RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    검색결과 좁혀 보기

    선택해제

    오늘 본 자료

    • 오늘 본 자료가 없습니다.
    더보기
    • 무료
    • 기관 내 무료
    • 유료
    • KCI등재

      개인정보보호법상 가명처리정지요구권에 대한 검토* -대법원 2025. 7. 18. 선고 2024다210554 판결-

      이지은 조선대학교 법학연구원 2025 법학논총 Vol.32 No.3

      정보주체의 개인정보에 관한 권리는 인격권의 일종인 개인정보자기결정권을 그 보호법익으로 하고 있다. 개인정보의 하나인 ‘가명정보’와 관련하여, 이동통신서비스 이용자들이 통신회사에 대하여 자신의 개인정보를 개인정보보호법 제28조의2에서 규정하는 가명정보의 처리에 관한 특례를 적용받기 위한 목적, 즉 통계작성, 과학적 연구, 공익적 기록보존의 목적으로 가명처리하지 말 것을 요구한 사안에서 하급심 판결과 대법원 판결은 그 결론은 달리 하였다. 1심 판결과 2심 판결의 취지는 가명처리가 이미 이루어진 정보, 즉 가명정보에 대해서는 정보주체가 처리정지요구권을 행사할 수 없으나, 가명정보의 처리에 관한 특례조항인 법 제28조의2에 따라 정보주체의 동의 없이 가명정보를 처리하기 위하여 가명처리하는 것을 사전에 정지할 수 있는 권리 이른바 ‘가명처리정지요구권’은 정보주체에게 인정된다고 판시하였다. 그러나 대법원은 가명정보가 가명정보의 처리에 관한 특례조항의 적용을 받는 경우라면 가명처리의 전후를 불문하고 정보주체에게 법 제37조에 기한 가명처리정지요구권은 인정되지 않는다는 취지로 판결하였다. 생각건대 개인정보보호법은 ‘가명처리’와 ‘가명정보의 처리’를 개념상 구별하고 있고, 가명정보의 처리에 관한 특례조항인 개인정보보호법 제28조의2는 ‘가명정보의 처리’에 관하여 규정하고 있으므로 그 적용을 전제로 하여 정보주체로부터 법 제37조에서 규정하고 있는 개인정보처리정지요구권을 박탈하는 법 제28조의7은 ‘가명처리’ 그 자체에는 적용되지 않는다고 보아 정보주체에게 가명처리정지요구권을 인정할 수 있다는 대상사안의 1심 판결과 2심 판결의 결론이 현행 개인정보보호법의 해석론으로서 타당하다고 생각한다. 다만, 가명정보의 활용과 관련하여 대상사안의 대법원 판결에서 고려하였던 데이터 관련 신산업 육성과 산업계의 데이터 이용 필요성에 개인정보 보호법이 적극적으로 대응하기 위해서는 가명정보의 재식별화 위험을 대비한 기술적 안전장치 마련, 가명처리에 관한 정보주체의 개인정보자기결정권 행사 제한에 대한 사회구성원들의 합의를 바탕으로 한 입법적 보완이 필요하다고 하겠다. he rights of data subjects regarding their personal information are aimed at protecting the right to self-determination over personal information, which is a type of personality right. Regarding ‘pseudonymized information,’ which is a type of personal information, lower court rulings and the Supreme Court ruling reached different conclusions in a case where mobile communication service users requested that telecommunications companies refrain from pseudonymizing their personal information for the purpose of applying the special provisions on processing pseudonymized information under Article 28-2 of the Personal Information Protection Act, namely for statistical purposes, scientific research purposes, and archiving purposes in the public interest. The essence of the first-instance and second-instance rulings was that while data subjects cannot exercise the right to request suspension of processing for information that has already been pseudonymized (i.e., pseudonymized information), they do possess the right to request prior suspension of pseudonymization. However, the Supreme Court ruled that if pseudonymized information falls under the special provisions governing its processing, the data subject is not entitled to the right to request suspension of pseudonymization under Article 37 of the Act, regardless of whether the information has already been pseudonymized or not. In my view, the Personal Information Protection Act conceptually distinguishes between ‘pseudonymization’ and ‘processing of pseudonymized information,’ and Article 28-2 of the Act, a special provision concerning the processing of pseudonymized information, regulates ‘processing of pseudonymized information.’ Therefore, Article 28-7 of the Act, which deprives data subjects of their right to request suspension of personal information processing as stipulated in Article 37, does not apply to pseudonymization itself. Therefore, the conclusions of the first-instance and second-instance judgments in the case — that the data subject retains the right to request suspension of pseudonymization — are considered reasonable interpretations under the current Personal Information Protection Act. However, regarding the utilization of pseudonymized information, for the Personal Information Protection Act to actively respond to the need for fostering new data-related industries and the industrial sector's requirement for data usage, as considered in the Supreme Court's ruling on the Case, it is necessary to establish technical safeguards against the risk of re-identification of pseudonymized information and to enact legislative supplements based on societal consensus regarding the restriction of data subjects' exercise of their right to self-determination over their personal information in relation to pseudonymization.

