고, 이러한 개인정보 침해 가능성이 상존하는 상황에서의 고찰 부분과 방안에 대해 살펴본다. 국내 디지털 산업의 현실을 고려할 때, 생체정보의 이용에 대해 정부의 최소한 개입이 조화를 이루어야 이용 자 권리를 보장하면서도 산업 혁신과 성장을 도모할 수 있을 것이다. 이 글에서는 범위를 경찰용 웨어러블 기기 개발에 대한 계획에 한정하여, 업무 밸런스를 위한 피로도 측정 바이오센서 디바이스의 기술 개발 사례를 중심으로 기술하였다.
In the digital city, big data based on wearable devices has emerged as a method for delivering personalized user experiences and enhancing marketing efficiency. But, there have been concerns about privacy violations from the user in process. Especially, consumer of devices with bio sensors have become increasingly concerned about possblility of enlargement usage its biometric information as there have been no suitable laws in Korea to apply behavioral information on commercial market. The purpose of this study is to research privacy problem of mining biomertic data for sensitive personal information of citizen in the digital city and to suggest solution. Concerning the practical realities of Korea’s digital circumstance a balanced approach with minimal government intervention may be necessary to safeguard user rights of biometric information while also fostering innovation and growth in the industry. This investigation puts focus on case study of development wearable device with biosensors for police. This study suggest that it is necessary a variety of strategies in order to improve the quality of working balance and to intervene in job stress and fatigue, eventually lead to enhancing working performance.
The Methodology of Security Management Cost Reduction using Security Level Lifecycle SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.7 No.3 2013.05 pp.205-214
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Security management cost for securing information is increasing rapidly, as increasing the use of electronic information. In this paper, we focused on the two respects. The one is security level lifecycle of the sensitive information (SI). The other is SI that has characteristics to decrease security level over time. We proposed the method that total security management cost reducing than before applying by differential costing over security level lifecycle. Also, we considered of predictability on security level decrease together. Last, we expressed the cost reduction target area through a comparison of the cost model.
The Sensitive Information Management System for Merger and Acquisition (M&A) Transactions SCOPUS
보안공학연구지원센터(IJMUE) International Journal of Multimedia and Ubiquitous Engineering Vol.9 No.3 2014.03 pp.203-212
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
In M&A transactions, there are many ‘data’ to be handled to complete any given transaction. There are personal and private data in nature to be transferred and examined during the due diligence process and completing the Representations and Warranties in the final contract. The due diligence sometimes requires “personal data” includes supplier and employee data. In most of the countries, data protection issues have long been neglected in merger and acquisition transactions. However, personal data in many forms can be accessed and may be disclosed even without the knowledge of the information owners. To solve the privacy issues in M&A transactions, we introduce a reliable system in M&A to support access protocol based on privacy policies. Our system helps to securely transfer from the target to the acquirer for any given M&A transaction.
Security Model for Sensitive Information Systems and Its Applications in Sensor Networks SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.9 No.5 2015.05 pp.1-18
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
The study of security models for sensitive information systems has been taken on for years, but still lag far away behind the progress of information security practice. During this century, the thought of seeking the system security to the source of system development lifecycle received huge improvement in the system and software assurance domain. This paper firstly expounds the understanding of information security by illustrating information security study development progress since pre-computer age and presents a description of cyberspace and cyberization security by summarizing the status quo of cyberization. Then a security model called PDRL, which includes six core security attributes of sensitive information systems, is proposed to protect the security of sensitive information systems in the whole system life-cycle. At last, this paper probes into further discussion about controllability attribute and proposes a controllability model in sensitive sensor networks, followed by a probability computing formula and the example for computing the controllability of sensitive sensor networks. By dividing each single element of sensitive information and each element-related operation into a corresponding classification, this paper makes a reasonable description of the quantitative description about controllability.
