
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
공공부문 개인영상정보 보안 강화와 AI 기술도입 대응 연구 : 법제도 개선을 중심으로
김광래 건국대학교 정보통신대학원 2025 국내석사
This study began with the finding that the legal basis for the operation of local government CCTV integrated control centers for public video information processing device operated nationwide was insufficient. public video information processing device installation and operation are mainly controlled by the Personal Information Protection Act, and there has been controversy throughout the entire process, including collection, control, use, provision to third parties, and export of personal video information with characteristics different from general personal information. In addition, as problems arising from insufficient management of personal video information in the CCTV integrated control center and personal video information infringement accidents resulting from illegal video manipulation by control personnel increase, the need for an independent law for the CCTV integrated control center continues to arise. This study investigates and analyzes several lawsuits filed so far regarding the installation and operation of CCTV integrated control centers and research on improving the legal system to respond to the Special Act, which focuses on the processing of personal video information, which stipulates special provisions of the Personal Information Protection. By enacting the tentative name “Act on Personal Video Information Protection Following Installation of Video Information Processing Devices and Integrated Control Operation,” we will put an end to the wasteful debate over personal video information infringement. By securing the legal status of the CCTV integrated control center, mandatory implementation of personal video information impact assessment, and safe management of personal video information by skilled control personnel, we will contribute to enabling public public video information processing device to perform its role as a protector rather than a monitor. In addition, as the introduction of AI CCTV control centers increases, we hope that AI technology in the public video information processing device field will be stably converged through proposals for AI ethics and national-level policy support that AI developers and control center operators must adhere to. 본 연구는 전국적으로 운영되고 있는 공공 영상정보처리기기에 대한 지방자치단체의 CCTV 통합관제센터 운영의 법적 근거가 미흡하다는 것에서 시작되었다. 영상정보처리기기 설치와 운영은 주로 개인정보보호법의 통제를 받고 있으며 일반적 개인정보와 다른 특성을 가진 개인영상정보의 수집, 관제, 이용, 제3자 제공, 반출 등 전 과정에서 논쟁이 진행되어왔다. 또한 CCTV 통합관제센터에서의 개인영상정보 관리 미흡으로 발생하는 문제와 관제요원의 불법적인 영상조작으로 발생하는 개인영상정보 침해사고가 증가함에 따라 CCTV 통합관제센터에 대한 독립적인 법률의 필요성이 꾸준히 제기되어왔다. 본 연구는 지금까지 제기된 CCTV 통합관제센터 설치 운영에 대한 수차례의 법률 발의안과 법 제도 개선에 대한 선행 연구 등을 조사, 분석하여 개인정보보호법의 특례를 규정한 개인영상정보 위주의 독립적인 특별법 제정을 연구하였다. 가칭 “영상정보처리기기 설치 및 통합관제운영에 따른 개인영상정보보호에 관한 법률”을 제정함으로써 그간의 개인영상정보침해에 대한 소모적 논쟁을 종식시키고 CCTV 통합관제센터의 법적 지위 확보와 개인영상정보영향평가 의무시행, 숙련된 관제요원에 의한 안전한 개인영상정보관리 등, 국민들로 하여금 공공 영상정보처리기기가 감시자가 아닌 보호자로서의 역할을 수행할 수 있도록 기여할 것이다. 아울러 AI 영상정보처리기기의 관제센터 도입증가에 따라 AI 개발자, 관제센터 운영자가 지켜야 할 AI 윤리 및 국가차원의 정책지원 제안을 통해 영상정보처리기기 분야에서의 AI 기술이 안정적으로 융합되기를 기대한다.
안덕근 인천대학교 정보통신대학원 2015 국내석사
Digital Signage는 Network 등을 통하여 제어가 가능한 digital display를 공공장소나 상업 장소에 설치하여 정보,entertainment,광고를 제공하는 Digital medea 제품으로 TV, 인터넷, 모바일 이후 제4의 미디어라고 불리며 빠른 속도로 성장하고 있는 미래 성장 동력 사업이며 SMART Signage의 글로벌 B2B 시장 수요에 따른 고성장이 전망되고 있다. 이에 따라 디스플레이의 절전 조절시스템과 몰입도에 관한 연구 논문으로 디스플레이가 구비된 영상장비에 구비되어 사람 또는 물체의 움직임을 감지하여 제어 부를 통해 디스플레이의 작동을 제어하는 감지센서와 영상장비의 외측에 결합되어 감지센서의 감지에 따라 디스플레이와 연동하는 알림수단과 영상장비의 일 측에 결합되어 감지센서가 사람 또는 물체의 움직임을 감지하면 제어부의 제어에 따라 디스플레이가 작동함과 동시에 알림수단(몰입도 향상)이 수 초간 작동하고 감지센서가 사람 또는 물체의 움직임을 설정시간 동안 감지하지 못하면 제어부의 제어부에 따라 디스플레이가 절전모드로 전환되는 것을 개발과정과 실험과정을 몇 명의 연구원들과 함께 연구를 하게 되었다. 연구의 주제는 영상정보기기의 감리적용항목이 특별하게 적용된 분야가 없기에 영상정보기기의 분석단계, 설계단계, 구현단계에 있어서 점검항목과 더불어 몰입효과와 절전효과를 분석하여 데이터를 얻어냄에 따라 본 연구논문으로 성과에 따른 과정과 시험 데이터는 매우 중요한 계기가 될 것이다. 따라서 제4의 미디어라고 하는 영상정보기기의 발전과정에 있어서 본 논문의 영구 내용이 영상정보기기의 발전에 기여하는 논문이 되길 바라며 각 성능과 기능에 따른 연구 결과는 시대와 환경에 적합한 감리적용이 필요함을 논문을 통하여 기술하였다. Ubiquitous시대를 맞아 다양한 정보통신의 Display Signage가 설치되고 있는 환경에서 디스플레이 장비는 여러 인터페이스 (터치, 카드리더기, 카메라, 프린터, 모션인식, 보안솔루션, 티켓발매기, ATM기기등)의 절전 및 영상정보 기기의 시각적인 몰입효과를 증대함에 본 연구논문 계획을 수립한다.
