구두 답변 · 2019-02-12 · 국회 13

공공기관 데이터 보호 면제 조항 심의

의원은 개인정보 보호법을 개정하고 공공기관 면제 조항을 폐지하여 데이터 유출 위험에 대응해야 하는지 질문했습니다. 정부는 공공부문이 데이터 보안을 보장하기 위한 다양한 법률과 정책을 이미 갖추고 있으며, 공공부문의 데이터 관리가 민간부문과 다르고 다른 법적 체계를 적용하고 있으며 관련 규정을 계속 검토할 것이라고 강조했습니다. 핵심 논쟁은 공공기관의 데이터 보호를 개인정보 보호법에 포함시켜 통일된 감독을 해야 하는지 여부입니다.

핵심 요점

  • Public-sector data has multiple legal safeguards
  • Public-sector data management differs from private sector
  • Will continue reviewing the regulations
정부 입장

공공부문 데이터는 다양한 규정으로 보호되며, 현행 면제 유지

질의 입장

공공기관 데이터 보호 면제 취소 제안

정책 신호

공공부문 데이터 거버넌스 지속 강화

“Because of these important differences, we need and have adopted different approaches to the protection of personal data in the public and in the private sectors.”

참여자 (3)

전문 번역(한국어)

Hansard 원문 · 2026-05-02

12번 의원 Sylvia Lim이 통신정보부장관에게 공공부문 데이터 보호 위반의 심각성을 감안하여 「개인정보보호법」을 개정하고 공공기관에 대한 적용 제외를 폐지해야 하는지 묻습니다.

통신정보부장관(S Iswaran 선생)이 답변합니다: 의장님, 「개인정보보호법」(PDPA)은 2012년에 시행되었습니다. 디지털화 진전이 가속화됨에 따라 우리는 민간부문의 데이터 보호를 강화해야 할 필요성을 인식했습니다. PDPA는 민간부문에 대한 데이터 보호의 기본 기준을 수립했으며, 동시에 개인정보의 합리적 이용에 대한 필요성을 균형 있게 고려했습니다.

정부는 공공부문에 위탁된 데이터를 보호할 책임을 진지하게 다루어왔으며, 계속해서 데이터 거버넌스 정책을 강화하고 있습니다. 2001년 이래로 정부 지침(IM)에는 공공기관 간의 개인정보 사용, 보유, 공유 및 보안을 관리하는 조치가 포함되어 있습니다.

2018년에 「공공부문(거버넌스)법안」(PSGA)이 제정되어 공공부문 개인정보에 대한 추가 보장을 제공했으며, 공직자의 데이터 남용 행위를 형사범죄로 규정했습니다. PSGA의 데이터 보호 기준도 PDPA와 일치합니다. 또한 공공부문이 수집한 데이터는 「관방기밀법」, 「소득세법」, 「전염병법」 및 「통계법」 등 특정 법률에 의해 보호됩니다. 이들 법률은 모든 공공기관에 높은 기준의 책임을 부과하며, 민감하거나 기밀 데이터의 보호에 대한 추가 요구사항이 있습니다. 동시에 정기적인 강제 감시를 실시하여 공공기관이 데이터 보호 및 정보통신기술 시스템 보안 기준을 준수하는지 확인합니다.

PSGA는 개인정보를 공공부문의 공동 자원으로 관리하여 더 나은 정책 수립과 더욱 반응성 있는 공공 서비스를 촉진할 수 있도록 합니다. 예를 들어, 싱가포르 국민이 사회서비스 사무소에서 경제 지원을 신청할 때, 일선 직원은 다른 관련 기관의 데이터에 접근할 수 있기 때문에 신청자의 자격을 빠르게 평가할 수 있습니다. 이런 방식으로 우리는 신청자가 제출해야 하는 서류의 수를 줄이고 공공 서비스의 효율성을 높입니다. 대조적으로, 각 민간부문 조직은 보유한 개인정보에 대해 개별적으로 책임을 지며, 서로 다른 상업 조직 간에 유사한 서비스 통합을 기대하지 않습니다.

