Y^Z
*
1)( 2017.4.7.
2016 61242 2016 13263 ) -
. . 1.
2.
3.
4.
(1) (2)
.
* 2017 - .
**
: 2017. 4. 30. / : 2017. 5. 26. / : 2017. 5. 31.
Y^[
.
.1)
2) 3)
. 2016 2018 5 25 GDPR4)
. 2017 4
FCC
‘Privacy of customer information’5)
.6)
. 7) 8)
1) 2005.5.26. 99 513 2004 190( ) (
17 8 ); 2005.7.21. 2003 282·425 (NEIS );
1995.12.28. 91 114 (
40 , 10 ); 1998.7.24. 96 42789 (
) ; BVerfGE 95,1.
2) , 21
, , 2015, 60-74 ; 2015.7.30. 2012 734 ; 2010.2.25.
2008 324·2009 31( ) ; 2005.5.26. 99 513 ;
2016.3.10. 2012 105482 ; 2012.12.27. 2010 79206 .
3) , “ : ”,
, . , 2002, 986 ;
2005.7.21. 2003 282 425( ) .
4) General Data Protection Regulation/GDPR(Datenschutz-Grundverordnung/DSGVO).
5) 47 U.S. Code § 222 Privacy of customer information;
<http://uk.pcmag.com/news/88516/gop-senators-hand-control-of-your-data-to-isps>, 2017.3., : customer information.
6) , “
”, 46 , 2014.6.30., 15 .
Y^\
9) .
.
. ,
‘ ’
. ‘
’(2016) . .
.10)
( ) 2011 3
.
‘ · ’( )
, 1 2
.
( )
7) , “
IT- ”, 46 , 2014.6.30.,
151-165 .
8) , 21 ,
, 2015, 15-16 .; , “ ”, 46 ,
2014.6.30., 123-135 .
9) , “
”, 46 , 2014.6.30., 92-107 . 10)
( 2005.5.26. 99 513 ; 2005.5.26. 2004
190 ; 2011.9.2. 2008 42430 ); 2016.8.17. 2014
235080 ( ); 2011.9.2. 2008 42430 (lawmarket ).
Y^]
. 2
22 2
(2017.4.18.) . 2017 10 19
. .
.
.
.
.
( ) 2011.8.11.
2014.6.18. 12 . ,
, “ 10 ”, “
14 ”, 2014 ,
”, “ , ”, “
5 , ”
, ,
7
. ,
712 1 1,980 7
Y^^
148
1,694 765 ( 190
) 929 ( 253 ) ,
1 2,800 83 5 .
231 . .11)
“
, 3
‘ ’
.
.” .
3 1 2 ‘
·
· .
9 12 , 14 15 .
“
, ,
3 3
”
4 3,500 12)
11) 2016.10.19. 2015 45177 .
Y^_
.13) ,
3 1 2
.
.
“
.
, 3
.
. 3
,
.” .
“ 1 mm(4 point)
. ‘
.’ ,
‘ .’
” .14)
12) ‘ ’ 2012-62 .
13) 2015.5.1. 2015-138 .
14) 2016.10.19. 2015 45177 .
Y^`
( 2 1 ),
.
3
.
.
85 ‘ · ’ II. 3 ·
‘
, · ’
3
‘ ’
· . 1 mm(4 point)
. ‘ · ’15)
·
· .
·
.16) ,
15) 2014-8 .
16) 2013.6.14. 2011 82 .
Y_W
, , ,
. ·
,
.17)
2 .18)
‘
.
. 3
1 mm(4 point)
, ,
,
. 15
( ) .
.’ .
17) 2017.4.7. 2016 61242 .
18) 2016.1.8. 2015 510 .
Y_X ,
3
3
3 1
2 .
‘ ,
, , ’ 16 1
2 3
. 1 mm(4
point)
22 1
. 72 2
.
‘ DB
DB (filtering)
(permission DB)
3 ’
. , ‘ 3 ’
, ‘ ’
. , ,
,
.
‘permission DB’
Y_Y Telemarketing
, DB
3
. 15 1 2 ,
3 5
17 1 2 1
3
71 1 24 , 24 2 1 2
26 3 71 3
.
.
.
.
3 ‘
’ .
Y_Z
3 1 2 3 2 ‘
’ ‘
’ .19)
‘ ’
.
, ,
‘ 3
’
. ‘ ’,
‘ ’, ‘ ’
, 4 point (
) ,
.
. .
3 ( )
19) 2014.12.24. 2012 26708 .
Y_[
.
. .
‘ ’
.
‘
’ , ,
, , .20)
.21) ‘ ’
.22) .23)
.24)
.
20) 2016.8.17. 2014 235080 ; 2014.7.24. 2012 49933 .
21) , “ ”, 17 , , 2011.12., 223-248
22) 2005.5.26. 99 513 ; 2005.5.26. 2004 190 ;
2015.10.15. 2014 77970 ( ).
23) 2014.7.30. 16 .
24) EU-Datenschutzbeauftragte Empfehlungen für den Cookie-Einsatz(20.6.2012).
Y_\
‘ ’
. , ‘ · ’
· ,
·
.25)
‘ ’
.26) ‘ ’
‘ ’
‘ ’ ‘ ’
.27) ‘
’ ‘
’ .
‘ ’
.
‘ ’ ‘
’ ‘ ’ .
25) 2017.4.7. 2016 61242 .
26) 2015.2.12. 2013 43994 ( ).
27) 1 ( ) 28 1 15
6 ( 67 )
‘ ’ .
Y_]
.
.
,
.
.
.
6 ,28)
.29)
.
