
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
가명처리 처리정지 요구권 배제 판결의 국제인권조약 위반 검토: 대법원 2024다 210554 판결의 ‘가명처리’ 개념을 중심으로
이승필(Seung-pil Lee) 경희법학연구소 2026 KHU 글로벌 기업법무 리뷰 Vol.19 No.1
세계적으로 AI(Artificial Intelligence)와 사물인터넷 등이 기술의 핵심으로 부상하고 있는 현대 디지털 시대에서, 인공지능 등의 디지털 기술의 활용, 발전에는 필수적으로 ‘빅데이터’의 이용이 수반된다. 현대사회에서 디지털 기술을 제공하는 기업(개인정보처리자)은 개인들의 개인정보 데이터를 이용하는 것이 필요하므로, 개별 정보주체들에게는 필연적으로 개인정보자기결정권을 비롯한 인격권의 침해 가능성이 발생하게 된다. 다만 개인정보처리자의 개인정보 이용에 있어 개별 정보주체의 일반적인 개인정보는 우리 헌법 제17조에 규정된 사생활의 자유와 비밀 조항을 통하여 소위 ‘프라이버시권’으로 헌법상 보호받고 있으므로, 개인정보처리자인 기업이 기술의 전제가 되는 개인정보들을 수집, 이용하기 위해서는 특정한 개인정보를 익명화(Masking) 처리하여 이를 기업들이 이용할 수 있는 ‘재산으로서의 정보’로 가공하는 과정이 필요하다. 관련하여 대한민국은 「개인정보 보호법」,「정보통신망 이용촉진 및 정보보호 등에 관한 법률」,「신용정보의 이용 및 보호에 관한 법률」, 소위 ‘데이터 3법’을 통하여 데이터 이용에 관한 규제, 개인정보 보호 체계를 관리 감독하고 있고, 특히 데이터 3법 중 개인정보 보호법에서 데이터 활용을 위하여 ‘가명정보(Pseudonymisation)’를 이용할 수 있도록 구체적으로 규정하고 있다. 가명정보는 기업이 이용할 수 있는 일종의 ‘정보재산’으로, 일반인의 개인정보에서 가명 정보로 바뀌는 가명화 과정은 인격권에서 재산권으로 그 정보에 수반되는 권리적 성격이 변화하는 지점이라 할 것이며, 이러한 과정에 대하여는 개인정보 보호법에서 2020년 3월 법률 제16930호 개정을 통하여 제2조 제1호의2 ‘가명처리’로서 입법하여 규율하고 있다. 개인정보 보호법에 따르면 기업은 가명처리 과정 이후의 가명정보를 이용할 수 있도록 보장받고 있으므로, 정보에 대한 권리를 갖는 주체가 개인에서 개인정보처리자로 넘어가게 된다. 이에 가명처리 과정 이후에 다루어지는 가명정보는 필연적으로 개인정보자기결정권과 관련하여 인격권의 침해 소지가 발생하게 된다. 이러한 인격권 침해를 방지하기 위하여, 특히 개인의 개인정보자기결정권을 보장하기 위하여 정보제공자인 개인에게 ‘가명처리’를 중단하여야 할 권리인 ‘처리정지요구권’이 인정되어야 하나, 최근 대법원은 정보주체가 되는 개인의 가명처리에 대한 정지요구권을 부정하는 판결을 선고하여 개인정보처리자의 손을 들어주었다(대법원 2025. 7. 18. 선고 2024다210554 판결). 이에 본 글에서는 이러한 판결의 인격권 침해 여부에 대하여, 국제 인권조약 위반의 측면에서 헌법 제 6조에 따라 국내법과 동등한 효력을 갖는 국제 조약 취지에 부합하도록 합치 해석을 했어야 함에도 이를 간과한 위헌성이 있음을 지적하고자 한다. In the modern digital age, where Artificial Intelligence (AI) and the Internet of Things (IoT) have emerged as core technologies worldwide, the utilization and advancement of digital technologies like AI inherently necessitate the use of ‘Big Data’. In modern society, companies providing digital technologies (personal information processors) require the use of individuals' personal information data. Consequently, this inevitably creates the potential for infringement upon the personal rights of individual data subjects, including their right to self-determination over personal information. However, the general personal information of individual data subjects, as used by personal information processors, is constitutionally protected as the so-called ‘right to privacy’ under Article 17 of the Constitution of the Republic of Korea, which guarantees the freedom and secrecy of private life. Therefore, for companies acting as personal information processors to collect and use the personal information that forms the basis of technology, it is necessary to anonymize (mask) specific personal information and process it into ‘information as property’ that companies can utilize. In this regard, the Republic of Korea manages and supervises regulations on data use and the personal information protection system through the “Personal Information Protection Act,” the “Act on Promotion of Information and Communications Network Utilization and Information Protection,” and the “Act on the Use and Protection of Credit Information,” collectively known as the ‘Data Three Acts.’ Specifically, among these three acts, the Personal Information Protection Act explicitly stipulates the use of ‘pseudonymized information’ for data utilization. Pseudonymized information is a form of ‘information asset’ that businesses can utilize. The process of pseudonymization, where an individual's personal information is transformed into pseudonymized information, represents a shift in the nature of rights associated with that information—from personality rights to property rights. This process is legislatively regulated as ‘pseudonymization’ under Article 2, Paragraph 1-2 of the Personal Information Protection Act, as amended by Act No. 16930 in March 2020. 'Pseudonymization' was legislated and regulated. According to the Personal Information Protection Act, companies are guaranteed the right to use pseudonymized information after the pseudonymization process. Consequently, the subject holding rights over the information shifts from the individual to the personal information processor. Therefore, pseudonymized information handled after the pseudonymization process inevitably carries the potential to infringe upon personality rights related to the right to self-determination over personal information. To prevent such infringement of personality rights, and particularly to safeguard an individual's right to self-determination over their personal information, the individual providing the information should be granted the ‘right to request suspension of processing’—the right to demand cessation of ‘pseudonymization’. However, the Supreme Court recently ruled against the individual data subject's right to request suspension of pseudonymization, siding with the personal information processor (Supreme Court Decision 2024Da210554, rendered July 18, 2025). This article argues that the ruling is unconstitutional. It points out that the court overlooked the need for a constitutional interpretation consistent with the intent of international treaties, which, under Article 6 of the Constitution, have equal force with domestic law. This oversight occurred despite the ruling potentially violating international human rights treaties and infringing upon personal rights.
