영문/국문 이단 법령보기
정보통신망 이용촉진 및 정보보호 등에 관한 법률 ACT ON PROMOTION OF INFORMATION AND COMMUNICATIONS NETWORK UTILIZATION AND INFORMATION PROTECTION
 전문개정 2001. 1. 16 법률 제 6360 호
개정 2001. 12. 31 법률 제 6585 호
2002. 12. 18 법률 제 6797 호
2004. 1. 29 법률 제 7139 호
2004. 1. 29 법률 제 7142 호
2004. 12. 30 법률 제 7262 호
2005. 12. 29 법률 제 7796 호
2005. 12. 30 법률 제 7812 호
2006. 3. 24 법률 제 7917 호
2006. 10. 4 법률 제 8031 호
2006. 10. 4 법률 제 8030 호
2007. 1. 26 법률 제 8289 호
2007. 5. 25 법률 제 8486 호
2007. 12. 21 법률 제 8778 호
2008. 2. 29 법률 제 8867 호
2008. 2. 29 법률 제 8852 호
2008. 6. 13 법률 제 9119 호
2009. 4. 22 법률 제 9637 호
2010. 3. 17 법률 제 10138 호
2010. 3. 22 법률 제 10165 호
2010. 3. 22 법률 제 10166 호
2011. 3. 29 법률 제 10465 호
2011. 4. 5 법률 제 10560 호
2012. 2. 17 법률 제 11322 호
2013. 3. 23 법률 제 11690 호
2014. 5. 28 법률 제 12681 호
2014. 11. 19 법률 제 12844 호
2015. 1. 20 법률 제 13014 호
2015. 3. 27 법률 제 13280 호
2015. 6. 22 법률 제 13344 호
2015. 6. 22 법률 제 13343 호
2015. 12. 1 법률 제 13520 호
2016. 3. 22 법률 제 14080 호
2017. 3. 14 법률 제 14580 호
2017. 7. 26 법률 제 14839 호
2018. 6. 12 법률 제 15628 호
2018. 9. 18 법률 제 15751 호
2018. 12. 24 법률 제 16019 호
2018. 12. 24 법률 제 16021 호
2019. 12. 10 법률 제 16825 호
2020. 2. 4 법률 제 16955 호
2020. 6. 9 법률 제 17347 호
2020. 6. 9 법률 제 17358 호
2020. 6. 9 법률 제 17348 호
2020. 6. 9 법률 제 17344 호
2020. 6. 9 법률 제 17354 호
2021. 6. 8 법률 제 18201 호
2022. 6. 10 법률 제 18871 호
2024. 1. 23 법률 제 20069 호
2024. 2. 13 법률 제 20260 호
2024. 12. 3 법률 제 20534 호
2025. 1. 21 법률 제 20678 호
2025. 10. 1 법률 제 21066 호
 Wholly Amended by Act No. 6360, Jan. 16, 2001
Amended by Act No. 6585, Dec. 31, 2001
Act No. 6797, Dec. 18, 2002
Act No. 7139, Jan. 29, 2004
Act No. 7142, Jan. 29, 2004
Act No. 7262, Dec. 30, 2004
Act No. 7796, Dec. 29, 2005
Act No. 7812, Dec. 30, 2005
Act No. 7917, Mar. 24, 2006
Act No. 8031, Oct. 4, 2006
Act No. 8030, Oct. 4, 2006
Act No. 8289, Jan. 26, 2007
Act No. 8486, May 25, 2007
Act No. 8778, Dec. 21, 2007
Act No. 8867, Feb. 29, 2008
Act No. 8852, Feb. 29, 2008
Act No. 9119, Jun. 13, 2008
Act No. 9637, Apr. 22, 2009
Act No. 10138, Mar. 17, 2010
Act No. 10165, Mar. 22, 2010
Act No. 10166, Mar. 22, 2010
Act No. 10465, Mar. 29, 2011
Act No. 10560, Apr. 5, 2011
Act No. 11322, Feb. 17, 2012
Act No. 11690, Mar. 23, 2013
Act No. 12681, May 28, 2014
Act No. 12844, Nov. 19, 2014
Act No. 13014, Jan. 20, 2015
Act No. 13280, Mar. 27, 2015
Act No. 13344, Jun. 22, 2015
Act No. 13343, Jun. 22, 2015
Act No. 13520, Dec. 1, 2015
Act No. 14080, Mar. 22, 2016
Act No. 14580, Mar. 14, 2017
Act No. 14839, Jul. 26, 2017
Act No. 15628, Jun. 12, 2018
Act No. 15751, Sep. 18, 2018
Act No. 16019, Dec. 24, 2018
Act No. 16021, Dec. 24, 2018
Act No. 16825, Dec. 10, 2019
Act No. 16955, Feb. 4, 2020
Act No. 17347, Jun. 9, 2020
Act No. 17358, Jun. 9, 2020
Act No. 17348, Jun. 9, 2020
Act No. 17344, Jun. 9, 2020
Act No. 17354, Jun. 9, 2020
Act No. 18201, Jun. 8, 2021
Act No. 18871, Jun. 10, 2022
Act No. 20069, Jan. 23, 2024
Act No. 20260, Feb. 13, 2024
Act No. 20534, Dec. 3, 2024
Act No. 20678, Jan. 21, 2025
Act No. 21066, Oct. 1, 2025
제1장 총칙
CHAPTER I GENERAL PROVISIONS
제1조(목적)
이 법은 정보통신망의 이용을 촉진하고 정보통신서비스를 이용하는 자를 보호함과 아울러 정보통신망을 건전하고 안전하게 이용할 수 있는 환경을 조성하여 국민생활의 향상과 공공복리의 증진에 이바지함을 목적으로 한다. <개정 2020. 2. 4.>
[전문개정 2008. 6. 13.]
Article 1 (Purpose)
The purpose of this Act is to contribute to improving citizens’ lives and enhancing public welfare by facilitating utilization of information and communications networks, protecting people using information and communications services, and developing an environment in which people can utilize information and communications networks in a healthier and safer way. <Amended on Feb. 4, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
제2조(정의)
이 법에서 사용하는 용어의 뜻은 다음과 같다. <개정 2004. 1. 29., 2007. 1. 26., 2007. 12. 21., 2008. 6. 13., 2010. 3. 22., 2014. 5. 28., 2020. 6. 9.>
1. "정보통신망"이란 「전기통신사업법」 제2조제2호에 따른 전기통신설비를 이용하거나 전기통신설비와 컴퓨터 및 컴퓨터의 이용기술을 활용하여 정보를 수집ㆍ가공ㆍ저장ㆍ검색ㆍ송신 또는 수신하는 정보통신체제를 말한다.
2. "정보통신서비스"란 「전기통신사업법」 제2조제6호에 따른 전기통신역무와 이를 이용하여 정보를 제공하거나 정보의 제공을 매개하는 것을 말한다.
3. "정보통신서비스 제공자"란 「전기통신사업법」 제2조제8호에 따른 전기통신사업자와 영리를 목적으로 전기통신사업자의 전기통신역무를 이용하여 정보를 제공하거나 정보의 제공을 매개하는 자를 말한다.
4. "이용자"란 정보통신서비스 제공자가 제공하는 정보통신서비스를 이용하는 자를 말한다.
5. "전자문서"란 컴퓨터 등 정보처리능력을 가진 장치에 의하여 전자적인 형태로 작성되어 송수신되거나 저장된 문서형식의 자료로서 표준화된 것을 말한다.
6. 삭제 <2020. 2. 4.>
7. "침해사고"란 다음 각 목의 방법으로 정보통신망 또는 이와 관련된 정보시스템을 공격하는 행위로 인하여 발생한 사태를 말한다.
가. 해킹, 컴퓨터바이러스, 논리폭탄, 메일폭탄, 서비스거부 또는 고출력 전자기파 등의 방법
나. 정보통신망의 정상적인 보호ㆍ인증 절차를 우회하여 정보통신망에 접근할 수 있도록 하는 프로그램이나 기술적 장치 등을 정보통신망 또는 이와 관련된 정보시스템에 설치하는 방법
8. 삭제 <2015. 6. 22.>
9. "게시판"이란 그 명칭과 관계없이 정보통신망을 이용하여 일반에게 공개할 목적으로 부호ㆍ문자ㆍ음성ㆍ음향ㆍ화상ㆍ동영상 등의 정보를 이용자가 게재할 수 있는 컴퓨터 프로그램이나 기술적 장치를 말한다.
10. "통신과금서비스"란 정보통신서비스로서 다음 각 목의 업무를 말한다.
가. 타인이 판매ㆍ제공하는 재화 또는 용역(이하 "재화등"이라 한다)의 대가를 자신이 제공하는 전기통신역무의 요금과 함께 청구ㆍ징수하는 업무
나. 타인이 판매ㆍ제공하는 재화등의 대가가 가목의 업무를 제공하는 자의 전기통신역무의 요금과 함께 청구ㆍ징수되도록 거래정보를 전자적으로 송수신하는 것 또는 그 대가의 정산을 대행하거나 매개하는 업무
11. "통신과금서비스제공자"란 제53조에 따라 등록을 하고 통신과금서비스를 제공하는 자를 말한다.
12. "통신과금서비스이용자"란 통신과금서비스제공자로부터 통신과금서비스를 이용하여 재화등을 구입ㆍ이용하는 자를 말한다.
13. "전자적 전송매체"란 정보통신망을 통하여 부호ㆍ문자ㆍ음성ㆍ화상 또는 영상 등을 수신자에게 전자문서 등의 전자적 형태로 전송하는 매체를 말한다.
이 법에서 사용하는 용어의 뜻은 제1항에서 정하는 것 외에는 「지능정보화 기본법」에서 정하는 바에 따른다. <개정 2008. 6. 13., 2013. 3. 23., 2020. 6. 9.>
Article 2 (Definitions)
(1) The terms used in this Act are defined as follows: <Amended on Jan. 29, 2004; Jan. 26, 2007; Dec. 21, 2007; Jun. 13, 2008; Mar. 22, 2010; May 28, 2014; Jun. 9, 2020>
1. The term "information and communications network" means an information and communications system for collecting, processing, storing, searching, transmitting, or receiving information by using telecommunications equipment defined in subparagraph 2 of Article 2 of the Telecommunications Business Act or telecommunications equipment, computers and applied computer technology;
2. The term "information and communications services" means telecommunications services defined in subparagraph 6 of Article 2 of the Telecommunications Business Act and services providing information or intermediating the provision of information by using such telecommunications services;
3. The term "provider of information and communications services" means a telecommunications business operator defined in subparagraph 8 of Article 2 of the Telecommunications Business Act and any other person who provides information or intermediates to provide information commercially by utilizing services provided by a telecommunications business operator;
4. The term "user" means a person who uses information and communications services rendered by providers of information and communications services;
5. The term "electronic document" means data prepared and transmitted, received, or stored electronically in a standardized document by a device capable of processing information, such as a computer;
6. Deleted; <Feb. 4, 2020>
7. The term "cyber security incident" means an event resulting from an attack on an information and communications network or an information system related to such network by any of the following:
(a) Means of hacking, computer virus, logic bomb, electronic mail bomb, denial of service, high-power electromagnetic wave, etc.;
(b) Means of installing, in an information and communications network or an information system related thereto, a program, technical device, etc. that enables to circumvent the normal protection and authentication processes of the information and communications network and makes access thereto possible;
8. Deleted; <Jun. 22, 2015>
9. The term "message board" means, regardless of its name, a computer program or a technical device with which users can publish information in the form of a code, letters, voice, sound, image, motion picture, or any other form purposely to disclose the information to the public by using an information and communications network;
10. The term "telecommunications billing services" means information and communications services to perform the following business activities:
(a) Business activities charging and collecting prices for goods or services sold or provided by a third person (hereinafter referred to as "goods or services") together with charges for the telecommunications services provided;
(b) Business activities transmitting and receiving information on transactions electronically so that prices for goods or services sold or provided by a third person can be billed or collected together with charges for the telecommunications services provided by under item (a), or settling, on behalf of another person, or intermediating payments for such prices;
11. The term "provider of telecommunications billing services" means a person who provides telecommunications billing services after being registered under Article 53;
12. The term "user of telecommunications billing services" means a person who purchases or uses goods or services by using telecommunications billing services rendered by a provider of telecommunications billing services;
13. The term "electronic transmission medium" means a medium transmitting codes, letters, voices, images, or motion pictures to addressees in an electronic form, such as an electronic document, via information and communications networks.
(2) Except as provided in paragraph (1), definitions of the terms used in this Act shall be governed by the Framework Act on Intelligent Informatization. <Amended on Jun. 13, 2008; Mar. 23, 2013; Jun. 9, 2020>
제3조(정보통신서비스 제공자 및 이용자의 책무)
정보통신서비스 제공자는 이용자를 보호하고 건전하고 안전한 정보통신서비스를 제공하여 이용자의 권익보호와 정보이용능력의 향상에 이바지하여야 한다. <개정 2020. 2. 4.>
이용자는 건전한 정보사회가 정착되도록 노력하여야 한다.
정부는 정보통신서비스 제공자단체 또는 이용자단체의 정보보호 및 정보통신망에서의 청소년 보호 등을 위한 활동을 지원할 수 있다. <개정 2020. 2. 4.>
[전문개정 2008. 6. 13.]
Article 3 (Responsibilities of providers and users of information and communications services)
(1) Every provider of information and communications services shall contribute to protection of rights and interests of users and enhancement of users’ abilities to use information by protecting users and providing information and communications services in a healthier and safer way. <Amended on Feb. 4, 2020>
(2) Every user shall make efforts to help to establish a healthier information society.
(3) The Government may provide support to organizations composed of providers or users of information and communications services in their activities for protecting information and protecting youths in information and communications networks. <Amended on Feb. 4, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
제4조(정보통신망 이용촉진 및 정보보호등에 관한 시책의 마련)
과학기술정보통신부장관 또는 방송미디어통신위원회는 정보통신망의 이용촉진 및 안정적 관리ㆍ운영과 이용자 보호 등(이하 "정보통신망 이용촉진 및 정보보호등"이라 한다)을 통하여 정보사회의 기반을 조성하기 위한 시책을 마련하여야 한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2020. 2. 4., 2025. 10. 1.>
제1항에 따른 시책에는 다음 각 호의 사항이 포함되어야 한다. <개정 2018. 12. 24., 2020. 6. 9.>
1. 정보통신망에 관련된 기술의 개발ㆍ보급
2. 정보통신망의 표준화
3. 정보내용물 및 제11조에 따른 정보통신망 응용서비스의 개발 등 정보통신망의 이용 활성화
4. 정보통신망을 이용한 정보의 공동활용 촉진
5. 인터넷 이용의 활성화
6. 삭제 <2020. 2. 4.>
6의2. 삭제 <2020. 2. 4.>
7. 정보통신망에서의 청소년 보호
7의2. 정보통신망을 통하여 유통되는 정보 중 인공지능 기술을 이용하여 만든 거짓의 음향ㆍ화상 또는 영상 등의 정보를 식별하는 기술의 개발ㆍ보급
8. 정보통신망의 안전성 및 신뢰성 제고
9. 그 밖에 정보통신망 이용촉진 및 정보보호등을 위하여 필요한 사항
과학기술정보통신부장관 또는 방송미디어통신위원회는 제1항에 따른 시책을 마련할 때에는 「지능정보화 기본법」 제6조에 따른 지능정보사회 종합계획과 연계되도록 하여야 한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2020. 6. 9., 2025. 10. 1.>
[전문개정 2008. 6. 13.]
Article 4 (Formulating policy on promotion of utilization of information and communications networks and protection of information)
(1) The Minister of Science and ICT or the Korea Media and Communications Commission shall formulate policy measures to lay the foundations for an information society through the promotion of utilization of information and communications networks, the stable management and operation of such networks, the protection of users, and other related activities (hereinafter referred to as "promotion of utilization of information and communications networks, the protection of information, and other related matters"). <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(2) The policy measures under paragraph (1) shall contain descriptions of the following: <Amended on Dec. 24, 2018; Jun. 9, 2020>
1. Development and dissemination of technology related to information and communications networks;
2. Standardization of information and communications networks;
3. Promotion of utilization of information and communications networks, including the development of contents of information and applied service for information and communications networks under Article 11;
4. Facilitation of sharing information through information and communications networks;
5. Promotion of use of the Internet;
6. Deleted; <Feb. 4, 2020>
6-2. Deleted; <Feb. 4, 2020>
7. Protection of youths in information and communications networks;
7-2. Development and dissemination of technologies that identify false sounds, visions, pictorial images, etc., made using artificial intelligence technology, among information circulated through information and communications networks;
8. Enhancement of safety and reliability of information and communications networks;
9. Other matters necessary for the promotion of utilization of information and communications networks, the protection of information, and other related matters.
(3) When preparing the policy measures under paragraph (1), the Minister of Science and ICT or the Korea Media and Communications Commission shall ensure that the policy measures are linked to the comprehensive plan for the intelligent information society under Article 6 of the Framework Act on Intelligent Informatization. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020; Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
제4조의2(합성영상등으로 인한 피해 예방을 위한 시책)
과학기술정보통신부장관과 방송미디어통신위원회는 인공지능 기술을 이용하여 사람의 얼굴ㆍ신체 또는 음성을 대상으로 한 촬영물ㆍ영상물 또는 음성물을 대상자의 의사에 반하여 편집ㆍ합성 또는 가공한 정보(이하 이 조에서 "합성영상등"이라 한다)의 무분별한 유통으로 인한 성범죄, 명예훼손 또는 사기 등의 피해를 예방하기 위하여 시책을 마련하여야 한다. <개정 2025. 10. 1.>
제1항에 따른 시책에는 다음 각 호의 사항이 포함되어야 한다.
1. 합성영상등으로 인한 피해 실태 파악
2. 합성영상등의 유통 실태 파악
3. 합성영상등 관련 국내외 기술 동향 파악
4. 합성영상등의 무분별한 유통 방지를 위한 기술 개발의 촉진
5. 합성영상등의 무분별한 유통 방지 및 피해 예방을 위한 교육ㆍ홍보
6. 그 밖에 합성영상등의 무분별한 유통 방지 및 피해 예방에 필요한 사항
[본조신설 2024. 12. 3.]
Article 4-2 (Policy measures to prevent harm caused by synthesized videos, etc.)
(1) The Minister of Science and ICT and the Korea Media and Communications Commission shall establish policy measures to prevent harm, such as sexual crimes, defamation, or fraud, caused by the indiscriminate distribution of information (hereinafter referred to as "synthesized videos, etc." in this Article) that has been edited, synthesized, or processed against the will of a person by using artificial intelligence technology on the person's face, body, or voice in photographs, videos, or audio recordings. <Amended on Oct. 1, 2025>
(2) The policy measures under paragraph (1) shall include the following:
1. Identify the actual state of harm caused by synthesized videos, etc.;
2. Identify the circulation status of synthesized videos, etc.;
3. Identify domestic and international technology trends related to synthesized videos, etc.;
4. Promote technology development to prevent the indiscriminate circulation of synthesized videos, etc.;
5. Education and public relations for preventing the indiscriminate circulation of synthesized videos, etc. and preventing harm;
6. Other matters necessary for preventing the indiscriminate circulation of synthesized videos, etc. and preventing harm;
[This Article Added on Dec. 3, 2024]
제5조(다른 법률과의 관계)
정보통신망 이용촉진 및 정보보호등에 관하여는 다른 법률에서 특별히 규정된 경우 외에는 이 법으로 정하는 바에 따른다. 다만, 제7장의 통신과금서비스에 관하여 이 법과 「전자금융거래법」의 적용이 경합하는 때에는 이 법을 우선 적용한다. <개정 2018. 6. 12., 2020. 2. 4.>
[전문개정 2008. 6. 13.]
Article 5 (Relationship to other statutes)
Except as otherwise provided in any other statute, the promotion of utilization of information and communications networks, the protection of information, and other related matters shall be governed by this Act; provided, in the event of a conflict between this Act and the Electronic Financial Transactions Act with respect to telecommunications billing services under Chapter VII, this Act shall prevail. <Amended on Jun. 12, 2018; Feb. 4, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
제5조의2(국외행위에 대한 적용)
이 법은 국외에서 이루어진 행위라도 국내 시장 또는 이용자에게 영향을 미치는 경우에는 적용한다.
[본조신설 2020. 6. 9.]
Article 5-2 (Application to acts done overseas)
This Act shall apply to any act done overseas if such conduct affects the domestic market or users in the market.
[This Article Added on Jun. 9, 2020]
제2장 정보통신망의 이용촉진
CHAPTER II PROMOTION OF UTILIZATION OF INFORMATION AND COMMUNICATIONS NETWORKS
제6조(기술개발의 추진 등)
과학기술정보통신부장관은 정보통신망과 관련된 기술 및 기기의 개발을 효율적으로 추진하기 위하여 대통령령으로 정하는 바에 따라 관련 연구기관으로 하여금 연구개발ㆍ기술협력ㆍ기술이전 또는 기술지도 등의 사업을 하게 할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
정부는 제1항에 따라 연구개발 등의 사업을 하는 연구기관에는 그 사업에 드는 비용의 전부 또는 일부를 지원할 수 있다.
제2항에 따른 비용의 지급 및 관리 등에 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 6 (Development of technology)
(1) The Minister of Science and ICT may engage the relevant research institute, as prescribed by Presidential Decree, to implement a project for research and development, technical cooperation, transfer of technology, technical guidance, or similar, in order to effectively promote the development of technology and devices related to information and communications networks. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Government may provide financial support to a research institute that implements a project for research and development or similar in accordance with paragraph (1) for all or part of the expenses incurred in conducting such project.
(3) Matters necessary for the disbursement and management of the expenses under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제7조(기술관련 정보의 관리 및 보급)
과학기술정보통신부장관은 정보통신망과 관련된 기술 및 기기에 관한 정보(이하 이 조에서 "기술관련 정보"라 한다)를 체계적이고 종합적으로 관리하여야 한다. <개정 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 기술관련 정보를 체계적이고 종합적으로 관리하기 위하여 필요하면 관계 행정기관 및 국공립 연구기관 등에 대하여 기술관련 정보와 관련된 자료를 요구할 수 있다. 이 경우 요구를 받은 기관의 장은 특별한 사유가 없으면 그 요구에 따라야 한다. <개정 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 기술관련 정보를 신속하고 편리하게 이용할 수 있도록 그 보급을 위한 사업을 하여야 한다. <개정 2013. 3. 23., 2017. 7. 26.>
제3항에 따라 보급하려는 정보통신망과 관련된 기술 및 기기의 범위에 관하여 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 7 (Management and dissemination of technology-related information)
(1) The Minister of Science and ICT shall manage, systematically and comprehensively, the information pertaining to technology and devices related to information and communications networks (hereafter in this Article referred to as "technology-related information"). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) If necessary for managing technology-related information systematically and comprehensively, the Minister of Science and ICT may request data relevant to technology-related information from the relevant administrative agency and a national or public research institute. Upon such request, the head of such agency or institute shall comply therewith, unless there is a special reason not to do so. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) The Minister of Science and ICT shall perform projects for dissemination of technology-related information, so that technology-related information can be used promptly and easily. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(4) Matters necessary for the scope of technology and devices related to information and communications networks which are to be disseminated pursuant to paragraph (3), shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제8조(정보통신망의 표준화 및 인증)
과학기술정보통신부장관은 정보통신망의 이용을 촉진하기 위하여 정보통신망에 관한 표준을 정하여 고시하고, 정보통신서비스 제공자 또는 정보통신망과 관련된 제품을 제조하거나 공급하는 자에게 그 표준을 사용하도록 권고할 수 있다. 다만, 「산업표준화법」 제12조에 따른 한국산업표준이 제정되어 있는 사항에 대하여는 그 표준에 따른다. <개정 2013. 3. 23., 2017. 7. 26.>
제1항에 따라 고시된 표준에 적합한 정보통신과 관련된 제품을 제조하거나 공급하는 자는 제9조제1항에 따른 인증기관의 인증을 받아 그 제품이 표준에 적합한 것임을 나타내는 표시를 할 수 있다.
제1항 단서에 해당하는 경우로서 「산업표준화법」 제15조에 따라 인증을 받은 경우에는 제2항에 따른 인증을 받은 것으로 본다.
제2항에 따른 인증을 받은 자가 아니면 그 제품이 표준에 적합한 것임을 나타내는 표시를 하거나 이와 비슷한 표시를 하여서는 아니 되며, 이와 비슷한 표시를 한 제품을 판매하거나 판매할 목적으로 진열하여서는 아니 된다.
과학기술정보통신부장관은 제4항을 위반하여 제품을 판매하거나 판매할 목적으로 진열한 자에게 그 제품을 수거ㆍ반품하도록 하거나 인증을 받아 그 표시를 하도록 하는 등 필요한 시정조치를 명할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
제1항부터 제3항까지의 규정에 따른 표준화의 대상ㆍ방법ㆍ절차 및 인증표시, 제5항에 따른 수거ㆍ반품ㆍ시정 등에 필요한 사항은 과학기술정보통신부령으로 정한다. <개정 2013. 3. 23., 2017. 7. 26.>
[전문개정 2008. 6. 13.]
Article 8 (Standardization and certification of information and communications networks)
(1) The Minister of Science and ICT shall establish and give public notice of the standards for information and communications networks in order to promote the utilization of information and communications networks, and may recommend providers of information and communications services or persons who manufacture or supply products related to information and communications networks to comply with the standards; provided, the matters for which the Korean Industrial Standards under Article 12 of the Industrial Standardization Act have already been established shall comply with such standards. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) A person who manufactures or supplies a product related to information communications in conformity with the standards publicly notified pursuant to paragraph (1) may put on the product a mark stating that the product conforms to the standards, subject to the prior certification of the certification body under Article 9 (1).
(3) Where a product falls under the proviso of paragraph (1) and the certification under Article 15 of the Industrial Standardization Act has been already given to the product, the product shall be deemed to have been certified pursuant to paragraph (2).
(4) No person other than a person who holds the certification under paragraph (2) may put a mark verifying that his or her product conforms to the standards or put any similar mark, nor may he or she sell a product with any similar mark or display such product for the purpose of sale.
(5) The Minister of Science and ICT may order a person who sells a product or displays such product for the purpose of sale in violation of paragraph (4), to collect and recall the product or to obtain certification to put such mark; or may take any other corrective measure as necessary. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(6) Matters regarding the subject matters of the standardization, the methods and procedures for such standardization, and a mark of certification under paragraphs (1) through (3), and the collection, recall, corrective measures, etc. under paragraph (5) shall be prescribed by Decree of the Ministry of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
제9조(인증기관의 지정 등)
과학기술정보통신부장관은 정보통신망과 관련된 제품을 제조하거나 공급하는 자의 제품이 제8조제1항 본문에 따라 고시된 표준에 적합한 제품임을 인증하는 기관(이하 "인증기관"이라 한다)을 지정할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 인증기관이 다음 각 호의 어느 하나에 해당하면 그 지정을 취소하거나 6개월 이내의 기간을 정하여 업무의 정지를 명할 수 있다. 다만, 제1호에 해당하는 경우에는 그 지정을 취소하여야 한다. <개정 2013. 3. 23., 2017. 7. 26.>
1. 속임수나 그 밖의 부정한 방법으로 지정을 받은 경우
2. 정당한 사유 없이 1년 이상 계속하여 인증업무를 하지 아니한 경우
3. 제3항에 따른 지정기준에 미달한 경우
제1항 및 제2항에 따른 인증기관의 지정기준ㆍ지정절차, 지정취소ㆍ업무정지의 기준 등에 필요한 사항은 과학기술정보통신부령으로 정한다. <개정 2013. 3. 23., 2017. 7. 26.>
[전문개정 2008. 6. 13.]
Article 9 (Designation of certification bodies)
(1) The Minister of Science and ICT may designate an organization to certify that products related to information and communications networks (hereinafter referred to as "certification body"), which are manufactured or supplied by a person, conform to the standards publicly notified pursuant to the main clause of Article 8 (1). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) If a certification body falls under any of the following, the Minister of Science and ICT may revoke the designation of such body or give an order of business suspension for a specified period not exceeding 6 months; provided, the Minister of Science and ICT shall revoke such designation, if it falls under subparagraph 1: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. If the body is designated by fraud or other improper means;
2. If the body has not continued its certification services for at least 1 year without good cause;
3. If the body fails to meet the standards for designation under paragraph (3).
(3) Matters regarding the standards and procedures for designation under paragraph (1), and the criteria for revocation of designation and for business suspension of a certification body under paragraph (2), and other related matters shall be prescribed by Decree of the Ministry of Science and ICT. <Amended on Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
제10조(정보내용물의 개발 지원)
정부는 국가경쟁력을 확보하거나 공익을 증진하기 위하여 정보통신망을 통하여 유통되는 정보내용물을 개발하는 자에게 재정 및 기술 등 필요한 지원을 할 수 있다.
[전문개정 2008. 6. 13.]
Article 10 (Support for development of contents of information)
With an aim of securing national competitiveness and enhancing the public interest, the Government may provide financial and technical support, or otherwise, to persons who develop relevant contents of information that can be distributed through information and communications networks.
[This Article Wholly Amended on Jun. 13, 2008]
제11조(정보통신망 응용서비스의 개발 촉진 등)
정부는 국가기관ㆍ지방자치단체 및 공공기관이 정보통신망을 활용하여 업무를 효율화ㆍ자동화ㆍ고도화하는 응용서비스(이하 "정보통신망 응용서비스"라 한다)를 개발ㆍ운영하는 경우 그 기관에 재정 및 기술 등 필요한 지원을 할 수 있다.
정부는 민간부문에 의한 정보통신망 응용서비스의 개발을 촉진하기 위하여 재정 및 기술 등 필요한 지원을 할 수 있으며, 정보통신망 응용서비스의 개발에 필요한 기술인력을 양성하기 위하여 다음 각 호의 시책을 마련하여야 한다.
1. 각급 학교나 그 밖의 교육기관에서 시행하는 인터넷 교육에 대한 지원
2. 국민에 대한 인터넷 교육의 확대
3. 정보통신망 기술인력 양성사업에 대한 지원
4. 정보통신망 전문기술인력 양성기관의 설립ㆍ지원
5. 정보통신망 이용 교육프로그램의 개발 및 보급 지원
6. 정보통신망 관련 기술자격제도의 정착 및 전문기술인력 수급 지원
7. 그 밖에 정보통신망 관련 기술인력의 양성에 필요한 사항
[전문개정 2008. 6. 13.]
Article 11 (Acceleration of development of applied services for information and communications networks)
(1) The Government may provide financial and technical support or other necessary support to any national agency, local government, or public institution that develops and operates applied services for improving efficiency in processing its business affairs or automatizing or upgrading its business process by utilizing information and communications networks (hereinafter referred to as "applied services for information and communications networks").
(2) The Government may provide financial and technical support or other necessary support to the private sector with an aim of facilitating the development of applied services for information and communications networks by the private sector; and shall prepare the following policy measures for nurturing technical human resources necessary to develop applied services for information and communications networks:
1. Support for Internet education conducted by schools at different levels and other educational institutions;
2. Extension of Internet education for citizens;
3. Support for projects to cultivate technical human resources specializing in information and communications networks;
4. Establishment of and support for institutions to cultivate technical human resources specializing in information and communications networks;
5. Support for development and dissemination of educational programs for utilizing information and communications networks;
6. Support for establishment of the technical qualification system related to information and communications networks and support for supply of technical human resources specializing in information and communications networks on demand;
7. Other matters necessary to cultivate technical human resources related to information and communications networks.
[This Article Wholly Amended on Jun. 13, 2008]
제12조(정보의 공동활용체제 구축)
정부는 정보통신망을 효율적으로 활용하기 위하여 정보통신망 상호 간의 연계 운영 및 표준화 등 정보의 공동활용체제 구축을 권장할 수 있다.
정부는 제1항에 따른 정보의 공동활용체제를 구축하는 자에게 재정 및 기술 등 필요한 지원을 할 수 있다.
제1항과 제2항에 따른 권장 및 지원에 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 12 (Establishment of system for sharing information)
(1) The Government may encourage the development of a system for sharing information through linked operation and standardization of information and communications networks or in any other way so that the networks can be made efficient use of.
(2) The Government may provide financial and technical support or other necessary support to any person who develops a system for sharing information under paragraph (1).
(3) Matters necessary for the encouragement and support under paragraphs (1) and (2) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제13조(정보통신망의 이용촉진 등에 관한 사업)
과학기술정보통신부장관은 공공, 지역, 산업, 생활 및 사회적 복지 등 각 분야의 정보통신망의 이용촉진과 정보격차의 해소를 위하여 관련 기술ㆍ기기 및 응용서비스의 효율적인 활용ㆍ보급을 촉진하기 위한 사업을 대통령령으로 정하는 바에 따라 실시할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
정부는 제1항에 따른 사업에 참여하는 자에게 재정 및 기술 등 필요한 지원을 할 수 있다.
[전문개정 2008. 6. 13.]
Article 13 (Projects for promoting utilization of information and communications networks)
(1) The Minister of Science and ICT may implement projects designed to promote efficient utilization and dissemination of technology, devices, and applied services related to information and communications networks, as prescribed by Presidential Decree, in order to promote the utilization of information and communications networks in various areas of public service, local communities, industry, life, and social welfare and to eliminate gaps in accessibility to information. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Government may provide financial and technical support or other necessary support to persons who participate in the projects under paragraph (1).
[This Article Wholly Amended on Jun. 13, 2008]
제14조(인터넷 이용의 확산)
정부는 인터넷 이용이 확산될 수 있도록 공공 및 민간의 인터넷 이용시설의 효율적 활용을 유도하고 인터넷 관련 교육 및 홍보 등의 인터넷 이용기반을 확충하며, 지역별ㆍ성별ㆍ연령별 인터넷 이용격차를 해소하기 위한 시책을 마련하고 추진하여야 한다.
[전문개정 2008. 6. 13.]
Article 14 (Proliferation of the Internet)
The Government shall formulate and implement policy measures to induce the public and private sectors to use Internet facilities available in the public and private sectors so that the Internet can be widely used; to form the basis for using the Internet through education and public relations activities on the Internet; and to eliminate gaps in accessibility to the Internet between localities, genders, and ages.
[This Article Wholly Amended on Jun. 13, 2008]
제15조(인터넷 서비스의 품질 개선)
과학기술정보통신부장관은 인터넷 서비스 이용자의 권익을 보호하고 인터넷 서비스의 품질 향상 및 안정적 제공을 보장하기 위한 시책을 마련하여야 한다. <개정 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 제1항에 따른 시책을 추진하기 위하여 필요하면 정보통신서비스 제공자단체 및 이용자단체 등의 의견을 들어 인터넷 서비스 품질의 측정ㆍ평가에 관한 기준을 정하여 고시할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
정보통신서비스 제공자는 제2항에 따른 기준에 따라 자율적으로 인터넷 서비스의 품질 현황을 평가하여 그 결과를 이용자에게 알려줄 수 있다.
[전문개정 2008. 6. 13.]
Article 15 (Improvement of quality of internet services)
(1) The Minister of Science and ICT shall formulate and implement policy measures to protect rights and interests of users of Internet services and to ensure improvement of quality of Internet services and stable availability of Internet services. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) If deemed necessary for implementing the policy measures under paragraph (1), the Minister of Science and ICT may prescribe and give public notice of the standards for measuring and assessing the quality of Internet services, hearing opinions of organizations of providers and users of information and communications services and others. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) Every provider of information and communications services may voluntarily assess the current status of quality of his or her own Internet services in accordance with the standards under paragraph (2) and may notify the results thereof to users.
[This Article Wholly Amended on Jun. 13, 2008]
제16조 삭제 <2004. 1. 29.>
Article 16 Deleted. <Jan. 29, 2004>
제17조 삭제 <2004. 1. 29.>
Article 17 Deleted. <Jan. 29, 2004>
제3장 삭제
CHAPTER III Deleted.
제18조 삭제 <2015. 6. 22.>
Article 18 Deleted. <Jun. 22, 2015>
제19조 삭제 <2015. 6. 22.>
Article 19 Deleted. <Jun. 22, 2015>
제20조 삭제 <2015. 6. 22.>
Article 20 Deleted. <Jun. 22, 2015>
제21조 삭제 <2015. 6. 22.>
Article 21 Deleted. <Jun. 22, 2015>
제4장 정보통신서비스의 안전한 이용환경 조성
CHAPTER IV CREATION OF SAFE ENVIRONMENT FOR USE OF INFORMATION AND COMMUNICATIONS SERVICES
제1절 삭제
SECTION 1 Deleted
제22조 삭제 <2020. 2. 4.>
Article 22 Deleted. <Feb. 4, 2020>
제22조의2(접근권한에 대한 동의)
정보통신서비스 제공자는 해당 서비스를 제공하기 위하여 이용자의 이동통신단말장치 내에 저장되어 있는 정보 및 이동통신단말장치에 설치된 기능에 대하여 접근할 수 있는 권한(이하 "접근권한"이라 한다)이 필요한 경우 다음 각 호의 사항을 이용자가 명확하게 인지할 수 있도록 알리고 이용자의 동의를 받아야 한다.
1. 해당 서비스를 제공하기 위하여 반드시 필요한 접근권한인 경우
가. 접근권한이 필요한 정보 및 기능의 항목
나. 접근권한이 필요한 이유
2. 해당 서비스를 제공하기 위하여 반드시 필요한 접근권한이 아닌 경우
가. 접근권한이 필요한 정보 및 기능의 항목
나. 접근권한이 필요한 이유
다. 접근권한 허용에 대하여 동의하지 아니할 수 있다는 사실
정보통신서비스 제공자는 해당 서비스를 제공하기 위하여 반드시 필요하지 아니한 접근권한을 설정하는 데 이용자가 동의하지 아니한다는 이유로 이용자에게 해당 서비스의 제공을 거부하여서는 아니 된다.
이동통신단말장치의 기본 운영체제(이동통신단말장치에서 소프트웨어를 실행할 수 있는 기반 환경을 말한다)를 제작하여 공급하는 자와 이동통신단말장치 제조업자 및 이동통신단말장치의 소프트웨어를 제작하여 공급하는 자는 정보통신서비스 제공자가 이동통신단말장치 내에 저장되어 있는 정보 및 이동통신단말장치에 설치된 기능에 접근하려는 경우 접근권한에 대한 이용자의 동의 및 철회방법을 마련하는 등 이용자 정보 보호에 필요한 조치를 하여야 한다.
방송미디어통신위원회는 해당 서비스의 접근권한의 설정이 제1항부터 제3항까지의 규정에 따라 이루어졌는지 여부에 대하여 실태조사를 실시할 수 있다. <신설 2018. 6. 12., 2025. 10. 1.>
제1항에 따른 접근권한의 범위 및 동의의 방법, 제3항에 따른 이용자 정보 보호를 위하여 필요한 조치 및 그 밖에 필요한 사항은 대통령령으로 정한다. <개정 2018. 6. 12.>
[본조신설 2016. 3. 22.]
Article 22-2 (Consent to access authority)
(1) Where a provider of information and communications services needs authority to access (hereinafter referred to as "access authority") information stored and functions installed in mobile devices of users in order to provide the relevant services, the provider shall inform users of the following so that users may clearly recognize such matters, and shall obtain consent of users:
1. In the case of access authority certainly necessary to provide the relevant services:
(a) Items of the information and functions for which access authority is necessary;
(b) Grounds that access authority is necessary;
2. In the case of access authority not certainly necessary to provide the relevant services:
(a) Items of the information and functions for which access authority is necessary;
(b) Grounds that access authority is necessary;
(c) Fact that users may give no consent to the permission for access authority.
(2) No provider of information and communications services shall refuse to provide the relevant services to users on the ground that the users give no consent to the establishment of access authority not certainly necessary to provide the relevant services.
