RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    검색결과 좁혀 보기

    선택해제
    • 좁혀본 항목 보기순서

      • 원문유무
      • 음성지원유무
      • 원문제공처
        펼치기
      • 등재정보
        펼치기
      • 학술지명
        펼치기
      • 주제분류
        펼치기
      • 발행연도
        펼치기
      • 작성언어

    오늘 본 자료

    • 오늘 본 자료가 없습니다.
    더보기
    • 무료
    • 기관 내 무료
    • 유료
    • KCI등재

      개인정보보호법상 가명처리정지요구권에 대한 검토* -대법원 2025. 7. 18. 선고 2024다210554 판결-

      이지은 조선대학교 법학연구원 2025 법학논총 Vol.32 No.3

      정보주체의 개인정보에 관한 권리는 인격권의 일종인 개인정보자기결정권을 그 보호법익으로 하고 있다. 개인정보의 하나인 ‘가명정보’와 관련하여, 이동통신서비스 이용자들이 통신회사에 대하여 자신의 개인정보를 개인정보보호법 제28조의2에서 규정하는 가명정보의 처리에 관한 특례를 적용받기 위한 목적, 즉 통계작성, 과학적 연구, 공익적 기록보존의 목적으로 가명처리하지 말 것을 요구한 사안에서 하급심 판결과 대법원 판결은 그 결론은 달리 하였다. 1심 판결과 2심 판결의 취지는 가명처리가 이미 이루어진 정보, 즉 가명정보에 대해서는 정보주체가 처리정지요구권을 행사할 수 없으나, 가명정보의 처리에 관한 특례조항인 법 제28조의2에 따라 정보주체의 동의 없이 가명정보를 처리하기 위하여 가명처리하는 것을 사전에 정지할 수 있는 권리 이른바 ‘가명처리정지요구권’은 정보주체에게 인정된다고 판시하였다. 그러나 대법원은 가명정보가 가명정보의 처리에 관한 특례조항의 적용을 받는 경우라면 가명처리의 전후를 불문하고 정보주체에게 법 제37조에 기한 가명처리정지요구권은 인정되지 않는다는 취지로 판결하였다. 생각건대 개인정보보호법은 ‘가명처리’와 ‘가명정보의 처리’를 개념상 구별하고 있고, 가명정보의 처리에 관한 특례조항인 개인정보보호법 제28조의2는 ‘가명정보의 처리’에 관하여 규정하고 있으므로 그 적용을 전제로 하여 정보주체로부터 법 제37조에서 규정하고 있는 개인정보처리정지요구권을 박탈하는 법 제28조의7은 ‘가명처리’ 그 자체에는 적용되지 않는다고 보아 정보주체에게 가명처리정지요구권을 인정할 수 있다는 대상사안의 1심 판결과 2심 판결의 결론이 현행 개인정보보호법의 해석론으로서 타당하다고 생각한다. 다만, 가명정보의 활용과 관련하여 대상사안의 대법원 판결에서 고려하였던 데이터 관련 신산업 육성과 산업계의 데이터 이용 필요성에 개인정보 보호법이 적극적으로 대응하기 위해서는 가명정보의 재식별화 위험을 대비한 기술적 안전장치 마련, 가명처리에 관한 정보주체의 개인정보자기결정권 행사 제한에 대한 사회구성원들의 합의를 바탕으로 한 입법적 보완이 필요하다고 하겠다. he rights of data subjects regarding their personal information are aimed at protecting the right to self-determination over personal information, which is a type of personality right. Regarding ‘pseudonymized information,’ which is a type of personal information, lower court rulings and the Supreme Court ruling reached different conclusions in a case where mobile communication service users requested that telecommunications companies refrain from pseudonymizing their personal information for the purpose of applying the special provisions on processing pseudonymized information under Article 28-2 of the Personal Information Protection Act, namely for statistical purposes, scientific research purposes, and archiving purposes in the public interest. The essence of the first-instance and second-instance rulings was that while data subjects cannot exercise the right to request suspension of processing for information that has already been pseudonymized (i.e., pseudonymized information), they do possess the right to request prior suspension of pseudonymization. However, the Supreme Court ruled that if pseudonymized information falls under the special provisions governing its processing, the data subject is not entitled to the right to request suspension of pseudonymization under Article 37 of the Act, regardless of whether the information has already been pseudonymized or not. In my view, the Personal Information Protection Act conceptually distinguishes between ‘pseudonymization’ and ‘processing of pseudonymized information,’ and Article 28-2 of the Act, a special provision concerning the processing of pseudonymized information, regulates ‘processing of pseudonymized information.’ Therefore, Article 28-7 of the Act, which deprives data subjects of their right to request suspension of personal information processing as stipulated in Article 37, does not apply to pseudonymization itself. Therefore, the conclusions of the first-instance and second-instance judgments in the case — that the data subject retains the right to request suspension of pseudonymization — are considered reasonable interpretations under the current Personal Information Protection Act. However, regarding the utilization of pseudonymized information, for the Personal Information Protection Act to actively respond to the need for fostering new data-related industries and the industrial sector's requirement for data usage, as considered in the Supreme Court's ruling on the Case, it is necessary to establish technical safeguards against the risk of re-identification of pseudonymized information and to enact legislative supplements based on societal consensus regarding the restriction of data subjects' exercise of their right to self-determination over their personal information in relation to pseudonymization.

