
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
정보주체의 인격권과 개인정보처리자의 재산권의 충돌과 조정- ‘가명처리정지요구권’에 관한 대법원 2024다210554 판결을 중심으로 -
이해원 한국재산법학회 2025 재산법연구 Vol.42 No.3
데이터가 경제사회 전 영역의 핵심 가치로 기능하는 디지털 전환 시대에서 자신의 개인정보 처리를 통제하려는 정보주체의 인격권과 정보주체의 개인정보를 처리하여 경제적 이익을 창출하려는 개인정보처리자의 재산권은 필연적으로 충돌한다. 2020년 3월 소위 ‘데이터 3법’ 개정으로 도입된 ‘가명정보(Pseudonymized Information)’ 제도는 이러한 권리 충돌의 최전선에 있다. 개인정보를 처리하여 가명정보로 바꾸는 ‘가명처리(Pseudonymisation)’는 개인정보를 인격권의 영역에서 재산권의 영역으로 이전시키는 지렛대 역할을 하기 때문이다. 따라서 정보주체가 ‘가명처리’ 자체를 중단시킬 수 있는 ‘처리정지요구권’을 갖는지는 두 기본권의 경계를 설정하는 핵심적인 법적 과제라 할 수 있다. 최근 대법원은 정보주체의 가명처리정지요구권을 부정하는 판결을 선고하여 개인정보처리자의 손을 들어 주었다(대법원 2025. 7. 18. 선고 2024다210554 판결, 이하 ‘대상판결’). 그러나 대상판결의 결론은 문리적ㆍ체계적ㆍ연혁적 해석 원칙에 모두 위반될 뿐 아니라, 개인정보가 가명처리되어 가명정보로 이용되는 과정에서 정보주체의 인격권을 일방적으로 희생시키고 개인정보처리자의 재산권에 지나치게 유리하게 기울어진 것이어서 비례의 원칙에도 위배된다. 데이터 3법 이후 정보주체의 동의가 없더라도 개인정보처리자가 적법하게 가명정보를 처리할 수 있는 상황에서, 정보주체의 가명처리정지요구권 행사를 원천 봉쇄하는 대상판결의 결론은 입법자가 개인정보 보호법에 마련하여 둔 이익형량 장치를 무력화시킨다는 점에서도 타당하지 않다. 입법을 통하여 가명정보를 둘러싼 정보주체의 인격권과 개인정보처리자의 재산권이 조화롭게 공존할 수 있는 방향으로 대상판결의 오류가 시정되거나, 아니면 입법자가 대상판결의 결론이 타당하다고 판단한다면 이를 분명히 하는 방향으로 법률을 개정하여 가명처리정지권을 둘러싼 수범자의 법적 안정성과 예측가능성을 보장할 필요가 있다. In the era of digital transformation, where data has become a core value across all sectors of the economy and society, an inevitable conflict arises between the personality rights of data subjects and the property rights of data controllers. The concept of ‘pseudonymized information’, introduced through the March 2020 amendments to the so-called the ‘Three Pillars of Data Acts,’ stands at the forefront of this conflict of rights. This is because ‘pseudonymisation’ —the process of transforming personal information into pseudonymized information— acts as a lever, shifting the data from the domain of personality rights to that of property rights. Consequently, whether a data subject possesses the ‘right to request the suspension of processing’ to halt pseudonymisation itself is a pivotal legal question in defining the boundary between these two legal rights. Recently, the Korean Supreme Court sided with data controllers by delivering a judgment that denies the data subject's right to request the suspension of pseudonymisation (Supreme Court Decision 2024da210554, rendered on July 18, 2025; hereinafter “The Decision”). However, the conclusion of The Decision contravenes established principles of legal interpretation—namely textual, systematic, and historical interpretation. Furthermore, it violates the principle of proportionality, as it unilaterally sacrifices the personality rights of data subjects in the course of pseudonymisation and subsequent use, while disproportionately favoring the property rights of data controllers. In the Three Pillars of Data Acts landscape, where data controllers can lawfully process personal information for pseudonymisation without the data subject's consent, The Decision's conclusion is untenable. By completely foreclosing the data subject's right to request the suspension of such processing, the ruling effectively neutralizes the interest-balancing mechanisms established by the legislature within the Personal Information Protection Act. Legislative action is necessary. Either the error of The Decision should be corrected through new legislation to ensure a harmonious coexistence between the personality rights of data subjects and the property rights of data controllers concerning pseudonymized information, or, if the legislature finds the court's conclusion valid, the law should be amended to explicitly affirm this position. Such clarification is essential to guarantee legal stability and predictability for all parties regarding the right to suspend pseudonymisation.