(3) Persons manufacturing and providing a basic operating system (referring to an operating environment in which software installed in mobile devices can be run) of mobile devices, manufacturers of mobile devices, and persons manufacturing and providing a software for mobile devices shall take measures necessary for protecting user information, such as devising methods for users to give or revoke consent to access authority where the provider of information and communications services intends to access the information stored and functions installed in mobile devices.
(4) The Korea Media and Communications Commission may conduct compliance inspections to ascertain that access authority is set for relevant services in accordance with paragraphs (1) through (3). <Added on Jun. 12, 2018; Oct. 1, 2025>
(5) The scope of, and methods for consenting to, access authority referred to in paragraph (1), the measures necessary for protecting user information referred to in paragraph (3), and other necessary matters shall be prescribed by Presidential Decree. <Amended on Jun. 12, 2018>
[This Article Added on Mar. 22, 2016]
제23조 삭제 <2020. 2. 4.>
Article 23 Deleted. <Feb. 4, 2020>
제23조의2(주민등록번호의 사용 제한)
정보통신서비스 제공자는 다음 각 호의 어느 하나에 해당하는 경우를 제외하고는 이용자의 주민등록번호를 수집ㆍ이용할 수 없다. <개정 2020. 2. 4.>
1. 제23조의3에 따라 본인확인기관으로 지정받은 경우
2. 삭제 <2020. 2. 4.>
3. 「전기통신사업법」 제38조제1항에 따라 기간통신사업자로부터 이동통신서비스 등을 제공받아 재판매하는 전기통신사업자가 제23조의3에 따라 본인확인기관으로 지정받은 이동통신사업자의 본인확인업무 수행과 관련하여 이용자의 주민등록번호를 수집ㆍ이용하는 경우
제1항제3호에 따라 주민등록번호를 수집ㆍ이용할 수 있는 경우에도 이용자의 주민등록번호를 사용하지 아니하고 본인을 확인하는 방법(이하 "대체수단"이라 한다)을 제공하여야 한다. <개정 2020. 2. 4.>
[전문개정 2012. 2. 17.]
Article 23-2 (Restrictions on use of resident registration numbers)
(1) Except in any of the following cases, no provider of information and communications services may collect or use users’ resident registration numbers: <Amended on Feb. 4, 2020>
1. Where the provider is designated as an identity verification agency pursuant to Article 23-3;
2. Deleted; <Feb. 4, 2020>
3. Where a telecommunications business operator, who resells a mobile communications service and the like provided by a facilities-based telecommunications business operator under Article 38 (1) of the Telecommunications Business Act, collects or uses resident registration numbers of users in relation to performing the identity verification service of a mobile telecommunications business operator designated as an identity verification agency under Article 23-3.
(2) Even where the collection and use of users’ resident registration numbers is authorized pursuant to paragraph (1) 3, an identification method without using the users’ resident registration numbers (hereinafter referred to as "alternative means") shall be provided. <Amended on Feb. 4, 2020>
[This Article Wholly Amended on Feb. 17, 2012]
제23조의3(본인확인기관의 지정 등)
방송미디어통신위원회는 다음 각 호의 사항을 심사하여 대체수단의 개발ㆍ제공ㆍ관리 업무(이하 "본인확인업무"라 한다)를 안전하고 신뢰성 있게 수행할 능력이 있다고 인정되는 자를 본인확인기관으로 지정할 수 있다. <개정 2025. 10. 1.>
1. 본인확인업무의 안전성 확보를 위한 물리적ㆍ기술적ㆍ관리적 조치계획
2. 본인확인업무의 수행을 위한 기술적ㆍ재정적 능력
3. 본인확인업무 관련 설비규모의 적정성
본인확인기관이 본인확인업무의 전부 또는 일부를 휴지하고자 하는 때에는 휴지기간을 정하여 휴지하고자 하는 날의 30일 전까지 이를 이용자에게 통보하고 방송미디어통신위원회에 신고하여야 한다. 이 경우 휴지기간은 6개월을 초과할 수 없다. <개정 2025. 10. 1.>
본인확인기관이 본인확인업무를 폐지하고자 하는 때에는 폐지하고자 하는 날의 60일 전까지 이를 이용자에게 통보하고 방송미디어통신위원회에 신고하여야 한다. <개정 2025. 10. 1.>
제1항부터 제3항까지의 규정에 따른 심사사항별 세부 심사기준ㆍ지정절차 및 휴지ㆍ폐지 등에 관하여 필요한 사항은 대통령령으로 정한다.
[본조신설 2011. 4. 5.]
Article 23-3 (Designation of identification service agencies)
(1) The Korea Media and Communications Commission may, after reviewing the following, designate a person as an identity verification agency who is deemed competent to safely and reliably perform the affairs of development, provision, and administration of the alternative means (hereinafter referred to as "identity verification service"): <Amended on Oct. 1, 2025>
1. A plan for physical, technological, and administrative measures in order to secure safety of the identity verification service;
2. Technological and financial capability necessary for performing the identity verification service;
3. Appropriateness of the scale of facilities relevant to the identity verification service.
(2) When an identity verification agency intends to discontinue the identity verification service temporarily, it shall determine and notify a discontinuation period to the users by not later than 30 days prior to the intended date of discontinuation and shall report the same to the Korea Media and Communications Commission. In such cases, the discontinuation period shall not exceed 6 months. <Amended on Oct. 1, 2025>
(3) When an identity verification agency intends to discontinue the identity verification service, it shall notify the intention to the users not later than 60 days prior to the intended date of discontinuation and shall report the same to the Korea Media and Communications Commission. <Amended on Oct. 1, 2025>
(4) Matters necessary for detailed review criteria for each item subject to review, designation procedures, temporary or permanent discontinuation, and other matters under paragraphs (1) through (3) shall be prescribed by Presidential Decree.
[This Article Added on Apr. 5, 2011]
제23조의4(본인확인업무의 정지 및 지정취소)
방송미디어통신위원회는 본인확인기관이 다음 각 호의 어느 하나에 해당하는 때에는 6개월 이내의 기간을 정하여 본인확인업무의 전부 또는 일부의 정지를 명하거나 지정을 취소할 수 있다. 다만, 제1호 또는 제2호에 해당하는 때에는 그 지정을 취소하여야 한다. <개정 2025. 10. 1.>
1. 거짓이나 그 밖의 부정한 방법으로 본인확인기관의 지정을 받은 경우
2. 본인확인업무의 정지명령을 받은 자가 그 명령을 위반하여 업무를 정지하지 아니한 경우
3. 지정받은 날부터 6개월 이내에 본인확인업무를 개시하지 아니하거나 6개월 이상 계속하여 본인확인업무를 휴지한 경우
4. 제23조의3제4항에 따른 지정기준에 적합하지 아니하게 된 경우
제1항에 따른 처분의 기준, 절차 및 그 밖에 필요한 사항은 대통령령으로 정한다.
[본조신설 2011. 4. 5.]
Article 23-4 (Suspension of identity verification services and revocation of designation of identification service agencies)
(1) When an identity verification agency falls under any of the following, the Korea Media and Communications Commission may order full or partial suspension of its identity verification service for a specified period of up to 6 months or revoke the designation of the identity verification agency; provided, in cases falling under subparagraph 1 or 2, the Korea Media and Communications Commission shall revoke the designation of the identity verification agency: <Amended on Oct. 1, 2025>
1. Where the identity verification agency is designated by fraud or other improper means;
2. Where a person who has received an order to suspend the identity verification service fails to suspend such service in violation of the order;
3. Where a person fails to start the identity verification service within 6 months from the date of designation, or has temporarily discontinued the service for at least 6 consecutive months;
4. Where the identification service agency no longer meets the standards for designation pursuant to Article 23-3 (4).
(2) Standards and procedures for disposition granted under paragraph (1) and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Apr. 5, 2011]
제23조의5(연계정보의 생성ㆍ처리 등)
본인확인기관은 다음 각 호의 어느 하나에 해당하는 경우를 제외하고는 정보통신서비스 제공자의 서비스 연계를 위하여 이용자의 주민등록번호를 비가역적으로 암호화한 정보(이하 "연계정보"라 한다)를 생성 또는 제공ㆍ이용ㆍ대조ㆍ연계 등 그 밖에 이와 유사한 행위(이하 "처리"라 한다)를 할 수 없다. <개정 2025. 10. 1.>
1. 이용자가 입력한 정보를 이용하여 이용자를 안전하게 식별ㆍ인증하기 위한 서비스를 제공하는 경우
2. 「개인정보 보호법」 제24조에 따른 고유식별정보(이하 이 조에서 "고유식별정보"라 한다)를 보유한 행정기관 및 공공기관(이하 "행정기관등"이라 한다)이 연계정보를 활용하여 「전자정부법」 제2조제5호에 따른 전자정부서비스를 제공하기 위한 경우로서 다음 각 목의 어느 하나에 해당하는 경우
가. 「전자정부법」 제2조제4호에 따른 중앙사무관장기관의 장이 행정기관등의 이용자 식별을 통합적으로 지원하기 위하여 연계정보 생성ㆍ처리를 요청한 경우
나. 행정기관등이 고유식별정보 처리 목적 범위에서 불가피하게 이용자의 동의를 받지 아니하고 연계정보 생성ㆍ처리를 요청한 경우
3. 고유식별정보를 보유한 자가 「개인정보 보호법」 제35조의2에 따른 개인정보 전송의무를 수행하기 위하여 개인정보 전송을 요구한 정보주체의 연계정보 생성ㆍ처리를 요청한 경우
4. 「개인정보 보호법」 제24조의2제1항 각 호에 따라 주민등록번호 처리가 허용된 경우로서 이용자의 동의를 받지 아니하고 연계정보 생성ㆍ처리가 불가피한 대통령령으로 정하는 정보통신서비스를 제공하기 위하여 본인확인기관과 해당 정보통신서비스 제공자가 함께 방송미디어통신위원회의 승인을 받은 경우
방송미디어통신위원회는 제1항제4호에 따라 연계정보의 생성ㆍ처리를 승인하려는 경우 다음 각 호의 사항을 종합적으로 심사하여야 한다. <개정 2025. 10. 1.>
1. 제공 서비스 구현의 적절성 및 혁신성
2. 연계정보 생성ㆍ처리 절차의 적절성
3. 연계정보 생성ㆍ처리의 안전성 확보를 위한 물리적ㆍ기술적ㆍ관리적 조치 계획
4. 이용자 권리 보호 방안의 적절성
5. 관련 시장과 이용자 편익에 미치는 영향 및 효과
방송미디어통신위원회는 다음 각 호의 어느 하나에 해당하는 경우에 제1항제4호에 따른 연계정보 생성ㆍ처리 승인을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 그 승인을 취소하여야 한다. <개정 2025. 10. 1.>
1. 거짓이나 그 밖의 부정한 방법으로 제1항제4호에 따른 연계정보 생성ㆍ처리 승인을 받은 경우
2. 제2항 각 호에 따른 심사사항에 부적합하게 된 경우
3. 제23조의6제1항에 따른 물리적ㆍ기술적ㆍ관리적 조치 의무를 위반한 경우
4. 개인정보 보호 관련 법령을 위반하고 그 위반사유가 중대한 경우
제1항 각 호에 따른 서비스를 위하여 본인확인기관으로부터 연계정보를 제공받은 자(이하 "연계정보 이용기관"이라 한다)는 제공받은 목적 범위에서 연계정보를 처리할 수 있다. 다만, 정보주체에게 별도로 동의받은 경우에는 동의받은 목적 범위에서 연계정보를 처리할 수 있다.
제1항부터 제4항까지에 따른 연계정보 생성ㆍ처리 승인 절차, 승인 심사사항별 세부심사기준, 승인취소 처분의 기준 등에 관하여 필요한 사항은 대통령령으로 정한다.
[본조신설 2024. 1. 23.]
Article 23-5 (Creation and processing of connecting information)
(1) An identity verification agency shall not create, provide, use, compare, link irreversibly encrypted form of any user's resident registration number (hereinafter referred to as "connecting information") or perform other similar acts (hereinafter referred to as "processing") for the purpose of interlinking the services of a provider of information and communication services, except in cases falling under any of the following subparagraphs: <Amended on Oct. 1, 2025>
1. Where providing services to safely identify and authenticate users using information entered by the users;
2. Where administrative agencies and public institutions (hereinafter referred to as "administrative agencies, etc.") holding uniquely identifiable information under Article 24 of the Personal Information Protection Act (hereinafter in this Article referred to as "uniquely identifiable information") utilize connecting information to provide electronic government service defined in subparagraph 5 of Article 2 of the Electronic Government Act, in any of the following cases:
(a) Where the head of a central agency responsible for administrative affairs under subparagraph 4 of Article 2 of the Electronic Government Act requests for the creation and processing of connecting information in order to provide integral support to administrative agencies, etc. for the identification of users;
(b) Where an administrative agency, etc. inevitably requests the creation and processing of connecting information without obtaining the user's consent within the scope of the purpose of processing uniquely identifiable information;
3. Where a person holding uniquely identifiable information requests the creation and processing of connecting information of a data subject who has requested the transmission of personal information in order to fulfill the obligation to transmit personal information pursuant to Article 35-2 of the Personal Information Protection Act;
4. Where the processing of resident registration numbers is permitted under the subparagraphs of Article 24-2 (1) of the Personal Information Protection Act, and the identity verification agency and the relevant provider of information and communications services together have obtained approval from the Korea Media and Communications Commission for providing information and communication services prescribed by the Presidential Decree for which it is inevitable to create and process connecting information without obtaining the consent of the user.
(2) Where the Korea Media and Communications Commission intends to approve the creation and processing of connecting information under paragraph (1) 4, the Commission shall comprehensively examine the following matters: <Amended on Oct. 1, 2025>
1. Appropriateness and innovativeness of the realization of services to be provided:
2. Adequacy of procedures for creating and processing connecting information;
3. Plans for physical, technical, and administrative measures to ensure safety in creating and processing connecting information;
4. Adequacy of measures to protect the rights of users:
5. Impacts and effects on relevant markets and user benefits:
(3) The Korea Media and Communications Commission may revoke approval for the creation and processing of connecting information under paragraph (1) 4 in any of the following; provided, in the case of subparagraph 1, the approval shall be revoked: <Amended on Oct. 1, 2025>
1. Where they have obtained approval for the creation and processing of connecting information under paragraph (1) 4 by fraud or in any other improper means;
2. Where they fail to comply with the matters examined under each subparagraph of paragraph (2);
3. Where they violate the obligation to take physical, technical, or administrative measures under Article 23-6 (1);
4. Where they violate a statute or regulation related to the protection of personal information and the reason for such violation is material.
(4) A person who is provided with connecting information from an identity verification agency (hereinafter referred to as a "entity using connecting information") for the services under the subparagraphs of paragraph (1) may process the connecting information within the scope of purposes for which the person has been provided; provided, if the data subject separately consents, the connecting information may be processed within the scope of the consented purpose.
(5) Matters necessary for approval procedures for creating and processing connecting information under paragraphs (1) through (4), detailed examination criteria for each approval, criteria for revoking approval, and other matters shall be prescribed by Presidential Decree.
[This Article Added on Jan. 23, 2024]
제23조의6(연계정보의 안전조치 의무 등)
본인확인기관이 연계정보를 생성ㆍ처리하는 경우 「개인정보 보호법」 제29조에 따른 조치 외에 연계정보 생성ㆍ처리의 안전성 확보를 위한 물리적ㆍ기술적ㆍ관리적 조치를 하여야 한다.
연계정보 이용기관은 제23조의5제1항 각 호에 따른 서비스를 제공하는 경우 「개인정보 보호법」 제29조에 따른 조치 외에 연계정보를 주민등록번호와 분리하여 보관ㆍ관리하고 연계정보가 분실ㆍ도난ㆍ유출ㆍ위조ㆍ변조 또는 훼손되지 아니하도록 조치(이하 "안전조치"라 한다)하여야 한다.
방송미디어통신위원회는 생성ㆍ처리하는 연계정보의 규모, 매출액 등이 대통령령으로 정하는 기준에 해당하는 본인확인기관의 물리적ㆍ기술적ㆍ관리적 조치 및 연계정보 이용기관의 안전조치에 대한 운영ㆍ관리 실태를 점검할 수 있다. <개정 2025. 10. 1.>
방송미디어통신위원회는 제3항에 따른 점검에 관한 업무를 대통령령으로 정하는 전문기관에 위탁할 수 있다. <개정 2025. 10. 1.>
제1항에 따른 물리적ㆍ기술적ㆍ관리적 조치와 제2항에 따른 안전조치에 관하여 필요한 사항은 대통령령으로 정한다.
[본조신설 2024. 1. 23.]
Article 23-6 (Obligation to take safety measures for connecting information)
(1) Where an identity verification agency creates and processes connecting information, it shall take physical, technical and administrative measures to ensure safety for creating and processing the connecting information in addition to the measures under Article 29 of the Personal Information Protection Act.
(2) Where an entity using connecting information provides services under the subparagraphs of Article 23-5 (1), in addition to measures pursuant to Article 29 of the Personal Information Protection Act, the entity shall store and manage the connecting information separately from resident registration numbers and take measures to ensure that the connecting information is not lost, stolen, leaked, falsified, altered, or damaged (hereinafter referred to as "safety measures").
(3) The Korea Media and Communications Commission may inspect the operation and management of physical, technical and administrative measures taken by an identity verification agency that meets the standards prescribed by the Presidential Decree, including the scale and turnover of connecting information created and processed, and safety measures taken by the entity using the connecting information. <Amended on Oct. 1, 2025>
(4) The Korea Media and Communications Commission may entrust the affairs regarding inspection under paragraph (3) to a specialized organization prescribed by Presidential Decree. <Amended on Oct. 1, 2025>
(5) Matters necessary for the physical, technical and administrative measures under paragraph (1) and the safety measures under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Added on Jan. 23, 2024]
제24조 삭제 <2020. 2. 4.>
Article 24 Deleted. <Feb. 4, 2020>
제24조의2 삭제 <2020. 2. 4.>
Article 24-2 Deleted. <Feb. 4, 2020>
제25조 삭제 <2020. 2. 4.>
Article 25 Deleted. <Feb. 4, 2020>
제26조 삭제 <2020. 2. 4.>
Article 26 Deleted. <Feb. 4, 2020>
제26조의2 삭제 <2020. 2. 4.>
Article 26-2 Deleted. <Feb. 4, 2020>
제2절 삭제
SECTION 2 Deleted
제27조 삭제 <2020. 2. 4.>
Article 27 Deleted. <Feb. 4, 2020>
제27조의2 삭제 <2020. 2. 4.>
Article 27-2 Deleted. <Feb. 4, 2020>
제27조의3 삭제 <2020. 2. 4.>
Article 27-3 Deleted. <Feb. 4, 2020>
제28조 삭제 <2020. 2. 4.>
Article 28 Deleted. <Feb. 4, 2020>
제28조의2 삭제 <2020. 2. 4.>
Article 28-2 Deleted. <Feb. 4, 2020>
제29조 삭제 <2020. 2. 4.>
Article 29 Deleted. <Feb. 4, 2020>
제29조의2 삭제 <2020. 2. 4.>
Article 29-2 Deleted. <Feb. 4, 2020>
제3절 삭제
SECTION 3 Deleted
제30조 삭제 <2020. 2. 4.>
Article 30 Deleted. <Feb. 4, 2020>
제30조의2 삭제 <2020. 2. 4.>
Article 30-2 Deleted. <Feb. 4, 2020>
제31조 삭제 <2020. 2. 4.>
Article 31 Deleted. <Feb. 4, 2020>
제32조 삭제 <2020. 2. 4.>
Article 32 Deleted. <Feb. 4, 2020>
제32조의2 삭제 <2020. 2. 4.>
Article 32-2 Deleted. <Feb. 4, 2020>
제32조의3 삭제 <2020. 2. 4.>
Article 32-3 Deleted. <Feb. 4, 2020>
제32조의4 삭제 <2020. 2. 4.>
Article 32-4 Deleted. <Feb. 4, 2020>
제32조의5(국내대리인의 지정)
국내에 주소 또는 영업소가 없는 정보통신서비스 제공자등으로서 이용자 수, 매출액 등을 고려하여 대통령령으로 정하는 기준에 해당하는 자는 다음 각 호의 사항을 대리하는 자(이하 "국내대리인"이라 한다)를 서면으로 지정하여야 한다.
1. 삭제 <2020. 2. 4.>
2. 삭제 <2020. 2. 4.>
3. 제64조제1항에 따른 관계 물품ㆍ서류 등의 제출
국내대리인은 국내에 주소 또는 영업소가 있는 자로 한다.
제1항에 따라 국내대리인을 지정한 때에는 다음 각 호의 사항 모두를 인터넷 사이트 등에 공개하여야 한다. <개정 2020. 2. 4.>
1. 국내대리인의 성명(법인의 경우에는 그 명칭 및 대표자의 성명을 말한다)
2. 국내대리인의 주소(법인의 경우에는 영업소 소재지를 말한다), 전화번호 및 전자우편 주소
국내대리인이 제1항 각 호와 관련하여 이 법을 위반한 경우에는 정보통신서비스 제공자등이 그 행위를 한 것으로 본다.
[본조신설 2018. 9. 18.]
Article 32-5 (Designation of domestic agents)
(1) A person who meets the criteria prescribed by Presidential Decree, based upon considerations such as the number of users and sales, from among providers of information and communications services or similar with no domicile or place of business in the Republic of Korea, shall designate, in writing, an agent to act on his or her behalf with respect to the following (hereinafter referred to as "domestic agent"):
1. Deleted; <Feb. 4, 2020>
2. Deleted; <Feb. 4, 2020>
3. Submission of related articles, documents, etc. under Article 64 (1).
(2) A domestic agent shall be a person who has a domicile or place of business in the Republic of Korea.
(3) In designating a domestic agent pursuant to paragraph (1), all the following matters shall be disclosed on its website and the like: <Amended on Feb. 4, 2020>
1. The domestic agent's name (if the domestic agent is a corporation, referring to the name of the corporation and the name of its representative);
2. The domestic agent's domicile (if the domestic agent is a corporation, referring to the address of its place of business), and his or her telephone number and electronic mail address.
(4) If a domestic agent violates this Act in relation to the subparagraphs of paragraph (1), such violation shall be deemed to have been committed by the relevant provider of information and communications services or similar.
[This Article Added on Sep. 18, 2018]
제4절 삭제
SECTION 4 Deleted
제33조 삭제 <2011. 3. 29.>
Article 33 Deleted. <Mar. 29, 2011>
제33조의2 삭제 <2011. 3. 29.>
Article 33-2 Deleted. <Mar. 29, 2011>
제34조 삭제 <2011. 3. 29.>
Article 34 Deleted. <Mar. 29, 2011>
제35조 삭제 <2011. 3. 29.>
Article 35 Deleted. <Mar. 29, 2011>
제36조 삭제 <2011. 3. 29.>
Article 36 Deleted. <Mar. 29, 2011>
제37조 삭제 <2011. 3. 29.>
Article 37 Deleted. <Mar. 29, 2011>
제38조 삭제 <2011. 3. 29.>
Article 38 Deleted. <Mar. 29, 2011>
제39조 삭제 <2011. 3. 29.>
Article 39 Deleted. <Mar. 29, 2011>
제40조 삭제 <2011. 3. 29.>
Article 40 Deleted. <Mar. 29, 2011>
제5장 정보통신망에서의 이용자 보호 등
CHAPTER V PROTECTION OF USERS IN INFORMATION AND COMMUNICATIONS NETWORKS
제41조(청소년 보호를 위한 시책의 마련 등)
방송미디어통신위원회는 정보통신망을 통하여 유통되는 음란ㆍ폭력정보 등 청소년에게 해로운 정보(이하 "청소년유해정보"라 한다)로부터 청소년을 보호하기 위하여 다음 각 호의 시책을 마련하여야 한다. <개정 2025. 10. 1.>
1. 내용 선별 소프트웨어의 개발 및 보급
2. 청소년 보호를 위한 기술의 개발 및 보급
3. 청소년 보호를 위한 교육 및 홍보
4. 그 밖에 청소년 보호를 위하여 대통령령으로 정하는 사항
방송미디어통신위원회는 제1항에 따른 시책을 추진할 때에는 「방송미디어통신위원회의 설치 및 운영에 관한 법률」제18조에 따른 방송미디어통신심의위원회(이하 "심의위원회"라 한다), 정보통신서비스 제공자단체ㆍ이용자단체, 그 밖의 관련 전문기관이 실시하는 청소년 보호를 위한 활동을 지원할 수 있다. <개정 2025. 10. 1.>
[전문개정 2008. 6. 13.]
Article 41 (Preparation of policy on protection of youths)
(1) The Korea Media and Communications Commission shall prepare a policy on the following measures to protect youths from information harmful to youth, such as information of obscenities and violence, circulated through information and communications networks (hereinafter referred to as "information harmful to youth"): <Amended on Oct. 1, 2025>
1. Development and dissemination of content-screening software;
2. Development and dissemination of technology for protection of youths;
3. Education and public relations activities for protection of youths;
4. Other matters prescribed by Presidential Decree for protection of youths.
(2) The Korea Media and Communications Commission may, in an effort to implement the policy under paragraph (1), support activities conducted by the Korea Communications Standards Commission under Article 18 of the Act on the Establishment and Operation of Korea Media and Communications Commission (hereinafter referred to as the "Communications Standards Commission"), organizations of providers or users of information and communications services, and other relevant specialized institutions for protection of youths. <Amended on Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
제42조(청소년유해매체물의 표시)
전기통신사업자의 전기통신역무를 이용하여 일반에게 공개를 목적으로 정보를 제공하는 자(이하 "정보제공자"라 한다) 중 「청소년 보호법」 제2조제2호마목에 따른 매체물로서 같은 법 제2조제3호에 따른 청소년유해매체물을 제공하려는 자는 대통령령으로 정하는 표시방법에 따라 그 정보가 청소년유해매체물임을 표시하여야 한다. <개정 2011. 9. 15.>
[전문개정 2008. 6. 13.]
Article 42 (Labeling of media products harmful to youths)
A person who provides information to the general public purposely to make it public through telecommunications services rendered by a telecommunications business operator (hereinafter referred to as "information provider") and who intends to provide any media product harmful to youths defined in subparagraph 3 of Article 2 of the Youth Protection Act among the media products referred to in subparagraph 2 (e) of Article 2 of that Act, shall put a label indicating that the information is a media product harmful to youths by the labeling method prescribed by Presidential Decree. <Amended on Sep. 15, 2011>
[This Article Wholly Amended on Jun. 13, 2008]
제42조의2(청소년유해매체물의 광고금지)
누구든지 「청소년 보호법」 제2조제2호마목에 따른 매체물로서 같은 법 제2조제3호에 따른 청소년유해매체물을 광고하는 내용의 정보를 정보통신망을 이용하여 부호ㆍ문자ㆍ음성ㆍ음향ㆍ화상 또는 영상 등의 형태로 같은 법 제2조제1호에 따른 청소년에게 전송하거나 청소년 접근을 제한하는 조치 없이 공개적으로 전시하여서는 아니 된다. <개정 2011. 9. 15.>
[전문개정 2008. 6. 13.]
Article 42-2 (Prohibition on advertisement of media products harmful to youths)
No one may transmit, to a youth defined in subparagraph 1 of Article 2 of the Youth Protection Act, any information containing an advertisement of a media product harmful to youths defined in subparagraph 3 of Article 2 of that Act among the media products referred to in subparagraph 2 (e) of Article 2 of that Act in the form of code, letter, voice, sound, image, or motion picture through an information and communications network or display such information to the general public without taking any measure to restrict access by a youth. <Amended on Sep. 15, 2011>
[This Article Wholly Amended on Jun. 13, 2008]
제42조의3(청소년 보호 책임자의 지정 등)
정보통신서비스 제공자 중 일일 평균 이용자의 수, 매출액 등이 대통령령으로 정하는 기준에 해당하는 자는 정보통신망의 청소년유해정보로부터 청소년을 보호하기 위하여 청소년 보호 책임자를 지정하여야 한다.
청소년 보호 책임자는 해당 사업자의 임원 또는 청소년 보호와 관련된 업무를 담당하는 부서의 장에 해당하는 지위에 있는 자 중에서 지정한다.
청소년 보호 책임자는 정보통신망의 청소년유해정보를 차단ㆍ관리하고, 청소년유해정보로부터의 청소년 보호계획을 수립하는 등 청소년 보호업무를 하여야 한다.
제1항에 따른 청소년 보호 책임자의 지정에 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 42-3 (Designation of persons responsible for protection of youths)
(1) A provider of information and communications services who meets the criteria prescribed by Presidential Decree, such as the average number of daily users and sales, shall designate a person responsible for protection of youths to keep youths from information harmful to youths in the information and communication network.
(2) The person responsible for protection of youths shall be chosen from among executive officers of the relevant business operator or the persons in a position equivalent to the head of a department responsible for business affairs related to protection of youths.
(3) The person responsible for protection of youths shall block and control information harmful to youths in the information and communications network and shall perform business affairs for protection of youths, including establishment of a plan for protection of youths from information harmful to youths.
(4) Matters necessary for designating a person responsible for protection of youths under paragraph (1) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제43조(영상 또는 음향정보 제공사업자의 보관의무)
「청소년 보호법」 제2조제2호마목에 따른 매체물로서 같은 법 제2조제3호에 따른 청소년유해매체물을 이용자의 컴퓨터에 저장 또는 기록되지 아니하는 방식으로 제공하는 것을 영업으로 하는 정보제공자 중 대통령령으로 정하는 자는 해당 정보를 보관하여야 한다. <개정 2011. 9. 15.>
제1항에 따른 정보제공자가 해당 정보를 보관하여야 할 기간은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 43 (Duty of providers of visual or sound Information to keep information)
(1) An information provider prescribed by Presidential Decree from among those who engage in business providing media products harmful to youths defined in subparagraph 3 of Article 2 of the Youth Protection Act among the media products referred to in subparagraph 2 (e) of Article 2 of that Act in a way to make it impossible to save or record the harmful media products in a user's computer shall keep relevant information. <Amended on Sep. 15, 2011>
(2) The period during which an information provider under paragraph (1) is obligated to keep relevant information shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제44조(정보통신망에서의 권리보호)
이용자는 사생활 침해 또는 명예훼손 등 타인의 권리를 침해하는 정보를 정보통신망에 유통시켜서는 아니 된다.
정보통신서비스 제공자는 자신이 운영ㆍ관리하는 정보통신망에 제1항에 따른 정보가 유통되지 아니하도록 노력하여야 한다.
방송미디어통신위원회는 정보통신망에 유통되는 정보로 인한 사생활 침해 또는 명예훼손 등 타인에 대한 권리침해를 방지하기 위하여 기술개발ㆍ교육ㆍ홍보 등에 대한 시책을 마련하고 이를 정보통신서비스 제공자에게 권고할 수 있다. <개정 2013. 3. 23., 2014. 5. 28., 2025. 10. 1.>
[전문개정 2008. 6. 13.]
Article 44 (Protection of rights in information and communications networks)
(1) No user may circulate any information in violation of other person's rights, including invasion of privacy and defamation, through an information and communications network.
(2) Every provider of information and communications services shall make efforts to prevent any information under paragraph (1) from being circulated through the information and communications network operated and managed by the provider.
(3) The Korea Media and Communications Commission may prepare policy measures on technological development, education, public relations activities, and other activities to prevent violation of other persons' rights by information circulated through information and communications networks, including invasion of privacy and defamation and may recommend providers of information and communications services to adopt the policy measures. <Amended on Mar. 23, 2013; May 28, 2014; Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
제44조의2(정보의 삭제요청 등)
정보통신망을 통하여 일반에게 공개를 목적으로 제공된 정보로 사생활 침해나 명예훼손 등 타인의 권리가 침해된 경우 그 침해를 받은 자는 해당 정보를 처리한 정보통신서비스 제공자에게 침해사실을 소명하여 그 정보의 삭제 또는 반박내용의 게재(이하 "삭제등"이라 한다)를 요청할 수 있다. 이 경우 삭제등을 요청하는 자(이하 이 조에서 "신청인"이라 한다)는 문자메시지, 전자우편 등 그 처리 경과 및 결과를 통지받을 수단을 지정할 수 있으며, 해당 정보를 게재한 자(이하 이 조에서 "정보게재자"라 한다)는 문자메시지, 전자우편 등 제2항에 따른 조치 사실을 통지받을 수단을 미리 지정할 수 있다. <개정 2016. 3. 22., 2023. 1. 3.>
정보통신서비스 제공자는 제1항에 따른 해당 정보의 삭제등을 요청받으면 지체 없이 삭제ㆍ임시조치 등의 필요한 조치를 하고 즉시 신청인 및 정보게재자에게 알려야 한다. 이 경우 정보통신서비스 제공자는 필요한 조치를 한 사실을 해당 게시판에 공시하는 등의 방법으로 이용자가 알 수 있도록 하여야 한다.
정보통신서비스 제공자는 자신이 운영ㆍ관리하는 정보통신망에 제42조에 따른 표시방법을 지키지 아니하는 청소년유해매체물이 게재되어 있거나 제42조의2에 따른 청소년 접근을 제한하는 조치 없이 청소년유해매체물을 광고하는 내용이 전시되어 있는 경우에는 지체 없이 그 내용을 삭제하여야 한다.
정보통신서비스 제공자는 제1항에 따른 정보의 삭제요청에도 불구하고 권리의 침해 여부를 판단하기 어렵거나 이해당사자 간에 다툼이 예상되는 경우에는 해당 정보에 대한 접근을 임시적으로 차단하는 조치(이하 "임시조치"라 한다)를 할 수 있다. 이 경우 임시조치의 기간은 30일 이내로 한다.
정보통신서비스 제공자는 필요한 조치에 관한 내용ㆍ절차 등을 미리 약관에 구체적으로 밝혀야 한다.
정보통신서비스 제공자는 자신이 운영ㆍ관리하는 정보통신망에 유통되는 정보에 대하여 제2항에 따른 필요한 조치를 하면 이로 인한 배상책임을 줄이거나 면제받을 수 있다.
[전문개정 2008. 6. 13.]
Article 44-2 (Request for deletion of information)
(1) Where information provided through an information and communications network purposely to be made public intrudes on other persons' privacy, defames other persons, or violates other persons' right otherwise, the victim of such violation may request the provider of information and communications services who managed the information to delete the information or publish a rebuttable statement (hereinafter referred to as "deletion or rebuttal"), presenting explanatory materials supporting the alleged violation. In such cases, a person who requesting deletion or rebuttal (hereafter in this Article referred to as "applicant") may designate a means to be notified of the progress and results of such processing, such as a text message or e-mail, and a person who has posted the relevant information (hereafter in this Article referred to as "person who posted information") may designate in advance the means to be notified of the fact of taking measures under paragraph (2), such as text messages or e-mails. <Amended on Mar. 22, 2016; Jan. 3, 2023>
(2) Upon receipt of a request for deletion or rebuttal of the information under paragraph (1), a provider of information and communications services shall delete the information or take a temporary or any other necessary measure and shall notify the applicant and the publisher of the information without delay. In such cases, the provider of information and communications services shall make it known to users that he or she has taken necessary measures by posting a public notification on the relevant message board or in any other way.
(3) If there is any media product harmful to youths published in violation of the labeling method under Article 42 in the information and communications network operated and managed by a provider of information and communications services or if a content advertising any media product harmful to youths is displayed in such network without any measures to restrict access by youths under Article 42-2, the provider shall delete such content without delay.
(4) Notwithstanding a request for deletion of the information under paragraph (1), if it is impracticable to judge whether information violates any right or it is anticipated that there will probably be a dispute between interested parties, a provider of information and communications services may take a measure to block access to the information temporarily (hereinafter referred to as "temporary measures"). In such cases, the period for the temporary measure shall not exceed 30 days.
(5) Every provider of information and communications services shall clearly state in advance the details, procedures, and other matters regarding necessary measures in the terms and conditions.
(6) If a provider of information and communications services takes necessary measures under paragraph (2) for the information circulated through the information and communications network operated and managed by himself or herself, the provider may have his or her liability to indemnify loss incurred by such information mitigated or discharged.
[This Article Wholly Amended on Jun. 13, 2008]
제44조의3(임의의 임시조치)
정보통신서비스 제공자는 자신이 운영ㆍ관리하는 정보통신망에 유통되는 정보가 사생활 침해 또는 명예훼손 등 타인의 권리를 침해한다고 인정되면 임의로 임시조치를 할 수 있다.
제1항에 따른 임시조치에 관하여는 제44조의2제2항 후단, 제4항 후단 및 제5항을 준용한다.
[전문개정 2008. 6. 13.]
Article 44-3 (Discretionary temporary measures)
(1) If a provider of information and communications services finds that information circulated through the information and communications network which he or she operates and manages, intrudes on someone's privacy, defames someone, or violates someone's rights, the provider may take temporary measures at his or her discretion.
(2) The latter part of Article 44-2 (2), the latter part of Article 44-2 (4), and Article 44-2 (5) shall apply mutatis mutandis to the temporary measures under paragraph (1).
[This Article Wholly Amended on Jun. 13, 2008]
제44조의4(자율규제)
정보통신서비스 제공자단체는 이용자를 보호하고 안전하며 신뢰할 수 있는 정보통신서비스를 제공하기 위하여 정보통신서비스 제공자 행동강령을 정하여 시행할 수 있다. <개정 2018. 12. 24.>
정보통신서비스 제공자단체는 다음 각 호의 어느 하나에 해당하는 정보가 정보통신망에 유통되지 아니하도록 모니터링 등 자율규제 가이드라인을 정하여 시행할 수 있다. <신설 2018. 12. 24.>
1. 청소년유해정보
2. 제44조의7에 따른 불법정보
정부는 제2항 각 호의 어느 하나에 해당하는 정보의 효과적인 유통 방지를 위하여 필요한 경우 정보통신서비스 제공자단체에 자율규제 가이드라인의 개선ㆍ보완을 권고할 수 있다. <신설 2024. 12. 3.>
정부는 제1항 및 제2항에 따른 정보통신서비스 제공자단체의 자율규제를 위한 활동을 지원할 수 있다. <신설 2018. 12. 24., 2024. 12. 3.>
[전문개정 2008. 6. 13.]
Article 44-4 (Self-regulation)
(1) An organization of providers of information and communications services may establish and implement a code of conduct applicable to providers of information and communications services with an objective to protect users and render information and communications services more safely and reliably. <Amended on Dec. 24, 2018>
(2) An organization of providers of information and communications services may establish and enforce self-regulating guidelines for monitoring, etc. so as to prevent any of the following information from being circulated in information and communications networks: <Added on Dec. 24, 2018>
1. Information harmful to youth;
2. Unlawful information under Article 44-7.
(3) The Government may recommend organizations of providers of information and communications services to improve and supplement self-regulation guidelines, if necessary to effectively prevent the circulation of information specified in any subparagraph of paragraph (2). <Added on Dec. 3, 2024>
(4) The Government may support self-regulating activities by organizations of providers of information and communications services under paragraphs (1) and (2). <Added on Dec. 24, 2018; Dec. 3, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
제44조의5(게시판 이용자의 본인 확인)
다음 각 호의 어느 하나에 해당하는 자가 게시판을 설치ㆍ운영하려면 그 게시판 이용자의 본인 확인을 위한 방법 및 절차의 마련 등 대통령령으로 정하는 필요한 조치(이하 "본인확인조치"라 한다)를 하여야 한다.
