Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 4
No
1

Personal Information Protection Crisis Management in Big Data KCI 등재

Kwan Sig Choi

위기관리 이론과 실천 한국위기관리논집 제17권 제11호 2021.11 pp.95-108

※ 기관로그인 시 무료 이용이 가능합니다.

4,600원

ICT의 비약적인 발달로 인하여 4차 산업시대의 총아인 빅데이터 시대가 도래하였지만 개인정보보 호법상 개인정보수집최소의 원칙과 일치되지 않는 빅데이터 수집과 생성 및 활용의 최대의 시대적 요청과 상충되지만 산업의 발전과 개인의 정보보호를 위하여 조화할 필요가 있다. 첫째, 정보주체에 관한 개인 정보 보호 면에서 빅데이터 산업의 효율과 경영을 저해하지 않는 범위에서 빅데이터에서 의 개인정보에 관한 자기정보통제권을 최대한 보장하여야 한다. 둘째, 정보처리자의 관련된 개인정 보보호에서 정보주체의 동의를 필요로 하지만 정보처리자의 일방적인 결정에 좌우되며 새로운 프라 이버시 침해가 제기된다. 개정 개인정보보호법은 빅데이터에서의 개인정보의 보호를 위하여 익명 내지 가명정보처리규정을 신설하여 빅데이터수집⋅생성과 개인정보보호의 조화를 모색하고 있으 나 개인정보보호법상 공익적 목적이 아닌 이의 적용여부가 명확하지 않다. 셋째, 빅데이터의 조작가 능성은 존재한다. 빅데이터가 자신의 의도대로 유도하기 위하여 사용되는 경우 관련된 이해당사자 들에게 심각한 폐해를 초래한다. 현행 통계법상 규정이외의 빅데이터를 조작하는 경우 이를 금지 규정이 없다는 점에서 이의 규제가 요구된다.

Due to rapidly-rising development of ICT the era of Big Data comes in modern lives and Big Data are deeply located at our everyday lives. Personal informations are integrated, used widely at the many aspects including public and private sectors. Big Data including personal informations in itself become giant industries in modern business nowadays. Big Data that personal informations have been integrated may cause serious infringements of personal informations. According to Personal Information Protection Act in the cases one collects or uses personal informations one has to obtain consent by concerned party of personal information. But it is not easy to obtain consent that is necessary to collect and use Big Data creating massively and automatically by ICT instruments. In the aspect of management of Big Data, to protect personal informations throughly, pseudonymisation, anonymisation of personal information have to be permitted in the Big Data collections and uses. And possibility of fake manipulation about Big Data may always exists.

2

「개인정보 보호법」상 “가명처리”와 “개인정보 처리정지권” 해석의 합리화 방안 검토 - 서울고등법원 2023나2009236 판결의 내용을 중심으로

김현경

[NRF 연계] 사법발전재단 사법 Vol.1 No.68 2024.06 pp.3-31

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

「개인정보 보호법」은 데이터의 이용을 활성화하면서도 정보주체의 개인정보자기결정권을 보호할 수 있도록 제28조의2를 신설하여 공익적 기록보존, 과학적 연구, 통계작성 등 제한적 목적하에 정보주체의 의사와 무관하게 개인식별정보를 가명처리하여 이용할 수 있도록 하였다. 이러한 가명정보의 처리에는 정보주체의 처리정지권 등 재식별을 전제로 행사할 수 있는 열람/통지권 등을 배제하였다. 그러나 가명정보의 생성에는 ‘가명처리(가명화)’가 필수 불가결한 요건임에도 불구하고 최근 법원은 ‘가명처리’와 ‘가명정보의 처리’를 구분하여 식별(가능)정보의 가명처리에는 정보주체의 처리정지권이 배제되지 않고 인정된다고 하였다. 따라서 제28조의2의 공익적 기록보존 등 제한된 목적을 위하여 개인식별정보를 가명처리하는 것이 정보주체의 처리정지권의 행사로 인해 불가능해질 수 있다. 이는 정보주체의 의사와 무관하게 제한된 목적하에 가명정보를 처리할 수 있도록 규정한 제28조의2의 실효성을 약화시키며 입법 취지를 희석화시킬 수 있다. 본고에서는 정보주체의 권리의 법적 성격과 처리정지권의 의미를 검토하고 제28조의2와 처리정지권에 대한 법원 판결의 쟁점과 문제점을 분석한다. 그리고 해결과제로써 ‘가명처리’와 ‘처리정지권’의 바람직한 해석 방향과 해석의 혼란을 방지하기 위한 입법과제를 제안하였다.

