Personal information risk management device and control method thereof

The personal information risk management device addresses the challenge of excessive personal information collection by using an AI model to determine the minimum necessary data and controlling access rights, thereby reducing leakage risks and enhancing security.

WO2025121884A1PCT designated stage expired Publication Date: 2025-06-12O NE PEOPLE CO LTD

Patent Information

Application Number
PCT/KR2024/019761
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-12-03
Filing Date
2024-12-04
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

The excessive collection of personal information leads to increased risks of leakage, as it is difficult to determine whether the collected information is the minimum necessary, causing inconvenience to users and making it challenging to identify responsible parties in cases of unauthorized access.

Method used

A personal information risk management device and method that utilizes an artificial intelligence model to determine the minimum necessary personal information required based on the purpose, industry, and items involved, while also controlling access rights according to the security level of personal information handlers and monitoring risk through risk analysis reports.

Benefits of technology

The solution effectively suppresses unnecessary collection of personal information, reduces the risk of leakage, and enhances the security and management of personal information by ensuring only the minimum necessary data is collected and processed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024019761_12062025_PF_FP_ABST
    Figure KR2024019761_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a personal information risk management device and a control method thereof, and the device may comprise: an input module which collects first data including a personal information processing status and a general status of a company; a communication module which transmits and receives the first data to and from an external device including a mobile device; a memory which stores at least one process for performing an operation and stores a user input and data; and a processor which performs a control method according to the process, wherein the processor: collects the first data including the personal information processing status and the general status of the company via the input module; assigns a purpose of processing personal information, on the basis of the collected first data; receives second data including content of a questionnaire form for collecting personal information; measures a first distance between the purpose of processing personal information and the content of the questionnaire form; and determines whether to collect personal information, on the basis of the measured first distance.
Need to check novelty before this filing date? Find Prior Art

Description

Personal information risk management device and its control method

[0001] The present disclosure relates to a personal information management device. More specifically, it relates to a device and method for managing personal information risks, controlling access based on the security level of personal information handlers, monitoring based on a risk analysis report from a trustee, and performing a risk assessment on the trustee for personal information processing.

[0002] With the recent advancements in IT technology, personal authentication and the collection of personal information are becoming essential procedures when using many IT devices. Pursuant to Article 16, Paragraph 1 of the Personal Information Protection Act, personal information processors must collect the minimum amount of personal information necessary for the purpose of collecting personal information. In this case, the burden of proof lies with the personal information processor, who has collected the minimum amount of personal information.

[0003] Currently, the purpose of personal information collection is often unclear, or unnecessary information is collected for that purpose. According to the 2015 Personal Information Protection Survey, approximately 64% of data subjects cited unnecessary and excessive collection of personal information as the primary cause of personal information leaks, and 72% of the public responded that personal information processors currently collect excessive amounts of personal information. However, the minimum necessary scope can vary depending on the industry of the personal information processor, the circumstances of collection, and the purpose of the data collection, making it practically difficult for individuals to determine this.

[0004] At this time, the possibility of personal information leaks increased due to excessive collection of personal information, and it was difficult to determine whether the personal information was the minimum necessary, so personal information was indiscriminately leaked to the outside, causing inconvenience to users.

[0005] Furthermore, if a user's computing resources (PC, server, smart device, etc.) are hijacked through hacking techniques such as malware or worms, or are used by unauthorized users, these computing resources can be illegally used when the user is away from their desk, working outside, or leaving work, regardless of the user's consent. Furthermore, these resources can be misused to leak personal information and confidential company information through the network. In particular, when information is leaked by unauthorized users, it can be difficult to determine who is responsible for the leak, which can cause inconvenience to users.

[0006] In addition, the excessive collection of personal information increases the possibility of personal information leaks, and there was a problem in which personal information was indiscriminately leaked to the outside because it was difficult to determine whether or not it was even minimal personal information, causing inconvenience to users.

[0007] In addition, the possibility of personal information leaks increases due to excessive collection of personal information by trustees who process personal information, and there is a problem in that personal information is indiscriminately leaked to the outside because it is difficult to determine whether it is a minimum amount of personal information, causing inconvenience to users.

[0008] The purpose of the embodiments disclosed in this disclosure is to provide a device and method that can provide guidelines for determining the minimum necessary personal information using an artificial intelligence model that has learned a large number of purposes and personal information items.

[0009] In addition, the embodiments disclosed in the present disclosure aim to provide a device and method capable of providing an artificial intelligence model that determines the minimum necessary personal information among a large amount of personal information items.

[0010] In addition, the embodiment disclosed in the present disclosure aims to provide a device and method capable of inputting the industry, purpose, and items into an artificial intelligence model when creating a service, determining whether it is at least necessary as O or X, and extracting a probability value for it.

