RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    빅데이터 환경에서 개인정보 이용에 관한 법적 고찰

    한글로보기

    https://www.riss.kr/link?id=T15362738

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
      • URL 복사
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    빅데이터는 미래 예측분석, 사회적 난제 해결, 신산업 발전 도모 등을 좌우할 수 있을 만큼 큰 파급력을 가진다. 빅데이터 활용을 통해 특정 패턴이나 링크, 행동, 트렌드, 정체성, 실용 지식 등 인간의 능력으로 도출하기 어렵던 유용하고 희소성 있는 정보를 얻을 수 있기 때문이다. 그러나 정보사회에서의 기술 현상 대부분이 그렇듯이 빅데이터의 집적과 개인정보의 디지털화는 프라이버시 내지 개인정보 침해에 대한 위험성 증대라는 부정적 영향을 초래하고 있다. 특히 빅데이터 환경에서 생성된 정보는 수집 당시 개인 식별이 어렵더라도 사전에 예측하기 어려운 방식 즉, 다른 정보와의 결합, 연동·연계, 가공 등을 통해 개인정보화 되거나 빅데이터 분석기술을 통해 언제든지 재식별될 우려가 잠재되어 있다. 예를 들어 프로파일링(profiling)이나 디지털 흔적의 추적(tracking)을 통해 특정 개인의 행동 패턴이나 선호도, 건강상태, 성적 취향, 위치정보 등이 노출될 수 있으며, 이로부터 야기되는 불공정한 평가나 평판으로 인해 개인의 사회적 인격의 형성에도 부정적인 영향을 끼칠 수 있다.
    따라서 빅데이터 기반 사회에서 개인의 사생활 보호를 강조하는 보호론적 관점과 정보 이용에 따른 부가가치 창출을 중시하는 활용론적 관점 중 어느 한 방향을 일률적으로 지지하는 것은 바람직하지 않다. 결론적으로 빅데이터 기술의 위험성 증폭에 따른 개인정보 유출이나 프라이버시 침해에 대한 해결책을 강구하면서도 빅데이터의 편익에 따른 혁신의 창출이 제한받지 않도록 양 이익 간 균형을 이룰 수 있는 조화로운 가치평가가 내려질 필요가 있다.
    기존의 연구는 현행법의 문제점에 대한 지적이 비교적 명료하였던 것에 반해 변화하는 빅데이터 환경에서의 구체적이고 실효적인 대안에 대한 검토가 미흡하였다. 특히 개인정보이동권, 프로파일링 거부권, 자기통제권 강화를 위한 기술적 보호조치(Privacy by Design, Differential Privacy 등) 등 개인정보의 이용 촉진을 위해 필요한 법제도에 관하여는 국내에서 비교적 활발히 논의되지 못한 경향이 있다.
    이에 따라 본 논문에서는 해외의 선제적 개정 동향을 참고하여 우리나라 개인정보 보호법제가 빅데이터 환경에서 개인정보의 안전한 이용을 효과적으로 지원할 수 있는 개선방안을 제시하였다. 특히 기존의 개인정보 보호법을 개편함으로써 개인정보 이용의 촉진을 기대할 수 있는 방안뿐만 아니라 자기주도적 정보통제 환경을 조성하기 위한 새로운 제도 및 권리 도입의 필요성도 함께 제안하고자 한다. 근래에 들어 개인정보의 이용을 확대하기 위한 개정안이 다수 제안되는 등 개인정보의 이용 측면을 확보하기 위한 다양한 입법론적 시도가 이루어지고 있으나, 아직 이를 통합적으로 구체화한 연구는 부족한 실정이며 개정안이 실제 입법화되는 단계에까지는 이르지 못하고 있다. 현재 잔존해 있는 개인정보 보호법의 문제점들로 인해 실무계에서 상당한 해석상의 혼란과 적용상의 문제를 겪고 있는 상황에 비추어 보건대, 빅데이터 환경에서 정보주체의 권익을 보호하면서도 개인정보의 이용이 안전하게 이루어질 수 있도록 신속한 입법 조치를 취하여야 한다. 이러한 관점에서 본 연구를 통해 다양하게 제안하는 개선방안은 빅데이터 산업의 활성화를 저해하는 규제로서 현행 개인정보 보호법의 한계를 극복하는데 기여할 수 있다. 또한 프라이버시 보호와 개인정보의 자유로운 유통을 균형적으로 조율하고자 하는 개인정보 규범의 궁극적인 취지를 실현케 할 것이다. 이를 통해 장기적인 관점에서는 새로운 빅데이터 시대에 적합한 개인정보의 현대적 의미를 재정립하고, 개인정보의 원활한 이용을 위한 융통성 있는 법적 토대를 구축하게 될 것으로 기대한다.
    번역하기

    빅데이터는 미래 예측분석, 사회적 난제 해결, 신산업 발전 도모 등을 좌우할 수 있을 만큼 큰 파급력을 가진다. 빅데이터 활용을 통해 특정 패턴이나 링크, 행동, 트렌드, 정체성, 실용 지식 ...