가명정보의 활용과 개인정보자기결정권 - 대법원 2025. 7. 18. 선고 2024다210554 판결 -
윤태영 한국경찰법학회 2026 경찰법연구 Vol.24 No.1
우리나라 개인정보 보호법 제28조의2에서는 “개인정보처리자는 통계작성, 과학적 연구, 공익적 기록보존 등을 위하여 정보주체의 동의 없이 가명정보를 처리할 수 있다.”고 규정하고 있다. 그런데 최근 이동통신회사와 이동통신 서비스 이용계약을 체결한 이용자들이 자신의 개인정보를 개인정보 보호법 제28조의2에 따라 통계작성 등 목적으로 활용하기 위해 가명처리하여서는 안 된다는 취지로 처리정지를 요구하는 소송을 제기하였다. 이에 대해 제1심과 제2심 법원은 ‘가명처리’와 ‘가명정보 처리’를 구분하면서 개인정보의 가명처리에 대한 처리정지 요구를 제28조의2에 의해 거절할 수는 없다고 하여 원고들의 청구를 인용하였다. 이에 대하여 대법원은 가명처리는 처리정지 요구의 대상이 되지 않는다고 하면서 하급심 판결들과는 정반대의 판단을 하였다. 최근 개인정보 보호법이 개정되었는데, 가명처리는 개인정보의 식별성을 낮춰 재식별 위험을 감소시키는 수단으로서, 개인정보 침해를 완화하면서도 데이터 활용 가치를 유지하기 위한 핵심 제도로 도입되었다. 그러나 개인정보를 계속적으로 보관・가공・결합・연산하는 과정에서, 정보의 활용 가치가 증가하는 만큼 정보주체가 다시 식별될 가능성 또한 완전히 배제할 수는 없다. 이로 인해 가명처리 단계에서 정보주체가 자신의 개인정보에 대한 통제권을 어디까지 행사할 수 있는지가 중요한 쟁점으로 부각된다. 그런데 현행 법규정상 가명정보에까지 처리정지요구권이 인정되는지에 대해 명확하게 규정되어 있지 않고 여전히 해석의 여지를 두고 있다. 이런 가운데 대법원은 대상판결에서 가명정보 처리에 관한 특례규정이 적용되는 경우에는 가명처리의 전후를 불문하고 정보주체에게 개인정보 보호법 제37조에 따른 처리정지요구권을 인정할 수 없다고 판시한 것이다. ‘가명처리’는 가명정보의 활용을 가능하게 하는 기능적으로 불가분의 선행 단계로서, 이것을 지나치게 논리적인 단계문제로서 분절적으로 파악하는 것은 적절하지 않다고 본다. 우리 개인정보 보호법 개정에 많은 영향을 미친 EU ‘일반 개인정보 보호법(GDPR, General Data Protection Regulation)’도 가명처리에 대해서만 규정하고 있다. 아울러 최근 사건(CJEU, EDPS v SRB, C-413/23 P (2025. 9. 4.))에서 유럽사법재판소는 GDPR에 기초하여 가명정보를 개인정보가 아닌 것으로 판단하려는 경향에 있다. 또한 오늘날 우리나라 및 일본에서 개인정보자기결정권을 논하는 경우, 개인정보를 무조건적으로 보호하는 절대적 권리로 보는 견해는 보이지 않고, 정보의 수집・처리・이용이 일상화된 사회에서 개인의 인격적 자율성을 어떠한 방식으로 보장할 것인가라는 문제와 결부되어 이해되어야 한다는 견해가 주를 이룬다. 아울러 처리정지를 인정한다면 재식별을 전제로 한 추가정보의 보관과 활용이 필요해 오히려 보호효과가 약화될 수 있다. 더구나 가명정보 제도를 도입한 이유는 빅데이터 시대에 데이터 활용이 필수적이기 때문인데 처리정지의 인정으로 인한 이익보다 그 이익이 크다고 할 수 있다. 이러한 점을 고려한다면 대법원의 판단은 매우 타당하다고 생각된다. Article 28-2 of the Personal Information Protection Act in Korea stipulates that "the transactor of personal information may process pseudonymized information without the consent of the data subject for statistics preparation, scientific research, and record of public interest." However, users who recently signed a mobile communication service use contract with the mobile communication company filed a lawsuit requesting the suspension of processing personal information. Their assertion is that in accordance with Article 28-2 of the Personal Information Protection Act, personal information should not be pseudonymized in order to use it for purposes such as statistics preparation. In response, the courts of the first and second trials distinguished between "pseudonymization" and "pseudonymized information processing" and cited the plaintiffs' claims, saying that they could not reject the request for suspension of processing of personal information under Article 28-2. In response, the Supreme Court ruled the opposite of the lower court rulings, saying that pseudonymization is not subject to a request for suspension of processing. In a recent amendment of Personal Information Protection Act, pseudonymization was introduced as a key system to reduce the risk of re-identification by lowering the identification of personal information and to maintain the value of data utilization while mitigating the infringement of personal information. However, in the process of continuously storing, processing, combining, and calculating personal information, the value of information utilization must increase and the possibility of re-identifying the data subject cannot be completely excluded. As a result, how far the data subject can exercise control over his or her personal information in the pseudonymization stage emerges as an important issue. However, under the current legal regulations, it is not clearly defined whether the right to request suspension of processing is recognized even for pseudonymized information, and there is still room for interpretation. The Supreme Court, meanwhile, ruled that the data subject cannot be granted the right to request suspension of processing information under Article 37 of the Personal Information Protection Act, regardless of whether pseudonymization is done of not if special provisions on the processing of pseudonym information are applied in the subject case. 'Pseudonymization' is a functionally inseparable preceding step that enables the utilization of pseudonymized information, and it is not considered appropriate to segment this as an overly logical problem. The EU 'General Data Protection Regulation (GDPR)', which has had a great influence on the revision of Korea’s Personal Information Protection Act, also stipulates only the processing of pseudonyms. In addition, in recent cases (CJEU, EDPS v SRB, C-413/23 P (September 4, 2025)), the European Court of Justice tends to judge pseudonym information as non-personal information based on GDPR. In recent years, when discussing the Right to Informational Self-Determination in Korea and Japan, the main view is that there is no absolute right to protect personal information unconditionally, and that it should be understood in conjunction with the question of how to guarantee individual personal autonomy in a society where information collection, processing, and usage are common. If the processing suspension is admitted, the protection effect may weaken because storage and application of additional information is required on the premise of re-identification. Moreover, the benefit of using pseudonymized information is greater than the benefit of the recognition of processing suspension for the reason of adopting pseudonymized information system is that the use of data is essential in the era of big data. Considering these points, the Supreme Court's judgment is considered very valid.