1. 국가기관, 지방자치단체, 「공공기관의 운영에 관한 법률」 제5조제3항에 따른 공기업ㆍ준정부기관 및 「지방공기업법」에 따른 지방공사ㆍ지방공단(이하 "공공기관등"이라 한다)
2. 삭제 <2014. 5. 28.>
삭제 <2014. 5. 28.>
정부는 제1항에 따른 본인 확인을 위하여 안전하고 신뢰할 수 있는 시스템을 개발하기 위한 시책을 마련하여야 한다.
공공기관등이 선량한 관리자의 주의로써 제1항에 따른 본인확인조치를 한 경우에는 이용자의 명의가 제3자에 의하여 부정사용됨에 따라 발생한 손해에 대한 배상책임을 줄이거나 면제받을 수 있다. <개정 2014. 5. 28.>
[전문개정 2008. 6. 13.]
[2014.5.28 법률 제12681호에 의하여 2012.8.23 헌법재판소에서 위헌 결정된 이 조 제1항제2호를 삭제함.]
Article 44-5 (Identity verification of users of message boards)
(1) If any of the following persons intends to install and operate a message board, he or she shall take necessary measures, as prescribed by Presidential Decree (hereinafter referred to as "measures for identity verification"), including preparation of methods and procedures for verifying identity of users of the message board:
1. A national agency, local government, public enterprise, or quasi-government agency under Article 5 (3) of the Act on the Management of Public Institutions, or a local government-invested public corporation or a local government public corporation under the Local Public Enterprises Act (hereinafter referred to as "public institution, etc.");
2. Deleted. <May 28, 2014>
(2) Deleted. <May 28, 2014>
(3) The Government shall prepare policy measures to develop a safer and more reliable system to verify identity of users under paragraph (1).
(4) A public institution, etc. may have its liability for damages caused by fraudulent use of a user's identity by a third party mitigated or discharged, if it has taken the measures for identity verification under paragraph (1) with care as a good manager. <Amended on May 28, 2014>
[This Article Wholly Amended on Jun. 13, 2008]
[Paragraph (1) 2 of this Article was deleted by Act No. 12681 on May 28, 2014, following the decision of unconstitutionality by the Constitutional Court made on Aug. 23, 2012].
제44조의6(이용자 정보의 제공청구)
특정한 이용자에 의한 정보의 게재나 유통으로 사생활 침해 또는 명예훼손 등 권리를 침해당하였다고 주장하는 자는 민ㆍ형사상의 소를 제기하기 위하여 침해사실을 소명하여 제44조의10에 따른 명예훼손 분쟁조정부에 해당 정보통신서비스 제공자가 보유하고 있는 해당 이용자의 정보(민ㆍ형사상의 소를 제기하기 위한 성명ㆍ주소 등 대통령령으로 정하는 최소한의 정보를 말한다)를 제공하도록 청구할 수 있다.
명예훼손 분쟁조정부는 제1항에 따른 청구를 받으면 해당 이용자와 연락할 수 없는 등의 특별한 사정이 있는 경우 외에는 그 이용자의 의견을 들어 정보제공 여부를 결정하여야 한다.
제1항에 따라 해당 이용자의 정보를 제공받은 자는 해당 이용자의 정보를 민ㆍ형사상의 소를 제기하기 위한 목적 외의 목적으로 사용하여서는 아니 된다.
그 밖의 이용자 정보 제공청구의 내용과 절차에 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 44-6 (Claim to furnish user information)
(1) A person who alleges that information published or circulated by a specific user has intruded on his or her privacy, defamed him or her, or violated his or her rights, may file a claim with the defamation dispute conciliation division under Article 44-10 to demand the relevant provider of information and communications services to furnish the information the provider possesses about the alleged offender (referring to the minimum information prescribed by Presidential Decree, including the name and address, necessary for filing a civil or criminal complaint), along with materials supporting his or her allegation of the violation, in order to file a civil or criminal complaint against the alleged offender.
(2) Upon receipt of a claim under paragraph (1), the defamation dispute conciliation division shall make a decision on whether to furnish information, hearing the opinion of the relevant user, unless it is impossible to contact the relevant user or there is any particular reason otherwise.
(3) A person who receives information about the relevant user under paragraph (1) shall not use the information for any purpose other than the purpose of filing a civil or criminal complaint.
(4) Other necessary matters regarding the content of a claim to furnish user information and the procedures therefor shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제44조의7(불법정보의 유통금지 등)
누구든지 정보통신망을 통하여 다음 각 호의 어느 하나에 해당하는 정보를 유통하여서는 아니 된다. <개정 2011. 9. 15., 2016. 3. 22., 2018. 6. 12., 2025. 1. 21.>
1. 음란한 부호ㆍ문언ㆍ음향ㆍ화상 또는 영상을 배포ㆍ판매ㆍ임대하거나 공공연하게 전시하는 내용의 정보
2. 사람을 비방할 목적으로 공공연하게 사실이나 거짓의 사실을 드러내어 타인의 명예를 훼손하는 내용의 정보
3. 공포심이나 불안감을 유발하는 부호ㆍ문언ㆍ음향ㆍ화상 또는 영상을 반복적으로 상대방에게 도달하도록 하는 내용의 정보
4. 정당한 사유 없이 정보통신시스템, 데이터 또는 프로그램 등을 훼손ㆍ멸실ㆍ변경ㆍ위조하거나 그 운용을 방해하는 내용의 정보
5. 「청소년 보호법」에 따른 청소년유해매체물로서 상대방의 연령 확인, 표시의무 등 법령에 따른 의무를 이행하지 아니하고 영리를 목적으로 제공하는 내용의 정보
6. 법령에 따라 금지되는 사행행위에 해당하는 내용의 정보
6의2. 이 법 또는 개인정보 보호에 관한 법령을 위반하여 개인정보를 거래하는 내용의 정보
6의3. 총포ㆍ화약류(생명ㆍ신체에 위해를 끼칠 수 있는 폭발력을 가진 물건을 포함한다)를 제조할 수 있는 방법이나 설계도 등의 정보
6의4. 「마약류 관리에 관한 법률」에서 금지하는 마약류의 사용, 제조, 매매 또는 매매의 알선 등에 해당하는 내용의 정보
7. 법령에 따라 분류된 비밀 등 국가기밀을 누설하는 내용의 정보
8. 「국가보안법」에서 금지하는 행위를 수행하는 내용의 정보
9. 그 밖에 범죄를 목적으로 하거나 교사(敎唆) 또는 방조하는 내용의 정보
방송미디어통신위원회는 제1항제1호부터 제6호까지, 제6호의2부터 제6호의4까지의 정보에 대하여는 심의위원회의 심의를 거쳐 정보통신서비스 제공자 또는 게시판 관리ㆍ운영자로 하여금 그 처리를 거부ㆍ정지 또는 제한하도록 명할 수 있다. 다만, 제1항제2호 및 제3호에 따른 정보의 경우에는 해당 정보로 인하여 피해를 받은 자가 구체적으로 밝힌 의사에 반하여 그 처리의 거부ㆍ정지 또는 제한을 명할 수 없다. <개정 2016. 3. 22., 2018. 6. 12., 2025. 1. 21., 2025. 10. 1.>
방송미디어통신위원회는 제1항제7호부터 제9호까지의 정보가 다음 각 호의 모두에 해당하는 경우에는 정보통신서비스 제공자 또는 게시판 관리ㆍ운영자에게 해당 정보의 처리를 거부ㆍ정지 또는 제한하도록 명하여야 한다. <개정 2016. 3. 22., 2018. 12. 24., 2024. 12. 3., 2025. 10. 1.>
1. 관계 중앙행정기관의 장의 요청[제1항제9호의 정보 중 「성폭력범죄의 처벌 등에 관한 특례법」 제14조 및 제14조의2에 따른 촬영물ㆍ편집물ㆍ합성물ㆍ가공물 또는 복제물(복제물의 복제물을 포함한다)과 「아동ㆍ청소년의 성보호에 관한 법률」 제2조제5호에 따른 아동ㆍ청소년성착취물에 대하여는 수사기관의 장의 요청을 포함한다]이 있었을 것
2. 제1호의 요청을 받은 날부터 7일 이내에 심의위원회의 심의를 거친 후 「방송미디어통신위원회의 설치 및 운영에 관한 법률」 제22조제4호에 따른 시정 요구를 하였을 것
3. 정보통신서비스 제공자나 게시판 관리ㆍ운영자가 시정 요구에 따르지 아니하였을 것
방송미디어통신위원회는 제2항 및 제3항에 따른 명령의 대상이 되는 정보통신서비스 제공자, 게시판 관리ㆍ운영자 또는 해당 이용자에게 미리 의견제출의 기회를 주어야 한다. 다만, 다음 각 호의 어느 하나에 해당하는 경우에는 의견제출의 기회를 주지 아니할 수 있다. <개정 2025. 10. 1.>
1. 공공의 안전 또는 복리를 위하여 긴급히 처분을 할 필요가 있는 경우
2. 의견청취가 뚜렷이 곤란하거나 명백히 불필요한 경우로서 대통령령으로 정하는 경우
3. 의견제출의 기회를 포기한다는 뜻을 명백히 표시한 경우
국내에 데이터를 임시적으로 저장하는 서버를 설치ㆍ운영하는 정보통신서비스 제공자 중 사업의 종류 및 규모 등이 대통령령으로 정하는 기준에 해당하는 자는 제1항 각 호에 해당하는 정보의 유통을 방지하기 위하여 다음 각 호의 기술적ㆍ관리적 조치를 하여야 한다. <신설 2024. 1. 23.>
1. 제2항 및 제3항에 따른 심의위원회의 심의를 거친 제1항 각 호의 정보가 서버에 저장되어 있는지 식별하여 신속하게 접근을 제한하는 조치
2. 제1호에 따라 식별한 정보의 게재자에게 해당 정보의 유통금지를 요청하는 조치
3. 제1호에 따른 조치의 운영ㆍ관리 실태를 시스템에 자동으로 기록되도록 하고, 이를 대통령령으로 정하는 기간 동안 보관하는 조치
4. 그 밖에 제1항 각 호에 해당하는 정보의 유통을 방지하기 위하여 필요한 대통령령으로 정하는 조치
[전문개정 2008. 6. 13.]
Article 44-7 (Prohibition on circulation of unlawful information)
(1) No one may circulate any of the following information through an information and communications network: <Amended on Sep. 15, 2011; Mar. 22, 2016; Jun. 12, 2018; Jan. 21, 2025>
1. Information with obscene content distributed, sold, rented, or displayed openly in the form of code, words, sound, images, or motion picture;
2. Information with content that defames other persons by divulging a fact or false information, openly and with intent to disparage the person's reputation;
3. Information with content that arouses fear or apprehension by reaching other persons repeatedly in the form of code, words, sound, image, or motion picture;
4. Information with content that damages, destroys, alters, or forges an information and communications system, data, a program, or similar or that interferes with the operation of such system, data, program, or similar without good cause;
5. Information with content that amounts to a media product harmful to youths under the Youth Protection Act and that is provided for profit without fulfilling the duties and obligations under the relevant statutes and regulations, including the duty to verify the subject's age and the duty of labeling;
6. Information with content that amounts to speculative activities prohibited by statutes and regulations;
6-2. Information with content of transactions of personal information in violation of this Act or any other statute or regulation regarding the protection of personal information;
6-3. Information regarding methods, drawings, etc. for manufacturing guns or explosives (including things with a yield that may expose people to risk of life or bodily injury);
6-4. Information with content of the use, manufacture, sale, or mediation of the sale of narcotics prohibited by the Narcotic Drugs Control Act;
7. Information with content that divulges a State secret, including secrets classified under statutes and regulations;
8. Information with content that violates the National Security Act;
9. Other information with content that attempts to commit, aids, or abets a crime.
(2) The Korea Media and Communications Commission may order a provider of information and communications services or a manager or an operator of a message board to reject, suspend, or restrict management of information under paragraph (1) 1 through 6, 6-2 through 6-4, subject to deliberation by the Communications Standards Commission; provided, if the information falls under paragraph (1) 2 or 3, the Commission shall not issue an order to reject, suspend, or restrict such management against the intention specifically manifested by the victim of the relevant information. <Amended on Mar. 22, 2016; Jun. 12, 2018; Jan. 21, 2025; Oct. 1, 2025>
(3) The Korea Media and Communications Commission shall order a provider of information and communications services or a manager or an operator of a message board to reject, suspend, or restrict management of information under paragraph (1) 7 through 9, if the information falls under all of the following: <Amended on Mar. 22, 2016; Dec. 24, 2018; Dec. 3, 2024; Oct. 1, 2025>
1. A request shall have been made by the head of the relevant central administrative agency [including requests from the head of an investigative agency for photographs and videos, compilations, composites, processed products, or their duplicates (including duplicates of duplicates) under Articles 14 and 14-2 of the Special Act on the Punishment of Sexual Crimes, and for child or youth sexual exploitation materials under subparagraph 5 of Article 2 of the Act on the Protection of Children and Youth against Sex Offenses];
2. A demand for correction was made pursuant to subparagraph 4 of Article 22 of the Act on the Establishment and Operation of Korea Media and Communications Commission after deliberation by the Communications Standards Commission within 7 days from the date the request under subparagraph 1 had been received;
3. The provider of information and communications services or the manager or operator of the message board has not complied with the demand for correction.
(4) The Korea Media and Communications Commission shall provide an opportunity to the provider of information and communications services or the manager, operator, or relevant user of the message board to whom an order is to be issued pursuant to paragraph (2) or (3) to present his or her opinion in advance; provided, the Commission need not provide an opportunity to present an opinion in any of the following cases: <Amended on Oct. 1, 2025>
1. Where it is necessary to make an urgent disposition for public safety or welfare;
2. Where there is a ground prescribed by Presidential Decree to believe that it is obviously impracticable or evidently unnecessary to hear an opinion;
3. Where a person concerned clearly manifests his or her intent to give up the opportunity to present his or her opinion.
(5) An information and communication service provider that installs and operates a domestic server for temporary storage of data and meets the criteria prescribed by the Presidential Decree for the type and scale of business shall take the following technical and administrative measures to prevent the distribution of information falling under the subparagraphs of paragraph (1): <Added on Jan. 23, 2024>
1. Measures to identify whether the information described in each of the subparagraphs of paragraph (1) is stored on the server and to promptly restrict access to it, subject to deliberation by the Communications Standards Commission in accordance with paragraphs 2 and 3;
2. Measures to request the person who posted the information identified under subparagraph 1 to prohibit the distribution of the relevant information;
3. Measures to have the actual status of the operation and management of the measures under subparagraph 1 recorded automatically in the system, and to keep it for the period prescribed by Presidential Decree;
4. Other measures prescribed by Presidential Decree as necessary to prevent the distribution of information falling under the subparagraphs of paragraph (1).
[This Article Wholly Amended on Jun. 13, 2008]
제44조의8(대화형정보통신서비스에서의 아동 보호)
정보통신서비스 제공자는 만 14세 미만의 아동에게 문자ㆍ음성을 이용하여 사람과 대화하는 방식으로 정보를 처리하는 시스템을 기반으로 하는 정보통신서비스를 제공하는 경우에는 그 아동에게 부적절한 내용의 정보가 제공되지 아니하도록 노력하여야 한다.
[본조신설 2018. 12. 24.]
Articles 44-8 (Protection of children in interactive information and communications services)
When a provider of information and communications services provides children under 14 years of age with information and communications services based on a system that processes information by engaging in a conversation with a human user through text messages or voice chat, it shall endeavor not to provide information containing inappropriate content to such children.
[This Article Added on Dec. 24, 2018]
제44조의9(불법촬영물등 유통방지 책임자)
정보통신서비스 제공자 중 일일 평균 이용자의 수, 매출액, 사업의 종류 등이 대통령령으로 정하는 기준에 해당하는 자는 자신이 운영ㆍ관리하는 정보통신망을 통하여 일반에게 공개되어 유통되는 정보 중 다음 각 호의 정보(이하 "불법촬영물등"이라 한다)의 유통을 방지하기 위한 책임자(이하 "불법촬영물등 유통방지 책임자"라 한다)를 지정하여야 한다.
1. 「성폭력범죄의 처벌 등에 관한 특례법」 제14조에 따른 촬영물 또는 복제물(복제물의 복제물을 포함한다)
2. 「성폭력범죄의 처벌 등에 관한 특례법」 제14조의2에 따른 편집물ㆍ합성물ㆍ가공물 또는 복제물(복제물의 복제물을 포함한다)
3. 「아동ㆍ청소년의 성보호에 관한 법률」 제2조제5호에 따른 아동ㆍ청소년성착취물
불법촬영물등 유통방지 책임자는 「전기통신사업법」 제22조의5제1항에 따른 불법촬영물등의 삭제ㆍ접속차단 등 유통방지에 필요한 조치 업무를 수행한다.
불법촬영물등 유통방지 책임자의 수 및 자격요건, 불법촬영물등 유통방지 책임자에 대한 교육 등에 관하여 필요한 사항은 대통령령으로 정한다.
[본조신설 2020. 6. 9.]
Article 44-9 (Persons responsible for preventing circulation of illegally filmed materials or the like)
(1) A provider of information and communications services who meets the criteria prescribed by Presidential Decree, such as the average number of daily users, sales, and types of business, shall designate a person (hereinafter referred to as a "person responsible for preventing the circulation of illegally filmed materials or the like") responsible for preventing the circulation of the following information (hereinafter referred to as "illegally filmed materials or the like") available to the public through the information and communications network the provider operates or manages:
1. A photograph or video or copies thereof (including copies of such copies) Article 14 of the Act on Special Cases concerning the Punishment of Sexual Crimes;
2. Compilations, composites, processed products, or their duplicates (including duplicates of duplicates) under Article 14-2 of the Act on Special Cases concerning the Punishment of Sexual Crimes;
3. Child or youth sexual exploitation materials defined in subparagraph 5 of Article 2 of the Act on the Protection of Children and Youth against Sex Offenses.
(2) Persons responsible for preventing the circulation of illegally filmed materials or the like shall take measures necessary to prevent the circulation thereof, such as deleting them and blocking access thereto, pursuant to Article 22-5 (1) of Telecommunications Business Act.
(3) Necessary matters regarding the number of persons responsible for preventing the circulation of illegally filmed materials or the like, qualification requirements, training, and other matters shall be prescribed by Presidential Decree.
[This Article Added on Jun. 9, 2020]
제44조의10(명예훼손 분쟁조정부)
심의위원회는 정보통신망을 통하여 유통되는 정보 중 사생활의 침해 또는 명예훼손 등 타인의 권리를 침해하는 정보와 관련된 분쟁의 조정업무를 효율적으로 수행하기 위하여 5명 이하의 위원으로 구성된 명예훼손 분쟁조정부를 두되, 그중 1명 이상은 변호사의 자격이 있는 사람으로 한다. <개정 2020. 6. 9.>
명예훼손 분쟁조정부의 위원은 심의위원회의 위원장이 심의위원회의 동의를 받아 위촉한다.
명예훼손 분쟁조정부의 분쟁조정절차 등에 관하여는 제33조의2제2항, 제35조부터 제39조까지의 규정을 준용한다. 이 경우 "분쟁조정위원회"는 "심의위원회"로, "개인정보와 관련한 분쟁"은 "정보통신망을 통하여 유통되는 정보 중 사생활의 침해 또는 명예훼손 등 타인의 권리를 침해하는 정보와 관련된 분쟁"으로 본다.
명예훼손 분쟁조정부의 설치ㆍ운영 및 분쟁조정 등에 관하여 그 밖의 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 44-10 (Defamation dispute conciliation division)
(1) The Communications Standards Commission shall have a defamation dispute conciliation division comprised of 5 members or fewer for efficient conciliation of disputes arising in connection with information that intrudes other persons' privacy, defames other persons, or violates other persons' rights, including a member or more holding the qualification of attorney-at-law. <Amended on Jun. 9, 2020>
(2) The members of the defamation dispute conciliation division shall be commissioned by the chairperson of the Communications Standards Commission with consent of the Communications Standards Commission.
(3) Articles 33-2 (2) and 35 through 39 shall apply mutatis mutandis to the procedures for conciliation of disputes by the defamation dispute conciliation division. In such cases, "Dispute Mediation Committee" shall be construed as "Communications Standards Commission", and "disputes over personal information" as "disputes arising in connection with information that intrudes other persons' privacy, defames other persons, or violates other persons' rights among information circulated through information and communications networks".
(4) Matters necessary for the installation and operation of the defamation dispute conciliation division and the conciliation of disputes, and other related matters shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제6장 정보통신망의 안정성 확보 등
CHAPTER VI SECURING OF STABILITY OF INFORMATION AND COMMUNICATIONS NETWORKS
제45조(정보통신망의 안정성 확보 등)
다음 각 호의 어느 하나에 해당하는 자는 정보통신서비스의 제공에 사용되는 정보통신망의 안정성 및 정보의 신뢰성을 확보하기 위한 보호조치를 하여야 한다. <개정 2020. 6. 9.>
1. 정보통신서비스 제공자
2. 정보통신망에 연결되어 정보를 송ㆍ수신할 수 있는 기기ㆍ설비ㆍ장비 중 대통령령으로 정하는 기기ㆍ설비ㆍ장비(이하 "정보통신망연결기기등"이라 한다)를 제조하거나 수입하는 자
과학기술정보통신부장관은 제1항에 따른 보호조치의 구체적 내용을 정한 정보보호조치에 관한 지침(이하 "정보보호지침"이라 한다)을 정하여 고시하고 제1항 각 호의 어느 하나에 해당하는 자에게 이를 지키도록 권고할 수 있다. <개정 2012. 2. 17., 2013. 3. 23., 2017. 7. 26., 2020. 6. 9.>
정보보호지침에는 다음 각 호의 사항이 포함되어야 한다. <개정 2016. 3. 22., 2020. 6. 9.>
1. 정당한 권한이 없는 자가 정보통신망에 접근ㆍ침입하는 것을 방지하거나 대응하기 위한 정보보호시스템의 설치ㆍ운영 등 기술적ㆍ물리적 보호조치
2. 정보의 불법 유출ㆍ위조ㆍ변조ㆍ삭제 등을 방지하기 위한 기술적 보호조치
3. 정보통신망의 지속적인 이용이 가능한 상태를 확보하기 위한 기술적ㆍ물리적 보호조치
4. 정보통신망의 안정 및 정보보호를 위한 인력ㆍ조직ㆍ경비의 확보 및 관련 계획수립 등 관리적 보호조치
5. 정보통신망연결기기등의 정보보호를 위한 기술적 보호조치
과학기술정보통신부장관은 관계 중앙행정기관의 장에게 소관 분야의 정보통신망연결기기등과 관련된 시험ㆍ검사ㆍ인증 등의 기준에 정보보호지침의 내용을 반영할 것을 요청할 수 있다. <신설 2020. 6. 9.>
[전문개정 2008. 6. 13.]
Article 45 (Securing of stability of information and communications networks)
(1) Any of the following persons shall take protective measures to secure the reliability of the information and ensure the stability of the information and communications networks used to provide information and communications services: <Amended on Jun. 9, 2020>
1. A provider of information and communications services;
2. A person who manufactures or imports devices, equipment, and facilities prescribed by Presidential Decree, among devices, equipment, and facilities which can transmit or receive information by being connected to an information and communications network (hereinafter referred to as "devices and the like connected to an information and communications network").
(2) The Minister of Science and ICT may determine and give public notice of guidelines for protective measures for information (hereinafter referred to as "information protection guidelines"), specifying details of the protective measures under paragraph (1) and may recommend any of the persons falling under paragraph (1) to observe the guidelines. <Amended on Feb. 17, 2012; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
(3) The information protection guidelines shall contain descriptions of the following: <Amended on Mar. 22, 2016; Jun. 9, 2020>
1. Technical and physical protective measures, including installation and operation of an information security system, to prevent or counteract access to or invasion upon an information and communications network by a person with no due authorization;
2. Technical protective measures for preventing unlawful leakage, forgery, alteration, or deletion of information;
3. Technical and physical protective measures for securing the state of enabling continuous use of information and communications networks;
4. Administrative protective measures for stabilization of information and communications networks and protection of information, including securing human resources, organization, and expenses and establishing related plans;
5. Technical protective measures for information security of devices and the like connected to an information and communications network.
(4) The Minister of Science and ICT may request the heads of relevant central administrative agencies to reflect the content of the information security guidelines in standards for testing, inspection, certification, etc. related to devices and the like connected to information and communications networks with regard to the substantive areas under their jurisdictions. <Added on Jun. 9, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
제45조의2(정보보호 사전점검)
정보통신서비스 제공자는 새로이 정보통신망을 구축하거나 정보통신서비스를 제공하고자 하는 때에는 그 계획 또는 설계에 정보보호에 관한 사항을 고려하여야 한다.
과학기술정보통신부장관은 다음 각 호의 어느 하나에 해당하는 정보통신서비스 또는 전기통신사업을 시행하고자 하는 자에게 대통령령으로 정하는 정보보호 사전점검기준에 따라 보호조치를 하도록 권고할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
1. 이 법 또는 다른 법령에 따라 과학기술정보통신부장관의 인가ㆍ허가를 받거나 등록ㆍ신고를 하도록 되어 있는 사업으로서 대통령령으로 정하는 정보통신서비스 또는 전기통신사업
2. 과학기술정보통신부장관이 사업비의 전부 또는 일부를 지원하는 사업으로서 대통령령으로 정하는 정보통신서비스 또는 전기통신사업
제2항에 따른 정보보호 사전점검의 기준ㆍ방법ㆍ절차ㆍ수수료 등 필요한 사항은 대통령령으로 정한다.
[본조신설 2012. 2. 17.]
Article 45-2 (Information security pre-inspection)
(1) If a provider of information and communications services intends to newly establish an information and communications network or to provide information and communications services, he or she shall take the matters regarding information security into account in planning or designing thereof.
(2) The Minister of Science and ICT may recommend a person who intends to operate the information and communications services or the telecommunications business falling under any of the following to take protective measures in accordance with the information security pre-inspection standards as prescribed by Presidential Decree: <Amended on Mar. 23, 2013; Jul. 26, 2017>
1. The information and communications services or telecommunications business prescribed by Presidential Decree, for which authorization or permission by the Minister of Science and ICT should be obtained or registration with or report to the Minister pursuant to this Act or other statutes and regulations;
2. The information and communications services or telecommunications business prescribed by Presidential Decree and fully or partially financed by the Minister of Science and ICT for the business expenses thereof.
(3) Standards, methods, procedures, fees for the information security pre-inspection standards under paragraph (2) and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Feb. 17, 2012]
제45조의3(정보보호 최고책임자의 지정 등)
정보통신서비스 제공자는 정보통신시스템 등에 대한 보안 및 정보의 안전한 관리를 위하여 대통령령으로 정하는 기준에 해당하는 임직원을 정보보호 최고책임자로 지정하고 과학기술정보통신부장관에게 신고하여야 한다. 다만, 자산총액, 매출액 등이 대통령령으로 정하는 기준에 해당하는 정보통신서비스 제공자의 경우에는 정보보호 최고책임자를 신고하지 아니할 수 있다. <개정 2014. 5. 28., 2017. 7. 26., 2018. 6. 12., 2021. 6. 8.>
제1항에 따른 신고의 방법 및 절차 등에 대해서는 대통령령으로 정한다. <신설 2014. 5. 28.>
제1항 본문에 따라 지정 및 신고된 정보보호 최고책임자(자산총액, 매출액 등 대통령령으로 정하는 기준에 해당하는 정보통신서비스 제공자의 경우로 한정한다)는 제4항의 업무 외의 다른 업무를 겸직할 수 없다. <신설 2018. 6. 12.>
정보보호 최고책임자의 업무는 다음 각 호와 같다. <개정 2021. 6. 8.>
1. 정보보호 최고책임자는 다음 각 목의 업무를 총괄한다.
가. 정보보호 계획의 수립ㆍ시행 및 개선
나. 정보보호 실태와 관행의 정기적인 감사 및 개선
다. 정보보호 위험의 식별 평가 및 정보보호 대책 마련
라. 정보보호 교육과 모의 훈련 계획의 수립 및 시행
2. 정보보호 최고책임자는 다음 각 목의 업무를 겸할 수 있다.
가. 「정보보호산업의 진흥에 관한 법률」 제13조에 따른 정보보호 공시에 관한 업무
나. 「정보통신기반 보호법」 제5조제5항에 따른 정보보호책임자의 업무
다. 「전자금융거래법」 제21조의2제4항에 따른 정보보호최고책임자의 업무
라. 「개인정보 보호법」 제31조제2항에 따른 개인정보 보호책임자의 업무
마. 그 밖에 이 법 또는 관계 법령에 따라 정보보호를 위하여 필요한 조치의 이행
정보통신서비스 제공자는 침해사고에 대한 공동 예방 및 대응, 필요한 정보의 교류, 그 밖에 대통령령으로 정하는 공동의 사업을 수행하기 위하여 제1항에 따른 정보보호 최고책임자를 구성원으로 하는 정보보호 최고책임자 협의회를 구성ㆍ운영할 수 있다. <개정 2014. 5. 28., 2018. 6. 12.>
정부는 제5항에 따른 정보보호 최고책임자 협의회의 활동에 필요한 경비의 전부 또는 일부를 지원할 수 있다. <개정 2014. 5. 28., 2015. 6. 22., 2018. 6. 12.>
정보보호 최고책임자의 자격요건 등에 필요한 사항은 대통령령으로 정한다. <신설 2018. 6. 12.>
[본조신설 2012. 2. 17.]
Article 45-3 (Designation of chief information security officers)
(1) A provider of information and communications services shall designate an executive officer or employee meeting the standards prescribed by Presidential Decree as a chief information security officer and shall file a report thereon to the Minister of Science and ICT, in order to ensure the security of information and communications systems, etc. and safe management of information; provided, a provider of information and communications services whose total assets, turnover, and the like meet the criteria prescribed by Presidential Decree need not file a report on such chief information security officer. <Amended on May 28, 2014; Jul. 26, 2017; Jun. 12, 2018; Jun. 8, 2021>
(2) Methods and procedures for reporting under paragraph (1) and other matters shall be prescribed by Presidential Decree. <Added on May 28, 2014>
(3) No chief information security officer designated and reported under the main clause of paragraph (1) (limited to where a provider of information and communications services whose total assets, turnover, and the like meet the criteria prescribed by Presidential Decree) may hold another office concurrently, other than perform duties referred to in paragraph (4). <Added on Jun. 12, 2018>
(4) A chief information security officer shall perform the following duties: <Amended on Jun. 8 2021>
1. The chief information security officer shall be responsible for the following duties:
(a) To formulate, implement, and improve information protection plans;
(b) To conduct regular audit and improve the actual conditions and practices of information protection;
(c) To identify and evaluate risks relating to information protection and develop countermeasures for information protection;
(d) To formulate and implement plans for information protection education and simulation training;
2. The chief information security officer may hold another office concurrently to perform the following:
(a) Duties of providing information security disclosure under Article 13 of the Act on the Promotion of Information Security Industry;
(b) Duties of chief information security officers under Article 5 (5) of the Act on the Protection of Information and Communications Infrastructure;
(c) Duties of chief information security officers under Article 21-2 (4) of the Electronic Financial Transactions Act;
(d) Duties of privacy officers under Article 31 (2) of the Personal Information Protection Act;
(e) Taking other measure necessary for information protection in accordance with this Act or any other relevant statute or regulation.
(5) A provider of information and communications services may establish and operate a council of chief information security officers comprised of chief information security officers prescribed in paragraph (1) in order to jointly prevent and respond to a cyber security incident, share necessary information, and implement other joint programs prescribed by Presidential Decree. <Amended on May 28, 2014; Jun. 12, 2018>
(6) The Government may fully or partially provide support to the Council of Information Security Officers under paragraph (5) for expenses incurred in conducting its activities. <Amended on May 28, 2014; Jun. 22, 2015; Jun. 12, 2018>
(7) Necessary matters regarding qualifications, etc. of chief information security officers shall be prescribed by Presidential Decree. <Added on Jun. 12, 2018>
[This Article Added on Feb. 17, 2012]
제46조(집적된 정보통신시설의 보호)
다음 각 호의 어느 하나에 해당하는 정보통신서비스 제공자 중 정보통신시설의 규모 등이 대통령령으로 정하는 기준에 해당하는 자(이하 "집적정보통신시설 사업자등"이라 한다)는 정보통신시설을 안정적으로 운영하기 위하여 대통령령으로 정하는 바에 따른 보호조치를 하여야 한다. <개정 2020. 6. 9., 2023. 1. 3.>
1. 타인의 정보통신서비스 제공을 위하여 집적된 정보통신시설을 운영ㆍ관리하는 자(이하 "집적정보통신시설 사업자"라 한다)
2. 자신의 정보통신서비스 제공을 위하여 직접 집적된 정보통신시설을 운영ㆍ관리하는 자
집적정보통신시설 사업자는 집적된 정보통신시설의 멸실, 훼손, 그 밖의 운영장애로 발생한 피해를 보상하기 위하여 대통령령으로 정하는 바에 따라 보험에 가입하여야 한다.
과학기술정보통신부장관은 정기적으로 제1항에 따른 보호조치의 이행 여부를 점검하고, 보완이 필요한 사항에 대하여 집적정보통신시설 사업자등에게 시정을 명할 수 있다. 다만, 집적정보통신시설 사업자등에 대하여 「방송통신발전 기본법」 제36조의2제2항에 따른 점검을 실시한 사항의 경우에는 제1항에 따른 보호조치의 이행 여부 점검 사항에서 제외한다. <신설 2023. 1. 3.>
과학기술정보통신부장관은 집적정보통신시설 사업자등에 해당하는지 여부의 확인 및 제3항에 따른 점검을 위하여 제1항 각 호의 어느 하나에 해당하는 정보통신서비스 제공자, 관계 중앙행정기관의 장, 지방자치단체의 장 및 「공공기관의 운영에 관한 법률」 제4조에 따라 공공기관으로 지정된 기관의 장에게 자료의 제출을 요구할 수 있다. 이 경우 자료제출 요구를 받은 자는 정당한 사유가 없으면 그 요구에 따라야 하며, 자료제출 요구의 절차ㆍ방법 등에 관하여는 제64조제6항 및 제9항부터 제11항까지를 준용한다. <신설 2023. 1. 3.>
제4항에 따라 제출받은 자료의 보호 및 폐기에 관하여는 제64조의2를 준용한다. <신설 2023. 1. 3.>
집적정보통신시설 사업자등은 재난이나 재해 및 그 밖의 물리적ㆍ기능적 결함 등으로 인하여 대통령령으로 정하는 기간 동안 정보통신서비스 제공의 중단이 발생한 때에는 그 중단 현황, 발생원인, 응급조치 및 복구대책을 지체 없이 과학기술정보통신부장관에게 보고하여야 한다. 이 경우 과학기술정보통신부장관은 집적된 정보통신시설의 복구 및 보호에 필요한 기술적 지원을 할 수 있다. <신설 2023. 1. 3.>
집적정보통신시설 사업자가 제공하는 집적된 정보통신시설을 임차한 정보통신서비스 제공자는 집적정보통신시설 사업자의 제1항에 따른 보호조치의 이행 등에 적극 협조하여야 하며, 제1항에 따른 보호조치에 필요한 설비를 직접 설치ㆍ운영하거나 출입 통제를 하는 등 임차시설을 배타적으로 운영ㆍ관리하는 경우에는 대통령령으로 정하는 바에 따라 보호조치의 이행, 재난 등으로 인한 서비스 중단 시 보고 등의 조치를 하여야 한다. <신설 2023. 1. 3.>
과학기술정보통신부장관은 제3항에 따른 점검과 제6항에 따른 기술적 지원에 관한 업무를 대통령령으로 정하는 전문기관에 위탁할 수 있다. <신설 2023. 1. 3.>
제3항에 따른 점검의 주기 및 방법, 제6항에 따른 보고의 방법, 그 밖에 필요한 사항은 대통령령으로 정한다. <신설 2023. 1. 3.>
[전문개정 2008. 6. 13.]
Article 46 (Protection of integrated information and communication facilities)
(1) Among the following information and communications service providers who meet the standards prescribed by Presidential Decree in terms of the scale, etc. of information and communications facilities (hereinafter referred to as "integrated information and communication facility operator, etc.") shall take protective measures, as prescribed by Presidential Decree, in order to operate information and communications facilities in a stable manner: <Amended on Jun. 9, 2020; Jan. 3, 2023>
1. A person who operates and manages integrated information and communications facilities to provide information and communications services for others (hereinafter referred to as "integrated information and communication facility operator");
2. A person who operates and manages integrated information and communication facilities directly to provide his or her own information and communications services.
(2) Every integrated information and communication facility operator shall purchase insurance policies as prescribed by Presidential Decree to cover damages that may be caused by destruction or damage of integrated information and communication facilities or any other trouble in operation.
(3) The Minister of Science and ICT may regularly inspect whether protective measures under paragraph (1) have been implemented and may order the integrated information and communication facility operator, etc. to take corrective measures with respect to matters requiring supplementation; provided, in cases of matters for which inspection under Article 36-2 (2) of the Framework Act on Broadcasting Communications Development has been conducted with respect to an integrated information and communication facility operator, etc. such matters shall be excluded from the inspection on whether protective measures under paragraph (1) have been implemented. <Added on Jan. 3, 2023>
(4) The Minister of Science and ICT may request providers of information and communications services falling under any subparagraph of paragraph (1), the heads of relevant central administrative agencies, the heads of local governments, and the heads of institutions designated as public institutions pursuant to Article 4 of the Act on the Management of Public Institutions to submit materials in order to verify whether they fall under the category of integrated information and communication facility operators and to conduct an inspection under paragraph (3). Upon receipt of a request for submission of materials in such cases, a person in receipt of such request shall comply therewith, in the absence of good cause, and Article 64 (6) and (9) through (11) shall apply mutatis mutandis to the procedures, methods, etc. for requesting submission of materials. <Added on Jan. 3, 2023>
(5) Article 64-2 shall apply mutatis mutandis to the protection and destruction of materials submitted pursuant to paragraph (4). <Added on Jan. 3, 2023>
(6) Where the provision of information and communications services has been interrupted during the period prescribed by Presidential Decree due to a disaster, calamity, or other physical or functional defects, an integrated information and communication facility operator shall report to the Minister of Science and ICT without delay the current status of interruption, causes of such interruption, emergency measures, and recovery measures. In such cases, the Minister of Science and ICT may provide technical support necessary for the recovery and protection of integrated information and communications facilities. <Added on Jan. 3, 2023>
(7) A provider of information and communications services who has leased an integrated information and communications facility provided by an integrated information and communication facility operator shall actively cooperate with the integrated information and communication facility operator in implementing protective measures under paragraph (1), and if exclusively operating and managing the leased facility, including directly installing and operating facilities necessary for protective measures under paragraph (1) or controlling access to such facilities, he or she shall take measures prescribed by Presidential Decree, such as implementing protective measures and reporting service interruption due to a disaster, etc. <Added on Jan. 3, 2023>
(8) The Minister of Science and ICT may entrust affairs regarding the inspection under paragraph (3) and technical support under paragraph (6) to a specialized organization prescribed by Presidential Decree. <Added on Jan. 3, 2023>
(9) The frequency and method of inspection under paragraph (3), the method of reporting under paragraph (6), and other necessary matters shall be prescribed by Presidential Decree. <Added on Jan. 3, 2023>
[This Article Wholly Amended on Jun. 13, 2008]
제46조의2(집적정보통신시설 사업자의 긴급대응)
집적정보통신시설 사업자는 다음 각 호의 어느 하나에 해당하는 경우에는 이용약관으로 정하는 바에 따라 해당 서비스의 전부 또는 일부의 제공을 중단할 수 있다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
1. 집적정보통신시설을 이용하는 자(이하 "시설이용자"라 한다)의 정보시스템에서 발생한 이상현상으로 다른 시설이용자의 정보통신망 또는 집적된 정보통신시설의 정보통신망에 심각한 장애를 발생시킬 우려가 있다고 판단되는 경우
2. 외부에서 발생한 침해사고로 집적된 정보통신시설에 심각한 장애가 발생할 우려가 있다고 판단되는 경우
3. 중대한 침해사고가 발생하여 과학기술정보통신부장관이나 한국인터넷진흥원이 요청하는 경우
집적정보통신시설 사업자는 제1항에 따라 해당 서비스의 제공을 중단하는 경우에는 중단사유, 발생일시, 기간 및 내용 등을 구체적으로 밝혀 시설이용자에게 즉시 알려야 한다.