    • KCI등재

      개인정보 보호법의 문제점과 법적 대안 - 가명정보를 중심으로 -

      윤익준,이부하 경북대학교 IT와 법연구소 2021 IT와 법 연구 Vol.- No.23

      The main contents of the revised “Personal Information Protection Act” are: First, clarification of the conceptual system related to personal information, second, definition of pseudonymized information and establishment of basis for processing, third, reinforcement of personal information controller's responsibility, and fourth, agreement within reasonable scope. Establishment of the basis for collecting, using, and providing personal information that is not available. Fifth, the supervisory body is unified with the Personal Information Protection Committee. The main contents of the revised 「Enforcement Decree of the Personal Information Protection Act」 include first, additional use and provision of personal information, second, procedures for combining pseudonymized information, third, measures to ensure safety of pseudonymized information, and fourth, information on race or ethnicity in sensitive information. Problems of the revised Personal Information Protection Act are: First, the liquidity of the concept of personal information, pseudonymized information, and anonymous information, second, the problem of handling pseudonymized information. (1) Processing of pseudonymized information without the consent of the data subject, (2) handling of pseudonymized information without consent to limited matters, (3) obligation to destroy pseudonymized information, and third, the risk of using pseudonymized information. (1) handling of sensitive information, (2) scope of application of pseudonymized information, (3) There is a problem of combining data with pseudonymized information, and (4) There is a problem with the designation and operation of a specialized data organization. It is necessary to stipulate clear regulations on how public officials or public institutions should pay expenses without cost handling regulations in the pseudonymization and combination processing steps, and in cases where pseudonymized information is provided or provided by pseudonymization. In the case of combining pseudonymized information, if personal information is leaked, there is a possibility of civil and criminal liability, so it is necessary to consider regulations on immunity for this.

    • KCI등재

      가명정보와 개인정보자기결정권 - 동의 없이 가명처리된 민감정보의 상업적 이용은 정당한가? - [대상결정] 헌재 2023. 10. 26. 2020헌마1477, 2021헌마748 결정

      김혜진 헌법재판연구원 2024 헌법재판연구 Vol.11 No.2

      In the era of the Fourth Industrial Revolution, balancing data utilization and personal information protection is of utmost importance. This paper analyzes the current status and issues of legal regulations surrounding the concepts of “pseudonymized information,” “pseudonymisation,” and “processing of pseudonymized information” introduced in the recently amended 3 Data Laws, using recent Constitutional Court rulings as a reference. Pseudonymized information provides a means of processing personal information in a way that does not allow for the identification of specific individuals; however, concerns about the potential for re-identification of data and violations of personal rights arise concurrently. In particular, legal regulations concerning the pseudonymization of sensitive information may restrict the rights of data subjects, potentially leading to legal and ethical issues if adequate protective measures are not established. The recognition of the “right to cease pseudonymization” in court rulings signifies a crucial judgment for the protection of data subjects’ rights to informational self-determination and suggests a necessary legal foundation for balancing public interests in data utilization with the protection of individual rights. Furthermore, the inclusion of “commercial and industrial purposes for the statics and scientific research” in the objectives of “processing pseudonymized information” emphasizes the need for a proper balance between the limitation of data subjects’ rights and those objectives. To identify practical solutions for protecting the interests of data subjects while promoting the advancement of a data economy. Through discussions of interest balancing, it proposes legal approaches and legislative improvements for the safe and effective use of pseudonymized information. Ultimately, it underscores the necessity of proactive legislative efforts to develop a legal framework that adequately protects the rights of data subjects without hindering innovation in data utilization.

