2.24 테러방지법’ 폐기촉구 시민서명 국회전달 기자회견
글 | 김가연(오픈넷 변호사)
일시: 2015년 11월 9일 – 11월 14일
장소: 조앙 페소아, 브라질
○ 11월 9일 월요일(Day 0)
- 주최: Rebecca MacKinnon, Director, Ranking Digital Rights, New America Foundation
- 세션 소개
○ 11월 11일 수요일(Day 2)
- 주최:
Mr Sérgio Branco – Instituto de Tecnologia e Sociedade do Rio de Janeiro
Ms Marianne Franklin – Internet Rights and Principles Coalition /Goldsmiths (University of London, UK)
Mr Hernán E. Vales – Office of the United Nations High Commissioner for Human Rights
- 김가연 변호사 발표 내용:
KELLY KIM: This discussion on the right to be forgotten is very important especially in Korea, as the Korean Communication Commission, which is FCC of Korea, is considering adopting a right-to-be-forgotten law since the ECJ decision Google Spain came out. It hasn’t been particularly successful yet, but we are worried that we might become the first country to have the right to be forgotten statute, on top of rigorous online censorship carried out by an administrative agency called the Korea Communications Standard Commission which is taking many lawful contents down whenever it’s “necessary for nurturing sound communication ethics.” a standard as vague and amorphous as the standards used by the Google Spain decision: ‘excessive’, ‘obsolete’, ‘irrelevant’.
Data Protection law in general defines “personal Information” as information related to a living individual and gives the data subject the power to control his or her personal data. A tenet that “one owns data about him or her (and therefore should have control over that data)” sounds good but is not always sustainable and compatible with respect for others’ freedom of thoughts and expressions. For example, “Kelly Kim is a lawyer” is data about me that is known to many already. And the question is, when and under what grounds can I control this perfectly lawful data about myself, that resides in other people’s heads, that is non-defamatory and non-privacy-infringing?
Well, the Google Spain case was one answer to that Question, which we consider more or less lousy. One reason is that the information deindexed, which was a hyperlink, was already publicly available data, which was published in the newspaper. So applying data protection law on such information is against its original purpose, because the data protection law was meant to protect data that are not publicly available and thus within the privacy area. We wanted to protect privacy through a data protection law. We should not protect people’s desire to wipe out unfavorable or embarrassing information about themselves.
Let me give you an example on how the right to be forgotten can be abused.
Korea became independent of a 36-year Japanese colonial rule in 1948. Many Korean people collaborated with the colonial administration and exploited their fellow Koreans.The issue is current because, unlike Germany or France, there has been no government-sponsored efforts to indict and bring to justice those collaborators who number in tens of thousands. And many were not public figures during the colonial periods and they have never been. Some of them were the officers or civic servants who carried out the military logistics and tactics of the Japanese invasion through Asia, which reached as far as Myanmar. And now there is an NGO-led effort to keep the encyclopedia of these Korean collaborators. Of course, the collaborators and the descendants are contesting these efforts. So, in this case, if the right to be forgotten law in the sense of Google Spain is in place, any links to the encyclopedia or the entries themselves may be required to be taken down for the reason that their past wrongdoings are now obsolete because it was more than half a century ago.
So we should stop talking data ownership and start talking about privacy. And the right to be forgotten should not be applied to data that are publicly available, although it’s about an individual. Thanks.
- 김가연 변호사 발표 내용:
KELLY KIM: This discussion on right to be forgotten or the right to be de-indexed is important for Korea as Korean government and the Korean Communication Commission, which is the U.S.’s FCC of Korea is considering adopting a right-to-be-forgotten law since the ECJ decision Google Spain came out. However, it hasn’t been particularly successful yet because right to be forgotten in a broad sense is very widely recognized in Korea already.