[0011] In addition, the embodiments disclosed in the present disclosure aim to provide a device and method for controlling and managing access rights to a system according to the security level of a personal information handler.

[0012] In addition, the embodiment disclosed in this disclosure aims to provide a device and method capable of determining whether a personal information processor has received a certain level of education and possesses capabilities during the personal information download process.

[0013] In addition, the embodiment disclosed in the present disclosure aims to provide a device and method for confirming whether guidance has been applied based on a risk analysis report and guidance of a trustee, calculating a risk grade based on a reflection rate for guidance application, and monitoring the calculated risk grade on a periodic basis.

[0014] In addition, the embodiment disclosed in the present disclosure aims to provide a device and method for evaluating risk by analyzing the risk and reliability of a personal information processing trustee.

[0015] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.

[0016] A personal information risk management device according to the present disclosure comprises: an input module for collecting first data including general conditions of a company and personal information processing conditions; a communication module for transmitting and receiving the first data with an external device including a mobile device; a memory for storing at least one process for performing an operation and storing user input and data; and a processor for performing a control method according to the process, wherein the processor collects first data including general conditions of a company and personal information processing conditions through the input module, assigns a purpose of personal information processing based on the collected first data, receives second data including the contents of a questionnaire form for personal information collection, measures a first distance between the purpose of personal information processing and the contents of the questionnaire form, and determines whether or not to collect personal information based on the measured first distance.

[0017] In addition, a personal information risk management method performed by a processor of a device according to the present disclosure may include a step of collecting first data including general information about a company and a personal information processing status through an input module; a step of assigning a purpose of personal information processing based on the collected first data; a step of receiving second data including the contents of a questionnaire form for collecting personal information; a step of measuring a first distance between the purpose of personal information processing and the contents of the questionnaire form; and a step of determining whether or not to collect personal information based on the measured first distance.

[0018] In addition, a computer program stored in a computer-readable recording medium may be further provided to execute a method for implementing the present disclosure.

[0019] In addition, a computer-readable recording medium recording a computer program for executing a method for implementing the present disclosure may be further provided.

[0020] According to the present disclosure, guidelines for determining the minimum amount of personal information required can be provided using an artificial intelligence model that has learned a large number of purposes and personal information items, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0021] In addition, according to the present disclosure, an artificial intelligence model can be provided that determines the minimum amount of personal information necessary among a large amount of personal information items, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0022] In addition, according to the present disclosure, when creating a service, the industry, purpose, and items can be input into an artificial intelligence model to determine whether it is necessary or not as a minimum, and a probability value can be extracted, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0023] In addition, according to the present disclosure, access rights to the system can be controlled and managed according to the security level of the personal information handler, thereby preventing personal information leakage and safely managing personal information.

[0024] In addition, according to the present disclosure, it is possible to determine whether the personal information processor has received a certain level of training and possesses capabilities during the personal information download process, thereby preventing personal information leakage and safely managing personal information.

[0025] In addition, according to the present disclosure, it is possible to generate a final risk analysis report with a high degree of completion and prevent personal information leakage by checking whether the guidance has been applied based on the risk analysis report and guidance of the trustee, calculating a risk grade based on the reflection rate of the guidance application, and monitoring the calculated risk grade on a periodic basis.

[0026] In addition, according to the present disclosure, the risk and reliability of the personal information processing trustee can be analyzed to assess the risk, thereby enabling a more objective judgment of the suitability of the trustee company, thereby preventing personal information leakage more efficiently.

[0027] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

[0028] Figure 1 is a configuration diagram of the entire system according to the present disclosure.

[0029] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.

[0030] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.

[0031] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.

[0032] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.

[0033] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.

[0034] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.

[0035] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.

[0036] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.

[0037] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.

[0038] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.

[0039] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.

[0040] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.

[0041] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.

[0042] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.

[0043] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.

[0044] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.

[0045] Figure 18 is a drawing showing the status of consignment companies according to the present disclosure.

[0046] Figure 19 is a diagram illustrating the status of personal information processing according to the present disclosure.

[0047] Figure 20 is a drawing showing the status of subcontracting companies according to the present disclosure.

[0048] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.

[0049] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.

[0050] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.

[0051] Figure 24 is a diagram illustrating the configuration of a personal information risk management device according to the present disclosure.

[0052] Figure 25 is a diagram illustrating a flowchart of a personal information risk management method according to the present disclosure.

[0053] FIG. 26 is a diagram illustrating an example of a first distance between the purpose of personal information processing according to the present disclosure and the contents of a questionnaire form.

[0054] Figure 27 is a diagram illustrating an embodiment of calculating the risk of misuse of personal information collected according to the present disclosure and displaying the risk level on the screen.

