「개인정보보호법」은 개인정보 영향평가의 평가대상기관, 평가기준, 평가방법 및 절차 등 개인정보 영향평가제도의 주요한 사항을 「개인정보보호법시행령」에 위임하고 있다. 따라서 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
「개인정보보호법」은 개인정보 영향평가의 평가대상기관, 평가기준, 평가방법 및 절차 등 개인정보 영향평가제도의 주요한 사항을 「개인정보보호법시행령」에 위임하고 있다. 따라서 ...
「개인정보보호법」은 개인정보 영향평가의 평가대상기관, 평가기준, 평가방법 및 절차 등 개인정보 영향평가제도의 주요한 사항을 「개인정보보호법시행령」에 위임하고 있다. 따라서 본 연구는 「개인정보보호법시행령」제정방안을 우선 검토 하였다. 「개인정보보호법」은 영향평가 대상기관을 공공기관으로 한정하되, 처리하는 개인정보의 양, 개인정보의 제3자 제공 여부, 정보주체의 권리를 해할 가능성 등을 고려하여 그 대상을 정하도록 하였는 바, 현재 공공기관에서 운영하고 있는 개인정보파일의 현황 등을 고려하여 우선 10만 명 이상의 개인정보(민감정보 또는 고유식별정보의 경우에는 1만명 이상의 개인정보)를 처리하는 개인정보파일을 신규로 구축·운영하는 경우 등에는 평가전문기관에 의뢰하여 영향평가를 실시하도록 하였다. 그러나, 평가대상의 범위는 상황 변화에 따라 융통성 있게 변경될 수 있다. 그 다음으로 영향평가의 기준, 방법 및 절차 등은 개인정보 영향평가의 기술적·절차적인 사항으로서 그 동안 행정안전부와 한국인터넷진흥원에서 일부 공공기관에서 시행하는 정보화사업을 대상으로 시범적으로 개인정보 영향평가사업을 하면서 축적된 경험을 바탕으로 하여 작성한 공공기관 영향평가 수행안내서의 관련 내용을 참고하였다.
다음으로는 새로 제정된 「개인정보보호법」의 시행으로 개인정보보호 측면에서 획기적인 진전을 이룰 것으로 판단되나, 법 제정 관련 이해관계자들의 의견을 조율하는 과정에서 개인정보 영향평가제도의 총괄기관을 어디로 하여야 하는 지, 영향평가 대상기관의 범위를 어디 까지 하여야 하는 지 등 여러 부문에서 입법정책적으로 문제점이 노정 되었는 바, 본 연구에서는 이러한 문제점을 개선하여 장기적으로 개인정보 영향평가가 형식에 그치지 않고 실질적으로 효율적인 개인정보 영향평가가 이루어질 수 있는 제도를 정립하기 위한 개선 방안에 대하여 검토하여 보았다. 새로 제정된 「개인정보보호법」상 개인정보 영향평가제도의 관장기관은 행정안전부장관으로 되어 있다. 그러나, 행정안전부 자체가 전자 정부사업의 주요한 집행기관으로서 그 사업 추진과정에서 개인정보를 침해할 소지가 있는 바, 그러한 기관에서 개인정보보호업무를 관장하는 것에 근본적인 의문이 있다. 「개인정보보호법」에 따라 새로 설치되는 개인정보보호위원회가 어느 정도 관계 행정기관으로부터 독립성을 갖추어 국가기관 상호간의 견제가 가능한 개인정보보호 감독기구로서의 역할을 수행할 것으로 기대되기 때문에 행정안전부장관을 대신하여 개인정보보호위원회가 개인정보 영향평가제도의 총괄기관으로서의 역할을 수행하여야 한다고 보았다. 다음으로는 「개인정보보호법」은 일정 기준에 해당하는 공공기관에 대하여만 개인정보 영향평가를 의무화하고 있으나, 최근 들어 민간부문에서의 개인정보 수집·활용능력이 고도화되고 그에 따른 침해 사례도 크게 증가하고 그 피해규모도 방대하여짐에 따라 민간무문의 영향평가 의무부과에 따른 사업지연 또는 비용부담 과다 측면에서 전면적인 확대는 어렵더라도 개인정보의 유출, 오남·용 사례가 자주 발생하는 경우, 처리되는 개인정보의 양, 개인정보의 민감성 등을 고려하여 개인정보보호위원회가 필요하다고 인정하는 경우에는 영향평가를 권고할 수 있는 제도적 장치를 마련할 필요가 있다고 보았다.