현행 「개인정보 보호법」상 개인영상정보 보호에 관한 검토
헌법상 모든 국민은 인간으로서의 존엄과 가치를 가지며, 사생활의 비밀과 자유를 침해받지 아니할 권리를 가지고 있다. 정보주체인 개인은 자신이 비밀로 하고자 하는 사항이 일반에 공개되지 않고 자신의 인격적 징표가 타인에 의하여 일방적으로 이용당하지 아니할 권리뿐만 아니라 자신에 대한 정보를 스스로 통제할 수 있는 권리도 가지는데, 정보주체의 권리보호 문제는 헌법상 개인정보자기결정권을 어떻게 구현할 것인가의 문제로 귀결된다고 할 수 있다. 최근 국민의 스마트폰 보급률 확대와 유튜브 등 온라인 영상 공유 플랫폼의 활성화로 인하여 정보주체인 개인의 의사와는 관계없이 촬영된 영상이 유출되는 상황이 빈번하게 일어나고 있다. 이러한 경우 정보주체인 개인의 인격권, 사생활의 비밀과 자유 등 기본권이 침해되는 상황이 발생할 수 있으며, 파일 형태로 한번 유출된 영상은 무한히 편집, 재생산 될 수 있기 때문에 삭제가 불가능하여 그 피해의 회복이 어렵다는 특징이 있다. 또한, 거리 및 도로, 건물 내ㆍ외부에 설치된 CCTV와 차량용 블랙박스도 정보주체의 동의여부와는 관계없이 영상을 촬영하고 저장한다. 우리는 집을 나서는 순간부터 개인정보가 침해될 위험성을 안고 살아가고 있는 것이다. 이상의 문제의식을 가지고 본 논문에서는 개인정보, 그 중에서도 개인영상정보가 어떻게 보호되고 있는지 검토해 보고자 하였다. 본격적인 연구에 착수하기에 앞서 개인정보보호제도의 필요성을 검토하였다. 정보통신기술의 발전에 따라 컴퓨터를 통한 개인정보의 데이터베이스화가 진행되고 손쉽게 개인정보를 처리할 수 있게 되면서 개인정보를 다루는 개인정보처리자의 확대로 인한 개인정보 유출위험이 증가하고 인터넷 환경상 개인정보 유출로 인한 피해 회복이 어려운 점 등을 들어 개인정보 보호를 위한 법규범 존재의 필요성을 도출하였다. 개인정보 보호의 헌법상 근거인 개인정보자기결정권과 관련하여, 학계의 논의와 헌법재판소의 입장을 정리하였다. 다음으로 개인정보 보호에 관한 일반법인 「개인정보 보호법」의 제정과정에 대해 살펴보았다. 「개인정보 보호법」 제정 전에는 개인정보 보호 관련 규정이 공공분야와 민간분야로 나뉘어 개별 법률들에 산재되어 규정되어 있던 것을 「개인정보 보호법」 제정과 함께 공공분야와 민간분야 구분 없이 적용될 수 있도록 하였다. 2011년 제정 이후 현재까지 총 7차에 걸친 개정이 이루어졌는데 개정 과정의 주요 내용을 살펴보았다. 「신용정보의 이용 및 보호에 관한 법률」, 「위치정보의 보호 및 이용 등에 관한 법률」 등 개별 분야의 특수성으로 인하여 개별 법률로 개인정보 보호에 관한 사항을 규정하고 있는 법률과 「개인정보 보호법」과의 관계도 살펴보았다. 다음으로 개인정보의 개념과 유형에 대해 살펴보았다. 「개인정보 보호법」에서는 “개인정보를 살아 있는 개인에 관한 정보로서 성명, 주민등록번호 및 영상 등을 통하여 개인을 알아볼 수 있는 정보로서 해당 정보만으로는 특정 개인을 알아볼 수 없더라도 다른 정보와 쉽게 결합하여 알아볼 수 있는 정보를 말한다.”고 규정한다. ‘영상’을 개인정보의 식별자로 하면서도 ‘개인영상정보’에 대한 개념 정의는 하지 않고 있다. 다만, 「표준 개인정보 보호지침」에서 개인영상정보를 “고정형 영상정보처리기기 또는 이동형 영상정보처리기기에 의해 촬영ㆍ처리되는 영상 형태의 개인정보를 말한다.”고 규정한다. 따라서, 개인영상정보는 실정법상의 개념은 아니다. 「개인정보 보호법」상 개인영상정보에 대한 규율은 동법 제25조 및 제25조의2에서 「표준 개인정보 보호지침」상의 개인영상정보 개념을 토대로 영상정보처리기기 설치 및 운영 제한 형태로 규정하고 있는바 이러한 규율형태의 문제점은 없는지 검토하고 세 가지 측면에서 문제가 있음을 밝혔다. 먼저, 현행 규정은 영상정보처리기기와 결합한 개인영상정보 개념을 규정하면서 시행령에 영상정보처리기기의 종류에 대해 열거식으로 규정하고 있다. 이는 새로운 영상정보처리기기가 출현하면 시행령 개정 전에는 규제의 공백이 발생하는 등 규제의 실효성을 약화시킨다는 점을 지적하였다. 다음으로, 규율구조 측면에서 「개인정보 보호법」상의 “영상”과 「표준 개인정보 보호지침」상의 “개인영상정보” 간 규범용어 관계에 있어서의 문제점을 지적하였다. 마지막으로, 장소의 차이에 따라 법 규정의 적용이 달라지는 비체계적 문제에 대해서 지적하였다. 이러한 문제를 지적하고 그에 대응한 대안으로 개인영상정보 개념의 재정의를 통한 명확성 확보, 그러한 개인영상정보 개념에 의한 규율구조의 완전성 확보를 주장하였고, 더 나아가 ‘개인정보 보호에 관한 법률’ 제정을 앞서 지적한 문제점에 대한 해결방안으로 제시하였다.