개인정보보호법상 가명처리정지요구권에 대한 검토* -대법원 2025. 7. 18. 선고 2024다210554 판결-
이지은 조선대학교 법학연구원 2025 법학논총 Vol.32 No.3
정보주체의 개인정보에 관한 권리는 인격권의 일종인 개인정보자기결정권을 그 보호법익으로 하고 있다. 개인정보의 하나인 ‘가명정보’와 관련하여, 이동통신서비스 이용자들이 통신회사에 대하여 자신의 개인정보를 개인정보보호법 제28조의2에서 규정하는 가명정보의 처리에 관한 특례를 적용받기 위한 목적, 즉 통계작성, 과학적 연구, 공익적 기록보존의 목적으로 가명처리하지 말 것을 요구한 사안에서 하급심 판결과 대법원 판결은 그 결론은 달리 하였다. 1심 판결과 2심 판결의 취지는 가명처리가 이미 이루어진 정보, 즉 가명정보에 대해서는 정보주체가 처리정지요구권을 행사할 수 없으나, 가명정보의 처리에 관한 특례조항인 법 제28조의2에 따라 정보주체의 동의 없이 가명정보를 처리하기 위하여 가명처리하는 것을 사전에 정지할 수 있는 권리 이른바 ‘가명처리정지요구권’은 정보주체에게 인정된다고 판시하였다. 그러나 대법원은 가명정보가 가명정보의 처리에 관한 특례조항의 적용을 받는 경우라면 가명처리의 전후를 불문하고 정보주체에게 법 제37조에 기한 가명처리정지요구권은 인정되지 않는다는 취지로 판결하였다. 생각건대 개인정보보호법은 ‘가명처리’와 ‘가명정보의 처리’를 개념상 구별하고 있고, 가명정보의 처리에 관한 특례조항인 개인정보보호법 제28조의2는 ‘가명정보의 처리’에 관하여 규정하고 있으므로 그 적용을 전제로 하여 정보주체로부터 법 제37조에서 규정하고 있는 개인정보처리정지요구권을 박탈하는 법 제28조의7은 ‘가명처리’ 그 자체에는 적용되지 않는다고 보아 정보주체에게 가명처리정지요구권을 인정할 수 있다는 대상사안의 1심 판결과 2심 판결의 결론이 현행 개인정보보호법의 해석론으로서 타당하다고 생각한다. 다만, 가명정보의 활용과 관련하여 대상사안의 대법원 판결에서 고려하였던 데이터 관련 신산업 육성과 산업계의 데이터 이용 필요성에 개인정보 보호법이 적극적으로 대응하기 위해서는 가명정보의 재식별화 위험을 대비한 기술적 안전장치 마련, 가명처리에 관한 정보주체의 개인정보자기결정권 행사 제한에 대한 사회구성원들의 합의를 바탕으로 한 입법적 보완이 필요하다고 하겠다. he rights of data subjects regarding their personal information are aimed at protecting the right to self-determination over personal information, which is a type of personality right. Regarding ‘pseudonymized information,’ which is a type of personal information, lower court rulings and the Supreme Court ruling reached different conclusions in a case where mobile communication service users requested that telecommunications companies refrain from pseudonymizing their personal information for the purpose of applying the special provisions on processing pseudonymized information under Article 28-2 of the Personal Information Protection Act, namely for statistical purposes, scientific research purposes, and archiving purposes in the public interest. The essence of the first-instance and second-instance rulings was that while data subjects cannot exercise the right to request suspension of processing for information that has already been pseudonymized (i.e., pseudonymized information), they do possess the right to request prior suspension of pseudonymization. However, the Supreme Court ruled that if pseudonymized information falls under the special provisions governing its processing, the data subject is not entitled to the right to request suspension of pseudonymization under Article 37 of the Act, regardless of whether the information has already been pseudonymized or not. In my view, the Personal Information Protection Act conceptually distinguishes between ‘pseudonymization’ and ‘processing of pseudonymized information,’ and Article 28-2 of the Act, a special provision concerning the processing of pseudonymized information, regulates ‘processing of pseudonymized information.’ Therefore, Article 28-7 of the Act, which deprives data subjects of their right to request suspension of personal information processing as stipulated in Article 37, does not apply to pseudonymization itself. Therefore, the conclusions of the first-instance and second-instance judgments in the case — that the data subject retains the right to request suspension of pseudonymization — are considered reasonable interpretations under the current Personal Information Protection Act. However, regarding the utilization of pseudonymized information, for the Personal Information Protection Act to actively respond to the need for fostering new data-related industries and the industrial sector's requirement for data usage, as considered in the Supreme Court's ruling on the Case, it is necessary to establish technical safeguards against the risk of re-identification of pseudonymized information and to enact legislative supplements based on societal consensus regarding the restriction of data subjects' exercise of their right to self-determination over their personal information in relation to pseudonymization.