집적정보통신시설 사업자는 중단사유가 없어지면 즉시 해당 서비스의 제공을 재개하여야 한다.
[전문개정 2008. 6. 13.]
Article 46-2 (Emergency countermeasures of integrated information and communication facility operators)
(1) In any of the following cases, an integrated information and communication facility operator may fully or partially interrupt the provision of relevant services, as stipulated in the terms and conditions of use: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
1. If it is anticipated that an abnormality found in the information system of a person using an integrated information and communication facility (hereinafter referred to as "facility user") may cause serious disruption to the information and communications network of other facility users or the information and communication network of the integrated information and communication facility;
2. If it is anticipated that an external cyber security incident will probably cause serious disruption to the integrated information and communication facility;
3. If there occurs a serious cyber security incident and the Minister of Science and ICT or the Korea Internet and Security Agency requests the interruption of the services.
(2) When the integrated information and communication facility operator interrupts his or her services in accordance with paragraph (1), he or she immediately notify users of the integrated information and communication facility the interruption of services, specifically stating the reasons for the interruption, the date, time, period, and details of the interruption, and other related matters.
(3) Once the event that caused the interruption of services ceases to exist, the integrated information and communication facility operator shall resume his or her services immediately.
[This Article Wholly Amended on Jun. 13, 2008]
제46조의3 삭제 <2012. 2. 17.>
Article 46-3 Deleted. <Feb. 17, 2012>
제47조(정보보호 관리체계의 인증)
과학기술정보통신부장관은 정보통신망의 안정성ㆍ신뢰성 확보를 위하여 관리적ㆍ기술적ㆍ물리적 보호조치를 포함한 종합적 관리체계(이하 "정보보호 관리체계"라 한다)를 수립ㆍ운영하고 있는 자에 대하여 제4항에 따른 기준에 적합한지에 관하여 인증을 할 수 있다. <개정 2012. 2. 17., 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
「전기통신사업법」 제2조제8호에 따른 전기통신사업자와 전기통신사업자의 전기통신역무를 이용하여 정보를 제공하거나 정보의 제공을 매개하는 자로서 다음 각 호의 어느 하나에 해당하는 자는 제1항에 따른 인증을 받아야 한다. <신설 2012. 2. 17., 2015. 12. 1., 2018. 12. 24., 2020. 6. 9., 2024. 1. 23.>
1. 「전기통신사업법」 제6조제1항에 따른 등록을 한 자로서 대통령령으로 정하는 바에 따라 정보통신망서비스를 제공하는 자(이하 "주요정보통신서비스 제공자"라 한다)
2. 집적정보통신시설 사업자
3. 전년도 매출액 또는 세입 등이 1,500억원 이상이거나 정보통신서비스 부문 전년도 매출액이 100억원 이상 또는 전년도 일일평균 이용자수 100만명 이상으로서, 대통령령으로 정하는 기준에 해당하는 자
과학기술정보통신부장관은 제2항에 따라 인증을 받아야 하는 자가 과학기술정보통신부령으로 정하는 바에 따라 국제표준 정보보호 인증을 받거나 정보보호 조치를 취한 경우에는 제1항에 따른 인증 심사의 일부를 생략할 수 있다. 이 경우 인증 심사의 세부 생략 범위에 대해서는 과학기술정보통신부장관이 정하여 고시한다. <신설 2015. 12. 1., 2017. 7. 26.>
과학기술정보통신부장관은 제1항에 따른 정보보호 관리체계 인증을 위하여 관리적ㆍ기술적ㆍ물리적 보호대책을 포함한 인증기준 등 그 밖에 필요한 사항을 정하여 고시할 수 있다. <개정 2012. 2. 17., 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
제1항에 따른 정보보호 관리체계 인증의 유효기간은 3년으로 한다. 다만, 제47조의5제1항에 따라 정보보호 관리등급을 받은 경우 그 유효기간 동안 제1항의 인증을 받은 것으로 본다. <신설 2012. 2. 17., 2015. 12. 1.>
과학기술정보통신부장관은 한국인터넷진흥원 또는 과학기술정보통신부장관이 지정한 기관(이하 "정보보호 관리체계 인증기관"이라 한다)으로 하여금 제1항 및 제2항에 따른 인증에 관한 업무로서 다음 각 호의 업무를 수행하게 할 수 있다. <신설 2012. 2. 17., 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
1. 인증 신청인이 수립한 정보보호 관리체계가 제4항에 따른 인증기준에 적합한지 여부를 확인하기 위한 심사(이하 "인증심사"라 한다)
2. 인증심사 결과의 심의
3. 인증서 발급ㆍ관리
4. 인증의 사후관리
5. 정보보호 관리체계 인증심사원의 양성 및 자격관리
6. 그 밖에 정보보호 관리체계 인증에 관한 업무
과학기술정보통신부장관은 인증에 관한 업무를 효율적으로 수행하기 위하여 필요한 경우 인증심사 업무를 수행하는 기관(이하 "정보보호 관리체계 심사기관"이라 한다)을 지정할 수 있다. <신설 2015. 12. 1., 2017. 7. 26.>
한국인터넷진흥원, 정보보호 관리체계 인증기관 및 정보보호 관리체계 심사기관은 정보보호 관리체계의 실효성 제고를 위하여 연 1회 이상 사후관리를 실시하고 그 결과를 과학기술정보통신부장관에게 통보하여야 한다. <신설 2012. 2. 17., 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
제1항 및 제2항에 따라 정보보호 관리체계의 인증을 받은 자는 대통령령으로 정하는 바에 따라 인증의 내용을 표시하거나 홍보할 수 있다. <개정 2012. 2. 17., 2015. 12. 1.>
과학기술정보통신부장관은 다음 각 호의 어느 하나에 해당하는 사유를 발견한 경우에는 인증을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 인증을 취소하여야 한다. <신설 2012. 2. 17., 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
1. 거짓이나 그 밖의 부정한 방법으로 정보보호 관리체계 인증을 받은 경우
2. 제4항에 따른 인증기준에 미달하게 된 경우
3. 제8항에 따른 사후관리를 거부 또는 방해한 경우
제1항 및 제2항에 따른 인증의 방법ㆍ절차ㆍ범위ㆍ수수료, 제8항에 따른 사후관리의 방법ㆍ절차, 제10항에 따른 인증취소의 방법ㆍ절차, 그 밖에 필요한 사항은 대통령령으로 정한다. <개정 2012. 2. 17., 2015. 12. 1.>
정보보호 관리체계 인증기관 및 정보보호 관리체계 심사기관 지정의 기준ㆍ절차ㆍ유효기간 등에 필요한 사항은 대통령령으로 정한다. <개정 2012. 2. 17., 2015. 12. 1.>
[전문개정 2008. 6. 13.]
Article 47 (Certification of information security management systems)
(1) With respect to a person who establishes and operates a comprehensive management system, including administrative, technical, and physical protective measures, for ensuring stability and reliability of an information and communications network (hereinafter referred to as "information security management system"), the Minister of Science and ICT may certify as to whether such person meets the standards under paragraph (4). <Amended on Feb. 17, 2012; Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>
(2) A telecommunications business operator under subparagraph 8 of Article 2 of the Telecommunications Business Act, or any of the following persons who provides or intermediates the provision of information by using telecommunications services of any telecommunications business operator, shall receive the certification under paragraph (1): <Added on Feb. 17, 2012; Dec. 1, 2015; Dec. 24, 2018; Jun. 9, 2020; Jan. 23, 2024>
1. A person who renders information and communications network services, as prescribed by Presidential Decree, as a person registered pursuant to Article 6 (1) of the Telecommunications Business Act (hereinafter referred to as a "major provider of information and communications services");
2. A integrated information and communication facility operator;
3. A person meeting the standards prescribed by Presidential Decree, whose sales, tax revenue, or any similar for the previous year is at least 150 billion won, whose sales in the information and communications service sector for the previous year is at least 10 billion won, or whose average daily users for the previous year is at least 1 million.
(3) Where a person required to be certified in accordance with paragraph (2) is certified for conformity with international standards for information protection or takes measures for information protection, as prescribed by Decree of the Ministry of Science and ICT, the Minister of Science and ICT may omit part of certification examination under paragraph (1). In such cases, the detailed scope of omitted certification examination shall be determined and publicly notified by the Minister of Science and ICT. <Added on Dec. 1, 2015; Jul. 26, 2017>
(4) For the purpose of certification of an information security management system under paragraph (1), the Minister of Science and ICT may determine and publicly notify certification standards, etc. including countermeasures for administrative, technical, and physical protection and other necessary matters. <Amended on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
(5) The period of validity of the certification of an information security management system under paragraph (1) shall be 3 years; provided, upon receipt of any information security management gradein accordance with Article 47-5 (1), the certification under paragraph (1) shall be deemed effective during the period of validity of such rating. <Added on Feb. 17, 2012; Dec. 1, 2015>
(6) The Minister of Science and ICT may have the Korea Internet and Security Agency or any institution designated by the Minister of Science and ICT (hereinafter referred to as "certification body for information security management systems") perform the following affairs related to the certification under paragraphs (1) and (2): <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Examination to verify whether the information security management system established by an applicant for certification meets the certification standards under paragraph (4) (hereinafter referred to as "examination for certification");
2. Review on the results of examination for certification;
3. Issuance and management of written certifications;
4. Follow-up management of granted certifications;
5. Fosterage and qualification management of the certification examiners of information security management systems;
6. Other affairs regarding the certification of information security management systems.
(7) If necessary for the efficient conduct of affairs related to certification, the Minister of Science and ICT may designate an institution that performs affairs related to examination for certification (hereinafter referred to as "examination institution for information security management systems"). <Added on Dec. 1, 2015; Jul. 26, 2017>
(8) The Korea Internet and Security Agency, a certification body for information security management systems, and an examination institution for information security management systems shall, in order to enhance the efficiency of information security management systems, perform follow-up management at least once a year and notify the Minister of Science and ICT of the results thereof. <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
(9) A person who has received the certification of an information security management system in accordance with paragraphs (1) and (2) may indicate or publicize the content of the certification, as prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>
(10) The Minister of Science and ICT may revoke the certification where any of the following grounds is found; provided, in cases falling under subparagraph 1, the Minister of Science and ICT shall revoke the certification: <Added on Feb. 17, 2012; Mar. 23. 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Having received the certification of an information security management system by fraud or other improper means;
2. Falling short of the certification standards under paragraph (4);
3. Refusing or obstructing the follow-up management under paragraph (8).
(11) Methods and procedures for, and scope and fees of, certification under paragraphs (1) and (2), methods and procedures for follow-up management under paragraph (8), methods and procedures for revoking certification under paragraph (10), and other necessary matters shall be prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>
(12) Standards and procedures for, and period of validity of, the designation of a certification body for information security management systems and an examination institution for information security management systems, and other necessary matters shall be prescribed by Presidential Decree. <Amended on Feb. 17, 2012; Dec. 1, 2015>
[This Article Wholly Amended on Jun. 13, 2008]
제47조의2(정보보호 관리체계 인증기관 및 정보보호 관리체계 심사기관의 지정취소 등)
과학기술정보통신부장관은 제47조에 따라 정보보호 관리체계 인증기관 또는 정보보호 관리체계 심사기관으로 지정받은 법인 또는 단체가 다음 각 호의 어느 하나에 해당하면 그 지정을 취소하거나 1년 이내의 기간을 정하여 해당 업무의 전부 또는 일부의 정지를 명할 수 있다. 다만, 제1호나 제2호에 해당하는 경우에는 그 지정을 취소하여야 한다. <개정 2012. 2. 17., 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
1. 거짓이나 그 밖의 부정한 방법으로 정보보호 관리체계 인증기관 또는 정보보호 관리체계 심사기관의 지정을 받은 경우
2. 업무정지기간 중에 인증 또는 인증심사를 한 경우
3. 정당한 사유 없이 인증 또는 인증심사를 하지 아니한 경우
4. 제47조제11항을 위반하여 인증 또는 인증심사를 한 경우
5. 제47조제12항에 따른 지정기준에 적합하지 아니하게 된 경우
제1항에 따른 지정취소 및 업무정지 등에 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
[제목개정 2015. 12. 1.]
Article 47-2 (Revocation of designation of certification body for information security management systems or examination institution for information security management systems)
(1) If a corporation or organization designated as a certification body for information security management systems or an examination institution for information security management systems pursuant to Article 47 falls under any of the following cases, the Minister of Science and ICT may revoke the designation or order it to fully or partially suspend the relevant business for a specified period not exceeding 1 year; provided, in cases falling under subparagraph 1 or 2, the Minister of Science and ICT shall revoke the designation: <Amended on Feb. 17, 2012; Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Where it has obtained the designation of a certification body for information security management systems or an examination institution for information security management systems by fraud or other improper means;
2. Where it has performed certification or examination for certification during a business suspension period;
3. Where it has not performed certification or examination for certification without good cause;
4. Where it has performed certification or examination for certification, in violation of Article 47 (11);
5. Where it no longer meets the standards for designation under Article 47 (12).
(2) Matters necessary for the revocation of designation and suspension of business under paragraph (1) and other related matters shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
[Title Amended on Dec. 1, 2015]
제47조의3 삭제 <2020. 2. 4.>
Article 47-3 Deleted. <Feb. 4, 2020>
제47조의4(이용자의 정보보호)
정부는 이용자의 정보보호에 필요한 기준을 정하여 이용자에게 권고하고, 침해사고의 예방 및 확산 방지를 위하여 취약점 점검, 기술 지원 등 필요한 조치를 할 수 있다.
정부는 제1항에 따른 조치에 관한 업무를 한국인터넷진흥원 또는 대통령령으로 정하는 전문기관에 위탁할 수 있다. <신설 2020. 6. 9.>
주요정보통신서비스 제공자는 정보통신망에 중대한 침해사고가 발생하여 자신의 서비스를 이용하는 이용자의 정보시스템 또는 정보통신망 등에 심각한 장애가 발생할 가능성이 있으면 이용약관으로 정하는 바에 따라 그 이용자에게 보호조치를 취하도록 요청하고, 이를 이행하지 아니하는 경우에는 해당 정보통신망으로의 접속을 일시적으로 제한할 수 있다. <개정 2020. 6. 9.>
「소프트웨어 진흥법」 제2조에 따른 소프트웨어사업자는 보안에 관한 취약점을 보완하는 프로그램을 제작하였을 때에는 한국인터넷진흥원에 알려야 하고, 그 소프트웨어 사용자에게는 제작한 날부터 1개월 이내에 2회 이상 알려야 한다. <개정 2009. 4. 22., 2020. 6. 9.>
제3항에 따른 보호조치의 요청 등에 관하여 이용약관으로 정하여야 하는 구체적인 사항은 대통령령으로 정한다. <개정 2020. 6. 9.>
[전문개정 2008. 6. 13.]
[제47조의3에서 이동 <2012. 2. 17.>]
Article 47-4 (Protection of users' information)
(1) The Government may prescribe guidelines necessary for protection of information of users to recommend users to observe the guidelines and may take measures necessary for preventing cyber security incidents and precluding spread thereof, such as inspection of vulnerabilities and technical support.
(2) The Government may entrust affairs regarding measures taken under paragraph (1) to the Korea Internet and Security Agency or a specialized organization prescribed by Presidential Decree. <Added on Jun. 9, 2020>
(3) If a major provider of information and communications services foresees that a serious problem is likely to occur in the information system of a user who uses the services, the information and communications network, or similar provided by such provider because of an occurrence of a serious cyber security incident on the information and communications network, the provider may request the user to take necessary protective measures as stipulated by the terms and conditions of use and may place a temporary restriction on access to the relevant information and communications network if the user does not perform as requested. <Amended on Jun. 9, 2020>
(4) When a software business operator defined in Article 2 of the Software Promotion Act has produced a program that can address security vulnerabilities, he or she shall notify the Korea Internet and Security Agency of such production and shall notify users of the software of the production at least twice within 1 month from the date of production. <Amended on Apr. 22, 2009; Jun. 9, 2020>
(5) Specific details that shall be stipulated by the terms and conditions of use with respect to the request for protective measures under paragraph (3) and other related matters shall be prescribed by Presidential Decree. <Amended on Jun. 9, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
[This Article Moved from Article 47-3 <Feb. 17, 2012>]
제47조의5(정보보호 관리등급 부여)
제47조에 따라 정보보호 관리체계 인증을 받은 자는 기업의 통합적 정보보호 관리수준을 제고하고 이용자로부터 정보보호 서비스에 대한 신뢰를 확보하기 위하여 과학기술정보통신부장관으로부터 정보보호 관리등급을 받을 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 한국인터넷진흥원으로 하여금 제1항에 따른 등급 부여에 관한 업무를 수행하게 할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
제1항에 따라 정보보호 관리등급을 받은 자는 대통령령으로 정하는 바에 따라 해당 등급의 내용을 표시하거나 홍보에 활용할 수 있다.
과학기술정보통신부장관은 다음 각 호의 어느 하나에 해당하는 사유를 발견한 경우에는 부여한 등급을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 부여한 등급을 취소하여야 한다. <개정 2013. 3. 23., 2015. 12. 1., 2017. 7. 26.>
1. 거짓이나 그 밖의 부정한 방법으로 정보보호 관리등급을 받은 경우
2. 제5항에 따른 등급기준에 미달하게 된 경우
제1항에 따른 등급 부여의 심사기준 및 등급 부여의 방법ㆍ절차ㆍ수수료, 등급의 유효기간, 제4항에 따른 등급취소의 방법ㆍ절차, 그 밖에 필요한 사항은 대통령령으로 정한다.
[본조신설 2012. 2. 17.]
Article 47-5 (Assignment of rating for information security management grade)
(1) A person who has obtained the certification of an information security management system pursuant to Article 47 is entitled to receive a information security management grade from the Minister of Science and ICT in order to enhance the level of a corporate's management of its comprehensive information security and to secure users' reliability on information security services. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(2) The Minister of Science and ICT may authorize the Korea Internet and Security Agency to perform the affairs of assigning ratings under paragraph (1). <Amended on Mar. 23, 2013; Jul. 26, 2017>
(3) A person who has obtained an information security management grade pursuant to paragraph (1) may indicate the obtained grade or advertise the details of such grade as prescribed by Presidential Decree.
(4) Where the Minister of Science and ICT finds any of the following cases, he or she may revoke the granted rating; provided, in the cases falling under subparagraph 1, the Minister of Science and ICT shall revoke the granted rating: <Amended on Mar. 23, 2013; Dec. 1, 2015; Jul. 26, 2017>
1. Where a person has obtained a information security management grade by fraud or other improper means;
2. Where a person falls short of the standards for assigning grades pursuant to paragraph (5).
(5) Standards for review in assigning ratings pursuant to paragraph (1); the methods and procedures for and fees of assigning ratings; the effective term of ratings; the methods and procedures for revocation of ratings pursuant to paragraph (4); and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Feb. 17, 2012]
제47조의6(정보보호 취약점 신고자에 대한 포상)
정부는 침해사고의 예방 및 피해 확산 방지를 위하여 정보통신서비스, 정보통신망연결기기등 또는 소프트웨어의 보안에 관한 취약점(이하 "정보보호 취약점"이라 한다)을 신고한 자에게 예산의 범위에서 포상금을 지급할 수 있다.
제1항에 따른 포상금의 지급 대상ㆍ기준 및 절차 등은 대통령령으로 정한다.
정부는 제1항에 따른 포상금 지급에 관한 업무를 한국인터넷진흥원에 위탁할 수 있다.
[본조신설 2022. 6. 10.]
Article 47-6 (Giving monetary award to person reporting information security vulnerability)
(1) The Government may pay a monetary award, within the budget, to a person who has reported any information security vulnerability relating to information communications services, devices and the like connected to information and communications networks, or software (hereinafter referred to as "information security vulnerability") to prevent cyber security incidents and stop damage from spreading.
(2) Persons eligible for monetary awards under paragraph (1), the standards and procedures for the payment of such monetary awards, and other relevant matters shall be prescribed by Presidential Decree.
(3) The Government may entrust affairs regarding the payment of monetary awards under paragraph (1) to the Korea Internet and Security Agency.
[This Article Added on Jun. 10, 2022]
제47조의7(정보보호 관리체계 인증의 특례)
과학기술정보통신부장관은 제47조제1항 및 제2항에 따른 인증을 받으려는 자 중 다음 각 호의 어느 하나에 해당하는 자에 대하여 제47조에 따른 인증기준 및 절차 등을 완화하여 적용할 수 있다.
1. 「중소기업기본법」 제2조제2항에 따른 소기업
2. 그 밖에 정보통신서비스의 규모 및 특성 등에 따라 대통령령으로 정하는 기준에 해당하는 자
과학기술정보통신부장관은 정보통신망의 안정성ㆍ신뢰성 확보를 위하여 제1항에 관련된 비용 및 기술 등 필요한 지원을 할 수 있다.
과학기술정보통신부장관은 제1항에 따른 인증기준 및 절차 등 그 밖에 필요한 사항을 정하여 고시할 수 있다.
[본조신설 2024. 1. 23.]
Article 47-7 (Special cases concerning certification of information security management system)
(1) The Minister of Science and ICT may relax and apply the certification standards and procedures under Article 47 to persons who fall under any of the following subparagraphs among persons seeking certification pursuant to Article 47 (1) and (2):
1. A small enterprise under Article 2 (2) of the Framework Act on Small and Medium Enterprises;
2. Any other person who meets the criteria prescribed by the Presidential Decree according to the scale and characteristics of information and communication services.
(2) The Minister of Science and ICT may provide necessary support, including costs and technology related to paragraph (1), to ensure the stability and reliability of the information and communication network.
(3) The Minister of Science and ICT may determine and publicly notify the certification standards and procedures under paragraph (1) and other necessary matters.
[This Article Added on Jan. 23, 2024]
제48조(정보통신망 침해행위 등의 금지)
누구든지 정당한 접근권한 없이 또는 허용된 접근권한을 넘어 정보통신망에 침입하여서는 아니 된다.
누구든지 정당한 사유 없이 정보통신시스템, 데이터 또는 프로그램 등을 훼손ㆍ멸실ㆍ변경ㆍ위조하거나 그 운용을 방해할 수 있는 프로그램(이하 "악성프로그램"이라 한다)을 전달 또는 유포하여서는 아니 된다.
누구든지 정보통신망의 안정적 운영을 방해할 목적으로 대량의 신호 또는 데이터를 보내거나 부정한 명령을 처리하도록 하는 등의 방법으로 정보통신망에 장애가 발생하게 하여서는 아니 된다.
누구든지 정당한 사유 없이 정보통신망의 정상적인 보호ㆍ인증 절차를 우회하여 정보통신망에 접근할 수 있도록 하는 프로그램이나 기술적 장치 등을 정보통신망 또는 이와 관련된 정보시스템에 설치하거나 이를 전달ㆍ유포하여서는 아니 된다. <신설 2024. 1. 23.>
[전문개정 2008. 6. 13.]
Article 48 (Prohibition on intrusive acts on information and communications networks)
(1) No one shall intrude on an information and communications network without a rightful authority for access or beyond a permitted authority for access.
(2) No one shall damage, destroy, alter, or forge an information and communications system, data, program, or similar without good cause, nor shall he or she convey or spread a program that is likely to interrupt operation of such system, data, program, or similar (hereinafter referred to as "malicious program").
(3) No one shall cause a trouble to an information and communications network to interfere with stable operation of the information and communications network by sending a large amount of signals or data, letting the network process an illegitimate order, or doing the similar actions.
(4) No person shall install a program or technical device that enables access to the information and communication network circumventing the normal protection and authentication procedures of the information and communication network without good cause on the information and communication network or the information system related to the information and communication network, or deliver or distribute it. < Added on Jan. 23, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
제48조의2(침해사고의 대응 등)
과학기술정보통신부장관은 침해사고에 적절히 대응하기 위하여 다음 각 호의 업무를 수행하고, 필요하면 업무의 전부 또는 일부를 한국인터넷진흥원이 수행하도록 할 수 있다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
1. 침해사고에 관한 정보의 수집ㆍ전파
2. 침해사고의 예보ㆍ경보
3. 침해사고에 대한 긴급조치
4. 그 밖에 대통령령으로 정하는 침해사고 대응조치
다음 각 호의 어느 하나에 해당하는 자는 대통령령으로 정하는 바에 따라 침해사고의 유형별 통계, 해당 정보통신망의 소통량 통계 및 접속경로별 이용 통계 등 침해사고 관련 정보를 과학기술정보통신부장관이나 한국인터넷진흥원에 제공하여야 한다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
1. 주요정보통신서비스 제공자
2. 집적정보통신시설 사업자
3. 그 밖에 정보통신망을 운영하는 자로서 대통령령으로 정하는 자
한국인터넷진흥원은 제2항에 따른 정보를 분석하여 과학기술정보통신부장관에게 보고하여야 한다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 제2항에 따라 정보를 제공하여야 하는 사업자가 정당한 사유 없이 정보의 제공을 거부하거나 거짓 정보를 제공하면 상당한 기간을 정하여 그 사업자에게 시정을 명할 수 있다. <개정 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관이나 한국인터넷진흥원은 제2항에 따라 제공받은 정보를 침해사고의 대응을 위하여 필요한 범위에서만 정당하게 사용하여야 한다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관이나 한국인터넷진흥원은 침해사고의 대응을 위하여 필요하면 제2항 각 호의 어느 하나에 해당하는 자에게 인력지원을 요청할 수 있다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
[전문개정 2008. 6. 13.]
Article 48-2 (Countermeasures against cyber security incidents)
(1) The Minister of Science and ICT shall perform the following business affairs to take proper countermeasures against cyber security incidents and may have the Korea Internet and Security Agency fully or partially perform the business affairs, if necessary to do so: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
1. Collection and spread of information about cyber security incidents;
2. Precaution and warning of computer security incidents;
3. Emergency measures against cyber security incidents;
4. Other countermeasures against cyber security incidents prescribed by Presidential Decree.
(2) Any of the following persons shall furnish the Minister of Science and ICT or the Korea Internet and Security Agency with the information related to cyber security incidents, including statistics by type of cyber security incidents, statistics of traffic of the relevant information and communications network, and statistics of use by access channel, as prescribed by Presidential Decree: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
1. A major provider of information and communications services;
2. A integrated information and communication facility operator;
3. Other persons prescribed by Presidential Decree from among those who operate an information and communications network.
(3) The Korea Internet and Security Agency shall analyze the information under paragraph (2) and report it to the Minister of Science and ICT. <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017; Jul. 26, 2017>
(4) If a business operator obligated to furnish the information in accordance with paragraph (2) refuses to do so without good cause or furnishes false information, the Minister of Science and ICT may order the business operator to make a correction within a reasonable period. <Amended on Mar. 23, 2013; Jul. 26, 2017>
(5) The Minister of Science and ICT or the Korea Internet and Security Agency shall use the information furnished in accordance with paragraph (2) properly within the extent necessary for taking countermeasures against a cyber security incident. <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
(6) If necessary to take countermeasures against a cyber security incident, the Minister of Science and ICT or the Korea Internet and Security Agency may request a person falling under any subparagraph of paragraph (2) to provide human resources for assistance. <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
제48조의3(침해사고의 신고 등)
정보통신서비스 제공자는 침해사고가 발생하면 즉시 그 사실을 과학기술정보통신부장관이나 한국인터넷진흥원에 신고하여야 한다. 이 경우 정보통신서비스 제공자가 이미 다른 법률에 따른 침해사고 통지 또는 신고를 했으면 전단에 따른 신고를 한 것으로 본다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26., 2022. 6. 10.>
1. 삭제 <2022. 6. 10.>
2. 삭제 <2022. 6. 10.>
과학기술정보통신부장관이나 한국인터넷진흥원은 제1항에 따라 침해사고의 신고를 받거나 침해사고를 알게 되면 제48조의2제1항 각 호에 따른 필요한 조치를 하여야 한다. <개정 2009. 4. 22., 2013. 3. 23., 2017. 7. 26.>
제1항 후단에 따라 침해사고의 통지 또는 신고를 받은 관계 기관의 장은 이와 관련된 정보를 과학기술정보통신부장관 또는 한국인터넷진흥원에 지체 없이 공유하여야 한다. <신설 2022. 6. 10.>
제1항에 따른 신고의 시기, 방법 및 절차 등에 관하여 필요한 사항은 대통령령으로 정한다. <신설 2024. 2. 13.>
[전문개정 2008. 6. 13.]
Article 48-3 (Report on cyber security incidents)
(1) If a cyber security incident occurs, a provider of information and communications services shall immediately report it to the Minister of Science and ICT or the Korea Internet and Security Agency; in such cases, if a provider of information and communications services has already notified or reported a cyber security incident in accordance with another statute, such report mandated under the former part shall be deemed to have been made: <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022>
1. Deleted; <Jun. 10, 2022>
2. Deleted. <Jun. 10, 2022>
(2) Upon receipt of a report on a cyber security incident under paragraph (1) or becoming aware of a cyber security incident, the Minister of Science and ICT or the Korea Internet and Security Agency shall take necessary measures under the subparagraphs of Article 48-2 (1). <Amended on Apr. 22, 2009; Mar. 23, 2013; Jul. 26, 2017>
(3) Upon receipt of a notice of or report on a cyber security incident under the latter part of paragraph (1), the head of a related agency shall share relevant information with the Minister of Science and ICT or the Korea Internet and Security Agency without delay. <Added on Jun. 10, 2022>
(4) Matters necessary for the time, method, and procedures for reporting under paragraph (1) shall be prescribed by Presidential Decree. <Added on Feb. 13, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
제48조의4(침해사고의 원인 분석 등)
정보통신서비스 제공자 등 정보통신망을 운영하는 자는 침해사고가 발생하면 침해사고의 원인을 분석하고 그 결과에 따라 피해의 확산 방지를 위하여 사고대응, 복구 및 재발 방지에 필요한 조치를 하여야 한다. <개정 2022. 6. 10.>
과학기술정보통신부장관은 정보통신서비스 제공자의 정보통신망에 침해사고가 발생하면 그 침해사고의 원인을 분석하고 피해 확산 방지, 사고대응, 복구 및 재발 방지를 위한 대책을 마련하여 해당 정보통신서비스 제공자(공공기관등은 제외한다)에게 필요한 조치를 이행하도록 명령할 수 있다. <신설 2022. 6. 10., 2024. 2. 13.>
과학기술정보통신부장관은 제2항에 따른 조치의 이행 여부를 점검하고, 보완이 필요한 사항에 대하여 해당 정보통신서비스 제공자에게 시정을 명할 수 있다. <신설 2024. 2. 13.>
과학기술정보통신부장관은 정보통신서비스 제공자의 정보통신망에 중대한 침해사고가 발생한 경우 제2항에 따른 원인 분석 및 대책 마련을 위하여 필요하면 정보보호에 전문성을 갖춘 민ㆍ관합동조사단을 구성하여 그 침해사고의 원인 분석을 할 수 있다. <개정 2013. 3. 23., 2017. 7. 26., 2022. 6. 10., 2024. 2. 13.>
과학기술정보통신부장관은 제2항에 따른 침해사고의 원인 분석 및 대책 마련을 위하여 필요하면 정보통신서비스 제공자에게 정보통신망의 접속기록 등 관련 자료의 보전을 명할 수 있다. <개정 2013. 3. 23., 2017. 7. 26., 2022. 6. 10., 2024. 2. 13.>
과학기술정보통신부장관은 제2항에 따른 침해사고의 원인 분석 및 대책 마련을 하기 위하여 필요하면 정보통신서비스 제공자에게 침해사고 관련 자료의 제출을 요구할 수 있으며, 중대한 침해사고의 경우 소속 공무원 또는 제4항에 따른 민ㆍ관합동조사단에게 관계인의 사업장에 출입하여 침해사고 원인을 조사하도록 할 수 있다. 다만, 「통신비밀보호법」 제2조제11호에 따른 통신사실확인자료에 해당하는 자료의 제출은 같은 법으로 정하는 바에 따른다. <개정 2013. 3. 23., 2017. 7. 26., 2022. 6. 10., 2024. 2. 13.>
과학기술정보통신부장관이나 민ㆍ관합동조사단은 제6항에 따라 제출받은 자료와 조사를 통하여 알게 된 정보를 침해사고의 원인 분석 및 대책 마련 외의 목적으로는 사용하지 못하며, 원인 분석이 끝난 후에는 즉시 파기하여야 한다. <개정 2013. 3. 23., 2017. 7. 26., 2022. 6. 10., 2024. 2. 13.>
제3항에 따른 점검의 방법ㆍ절차, 제4항에 따른 민ㆍ관합동조사단의 구성ㆍ운영, 제6항에 따라 제출된 자료의 보호 및 조사의 방법ㆍ절차 등에 필요한 사항은 대통령령으로 정한다. <개정 2022. 6. 10., 2024. 2. 13.>
[전문개정 2008. 6. 13.]
Article 48-4 (Analysis of causes of cyber security incidents)
(1) If a cyber security incident occurs, a person who operates an information and communications network, including a provider of information and communications services, shall analyze the causes of the cyber security incident; respond thereto, based on the results of analysis, for stopping damage from spreading; and take measures necessary to recover from the damage and prevent a recurrence of such cyber security incident. <Amended on Jun. 10, 2022>
(2) If a cyber security incident occurs in an information and communications network operated by a provider of information and communications services, the Minister of Science and ICT may analyze the causes of the cyber security incident and develop countermeasures to stop damage from spreading, to respond to such incident, to recover from damage, and to prevent a recurrence of such incident; and may order the provider of information and communications services (excluding public institutions) to implement necessary measures. <Added on Jun. 10, 2022; Feb. 13, 2024>
(3) The Minister of Science and ICT may inspect whether measures under paragraph (2) have been implemented and order the provider of information and communications services to make a correction for matters requiring supplementation. <Added on Feb. 13, 2024>
(4) Where a serious cyber security incident occurs in an information and communications network operated by a provider of information and communications services, the Minister of Science and ICT may organize a private-public joint investigation team having expertise in the protection of information and analyze the causes of such cyber security incident if necessary for analyzing such causes and developing countermeasures pursuant to paragraph (2). <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(5) If deemed necessary for analyzing the causes of a cyber security incident and developing countermeasures pursuant to paragraph (2), the Minister of Science and ICT may order the relevant provider of information and communications services to preserve relevant data, such as records on access to the relevant information and communications network. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(6) The Minister of Science and ICT may demand a provider of information and communications services to submit data related to a cyber security incident, if deemed necessary for analyzing the causes of such cyber security incident and developing countermeasures pursuant to paragraph (2); and in the case of a serious cyber security incident, the Minister may require public officials under his or her jurisdiction or a private-public joint investigation team under paragraph (4) to enter the place of business of the relevant person and to investigate the causes of the incident; provided, data corresponding to the communication confirmation data defined in subparagraph 11 of Article 2 of the Protection of Communications Secrets Act shall be submitted in the manner prescribed by that Act. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(7) The Minister of Science and ICT or the private-public joint investigation team shall not use the information learned through the data submitted and the investigation conducted in accordance with paragraph (6) for any purpose other than the analysis of the causes of the cyber security incident and development of countermeasures and shall destroy it immediately after the analysis of the causes is completed. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 10, 2022; Feb. 13, 2024>
(8) Matters necessary for the methods and procedures for inspection under paragraph (3), the organization and operation of a private-public joint investigation team under paragraph (4), the protection of data submitted pursuant to paragraph (6), the methods and procedures for investigations, etc. shall be prescribed by Presidential Decree. <Amended on Jun. 10, 2022; Feb. 13, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
제48조의5(정보통신망연결기기등 관련 침해사고의 대응 등)
과학기술정보통신부장관은 정보통신망연결기기등과 관련된 침해사고가 발생하면 관계 중앙행정기관의 장과 협력하여 해당 침해사고의 원인을 분석할 수 있다.
과학기술정보통신부장관은 정보통신망연결기기등과 관련된 침해사고가 발생하여 국민의 생명ㆍ신체 또는 재산에 위험을 초래할 가능성이 있는 경우 관계 중앙행정기관의 장에게 다음 각 호의 조치를 하도록 요청할 수 있다.
1. 제47조의4제1항에 따른 취약점 점검, 기술 지원 등의 조치
2. 피해 확산을 방지하기 위하여 필요한 조치
3. 그 밖에 정보통신망연결기기등의 정보보호를 위한 제도의 개선
과학기술정보통신부장관은 정보통신망연결기기등과 관련된 침해사고가 발생한 경우 해당 정보통신망연결기기등을 제조하거나 수입한 자에게 제품 취약점 개선 등 침해사고의 확대 또는 재발을 방지하기 위한 조치를 할 것을 권고할 수 있다.
과학기술정보통신부장관은 대통령령으로 정하는 전문기관이 다음 각 호의 사업을 수행하는 데 필요한 비용을 지원할 수 있다.
1. 정보통신망연결기기등과 관련된 정보보호지침 마련을 위한 연구
2. 정보통신망연결기기등과 관련된 시험ㆍ검사ㆍ인증 등의 기준 개선 연구
[본조신설 2020. 6. 9.]
Article 48-5 (Countermeasures against cyber security incidents related to devices and the like connected to information and communications networks)
(1) Where a computer security incident related to devices and the like connected to an information and communications network occurs, the Minister of Science and ICT may analyze the cause of the relevant computer security incident in cooperation with the heads of relevant central administrative agencies.
(2) Where there occurs a computer security incident related to devices and the like connected to an information and communications network, which is likely to cause any danger to the lives, bodies, or property of citizens, the Minister of Science and ICT may request the heads of relevant central administrative agencies to take the following measures:
1. Measures, such as the inspection of vulnerabilities and technical support under Article 47-4 (1);
2. Measures necessary for precluding the spread of damage;
3. Improvement of other systems for the information security of devices and the like connected to an information and communications network.
(3) Where there occurs a cyber security incident related to devices and the like connected to an information and communications network, the Minister of Science and ICT may recommend a person who manufactures or imports the relevant devices and the like connected to an information and communications network to take measures, such as improving vulnerabilities thereof, for preventing an expansion or recurrence of the cyber security incident.
(4) The Minister of Science and ICT may provide support to a specialized organization prescribed by Presidential Decree for expenses incurred in conducting the following business activities:
1. Research to formulate guidelines for information security related to devices and the like connected to information and communications networks;
2. Research for improving standards for testing, inspection, authentication, etc. related to devices or the like connected to information and communications networks.
[This Article Added on Jun. 9, 2020]
제48조의6(정보통신망연결기기등에 관한 인증)
과학기술정보통신부장관은 제4항에 따른 인증시험대행기관의 시험 결과 정보통신망연결기기등이 제2항에 따른 인증기준에 적합한 경우 정보보호인증을 할 수 있다.
과학기술정보통신부장관은 제1항에 따른 정보보호인증(이하 "정보보호인증"이라 한다)을 위하여 정보통신망의 안정성 및 정보의 신뢰성 확보 등에 관한 인증기준을 정하여 고시할 수 있다.
과학기술정보통신부장관은 정보보호인증을 받은 자가 다음 각 호의 어느 하나에 해당하는 경우에는 그 정보보호인증을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 그 정보보호인증을 취소하여야 한다.