Secure Healthcare Management: Protecting Sensitive Information from Unauthorized Users
국제인공지능학회(구 한국인터넷방송통신학회) International Journal of Internet, Broadcasting and Communication Vol.13 No.1 2021.02 pp.82-89
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Recently, applications are increasing the importance of security for published documents. This paper deals with data-publishing where the publishers must state sensitive information that they need to protect. If a document containing such sensitive information is accidentally posted, users can use common-sense reasoning to infer unauthorized information. In recent studied of peer-to-peer databases, studies on the security of data of various unique groups are conducted. In this paper, we propose a security framework that fundamentally blocks user inference about sensitive information that may be leaked by XML constraints and prevents sensitive information from leaking from general user. The proposed framework protects sensitive information disclosed through encryption technology. Moreover, the proposed framework is query view security without any three types of XML constraints. As a result of the experiment, the proposed framework has mathematically proved a way to prevent leakage of user information through data inference more than the existing method.
원문정보공개 지원을 위한 민감정보 필터링 요건에 관한 연구 KCI 등재
한국기록관리학회 한국기록관리학회지 제17권 제1호 2017.02 pp.51-71
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
원문정보공개 서비스를 개시한 후 한해 천만 건에 가까운 전자 결재문서가 온라인을 통해 공개되고 있다. 하지만 대량의 전자결재문서를 정보공개 업무담당자가 모두 확인하여 원문정보공개 서비스를 수행하는 것은 현실적으로 불가능한 상황이다. 이에 따라 최근 일부 공공기관에서는 개인정보 필터링 도구를 활용하여 문서 생산단계에서 정형화된 개인정보를 필터링하고 있으나 비정형화된 민감정보는 관리되지 않고 있다. 본 연구에서는 원문정보공개 지원을 위해 사용 중인 필터링 도구 분석을 통해 필터링 도구의 고도화 방향을 설정하였으며, 필터링 도구 활용단계가 추가된 결재문서 본문 작성과 원문정보공개 프로세스를 재설계하였다.
Approximately 10 million electronic approval documents have been released online since the commencement of the original information disclosure service. However, it is practically impossible to carry out an original information disclosure service by confirming a large amount of electronic approval documents to all persons in charge of information disclosure. Recently, some public organizations have been using private information filtering tools to filter personal information at the stage of document production, but the management of different sensitive information has not been managed using solutions. In this study, we set up the advanced direction of the filtering tool by analyzing the filtering tool in use to support the original information disclosure, and redesigned the text of the approval document and the original information disclosure process with the use of the filtering tool.
[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.22 No.12 2017 pp.101-108
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The study proposed a system that filters the data that is entered when analyzing big data such as SNS and BLOG. Personal information includes impersonal personal information, but there is also personal information that distinguishes it from personal information, such as religious institution, personal feelings, thoughts, or beliefs. Define these personally identifiable information as sensitive information. In order to prevent this, Article 23 of the Privacy Act has clauses on the collection and utilization of the information. The proposed system structure is divided into two stages, including Big Data Processing Processes and Sensitive Information Filtering Processes, and Big Data processing is analyzed and applied in Big Data collection in four stages. Big Data Processing Processes include data collection and storage, vocabulary analysis and parsing and semantics. Sensitive Information Filtering Processes includes sensitive information questionnaires, establishing sensitive information DB, qualifying information, filtering sensitive information, and reliability analysis. As a result, the number of Big Data performed in the experiment was carried out at 84.13%, until 7553 of 8978 was produced to create the Ontology Generation. There is considerable significan ce to the point that Performing a sensitive information cut phase was carried out by 98%.
Implementation of Forced Answer Model for Sensitive Information at On-Line Survey
[Kisti 연계] 한국데이터정보과학회 한국데이터정보과학회지 Vol.14 No.3 2003 pp.489-499
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this paper we implement the system for the forced answer model which is an indirect response technique on the internet as a way of obtaining much more precise information, not revealing secrets of responsors. In this system we consider that respondents are generally reluctant to answer in a survey to get sensitive information targeting employees, customers, etc.
[Kisti 연계] 한국데이터정보과학회 한국데이터정보과학회지 Vol.15 No.4 2004 pp.731-741
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper is planned to use multi-proportions randomized response model for sensitive information on internet survey. This is an indirect response technique as a way of obtaining much more precise information. In this system we consider that respondents are generally reluctant to answer in a survey to get sensitive information targeting employees, customers, etc.