    • KCI등재

      개인정보 처리정지요구권의 법적 성질과 가명처리 정지요구권 인정 여부 - 서울고등법원 2023. 12. 20. 선고 2023나2009236 판결을 계기로

      양소연 대한변호사협회 2024 인권과 정의 Vol.- No.522

      개인정보 보호법에 가명정보 특례규정이 도입된 이후 통신서비스이용자들이 통신사를 상대로 사전적 가명처리 정지요구권을 행사하여 제1심 및 항소심에서 청구가 인용되었다. 법원은 ‘가명처리’와 ‘가명정보 처리’를 구별하고, 가명처리를 개인정보 처리의 일종으로 보았으며, ‘가명정보’에 대해서 처리정지요구권 규정을 적용하지 않도록 하는 예외조항이 ‘가명처리’에 대한 정지요구권까지 배제하는 것은 아니라고 판단하였다. 개인정보 보호법은 개인정보자기결정권 보장을 목표로 제정되었지만 개인정보의 보호와 활용 사이에서 적절한 균형을 도모하는 방향으로 개정되어 왔다. 개별조항을 해석할 때에도 데이터 활용의 측면을 고려할 필요가 있다. 개인정보 보호법이 정보주체의 동의를 개인정보 처리의 기본 원칙으로 삼는 동시에 그 밖에 다른 처리근거도 인정하고 있는 점에 비추어 보아도 알 수 있듯이, 모든 개인정보 처리가 오직 정보주체의 의사에 따라서만 이루어지거나 정보주체가 모든 경우에 개인정보 처리의 전체 과정을 통제할 수 있는 것은 아니다. 처리정지요구권은 민법상 권리에 빗대어 보면 인격권에 기초한 금지청구권과 유사한 권리이다. 금지청구권은 상대방의 행동의 자유를 직접 제한하는 것을 정당화할 수 있을 정도의 위법성이 있는 행위에 대해서만 인정된다. 정보주체와 개인정보처리자의 법익 균형을 고려할 때, 처리정지요구권도 위법하거나 적어도 부당한 권리 침해의 개연성이 인정되는 처리에 대해서만 인정되는 것으로 해석하여야 한다. 개인정보의 ‘처리’ 중에서 가명처리는 정보주체의 식별가능성을 낮추어 오히려 처리에 따른 법익 침해 위험성을 낮추는 보호조치에 해당하므로, 개인정보에 대한 적법한 처리 권한을 가진 자가 그 개인정보를 가명처리하는 것은 별도의 근거 없이도 가능하다. 따라서 가명처리에는 일반적으로 부당한 권리 침해의 개연성이 인정될 여지가 없으므로, 대상판결과는 달리 가명처리는 처리정지요구의 대상이 될 수 없다고 보아야 한다. 가명처리된 정보에 개인정보 보호법 제28조의2가 적용됨으로써 증대되는 법익 침해의 위험성은 ‘가명정보 처리’ 단계에서 안전조치의무 등을 통해 통제할 수 있다. The court recently ruled in favor of the data subjects who filed a lawsuit against a telecommunications service provider, seeking a preliminary ban on the pseudonymization of their personal data. While emphasizing the distinction between pseudonymization as a type of data processing and the processing of pseudonymized data, the court decided that the plaintiffs maintain the right to restrict pseudonymization as part of the right to restrict data processing. However, the Personal Information Protection Act should be interpreted in a way that can find a balance between the privacy rights of the data subject and the interests of the processor. The act does not intend all processing to be based solely on the will of the data subject, nor can the data subject control every aspect of the processing without exceptions. The right to restrict processing is similar to the civil law right to restrict infringements on personality rights. The latter applies only to acts with illegality sufficient to justify a restriction on the freedom of the other party's actions. Considering the balance between the interests of the data subject and those of the processor, the right to restrict processing should be interpreted as applicable only to illegal processing, or at least to processing that involves a foreseeable infringement of rights. Pseudonymization is a protective measure that reduces the identifiability of the data subject, lowering the risk of the processing. Therefore, pseudonymization does not require any separate authorization, and thus, there is no situation where pseudonymization itself infringes the rights of the data subject. Consequently, it should be interpreted that the right to restrict processing does not include the right to restrict pseudonymization.

