개인정보 전송요구권: 사회적 문제와 대응 방안The Right to Data Transfer: Social Problems and Response Plans
개인정보 보호법 시행령 개정안에 대한 비판적 분석Critical Analysis of Personal Information Protection Act Enforcement Decree Amendment
초록Abstract
2025년 6월 개정안은 규제개혁위원회의 권고(2024년 8월)를 무시하고, 헌법 원칙에 어긋나며, GDPR 기준과 충돌한다. 또한 전문기관에 부당한 특혜를 부여해 한국 스타트업 생태계를 무너뜨릴 우려가 있다.The June 2025 amendment proposal ignores Regulatory Reform Committee recommendations (August 2024), violates constitutional principles, contradicts GDPR standards, and threatens to destroy Korea's startup ecosystem through unfair privileges to specialized agencies.
주요 결과Key Findings
- 절차적 위반: 규제개혁위원회 결정 후 단 4개월 만에 부결된 내용을 다시 발의
- 위헌 소지: 시행령을 통한 대리권 위임은 위헌적 위임에 해당
- GDPR 기준 불일치: 유럽연합 기준과 달리 영업비밀 보호 장치 부재
- 시장 왜곡: 전문기관에 배타적 특혜를 부여해 불공정한 우위를 형성
- 보안 위험: 금융권은 금지한 화면 스크래핑을 허용
- 경제적 부담: 이용자 100만 명에 도달한 스타트업의 준수 비용이 수십억 원으로 추정
- 정책 비일관성: 금융위원회의 스크래핑 금지 조치(2022년)와 모순
- Procedural violation: Re-proposing rejected content only 4 months after Regulatory Reform Committee decision
- Constitutional issue: Unconstitutional delegation of proxy rights via enforcement decree
- GDPR non-compliance: Lack of trade secret protection unlike EU standards
- Market distortion: Exclusive privileges to specialized agencies creating unfair advantage
- Security risk: Allowing screen scraping despite financial sector ban
- Economic burden: Estimated billions in compliance costs for startups reaching 1M users
- Policy inconsistency: Contradicting Financial Services Commission's scraping ban (2022)
정책 쟁점Policy Concerns
- 3개 분야(의료, 통신, 에너지)에서 전 산업으로 확대
- 영업비밀 보호 없이 핵심 사업 데이터의 전송을 강제
- 데이터 집중화로 단일 장애점(SPOF)을 형성
- 성장 중인 스타트업에 과도한 비용을 부과(매출 1,500억 원 및 이용자 100만 명 기준)
- Expansion from 3 sectors (medical, telecom, energy) to ALL industries
- Forcing core business data transfer without trade secret protection
- Creating Single Point of Failure (SPOF) through data centralization
- Imposing excessive costs on growing startups (Revenue 150B KRW & 1M users threshold)
핵심 요약: 혁신을 위협하는 규제 과잉
2025년 11월 21일, 서울 강남 디캠프에서 한국스타트업포럼이 주최한 마이데이터 정책 스타트업 세미나에서 발표했다. 데이터 정책, 규제, 혁신이 만나는 지점을 연구하는 사람으로서, 2025년 6월에 발의된 개인정보 보호법 시행령 개정안에 대해 깊은 우려를 제기했다.
이 개정안은 “개인정보 전송요구권”을 전 산업으로 확대하려는 것으로, 데이터 활성화에서 데이터 통제로 향하는 근본적 전환을 뜻한다. 이는 확립된 규제 원칙과 국제 규범을 어기면서 한국의 스타트업 생태계를 흔들 우려가 있다.
중대한 경고
2025년 6월 개정안은 규제개혁위원회의 2024년 8월 결정을 어기고, 동일한 내용을 단 4개월 만에 다시 발의했다. 이런 절차적 위반은 행정의 신뢰성을 훼손하고, 보안, 비용, 영업비밀에 관한 업계의 정당한 우려를 외면한다.Executive Summary: A Regulatory Overreach Threatening Innovation
On November 21, 2025, I presented at the MyData Policy Startup Seminar hosted by the Korea Startup Forum at D.CAMP in Gangnam, Seoul. As a researcher examining the intersection of data policy, regulation, and innovation, I raised serious concerns about the Personal Information Protection Act Enforcement Decree amendment proposed in June 2025.
The amendment, which aims to expand the “Right to Request Data Transfer” to all industries, represents a fundamental shift from data activation to data control, one that threatens to undermine Korea’s startup ecosystem while violating established regulatory principles and international norms.