    빅데이터는 미래 예측분석, 사회적 난제 해결, 신산업 발전 도모 등을 좌우할 수 있을 만큼 큰 파급력을 가진다. 빅데이터 활용을 통해 특정 패턴이나 링크, 행동, 트렌드, 정체성, 실용 지식 등 인간의 능력으로 도출하기 어렵던 유용하고 희소성 있는 정보를 얻을 수 있기 때문이다. 그러나 정보사회에서의 기술 현상 대부분이 그렇듯이 빅데이터의 집적과 개인정보의 디지털화는 프라이버시 내지 개인정보 침해에 대한 위험성 증대라는 부정적 영향을 초래하고 있다. 특히 빅데이터 환경에서 생성된 정보는 수집 당시 개인 식별이 어렵더라도 사전에 예측하기 어려운 방식 즉, 다른 정보와의 결합, 연동·연계, 가공 등을 통해 개인정보화 되거나 빅데이터 분석기술을 통해 언제든지 재식별될 우려가 잠재되어 있다. 예를 들어 프로파일링(profiling)이나 디지털 흔적의 추적(tracking)을 통해 특정 개인의 행동 패턴이나 선호도, 건강상태, 성적 취향, 위치정보 등이 노출될 수 있으며, 이로부터 야기되는 불공정한 평가나 평판으로 인해 개인의 사회적 인격의 형성에도 부정적인 영향을 끼칠 수 있다.
    따라서 빅데이터 기반 사회에서 개인의 사생활 보호를 강조하는 보호론적 관점과 정보 이용에 따른 부가가치 창출을 중시하는 활용론적 관점 중 어느 한 방향을 일률적으로 지지하는 것은 바람직하지 않다. 결론적으로 빅데이터 기술의 위험성 증폭에 따른 개인정보 유출이나 프라이버시 침해에 대한 해결책을 강구하면서도 빅데이터의 편익에 따른 혁신의 창출이 제한받지 않도록 양 이익 간 균형을 이룰 수 있는 조화로운 가치평가가 내려질 필요가 있다.
    기존의 연구는 현행법의 문제점에 대한 지적이 비교적 명료하였던 것에 반해 변화하는 빅데이터 환경에서의 구체적이고 실효적인 대안에 대한 검토가 미흡하였다. 특히 개인정보이동권, 프로파일링 거부권, 자기통제권 강화를 위한 기술적 보호조치(Privacy by Design, Differential Privacy 등) 등 개인정보의 이용 촉진을 위해 필요한 법제도에 관하여는 국내에서 비교적 활발히 논의되지 못한 경향이 있다.
    이에 따라 본 논문에서는 해외의 선제적 개정 동향을 참고하여 우리나라 개인정보 보호법제가 빅데이터 환경에서 개인정보의 안전한 이용을 효과적으로 지원할 수 있는 개선방안을 제시하였다. 특히 기존의 개인정보 보호법을 개편함으로써 개인정보 이용의 촉진을 기대할 수 있는 방안뿐만 아니라 자기주도적 정보통제 환경을 조성하기 위한 새로운 제도 및 권리 도입의 필요성도 함께 제안하고자 한다. 근래에 들어 개인정보의 이용을 확대하기 위한 개정안이 다수 제안되는 등 개인정보의 이용 측면을 확보하기 위한 다양한 입법론적 시도가 이루어지고 있으나, 아직 이를 통합적으로 구체화한 연구는 부족한 실정이며 개정안이 실제 입법화되는 단계에까지는 이르지 못하고 있다. 현재 잔존해 있는 개인정보 보호법의 문제점들로 인해 실무계에서 상당한 해석상의 혼란과 적용상의 문제를 겪고 있는 상황에 비추어 보건대, 빅데이터 환경에서 정보주체의 권익을 보호하면서도 개인정보의 이용이 안전하게 이루어질 수 있도록 신속한 입법 조치를 취하여야 한다. 이러한 관점에서 본 연구를 통해 다양하게 제안하는 개선방안은 빅데이터 산업의 활성화를 저해하는 규제로서 현행 개인정보 보호법의 한계를 극복하는데 기여할 수 있다. 또한 프라이버시 보호와 개인정보의 자유로운 유통을 균형적으로 조율하고자 하는 개인정보 규범의 궁극적인 취지를 실현케 할 것이다. 이를 통해 장기적인 관점에서는 새로운 빅데이터 시대에 적합한 개인정보의 현대적 의미를 재정립하고, 개인정보의 원활한 이용을 위한 융통성 있는 법적 토대를 구축하게 될 것으로 기대한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    From information-oriented society, utility of the personal information is not oriented from fragmentary information, but from the phenomenon that creates the added value underlying information derived from the database in which the data are collected and saved. In other words, as much greater number of personal information is obtained and processed because of the proliferated big data, the whole behavior related with the big data is subject to application of 'personal information protection act'.
    But in the big data circumstances, it is difficult to carry through the principle of personal information protection which are the principle of minimum collection, clarity of purpose, prior consent. For instance, the big data bring out the more useful result with the more data, which aim for the contrary target against the minimum collection principle. Also, personal information norms need 'express consent' and 'clarity of purpose' by the subject(principal) of information for the collection and utilization of personal information, which is contradict to the essence of big data for the secondary data usage. On this wise, 'personal information self-determination right' to manage and control its own information and 'personal information protection act' as the base law are challenged in big data circumstance.
    However, the current law doesn't resolve this problematic phenomenon completely. 'personal information protection act' doesn't take account of the personal information's industrial utilization although it is legislated in 2011, which could be named as comparatively recent. And the law is insufficient for the control to information combination or profiling analysis, which are crucial phenomenon of big data since it's mainly about the manager of personal information. It would be hard to find the binding legislation or progressive argument on the personal information issue in big data circumstance such as profiling even in other countries. But, the international organizations has complemented the existing guideline by focusing on the invigoration of new data industry and many of national laws are trying to find out the appropriate regulation. Merely, the direction of regulation is not for the coherent regulation to the manager of personal information(for example, the prohibition of automatic profiling by EU GDPR, and guaranteed control). It's rather in the form of granting the big data within the frame of existing personal information norms. That is, they tend to resolve the matters with the domestic laws under the existing regulation system by clear personal information concept, mandatory regulation of false name or anonymous process, the flexibility of the consent system in the context of clear data process.