노지은 연세대학교 법무대학원 2024 국내석사
Over the last decade, a significant emphasis has been placed on the development of autonomous vehicles. The innovative technologies in autonomous vehicles significantly benefit society by reducing the number of accidents, congestion, and various social and environmental issues. As a result, the Korean government aims to set the year 2027 as the target year for full commercial autonomous vehicles, and Korean automobile manufacturers are actively planning the launch of level 3 autonomous vehicles. As the rapid development of digital, communication and AI technology provides autonomous vehicles with the ability to create, collect, analyze, transfer, and use data, attention is now turning towards the potential privacy and data breach concerns that may arise in an autonomous driving environment. The core autonomous vehicle technologies and functions are based on the acquisition and meticulous interpretation of an extensive swath of driving environment and personal data to enable the proper driving and control of the vehicle. The collection of such data encompasses specific data about a driver's behaviour, location, habits, and even comprehensive information on unrelated individuals, especially categorical identification of vulnerable road users, pedestrians, and the collection of facial recognition. The collection and use of data by autonomous vehicles are seen as inevitable by some, while others argue that strict regulations must be established to protect people's privacy. Many developed countries and key industry stakeholders have dedicated efforts to set privacy and data protection standards to address potential ethical, legal and technical challenges. However, devising regulations that effectively balance innovation with privacy protection is challenging. In Korea, mobile video devices installed in autonomous vehicles are the most likely technology to create privacy and data breach issues. The type of data generated by mobile video devices requires the collection of pedestrian behaviors, facial recognition, random objects, roads, and vehicle exterior environment to enable proper driving and control of the vehicle in different types of conditions, environments and situations. Historically, South Korea imposed strict laws relating to privacy and the collection of personal data and information. Accordingly, there were no specific legislative frameworks to address the privacy issues and allow the use of mobile video devices for autonomous vehicles. However, on 15 September 2023, an amendment of the Personal Information Protection Act introduced a distinct definition for "mobile video devices," categorically encompassing autonomous vehicles. Under specific conditions, the statute permits the recording of visual imagery involving persons or objects in public spaces via mobile video devices, even without the subject’s consent, provided such recording serves a business related purpose, and the act of recording is unequivocally communicated. Despite this, the practical execution of satisfying legal requirements still poses many challenges. The conspicuous placement of notification signs or the utilization of LED and flashlight indicators on the surface of autonomous vehicles has practical