[Kisti 연계] 한국데이터정보과학회 한국데이터정보과학회지 Vol.14 No.3 2003 pp.591-603
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper is planned to use randomized response technique which is an indirect response technique on internet as a way of obtaining much more precise information, not revealing secrets of responsors, considering that respondents are generally reluctant to answer in a survey to get sensitive information targeting employees, customers, etc.
[Kisti 연계] 한국데이터정보과학회 한국데이터정보과학회 학술대회논문집 2002 pp.107-118
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper is planned to use randomized response technique which is an indirect response technique on internet as a way of obtaining much more precise information, not revealing secrets of responsors, considering that respondents are generally reluctant to answer in a survey to get sensitive information targeting employees, customers, etc.
[Kisti 연계] 한국데이터정보과학회 한국데이터정보과학회지 Vol.13 No.2 2002 pp.341-354
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
This paper is planned to use randomized response technique which is an indirect response technique on internet as a way of obtaining much more precise information, not revealing secrets of responsors, considering that respondents are generally reluctant to answer in a survey to get sensitive information targeting employees, customers, etc.
The Three-Stage Cluster Randomized Response Model for Obtaining Sensitive Information
[Kisti 연계] 한국통계학회 Communications for statistical applications and methods Vol.10 No.1 2003 pp.247-256
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this study, we systemize the theoretical validity for applying RRM to three-stage cluster sampling method and derive the estimate and it's variance of sensitive parameter. We derive the minimum variance form under the optimal values of the subsample sizes when the costs are fixed. Under the some given precision, we obtain the optimal values of the subsample sizes and derive the minimum cost form by using them. We apply the three-stage cluster RRM to field survey and suggest some necessary points for practical use.
[Kisti 연계] 한국데이터정보과학회 한국데이터정보과학회지 Vol.17 No.4 2006 pp.1237-1250
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
In this paper we develop the web-based unified randomized response system for obtaining more reliable response to the sensitive characteristic such as a crime of violence at home, and a bribing and so on. This survey system embody to apply with from the classical to recently research, for example from the Warner's model to the 2-stage model. In addition, our survey system is able to link between the typical and the randomized response system. Finally, our survey system looks into a variation according to various sensitive questions as well as it can be used for a single question.
가명정보와 개인정보자기결정권 - 동의 없이 가명처리된 민감정보의 상업적 이용은 정당한가? - [대상결정] 헌재 2023. 10. 26. 2020헌마1477, 2021헌마748 결정
[NRF 연계] 헌법재판연구원 헌법재판연구 Vol.11 No.2 2024.12 pp.355-386
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
4차 산업혁명 시대에서의 데이터 활용과 개인정보 보호 간의 균형은 더없이 중요하다. 본 논문에서는최근 개정된 데이터 3법(‘개인정보 보호법’, 정보통신망법, 신용정보법)에서 도입된 “가명정보”, “가명처리”, “가명정보 처리” 개념을 중심으로 한 법적 규제의 현황과 문제점을 최근 선고된 헌법재판소 결정례를 소재로 분석한다. “가명정보”는 특정 개인을 식별할 수 없는 형태로 개인정보를 처리하는 방식을 제공하지만, 데이터의 재식별 가능성과 개인정보 자기결정권 침해에 대한 우려가 동시에 제기되고 있다. 특히, 민감정보의 가명처리에 대한 법적 규제로 인해 정보주체의 권리가 제한될 수 있으며, 이에 대한 적절한 보호조치가 마련되지 않을 경우 법적 및 윤리적 문제를 야기할 수 있다. 하급심 판결에서 ‘가명처리정지권’이 인정된 사례는 정보주체의 개인정보자기결정권 보호를 위한 중요한 판단으로, 데이터 활용의공익과 개인 권리 보호 간의 균형을 위해 필요한 법적 기초가 될 수 있음을 시사한다. 또한, “가명정보처리”의 목적에서 ‘상업적, 산업적 목적의 통계작성 및 과학적 연구’가 포함되면서 정보주체의 권리 제한과 그 목적 간의 적정한 균형이 이루어져야 할 필요성이 더욱더 강조된다. 본 논문은 정보주체의 권익보호와 데이터 경제의 발전을 위한 실질적인 방안을 모색하면서, 이익형량의 논의를 통해 가명정보의 안전하고 효율적인 활용을 위한 법적 접근 방안 및 입법적 개선 방향에 대해 제안한다. 궁극적으로, 개인정보 보호에 대한 법적 규제가 데이터 활용의 혁신을 방해하지 않으면서도 정보주체의 권리를 충분히 보장할 수 있는 체계로 발전해 나가기 위해 입법자의 적극적인 노력이 필요함을 강조한다.