    Therefore, it is required to supplement the current law so as to present the obvious law interpretation standard and reflect the distinctiveness of the big data circumstance by legislation. But it should be allowed to utilize personal information based on 'personal information protection act' only when it is inherent with personal information protection value. Thus, the various legislation measure suggested in this thesis have a great significance in the change and adaptation to the new environment of our legislative system and to secure new systematic justification.
    Hence, the chapter 2 in this thesis refers to the juridical study on the definition that in the issue of 'personal information right' set off from the 'personal rights', it is necessary to take the economic utilization of personal information into account. It is for the purpose of supporting 'information privacy' as self-initiative right needed in information-oriented era. As we call it, 'personal information self-determination right' as a basic right guaranteed by the national constitution law would be the key standard to set the overall direction of personal information protection act by harmoniously balancing conflicting interests. For the actual effect, it is the prerequisite of discussing issuable positive law on personal information protection act that there should be the consensus of interests between the personal information business and subject(principal) of information.
    Following chapter 3 contains the comparative law analysis on the current trend of personal information protection act legislation overseas under big data circumstance. Judging that the trade and circulation of personal information is in the global scope, personal information protection act should be amended on the direction to secure international interoperability. It will be focused on the possible industrial utilization of the personal information by studying on the latest legislation trend in EU, USA, Japan, China, etc. Especially, the chapter3 mainly deals with EU GDPR and Japanese amended personal information protection act(2015) as they are similar to Korean legal system but proceeded to the enactment of new regulation and law revision.
    And the chapter 4 indicates the problems of current personal information protection act and proposes the actual effective legislation measure in the interest of industrial utilization of personal information. Specifically, it analyzed the problems of current law impeding invigoration of personal information utilization and made a suggestion on the available and reasonable improving measure of legislation and system according to the individual issues. Meanwhile, it is needed to look through 'information subject(principal) rights' articles which are reflected in many foreign legislations but less dealt in Korea such as 'Right of data portability', 'Automated individual decision-making including profiling)'. Because it is possible to achieve the secure personal information utilization based on personal choice and decision by guaranteeing the actual rights of personal information principle after imposing these systems. And the chapter5 is the conclusion of the thesis summarizing the significances and implications of the proposed legislation measures in Korean legal system.
    Though, it is important to take note that it shouldn't sacrifice or restrain a legitimate personal right simply for the personal information utilization and 'restriction on a right' articles to encourage innovative technology shouln't be approved in broad sense too. Afterall, it is desirable to amend the personal information norms in balance in order to protect personal information or privacy strongly. For this purpose, we need to shift our focus from the stereotype regarding big data and privacy as opposite to the more flexible and interactive integrated things granting the coherent technology value of personal information. In addition, the legal system should be established to enable the balancing conflicting interests in individual cases covering interest of information subject(principal) or public interest, not infringing the essence of personal information self-determination right which is constitutional.
    Finally, from this study, it would contribute not only to overcome the limit of current personal information protection act as a regulation impeding the efficient proliferation of information in big data industry, but also to enact the ultimate legislation purpose of personal information legal system requiring the balance of contradictive value(personal information protection and unconstrained circulation).
    번역하기