constraints. Moreover, even when these indications are observed, pedestrians and bystanders may lack the perceptual awareness to understand and recognize the actual recording. Furthermore, while the law governing the operation of mobile video processing devices permits recording under defined conditions, the law still requires adherence to the principle of prior consent for the use of personal information. The principle of prior consent raises questions about the effectiveness of the new regulation in developing fully autonomous vehicles in Korea without violating privacy laws and regulations. This research proposes two simultaneous strategies. In the short term, the government should issue temporary special permits for personal information collection and encourage various stakeholders to achieve fully autonomous vehicles. In the long term, the research recommends amending the Personal Information Protection Act to introduce new mechanisms like personal information processing privacy policy certification and privacy impact assessments to protect personal information collected from diverse groups of individuals. Finally, regulatory bodies should develop strict guidelines to enhance security on the relevant technology to strengthen data protection in autonomous vehicles. This research aims to provide solutions to the Korean autonomous vehicle industry with actionable solutions aiming to strike an optimal balance between privacy protection amidst the active development of fully autonomous vehicles in Korea. 바야흐로 자율주행자동차의 시대이다. 정부는 2027년 완전자율주행 상용화를 위해 박차를 가하고 있고, 국내외 자동차 제조사들은 앞 다투어 레벨 3단계 자가용 상용화 계획을 발표하고 있다. 대부분의 교통사고가 운전자의 부주의에 의한 것이라는 연구결과에 비추어 볼 때, 운전자 또는 승객의 조작 없이 자동차 스스로 운행이 가능한 자율주행자동차가 이러한 교통사고로 인한 생명, 신체, 재산 등의 손실의 해결책이자 흐름이다. 자율주행시스템의 가동을 위해서는, 자율주행자동차 기술의 특성상 자율주행시스템의 운전 판단의 기초가 되는 자동차 소유자 또는 운행자는 물론 보행자와 같은 불특정 다수의 위치정보, 노약자 여부 등을 확인하기 위한 안면인식정보 등 광범위한 개인정보 수집과 이를 분석하여 판단을 내리기 위한 개인정보 이용이 필수적이다. 사전 동의 (Opt-in) 원칙 및 2023년 9월 15일부터 시행된 현행 개인정보 보호법에서 자율주행자동차가 해당할 수 있는 ‘이동형 영상정보처리기기’의 경우 (ⅰ) 업무를 목적으로 이동형 영상정보처리기기를 운영하는 경우로서 (ⅱ) 촬영 사실을 명확히 표시하여 정보주체가 촬영 사실을 알 수 있도록 하였음에도 불구하고 촬영 거부 의사를 밝히지 아니한 경우에 공개된 장소에서 이동형 영상정보처리기기로 사람 또는 그 사람과 관련된 사물의 영상을 촬영하는 것을 허용한 것은 이처럼 다량의 개인정보 처리가 필수불가결한 자율주행자동차의 경우를 반영하기 위한 방안으로서의 의의가 있다. 다만 실제 이러한 요건을 충족하여 이동형 영상정보처리기기인 자율주행자동차로 개인정보를 촬영하기 위해서는 정보주체가 촬영사실을 알 수 있도록 표시하여야 하는데, 실제 자율주행자동차 표면에 안내문구가 기재된 스티커를 부착하거나 LED 또는 섬광등 불빛 표시를 하기 어렵다는 점, 설령 이러한 표시를 하였다고 하더라도 사후 동의 제도의 한계로서 보행자들이 실제 주행 중인 자율주행자동차들의 촬영 사실 표시 사항을 실질적으로 인지할 수 없는 경우도 있다는 점, 이동형 영상정보처리기기의 운영에 관한 규정은 일정한 경우에 ‘촬영’하는 것을 허용할 뿐이므로 자율주행시스템에서 촬영된 개인정보를 이용하는 데에는 여전히 사전 동의 원칙이 적용되고 그 동의 받은 이용 범위 내에서만 이용이 가능하므로 여전히 자율주행자동차를 통해 개인정보를 처리하는 것에 대한 근거로서의 실효성 문제가 있다. 이에 기존에 사전 동의 (Opt-in) 원칙에서 출발하여 자율주행자동차를 통한 촬영을 일부 사전 동의 없이도 허용하는 기존의 관점에서와 달리, 자율주행기술의 특성상 개인정보의 수집은 필수불가결하다는 점을 인정하고 오히려 이를 통해 처리되는 개인정보의 양이 다량인 점을 고려하여 개인정보를 이용하는 범위와 방법에 대해 명확한 가이드라인을 제시하는 방안이 보다 현실적일 것으로 사료된다. 또한 자율주행자동차를 통해 처리되는 개인정보의 항목과 그 이용 방안에 대해 가장 잘 알고 있는 자율주행자동차 사업자들이 단체를 설립하여 안전하게 개인정보를 처리할 수 있는 기준에 대해 가이드라인 또는 기본 원칙을 만들도록 함으로써 빠르게 변화하는 자율주행기술을 고려한 기준이 반영될 수 있도록 하는 방안도 고려해볼 수 있다. 특히 이러한 방안은 개인정보처리자가 스스로 그 기준을 정하는 과정에서 보다 안전한 개인정보 처리에 관한 사회적 소통의 창구 역할을 할 수 있다는 점에서 기대해볼 만하다. 본 연구를 통해 다양한 센서를 통해 대량의 개인정보를 수집하는 자율주행자동차에서의 개인정보 활용과 개인정보 보호라는 두 법익간의 균형을 찾는 방안을 논의하는 데 의의를 두고자 한다.