이러한 중요한 차이들을 감안할 때, 우리는 공공부문과 민간부문의 개인정보 보호에 대해 다른 접근방식을 취했습니다. 이것이 PDPA는 오직 민간부문에만 적용되고, PSGA와 다른 법률은 공공부문 데이터 보호를 규범하는 이유입니다. 우리는 PDPA, PSGA 및 기타 법률을 정기적으로 검토하여 공공부문 및 민간부문의 개인정보 보호에 있어서 관련성과 효과성을 유지할 것입니다.

의장: Sylvia Lim 의원.

Sylvia Lim 의원(아유낭 선거구): 저는 네 가지 추가 질문이 있습니다. 먼저, 부장관이 언급한 각종 규정과 IM이 실제로 공공 서비스의 기준을 설정했음을 인정합니다. 하지만 부장관은 이러한 규정이나 IM이 일반적으로 데이터 유출 시 시민이 취할 수 있는 구제 조치에 대해 침묵하거나 불충분한가에 동의하십니까? 이들은 규정 위반 공직자에 대한 처벌이 더 엄할 수 있지만, 일반적으로 시민의 권리에 대한 명확한 규정이 부족합니다.

둘째, 부장관은 PDPA의 장점 중 하나가 조직의 데이터 수집 필요성과 개인의 데이터에 대한 소유권 및 보호 권리 사이의 균형을 맞추려고 시도한다는 점에 동의하십니까? 예를 들어, 제3조는 개인정보가 개인에게 속하며 개인은 자신의 데이터를 보호할 권리가 있음을 명확히 인정합니다.

셋째, 우리는 최근 SingHealth 사건에 대해 논의했습니다. 부장관은 SingHealth가 PDPA 규제 범위 내의 기관이며 법안에서 정의한 공공기관이 아니기 때문에, SingHealth 사이버 공격 사건이 개인정보보호위원회(PDPC)가 공익 측면에서 매우 유용한 역할을 할 수 있음을 보여준다는 점에 동의하십니까? PDPC는 해당 사건에서 시민이 자신의 데이터가 SingHealth에 의해 충분히 보호되지 않았다고 불평했으며, PDPC의 조사 결과가 SingHealth와 통합 의료 정보 시스템(IHiS)의 개선을 촉발할 수 있다고 지적했습니다.

마지막으로, PDPA는 실제로 불만 처리 절차를 제공하며, 부장관이 이것이 시민에게 매우 유용하다고 확인해 주기를 바랍니다. 왜냐하면 시민이 손해에 대해 정부 기관을 상대로 소송을 제기하도록 강제하지 않기 때문입니다. 이것은 PDPA가 시민에게 제공하는 실질적인 이점입니다.

S Iswaran 선생 답변: 의장님, 의원의 의견 감사합니다. 모든 내용이 질문인지는 확실하지 않으며, 일부는 관찰에 더 가깝지만 해석해 보겠습니다.

먼저 강조하고 싶은 점은 공공부문이 PDPA에서 「면제」된다고 할 때(의원께서 사용하신 용어처럼), 이것이 공공부문이 데이터 안보와 보호 측면에서 기준이 더 낮거나 다르다는 의미는 아니라는 것입니다. 실제로 제가 앞서 언급했듯이, 공공부문, 특히 PSGA는 PDPA를 참고하여 대체로 일치합니다. 하지만 동시에 공공 서비스가 효율적인 서비스 제공을 위해 데이터를 사용하는 방식과 기대가 다르다는 점을 명확히 인식하고 있으므로 다른 데이터 거버넌스 방법이 필요합니다. 이것이 우리가 차별화된 접근방식을 취하는 이유입니다. PSGA 외에도 우리는 다른 관련 법률을 가지고 있습니다.

의원께 참고가 되도록, 우리는 이러한 접근방식을 취하는 유일한 국가가 아닙니다. 예를 들어, 캐나다 연방 차원에서도 민간부문과 공공부문에 다른 법률을 적용합니다. 따라서 이것은 기준이 다르거나 문턱이 다른 문제가 아닙니다. 실제로 우리는 공공부문에 동일하거나 더 높은 데이터 거버넌스 기준을 적용합니다. 왜냐하면 공공부문에 위탁된 데이터는 신뢰를 기반으로 하며 안전하게 처리되어야 합니다.