    • KCI등재

      가명정보의 활용과 개인정보자기결정권 - 대법원 2025. 7. 18. 선고 2024다210554 판결 -

      윤태영 한국경찰법학회 2026 경찰법연구 Vol.24 No.1

      우리나라 개인정보 보호법 제28조의2에서는 “개인정보처리자는 통계작성, 과학적 연구, 공익적 기록보존 등을 위하여 정보주체의 동의 없이 가명정보를 처리할 수 있다.”고 규정하고 있다. 그런데 최근 이동통신회사와 이동통신 서비스 이용계약을 체결한 이용자들이 자신의 개인정보를 개인정보 보호법 제28조의2에 따라 통계작성 등 목적으로 활용하기 위해 가명처리하여서는 안 된다는 취지로 처리정지를 요구하는 소송을 제기하였다. 이에 대해 제1심과 제2심 법원은 ‘가명처리’와 ‘가명정보 처리’를 구분하면서 개인정보의 가명처리에 대한 처리정지 요구를 제28조의2에 의해 거절할 수는 없다고 하여 원고들의 청구를 인용하였다. 이에 대하여 대법원은 가명처리는 처리정지 요구의 대상이 되지 않는다고 하면서 하급심 판결들과는 정반대의 판단을 하였다. 최근 개인정보 보호법이 개정되었는데, 가명처리는 개인정보의 식별성을 낮춰 재식별 위험을 감소시키는 수단으로서, 개인정보 침해를 완화하면서도 데이터 활용 가치를 유지하기 위한 핵심 제도로 도입되었다. 그러나 개인정보를 계속적으로 보관・가공・결합・연산하는 과정에서, 정보의 활용 가치가 증가하는 만큼 정보주체가 다시 식별될 가능성 또한 완전히 배제할 수는 없다. 이로 인해 가명처리 단계에서 정보주체가 자신의 개인정보에 대한 통제권을 어디까지 행사할 수 있는지가 중요한 쟁점으로 부각된다. 그런데 현행 법규정상 가명정보에까지 처리정지요구권이 인정되는지에 대해 명확하게 규정되어 있지 않고 여전히 해석의 여지를 두고 있다. 이런 가운데 대법원은 대상판결에서 가명정보 처리에 관한 특례규정이 적용되는 경우에는 가명처리의 전후를 불문하고 정보주체에게 개인정보 보호법 제37조에 따른 처리정지요구권을 인정할 수 없다고 판시한 것이다. ‘가명처리’는 가명정보의 활용을 가능하게 하는 기능적으로 불가분의 선행 단계로서, 이것을 지나치게 논리적인 단계문제로서 분절적으로 파악하는 것은 적절하지 않다고 본다. 우리 개인정보 보호법 개정에 많은 영향을 미친 EU ‘일반 개인정보 보호법(GDPR, General Data Protection Regulation)’도 가명처리에 대해서만 규정하고 있다. 아울러 최근 사건(CJEU, EDPS v SRB, C-413/23 P (2025. 9. 4.))에서 유럽사법재판소는 GDPR에 기초하여 가명정보를 개인정보가 아닌 것으로 판단하려는 경향에 있다. 또한 오늘날 우리나라 및 일본에서 개인정보자기결정권을 논하는 경우, 개인정보를 무조건적으로 보호하는 절대적 권리로 보는 견해는 보이지 않고, 정보의 수집・처리・이용이 일상화된 사회에서 개인의 인격적 자율성을 어떠한 방식으로 보장할 것인가라는 문제와 결부되어 이해되어야 한다는 견해가 주를 이룬다. 아울러 처리정지를 인정한다면 재식별을 전제로 한 추가정보의 보관과 활용이 필요해 오히려 보호효과가 약화될 수 있다. 더구나 가명정보 제도를 도입한 이유는 빅데이터 시대에 데이터 활용이 필수적이기 때문인데 처리정지의 인정으로 인한 이익보다 그 이익이 크다고 할 수 있다. 이러한 점을 고려한다면 대법원의 판단은 매우 타당하다고 생각된다. Article 28-2 of the Personal Information Protection Act in Korea stipulates that "the transactor of personal information may process pseudonymized information without the consent of the data subject for statistics preparation, scientific research, and record of public interest." However, users who recently signed a mobile communication service use contract with the mobile communication company filed a lawsuit requesting the suspension of processing personal information. Their assertion is that in accordance with Article 28-2 of the Personal Information Protection Act, personal information should not be pseudonymized in order to use it for purposes such as statistics preparation. In response, the courts of the first and second trials distinguished between "pseudonymization" and "pseudonymized information processing" and cited the plaintiffs' claims, saying that they could not reject the request for suspension of processing of personal information under Article 28-2. In response, the Supreme Court ruled the opposite of the lower court rulings, saying that pseudonymization is not subject to a request for suspension of processing. In a recent amendment of Personal Information Protection Act, pseudonymization was introduced as a key system to reduce the risk of re-identification by lowering the identification of personal information and to maintain the value of data utilization while mitigating the infringement of personal information. However, in the process of continuously storing, processing, combining, and calculating personal information, the value of information utilization must increase and the possibility of re-identifying the data subject cannot be completely excluded. As a result, how far the data subject can exercise control over his or her personal information in the pseudonymization stage emerges as an important issue. However, under the current legal regulations, it is not clearly defined whether the right to request suspension of processing is recognized even for pseudonymized information, and there is still room for interpretation. The Supreme Court, meanwhile, ruled that the data subject cannot be granted the right to request suspension of processing information under Article 37 of the Personal Information Protection Act, regardless of whether pseudonymization is done of not if special provisions on the processing of pseudonym information are applied in the subject case. 'Pseudonymization' is a functionally inseparable preceding step that enables the utilization of pseudonymized information, and it is not considered appropriate to segment this as an overly logical problem. The EU 'General Data Protection Regulation (GDPR)', which has had a great influence on the revision of Korea’s Personal Information Protection Act, also stipulates only the processing of pseudonyms. In addition, in recent cases (CJEU, EDPS v SRB, C-413/23 P (September 4, 2025)), the European Court of Justice tends to judge pseudonym information as non-personal information based on GDPR. In recent years, when discussing the Right to Informational Self-Determination in Korea and Japan, the main view is that there is no absolute right to protect personal information unconditionally, and that it should be understood in conjunction with the question of how to guarantee individual personal autonomy in a society where information collection, processing, and usage are common. If the processing suspension is admitted, the protection effect may weaken because storage and application of additional information is required on the premise of re-identification. Moreover, the benefit of using pseudonymized information is greater than the benefit of the recognition of processing suspension for the reason of adopting pseudonymized information system is that the use of data is essential in the era of big data. Considering these points, the Supreme Court's judgment is considered very valid.