Critical Alert
The June 2025 amendment proposal violates the Regulatory Reform Committee's August 2024 decision by re-proposing identical content only 4 months later. This procedural violation undermines administrative integrity and ignores legitimate industry concerns about security, costs, and trade secrets.경과: 신중한 접근에서 규제 과잉으로
법적 근거 마련
개인정보 보호법 2차 개정안이 국회를 통과하며 개인정보 전송요구권(제35조의2)이 신설
규제개혁위원회 결정
주요 권고 사항:
- 3개 분야(의료, 통신, 에너지)로 제한
- 본인 전송과 제3자 전송의 범위를 일치시켜 일관성 유지
- 기술 인프라 준비를 위한 충분한 시간 부여
- 시장 준비 정도에 따른 단계적 확대
시행령 제정(대통령령 제35343호)
규제개혁위원회 권고를 수용해 3개 분야(의료, 통신, 에너지)로 한정
제도 시행
지정된 3개 분야에서 개인정보 전송요구권 제도가 운영을 시작
논란의 개정안 발의
개인정보보호위원회가 전 산업으로의 확대를 다시 발의
- 불과 4개월 전의 규제개혁위원회 결정을 무시
- 전자상거래, 플랫폼, 게임, 교육, 숙박, 문화·여가로 범위를 확대
- 기준: 매출 1,500억 원 + 이용자 100만 명
- 전문기관 특혜를 신설
Timeline: From Cautious Approach to Regulatory Overreach
Legal Framework Established
Personal Information Protection Act 2nd Amendment passes National Assembly, establishing Right to Request Data Transfer (Article 35-2)
Regulatory Reform Committee Decision
Key Recommendations:
- Limit to 3 sectors: Medical, Telecommunications, Energy
- Maintain consistency between self-transfer and third-party transfer scopes
- Allow sufficient preparation time for technical infrastructure
- Gradual expansion based on market readiness
Enforcement Decree Enacted (Presidential Decree No. 35343)
Adopted Regulatory Reform Committee recommendations: Limited to 3 sectors (Medical, Telecom, Energy)
System Launch
Right to Request Data Transfer system begins operation in 3 designated sectors
Controversial Amendment Proposed
Personal Information Protection Commission re-proposes expansion to ALL industries
- Ignores Regulatory Reform Committee decision from just 4 months prior
- Expands scope to: E-commerce, Platforms, Gaming, Education, Hospitality, Culture & Leisure
- Threshold: Revenue 150B KRW + 1M users
- Creates specialized agency privileges
확대의 함정: 현행법 대 개정안
현행 시행령(2025년 2월)
범위
- 의료기관
- 통신사업자
- 에너지 공급자
특징
- 본인 전송 = 제3자 전송 범위
- 규제개혁위원회 권고를 준수
- 단계적 확대 원칙
- 충분한 시범 운영 기간
개정안(2025년 6월)
범위
다음을 충족하는 모든 사업자:
- 연 매출 1,500억 원 이상 그리고
- 이용자 100만 명 이상
- 추가: 모든 초·중·고 및 고등 교육기관
- 추가: 위원회가 지정하는 모든 사업자
문제점
- 본인 전송과 제3자 전송의 범위가 불일치
- 규제개혁위원회 결정에 위반
- 전 분야로 동시에 확대
- 최초 시행 후 불과 4개월 만에 추진
"매출 1,500억 원 및 이용자 100만 명"의 실제 의미
이 기준에 포함되는 대상:
- 주요 플랫폼: 네이버, 카카오, 쿠팡, 배민, 11번가, G마켓, 옥션
- 성장 중인 스타트업: 이용자 100만 명에 도달하면 자동으로 포함
- 영향받는 분야: 전자상거래, 배달, 게임, 교육, 숙박, 문화·여가
결과: 사실상 성공한 디지털 사업 대부분이 포함되어, 사실상 전 산업으로 확대되는 효과
The Expansion Trap: Current Law vs. Proposed Amendment
Current Enforcement Decree (Feb 2025)
Scope
- Medical institutions
- Telecommunications carriers
- Energy providers
Characteristics
- Self-transfer = Third-party transfer scope
- Follows Regulatory Reform Committee guidance
- Gradual expansion principle
- Sufficient pilot period
Proposed Amendment (June 2025)
Scope
Any entity meeting:
- Annual revenue ≥ 150B KRW AND
- User base ≥ 1M persons
- Plus: All elementary/secondary/higher education institutions
- Plus: Any entity designated by Commission
Problems
- Self-transfer and third-party transfer scope inconsistent
