개인정보 보호법
Article 21 (Destruction of Personal Information)
제21조 개인정보의 파기
- Ministry
- 개인정보보호위원회
- In force
- 2026-09-11
- Articles
- 125
개인정보처리자는 보유기간의 경과, 개인정보의 처리 목적 달성, 가명정보의 처리 기간 경과 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 그 개인정보를 파기하여야 한다. 다만, 다른 법령에 따라 보존하여야 하는 경우에는 그러하지 아니하다. <개정 2023.3.14>
A personal information controller shall, without delay, destroy the personal information when it has become unnecessary due to the expiration of the retention period, the achievement of the purpose of processing personal information, the expiration of the processing period for pseudonymized information, etc. Provided, That this shall not apply where preservation is required by other Acts and subordinate statutes. <Amended by Act No. 18065, Mar. 14, 2023>
개인정보처리자가 제1항에 따라 개인정보를 파기할 때에는 복구 또는 재생되지 아니하도록 조치하여야 한다.
When a personal information controller destroys personal information pursuant to paragraph (1), he/she shall take measures to ensure that it cannot be restored or reproduced.
개인정보처리자가 제1항 단서에 따라 개인정보를 파기하지 아니하고 보존하여야 하는 경우에는 해당 개인정보 또는 개인정보파일을 다른 개인정보와 분리하여서 저장ㆍ관리하여야 한다.
Where a personal information controller is required to preserve personal information pursuant to the proviso to paragraph (1) without destroying it, he/she shall store and manage such personal information or personal information file separately from other personal information.
개인정보의 파기방법 및 절차 등에 필요한 사항은 대통령령으로 정한다.
Matters necessary for the methods and procedures for destroying personal information, etc., shall be prescribed by Presidential Decree.
Translation
Machine translation. The Korean text is authoritative.
Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.