1. 거짓이나 그 밖의 부정한 방법으로 정보보호인증을 받은 경우
2. 제2항에 따른 인증기준에 미달하게 된 경우
과학기술정보통신부장관은 정보통신망연결기기등이 제2항에 따른 인증기준에 적합한지 여부를 확인하는 시험을 효율적으로 수행하기 위하여 필요한 경우에는 대통령령으로 정하는 지정기준을 충족하는 기관을 인증시험대행기관으로 지정할 수 있다.
과학기술정보통신부장관은 제4항에 따라 지정된 인증시험대행기관(이하 "인증시험대행기관"이라 한다)이 다음 각 호의 어느 하나에 해당하면 인증시험대행기관의 지정을 취소할 수 있다. 다만, 제1호에 해당하는 경우에는 그 지정을 취소하여야 한다.
1. 거짓이나 그 밖의 부정한 방법으로 지정을 받은 경우
2. 제4항에 따른 지정기준에 미달하게 된 경우
과학기술정보통신부장관은 정보보호인증 및 정보보호인증 취소에 관한 업무를 한국인터넷진흥원에 위탁할 수 있다.
정보보호인증ㆍ정보보호인증 취소의 절차 및 인증시험대행기관의 지정ㆍ지정취소의 절차 등에 관하여 필요한 사항은 대통령령으로 정한다.
[본조신설 2020. 6. 9.]
Article 48-6 (Certification of devices and the like connected to information and communications networks)
(1) Where devices and the like connected to an information and communications network meet the certification standards under paragraph (2) as a result of an examination conducted by a testing agency for certification under paragraph (4), the Minister of Science and ICT may grant information security certification.
(2) The Minister of Science and ICT may determine and publicly notify certification standards for ensuring the stability of information and communications networks and securing the reliability of information, with regard to the information security certification under paragraph (1) (hereinafter referred to as "information security certification").
(3) Where a person who has obtained information security certification falls under any of the following subparagraphs, the Minister of Science and ICT may revoke such certification; provided, in cases falling under subparagraph 1, such certification shall be revoked:
1. Where he or she has obtained information security certification by fraud or other improper means;
2. Where he or she fails to meet the certification standards provided for in paragraph (2).
(4) In order to efficiently conduct tests verifying whether devices and the like connected to an information and communications network meet the certification standards referred to in paragraph (2), the Minister of Science and ICT may, if necessary, designate, as a testing agency for certification, an institution satisfying the designation standards prescribed by Presidential Decree.
(5) Where a testing agency for certification designated pursuant to paragraph (4) (hereinafter referred to as a "testing agency for certification") falls under any of the following cases, the Minister of Science and ICT may revoke such designation; provided, in cases falling under subparagraph 1, such certification shall be revoked:
1. Where it has obtained the designation by fraud or other improper means;
2. If it fails to meet the criteria for designation under paragraph (4).
(6) The Minister of Science and ICT may entrust affairs related to information security certification and the revocation thereof to the Korea Internet and Security Agency.
(7) Necessary matters regarding procedures, etc. for information security certification and cancellation of such certification and procedures, etc. for designation of testing agencies for certification and cancellation of such designation shall be prescribed by Presidential Decree.
[This Article Added on Jun. 9, 2020]
제49조(비밀 등의 보호)
누구든지 정보통신망에 의하여 처리ㆍ보관 또는 전송되는 타인의 정보를 훼손하거나 타인의 비밀을 침해ㆍ도용 또는 누설하여서는 아니 된다.
[전문개정 2008. 6. 13.]
Article 49 (Protection of secrets)
No one shall damage another person's information processed, stored, or transmitted through an information and communications network, nor shall he or she infringe, misappropriate, or divulge another person's secret.
[This Article Wholly Amended on Jun. 13, 2008]
제49조의2(속이는 행위에 의한 정보의 수집금지 등)
누구든지 정보통신망을 통하여 속이는 행위로 다른 사람의 정보를 수집하거나 다른 사람이 정보를 제공하도록 유인하여서는 아니 된다.
정보통신서비스 제공자는 제1항을 위반한 사실을 발견하면 즉시 과학기술정보통신부장관 또는 한국인터넷진흥원에 신고하여야 한다. <개정 2009. 4. 22., 2016. 3. 22., 2017. 7. 26., 2020. 2. 4.>
과학기술정보통신부장관 또는 한국인터넷진흥원은 제2항에 따른 신고를 받거나 제1항을 위반한 사실을 알게 되면 다음 각 호의 필요한 조치를 하여야 한다. <개정 2009. 4. 22., 2016. 3. 22., 2017. 7. 26., 2020. 2. 4., 2022. 6. 10.>
1. 위반 사실에 관한 정보의 수집ㆍ전파
2. 유사 피해에 대한 예보ㆍ경보
3. 정보통신서비스 제공자에게 다음 각 목의 사항 중 전부 또는 일부를 요청하는 등 피해 예방 및 피해 확산을 방지하기 위한 긴급조치
가. 접속경로의 차단
나. 제1항의 위반행위에 이용된 전화번호에 대한 정보통신서비스의 제공 중지
다. 이용자에게 제1항의 위반행위에 노출되었다는 사실의 통지
과학기술정보통신부장관은 제3항제3호의 조치를 취하기 위하여 정보통신서비스 제공자에게 정보통신서비스 제공자 간 정보통신망을 통하여 속이는 행위에 대한 정보 공유 등 필요한 조치를 취하도록 명할 수 있다. <신설 2016. 3. 22., 2017. 7. 26., 2020. 2. 4.>
제3항제3호에 따른 요청을 받은 정보통신서비스 제공자는 이용약관으로 정하는 바에 따라 해당 조치를 할 수 있다. <신설 2022. 6. 10.>
제5항에 따른 이용약관으로 정하여야 하는 구체적인 사항은 대통령령으로 정한다. <신설 2022. 6. 10.>
[전문개정 2008. 6. 13.]
[제목개정 2020. 2. 4.]
Article 49-2 (Prohibition on collection of information by deception)
(1) No one shall collect another person's information or entice another person to furnish information through an information and communications network by deception.
(2) Whenever a provider of information and communications services discovers a violation of paragraph (1), he or she immediately report it to the Minister of Science and ICT or the Korea Internet and Security Agency. <Amended on Apr. 22, 2009; Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020>
(3) Upon receipt of a report under paragraph (2) or becoming aware of a violation of paragraph (1), the Minister of Science and ICT or the Korea Internet and Security Agency shall take the following measures as necessary: <Amended on Apr. 22, 2009; Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020; Jun. 10, 2022>
1. Collection and diffusion of the information related to the violation;
2. Precaution and warning of similar damage;
3. Emergency measures for preventing damage and spread thereof, including requesting a provider of information and communications services to conduct all or some of the following:
(a) Blockage of access paths;
(b) Suspension of the provision of information and communications services for telephone numbers used for a violation described in paragraph (1);
(c) Notification to relevant users of the fact that they have been exposed to a violation described in paragraph (1).
(4) To take measures referred to in paragraph (3) 3, the Minister of Science and ICT may order providers of information and communications services to take necessary measures, such as sharing among themselves information regarding deception through information and communications networks. <Added on Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020>
(5) Upon receipt of a request made under paragraph (3) 3, a provider of information and communications services may take the relevant measures in the manner prescribed by relevant terms and conditions of use. <Added on Jun. 10, 2022>
(6) Details to be stipulated by the terms and conditions of use under paragraph (5) shall be prescribed by Presidential Decree. <Added on Jun. 10, 2022>
[This Article Wholly Amended on Jun. 13, 2008]
[Title Amended on Feb. 4, 2020]
제49조의3(속이는 행위에 사용된 전화번호의 전기통신역무 제공의 중지 등)
경찰청장ㆍ검찰총장ㆍ금융감독원장 등 대통령령으로 정하는 자는 제49조의2제1항에 따른 속이는 행위에 이용된 전화번호를 확인한 때에는 과학기술정보통신부장관에게 해당 전화번호에 대한 전기통신역무 제공의 중지를 요청할 수 있다.
제1항에 따른 요청으로 전기통신역무 제공이 중지된 이용자는 전기통신역무 제공의 중지를 요청한 기관에 이의신청을 할 수 있다.
제2항에 따른 이의신청의 절차 등에 필요한 사항은 대통령령으로 정한다.
[본조신설 2022. 6. 10.]
Article 49-3 (Suspension of provision of telecommunications services for telephone numbers used as means of deception)
(1) When a person prescribed by Presidential Decree, including the Commissioner General of the National Police Agency, the Prosecutor General, and the Governor of the Financial Supervisory Service, has verified telephone numbers used as means of deception described in Article 49-2 (1), the person may request the Minister of Science and ICT to suspend the provision of telecommunications services for the relevant telephone numbers.
(2) A user whose telecommunication services have been suspended due to a request made paragraph (1) may file an objection with the agency that has requested the suspension.
(3) Matters necessary for procedures, etc. for filing an objection under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Added on Jun. 10, 2022]
제50조(영리목적의 광고성 정보 전송 제한)
누구든지 전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하려면 그 수신자의 명시적인 사전 동의를 받아야 한다. 다만, 다음 각 호의 어느 하나에 해당하는 경우에는 사전 동의를 받지 아니한다. <개정 2016. 3. 22., 2020. 6. 9.>
1. 재화등의 거래관계를 통하여 수신자로부터 직접 연락처를 수집한 자가 대통령령으로 정한 기간 이내에 자신이 처리하고 수신자와 거래한 것과 같은 종류의 재화등에 대한 영리목적의 광고성 정보를 전송하려는 경우
2. 「방문판매 등에 관한 법률」에 따른 전화권유판매자가 육성으로 수신자에게 개인정보의 수집출처를 고지하고 전화권유를 하는 경우
전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하려는 자는 제1항에도 불구하고 수신자가 수신거부의사를 표시하거나 사전 동의를 철회한 경우에는 영리목적의 광고성 정보를 전송하여서는 아니 된다.
오후 9시부터 그 다음 날 오전 8시까지의 시간에 전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하려는 자는 제1항에도 불구하고 그 수신자로부터 별도의 사전 동의를 받아야 한다. 다만, 대통령령으로 정하는 매체의 경우에는 그러하지 아니하다.
전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하는 자는 대통령령으로 정하는 바에 따라 다음 각 호의 사항 등을 광고성 정보에 구체적으로 밝혀야 한다.
1. 전송자의 명칭 및 연락처
2. 수신의 거부 또는 수신동의의 철회 의사표시를 쉽게 할 수 있는 조치 및 방법에 관한 사항
전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하는 자는 다음 각 호의 어느 하나에 해당하는 행위를 하여서는 아니 된다. <개정 2024. 1. 23.>
1. 광고성 정보 수신자의 수신거부 또는 수신동의의 철회를 회피ㆍ방해하는 행위
2. 숫자ㆍ부호 또는 문자를 조합하여 전화번호ㆍ전자우편주소 등 수신자의 연락처를 자동으로 만들어 내는 행위
3. 영리목적의 광고성 정보를 전송할 목적으로 전화번호 또는 전자우편주소를 자동으로 등록하는 행위
4. 광고성 정보 전송자의 신원이나 광고 전송 출처를 감추기 위한 각종 행위
5. 영리목적의 광고성 정보를 전송할 목적으로 수신자를 기망하여 회신을 유도하는 각종 행위
전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하는 자는 수신자가 수신거부나 수신동의의 철회를 할 때 발생하는 전화요금 등의 금전적 비용을 수신자가 부담하지 아니하도록 대통령령으로 정하는 바에 따라 필요한 조치를 하여야 한다.
전자적 전송매체를 이용하여 영리목적의 광고성 정보를 전송하려는 자는 수신자가 제1항 및 제3항에 따른 수신동의, 제2항에 따른 수신거부 또는 수신동의 철회에 관한 의사를 표시할 때에는 해당 수신자에게 대통령령으로 정하는 바에 따라 수신동의, 수신거부 또는 수신동의 철회에 대한 처리 결과를 알려야 한다. <개정 2024. 1. 23.>
제1항 또는 제3항에 따라 수신동의를 받은 자는 대통령령으로 정하는 바에 따라 정기적으로 광고성 정보 수신자의 수신동의 여부를 확인하여야 한다.
[전문개정 2014. 5. 28.]
Article 50 (Restrictions on transmission of advertising information for profit-making purpose)
(1) If any person intends to transmit advertising information for profit-making purpose by using an electronic transmission medium, he or she shall obtain express prior consent from an addressee of such information; provided, he or she need not obtain prior consent in any of the following cases: <Amended on Mar. 22, 2016; Jun. 9, 2020>
1. Where a person who has directly collected contact details from the addressee in his or her dealings of goods, etc. intends to transmit advertising information for profit-making purpose on the same kinds of goods, etc. as those he or she manages and has dealt with the addressee within a period prescribed by Presidential Decree;
2. Where a telemarketer under the Act on Door-to-Door Sales informs prospective customers of the collection source of their personal information by voice, and solicits them to buy products or services by means of a telephone call.
(2) Notwithstanding paragraph (1), where an addressee expresses his or her intention to refuse to receive information or revokes his or her prior consent, no person who intends to transmit advertising information for profit-making purpose by using an electronic transmission medium shall transmit advertising information for profit-making purpose.
(3) Notwithstanding paragraph (1), a person who intends to transmit advertising information for profit-making purpose by using an electronic transmission medium during the time between 9:00 pm and 8:00 am of the following day shall obtain express prior consent from the addressee of such information; provided, the forgoing shall not apply to media prescribed by Presidential Decree.
(4) A person who transmits advertising information for profit-making purpose by using an electronic transmission medium shall specify the following matters in advertising information, as prescribed by Presidential Decree:
1. The name and contact details of a sender;
2. Matters regarding measures and methods by which an addressee can readily express his or her intention to refuse to receive information or to revoke his or her consent to receive information.
(5) A person who transmits advertising information for profit-making purpose by using an electronic transmission medium shall not engage in any of the following acts: <Amended on Jan. 23, 2024>
1. Act of evading or preventing addressees from opting out or withdrawing their consent to receive advertising information;
2. Act of automatically generating an addressee's contact information, such as a telephone number and e-mail address, using a combination of numbers, symbols, or letters;
3. Act of automatically registering a telephone number or e-mail address for the purpose of transmitting advertising information for profit-making purpose;
4. Various acts to conceal the identity of the sender of advertising information or the source of the transmission of the advertisement;
5. Various acts to deceive an addressee into responding for the purpose of transmitting advertising information for profit-making purpose.
(6) A person who transmits advertising information for profit-making purpose by using an electronic transmission medium shall take necessary measures so that an addressee does not incur any cost, such as telephone charges, when the addressee refuses to receive or revokes his or her consent to receive such information, as prescribed by Presidential Decree.
(7) A person who intends to transmit advertising information for profit-making purpose using an electronic transmission medium shall, when an addressee expresses his or her intention to consent to the receipt of such information under paragraphs (1) and (3) refuse to receive, or revoke his or her consent to receive, advertising information under paragraph (2), inform the relevant addressee of the outcomes of measures taken in relation to consent to receive, refusal to receive, or revocation of consent to receive, advertising information, as prescribed by Presidential Decree. <Amended on Jan. 23, 2024>
(8) A person who obtains consent to receive advertising information pursuant to paragraph (1) or (3) shall regularly verify whether an addressee of advertising information consents to receive such information, as prescribed by Presidential Decree.
[This Article Wholly Amended on May 28, 2014]
제50조의2 삭제 <2014. 5. 28.>
Article 50-2 Deleted. <May 28, 2014>
제50조의3(영리목적의 광고성 정보 전송의 위탁 등)
영리목적의 광고성 정보의 전송을 타인에게 위탁한 자는 그 업무를 위탁받은 자가 제50조를 위반하지 아니하도록 관리ㆍ감독하여야 한다. <개정 2014. 5. 28.>
제1항에 따라 영리목적의 광고성 정보의 전송을 위탁받은 자는 그 업무와 관련한 법을 위반하여 발생한 손해의 배상책임에서 정보 전송을 위탁한 자의 소속 직원으로 본다. <개정 2020. 6. 9.>
[전문개정 2008. 6. 13.]
Article 50-3 (Entrustment of transmission of advertising information for profit-making purpose)
(1) A person who has entrusted the transmission of advertising information for profit-making purpose to a third party shall control and oversee the third party to ensure that the third party does not violate Article 50. <Amended on May 28, 2014>
(2) A person entrusted with the transmission of advertising information for profit-making purpose under paragraph (1) shall be deemed an employee of a person who has entrusted the transmission of information in determining liability for damages caused by a violation of a statute related to such business affair. <Amended on Jun. 9, 2020>
[This Article Wholly Amended on Jun. 13, 2008]
제50조의4(정보 전송 역무 제공 등의 제한)
정보통신서비스 제공자는 다음 각 호의 어느 하나에 해당하는 경우에 해당 역무의 제공을 거부하는 조치를 할 수 있다.
1. 광고성 정보의 전송 또는 수신으로 역무의 제공에 장애가 일어나거나 일어날 우려가 있는 경우
2. 이용자가 광고성 정보의 수신을 원하지 아니하는 경우
3. 삭제 <2014. 5. 28.>
정보통신서비스 제공자는 제1항 또는 제4항에 따른 거부조치를 하려면 해당 역무 제공의 거부에 관한 사항을 그 역무의 이용자와 체결하는 정보통신서비스 이용계약의 내용에 포함하여야 한다. <개정 2014. 5. 28.>
정보통신서비스 제공자는 제1항 또는 제4항에 따른 거부조치 사실을 그 역무를 제공받는 이용자 등 이해관계인에게 알려야 한다. 다만, 미리 알리는 것이 곤란한 경우에는 거부조치를 한 후 지체 없이 알려야 한다. <개정 2014. 5. 28.>
정보통신서비스 제공자는 이용계약을 통하여 해당 정보통신서비스 제공자가 이용자에게 제공하는 서비스가 제50조 또는 제50조의8을 위반하여 영리목적의 광고성 정보전송에 이용되고 있는 경우 해당 역무의 제공을 거부하거나 정보통신망이나 서비스의 취약점을 개선하는 등 필요한 조치를 강구하여야 한다. <신설 2014. 5. 28.>
[전문개정 2008. 6. 13.]
Article 50-4 (Restrictions on rendering information transmission services)
(1) A provider of information and communications services may take measures to refuse rendering corresponding services in any of the following cases:
1. If transmission or reception of advertising information hinders or is likely to hinder rendering the services;
2. If a user does not want to receive advertising information;
3. Deleted. <May 28, 2014>
(2) If a provider of information and communications services intends to take any measure for refusal under paragraph (1) or (4), he or she shall include matters regarding the refusal of the relevant services in the terms and conditions of a contract for use of information and communications services for which he or she concludes with the user of such services. <Amended on May 28, 2014>
(3) A provider of information and communications services shall inform interested persons, such as users to whom such services are provided, of the fact that he or she has taken measures for refusal under paragraph (1) or (4); provided, where it is impracticable to inform them of the fact in advance, he or she shall inform them of the fact without delay after he or she has taken measures for refusal. <Amended on May 28, 2014>
(4) Where services which a provider of information and communications services provides to users under a contract for use are used for transmitting advertising information for profit-making purpose, in violation of Article 50 or 50-8, the relevant provider of information and communications services shall formulate necessary measures, such as refusal to provide the relevant services or redressing problems of information and communications networks or services. <Added on May 28, 2014>
[This Article Wholly Amended on Jun. 13, 2008]
제50조의5(영리목적의 광고성 프로그램 등의 설치)
정보통신서비스 제공자는 영리목적의 광고성 정보가 보이도록 하거나 개인정보를 수집하는 프로그램을 이용자의 컴퓨터나 그 밖에 대통령령으로 정하는 정보처리장치에 설치하려면 이용자의 동의를 받아야 한다. 이 경우 해당 프로그램의 용도와 삭제방법을 고지하여야 한다.
[전문개정 2008. 6. 13.]
Article 50-5 (Installation of advertising programs for profit-making purpose)
When a provider of information and communications services intends to install a program designed to display advertising information or collect personal information in a user's computer or any other information processing device prescribed by Presidential Decree, he or she shall obtain consent from the user. In such cases, the provider shall notify the purpose of use of the program and the method of deletion.
[This Article Wholly Amended on Jun. 13, 2008]
제50조의6(영리목적의 광고성 정보 전송차단 소프트웨어의 보급 등)
방송미디어통신위원회는 수신자가 제50조를 위반하여 전송되는 영리목적의 광고성 정보를 편리하게 차단하거나 신고할 수 있는 소프트웨어나 컴퓨터프로그램을 개발하여 보급할 수 있다. <개정 2025. 10. 1.>
방송미디어통신위원회는 제1항에 따른 전송차단, 신고 소프트웨어 또는 컴퓨터프로그램의 개발과 보급을 촉진하기 위하여 관련 공공기관ㆍ법인ㆍ단체 등에 필요한 지원을 할 수 있다. <개정 2025. 10. 1.>
방송미디어통신위원회는 정보통신서비스 제공자의 전기통신역무가 제50조를 위반하여 발송되는 영리목적의 광고성 정보 전송에 이용되면 수신자 보호를 위하여 기술개발ㆍ교육ㆍ홍보 등 필요한 조치를 할 것을 정보통신서비스 제공자에게 권고할 수 있다. <개정 2025. 10. 1.>
제1항에 따른 개발ㆍ보급의 방법과 제2항에 따른 지원에 필요한 사항은 대통령령으로 정한다.
[전문개정 2008. 6. 13.]
Article 50-6 (Distribution of software designed to block transmission of advertising information for profit-making purpose)
(1) The Korea Media and Communications Commission may develop and distribute software or computer programs designed for addressees to conveniently block or report any advertising information for profit-making purpose when it is transmitted in violation of Article 50. <Amended on Oct. 1, 2025>
(2) The Korea Media and Communications Commission may provide necessary support to related public agencies, corporations, organizations, or similar for facilitating the development and distribution of software or computer programs for blocking or reporting transmission under paragraph (1). <Amended on Oct. 1, 2025>
(3) If telecommunications services rendered by a provider of information and communications services are used in transmitting advertising information for profit-making purpose in violation of Article 50, the Korea Media and Communications Commission may recommend the provider of information and communications services to take necessary measures, such as development of technology, education, and public relations activities to protect addressees. <Amended on Oct. 1, 2025>
(4) The method of the development and distribution under paragraph (1) and the matters necessary for the support under paragraph (2) shall be prescribed by Presidential Decree.
[This Article Wholly Amended on Jun. 13, 2008]
제50조의7(영리목적의 광고성 정보 게시의 제한)
누구든지 영리목적의 광고성 정보를 인터넷 홈페이지에 게시하려면 인터넷 홈페이지 운영자 또는 관리자의 사전 동의를 받아야 한다. 다만, 별도의 권한 없이 누구든지 쉽게 접근하여 글을 게시할 수 있는 게시판의 경우에는 사전 동의를 받지 아니한다.
영리목적의 광고성 정보를 게시하려는 자는 제1항에도 불구하고 인터넷 홈페이지 운영자 또는 관리자가 명시적으로 게시 거부의사를 표시하거나 사전 동의를 철회한 경우에는 영리목적의 광고성 정보를 게시하여서는 아니 된다.
인터넷 홈페이지 운영자 또는 관리자는 제1항 또는 제2항을 위반하여 게시된 영리목적의 광고성 정보를 삭제하는 등의 조치를 할 수 있다.
[전문개정 2014. 5. 28.]
Article 50-7 (Restrictions on posting of advertising information for profit-making purpose)
(1) Where any person intends to post advertising information for profit-making purpose on a website, he or she shall obtain prior consent from the operator or the manager of a website; provided, in cases of a message board to which any person can have easy access without special authority and on which any person can post his or her message, he or she need not obtain prior consent.
(2) Notwithstanding paragraph (1), where the operator or the manager of a website explicitly expresses his or her intention to refuse to post a notice or to revoke his or her prior consent, no person who intends to post advertising information for profit-making purpose shall post advertising information for profit-making purpose.
(3) The operator or the manager of a website may take measures, such as deletion of advertising information for profit-making purpose posted in violation of paragraph (1) or (2).
[This Article Wholly Amended on May 28, 2014]
제50조의8(불법행위를 위한 광고성 정보 전송금지)
누구든지 정보통신망을 이용하여 이 법 또는 다른 법률에서 이용, 판매, 제공, 유통, 그 밖에 이와 유사한 행위를 금지하는 재화 또는 서비스에 대한 광고성 정보를 전송하여서는 아니 된다. <개정 2024. 1. 23.>
[전문개정 2008. 6. 13.]
Article 50-8 (Prohibition on transmission of advertising information for unlawful acts)
No person shall use a telecommunications network to transmit any advertising information about any goods or services whose use, sale, offering, distribution, or other similar conduct is prohibited by this Act or any other statute. <Amended on Jan. 23, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
제51조(중요 정보의 국외유출 제한 등)
정부는 국내의 산업ㆍ경제 및 과학기술 등에 관한 중요 정보가 정보통신망을 통하여 국외로 유출되는 것을 방지하기 위하여 정보통신서비스 제공자 또는 이용자에게 필요한 조치를 하도록 할 수 있다.
제1항에 따른 중요 정보의 범위는 다음 각 호와 같다.
1. 국가안전보장과 관련된 보안정보 및 주요 정책에 관한 정보
2. 국내에서 개발된 첨단과학 기술 또는 기기의 내용에 관한 정보
정부는 제2항 각 호에 따른 정보를 처리하는 정보통신서비스 제공자에게 다음 각 호의 조치를 하도록 할 수 있다. <개정 2016. 3. 22.>
1. 정보통신망의 부당한 이용을 방지할 수 있는 제도적ㆍ기술적 장치의 설정
2. 정보의 불법파괴 또는 불법조작을 방지할 수 있는 제도적ㆍ기술적 조치
3. 정보통신서비스 제공자가 처리 중 알게 된 중요 정보의 유출을 방지할 수 있는 조치
[전문개정 2008. 6. 13.]
Article 51 (Restrictions to prevent overseas leakage of important information)
(1) The Government may authorize providers or users of information and communications services to take necessary measures to prevent overseas leakage of any important information about industry, economy, science, technology, etc. of this county through information and communications networks.
(2) The scope of the important information under paragraph (1) shall be as follows:
1. Information related to the national security and major policies;
2. Information about details of cutting-edge science and technology or devices developed within this country.
(3) The Government may authorize the providers of information and communications services that manage the information under the subparagraphs of paragraph (2) to take the following measures: <Amended on Mar. 22, 2016>
1. Installation of a systematic or technical device for preventing unlawful use of information and communications networks;
2. Systematic and technical measures for preventing unlawful destruction or manipulation of information;
3. Measures for preventing leakage of important information that providers of information and communications services have learned while managing the information.
[This Article Wholly Amended on Jun. 13, 2008]
제52조(한국인터넷진흥원)
정부는 정보통신망의 고도화(정보통신망의 구축ㆍ개선 및 관리에 관한 사항은 제외한다)와 안전한 이용 촉진 및 방송통신과 관련한 국제협력ㆍ국외진출 지원을 효율적으로 추진하기 위하여 한국인터넷진흥원(이하 "인터넷진흥원"이라 한다)을 설립한다. <개정 2009. 4. 22., 2020. 6. 9.>
인터넷진흥원은 법인으로 한다. <개정 2009. 4. 22.>
인터넷진흥원은 다음 각 호의 사업을 한다. <개정 2009. 4. 22., 2012. 2. 17., 2013. 3. 23., 2014. 11. 19., 2015. 6. 22., 2017. 7. 26., 2020. 2. 4., 2020. 6. 9., 2021. 6. 8., 2022. 6. 10., 2024. 1. 23., 2025. 10. 1.>
1. 정보통신망의 이용 및 보호, 방송통신과 관련한 국제협력ㆍ국외진출 등을 위한 법ㆍ정책 및 제도의 조사ㆍ연구
2. 정보통신망의 이용 및 보호와 관련한 통계의 조사ㆍ분석
3. 정보통신망의 이용에 따른 역기능 분석 및 대책 연구
4. 정보통신망의 이용 및 보호를 위한 홍보 및 교육ㆍ훈련
5. 정보통신망의 정보보호 및 인터넷주소자원 관련 기술 개발 및 표준화
6. 정보보호산업 정책 지원 및 관련 기술 개발과 인력양성
7. 정보보호 관리체계의 인증, 정보보호시스템 평가ㆍ인증, 정보통신망연결기기등의 정보보호인증, 소프트웨어 개발보안 진단 등 정보보호 인증ㆍ평가 등의 실시 및 지원
8. 「개인정보 보호법」에 따른 개인정보 보호를 위한 대책의 연구 및 보호기술의 개발ㆍ보급 지원
9. 「개인정보 보호법」에 따른 개인정보침해 신고센터의 운영
10. 광고성 정보 전송 및 인터넷광고와 관련한 고충의 상담ㆍ처리
11. 정보통신망 침해사고의 처리ㆍ원인분석ㆍ대응체계 운영 및 정보보호 최고책임자를 통한 예방ㆍ대응ㆍ협력 활동
12. 「전자서명법」 제21조에 따른 전자서명인증 정책의 지원
13. 인터넷의 효율적 운영과 이용활성화를 위한 지원
14. 인터넷 이용자의 저장 정보 보호 지원
15. 인터넷 관련 서비스정책 지원
16. 인터넷상에서의 이용자 보호 및 건전 정보 유통 확산 지원
17. 「인터넷주소자원에 관한 법률」에 따른 인터넷주소자원의 관리에 관한 업무
18. 「인터넷주소자원에 관한 법률」 제16조에 따른 인터넷주소분쟁조정위원회의 운영 지원
19. 「정보보호산업의 진흥에 관한 법률」 제25조제7항에 따른 조정위원회의 운영지원
20. 방송통신과 관련한 국제협력ㆍ국외진출 및 국외홍보 지원
21. 본인확인업무 및 연계정보 생성ㆍ처리 관련 정책의 지원
22. 제1호부터 제21호까지의 사업에 부수되는 사업
23. 그 밖에 이 법 또는 다른 법령에 따라 인터넷진흥원의 업무로 정하거나 위탁한 사업이나 과학기술정보통신부장관ㆍ행정안전부장관ㆍ방송미디어통신위원회 또는 다른 행정기관의 장으로부터 위탁받은 사업
인터넷진흥원이 사업을 수행하는 데 필요한 경비는 다음 각 호의 재원으로 충당한다. <개정 2016. 3. 22.>
1. 정부의 출연금
2. 제3항 각 호의 사업수행에 따른 수입금
3. 그 밖에 인터넷진흥원의 운영에 따른 수입금
인터넷진흥원에 관하여 이 법에서 정하지 아니한 사항에 대하여는 「민법」의 재단법인에 관한 규정을 준용한다. <개정 2009. 4. 22.>
인터넷진흥원이 아닌 자는 한국인터넷진흥원의 명칭을 사용하지 못한다. <개정 2009. 4. 22.>
인터넷진흥원의 운영 및 업무수행에 필요한 사항은 대통령령으로 정한다. <개정 2009. 4. 22.>
[전문개정 2008. 6. 13.]
[제목개정 2009. 4. 22.]
Article 52 (Korea Internet and Security Agency)
(1) The Government shall establish the Korea Internet and Security Agency (hereinafter referred to as the "Internet and Security Agency") to upgrade information and communications networks (excluding matters regarding establishment, improvement, and management of information and telecommunications networks), encourage the safe use thereof, and promote the international cooperation and advancement into the overseas market in relation to broadcasting and communications. <Amended on Apr. 22, 2009; Jun. 9, 2020>
(2) The Internet and Security Agency shall be a corporation. <Amended on Apr. 22, 2009>
(3) The Internet and Security Agency shall perform the following business affairs: <Amended on Apr. 22, 2009; Feb. 17, 2012; Mar. 23, 2013; Nov. 19, 2014; Jun. 22, 2015; Jul. 26, 2017; Feb. 4, 2020; Jun. 9, 2020; Jun. 8, 2021; Jun. 10, 2022; Jan. 23, 2024; Oct. 1, 2025>
1. Survey and research of laws, policies, and systems for the use and protection of information and telecommunications networks, promotion of the international cooperation and advancement into the overseas market in relation to broadcasting and communications, etc.;
2. Survey and analysis of statistics regarding the use and protection of information and telecommunications networks;
3. Analysis of negative effects arising from the use of information and telecommunications networks and research on countermeasures;
4. Public relations activities, education, and training for using and protecting information and telecommunications networks;
5. Information protection for information and telecommunications networks, development of technologies regarding the Internet address resources and standardization thereof;
6. Support for policies for the information security industry, development of relevant technology, and fostering of human resources;
7. Implementation of certification and evaluation of information security, such as certification of information security management systems, certification and evaluation of information security systems, certification of information security of devices and the like connected to information and communications networks, and software development security assessment; and the provision of support therefor;
8. Research of countermeasures for protecting personal information, and support for development and dissemination of protective technologies under the Personal Information Protection Act;
9. Operation of a personal information infringement call center under the Personal Information Protection Act;
10. Consultation on and processing of complaints related to transmission of advertising information and online advertisements;
11. Management of cyber security incidents in information and communications networks, analysis of causes thereof, operation of systems for responding thereto; and promotion of chief information security officers' activities to prevent and respond to such incidents and to cooperate each other;
12. Support for policies on electronic signature certification under Article 21 of the Electronic Signature Act;
13. Support for an efficient operation of the Internet and encouragement of wider use thereof;
14. Support for the protection of stored information of the Internet users;
15. Support for service policies pertaining to the Internet;
16. Protection of users and support for the dissemination of sound information on the Internet;
17. Affairs related to the management of Internet address resources under the Internet Address Resources Act;
18. Support for the operation of the Internet Address Dispute Resolution Committee under Article 16 of the Internet Address Resources Act;
19. Support for operation of the conciliation committee under Article 25 (7) of the Act on the Promotion of Information Security Industry;
20. Support for such international cooperation, overseas expansion, and overseas publicity activities as are regarding broadcasting and communications;
21. Support for policies related to identity verification services and to the creation and processing of connecting information;
22. Any other business incidental to the business referred to in subparagraphs 1 through 21;
23. Other business determined to fall under the affairs of, or entrusted to, the Internet and Security Agency in accordance with this Act, or any other statute or regulation, or other business entrusted by the Minister of Science and ICT, the Minister of the Interior and Safety, the Korea Media and Communications Commission, or the head of any other administrative agency.
(4) Expenses necessary for the business affairs of the Internet and Security Agency shall be funded by the following financial resources: <Amended on Mar. 22, 2016>
1. Government’s contributions;
2. Revenues accrued from the business referred to in each subparagraph of paragraph (3);
3. Other revenues accrued from operating the Internet and Security Agency.
(5) Except as provided in this Act, the provisions governing incorporated foundations under the Civil Act shall apply mutatis mutandis to matters regarding the Internet and Security Agency. <Amended on Apr. 22, 2009>
(6) No person, other than the Internet and Security Agency, shall use the name "Korea Internet and Security Agency". <Amended on Apr. 22, 2009>
(7) Matters necessary for the operation of the Internet and Security Agency and performance of its business affairs shall be prescribed by Presidential Decree. <Amended on Apr. 22, 2009>
[This Article Wholly Amended on Jun. 13, 2008]
[Title Amended on Apr. 22, 2009]
제7장 통신과금서비스
CHAPTER VII TELECOMMUNICATIONS BILLING SERVICES
제53조(통신과금서비스제공자의 등록 등)
통신과금서비스를 제공하려는 자는 대통령령으로 정하는 바에 따라 다음 각 호의 사항을 갖추어 과학기술정보통신부장관에게 등록하여야 한다. <개정 2008. 2. 29., 2013. 3. 23., 2017. 7. 26.>
1. 재무건전성
2. 통신과금서비스이용자보호계획
3. 업무를 수행할 수 있는 인력과 물적 설비
4. 사업계획서
제1항에 따라 등록할 수 있는 자는 「상법」제170조에 따른 회사 또는 「민법」제32조에 따른 법인으로서 자본금ㆍ출자총액 또는 기본재산이 5억원 이상의 범위에서 대통령령으로 정하는 금액 이상이어야 한다.
통신과금서비스제공자는 「전기통신사업법」 제22조에도 불구하고 부가통신사업자의 신고를 하지 아니할 수 있다. <개정 2010. 3. 22.>
「전기통신사업법」 제23조부터 제26조까지의 규정은 통신과금서비스제공자의 등록사항의 변경, 사업의 양도ㆍ양수 또는 합병ㆍ상속, 사업의 승계, 사업의 휴업ㆍ폐업ㆍ해산 등에 준용한다. 이 경우 "별정통신사업자"는 "통신과금서비스제공자"로 보고, "별정통신사업"은 "통신과금서비스제공업"으로 본다. <개정 2010. 3. 22., 2020. 6. 9.>
제1항에 따른 등록의 세부요건, 절차, 그 밖에 필요한 사항은 대통령령으로 정한다.
[본조신설 2007. 12. 21.]
[종전 제53조는 제62조로 이동 <2007. 12. 21.>]
Article 53 (Registration of providers of telecommunications billing services)
(1) A person who intends to render telecommunications billing services shall meet the following requirements and file for registration with the Minister of Science and ICT, as prescribed by Presidential Decree: <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017>
1. Financial soundness;
2. A plan for protection of users of telecommunications billing services;
3. Human resources and physical facilities required for conducting the business;
4. A business plan.
(2) A person eligible for the registration under paragraph (1) shall be either a company under Article 170 of the Commercial Act or a corporation under Article 32 of the Civil Act; and the total amount of its capital, contributions, or fundamental property shall be at least the amount prescribed by Presidential Decree, not less than 500 million won.
(3) Notwithstanding Article 22 of the Telecommunications Business Act, a provider of telecommunications billing services need not file a report of a value-added telecommunications business operator. <Amended on Mar. 22, 2010>
(4) Articles 23 through 26 of the Telecommunications Business Act shall apply mutatis mutandis to the modification of registered matters of a provider of telecommunications billing services, the transfer of business or acquisition by transfer of business, or the merger or inheritance of business, the succession to business, and the temporary closure, permanent closure, dissolution, or similar of business of a provider of telecommunications billing services. In such cases, "special telecommunications business operator" shall be construed as "provider of telecommunications billing services", and "special telecommunications business" as "telecommunications billing services". <Amended on Mar. 22, 2010; Jun. 9, 2020>
(5) Detailed requirements and procedures for the registration under paragraph (1) and other necessary matters shall be prescribed by Presidential Decree.
[This Article Added on Dec. 21, 2007]
[Previous Article 53 moved to Article 62 <Dec. 21, 2007>]
제54조(등록의 결격사유)
다음 각 호의 어느 하나에 해당하는 자는 제53조에 따른 등록을 할 수 없다. <개정 2008. 2. 29., 2013. 3. 23., 2017. 7. 26., 2020. 6. 9.>
1. 제53조제4항에 따라 사업을 폐업한 날부터 1년이 지나지 아니한 법인 및 그 사업이 폐업될 당시 그 법인의 대주주(대통령령으로 정하는 출자자를 말한다. 이하 같다)이었던 자로서 그 폐업일부터 1년이 지나지 아니한 자
2. 제55조제1항에 따라 등록이 취소된 날부터 3년이 지나지 아니한 법인 및 그 취소 당시 그 법인의 대주주이었던 자로서 그 취소가 된 날부터 3년이 지나지 아니한 자
3. 「채무자 회생 및 파산에 관한 법률」에 따른 회생절차 중에 있는 법인 및 그 법인의 대주주
4. 금융거래 등 상거래를 할 때 약정한 기일 내에 채무를 변제하지 아니한 자로서 과학기술정보통신부장관이 정하는 자
5. 제1호부터 제4호까지의 규정에 해당하는 자가 대주주인 법인
[본조신설 2007. 12. 21.]
