RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    마이데이터(MyData) 서비스 활용실태 분석을 통한 개선방안 연구 = Research on improvement measures through analysis of MyData service utilization status.

    한글로보기

    https://www.riss.kr/link?id=T17380413

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    4차 산업혁명과 데이터 경제의 부상으로 개인을 둘러싼 데이터의 수집·이 용·결합이 폭발적으로 증가하면서, 데이터 거버넌스와 개인정보 자기결정 권 보장은 단순한 기술·산업 정책을 넘어 민주주의와 기본권 보장의 핵심 과제로 부상하고 있다. 디지털 플랫폼과 인공지능 기술이 고도화될수록, 개 인은 자신의 데이터가 어떤 경로를 통해 수집되고 어떤 목적을 위해 활용되 며, 누가 그 데이터를 통제하는지 파악하기 점점 더 어려워지고 있다. 이러 한 환경에서 마이데이터(MyData)는 기업·기관이 독점적으로 보유하던 개인 정보에 대한 통제권을 정보주체에게 재부여하고, 정보주체가 자신의 데이터 이동과 활용을 직접 결정할 수 있도록 하는 새로운 데이터 거버넌스 패러다 임으로 이해된다. 우리나라는 신용정보법 개정을 통한 금융분야 마이데이터 제도 도입을 시작 으로, 2023년 개인정보 보호법 전면 개정과 2024년 시행령 개정을 통해 금 융·공공·의료·통신 등 모든 분야에 적용 가능한 개인정보 전송요구권을 도입하였다. 이는 특정 업권에 국한된 부분적 제도 개선이 아니라, 데이터 처리 구조 전반을 기업·기관 중심에서 정보주체 중심으로 전환하려는 큰 흐름의 일환이라는 점에서 의미가 크다. 특히 금융 마이데이터를 통해 축적 된 경험과 인프라가 향후 의료·헬스케어 및 공공 행정 분야로 확산되면서, 마이데이터 제도는 데이터 경제의 핵심 인프라로서 그 중요성이 더욱 커지 고 있다. 본 논문은 이러한 제도적 변화 속에서 국내외 마이데이터 서비스의 활용 실 태와 관련 법·제도의 발전 과정을 체계적으로 분석하고, 제도의 실효성을 저해하는 구조적 문제점과 법적·기술적 한계를 도출한 다음, 보다 안전하 고 활용도 높은 마이데이터 서비스 모델과 법제 개선 방향을 제시하는 것을 목적으로 한다. 특히, 금융 분야에서 먼저 도입·정착되고 있는 마이데이터 사업의 경험을 출발점으로 삼아, 의료·헬스케어 및 공공 행정 분야로의 확 장 가능성과 그에 따른 위험 요소, 규범적 쟁점을 심층적으로 검토한다. 연구방법으로는 국내외 선행연구 및 학위논문, 정책보고서, 입법자료, 감독 당국 보도자료 등을 폭넓게 검토하는 문헌연구를 기본 축으로 삼고, 금융· 의료 분야 중심의 사례연구를 병행하였다. 또한 관련 법령의 조문 분석과 더불어, 마이데이터 전송 프로세스에 활용되는 API 구조, 인증·인가 방식, 암호화 기술 등 기술적 요소를 함께 살펴봄으로써 법·제도·기술의 연계 구조를 종합적으로 파악하고자 하였다. 분석 결과, 첫째, 개인정보 보호법·신용정보법·전자정부법·민원처리법 등 개별 법률에 분산된 전송요구권 규정과 의료법·저작권법 등 특별법 간의 체계 정합성이 충분히 확보되지 않아 제도적 불확실성이 크다는 점이 드러 났다. 둘째, 의료 마이데이터의 경우 환자 정보의 민감성과 진료기록 관리 의무, 데이터베이스 제작자의 권리가 중첩되면서 전송요구를 거부할 여지가 존재한다는 문제가 확인되었다. 셋째, API 방식을 통한 데이터 전송과 통합 인증 도입에도 불구하고 도입 초기부터 반복적으로 발생한 정보 노출 및 오 류 사례는 운영 리스크 대응 체계와 보안 거버넌스의 미흡함을 보여준다. 이에 본 논문은 개선 방안으로 개인정보 보호법 중심의 전송요구권 일반법 체계 구축, 의료법 개정 및 의료 마이데이터 전용 가이드라인 마련, 저작권 법상 데이터베이스 제작자 권리 예외 신설, Kerberos 기반 통합인증(SSO)을 중심으로 한 보안체계 강화 등을 제안한다. 나아가 정보주체의 이해가능성 을 높이기 위한 동의 화면 표준화, 이용자 권리 교육 강화, 데이터 처리 전 과정의 투명성 제고와 같은 소프트 측면의 거버넌스 개선도 함께 강조함으 로써, 마이데이터 제도가 실질적인 권리 보장과 산업 혁신을 동시에 달성할 수 있는 방향을 모색한다.
    번역하기