[0055] Figure 28 is a diagram illustrating an embodiment of calculating the suitability of personal information provided according to the present disclosure, displaying it on a screen, and notifying it to the information subject.

[0056] Figure 29 is a diagram illustrating an embodiment of calculating the risk level according to the level of personal information management of a trustee according to the present disclosure and outputting it on the screen.

[0057] Figure 30 is a diagram illustrating the structure of data according to the present disclosure.

[0058] Figure 31 is a diagram illustrating the formula of OCSVM according to the present disclosure.

[0059] Figure 32 is a diagram illustrating the structure of an isolation forest according to the present disclosure.

[0060] Figure 33 is a diagram illustrating a DATE learning method according to the present disclosure.

[0061] Figure 34 is a drawing illustrating a DPR structure according to the present disclosure.

[0062] Figure 35 is a drawing illustrating an example of output according to the present disclosure.

[0063] Fig. 36 is a diagram illustrating a Cross-Encoder according to the present disclosure.

[0064] Figure 37 is a diagram illustrating a system structure according to the present disclosure.

[0065] Figure 38 is a drawing illustrating the concept of a personal information risk management method according to the present disclosure.

[0066] FIG. 39 is a diagram illustrating a module that determines whether the authority of a user seeking to be granted authority is appropriate in the process of granting roles and authority according to the present disclosure.

[0067] Figure 40 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0068] Figure 41 is a flowchart of an access control method according to the security level of a personal information handler according to the present disclosure.

[0069] Figure 42 is an example of classifying personal information by finding items that are likely to collect personal information in a sentence entered by a user according to the present disclosure.

[0070] Figure 43 is an embodiment of suggesting the purpose of personal information processing based on the title and content of a form entered by a user according to the present disclosure.

[0071] FIG. 44 is a diagram illustrating an embodiment of classifying personal information by analyzing the context of all sentences entered by a user according to the present disclosure to find items that may directly or indirectly collect personal information.

[0072] Figure 45 is a diagram illustrating an embodiment of determining whether to allow system access based on the security level of a personal information handler according to the present disclosure.

[0073] FIG. 46 is a diagram illustrating an example of access control according to the user's role and authority according to the present disclosure.

[0074] Figure 47 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0075] Figure 48 is a diagram illustrating an example of recording a log for processing personal information according to the present disclosure.

[0076] Figure 49 is a diagram illustrating an example of establishing a policy for destroying personal information according to the present disclosure and deleting or storing the information separately.

[0077] Figure 50 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0078] Figure 51 is a diagram illustrating a flowchart 1 of an access control method according to the security level of a personal information handler according to the present disclosure.

[0079] Figure 52 is a diagram illustrating a flowchart 2 of an access control method according to the security level of a personal information handler according to the present disclosure.

[0080] Figure 53 is a diagram illustrating a flowchart of a consulting method for monitoring based on a risk analysis report of a trustee according to the present disclosure.

[0081] FIG. 54 is a drawing illustrating an embodiment of the core concept of the present invention according to the present disclosure.

[0082] Figure 55 is a diagram illustrating a flowchart 1 of a consulting method for monitoring based on a risk analysis report of a trustee according to the present disclosure.

[0083] Figure 56 is a diagram illustrating a flowchart 2 of a consulting method for monitoring based on a risk analysis report of a trustee according to the present disclosure.

[0084] Figure 57 is a diagram illustrating a flowchart of a personal information processing trustee risk assessment method according to the present disclosure.

[0085] FIG. 58 is a drawing illustrating an embodiment explaining the core concept of the present invention according to the present disclosure.

[0086] Figure 59 is a flowchart illustrating a method for assessing the risk of a personal information processing trustee combined with a server according to the present disclosure.

[0087] Throughout this disclosure, the same reference numerals denote the same components. This disclosure does not describe all elements of the embodiments, and any content that is common in the technical field to which this disclosure pertains or that overlaps between embodiments is omitted. The terms "part, module, element, block" used in the specification may be implemented in software or hardware, and depending on the embodiments, multiple "parts, modules, elements, blocks" may be implemented as a single component, or a single "part, module, element, block" may include multiple components.

[0088] Throughout the specification, when a part is said to be "connected" to another part, this includes not only direct connection but also indirect connection, and indirect connection includes connection via a wireless communication network.

[0089] Additionally, when a part is said to "include" a component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.

[0090] Throughout the specification, when we say that an element is "on" another element, this includes not only cases where the element is in contact with the other element, but also cases where another element exists between the two elements.

[0091] The terms first, second, etc. are used to distinguish one component from another, and the components are not limited by the aforementioned terms.