    • 개인정보 보호법 상 가명처리와 개인정보 처리정지요구권의 합리적 해석 ― 대법원 2025. 7. 18. 선고 2024다210554 판결을 중심으로 ―

      임용현 ( Lim Yong Hyun ) 연세대학교 법학연구원 2026 연세법현논총 Vol.4 No.2

      원고는 피고가 보유한 본인 개인정보를 과학적 연구 등의 목적으로 가명처리한 사실이 있는지 여부에 대한 열람 및 해당 개인정보의 향후 가명처리 정지를 요구하였다. 피고는 개인정보 보호법 제28조의2, 제28조의7을 근거로 같은 법 제37조에서 규정하고 있는 개인정보 처리정지요구권이 적용되지 않아 가명처리 정지요구권이 제한된다며 해당 요구를 거절하였다. 하급심은 가명처리는 개인정보 처리에 해당하며, 가명처리 정지요구권이 정보주체가 가명정보에 대하여 개인정보자기결정권을 행사할 수 있는 유일한 방법이라는 근거로 가명처리 정지요구권을 인정하였다. 그러나 대법원은 개인정보 보호법에서 ‘가명처리’와 ‘처리’를 별도로 규정하고 있는 점, ‘가명처리’는 개인정보에 대한 식별의 위험성을 낮추는 방법이므로 정보주체 권리 또는 사생활 침해의 위험을 발생시킬 수 있는 개인정보의 ‘처리’와는 구별되는 점, 인공지능 등 신기술을 활용한 데이터 이용이 필요한 상황에서 데이터 이용을 활성화하기 위한 가명정보 조항의 입법 취지를 고려해야 한다는 점 등을 이유로 가명처리는 개인정보 처리정지 요구의 대상으로 정한 개인정보 처리에 해당하지 않는다고 판단하였다. 본고에서는 개인정보 보호와 활용의 조화를 이루는 가명처리와 개인정보 처리정지요구권의 합리적인 해석방안을 다음과 같이 제시하고자 한다. 첫째, 개인정보 보호법 상의 ‘처리’와 ‘가명처리’에 대한 체계적 해석, 개인정보 보호법과 다른 법률 간의 정합성, ‘가명처리’에 대한 국제적 규범 등을 고려하면 개인정보 보호법 상 ‘처리’에는 ‘가명처리’가 포함된다고 해석해야 한다. 둘째, 개인정보자기결정권의 본질적인 내용, 불완전한 가명처리로 인한 가명정보의 식별 가능성, 개인정보 보호법 개정 과정 등을 종합적으로 살펴보면 개인정보 처리정지요구권의 대상에 가명처리도 해당된다고 해석해야 한다. 셋째, 가명처리, 가명정보의 개념과 개인정보 보호법 개정의 취지나 목적 등을 고려하면 가명처리에 대해 정보주체의 동의를 요구하는 것은 적절하지 않고 정보주체의 동의 없이 가명정보 처리 뿐만 아니라 가명처리도 할 수 있도록 개인정보 보호법 제28조의2를 개정하여 법적 불확실성을 해소할 필요가 있다. 결국 정보주체에게 ‘가명처리 동의권’이 아닌 ‘가명처리 정지요구권’을 보장함으로써 가명정보에 대한 개인정보자기결정권을 행사할 수 있도록 하는 것이 개인정보 보호와 활용의 조화로운 해석이라고 볼 수 있다. The plaintiff requested access to information regarding whether the defendant had pseudonymized his personal data for scientific research and other purposes, as well as a suspension of any future pseudonymization of his personal data. The defendant rejected the request, arguing that Articles 28-2 and 28-7 of the Personal Information Protection Act (PIPA) exclude pseudonymization from the scope of the right to request suspension of personal data processing under Article 37. Lower courts recognized the right to request suspension of pseudonymization, reasoning that pseudonymization constitutes “processing” of personal data and that such a right is the only means for a data subject to exercise informational self-determination over pseudonymized data. However, the Supreme Court held that pseudonymization does not constitute “processing” subject to a suspension request. Its reasoning included: PIPA separately defines “processing” and “pseudonymization,” pseudonymization reduces rather than creates privacy risks, and the legislative purpose of the pseudonymization provisions is to promote data use―such as for AI and other emerging technologies―where broader data utilization is necessary. This paper proposes the following reasonable interpretive approaches to harmonize personal data protection and data utilization with respect to pseudonymization and the right to request suspension: First, based on systematic interpretation of “processing” and “pseudonymization” under PIPA, consistency with other statutes, and international regulatory trends, pseudonymization should be understood as falling within the meaning of “processing.” Second, considering the essential content of informational self-determination, potential identifiability arising from imperfect pseudonymization, and the legislative history of PIPA, the right to request suspension of processing should be interpreted to include pseudonymization. Third, given the concept and legislative intent of pseudonymization and pseudonymized data, it is inappropriate to require data subject consent for pseudonymization itself. To reduce legal uncertainty, Article 28-2 of PIPA should be amended to explicitly allow pseudonymization and processing of pseudonymized data without data subject consent. Ultimately, ensuring a “right to request suspension of pseudonymization,” rather than a “right to consent to pseudonymization,” is the proper approach to harmonize the protection and utilization of personal data by enabling data subjects to exercise informational self-determination over pseudonymized data.