    • 가명처리 처리정지 요구권 배제 판결의 국제인권조약 위반 검토: 대법원 2024다 210554 판결의 ‘가명처리’ 개념을 중심으로

      이승필(Seung-pil Lee) 경희법학연구소 2026 KHU 글로벌 기업법무 리뷰 Vol.19 No.1

      세계적으로 AI(Artificial Intelligence)와 사물인터넷 등이 기술의 핵심으로 부상하고 있는 현대 디지털 시대에서, 인공지능 등의 디지털 기술의 활용, 발전에는 필수적으로 ‘빅데이터’의 이용이 수반된다. 현대사회에서 디지털 기술을 제공하는 기업(개인정보처리자)은 개인들의 개인정보 데이터를 이용하는 것이 필요하므로, 개별 정보주체들에게는 필연적으로 개인정보자기결정권을 비롯한 인격권의 침해 가능성이 발생하게 된다. 다만 개인정보처리자의 개인정보 이용에 있어 개별 정보주체의 일반적인 개인정보는 우리 헌법 제17조에 규정된 사생활의 자유와 비밀 조항을 통하여 소위 ‘프라이버시권’으로 헌법상 보호받고 있으므로, 개인정보처리자인 기업이 기술의 전제가 되는 개인정보들을 수집, 이용하기 위해서는 특정한 개인정보를 익명화(Masking) 처리하여 이를 기업들이 이용할 수 있는 ‘재산으로서의 정보’로 가공하는 과정이 필요하다. 관련하여 대한민국은 「개인정보 보호법」,「정보통신망 이용촉진 및 정보보호 등에 관한 법률」,「신용정보의 이용 및 보호에 관한 법률」, 소위 ‘데이터 3법’을 통하여 데이터 이용에 관한 규제, 개인정보 보호 체계를 관리 감독하고 있고, 특히 데이터 3법 중 개인정보 보호법에서 데이터 활용을 위하여 ‘가명정보(Pseudonymisation)’를 이용할 수 있도록 구체적으로 규정하고 있다. 가명정보는 기업이 이용할 수 있는 일종의 ‘정보재산’으로, 일반인의 개인정보에서 가명 정보로 바뀌는 가명화 과정은 인격권에서 재산권으로 그 정보에 수반되는 권리적 성격이 변화하는 지점이라 할 것이며, 이러한 과정에 대하여는 개인정보 보호법에서 2020년 3월 법률 제16930호 개정을 통하여 제2조 제1호의2 ‘가명처리’로서 입법하여 규율하고 있다. 개인정보 보호법에 따르면 기업은 가명처리 과정 이후의 가명정보를 이용할 수 있도록 보장받고 있으므로, 정보에 대한 권리를 갖는 주체가 개인에서 개인정보처리자로 넘어가게 된다. 이에 가명처리 과정 이후에 다루어지는 가명정보는 필연적으로 개인정보자기결정권과 관련하여 인격권의 침해 소지가 발생하게 된다. 이러한 인격권 침해를 방지하기 위하여, 특히 개인의 개인정보자기결정권을 보장하기 위하여 정보제공자인 개인에게 ‘가명처리’를 중단하여야 할 권리인 ‘처리정지요구권’이 인정되어야 하나, 최근 대법원은 정보주체가 되는 개인의 가명처리에 대한 정지요구권을 부정하는 판결을 선고하여 개인정보처리자의 손을 들어주었다(대법원 2025. 7. 18. 선고 2024다210554 판결). 이에 본 글에서는 이러한 판결의 인격권 침해 여부에 대하여, 국제 인권조약 위반의 측면에서 헌법 제 6조에 따라 국내법과 동등한 효력을 갖는 국제 조약 취지에 부합하도록 합치 해석을 했어야 함에도 이를 간과한 위헌성이 있음을 지적하고자 한다. In the modern digital age, where Artificial Intelligence (AI) and the Internet of Things (IoT) have emerged as core technologies worldwide, the utilization and advancement of digital technologies like AI inherently necessitate the use of ‘Big Data’. In modern society, companies providing digital technologies (personal information processors) require the use of individuals' personal information data. Consequently, this inevitably creates the potential for infringement upon the personal rights of individual data subjects, including their right to self-determination over personal information. However, the general personal information of individual data subjects, as used by personal information processors, is constitutionally protected as the so-called ‘right to privacy’ under Article 17 of the Constitution of the Republic of Korea, which guarantees the freedom and secrecy of private life. Therefore, for companies acting as personal information processors to collect and use the personal information that forms the basis of technology, it is necessary to anonymize (mask) specific personal information and process it into ‘information as property’ that companies can utilize. In this regard, the Republic of Korea manages and supervises regulations on data use and the personal information protection system through the “Personal Information Protection Act,” the “Act on Promotion of Information and Communications Network Utilization and Information Protection,” and the “Act on the Use and Protection of Credit Information,” collectively known as the ‘Data Three Acts.’ Specifically, among these three acts, the Personal Information Protection Act explicitly stipulates the use of ‘pseudonymized information’ for data utilization. Pseudonymized information is a form of ‘information asset’ that businesses can utilize. The process of pseudonymization, where an individual's personal information is transformed into pseudonymized information, represents a shift in the nature of rights associated with that information—from personality rights to property rights. This process is legislatively regulated as ‘pseudonymization’ under Article 2, Paragraph 1-2 of the Personal Information Protection Act, as amended by Act No. 16930 in March 2020. 'Pseudonymization' was legislated and regulated. According to the Personal Information Protection Act, companies are guaranteed the right to use pseudonymized information after the pseudonymization process. Consequently, the subject holding rights over the information shifts from the individual to the personal information processor. Therefore, pseudonymized information handled after the pseudonymization process inevitably carries the potential to infringe upon personality rights related to the right to self-determination over personal information. To prevent such infringement of personality rights, and particularly to safeguard an individual's right to self-determination over their personal information, the individual providing the information should be granted the ‘right to request suspension of processing’—the right to demand cessation of ‘pseudonymization’. However, the Supreme Court recently ruled against the individual data subject's right to request suspension of pseudonymization, siding with the personal information processor (Supreme Court Decision 2024Da210554, rendered July 18, 2025). This article argues that the ruling is unconstitutional. It points out that the court overlooked the need for a constitutional interpretation consistent with the intent of international treaties, which, under Article 6 of the Constitution, have equal force with domestic law. This oversight occurred despite the ruling potentially violating international human rights treaties and infringing upon personal rights.