빅데이터 분석기술 활성화를 위한 개인정보보호법의 개선 방안 - EU GDPR과의 비교 분석을 중심으로 -
박노형 ( Nohyoung Park ),정명현 ( Myung-hyun Chung ) 고려대학교 법학연구원 2017 고려법학 Vol.0 No.85
빅데이터 분석기술 차원에서 개인정보의 광범위한 수집과 추가 처리는 대규모의 전자적 감시, 프로파일링 및 개인정보의 공개와 관련하여 심각한 프라이버시 침해 우려를 제기한다. 빅데이터 분석기술이 정보의 최대한의 수집과 활용인 점에서 개인정보보호의 기본원칙 중에서 `개인정보 최소화` 원칙을 위반할 가능성이 높기 때문이다. 빅데이터 분석기술의 활성화를 위하여 개인의 프라이버시와 개인정보보호가 일방적으로 제한되거나 침해될 수 없을 것이고, 동시에 관련 기술과 혁신의 발전이 무조건 제한되거나 침해될 수 없다. 프라이버시와 개인정보보호의 법익과 기술발전에 근거한 빅데이터 분석기술의 활용 사이의 올바른 균형이 요구된다. 한국의 개인정보보호법은 개인정보보호에 관한 일반법으로서 2011년 채택되어 상당히 최근에 제정되었음에도, 빅데이터 분석기술 등 개인정보의 활용 측면에서는 상당히 부정적인 역할을 하는 것으로 비판을 받고 있다. IT강국이라고 자타가 공인하는 한국에서 개인정보보호와 개인정보 활용의 올바른 균형이 상실된 것으로 볼 수 있다. 한국 개인정보보호법의 빅데이터 분석기술의 활성화에 대한 문제는 크게 개인정보의 `목적 외 이용·제공`과 개인정보의 소위 `비식별처리`에 기인하는 것으로 볼 수 있다. 빅데이터 분석기술에서 개인정보가 수집 또는 제공되어 이용되는 과정에서 그 대상인 대량의 개인정보가 원래의 수집 목적으로만 처리될 수 없는 현실적인 한계가 있기 때문이다. 이러한 점에서 개인정보의 특정 개인에 대한 식별성을 제거하는 비식별처리가 빅데이터 분석기술을 위한 모범답안으로서 제시되고 있지만, 일단 비식별처리된 개인정보가 달리 재식별화되는 현실적인 문제가 제기된다. 그럼에도, 개인정보의 목적 외 이용·제공과 비식별처리는 현실적으로 불가피하고, 이들은 개인정보보호를 주된 목적으로 하는 개인정보보호법의 법적 테두리 내에 존재해야 할 것이다. 유럽연합의 `일반개인정보보호규칙`(GDPR)은 가명처리정보와 익명처리정보를 구분하여, 개인정보에 해당하는 가명처리정보는 일정한 법률요건을 충족하는 경우 목적 외 처리로서 허용하고 있다. 빅데이터 분석기술과 개인정보보호의 조화에 관하여 목적 외 처리로서 가명조치를 포함하는 유럽연합의 접근이 보다 현실적이고 법적으로 안정적이라고 판단된다. 특히 가명조치가 익명조치보다 선호되는 것은 가역성이라는 점에서 익명조치도 결코 완전하지 않으며, 또한 익명조치와 달리 가명조치는 여전히 개인정보보호법의 적용 범위 내에 있기 때문이다. 즉, 개인정보보호법의 세계적 추세인 개인정보보호와 개인정보 활용 사이의 균형 추구가 반영될 수 있을 것이다. 2016년 발표된 `개인정보 비식별 조치 가이드라인 -비식별 조치 기준 및 지원·관리체계 안내-`는 익명조치에 집중한 점에서, 또한 보다 정상적인 개인정보보호법의 개정을 `가이드라인`으로 대신하는 점에서 긍정적이라고 볼 수 없다. 개인정보보호법의 목적으로부터 빅데이터 분석기술을 포용까지 동법의 전면적인 개정이 필요할 것이다. The digital economy in the 21st century does have to accommodate the active utilization of personal data through big data analytics. At the same time, the data protection for individuals, who are the basic components of the society being domestic or international, may not be precluded. Accordingly both big data analytics and data protection should go together, and data protection should be integrated in the use of personal data. Big data analytics, however, while aiming at collecting and processing a maximum amount of personal data, is very likely to violate the principle of data minimization, which is a primary principle of data protection. The Personal Information Protection Act(PIPA) of Korea, however, is being criticized for its lack of flexibility in allowing big data analytics, although it was adopted as a general law of data protection very recently, i.e., in 2011. The main difficulty of the PIPA in respect of big data analytics seems to come from the provisions relating to `the use and provision of personal data for purposes other than those in the original collection` and the so-called `de-identification` of personal data. Big data analytics tends to naturally require processing of an enormous amount of personal data so that personal data may not be processed only for the original purposes in collection. De-identification of personal data, in particular anonymisation, is suggested and introduced administratively for the purposes to promote big data analytics by eliminating identifiability of specific individuals. But it cannot avoid a risk of re-identification as technology develops. The approach of the EU to allow pseudonymisation for processing of personal data for the purposes other than those in the original collection seems to be more practically reasonable and legally certain. One of the reasons why pseudonymisation is preferred to anonymisation is that the latter may not be perfect in its possible reversibility, and that the former is still under the scope