Firstly, we already have a law under which an individual can compel intermediaries to take down information that is allegedly defamatory or infringing on privacy. And what makes this law similar to the right to be forgotten is that information is required to be taken down simply upon allegation short of any proof of infringement. So every year, more than 200,000 postings are being taken down by the intermediaries, simply for a reason that that data subjects do not like the postings about them. Marianne just mentioned stats from Google that last year like 228,000 requests were received. So you can tell how bad the situation is in Korea. and that means we have that many individual cases that year.
Secondly, we also have an administrative agency called the Korea Communications Standard Commission, which exercises rigorous online censorship. Korea Communications Standard Commission is empowered by the law to make takedown requests on even lawful contents, whenever it is “necessary for nurturing sound communication ethics.” Any lawful content can be taken down by the Korea Communications Standard Commission if it violates the standard. This is a standard as vague and amorphous as the standards used by the Google Spain decision: which are ‘excessive’, ‘obsolete’, ‘irrelevant’.
Thirdly, we have criminal defamation law that punishes even non-privacy infringing, truthful statements, which allows a data subject not only to request takedown but also to criminally punish others for saying bad but true statements about him or her.
And fourthly and finally, you also have data protection law that may or may not give a data subject a blanket authority to demand data erasure about him or her. Well, apparently there aren’t many such requests made, so we don’t have a court case yet.
I just want to underline that if we limit right to be forgotten only to de-indexing from the search, okay, we don’t have any case yet. However, we don’t need a such right in Korea because there are many legal tools that I just illustrated that are used to expunge online information that you don’t like.
So we want to protect privacy through data protection law. We should not protect people’s desire to wipe out unfavorable or embarrassing information about themselves. Think about a word where only favorable or delightful information about a person lasts. I don’t want to live in that world. Thank you.
○ 11월 12일 목요일(Day 3)
- 주최:
Diego R. Canabarro / Carlos Affonso de Souza – Brazilian Internet Observatory, Multistakeholder Initiative
- 김가연 변호사 발표 내용:
KELLY KIM: Open Net is a Civil Society Organization fighting for digital rights in Korea. We are supporting the Korea Internet Transparency Report project, which is very well staffed as we have one full‑time lawyer. The methodology of the project is, we gather all legally available data on government requests related to internet transparency, which are online censorship and surveillance. And then we analyse the data and present observations and findings in accessible form and you will find them on the website. PDF version of our report is also available.
And the sources of the data are varied from government to private companies. And the aim of the project is: promoting civic awareness of online censorship and surveillance carried out by the government; promoting transparency reporting of both the government and private companies; and raising issues and making the public aware of the problems associated with the government’s practices and policies of Internet censorship and surveillance, and in the end, bring about changes.
So the project launched last year. And interestingly, two major Internet companies in Korea, which are Daumkakao and Naver, started to publish transparency reports in few months. So we considered it a great achievement and we also proposed a Bill together with National Assembly members mandating Government’s transparency reporting on mass surveillance.
And also we are involved in Stanford’s WILmap project in building South Korea page. And the map has been very useful in our advocacy for fixing intermediary regime in Korea. I must say we have been integrating the data and observations with our actions in promoting user rights on the Internet very effectively. Thank you.
○ 11월 13일 금요일
- 김가연 변호사 발표 자료: 151113 Manila Principles(Kelly Kim)
오병일 정보인권연구소 이사
지난 9월 1일 국가정보원은 '국가사이버안보기본법' 제정안을 입법예고했다. 결론부터 얘기하자면, 이 법은 이름만 바꾼 '사이버테러 방지법'이며, 민간 정보통신망에 대한 국정원의 감시와 사찰을 확대할 국정원 권한 강화법이다.
올해 초, 국가비상사태라는 (물론 그러한 사태는 전혀 일어나지 않았지만) 황당한 명분으로 정의화 국회의장이 테러방지법을 직권 상정하고, 192시간에 걸친 야당 의원들의 필리버스터에도 결국 국회를 통과한 것을 모두들 기억하고 있을 것이다. 당시 청와대와 새누리당이 밀어붙였던 또 하나의 법안이 사이버테러방지법이었는데, 정의화 국회의장도 이것까지 직권 상정하는 것은 부담스러웠던 모양이다. 결국 사이버테러 방지법은 19대 국회에서 임기 만료로 폐기됐다.
