개인정보보호위원회는 2023년 3월 14일 법 개정을 통하여, ‘개인정보 전송요구권’ 규정을 신설함으로써 ‘전 분야 마이데이터’ 정책의 법적 기반을 마련하였다. ‘개인정보 전송요구권’...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=A110412874
박가람 (한양대학교 법학일반대학원 박사과정)
2026
Korean
KCI등재
학술저널
103-140(38쪽)
0
상세조회0
다운로드개인정보보호위원회는 2023년 3월 14일 법 개정을 통하여, ‘개인정보 전송요구권’ 규정을 신설함으로써 ‘전 분야 마이데이터’ 정책의 법적 기반을 마련하였다. ‘개인정보 전송요구권’...
개인정보보호위원회는 2023년 3월 14일 법 개정을 통하여, ‘개인정보 전송요구권’ 규정을 신설함으로써 ‘전 분야 마이데이터’ 정책의 법적 기반을 마련하였다. ‘개인정보 전송요구권’이란 정보주체가 자신의 개인정보를 본인 또는 제3자에게 전송하여 줄 것을 요구할 수 있는 권리로, 정부는 ‘개인정보 전송요구권’에 기반한 ‘전 분야 마이데이터’ 정책으로 정보주체의 통제권을 강화하는 한편, 데이터 경제의 활성화를 촉진하고, 특정 기업의 데이터 독점을 완화한다는 목표를 가지고 있다.
개인정보보호위원회의 ‘전 분야 마이데이터’에 대한 확고한 의지에도 불구하고, 관련 산업계와 시민단체는 ‘전 분야 마이데이터’의 도입에 반대 목소리를 내고 있다. 해서, 본고에서는 개인정보보호의 관점에서 향후 ‘전 분야 마이데이터’ 정책으로 인하여 발생할 수 있는 문제점을 살펴보고자 한다. 구체적으로, ‘전 분야 마이데이터’ 정책은 ①이용자 데이터를 기반으로 한 가격차별의 문제를 심화시킬 수 있고, ②정보주체의 권리 행사로 인한 제3자 권리 침해의 문제를 야기할 수 있다. 또한, ③‘전 분야 마이데이터’ 정책은 필연적으로 기술적 측면에서 상호운용성을 필요로 함에 따라 정보보안의 위험을 발생시킬 수 있다. 마지막으로, ④가명처리정지요구권에 대한 우리 대법원의 판단에 따르면, 정보주체에게는 보호법상 도출되는 가명처리정지요구권이 인정되지 않는다. 이러한 우리 대법원의 판단하에서 이루어지는 ‘전 분야 마이데이터’ 정책은 기업이 정보주체의 동의없이(정보주체의 통제권이 미치지 않는 영역에서) 가용할 수 있는 데이터의 양을 증대시키는 결과를 가지고 올 수 있는데, 인공지능 기술의 발달과 함께 가명정보의 재식별 위험성, 즉 비식별화 조치에 의문이 제기되는 현시점에서 이를 되돌아볼 필요가 있다.
다국어 초록 (Multilingual Abstract)
The Personal Information Protection Commission (PIPC) laid the legal foundation for the “all‑sector MyData” policy by amending the Personal Information Protection Act on 14 March 2023 and newly introducing a provision on the “right to request ...
The Personal Information Protection Commission (PIPC) laid the legal foundation for the “all‑sector MyData” policy by amending the Personal Information Protection Act on 14 March 2023 and newly introducing a provision on the “right to request transmission of personal information.” The “right to request transmission of personal information” refers to the right of the data subject to demand that his or her personal information be transmitted to the data subject him‑ or herself or to a third party designated by the data subject. On the basis of this right, the government pursues an “all‑sector MyData” policy with the objectives of strengthening the data subject’s control over personal information, invigorating the data‑driven economy, and mitigating data monopolies held by particular undertakings.
Notwithstanding the PIPC’s clear commitment to “all‑sector MyData,” relevant industry actors and civil‑society organisations have voiced opposition to the introduction of the policy. Against this backdrop, this article examines, from the perspective of personal data protection, the potential problems that may arise in the future from the implementation of an “all‑sector MyData” policy. More specifically, first, an “all‑sector MyData” policy may aggravate concerns about price discrimination based on user data. Second, it may give rise to situations in which the exercise of data‑subject rights leads to infringements of third‑party rights. Third, insofar as an “all‑sector MyData” policy necessarily presupposes technical interoperability, it may generate information‑security risks.
Finally, according to the position taken by the Korean Supreme Court on the right to request cessation of pseudonymisation, the data subject is not recognised as having a right, derived from the Personal Information Protection Act, to demand the cessation of pseudonymisation. If an “all‑sector MyData” policy is implemented under this judicial interpretation, it may result in an increase in the volume of data that undertakings can use without the data subject’s consentS—that is, in a domain beyond the reach of the data subject’s control. At a time when advances in artificial intelligence have heightened concerns about the re‑identification risks associated with pseudonymised data and cast doubt on the effectiveness of de‑identification measures, it is necessary to revisit this issue.
전용물소권에 관한 한정적 승인론의 옹호 -전면적 승인론의 비판에 대한 응답을 중심으로-
Covert Investigations in Data-Saturated Environments: Toward a Normatively Constrained Framework
공통이지만 차별화된 책임의 확장과 한계: 팬데믹 협정을 중심으로