of the application of data protection law. However, the `de-identification guideline` published in June 2016 by the Korean governments concerned with data protection does not seem to be positive in that it focuses mainly anonymisation and that it lacks a formal legal status. The guideline seems to confuse data processors and also data subjects. The PIPA should be amended at least to include the use of personal data along with data protection in the provision of its purposes and objects and also to allow big data analytics more flexibly by adopting pseudonymisation.
개정 개인정보 보호법에 대한 검토와 비판: 정보주체의 자기결정권에 대한 사항을 중심으로
오길영 민주주의법학연구회 2020 민주법학 Vol.0 No.73
This article reviews and criticizes the Personal Information Protection Act, which has been recently revised and is expected to be enforced, focusing on revisions related to the information subject’s right to self-determination. The first part of this article is allotted to outlining the major revisions. I analyze the most important contents in this revision, that is, changes in the definition regulations that complement the definition of ‘personal information’ and establish the concepts of ‘pseudonymisation’ and ‘pseudonym information’, expansion of the exception rules by newly introduced compatibility provisions, and new establishment of special provisions regarding the processing of pseudonym information. Based on this analysis, In the middle part of this article I conduct a critical review of the problems arising from this revision. First, I point out the limitations of the definition regulations that complement the personal information definition and that profound interpretation error could be brought by the confusion about conceptual setting of pseudonymisation and pseudonym information. Next, a critical review is conducted on the possibility of misuse of the exception rule, which would result from the simple introduction of the compatibility provision, while neglecting the legitimate interests provisions that has been proved a dead letter. Finally, I criticize the adverse effects of this revision on self-determination. In this issue, I analyze the legislative attitude of the GDPR. GDPR adopts an approach which is completely different from ours, where the rights of the data subject have been completely deprived by new establishment of exception provisions. In the last part of this article, the background of the discussion is briefly explained. I say what is the desirable stance we shall have regarding the provisions of the omission of consent or exception rules, and that the purpose of this revision was an implied acceptance of the limitations of pseudonymisation. In order to facilitate readers’ understanding, I use metaphorical expressions with easy examples. 본고는 최근 개정되어 시행을 앞두고 있는 개인정보 보호법에 대하여 정보주체의 자기결정권과 관련한 개정 내용을 중심으로 검토와 비판을 진행하는 글이다. 글의 전반부에서는 주요한 개정의 내용을 개관하였다. 개인정보의 정의 규정을 보완하고 가명처리와 가명정보의 개념을 신설한 정의 규정의 변화와, 양립가능성 조항을 새로이 도입한 예외규정의 확대, 그리고 가명정보의 처리에 관한 특례 규정의 신설 등 금번 개정에 있어 가장 중요한 내용들을 분석하였다. 글의 중반부에는 금번의 개정에서 비롯된 문제점들에 대한 비판적 검토를 진행하였다. 먼저 해석상의 혼란에 대하여는 보완된 정의 규정의 한계를 지적하고, 가명처리와 가명정보의 개념 설정에 대한 혼란이 가져오는 심대한 해석상의 오류를 지적하였다. 다음으로 사문화되어있는 정당한 이익 조항을 방치한 채로 진행된 양립가능성 조항의 단순 도입이 가져오게 될 예외 조항의 오남용 가능성에 대해 비판적인 검토를 진행하였다. 마지막으로는 금번의 개정이 자기결정권에 미치게 되는 악영향에 대하여 비판하였다. 여기에는 적용배제 규정의 신설로 인해 가명정보에 대한 정보주체의 권리를 완전히 박탈해버린 우리의 경우와, 이에 대해 전혀 다른 방식으로 접근하고 있는 GDPR의 입법태도를 비교․분석하는 방법이 사용되었다. 글의 후반부에는 본문에서 미처 언급하지 못한 논의의 배경을 간략히 설명하였다. 동의 면제 규정이나 예외규정에 대하여 앞으로 우리가 가져야할 바람직한 입장, 그리고 금번의 입법취지가 사실 가명화의 한계에 대한 묵시적 용인이었다는 점, 이 두 가지의 이야기를 제한된 지면에도 불구하고 반드시 밝히고 싶었다. 이해의 편의를 도모하기 위해 쉬운 사례를 들어 은유적으로 표현하였다.