    From information-oriented society, utility of the personal information is not oriented from fragmentary information, but from the phenomenon that creates the added value underlying information derived from the database in which the data are collected...

    From information-oriented society, utility of the personal information is not oriented from fragmentary information, but from the phenomenon that creates the added value underlying information derived from the database in which the data are collected and saved. In other words, as much greater number of personal information is obtained and processed because of the proliferated big data, the whole behavior related with the big data is subject to application of 'personal information protection act'.
    But in the big data circumstances, it is difficult to carry through the principle of personal information protection which are the principle of minimum collection, clarity of purpose, prior consent. For instance, the big data bring out the more useful result with the more data, which aim for the contrary target against the minimum collection principle. Also, personal information norms need 'express consent' and 'clarity of purpose' by the subject(principal) of information for the collection and utilization of personal information, which is contradict to the essence of big data for the secondary data usage. On this wise, 'personal information self-determination right' to manage and control its own information and 'personal information protection act' as the base law are challenged in big data circumstance.
    However, the current law doesn't resolve this problematic phenomenon completely. 'personal information protection act' doesn't take account of the personal information's industrial utilization although it is legislated in 2011, which could be named as comparatively recent. And the law is insufficient for the control to information combination or profiling analysis, which are crucial phenomenon of big data since it's mainly about the manager of personal information. It would be hard to find the binding legislation or progressive argument on the personal information issue in big data circumstance such as profiling even in other countries. But, the international organizations has complemented the existing guideline by focusing on the invigoration of new data industry and many of national laws are trying to find out the appropriate regulation. Merely, the direction of regulation is not for the coherent regulation to the manager of personal information(for example, the prohibition of automatic profiling by EU GDPR, and guaranteed control). It's rather in the form of granting the big data within the frame of existing personal information norms. That is, they tend to resolve the matters with the domestic laws under the existing regulation system by clear personal information concept, mandatory regulation of false name or anonymous process, the flexibility of the consent system in the context of clear data process.
    Therefore, it is required to supplement the current law so as to present the obvious law interpretation standard and reflect the distinctiveness of the big data circumstance by legislation. But it should be allowed to utilize personal information based on 'personal information protection act' only when it is inherent with personal information protection value. Thus, the various legislation measure suggested in this thesis have a great significance in the change and adaptation to the new environment of our legislative system and to secure new systematic justification.
    Hence, the chapter 2 in this thesis refers to the juridical study on the definition that in the issue of 'personal information right' set off from the 'personal rights', it is necessary to take the economic utilization of personal information into account. It is for the purpose of supporting 'information privacy' as self-initiative right needed in information-oriented era. As we call it, 'personal information self-determination right' as a basic right guaranteed by the national constitution law would be the key standard to set the overall direction of personal information protection act by harmoniously balancing conflicting interests. For the actual effect, it is the prerequisite of discussing issuable positive law on personal information protection act that there should be the consensus of interests between the personal information business and subject(principal) of information.
    Following chapter 3 contains the comparative law analysis on the current trend of personal information protection act legislation overseas under big data circumstance. Judging that the trade and circulation of personal information is in the global scope, personal information protection act should be amended on the direction to secure international interoperability. It will be focused on the possible industrial utilization of the personal information by studying on the latest legislation trend in EU, USA, Japan, China, etc. Especially, the chapter3 mainly deals with EU GDPR and Japanese amended personal information protection act(2015) as they are similar to Korean legal system but proceeded to the enactment of new regulation and law revision.
    And the chapter 4 indicates the problems of current personal information protection act and proposes the actual effective legislation measure in the interest of industrial utilization of personal information. Specifically, it analyzed the problems of current law impeding invigoration of personal information utilization and made a suggestion on the available and reasonable improving measure of legislation and system according to the individual issues. Meanwhile, it is needed to look through 'information subject(principal) rights' articles which are reflected in many foreign legislations but less dealt in Korea such as 'Right of data portability', 'Automated individual decision-making including profiling)'. Because it is possible to achieve the secure personal information utilization based on personal choice and decision by guaranteeing the actual rights of personal information principle after imposing these systems. And the chapter5 is the conclusion of the thesis summarizing the significances and implications of the proposed legislation measures in Korean legal system.
    Though, it is important to take note that it shouldn't sacrifice or restrain a legitimate personal right simply for the personal information utilization and 'restriction on a right' articles to encourage innovative technology shouln't be approved in broad sense too. Afterall, it is desirable to amend the personal information norms in balance in order to protect personal information or privacy strongly. For this purpose, we need to shift our focus from the stereotype regarding big data and privacy as opposite to the more flexible and interactive integrated things granting the coherent technology value of personal information. In addition, the legal system should be established to enable the balancing conflicting interests in individual cases covering interest of information subject(principal) or public interest, not infringing the essence of personal information self-determination right which is constitutional.
    Finally, from this study, it would contribute not only to overcome the limit of current personal information protection act as a regulation impeding the efficient proliferation of information in big data industry, but also to enact the ultimate legislation purpose of personal information legal system requiring the balance of contradictive value(personal information protection and unconstrained circulation).