    • KCI등재

      가명화 개인건강정보 보호 관련 기본권 보장에 관한 연구

      김강한(Kim, Kang Han) 세계헌법학회 한국학회 2021 세계헌법연구 Vol.27 No.2

      데이터 3법이 개정됨에 따라 국내에서 가장 큰 이슈가 되었던 것은 ‘가명정보’의 개념 수용과 가명정보의 처리 및 결합에 관한 사항이었다. 가명정보는 개인정보의 일부를 삭제하거나 일부・전부를 대체하는 방법 등으로 추가 정보 없이는 특정 개인을 식별할 수 없도록 가명처리된 정보이지만, 만약 추가 정보의 사용 또는 결합이 이루어지게 된다면 재식별 가능성이 여전히 남아 있으므로 개인정보에 준하여 보호되는 정보이다. 그러나 우리나라 개인정보보호법에서는 가명정보를 개인정보로서 규율하고 있지만 가명정보의 활용에 대한 규제는 거의 보호영역 밖의 수준에 가깝게 규정하고 있다. 가명정보의 처리에 대해서는 정보주체가 일체 본인의 통제권 및 결정권을 행사할 수 없고, 심지어 개인정보처리자 등의 안전조치 등 의무도 배제되기 때문이다. 이러한 문제는 민감정보인 개인건강정보의 가명처리의 경우에 더 심각해진다. 왜냐하면 개인건강정보는 일반 개인정보보다 정보주체의 사생활에 현저한 침해의 우려가 높은 민감정보로서 우리나라뿐만 아니라 해외 주요 법제에서도 개인건강정보에 대해서는 특별하게 보호하고 있는데, 이러한 개인건강정보도 가명처리의 절차만 거치기만 하면 정보주체의 동의 없이도 공익목적과 상업적 목적으로 이용 또는 제3자 제공이 가능해질 수 있을 뿐만 아니라 가명화된 개인건강정보에 대하여 정보주체는 본인의 통제권을 행사할 수 없게 되기 때문이다. 이는 개인건강정보 자기결정권에 대한 중대한 침해에 해당하는 것으로 이를 해결하기 위해서는 가명화 개인건강정보의 실효적 보호방안이 무엇인지 진지하게 생각해보아야 할 것이다. 이러한 이유로 개인건강정보의 가명처리는 일반 개인정보의 경우보다 엄격하고 까다로운 요건 및 절차에 따라 이루어져야 하며, 이를 위해서는 개인건강정보 보호 및 이용에 관한 특별법(안)을 별도로 마련하여 가명화 개인건강정보의 보호와 활용 간의 균형을 이룰 수 있도록 관련 내용을 보다 구체적으로 규정할 필요가 있다. As the Data 3 Act was amended, the biggest issue in Korea was the acceptance of the concept of ‘pseudonym information’ and the processing and combination of pseudonymous information. Pseudonymized information is information that has been pseudonymized so that a specific individual cannot be identified without additional information, such as by deleting part or replacing part or all of personal information, but if additional information is used or combined, the possibility of re-identification As it still remains, it is information that is protected according to personal information. However, although the Personal Information Protection Act of Korea regulates pseudonymous information as personal information, the regulation on the use of pseudonymous information is almost outside the scope of protection. As for the processing of pseudonymous information, the information subject cannot exercise his or her control and decision-making rights at all, and even the obligations of the personal information controller, such as safety measures, are excluded. This problem becomes more serious in the case of pseudonymization of personal health information, which is sensitive information. Because personal health information is sensitive information that has a higher risk of infringing on the privacy of the information subject than general personal information, personal health information is specially protected not only in Korea but also in major foreign laws. This is because, without the consent of the data subject, it can be used or provided to a third party for public interest and commercial purposes without the consent of the data subject, and the data subject cannot exercise his or her control over pseudonymized personal health information. This is a serious violation of the right to self-determination of personal health information, and in order to solve this problem, it is necessary to seriously consider what is the effective protection method of pseudonymized personal health information. For this reason, pseudonymization of personal health information must be made in accordance with stricter and more stringent requirements and procedures than in the case of general personal information. In order to achieve a balance between protection and utilization, the relevant content needs to be defined more specifically.