In the era of the Fourth Industrial Revolution, balancing data utilization and personal information protection is of utmost importance. This paper analyzes the current status and issues of legal regulations surrounding the concepts of “pseudonymized information,” “pseudonymisation,” and “processing of pseudonymized information” introduced in the recently amended 3 Data Laws, using recent Constitutional Court rulings as a reference. Pseudonymized information provides a means of processing personal information in a way that does not allow for the identification of specific individuals; however, concerns about the potential for re-identification of data and violations of personal rights arise concurrently. In particular, legal regulations concerning the pseudonymization of sensitive information may restrict the rights of data subjects, potentially leading to legal and ethical issues if adequate protective measures are not established. The recognition of the “right to cease pseudonymization” in court rulings signifies a crucial judgment for the protection of data subjects’ rights to informational self-determination and suggests a necessary legal foundation for balancing public interests in data utilization with the protection of individual rights. Furthermore, the inclusion of “commercial and industrial purposes for the statics and scientific research” in the objectives of “processing pseudonymized information” emphasizes the need for a proper balance between the limitation of data subjects’ rights and those objectives. To identify practical solutions for protecting the interests of data subjects while promoting the advancement of a data economy. Through discussions of interest balancing, it proposes legal approaches and legislative improvements for the safe and effective use of pseudonymized information. Ultimately, it underscores the necessity of proactive legislative efforts to develop a legal framework that adequately protects the rights of data subjects without hindering innovation in data utilization.
지능정보사회에서 민감정보의 보호와 이용을 위한 법제 정비방안 연구
[NRF 연계] 서울시립대학교 법학연구소 서울법학 Vol.29 No.2 2021.08 pp.77-116
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
지능정보사회의 도래에 따라 인공지능, 빅데이터, 사물인터넷, 클라우드 등 신기술을 바탕으로 방대한 양의 개인정보가 수집 및 이용될 것으로 전망되고 있다. 다만, 지능정보기술의 특성상 개인정보의 이용이 요청됨에 따라 그에 못지않게 개인정보의 침해가능성도 증대할 것으로 보인다. 이는 결국 개인의 사생활의 비밀과 자유, 인격권 등 헌법상 기본권 보장을 위해 개인정보의 안전한 보호와 이용이 중요한 과제로 부각하게 되는 기반을 제공하게 된다. 현행 개인정보 보호법에서는 개인정보를 살아 있는 개인에 관한 정보로서 성명, 주민등록번호 및 영상 등을 통하여 개인을 알아볼 수 있는 정보 그리고 해당 정보만으로는 특정 개인을 알아볼 수 없더라도 다른 정보와 쉽게 결합하여 알아볼 수 있는 정보(이 경우 쉽게 결합할 수 있는지 여부는 다른 정보의 입수 가능성 등 개인을 알아보는 데 소요되는 시간, 비용, 기술 등을 합리적으로 고려하여야 한다)라고 정의하고 있다. 지능정보기술은 이러한 개인정보를 광범위하게 수집하는 과정에서 정보주체의 사생활과 밀접한 관련성이 있는 민감정보도 그 대상으로 하고 있다. 민감정보는 그 특성상 개인의 사생활과 연결이 될 뿐만 아니라 민감정보가 오・남용될 경우에는 사회적으로 부당한 편견과 차별을 유발할 수 있는 성격을 보유하고 있다. 그러나 민감정보라고 하여 보호만 하여야할 것은 아니며, 개인의 건강정보를 기반으로 맞춤형 의료 서비스를 제공하는 모바일 헬스케어 등 신산업의 부가가치를 고려하면 적정한 이용을 보장해줄 필요성도 있을 것이다. 위와 같은 관점에서 현행 개인정보 보호법상 민감정보의 보호범위를 유럽연합, 미국, 일본 등 주요 국가의 개인정보 보호법과 비교하여 민감정보의 범위와 활용에 대해 검토해본다. 그러한 비교법적 검토를 바탕으로 현행 개인정보 보호법의 정비방안을 제언함으로써 지능정보사회에서 민감정보 관련 정보주체의 보호 강화와 적정한 이용을 도모하고자 한다.