    더보기

    목차 (Table of Contents)

    • 제1장 서 론
    • 제1절 연구의 배경과 목적 1
    • 제2절 연구의 내용과 범위 3
    • 제2장 빅데이터 활용과 개인정보의 법적 문제
    • 제1절 빅데이터 활용과 개인정보의 침해 문제 6
    • 제1장 서 론
    • 제1절 연구의 배경과 목적 1
    • 제2절 연구의 내용과 범위 3
    • 제2장 빅데이터 활용과 개인정보의 법적 문제
    • 제1절 빅데이터 활용과 개인정보의 침해 문제 6
    • Ⅰ. 빅데이터의 등장과 개인정보 가치의 변화 6
    • 1. 빅데이터 기술의 출현 6
    • 2. 개인정보 가치에 대한 인식 변화 7
    • Ⅱ. 빅데이터 특성에 따른 활용상의 이점 8
    • 1. 빅데이터의 개념 및 특징 8
    • 가. 빅데이터의 개념 및 속성 8
    • 나. 데이터와 정보의 개념 구분 10
    • 다. 빅데이터 형태별 유형 11
    • 라. 기존 환경과 구분되는 특징 12
    • 2. 빅데이터의 유용성과 긍정적 기대효과 13
    • Ⅱ. 빅데이터 활용에 따른 개인정보 침해의 위험성 15
    • 1. 빅데이터의 위험과 규범 개입의 필요성 15
    • 2. 법규 위반 행위로서의 개인정보 침해 17
    • 3. 빅데이터 기술의 활용 단계별 침해 위험요인 17
    • 4. 빅데이터 처리상의 침해 유형 및 관련 사안 검토 19
    • 가. 정보 결합 및 분석을 통한 재식별화 위험 19
    • 나. 프로파일링 등 행위추적에 의한 사생활 침해 20
    • 다. 공개된 정보의 취합행위 21
    • 라. 개인정보 자기통제권 행사의 박탈 22
    • 마. 개인정보의 국제적 이전 및 유통의 증가 22
    • 제2절 빅데이터 환경에서 개인정보 규율의 변화 필요성 23
    • Ⅰ. 빅데이터 환경에서 정보 프라이버시의 재해석 23
    • 1. 프라이버시와 개인정보 보호영역의 구분 23
    • 2. 정보 프라이버시의 등장과 빅데이터 환경에의 의의 24
    • 3. 프라이버시 보호에 대한 각국의 접근방식 차이 26
    • 가. 미국의 경우 26
    • 나. 독일의 경우 28
    • 다. 비교법적 시사점 29
    • 4. 법익형량을 통한 규범적 대응의 필요성 30
    • Ⅱ. 빅데이터 환경에서 개인정보 규율의 특수성 31
    • 1. 개인정보의 개념 및 유형 31
    • 가. 개인데이터와 개인정보의 구분 31
    • 나. 개인정보의 개념 정의 31
    • 다. 법률상 개인정보의 일반적 유형 32
    • 2. 빅데이터 처리 과정에서 생성된 개인정보의 법적 취급 34
    • 가. 생성정보와 생산정보 34
    • 나. 관찰정보와 추론정보 35
    • 다. 개념 구별에 따른 법률상 실익 35
    • 3. 빅데이터 환경에서 개인정보 보호의 법적 성격 37
    • 가. 인격권적 성격 37
    • 나. 재산권적 성격 38
    • 다. 학설의 대립과 우리 법에의 적용 38
    • 제3절 빅데이터 환경에서 개인정보 이용의 법적 한계와 개선방향 39
    • Ⅰ. 빅데이터 환경에서 기존 개인정보보호 법리 적용의 한계 39
    • 1. 보편적 법리로서 공정정보관행 원칙(FIPPs)의 한계점 39
    • 가. 문제의 제기 39
    • 나. 최소수집 원칙의 한계 41
    • 다. 통지 및 동의 원칙의 한계 41
    • 라. 목적 구속 원칙의 한계 43
    • 2. 새로운 법리의 제안과 보완 방향 44
    • 가. 위험성 판단 모형의 내재화 44
    • 나. 데이터 접근 및 투명성 원칙의 강화 45
    • 다. 전후상황 원칙(Context Principle)의 적용 47
    • 3. 개인정보 보호법리의 적용 완화 필요성 48
    • Ⅱ. 개인정보 이용에 따른 헌법상 개인정보자기결정권의 제한 49
    • 1. 개인정보 보호와 이용의 헌법상 함의 50
    • 2. 개인정보자기결정권의 개념 및 효력 50
