서면 답변 · 2024-04-03 · 국회 14

개인정보 삭제권 및 구제 메커니즘

AI 경제 및 산업 AI 전략 논쟁도 3 · 실질적 토론

의원이 개인정보 보호법에 개인정보 삭제권 및 관련 구제 메커니즘이 포함되어 있는지를 질의하였습니다. 정부는 법률이 조직들에게 데이터가 더 이상 필요하지 않을 때 보존을 중단하거나 적절히 처분하도록 규정하고 있으며, 동의 여부와 관계없이 개인정보 보호위원회가 조직에 데이터 삭제 또는 사용 중단을 명령할 권한이 있다고 응답하였습니다. 핵심 논쟁은 명확한 「삭제권」 조항 및 그 이행 보장이 존재하는지 여부입니다.

핵심 요점

  • No explicit right to erasure clause
  • Strict limits on data retention
  • Regulator has enforcement power
정부 입장

현행 법률 규정 및 감시 메커니즘 지지

질의 입장

명확한 삭제권 보장 부족에 의문

정책 신호

데이터 보유 및 폐기 감시 강화

“The Personal Data Protection Commission (PDPC) has the power to direct the organisation to destroy, or stop collecting, using or disclosing, the personal data concerned.”

참여자 (2)

전문 번역(한국어)

Hansard 원문 · 2026-05-02

27호 의원 차이칭웨이 씨가 통신정보부 장관에게, 「삭제권」 조항의 부재를 감안하여 『2012년 개인정보보호법』이 다음을 규정하고 있는지 질문하였습니다: (i) 자신의 개인정보 수집, 사용 또는 공개에 동의하지 않은 개인이 요청 시 조직에 자신의 개인정보 삭제를 요청할 수 있는지 여부; 그리고 (ii) 조직이 삭제를 거부하는 경우 그러한 개인이 취할 수 있는 구제 방안.

장유펀 여사가 답변하였습니다: 개인정보보호법(PDPA)은 개인정보가 수집된 목적이나 기타 합법적인 상업적 또는 법적 목적으로 더 이상 사용되지 않을 때 조직이 해당 개인정보의 보유를 중단하거나 적절한 방식으로 폐기하도록 요구합니다.

동의 여부와 관계없이 조직은 이 요구사항을 준수해야 합니다. PDPA 하에서의 보유기한은 개인정보가 추가로 사용되지 않도록 충분히 보장합니다. 조직이 이러한 요구사항을 준수하지 않는 경우, 개인정보보호위원회(PDPC)는 해당 조직에 관련 개인정보를 파기하거나 개인정보의 수집, 사용 또는 공개를 중단하도록 지시할 권한을 갖습니다.

영어 원문

SPRS Hansard 원본 기록 · 수집일: 2026-05-02

27 Mr Chua Kheng Wee Louis asked the Minister for Communications and Information given the absence of a 'right to erasure' clause, whether the Personal Data Protection Act 2012 provides for (i) individuals who have not given consent for the collection, use, or disclosure of their personal data and requiring an organisation to delete their personal data upon request and (ii) the recourse for such individuals if the organisation does not do so.

Mrs Josephine Teo : The Personal Data Protection Act (PDPA) requires an organisation to cease retention of personal data or dispose of it in a proper manner when it is no longer needed for the purposes it was collected for, or other legitimate business or legal purpose.

This requirement applies regardless of whether consent had or had not been given for the organisation's collection, use or disclosure of personal data. Retention limits under the PDPA sufficiently safeguard the further use of an individual's personal data. If the organisation does not adhere to these requirements, the Personal Data Protection Commission (PDPC) has the power to direct the organisation to destroy, or stop collecting, using or disclosing, the personal data concerned.

같은 주제 더 보기