- Violates Regulatory Reform Committee decision
- Simultaneous expansion to all sectors
- Only 4 months after initial implementation
What "Revenue 150B KRW & 1M Users" Really Means
This threshold captures:
- Major platforms: Naver, Kakao, Coupang, Baemin, 11st, Gmarket, Auction
- Growing startups: Any company reaching 1M users automatically included
- Sectors affected: E-commerce, delivery, gaming, education, hospitality, culture & leisure
Result: Virtually all successful digital businesses are captured → De facto expansion to ALL industries
Seven Critical Concerns
절차적 위반
쟁점: 규제개혁위원회 결정 후 단 4개월 만에 부결된 내용을 다시 발의
위험: 규제 심사 절차를 훼손하고 행정 신뢰를 약화
위헌 소지
쟁점: 본질적 사항(대리권)을 시행령에 위임하는 것은 법률유보 원칙에 위반
위험: 입법권 침해, 법체계 교란
GDPR 기준 불일치
쟁점: "타인의 권리와 자유"(영업비밀)를 보호하는 GDPR 제20조 4항에 해당하는 장치 부재
위험: 국제 규범 이탈, 재산권 침해
시장 왜곡
쟁점: 전문기관에 대한 배타적 특혜가 데이터 무임승차를 가능하게 함
위험: 시장 조작, 생태계 파괴
보안 위험
쟁점: 화면 스크래핑을 허용하고 단일 장애점(SPOF)을 형성
위험: 아이디·비밀번호 노출, 전국 동시 데이터 유출
경제적 부담
쟁점: 영업비밀 공개를 강제하고 과도한 준수 비용을 부과
위험: 경쟁력 약화, 성장 저해
정책 비일관성
쟁점: 금융위원회의 스크래핑 금지 조치(2022년)와 모순
위험: 행정 일관성 상실
Procedural Violation
Issue: Re-proposing rejected content only 4 months after Regulatory Reform Committee decision
Risk: Undermines regulatory review process, erodes administrative credibility
Constitutional Issues
Issue: Delegation of essential matters (proxy rights) to enforcement decree violates legal reservation principle
Risk: Legislative power infringement, legal system disruption
GDPR Non-Compliance
Issue: Lacks GDPR Article 20(4) protection for "rights and freedoms of others" (trade secrets)
Risk: International norm deviation, property rights violation
Market Distortion
Issue: Exclusive privileges to specialized agencies enable data free-riding
Risk: Market manipulation, ecosystem destruction
Security Risks
Issue: Allows screen scraping, creates Single Point of Failure (SPOF)
Risk: ID/PW exposure, nationwide simultaneous data breach
Economic Burden
Issue: Forces trade secret disclosure, imposes excessive compliance costs
Risk: Competitiveness erosion, growth inhibition
Policy Inconsistency
Issue: Contradicts Financial Services Commission's scraping ban (2022)
Risk: Administrative consistency loss
Deep Dive: GDPR Compliance Gap
GDPR 방식(균형)
- 정보주체의 권리를 보호
- 사업자의 재산권을 존중
- 영업비밀을 명시적으로 보호
- 기술적 실행 가능성을 고려
- 균형 잡힌 접근
"제1항에 명시된 권리는 타인의 권리와 자유를 부당하게 침해해서는 안 된다."
한국 개정안(불균형)
- 정보주체의 권리를 보호
- 사업자의 재산권을 무시
- 영업비밀 보호 없음
- 무조건적 전송 의무
- 일방적 규제
구매 패턴, 가격 정책, 고객 세분화, 판매자 정보 등 수년간의 투자로 축적한 영업비밀임에도, "정당한 사유" 없이 핵심 사업 데이터의 전송을 강제
유럽연합 제29조 작업반 지침(WP242)
유럽연합의 권위 있는 해석은 명확한 경계를 제시한다.
| 원칙 | 유럽연합 해석 | 한국 개정안 |
|---|---|---|
| 정보주체가 "제공한" 데이터 | 이용자가 직접 제공한 데이터로 한정하며, 기업이 생성한 분석 자료는 제외 | 그러한 제한 없음 |
| "가공 산물" 제외 | 기업의 가공 산물(신용점수, 추천 알고리즘)을 명시적으로 제외 | 규정 없음 |
| 타인의 권리와 자유 | 영업비밀이나 데이터베이스 제작자의 권리를 침해할 수 없음 | 보호 조항 없음 |
| 기술적 실행 가능성 | "기술적으로 가능한 경우"에만 직접 전송 | 무조건적 의무 |
GDPR Approach (Balanced)
- Protects data subject rights
- Respects business property rights
- Explicitly protects trade secrets
- Considers technical feasibility
- Balanced approach
"The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others."