[종전 제54조는 제63조로 이동 <2007. 12. 21.>]
Article 54 (Disqualification from filing for registration)
Any of the following persons shall be disqualified from filing for registration under Article 53: <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
1. A corporation for which 1 year has not elapsed since its business was permanently closed pursuant to Article 53 (4) or a person who was a majority shareholder (referring to an investor prescribed by Presidential Decree; hereinafter the same shall apply) of such corporation as at the time its business was permanently closed, if 1 year has not elapsed since the date of permanent closure of its business;
2. A corporation for which 3 years have not elapsed since its registration was revoked pursuant to Article 55 (1) or a person who was a majority shareholder of such corporation as at the time its registration was revoked, if 3 years have not elapsed since the date of revocation;
3. A corporation that is still under rehabilitation proceedings under the Debtor Rehabilitation and Bankruptcy Act or a majority shareholder of such corporation;
4. A person who did not perform his or her obligations within an agreed time limit in conducting a banking transaction or any other commercial transaction and who is prescribed by the Minister of Science and ICT;
5. A corporation any of whose majority shareholders falls under subparagraphs 1 through 4.
[This Article Added on Dec. 21, 2007]
[Previous Article 54 Moved to Article 63 <Dec. 21, 2007>]
제55조(등록의 취소명령)
과학기술정보통신부장관은 통신과금서비스제공자가 거짓이나 그 밖의 부정한 방법으로 등록을 한 때에는 등록을 취소하여야 한다. <개정 2015. 6. 22., 2017. 7. 26.>
제1항에 따른 처분의 절차, 그 밖에 필요한 사항은 대통령령으로 정한다. <개정 2015. 6. 22.>
[본조신설 2007. 12. 21.]
[제목개정 2015. 6. 22.]
[종전 제55조는 제64조로 이동 <2007. 12. 21.>]
Article 55 (Orders to revoke registration)
(1) Where a provider of telecommunications billing services files for registration by fraud or other improper means, the Minister of Science and ICT shall revoke the registration. <Amended on Jun. 22, 2015; Jul. 26, 2017>
(2) The procedures for the disposition under paragraph (1) and other necessary matters shall be prescribed by Presidential Decree. <Amended on Jun. 22, 2015>
[This Article Added on Dec. 21, 2007]
[Title Amended on Jun. 22, 2015]
[Previous Article 55 moved to Article 64 <Dec. 21, 2007>]
제56조(약관의 신고 등)
통신과금서비스제공자는 통신과금서비스에 관한 약관을 정하여 과학기술정보통신부장관에게 신고(변경신고를 포함한다)하여야 한다. <개정 2008. 2. 29., 2013. 3. 23., 2017. 7. 26.>
과학기술정보통신부장관은 제1항에 따른 약관이 통신과금서비스이용자의 이익을 침해할 우려가 있다고 판단되는 경우에는 통신과금서비스제공자에게 약관의 변경을 권고할 수 있다. <개정 2008. 2. 29., 2013. 3. 23., 2017. 7. 26.>
[본조신설 2007. 12. 21.]
[종전 제56조는 제65조로 이동 <2007. 12. 21.>]
Article 56 (Reporting on terms and conditions)
(1) Every provider of telecommunications billing services shall prepare terms and conditions on telecommunications billing services and report it to the Minister of Science and ICT (including reporting on a revision thereto). <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017>
(2) If it is found that the terms and conditions under paragraph (1) are likely to undermine interests of users of telecommunications billing services, the Minister of Science and ICT may recommend the relevant provider of telecommunications billing services to revise the terms and conditions. <Amended on Feb. 29, 2008; Mar. 23, 2013; Jul. 26, 2017>
[This Article Added on Dec. 21, 2007]
[Previous Article 56 moved to Article 65 <Dec. 21, 2007>]
제57조(통신과금서비스의 안전성 확보 등)
통신과금서비스제공자는 통신과금서비스가 안전하게 제공될 수 있도록 선량한 관리자로서의 주의의무를 다하여야 한다. <개정 2014. 5. 28.>
통신과금서비스제공자는 통신과금서비스를 통한 거래의 안전성과 신뢰성을 확보하기 위하여 대통령령으로 정하는 바에 따라 업무처리지침의 제정 및 회계처리 구분 등의 관리적 조치와 정보보호시스템 구축 등의 기술적 조치를 하여야 한다.
[본조신설 2007. 12. 21.]
[종전 제57조는 제66조로 이동 <2007. 12. 21.>]
Article 57 (Securing safety in telecommunications billing services)
(1) Every provider of telecommunications billing services shall perform his or her duty to pay attention as a good manager so that telecommunications billing services may be provided in a safe manner. <Amended on May 28, 2014>
(2) Every provider of telecommunications billing services shall take administrative measures, including formulation of guidelines for work process and classification of accounts, and technical measures, including establishment of an information security system, to secure safety and reliability of transactions through telecommunications billing services, as prescribed by Presidential Decree.
[This Article Added on Dec. 21, 2007]
[Previous Article 57 moved to Article 66 <Dec. 21, 2007>]
제58조(통신과금서비스이용자의 권리 등)
통신과금서비스제공자는 재화등의 판매ㆍ제공의 대가가 발생한 때 및 대가를 청구할 때에 통신과금서비스이용자에게 다음 각 호의 사항을 고지하여야 한다. <개정 2011. 4. 5., 2014. 5. 28.>
1. 통신과금서비스 이용일시
2. 통신과금서비스를 통한 구매ㆍ이용의 거래 상대방(통신과금서비스를 이용하여 그 대가를 받고 재화 또는 용역을 판매ㆍ제공하는 자를 말한다. 이하 "거래 상대방"이라 한다)의 상호와 연락처
3. 통신과금서비스를 통한 구매ㆍ이용 금액과 그 명세
4. 이의신청 방법 및 연락처
통신과금서비스제공자는 통신과금서비스이용자가 구매ㆍ이용 내역을 확인할 수 있는 방법을 제공하여야 하며, 통신과금서비스이용자가 구매ㆍ이용 내역에 관한 서면(전자문서를 포함한다. 이하 같다)을 요청하는 경우에는 그 요청을 받은 날부터 2주 이내에 이를 제공하여야 한다.
통신과금서비스이용자는 통신과금서비스가 자신의 의사에 반하여 제공되었음을 안 때에는 통신과금서비스제공자에게 이에 대한 정정을 요구할 수 있으며(통신과금서비스이용자의 고의 또는 중과실이 있는 경우는 제외한다), 통신과금서비스제공자는 이용자의 정정요구가 이유 있을 경우 판매자에 대한 이용 대금의 지급을 유보하고 그 정정 요구를 받은 날부터 2주 이내에 처리 결과를 알려 주어야 한다. <개정 2014. 5. 28.>
통신과금서비스제공자는 통신과금서비스에 관한 기록을 5년 이내의 범위에서 대통령령으로 정하는 기간 동안 보존하여야 한다.
통신과금서비스제공자(제2조제1항제10호가목의 업무를 제공하는 자)는 통신과금서비스를 제공하거나 이용한도액을 증액할 경우에는 미리 해당 통신과금서비스이용자의 동의를 받아야 한다. <신설 2014. 5. 28.>
통신과금서비스제공자(제2조제1항제10호가목의 업무를 제공하는 자)는 약관을 변경하는 때에는 변경되는 약관의 시행일 1개월 전에 이용자에게 통지하여야 한다. 이 경우 변경되는 약관에 대하여 이의가 있는 이용자는 통신과금서비스에 관한 계약을 해지할 수 있다. <신설 2014. 5. 28.>
제2항에 따라 통신과금서비스제공자가 제공하여야 하는 구매ㆍ이용내역의 대상기간, 종류 및 범위, 제4항에 따라 통신과금서비스제공자가 보존하여야 하는 기록의 종류 및 보존방법, 제6항에 따른 약관변경에 관한 통지의 방법 및 이의기간ㆍ절차 등 계약해지에 필요한 사항은 대통령령으로 정한다. <개정 2014. 5. 28.>
제5항에 따른 동의의 방법 등에 필요한 사항은 과학기술정보통신부장관이 정하여 고시한다. <신설 2014. 5. 28., 2017. 7. 26.>
과학기술정보통신부장관은 통신과금서비스가 통신과금서비스이용자의 의사에 반하여 제공되지 아니하도록 결제방식 등에 관한 세부적인 사항을 정하여 고시할 수 있다. <신설 2014. 5. 28., 2017. 7. 26.>
[본조신설 2007. 12. 21.]
[종전 제58조는 제67조로 이동 <2007. 12. 21.>]
Article 58 (Rights of users of telecommunications billing services)
(1) When the price for goods, etc. sold or provided must be paid, or a provider of telecommunications billing services charges the price therefor; such provider shall notify the users of telecommunications billing services of the following: <Amended on Apr. 5, 2011; May 28, 2014>
1. Date and time telecommunications billing services are used;
2. Trade name and contact information of the other party with respect to purchasing or using any good or service through telecommunications billing services (referring to a person who sells or provides any good or service in a transaction through telecommunications billing services; hereinafter referred to as "other party to a transaction");
3. Amount purchased or used through telecommunications billing services and details thereof;
4. Methods for raising an objection and contact information.
(2) A provider of telecommunications billing services shall provide users of telecommunications billing services with a method by which users can verify the details of purchase and use and shall also furnish a user, upon request, with a written statement on the details of purchase and use (including an electronic document; hereinafter the same shall apply) within 2 weeks from the date of the request.
(3) A user of telecommunications billing services discovers that the telecommunications billing services have been rendered against his or her will, the user may request the provider of telecommunications billing services to make corrections (excluding where there is an intentional act or negligence on the part of the user of the telecommunications billing services), and where the provider of telecommunications billing services finds that the user's request for correction is reasonable, the provider shall withhold the payment of the price for use to a seller and shall notify the user of the results thereof within 2 weeks from the date of the request for correction. <Amended on May 28, 2014>
(4) Every provider of telecommunications billing services shall preserve records of telecommunications billing services during the period, within 5 years, prescribed by Presidential Decree.
(5) Where a provider of telecommunications billing services (referring to a person who provides services under Article 2 (1) 10 (a)) provides telecommunications billing services or increases the upper limits of use, he or she shall obtain consent from a user of the relevant telecommunications billing services in advance. <Added on May 28, 2014>
(6) When a provider of telecommunications billing services (referring to a person who provides services under Article 2 (1) 10 (a)) amends the terms and conditions, he or she shall notify users of the amendment thereof 1 month prior to the effective date of the amended terms and conditions. In such cases, a user who has an objection to the amended terms and conditions may terminate the contract for telecommunications billing services. <Added on May 28, 2014>
(7) The period, types, and scope of the details of purchase and use that a provider of telecommunications billing services should provide pursuant to paragraph (2); the types of records that a provider of telecommunications billing services should preserve pursuant to paragraph (4) and the methods for preserving such records; the methods for notifying amendment to the terms and conditions pursuant to paragraph (6); and matters necessary for terminating the contract, such as the period and procedures for raising an objection; shall be prescribed by Presidential Decree. <Amended on May 28, 2014>
(8) The Minister of Science and ICT shall prescribe and provide public notice of matters necessary for methods for giving consent, etc. under paragraph (5). <Added on May 28, 2014; Jul. 26, 2017>
(9) The Minister of Science and ICT may prescribe and provide public notice of detailed matters regarding the methods for settling accounts, etc. so that telecommunications billing services are not provided against the will of users of telecommunications billing services. <Added on May 28, 2014; Jul. 26, 2017>
[This Article Added on Dec. 21, 2007]
[Previous Article 58 Moved to Article 67 <Dec. 21, 2007>]
제58조의2(구매자정보 제공 요청 등)
통신과금서비스이용자는 자신의 의사에 따라 통신과금서비스가 제공되었는지 여부를 확인하기 위하여 필요한 경우에는 거래 상대방에게 재화등을 구매ㆍ이용한 자의 이름과 생년월일에 대한 정보(이하 "구매자정보"라 한다)의 제공을 요청할 수 있다. 이 경우 구매자정보 제공 요청을 받은 거래 상대방은 정당한 사유가 없으면 그 요청을 받은 날부터 3일 이내에 이를 제공하여야 한다.
제1항에 따라 구매자정보를 제공받은 통신과금서비스이용자는 해당 정보를 본인 여부를 확인하거나 고소ㆍ고발을 위하여 수사기관에 제출하기 위한 목적으로만 사용하여야 한다.
그 밖에 구매자정보 제공 요청의 내용과 절차 등에 필요한 사항은 대통령령으로 정한다.
[본조신설 2018. 6. 12.]
Article 58-2 (Request for providing information about purchasers)
(1) Any user of telecommunications billing services may request the counter-party to a transaction to provide information about the name and date of birth of a person who purchased or used goods, etc. (hereinafter referred to as "purchaser information") if necessary to ascertain that telecommunications billing services have been provided according to his or her intention. In such cases, the counter-party so requested to provide purchaser information shall provide such information within 3 days from the date of the request without good cause.
(2) A user of telecommunications billing services shall use the purchaser information provided pursuant to paragraph (1) only for the purpose of identifying the relevant purchaser or submitting such information to an investigative agency in filing a criminal complaint or report.
(3) Other matters necessary relating to the content of, and the procedures for, requests for purchaser information shall be prescribed by Presidential Decree.
[This Article Added on Jun. 12, 2018]
제59조(분쟁 조정 및 해결 등)
통신과금서비스제공자는 통신과금서비스에 대한 이용자의 권익을 보호하기 위하여 자율적인 분쟁 조정 및 해결 등을 시행하는 기관 또는 단체를 설치ㆍ운영할 수 있다. <개정 2018. 6. 12., 2020. 6. 9.>
제1항에 따른 분쟁 조정 및 해결 등을 시행하는 기관 또는 단체는 분쟁 조정 및 해결 등을 위하여 필요하다고 인정하는 경우 통신과금서비스이용자의 동의를 받아 구매자정보 제공 요청을 대행할 수 있다. 이 경우 구매자정보 제공 요청 등에 대하여는 제58조의2를 준용한다. <신설 2018. 6. 12.>
통신과금서비스제공자는 대통령령으로 정하는 바에 따라 통신과금서비스와 관련한 통신과금서비스이용자의 이의신청 및 권리구제를 위한 절차를 마련하여야 하고, 통신과금서비스 계약을 체결하는 경우 이를 이용약관에 명시하여야 한다. <개정 2014. 5. 28., 2018. 6. 12.>
[본조신설 2007. 12. 21.]
[제목개정 2018. 6. 12.]
[종전 제59조는 제68조로 이동 <2007. 12. 21.>]
Article 59 (Mediation in and resolution of disputes)
(1) Any provider of telecommunications billing services may establish and operate an institution or organization to autonomously mediate, resolve, or otherwise address disputes to protect rights and interests of users of telecommunications billing services. <Amended on Jun. 12, 2018; Jun. 9, 2020>
(2) If deemed necessary for mediating, resolving, or otherwise addressing disputes, an organization or institution authorized to mediate and resolve disputes under paragraph (1) may request purchaser information on behalf of a user of telecommunications billing services with consent of the user. In such cases, Article 58-2 shall apply mutatis mutandis to the request for purchaser information, etc. <Added on Jun. 12, 2018>
(3) Every provider of telecommunications billing services shall prepare a procedure for raising an objection by users of telecommunications billing services in connection with the services and redressing damages to their rights, as prescribed by Presidential Decree, and where the provider enters into a contract for telecommunications billing services, the provider shall stipulate such procedure in the terms and conditions of use. <Amended on May 28, 2014; Jun. 12, 2018>
[This Article Added on Dec. 21, 2007]
[Title Amended on Jul. 12, 2018]
[Previous Article 59 Moved to Article 68 <Dec. 21, 2007>]
제60조(손해배상 등)
통신과금서비스제공자는 통신과금서비스의 제공과 관련하여 통신과금서비스이용자에게 손해가 발생한 경우에 그 손해를 배상하여야 한다. 다만, 그 손해의 발생이 통신과금서비스이용자의 고의 또는 중과실로 인한 경우에는 그러하지 아니하다. <개정 2020. 6. 9.>
제1항에 따라 손해배상을 하는 경우에는 손해배상을 받을 자와 협의하여야 한다. <개정 2020. 6. 9.>
제2항에 따른 손해배상에 관한 협의가 성립되지 아니하거나 협의를 할 수 없는 경우에는 당사자는 방송미디어통신위원회에 재정을 신청할 수 있다. <개정 2008. 2. 29., 2025. 10. 1.>
[본조신설 2007. 12. 21.]
[종전 제60조는 제69조로 이동 <2007. 12. 21.>]
Article 60 (Liability for damages)
(1) A provider of telecommunications billing services shall be liable for damages caused to a user of the telecommunications billing services while rendering the services; provided, the same shall not apply where the damages were caused by intention or gross negligence on the part of the user of the telecommunications billing services. <Amended on Jun. 9, 2020>
(2) A provider of telecommunications billing services shall negotiate with the claimant to damages for agreement on compensation for the damages under paragraph (1). <Amended on Jun. 9, 2020>
(3) If parties fail to or are unable to reach an agreement on compensation for damages under paragraph (2), either party may file an application for decision with the Korea Media and Communications Commission. <Amended on Feb. 29, 2008; Oct. 1, 2025>
[This Article Added on Dec. 21, 2007]
[Previous Article 60 moved to Article 69 <Dec. 21, 2007>]
제61조(통신과금서비스의 이용제한)
과학기술정보통신부장관은 통신과금서비스제공자에게 다음 각 호의 어느 하나에 해당하는 자에 대한 서비스의 제공을 거부, 정지 또는 제한하도록 명할 수 있다. <개정 2008. 2. 29., 2011. 9. 15., 2013. 3. 23., 2017. 7. 26.>
1. 「청소년 보호법」 제16조를 위반하여 청소년유해매체물을 청소년에게 판매ㆍ대여ㆍ제공하는 자
2. 다음 각 목의 어느 하나에 해당하는 수단을 이용하여 통신과금서비스이용자로 하여금 재화등을 구매ㆍ이용하게 함으로써 통신과금서비스이용자의 이익을 현저하게 저해하는 자
가. 제50조를 위반한 영리목적의 광고성 정보 전송
나. 통신과금서비스이용자에 대한 기망 또는 부당한 유인
3. 이 법 또는 다른 법률에서 금지하는 재화등을 판매ㆍ제공하는 자
[본조신설 2007. 12. 21.]
[종전 제61조는 제70조로 이동 <2007. 12. 21.>]
Article 61 (Restrictions on use of telecommunications billing services)
The Minister of Science and ICT may order a provider of telecommunications billing services to deny, suspend, or place a restriction on, the services against any of the following persons: <Amended on Feb. 29, 2008; Sep. 15, 2011; Mar. 23, 2013; Jul. 26, 2017>
1. A person who sells, lends, or provides any media product harmful to youths to a youth in violation of Article 16 of the Youth Protection Act;
2. A person who undermines interests of users of telecommunications billing services seriously by enticing the users to purchase or use goods or services in any of the following means:
(a) Transmitting any advertising information for profit-making purpose in violation of Article 50;
(b) Deceiving or enticing users of telecommunications billing services wrongfully;
3. A person who sells or renders goods or services prohibited by this Act or any other statute.
[This Article Added on Dec. 21, 2007]
[Previous Article 61 Moved to Article 70 <Dec. 21, 2007>]
제8장 국제협력
CHAPTER VIII INTERNATIONAL COOPERATION
제62조(국제협력)
정부는 다음 각 호의 사항을 추진할 때 다른 국가 또는 국제기구와 상호 협력하여야 한다.
1. 삭제 <2020. 2. 4.>
2. 정보통신망에서의 청소년 보호를 위한 업무
3. 정보통신망의 안전성을 침해하는 행위를 방지하기 위한 업무
4. 그 밖에 정보통신서비스의 건전하고 안전한 이용에 관한 업무
[전문개정 2008. 6. 13.]
Article 62 (International cooperation)
The Government shall cooperate reciprocally with other nations or international organizations in performing the following affairs:
1. Deleted; <Feb. 4, 2020>
2. Affairs for the protection of youths in information and communications networks;
3. Affairs for the prevention of acts that undermine safety of information and communications networks;
4. Other affairs for the facilitation of sounder and safer use of information and communications services.
[This Article Wholly Amended on Jun. 13, 2008]
제63조 삭제 <2020. 2. 4.>
Article 63 Deleted. <Feb. 4, 2020>
제63조의2 삭제 <2020. 2. 4.>
Article 63-2 Deleted. <Feb. 4, 2020>
제9장 보칙
CHAPTER IX SUPPLEMENTARY PROVISIONS
제64조(자료의 제출 등)
과학기술정보통신부장관 또는 방송미디어통신위원회는 다음 각 호의 어느 하나에 해당하는 경우에는 정보통신서비스 제공자(국내대리인을 포함한다. 이하 이 조에서 같다)에게 관계 물품ㆍ서류 등을 제출하게 할 수 있다. <개정 2011. 3. 29., 2012. 2. 17., 2013. 3. 23., 2017. 7. 26., 2018. 9. 18., 2020. 2. 4., 2025. 10. 1.>
1. 이 법에 위반되는 사항을 발견하거나 혐의가 있음을 알게 된 경우
2. 이 법의 위반에 대한 신고를 받거나 민원이 접수된 경우
2의2. 이용자 정보의 안전성과 신뢰성 확보를 현저히 해치는 사건ㆍ사고 등이 발생하였거나 발생할 가능성이 있는 경우
3. 그 밖에 이용자 보호를 위하여 필요한 경우로서 대통령령으로 정하는 경우
방송미디어통신위원회는 이 법을 위반하여 영리목적 광고성 정보를 전송한 자에게 다음 각 호의 조치를 하기 위하여 정보통신서비스 제공자에게 해당 광고성 정보 전송자의 성명ㆍ주소ㆍ주민등록번호ㆍ이용기간 등에 대한 자료의 열람이나 제출을 요청할 수 있다. <개정 2020. 2. 4., 2025. 10. 1.>
1. 제4항에 따른 시정조치
2. 제76조에 따른 과태료 부과
3. 그 밖에 이에 준하는 조치
과학기술정보통신부장관 또는 방송미디어통신위원회는 정보통신서비스 제공자가 제1항 및 제2항에 따른 자료를 제출하지 아니하거나 이 법을 위반한 사실이 있다고 인정되면 소속 공무원에게 정보통신서비스 제공자, 해당 법 위반 사실과 관련한 관계인의 사업장에 출입하여 업무상황, 장부 또는 서류 등을 검사하도록 할 수 있다. <개정 2011. 3. 29., 2013. 3. 23., 2016. 3. 22., 2017. 7. 26., 2020. 2. 4., 2025. 10. 1.>
과학기술정보통신부장관 또는 방송미디어통신위원회는 이 법을 위반한 정보통신서비스 제공자에게 해당 위반행위의 중지나 시정을 위하여 필요한 시정조치를 명할 수 있고, 시정조치의 명령을 받은 정보통신서비스 제공자에게 시정조치의 명령을 받은 사실을 공표하도록 할 수 있다. 이 경우 공표의 방법ㆍ기준 및 절차 등에 필요한 사항은 대통령령으로 정한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2020. 2. 4., 2025. 10. 1.>
과학기술정보통신부장관 또는 방송미디어통신위원회는 제4항에 따라 필요한 시정조치를 명한 경우에는 시정조치를 명한 사실을 공개할 수 있다. 이 경우 공개의 방법ㆍ기준 및 절차 등에 필요한 사항은 대통령령으로 정한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
과학기술정보통신부장관 또는 방송미디어통신위원회가 제1항 및 제2항에 따라 자료 등의 제출 또는 열람을 요구할 때에는 요구사유, 법적 근거, 제출시한 또는 열람일시, 제출ㆍ열람할 자료의 내용 등을 구체적으로 밝혀 서면(전자문서를 포함한다)으로 알려야 한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
제3항에 따른 검사를 하는 경우에는 검사 시작 7일 전까지 검사일시, 검사이유 및 검사내용 등에 대한 검사계획을 해당 정보통신서비스 제공자에게 알려야 한다. 다만, 긴급한 경우나 사전통지를 하면 증거인멸 등으로 검사목적을 달성할 수 없다고 인정하는 경우에는 그 검사계획을 알리지 아니한다. <개정 2020. 2. 4.>
제3항에 따라 검사를 하는 공무원은 그 권한을 표시하는 증표를 지니고 이를 관계인에게 내보여야 하며, 출입할 때 성명ㆍ출입시간ㆍ출입목적 등이 표시된 문서를 관계인에게 내주어야 한다.
과학기술정보통신부장관 또는 방송미디어통신위원회는 제1항부터 제3항까지의 규정에 따라 자료 등을 제출받거나 열람 또는 검사한 경우에는 그 결과(조사 결과 시정조치명령 등의 처분을 하려는 경우에는 그 처분의 내용을 포함한다)를 해당 정보통신서비스 제공자에게 서면으로 알려야 한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2020. 2. 4., 2025. 10. 1.>
과학기술정보통신부장관 또는 방송미디어통신위원회는 제1항부터 제4항까지의 규정에 따른 자료의 제출 요구 및 검사 등을 위하여 인터넷진흥원의 장에게 기술적 자문을 하거나 그 밖에 필요한 지원을 요청할 수 있다. <개정 2009. 4. 22., 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
제1항부터 제3항까지의 규정에 따른 자료 등의 제출 요구, 열람 및 검사 등은 이 법의 시행을 위하여 필요한 최소한의 범위에서 하여야 하며 다른 목적을 위하여 남용하여서는 아니 된다.
[전문개정 2008. 6. 13.]
Article 64 (Submission of data)
(1) The Minister of Science and ICT or the Korea Media and Communications Commission may require a provider of information and communications services (including a domestic agent; hereafter in this Article the same shall apply) to submit related articles, documents, and others in any of the following cases: <Amended on Mar. 29, 2011; Feb. 17, 2012; Mar. 23, 2013; Jul. 26, 2017; Sep. 18, 2018; Feb. 4, 2020; Oct. 1, 2025>
1. Where the Minister or the Commission becomes aware of a violation or suspected violation of this Act;
2. Where the Minister or the Commission receives a report or petition on a violation of this Act;
2-2. Where an event, accident, or similar occurs or is likely to occur that noticeably damages safety and reliability of user information;
3. Where there is any other ground prescribed by Presidential Decree to believe that it is necessary for the protection of users.
(2) When the Korea Media and Communications Commission intends to take the following measures against a person who transmitted any advertising information for profit-making purpose in violation of this Act, it may request a provider of information and communications services to let it peruse or to submit data of the person who transmitted the advertising information, such as the name, address, and resident registration number of the person and the period for access: <Amended on Feb. 4, 2020; Oct. 1, 2025>
1. Corrective measures under paragraph (4);
2. Imposition of administrative fines under Article 76;
3. Any similar measures.
(3) If a provider of information and communications services fails to submit data under paragraph (1) or (2) or if it is found that a provider of information and communications services has violated this Act, the Minister of Science and ICT or the Korea Media and Communications Commission may assign public officials under his, her, or its control to enter the place of business of the person concerned related to such violation of this Act, including the provider of information and communications services, for inspecting the current status of business, account books, documents, and others. <Amended on Mar. 29, 2011; Mar. 23, 2013; Mar. 22, 2016; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(4) The Minister of Science and ICT or the Korea Media and Communications Commission may order a provider of information and communications services who has violated this Act to take corrective measures as necessary to stop or correct the violation and may also require a provider of information and communications services who has been ordered to take corrective measures to announce to the public the fact that he or she received the order to take such corrective measures. In such cases, the matters necessary for the methods, guidelines, and procedures for the public announcement and other related matters shall be prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(5) In cases of issuing an order to take corrective measures as necessary pursuant to paragraph (4), the Minister of Science and ICT or the Korea Media and Communications Commission may disclose to the public the issuance of the order to take corrective measures. In such cases, the matters necessary for the methods, guidelines, and procedures for the public disclosure and other related matters shall be prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(6) When demanding submission or perusal of data or other materials pursuant to paragraph (1) or (2), the Minister of Science and ICT or the Korea Media and Communications Commission shall give a written notice (including an electronic document), specifically stating the reasons and legal authority for such demand, the time limit for submission or the date and time for perusal, the details of data subject to the submission or perusal, and other related matters. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(7) When an inspection under paragraph (3) is to be conducted, the plan for the inspection, including the date and time of, and the reasons for and details of, the inspection, shall be notified to the relevant provider of information and communications services not later than 7 days before the commencement of the inspection; provided, the plan for such inspection shall not be notified in an emergency case or if it is deemed impossible to accomplish the purposes of the inspection because of anticipated destruction of evidence or any other factor if a prior notice is given. <Amended on Feb. 4, 2020>
(8) The public officials who conduct an inspection pursuant to paragraph (3) shall carry an identification indicating their authority with them to present it to people concerned, and shall deliver to the people concerned a document stating their names, the time and purposes of access, and other related matters, whenever they access to a place of business.
(9) In cases of receiving, perusing, or inspecting data or any other material submitted pursuant to paragraphs (1) through (3), the Minister of Science and ICT or the Korea Media and Communications Commission shall notify the relevant provider of information and communications services of the results thereof (including the details of disposition, in cases of intending to make a disposition, such as an order to take corrective measures, as a result of the inspection) in writing. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(10) The Minister of Science and ICT or the Korea Media and Communications Commission may ask technical advice or any other support of the head of the Internet and Security Agency as necessary in demanding submission of data or conducting an inspection pursuant to paragraphs (1) through (4). <Amended on Apr. 22, 2009; Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(11) Demand for submission of data or any other material, and perusal and inspection thereof under paragraphs (1) through (3) shall be limited to the least extent necessary for the enforcement of this Act and shall be not abused for any other purpose.
[This Article Wholly Amended on Jun. 13, 2008]
제64조의2(자료 등의 보호 및 폐기)
과학기술정보통신부장관 또는 방송미디어통신위원회는 정보통신서비스 제공자로부터 제64조에 따라 제출되거나 수집된 서류ㆍ자료 등에 대한 보호 요구를 받으면 이를 제3자에게 제공하거나 일반에게 공개하여서는 아니 된다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2020. 2. 4., 2025. 10. 1.>
과학기술정보통신부장관 또는 방송미디어통신위원회는 정보통신망을 통하여 자료의 제출 등을 받은 경우나 수집한 자료 등을 전자화한 경우에는 개인정보ㆍ영업비밀 등이 유출되지 아니하도록 제도적ㆍ기술적 보안조치를 하여야 한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
과학기술정보통신부장관 또는 방송미디어통신위원회는 다른 법률에 특별한 규정이 있는 경우 외에 다음 각 호의 어느 하나에 해당하는 사유가 발생하면 제64조에 따라 제출되거나 수집된 서류ㆍ자료 등을 즉시 폐기하여야 한다. 제65조에 따라 과학기술정보통신부장관 또는 방송미디어통신위원회의 권한의 전부 또는 일부를 위임 또는 위탁받은 자도 또한 같다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
1. 제64조에 따른 자료제출 요구, 출입검사, 시정명령 등의 목적이 달성된 경우
2. 제64조제4항에 따른 시정조치명령에 불복하여 행정심판이 청구되거나 행정소송이 제기된 경우에는 해당 행정쟁송절차가 끝난 경우
3. 제76조제4항에 따른 과태료 처분이 있고 이에 대한 이의제기가 없는 경우에는 같은 조 제5항에 따른 이의제기기간이 끝난 경우
4. 제76조제4항에 따른 과태료 처분에 대하여 이의제기가 있는 경우에는 해당 관할 법원에 의한 비송사건절차가 끝난 경우
[전문개정 2008. 6. 13.]
Article 64-2 (Protection and destruction of data)
(1) If asked by a provider of information and communications services to protect documents, data, or any other material submitted or collected pursuant to Article 64, the Minister of Science and ICT or the Korea Media and Communications Commission shall not furnish them to a third party or disclose them to the general public. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(2) In cases of receiving data submitted through an information and communications network or converting collected data or any other material into an electronic format, the Minister of Science and ICT or the Korea Media and Communications Commission shall take systematic and technical measures for security to protect personal information, trade secret, or similar from being leaked. <Amended on Mar 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(3) If any of the following events occurs, the Minister of Science and ICT or the Korea Media and Communications Commission shall immediately destroy documents, data, or any other material submitted or collected pursuant to Article 64, except as otherwise provided in any other statute. The same shall apply to a person to whom the authority of the Minister of Science and ICT or the Korea Media and Communications Commission has been fully or partially delegated or entrusted under Article 65: <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
1. If the objectives of demanding submission of data, conducting a field inspection, or issuing an order to take corrective measures pursuant to Article 64 have been achieved;
2. If an administrative trial or administrative litigation is filed against an order issued to take corrective measures pursuant to Article 64 (4), when proceedings of such administrative trial are completed;
3. If a disposition is made to impose an administrative fine under Article 76 (4) and there is no objection to it, when the period to raise an objection under paragraph (5) of that Article ends;
4. If there is an objection filed against disposition of an administrative fine under Article 76 (4), when the non-contentious case procedures are closed at the competent court.
[This Article Wholly Amended on Jun. 13, 2008]
제64조의3 삭제 <2020. 2. 4.>
Article 64-3 Deleted. <Feb. 4, 2020>
제64조의4(청문)
과학기술정보통신부장관 또는 방송미디어통신위원회는 다음 각 호의 어느 하나에 해당하는 경우에는 청문을 하여야 한다. <개정 2017. 7. 26., 2020. 2. 4., 2020. 6. 9., 2025. 10. 1.>
1. 제9조제2항에 따라 인증기관의 지정을 취소하려는 경우
2. 제23조의4제1항에 따라 본인확인기관의 지정을 취소하려는 경우
3. 제47조제10항에 따라 정보보호 관리체계 인증을 취소하려는 경우
4. 제47조의2제1항에 따라 정보보호 관리체계 인증기관의 지정을 취소하려는 경우
5. 제47조의5제4항에 따라 정보보호 관리등급을 취소하려는 경우
5의2. 제48조의6제3항에 따라 정보보호인증을 취소하려는 경우
5의3. 제48조의6제5항에 따라 인증시험대행기관의 지정을 취소하려는 경우
6. 제55조제1항에 따라 등록을 취소하려는 경우
[본조신설 2015. 12. 1.]
Article 64-4 (Hearings)
The Minister of Science and ICT or the Korea Media and Communications Commission shall hold a hearing in any of the following cases: <Amended on Jul. 26, 2017; Feb. 4, 2020; Jun. 9, 2020; Oct. 1, 2025>
1. Where intending to revoke the designation of a certification body in accordance with Article 9 (2);
2. Where intending to revoke the designation of an identity verification agency in accordance with Article 23-4 (1);
3. Where intending to revoke certification of an information security management system in accordance with Article 47 (10);
4. Where intending to revoke the designation of a certification body for information security management systems in accordance with Article 47-2 (1);
5. Where intending to revoke any information security management grade in accordance with Article 47-5 (4);
5-2. Where intending to revoke information security certification under Article 48-6 (3);
5-3. Where intending to revoke the designation of a testing agency for certification under Article 48-6 (5);
6. Where intending to revoke the registration in accordance with Article 55 (1).
[This Article Added on Dec. 1, 2015]
제64조의5(투명성 보고서 제출의무 등)
정보통신서비스 제공자 중 일일 평균 이용자의 수, 매출액, 사업의 종류 등이 대통령령으로 정하는 기준에 해당하는 자는 매년 자신이 제공하는 정보통신서비스를 통하여 유통되는 불법촬영물등의 처리에 관하여 다음 각 호의 사항을 포함한 보고서(이하 "투명성 보고서"라 한다)를 작성하여 다음해 1월 31일까지 방송미디어통신위원회에 제출하여야 한다. <개정 2025. 10. 1.>
1. 정보통신서비스 제공자가 불법촬영물등의 유통 방지를 위하여 기울인 일반적인 노력에 관한 사항
2. 「전기통신사업법」 제22조의5제1항에 따른 불법촬영물등의 신고, 삭제요청 등의 횟수, 내용, 처리기준, 검토결과 및 처리결과에 관한 사항
3. 「전기통신사업법」 제22조의5제1항에 따른 불법촬영물등의 삭제ㆍ접속차단 등 유통방지에 필요한 절차의 마련 및 운영에 관한 사항
4. 불법촬영물등 유통방지 책임자의 배치에 관한 사항
5. 불법촬영물등 유통방지를 위한 내부 교육의 실시와 지원에 관한 사항
방송미디어통신위원회는 투명성 보고서를 자신이 운영ㆍ관리하는 정보통신망을 통하여 공개하여야 한다. <개정 2025. 10. 1.>
방송미디어통신위원회는 투명성 보고서의 사실을 확인하거나 제출된 자료의 진위를 확인하기 위하여 정보통신서비스제공자에게 자료의 제출을 요구할 수 있다. <개정 2025. 10. 1.>
[본조신설 2020. 6. 9.]
Article 64-5 (Obligation to submit transparency reports)
(1) A provider of information and communications services who meet the criteria prescribed Presidential Decree, such as the average number of daily users, sales, and types of business, shall prepare an annual report stating the following (hereinafter referred to as "transparency report") with regard to the disposition of illegally filmed materials or the like circulated through information and communications services rendered by the provider and shall submit the report to the Korea Media and Communications Commission by January 31 of the following year: <Amended on Oct. 1, 2025>
1. Matters concerning the general efforts made by the provider of information and communications services to prevent the circulation of illegally filmed materials or the like;
2. Matters concerning the number, details, criteria for processing, results of examination, and results of processing of reports on illegally filmed materials or the like and requests for deletion, etc. of such materials under Article 22-5 (1) of the Telecommunications Business Act;
3. Matters concerning the preparation and operation of procedures necessary for preventing circulation, such as deleting illegally filmed materials or the like and blocking access thereto, under Article 22-5 (1) of the Telecommunications Business Act;
4. Matters concerning the placement of persons responsible for preventing the circulation of illegally filmed materials or the like;
5. Matters concerning the provision of internal training and support for preventing the circulation of illegally filmed materials or the like.
(2) The Korea Media and Communications Commission shall disclose transparency reports through the information and communications network operated and managed by it. <Amended on Oct. 1, 2025>
(3) The Korea Media and Communications Commission may request a provider of information and communications services to submit data to ascertain the facts of a transparency report or ascertain the authenticity of the submitted data. <Amended on Oct. 1, 2025>
[This Article Added on Jun. 9, 2020]
제65조(권한의 위임ㆍ위탁)
이 법에 따른 과학기술정보통신부장관 또는 방송미디어통신위원회의 권한은 대통령령으로 정하는 바에 따라 그 일부를 소속 기관의 장 또는 지방우정청장에게 위임ㆍ위탁할 수 있다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2020. 2. 4., 2025. 10. 1.>
과학기술정보통신부장관은 제13조에 따른 정보통신망의 이용촉진 등에 관한 사업을 대통령령으로 정하는 바에 따라 「지능정보화 기본법」 제12조에 따른 한국지능정보사회진흥원에 위탁할 수 있다. <개정 2013. 3. 23., 2017. 7. 26., 2020. 6. 9.>
과학기술정보통신부장관 또는 방송미디어통신위원회는 제64조제1항 및 제2항에 따른 자료의 제출 요구 및 검사에 관한 업무를 대통령령으로 정하는 바에 따라 인터넷진흥원에 위탁할 수 있다. <개정 2009. 4. 22., 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
제3항에 따른 인터넷진흥원의 직원에게는 제64조제8항을 준용한다. <개정 2009. 4. 22.>
[전문개정 2008. 6. 13.]