또한, 개인정보 영향평가를 실무적으로 수행하는 평가전문기관의 적정한 관리·감독이 필요한 바, 평가전문기관의 지정·감독에 관한 사항에 대하여 검토하였고 , 「개인정보보호법」은 영향평가의 결과를 개인정보파일을 등록할 때 첨부 하도록만 할 뿐 공개 의무를 부과하고 있지 않고 있는데, 평가결과의 공개 문제도 개인정보 영향평가제도 도입취지와 연계하여 반드시 시행되어야 할 사항이다. 특히 「개인정보보호법」은 영향평가를 의무화하면서 이를 이행하지 않는 경우의 조치사항에 대하여 침묵을 지킴으로서 법의 실효성을 감소시키는 중대한 입법불비를 드러냈다. 이에 본 논문에서는 그에 대한 일차적으로는 시정명령을 하고, 시정명령에도 응하지 않는 경우에는 행정질서벌로서의 과태료를 부과하는 방안을 제시하였다.
다국어 초록 (Multilingual Abstract)
The Act on the Protection of Personal Information delegated several important things such as the institution that shall be subject to the impact assessment, the standard of assessment, the method of assessment, the process of it and etc. to be prescri...
The Act on the Protection of Personal Information delegated several important things such as the institution that shall be subject to the impact assessment, the standard of assessment, the method of assessment, the process of it and etc. to be prescribed by Presidential Decree. Therefore, this doctoral dissertation focused on the desirable form of future Presidential Decree of this Act. The Act on the Protection of Personal Information limited the institution that is subject to the impact assessment to public institutions, but the specific subject institution shall be determined considering several facts such as the amount of processed personal information, whether the personal information shall be provided to a third party, the possibility of hampering the right of information subject and etc. This doctoral dissertation suggests the impact assessment shall be done by the professional assessment institution when personal information files of more than 100,000 people (in case of sensitive information or inherent identification information: more than 10,000 people's information) will be newly developed and managed. However, the scope of the subject of impact assessment can be changed flexibly due to the change of environment. Secondly, this doctoral dissertation suggests the standard of assessment, the method of assessment and the process of it after consulting the guidebook for the impact assessment public institutions published by the Ministry of Public Administration and Security and the Korea Internet Security Agency, what they made based on their experience on the personal information impact assessment during the temporal assessment to several public institutions.
Furthermore, there are some unsolved problems to decide which institution shall be the managing institution of this impact assessment, how many institutions shall be subject to this assessment, etc., even though this new law will be very helpful for the protection of personal information. this thesis examined several suggestions on how to set up a desirable method that this assessment process can be a really effective impact assessment tool rather than a superficial one in the long run.
The Act on the Protection of Personal Information set the managing institution of the impact assessment shall be the Minister of Public Administration and Security. However, the Ministry of Public Administration and Security itself acts as a major performer of big electronic government projects and it can infringe some personal information rights during the project. It would possibly be a good choice the Minister of Public Administration and Security shall be the managing institution. The newly organized "Committee for the Protection of Personal Information" by the Act on the Protection of Personal Information could be act as an independent supervisory institution and this committee shall be the managing institution of privacy impact assessment process. In addition, the law ordered only some public institutions shall have duties of privacy information assessment, but the scope of it is too restrictive. The Committee for the Protection of Personal Information shall have some way at least to recommend the impact assessment when it considers necessary considering the frequency of information right infringements, the amount of processed information, the sensitivity of mattered information and etc., even we cannot enforce compulsory impact assessment to all private institutions because the process can hamper the private economic activities and cause big burden of money.
In addition, the "professional assessment institution", which actually does the privacy impact assessment, needs appropriate management and supervision. This doctoral dissertation examined some items for the designation and supervision of the professional assessment institution. Upon this, the Law does not impose the duty of opening the information of the result of impact assessment and only make it attached to the personal information file when it registered. However, when considering the reason why we introduce this impact assessment system, the opening of the result of impact assessment shall be accomplished in the near future. Specially, the Law is silent about how to sanction when the subject institution does not follow the duty of impact assessment. It's a big legislative mistake and it can be a huge hampering factor of this new law. Therefore, I added a suggestion that we shall order a corrective order for the first place and, if the subject institution does not follow the order, the imposition of fine for negligence or charge for compelling the performance.
목차 (Table of Contents)