Korean Amendment (Unbalanced)
- Protects data subject rights
- Ignores business property rights
- No trade secret protection
- Unconditional transfer obligation
- One-sided regulation
Forces transfer of core business data (purchase patterns, pricing policies, customer segmentation, seller information) without "legitimate grounds" despite being trade secrets accumulated through years of investment
EU Article 29 Working Party Guidelines (WP242)
The EU’s authoritative interpretation provides clear boundaries:
| Principle | EU Interpretation | Korean Amendment |
|---|---|---|
| "Provided by" data subject | Limited to data directly provided by user; excludes company-generated analytics | No such limitation |
| "Work product" exclusion | Company work products (credit scores, recommendation algorithms) explicitly excluded | Not addressed |
| Rights and freedoms of others | Cannot violate trade secrets or database maker's rights | No protection clause |
| Technical feasibility | Direct transfer only "where technically feasible" | Unconditional obligation |
금융 분야의 역설: 규제의 자기모순
금융위원회(2022년): 보안 위험을 이유로 화면 스크래핑 금지
경과:
- 2020년 8월 5일: 신용정보법 개정으로 마이데이터 법적 근거 마련
- 2021년 12월 1일: 마이데이터 시범 서비스 시작(17개 기관) - 스크래핑 한시 허용
- 2022년 1월 5일: 화면 스크래핑 전면 금지, API 방식 의무화
공식 근거(금융위 보도자료, 2022년 1월 4일):
“2022년 1월 5일부터 화면 스크래핑은 전면 금지되며, 마이데이터 사업자는 모든 이용자에게 오직 API 방식으로만 서비스를 제공해야 한다.”
제기된 보안 우려:
| 위험 | 내용 |
|---|---|
| 아이디·비밀번호 직접 수집 | 마이데이터 사업자가 이용자의 아이디와 비밀번호를 직접 수집·저장해야 함 |
| 일방향 암호화 사용 불가 | 비밀번호를 평문 또는 복호화 가능한 방식으로 저장해야 하므로, 해킹 시 대량 유출 위험 |
| 2차 인증 우회 | 2차 인증, 일회용 비밀번호 등 추가 보안 수단을 우회해야 함 |
| 불분명한 책임 소재 | 유출 시 금융기관과 사업자 사이의 책임이 불분명 |
API 방식의 장점:
- 금융기관이 전송을 통제 → 책임 소재가 명확
- 토큰 기반 인증 → 비밀번호 노출 없음
- 전송 범위 한정 → 필요한 데이터만 전송
- 전송 이력 추적 가능 → 감사 가능
- 전송 계층 보안 암호화 → 안전한 전송
개인정보보호위원회(2025년): 스크래핑을 "자동화 도구"로 허용
근거:
- “권리 행사의 편의성”
- “기술적 유연성”
- 명확한 보안 조치 없음
예상 결과: 금융위원회가 금지한 위험의 재발
범위: 전자상거래, 플랫폼, 게임, 교육, 문화·여가 등 전 산업
논리적 모순
규제 비일관성:
- 금융 정보는 중요하다 → 스크래핑 금지
- 의료, 쇼핑, 교육 정보는 중요하지 않다 → 스크래핑 허용?
개인정보 보호법 제29조 위반:
제29조(안전조치 의무): 개인정보처리자는 개인정보가 분실·도난·유출·위조·변조 또는 훼손되지 않도록 내부 관리계획을 수립하고 접속기록을 보관하며, 대통령령으로 정하는 바에 따라 안전성 확보에 필요한 기술적·관리적·물리적 조치를 해야 한다.
→ 스크래핑 허용은 안전성 확보 의무와 정면으로 모순된다
결과: 개인정보 보호 원칙의 일관성 상실
The Financial Sector Paradox: Regulatory Self-Contradiction
Financial Services Commission (2022): Screen Scraping Banned as Security Risk
Timeline:
- August 5, 2020: Credit Information Act amended - MyData legal framework established
- December 1, 2021: MyData pilot service launched (17 institutions) - Scraping temporarily allowed
- January 5, 2022: Screen scraping completely banned, API-only mandate
Official Rationale (FSC Press Release, Jan 4, 2022):
“From January 5, 2022, screen scraping is completely prohibited and MyData operators must provide services exclusively through API methods to all users.”