    • KCI등재

      가명정보의 재식별 위험과 안전조치 기준의 법적 명확성 ― 2026년 개정 가이드라인의 위험도 판단체계를 중심으로 ―

      엄민수 충남대학교 법학연구소 2026 법학연구 Vol.37 No.3

      가명정보는 「개인정보 보호법」상 개념 정의 자체가 ‘추가 정보와 결합하면 재식별이 가능한’ 정보라는 점에서, 재식별 위험을 구조적으로 내포하고 있다. 2020년 ‘데이터 3법’ 개정은 이러한 가명정보 개념을 도입하면서 정보주체의 동의라는 사전적 보호장치를 후퇴시켰는데, 그 반대급부로 요구되는 안전조치 및 재식별 금지 규정이 실효적으로 작동하는지 여부는 가명정보 제도 전체의 정당성을 좌우하는 핵심적인 문제이다. 본 연구는 「개인정보 보호법」 제28조의2 내지 제28조의7이 구성하는 가명정보 처리 특례의 규범 체계를 분석하고, 재식별 금지 규정(제28조의5)이 ‘알아보기 위한 목적’이라는 재식별 목적 요건을 매개로 한 행위책임 구조를 취함으로써 그 실효성이 안전조치 기준의 명확성에 종속적으로 좌우된다는 점을 확인하였다. 나아가 가명정보 안전조치의 일반적 기준은 법률·대통령령·고시로 이어지는 위임의 연쇄를 통해 확정되나, 개별 가명정보의 위험도 판단과 그에 따른 안전조치 수준의 결정이라는 영역은 법령상 위임의 근거 없이 비구속적인 「가명정보 처리 가이드라인」이 사실상 대체하고 있음을 규명하였다. 이러한 문제의식 위에서 헌법재판소의 법률유보 원칙 및 위임입법의 한계 법리를 기준으로 위임 구조를 단계별로 검토한 결과, 법률 단계에서는 2026년 3월 10일 개정으로 안전조치 대상 침해유형의 문언이 열거식에서 포괄적 표현으로 전환되었고, 대통령령 단계에서는 위험도 판단·안전조치 수준의 결정 영역에 관한 위임 근거가 존재하지 아니하며, 그 공백을 대체하는 가이드라인은 법령보충적 행정규칙의 요건에도 미달함을 확인하였다. 나아가 2026년 3월 개정 가이드라인이 신설한 위험도 판단체계(기본 위험도 판단·사례별 조정·최종 위험도 확정) 역시 불확정개념으로 구성되어 있고 정량적 산정기준의 제시도 명시적으로 유보되어 있어, 법률에서 가이드라인에 이르는 위임의 전 단계에 걸쳐 다층적 불명확성이 중첩적으로 작용하고 있음을 확인하였다. 이어서 EU GDPR·EDPB, 영국 ICO, 일본의 가명가공정보 제도에 대한 비교법적 검토를 통해, 대한민국 법제가 활용범위를 넓히는 대신 사후적 통제에 의존하는 전략을 취하고 있는 만큼 그 통제기준의 명확성에 대한 요구가 결코 낮아질 수 없다는 시사점을 도출하였다. 이를 토대로 본 연구는 위험도 판단 기준에 관한 위임 근거의 신설과 정식 고시 제정, 불확정개념의 유형별 세분화를 통한 최소한의 객관적 지표 도입, 위험성 검토서의 법적 효력 강화, 재식별 시도 금지 규정의 구성요건 명확화라는 네 가지 개선방안을 제시하였다. 본 연구는 아직 시행되지 않은 2026년 개정 법령과 최신 가이드라인을 분석 대상으로 삼음으로써, 가명정보 안전조치 기준의 법적 명확성이라는 문제를 시의성 있게 조명하고, 향후 관련 규범의 정비 방향에 관한 실천적 시사점을 제공하고자 하였다. Under the Personal Information Protection Act (PIPA), the very definition of pseudonymized information—information that can be re-identified if combined with additional information—means that it structurally embeds a risk of re-identification. The 2020 amendment to the three data-related statutes (“Data 3 Acts”) introduced this concept of pseudonymized information while relaxing the ex ante safeguard of data-subject consent. Whether the safety measures and the prohibition on re-identification demanded in return actually operate effectively is therefore a pivotal question that determines the legitimacy of the pseudonymized-information regime as a whole. This study analyzes the normative structure of the special provisions on the processing of pseudonymized information set out in Articles 28-2 through 28-7 of PIPA, and finds that the prohibition on re-identification (Article 28-5) adopts a conduct-liability structure premised on a re-identification-purpose requirement—the purpose of “identifying” a particular individual—so that its effectiveness is contingent upon, and derivative of, the clarity of the safety-measure standards. It further establishes that, while the general standards for the safety measures applicable to pseudonymized information are fixed through a chain of delegation running from the statute to the Presidential Decree and then to the administrative notice (gosi), the domain of assessing the risk level of individual pseudonymized information and determining the corresponding level of safety measures is in fact being supplanted by the non-binding “Guidelines on the Processing of Pseudonymized Information,” without any statutory basis for such delegation. Examining this delegation structure stage by stage against the Constitutional Court's principles of statutory reservation (Gesetzesvorbehalt) and the limits on delegated legislation, the study finds the following. At the statutory level, the March 10, 2026 amendment shifted the wording of the categories of infringement targeted by the safety measures from an enumerative form to a comprehensive expression. At the Presidential Decree level, there is no basis of delegation covering the domain of risk-level assessment and the determination of the level of safety measures; and the Guidelines that fill this gap fall short even of the requirements for a law-supplementing administrative rule. Moreover, the risk-assessment framework newly established by the amended Guidelines of March 2026 (baseline risk-level assessment, case-specific adjustment, and final risk-level determination) is itself composed of indeterminate concepts, and even the presentation of any quantitative calculation standard is expressly reserved—so that a multilayered indeterminacy operates cumulatively across every stage of delegation from the statute down to the Guidelines. A comparative-law review of the EU's GDPR and EDPB framework, the United Kingdom's ICO guidance, and Japan's pseudonymously processed information (kamei kakō jōhō) regime yields the following implication: precisely because the Korean legal framework has chosen a strategy of broadening the scope of use while relying on ex post control, the demand for clarity in the standards of that control can by no means be lowered. On this basis, the study proposes four reform measures: establishing a statutory basis of delegation for the risk-assessment standards together with the enactment of a formal administrative notice; introducing minimal objective indicators by subdividing the indeterminate concepts by type; strengthening the legal effect of the risk-review report; and clarifying the elements of the provision prohibiting attempts at re-identification. By taking as its object of analysis the 2026 amended statute and the latest Guidelines, which have not yet entered into force, this study seeks to shed timely light on the problem of the legal clarity of the safety-measure standards for pseudonymized inform...