    4차 산업혁명과 데이터 경제의 부상으로 개인을 둘러싼 데이터의 수집·이 용·결합이 폭발적으로 증가하면서, 데이터 거버넌스와 개인정보 자기결정 권 보장은 단순한 기술·산업 정책을 �...

    4차 산업혁명과 데이터 경제의 부상으로 개인을 둘러싼 데이터의 수집·이 용·결합이 폭발적으로 증가하면서, 데이터 거버넌스와 개인정보 자기결정 권 보장은 단순한 기술·산업 정책을 넘어 민주주의와 기본권 보장의 핵심 과제로 부상하고 있다. 디지털 플랫폼과 인공지능 기술이 고도화될수록, 개 인은 자신의 데이터가 어떤 경로를 통해 수집되고 어떤 목적을 위해 활용되 며, 누가 그 데이터를 통제하는지 파악하기 점점 더 어려워지고 있다. 이러 한 환경에서 마이데이터(MyData)는 기업·기관이 독점적으로 보유하던 개인 정보에 대한 통제권을 정보주체에게 재부여하고, 정보주체가 자신의 데이터 이동과 활용을 직접 결정할 수 있도록 하는 새로운 데이터 거버넌스 패러다 임으로 이해된다. 우리나라는 신용정보법 개정을 통한 금융분야 마이데이터 제도 도입을 시작 으로, 2023년 개인정보 보호법 전면 개정과 2024년 시행령 개정을 통해 금 융·공공·의료·통신 등 모든 분야에 적용 가능한 개인정보 전송요구권을 도입하였다. 이는 특정 업권에 국한된 부분적 제도 개선이 아니라, 데이터 처리 구조 전반을 기업·기관 중심에서 정보주체 중심으로 전환하려는 큰 흐름의 일환이라는 점에서 의미가 크다. 특히 금융 마이데이터를 통해 축적 된 경험과 인프라가 향후 의료·헬스케어 및 공공 행정 분야로 확산되면서, 마이데이터 제도는 데이터 경제의 핵심 인프라로서 그 중요성이 더욱 커지 고 있다. 본 논문은 이러한 제도적 변화 속에서 국내외 마이데이터 서비스의 활용 실 태와 관련 법·제도의 발전 과정을 체계적으로 분석하고, 제도의 실효성을 저해하는 구조적 문제점과 법적·기술적 한계를 도출한 다음, 보다 안전하 고 활용도 높은 마이데이터 서비스 모델과 법제 개선 방향을 제시하는 것을 목적으로 한다. 특히, 금융 분야에서 먼저 도입·정착되고 있는 마이데이터 사업의 경험을 출발점으로 삼아, 의료·헬스케어 및 공공 행정 분야로의 확 장 가능성과 그에 따른 위험 요소, 규범적 쟁점을 심층적으로 검토한다. 연구방법으로는 국내외 선행연구 및 학위논문, 정책보고서, 입법자료, 감독 당국 보도자료 등을 폭넓게 검토하는 문헌연구를 기본 축으로 삼고, 금융· 의료 분야 중심의 사례연구를 병행하였다. 또한 관련 법령의 조문 분석과 더불어, 마이데이터 전송 프로세스에 활용되는 API 구조, 인증·인가 방식, 암호화 기술 등 기술적 요소를 함께 살펴봄으로써 법·제도·기술의 연계 구조를 종합적으로 파악하고자 하였다. 분석 결과, 첫째, 개인정보 보호법·신용정보법·전자정부법·민원처리법 등 개별 법률에 분산된 전송요구권 규정과 의료법·저작권법 등 특별법 간의 체계 정합성이 충분히 확보되지 않아 제도적 불확실성이 크다는 점이 드러 났다. 둘째, 의료 마이데이터의 경우 환자 정보의 민감성과 진료기록 관리 의무, 데이터베이스 제작자의 권리가 중첩되면서 전송요구를 거부할 여지가 존재한다는 문제가 확인되었다. 셋째, API 방식을 통한 데이터 전송과 통합 인증 도입에도 불구하고 도입 초기부터 반복적으로 발생한 정보 노출 및 오 류 사례는 운영 리스크 대응 체계와 보안 거버넌스의 미흡함을 보여준다. 이에 본 논문은 개선 방안으로 개인정보 보호법 중심의 전송요구권 일반법 체계 구축, 의료법 개정 및 의료 마이데이터 전용 가이드라인 마련, 저작권 법상 데이터베이스 제작자 권리 예외 신설, Kerberos 기반 통합인증(SSO)을 중심으로 한 보안체계 강화 등을 제안한다. 나아가 정보주체의 이해가능성 을 높이기 위한 동의 화면 표준화, 이용자 권리 교육 강화, 데이터 처리 전 과정의 투명성 제고와 같은 소프트 측면의 거버넌스 개선도 함께 강조함으 로써, 마이데이터 제도가 실질적인 권리 보장과 산업 혁신을 동시에 달성할 수 있는 방향을 모색한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    With the Fourth Industrial Revolution and the rise of the data economy, the collection, use, and integration of personal data has expanded at an unprecedented scale. As a result, data governance and the protection of informational self-determination have emerged as core policy challenges that cut across legal, technological, and social domains. As digital platforms and AI-based services become increasingly pervasive, individuals find it more difficult to understand how their data is collected, processed, combined, and shared, and who ultimately controls it. Within this dynamic, MyData is understood as a new paradigm that gives data subjects control over their personal data held by companies and institutions, empowering them to directly determine the movement and use of their data.
    South Korea has established the legal foundation for the MyData system by introducing MyData in the financial sector following revisions to the Credit Information Act, and by subsequently enacting a comprehensive revision of the Personal Information Protection Act in 2023 and a revision of its enforcement decree in 2024. Through these reforms, the right to request personal information transmission has been introduced as a general right applicable across sectors, ranging from finance and public administration to healthcare and telecommunications. This shift signifies a transition from an organization-centric data ecosystem to a more user-centric model in which individuals can exercise substantive control over the lifecycle of their data, from collection and storage to transfer, reuse, and deletion.
