디지털 전환이 가속화되면서 클라우드 기반 서비스의 활용은 전 세계적으 로 선택이 아닌 필수가 되었다. 국내 기업들도 업무효율성과 비용 절감을 위해 클라우드 서비스를 적극 도입함에 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17380608
서울 : 건국대학교 정보통신대학원, 2026
학위논문(석사) -- 건국대학교 정보통신대학원 , 정보보안학과 , 2026. 2
2026
한국어
서울
62 ; 26 cm
지도교수: 김용학
I804:11004-200000966004
0
상세조회0
다운로드디지털 전환이 가속화되면서 클라우드 기반 서비스의 활용은 전 세계적으 로 선택이 아닌 필수가 되었다. 국내 기업들도 업무효율성과 비용 절감을 위해 클라우드 서비스를 적극 도입함에 ...
디지털 전환이 가속화되면서 클라우드 기반 서비스의 활용은 전 세계적으 로 선택이 아닌 필수가 되었다. 국내 기업들도 업무효율성과 비용 절감을 위해 클라우드 서비스를 적극 도입함에 따라, 전 세계를 대상으로 한 개인 정보 위·수탁 관계가 급증하고 재위탁 처리도 빠르게 확산되고 있다. 특히 글로벌 클라우드 서비스 사업자는 다수의 하위수탁자가 참여하는 다층적 수 탁망을 통해 서비스를 운영한다. 그러나 한국의 개인정보보호법은 위탁자와 수탁자 간의 단층적 관계를 전 제로 설계되어 있어 이러한 현실을 충분히 반영하지 못하고 있다. 현행 법 제는 재위탁 시 위탁자의 사전 승인을 요구하고, 수탁자 및 재수탁자에 대 한 관리·감독 의무를 부과하고 있으나, 글로벌 클라우드 사업자와 계약된 수많은 하위처리자를 위탁자가 직접 승인·감독하기는 현실적으로 한계가 있다. 이로 인해 복수의 클라우드 서비스를 병행하는 기업의 부담이 가중되 고, 법제와 현실 간 괴리가 심화되고 있다. 본 연구는 이러한 한계의 구조적 원인을 분석하고, 해외 주요 법제(GDPR, APPI, CCPA 등)와의 비교를 통해 차이점을 도출하였다. 이를 바탕으로 ‘연 쇄적 책임체계’와 ‘표준계약조항(SCC)’을 통한 계약 단계의 책임 연속성 확보를 중심으로 개선방안을 제시하였다. 본 연구의 결과는 다층적 글로벌 위탁 구조를 합법적으로 포섭할 수 있는 제도적 기반을 마련함으로써, 국내 개인정보보호 체계의 실효성을 높이고 클라우드 환경에서 책임성을 강화하 는데 기여할 것으로 기대한다.
다국어 초록 (Multilingual Abstract)
As digital transformation accelerates, the use of cloud-based services has become a necessity rather than a choice worldwide. Korean enterprises are actively adopting cloud services to enhance operational efficiency and reduce costs, which has led to ...
As digital transformation accelerates, the use of cloud-based services has become a necessity rather than a choice worldwide.
Korean enterprises are actively adopting cloud services to enhance operational efficiency and reduce costs, which has led to a sharp increase
in the outsourcing and re-outsourcing of personal data across global networks.
Global cloud service providers, in particular, operate through multi-layered subcontracting structures involving numerous sub-processors.
However, the Korean Personal Information Protection Act (PIPA) was designed on the premise of a single-layer relationship between the delegator and the contractor, and therefore fails to adequately reflect the
multi-tiered outsourcing structure prevalent in practice.
The current framework requires prior approval for re-outsourcing and 62 imposes supervisory duties on both contractors and sub-contractors, yet it is practically impossible for data controllers to directly monitor or authorize the vast number of sub-processors contracted by global cloud providers.
Consequently, organizations utilizing multiple global cloud services face an increasing compliance burden, deepening the gap between legal requirements and operational realities.
This study analyzes the structural causes of these limitations and compares Korea’s legal framework with major foreign regulations such as the GDPR, APPI, and CCPA.
Based on this comparative analysis, it proposes improvement measures focusing on the introduction of a “chain of accountability” and the adoption of “standard contractual clauses (SCCs)” to ensure continuity of
responsibility at the contractual level.
The results of this study are expected to contribute to strengthening accountability in personal data protection and enhancing the effectiveness of Korea’s data protection framework by establishing a legal foundation capable of accommodating multi-layered global outsourcing structures.
목차 (Table of Contents)