상세 보기
개인정보보호법상 금지행위 규정의 의무주체 요건
- 유지현;
- 변종필
초록
Article 59 of the Personal Information Protection Act (PIPA), under the heading “Prohibited Acts,” provides that “a person who processes or has processed personal information shall not commit any of the following acts.” It then prohibits: (i) in subparagraph 1, “acquiring personal information or obtaining consent for processing by deception or by any other wrongful means or methods”; (ii) in subparagraph 2, “disclosing personal information learned in the course of one’s duties or providing it for use by another person without authority”; and (iii) in subparagraph 3, “using, damaging, destroying, altering, forging, or leaking another person’s personal information without legitimate authority or beyond the scope of permitted authority.” Acts falling under (i) constitute the offence under Article 72(2) of the PIPA, those under (ii) constitute the offence under Article 71(9), and those under (iii) correspond to the offence under Article 71(10). In contrast to most penal provisions of the PIPA, which designate a “personal information controller” as the duty-bearer, the perpetrators of offences under each subparagraph of Article 59 are defined as “persons who process or have processed personal information.” This difference in statutory language has given rise to various theoretical and practical issues concerning the meaning and scope of “persons who process or have processed personal information.” This article, adopting the format of case commentaries on relevant judgments (Supreme Court Decision 2015Do8766; Seoul High Court Decision 2018No2498; Daejeon District Court Decision 2019No3644; Seoul Western District Court Decision 2020No713; Busan High Court Decision 2019No365), has sought to comprehensively address practical disputes frequently arising in connection with the perpetrator element of these offences. The author’s conclusions are as follows: In light of the statutory text of Article 59 and the legislative purpose of the PIPA to protect the right to informational self-determination, the “persons who process or have processed personal information” subject to the obligation in this provision should be interpreted as a concept distinct from “personal information controllers.” The reasoning of the Supreme Court in Decision 2015Do8766, which adopts this view, can be regarded as sound. Although, in relation to the application of Article 59(2), that decision may at first appear to lack precision by extending the qualifier “learned in the course of one’s duties”—which defines the object element of the offence—to the perpetrator (or status) element, in substance it reaches a conclusion consistent with the intent of the statutory text. Seoul High Court Decision 2018No2498 attempts a purposive restrictive interpretation by refining the criteria in the above Supreme Court judgment. However, some of the arguments it advances do not logically lead to its conclusion, or reflect a partial misunderstanding of the structure of the PIPA’s provisions on prohibited acts, and are therefore inadequate. Moreover, its policy-oriented aim of narrowing criminal liability risks unjustifiably excluding punishable conduct from the scope of Article 59(2). As the statutory text provides, if a person who “processes or has processed” personal information “learned in the course of one’s duties” “discloses” such information, the offence under Article 59(2) is established. There is no need to construe “duties” here as limited to “personal information processing duties.” The wrongful acquisition or unauthorized leakage of another person’s personal information—whether or not done in the course of duties—should be regarded as culpable conduct infringing the data subject’s right to control his or her own information. In offences under Article 59(1) or (3), the gravity of unlawfulness depends not on whether the perpetrator’s conduct is work-related, but on the extent to which the data subject’s rights are infringed. Article 59 functions as a final and supplementary regulatory provision (a “safety-net function”) over the entire process of personal information handling by comprehensively prohibiting acquisition or processing beyond legitimate authority. Imposing an additional requirement of work-relatedness for the perpetrator element lacks textual basis, is inconsistent with the general legislative approach of expressly providing such a requirement where intended, and would create regulatory blind spots, thereby undermining the supplementary function described above. In this respect, the standard articulated in Busan High Court Decision 2019No365 is appropriate, whereas the criteria set forth in Daejeon District Court Decision 2019No3644 and Seoul Western District Court Decision 2020No713 cannot be deemed sound.
키워드
- 제목
- 개인정보보호법상 금지행위 규정의 의무주체 요건
- 제목 (타언어)
- Who is Considered the Actor in Violations of Article 59 of the Personal Information Protection Act?
- 저자
- 유지현; 변종필
- 발행일
- 2025-09
- 유형
- Y
- 저널명
- 형사정책연구
- 권
- 36
- 호
- 3
- 페이지
- 1 ~ 49