상세 보기
개인정보 유출로 인한 비재산적 손해의 판단 구조의 재구성 - 손해 발생과 손해액 판단 요소의 분리 -
초록
Since the GS Caltex decision, the Korean Supreme Court has applied seven comprehensive factors to determine whether non-pecuniary damage has arisen from a personal data breach. These factors, however, conflate matters of distinct character: some bear on whether damage exists at all, while others concern the magnitude of the damage, the establishment of liability, or grounds for mitigation. As a result, circumstances that should operate to reduce the amount of compensation or to adjust the scope of liability may instead be invoked to deny the very existence of damage. In its recent decision 2023Da311184, the Supreme Court held that, under the statutory damages provision of Article 39-2 of the Personal Information Protection Act, a data subject need not specifically prove the occurrence of damage, yet also held that a controller may be discharged from liability by proving the absence of mental suffering. In making that determination, the Court relied on the same seven factors, thereby mobilizing considerations proper to the assessment of the amount of damage as grounds for denying its existence. This article proposes to restructure these factors by distinguishing the determination of whether damage exists from the determination of its amount. Whether damage has arisen should be judged by a single criterion: whether personal information, against the data subject's will, has left the subject's sphere of control and been placed in a state accessible to unauthorized third parties. The remaining factors—the sensitivity and identifiability of the information, the scope of dissemination, the likelihood of further infringement, and post-incident measures—belong to the stage of assessing the amount, while the controller's management practices and the circumstances of the breach pertain both to the establishment of liability and to the assessment of the amount. This restructuring does not introduce a novel concept of damage; rather, it formulates explicitly the approach that some lower courts have already adopted, recognizing damage on the basis of third-party accessibility. Comparative law points in the same direction. The Court of Justice of the European Union and the German Federal Court of Justice have held that the loss of control itself may constitute non-pecuniary damage, relaxing the threshold for the existence of damage while keeping awards modest. Because personal data breaches constitute a type of diffused harm—where each individual's loss is slight but many are harmed simultaneously—denying the existence of damage on the ground that individual losses are minor deprives the corrective mechanisms enacted by the legislature (the reversal of the burden of proof as to fault, statutory damages, and punitive damages) of any foundation on which to operate. An interpretive approach that clarifies the criterion for the existence of damage and separates out the factors for assessing its amount is therefore a precondition not only for the relief of victims but also for enabling the existing statutory mechanisms to perform their intended functions.
키워드
- 제목
- 개인정보 유출로 인한 비재산적 손해의 판단 구조의 재구성 - 손해 발생과 손해액 판단 요소의 분리 -
- 제목 (타언어)
- Reconstructing the Analytical Framework for Non-Pecuniary Damage Caused by Personal Data Breaches: Separating the Existence of Damage from the Assessment of Damages
- 저자
- 박혜진
- 발행일
- 2026-06
- 유형
- Y
- 저널명
- 민사법학
- 권
- 115
- 페이지
- 121 ~ 168