Personal information gradually turns into be one of the key resources in the intelligent information society in which the cutting-edge technologies such as artificial intelligence, big data, internet of things, clouds play significant roles for innovative services and products. However, there is no doubt that the probability of data breach rises as the importance of personal information grows with the latest technologies. The definition of sensitive information is clearly written in the Personal Information Protection Act. The Act explicitly provides examples to define what the sensitive information is. Pursuant to the article 23 of the Act, information about one’s ideology, belief, admission to or withdrawal from a trade union or political party, political opinions, health, sex life falls into the scope of the sensitive information. Besides, other personal information that is likely to markedly threaten the privacy of any data subject is equivalently treated as the sensitive information. Furthermore, the Act limits the use of such information since sensitive information is highly related to the right to privacy given to each data subject. How we set balance between the protection and the use of personal information comes to the critical task in the fast-evolving society driven by latest data technologies. The sensitive information is not in difference. To that end, this article looks into global protection laws in order to compare the protection scope of sensitive information. In addition, under the perspective that the safe use of personal information is required for economical innovation driven by the data technologies, this article suggests to amend the Personal Information Protection Act. First, the Act should expand the scope of sensitive information by adding information about sexual orientation and information about criminal victimization. Second, in order to protect data subjects, the legal basis for processing sensitive information should be limited to laws only passed by the legislature body. These would expand the protection scope of data subjects with regard to sensitive information. Currently, the Act only allows two conditions to process sensitive information, consent from a data subject or by other statute that allows to process sensitive information. Comparing to relevant provisions written in the EU GDPR, this limitation is likely to be narrowly regulated. Thus, the Act should be amended in order to process sensitive information by adding four exceptions like the EU GDPR. With four exceptions, the task to balance the protection and the use of personal information, including sensitive information, would be completed without harming the data subject in the intelligent information society.
담배 유해성분 정보 공개에서 소비자의 정보민감 흡연행동 의향 분석 - 정보회피의 매개효과를 중심으로 -
[NRF 연계] 사단법인 안전문화포럼 안전문화연구 Vol.50 2026.01 pp.167-182
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 연구는 2025년부터 시행되는 담배 유해성분 정보 공개 제도를 배경으로, 정보탐색비용과 소비자자신감이 정보회피를 매개로 정보민감 흡연행동 의향에 미치는 영향을 분석하였다. 단순한 정보 제공을 넘어 소비자가 실제로 이해하고 활용할 수 있는 정보 설계에 대한 정책적 시사점 제공을 목적으로 한다. 이를 위해 국내 성인 흡연자 350명을 대상으로 설문조사를 실시하고, 구조방정식 모형(SEM)을 활용하여 변수 간의 인과관계와 매개효과를 분석하였다. 주요 변수는 정보탐색비용, 소비자자신감, 정보회피, 정보민감 흡연행동 의향으로 구성되었으며, 탐색적 요인분석과 확인적 요인분석을 통해 각 변수의 신뢰도와 타당성을 확보하였다. 연구 결과는 다음과 같다. 첫째, 정보탐색비용은 정보회피에 긍정적인 영향을 미쳐 정보민감 흡연행동의향에는 간접적으로 부(-)적 영향을 보였지만, 직접효과는 정(+)적 효과를 미치는 비일관적 매개 효과가 나타났다. 이는 정보탐색비용이 낮은 경우에도 개인에게 심리적으로 불편한 결과를 암시하거나 위협적일 때, 정보민감 행동의향이 낮게 나타날 수 있음을 보여준다. 둘째, 소비자자신감은 정보회피를 감소시키며 흡연행동에도 긍정적인 영향을 미치는 것으로 나타났다. 셋째, 정보회피는 정보탐색비용과 소비자자신감이 정보민감 흡연행동 의향에 미치는 영향 과정에서 매개변수로 작용하였으며, 정보민감 흡연행동 의향에 부정적인 영향을 미치는 것으로 나타났다. 이러한 결과는 정보의 접근성 제고뿐만 아니라, 정보의 중요성과 담배의 위해성에 대한 인식을 강화하고 인지적 부담을 완화함으로써 정보회피를 감소시킬 수 있는 정보 설계의 중요성을 시사한다.