    • 개인정보 보호법 상 가명처리와 개인정보 처리정지요구권의 합리적 해석 ― 대법원 2025. 7. 18. 선고 2024다210554 판결을 중심으로 ―

      임용현 ( Lim Yong Hyun ) 연세대학교 법학연구원 2026 연세법현논총 Vol.4 No.2

      원고는 피고가 보유한 본인 개인정보를 과학적 연구 등의 목적으로 가명처리한 사실이 있는지 여부에 대한 열람 및 해당 개인정보의 향후 가명처리 정지를 요구하였다. 피고는 개인정보 보호법 제28조의2, 제28조의7을 근거로 같은 법 제37조에서 규정하고 있는 개인정보 처리정지요구권이 적용되지 않아 가명처리 정지요구권이 제한된다며 해당 요구를 거절하였다. 하급심은 가명처리는 개인정보 처리에 해당하며, 가명처리 정지요구권이 정보주체가 가명정보에 대하여 개인정보자기결정권을 행사할 수 있는 유일한 방법이라는 근거로 가명처리 정지요구권을 인정하였다. 그러나 대법원은 개인정보 보호법에서 ‘가명처리’와 ‘처리’를 별도로 규정하고 있는 점, ‘가명처리’는 개인정보에 대한 식별의 위험성을 낮추는 방법이므로 정보주체 권리 또는 사생활 침해의 위험을 발생시킬 수 있는 개인정보의 ‘처리’와는 구별되는 점, 인공지능 등 신기술을 활용한 데이터 이용이 필요한 상황에서 데이터 이용을 활성화하기 위한 가명정보 조항의 입법 취지를 고려해야 한다는 점 등을 이유로 가명처리는 개인정보 처리정지 요구의 대상으로 정한 개인정보 처리에 해당하지 않는다고 판단하였다. 본고에서는 개인정보 보호와 활용의 조화를 이루는 가명처리와 개인정보 처리정지요구권의 합리적인 해석방안을 다음과 같이 제시하고자 한다. 첫째, 개인정보 보호법 상의 ‘처리’와 ‘가명처리’에 대한 체계적 해석, 개인정보 보호법과 다른 법률 간의 정합성, ‘가명처리’에 대한 국제적 규범 등을 고려하면 개인정보 보호법 상 ‘처리’에는 ‘가명처리’가 포함된다고 해석해야 한다. 둘째, 개인정보자기결정권의 본질적인 내용, 불완전한 가명처리로 인한 가명정보의 식별 가능성, 개인정보 보호법 개정 과정 등을 종합적으로 살펴보면 개인정보 처리정지요구권의 대상에 가명처리도 해당된다고 해석해야 한다. 셋째, 가명처리, 가명정보의 개념과 개인정보 보호법 개정의 취지나 목적 등을 고려하면 가명처리에 대해 정보주체의 동의를 요구하는 것은 적절하지 않고 정보주체의 동의 없이 가명정보 처리 뿐만 아니라 가명처리도 할 수 있도록 개인정보 보호법 제28조의2를 개정하여 법적 불확실성을 해소할 필요가 있다. 결국 정보주체에게 ‘가명처리 동의권’이 아닌 ‘가명처리 정지요구권’을 보장함으로써 가명정보에 대한 개인정보자기결정권을 행사할 수 있도록 하는 것이 개인정보 보호와 활용의 조화로운 해석이라고 볼 수 있다. The plaintiff requested access to information regarding whether the defendant had pseudonymized his personal data for scientific research and other purposes, as well as a suspension of any future pseudonymization of his personal data. The defendant rejected the request, arguing that Articles 28-2 and 28-7 of the Personal Information Protection Act (PIPA) exclude pseudonymization from the scope of the right to request suspension of personal data processing under Article 37. Lower courts recognized the right to request suspension of pseudonymization, reasoning that pseudonymization constitutes “processing” of personal data and that such a right is the only means for a data subject to exercise informational self-determination over pseudonymized data. However, the Supreme Court held that pseudonymization does not constitute “processing” subject to a suspension request. Its reasoning included: PIPA separately defines “processing” and “pseudonymization,” pseudonymization reduces rather than creates privacy risks, and the legislative purpose of the pseudonymization provisions is to promote data use―such as for AI and other emerging technologies―where broader data utilization is necessary. This paper proposes the following reasonable interpretive approaches to harmonize personal data protection and data utilization with respect to pseudonymization and the right to request suspension: First, based on systematic interpretation of “processing” and “pseudonymization” under PIPA, consistency with other statutes, and international regulatory trends, pseudonymization should be understood as falling within the meaning of “processing.” Second, considering the essential content of informational self-determination, potential identifiability arising from imperfect pseudonymization, and the legislative history of PIPA, the right to request suspension of processing should be interpreted to include pseudonymization. Third, given the concept and legislative intent of pseudonymization and pseudonymized data, it is inappropriate to require data subject consent for pseudonymization itself. To reduce legal uncertainty, Article 28-2 of PIPA should be amended to explicitly allow pseudonymization and processing of pseudonymized data without data subject consent. Ultimately, ensuring a “right to request suspension of pseudonymization,” rather than a “right to consent to pseudonymization,” is the proper approach to harmonize the protection and utilization of personal data by enabling data subjects to exercise informational self-determination over pseudonymized data.

