개인정보 보호법
Article 39 (Liability for Damages)
제39조 손해배상책임
- Ministry
- 개인정보보호위원회
- In force
- 2025-10-02
- Articles
- 124
정보주체는 개인정보처리자가 이 법을 위반한 행위로 손해를 입으면 개인정보처리자에게 손해배상을 청구할 수 있다. 이 경우 그 개인정보처리자는 고의 또는 과실이 없음을 입증하지 아니하면 책임을 면할 수 없다.
If a data subject suffers damage due to the act of a personal information processor violating this Act, they may claim compensation for damages from the personal information processor. In this case, the personal information processor shall not be exempt from liability unless they prove that they were not negligent or did not act intentionally.
삭제 <2015.7.24>
Deleted <2015.7.24>
개인정보처리자의 고의 또는 중대한 과실로 인하여 개인정보가 분실ㆍ도난ㆍ유출ㆍ위조ㆍ변조 또는 훼손된 경우로서 정보주체에게 손해가 발생한 때에는 법원은 그 손해액의 5배를 넘지 아니하는 범위에서 손해배상액을 정할 수 있다. 다만, 개인정보처리자가 고의 또는 중대한 과실이 없음을 증명한 경우에는 그러하지 아니하다. <신설 2015.7.24, 2023.3.14>
When personal information is lost, stolen, leaked, falsified, altered, or damaged due to the intentional act or gross negligence of a personal information processor, and damage is caused to the data subject, the court may determine the amount of damages within a range not exceeding five times the amount of damages. However, this shall not apply if the personal information processor proves that they were not negligent or did not act intentionally. <Newly enacted 2015.7.24, Amended 2023.3.14>
법원은 제3항의 배상액을 정할 때에는 다음 각 호의 사항을 고려하여야 한다. <신설 2015.7.24>
1. 고의 또는 손해 발생의 우려를 인식한 정도
2. 위반행위로 인하여 입은 피해 규모
3. 위법행위로 인하여 개인정보처리자가 취득한 경제적 이익
4. 위반행위에 따른 벌금 및 과징금
5. 위반행위의 기간ㆍ횟수 등
6. 개인정보처리자의 재산상태
7. 개인정보처리자가 정보주체의 개인정보 분실ㆍ도난ㆍ유출 후 해당 개인정보를 회수하기 위하여 노력한 정도
8. 개인정보처리자가 정보주체의 피해구제를 위하여 노력한 정도
When determining the amount of damages under paragraph ③, the court shall consider the following factors: <Newly enacted 2015.7.24> 1. The degree of intent or awareness of the risk of damage occurring. 2. The scale of damage incurred due to the violation. 3. The economic benefit obtained by the personal information processor due to the illegal act. 4. Fines and administrative penalties resulting from the violation. 5. The duration and frequency of the violation, etc. 6. The financial status of the personal information processor. 7. The extent of efforts made by the personal information processor to recover the personal information after its loss, theft, or leakage. 8. The extent of efforts made by the personal information processor to remedy the damage to the data subject.
Translation
Machine translation. The Korean text is authoritative.
Statute text is reproduced from 법제처 국가법령정보센터. This is information, not legal advice.