Security Concerns Cited:
| Risk | Details |
|---|---|
| ID/PW Direct Collection | MyData operators must directly collect and store user IDs and passwords |
| Inability to Use One-Way Encryption | Passwords must be stored in plaintext or reversible encryption → mass breach risk if hacked |
| 2FA Bypass | Must circumvent additional security measures like 2FA, OTP |
| Unclear Liability | Responsibility unclear between financial institutions and operators in case of breach |
API Benefits:
- Financial institution controls transfer → clear liability
- Token-based authentication → no password exposure
- Limited transfer scope → only necessary data
- Traceable transfer history → auditable
- TLS encryption → secure transmission
Personal Information Protection Commission (2025): Allowing Scraping as "Automated Tool"
Justification:
- “Convenience for exercising rights”
- “Technical flexibility”
- No clear security measures
Expected Result: Revival of risks that FSC banned
Scope: E-commerce, platforms, gaming, education, culture & leisure - ALL industries
The Logical Contradiction
Regulatory Inconsistency:
- Financial information is important → scraping banned
- Medical, shopping, education information is not important → scraping allowed?
Violation of Personal Information Protection Act Article 29:
Article 29 (Security Measures Obligation): Personal information controllers must establish internal management plans, maintain access records, and take technical, administrative, and physical measures necessary to ensure safety as prescribed by Presidential Decree to prevent personal information from being lost, stolen, leaked, forged, altered, or damaged.
→ Allowing scraping directly contradicts the obligation to ensure security
Result: Loss of consistency in personal information protection principles
전문기관 특혜 문제
합법적 데이터 브로커의 탄생
시행령 개정안 제42조의9(개인정보관리 전문기관의 업무):
- 정보주체로부터 받은 개인정보의 통합 조회
- 정보주체를 위한 맞춤형 서비스 제공
- 개인정보 활용 관련 연구 및 교육
- 그 밖에 개인정보보호위원회가 정하는 업무 → 사실상 데이터 수집·분석·활용 사업
핵심 쟁점: 전문기관은 수집한 정보를 미끼(예: 커피 쿠폰)로 활용해 정보주체로부터 추가 동의를 받은 뒤, 이 정보를 제3자에게 판매하거나 상업적으로 이용할 수 있다. 이는 개인정보 거래와 유통의 합법적 통로를 열어 준다.
위원회가 밝힌 목표(2025년 6월 입법예고):
“새로운 사업 기회를 통한 데이터 경제 활성화”
→ 이는 정보주체 보호 조치가 아니라 산업정책 목표임을 자인한 것
무임승차 구조
| 주체 | 투자와 노력 | 결과 |
|---|---|---|
| 플랫폼 기업 |
|
자산의 강제 전송 |
| 전문기관 |
|
무상으로 데이터 수집 → 자체 수익 사업 |
The Specialized Agency Privilege Problem
Creating Legal Data Brokers
Enforcement Decree Draft Article 42-9 (Duties of Personal Information Management Specialized Agencies):
- Integrated inquiry of personal information received from data subjects
- Providing customized services for data subjects
- Research and education related to personal information utilization
- Other duties determined by the Personal Information Protection Commission → Effectively: data collection, analysis, and utilization business
Critical Issue: Specialized agencies can use collected information as bait (e.g., coffee coupons) to obtain additional consent from data subjects, then sell or commercially exploit this information to third parties. This opens a legitimate channel for personal information trading and distribution.