의원이 제기한 많은 질문들은 PDPA의 요소들, 예를 들어 공중이 PDPC에 데이터 권리 문제에 대해 불만을 제기할 수 있는 불만 절차와 더 관련이 있습니다. 의원은 PDPA가 개인정보 보호 권리와 기업의 데이터 사용 권리 사이의 균형을 맞춘다고 지적했으며, 이것은 실제로 공공부문이든 민간부문이든 우리가 노력하는 방향입니다. 공공부문은 동등하게 개인정보를 보호해야 하면서 동시에 시민에게 더 나은 서비스를 제공하기 위해 그것을 공공 자원으로 활용해야 합니다. 우리가 당연하게 여기는 많은 서비스들은 백그라운드 데이터 공유에 의존합니다.

불만 절차에 관해서는, 자신의 데이터가 부당하게 처리되었다고 생각하는 모든 개인은 불만을 제기할 수 있으며, 여러 채널이 있습니다.

SingHealth 사건에 관해서는, 의원이 PDPC가 유용한 제안을 제시했다고 언급했습니다. 실제로 전체 사건의 핵심 제안은 정부가 설립한 조사위원회(COI)에서 나왔습니다. PDPC는 초기에 불만을 받았기 때문에 COI의 조사 결과를 참고하여 관련 기관(SingHealth과 IHiS)이 위반했는지 및 어떤 처벌을 받아야 하는지 판단하기로 결정했습니다. 대부분의 제안은 법적 강제가 아닌 정부 주도의 COI 절차를 통해 제시되었습니다.

구제 문제에 관해서는, 공중이 자신의 데이터가 부당하게 처리되었다고 생각할 경우, 부장관, 관련 부처에 불만을 제기할 권리가 있으며, 정부가 조치를 취할 것입니다. 범죄로 간주되는 경우, 또한 경찰에 신고할 수 있으며, 경찰이 조사할 것입니다.

요약하면, 우리는 공공부문에 동일하거나 더욱 엄격한 데이터 거버넌스 기준을 부과합니다. 그렇지 않다면 우리의 스마트 국가 건설과 디지털 기술을 활용하여 공공 서비스를 개선하려는 노력이 방해받을 것입니다. 이것이 우리가 이 문제를 진지하게 다루는 이유입니다. 전체적으로 PSGA는 공공부문 데이터 거버넌스 법칙으로서 PDPA를 참고했으며, 우리는 특정 분야를 대상으로 하는 다른 법률도 보유하고 있습니다.

의장: Sylvia Lim 의원.

Sylvia Lim 의원: 저는 두 가지 추가 질문이 있습니다. 먼저, 부장관이 앞서 공중이 자신의 정보가 공공기관에 의해 부당하게 처리되었다고 생각할 경우 불만을 제기할 수 있다고 언급했습니다. 문제는 누구에게 불만을 제기하는가입니다. 부장관은 부장관에게 불만을 제기할 수 있다고 언급했습니다. 부장관은 개인정보 보호에 중점을 둔 PDPC가 이러한 불만을 받는 역할을 맡아야 한다는 점에 동의하십니까? 왜냐하면 결국 그들은 개인정보 보호 분야의 전문가이기 때문입니다.

둘째, 부장관이 공공부문 기관들이 상호 연결되어 있기 때문에 다른 접근방식이 필요하다고 언급했습니다. 하지만 SingHealth 사건은 또한 의료 분야에 어떤 인위적 구분이 존재함을 보여줍니다. SingHealth는 PDPA에서 정의한 공공기관에 속하지 않지만, 보건부(MOH)와 긴밀하게 연결되어 있으며, 실제로 MOH Holdings가 소유하고 있으며, 의료기관과 모 부서 간에 자주 데이터를 교환합니다. 부장관은 제 데이터가 어떤 의료 그룹의 진료소에 전달되면 PDPC에 불만을 제기할 수 있지만, 데이터가 보건부로 전달되고 그곳에서 유출이 발생하면 PDPC를 통해 구제를 받을 수 없다는 점에 동의하십니까? 이것이 의료 분야에서 어떤 인위적 구분을 만들어냅니다.

S Iswaran 선생 답변: 의장님, 공공 의료 시스템 관련 사항과 관련된 부장관 성명이 예정되어 있음을 감안할 때, 제 답변은 간략하고 후속 성명 후에 추가 설명을 할 수 있습니다.