Article 65 (Delegation and entrustment of authority)
(1) The Minister of Science and ICT or the Korea Media and Communications Commission may delegate or entrust part of his or her authority under this Act to the heads of affiliated agencies or the presidents of the regional Korea posts, as prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Feb. 4, 2020; Oct. 1, 2025>
(2) The Minister of Science and ICT may entrust projects under Article 13 for facilitating the use of information and communications networks to the National Information Society Agency under Article 12 of the Framework Act on Intelligent Informatization, as prescribed by Presidential Decree. <Amended on Mar. 23, 2013; Jul. 26, 2017; Jun. 9, 2020>
(3) The Minister of Science and ICT or the Korea Media and Communications Commission may entrust the Internet and Security Agency with business affairs related to demanding submission of data and conducting inspections pursuant to Article 64 (1) and (2), as prescribed by Presidential Decree. <Amended on Apr. 22, 2009; Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(4) Article 64 (8) shall apply mutatis mutandis to employees of the Internet and Security Agency under paragraph (3). <Amended on Apr. 22, 2009>
[This Article Wholly Amended on Jun. 13, 2008]
제65조의2 삭제 <2005. 12. 30.>
Article 65-2 Deleted. <Dec. 30, 2005>
제66조(비밀유지 등)
다음 각 호의 어느 하나에 해당하는 업무에 종사하는 사람 또는 종사하였던 사람은 그 직무상 알게 된 비밀을 타인에게 누설하거나 직무 외의 목적으로 사용하여서는 아니 된다. 다만, 다른 법률에 특별한 규정이 있는 경우에는 그러하지 아니하다. <개정 2012. 2. 17., 2020. 6. 9.>
1. 삭제 <2011. 3. 29.>
2. 제47조에 따른 정보보호 관리체계 인증 업무
2의2. 삭제 <2020. 2. 4.>
3. 제52조제3항제4호에 따른 정보보호시스템의 평가 업무
4. 삭제 <2012. 2. 17.>
5. 제44조의10에 따른 명예훼손 분쟁조정부의 분쟁조정 업무
[전문개정 2008. 6. 13.]
Article 66 (Confidentiality)
A person who is or was engaged in a job related to any of the following business affairs shall not divulge to another person any secret that he or she has learned while performing his or her duties, nor does he or she use it for any purpose other than performance of his or her duties; provided, the same shall not apply if any other statute provides otherwise: <Amended on Feb. 17, 2012; Jun. 9, 2020>
1. Deleted; <Mar. 29, 2011>
2. Certification of an information security management system under Article 47;
2-2. Deleted; <Feb. 4, 2020>
3. Evaluation of information security systems under Article 52 (3) 4;
4. Deleted; <Feb. 17, 2012>
5. Conciliation of disputes by the defamation dispute conciliation division under Article 44-10.
[This Article Wholly Amended on Jun. 13, 2008]
제67조 삭제 <2020. 2. 4.>
Article 67 Deleted. <Feb. 4, 2020>
제68조 삭제 <2010. 3. 22.>
Article 68 Deleted. <Mar. 22, 2010>
제68조의2 삭제 <2015. 6. 22.>
Article 68-2 Deleted. <Jun. 22, 2015>
제69조(벌칙 적용 시의 공무원 의제)
과학기술정보통신부장관 또는 방송미디어통신위원회가 제65조제2항 및 제3항에 따라 위탁한 업무에 종사하는 한국정보화진흥원과 인터넷진흥원의 임직원은 「형법」 제129조부터 제132조까지의 규정에 따른 벌칙을 적용할 때에는 공무원으로 본다. <개정 2009. 4. 22., 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
[전문개정 2008. 6. 13.]
Article 69 (Legal fiction as public officials in application of penalty provisions)
Executive officers and employees of the National Information Society Agency and the Internet and Security Agency who engage in the business affairs entrusted by the Minister of Science and ICT or the Korea Media and Communications Commission pursuant to Article 65 (2) or (3) shall be deemed public officials in applying Articles 129 through 132 of the Criminal Act. <Amended on Apr. 22, 2009; Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
[This Article Wholly Amended on Jun. 13, 2008]
제69조의2 삭제 <2020. 2. 4.>
Article 69-2 Deleted. <Feb. 4, 2020>
제10장 벌칙
CHAPTER X PENALTY PROVISIONS
제70조(벌칙)
사람을 비방할 목적으로 정보통신망을 통하여 공공연하게 사실을 드러내어 다른 사람의 명예를 훼손한 자는 3년 이하의 징역 또는 3천만원 이하의 벌금에 처한다. <개정 2014. 5. 28.>
사람을 비방할 목적으로 정보통신망을 통하여 공공연하게 거짓의 사실을 드러내어 다른 사람의 명예를 훼손한 자는 7년 이하의 징역, 10년 이하의 자격정지 또는 5천만원 이하의 벌금에 처한다.
제1항과 제2항의 죄는 피해자가 구체적으로 밝힌 의사에 반하여 공소를 제기할 수 없다.
[전문개정 2008. 6. 13.]
Article 70 (Penalty provisions)
(1) A person who commits defamation of another person by disclosing a fact to the public through an information and communications network purposely to disparage the reputation of such person, shall be punished by imprisonment with labor for up to 3 years or by a fine not exceeding 30 million won. <Amended on May 28, 2014>
(2) A person who commits defamation of another person by disclosing a false fact to the public through an information and communications network purposely to disparage the reputation of such person, shall be punished by imprisonment with labor for up to 7 years, by suspension of qualification for up to 10 years, or by a fine not exceeding 50 million won.
(3) The prosecution may not prosecute a person who committed a crime under paragraph (1) or (2) against the victim's will explicitly manifested.
[This Article Wholly Amended on Jun. 13, 2008]
제70조의2(벌칙)
제48조제2항을 위반하여 악성프로그램을 전달 또는 유포하는 자는 7년 이하의 징역 또는 7천만원 이하의 벌금에 처한다.
[본조신설 2016. 3. 22.]
Article 70-2 (Penalty provisions)
A person who conveys or spread a malicious program in violation of Article 48 (2) shall be punished by imprisonment with labor for up to 7 years or by a fine not exceeding 70 million won.
[This Article Added on Mar. 22, 2016]
제71조(벌칙)
다음 각 호의 어느 하나에 해당하는 자는 5년 이하의 징역 또는 5천만원 이하의 벌금에 처한다. <개정 2016. 3. 22., 2018. 12. 24., 2024. 1. 23.>
1. 삭제 <2020. 2. 4.>
2. 삭제 <2020. 2. 4.>
3. 삭제 <2020. 2. 4.>
4. 삭제 <2020. 2. 4.>
5. 삭제 <2020. 2. 4.>
6. 삭제 <2020. 2. 4.>
7. 삭제 <2020. 2. 4.>
8. 삭제 <2020. 2. 4.>
9. 제23조의5제1항을 위반하여 연계정보를 생성ㆍ처리한 자
10. 제23조의5제4항에 따른 목적 범위를 넘어서 연계정보를 처리한 자
11. 제48조제1항을 위반하여 정보통신망에 침입한 자
12. 제48조제3항을 위반하여 정보통신망에 장애가 발생하게 한 자
13. 제48조제4항을 위반하여 프로그램이나 기술적 장치 등을 정보통신망 또는 이와 관련된 정보시스템에 설치하거나 이를 전달ㆍ유포한 자
14. 제49조를 위반하여 타인의 정보를 훼손하거나 타인의 비밀을 침해ㆍ도용 또는 누설한 자
제1항제11호의 미수범은 처벌한다. <신설 2016. 3. 22., 2024. 1. 23.>
[전문개정 2008. 6. 13.]
Article 71 (Penalty provisions)
(1) Any of the following persons shall be punished by imprisonment with labor for up to 5 years or by a fine not exceeding 50 million won: <Amended on Mar. 22, 2016; Dec. 24, 2018; Jan. 23, 2024>
1. Deleted; <Feb. 4, 2020>
2. Deleted; <Feb. 4, 2020>
3. Deleted; <Feb. 4, 2020>
4. Deleted; <Feb. 4, 2020>
5. Deleted; <Feb. 4, 2020>
6. Deleted; <Feb. 4, 2020>
7. Deleted; <Feb. 4, 2020>
8. Deleted; <Feb. 4, 2020>
9. A person who creates and processes connecting information, in violation of Article 23-5 (1);
10. A person who processes connecting information beyond the scope of purposes under Article 23-5 (4);
11. A person who intrudes into the information and communication network, in violation of Article 48 (1);
12. A person who causes a trouble to the information and communication network, in violation of Article 48 (3);
13. A person who installs a program, technical device, etc. in the information and communications network or an information system related thereto, or transmits or disseminates it, in violation of Article 48 (4);
14. A person damages the information of others or infringes, misappropriates, or divulges the secrets of others, in violation of Article 49.
(2) Any attempt referred to in paragraph (1) 11 shall be punished. < Added on Mar. 22, 2016; Jan. 23, 2024>
[This Article Wholly Amended on Jun. 13, 2008]
제72조(벌칙)
다음 각 호의 어느 하나에 해당하는 자는 3년 이하의 징역 또는 3천만원 이하의 벌금에 처한다. <개정 2015. 1. 20., 2015. 3. 27., 2020. 2. 4., 2024. 1. 23.>
1. 삭제 <2016. 3. 22.>
1의2. 제42조의2를 위반하여 청소년유해매체물을 광고하는 내용의 정보를 청소년에게 전송하거나 청소년 접근을 제한하는 조치 없이 공개적으로 전시한 자
2. 제49조의2제1항을 위반하여 다른 사람의 정보를 수집한 자
2의2. 제50조의8을 위반하여 광고성 정보를 전송한 자
3. 제53조제1항에 따른 등록을 하지 아니하고 그 업무를 수행한 자
4. 다음 각 목의 어느 하나에 해당하는 행위를 통하여 자금을 융통하여 준 자 또는 이를 알선ㆍ중개ㆍ권유ㆍ광고한 자
가. 재화등의 판매ㆍ제공을 가장하거나 실제 매출금액을 초과하여 통신과금서비스에 의한 거래를 하거나 이를 대행하게 하는 행위
나. 통신과금서비스이용자로 하여금 통신과금서비스에 의하여 재화등을 구매ㆍ이용하도록 한 후 통신과금서비스이용자가 구매ㆍ이용한 재화등을 할인하여 매입하는 행위
5. 제66조를 위반하여 직무상 알게 된 비밀을 타인에게 누설하거나 직무 외의 목적으로 사용한 자
삭제 <2016. 3. 22.>
[전문개정 2008. 6. 13.]
Article 72 (Penalty provisions)
(1) Any of the following persons shall be punished by imprisonment with labor for up to 3 years or by a fine not exceeding 30 million won: <Amended on Jan. 20, 2015; Mar. 27, 2015; Feb. 4, 2020; Jan. 23, 2024>
1. Deleted; <Mar. 22, 2016>
1-2. A person who transmits to a youth any information containing advertisement of a media product harmful to youths or displays such information openly without taking any measures to restrict access by youths, in violation of Article 42-2;
2. A person who collects another person's information in violation of Article 49-2 (1);
2-2. A person who transmits any advertising information, in violation of Article 50-8;
3. A person who conducts affairs without filing for registration under Article 53 (1);
4. A person who lends a loan to someone, or offers, intermediates, recommends, or advertise such loan by committing any of the following acts:
(a) Conducting, or engaging someone to conduct vicariously, a transaction through telecommunications billing services by pretending sale or supply of goods or services or billing more than an actual selling price;
(b) Engaging a user of telecommunications billing services to purchase or use certain goods or services through telecommunications billing services and then purchasing, at a discount, the goods or services purchased or used by the user of telecommunications billing services;
5. A person who divulges to another person any secret he or she has learned while performing his or her duties or uses such secret for any purpose other than performance of his or her duties, in violation of Article 66.
(3) Deleted. <Feb. 22, 2016>
[This Article Wholly Amended on Jun. 13, 2008]
제73조(벌칙)
다음 각 호의 어느 하나에 해당하는 자는 2년 이하의 징역 또는 2천만원 이하의 벌금에 처한다. <개정 2014. 5. 28., 2016. 3. 22., 2018. 6. 12., 2020. 2. 4., 2022. 6. 10., 2024. 2. 13., 2025. 10. 1.>
1. 삭제 <2020. 2. 4.>
1의2. 삭제 <2020. 2. 4.>
2. 제42조를 위반하여 청소년유해매체물임을 표시하지 아니하고 영리를 목적으로 제공한 자
3. 삭제 <2024. 1. 23.>
4. 제44조의6제3항을 위반하여 이용자의 정보를 민ㆍ형사상의 소를 제기하는 것 외의 목적으로 사용한 자
5. 제44조의7제2항 및 제3항에 따른 방송미디어통신위원회의 명령을 이행하지 아니한 자
6. 제48조의4제5항에 따른 명령을 위반하여 관련 자료를 보전하지 아니한 자
7. 제49조의2제1항을 위반하여 정보의 제공을 유인한 자
7의2. 제58조의2(제59조제2항에 따라 준용되는 경우를 포함한다)를 위반하여 제공받은 정보를 본인 여부를 확인하거나 고소ㆍ고발을 위하여 수사기관에 제출하기 위한 목적 외의 용도로 사용한 자
8. 제61조에 따른 명령을 이행하지 아니한 자
[전문개정 2008. 6. 13.]
Article 73 (Penalty provisions)
Any of the following persons shall be punished by imprisonment with labor for not more than 2 years or by a fine not exceeding 20 million won: <Amended on May 28, 2014; Mar. 22, 2016; Jun. 12, 2018; Feb. 4, 2020; Jun. 10, 2022; Feb. 13, 2024; Oct. 1, 2025>
1. Deleted; <Feb. 4, 2020>
1-2. Deleted; <Feb. 4, 2020>
2. A person who provides a media product harmful to youths for profit without labeling it as such in violation of Article 42;
3. Deleted; <Jan. 23, 2024>
4. A person who uses user's information for any purpose other than filing a civil or criminal lawsuit, in violation of Article 44-6 (3);
5. A person who fails to comply with an order issued by the Korea Media and Communications Commission under Article 44-7 (2) or (3);
6. A person who fails to preserve relevant data, in violation of an order issued pursuant to Article 48-4 (5);
7. A person who entices another person to provide him or her with information in violation of Article 49-2 (1);
7-2. A person who uses provided information for any purpose other than identifying a purchaser or submitting the information to an investigative agency in filing a criminal complaint or report, in violation of Article 58-2 (including where that Article shall apply mutatis mutandis under Article 59 (2));
8. A person who fails to comply with an order issued pursuant to Article 61.
[This Article Wholly Amended on Jun. 13, 2008]
제74조(벌칙)
다음 각 호의 어느 하나에 해당하는 자는 1년 이하의 징역 또는 1천만원 이하의 벌금에 처한다. <개정 2012. 2. 17., 2014. 5. 28.>
1. 제8조제4항을 위반하여 비슷한 표시를 한 제품을 표시ㆍ판매 또는 판매할 목적으로 진열한 자
2. 제44조의7제1항제1호를 위반하여 음란한 부호ㆍ문언ㆍ음향ㆍ화상 또는 영상을 배포ㆍ판매ㆍ임대하거나 공공연하게 전시한 자
3. 제44조의7제1항제3호를 위반하여 공포심이나 불안감을 유발하는 부호ㆍ문언ㆍ음향ㆍ화상 또는 영상을 반복적으로 상대방에게 도달하게 한 자
4. 제50조제5항을 위반하여 조치를 한 자
5. 삭제 <2014. 5. 28.>
6. 삭제 <2024. 1. 23.>
7. 제53조제4항을 위반하여 등록사항의 변경등록 또는 사업의 양도ㆍ양수 또는 합병ㆍ상속의 신고를 하지 아니한 자
제1항제3호의 죄는 피해자가 구체적으로 밝힌 의사에 반하여 공소를 제기할 수 없다.
[전문개정 2008. 6. 13.]
Article 74 (Penalty provisions)
(1) Any of the following persons shall be punished by imprisonment with labor for up to 1 year or by a fine not exceeding 10 million won: <Amended on Feb. 17, 2012; May 28, 2014>
1. A person who puts any similar label on a product or sells a product bearing any similar label, or who displays such product with intent to sell it, in violation of Article 8 (4);
2. A person who distributes, sells, lends, or openly displays any obscene codes, letters, sound, images, or motion pictures in violation of Article 44-7 (1) 1;
3. A person who makes any codes, letters, sound, images, or motion pictures arousing fear or apprehension reach another person repeatedly in violation of Article 44-7 (1) 3;
4. A person who takes measures, in violation of Article 50 (5);
5. Deleted; <May 28, 2014>
6. Deleted; <Jan. 23, 2024>
7. A person who fails to file for any modification of registered matters, or who fails to file a report on transfer, acquisition by transfer, merger, or inheritance of business, in violation of Article 53 (4).
(2) The prosecution may not prosecute a person who committed a crime under paragraph (1) 3 against the victim's will explicitly manifested.
[This Article Wholly Amended on Jun. 13, 2008]
제75조(양벌규정)
법인의 대표자나 법인 또는 개인의 대리인, 사용인, 그 밖의 종업원이 그 법인 또는 개인의 업무에 관하여 제71조부터 제73조까지 또는 제74조제1항의 어느 하나에 해당하는 위반행위를 하면 그 행위자를 벌하는 외에 그 법인 또는 개인에게도 해당 조문의 벌금형을 과(科)한다. 다만, 법인 또는 개인이 그 위반행위를 방지하기 위하여 해당 업무에 관하여 상당한 주의와 감독을 게을리하지 아니한 경우에는 그러하지 아니하다.
[전문개정 2010. 3. 17.]
Article 75 (Joint penalty provisions)
If the representative of a corporation, or an agent or employee of, or any other person employed by, a corporation or individual commits any violation referred to in Articles 71 through 73 or Article 74 (1) in conducting the business affairs of the corporation or individual, the corporation or the individual shall, in addition to punishing the violator accordingly, be punished by a fine prescribed in the relevant Article; provided, this shall not apply where such corporation or individual has not been negligent in giving due attention and supervision regarding the relevant business affairs to prevent such violation.
[This Article Wholly Amended on Mar. 17, 2010]
제75조의2(몰수ㆍ추징)
제72조제1항제2호 및 제73조제7호의 어느 하나에 해당하는 죄를 지은 자가 해당 위반행위와 관련하여 취득한 금품이나 그 밖의 이익은 몰수할 수 있으며, 이를 몰수할 수 없을 때에는 그 가액을 추징할 수 있다. 이 경우 몰수 또는 추징은 다른 벌칙에 부가하여 과할 수 있다. <개정 2020. 2. 4.>
[본조신설 2016. 3. 22.]
Article 75-2 (Confiscation and punitive collection)
Money and goods or other profits received by a person committing any crime referred to in Article 72 (1) 2 and subparagraph 7 of Article 73 with respect to the relevant violation may be confiscated, and if it is impossible to confiscate such money and goods or other profits, the value thereof may be punitively collected. In such cases, the penalty of confiscation or punitive collection may be imposed in addition to any other penalty. <Amended on Feb. 4, 2020>
[This Article Added on Mar. 22, 2016]
제76조(과태료)
다음 각 호의 어느 하나에 해당하는 자와 제7호부터 제11호까지의 경우에 해당하는 행위를 하도록 한 자에게는 3천만원 이하의 과태료를 부과한다. <개정 2011. 3. 29., 2012. 2. 17., 2013. 3. 23., 2014. 5. 28., 2015. 6. 22., 2015. 12. 1., 2016. 3. 22., 2017. 7. 26., 2018. 9. 18., 2020. 2. 4., 2021. 6. 8., 2023. 1. 3., 2024. 1. 23., 2024. 2. 13., 2025. 10. 1.>
1. 제22조의2제2항을 위반하여 서비스의 제공을 거부한 자
1의2. 제22조의2제3항을 위반하여 접근권한에 대한 이용자의 동의 및 철회방법을 마련하는 등 이용자 정보 보호를 위하여 필요한 조치를 하지 아니한 자
2. 제23조의2제1항을 위반하여 주민등록번호를 수집ㆍ이용하거나 같은 조 제2항에 따른 필요한 조치를 하지 아니한 자
2의2. 삭제 <2020. 2. 4.>
2의3. 삭제 <2020. 2. 4.>
2의4. 삭제 <2020. 2. 4.>
2의5. 제23조의6제1항에 따른 물리적ㆍ기술적ㆍ관리적 조치를 하지 아니한 자
2의6. 제23조의6제2항에 따른 안전조치를 하지 아니한 자
3. 삭제 <2020. 2. 4.>
4. 삭제 <2020. 2. 4.>
5. 삭제 <2020. 2. 4.>
5의2. 삭제 <2020. 2. 4.>
6. 삭제 <2014. 5. 28.>
6의2. 제45조의3제1항을 위반하여 대통령령으로 정하는 기준에 해당하는 임직원을 정보보호 최고책임자로 지정하지 아니하거나 정보보호 최고책임자의 지정을 신고하지 아니한 자
6의3. 제45조의3제3항을 위반하여 정보보호 최고책임자로 하여금 같은 조 제4항의 업무 외의 다른 업무를 겸직하게 한 자
6의4. 제46조제3항에 따른 시정명령을 이행하지 아니한 자
6의5. 제47조제2항을 위반하여 정보보호 관리체계 인증을 받지 아니한 자
6의6. 제48조의3제1항을 위반하여 침해사고의 신고를 하지 아니한 자
6의7. 제48조의4제3항에 따른 시정명령을 이행하지 아니한 자
7. 제50조제1항부터 제3항까지의 규정을 위반하여 영리 목적의 광고성 정보를 전송한 자
8. 제50조제4항을 위반하여 광고성 정보를 전송할 때 밝혀야 하는 사항을 밝히지 아니하거나 거짓으로 밝힌 자
9. 제50조제6항을 위반하여 비용을 수신자에게 부담하도록 한 자
9의2. 제50조제8항을 위반하여 수신동의 여부를 확인하지 아니한 자
9의3. 제50조의4제4항을 위반하여 필요한 조치를 하지 아니한 자
10. 제50조의5를 위반하여 이용자의 동의를 받지 아니하고 프로그램을 설치한 자
11. 제50조의7제1항 또는 제2항을 위반하여 인터넷 홈페이지에 영리목적의 광고성 정보를 게시한 자
11의2. 삭제 <2020. 2. 4.>
12. 이 법을 위반하여 제64조제4항에 따라 과학기술정보통신부장관 또는 방송미디어통신위원회로부터 받은 시정조치 명령을 이행하지 아니한 자
다음 각 호의 어느 하나에 해당하는 자에게는 2천만원 이하의 과태료를 부과한다. <개정 2016. 3. 22., 2018. 6. 12., 2018. 9. 18., 2020. 2. 4., 2020. 6. 9.>
1. 삭제 <2020. 2. 4.>
1의2. 삭제 <2020. 2. 4.>
2. 삭제 <2020. 2. 4.>
3. 삭제 <2020. 2. 4.>
4. 삭제 <2020. 2. 4.>
4의2. 제46조제2항을 위반하여 보험에 가입하지 아니한 자
4의3. 제32조의5제1항을 위반하여 국내대리인을 지정하지 아니한 자
4의4. 제44조의9제1항을 위반하여 불법촬영물등 유통방지 책임자를 지정하지 아니한 자
5. 삭제 <2020. 2. 4.>
다음 각 호의 어느 하나에 해당하는 자에게는 1천만원 이하의 과태료를 부과한다. <개정 2009. 4. 22., 2011. 4. 5., 2012. 2. 17., 2014. 5. 28., 2015. 6. 22., 2015. 12. 1., 2016. 3. 22., 2017. 7. 26., 2018. 6. 12., 2020. 2. 4., 2020. 6. 9., 2022. 6. 10., 2023. 1. 3., 2024. 1. 23., 2024. 2. 13., 2025. 10. 1.>
1. 삭제 <2015. 6. 22.>
2. 삭제 <2015. 6. 22.>
2의2. 제23조의3제1항을 위반하여 본인확인기관의 지정을 받지 아니하고 본인확인업무를 한 자
2의3. 제23조의3제2항에 따른 본인확인업무의 휴지 또는 같은 조 제3항에 따른 본인확인업무의 폐지 사실을 이용자에게 통보하지 아니하거나 방송미디어통신위원회에 신고하지 아니한 자
2의4. 제23조의4제1항에 따른 본인확인업무의 정지 및 지정취소 처분에도 불구하고 본인확인업무를 계속한 자
2의5. 삭제 <2020. 2. 4.>
3. 제42조의3제1항을 위반하여 청소년 보호 책임자를 지정하지 아니한 자
4. 제43조를 위반하여 정보를 보관하지 아니한 자
4의2. 제44조의7제5항을 위반하여 기술적ㆍ관리적 조치를 하지 아니한 자
4의3. 제46조제4항에 따른 자료의 제출요구에 정당한 사유 없이 따르지 아니한 자. 다만, 관계 중앙행정기관(그 소속기관을 포함한다)의 장은 제외한다.
4의4. 제46조제6항을 위반하여 보고를 하지 아니하거나 거짓으로 보고한 자
5. 삭제 <2018. 6. 12.>
6. 삭제 <2015. 12. 1.>
7. 제47조제9항을 위반하여 인증받은 내용을 거짓으로 홍보한 자
8. 삭제 <2012. 2. 17.>
9. 삭제 <2012. 2. 17.>
10. 제47조의4제4항을 위반하여 소프트웨어 사용자에게 알리지 아니한 자
11. 제48조의2제4항에 따른 시정명령을 이행하지 아니한 자
11의2. 삭제 <2024. 2. 13.>
11의3. 제48조의4제6항에 따른 자료를 제출하지 아니하거나 거짓으로 제출한 자
12. 제48조의4제6항에 따른 사업장 출입 및 조사를 방해하거나 거부 또는 기피한 자
12의2. 제49조의2제4항을 위반하여 과학기술정보통신부장관 또는 방송미디어통신위원회의 명령을 이행하지 아니한 자
12의3. 제50조제7항을 위반하여 수신동의, 수신거부 또는 수신동의 철회에 대한 처리 결과를 알리지 아니한 자
12의4. 삭제 <2024. 1. 23.>
13. 제52조제6항을 위반하여 한국인터넷진흥원의 명칭을 사용한 자
14. 제53조제4항을 위반하여 사업의 휴업ㆍ폐업ㆍ해산의 신고를 아니한 자
15. 제56조제1항을 위반하여 약관을 신고하지 아니한 자
16. 제57조제2항을 위반하여 관리적 조치 또는 기술적 조치를 하지 아니한 자
17. 제58조제1항을 위반하여 통신과금서비스 이용일시 등을 통신과금서비스이용자에게 고지하지 아니한 자
18. 제58조제2항을 위반하여 통신과금서비스이용자가 구매ㆍ이용 내역을 확인할 수 있는 방법을 제공하지 아니하거나 통신과금서비스이용자의 제공 요청에 따르지 아니한 자
19. 제58조제3항을 위반하여 통신과금서비스이용자로부터 받은 통신과금에 대한 정정요구가 이유 있음에도 결제대금의 지급을 유보하지 아니하거나 통신과금서비스이용자의 요청에 대한 처리 결과를 통신과금서비스이용자에게 알려 주지 아니한 자
20. 제58조제4항을 위반하여 통신과금서비스에 관한 기록을 보존하지 아니한 자
20의2. 제58조제5항을 위반하여 통신과금서비스이용자의 동의를 받지 아니하고 통신과금서비스를 제공하거나 이용한도액을 증액한 자
20의3. 제58조제6항을 위반하여 통신과금서비스 약관의 변경에 관한 통지를 하지 아니한 자
20의4. 제58조의2(제59조제2항에 따라 준용되는 경우를 포함한다)를 위반하여 통신과금서비스이용자의 정보 제공 요청에 따르지 아니한 자
21. 제59조제3항을 위반하여 통신과금서비스이용자의 이의신청 및 권리구제를 위한 절차를 마련하지 아니하거나 통신과금서비스 계약 시 이를 명시하지 아니한 자
22. 제64조제1항에 따른 관계 물품ㆍ서류 등을 제출하지 아니하거나 거짓으로 제출한 자
23. 제64조제2항에 따른 자료의 열람ㆍ제출요청에 따르지 아니한 자
24. 제64조제3항에 따른 출입ㆍ검사를 거부ㆍ방해 또는 기피한 자
25. 제64조의5제1항을 위반하여 투명성 보고서를 제출하지 아니한 자
제1항부터 제3항까지의 과태료는 대통령령으로 정하는 바에 따라 과학기술정보통신부장관 또는 방송미디어통신위원회가 부과ㆍ징수한다. <개정 2011. 3. 29., 2013. 3. 23., 2017. 7. 26., 2025. 10. 1.>
삭제 <2017. 3. 14.>
삭제 <2017. 3. 14.>
삭제 <2017. 3. 14.>
[전문개정 2008. 6. 13.]
Article 76 (Administrative fines)
(1) Any of the following persons and any of the following persons who commit an act falling under any of subparagraphs 7 through 11 shall be subject to an administrative fine not exceeding 30 million won: <Amended on Mar. 29, 2011; Feb. 17, 2012; Mar. 23, 2013; May 28, 2014; Jun. 22, 2015; Dec. 1, 2015; Mar. 22, 2016; Jul. 26, 2017; Sep. 18, 2018; Feb. 4, 2020; Jun. 8, 2021; Jan. 3, 2023; Jan. 23, 2024; Feb. 13, 2024; Oct. 1, 2025>
1. A person who refuses to provide services, in violation of Article 22-2 (2);
1-2. A person who fails to take measures necessary to protect user information such as devising methods for users to give or revoke consent to access authority, in violation of Article 22-2 (3);
2. A person who collects or uses resident registration numbers in violation of Article 23-2 (1) or fails to take necessary measures in violation of Article 23-2 (2);
2-2. Deleted; <Feb. 4, 2020>
2-3. Deleted; <Feb. 4, 2020>
2-4. Deleted; <Feb. 4, 2020>
2-5. A person who fails to take physical, technical or administrative measures under Article 23-6 (1);
2-6. A person who fails to take safety measures in accordance with Article 23-6 (2);
3. Deleted; <Feb. 4, 2020>
4. Deleted; <Feb. 4, 2020>
5. Deleted; <Feb. 4, 2020>
5-2. Deleted; <Feb. 4, 2020>
6. Deleted; <May 28, 2014>
6-2. A person who fails to designate an executive officer or employee meeting the standards prescribed by Presidential Decree as a chief information security officer, or fails to report the designation of a chief information security officer, in violation of Article 45-3 (1);
6-3. A person who requires a chief information security officer to hold another office concurrently other than to perform duties prescribed in Article 45-3 (4), in violation of paragraph (3) of that Article;
6-4. A person who fails to comply with a corrective order issued under Article 46 (3);
6-5. A person who fails to have an information security management system certified, in violation of Article 47 (2);
6-6. A person who fails to report a cyber security incident, in violation of Article 48-3 (1);
6-7. A person who fails to comply with a corrective order issued under Article 48-4 (3);
7. A person who transmits any advertising information for profit, in violation of Article 50 (1) through (3);
8. A person who fails to state the matters required to be stated, or who states false information on such matters, when transmitting any advertising information, in violation of Article 50 (4);
9. A person who imposes the burden of any expense on an addressee, in violation of Article 50 (6);
9-2. A person who fails to verify whether an addressee consents to receiving advertising information, in violation of Article 50 (8);
9-3. A person who fails to take necessary measures, in violation of Article 50-4 (4);
10. A person who installs a program without consent of the relevant user, in violation of Article 50-5;
11. A person who posts any advertising information for profit-making purpose on a website, in violation of Article 50-7 (1) or (2);
11-2. Deleted; <Feb. 4, 2020>
12. A person who fails to comply with an order issued, for violation of this Act, by the Minister of Science and ICT or the Korea Media and Communications Commission pursuant to Article 64 (4).
(2) Any of the following persons shall be subject to an administrative fine not exceeding 20 million won: <Amended on Mar. 22, 2016; Jun 12, 2018; Sep. 18, 2018; Feb. 4, 2020; Jun. 9, 2020>
1. Deleted; <Feb. 4, 2020>
1-2. Deleted; <Feb. 4, 2020>
2. Deleted; <Feb. 4, 2020>
3. Deleted; <Feb. 4, 2020>
4. Deleted; <Feb. 4, 2020>
4-2. A person who fails to take out insurance, in violation of Article 46 (2);
4-3. A person who fails to designate a domestic agent, in violation of Article 32-5 (1);
4-4. A person who fails to designate a person responsible for preventing the circulation of illegally filmed materials or the like, in violation of Article 44-9 (1);
5. Deleted. <Feb. 4, 2020>
(3) Any of the following persons shall be subject to an administrative fine not exceeding 10 million won: <Amended on Apr. 22, 2009; Apr. 5, 2011; Feb. 17, 2012; May 28, 2014; Jun. 22, 2015; Dec. 1, 2015; Mar. 22, 2016; Jul. 26, 2017; Jun. 12, 2018; Jun. 12, 2018; Feb. 4, 2020; Jun. 9, 2020; Jun. 10, 2022; Jan. 3, 2023; Jan. 23, 2024; Feb. 13, 2024; Oct. 1, 2025>
1. Deleted; <Jun. 22, 2015>
2. Deleted; <Jun. 22, 2015>
2-2. A person who engages in the identity verification service without being designated as an identity verification agency, in violation of Article 23-3 (1);
2-3. A person who fails to notify as to the temporary discontinuation of the identity verification service under Article 23-3 (2) or as to the permanent discontinuation of the identity verification service under Article 23-3 (3) to users or who fails to report the same to the Korea Media and Communications Commission;
2-4. A person who continuously engages in the identity verification service notwithstanding a disposition for suspension of the identity verification service and revocation of the designation as an identity verification agency under Article 23-4 (1);
2-5. Deleted; <Feb. 4, 2020>
3. A person who fails to designate a person responsible for protection of youths in violation of Article 42-3 (1);
4. A person who fails to preserve information, in violation of Article 43;
4-2. A person who fails to take technical and administrative measures, in violation of Article 44-7 (5);
4-3. A person who fails to comply without good cause with a request to submit data under Article 46 (4) of the Act; provided, the foregoing shall not apply to the heads of relevant central administrative agencies (including their affiliated agencies) shall be excluded;
4-4. A person who fails to file a report or files a false report, in violation of Article 46 (6);
5. Deleted; <Jun. 12, 2018>
6. Deleted; <Dec. 1, 2015>
7. A person who advertises false details of the certification he or she has obtained, in violation of Articles 47 (9);
8. Deleted; <Feb. 17, 2012>
9. Deleted; <Feb. 17, 2012>
10. A person who fails to give notice to users of software, in violation of Article 47-4 (4);
11. A person who fails to comply with an order issued pursuant to Article 48-2 (4) to take corrective measures;
11-2. Deleted; <Feb. 13, 2024>
11-3. A person who fails to submit data demanded under Article 48-4 (6) or submits false data;
12. A person who obstructs, refuses, or evades access to a place of business to conduct an investigation under Article 48-4 (6);
12-2. A person who fails to comply with an order issued by the Minister of Science and ICT or the Korea Media and Communications Commission, in violation of Article 49-2 (4);
12-3. A person who fails to inform the results of handling consent to receive, refusal to receive, or revocation of consent to receive, advertising information, in violation of Article 50 (7);
12-4. Deleted; <Jan. 23, 2024>
13. A person who uses the name of the Korea Internet and Security Agency, in violation of Article 52 (6);
14. A person who fails to file a report on temporary closure, permanent closure, or dissolution of business, in violation of Article 53 (4);
15. A person who fails to report terms and conditions, in violation of Article 56 (1);
16. A person who fails to take administrative or technical measures, in violation of Article 57 (2);
17. A person who fails to notify a user of telecommunications billing services of the date and time of using the aforementioned services and other necessary matters, in violation of Article 58 (1);
18. A person who fails to provide a user of telecommunications billing services with the method by which the user can verify the details of purchase or use, or who fails to respond to a request by a user of telecommunications billing services for the provision of such method, in violation of Article 58 (2);
19. A person who fails to withhold payment of the price though a request to correct a telecommunications bill he or she has received from a user of telecommunications billing services is reasonable or who fails to notify the user of telecommunications billing services of the results of the measures taken in response to a request of the user, in violation of Article 58 (3);
20. A person who fails to preserve records of telecommunications billing services, in violation of Article 58 (4);
20-2. A person who provides telecommunications billing services or increases the maximum use without obtaining consent from a user of telecommunications billing services, in violation of Article 58 (5);
20-3. A person who fails to give notice regarding amendment to the terms and conditions of telecommunications billing services, in violation of Article 58 (6);
20-4. A person who fails to comply with a request by a user of telecommunications billing services for information, in violation of Article 58-2 (including where that Article shall apply mutatis mutandis under Article 59 (2));
21. A person who fails to prepare the procedures for raising an objection by users of telecommunications billing services and redressing their infringed rights or who fails to stipulate such procedures when he or she enters into a contract for telecommunications billing services, in violation of Article 59 (3);
22. A person who fails to submit, or who falsely submitted, goods, documents, or any other material under Article 64 (1);
23. A person who fails to respond to a request for perusal or submission of data under Article 64 (2);
24. A person who refuses, obstructs or evades access and inspection under Article 64 (3);
25. A person who fails to submit rules, etc. in violation of Article 64-5 (1).
(4) The administrative fines prescribed in paragraphs (1) through (3) shall be imposed and collected by the Minister of Science and ICT or the Korea Media and Communications Commission, as prescribed by Presidential Decree. <Amended on Mar. 29, 2011; Mar. 23, 2013; Jul. 26, 2017; Oct. 1, 2025>
(5) Deleted. <Mar. 14, 2017>
(6) Deleted. <Mar. 14, 2017>
(7) Deleted. <Mar. 14, 2017>
[This Article Wholly Amended on Jun. 13, 2008]
부칙 <제6360호, 2001. 1. 16.>
제1조 (시행일)
이 법은 2001년 7월 1일부터 시행한다.
제2조 (한국정보보호센터의 설립근거와 명칭의 변경에 따른 경과조치)
이 법 시행당시 정보화촉진기본법 제14조의2의 규정에 의하여 설립된 한국정보보호센터는 이 법 제52조의 규정에 의한 한국정보보호진흥원으로 본다.
이 법 시행당시 한국정보보호센터가 행한 행위 그 밖의 법률관계에 있어서 한국정보보호센터는 이를 보호진흥원으로 본다.
이 법 시행당시 등기부 그 밖의 공부상 한국정보보호센터의 명의는 이를 한국정보보호진흥원으로 본다.
제3조 (한국정보통신진흥협회의 명칭변경에 따른 경과조치)
이 법 시행당시 한국정보통신진흥협회는 이를 한국정보통신산업협회로 본다.
이 법 시행당시 한국정보통신진흥협회가 행한 행위 그 밖의 법률관계에 있어서 한국정보통신진흥협회는 이를 협회로 본다.
이 법 시행당시 등기부 그 밖의 공부상 한국정보통신진흥협회의 명의는 이를 한국정보통신산업협회로 본다.
제4조 (벌칙의 적용에 관한 경과조치)
이 법 시행전의 행위에 관한 벌칙의 적용에 있어서는 종전의 규정에 의한다.
제5조 생략
제6조 (다른 법령과의 관계)
이 법 시행당시 다른 법령에서 종전의 정보통신망이용촉진등에관한법률 또는 그 규정을 인용하고 있는 경우 이 법에 그에 해당하는 규정이 있는 때에는 이 법 또는 이 법의 해당규정을 인용한 것으로 본다.
ADDENDA <Act No. 6360, Jan. 16, 2001>
Article 1 (Enforcement date)
This Act shall enter into force on July 1, 2001.
Article 2 (Transitional measures following change of basis for establishing the Korea Information Security Center and of its name)
(1) The Korea Information Security Center established pursuant to Article 14-2 of the Framework Act on Informatization Promotion as at the time this Act enters into force shall be deemed the Korea Information Security Agency established pursuant to Article 52 of this Act.