[0092] Singular expressions include plural expressions unless the context clearly indicates otherwise.

[0093] The identification codes for each step are used for convenience of explanation and do not describe the order of each step. Each step may be performed in a different order than specified unless the context clearly indicates a specific order.

[0094] The operating principle and embodiments of the present disclosure are described below with reference to the attached drawings.

[0095] The present invention can be implemented not only in a server system but also in various devices capable of performing computational processing and providing results to a user. For example, the present invention can include a computer, a server device, and a mobile terminal, or can be implemented in any one of these forms.

[0096] Here, the computer may include, for example, a notebook, desktop, laptop, tablet PC, slate PC, etc. equipped with a web browser.

[0097] The above server device is a server that processes information by communicating with an external device, and may include an application server, a computing server, a database server, a file server, a game server, a mail server, a proxy server, and a web server.

[0098] The above portable terminal may include, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as a PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), WiBro (Wireless Broadband Internet) terminal, a smart phone, and a wearable device such as a watch, a ring, a bracelet, an anklet, a necklace, glasses, contact lenses, or a head-mounted device (HMD).

[0099] The artificial intelligence-related functions according to the present disclosure are operated through a processor and memory. The processor may be composed of one or more processors. In this case, one or more processors may be a general-purpose processor such as a CPU, an AP, a DSP (Digital Signal Processor), a graphics-only processor such as a GPU or a VPU (Vision Processing Unit), or an artificial intelligence-only processor such as an NPU. One or more processors control the processing of input data according to predefined operation rules or artificial intelligence models stored in memory. Alternatively, if one or more processors are artificial intelligence-only processors, the artificial intelligence-only processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0100] The predefined operation rules or artificial intelligence models are characterized by being created through learning. Here, being created through learning means that the basic artificial intelligence model is learned by a learning algorithm using a plurality of learning data, thereby creating a predefined operation rules or artificial intelligence model set to perform a desired characteristic (or purpose). This learning may be performed in the device itself on which the artificial intelligence according to the present disclosure is performed, or may be performed through a separate server and / or system. Examples of the learning algorithm include, but are not limited to, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning.

[0101] An artificial intelligence model may be composed of multiple neural network modules. Each of the multiple neural network modules has multiple weight values, and performs neural network operations through operations between the operation results of the previous module and the multiple weights. The multiple weights of the multiple neural network modules may be optimized based on the learning results of the artificial intelligence model. For example, the multiple weights may be updated so that the loss value or cost value obtained from the artificial intelligence model is reduced or minimized during the learning process. The artificial neural network may include a deep neural network (DNN), and examples thereof include, but are not limited to, a convolutional neural network (CNN), a deep neural network (DNN), a recurrent neural network (RNN), a restricted boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), or deep Q-networks.

[0102] The processor can create a neural network, train (or learn) a neural network, perform computations based on received input data, and generate information signals based on the results of the computations, or retrain the neural network.

[0103] Neural networks include CNN (Convolutional Neural Network), RNN (Recurrent Neural Network), perceptron, multilayer perceptron, FF (Feed Forward), RBF (Radial Basis Network), DFF (Deep Feed Forward), LSTM (Long Short Term Memory), GRU (Gated Recurrent Unit), AE (Auto Encoder), VAE (Variational Auto) Encoder), DAE (Denoising Auto Encoder), SAE (Sparse Auto Encoder), MC (Markov Chain), HN (Hopfield Network), BM (Boltzmann Machine), RBM (Restricted Boltzmann Machine), DBN (Depp Belief Network), DCN (Deep Convolutional Network), DN (Deconvolutional Network), DCIGN (Deep Convolutional Inverse Graphics Network), Generative Adversarial Network (GAN), Liquid State Machine (LSM), Extreme Learning Machine (ELM), It will be understood by those skilled in the art that any neural network may be included, including but not limited to ESN (Echo State Network), DRN (Deep Residual Network), DNC (Differentiable Neural Computer), NTM (Neural Turning Machine), CN (Capsule Network), KN (Kohonen Network), and AN (Attention Network).

[0104] According to an exemplary embodiment of the present disclosure, the processor may be configured to perform a process for generating a CNN (Convolution Neural Network) such as GoogleNet, AlexNet, VGG Network, Region with Convolution Neural Network (R-CNN), Region Proposal Network (RPN), Recurrent Neural Network (RNN), Stacking-based deep Neural Network (S-DNN), State-Space Dynamic Neural Network (S-SDNN), Deconvolution Network, Deep Belief Network (DBN), Restrcted Boltzman Machine (RBM), Fully Convolutional Network, Long Short-Term Memory (LSTM) Network, Classification Network, Generative Modeling, eXplainable AI, Continual AI, Representation Learning, AI for Material Design, BERT, SP-BERT, MRC / QA for natural language processing, Text Analysis, Dialog System, GPT-3, GPT-4, Visual Analytics for vision processing, Visual Understanding, Video Synthesis, ResNet for data intelligence, Anomaly Detection, Prediction, Time-Series Forecasting, Various artificial intelligence structures and algorithms, including optimization, recommendation, and data creation, can be utilized, but are not limited thereto. Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.

