RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    중소기업의 클라우드 서비스 활용에 따른 개인정보 위·수탁 법제의 한계 연구 : 글로벌 기업에 대한 개인정보 위·수탁을 중심으로 = A Study on the Limitations of the Legal Framework Governing Personal Data Processing Outsourcing Arising from SMEs’Use of Cloud Services : Focusing on Outsourcing to Global Corporations

    한글로보기

    https://www.riss.kr/link?id=T17380608

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    디지털 전환이 가속화되면서 클라우드 기반 서비스의 활용은 전 세계적으 로 선택이 아닌 필수가 되었다. 국내 기업들도 업무효율성과 비용 절감을 위해 클라우드 서비스를 적극 도입함에 따라, 전 세계를 대상으로 한 개인 정보 위·수탁 관계가 급증하고 재위탁 처리도 빠르게 확산되고 있다. 특히 글로벌 클라우드 서비스 사업자는 다수의 하위수탁자가 참여하는 다층적 수 탁망을 통해 서비스를 운영한다. 그러나 한국의 개인정보보호법은 위탁자와 수탁자 간의 단층적 관계를 전 제로 설계되어 있어 이러한 현실을 충분히 반영하지 못하고 있다. 현행 법 제는 재위탁 시 위탁자의 사전 승인을 요구하고, 수탁자 및 재수탁자에 대 한 관리·감독 의무를 부과하고 있으나, 글로벌 클라우드 사업자와 계약된 수많은 하위처리자를 위탁자가 직접 승인·감독하기는 현실적으로 한계가 있다. 이로 인해 복수의 클라우드 서비스를 병행하는 기업의 부담이 가중되 고, 법제와 현실 간 괴리가 심화되고 있다. 본 연구는 이러한 한계의 구조적 원인을 분석하고, 해외 주요 법제(GDPR, APPI, CCPA 등)와의 비교를 통해 차이점을 도출하였다. 이를 바탕으로 ‘연 쇄적 책임체계’와 ‘표준계약조항(SCC)’을 통한 계약 단계의 책임 연속성 확보를 중심으로 개선방안을 제시하였다. 본 연구의 결과는 다층적 글로벌 위탁 구조를 합법적으로 포섭할 수 있는 제도적 기반을 마련함으로써, 국내 개인정보보호 체계의 실효성을 높이고 클라우드 환경에서 책임성을 강화하 는데 기여할 것으로 기대한다.
    번역하기

    디지털 전환이 가속화되면서 클라우드 기반 서비스의 활용은 전 세계적으 로 선택이 아닌 필수가 되었다. 국내 기업들도 업무효율성과 비용 절감을 위해 클라우드 서비스를 적극 도입함에 ...

    디지털 전환이 가속화되면서 클라우드 기반 서비스의 활용은 전 세계적으 로 선택이 아닌 필수가 되었다. 국내 기업들도 업무효율성과 비용 절감을 위해 클라우드 서비스를 적극 도입함에 따라, 전 세계를 대상으로 한 개인 정보 위·수탁 관계가 급증하고 재위탁 처리도 빠르게 확산되고 있다. 특히 글로벌 클라우드 서비스 사업자는 다수의 하위수탁자가 참여하는 다층적 수 탁망을 통해 서비스를 운영한다. 그러나 한국의 개인정보보호법은 위탁자와 수탁자 간의 단층적 관계를 전 제로 설계되어 있어 이러한 현실을 충분히 반영하지 못하고 있다. 현행 법 제는 재위탁 시 위탁자의 사전 승인을 요구하고, 수탁자 및 재수탁자에 대 한 관리·감독 의무를 부과하고 있으나, 글로벌 클라우드 사업자와 계약된 수많은 하위처리자를 위탁자가 직접 승인·감독하기는 현실적으로 한계가 있다. 이로 인해 복수의 클라우드 서비스를 병행하는 기업의 부담이 가중되 고, 법제와 현실 간 괴리가 심화되고 있다. 본 연구는 이러한 한계의 구조적 원인을 분석하고, 해외 주요 법제(GDPR, APPI, CCPA 등)와의 비교를 통해 차이점을 도출하였다. 이를 바탕으로 ‘연 쇄적 책임체계’와 ‘표준계약조항(SCC)’을 통한 계약 단계의 책임 연속성 확보를 중심으로 개선방안을 제시하였다. 본 연구의 결과는 다층적 글로벌 위탁 구조를 합법적으로 포섭할 수 있는 제도적 기반을 마련함으로써, 국내 개인정보보호 체계의 실효성을 높이고 클라우드 환경에서 책임성을 강화하 는데 기여할 것으로 기대한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    As digital transformation accelerates, the use of cloud-based services has become a necessity rather than a choice worldwide.
    Korean enterprises are actively adopting cloud services to enhance operational efficiency and reduce costs, which has led to a sharp increase
    in the outsourcing and re-outsourcing of personal data across global networks.
    Global cloud service providers, in particular, operate through multi-layered subcontracting structures involving numerous sub-processors.
    However, the Korean Personal Information Protection Act (PIPA) was designed on the premise of a single-layer relationship between the delegator and the contractor, and therefore fails to adequately reflect the
    multi-tiered outsourcing structure prevalent in practice.
    The current framework requires prior approval for re-outsourcing and 62 imposes supervisory duties on both contractors and sub-contractors, yet it is practically impossible for data controllers to directly monitor or authorize the vast number of sub-processors contracted by global cloud providers.
    Consequently, organizations utilizing multiple global cloud services face an increasing compliance burden, deepening the gap between legal requirements and operational realities.
    This study analyzes the structural causes of these limitations and compares Korea’s legal framework with major foreign regulations such as the GDPR, APPI, and CCPA.
    Based on this comparative analysis, it proposes improvement measures focusing on the introduction of a “chain of accountability” and the adoption of “standard contractual clauses (SCCs)” to ensure continuity of
    responsibility at the contractual level.
    The results of this study are expected to contribute to strengthening accountability in personal data protection and enhancing the effectiveness of Korea’s data protection framework by establishing a legal foundation capable of accommodating multi-layered global outsourcing structures.
    번역하기