    • 3. 개인정보자기결정권의 제한으로서 기본권 충돌 53
    • 가. 제한적 법리의 적용 가능성 53
    • 나. 표현의 자유 및 알 권리의 충돌 53
    • 다. 공익적 목적과의 충돌 54
    • 라. 자발적 공개 정보와 영업상 자유의 충돌 55
    • 4. 개인정보 이용을 위한 헌법적 기준의 정립 필요성 56
    • Ⅲ. 개인정보의 안전한 이용을 위한 법적 과제 57
    • 1. 안전한 이용으로의 규제 초점 전환 57
    • 2. 개인정보 이용의 법적 한계와 개선방향 58
    • 가. 비정형 데이터의 증가와 규제 대상의 불확정성 58
    • 나. 비개인정보의 개인정보화 58
    • 다. 재식별화에 대한 법적기술적 판단 문제 59
    • 라. 동의제도의 실효성 한계와 대안적 방안 60
    • 제3장 빅데이터 환경에 따른 해외 법제의 변응
    • 제1절 개인정보보호 원칙에 대한 규범적 논의 63
    • Ⅰ. 기존의 개인정보보호 원칙 63
    • 1. 1980년 OECD 가이드라인의 8대 기본 원칙 63
    • 2. 기타 국제기구의 개인정보보호 원칙 64
    • Ⅱ. 개인정보보호 원칙의 변경 및 수정 논의 66
    • 1. 개정 OECD 가이드라인의 변경 취지 및 평가 66
    • 2. 기본 법리에 대한 수정 논의 동향 68
    • 가. 논의의 배경 68
    • 나. 미국에서의 논의 68
    • 다. EU WP29에서의 논의 69
    • 제2절 EU의 동향 70
    • Ⅰ. EU 개인정보 법제와 빅데이터 규율 70
    • 1. 개인정보 법체계 개관 70
    • 2. 빅데이터 규율의 관점에서 GDPR의 도입배경 72
    • Ⅱ. GDPR의 정보 활용 촉진에 관한 규율 방향 73
    • 1. GDPR의 적용 범위 확대 73
    • 2. 식별가능성에 대한 구체적 해석 기준 마련 74
    • 가. 개인정보 개념 범위의 명확화 74
    • 나. WP29 해석 기준과의 비교 75
    • 다. 기존 판례의 식별성 요건 판단 76
    • 3. 익명화 및 가명화를 통한 정보 이용 방안 확보 79
    • 가. 익명화 및 가명화의 개념 79
    • 나. 가명정보의 활용 방안 확보 81
    • 4. 목적 외 처리의 허용범위 확대 81
    • 가. 목적 외 처리와 양립가능성 판단 82
    • 나. 공적 기록보존 등의 목적 범주 82
    • 다. 기타 적용 배제 사유 84
    • 5. 빅데이터 서비스 관련 조항 마련 85
    • 가. 서 85
    • 나. 개인정보이동권의 신설 86
    • (1) 도입의 배경 및 취지 86
    • (2) 권리 행사의 요건 86
    • (3) 이동의 대상 및 방법 87
    • 다. 프로파일링 관련 권리의 보장 88
    • (1) GDPR상 프로파일링의 개념 88
    • (2) 권리 행사의 요건 및 내용 89
    • 라. 프라이버시 중심 설계의무 조항 신설 90
    • 제3절 일본의 동향 91
    • Ⅰ. 일본 개인정보 법제와 빅데이터 규율 91
    • 1. 개인정보 법체계 개관 91
    • 2. 빅데이터 규율의 관점에서 개정법의 도입배경 92
    • Ⅱ. 개정법의 정보 활용 촉진에 관한 규율 방향 93
    • 1. 개인정보 개념 및 보호대상의 명확화 93
    • 가. 개인정보 정의조항의 구체화 93
    • 나. 개인정보 개념의 구체적 해석 기준 마련 95
    • 다. 요배려개인정보 활용의 제한 95
    • 라. 정의조항 개선에 대한 평가 96
    • 2. 익명가공정보의 유통을 통한 정보 이용 방안 확보 97
    • 가. 익명가공정보 개념의 신설 및 취지 97
    • 나. 익명가공정보의 활용 범위 99
    • 다. 개인정보취급사업자와 익명가공정보취급사업자의 의무사항 99
    • 라. 공공 부문의 비식별 가공정보 활용 100
    • 3. 개인정보 이용의 목적 제한 완화 101
    • 4. Opt-out 방식의 투명화 101
