개인정보 보호법
Article 26 (Restriction on Processing of Personal Information due to Entrustment of Business)
제26조 업무위탁에 따른 개인정보의 처리 제한
- Ministry
- 개인정보보호위원회
- In force
- 2025-10-02
- Articles
- 124
개인정보처리자가 제3자에게 개인정보의 처리 업무를 위탁하는 경우에는 다음 각 호의 내용이 포함된 문서로 하여야 한다. <개정 2023.3.14>
1. 위탁업무 수행 목적 외 개인정보의 처리 금지에 관한 사항
2. 개인정보의 기술적ㆍ관리적 보호조치에 관한 사항
3. 그 밖에 개인정보의 안전한 관리를 위하여 대통령령으로 정한 사항
When a personal information controller entrusts personal information processing business to a third party, it shall be done by a document that includes the following matters: <Amended by Act No. 12460, Mar. 14, 2023> 1. Matters concerning the prohibition of processing personal information for purposes other than the entrusted business; 2. Matters concerning technical and administrative protective measures for personal information; 3. Other matters prescribed by Presidential Decree for the safe management of personal information.
제1항에 따라 개인정보의 처리 업무를 위탁하는 개인정보처리자(이하 "위탁자"라 한다)는 위탁하는 업무의 내용과 개인정보 처리 업무를 위탁받아 처리하는 자(개인정보 처리 업무를 위탁받아 처리하는 자로부터 위탁받은 업무를 다시 위탁받은 제3자를 포함하며, 이하 "수탁자"라 한다)를 정보주체가 언제든지 쉽게 확인할 수 있도록 대통령령으로 정하는 방법에 따라 공개하여야 한다. <개정 2023.3.14>
A personal information controller (hereinafter referred to as the "entrustor") who entrusts personal information processing business pursuant to paragraph ① shall disclose the details of the entrusted business and the party processing the personal information processing business (including a third party who is re-entrusted with business from a party processing personal information processing business, and hereinafter referred to as the "entrusted party") in a manner prescribed by Presidential Decree so that the data subject can easily identify them at any time. <Amended by Act No. 12460, Mar. 14, 2023>
위탁자가 재화 또는 서비스를 홍보하거나 판매를 권유하는 업무를 위탁하는 경우에는 대통령령으로 정하는 방법에 따라 위탁하는 업무의 내용과 수탁자를 정보주체에게 알려야 한다. 위탁하는 업무의 내용이나 수탁자가 변경된 경우에도 또한 같다.
When the entrustor entrusts business for promoting goods or services or soliciting sales, they shall inform the data subject of the details of the entrusted business and the entrusted party in a manner prescribed by Presidential Decree. The same shall apply when the details of the entrusted business or the entrusted party are changed.
위탁자는 업무 위탁으로 인하여 정보주체의 개인정보가 분실ㆍ도난ㆍ유출ㆍ위조ㆍ변조 또는 훼손되지 아니하도록 수탁자를 교육하고, 처리 현황 점검 등 대통령령으로 정하는 바에 따라 수탁자가 개인정보를 안전하게 처리하는지를 감독하여야 한다. <개정 2015.7.24>
The entrustor shall educate the entrusted party and supervise whether the entrusted party processes personal information safely by checking the processing status, etc., as prescribed by Presidential Decree, to prevent the personal information of the data subject from being lost, stolen, leaked, forged, altered, or damaged due to the entrustment of business. <Amended by Act No. 11300, Jul. 24, 2015>
수탁자는 개인정보처리자로부터 위탁받은 해당 업무 범위를 초과하여 개인정보를 이용하거나 제3자에게 제공하여서는 아니 된다.
The entrusted party shall not use or provide personal information to a third party beyond the scope of the entrusted business received from the personal information controller.
수탁자는 위탁받은 개인정보의 처리 업무를 제3자에게 다시 위탁하려는 경우에는 위탁자의 동의를 받아야 한다. <신설 2023.3.14>
If the entrusted party intends to re-entrust the personal information processing business entrusted to them to a third party, they shall obtain the consent of the entrustor. <Newly Inserted by Act No. 12460, Mar. 14, 2023>
수탁자가 위탁받은 업무와 관련하여 개인정보를 처리하는 과정에서 이 법을 위반하여 발생한 손해배상책임에 대하여는 수탁자를 개인정보처리자의 소속 직원으로 본다. <개정 2023.3.14>
With respect to liability for damages incurred due to the violation of this Act in the process of processing personal information related to the entrusted business, the entrusted party shall be deemed an employee of the personal information controller. <Amended by Act No. 12460, Mar. 14, 2023>
수탁자에 관하여는 제15조부터 제18조까지, 제21조, 제22조, 제22조의2, 제23조, 제24조, 제24조의2, 제25조, 제25조의2, 제27조, 제28조, 제28조의2부터 제28조의5까지, 제28조의7부터 제28조의11까지, 제29조, 제30조, 제30조의2, 제31조, 제33조, 제34조, 제34조의2, 제35조, 제35조의2, 제36조, 제37조, 제37조의2, 제38조, 제59조, 제63조, 제63조의2 및 제64조의2를 준용한다. 이 경우 "개인정보처리자"는 "수탁자"로 본다. <개정 2023.3.14>
Articles 15 through 18, 21, 22, 22-2, 23, 24, 24-2, 25, 25-2, 27, 28, 28-2 through 28-5, 28-7 through 28-11, 29, 30, 30-2, 31, 33, 34, 34-2, 35, 35-2, 36, 37, 37-2, 38, 59, 63, 63-2, and 64-2 shall apply mutatis mutandis to the entrusted party. In this case, "personal information controller" shall be deemed "entrusted party". <Amended by Act No. 12460, Mar. 14, 2023>
Translation
Machine translation. The Korean text is authoritative.
Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.