Skip to main content
Law4Kor
Personal Information Protection Act

개인정보 보호법

Article 31 (Designation of Personal Information Protection Officer, etc.)

제31조 개인정보 보호책임자의 지정 등

Ministry
개인정보보호위원회
In force
2025-10-02
Articles
124
Original (Korean)

개인정보처리자는 개인정보의 처리에 관한 업무를 총괄해서 책임질 개인정보 보호책임자를 지정하여야 한다. 다만, 종업원 수, 매출액 등이 대통령령으로 정하는 기준에 해당하는 개인정보처리자의 경우에는 지정하지 아니할 수 있다. <개정 2023.3.14>

A personal information controller shall designate a personal information protection officer who will be in charge of and responsible for tasks related to the processing of personal information. However, a personal information controller meeting the criteria prescribed by Presidential Decree regarding the number of employees, sales, etc., may not designate one. <Amended by Act No. 17963, Mar. 14, 2023>

제1항 단서에 따라 개인정보 보호책임자를 지정하지 아니하는 경우에는 개인정보처리자의 사업주 또는 대표자가 개인정보 보호책임자가 된다. <신설 2023.3.14>

If a personal information protection officer is not designated pursuant to the proviso to paragraph (1), the owner or representative of the business of the personal information controller shall serve as the personal information protection officer. <Newly Inserted by Act No. 17963, Mar. 14, 2023>

개인정보 보호책임자는 다음 각 호의 업무를 수행한다. <개정 2023.3.14>

  1. 1. 개인정보 보호 계획의 수립 및 시행

  2. 2. 개인정보 처리 실태 및 관행의 정기적인 조사 및 개선

  3. 3. 개인정보 처리와 관련한 불만의 처리 및 피해 구제

  4. 4. 개인정보 유출 및 오용ㆍ남용 방지를 위한 내부통제시스템의 구축

  5. 5. 개인정보 보호 교육 계획의 수립 및 시행

  6. 6. 개인정보파일의 보호 및 관리ㆍ감독

  7. 7. 그 밖에 개인정보의 적절한 처리를 위하여 대통령령으로 정한 업무

The personal information protection officer shall perform the following tasks: <Amended by Act No. 17963, Mar. 14, 2023> 1. Establishment and implementation of personal information protection plans. 2. Regular investigation and improvement of personal information processing practices and customs. 3. Handling of complaints and remedy of damages related to personal information processing. 4. Establishment of an internal control system to prevent leakage and misuse or abuse of personal information. 5. Establishment and implementation of personal information protection training plans. 6. Protection, management, and supervision of personal information files. 7. Other tasks prescribed by Presidential Decree for the proper processing of personal information.

개인정보 보호책임자는 제3항 각 호의 업무를 수행함에 있어서 필요한 경우 개인정보의 처리 현황, 처리 체계 등에 대하여 수시로 조사하거나 관계 당사자로부터 보고를 받을 수 있다. <개정 2023.3.14>

The personal information protection officer may, if necessary for performing the tasks referred to in subparagraphs of paragraph (3), conduct investigations into the status and processing system of personal information at any time or receive reports from related parties. <Amended by Act No. 17963, Mar. 14, 2023>

개인정보 보호책임자는 개인정보 보호와 관련하여 이 법 및 다른 관계 법령의 위반 사실을 알게 된 경우에는 즉시 개선조치를 하여야 하며, 필요하면 소속 기관 또는 단체의 장에게 개선조치를 보고하여야 한다. <개정 2023.3.14>

If the personal information protection officer becomes aware of a violation of this Act or other related laws and subordinate statutes concerning personal information protection, they shall take immediate corrective measures and, if necessary, report the corrective measures to the head of their affiliated institution or organization. <Amended by Act No. 17963, Mar. 14, 2023>

개인정보처리자는 개인정보 보호책임자가 제3항 각 호의 업무를 수행함에 있어서 정당한 이유 없이 불이익을 주거나 받게 하여서는 아니 되며, 개인정보 보호책임자가 업무를 독립적으로 수행할 수 있도록 보장하여야 한다. <개정 2023.3.14>

The personal information controller shall not cause or allow disadvantages to the personal information protection officer without just cause in the performance of the tasks referred to in subparagraphs of paragraph (3), and shall guarantee the independent performance of duties by the personal information protection officer. <Amended by Act No. 17963, Mar. 14, 2023>

개인정보처리자는 개인정보의 안전한 처리 및 보호, 정보의 교류, 그 밖에 대통령령으로 정하는 공동의 사업을 수행하기 위하여 제1항에 따른 개인정보 보호책임자를 구성원으로 하는 개인정보 보호책임자 협의회를 구성ㆍ운영할 수 있다. <신설 2023.3.14>

A personal information controller may establish and operate a council of personal information protection officers, comprising personal information protection officers appointed under paragraph (1), to jointly carry out tasks such as the secure processing and protection of personal information, information exchange, and other joint projects prescribed by Presidential Decree. <Newly Inserted by Act No. 17963, Mar. 14, 2023>

보호위원회는 제7항에 따른 개인정보 보호책임자 협의회의 활동에 필요한 지원을 할 수 있다. <신설 2023.3.14>

The Protection Commission may provide necessary support for the activities of the council of personal information protection officers under paragraph (7). <Newly Inserted by Act No. 17963, Mar. 14, 2023>

제1항에 따른 개인정보 보호책임자의 자격요건, 제3항에 따른 업무 및 제6항에 따른 독립성 보장 등에 필요한 사항은 매출액, 개인정보의 보유 규모 등을 고려하여 대통령령으로 정한다. <개정 2023.3.14>

Qualifications for the personal information protection officer under paragraph (1), tasks under paragraph (3), and guarantees of independence under paragraph (6) shall be prescribed by Presidential Decree, taking into account sales, the scale of personal information retention, etc. <Amended by Act No. 17963, Mar. 14, 2023>

Translation

Machine translation. The Korean text is authoritative.

Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.

Personal Information Protection Act 제31조 — Article 31 (Designation of Personal Information Protection Officer, etc.) · Law4Kor