This study examines the effects of information search cost and consumer self-confidence on information-sensitive smoking behavior intention, with information avoidance as a mediating variable, in the context of the tobacco harmful constituent disclosure policy implemented from 2025. The objective is to provide policy implications for designing information that not only presents data but also enables consumers to understand and utilize it effectively. A survey was conducted with 350 adult smokers in Korea, and Structural Equation Modeling(SEM) was employed to analyze the causal relationships and mediating effects among the variables. The main variables include information search cost, consumer self-confidence, information avoidance, and information-sensitive smoking behavior intention. Reliability and validity of each variable were verified through exploratory and confirmatory factor analyses. The results are as follows. First, information search cost had a positive effect on information avoidance and an indirect negative effect on information-sensitive smoking behavior intention, while also showing a positive direct effect?indicating an inconsistent mediation effect. This suggests that even when the information search cost is low, if the information implies psychologically discomforting or threatening outcomes, the intention to engage in information-sensitive behavior may remain low. Second, consumer self-confidence was found to reduce information avoidance and positively influence smoking behavior intention. Third, information avoidance mediated the effects of information search cost and consumer self-confidence on information-sensitive smoking behavior intention, and had a negative impact on such behavioral intention. These findings suggest the importance of information design that can reduce information avoidance by strengthening awareness of the importance of information and the harmfulness of tobacco, and by alleviating cognitive burden.
헌법체계상 인격권과의 관계에서 본 프라이버시권(사생활의 비밀과 자유)의 내용 및 성격 -암호화된 의료정보에 있어 민감정보 범위 및 안전조치 기준에 관한 보론
[NRF 연계] 사법발전재단 사법 Vol.1 No.65 2023.09 pp.135-174
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
프라이버시권은 미국에서 생성·발전한 권리이지만 수정헌법에 직접 명시한 권리는 아니다. 다만, 헌법에 명시된 기본권이 실현되는 과정에서 그 빛의 발산으로 새로운 생명력을 가진 권리를 만드는 반영권의 성격을 지닌다. 초기에는 자신의 집 안에서 정부의 권력으로부터 안전을 보장받을 권리로 나타났다. 이후 사회의 변화와 과학기술의 발전에 따라 혼자 있을 권리라는 포괄적 의미로 변천하여 지성과 감성의 정신적 생활도 보호영역에 속하게 되었다. 오늘날 프라이버시권은 수정헌법 제14조 정당한 법의 절차로 보호되는 자유에 근거하여 설명하는 입장으로 수렴된다. 프라이버시권에 있어 법적 구제의 중심은 손실의 전보에 있지 않고 사회적 위협으로부터의 개인의 존엄과 정신을 옹호하는 데 있다. 이는 사회의 규범적 비난으로부터 벗어나 개인이 자신의 사적인 삶을 존중받을 수 있는 권리를 의미한다. 프라이버시권은 사적 생활영역에서의 개인의 자율성 그 자체를 보장하는 관념적·형식적 권리이다. 한편, 인격권은 독일에서 생성·발전한 권리로 일반적 행동의 자유와 좁은 인격적 생활영역의 권리로 나누어진다. 일반적 행동의 자유는 다른 개별 기본권들을 모두 포함하는 포괄적 권리의 성격을 갖는다. 반면, 좁은 인격적 생활영역의 권리는 개별 기본권들에 의해 미처 파악하지 못한 인격적 이익을 보호하는 보충적 권리로서의 성격을 갖는다. 그러함에도 두 기본권은 별개의 권리가 아니라 자기결정권을 공통의 기초로 하는 관념적 형식의 권리이다. 프라이버시권과 인격권은 관념적 형식의 권리라는 점에서 다른 개별 기본권들과 구별된다. 또한 법체계의 근본규범이 될 요건을 동일하게 갖추고 있다. 그러나 우리 헌법이 추구하는 인간상이 개인성과 사회성이 조화를 이룬 균형잡힌 인간이라는 점에서 사적 자율성과 공적 자율성을 함께 추구하는 인격권과 그 근거인 인간의 존엄성이 프라이버시권 보다는 근본규범에 더 부합한다. 우리 헌법 제17조는 사생활의 자유와 비밀을 규정하여 프라이버시권을 별도로 규정하고 있다. 이렇게 규정된 프라이버시권의 독자적 의미는 헌법이 추구하는 인간상에 맞는 인격을 형성하는 과정이 단순하지 않다는 데서 찾아야 한다. 인격권이 전제하고 있는 고양된 인격의 완성은 각 개인이 자신만의 고유한 가치를 잃지 않는 데서 출발하는데, 이는 국가나 다른 개인으로부터는 물론 사회가 자신에게 부여한 역할로 부터도 벗어날 때라야 비로소 개발할 수 있다. 프라이버시권은 개인이 사회적 관계로부터 단절되어 자연인으로서 갖는 고유한 가치를 실현하기 위한 기본권으로 사적 자율성만을 보장한다. 이러한 점에서 관념적 형식의 권리이지만 인격권과는 구별된다.