유진만 건국대학교 정보통신대학원 2025 국내석사
This study highlights how intelligent CCTV, combined with artificial intelligence (AI) technology, significantly improves societal efficiency in fields such as crime prevention, disaster management, and traffic control, while enhancing public safety. As a key tool for future societies, intelligent CCTV also raises concerns about privacy infringement. Sensitive information, including facial data, license plates, and behavioral patterns, is collected and analyzed in real-time, increasing the potential for data misuse and violations of privacy. Therefore, it is essential to establish legal, technical, and social measures to protect individual rights while leveraging the benefits of technological advancement. Currently, the Personal Information Protection Act provides a basic framework by emphasizing principles such as minimizing data collection, limiting usage purposes, and ensuring data security. However, the vast amount of data generated by intelligent CCTV systems and the rapid progress of AI technology expose limitations in existing legal frameworks. These gaps create legal blind spots and fuel social controversies. In particular, privacy infringements related to sensitive information, such as video data, have emerged as significant legal challenges. To address these issues, a combination of technical, managerial, and legal protective measures is necessary. Technically, secure data management systems such as data encryption, video anonymization, and access control systems must be implemented. From a managerial perspective, fostering a culture of privacy protection through operator training, systematic management, and regular inspections is essential. Legally, it is necessary to establish regulations tailored to the unique characteristics of intelligent CCTV, continuously improve existing privacy protection laws, and develop integrated international standards and cooperative frameworks. In the future, the development of technology and legal regulations must focus on achieving harmony. Balancing public interests with the protection of personal privacy requires social consensus and ethical standards. This issue cannot be resolved solely through legal regulations or technical safeguards but requires increased public awareness and responsible use of technology. In conclusion, intelligent CCTV can only progress in a safe and trustworthy manner when technology, law, and social consensus are harmonized. Sustained efforts are needed to protect personal information while simultaneously ensuring public safety, paving the way for a balanced and trustworthy integration of technology and society. 본 연구는 지능형 CCTV는 인공지능 기술과 결합하여 범죄 예방, 재난 관리, 교통 통제 등 다양한 분야에서 사회적 효율성을 높이고 공공의 안전을 강화하는 데 기여하고 있다. 또한, 미래 사회의 핵심 도구로 자리 잡고 있지만, 동시에 개인정보 침해에 대한 우려를 증대시키고 있다. 개인의 얼굴, 차량 번호판, 행동 패턴 등 민감한 정보가 실시간으로 수집·분석되며, 데이터의 오남용 및 사생활 침해 가능성이 커지고 있다. 따라서 기술 발전의 혜택을 누리면서도 개인의 권리를 보호하기 위한 법적, 기술적, 사회적 방안 마련이 필수적이다. 현재 개인정보보호법은 개인정보 수집 최소화, 목적 제한, 안전성 확보 등 기본적인 틀을 제공하고 있지만, 지능형 CCTV가 생성하는 방대한 데이터와 인공지능 기술의 발전 속도를 따라잡는 데 한계를 보이고 있다. 이로 인해 법적 사각지대가 발생하며, 사회적 논란을 야기하고 있다. 특히, 영상정보는 민감한 정보 처리에서 발생하는 프라이버시 침해는 법적 쟁점으로 부각 되고 있다. 이를 해결하기 위해 기술적, 관리적, 법적 보호 방안이 유기적으로 결합되어야 한다. 기술적으로 데이터 암호화, 영상 비식별화, 접근 통제 시스템 등 안전한 정보 관리 체계가 필요하다. 관리적 측면에서 운영자 교육, 체계적인 관리 시스템, 정기적인 점검과 감사를 통해 개인정보 보호 문화를 정착시켜야 한다. 법적으로 지능형 CCTV 특성을 반영한 전용 규제를 마련하고, 기존 개인정보보호법을 지속적으로 보완해야 하며, 국제적인 협력 체계와 통합된 기준 수립도 중요하다. 앞으로 기술 발전과 법적 규제는 상호 조화를 이루는 데 초점을 맞춰야 한다. 공익과 개인 사생활 보호 간 균형을 이루기 위해 사회적 합의와 윤리적 기준이 필요하며, 이는 법적 규제나 기술적 보호만으로 해결될 문제가 아니다. 사회적 인식 제고와 책임 있는 기술 활용이 필수적이다. 결론적으로, 지능형 CCTV는 기술, 법, 사회적 합의가 조화를 이루어야 안전하고 신뢰받는 방향으로 발전할 수 있다. 개인정보 보호와 공공 안전을 동시에 확보하기 위한 지속적인 노력이 요구된다.
개인정보보호법상의 CCTV의 운영에 대한 고찰 : 위수탁 관계 위주를 중심으로
임수용 연세대학교 법무대학원 2015 국내석사
개인정보보호법에 제정된 후 우리 일상생활에서는 많은 변화가 있었다. 가장 큰 변화는 개인정보의 중요성을 인식하고, 제공자나 처리자가 관리를 할 때 보다 세심한 주의를 기울이게 된 것이 가장 큰 변화라 할 수 있다. 개인정보 이용의 목적을 밝히고, 제공에 대한 동의를 받으며, 목적이 달성된 경우에는 삭제하는 절차가 제정 초기에는 지켜질 수 있을까라는 우려가 많았지만 시행 몇 년 후가 지난 지금 시점에서는 많은 부분 지켜지고 있다고 평가된다. 하지만 CCTV(Closed Circuit Television) 운영에 대해서는 개인정보보호법 제정 초기에서부터 논란이 있었던 부분들이 아직 치유되지 못한 부분들이 아직까지 존재하고 있다. 예를 들면 녹화된 영상에 대해서 개인정보의 해당여부를 판단하는 ‘식별’의 기준, 카메라 각도는 어느 정도까지가 다른 사람의 인격이나 사생활을 침해하는 것에 대해서 명백한 기준이 없는 문제, 어떠한 사건이 발생 했을 때에는 당사자 일방이 소설 네트워크에 자신에게 유리한 영상을 공개하여 오히려 정확한 재판을 방해하는 경우를 방지할 수 있는 가능성의 문제, 그리고 객관적 자료여야 하는 영상 자체가 위?변조 될 가능성이 있는 등 기술적인 부분과 운영적인 부분에 대해서 계속 법 적용 부분에서 문제점이 발생되고 있다. 현재 법 체계상에서는 개인정보보호법에서는 영상으로서의 개인정보의 판단과 이미 상용화된 CCTV 운영적인 측면을 전부 포괄하고 있다. 법을 바탕으로 관련기관에서는 CCTV 설치 및 운영에 대해서 민간에 일임을 하고 가이드라인을 배포하여 자율적 준수를 유도하고 있는데 이것도 정확한 기준을 제시하지 못하여 다른 분쟁의 빌미를 제공하는 경우가 종종 있다. 또한 개인정보의 활용 부분에서는 문자적, 숫자적으로 표현되는 개인정보는 위수탁, 제3자 제공이라는 개념으로 관리가 가능하지만 영상에 대해서는 이 두 가지 개념으로 호과적인 관리를 유지하게 할 수 없다. 이러한 현실 적용에 문제가 발생한 이유는 개인정보보호법의 정의에서 영상 자체의 특성을 무시한 채 문자나 숫자로 표현되는 일반 개인정보로 분류한 출발점에서부터 문제가 있었다고 판단된다. 