서면 답변 · 2019-05-06 · 국회 13
공공 기관 데이터 보호 면책 문제
의원들은 공공 기관이 「개인정보보호법」 면책권을 향유하는지 및 데이터 유출에 대한 책임이 무엇인지 질문했습니다. 정부는 공공 기관이 「공공 부문 거버넌스법」 및 「지침 매뉴얼 8」 등 법규로 규제되며, 형사 처벌 및 내부 징계 조치가 있고, 기술 및 관리 조치를 통해 데이터 유출을 방지한다고 답변했습니다. 핵심 쟁점은 공공 기관의 데이터 보호 책임의 법적 기초 및 실행 강도입니다.
핵심 요점
- • Public agencies bound by multiple regulations
- • Criminal and disciplinary measures combined
- • Strict technical and management measures
공공 기관의 엄격한 데이터 보호 책임 부담
공공 기관 면책 조항 및 책임 질문
공공 부문 데이터 보안 관리 강화
“The PSGA criminalises the acts of unauthorised disclosure of data, misuse of data and the re-identification of individuals from anonymised data.”
참여자 (2)
전문 번역(한국어)
Hansard 원문 · 2026-05-02
1 에린 퀘이 슈청 여사는 총리에게 공공기관이 『개인정보보호법』의 적용에서 제외되는지 여부에 관하여 다음을 질문합니다: (a) 공공 정보통신기술 시스템의 데이터 유출(데이터 남용이 아닌)에 대한 공공기관의 책임을 규정하는 현행법 및 지침 문서의 구체적 조항들을 나열할 수 있는지 여부; (b) 이러한 법률 조항들이 모든 공공기관에 높은 수준의 책임을 함께 부과하는 방식을 설명할 수 있는지 여부입니다.
장지현 선생(총리 대리)이 답변합니다: 공공기관 및 그 직원들은 『공공부문(거버넌스) 법안』(PSGA)과 『지침서 8』(IM8) 및 기타 관련 법률에 명시된 데이터 보호 조항을 준수해야 합니다. PSGA는 미승인 데이터 공개, 데이터 남용, 그리고 익명 데이터에서 개인을 재식별하는 행위를 형사범죄로 규정합니다. 이러한 범죄로 유죄판결을 받은 공무원은 최고 5,000 싱가포르 달러의 벌금 및/또는 최고 2년의 징역에 처해질 수 있습니다. PSGA 외에도 『공식기밀법』, 『은행법』, 『소득세법』, 『통계법』 등의 다른 법률들도 미승인 데이터 공개를 형사범죄로 규정합니다. 이러한 규정들은 공무원이 무책임하게 데이터를 사용하고 처리하는 것을 억지하고 처벌하기 위해 의도된 것입니다. 관련 법률 조항 목록은 첨부 A를 참조하십시오.
형사소추 외에도, 자신이 통제하는 데이터 보호에 있어 부주의한 것으로 판단되는 공무원은 1999년 『공공서비스(징계절차) 규정』에 따라 내부 징계 처분에 처해질 수 있습니다.
이러한 입법적 제재 외에도, 정부는 데이터 보안 유출의 가능성을 예방하거나 최소화하고 데이터 유출의 영향을 완화하기 위한 여러 조치를 취하고 있습니다. 모든 공공기관은 IM8의 규정을 준수해야 합니다. IM8은 PSGA의 광범위한 데이터 조항을 보완하며, 기관이 자신이 통제하는 정부 데이터를 관리하고 보호하기 위해 준수해야 하는 규칙과 요구사항을 명시합니다. IM8은 정부 데이터 보호를 위한 구체적 조치를 규정하고 있습니다. 예를 들어, IM8은 인터넷 브라우징 격리 구현, 미승인 장치의 USB 포트 접근 금지, 그리고 개인정보를 포함하는 파일의 암호 보호를 요구합니다. IM8은 또한 접근권의 신속한 취소, 비활성 사용자 탐지, 그리고 시스템 접근권의 주기적 검토와 같은 특정 데이터 보호 절차를 규정합니다.
기관들은 IM8 준수 및 실시된 조치들의 효과성에 대해 정기적으로 감사받습니다. 감사의 목적은 기관들이 데이터 사건 발생 전에 해결해야 할 프로세스 및 시스템 결점을 발견하도록 돕는 것입니다. 결점이 발견되면, 기관은 특정 시간 내에 이들 결점을 개선하기 위한 계획을 수립해야 하며, 계획의 진전은 결점이 완전히 해결될 때까지 지속적으로 모니터링됩니다. 정기적 IM8 준수 감사 외에도, 감사원은 기관의 데이터 관리 관행에 대한 감사를 수행할 수 있습니다. 감사 결과는 국회에 보고되고 공개적으로 공표됩니다. 기관이 결점을 개선하기 위한 조치는 완성될 때까지 추적됩니다. 심각한 위반은 감사 과정 중에 재무부 내부 처리를 위해 제출될 수 있습니다.