28) , “
”, 41 , , 2013, 133-157 ; , “
-”, , , 2014, 145-162 .
29) 2017.4.7. 2016 13263 .
Y_^
(data broker)
2004 KT
‘ ’30)
.
. DB
31) (2011.9.30. )
.32)
18 2 4
‘ ’ . ‘ ’
2016 6 ‘ ’
( )
.
(NSA) 1 ‘
’ 30 3
, 2 1 6
‘
.’
‘ .’
.33)
30) http://www.sodis.co.kr/index.jsp(2004). ‘ ’
( ).
31) , “ ”, ·
, , 2011.11., 12 .
32) , 21 ,
, 2015, 87-90 .
33) 2016.12.22. 2015 2065729 .
Y__
.
‘ ’
17 18
.34)
‘ ’
.35) ,
, DB ‘
,
, ,
,
,
.’ .36)
‘ ’
.
’
.37)38)
34) 2012.10.15. .
35) 2012.6.14. (
).
36) 2016.8.17. 2014 235080 .
37) , “ , , ”,
54 4 , , 2013.11., 27-46 .
Y_`
16 1 , 2 3 , 3
17 1 2 ,
22 1 ,
59 1
72 2 . 72 2 ‘
’
.
,
, ,
. 24 , 24 2 1 2
26 3 71 3 .
16 . , “
.
( 1 ).
( 2 ).
( 3
38) 2011.9.2. 2008 42430 (lawmarket ).
Y`W
).” .
‘ , ,
, ’ 16 1 3
.
24 2 23 2
. .
3 ‘
3 ’
, ‘ ’
.39)
.40) ‘
, , ,
.’ . ‘permission DB’
Telemarketing ,
DB
39) / , “ 3 ”,
, , 2014, 233-248 .
40) , “
‘ 3 ’ ‘ 3 ’ ”, 14 1 ,
2009.9., 1 .; 3
. .
.
.; / / ,
, 2016, 184 .
Y`X
3 .
3
71 1 24 , 24 2 1
2 26 3 71 3
. 1 mm(4 point)
22 1 .
GDPR 12 1 ‘
, ,
.
.’ .
‘ ’
.
84 99
. .41)
.
42)
41) 83 ( ) 91
,
. 99 ( )
83
, , .
, · .
42) 2016.8.12. 2016 223 .
Y`Y
22
2017.4.18. 2017.10.19. .
.
22 1 ‘
.’ . 2 .
‘ 1
, ,
.’ .
, ,
, 3 ‘
’ . ·
, , ‘ ’
. ‘ ’ .
‘ ’
·
‘ ’
.
. 2 4 ‘
.’ . GDPR
12 ‘ , , ’
.43)
43) GDPR , , ,
2015.10.; EU , , 2015.1. .
Y`Z
24 2
3
‘ , ,
,
’(4 )
. 2016 12 24 2 5 ‘ ’
.
.
( )
, .
.
.
.
.
.
Y`[
.
. ‘ (NSA)
’
.
.
. ,
3
4 point
‘
.
.
.
2017 10 , 4
‘ ’
Y`\
.
. ,
,
.
Y`]
, “ : ”,
,
. , 2002.
, “ ”, 46 , 2014.6.
, “
IT- ”, 46 , 2014.6.
, “ ‘ 3
’ ‘ 3 ’ ”,
14 1 , 2009.9.
, “ ”, 41
, , 2013.
, “ ”, 46 , 2014.6.
, “
”, 46 ,
2014.6.
, “
-”,
, , 2014.
, “ ”, ·
, , 2011.11.
/ , “ 3 ”,
, , 2014.
, “ , ,
”, 54 4 , , 2013.11.
“ ”, 17 , , 2011.12.
, “ ”, 46 , 2014.6.
Y`^
, , , 2012.
, 21 , , 2015.
, , , 2015.10.; EU
, , 2015.
/ / , ,
2016.
Y`_
< >
7
‘ ’
3 1 2 ‘
·
·
.’ ·
.
. .
‘ ’
.
.
‘ ,
, , ’
16 1 2 , 1 mm(4 point)
3
17 22 1 .
72 2 ‘
’ .
‘ ’
Y``
. 3
15
24 24 2 . 22
2
(2017.10.19. ).
24 2 5 ‘
’ .
.
Journal of Legislation Research / 52th Issue
ZWW
Studying on commercial sales of personal information and conditions
- Focused on the Home-Plus case of the Supreme Court -
LIM, Gyeo-Cheol*44)
The Fair Trade Commission and the Supreme Court in Korea ruled that Home-Plus and seven insurance companies intentionally did not notice
‘paid-for-sale of personal information’ to data subject and user for collecting personal information. It also violated the principle of minimum collecting.
Therefore they was liable for the violation of the Personal Information Protection Act in Korea Articles 16, 17 and 22. Considering the situation as a whole judged the Supreme Court that the act of Home-Plus is 'to be regarded as a person who acquires personal information or agrees to deal with personal information through false or other illegal means or methods' did. The court also judged the violation of the Display Advertising Act judging as a deceptive advertising. In the case of judgment under the Information and Communications Network Act in Korea, it was judged to be a violation of Article 24 and Article 24-2 in addition to Article 15 which is a violation of use within the purpose of collection. And to impose a duty on the personal information processor to make clear notice of consent through the amendment of Article 22(2) of the Personal Information Protection Act and the enforcement decree and the enforcement regulations(10.19.2017). In the contents of the statutory notice of Article 24-2(5) of the Information and Communications Network Act, ‘paid-for-sale of personal information’ is included(Committee pending).
* Prof., Dongguk Univ. College of Law.
Abstract
ZWX :