[0105] Figure 1 is a configuration diagram of the entire system according to the present disclosure.

[0106] Referring to Fig. 1(10), the configuration of the entire system is described.

[0107] The system (10) is briefly composed of part A (100), part B (200), part C (300), part D (400), part E (500), part F (600), and a processor (50).

[0108] Part A (100) may be referred to as the Compliance Collection and Registration Department.

[0109] Part B (200) may be named the Personal Information Collection and Use and Analysis Department.

[0110] Part C (300) may be named the Compliance and Security Risk Analysis Department.

[0111] Department D (400) may be called a service-specific personal information analysis department.

[0112] Part E (500) may be called a personal information destruction part.

[0113] Part F (600) may be called the authentication management department.

[0114] The processor (50) controls section A (100), section B (200), section C (300), section D (400), section E (500), and section F (600).

[0115] At least one detailed function among Part A (100), Part B (200), Part C (300), Part D (400), Part E (500), and Part F (600) can be stored in memory as software, and the processor (50) can execute the detailed function of each part by referring to the memory.

[0116] Define key terms of the present invention.

[0117] Compliance typically encompasses legal compliance, compliance monitoring, and internal control. A compliance program is a set of systems designed to ensure companies voluntarily comply with relevant laws and regulations during their business operations. Compliance also includes security regulations.

[0118] Regulations include laws, enforcement decrees, notices, guides, etc.

[0119] Inspection means construction, and investigation means the act of creating and configuring control items for investigation, that is, the act of establishing standards.

[0120] Control items refer to items that an organization must comply with to protect personal information.

[0121] A trigger is a condition for an occurrence.

[0122] Tags represent main keywords.

[0123] Internal compliance refers to internal rules.

[0124] Security requirements refer to the security standards and security rules requested by each organization (company) or service situation to protect information assets.

[0125] Common regulations are commonalities among national regulations, including national common regulations and industry-specific common regulations.

[0126] Common regulations by country refer to regulations that exist in common among the regulations that exist in each country selected by the institution or company.

[0127] Common regulations by industry refer to regulations that exist in common among the regulations required for the industry, industry, and scale selected by the organization or company.

[0128] Microregulations are regulations that differ among multiple regulations.

[0129] For example, micro-regulations may be regulations that institutions or companies choose to comply with individually, or may be regulations that are not specifically stipulated in the law or have no specific timing or method.

[0130] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.

[0131] Referring to FIG. 2 (210), the compliance collection and registration unit (100) is described.

[0132] The Compliance Collection and Registration Department (100) is abbreviated as Department A (100).

[0133] The A1 module (110) may be named a compliance collection automation module, the A2 module (120) may be named a compliance inspection automation module, and the A3 module may be named a company-specific security requirements analysis automation module.

[0134] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.

[0135] Referring to FIG. 3 (310), the compliance collection automation module (110) is described.

[0136] The compliance collection automation module (110) finds regulations related to personal information by country, classifies the regulatory provisions, and analyzes the ‘subject’, ‘object’, and ‘predicate’ appearing in the provisions by dividing them into main text and clauses.

[0137] The compliance collection automation module (110) sets keywords based on the analysis and creates tags using these.

[0138] The compliance collection automation module (110) includes a compliance collection module (111) and a compliance analysis-refinement ML module (112).

[0139] The compliance collection module (111) includes a Crawler, Scraper, and API.

[0140] The Compliance Analysis-Refinement ML module (112) sets keywords based on the analysis and converts them into tags. It includes Vision AI, NLP AI, and ETC.

[0141] The Compliance Analysis-Refinement ML module (112) performs the following:

[0142] First, determine your priorities.

[0143] 1) Determine whether it is the main text or a proviso, 2) the priority of regulations based on whether it is a general law or a special law, and 3) the priority of application of regulations based on the legal system.

[0144] Second, it performs subject, object, and verb judgment and tagging.

[0145] 1) Defining the ‘subject of law’ for each clause means judging what corresponds to the subject of a legal provision based on the citation relationship of the legal provision.

[0146] 2) Defining the ‘object of law’ for each clause means judging what corresponds to the object of a legal provision based on the citation relationship of the legal provision.

[0147] 3) Define ‘verb’.

[0148] Third, legal differences are judged and tagging is performed.