    • 가명처리 처리정지 요구권 배제 판결의 국제인권조약 위반 검토: 대법원 2024다 210554 판결의 ‘가명처리’ 개념을 중심으로

      이승필(Seung-pil Lee) 경희법학연구소 2026 KHU 글로벌 기업법무 리뷰 Vol.19 No.1

      세계적으로 AI(Artificial Intelligence)와 사물인터넷 등이 기술의 핵심으로 부상하고 있는 현대 디지털 시대에서, 인공지능 등의 디지털 기술의 활용, 발전에는 필수적으로 ‘빅데이터’의 이용이 수반된다. 현대사회에서 디지털 기술을 제공하는 기업(개인정보처리자)은 개인들의 개인정보 데이터를 이용하는 것이 필요하므로, 개별 정보주체들에게는 필연적으로 개인정보자기결정권을 비롯한 인격권의 침해 가능성이 발생하게 된다. 다만 개인정보처리자의 개인정보 이용에 있어 개별 정보주체의 일반적인 개인정보는 우리 헌법 제17조에 규정된 사생활의 자유와 비밀 조항을 통하여 소위 ‘프라이버시권’으로 헌법상 보호받고 있으므로, 개인정보처리자인 기업이 기술의 전제가 되는 개인정보들을 수집, 이용하기 위해서는 특정한 개인정보를 익명화(Masking) 처리하여 이를 기업들이 이용할 수 있는 ‘재산으로서의 정보’로 가공하는 과정이 필요하다. 관련하여 대한민국은 「개인정보 보호법」,「정보통신망 이용촉진 및 정보보호 등에 관한 법률」,「신용정보의 이용 및 보호에 관한 법률」, 소위 ‘데이터 3법’을 통하여 데이터 이용에 관한 규제, 개인정보 보호 체계를 관리 감독하고 있고, 특히 데이터 3법 중 개인정보 보호법에서 데이터 활용을 위하여 ‘가명정보(Pseudonymisation)’를 이용할 수 있도록 구체적으로 규정하고 있다. 가명정보는 기업이 이용할 수 있는 일종의 ‘정보재산’으로, 일반인의 개인정보에서 가명 정보로 바뀌는 가명화 과정은 인격권에서 재산권으로 그 정보에 수반되는 권리적 성격이 변화하는 지점이라 할 것이며, 이러한 과정에 대하여는 개인정보 보호법에서 2020년 3월 법률 제16930호 개정을 통하여 제2조 제1호의2 ‘가명처리’로서 입법하여 규율하고 있다. 개인정보 보호법에 따르면 기업은 가명처리 과정 이후의 가명정보를 이용할 수 있도록 보장받고 있으므로, 정보에 대한 권리를 갖는 주체가 개인에서 개인정보처리자로 넘어가게 된다. 이에 가명처리 과정 이후에 다루어지는 가명정보는 필연적으로 개인정보자기결정권과 관련하여 인격권의 침해 소지가 발생하게 된다. 이러한 인격권 침해를 방지하기 위하여, 특히 개인의 개인정보자기결정권을 보장하기 위하여 정보제공자인 개인에게 ‘가명처리’를 중단하여야 할 권리인 ‘처리정지요구권’이 인정되어야 하나, 최근 대법원은 정보주체가 되는 개인의 가명처리에 대한 정지요구권을 부정하는 판결을 선고하여 개인정보처리자의 손을 들어주었다(대법원 2025. 7. 18. 선고 2024다210554 판결). 이에 본 글에서는 이러한 판결의 인격권 침해 여부에 대하여, 국제 인권조약 위반의 측면에서 헌법 제 6조에 따라 국내법과 동등한 효력을 갖는 국제 조약 취지에 부합하도록 합치 해석을 했어야 함에도 이를 간과한 위헌성이 있음을 지적하고자 한다. In the modern digital age, where Artificial Intelligence (AI) and the Internet of Things (IoT) have emerged as core technologies worldwide, the utilization and advancement of digital technologies like AI inherently necessitate the use of ‘Big Data’. In modern society, companies providing digital technologies (personal information processors) require the use of individuals' personal information data. Consequently, this inevitably creates the potential for infringement upon the personal rights of individual data subjects, including their right to self-determination over personal information. However, the general personal information of individual data subjects, as used by personal information processors, is constitutionally protected as the so-called ‘right to privacy’ under Article 17 of the Constitution of the Republic of Korea, which guarantees the freedom and secrecy of private life. Therefore, for companies acting as personal information processors to collect and use the personal information that forms the basis of technology, it is necessary to anonymize (mask) specific personal information and