    • 제4절 미국의 동향 102
    • Ⅰ. 자율 규제 방식의 법제와 빅데이터 규율 102
    • 1. 개인정보 법체계 개관 102
    • 2. 소비자 프라이버시 보호에 관한 규범적 논의 104
    • 가. FTC의 소비자 프라이버시 권고 104
    • 나. 미 백악관의 소비자 프라이버시 권리장전 105
    • 3. 빅데이터 규율을 위한 법제화 시도 105
    • 가. 프로파일링 관련 법안의 제출 106
    • 나. 최근 빅데이터 관련 입법 논의 106
    • Ⅱ. 개별법상 정보 활용 촉진에 관한 규율방향 107
    • 1. 보건의료 정보의 이용 촉진 107
    • 2. 비식별화 조치를 통한 정보 이용 방안 확보 108
    • 가. HIPAA Privacy Rule에 따른 비식별 조치 방법 108
    • 나. FTC의 비식별 조치의 내용 109
    • 제5절 해외 법제의 비교 및 시사점 110
    • 제4장 빅데이터 활용에 있어서 현행법상 쟁점 고찰
    • 제1절 국내 개인정보 법제와 빅데이터 규율상의 문제점 113
    • Ⅰ. 개인정보 법체계 개관 113
    • Ⅱ. 파편화된 규율체계로 인한 문제 114
    • 1. 문제의 제기 114
    • 2. 법률간 유사중복에 따른 해석상 혼동 115
    • 3. 다중적 법적 지위로 인한 사업자 책임의 가중 117
    • Ⅲ. 빅데이터 활성화를 위한 정책 추진체계의 비효율성 118
    • 제2절 빅데이터 활용을 저해하는 현행법의 내용과 문제점 119
    • Ⅰ. 빅데이터 환경의 특징과 우리 법제의 개선 필요성 119
    • Ⅱ. 개인정보 개념 및 범위의 불확정성 120
    • 1. 현행법상 개인정보 개념과 해석 120
    • 2. 빅데이터 환경에서 현행 정의규정의 문제점과 개선방향 122
    • 가. 해석론적 관점 123
    • 나. 입법론적 관점 123
    • 3. 식별가능성에 대한 법원의 해석기준과 평가 125
    • 가. 기존 판례의 검토 125
    • 나. 평가 128
    • 4. 식별성 판단기준의 해석론상 난점 128
    • 가. 문제의 제기 128
    • 나. 식별성 개념의 의미와 정도 129
    • 다. 식별성 인식의 주체 130
    • 5. 쉽게 결합하여의 의미와 해석기준 132
    • 가. 결합용이성의 의미와 해석 132
    • 나. 획득의 용이성에 대한 판단기준 133
    • Ⅲ. 비식별화 관련 기준의 구체성 결여 문제 135
    • 1. 비식별화 관련 개념의 이해 135
    • 가. 비식별화 및 유사 개념의 정의 135
    • 나. 해외 개념과의 구분 137
    • 2. 국내 비식별화 논의에 대한 비판적 검토 138
    • 가. 유권해석상의 혼란 138
    • 나. 개인정보 비식별 조치 가이드라인의 주요 내용 및 문제점 139
    • (1) 가이드라인의 주요 내용 139
    • (2) 가이드라인에 대한 평가 141
    • 3. 비식별화의 구체적 판단기준에 대한 검토 143
    • 가. 문제의 제기 143
    • 나. 학설의 대립 144
    • 다. 관련 판례의 해석 145
    • 라. 검토 147
    • 4. 비식별 정보의 목적 외 처리 한계 148
    • 가. 동의 원칙에 대한 예외적 처리 148
    • 나. 통계작성 및 학술연구 등 목적의 범위 149
    • 다. 개인정보 보호법 제18조 제2항 제4호의 해석 151
    • 라. 개인정보 보호법 제18조 제5항의 안전조치 범위 153
    • Ⅳ. 사전 동의제도의 실효성 한계 153
    • 1. 동의의 개념 및 법적 성질 153
    • 2. 국내외 동의 방식의 비교 154
    • 가. 외국의 입법례 154
    • 나. 국내 동의제도의 내용 및 방식 156
    • 3. 빅데이터 환경에서 현행 동의제도의 문제점과 개선방향 157
    • 가. 동의 취득의 난점 157
    • 나. 포괄적 동의 금지와 재동의 요구 158