이정념(Lee Jungnyum) 조선대학교 법학연구원 2020 법학논총 Vol.27 No.2
The revised Personal Information Protection Act has been in force since 5 August 2020. Before the act was revised, it gave rise to various criticisms, including that the act vaguely defines the concept of personal information, that the legal basis related to the protection of personal information is distributed in various laws, and that the scope of use of personal information stipulated in the act should be expanded to foster new industries. Following the submission of various legislative proposals to amend the Personal Information Protection Act at the National Assembly, a bill amending the Personal Information Protection Act was finally adopted on 9 January 2020. An important new feature of the revised Personal Information Protection Act is the introduction of the concept of pseudonym information and the expansion of the scope of use of personal information by establishing provisions regarding pseudonymisation. This article focuses on analysing the legal justification of provisions that stipulate exceptions from the application of sanctions for violations of the revised Personal Information Protection Act in the case that the handling or use of pseudonym information violates the act. In detail, this article critically examines the concrete requirements and effects of the various reasons for exceptions from the application of sanctions regulated in Article 28-7 of the revised Personal Information Protection Act. Finally, this article suggests further conditions that should be contained in Article 28-7 to protect the basic rights on personal information of the informational subject.
김나루 ( Kim Na Roo ) 고려대학교 법학연구원 2017 고려법학 Vol.0 No.86
European Commission published the draft of General Data Protection Regulation on January 25 2012 in order to update the legislative system on personal information protection of the European Union(EU). The EU has settled on the final text of its General Data Protection Regulation after four years' debate and it will come into force on May 2018. It’s absolutely necessary for the authorities and companies which will use the personal information of european citizens to sufficiently understand General Data Protection Regulation because they could determine the limitation of legitimate use about personal information and address the problems involved. In addition, it’s meaningful for us to understand personal information protection system of EU in order to establish our environment that protects personal information and encourages to use that at the same time. Therefore, I deal with the fundamental characteristics about legislative system on personal information protection of the European Union and critical changes introduced by General Data Protection Regulation and its implications in this paper. It will come into direct legal effect in all EU member states. Specifically, it extends the range of application, modifies the definition of personal data and introduces the concept of pseudonymisation. It adds new principles regarding the process of personal data and introduces more hurdles around what constitutes a valid consent and the procedure of children’s consent. Moreover, it enhances the rights for individuals and asks data controllers to have more responsibilities for the process of personal information. It also enhances rules for transfers of personal information out of the European Union and introduces a ‘One-Stop Shop’ mechanism. Lastly, it strengthens the sanctions against the infringement of personal information.