    This study aims to analyze the current state of domestic and international MyData service utilization and the development of related laws and systems amidst these institutional changes, identify structural problems and legal and technical limitations that hinder the effectiveness of the system, and then propose a safer and more usable MyData service model and directions for legal improvement. Particular emphasis is placed on the interplay between general data protection laws, sector-specific regulations such as medical and copyright law, and emerging technological architectures such as standard APIs, OAuth 2.0, TLS-based secure communication, and Kerberos-based single sign-on (SSO). By doing so, the study seeks to bridge the gap between abstract legal principles and the concrete design of information systems. The research methodology involved a comprehensive literature review of domestic and international research, dissertations, policy reports, legislative materials, and press releases from regulatory authorities, along with case studies focusing on the financial and medical sectors. Specifically, the analysis focused on the legal nature and limitations of the right to request personal information transfer, issues related to data portability in the medical and bioinformatics sectors, conflicts with database creators’ rights under copyright law, and the risks associated with the MyData platform’s security architecture and authentication methods. In addition, technical standards and reference architectures published by supervisory authorities and industry bodies are examined to understand how legal norms are materialized in concrete system designs and operational practices. The analysis revealed, first, that the systemic consistency between the provisions on data transmission requests, which are scattered across individual laws such as the Personal Information Protection Act, the Credit Information Act, the Electronic Government Act, and the Civil Complaints Handling Act, and special laws such as the Medical Service Act and the Copyright Act, is insufficient, resulting in significant institutional uncertainty. Second, in the case of medical MyData, the overlapping of the sensitivity of patient information, the obligation to manage medical records, and the rights of database creators creates the potential for refusal of data transmission requests, despite the formal existence of data portability rights. Third, despite the introduction of data transmission via API and integrated authentication, initial instances of information exposure and configuration errors demonstrate the inadequacy of the operational risk response system and the limitations of current security governance.
    Therefore, this study proposes improvement measures, including establishing a general legal system for transmission requests centered on the Personal Information Protection Act, revising the Medical Service Act and establishing dedicated guidelines for medical MyData, introducing explicit exceptions to the Copyright Act for database creators’ rights where data subjects exercise their personal data transmission rights, and strengthening the integrated authentication-based security system, particularly through the adoption of Kerberos-based SSO in backend infrastructures. Furthermore, the study argues for the need to enhance user involvement and literacy, standardize consent and data access interfaces, and promote a trust-based data ecosystem that can support sustainable innovation in the data economy.
    번역하기

