Skip to main content
Law4Kor
Personal Information Protection Act

개인정보 보호법

Article 28-4 (Obligation to Take Safety Measures for Pseudonymized Information, etc.)

제28조의4 가명정보에 대한 안전조치의무 등

Ministry
개인정보보호위원회
In force
2025-10-02
Articles
124
Original (Korean)

개인정보처리자는 제28조의2 또는 제28조의3에 따라 가명정보를 처리하는 경우에는 원래의 상태로 복원하기 위한 추가 정보를 별도로 분리하여 보관ㆍ관리하는 등 해당 정보가 분실ㆍ도난ㆍ유출ㆍ위조ㆍ변조 또는 훼손되지 않도록 대통령령으로 정하는 바에 따라 안전성 확보에 필요한 기술적ㆍ관리적 및 물리적 조치를 하여야 한다. <개정 2023.3.14>

A personal information controller processing pseudonymized information in accordance with Article 28-2 or Article 28-3 shall take technical, managerial, and physical measures necessary for ensuring safety, as prescribed by Presidential Decree, to prevent such information from being lost, stolen, leaked, falsified, altered, or damaged, including separately storing and managing additional information for the restoration to the original state. <Amended by Act No. 17973, Mar. 14, 2023>

개인정보처리자는 제28조의2 또는 제28조의3에 따라 가명정보를 처리하는 경우 처리목적 등을 고려하여 가명정보의 처리 기간을 별도로 정할 수 있다. <신설 2023.3.14>

A personal information controller processing pseudonymized information in accordance with Article 28-2 or Article 28-3 may separately determine the processing period of the pseudonymized information, taking into account the processing purpose, etc. <Newly Established by Act No. 17973, Mar. 14, 2023>

개인정보처리자는 제28조의2 또는 제28조의3에 따라 가명정보를 처리하고자 하는 경우에는 가명정보의 처리 목적, 제3자 제공 시 제공받는 자, 가명정보의 처리 기간(제2항에 따라 처리 기간을 별도로 정한 경우에 한한다) 등 가명정보의 처리 내용을 관리하기 위하여 대통령령으로 정하는 사항에 대한 관련 기록을 작성하여 보관하여야 하며, 가명정보를 파기한 경우에는 파기한 날부터 3년 이상 보관하여야 한다. <개정 2023.3.14>

A personal information controller intending to process pseudonymized information in accordance with Article 28-2 or Article 28-3 shall prepare and retain relevant records on matters prescribed by Presidential Decree for managing the processing details of the pseudonymized information, such as the processing purpose of the pseudonymized information, the recipient when provided to a third party, and the processing period of the pseudonymized information (limited to cases where the processing period is separately determined under Paragraph 2), and shall retain records of pseudonymized information that has been destroyed for at least 3 years from the date of destruction. <Amended by Act No. 17973, Mar. 14, 2023>

Translation

Machine translation. The Korean text is authoritative.

Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.

Personal Information Protection Act 제28조의4 — Article 28-4 (Obligation to Take Safety Measures for Pseudonymized Information, etc.) · Law4Kor