    • 다. 동의 절차의 형해화 159
    • 라. 엄격한 요건으로 인한 영업의 장애 160
    • 마. 공개된 정보의 묵시적 동의 여부 161
    • 바. 개인정보 생성 시 동의의 요구 162
    • 4. 관련 판례의 검토 163
    • 제3절 빅데이터 활용 촉진을 위한 입법적 개선의 시도와 평가 165
    • Ⅰ. 빅데이터 관련 가이드라인의 마련 165
    • 1. 빅데이터 개인정보보호 가이드라인 165
    • 2. 개인정보 비식별 조치 가이드라인 165
    • Ⅱ. 빅데이터 활성화 관련 개인정보 보호법 개정 법안의 분석 166
    • 1. 개정안의 배경 및 취지 166
    • 2. 개정안의 주요 내용 및 평가 167
    • 가. 개인정보 개념의 세분화 167
    • 나. 결합용이성에 대한 구체적 판단 기준 마련 169
    • 다. 가명처리의 도입과 활용 범위 169
    • 라. 목적 범위 내 활용 범위 확대 170
    • 마. 데이터 결합 조항의 신설 171
    • 제5장 빅데이터 환경에서 개인정보의 안전한 이용을 위한 법적 제언
    • 제1절 현행법의 개선을 통한 개인정보 이용 방안 172
    • Ⅰ. 개인정보 개념의 재정립 172
    • 1. 기존 정의조항에 대한 수정 및 보완 172
    • 가. 식별정보와 식별가능정보의 구분 적용 필요성 172
    • 나. 개인 식별부호에 관한 예시조항 신설 174
    • 다. 결합용이성에 관한 해석 기준 보완 175
    • 2. 빅데이터 관련 개념의 정립과 그 활용 방안 176
    • 가. 공개된 정보의 활용 방안 176
    • 나. 빅데이터 환경 하의 특수한 정보 개념과 목적 외 처리 허용 177
    • Ⅱ. 익명화 및 가명화를 통한 개인정보 이용 확대 179
    • 1. 프라이버시 침해의 위험 수준에 따른 정보 활용 방안 179
    • 2. 익명화 및 가명화의 도입을 통한 목적 외 처리 확대 180
    • 3. 양립가능성 요건의 신설 181
    • 4. 현행 비식별 조치 가이드라인의 재편 182
    • 5. 데이터 결합 전문기관의 법제화 183
    • Ⅲ. 사전 동의제도에 대한 예외적 허용 확대 183
    • 1. 정보주체 권리 조항의 수정 183
    • 2. 예외적 허용 기준의 완화 184
    • 3. 제3자 제공 범위의 확대 186
    • 가. 개인정보 보호법 제17조 제1항 제2호의 개선 186
    • 나. 사후 동의 방식(Opt-out)의 부분적 도입 187
    • 제2절 자기통제 기반의 정보 이용 환경 조성방안 188
    • Ⅰ. 개인정보이동권의 도입 189
    • 1. 도입의 의의 및 이점 189
    • 2. 국내 도입 시 고려사항 190
    • Ⅱ. 자기통제 기반 정보서비스의 활성화 방안 192
    • 1. 프로파일링 관련 거부권의 부여 192
    • 가. 도입의 의의 및 취지 192
    • 나. 국내 도입 시 고려요소 193
    • 2. 자기통제권 강화를 위한 기술적 보호조치 마련 194
    • 가. 개인정보 보호 기술의 도입 필요성 194
    • 나. Privacy by Design에 근거한 사전적 기술의 도입 195
    • 다. Differential Privacy의 제도적 지원 195
    • 라. Do Not Tracking 방식의 의무화 196
    • 제6장 결 론
    더보기

    참고문헌 (Reference)

    1. 『빅 데이터가 만드는 세상』, 케네스 쿠키어, 빅토르 마이어 쇤버거, 21세기북스, , 2013

    2. 신구현 역, 『프라이버시와 고도정보화사회』, 堀部政男, 청림출판, , 1995

    1. 『빅 데이터가 만드는 세상』, 케네스 쿠키어, 빅토르 마이어 쇤버거, 21세기북스, , 2013

    2. 신구현 역, 『프라이버시와 고도정보화사회』, 堀部政男, 청림출판, , 1995

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