정보주체의 인격권과 개인정보처리자의 재산권의 충돌과 조정- ‘가명처리정지요구권’에 관한 대법원 2024다210554 판결을 중심으로 -
이해원 한국재산법학회 2025 재산법연구 Vol.42 No.3
데이터가 경제사회 전 영역의 핵심 가치로 기능하는 디지털 전환 시대에서 자신의 개인정보 처리를 통제하려는 정보주체의 인격권과 정보주체의 개인정보를 처리하여 경제적 이익을 창출하려는 개인정보처리자의 재산권은 필연적으로 충돌한다. 2020년 3월 소위 ‘데이터 3법’ 개정으로 도입된 ‘가명정보(Pseudonymized Information)’ 제도는 이러한 권리 충돌의 최전선에 있다. 개인정보를 처리하여 가명정보로 바꾸는 ‘가명처리(Pseudonymisation)’는 개인정보를 인격권의 영역에서 재산권의 영역으로 이전시키는 지렛대 역할을 하기 때문이다. 따라서 정보주체가 ‘가명처리’ 자체를 중단시킬 수 있는 ‘처리정지요구권’을 갖는지는 두 기본권의 경계를 설정하는 핵심적인 법적 과제라 할 수 있다. 최근 대법원은 정보주체의 가명처리정지요구권을 부정하는 판결을 선고하여 개인정보처리자의 손을 들어 주었다(대법원 2025. 7. 18. 선고 2024다210554 판결, 이하 ‘대상판결’). 그러나 대상판결의 결론은 문리적ㆍ체계적ㆍ연혁적 해석 원칙에 모두 위반될 뿐 아니라, 개인정보가 가명처리되어 가명정보로 이용되는 과정에서 정보주체의 인격권을 일방적으로 희생시키고 개인정보처리자의 재산권에 지나치게 유리하게 기울어진 것이어서 비례의 원칙에도 위배된다. 데이터 3법 이후 정보주체의 동의가 없더라도 개인정보처리자가 적법하게 가명정보를 처리할 수 있는 상황에서, 정보주체의 가명처리정지요구권 행사를 원천 봉쇄하는 대상판결의 결론은 입법자가 개인정보 보호법에 마련하여 둔 이익형량 장치를 무력화시킨다는 점에서도 타당하지 않다. 입법을 통하여 가명정보를 둘러싼 정보주체의 인격권과 개인정보처리자의 재산권이 조화롭게 공존할 수 있는 방향으로 대상판결의 오류가 시정되거나, 아니면 입법자가 대상판결의 결론이 타당하다고 판단한다면 이를 분명히 하는 방향으로 법률을 개정하여 가명처리정지권을 둘러싼 수범자의 법적 안정성과 예측가능성을 보장할 필요가 있다. In the era of digital transformation, where data has become a core value across all sectors of the economy and society, an inevitable conflict arises between the personality rights of data subjects and the property rights of data controllers. The concept of ‘pseudonymized information’, introduced through the March 2020 amendments to the so-called the ‘Three Pillars of Data Acts,’ stands at the forefront of this conflict of rights. This is because ‘pseudonymisation’ —the process of transforming personal information into pseudonymized information— acts as a lever, shifting the data from the domain of personality rights to that of property rights. Consequently, whether a data subject possesses the ‘right to request the suspension of processing’ to halt pseudonymisation itself is a pivotal legal question in defining the boundary between these two legal rights. Recently, the Korean Supreme Court sided with data controllers by delivering a judgment that denies the data subject's right to request the suspension of pseudonymisation (Supreme Court Decision 2024da210554, rendered on July 18, 2025; hereinafter “The Decision”). However, the conclusion of The Decision contravenes established principles of legal interpretation—namely textual, systematic, and historical interpretation. Furthermore, it violates the principle of proportionality, as it unilaterally sacrifices the personality rights of data subjects in the course of pseudonymisation and subsequent use, while disproportionately favoring the property rights of data controllers. In the Three Pillars of Data Acts landscape, where data controllers can lawfully process personal information for pseudonymisation without the data subject's consent, The Decision's conclusion is untenable. By completely foreclosing the data subject's right to request the suspension of such processing, the ruling effectively neutralizes the interest-balancing mechanisms established by the legislature within the Personal Information Protection Act. Legislative action is necessary. Either the error of The Decision should be corrected through new legislation to ensure a harmonious coexistence between the personality rights of data subjects and the property rights of data controllers concerning pseudonymized information, or, if the legislature finds the court's conclusion valid, the law should be amended to explicitly affirm this position. Such clarification is essential to guarantee legal stability and predictability for all parties regarding the right to suspend pseudonymisation.