process it into ‘information as property’ that companies can utilize. In this regard, the Republic of Korea manages and supervises regulations on data use and the personal information protection system through the “Personal Information Protection Act,” the “Act on Promotion of Information and Communications Network Utilization and Information Protection,” and the “Act on the Use and Protection of Credit Information,” collectively known as the ‘Data Three Acts.’ Specifically, among these three acts, the Personal Information Protection Act explicitly stipulates the use of ‘pseudonymized information’ for data utilization. Pseudonymized information is a form of ‘information asset’ that businesses can utilize. The process of pseudonymization, where an individual's personal information is transformed into pseudonymized information, represents a shift in the nature of rights associated with that information—from personality rights to property rights. This process is legislatively regulated as ‘pseudonymization’ under Article 2, Paragraph 1-2 of the Personal Information Protection Act, as amended by Act No. 16930 in March 2020. 'Pseudonymization' was legislated and regulated. According to the Personal Information Protection Act, companies are guaranteed the right to use pseudonymized information after the pseudonymization process. Consequently, the subject holding rights over the information shifts from the individual to the personal information processor. Therefore, pseudonymized information handled after the pseudonymization process inevitably carries the potential to infringe upon personality rights related to the right to self-determination over personal information. To prevent such infringement of personality rights, and particularly to safeguard an individual's right to self-determination over their personal information, the individual providing the information should be granted the ‘right to request suspension of processing’—the right to demand cessation of ‘pseudonymization’. However, the Supreme Court recently ruled against the individual data subject's right to request suspension of pseudonymization, siding with the personal information processor (Supreme Court Decision 2024Da210554, rendered July 18, 2025). This article argues that the ruling is unconstitutional. It points out that the court overlooked the need for a constitutional interpretation consistent with the intent of international treaties, which, under Article 6 of the Constitution, have equal force with domestic law. This oversight occurred despite the ruling potentially violating international human rights treaties and infringing upon personal rights.