개인정보 전송요구권에 대한 연구 - 개인정보보호의 관점에서 바라본 ‘전 분야 마이데이터’의 문제점을 중심으로 -
박가람 성균관대학교 법학연구원 2026 성균관법학 Vol.38 No.2
개인정보보호위원회는 2023년 3월 14일 법 개정을 통하여, ‘개인정보 전송요구권’ 규정을 신설함으로써 ‘전 분야 마이데이터’ 정책의 법적 기반을 마련하였다. ‘개인정보 전송요구권’이란 정보주체가 자신의 개인정보를 본인 또는 제3자에게 전송하여 줄 것을 요구할 수 있는 권리로, 정부는 ‘개인정보 전송요구권’에 기반한 ‘전 분야 마이데이터’ 정책으로 정보주체의 통제권을 강화하는 한편, 데이터 경제의 활성화를 촉진하고, 특정 기업의 데이터 독점을 완화한다는 목표를 가지고 있다. 개인정보보호위원회의 ‘전 분야 마이데이터’에 대한 확고한 의지에도 불구하고, 관련 산업계와 시민단체는 ‘전 분야 마이데이터’의 도입에 반대 목소리를 내고 있다. 해서, 본고에서는 개인정보보호의 관점에서 향후 ‘전 분야 마이데이터’ 정책으로 인하여 발생할 수 있는 문제점을 살펴보고자 한다. 구체적으로, ‘전 분야 마이데이터’ 정책은 ①이용자 데이터를 기반으로 한 가격차별의 문제를 심화시킬 수 있고, ②정보주체의 권리 행사로 인한 제3자 권리 침해의 문제를 야기할 수 있다. 또한, ③‘전 분야 마이데이터’ 정책은 필연적으로 기술적 측면에서 상호운용성을 필요로 함에 따라 정보보안의 위험을 발생시킬 수 있다. 마지막으로, ④가명처리정지요구권에 대한 우리 대법원의 판단에 따르면, 정보주체에게는 보호법상 도출되는 가명처리정지요구권이 인정되지 않는다. 이러한 우리 대법원의 판단하에서 이루어지는 ‘전 분야 마이데이터’ 정책은 기업이 정보주체의 동의없이(정보주체의 통제권이 미치지 않는 영역에서) 가용할 수 있는 데이터의 양을 증대시키는 결과를 가지고 올 수 있는데, 인공지능 기술의 발달과 함께 가명정보의 재식별 위험성, 즉 비식별화 조치에 의문이 제기되는 현시점에서 이를 되돌아볼 필요가 있다. The Personal Information Protection Commission (PIPC) laid the legal foundation for the “all‑sector MyData” policy by amending the Personal Information Protection Act on 14 March 2023 and newly introducing a provision on the “right to request transmission of personal information.” The “right to request transmission of personal information” refers to the right of the data subject to demand that his or her personal information be transmitted to the data subject him‑ or herself or to a third party designated by the data subject. On the basis of this right, the government pursues an “all‑sector MyData” policy with the objectives of strengthening the data subject’s control over personal information, invigorating the data‑driven economy, and mitigating data monopolies held by particular undertakings. Notwithstanding the PIPC’s clear commitment to “all‑sector MyData,” relevant industry actors and civil‑society organisations have voiced opposition to the introduction of the policy. Against this backdrop, this article examines, from the perspective of personal data protection, the potential problems that may arise in the future from the implementation of an “all‑sector MyData” policy. More specifically, first, an “all‑sector MyData” policy may aggravate concerns about price discrimination based on user data. Second, it may give rise to situations in which the exercise of data‑subject rights leads to infringements of third‑party rights. Third, insofar as an “all‑sector MyData” policy necessarily presupposes technical interoperability, it may generate information‑security risks. Finally, according to the position taken by the Korean Supreme Court on the right to request cessation of pseudonymisation, the data subject is not recognised as having a right, derived from the Personal Information Protection Act, to demand the cessation of pseudonymisation. If an “all‑sector MyData” policy is implemented under this judicial interpretation, it may result in an increase in the volume of data that undertakings can use without the data subject’s consentS—that is, in a domain beyond the reach of the data subject’s control. At a time when advances in artificial intelligence have heightened concerns about the re‑identification risks associated with pseudonymised data and cast doubt on the effectiveness of de‑identification measures, it is necessary to revisit this issue.
「개인정보 보호법」상 “가명처리”와 “개인정보 처리정지권” 해석의 합리화 방안 검토 - 서울고등법원 2023나2009236 판결의 내용을 중심으로
김현경 사법발전재단 2024 사법 Vol.1 No.68
In order to facilitate the use of data while protecting the right to self-determination of personal information, the Personal Information Protection Act established Article 28-2 (Processing of Pseudonymized Information), which allows the pseudonymisation of personally identifiable information for limited purposes such as public record-keeping, scientific research, and statistical compilation, without the consent of data subjectst. However, despite the fact that pseudonymisation is an indispensable requirement for the creation of pseudonymized information, the court recently distinguished between ‘pseudonymisation’ and ‘processing of pseudonymized information’ and held that the pseudonymisation of identifiable information does not exclude the right of the information subject to suspend processing. Therefore, the pseudonymisation of personally identifiable information for the limited purposes of Article 28-2 may become impossible due to the exercise of the information subject’s right to suspend processing. This would undermine the effectiveness of Article 28-2, which provides that pseudonymized information may be processed for limited purposes regardless of the data subject’s will, and dilute the legislative intent. This article examines the legal nature of the data subject’s rights and the meaning of the right to suspend processing, and analyzes the issues and problems in court decisions on Article 28-2 and the right to suspension of processing of personal information. It also suggests the desirable interpretation direction of ‘pseudonymisation’ and ‘right to suspension of processing of personal information’ as a solution, and legislative tasks to prevent confusion in interpretation.