개인정보 처리정지요구권의 법적 성질과 가명처리 정지요구권 인정 여부 - 서울고등법원 2023. 12. 20. 선고 2023나2009236 판결을 계기로
양소연 대한변호사협회 2024 인권과 정의 Vol.- No.522
개인정보 보호법에 가명정보 특례규정이 도입된 이후 통신서비스이용자들이 통신사를 상대로 사전적 가명처리 정지요구권을 행사하여 제1심 및 항소심에서 청구가 인용되었다. 법원은 ‘가명처리’와 ‘가명정보 처리’를 구별하고, 가명처리를 개인정보 처리의 일종으로 보았으며, ‘가명정보’에 대해서 처리정지요구권 규정을 적용하지 않도록 하는 예외조항이 ‘가명처리’에 대한 정지요구권까지 배제하는 것은 아니라고 판단하였다. 개인정보 보호법은 개인정보자기결정권 보장을 목표로 제정되었지만 개인정보의 보호와 활용 사이에서 적절한 균형을 도모하는 방향으로 개정되어 왔다. 개별조항을 해석할 때에도 데이터 활용의 측면을 고려할 필요가 있다. 개인정보 보호법이 정보주체의 동의를 개인정보 처리의 기본 원칙으로 삼는 동시에 그 밖에 다른 처리근거도 인정하고 있는 점에 비추어 보아도 알 수 있듯이, 모든 개인정보 처리가 오직 정보주체의 의사에 따라서만 이루어지거나 정보주체가 모든 경우에 개인정보 처리의 전체 과정을 통제할 수 있는 것은 아니다. 처리정지요구권은 민법상 권리에 빗대어 보면 인격권에 기초한 금지청구권과 유사한 권리이다. 금지청구권은 상대방의 행동의 자유를 직접 제한하는 것을 정당화할 수 있을 정도의 위법성이 있는 행위에 대해서만 인정된다. 정보주체와 개인정보처리자의 법익 균형을 고려할 때, 처리정지요구권도 위법하거나 적어도 부당한 권리 침해의 개연성이 인정되는 처리에 대해서만 인정되는 것으로 해석하여야 한다. 개인정보의 ‘처리’ 중에서 가명처리는 정보주체의 식별가능성을 낮추어 오히려 처리에 따른 법익 침해 위험성을 낮추는 보호조치에 해당하므로, 개인정보에 대한 적법한 처리 권한을 가진 자가 그 개인정보를 가명처리하는 것은 별도의 근거 없이도 가능하다. 따라서 가명처리에는 일반적으로 부당한 권리 침해의 개연성이 인정될 여지가 없으므로, 대상판결과는 달리 가명처리는 처리정지요구의 대상이 될 수 없다고 보아야 한다. 가명처리된 정보에 개인정보 보호법 제28조의2가 적용됨으로써 증대되는 법익 침해의 위험성은 ‘가명정보 처리’ 단계에서 안전조치의무 등을 통해 통제할 수 있다. The court recently ruled in favor of the data subjects who filed a lawsuit against a telecommunications service provider, seeking a preliminary ban on the pseudonymization of their personal data. While emphasizing the distinction between pseudonymization as a type of data processing and the processing of pseudonymized data, the court decided that the plaintiffs maintain the right to restrict pseudonymization as part of the right to restrict data processing. However, the Personal Information Protection Act should be interpreted in a way that can find a balance between the privacy rights of the data subject and the interests of the processor. The act does not intend all processing to be based solely on the will of the data subject, nor can the data subject control every aspect of the processing without exceptions. The right to restrict processing is similar to the civil law right to restrict infringements on personality rights. The latter applies only to acts with illegality sufficient to justify a restriction on the freedom of the other party's actions. Considering the balance between the interests of the data subject and those of the processor, the right to restrict processing should be interpreted as applicable only to illegal processing, or at least to processing that involves a foreseeable infringement of rights. Pseudonymization is a protective measure that reduces the identifiability of the data subject, lowering the risk of the processing. Therefore, pseudonymization does not require any separate authorization, and thus, there is no situation where pseudonymization itself infringes the rights of the data subject. Consequently, it should be interpreted that the right to restrict processing does not include the right to restrict pseudonymization.
개인정보 보호법 상 가명처리와 개인정보 처리정지요구권의 합리적 해석 ― 대법원 2025. 7. 18. 선고 2024다210554 판결을 중심으로 ―
임용현 ( Lim Yong Hyun ) 연세대학교 법학연구원 2026 연세법현논총 Vol.4 No.2
원고는 피고가 보유한 본인 개인정보를 과학적 연구 등의 목적으로 가명처리한 사실이 있는지 여부에 대한 열람 및 해당 개인정보의 향후 가명처리 정지를 요구하였다. 피고는 개인정보 보호법 제28조의2, 제28조의7을 근거로 같은 법 제37조에서 규정하고 있는 개인정보 처리정지요구권이 적용되지 않아 가명처리 정지요구권이 제한된다며 해당 요구를 거절하였다. 하급심은 가명처리는 개인정보 처리에 해당하며, 가명처리 정지요구권이 정보주체가 가명정보에 대하여 개인정보자기결정권을 행사할 수 있는 유일한 방법이라는 근거로 가명처리 정지요구권을 인정하였다. 그러나 대법원은 개인정보 보호법에서 ‘가명처리’와 ‘처리’를 별도로 규정하고 있는 점, ‘가명처리’는 개인정보에 대한 식별의 위험성을 낮추는 방법이므로 정보주체 권리 또는 사생활 침해의 위험을 발생시킬 수 있는 개인정보의 ‘처리’와는 구별되는 점, 인공지능 등 신기술을 활용한 데이터 이용이 필요한 상황에서 데이터 이용을 활성화하기 위한 가명정보 조항의 입법 취지를 고려해야 한다는 점 등을 이유로 가명처리는 개인정보 처리정지 요구의 대상으로 정한 개인정보 처리에 해당하지 않는다고 판단하였다. 본고에서는 개인정보 보호와 활용의 조화를 이루는 가명처리와 개인정보 처리정지요구권의 합리적인 해석방안을 다음과 같이 제시하고자 한다. 첫째, 개인정보 보호법 상의 ‘처리’와 ‘가명처리’에 대한 체계적 해석, 개인정보 보호법과 다른 법률 간의 정합성, ‘가명처리’에 대한 국제적 규범 등을 고려하면 개인정보 보호법 상 ‘처리’에는 ‘가명처리’가 포함된다고 해석해야 한다. 둘째, 개인정보자기결정권의 본질적인 내용, 불완전한 가명처리로 인한 가명정보의 식별 가능성, 개인정보 보호법 개정 과정 등을 종합적으로 살펴보면 개인정보 처리정지요구권의 대상에 가명처리도 해당된다고 해석해야 한다. 셋째, 가명처리, 가명정보의 개념과 개인정보 보호법 개정의 취지나 목적 등을 고려하면 가명처리에 대해 정보주체의 동의를 요구하는 것은 적절하지 않고 정보주체의 동의 없이 가명정보 처리 뿐만 아니라 가명처리도 할 수 있도록 개인정보 보호법 제28조의2를 개정하여 법적 불확실성을 해소할 필요가 있다. 결국 정보주체에게 ‘가명처리 동의권’이 아닌 ‘가명처리 정지요구권’을 보장함으로써 가명정보에 대한 개인정보자기결정권을 행사할 수 있도록 하는 것이 개인정보 보호와 활용의 조화로운 해석이라고 볼 수 있다. The plaintiff requested access to information regarding whether the defendant had pseudonymized his personal data for scientific research and other purposes, as well as a suspension of any future pseudonymization of his personal data. The defendant rejected the request, arguing that Articles 28-2 and 28-7 of the Personal Information Protection Act (PIPA) exclude pseudonymization from the scope of the right to request suspension of personal data processing under Article 37. Lower courts recognized the right to request suspension of pseudonymization, reasoning that pseudonymization constitutes “processing” of personal data and that such a right is the only means for a data subject to exercise informational self-determination over pseudonymized data. However, the Supreme Court held that pseudonymization does not constitute “processing” subject to a suspension