Privacy right is a right that has been created and developed in the United States. but It is not stipulated in the Constitution. It has the nature of the penumbras creating a new life-force right stipulated in the Constitution. In the beginning, it appeared to be the right of security within one’s home from the power of the government. But it has changed into a comprehensive meaning of the right to be let alone with the changes of society and the development of science and technology. It also included the spiritual life of intelligence and emotion, Currently, the basis for the right to privacy converges to something based on the 14th Amendment. The backbone of the legal remedy is not in the compensation for damages but in the social advocacy of individual dignity and spirit. For this reason, the right to privacy is developed into the right to respect one's private life free from the normative condemnation of society. It has become an abstract and formal right guaranteeing individual autonomy in the private sphere of life. Meanwhile, personal rights is a right that has been created and developed in Germany. It is classified into general freedom of action and the right to personal life in a narrow sense. General freedom of action has a comprehensive nature of rights covering all other fundamental rights. Whereas the right to personal life in a narrow sense has a nature of supplementary rights. It protects personal interests that have not yet been identified with other fundamental rights. The two fundamental rights are not separate rights but two aspects in which the same rights are realized in reality because both are based on self-determination based on personal rights. The right to privacy and personal rights have a commonality that distinguishes themselves from other fundamental rights in that they are abstract rights. But Personal rights and human dignity are more consistent with basic norm because the human image pursued by the Constitution is a balanced human being whose individuality and sociality are harmonized. Personal rights have both private and public autonomy. Article 17 of the Korean Constitution separately protects the right to privacy by stipulating freedom of privacy and confidentiality. The right to privacy has its own meaning that distinguishes it from personal rights. The completion of an elevated personality, which personal rights makes a premise, begins with each individual not losing his or her own unique value. It can only be developed when an individual breaks away from other individuals as well as the social role given to himself. The right to privacy is a fundamental right that guarantees a person's unique value which an individual has as a natural person cutting off from social relationships. It is an abstract form of right in that it only guarantees private autonomy but distinct from personal rights.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.