    With the Fourth Industrial Revolution and the rise of the data economy, the collection, use, and integration of personal data has expanded at an unprecedented scale. As a result, data governance and the protection of informational self-determination h...

    With the Fourth Industrial Revolution and the rise of the data economy, the collection, use, and integration of personal data has expanded at an unprecedented scale. As a result, data governance and the protection of informational self-determination have emerged as core policy challenges that cut across legal, technological, and social domains. As digital platforms and AI-based services become increasingly pervasive, individuals find it more difficult to understand how their data is collected, processed, combined, and shared, and who ultimately controls it. Within this dynamic, MyData is understood as a new paradigm that gives data subjects control over their personal data held by companies and institutions, empowering them to directly determine the movement and use of their data.
    South Korea has established the legal foundation for the MyData system by introducing MyData in the financial sector following revisions to the Credit Information Act, and by subsequently enacting a comprehensive revision of the Personal Information Protection Act in 2023 and a revision of its enforcement decree in 2024. Through these reforms, the right to request personal information transmission has been introduced as a general right applicable across sectors, ranging from finance and public administration to healthcare and telecommunications. This shift signifies a transition from an organization-centric data ecosystem to a more user-centric model in which individuals can exercise substantive control over the lifecycle of their data, from collection and storage to transfer, reuse, and deletion.
    This study aims to analyze the current state of domestic and international MyData service utilization and the development of related laws and systems amidst these institutional changes, identify structural problems and legal and technical limitations that hinder the effectiveness of the system, and then propose a safer and more usable MyData service model and directions for legal improvement. Particular emphasis is placed on the interplay between general data protection laws, sector-specific regulations such as medical and copyright law, and emerging technological architectures such as standard APIs, OAuth 2.0, TLS-based secure communication, and Kerberos-based single sign-on (SSO). By doing so, the study seeks to bridge the gap between abstract legal principles and the concrete design of information systems. The research methodology involved a comprehensive literature review of domestic and international research, dissertations, policy reports, legislative materials, and press releases from regulatory authorities, along with case studies focusing on the financial and medical sectors. Specifically, the analysis focused on the legal nature and limitations of the right to request personal information transfer, issues related to data portability in the medical and bioinformatics sectors, conflicts with database creators’ rights under copyright law, and the risks associated with the MyData platform’s security architecture and authentication methods. In addition, technical standards and reference architectures published by supervisory authorities and industry bodies are examined to understand how legal norms are materialized in concrete system designs and operational practices. The analysis revealed, first, that the systemic consistency between the provisions on data transmission requests, which are scattered across individual laws such as the Personal Information Protection Act, the Credit Information Act, the Electronic Government Act, and the Civil Complaints Handling Act, and special laws such as the Medical Service Act and the Copyright Act, is insufficient, resulting in significant institutional uncertainty. Second, in the case of medical MyData, the overlapping of the sensitivity of patient information, the obligation to manage medical records, and the rights of database creators creates the potential for refusal of data transmission requests, despite the formal existence of data portability rights. Third, despite the introduction of data transmission via API and integrated authentication, initial instances of information exposure and configuration errors demonstrate the inadequacy of the operational risk response system and the limitations of current security governance.
    Therefore, this study proposes improvement measures, including establishing a general legal system for transmission requests centered on the Personal Information Protection Act, revising the Medical Service Act and establishing dedicated guidelines for medical MyData, introducing explicit exceptions to the Copyright Act for database creators’ rights where data subjects exercise their personal data transmission rights, and strengthening the integrated authentication-based security system, particularly through the adoption of Kerberos-based SSO in backend infrastructures. Furthermore, the study argues for the need to enhance user involvement and literacy, standardize consent and data access interfaces, and promote a trust-based data ecosystem that can support sustainable innovation in the data economy.