In order to facilitate the use of data while protecting the right to self-determination of personal information, the Personal Information Protection Act established Article 28-2 (Processing of Pseudonymized Information), which allows the pseudonymisation of personally identifiable information for limited purposes such as public record-keeping, scientific research, and statistical compilation, without the consent of data subjectst. However, despite the fact that pseudonymisation is an indispensable requirement for the creation of pseudonymized information, the court recently distinguished between ‘pseudonymisation’ and ‘processing of pseudonymized information’ and held that the pseudonymisation of identifiable information does not exclude the right of the information subject to suspend processing. Therefore, the pseudonymisation of personally identifiable information for the limited purposes of Article 28-2 may become impossible due to the exercise of the information subject’s right to suspend processing. This would undermine the effectiveness of Article 28-2, which provides that pseudonymized information may be processed for limited purposes regardless of the data subject’s will, and dilute the legislative intent. This article examines the legal nature of the data subject’s rights and the meaning of the right to suspend processing, and analyzes the issues and problems in court decisions on Article 28-2 and the right to suspension of processing of personal information. It also suggests the desirable interpretation direction of ‘pseudonymisation’ and ‘right to suspension of processing of personal information’ as a solution, and legislative tasks to prevent confusion in interpretation.

3

컨소시엄 블록체인 네트워크 기반에서 가명처리를 활용한 안전한 기업 내부자 위협 행위 데이터 공유 시스템 연구

윤원석, 장항배

[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2021 pp.348-351

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 지속적으로 늘어나고 있는 내부의 유출자를 탐지하기위해 컨소시엄 블록체인 기술을 활용하여 기업간 직원의 PC사용 행위 로그 데이터를 가명처리하여 블록에 기록하여 네트워크에 참여한 다른 기업들간의 안전한 공유를 통해 내부자 유출 데이터 및 시나리오의 확장하여 내부에서의 유출을 탐지할 수 있는 데이터 셋을 확보하는 연구를 제안한다. 현재 내부자 위협탐지의 한계점중 가장 큰 요소를 차지하는 부족한 실제 사례의 내부자 유출 데이터 셋의 문제점을 본 연구를 통해서 네트워크 참여 기업간의 내부자 유출 데이터를 확장하고 타기업의 유출 사례를 활용해 기업에서 발생할 수 있는 내부자 유출을 미연에 방지할 수 있다.

4

GDPR의 관점상 신용정보법 개정안(김병욱 의원 대표발의안)의 검토 - 가명조치·익명조치 개념, 정보주체의 동의범주 이슈를 중심으로 -

양기진

[NRF 연계] 한국상사법학회 상사법연구 Vol.38 No.2 2019.08 pp.249-276

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

이 글에서는 2018년 11월 김병욱 의원이 대표발의한 신용정보법 개정안(이하 ʻ개정안ʼ) 중 가명조치·익명조치, 공개된 개인정보의 동의없는 수집 허용 이슈를 검토하였다. 개정안은 정보주체의 실질적 보호장치를 정비・강화하고 빅데이터 활용에 관한 장치를 대폭 보완 또는 도입을 추구한다는 명분을 내세우고 있다. 그럼에도 불구하고 개정안은 익명조치의 적정성 판단에 관한 정부의 개입 및 관련 법적 효력의 적극적 부여(익명정보로의 추정효), 가명조치 방식에 관한 기술중립을 깨고 정부가 직접 개입한다는 점, SNS 등에 오픈한 개인정보를 정보주체의 동의 없이 수집할 수 있도록 허용하여 문제가 있다. 정보에 관한 불필요한 이용동의 절차를 생략하고자 개정안이 도입하는 추가처리 개념 역시 ʻʻ당초 수집한 목적과 상충되지 아니하는 범위ʼʼ에서라고 하여 GDPR의 추가처리(further processing)와 상당히 다른 양태를 보이고 있어서 정보주체의 합리적 기대에 반할 여지가 적지 않다. 따라서 빅데이터의 시급한 활용만을 바라보고 조급하게 개정안을 통과시키는 것은 오히려 되돌리기 어려운 문제의 소지가 크다. 따라서 개정안의 국회 통과를 밀어붙일 것이 아니라 논의를 좀더 오픈시키고 광범위한 의견청취를 통하여 개정안을 통한 법제 변경이 가져올 직・간접적인 긍정적·부정적 효과를 냉정히 분석하고 부정적인 영향이 큰 부분은 GDPR 등 법제와 비교하여 개정안을 전반적으로 검토, 수정할 필요가 있다.

This article reviews the issue of allowing pseudonymisation or anonymisation of personal data and its legal effect, and unauthorized collection of personal data disclosed to SNS under the new bill of the Credit Information Act (hereinafter referred to as 'the bill') introduced by Kim ByungWook, member of Korean National Assembly in November 2018. The bill has the cause of improving and strengthening effective devices to protect data subjects, and at the same time, of supplementing the use of big data. Nevertheless, the bill proposes that the Korean government intervenes in judging the appropriateness of anonymization and actively grants the relevant legal effects such as giving legal presumption as anonymous data. Furthermore, it is also problematic to allow a data processor, etc. to collect personal data without the data subject?s consent. The newly introduced concept of ?further processing? by the bill is designed to omit the unnecessary step of data subject?s agreement for processing his or her data. However, it is allowed in the range ??not in conflict with the originally collected purpose??, which differs considerably from the GDPR?s further processing that allows only when compatible with the originally collected purpose. The bill will incur controversy over the rational expectations of data subjects. Therefore, rather than pushing the bill to pass the National Assembly, this paper recommends discussions open to all stakeholders thereby analyzing all the effects which will be directly or indirectly brought about by the bill to gain acceptable and reasonable balance between personal data protection and smooth data use.

 
페이지 저장