그러나 사이버테러 방지법에 대한 국정원의 열망은 멈추지 않는다. '국가 사이버위기 관리 법안', '국가 사이버테러 방지 등에 관한 법률안' 등 이름만 바뀌었을 뿐 18대, 19대 국회에서 계속 발의되었고, 이미 20대 국회에서도 새누리당 이철우 의원 대표 발의로 '국가 사이버안보에 관한 법률안'이 국정원의 입법예고안과 별개로 발의돼있다.
국가사이버안보 기본법을 반대해야 하는 이유
그럼, 이 법률안이 어떠한 문제가 있는지 찬찬히 들여다보자. 입법예고안은 국정원에 다음과 같은 역할을 부여하고 있다.
법안에서 국가정보원의 역할
- 지원기관에 사실상 국정원 영향 하에 있는 국가보안기술연구소 포함 (제2조 7호)
- 국가사이버안보 실무위원회 공동 운영 (제5조 3항)
- 사이버안보 기본계획 수립·시행 권한 (제7조 1항)
- 사이버안보 실태 평가 권한 (제8조)
- 국가 차원의 일원화된 신고 및 조사 체계 운영 (제12조 1항)
- '국가 안보를 위협하는 사이버 공격'의 신고 접수 (제12조 2항)
- '국가안보를 위협하는 사이버공격'에 대한 사고조사 (제12조 4항)
- 사이버위기대책본부의 구성 관여 (제15조 2항)
우선 법률안은 국정원이 국가사이버안보 실무위원회를 공동 운영하고 사이버안보 기본계획을 수립, 시행하도록 함으로써 콘트롤타워로서의 실질적인 역할을 하도록 하고 있다. 비밀정보기관에 국가 사이버보안의 콘트롤타워를 맡기는 나라는 없다. 이는 마치 미국의 국가안보국(NSA)이나 중앙정보국(CIA)이 미국 사이버보안 콘트롤타워 역할을 하는 것이나 다름없다.
또한, 법률안은 국정원이 공공기관 및 민간업체의 정보통신망에 침해 사고 조사를 명분으로 접근할 수 있도록 하고 있다. 침해사고 조사는 일종의 수사와 유사한 과정으로 볼 수 있는데, 국정원이 이를 통해 공공기관과 민간업체의 민감한 정보에 접근하여 이들을 감시, 사찰할 우려가 있다. 지난 '사이버테러방지법'에 대한 비판을 의식했는지, 이번 법률안에는 포털 등이 명시적으로 포함되어 있지는 않지만, 국가사이버안보위원회가 의결을 통해 법률의 규율 대상이 되는 '책임기관'을 지정할 수 있도록 하고 있어, 포털이나 언론 등으로 그 대상이 확대될 가능성이 존재한다.
국가정보원은 공공기관들의 사이버 보안에 대한 실태 평가도 할 수 있는데, 시행령이 어떻게 제정되느냐에 따라 법원, 국회, 헌법재판소, 선관위 등의 사이버 보안 관련 정보와 시설에 접근할 수 있다. 비밀정보기관인 국가정보원이 국회, 법원 등의 사이버 보안을 관할하는 것은 헌법기관의 독립성을 침해할 우려가 있다.
지금까지 국내 정치 개입, 민간인 사찰 등으로 물의를 빚어왔음에도 불구하고, 여전히 국회나 법원의 통제를 받지 않는 국정원이 사이버 보안을 명분으로 포털이나 주요 대기업, 언론사, 국회 등의 정보통신망에 접근하여 민감한 정보를 취득할 수 있다면 국정원의 정치 공작이 더욱 심각해질 것임은 불 보듯 뻔한 일이다.
국정원은 사이버 보안에서 손을 떼라!