    • KCI등재

      정보주체의 인격권과 개인정보처리자의 재산권의 충돌과 조정- ‘가명처리정지요구권’에 관한 대법원 2024다210554 판결을 중심으로 -

      이해원 한국재산법학회 2025 재산법연구 Vol.42 No.3

      데이터가 경제사회 전 영역의 핵심 가치로 기능하는 디지털 전환 시대에서 자신의 개인정보 처리를 통제하려는 정보주체의 인격권과 정보주체의 개인정보를 처리하여 경제적 이익을 창출하려는 개인정보처리자의 재산권은 필연적으로 충돌한다. 2020년 3월 소위 ‘데이터 3법’ 개정으로 도입된 ‘가명정보(Pseudonymized Information)’ 제도는 이러한 권리 충돌의 최전선에 있다. 개인정보를 처리하여 가명정보로 바꾸는 ‘가명처리(Pseudonymisation)’는 개인정보를 인격권의 영역에서 재산권의 영역으로 이전시키는 지렛대 역할을 하기 때문이다. 따라서 정보주체가 ‘가명처리’ 자체를 중단시킬 수 있는 ‘처리정지요구권’을 갖는지는 두 기본권의 경계를 설정하는 핵심적인 법적 과제라 할 수 있다. 최근 대법원은 정보주체의 가명처리정지요구권을 부정하는 판결을 선고하여 개인정보처리자의 손을 들어 주었다(대법원 2025. 7. 18. 선고 2024다210554 판결, 이하 ‘대상판결’). 그러나 대상판결의 결론은 문리적ㆍ체계적ㆍ연혁적 해석 원칙에 모두 위반될 뿐 아니라, 개인정보가 가명처리되어 가명정보로 이용되는 과정에서 정보주체의 인격권을 일방적으로 희생시키고 개인정보처리자의 재산권에 지나치게 유리하게 기울어진 것이어서 비례의 원칙에도 위배된다. 데이터 3법 이후 정보주체의 동의가 없더라도 개인정보처리자가 적법하게 가명정보를 처리할 수 있는 상황에서, 정보주체의 가명처리정지요구권 행사를 원천 봉쇄하는 대상판결의 결론은 입법자가 개인정보 보호법에 마련하여 둔 이익형량 장치를 무력화시킨다는 점에서도 타당하지 않다. 입법을 통하여 가명정보를 둘러싼 정보주체의 인격권과 개인정보처리자의 재산권이 조화롭게 공존할 수 있는 방향으로 대상판결의 오류가 시정되거나, 아니면 입법자가 대상판결의 결론이 타당하다고 판단한다면 이를 분명히 하는 방향으로 법률을 개정하여 가명처리정지권을 둘러싼 수범자의 법적 안정성과 예측가능성을 보장할 필요가 있다. In the era of digital transformation, where data has become a core value across all sectors of the economy and society, an inevitable conflict arises between the personality rights of data subjects and the property rights of data controllers. The concept of ‘pseudonymized information’, introduced through the March 2020 amendments to the so-called the ‘Three Pillars of Data Acts,’ stands at the forefront of this conflict of rights. This is because ‘pseudonymisation’ —the process of transforming personal information into pseudonymized information— acts as a lever, shifting the data from the domain of personality rights to that of property rights. Consequently, whether a data subject possesses the ‘right to request the suspension of processing’ to halt pseudonymisation itself is a pivotal legal question in defining the boundary between these two legal rights. Recently, the Korean Supreme Court sided with data controllers by delivering a judgment that denies the data subject's right to request the suspension of pseudonymisation (Supreme Court Decision 2024da210554, rendered on July 18, 2025; hereinafter “The Decision”). However, the conclusion of The Decision contravenes established principles of legal interpretation—namely textual, systematic, and historical interpretation. Furthermore, it violates the principle of proportionality, as it unilaterally sacrifices the personality rights of data subjects in the course of pseudonymisation and subsequent use, while disproportionately favoring the property rights of data controllers. In the Three Pillars of Data Acts landscape, where data controllers can lawfully process personal information for pseudonymisation without the data subject's consent, The Decision's conclusion is untenable. By completely foreclosing the data subject's right to request the suspension of such processing, the ruling effectively neutralizes the interest-balancing mechanisms established by the legislature within the Personal Information Protection Act. Legislative action is necessary. Either the error of The Decision should be corrected through new legislation to ensure a harmonious coexistence between the personality rights of data subjects and the property rights of data controllers concerning pseudonymized information, or, if the legislature finds the court's conclusion valid, the law should be amended to explicitly affirm this position. Such clarification is essential to guarantee legal stability and predictability for all parties regarding the right to suspend pseudonymisation.