[0149] 1) Determine differences between countries regarding specific regulations (laws, enforcement decrees, enforcement rules, notices, instructions, rules, etc.).

[0150] Here, the regulations include:

[0151] An Act (or Law, or Statute) is a law enacted through the legislative process of the National Assembly. It is translated into English as "Act," "Law," or "Statute." For example, "Civil Act" can be translated as "Civil Law."

[0152] An Enforcement Decree is a presidential decree to specifically enforce a law, and is translated into English as "Enforcement Decree."

[0153] Enforcement Rule refers to a regulation of a ministry that provides more detailed regulations for enforcement ordinances, and is translated into English as "Enforcement Rule."

[0154] A public notice (notification) is issued to inform of specific matters and is translated as "Public Notice" or "Notification".

[0155] A directive (or instruction) is an administrative order that gives instructions from a higher authority to a lower authority, and is translated as "directive" or "instruction."

[0156] Regulations (Official Instructions) contain rules regarding procedures or work within an administrative agency and can be translated as "Regulation" or "Official Instruction."

[0157] The country-specific personal information laws (laws, enforcement decrees, rules, notices, instructions, and regulations) management module (not shown) processes personal information-related regulations by country to enable quick assessment.

[0158] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.

[0159] Referring to FIG. 4 (410), the compliance inspection module (120) is described.

[0160] The compliance inspection module (120) builds and creates customized control items related to personal information protection that the organization must comply with.

[0161] The compliance inspection module (120) creates control items by considering 1) the ‘country compliance’ collected and refined in the A1 module (110) and 2) the security requirements.

[0162] The compliance inspection module (120) includes a country-specific compliance inspection trigger automation module (121) and an internal regulation generation module (122).

[0163] The country-specific compliance inspection trigger automation module (121) investigates personal information protection regulations (compliance) by country (the method is to attach an appropriate tag to each provision) and classifies the investigated regulatory tags as micro-regulations or common regulations.

[0164] The internal regulation generation module (122) selects micro-regulations in accordance with internal compliance and generates internal regulations based on the selected micro-regulations.

[0165] The internal regulation creation module (122) allows the internal security officer to review the values ​​from the primary module, select micro-regulations that fit the internal regulations, and create internal regulations using the selected regulations.

[0166] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.

[0167] Referring to FIG. 5 (510), the in-house compliance inspection automation module (123) is described.

[0168] The in-house compliance inspection automation module (123) creates internal regulations as inspection automation modules (as inspection items) so that inspection can be turned on or off.

[0169] The in-house compliance inspection automation module (123) can be connected to the B2 module (220).

[0170] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.

[0171] Referring to Figure 6 (610), the company-specific security requirements analysis automation module (130) is described.

[0172] The company-specific security requirements analysis automation module (130) includes a business security requirements analysis module (131). Here, the company also includes an institution.

[0173] The company-specific security requirements analysis automation module (130) obtains agency information and service information.

[0174] Obtain country information from the location, company name, size, company identification number, and service information.

[0175] The business security requirements analysis module (131) determines which regulation applies based on the acquired information.

[0176] Specifically, the business security requirements analysis module (131) determines which regulations will be applied based on the (obtained) organization / service information.

[0177] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.

[0178] Referring to Figure 7 (710), the personal information collection and use and analysis unit (200) will be described.

[0179] The personal information collection and use and analysis department (200) corresponds to Department B (200).

[0180] Part B (200) includes a B1 module (210), a B2 module (220), a B3 module (230), a B4 module (240), and a B5 module (250).

[0181] The B1 module (210) may be named a collection form creation and response automation module, the B2 module (220) may be named a personal information collection detection automation module, the B3 module (230) may be named a collection and use consent form automatic creation module, the B4 module (240) may be named a personal information processing policy automatic creation module, and the B5 module (250) may be named a personal information subject token and consent history hash creation module.

[0182] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.

[0183] Referring to FIG. 8 (810), the collection form creation and response automation module (210) is described.

[0184] The collection form creation and response automation module (210) allows the administrator to create an input form and collect personal information from the information subject.

[0185] The collection form creation and response automation module (210) includes a personal information collection form creation module (211), a personal information collection detection module (212), an in-house compliance establishment module (213), a processing basis creation module (214), and a personal information processing policy creation module (215).

[0186] The personal information collection form creation module (211) collects content (text, image, video), determines the response method (electronic signature, identity verification), and creates a list and type of information to be collected.

[0187] The personal information collection detection module (212) determines whether the personal information collected in the form for collecting personal information is actual personal information, and if the collected information corresponds to personal information, it transmits the information to the ‘Collection Behavior Management Department’ in charge of personal information collection detection.

[0188] The in-house compliance building module (213) investigates in-house compliance.