과학적 연구목적을 위한 개인정보 처리에 관한 비교법적 연구
김현숙 한국정보법학회 2020 정보법학 Vol.24 No.1
2018년에 발효된 EU의 GDPR(General Data Protection Regulation)은 과학적 연구를목적으로 하는 개인정보의 처리에 대하여 특권적 지위를 부여하고 있다. 연구에는 사전 동의를 면제하고 그 밖에도 개인정보 처리자가 준수해야 할 정보주체의 삭제권, 반대권 등 많은 의무를 면제하고 있다. GDPR은 이전의 개인정보 보호규범인 1995년 지침(Data Protection Directive 95/46/EC)에는 존재하지 않았던 “가명처리(pseudonymisation)” 개념을 도입하여, 고도화된 정보통신기술(ICT) 시대에서 개인정보의 식별성을 제거(또는 감소)하여 과학적 연구에 폭넓게 활용될 수 있도록 ‘산업발전’과 ‘정보보호’라는 양 가치의 조화를 도모하였다. 최근 우리나라도 빅데이터, 인공지능 등 ICT기술과 데이터를 활용하여 신산업을 발전시키고자 하는 산업계의 요구에 부응하여, GDPR의 입법례를 참고하여 「개인정보보호법」을 개정하였다. GDPR과 같이 가명처리 개념을 도입하고, 과학적 연구를 목적으로 하는 개인정보 처리에는 사전 동의를 면제하는 등 광범위한 의무의 면제를 두고있다. 그러나 개정법은 과학적 연구에 개인정보를 활용하겠다는 방향만 설정하고 연구자가 어느 범위까지 어떻게 활용해야 하는지에 대해 명확한 답변을 주지 못하고 있어, 이로 인한 해석의 논의가 한참이다. 과학적 연구에 산업적 목적(상업적 통계 포함) 의 연구가 포함되는가에 대한 논의가 그 중심에 있다. 포함한다는 산업계 및 정부의입장에 대하여 시민단체는 정보인권의 심각한 침해를 이유로 반박하고 있다. 개정법의 가명처리와 그 면제를 규정하는 방식에도 해석의 여지가 많다. GDPR과 동일하게개정하였다고 하지만, 양 법의 법체계와 내용이 동일하지 않음에도 불구하고 개정되는 부분만을 가져오다 보니 전체적으로 체계 정합성이 결여되는 문제점을 낳았다. 첫째, 과학적 연구의 동의 면제가 본래목적의 처리와 추가처리 모두에 인정되는 것인지아니면 추가처리에만 인정되는 것인지 명확하지가 않다. 둘째, 본래목적과 추가목적이 양립가능할 때(compatible) 동의 없이 처리가 가능하도록 하는 조항과 가명처리 특례조항과의 연계가 누락되어 있다. 셋째, 정보주체로부터 개인정보를 수집하지 않을경우 가명처리 시의 고지의무를 면제하고 있으나 정보주체로부터 수집한 경우 고지에 대하여는 침묵하고 있다. 넷째, 연구자의 의무면제 항목을 한 조문에서 일률적으로제한하고 있으므로 의무의 성격과 관계없이 무제한적으로 면제하고 있다. 마지막으로, 민감정보와 가명처리와의 관계에 대해서 침묵하고 있어 가명처리만 하면 동의 없이 무제한으로 이용할 수 있는 것처럼 해석될 수 있다. 본고에서는 개정법이 가지고 있는 해석의 모호성과 법의 흠결에 대한 답변을 제시하고자 한다. 그 과정은 개정법이 입법과정에서 많은 부분을 참고한 GDPR의 규정을해석하는 것으로부터 시작하였다. 우리가 GDPR의 제도와 취지를 그대로 받아들이기위해서는, 먼저 GDPR을 정확히 이해한 다음 우리법 체계 및 법 환경에 적합한 제도로 규범화하는 것이 바람직하다고 생각하기 때문이다 EU GDPR(General Data Protection Regulation) which came into force in 2018 grants a privileged position to scientific research. GDPR permits controllers to process personal data for research purposes without the data subject’s prior consent. Further, researchers are given exemptions from a variety of responsibilities within GDPR. GDPR intends to utilize personal data by removing(or reducing) identifiability in connection with data subjects via introducing the concept of “pseudonymisation” which did not exist in Data Protection Directive of 1995, the former data protection rules in the EU. Differently put, research exemption within GDPR leads stakeholders to reconcile opposite two values, “industry innovation” and “data protection” in the advanced ICT era. Recently, Korean PIPA(Personal Information Protection Act) was revised on the basis of GDPR in order to foster new industry by combining data and technologies such as Big Data Analysis and Artificial Intelligence. Similar to GDPR, scientific research occupies a privileged position in the revised PIPA. But, it is uncertain ‘to what extent’ and ‘in what way’ researchers can process personal data exempt from responsibilities within PIPA. Whether ‘research for industrial purposes(including statistics for