이미 국정원은 '국가사이버안전관리규정'에 근거하여, 국가 및 공공기관망 에 대한 관리 권한과 함께, '국가사이버안전센터'를 통해 '민관군 사이버위협 합동대응팀'을 이끌고 있다. 또한, 정보 보호 시스템에 대한 인증, 암호 인증 등의 업무를 수행하면서, 국내 보안 업계에도 막강한 영향력을 행사하고 있다.
그러나 사이버 보안(Cyber Security)을 국가 안보(National Security)와 혼동해서는 안 된다. 물론 북한의 사이버 공격이 있을 수도 있고, 중대한 사이버 공격은 국가안보에 위협이 될 수도 있다. 그러나 모든 사이버 공격이 북한이나 국가안보에 관련된 것은 아니다. 호기심이 많은 해커에서부터 인터넷 상의 크고 작은 사기꾼이나 범죄자들까지, 혹은 해외의 정보기관이나 심지어 국정원까지 누구나 사이버 공격자가 될 수 있다. 지난 2015년, 국정원도 RCS라는 해킹 프로그램을 사용하고 악성 코드를 유포해왔음이 드러나지 않았나. 사이버보안은 예방, 탐지, 복구, 대응 등 여러 단계로 이루어져 있는데, 누가 공격자이든 정보통신망을 운영하는 기관은 자신에게 필요한 보안 조치를 취해야 한다. 조사 결과 범죄와 관련되어 있다면 경찰이나 검찰이 수사하면 된다.
국정원에 국가 사이버보안에 대한 콘트롤타워를 맡기는 것은 오프라인으로 비유하자면 국정원이 민간의 자치적인 방범부터 경찰과 검찰까지 통솔하는 것이나 다름없다. 이는 국정원의 기본 직무 범위를 한참 벗어난 것이다. 다시 말하지만, 어떤 나라가 비밀정보기관에 사이버보안에 대한 콘트롤타워를 맡기고 있는가! 국가적 콘트롤타워가 필요하다면 국회의 감독을 받을 수 있는 일반 행정기관이 담당해야 한다.
이제 국가사이버안보기본법에 대한 반대라는 네거티브적 접근에서 벗어나서, 국정원으로부터 사이버보안 업무를 분리하도록 요구해야 한다. 국정원의 개혁과 국정원에 대한 입법적, 사법적 감독의 강화와 함께 가야 하는 것은 물론이다.
참여사회연구소는 2011년 10월 13일부터 '시민정치시평'이란 제목으로 <프레시안> 에 칼럼을 연재하고 있습니다. 참여사회연구소는 1996년 "시민사회 현장이 우리의 연구실입니다"라는 기치를 내걸고 출범한 참여연대 부설 연구소입니다. 지난 19년 동안 참여민주사회의 비전과 모델, 전략을 진지하게 모색해 온 참여사회연구소는 한국 사회의 현안과 쟁점을 다룬 칼럼을 통해 보다 많은 시민들과 만나고자 합니다. 참여사회연구소의 시민정치는 우리가 속한 공동체에 주체적으로 참여하고, 책임지는 정치를 말합니다. 시민정치가 이루어지는 곳은 우리 삶의 결이 담긴 모든 곳이며, 공동체의 운명에 관한 진지한 숙의와 실천이 이루어지는 모든 곳입니다. '시민정치시평'은 그 모든 곳에서 울려 퍼지는 혹은 솟아 움트는 목소리를 담아 소통하고 공론을 하는 마당이 될 것입니다. 많은 독자들의 성원을 기대합니다.
같은 내용이 프레시안에도 게시됩니다. 목록 바로가기(클릭)
* 본 내용은 참여연대나 참여사회연구소의 공식 입장이 아닙니다.
테러방지법이 국회에서 통과된 지 일주일도 안 돼 박근혜 대통령과 정부·여당이 사이버테러방지법 제정을 압박하고 나섰습니다.