[0189] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts an investigation, it can be considered an inspection.

[0190] The processing basis generation module (214) automatically generates a personal information collection and use consent form.

[0191] The processing basis generation module (214) automatically generates personal information collection / provision and use consent forms, as well as processing basis forms. Because the consent forms are generated based on institutional and service information, they can be customized. The consent forms can be modified, such as by tailoring them based on the information of the data subject providing the personal information.

[0192] The grounds for processing are as follows:

[0193] 1. In case the consent of the information subject has been obtained.

[0194] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.

[0195] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.

[0196] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.

[0197] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.

[0198] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the legitimate interests of the personal information processor are significantly related and do not exceed a reasonable scope.

[0199] 7. In cases where it is for public safety and well-being, such as public health.

[0200] The personal information processing policy creation module (215) automatically creates a personal information processing policy.

[0201] The personal information processing policy creation module (215) automatically generates a personal information processing policy based on institutional and service information. It can also create a customized personal information processing policy based on the information of the data subject providing the personal information. The generated personal information processing policy is then transferred to the "Processing Policy Management Department" for management.

[0202] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.

[0203] Figure 9 includes Figures 9(a), 9(b) and 9(c).

[0204] Figure 9(a)(910) is a drawing illustrating a personal information collection form creation module (211).

[0205] Figure 9(b)(920) is a diagram illustrating a personal information collection detection module (212), an in-house compliance establishment module (213), and a processing basis generation module (214).

[0206] Figure 9(c)(930) is a diagram illustrating a personal information processing policy creation module (215).

[0207] As shown in Fig. 9(a)(910), the personal information collection form generation module (211) generates a form for importing personal information, which can be selected by the in-house service manager based on organization information and service information, and automatically generates a personal information collection form (S1).

[0208] As shown in Fig. 9(b)(920), the personal information collection detection module (212) determines whether the information collected in the form for collecting personal information is personal information or not, and if the collected information corresponds to personal information, it transmits the information to the ‘collection behavior management department’ in charge of personal information collection detection (S2).

[0209] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts investigations, it conducts inspections (S3).

[0210] The processing basis generation module (214) automatically generates a consent form for the collection / provision of personal information or a basis for processing (S4). Because it generates a consent form based on institutional and service information, it can be customized. The consent form can be modified, such as by tailoring it based on the information of the data subject providing the personal information.

[0211] The grounds for processing are as follows:

[0212] 1. In case the consent of the information subject has been obtained.

[0213] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.

[0214] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.

[0215] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.

[0216] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.

[0217] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the legitimate interests of the personal information processor are significantly related and do not exceed a reasonable scope.

[0218] 7. For public safety and well-being, including public health.

[0219] As illustrated in Fig. 9(c)(930), the personal information processing policy creation module (215) automatically creates a personal information processing policy based on institutional information and service information, and manages it by transferring it to the ‘processing policy management department’ (S5).

[0220] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.

[0221] Referring to FIG. 10 (1010), the personal information collection detection automation module (220) includes an AI inspection module (221) for detecting whether personal information collection is requested and an AI inspection module (222) for detecting whether personal information is submitted.

[0222] The personal information collection detection automation module (220) is linked with the personal information collection detection module (212) of the B1 module (210).

[0223] The personal information collection detection automation module (220) is linked with the in-house compliance inspection automation module (123).

[0224] The personal information collection detection automation module (220) detects whether a personal information collection request has occurred and manages the collected information by determining whether it corresponds to actual personal information. Personal information includes sensitive information, unique identification numbers, and resident registration numbers.

[0225] The AI ​​Inspect module (221) detects whether a request for personal information collection has been made and automatically classifies the type of information being collected (e.g., personal information, sensitive information, unique identification number, etc.) according to the type of personal information, and automatically applies the appropriate processing procedure for each type.

[0226] The AI ​​Inspect module (222) detects whether personal information has been submitted, and determines whether the information provided by the user is personal information through AI-based analysis (e.g. Vision AI, NLP AI, etc.) to prevent unwanted, unnecessary, and unintended collection of personal information, and detects whether it has been collected.

[0227] The AI ​​Inspect module (222) that detects whether personal information has been submitted analyzes the user's input data using various artificial intelligence technologies such as Vision AI and NLP AI, and determines in real time whether the input information corresponds to personal information.

[0228] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.

[0229] Referring to FIG. 11 (1110), the automatic collection and use consent form generation module (230) is described.

[0230] The automatic collection and use consent form generation module (230) corresponds to the B3 module (230).

[0231] The automatic collection and use consent form automatic generation module (230) includes a processing guide, an automatic collection and use consent form generation module (231), an automatic consent form type template reflection module (232), and a personal information collection purpose analysis module (233).