commercial purposes)’ qualify as scientific research is the center of the debate on uncertainty of revised PIPA. Additionally, there are some issues of interpretation on pseudonymisation and exceptional provisions. While the government authorities announce that PIPA was revised according to GDPR’s pseudonymisation rules, PIPA does not fully reflect and consider GDPR and results in systemized inconsistency within PIPA. This paper intends to give solutions in reference to this ambiguity and deficiency of revised PIPA. My study starts from understanding of GDPR because revised rules of PIPA originates from GDPR. Based upon scrutinizing GDPR and pros and cons on this issue, the paper interprets the reasonable scope of research exemption. On top of that, the paper provides re-revision direction to respond the deficiency of PIPA.
김정현 숭실대학교 법학연구소 2020 法學論叢 Vol.46 No.-
빅데이터 시대에 개인정보의 보호와 개인정보의 활용은 충돌이 불가피하다. 빅데이터 산업을 활성화하기 위해서 개인정보를 이용하는 것은 필수적이기 때문이다. 현행법에 따를 경우 개인정보를 활용하는 데 제약조건이 많아서 개인정보 보호관련 법제에 대한 개선이 필요하다는 주장이 힘을 얻고 있는 형국이다. 이러한 주장에 바탕해 국회는 이른바 ‘데이터 3법’을 개정하였다. 법개정을 통해 빅데이터 산업 활성화의 제도적 기반을 마련하겠다는 것이다. 개정법은 가명처리와 가명정보를 규정하여 빅데이터 시대에 신산업 육성의 토대를 구축했다. 그러나 민감정보는 더욱 강하게 보호해야 한다. 따라서 가명정보의 정의규정에서 민감정보를 제외하거나 민감정보가 가명처리될 때에는 정보주체의 별도의 동의를 얻도록 명확하게 규정하는 추가적인 법개정이 필요하다. 법개정은 이제 시작이다. 비판과 불신을 불식시킬 수 있도록 지속적인 논의가 있어야 하고, 필요한 경우에는 입법적 조치가 계속적으로 있어야 한다. 기술개발이 급격하게 이루어지는 분야이기 때문이다. 법제도가 기술변화를 이끌어가진 못하더라도, 기술변화에 대응할 수는 있어야 한다. In the era of big data, the protection of personal information and the use of personal information are bound to conflict. It is essential to use personal information to boost the big data industry. Under the current law, there are many constraints on the use of personal information, which has encouraged calls for improvement in the privacy-related legislation. Based on this argument, the National Assembly revised the so-called “Data 3 Act”. It aims to lay the institutional foundation for revitalizing the big data industry through the revision of laws. The revised law established the foundation for fostering new industries in the era of big data by stipulating pseudonymisation and pseudonymised information. However, sensitive information should be protected more strongly. Therefore, an additional amendment to the Act that clearly stipulates that a separate consent of the information subject is obtained when the sensitive information is excluded from the definition of pseudonymised information or when the sensitive information is processed under an assumed name. The law revision is just beginning. There should be ongoing discussions to dispel criticism and distrust, and if necessary, there should be continuous legislative action. This is because technology development is an area that takes place rapidly. Even if the legislation does not lead to technology change, it should be able to respond to technology change.
