Recently, there has been increased awareness of the importance of private data protection laws due to frequent private information leaks. While these leaks were limited in the past, nowadays, the extent of damage caused by leaks has rapidly expanded d...
Recently, there has been increased awareness of the importance of private data protection laws due to frequent private information leaks. While these leaks were limited in the past, nowadays, the extent of damage caused by leaks has rapidly expanded due to online computerized processing of personal information.
Moreover, private-sector data protection is governed by many separate individual laws. Therefore, it is difficult for individuals to know in what ways their private information should be protected and what they should do in case of information leakage.
The public sector makes as its primary goal the promotion of public welfare. To achieve this goal, there has been an inevitable, growing need for public organizations responsible for collecting and processing private data. The private information held by the public sector is different from that of the private sector in that while it is very sensitive, it is still mandatory to provide. For example, if the records of an individual's divorce, medical or crime history were opened to the public, that is not only a clear privacy infringement, but could also result in that individual suffering other hardships such as loss of social security benefits and character defamation. It is for these reasons that private information should be subject to constitutional protection.
This paper takes a close look at legislation on the data protection laws of the Republic of Korea, and suggests controversial issues and solutions as follows.
First of all, the data protection laws in the Republic of Korea govern the public sector and private sector separately. Due to this separate system, regulation disparities between the public and private sector and blind spots in private information protection emerge. Therefore, there is a necessity to establish an improved regulatory system that governs the public and private sectors together, as exists in other OECD countries.
Secondly, information on the process of obtaining consent for collecting private data and providing that data to a third party is perfunctory – that is, it is merely offered with other general information. When data processing entities request consent from private entities for private data, information on the consent request process and where the personal data provided ends up should be required to be given separately from other general information.
Thirdly, current private data protection laws should be more expanded and rationalized in terms of protection scope and retention period. Data protection for the deceased is needed as well. Computerized private information that is currently excluded from subjects to be protected by the private sector should be included. It is currently up to the heads of organizations holding the private information to determine the retention period of private data. However, the retention period of private data could be a matter of significant importance to the individuals who provided such information. Therefore, the data retention period should be expressly stipulated in a law or private data supervisory authorities should be granted the power to administer and supervise the retention period. Moreover, data protection for the deceased is needed to protect the right of personality of bereaved families.
Fourthly, leakage of private data usually entails multiple victims at a time, and the pattern of damage is the same. Therefore, private data protection laws should include a collective dispute resolution system that would serve to arbitrate conflicts in a timely manner.
Lastly, to effectively protect an individual’s private information, the independence of the data protection supervisory authority is critical. For this, two options are under discussion: to establish the supervisory authority under the president's direct authority; or to establish it as a central government agency. Taking into consideration that a central government agency is also subject to supervision, it is better to establish the supervisory authority in the form of an independent committee under the president's authority. Since the current data protection supervisory authority lacks the substantial power to monitor and investigate, it is necessary to change this so that the supervisory authority is granted the right to monitor, investigate, order suspension of infringement, decide compensation for damage and intervene in a dispute, to ensure that private data protection laws work effectively in reality.