따라서 영상에 대해서는 별도의 개별법 제정이 필요하다. 이 개별법에서는 영상의 특성을 고려하여 현실적 적용이 가능한 개인영상정보를 정의하고, 현재 일반 생활에서 정확한 정의 없이 사용되고 있는 초상권에 대한 범위 등을 정의한 후 보호법익으로 하면서 개인정보보호법 테두리 안에 포괄하지 못한 스마트폰으로 찍는 타인의 영상 및 블랙박스 등도 규율을 할 필요가 있다. 개인정보보호법에서는 카메라와 녹화장치를 구분하지 못하여 앞으로 개발될 시스템은 본 법에 적용 범위에서 벗어날 위험성이 있다. 따라서 법에서 보다 상세하게 이를 구분하여 정의할 필요가 있다. 그리고 위수탁 및 제3자제공 외에 ‘관리’라는 개념을 도입하여 CCTV가 의무적으로 설치되는 곳에서부터는 설치만 하고 운영을 자율적으로 맡길 것이 아니라 영상정보에 대해서도 객관적이 관리를 하게 한다면 우려되는 사생활 침해 및 인격권 침해의 위험성을 줄일 수 있다. 또한 법적으로 의무 설치되는 곳뿐만 아니라 문제가 될 수 있는 장소의 설치에는 운영을 개인에게 일임하지 말고, 허가 받은 업체에서 이를 관리하게 하고, 국가는 이 업체를 관리한다면 관련 기관의 실효적인 규율문제 또한 해결될 수 있다. 설치와 운영에 대해서 관련 기관에서는 애매한 가이드라인으로만 안내하기 보다는 허가된 업체가 객관성을 띄고 이를 관리하게 하고 관련 기관에서는 업체가 관련법에 따라 저장, 열람 등을 하는지 감독을 하게 한다면 현재 우려되고 있는 CCTV 관련 문제들을 조금이나마 해결할 수 있을 것이라 생각한다. After enacting personal information protecting Act, there have been a lot of changes in daily life. The biggest change is to recognize importance of person information and to give more cautious attention information when providers or managers manage the information. There were a lot of concern whether processes from revealing usage purpose of personal information to receiving agreement on providing information and deleting the information after the usage purpose become complete could be maintained or not in the early stage of the Act, but this study assesses that many parts of the processes have been kept until today after past years from the enactment. However, in case of CCTV (Closed Circuit Television) operation, controversy, which has occurred from the early stage of personal information protecting Act, still exists until today. A lot of problems on legal applications have occurred in various cases such as ‘discrimination’ criteria, which could judge that a recorded video is in charge of personal information or not, no specific standard how degree cameras move to not to infringe personality or personal life, possibility problem to impede right trial by opening partial video, which support just one side, in social network service when some incidents occur, technical problems that it is possible for objective video to be forgery, and operational problems. Current on the legal system, the personal information protecting Act includes all range of judging personal information as video and operational aspects of CCTV, which is already commercialized. Based on the law, related authorities entrust all of installation and operation of CCTV with private institutions and drive self observance by distributing guidelines. However, the activities cannot suggest clear criteria so that it could be excuses for other conflicts. Also, texting and numbering personal information could be managed with notions of entrustment and third-party offers in an aspect of using personal information, but video information could not be managed with the notions. The reason of these reality application problems is that definition of personal information protecting Act only included texting and numbering information ignoring characteristics of video. Therefore, it is needed for video to enact separated identification law. The identification law defines individual information video, which could be applied into reality, by considering characteristics of videos, and it sets ranges on portrait rights, which could be used, in daily life without specific definition. Then as it is going to be benefit and protection of the law, it should be needed to regulate smartphone video and black box video that the individual information protecting Act could not include. Since the individual information protecting Act cannot distinguish cameras and recording devices, there is risk that it is possible for systems developed in future to escape from a range of this law. Therefore, the law must define the range more specifically by classifying the devices. A notion of ‘management’ is to be introduced with the entrustment and third-party offers, so, if institutions do not operate CCTV by self-regulatory and institutions just install CCTV in places where CCTV installation is mandatory, it will be possible to reduce infringement of privacy and personal rights. In addition, if qualified institutions manage CCTV and government manage the qualified institutions not to entrust individuals in not only places where CCTV installation is mandatory but also other places where CCTV installation could become problem, it will be possible to solve effective discipline problems on related authorities. When qualified institutions manage CCTV with objectivity and related authorities supervise that the qualified institutions could save and browse the video abiding by related laws rather than related authorities provide vague guidelines on installation and operation, this study considers that current CCTV problems would be resolved.