request. Its reasoning included: PIPA separately defines “processing” and “pseudonymization,” pseudonymization reduces rather than creates privacy risks, and the legislative purpose of the pseudonymization provisions is to promote data use―such as for AI and other emerging technologies―where broader data utilization is necessary. This paper proposes the following reasonable interpretive approaches to harmonize personal data protection and data utilization with respect to pseudonymization and the right to request suspension: First, based on systematic interpretation of “processing” and “pseudonymization” under PIPA, consistency with other statutes, and international regulatory trends, pseudonymization should be understood as falling within the meaning of “processing.” Second, considering the essential content of informational self-determination, potential identifiability arising from imperfect pseudonymization, and the legislative history of PIPA, the right to request suspension of processing should be interpreted to include pseudonymization. Third, given the concept and legislative intent of pseudonymization and pseudonymized data, it is inappropriate to require data subject consent for pseudonymization itself. To reduce legal uncertainty, Article 28-2 of PIPA should be amended to explicitly allow pseudonymization and processing of pseudonymized data without data subject consent. Ultimately, ensuring a “right to request suspension of pseudonymization,” rather than a “right to consent to pseudonymization,” is the proper approach to harmonize the protection and utilization of personal data by enabling data subjects to exercise informational self-determination over pseudonymized data.
가명정보의 안전한 처리와 합리적 이용을 위한 균형점 - 데이터3법에 대한 헌법적 평가를 겸하여 -
김송옥(Kim, Song-Ok) 한국공법학회 2020 공법연구 Vol.49 No.2
데이터3법의 개정으로 인해 가장 주목받는 동시에 가장 중요한 이슈는 가명정보의 개념 도입과 가명처리한 정보간의 결합, 이른바 데이터 결합에 관한 명시적 규정을 둔 점이라 할 것이다. 그동안 정부는 가이드라인을 통해 비식별조치를 거친 개인정보의 활용을 장려해 왔으나, 데이터3법의 개정을 통해 그동안 가이드라인의 효력문제와 더불어 가명정보 활용에 제약으로 여겨졌던 여러 불명확한 요소들을 제거하고 무엇보다 가명정보 처리에 대한 명확한 법적 근거를 확보했다는 점에서 그 의의를 찾을 수 있다. 그러나 데이터3법에 대하여 긍정적인 평가만이 존재하는 것은 아니다. 가명정보의 확실한 법적 근거를 바라고 지지해왔던 산업계나 이를 반대하는 시민단체 모두 문제를 제기하고 있기 때문에, 무엇이 문제가 되고 이를 해결하기 위한 접점을 어디로 설정할 것인지 고찰할 필요가 있다. 또한 데이터3법을 비판하면서 그 근거로 해외입법례를 들고 있는데, 간혹 잘못된 소개로 오히려 혼란을 주는 경우도 있으므로 보다 정확한 소개와 분석을 요한다고 하겠다. 따라서 본고에서는 가명정보 및 데이터 결합과 관련하여 일본, 유럽연합, 우리나라의 법률을 비교함으로써 우리 데이터3법이 가명정보의 처리를 지나치게 제한하는 것은 아닌지, 정보주체의 권리들을 제대로 보장하고 있는지, 궁극적으로 데이터3법이 추구해야 할 보호와 이용간의 조화를 달성하고 있는지에 대하여 구체적으로 살펴보았다. 비교법적으로 보면, 우리나라만이 정보주체의 동의 없이 처리할 수 있는 가명정보의 처리 목적을 통계작성, 과학적 연구, 공익적 기록보존의 3가지로 제한하고 있으며, 또한 우리나라만이 데이터 결합을 정부가 지정한 결합전문기관을 통하도록 하고 있다. 그러면서도 정보주체의 권리들과 정보처리자의 의무들을 한 줄의 조항으로 배제 또는 면제하는 유래 없는 보호체계를 채택하고 있다. 이러한 점들은 또한 어떠한 헌법적 평가를 받을 수 있는지, 즉 정보주체의 동의와 개인정보자기결정권의 관계, 형벌법규의 명확성의 원칙, 입법권위임의 법리, 법률간 정합성의 문제 등 다양한 차원에서 접근해보았다. As a result of the revision of 3 Acts regarding to Data, the most notable and important issue is the introduction of the concept of pseudonymous data and the combination of pseudonymous data(also known as data combinations). Before the revision, the government had encouraged the use of personal information through non-identification measures through Guidelines, but this revision can be meaningful in that it has eliminated various unclear factors that have been considered obstacles on the use of pseudonymous data under Guidelines and secured clear legal grounds for processing pseudonymous data. However, there is not only a positive assessment of 3 Acts regarding to Data. As the industry, which had hoped for and supported a clear legal basis for processing pseudonymous data, and civic groups against it are pointing out the problems at the same time, it is necessary to consider what is the problem and how to resolve it. In addition, more accurate introduction and analysis are needed as there are cases where criticism of 3 Acts regarding to Data is often made based on misintroduced laws in other countries. Therefore, this paper contains a specific assessment of whether our 3 Acts regarding to Data excessively restricts the processing of pseudonymous data, whether it properly guarantees the rights of data subjects, and ultimately whether 3 Acts regarding to Data achieves a harmony between protection and use that should be pursued, by comparing the laws of Japan, the European Union, and Korea. According to comparative analysis, Korea is the only country that limits the purpose of processing pseudonymous data to 3: statistical purposes, scientific research purposes and archiving purposes in the public interest. Also, only Korea is required to conduct data combination through a specialized institution designated by the Protection Commission or the head of the related central administrative agency. However, the rights of data subjects and the obligations of data controllers are excluded or exempted through a single line provision. Thus, this paper makes various assessments of these problems on the constitutional levels, especially establishing the relationship between the consent of data subject and Right to the Protection of Personal Data and applying the rule of law.