지난 3월 2일 본회의를 통과한 테러방지법은 민감 정보를 포함한 개인정보의 수집, 위치추적, 대테러조사 권한을 국정원에게 부여했습니다. 사이버테러방지법 또한 합리적인 이유 없이 민간 인터넷의 사이버안전 관리 권한을 국정원에게 부여합니다. 헌법이 보장한 기본권 및 개인의 프라이버시권 침해가 우려됩니다.
이에 테러방지법과 사이버테러방지법의 문제점을 진단하는 긴급토론회를 진행하려 합니다.
토론회 개요
일시·장소 3월 22일(화) 오후 2시~5시 국회 의원회관 제2소회의실
주 최
민주사회를위한변호사모임, 민주주의법학연구회, 인권운동공간 ‘활’, 인권운동사랑방, 진보네트워크센터, 참여연대, 김광진 의원(더불어민주당)
사 회 오동석 (민주주의법학연구회 회장, 아주대 교수)
토론회 순서
발제1 테러방지법의 문제점 - 위헌성을 중심으로 / 이광철 (변호사, 민주사회를 위한 변호사모임)
발제2 사이버테러방지법 문제점과 국제사례비교 / 이은우 (변호사, 정보인권연구소 이사)
토 론 심우민 (국회 입법조사처 과학방송통신팀 입법조사관)
오영중 (변호사, 서울지방변호사회 인권위원장)
이동산 (페이게이트 이사)
이태호 (참여연대 정책위원장)
종합토론
문 의 참여연대 행정감시센터(02-723-5302)
2016. 3. 21.(월) 저녁 7시 30분 ~ 9시 30분
스타트업얼라이언스 앤스페이스
빅데이터와 사물인터넷 시대에 개인정보는 어떻게 보호되어야 할까요?
방송통신위원회는 2016년 업무계획에서 빅데이터 시대를 대비하여 비식별화와 익명화 조치 근거를 만들어 선사용-후동의(opt-out) 방식의 개인정보 활용 산업을 활성화하겠다고 밝힌 바 있습니다. 이 같은 움직임은 이익형량의 고려가 부족한 사전 동의(opt-in) 방식의 현행 개인정보보호 법령이 기업들의 개인정보를 활용한 서비스를 부당하게 제한하고 있다는 인식에 근거하고 있습니다.
그러나 비식별화 및 익명화 처리에 대한 이해와 방법론이 불분명한 상황에서 옵트아웃 제도의 도입은 개인정보 자기결정권을 사실상 무력화시킬 수 있다는 우려와 비판의 목소리가 큽니다. 논의의 전제인 사전동의 방식의 개인정보 보호 효과에서부터 비식별화와 익명화의 개념정의, 국내외 개인정보보호 법령의 해석 등 많은 부분에서 주장이 엇갈리고 있는 것도 사실입니다.
이번 3월 정기 오픈넷 포럼에서는 개인정보 분야의 전문가들을 모시고 개인정보 비식별화/익명화 및 옵트아웃 정책을 둘러싼 각 계의 주장을 정리해보고 개인정보 보호에 대한 합리적 정책 방향을 모색하고자 합니다.
개인정보 분야에 관심 있는 여러분들의 많은 참석 부탁드립니다. 참가신청은 오픈넷 홈페이지(http://opennet.or.kr/11312)에서 하실 수 있습니다.
일 시: 2016. 3. 21.(월) 저녁 7시 30분 ~ 9시 30분
장 소: 스타트업얼라이언스 앤스페이스
(서울시 강남구 테헤란로 423, 현대타워 7층/선릉역 10번 출구에서 직진, 3분거리)
발 제
심 우 민 국회입법조사처 입법조사관
토 론
박 경 신 고려대학교 법학전문대학원 교수, 오픈넷 이사
전 응 준 법무법인 유미 변호사
이 영 환 건국대학교 정보통신대학원 교수
문의: 오픈넷 사무국 02-581-1643, [email protected]
시민들의 의견
댓글 달기