강조하고 싶은 점은 공중의 「구제」라는 용어가 이번 교환에서 여러 번 나왔다는 것입니다. 핵심은 구제 경로가 반드시 있어야 한다는 것입니다. 구제가 PDPC, PDPA, 법률 또는 다른 적절한 메커니즘을 통하든 간에, 핵심은 반드시 존재해야 한다는 것입니다.

저는 개인이 구체적인 상황에 따라 불만을 제기할 수 있다고 말씀드렸습니다. 참고로, PDPC는 때때로 공공부문과 관련된 불만도 받습니다. 수신자로서 PDPC는 거절하지 않고 관할권에 따라 PDPA 범위에 속하지 않는 사건을 관련 정부 기관으로 전달합니다. 정부기술청(GovTech)은 정부 데이터 보안과 보장 시스템을 담당하며, 정부 기관이 IM 및 관련 규정을 준수하는지 확인하기 위해 검토를 수행합니다. 또한, 감사원도 불정기적으로 보안 검토를 수행합니다.

제 관점은 공중이 구제 경로의 부족을 걱정할 필요가 없다는 것입니다. 실제로 그들은 여러 구제 채널을 가지고 있습니다. 민간부문과 비교할 때, 공공부문은 어떤 측면에서 더 많은 채널과 경로를 가질 수 있습니다. 민간부문은 일반적으로 PDPC에만 불만을 제기하거나 스스로 법적 소송을 제기할 수 있는 반면, 공공부문은 PDPC, GovTech, 관련 부처 및 경찰 신고 등 다양한 경로를 통해 도움을 받을 수 있습니다.

따라서 의원들은 의심의 여지 없이, 우리는 적절한 구제 메커니즘을 갖추고 있습니다. 공공부문 데이터 거버넌스 기준은 결코 민간부문보다 낮지 않으며 오히려 더 높습니다. 이것이 우리의 기대입니다.

영어 원문

SPRS Hansard 원본 기록 · 수집일: 2026-05-02

12 Ms Sylvia Lim asked the Minister for Communications and Information given the gravity of data protection breaches in the public sector, whether the Personal Data Protection Act should be amended to remove the exemptions for public agencies.

The Minister for Communications and Information (Mr S Iswaran) : Mr Speaker, the Personal Data Protection Act (PDPA) came into force in 2012. With the gathering pace of digitalisation, we recognised the need to strengthen data protection in the private sector. PDPA establishes a baseline standard for data protection in the private sector, balanced against its need to use personal data for reasonable purposes.

On its part, the Government has always taken seriously its responsibility to protect the data entrusted to the public sector and we continue to strengthen our data governance policies. Since 2001, the Government Instruction Manuals (IMs) already include measures to govern the use, retention, sharing and security of personal data among public agencies .

In 2018, the Public Sector (Governance) Act (PSGA) was introduced and it provided for additional safeguards for personal data in the public sector, including criminalising the misuse of data by public servants. The data protection standards in PSGA are also aligned with the PDPA. In addition, data collected by the public sector is also protected by specific legislation, such as the Official Secrets Act, the Income Tax Act, the Infectious Diseases Act and the Statistics Act. Collectively, these laws impose a high standard of responsibility on all public agencies, with additional requirements for the protection of sensitive or confidential data. Also, regular mandatory audits are conducted to ensure that public agencies comply with the standards for data protection and the security of information and communications technology systems.

PSGA allows personal data to be managed as a common resource within the public sector for better policymaking and also for more responsive public services. For example, when a Singaporean applies for financial assistance at a Social Service Office, the frontline officers are able to quickly evaluate his or her eligibility for financial assistance because they have access to data from other relevant agencies. In this way, we minimise the documents that need to be submitted by the applicant and improve the delivery of public services. In contrast, each private sector organisation is expected to be individually accountable for the personal data in its possession, and there is no expectation of a similar integrated delivery of services across different commercial organisations.

Because of these important differences, we need and have adopted different approaches to the protection of personal data in the public and in the private sectors. That is also why the PDPA applies only to the private sector, while the PSGA and other legislation govern data protection in the public sector. We will regularly review the PDPA, PSGA and other legislation to ensure that they remain relevant and effective in safeguarding personal data in both the public and private sectors.

