학회장 인사말
학회소개
연혁 및 활동
조직 및 구성
정관
규정
공지사항
학회행사 안내
학회사진
학회지
세미나 자료
기타 회원논문
회원가입안내
회비납부안내
로그인

[20-3] Legal Concerns of Financial Institutions in the Big Data Era* - The Use of De-Identified Personal Information without Prior Consent under the Korean Privacy Laws -

Legal Concerns of Financial Institutions in the Big Data Era* - The Use of De-Identified Personal Information without Prior Consent under the Korean Privacy Laws -

빅데이터 활용에 관한 금융기관의 법적 고민- 비식별화된 개인정보의 사전동의 없는 이용과한국개인정보보호법을 중심으로 -

 

개요


저자  Cho, Hyechan(조혜찬)

권호 제20권 제3호

발행일 2017.01.09

요약


The importance of big data as a new source of industry development is rapidly on the rise globally. Commonly referred to as being in the “Big Data Era,” business analystsobserve that big data will create new value both in public and private sectors. Empirical research shows that the financial industry will perhaps benefit the most from big data capabilities by tilizing large amount of personal information.
Korea begins putting a significant value on big data potentials. Korean financial institutions have necessarily demanded deregulation of utilizing personal information to fully take dvantage of big data systems for their businesses. Likewise, the Korean government wants to promote a favorable environment for big data utilization. One tangible effort is to relax the regulatory burdens as shown in Big Data Personal Information Protection Guideline (“Big Data Guideline”) published by a governmental authority, the Korea Communications ommission. According to the guideline, personal information managers can collect, use and transfer publicly available information and customer’s usage history information without prior consent if the information is de-identified.
However, Korean regulatory agencies are rather cautious of allowing personal information utilization by virtue of big data because they experienced a series of high profile and serious personal information leakage incidents by big corporations in recent times. The Korean Personal Information Protection Act (“PIPA”), known as one of the far-reaching and austere personal information protection laws in the world, is a byproduct of this heightenedconcern. PIPA strictly requires prior informed consent when a person collects or utilizes other erson’s personal information.
With the backdrop of this arguably tense atmosphere in Korea, this thesis will attempt to deal with the relevant legal issues surrounding financial institutions’ use of publiclyavailable information and usage history information without prior consent. First, it is posited that it is too risky for financial institutions to solely rely on the Big Data Guideline because it is an administrative rule, lacking relevant statutory basis. Second, de-identification as a sole prerequisite to consent exemption is a vulnerable method. Information profiling enables re-entification of once de-identified personal information, and thus the re-identified information should be subject to PIPA’s prior consent requirement. Especially, much of usage history information is sensitive information where PIPA adds extra caution. Third, taking publicly available personal information for profit is against the Constitutional right of self-determination on personal information. In order to fully appreciate the merits of big data but minimizing infringement of personal information rights, this thesis delivers two possible suggestions. First, PIPA should be amended with possibly three options to relieve or relax the current statutory regulation. The administrative rule alone, possibly conflicting with PIPA, falls short of truly encouraging financial institutions to benefit the value of big data given the reality of harsh potential penalties under PIPA. Secondly, anonymization should be adopted instead of de-identification as a pre-condition to allow personal information utilization without prior consent as UK, EU and Japan.

 

목차


Ⅰ. Introduction
Ⅱ. Financial Institutions’ Use of Personal Information and Customers’
Awareness
1. Insurance Companies
2. Credit Card Companies
3. Banks
4. Customers’ Awareness
Ⅲ. The Korean Privacy Laws
*

첨부파일

08.-조혜찬.pdf

이전 목록으로 돌아가기 전체 목록으로 돌아가기

Designed and Developed by BRICKSPOON