(2) Any act performed by and any legal relations maintained by the Korea Information Security Center as at the time this Act enters into force shall be deemed performed and maintained by the Korea Information Security Agency.
(3) The name of the Korea Information Security Center on the register book and other public registers as at the time this Act enters into force shall be deemed the name of the Korea Information Security Agency.
Article 3 (Transitional measures following change of name of the Korea Information and Communications Promotion Association)
(1) The Korea Information and Communications Promotion Association as at the time this Act enters into force shall be deemed the Korea Association of Information and Telecommunication.
(2) Any act performed and any legal relations maintained by the Korea Information and Communications Promotion Association as at the time this Act enters into force shall be deemed performed and maintained by the Association.
(3) The name of the Korea Information and Communications Promotion Association on the register book and other public registers as at the time this Act enters into force shall be deemed the name of the Korea Association of Information and Telecommunication.
Article 4 (Transitional measures concerning application of penalty provisions)
The application of penalty provisions to any act committed before this Act enters into force shall be governed by the previous provisions.
Article 5 Omitted.
Article 6 (Relationship to other statutes or regulations)
If other statutes or regulations cite the previous Act on Promotion of Utilization of Information System or the provisions thereof as at the time this Act enters into force and if there exist corresponding provisions thereto in this Act, this Act or the corresponding provisions in this Act shall be deemed cited.
부칙 <제6585호, 2001. 12. 31.>
제1조 (시행일)
이 법은 2002년 4월 1일부터 시행한다.
제2조 및 제3조 생략
제4조 생략
ADDENDA <Act No. 6585, Dec. 31, 2001>
Article 1 (Enforcement date)
This Act shall enter into force on April 1, 2002.
Articles 2 through 4 Omitted.
부칙 <제6797호, 2002. 12. 18.>
(시행일) 이 법은 공포후 1월이 경과한 날부터 시행한다. 다만, 제50조제2항ㆍ제5항, 제56조제3항ㆍ제4항, 제60조 및 제67조제1항(제15호의2 및 제15호의4의 규정에 한한다)의 개정규정은 공포후 6월이 경과한 날부터 시행한다.
(과태료의 적용에 관한 경과조치) 이 법 시행전의 위반행위에 대한 과태료의 적용에 있어서는 종전의 규정에 의한다.
ADDENDA <Act No. 6797, Dec. 18, 2002>
(1) (Enforcement date) This Act shall enter into force 1 month after the date of its promulgation; provided, the amended provisions of Articles 50 (2) and (5), 56 (3) and (4), 60, and 67 (1) (limited to subparagraphs 15-2 and 15-4) shall enter into force 6 months after the date of promulgation of this Act.
(2) (Transitional measures concerning imposition of administrative fines) The previous provisions of this Act shall apply to the imposition of administrative fines for violations committed before this Act enters into force.
부칙 <제7139호, 2004. 1. 29.>
(시행일) 이 법은 공포한 날부터 시행한다. 다만, 제28조ㆍ제45조제4항ㆍ제46조의3ㆍ제47조의2제4항 및 제48조의4제6항의 개정규정은 공포후 6월이 경과한 날부터 시행한다.
(과태료의 적용에 관한 경과조치) 이 법 시행전의 위반행위에 대한 과태료의 적용에 있어서는 종전의 규정에 의한다.
ADDENDA <Act No. 7139, Jan. 29, 2004>
(1) (Enforcement date) This Act shall enter into force on the date of its promulgation; provided, the amended provisions of Articles 28, 45 (4), 46-3, 47-2 (4), and 48-4 (6) shall enter into force 6 months after the date of promulgation of this Act.
(2) (Transitional measures concerning imposition of administrative fines) The previous provisions of this Act shall apply to the imposition of administrative fines for violations committed before this Act enters into force.
부칙 <제7142호, 2004. 1. 29.>
제1조 (시행일)
이 법은 공포후 6월이 경과한 날부터 시행한다.
제2조 및 제3조 생략
제4조 생략
ADDENDA <Act No. 7142, Jan. 29, 2004>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Articles 2 through 4 Omitted.
부칙 <제7262호, 2004. 12. 30.>
이 법은 공포후 3월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 7262, Dec. 30, 2004>
This Act shall enter into force 3 months on the date of its promulgation.
부칙 <제7796호, 2005. 12. 29.>
제1조 (시행일)
이 법은 2006년 7월 1일부터 시행한다.
제2조 내지 제5조 생략
제6조 생략
ADDENDA <Act No. 7796, Dec. 29, 2005>
Article 1 (Enforcement date)
This Act shall enter into force on July 1, 2006.
Articles 2 through 6 Omitted.
부칙 <제7812호, 2005. 12. 30.>
이 법은 공포 후 3개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 7812, Dec. 30, 2005>
This Act shall enter into force 3 months after the date of its promulgation.
부칙 <제7917호, 2006. 3. 24.>
(시행일) 이 법은 공포 후 3개월이 경과한 날부터 시행한다.
(정보보호 안전진단에 관한 경과조치) 이 법 시행 전에 「정보통신기반 보호법」 제17조의 규정에 의한 정보보호컨설팅전문업체가 정보보호 안전전단 업무를 시작한 경우에는 제46조의3제1항의 개정규정에 불구하고 종전의 규정에 따라 정보보호 안전진단 업무를 계속하여 수행할 수 있다.
ADDENDA <Act No. 7917, Mar. 24, 2006>
(1) (Enforcement date) This Act shall enter into force 3 months after the date of its promulgation.
(2) (Transitional measures concerning safety check of information protection) Where a company specializing in information protection consulting under Article 17 of the Act on the Protection of Information and Communications Infrastructure has commenced the works of safety check of information protection before this Act enters into force, it may continue to perform the works of safety check of information protection pursuant to the previous provisions, notwithstanding the amended provisions of Article 46-3 (1).
부칙 <제8030호, 2006. 10. 4.>
이 법은 공포 후 3개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 8030, Oct. 4, 2006>
This Act shall enter into force 3 months after the date of its promulgation.
부칙 <제8031호, 2006. 10. 4.>
제1조 (시행일)
이 법은 공포한 날부터 시행한다. <단서 생략
제2조 내지 제4조 생략
제5조 생략
ADDENDA <Act No. 8031, Oct. 4, 2006>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
부칙 <제8289호, 2007. 1. 26.>
제1조 (시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
제2조 (불법통신의 금지 등에 관한 경과조치)
이 법 시행 전에 「전기통신사업법」 제53조의 규정에 따라 정보통신부장관이 행한 전기통신 취급에 대한 거부ㆍ정지 또는 제한의 명령은 이를 이 법 제44조의7의 개정규정에 따라 행한 것으로 본다.
제3조 (정보통신윤리위원회 설치근거 변경에 따른 경과조치)
이 법 시행 당시 종전의 「전기통신사업법」 제53조의2의 규정에 따라 설치된 정보통신윤리위원회는 이 법 제44조의8의 개정규정에 따라 설치된 정보통신윤리위원회로 본다.
이 법 시행 전에 종전의 규정에 따른 정보통신윤리위원회가 행한 행위 또는 정보통신윤리위원회에 대하여 행한 행위 그 밖의 법률관계는 이 법 제44조의8의 개정규정에 따른 정보통신윤리위원회가 행한 행위 또는 정보통신윤리위원회에 대하여 행한 행위 그 밖의 법률관계로 본다.
제4조 (개인정보수집ㆍ이용ㆍ제공 등에 관한 경과조치)
이 법 시행 당시 종전의 제22조ㆍ제23조ㆍ제24조 또는 제54조의 규정에 따라 개인정보수집ㆍ이용ㆍ제공 등에 대한 이용자의 동의를 얻은 경우에는 제22조ㆍ제23조ㆍ제24조ㆍ제24조의2 또는 제54조의 개정규정에 따라 적법하게 동의를 얻은 것으로 본다.
이 법 시행 당시 종전의 제25조의 규정에 따라 적법하게 개인정보취급위탁을 한 경우에는 제25조제1항의 개정규정에 따라 적법하게 동의를 얻은 것으로 본다.
이 법 시행 당시 종전의 제26조의 규정에 따라 정보통신서비스제공자등의 권리ㆍ의무를 승계한 자가 이용자의 동의를 얻어 개인정보를 이용하거나 제공한 행위는 제26조제3항의 개정규정에 따라 적법하게 동의를 얻은 것으로 본다.
제5조 (벌칙의 적용에 관한 경과조치)
이 법 시행 전의 행위에 관한 벌칙의 적용에 있어서는 종전의 규정에 따른다.
제6조 생략
ADDENDA <Act No. 8289, Jan. 26, 2007>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 (Transitional measures concerning prohibition on illegal communications)
The orders issued by the Minister of Information and Communication to reject, suspend, or restrict handling of telecommunications services pursuant to Article 53 of the Telecommunications Business Act before this Act enters into force shall be deemed to have been issued pursuant to the amended provisions of Article 44-7 of this Act.
Article 3 (Transitional measures following change in authority for establishment of the Information and Communications Ethics Committee)
(1) The Information and Communications Ethics Committee established pursuant to Article 53-2 of the previous Telecommunications Business Act as at the time this Act enters into force shall be deemed the Information and Communications Ethics Committee established pursuant to the amended provisions of Article 44-8 of this Act.
(2) The acts done by or against the Information and Communications Ethics Committee and other legal relationships with the Information and Communications Ethics Committee under the previous provisions before this Act enters into force shall be deemed the acts done by or against the Information and Communications Ethics Committee and other legal relationships with the Information and Communications Ethics Committee under the amended provisions of Article 44-8 of this Act.
Article 4 (Transitional measures concerning collection, use, and provision of personal information)
(1) Consent obtained from a user in relation to collection, use, provision, or similar of personal information in accordance with the previous provisions of Article 22, 23, 24, or 54 as at the time this Act enters into force shall be deemed consent obtained lawfully in accordance with the amended provisions of Article 22, 23, 24, 24-2, or 54.
(2) Handling of personal information, which has been entrusted lawfully in accordance with the previous provisions of Article 25 as at the time this Act enters into force shall be deemed to have been entrusted with consent obtained lawfully in accordance with the amended provisions of Article 25 (1).
(3) An act performed by a person who succeeded rights and obligations of a provider of information and communications services or similar in accordance with the previous provisions of Article 26 as at the time this Act enters into force to use or provide personal information, shall be deemed to have been performed with consent obtained lawfully in accordance with the amended provisions of Article 26 (3).
Article 5 (Transitional measures concerning application of penalty provisions)
The previous provisions of this Act shall apply to the imposition of penalties for acts committed before this Act enters into force.
Article 6 Omitted.
부칙 <제8486호, 2007. 5. 25.>
제1조 (시행일)
이 법은 공포 후 1년이 경과한 날부터 시행한다.
제2조 부터 제8조까지 생략
제9조 생략
ADDENDA <Act No. 8486, May 25, 2007>
Article 1 (Enforcement date)
This Act shall enter into force 1 year after the date of its promulgation.
Articles 2 through 8 Omitted.
Article 9 Omitted.
Article 10 Omitted.
부칙 <제8778호, 2007. 12. 21.>
제1조 (시행일)
이 법은 공포 후 3개월이 경과한 날부터 시행한다.
제2조 (통신과금서비스제공자의 등록에 관한 경과조치)
이 법 시행 당시 통신과금서비스를 제공하고 있는 자는 이 법 시행일부터 3개월 이내에 제53조제1항의 개정규정에 따라 정보통신부장관에게 등록하여야 한다.
이 법 시행 당시 「전자금융거래법」 제28조제2항에 따라 등록을 한 통신과금서비스제공자는 이 법 시행일부터 3개월 이내에 해당 등록사실을 증명하는 서면을 정보통신부장관에게 제출하여야 한다.
제2항에 따라 서면을 제출한 자는 제53조제1항의 개정규정에 따라 등록한 것으로 본다.
ADDENDA <Act No. 8778, Dec. 21, 2007>
Article 1 (Enforcement date)
This Act shall enter into force 3 months after the date of its promulgation.
Article 2 (Transitional measures concerning registration of providers of telecommunications billing services)
(1) A person who renders telecommunications billing services as at the time this Act enters into force shall complete the registration with the Minister of Information and Communication in accordance with the amended provisions of Article 53 (1) within 3 months from the date this Act enters into force.
(2) A provider of telecommunications billing services who is registered in accordance with Article 28 (2) of the Electronic Financial Transactions Act as at the time this Act enters into force shall submit a written statement certifying the registration to the Minister of Information and Communication within 3 months from the date this Act enters into force.
(3) A person who submits a written statement in accordance with paragraph (2) shall be deemed to have been registered in accordance with the amended provisions of Article 53 (1).
부칙 <제8852호, 2008. 2. 29.>
제1조 (시행일)
이 법은 공포한 날부터 시행한다. 다만, ㆍㆍㆍ<생략
제2조 부터 제5조까지 생략
제6조 생략
부터 <431> 까지 생략
ADDENDA <Act No. 8852, Feb. 29, 2008>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation; provided, ... <omitted> among the statutes to be amended under Article 6 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
부칙 <제8867호, 2008. 2. 29.>
제1조(시행일 등)
이 법은 공포한 날부터 시행한다. <단서 생략
제2조 부터 제6조까지 생략
제7조 생략
ADDENDA <Act No. 8867, Feb. 29, 2008>
Article 1 (Enforcement date and others)
This Act shall enter into force on the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
Article 7 Omitted.
Articles 8 through 12 Omitted.
부칙 <제9119호, 2008. 6. 13.>
(시행일) 이 법은 공포 후 6개월이 경과한 날부터 시행한다.
(벌칙 및 과태료의 적용에 관한 경과조치) 이 법 시행 전의 행위에 관한 벌칙 및 과태료의 적용은 종전의 규정에 따른다.
ADDENDA <Act No. 9119, Jun. 13, 2008>
(1) (Enforcement date) This Act shall enter into force 6 months after the date of its promulgation.
(2) (Transitional measures concerning application of penalty provisions and administrative fines) The previous provisions of this Act shall apply to the imposition of penalties and administrative fines for acts committed before this Act enters into force.
부칙 <제9637호, 2009. 4. 22.>
제1조(시행일)
이 법은 공포 후 3개월이 경과한 날부터 시행한다.
제2조(한국인터넷진흥원의 설립준비)
방송통신위원회는 이 법 시행 전에 5명 이내의 설립위원을 위촉하여 한국인터넷진흥원의 설립을 위한 준비행위를 할 수 있다.
설립위원은 한국인터넷진흥원의 정관을 작성하여 방송통신위원회의 인가를 받아야 한다.
설립위원은 제2항에 따른 인가를 받은 때에는 연명으로 한국인터넷진흥원의 설립등기를 한 후 한국인터넷진흥원원장에게 사무를 인계하여야 한다.
설립위원은 제3항에 따른 사무인계가 끝난 때에는 해촉된 것으로 본다.
제3조(한국정보보호진흥원ㆍ한국인터넷진흥원ㆍ정보통신국제협력진흥원의 승계에 관한 경과조치)
이 법 시행 당시 종전의 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 제52조에 따른 한국정보보호진흥원(이하 "한국정보보호진흥원"이라 한다), 「인터넷주소자원에 관한 법률」 제9조에 따른 한국인터넷진흥원(이하 "한국인터넷진흥원"이라 한다), 「정보화촉진기본법」 제24조의2에 따른 정보통신국제협력진흥원(이하 "정보통신국제협력진흥원"이라 한다)의 소관 사무는 이 법에 따른 한국인터넷진흥원이 포괄 승계한다.
이 법 시행 당시 종전의 한국정보보호진흥원, 한국인터넷진흥원, 정보통신국제협력진흥원의 권리ㆍ의무와 재산은 이 법에 따른 한국인터넷진흥원이 포괄 승계한다.
이 법 시행 당시 종전의 한국정보보호진흥원, 한국인터넷진흥원, 정보통신국제협력진흥원의 직원의 고용관계는 이 법에 따른 한국인터넷진흥원이 포괄 승계한다.
이 법 시행 당시 종전의 한국정보보호진흥원, 한국인터넷진흥원, 정보통신국제협력진흥원이 행한 행위 또는 종전의 한국정보보호진흥원, 한국인터넷진흥원, 정보통신국제협력진흥원에 대하여 행하여진 행위는 이 법에 따른 한국인터넷진흥원이 행하였거나 이 법에 따른 한국인터넷진흥원에 대하여 행하여진 행위로 본다.
이 법 시행 당시 등기부나 그 밖의 공부에 표시된 종전의 한국정보보호진흥원, 한국인터넷진흥원, 정보통신국제협력진흥원의 명의는 이 법에 따른 한국인터넷진흥원의 명의로 본다.
제4조 생략
제5조(다른 법령과의 관계)
이 법 시행 당시 다른 법령에서 종전의 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 또는 그 규정을 인용한 경우 이 법 가운데 그에 해당하는 규정이 있는 때에는 종전의 규정을 갈음하여 이 법 또는 이 법의 해당 규정을 인용한 것으로 본다.
ADDENDA <Act No. 9637, Apr. 22, 2009>
Article 1 (Enforcement date)
This Act shall enter into force 3 months after the date of its promulgation.
Article 2 (Preparation for establishment of the Korea Internet and Security Agency)
(1) The Korea Communications Commission may perform preparatory activities to establish the Korea Internet and Security Agency by commissioning not more than 5 incorporators before this Act enters into force.
(2) The incorporators shall prepare the articles of incorporation of the Korea Internet and Security Agency and obtain approval from the Korea Communications Commission.
(3) Upon obtaining authorization under paragraph (2), the incorporators shall register the incorporation of the Korea Internet and Security Agency by joint signature and turn over the administrative responsibility to the President of Korea Internet and Security Agency.
(4) The incorporators shall be deemed decommissioned at the time the take-over of the administrative responsibility is complete pursuant to paragraph (3).
Article 3 (Transitional measures concerning succession of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency)
(1) The administrative responsibilities of the Korea Information Security Agency under Article 52 of the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter referred to as the "Korea Information Security Agency"), the Korea Internet and Security Agency under Article 9 of the Internet Address Resources Act (hereinafter referred to as the "Korea Internet and Security Agency"), and the Korea IT International Cooperation Agency under Article 24-2 of the Framework Act on Informatization Promotion (hereinafter referred to as the "Korea IT International Cooperation Agency"), which are governed by the previous provisions as at the time this Act enters into force, shall be comprehensively succeeded to the Korea Internet and Security Agency under this Act.
(2) The previous rights, obligations, properties of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency as at the time this Act enters into force shall be comprehensively succeeded to the Korea Internet and Security Agency under this Act.
(3) The previous employment relationship covering the employees of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency as at the time this Act enters into force shall be comprehensively succeeded to the Korea Internet and Security Agency under this Act.
(4) The previous activities performed by or in relation to the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency as at the time this Act enters into force shall be deemed to have been performed by or in relation to the Korea Internet and Security Agency under this Act.
(5) The names of the Korea Information Security Agency, the Korea Internet and Security Agency, and the Korea IT International Cooperation Agency indicated on the register as at the time this Act enters into force or other public books shall be deemed to be that of the Korea Internet and Security Agency under this Act.
Article 4 Omitted.
Article 5 (Relationship to other statutes or regulations)
Where the previous Act on Promotion of Information and Communications Network Utilization and Information Protection or the provisions thereof are cited in other statutes or regulations as at the time this Act enters into force, and provisions corresponding thereto are included in this Act, this Act or the corresponding provision of this Act shall be deemed cited in lieu of the previous provisions.
부칙 <제10138호, 2010. 3. 17.>
이 법은 공포한 날부터 시행한다.
ADDENDUM <Act No. 10138, Mar. 17, 2010>
This Act shall enter into force on the date of its promulgation.
부칙 <제10165호, 2010. 3. 22.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. <단서 생략
제2조 부터 제5조까지 생략
제6조 생략
ADDENDA <Act No. 10165, Mar. 22, 2010>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
부칙 <제10166호, 2010. 3. 22.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
제2조 부터 제6조까지 생략
제7조 생략
ADDENDA <Act No. 10166, Mar. 22, 2010>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Articles 2 through 6 Omitted.
Article 7 Omitted.
Articles 8 through 9 Omitted.
부칙 <제10465호, 2011. 3. 29.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. <단서 생략
제2조 부터 제5조까지 생략
제6조 생략
ADDENDA <Act No. 10465, Mar. 29, 2011>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
부칙 <제10560호, 2011. 4. 5.>
제1조(시행일)
이 법은 공포 후 3개월이 경과한 날부터 시행한다.
제2조(일반적 경과조치)
이 법 시행 당시 종전의 본인확인업무를 개발ㆍ제공한 본인확인기관의 행위는 그 본인확인기관이 이 법에 따른 지정을 받은 경우에 한하여 적법하게 본인확인업무를 개발ㆍ제공한 것으로 본다.
제3조(본인확인기관 지정에 관한 경과조치)
이 법 시행 당시 본인확인업무를 하는 자는 이 법 시행일부터 3개월 이내에 제23조의3제1항의 개정규정에 따라 방송통신위원회로부터 본인확인기관으로 지정받아야 한다.
ADDENDA <Act No. 10560, Apr. 5, 2011>
Article 1 (Enforcement date)
This Act shall enter into force 3 months after the date of its promulgation.
Article 2 (General transitional measures)
Previous acts of the identity verification agency which developed and provided the previous identity verification service as at the time this Act enters into force shall be deemed to have been legitimately developed and provided only if the agency obtains the designation as an identity verification agency under this Act.
Article 3 (Transitional measures concerning designation of identity verification agency)
A person who was conducting the identity verification service as at the time this Act enters into force shall be designated, within 3 months from the date this Act enters into force, as an identity verification agency by the Korea Communications Commission pursuant to the amended provisions of Article 23-3 (1).
부칙 <제11048호, 2011. 9. 15.>
제1조(시행일)
이 법은 공포 후 1년이 경과한 날부터 시행한다. <단서 생략
제2조 및 제3조 생략
제4조 생략
ADDENDA <Act No. 11048, Sep. 15, 2011>
Article 1 (Enforcement date)
This Act shall enter into force 1 year after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 5 Omitted.
부칙 <제11322호, 2012. 2. 17.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제45조, 제45조의2, 제45조의3, 제46조의3, 제47조, 제47조의2, 제47조의3, 제47조의5, 제52조제3항제7호, 제66조 및 제76조제3항제6호부터 제9호까지의 개정규정은 공포 후 1년이 경과한 날부터 시행한다.
제2조(주민등록번호 수집ㆍ이용 제한에 관한 경과조치)
이 법 시행 당시 주민등록번호를 사용한 회원가입 방법을 제공하고 있는 정보통신서비스 제공자는 이 법 시행일부터 2년 이내에 보유하고 있는 주민등록번호를 파기하여야 한다. 다만, 제23조의2제1항 각 호의 어느 하나에 해당하는 경우는 제외한다.
제1항에 따른 기간 이내에 보유하고 있는 주민등록번호를 파기하지 아니한 경우에는 제23조의2제1항의 개정규정을 위반한 것으로 본다.
제3조(정보보호 안전진단의 폐지에 따른 경과조치)
이 법 시행 당시 종전의 규정에 따라 정보보호 안전진단을 받은 사업자는 정보보호 안전진단을 받은 해당 연도에는 제47조제2항의 개정규정에 따른 정보보호 관리체계 인증을 받은 사업자로 본다.
제4조(개인정보보호 관리체계 인증에 관한 경과조치)
이 법 시행 당시 한국인터넷진흥원으로부터 개인정보보호 관리체계 인증을 받은 자는 제47조의3의 개정규정에 따라 개인정보보호 관리체계 인증을 받은 것으로 본다.
제5조(과태료에 관한 경과조치)
이 법 시행 전의 위반행위에 대하여 과태료를 적용할 때에는 종전의 규정에 따른다.
ADDENDA <Act No. 11322, Feb. 17, 2012>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 45, 45-2, 45-3, 46-3, 47, 47-2, 47-3, 47-5, 52 (3) 7, 66, and 76 (3) 6 through 9 shall enter into force 1 year after the date of promulgation of this Act.
Article 2 (Transitional measures concerning restrictions on collection and use of resident registration numbers)
(1) A provider of information and communications services who provides methods of subscription for membership by using the subscriber's resident registration number as at the time this Act enters into force shall destroy all the resident registration numbers possessed by the provider within 2 years after this Act enters into force; provided, this shall not apply in the case of any subparagraph of Article 23-2 (1).
(2) Where a provider of information and communications services fails to destroy the resident registration numbers possessed by him or her within the period under paragraph (1), the amended provisions of Article 23-2 (1) shall be deemed violated.
Article 3 (Transitional measures concerning abolition of safety inspection on protection of information)
A business operator who received a safety inspection on the protection of information pursuant to the previous provisions as at the time this Act enters into force shall be deemed, during the relevant year in which he or she underwent the safety inspection on the protection of information, a business operator who received the certification of an information security management system pursuant to the amended provisions of Article 47 (2).
Article 4 (Transitional measures concerning certification of personal information management system)
A person who received the certification of a personal information management system from the Korea Internet and Security Agency as at the time this Act enters into force shall be deemed to have received the certification of a personal information management system pursuant to the amended provisions of Article 47-3.
Article 5 (Transitional measures concerning administrative fines)
The previous provisions of this Act shall apply to the imposition of penalties for violations committed before this Act enters into force.
부칙 <제11690호, 2013. 3. 23.>
제1조(시행일)
이 법은 공포한 날부터 시행한다.
생략
제2조 부터 제5조까지 생략
제6조 생략
ADDENDA <Act No. 11690, Mar. 23, 2013>
Article 1 (Enforcement date)
(1) This Act shall enter into force on the date of its promulgation.
(2) Omitted.
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
부칙 <제12681호, 2014. 5. 28.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제44조제3항, 제44조의5, 제76조제1항제6호의 개정규정은 공포한 날부터 시행한다.
제2조(과징금 및 벌칙에 관한 경과조치)
이 법 시행 전의 위반행위에 대하여 과징금 및 벌칙을 적용할 때에는 종전의 규정에 따른다.
ADDENDA <Act No. 12681, May 28, 2014>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 44 (3), 44-5, and 76 (1) 6 shall enter into force on the date of promulgation of this Act.
Article 2 (Transitional measures concerning penalty surcharges and penalty provisions)
The previous provisions of this Act shall apply to the imposition of penalty surcharges and penalties for violations committed before this Act enters into force.
부칙 <제12844호, 2014. 11. 19.>
제1조(시행일)
이 법은 공포한 날부터 시행한다. 다만, 부칙 제6조에 따라 개정되는 법률 중 이 법 시행 전에 공포되었으나 시행일이 도래하지 아니한 법률을 개정한 부분은 각각 해당 법률의 시행일부터 시행한다.
제2조 부터 제5조까지 생략
제6조 생략
ADDENDA <Act No. 12844, Nov. 19, 2014>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation: provided, among the statutes to be amended under Article 6 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 5 Omitted.
Article 6 Omitted.
Article 7 Omitted.
부칙 <제13014호, 2015. 1. 20.>
이 법은 공포 후 3개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 13014, Jan. 20, 2015>
This Act shall enter into force 3 months after the date of its promulgation.
부칙 <제13280호, 2015. 3. 27.>
이 법은 공포한 날부터 시행한다.
ADDENDUM <Act No. 13280, Mar. 27, 2015>
This Act shall enter into force on the date of its promulgation.
부칙 <제13343호, 2015. 6. 22.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
제2조 생략
제3조 생략
ADDENDA <Act No. 13343, Jun. 22, 2015>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 Omitted.
Article 3 Omitted.
부칙 <제13344호, 2015. 6. 22.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
제2조(행정처분에 관한 적용례)
제55조제1항의 개정규정은 이 법 시행 전의 위반행위에 대한 행정처분의 경우에도 적용한다.
ADDENDA <Act No. 13344, Jun. 22, 2015>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 (Applicability concerning administrative dispositions)
The amended provisions of Article 55 (1) shall apply even where administrative dispositions are imposed against violations committed before this Act enters into force.
부칙 <제13520호, 2015. 12. 1.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제29조제2항 및 제3항의 개정규정은 공포한 날부터 시행한다.
제2조(개인정보의 파기 등에 관한 적용례)
제29조제2항 및 제3항의 개정규정은 같은 개정규정 시행 전에 수집하거나 제공받은 개인정보에 대해서도 적용한다.
제3조(정보보호 관리체계 인증 심사 생략에 관한 적용례)
제47조제3항의 개정규정은 이 법 시행 전에 정보보호 관리체계에 대한 인증을 신청하여 그 절차가 진행 중인 자에 대해서도 적용한다.
제4조(정보보호 관리체계의 인증에 관한 경과조치)
정보보호 관리체계의 인증을 받지 아니한 자는 이 법 시행 후 6개월 이내에 제47조제2항의 개정규정에 따라 인증을 받아야 한다.
제5조(과태료에 관한 경과조치)
이 법 시행 전의 위반행위에 대하여 과태료를 적용할 때에는 종전의 규정에 따른다.
ADDENDA <Act No. 13520, Dec. 1, 2015>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Article 29 (2) and (3) shall enter into force on the date of its promulgation.
Article 2 (Applicability to destruction of personal information)
The amended provisions of Article 29 (2) and (3) shall apply even to the personal information collected or provided before the amended provisions enter into force.
Article 3 (Applicability to omission of examination for certification of information security management systems)
The amended provisions of Article 47 (3) shall apply even to persons who have made an application for the certification of an information security management system, procedures for which are in progress before this Act enters into force.
Article 4 (Transitional measures concerning certification of information security management systems)
A person who has not received the certification of an information security management system shall receive the certification within 6 months after this Act enters into force, in accordance with the amended provisions of Article 47 (2).
Article 5 (Transitional measures concerning administrative fines)
The previous provisions of this Act shall apply to the imposition of penalties for violations committed before this Act enters into force.
부칙 <제14080호, 2016. 3. 22.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제22조의2, 제76조제1항제1호 및 제1호의2의 개정규정은 공포 후 1년이 경과한 날부터, 제32조제2항ㆍ제3항 및 제32조의2제3항의 개정규정은 2016년 7월 25일부터, 제52조제4항의 개정규정은 공포한 날부터 시행한다.
제2조(손해배상에 관한 적용례)
제32조제2항ㆍ제3항 및 제32조의2제3항의 개정규정은 같은 개정규정 시행 후에 분실ㆍ도난ㆍ유출ㆍ위조ㆍ변조 또는 훼손된 개인정보에 관한 손해배상 청구분부터 적용한다.
제3조(위반행위에 노출된 사실 안내에 관한 경과조치)
정보통신서비스 제공자는 이 법 공포 후 6개월 이내에 제49조의2제3항의 개정규정에 따라 이용자에게 안내메시지를 보낼 수 있는 설비를 구축하여야 한다.
제4조(벌칙에 관한 경과조치)
이 법 시행 전의 행위에 대하여 벌칙을 적용할 때에는 종전의 규정에 따른다.
제5조 생략
ADDENDA <Act No. 14080, Mar. 22, 2016>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 22-2 and 76 (1) 1 and 1-2 shall enter into force 1 year after the date of promulgation of this Act; the amended provisions of Articles 32 (2) and (3) and 32-2 (3) shall enter into force on July 25, 2016; and the amended provisions of Article 52 (4) shall enter into force on the date of promulgation of this Act.
Article 2 (Applicability to compensation for damage)
The amended provisions of Articles 32 (2) and (3) and 32-2 (3) shall begin to apply to claims made for compensation for damage against information lost, stolen, leaked, forged, altered, or damaged after said amended provisions enter into force.
Article 3 (Transitional measures concerning informing fact of exposure to violations)
A provider of information and communications services shall, not later than 6 months after this Act enters into force, establish equipment, by means of which informing messages can be sent to users pursuant to the amended provisions of Article 49-2 (3).
Article 4 (Transitional measures concerning penalty provisions)
The previous provisions of this Act shall apply to the imposition of penalties for acts committed before this Act enters into force.
Article 5 Omitted.
부칙 <제14580호, 2017. 3. 14.>
이 법은 공포한 날부터 시행한다.
ADDENDUM <Act No. 14580, Mar. 14, 2017>
This Act shall enter into force on the date of its promulgation.
부칙 <제14839호, 2017. 7. 26.>
제1조(시행일)
이 법은 공포한 날부터 시행한다. 다만, 부칙 제5조에 따라 개정되는 법률 중 이 법 시행 전에 공포되었으나 시행일이 도래하지 아니한 법률을 개정한 부분은 각각 해당 법률의 시행일부터 시행한다.
제2조 부터 제4조까지 생략
제5조 생략
ADDENDA <Act No. 14839, Jul. 26, 2017>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation; provided, among the statutes to be amended under Article 5 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 4 Omitted.
Article 5 Omitted.
Article 6 Omitted.
부칙 <제15628호, 2018. 6. 12.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제32조의3, 제45조의3 및 제76조제2항제4호의2(제32조의3의 개정규정과 관련된 부분에 한정한다)의 개정규정은 공포 후 1년이 경과한 날부터 시행한다.
ADDENDUM <Act No. 15628, Jun. 12, 2018>
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 32-3, 45-3, and 76 (2) 4-2 (limited to the part relevant to the amended provisions of Article 32-3) shall enter into force 1 year after the date of its promulgation.
부칙 <제15751호, 2018. 9. 18.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 15751, Sep. 18, 2018>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제16019호, 2018. 12. 24.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. <단서 생략
제2조 생략
제3조 생략
ADDENDA <Act No. 16019, Dec. 24, 2018>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Article 2 Omitted.
Article 3 Omitted.
부칙 <제16021호, 2018. 12. 24.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제44조의4 및 제44조의7제3항제1호의 개정규정은 공포 후 3개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 16021, Dec. 24, 2018>
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 44-4 and 44-7 (3) 1 shall enter into force 3 months after the date of its promulgation.
부칙 <제16825호, 2019. 12. 10.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
제2조(환급가산금에 관한 적용례)
제64조의3제7항 및 제8항의 개정규정은 이 법 시행 후 법원의 판결 등의 사유로 과징금을 환급하는 경우부터 적용한다.
ADDENDA <Act No. 16825, Dec. 10, 2019>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Article 2 (Applicability to additional payment on refund)
The amended provisions of Article 64-3 (7) and (8) shall begin to apply where penalty surcharges are refunded on such grounds as a court judgment after this Act enters into force.
부칙 <제16955호, 2020. 2. 4.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 16955, Feb. 4, 2020>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제17344호, 2020. 6. 9.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. <단서 생략
제2조 부터 제6조까지 생략
제7조 생략
ADDENDA <Act No. 17344, Jun. 9, 2020>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
Article 7 Omitted.
Article 8 Omitted.
부칙 <제17347호, 2020. 6. 9.>
이 법은 공포한 날부터 시행한다.
ADDENDUM <Act No. 17347, Jun. 9, 2020>
This Act shall enter into force on the date of its promulgation.
부칙 <제17348호, 2020. 6. 9.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
제2조 부터 제13조까지 생략
제14조 생략
ADDENDA <Act No. 17348, Jun. 9, 2020>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation.
Articles 2 through 13 Omitted.
Article 14 Omitted.
Article 15 Omitted.
부칙 <제17354호, 2020. 6. 9.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. <단서 생략
제2조 부터 제6조까지 생략
제7조 생략
ADDENDA <Act No. 17354, Jun. 9, 2020>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation. (Proviso Omitted.)
Articles 2 through 6 Omitted.
Article 7 Omitted.
Article 8 Omitted.
부칙 <제17358호, 2020. 6. 9.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제4조제2항제7호의2의 개정규정은 공포 후 3개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 17358, Jun. 9, 2020>
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Article 4 (2) 7-2 shall enter into force 3 months after the date of its promulgation.
부칙 <제18201호, 2021. 6. 8.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 18201, Jun. 8, 2021>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제18871호, 2022. 6. 10.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 18871, Jun. 10, 2022>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제19154호, 2023. 1. 3.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 19154, Jan. 3, 2023>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제20069호, 2024. 1. 23.>
제1조(시행일)
이 법은 공포 후 6개월이 경과한 날부터 시행한다. 다만, 제48조제4항 및 제71조제1항제13호의 개정규정은 공포한 날부터 시행하고, 제23조의5제1항제3호의 개정규정은 법률 제19234호 개인정보 보호법 일부개정법률 부칙 제1조제2호에 따른 시행일부터 시행한다.
제2조(정보보호 관리체계 인증의 특례에 관한 적용례)
제47조의7제1항 및 제3항의 개정규정은 이 법 시행 이후 제47조제1항 및 제2항에 따른 인증을 받으려는 자부터 적용한다.
제3조(연계정보 생성ㆍ처리의 승인에 관한 경과조치)
이 법 시행 당시 종전의 「정보통신 진흥 및 융합 활성화 등에 관한 특별법」 제37조 등 다른 법령에 따라 연계정보 생성ㆍ처리 관련 임시허가 또는 그와 유사한 특례 지정 등을 받은 본인확인기관과 정보통신서비스 제공자는 제23조의5제1항제4호의 개정규정에도 불구하고 이 법 시행일부터 1년까지는 같은 개정규정에 따른 방송통신위원회의 승인을 받지 아니하고 연계정보를 생성ㆍ처리할 수 있다.
ADDENDA <Act No. 20069, Jan. 23, 2024>
Article 1 (Enforcement date)
This Act shall enter into force 6 months after the date of its promulgation; provided, the amended provisions of Articles 48 (4) and 71 (1) 13 shall enter into force on the date of their promulgation, and the amended provisions of Article 23-5 (1) 3 shall enter into force on the enforcement date specified in subparagraph 2 of Article 1 of the Addenda of the Personal Information Protection Act (Act No. 19234).
Article 2 (Applicability to special cases concerning certification of information security management system)
The amended provisions of Article 47-7 (1) and (3) shall apply to persons seeking certification under Article 47 (1) and (2) after this Act enters into force.
Article 3 (Transitional measures for approval for creating and processing connecting information)
Identification service agencies and the providers of information and communication services that have received temporary permission or similar special designation for creating and processing connecting information pursuant to other statutes and regulations, including Article 37 of the former Act on the Promotion of Information and Communication and Convergence Activation at the time this Act enters into force, may create and process connecting information without obtaining approval from the Korea Communications Commission under Article 23-5 (1) 4 until 1 year from the date this Act enters into force, notwithstanding its amended provisions.
부칙 <제20260호, 2024. 2. 13.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 20260, Feb. 23, 2024>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제20534호, 2024. 12. 3.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 20534, Dec. 3, 2024>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제20678호, 2025. 1. 21.>
이 법은 공포 후 6개월이 경과한 날부터 시행한다.
ADDENDUM <Act No. 20678, Jan. 21, 2025>
This Act shall enter into force 6 months after the date of its promulgation.
부칙 <제21066호, 2025. 10. 1.>
제1조(시행일)
이 법은 공포한 날부터 시행한다. 다만, 부칙 제7조에 따라 개정되는 법률 중 이 법 시행 전에 공포되었으나 시행일이 도래하지 아니한 법률을 개정한 부분은 각각 해당 법률의 시행일부터 시행한다.
제2조 부터 제6조까지 생략
제7조 생략
ADDENDA <Act No. 21066, Oct. 1, 2025>
Article 1 (Enforcement date)
This Act shall enter into force on the date of its promulgation; provided, among the statutes to be amended under Article 7 of the Addenda, any amendment made by this Act to the statutes that were promulgated before this Act enters into force but whose enforcement dates have yet to arrive shall enter into force on the respective enforcement dates of those statutes.
Articles 2 through 6 Omitted.
Article 7 Omitted.
Article 8 Omitted.
Last updated : - -