동의 없이 가명화한 개인정보의 사용은 정당한가?: IRB의 승인도 정보 주체의 동의도 없는, 개인정보의 2차적 연구 사용의 문제
최경석 이화여자대학교 생명의료법연구소 2022 Asia Pacific Journal of Health Law & Ethics Vol.16 No.1
The recent development of big data technology has increased our interest in collecting, storing, and using personal information like genetic or health information in the use of health and medical data. The ethical principle to obtaining informed consent has been observed in bioethics for human subject research with the exceptional allowance to waive informed consent through the review of IRB. However, Europe’s GDPR allows to use personal information pseudonymized without informed consent from or notification to data subject for the the secondary use like public record, scientific or historic research, or statistics although respecting the ethical principle to obtain informed consent. Similarly, Personal Information Protection Act in Korea allows to use the personal information with the pseudonymisation for the secondary use without consent. However, these have the following problems. First, GDPR’s requirement for the exempt from notification to data subject cannot be considered to be close to the criteria for waiving an informed consent, which have been adopted in bioethics. Second, unlike GDPR, there is no regulation in Personal Information Protection Act to indicate the criteria for the secondary use of the collected personal information without the notification to data subject. Third, there is no clear regulation to give a controller, who determines the purposes and means of the processing of personal data, the authority to pseudonymize the already-collected personal information without informed consent. Fourth, GDPR has the regulation to give a controller the authority to pseudonymize personal information without consent. However, its theoretical ground is too weak. Public good may be a reason to support such a secondary use. This reason cannot be a sufficient one because the concept of public good is vague. Restriction on right to self-determination of date subject for public good may distrupt trust building necessary to the improvement in using data. In order to overcome the problems mentioned earlier, I argue that the introduction of blanket consent for secondary use into Bioethics and Safety Act in Korea is needed as observed in the revision of 45 CFR 46 in U.S.A. 최근 빅데이터 기술의 발달로 보건의료 데이터 활용의 영역에서는 유전정보, 건강정보와 같은 개인정보의 수집과 축적 및 이용에 대한 관심이 더욱 증대되고 있다. 인간대상연구와 관련하여 생명윤리의 영역에서는 연구대상자로부터의 동의 획득이란 윤리 원칙을 존중해 왔으며, 동의 획득이 곤란한 경우에는 예외적으로 IRB의 심의를 거쳐 동의 획득을 면제하였다. 유럽의 GDPR 은 동의 획득이나 통보라는 원칙을 존중하고는 있지만, 공익적 기록이나 과학적 연구나 역사적 연구, 또는 통계 목적 등과 같은 목적에는 동의나 통보 없이도, 수집된 정보를 2차적으로 사용할 수 있도록 허용하고 있다. 우리나라의 개인정보보호법은 상기한 목적의 경우 가명처리를 필수요 건으로 정보 주체의 동의 없는 2차적 사용을 허용하고 있다. 하지만 이러한 정보 이용에는 다음과 같은 문제점이 있다. 첫째, GDPR은 정보 주체의 통보라는 원칙의 예외 조건을 두고 있지만 그것이 생명윤리 분야에서 축적된 원칙인 IRB의 동의 획득 면제 승인에 따르는 것이라고 보기 어렵다. 둘째, 우리나라의 개인정보보호법은 GDPR과는 달리 통보의 예외 조건과 같은 통보 없이, 수집된 정보를 2차적으로 사용하는 기준에 대한 규정이 없다. 셋째, 우리나라의 개인정보보호법은 정보 주체의 동의 없는 가명처리의 권한을 개인정보처리자에게 부여하는 명문의 규정이 존재하지 않는다. 넷째, GDPR은 정보 주체에게 동의 없는 가명처리의 권한을 개인정보처리자에게 부여하는 조항은 있지만, 이 조항을 정당화하는 이론적 근거가 빈약하다. 공익이 하나의 근거가 될 수 있지만, 공익 개념의 모호성으로 인해 충분한 근거가 되기 어렵다. 공익을 명분으로 정보 주체 의 자기결정권을 제한하는 것은 정보 이용의 활성화를 위해 필수적인 신뢰 구축을 저해할 수 있다. 따라서 열거한 문제점을 극복하기 위해서는 미국의 45 CFR 46의 개정에서 확인할 수 있듯이, 2차적 사용에 대해 포괄 동의를 획득하는 방안을 좀 더 구체적으로 생명윤리법에 도입할 필요가 있다.