Skip to main content
Law4Kor
Personal Information Protection Act

개인정보 보호법

Article 23 (Restriction on Processing of Sensitive Information)

제23조 민감정보의 처리 제한

Ministry
개인정보보호위원회
In force
2026-09-11
Articles
125
Original (Korean)

개인정보처리자는 사상ㆍ신념, 노동조합ㆍ정당의 가입ㆍ탈퇴, 정치적 견해, 건강, 성생활 등에 관한 정보, 그 밖에 정보주체의 사생활을 현저히 침해할 우려가 있는 개인정보로서 대통령령으로 정하는 정보(이하 "민감정보"라 한다)를 처리하여서는 아니 된다. 다만, 다음 각 호의 어느 하나에 해당하는 경우에는 그러하지 아니하다. <개정 2016.3.29>

  1. 1. 정보주체에게 제15조제2항 각 호 또는 제17조제2항 각 호의 사항을 알리고 다른 개인정보의 처리에 대한 동의와 별도로 동의를 받은 경우

  2. 2. 법령에서 민감정보의 처리를 요구하거나 허용하는 경우

A personal information controller shall not process information concerning beliefs and ideologies, membership or withdrawal from a labor union or political party, political views, health, sexual life, or other personal information that is likely to significantly infringe upon the privacy of the data subject as prescribed by Presidential Decree (hereinafter referred to as "sensitive information"). Provided, however, that this shall not apply in any of the following cases. <Amended by Act No. 13736, Mar. 29, 2016> 1. Where the data subject has been informed of the matters prescribed in subparagraphs of Article 15 (2) or subparagraphs of Article 17 (2) and has given consent separately from consent for the processing of other personal information. 2. Where the processing of sensitive information is required or permitted by other Acts and subordinate statutes.

개인정보처리자가 제1항 각 호에 따라 민감정보를 처리하는 경우에는 그 민감정보가 분실ㆍ도난ㆍ유출ㆍ위조ㆍ변조 또는 훼손(이하 "유출등"이라 한다)이 되지 아니하도록 제29조에 따른 안전성 확보에 필요한 조치를 하여야 한다. <신설 2016.3.29, 2026.3.10>

Where a personal information controller processes sensitive information pursuant to subparagraphs of paragraph (1), the controller shall take measures necessary to secure safety as prescribed by Article 29 to prevent such sensitive information from being lost, stolen, leaked, forged, altered, or damaged. <Newly Inserted by Act No. 13736, Mar. 29, 2016>

개인정보처리자는 재화 또는 서비스를 제공하는 과정에서 공개되는 정보에 정보주체의 민감정보가 포함됨으로써 사생활 침해의 위험성이 있다고 판단하는 때에는 재화 또는 서비스의 제공 전에 민감정보의 공개 가능성 및 비공개를 선택하는 방법을 정보주체가 알아보기 쉽게 알려야 한다. <신설 2023.3.14>

If a personal information controller determines that there is a risk of privacy infringement due to the inclusion of the data subject's sensitive information in information disclosed in the process of providing goods or services, the controller shall inform the data subject in an easily understandable manner about the possibility of sensitive information disclosure and methods to choose non-disclosure before providing the goods or services. <Newly Inserted by Act No. 15413, Mar. 14, 2023>

Translation

Machine translation. The Korean text is authoritative.

Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.

Personal Information Protection Act 제23조 — Article 23 (Restriction on Processing of Sensitive Information) · Law4Kor