    더보기

    목차 (Table of Contents)

    • 표목차 iv
    • 그림목차iv
    • 국문초록vi
    • Ⅰ. 서론 1
    • 1. 연구배경과 목적 1
    • 표목차 iv
    • 그림목차iv
    • 국문초록vi
    • Ⅰ. 서론 1
    • 1. 연구배경과 목적 1
    • 1.1. 연구배경1
    • 1.2. 연구목적4
    • 2. 연구방법 및 구성 6
    • Ⅱ. 본론 9
    • 1. 국내외 관련법과 제도9
    • 1.1. 데이터 3법 개정과 국내 마이데이터 법제의 출발11
    • 1.2. 공공 마이데이터 확산과 민원·행정 분야 법제 정비13
    • 1.3. 마이데이터 사업자 허가 요건과 스크린 스크래핑 규제 13
    • 1.4. 개인정보보호법상 전송요구권 도입과 전문기관 제도15
    • 1.5. 국내 주요 법령의 마이데이터 관련 내용 비교18
    • 1.6. 해외 법제와의 연계: GDPR, CCPA, APRA(안)와의 비교 20
    • 1.7. 2023년 전부개정 및 2025년 시행을 중심으로 본 주요 쟁점 정리 ··21
    • 2. 국내 마이데이터 활용 및 현황 23
    • 3. 해외 마이데이터 활용 및 현황 29
    • 3.1. 마이데이터 개념의 초기 논의 (2000~2015년) 30
    • 3.2. EU 마이데이터 정책 발전 단계 31
    • 3.3. 영국 오픈뱅킹 및 스마트데이터 정책 32
    • 3.4. 미국의 마이데이터 정책 전개 33
    • 3.5. 일본의 정보은행 제도 발전 과정과 APPI 개정 방향 35
    • 3.6. 핀란드 Kanta 시스템 38
    • 3.7. 호주 My Health Record 39
    • 4. 국내 마이데이터 전송 프로세스41
    • 4.1. API 구조 개요 41
    • 4.2. 인증 방식과 데이터 전송 절차 43
    • 4.2.1. 개별 인증 방식 43
    • 4.2.2. 통합 인증 방식 44
    • 4.2.3. 정보제공 API45
    • 4.2.4. 전송요구 및 지원 API 45
    • 4.3. 데이터 표준 및 기술 규격 47
    • 4.4. 보안 및 운영상 한계 분석 50
    • 5. 통합인증 방식의 장점과 커버로스(keberos) 프로토콜 51
    • 5.1. 통합인증 방식의 필요성과 Kerberos 기반 구조 51
    • 5.2. 통합인증 방식의 실제 적용 가능성과 Kerberos 프로토콜의 동작 방식
    • 5.3. 마이데이터 보안체계에서의 의의 57
    • 6. 국내외 관련 법·제도의 문제점과 보안 인증 구조의 취약점 60
    • 6.1. 개인정보 전송요구권의 실효성 부족 60
    • 6.2. 의료·생명정보 분야의 제도적 한계 63
    • 6.3. 저작권법·데이터베이스 제작자 권리와의 충돌 64
    • 6.4. 보안·인증 구조의 취약성 66
    • 6.5. 이용자 관여 부족 및 동의 구조의 한계 67
    • Ⅲ. 결론 및 개선방안70
    • 1. 국내외 관련 법·제도의 개선 방향70
    • 2. 보안 취약점 및 인증 구조 개선 방안 72
    • 3. 연구 한계 및 향후 과제76
    • 참고문헌 79
    • Abstract83
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