PSGA 및 기타 법률의 억지력 있는 조치, IM8의 규정된 조치, 그리고 정기적 IM8 준수 감사는 공공기관 및 공무원에게 높은 수준의 데이터 보호 책임을 함께 부과합니다. 데이터 보안은 데이터를 통해 고품질 공공 서비스를 제공하는 정부의 능력에 대한 국민의 신뢰를 유지하는 데 필수적입니다. 총리의 위임을 받아 고위 장관 장지현이 의장을 맡은 공공부문 데이터 보안 검토위원회는 공공부문의 현존 정책 및 관행을 강화하고 기술 진보에 발맞추기 위한 권고사항을 제시할 것입니다. 여기에는 억지력 있는 조치를 최신 상태로 유지하고, 데이터 보안이 공공 서비스 지도자들의 우선순위로 계속 남도록 보장하며, 견고한 데이터 보안 체계를 유지하기 위해 정책 및 관행을 지속적으로 개선하는 것이 포함됩니다. 위원회는 2019년 11월에 그 조사 결과 및 권고사항을 총리에게 제출할 것입니다.
영어 원문
SPRS Hansard 원본 기록 · 수집일: 2026-05-02
1 Ms Irene Quay Siew Ching asked the Prime Minister with regard to public agencies' exemption from the Personal Data Protection Act (a) whether he can list out the specific clauses in the current laws and instruction manuals that provide for public agencies' accountability on data breaches (not misuse of data) in public IT systems; and (b) whether he can explain how these clauses in the laws collectively impose a high standard of responsibility on all public agencies.
Mr Teo Chee Hean (for the Prime Minister): Public agencies and their officers are subject to data protection provisions set out in the Public Sector (Governance) Act (PSGA) and the Instruction Manual 8 (IM8), as well as in other related legislation. The PSGA criminalises the acts of unauthorised disclosure of data, misuse of data and the re-identification of individuals from anonymised data. Public officers found guilty of these offences can be fined up to $5,000 and/or face a jail term of up to two years. Besides the PSGA, other legislation also criminalise the act of unauthorised disclosure of data, such as the Official Secrets Act, the Banking Act, the Income Tax Act, and the Statistics Act. These provisions serve to deter public service officers from and punish them for the irresponsible use and handling of data. Please refer to Annex A for a list of the relevant clauses in the aforementioned Acts.
Apart from criminal proceedings, public officers found to be negligent in protecting data under their control can face internal disciplinary actions, as provided for in the Public Service (Disciplinary Proceedings) Regulations 1999.
Apart from such legislative sanctions, the government has a number of measures to prevent or minimize the chances of a data security breach and to minimise the consequences of a data breach. All public agencies are required to comply with the provisions of the IM8. The IM8 complements the broad data provisions in the PSGA by setting out the rules and requirements that agencies have to adhere to in order to manage and protect government data under their control. The IM8 prescribes specific measures to protect government data. For example, the IM8 mandates Internet surfing separation, the disabling of USB ports from being accessed by unauthorised devices, and the use of passwords to protect files that contain personal data. The IM8 also prescribes certain data protection processes, such as the prompt removal of access rights, the detection of inactive users and the regular review of system access rights.
Agencies are regularly audited for their compliance with the IM8 requirements, as well as the effectiveness of the measures implemented. The objective of audits is to enable agencies to uncover process and system gaps that should be addressed before a data incident occurs. Where such gaps are identified, agencies are required to draw up plans to close these gaps within a specific timeframe, and the progress of these plans are monitored until the gaps are fully closed. Besides regular IM8 audits, agencies' data management practices may also be audited by the Auditor-General. The outcomes of these audits are reported in Parliament and publicly available; agencies' actions to close the gaps are tracked until completion. Serious irregularities can be brought to the attention of the Ministry of Finance for internal action, as part of the audit process.
The deterrent measures in the PSGA and other legislation, the prescriptive measures in the IM8, as well as the regular IM8 compliance audits, collectively impose upon public agencies and public officers a high level of responsibility for data protection. Data security is essential to upholding public confidence in the Government's ability to deliver a high quality of public service to our citizens through the use of data. The Public Sector Data Security Review Committee, commissioned by the Prime Minister and chaired by Senior Minister Teo Chee Hean, will recommend ways to enhance the policies and practices the public sector already has, to keep pace with advances in technology. This includes keeping accountability measures up-to-date to ensure that data security remains a priority among public service leaders, and to ensure that policies and practices are continually improved to maintain a robust data security regime. The Committee will present its findings and recommendations to the Prime Minister in November 2019.