Mr Speaker: Ms Sylvia Lim.

Ms Sylvia Lim (Aljunied) : I have four supplementary questions for the Minister. The first question is, I acknowledge that the various statutes and the IMs, as the Minister mentioned, do set out standards for the Public Service to comply with. Does the Minister agree, however, that these instruments, legislation or IMs are usually silent or weak on the recourse that citizens may have if there is a data breach? They may be strong on penalties for errant officers but, generally, we get silences on the rights of citizens.

Secondly, does the Minister also agree that for the PDPA itself, I suppose one of the advantages or assets of the PDPA is its approach to try to balance the need of organisations to collect data and, at the same time, if we look at section 3, it also recognises that personal data belongs to individuals, and individuals have a right to protect that data?

The third question is, we talked recently about the SingHealth incident. Does the Minister agree, because SingHealth is a body that comes within the purview of PDPA, it is not a Public Agency as defined in the Act, and the SingHealth cyberattack case has shown that the Personal Data Protection Commission (PDPC) can actually play a very useful role as far as the public is concerned? The PDPC's judgement in the cyberattack case mentioned that members of the public complained to it that their data had not been adequately protected by SingHealth. PDPC actually made some findings which will likely lead to improvements on the part of SingHealth and the Integrated Healthcare Information Systems (IHiS) as well.

Perhaps the last question for now is that one of the things that the PDPA does provide is a complaints procedure which I would like the Minister to confirm that this is something that is very useful to the citizens, which does not force the citizens to commence a lawsuit against a Government agency should one suffer damage and so on. So, these are very real advantages of the PDPA which I believe citizens can benefit from.

Mr S Iswaran : Mr Speaker, I thank the Member for her comments. I am not sure all of them were questions because some of them were observations. But let me interpret them.

Let me start by making a more general point. I think the key conclusion we have to draw is this. When we say exempt – and that is the language that the Member has used in her question – that the public sector is exempt from the PDPA, that does not mean that the public sector is somehow subject to a different or lower standard, as might be implied, in terms of data security and safety. In fact, and that was the thrust of my reply that, one, the public sector and the PSGA, in particular, takes reference, and it is in broad alignment with PDPA. But having said that, there is a clear recognition that the mode of operation and the expectation of how data is used in order to provide an effective and efficient Public Service, implies that we do need a different methodology in the way we govern public sector data governance. That is why we have this differentiated approach. In addition to the PSGA, as I had said, we do have other legislations in place.

Just for Members' information, we are by no means alone in this approach. The Canadians, for example, at the federal level, also have different laws in terms of its application to the private sector and its application to the public sector. So, it is not about differing standards or somehow having a different threshold when it comes to the public sector. In fact, we subject the public sector to the same kind of standards, if not higher standards, precisely because we know that the data that is being entrusted to the public sector is done with the confidence that it would be dealt with in a secure manner.

So, many of the questions that the Member has raised pertain more to whether there are elements of the PDPA. For example, there is a complaints procedure where they can complain to the PDPC on, for example, the right to data. I think the Member made the point that the PDPA strikes the balance between the right to data of the individual versus the right to use the data of the enterprises. Indeed, that is the balance we are trying to strike, whether it is in the public domain or in the private domain. Because essentially, you can say the same sets of considerations apply in the public sector – that we want to ensure individual data is protected, accorded due safeguards, but, at the same time, it should be a common resource that public sector agencies can tap on in order to better serve citizens. Many of the services that we take quite for granted today actually rely on that backend sharing. So, when it comes to a complaints procedure today, there is nothing stopping an individual who feels aggrieved that their data has somehow been mishandled to launch a complaint. And they have different channels for doing so.

On the SingHealth piece, the Member made the point that PDPC came out with the recommendations and so on which were very useful and so on. But actually, if you look at the morphology of the entire incident, the key recommendations that came out of this was actually from the Committee of Inquiry (COI) which the Government established. That is the process through which we derived a whole set of very detailed recommendations. What the PDPC did, because it received the complaint early in the process, was to say that it will take reference from the COI's process in determining whether there was a breach by the relevant agencies, in this case SingHealth and IHiS, and, if so, what penalty should be meted out. But the substantial portion of the recommendations was actually made through the COI process which was, in fact, initiated by the Government, not mandated by any legislation but something that was because of the judgement that was exercised.