    As digital transformation accelerates, the use of cloud-based services has become a necessity rather than a choice worldwide. Korean enterprises are actively adopting cloud services to enhance operational efficiency and reduce costs, which has led to ...

    As digital transformation accelerates, the use of cloud-based services has become a necessity rather than a choice worldwide.
    Korean enterprises are actively adopting cloud services to enhance operational efficiency and reduce costs, which has led to a sharp increase
    in the outsourcing and re-outsourcing of personal data across global networks.
    Global cloud service providers, in particular, operate through multi-layered subcontracting structures involving numerous sub-processors.
    However, the Korean Personal Information Protection Act (PIPA) was designed on the premise of a single-layer relationship between the delegator and the contractor, and therefore fails to adequately reflect the
    multi-tiered outsourcing structure prevalent in practice.
    The current framework requires prior approval for re-outsourcing and 62 imposes supervisory duties on both contractors and sub-contractors, yet it is practically impossible for data controllers to directly monitor or authorize the vast number of sub-processors contracted by global cloud providers.
    Consequently, organizations utilizing multiple global cloud services face an increasing compliance burden, deepening the gap between legal requirements and operational realities.
    This study analyzes the structural causes of these limitations and compares Korea’s legal framework with major foreign regulations such as the GDPR, APPI, and CCPA.
    Based on this comparative analysis, it proposes improvement measures focusing on the introduction of a “chain of accountability” and the adoption of “standard contractual clauses (SCCs)” to ensure continuity of
    responsibility at the contractual level.
    The results of this study are expected to contribute to strengthening accountability in personal data protection and enhancing the effectiveness of Korea’s data protection framework by establishing a legal foundation capable of accommodating multi-layered global outsourcing structures.

    더보기

    목차 (Table of Contents)

    • 표목차 ⅲ
    • 그림목차 ⅳ
    • 국문초록 ⅴ
    • 제1장 서론 1
    • 제1절 연구의 배경 및 필요성 1
    • 표목차 ⅲ
    • 그림목차 ⅳ
    • 국문초록 ⅴ
    • 제1장 서론 1
    • 제1절 연구의 배경 및 필요성 1
    • 1. 중소기업의 클라우드 활용 확산과 개인정보보호의 과제 1
    • 2. 글로벌 클라우드 서비스 구조와 국내 법제 간의 불일치 3
    • 제2절 연구의 목적과 구성 4
    • 1. 연구 범위와 분석 대상 4
    • 2. 연구 방법 및 논문 구성 5
    • 제2장 이론적 배경 6
    • 제1절 개인정보 위·수탁의 개념과 법적 구조 6
    • 1. 위탁·재위탁 개념 및 법적 관계 6
    • 2. 관리·감독 의무의 개념 7
    • 제2절 클라우드 서비스 구조와 책임성 원리 9
    • 1. 클라우드 서비스 유형별 개인정보 처리 구조 9
    • 2. OECD 책임성(Accountability) 원칙의 의의 10
    • 제3장 개인정보 위·수탁 법제의 비교와 구조적 한계 12
    • 제1절 한국 개인정보보호법의 위탁 규율 체계 12
    • 1. 제26조의 주요 내용과 위탁계약 요건 12
    • 2. 재위탁 승인 절차의 한계 13
    • 3. 관리·감독 의무의 실효성 문제 15
    • 제2절 해외 법제 비교 19
    • 1. EU GDPR 제28조의 하위수탁자 규율 19
    • 2. 일본 APPI와 미국 CCPA의 규제모델 22
    • 3. 해외 법제 비교를 통한 국내 법제의 특징 25
    • 제3절 한국 법제의 구조적 한계 31
    • 제4장 개선 방향 39
    • 제1절 법제 개선 방향 39
    • 1. 연쇄적 책임체계(Chain of Accountability)의 법제화 39
    • 2. 표준계약조항(SCC) 도입 41
    • 제2절 행정·정책적 개선 방향 46
    • 제5장 결론 50
    • 제1절 연구 요약 50
    • 제2절 연구 의의 및 한계 53
    • 제3절 향후 과제 55
    • 참고문헌 57
    • ABSTRACT 61
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