과학적 연구목적을 위한 개인정보 처리에 관한 비교법적 연구
김현숙 한국정보법학회 2020 정보법학 Vol.24 No.1
2018년에 발효된 EU의 GDPR(General Data Protection Regulation)은 과학적 연구를목적으로 하는 개인정보의 처리에 대하여 특권적 지위를 부여하고 있다. 연구에는 사전 동의를 면제하고 그 밖에도 개인정보 처리자가 준수해야 할 정보주체의 삭제권, 반대권 등 많은 의무를 면제하고 있다. GDPR은 이전의 개인정보 보호규범인 1995년 지침(Data Protection Directive 95/46/EC)에는 존재하지 않았던 “가명처리(pseudonymisation)” 개념을 도입하여, 고도화된 정보통신기술(ICT) 시대에서 개인정보의 식별성을 제거(또는 감소)하여 과학적 연구에 폭넓게 활용될 수 있도록 ‘산업발전’과 ‘정보보호’라는 양 가치의 조화를 도모하였다. 최근 우리나라도 빅데이터, 인공지능 등 ICT기술과 데이터를 활용하여 신산업을 발전시키고자 하는 산업계의 요구에 부응하여, GDPR의 입법례를 참고하여 「개인정보보호법」을 개정하였다. GDPR과 같이 가명처리 개념을 도입하고, 과학적 연구를 목적으로 하는 개인정보 처리에는 사전 동의를 면제하는 등 광범위한 의무의 면제를 두고있다. 그러나 개정법은 과학적 연구에 개인정보를 활용하겠다는 방향만 설정하고 연구자가 어느 범위까지 어떻게 활용해야 하는지에 대해 명확한 답변을 주지 못하고 있어, 이로 인한 해석의 논의가 한참이다. 과학적 연구에 산업적 목적(상업적 통계 포함) 의 연구가 포함되는가에 대한 논의가 그 중심에 있다. 포함한다는 산업계 및 정부의입장에 대하여 시민단체는 정보인권의 심각한 침해를 이유로 반박하고 있다. 개정법의 가명처리와 그 면제를 규정하는 방식에도 해석의 여지가 많다. GDPR과 동일하게개정하였다고 하지만, 양 법의 법체계와 내용이 동일하지 않음에도 불구하고 개정되는 부분만을 가져오다 보니 전체적으로 체계 정합성이 결여되는 문제점을 낳았다. 첫째, 과학적 연구의 동의 면제가 본래목적의 처리와 추가처리 모두에 인정되는 것인지아니면 추가처리에만 인정되는 것인지 명확하지가 않다. 둘째, 본래목적과 추가목적이 양립가능할 때(compatible) 동의 없이 처리가 가능하도록 하는 조항과 가명처리 특례조항과의 연계가 누락되어 있다. 셋째, 정보주체로부터 개인정보를 수집하지 않을경우 가명처리 시의 고지의무를 면제하고 있으나 정보주체로부터 수집한 경우 고지에 대하여는 침묵하고 있다. 넷째, 연구자의 의무면제 항목을 한 조문에서 일률적으로제한하고 있으므로 의무의 성격과 관계없이 무제한적으로 면제하고 있다. 마지막으로, 민감정보와 가명처리와의 관계에 대해서 침묵하고 있어 가명처리만 하면 동의 없이 무제한으로 이용할 수 있는 것처럼 해석될 수 있다. 본고에서는 개정법이 가지고 있는 해석의 모호성과 법의 흠결에 대한 답변을 제시하고자 한다. 그 과정은 개정법이 입법과정에서 많은 부분을 참고한 GDPR의 규정을해석하는 것으로부터 시작하였다. 우리가 GDPR의 제도와 취지를 그대로 받아들이기위해서는, 먼저 GDPR을 정확히 이해한 다음 우리법 체계 및 법 환경에 적합한 제도로 규범화하는 것이 바람직하다고 생각하기 때문이다 EU GDPR(General Data Protection Regulation) which came into force in 2018 grants a privileged position to scientific research. GDPR permits controllers to process personal data for research purposes without the data subject’s prior consent. Further, researchers are given exemptions from a variety of responsibilities within GDPR. GDPR intends to utilize personal data by removing(or reducing) identifiability in connection with data subjects via introducing the concept of “pseudonymisation” which did not exist in Data Protection Directive of 1995, the former data protection rules in the EU. Differently put, research exemption within GDPR leads stakeholders to reconcile opposite two values, “industry innovation” and “data protection” in the advanced ICT era. Recently, Korean PIPA(Personal Information Protection Act) was revised on the basis of GDPR in order to foster new industry by combining data and technologies such as Big Data Analysis and Artificial Intelligence. Similar to GDPR, scientific research occupies a privileged position in the revised PIPA. But, it is uncertain ‘to what extent’ and ‘in what way’ researchers can process personal data exempt from responsibilities within PIPA. Whether ‘research for industrial purposes(including statistics for commercial purposes)’ qualify as scientific research is the center of the debate on uncertainty of revised PIPA. Additionally, there are some issues of interpretation on pseudonymisation and exceptional provisions. While the government authorities announce that PIPA was revised according to GDPR’s pseudonymisation rules, PIPA does not fully reflect and consider GDPR and results in systemized inconsistency within PIPA. This paper intends to give solutions in reference to this ambiguity and deficiency of revised PIPA. My study starts from understanding of GDPR because revised rules of PIPA originates from GDPR. Based upon scrutinizing GDPR and pros and cons on this issue, the paper interprets the reasonable scope of research exemption. On top of that, the paper provides re-revision direction to respond the deficiency of PIPA.