디지털포렌식 관점에서 본 수사기관의 CCTV 영상정보 수집의 적법성 및 무결성 확보에 관한 연구
이규민 성균관대학교 일반대학원 2022 국내석사
범죄예방 및 시설관리 등 다양한 목적으로 활용되고 있는 CCTV는 사회적 이슈로 대두되고 있는 살인·강도·성범죄·절도·폭력 등 5대 강력범죄와 크고 작은 여러 사고들의 발생률을 감소시키는 데 기여하였으며, 범죄 전후의 정황이나 범인을 특정할 수 있는 증거자료로 중요한 역할을 담당하고 있어 수사실무상 CCTV에 의해 촬영된 영상정보는 범죄수사를 함에 있어서 필요불가결한 존재가 되었다. 영상정보는 범죄수사에 있어 매우 효율적이지만, 정보주체의 의사와 상관없이 촬영되었다는 점에서 기본권 침해에 대한 논란은 계속되고 있다. 수사기관은 국가의 안녕과 국민의 기본권 침해라는 양날의 칼 위에 서서 어느 한 곳으로 치우치지 않게 본연의 업무를 수행하여야 한다. 현행 법령이 규정하고 있는 범위 내에서 국민의 기본권 침해를 최소화하고 과학적이고 객관적인 수사기법으로 영상정보를 수집하여야 한다. 본 논문에서는 수사목적으로 수사기관이 영상정보를 수집하는 행위가 헌법상 국민의 기본권 침해에 해당하는지와 영상정보 수집 및 처리를 규정한 개인정보보호법상 수사기관이 영상정보처리자로서 영상정보를 수집・활용할 수 있는지에 대한 연구를 통해 수사기관에 의한 영상정보 수집의 적법성을 검토하고, 형사소송법상 디지털 형태로 존재하는 영상정보가 증거능력을 인정받기 위한 적법절차와 무결성 확보방안을 고찰하고자 한다. CCTV (Closed-Circuit Television), which is increasingly used for various purposes like crime investigation and facility management, has significantly contributed to reduce myriads of crimes including murder, robbery, sexual assault, and violence. Furthermore, as it plays as a critical evidence that can not only specify criminals but also clarify circumstances before and after the crime, video information recorded by CCTV has become an essential part of the crime investigation. Although video information is an efficient part of crime and national security investigation, controversy over breaching of fundamental rights continues as it is filmed without the consent of the parties concerned. Investigation agency should carry out its mission without being one-sided to either peace of a nation or breaching of basic rights. Thus, video information should be gathered via scientific and objective investigation methods to minimized infringement of fundamental rights by observing the existing law. In this regard, this paper considers whether investigation agency’s gathering of video information corresponds to breaching of basic human rights. At the same time, legality of investigation agency’s video information gathering is reviewed by considering whether investigation agency can be a personal information manager in terms of Personal Information Protection Act. Lastly, ways to secure integrity and due process, which give admissibility of evidence to digital video information, are studied.
AI 기반 CCTV 개인영상정보 안전성 확보조치 연구 : 새로운 위협에 따른 개인정보보호 방안
박민영 건국대학교 정보통신대학원 2026 국내석사
AI(인공지능) 기반 CCTV는 객체 탐지·얼굴 인식·행동 분석을 통해 공공 안전에 기여하지만, 영상에서 생체인식정보와 추론정보를 실시간으로 생성한다는 점에서 기존 영상정보처리기기와는 다른 차원의 개인정보 침해 위험을 발생시킨다. 본 연구는 「개인정보 보호법」, 「개인정보의 안전성 확보조치 기준」 및 관련 안내서, 그리고 「ISMS-P」 기준을 토대로, AI 기반 CCTV의 데이터 수집·처리·보관·파기 전 과정에서 발생하는 위협 요인을 분석하였다. 분석 결과, 핵심 위험은 ① 엣지 환경에서의 분산 저장과 단말 보안 공백에 따른 수집·전송·파기 단계의 위험, ② 유출 시 회복이 불가능한 생체인식정보(임베딩 벡터)의 비가역성, ③ 정보주체가 제공한 적 없는 감정·건강·성향 등 추론정보의 무단 생성, ④ 학습데이터 편향에 따른 알고리즘의 지능형 차별, ⑤ 비식별 조치를 무력화하는 AI 복원·재식별(Re-ID) 기술, ⑥ AI 모델·학습데이터·추론정보·판단 이력을 독립적 보호 대상으로 명시하지 못하는 현행 ISMS-P의 구조적 한계로 도출되었다. 이를 바탕으로 본 연구는 엣지 AI 기반 보안 아키텍처와 데이터 생애주기 관리, 동적 비식별화 및 재식별 방지 기술, 설명 가능한 AI(XAI) 기반 판단 근거 기록, 알고리즘 편향 완화를 기술적 개선 방안으로, ISMS-P를 보완한 AI 특화 관리체계 수립과 개인정보 영향평가(PIA) 강화, 정보주체의 자동화된 결정에 대한 권리 보장 절차 마련을 관리적 개선 방안으로 제시하였다. 아울러, 정보보호 실무 전문가 10명을 대상으로 설문조사를 실시한 결과, 현행 ISMS-P 인증기준의 보완 필요성(100.0%) 및 본 연구가 제안한 핵심 개선방안에 대해 모든 항목에서 90.0% 이상의 긍정적 동의를 확보하여 개선방안의 현장 타당성을 확인하였다. 본 연구는 향후 AI 영상정보처리기기 가이드라인 제정과 ISMS-P의 AI 특화 보완 기준 마련에 기초 자료로 활용될 수 있다. AI-based CCTV contributes to public safety through object detection, facial recognition, and behavior analysis. However, unlike conventional video surveillance systems, AI-Based CCTV generates biometric information and inferred information from video images in real time, thereby creating new and heightened risks of personal information infringement. Based on the Personal Information Protection Act, the Standards for Ensuring the Safety of Personal Information, related guidelines, and the ISMS-P certification standards, this study analyzes threat factors that may arise throughout the entire life cycle of AI-Based CCTV data, including collection, processing, storage, and