Commission’s Stated Objective (June 2025 Legislative Notice):
“Activate data economy through new business opportunities”
→ Admits this is an industrial policy goal, not a data subject protection measure
The Free-Riding Structure
| Actor | Investment & Effort | Result |
|---|---|---|
| Platform Companies |
|
Forced asset transfer |
| Specialized Agencies |
|
Free data collection → Own revenue business |
단일 장애점(SPOF): 국가 안보 위험
분산된 위험에서 집중된 재앙으로
현행 체계(분산형):
- 쇼핑 사이트 유출 → 구매 이력만
- 병원 유출 → 진료 기록만
- 피해 범위가 한정됨
개정안 체계(집중형):
- 전문기관 유출 → 삶의 이력 전체가 노출
- 모든 국민이 동시에 피해
- 국가적 재난
전문기관 한 곳이 개인에 대해 알게 되는 정보:
| 분류 | 정보 |
|---|---|
| 의료 | 진료 기록, 처방, 건강검진, 유전 정보 |
| 통신 | 통화 내역, 메시지, 위치 데이터, 인터넷 이용 |
| 금융 | 계좌 잔액, 거래 내역, 카드 사용, 대출 |
| 쇼핑 | 구매 이력, 찜 목록, 결제 수단, 배송지 |
| 교육 | 학습 기록, 성적, 수강 이력 |
| 민감 | 성인용품, 임신 정보, 개인적 취향 |
→ 삶의 전체 프로필이 한곳에 집중
유출 시나리오:
A씨: 임신(산부인과) + 성인용품(쇼핑) + 특정 위치(위치정보) + 금융 거래 = 사생활 전면 노출
전문기관 유출 시: A씨 같은 5,000만 명이 동시에 피해
Single Point of Failure (SPOF): A National Security Risk
From Distributed Risk to Concentrated Catastrophe
Current System (Distributed):
- Shopping site breach → Purchase history only
- Hospital breach → Medical records only
- Limited damage scope
Amendment System (Centralized):
- Specialized agency breach → Entire life history exposed
- All citizens affected simultaneously
- National-level disaster
What One Specialized Agency Would Know About Each Person:
| Category | Information |
|---|---|
| Medical | Medical records, prescriptions, health checkups, genetic information |
| Telecom | Call history, messages, location data, internet usage |
| Financial | Account balances, transaction history, card usage, loans |
| Shopping | Purchase history, wish lists, payment methods, delivery addresses |
| Education | Learning records, grades, course history |
| Sensitive | Adult products, pregnancy info, personal preferences |
→ Complete life profile in one location
Breach Scenario:
Person A: Pregnancy (obstetrics) + Adult products (shopping) + Specific locations (GPS) + Financial transactions = Complete privacy exposure
Specialized agency breach: 50 million people like Person A simultaneously affected
경제적 영향: 스타트업을 짓누르다
실제 금융 마이데이터 비용
| 항목 | 비용 |
|---|---|
| 전체 시스템 구축(전 기관) | 약 372억 원 |
| 연간 운영 비용(전 기관) | 약 921억 원 |
| 연간 총비용 | 약 1,293억 원 |
| 기관당 평균 비용 | 수억 원에서 수십억 원(규모에 따라 상이) |
출처: 금융위원회 발표(2023년 1월 10일), 삼정KPMG 비용 분석
Economic Impact: Crushing Startups
Actual Financial MyData Costs
| Item | Cost |
|---|---|
| Total System Construction (All institutions) | ~37.2B KRW |
| Annual Operating Cost (All institutions) | ~92.1B KRW |
| Annual Total Cost | ~129.3B KRW |
| Average Cost Per Institution | Hundreds of millions to billions KRW (varies by size) |
Source: Financial Services Commission announcement (Jan 10, 2023), Samjong KPMG cost analysis
전 산업 확대의 영향(추정)
- 대상 기업: 매출 1,500억 원 이상 및 이용자 100만 명 이상
- 추정 기업 수: 100~200개(전자상거래, 의료, 통신 등)
- 금융권과 달리: 인프라를 처음부터 새로 구축해야 함
- 기업당 초기 비용: 수천만 원에서 수억 원
- 총 추정 비용: 최소 수천억 원에서 수조 원
스타트업 성장의 함정
딜레마:
이용자 50만 명 → 성장, 데이터 축적, 투자 유치
이용자 100만 명 도달 → 전송 의무 발생 → API 구축에 수천만 원 비용
선택 → 추가 성장 = 막대한 비용 + 핵심 데이터 노출
결과 → 이용자 100만 명 직전에 성장을 멈춤 → 혁신 동력 상실
역설: “매출 1,500억 원 및 이용자 100만 명” 기준은 “대기업”을 겨냥한다고 홍보되지만, 실제로는 성장 중인 기업에 가장 큰 타격을 준다.
All-Industry Expansion Impact (Estimated)
- Target companies: Revenue ≥150B KRW & ≥1M users
- Estimated number: 100-200 companies (e-commerce, medical, telecom, etc.)
- Unlike financial sector: Must build new infrastructure from scratch
- Initial cost per company: Tens to hundreds of millions KRW
- Total estimated cost: Minimum hundreds of billions to trillions of KRW
The Startup Growth Trap
The Dilemma:
500K users → Growth, data accumulation, investment attraction
1M users milestone → Transfer obligation triggered → API construction costs tens of millions KRW
Choice → More growth = Massive costs + Core data exposure
Result → Stop growth just before 1M users → Loss of innovation momentum
Irony: The threshold “Revenue 150B KRW & 1M users” is marketed as targeting “large businesses” but actually hits growing companies the hardest.
