DOI QR코드

DOI QR Code

A Legal Review of Personal Information Protection for Invigorating Online Targeted Advertising: Focusing on the Concept of Personal Information

온라인 맞춤형 광고 활성화를 위한 개인 정보 보호에 대한 법적 고찰: '개인 정보'의 개념을 중심으로

  • Cho, Jae-Yung (Department of Advertising and PR, Chungwoon University)
  • 조재영 (청운대학교 광고홍보학과)
  • Received : 2018.12.14
  • Accepted : 2019.02.01
  • Published : 2019.02.28

Abstract

This study analysed the legal concept of personal information(PI), which was not differentiated from behavioral information, and established it clearly for invigorating online targeted advertising(OTA), which draw attention in big data era; by selecting Guidelines of Assessment of Data Breach Incident Factors and Guidelines of Measures for No-Identifying Personal Information based on Personal Information Protection Act(PIPA) and Enforcement Decree of the PIPA. As a result, PI was defined as any kind of information relating to (1)a living individual(not group, corporate body or things etc.); (2)makes possibly identify the individual by his or her identifiers such as name, resident registration number, image, etc. (not included if not identify the individual); and (3)including information like attribute values which makes possibly identify any specific individual, if not by itself, but combined with other information which can be actually collected and combined). Specifically, PI includes basic, proper distinguishable, sensitive and other PI. It is suggested that PI concept should be researched continually with digital technology development; the effectiveness of the Guidelines of PI Protection in OTA, the legal principles of PI protection from not only users' but business operators' perspectives and the differentiation between PI and behavioral information in OTA should be researched.

본 연구에서는 빅데이터 시대에 주목을 받고 있는 온라인 맞춤형 광고를 활성화시킬 목적으로 기존 연구들에서 분명하게 규명되지 않았던 '개인 정보'와 '행태정보'의 의미를 명확히 하기 위해 '개인 정보'에 대한 법적 개념을 분석하였다. 분석 대상으로는 '개인정보보호법' 및 동법 시행령에 근거하여 마련된 '개인 정보 침해 요인 평가 지침'과 '개인 정보 비식별 조치 가이드라인'을 선정하였다. 결과에 의하면, '개인 정보'란, (1)살아 있는 개인(단체, 법인, 사물 등은 해당되지 않음)에 관한 모든 종류의 정보로서, (2)개인을 알아볼 수 있는 정보(식별자)이며 개인을 알아보기 어려운 것은 해당되지 않으며, (3)해당 정보 자체로는 개인을 알아볼 수 없어도 다른 정보와 쉽게 결합(결합 대상 정보의 입수 가능성, 결합 가능성이 있어야 함)하여 알아볼 수 있는 정보(속성자)를 포함한다. 보다 구체적으로, 개인 정보에는 기본정보, 고유식별정보, 민감정보, 기타 개인정보 등이 포함된다. 그리고 향후의 연구 방향으로서 기술 발달에 따른 '개인 정보' 개념에 대한 지속적인 연구, '온라인 맞춤형 광고 개인 정보 보호 가이드라인'의 실효성에 대한 연구, 이용자는 물론 사업자의 시각에서 본 개인 정보 보호의 법리에 대한 연구 및 개인 정보와 행태 정보의 명확한 구분을 전제로 한 온라인 맞춤형 광고 연구의 필요성 등을 제안하였다.

Keywords

Table 1. Counseling cases of breach incident of personal information

SHGSCZ_2019_v20n2_492_t0001.png 이미지

Table 2. Concrete personal informations(identifier) presented in the Guidelines of Assessment of Data Breach Incident Factors

SHGSCZ_2019_v20n2_492_t0002.png 이미지

References

  1. Korea Communications Commission. Guidelines for Protection of Personal Information in Online Behavioral Advertising, 2017. Available from: http://www.kcc.go.kr/user.do?boardId=1113&page=A050 30000&dc=&boardSeq=44427&mode=view (accessed Dec. 10, 2018)
  2. S. Y. Son, J. Y. Yu, "The Development of Online Advertising Industry and Privacy Violation", Korea Economic Forum, vol. 5, no. 3, pp.27-50, 2012. Available from: http://www.kea.ne.kr/common/download?id=1715§ion=pub
  3. J. J. Ahn, "Online Behavioral Advertising and Privacy", Journal of Cybercommunication Academic Society, vol. 30, no. 4, pp. 43-86, Dec., 2013. Available from: http://www.dbpia.co.kr/Article/NODE02330914
  4. Korea Internet & Security Agency. Report Center of Personal Information Violation [Ienternet]. Available from: https://blog.naver.com/hi_nso/221272246583 (accessed Oct. 10, 2018)
  5. S. Lee, "The Regulation Policy of the Personal Targeting Advertising based on Online Behavior Analysis", Journal of Media Law, Ethics and Policy Research, vol. 9, no. 2, pp. 49-73, Dec., 2010. Available from: http://www.dbpia.co.kr/Article/NODE01973443
  6. H. S. Ko, S. M. Lee, "An Analysis of Gathering of Personal Information by Major Korean Internet Sites", Korean Journal of Law And Economics, vol. 10, no. 2, pp. 181-216, 2013. UCI : G704-SER000010215.2013.10.2.001
  7. C. J. Hoofnagle, N. Good. The Web Privacy Census, October 2012 [Internet].. Available from http://law.berkeley.edu/privacycensus.htm. (accessed Dec. 10, 2018)
  8. S. Y. Park, "Critical Review of Guidelines for Protection of Personal Information in Online Behavioral Advertising", Journal of Consumer Policy Studies, vol. 48, no. 3, pp.205-231, 2017. URL http://www.dbpia.co.kr/Article/NODE07301773 https://doi.org/10.15723/jcps.48.3.201712.205
  9. S. K. Jang, "A Study on the Online Custom Advertisement and the Legal Law of User's Information Protection", Advertising Research, vol. 117, pp. 117-147, 2018. URL http://www.dbpia.co.kr/Article/NODE07511052 https://doi.org/10.16914/ar.2018.117.117
  10. Personal Information Protection Act. Available from: www.law.go.kr
  11. Korea Communications Commission. Guidelines for Protection of Personal Information in Online Behavioral Advertising, 2017. Available from: http://www.kcc.go.kr/user.do?boardId=1113&page=A05030000&dc=&boardSeq=44427&mode=view (accessed Nov. 15, 2018)
  12. Act on Promotion of Utilization of Information and Communications Network. Available from: www.law.go.kr
  13. Personal Information Protection Commission, Guidelines of Assessment of Data Breach Incident Factors. Available from: http://www.pipc.go.kr/cmt/search/unifiedDetailSearch.do
  14. Ministry of the Interior and Safety. Guidelines of Measures for No-Identifying Personal Information. Available from: https://www.mois.go.kr/frt/bbs/type001/commonSelectBoardArticle.do?bbsId=BBSMSTR_000000000015&nttId=55350
  15. Constitutional Court 2005. 5. 26. 99Heonma513 etc.; 2005. 7. 21. 2003Heonma282 etc.
  16. Ministry of the Interior and Safety. Press Release: Issued the Guidelines of Measures for No-Identifying Personal Information. Available from: https://www.mois.go.kr/frt/bbs/type010/commonSelectBoardArticle.do?bbsId=BBSMSTR_000000000008&nttId=55287