deletion. The analysis identifies the following key risks: first, risks in the collection, transmission, and deletion stages caused by distributed storage in edge environments and security gaps in terminal devices; second, the irreversibility of biometric information, such as embedding vectors, which cannot be restored or replaced once leaked; third, the unauthorized generation of inferred information, including emotions, health conditions, and personal tendencies, that has not been directly provided by the data subject; fourth, algorithmic discrimination caused by bias in training data; fifth, AI-based restoration and re-identification technologies that may undermine de-identification measures; and sixth, the structural limitations of the current ISMS-P framework, which does not clearly designate AI models, training data, inferred information, and decision-making records as independent objects of protection. Based on these findings, this study proposes technical improvement measures, including an Edge AI-based security architecture, data life cycle management, dynamic de-identification and re-identification prevention technologies, recording of decision-making grounds based on explainable AI (XAI), and mitigation of algorithmic bias. It also proposes managerial improvement measures, including the establishment of an AI-specialized management system that supplements ISMS-P, the strengthening of Privacy Impact Assessment (PIA), and the preparation of procedures to guarantee data subjects’ rights regarding automated decision-making. In addition, a survey of ten information security experts confirmed the practical validity of the proposed measures, with 100.0% of respondents recognizing the need to supplement the current ISMS-P certification standards and more than 90.0% expressing positive agreement with each of the key improvement measures proposed in this study. These findings confirm the practical applicability of the proposed measures. This study is expected to serve as a basic reference for establishing future guidelines on AI-Based video information processing devices and for developing AI-specific supplementary standards within the ISMS-P framework.
CCTV 촬영에 대한 우려와 CCTV 촬영에 대한 태도 간의 관계에서 인식의 조절효과
조동환 상명대학교 일반대학원 2017 국내석사
This paper wants to identify the alleviating effects of awareness on the negative attitude toward CCTV recording. Specifically, this paper made 5 subordinate concepts of awareness. As a result of the analysis, awareness turned out to have a moderating effect on the negative attitude to CCTV Recording. Among the five subordinate concepts of awareness, it is turned out that there is no moderating effect or alleviating effect on the negative attitude(when a person knows CCTV recording area, when he or she recognizes notice sign of the CCTV recording, and when a person notices the fact that he or she is being recorded by CCTV). Except for those 3 subordinate concepts of awareness picked in this paper, the results of the 2 other types of awareness are statistically meaningful on the matter of whether there is moderating or mitigating effect or not(when a person knows how the recordings are used and are under control). Especially, these two kinds of CCTV awareness suggest the significance of educational necessity for the better and enhanced standards of CCTV awareness in a matter of the personal information protection. Key Words: CCTV, privacy, concern, attitude 본 논문은 정보주체의 CCTV 촬영에 대한 인식의 정도가 CCTV 촬영에 대한 태도에 미치는 영향을 규명하고자 하였다. 세부적으로 하위인식을 유형화하여 이들의 조절효과 역시 규명하고자 하였다. 분석한 결과, 인식은 CCTV 촬영에 대한 반감을 상쇄시켜주는 효과가 있었다. 인식의 하위유형인 5 가지 유형 중, CCTV 촬영장소를 인지하고 있는 유형과 CCTV 안내판을 인지하고 있는 유형, 그리고 CCTV에 촬영되고 있음을 인지하고 행동하는 인식의 유형 대해서는 CCTV 촬영에 대한 부정적인 태도를 경감시키는데 효과가 있지는 않는 것으로 나타났다. 이를 제외한 나머지 유형의 인식(CCTV를 통해 수집된 영상정보의 활용방법을 인지, CCTV를 통해 수집된 영상정보의 관리방법을 인지)하고 있을 경우에 대한 조절효과는 통계적으로 상당히 유의미 하였다. 특히 이 두 가지 유형의 인식이 개인정보보호 측면에서 정보주체를 대상으로 우선적으로 필요한 교육임을 알 수 있다. 주제어: CCTV, 영상정보처리기기, 우려, 태도, 조절효과