    • KCI등재

      빅 데이터(Big Data) 시대 개정 개인정보 보호법에 관한 법적 고찰

      이부하 경북대학교 IT와 법연구소 2020 IT와 법 연구 Vol.0 No.21

      With the revision of the Personal Information Protection Act, the concept of ‘pseudonymized information’, which cannot identify a specific individual without using or combining additional information, was newly established, and it was possible to process pseudonym information without the consent of the data subject. It is meaningful that a legal basis for contributing to the development of the ICT industry was prepared by using such pseudonymized information. The revised Personal Information Protection Act does not apply to information that can no longer be recognized by an individual, ie, ‘anonymous information’ when other information is used when reasonably considering time, cost, and technology. However, the distinction between pseudonymized information and anonymous information is not a definitive concept, but a tentative concept that can be changed depending on the level of technology available at the time of information processing. In the Personal Information Protection Act, ‘scientific research’ is defined as “research that applies scientific methods such as technology development and demonstration, basic research, applied research, and private investment research.” The scope of use of ‘scientific research’ in personal information is unclear. It should be considered that the statistical preparation, scientific research, and preservation of public records recorded in the Personal Information Protection Act are limited to public works or activities for the public good. Between the Personal Information Protection Act and the Credit Information Use and Protection Act, it is limited to writing statistics, scientific research, and preserving records in the public interest to the extent that it can process pseudonymized information without the consent of the data subject or statistics for commercial purposes. There is a difference whether writing and industrial research are also included. The Personal Information Protection Act stipulates that, in relation to relationship with other Acts, “The protection of personal information shall be governed by this Act, except as otherwise specifically provided for in other Acts.” Between the ‘Personal Information Protection Act’ and ‘Bioethics and Safety Act’, ‘Medical Service Act’, and ‘Act on the Protection, Use, etc. of Location Information, there is a question as to which law should be applied first with regard to the application of pseudonymized information processing.

    • KCI등재

      가명정보의 미동의 처리의 기본권 침해 검토

      김희정 ( Kim Hee Jeong ) 단국대학교 법학연구소 2021 법학논총 Vol.45 No.1

      As the 「Personal Information Protection Act」 and 「Act on the Use and Protection of Credit Information」 were revised in 2020, the concept of ‘pseudonym information’ was introduced. ‘Pseudonym information’ refers to information in which the subject of information cannot be identified without additional information by deleting or replacing part of personal information, but the Personal Information Protection Act still classifies it as one of personal information because there is a possibility that the pseudonym information is re-identifiable. It is expected that the use of pseudonym information will expand the range of data use, and the use of big data analysis and artificial intelligence (AI) will create information services in various fields such as transportation, finance, and medical care. In particular, it seems that it will contribute to the creation of a converged information industry that will enable new added value and innovation by combining heterogeneous industrial data. However, it is understood that the introduction of pseudonym information has been so focused on the support of the information industry that the minimum protection as personal information is omitted. In fact, the introduction of pseudonymized information was modeled on the provisions related to’pseudonym processing’ of the EU’s General Data Protection Regulation (GDPR, hereinafter referred to as “GDPR”) There is a significant difference when it comes to the protection of pseudonym information. This study criticizes the fact that the newly introduced pseudonym information system basically excludes the exercise of the data subject’s right to consent and the data subject’s other rights when processing pseudonym information. In addition, while making it possible to combine pseudonymized information of different information controllers regardless of the content and type of information, critically reviewed the regulations that prevented the subject of any objection from being exercised. For this review, a review of the concept of pseudonym information and the status of regulations, comparison with the European GDPR regulations, and an examination of the rules for surplus funding were conducted. In addition, it was judged that the provisions related to pseudonymized information in the Personal Information Protection Act violate the right to self-determination of personal information.

    연관 검색어 추천

    이 검색어로 많이 본 자료

    활용도 높은 자료

    해외이동버튼