    • KCI등재
    • KCI등재

      인공지능 시대 개인정보에 관한 통계처리거부권ㆍ가명처리거부권의 인정가부 - 서울중앙지법 2022. 11. 17. 2021가합509722 판결에 관하여

      전승재 은행법학회 2023 은행법연구 Vol.16 No.1

      Recently, civil society organizations filed a lawsuit against telecommunications companies to prohibit them from pseudonymizing customers’ personal information in the future. The district court ruled that the right to suspension of processing is not applicable to pseudonymized information because it is impossible to find and erase a specific individual's information when the pseudonymization process has already been completed, but the right to suspension of processing is allowed for personal information before pseudonymization. The court also recognized that the right to self-determination of pseudonymized information is guaranteed only by recognizing such a right. However, there are several issues. First, the right to suspension of personal information processing requires the destruction of personal information when it is no longer necessary to process it for reasons such as termination of service. However, the question is whether its scope can be extended to 'processing for service purposes but prohibiting pseudonymization'. Second, when a single organization does not possess big data to respond to the demand for data analysis such as artificial intelligence learning, there are many cases where multiple organizations combine their own data to fill in the gaps. In this case, if the consent of the information subject is not obtained in advance, pseudonymization is the only way to legally combine datasets under the current law. In this case, opting out of pseudonymization has a similar effect to opting out of statistical processing, and it is questionable whether the benefits of such pseudonymization have not been unduly diminished. Third, the effectiveness of various safeguards mandated by the current law to control the risk of re-identification of pseudonymized information has been neglected, and the risk of pseudonymized information has been inflated.

    • KCI등재

      두 사람에 대한 개인정보는 한 사람의 동의에 의하여 처리될 수 있는가

      전승재,김혜성 법무부 2022 선진상사법률연구 Vol.- No.99

      Personal information that records the actions between two people is referred to as “two person’s information” in this paper; for example, conversations, account transactions, and photos taken together. This is information about two people, but it is often processed by one party’s consent. Some claim that such consent is only half consent, indicating that neither party has full consent to the processing of this data. However, its legal nature should be understood as ‘exercise of freedom of action’ rather than ‘consent’ of one party. If one party's exercise of the right to freedom of action is within the legal scope, the other party should consent to the processing of this information. Therefore, the processing of this information becomes legal. The right to self-determination of personal information is not absolutely protected, but ‘the right to be relatively protected in a relationship with others who have the right to use the information’. This paper summarizes the general theory of proportionality surrounding personal information processing, and then looks at some common examples of processing two person’s information we see around us. 두 사람 간 행위의 내용을 기록한 개인정보를 본고에서는 ‘대향(對向)적 개인정보’라 지칭한다. 대화, 송금내역, 함께 찍은 사진 등이 그 예이다. 이는 두 사람에 관한 정보이지만, 한 사람의 동의를 근거로 처리되는 사례가 흔히 있다. 그러한 일방의 동의를 가리켜 ‘반쪽짜리 동의’라 하는 주장도 있으며, 이는 일방 당사자가 이 정보 처리에 관한 완전한 승낙 권한을 갖지 못함을 지적하는 것이다. 그러나 그 법적 성질은 일방의 ‘동의’라기 보다는 ‘행동자유권 행사’로 이해하여야 한다. 일방의 행동자유권 행사가 적법한 범위 내에 있다면 상대방은 이 정보가 처리되는 것을 수인하여야 하기 때문에 이 정보의 처리가 적법하게 되는 구조이다. 이에 대한 법리적 근거는, 개인정보자기결정권이 절대적으로 보호받는 것이 아니라 ‘그 정보를 적법하게 이용할 권리를 갖는 타인과의 관계 속에서 상대적으로 보호받을 수 있는 권리’라는 점이다. 본고에서는 개인정보 처리를 둘러싼 법익형량 일반론을 정리한 후, 이를 토대로 우리 생활 주변의 대향적 개인정보 처리 사례를 하나씩 살펴보고자 한다.