영업비밀 침해
부정경쟁방지 및 영업비밀보호에 관한 법률 제2조 제2호
“영업비밀”이란 공공연히 알려져 있지 않고 독립된 경제적 가치를 가지며, 상당한 노력으로 비밀로 유지·관리된 생산방법, 판매방법, 그 밖에 영업활동에 유용한 기술상 또는 경영상의 정보를 말한다.
위험에 처한 전자상거래 플랫폼의 영업비밀
| 정보 유형 | 영업비밀 해당성 | 전송 강제 여부 |
|---|---|---|
| 구매 패턴 | 수년간의 분석 투자 | 강제 |
| 가격 정책 | 핵심 경쟁 우위 | 강제 |
| 고객 세분화 | AI·머신러닝 투자 | 강제 |
| 판매자 정보 | 거래처 데이터 | 강제 |
데이터 유출 경로
전문기관이 얻는 것:
- 수백만 소비자의 구매 패턴
- 가격 민감도, 선호 상품, 구매 시점
- 이는 플랫폼이 수년간의 투자로 축적한 영업비밀과 같다
결과:
- 전문기관이 무상으로 취득
- 자체 서비스에 활용
- 한국 전자상거래의 경쟁 우위가 약화
GDPR 보호
"타인의 권리와 자유를 부당하게 침해해서는 안 된다"
→ 영업비밀이 침해되면 거부 가능
한국 개정안
영업비밀 보호 조항 없음
→ 무조건적 강제 전송
Trade Secret Violation
Unfair Competition Prevention Act Article 2, Paragraph 2
“Trade secret” means production methods, sales methods, and other technical or business information useful for business activities that is not publicly known, has independent economic value, and has been maintained as confidential through considerable effort.
E-Commerce Platform Trade Secrets at Risk
| Information Type | Trade Secret Status | Transfer Mandate |
|---|---|---|
| Purchase Patterns | Years of analysis investment | Forced |
| Pricing Policies | Core competitive advantage | Forced |
| Customer Segmentation | AI/ML investment | Forced |
| Seller Information | Business partner data | Forced |
The Data Leakage Path
Specialized Agency Gains:
- Purchase patterns of millions of consumers
- Price sensitivity, preferred products, purchase timing
- This equals trade secrets accumulated by platforms through years of investment
Result:
- Specialized agency acquires for free
- Uses for own services
- Korean e-commerce competitive advantage eroded
GDPR Protection
"shall not adversely affect the rights and freedoms of others"
→ Can refuse if trade secrets are infringed
Korean Amendment
NO trade secret protection clause
→ Unconditional forced transfer
네 가지 핵심 해법
1. 개정안 철회 및 위원회 권고 준수
- 2025년 6월 개정안을 즉시 철회
- 2024년 8월 규제개혁위원회 결정을 준수
- 현행 시행령(3개 분야)을 유지
- 재검토에 앞서 충분한 시범 운영
2. 법률유보: 국회 입법
- 시행령에서 대리권 조항을 삭제
- 대리권의 본질적 사항은 법률로 규율
- 국회 심의를 통한 사회적 합의
3. GDPR 방식 채택
- 전문기관 집중화를 폐지
- 본인 내려받기 권리를 우선
- 영업비밀과 데이터베이스 권리를 명시적으로 보호
- 시장 자율을 장려
4. 보안 강화: 스크래핑 금지
- 금융위원회와 동일하게 스크래핑 금지
- 표준 API만 허용
- 분산 구조로 단일 장애점 방지
Four Essential Solutions
1. Withdraw Amendment & Follow Committee Guidance
- Immediately withdraw June 2025 amendment
- Comply with August 2024 Regulatory Reform Committee decision
- Maintain current enforcement decree (3 sectors)
- Sufficient pilot operation before reconsidering
2. Legal Reservation - National Assembly Legislation
- Delete proxy rights clause from enforcement decree
- Regulate essential proxy rights matters by law
- Social consensus through National Assembly deliberation
3. Adopt GDPR Approach
- Abolish specialized agency centralization
- Prioritize self-download rights
- Explicitly protect trade secrets & database rights
- Encourage market autonomy
4. Security Enhancement - Ban Scraping
- Ban scraping same as Financial Services Commission
- Allow only standard APIs
- Prevent SPOF through distributed structure
권고하는 GDPR형 조항
개정안 제○조(전송요구의 제한)
① 다음의 경우 전송을 거부할 수 있다:
- 영업비밀 또는 지식재산을 포함하는 경우