The point on recourse comes back to the same thing again. If a member of the public feels that, in some way, their data has been mishandled, then they have every opportunity to lodge a complaint with the Minister, the Ministry, the relevant department, and action will be taken. And you can also, if you think a crime has been committed, make a Police report, and that will also be investigated.

So, if I can summarise, we subject our public sector to the same, if not higher, rigorous standards of data governance. And we have to do that, because if we do not, then a lot of our other efforts, in terms of wanting to build a Smart Nation and delivering, harnessing the digital technologies and all these in order to deliver better public services will all be thwarted. So, that is exactly why we take this very seriously. By and large, the PSGA, in other words, the legislation that governs the public sector data governance, takes reference from the PDPA and we also have other legislation for specific sectoral matters which can also be implied in addition.

Mr Speaker: Ms Sylvia Lim.

Ms Sylvia Lim : Two supplementary questions for the Minister. First, the Minister, in his answer earlier, mentioned that for members of the public who are aggrieved that their information has been mishandled by a public agency can always make a complaint. The question is: to whom? And the Minister mentioned that it could be to the Minister. Does the Minister not agree that the PDPC itself, which is focused on personal data protection, should have a role to receive such complaints because they are, after all, the domain expert on personal data protection?

The second supplementary question is: Minister mentioned the issue of public sector agencies being interconnected and, therefore, there needs to be a different approach. But I think the SingHealth incident also illustrates some artificiality in what is actually happening in the healthcare sector. If we look at the setup of SingHealth, for example, no doubt, it is not under the definition of public agency under the PDPA. But the fact is that it is very connected to the Ministry of Health (MOH). In fact, it is owned by MOH Holdings, and there is a frequent, I believe, exchange of data between such healthcare bodies and the parent Ministry. So, it would come to a stage, does Minister not agree that, if my data is given to a clinic, for example, under a cluster, I may be able to complain to the PDPC, but once that data goes to the Ministry and the breach happens there, I do not have recourse under the PDPC? So, there is some artificiality in the distinction as far as the healthcare sector is concerned.

Mr S Iswaran : Mr Speaker, because there will be a Ministerial Statement governing many of the matters pertaining to the public healthcare system, I will keep my comments in response to the Member's queries limited, and I think we can take up clarifications after the Ministerial Statement as well.

The key point I want to emphasise in my response to the Member is this: the term "recourse" for the public has been used several times in the course of this exchange. The fact of the matter is that you need recourse. It does not matter whether the recourse is under the PDPC or PDPA, the legislation or there are other established improved mechanisms. But the key point is you must have recourse.

And that is my point when I said that individuals, depending on where or what circumstances they find themselves in, they can make complaints. By the way, the PDPC does receive complaints sometimes pertaining to the public sector. So, as a recipient of such complaints from the public, it does not turn them away. Rather, the standing arrangement is that they look at it and, if the jurisdiction is such that it does not come under the PDPA, they then refer it to the Government agencies involved to then follow through. In the case of the Government, the Government Technology Agency (GovTech), for example, is overall in-charge of the security and safeguard systems for data. And GovTech is the agency that does many of the reviews and ensures that the Government agencies are in compliance with the IMs and other provisions and so on. Moreover, there is also the Auditor-General's review as well, which occurs from time to time, and it includes security.

My point is that members of the public should not at all be concerned that they do not have recourse. They do, and, in fact, they have a multiplicity of recourse. And I would add that, in the case of the public sector, they probably have more channels and more avenues of recourse in some ways, compared to what you see in the context of the private sector. Because essentially, for private sectors, you go to the PDPC, or you take out a specific legal action against the company on your own. Here, you have got more options because you can go through the PDPC. It would be referred to the relevant agencies. You can go to GovTech, you can go to the Ministry that oversees the relevant department, you can also make a Police report if you feel that it warrants such action.

So, there should be no doubt in Members' minds that we have the appropriate recourse mechanisms. There should also be no doubt in Members' minds that the public sector's data governance standards are in no way inferior to the standards that we impose on the private sector. And, if anything, we impose a higher set of standards. That is the expectation that we have.

같은 주제 더 보기