    • KCI등재

      이른바 ‘잊혀질 권리’와 개인정보보호

      이민영(Lee, Min-Yeong) 조선대학교 법학연구원 2013 法學論叢 Vol.20 No.1

      아날로그 시대에는 망각이 일반적이었고 기억이 예외였던 데 반하여, 디지털 혁명으로 인해 기억이 일반적이 되었고 망각이 예외가 되어 버렸다. 최근 프랑스에서는 과거 인터넷 이용자들이 웹상 남겼던 개인정보로 인해 피해를 보는 상황이 빈번히 발생하자 ‘인터넷 이용자들이 과거 웹상 남겼던 개인정보를 삭제할 수 있는, 소위 ‘잊혀질 권리(right to oblivion on the Internet)’의 문제가 대두되었다. 무엇보다 ‘정보주체의 잊혀질 권리(the data subject's right to be forgotten and to erasure)’를 명시하고 있는 유럽연합 규정(EU Regulation)은 제17조에서 1995년 유럽연합 준칙에 따른 개인정보에 대한 삭제요구권을 보다 구체화하여 제3자에 대하여 정보주체의 개인정보에 대한 링크ㆍ복제ㆍ복사의 삭제 요구를 통지하도록 개인정보처리자에게 의무를 부과하는 것을 포함하여 ‘잊혀질 권리’의 제반조건에 대하여 규정하고 있다. 비록 소극적으로 다른 접근방식에 의한 것이지만 이러한 논의는 미국에서도 거론되고 있다. 그럼에도 불구하고 ‘잊혀질 권리’는 개인정보자기결정권의 파생적 권리이므로 이와 같은 헌법상 기본권 혹은 정보인권의 구체화로서 입법적 규율이 선행되어야 한다. 입법방안의 마련은 일반법인 개인정보 보호법 차원의 개정이 아니라 정보통신망 이용촉진 및 정보보호 등에 관한 법률의 개정으로 갈음한다. 인터넷을 통한 온라인 개인정보에 있어 정보주체의 ‘잊혀질 권리’ 보장에 관한 논의 중 그 입법방안은 개별법의 정비로써 입법목적을 구현한다. 다만 그 규율내용에 있어서 현행 법제와 비교해볼 때, 유럽연합 규정의 ‘잊혀질 권리’가 그대로 원용되어 반영될 사항은 아니다. Whereas the oblivion was general and the memory was exceptional in the era of analogue, digital revolution has changed it in reverse. It is the right to oblivion on the Internet that became conspicious against the usual situation which has come into existence from the damage to internet users on account of personal data left on-line in France. Above all, the data subject's right to be forgotten and to erasure is regulated at the Article 17 in the General Data Protection Regulation of European Union on the protection of individuals with regard to the processing of personal data and on the free movement of such data materializing request to carry out the erasure without delay, except to the extent that the retention of the personal data and request to restrict processing of personal data Instead of erasure, originated in the request to erasure regulated in Directive of the European Parliament and the Council on the protection of individuals with regards to the processing of personal data and the free movement of such data in 1995. Nevertheless, the legislative regulation from the viewpoint of concretization on norms guaranteeing fundamental right of the constitution or human rights to information should be precedent, since the right to be forgotten can be explicated as the derived right of information privacy. Consequently, it is not 「Personal Information Protection Act」 but 「Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.」 which must be focused on by the tue-up of the legislative system peculiar to Republic of Korea.

    연관 검색어 추천

    이 검색어로 많이 본 자료

    활용도 높은 자료

    해외이동버튼