- 데이터베이스 제작자의 권리를 침해하는 경우
- 타인의 권리와 자유를 침해하는 경우
- 기술적으로 곤란하거나 과도한 비용이 드는 경우
② 거부 시 사유를 통지할 의무
Recommended GDPR-Style Provisions
Proposed Amendment Article ○ (Limitations on Transfer Requests)
① Transfer may be refused in the following cases:
- Contains trade secrets or intellectual property
- Infringes database maker’s rights
- Violates rights and freedoms of others
- Technically difficult or excessively costly
② Obligation to notify reasons when refusing
결론: 균형이 필수다
일곱 가지 핵심 우려 요약
| 번호 | 영역 | 핵심 문제 | 사회적 위험 |
|---|---|---|---|
| 1 | 절차적 정당성 | 위원회 권고를 무시하고 4개월 만에 재발의 | 규제 절차 무력화, 행정 신뢰 훼손 |
| 2 | 법적 타당성 | 법률유보 원칙 위반, 위헌적 대리권 | 입법권 침해, 법체계 교란 |
| 3 | 국제 기준 부합 | GDPR 모순, 영업비밀 보호 부재 | 국제 규범 이탈, 재산권 무시 |
| 4 | 정책 공정성 | 전문기관 특혜, 데이터 무임승차 | 시장 왜곡, 생태계 파괴 |
| 5 | 보안 안정성 | 스크래핑 허용, 단일 장애점 형성 | 아이디·비밀번호 노출, 전국 동시 유출 |
| 6 | 경제적 합리성 | 영업비밀 노출, 과도한 비용 | 경쟁력 약화, 성장 저해 |
| 7 | 정책 일관성 | 금융위 조치와 모순, 자기모순 | 행정 일관성 상실 |
이것은 “개인정보 보호”가 아니라 “규제를 통한 시장 재편”이다
“데이터 활성화”가 아니라 “데이터 통제"
"혁신 촉진”이 아니라 “성장 규제"
"보호 강화”가 아니라 “위험 집중”
→ 신중한 재검토와 충분한 사회적 합의가 필요하다
Conclusion: Balance is Essential
Seven Critical Concerns Summary
| No. | Area | Core Problem | Social Risk |
|---|---|---|---|
| 1 | Procedural Legitimacy | Ignoring Committee guidance, re-proposing after 4 months | Regulatory process nullification, administrative trust damage |
| 2 | Legal Validity | Violating legal reservation principle, unconstitutional proxy rights | Legislative power infringement, legal system disruption |
| 3 | Global Compliance | GDPR contradiction, lack of trade secret protection | International norm deviation, property rights ignored |
| 4 | Policy Fairness | Specialized agency privileges, data free-riding | Market distortion, ecosystem destruction |
| 5 | Security Stability | Allowing scraping, SPOF formation | ID/PW exposure, nationwide simultaneous breach |
| 6 | Economic Rationality | Trade secret exposure, excessive costs | Competitiveness erosion, growth inhibition |
| 7 | Policy Consistency | Contradicting FSC measures, self-contradiction | Administrative consistency loss |
This is not “personal information protection” but “market restructuring through regulation”
Not “data activation” but “data control”
Not “innovation promotion” but “growth regulation”
Not “protection enhancement” but “risk centralization”
→ Careful reconsideration and sufficient social consensus required
연구 정보
발표일: 2025년 11월 21일
행사: 마이데이터 정책 스타트업 세미나
주최: 한국스타트업포럼
장소: 디캠프, 서울 강남
발표자: 김용희(Yonghee Kim, Ph.D.)
연구 분야:
- 데이터 정책과 거버넌스
- 디지털 플랫폼 규제
- 스타트업 생태계 보호
- 규제 영향 분석
연락처:
- 이메일: yhkim1981@sunmoon.ac.kr
- 소속: 선문대학교 경영학과
- ORCID: 0000-0002-5643-2748
Research Information
Presentation Date: November 21, 2025
Event: MyData Policy Startup Seminar
Host: Korea Startup Forum
Venue: D.CAMP, Gangnam, Seoul
Speaker: Yonghee Kim, Ph.D.
Research Focus:
- Data policy and governance
- Digital platform regulation
- Startup ecosystem protection
- Regulatory impact analysis
Contact:
- Email: yhkim1981@sunmoon.ac.kr
- Institution: Sunmoon University, Department of Business Administration
- ORCID: 0000-0002-5643-2748