빅데이터 분석기술 활성화를 위한 개인정보보호법의 개선 방안 - EU GDPR과의 비교 분석을 중심으로 -
박노형 ( Nohyoung Park ),정명현 ( Myung-hyun Chung ) 고려대학교 법학연구원 2017 고려법학 Vol.0 No.85
빅데이터 분석기술 차원에서 개인정보의 광범위한 수집과 추가 처리는 대규모의 전자적 감시, 프로파일링 및 개인정보의 공개와 관련하여 심각한 프라이버시 침해 우려를 제기한다. 빅데이터 분석기술이 정보의 최대한의 수집과 활용인 점에서 개인정보보호의 기본원칙 중에서 `개인정보 최소화` 원칙을 위반할 가능성이 높기 때문이다. 빅데이터 분석기술의 활성화를 위하여 개인의 프라이버시와 개인정보보호가 일방적으로 제한되거나 침해될 수 없을 것이고, 동시에 관련 기술과 혁신의 발전이 무조건 제한되거나 침해될 수 없다. 프라이버시와 개인정보보호의 법익과 기술발전에 근거한 빅데이터 분석기술의 활용 사이의 올바른 균형이 요구된다. 한국의 개인정보보호법은 개인정보보호에 관한 일반법으로서 2011년 채택되어 상당히 최근에 제정되었음에도, 빅데이터 분석기술 등 개인정보의 활용 측면에서는 상당히 부정적인 역할을 하는 것으로 비판을 받고 있다. IT강국이라고 자타가 공인하는 한국에서 개인정보보호와 개인정보 활용의 올바른 균형이 상실된 것으로 볼 수 있다. 한국 개인정보보호법의 빅데이터 분석기술의 활성화에 대한 문제는 크게 개인정보의 `목적 외 이용·제공`과 개인정보의 소위 `비식별처리`에 기인하는 것으로 볼 수 있다. 빅데이터 분석기술에서 개인정보가 수집 또는 제공되어 이용되는 과정에서 그 대상인 대량의 개인정보가 원래의 수집 목적으로만 처리될 수 없는 현실적인 한계가 있기 때문이다. 이러한 점에서 개인정보의 특정 개인에 대한 식별성을 제거하는 비식별처리가 빅데이터 분석기술을 위한 모범답안으로서 제시되고 있지만, 일단 비식별처리된 개인정보가 달리 재식별화되는 현실적인 문제가 제기된다. 그럼에도, 개인정보의 목적 외 이용·제공과 비식별처리는 현실적으로 불가피하고, 이들은 개인정보보호를 주된 목적으로 하는 개인정보보호법의 법적 테두리 내에 존재해야 할 것이다. 유럽연합의 `일반개인정보보호규칙`(GDPR)은 가명처리정보와 익명처리정보를 구분하여, 개인정보에 해당하는 가명처리정보는 일정한 법률요건을 충족하는 경우 목적 외 처리로서 허용하고 있다. 빅데이터 분석기술과 개인정보보호의 조화에 관하여 목적 외 처리로서 가명조치를 포함하는 유럽연합의 접근이 보다 현실적이고 법적으로 안정적이라고 판단된다. 특히 가명조치가 익명조치보다 선호되는 것은 가역성이라는 점에서 익명조치도 결코 완전하지 않으며, 또한 익명조치와 달리 가명조치는 여전히 개인정보보호법의 적용 범위 내에 있기 때문이다. 즉, 개인정보보호법의 세계적 추세인 개인정보보호와 개인정보 활용 사이의 균형 추구가 반영될 수 있을 것이다. 2016년 발표된 `개인정보 비식별 조치 가이드라인 -비식별 조치 기준 및 지원·관리체계 안내-`는 익명조치에 집중한 점에서, 또한 보다 정상적인 개인정보보호법의 개정을 `가이드라인`으로 대신하는 점에서 긍정적이라고 볼 수 없다. 개인정보보호법의 목적으로부터 빅데이터 분석기술을 포용까지 동법의 전면적인 개정이 필요할 것이다. The digital economy in the 21st century does have to accommodate the active utilization of personal data through big data analytics. At the same time, the data protection for individuals, who are the basic components of the society being domestic or international, may not be precluded. Accordingly both big data analytics and data protection should go together, and data protection should be integrated in the use of personal data. Big data analytics, however, while aiming at collecting and processing a maximum amount of personal data, is very likely to violate the principle of data minimization, which is a primary principle of data protection. The Personal Information Protection Act(PIPA) of Korea, however, is being criticized for its lack of flexibility in allowing big data analytics, although it was adopted as a general law of data protection very recently, i.e., in 2011. The main difficulty of the PIPA in respect of big data analytics seems to come from the provisions relating to `the use and provision of personal data for purposes other than those in the original collection` and the so-called `de-identification` of personal data. Big data analytics tends to naturally require processing of an enormous amount of personal data so that personal data may not be processed only for the original purposes in collection. De-identification of personal data, in particular anonymisation, is suggested and introduced administratively for the purposes to promote big data analytics by eliminating identifiability of specific individuals. But it cannot avoid a risk of re-identification as technology develops. The approach of the EU to allow pseudonymisation for processing of personal data for the purposes other than those in the original collection seems to be more practically reasonable and legally certain. One of the reasons why pseudonymisation is preferred to anonymisation is that the latter may not be perfect in its possible reversibility, and that the former is still under the scope of the application of data protection law. However, the `de-identification guideline` published in June 2016 by the Korean governments concerned with data protection does not seem to be positive in that it focuses mainly anonymisation and that it lacks a formal legal status. The guideline seems to confuse data processors and also data subjects. The PIPA should be amended at least to include the use of personal data along with data protection in the provision of its purposes and objects and also to allow big data analytics more flexibly by adopting pseudonymisation.