[0232] The automatic collection and use consent form generation module (230) is a system that automatically generates and manages consent forms required during the collection and processing of personal information. It analyzes the type and purpose of personal information collection to automatically apply an appropriate consent form template. It also generates customized consent forms that reflect legal requirements, automating the process of obtaining consent from data subjects, thereby complying with personal information protection regulations.

[0233] The operational flow of the present invention is described.

[0234] First, the type of personal information consent form is selected according to the type of personal information classified by the B2 module (220).

[0235] Second, the information that should be included in the consent form is directly entered by the personal information processor.

[0236] 1. If the purpose of processing personal information falls under the conditions that do not require the creation of a consent form, a basis for consent is created.

[0237] 2. In the case of creating a consent form, the purpose of processing personal information in the consent form is proposed in the personal information collection purpose analysis module by referring to the value of the personal information collection form creation module.

[0238] 3. Create a consent form using the above information and the template selected by the personal information processor.

[0239] The automated processing guide, collection and use consent form generation module (231) automatically generates consent forms and processing guides related to personal information, sensitive information, and unique identification information. Consent forms and guides are categorized into the following formats.

[0240] 1) In the case of a consent form for collection and use of personal information, it is created when collecting general personal information (name, phone number, email, etc.) and includes the items collected, purpose, retention period, right to refuse consent, and disadvantages thereof.

[0241] 2) In the case of consent to collection and use of sensitive information, it is used when collecting sensitive personal information such as health information and financial information, and includes notifications and requests for additional consent in accordance with relevant laws.

[0242] 3) In the case of a consent form for the collection and use of unique identification information, it is created when collecting unique identification numbers such as alien registration number, passport number, and driver's license number, and includes a request for notification and additional consent items in accordance with relevant laws.

[0243] 4) In the case of the Resident Registration Number Processing Guide, it is a guide provided when processing a unique identification number such as the Resident Registration Number, and the purpose of processing and legal basis are clearly stated.

[0244] 5) In the case of an optional consent form, it is created when personal information is collected selectively rather than for essential purposes such as advertising, and includes the collected items, purpose, retention period, right to refuse consent, and disadvantages thereof.

[0245] The automated module for creating a processing guide, collection and use consent form (231) provides an intuitive interface so that the data subject can understand the consent form and easily choose whether to consent, and each item of the consent form is updated in accordance with relevant laws and regulations.

[0246] The automated consent form template reflection module (232) predefines various types of consent forms and processing guide templates and automatically reflects the appropriate template based on the user's selected personal information collection purpose and legal requirements. The main functions of this module are as follows:

[0247] First, consent form template management.

[0248] Different templates are provided depending on the type of personal information collected, and customized consent forms are created based on the service purpose. For example, different templates can be applied depending on the personal information required for online service registration and offline transactions.

[0249] Second, there are template reflection rules.

[0250] It operates based on rules that automatically select the appropriate template when a specific type of information is entered, as well as the preferences of the personal information handler. For example, when collecting health information, a sensitive information template is applied, while when collecting simple contact information, a personal information template is applied.

[0251] Third, it is an automatic reflection of legal regulations.

[0252] Consent form templates reflect country-specific and industry-specific legal regulations according to predefined rules. For example, consent forms are tailored to the application of the GDPR (European General Data Protection Regulation) and the CCPA (California Consumer Privacy Act).

[0253] The consent form type template reflection automation module (232) is continuously updated, and when new laws or regulations are announced, the corresponding contents can be immediately reflected in the template.

[0254] The personal information collection purpose analysis module (233) utilizes Vision AI, NLP AI, and other artificial intelligence technologies to analyze user-entered information and automatically classify and process the personal information collection purpose accordingly. Its main functions are as follows:

[0255] First, it is Vision AI-based image analysis.

[0256] If the personal information collection form includes an image, the subject matter within the text or image is extracted and analyzed to suggest an appropriate purpose. For example, if the subject matter of an event is extracted from an event poster image, a corresponding purpose is recommended.

[0257] Second, it is NLP AI-based text analysis.

[0258] We analyze text data entered by users to determine the purpose of collection. For example, we analyze information entered by users to create an online registration page and suggest that the purpose is to sign up for a service.

[0259] Third, it is recommended to provide consent forms for each purpose.

[0260] Based on the collected information, we analyze which legal requirements the information must meet and recommend a suitable purpose. For example, if a resident registration number is collected on a prize winner's personal information collection form, we recommend tax reporting purposes.

[0261] The personal information collection purpose analysis module (233) accurately analyzes the purpose of processing collected personal information and helps to notify and obtain consent from the data subject by applying an appropriate processing method in accordance with the Personal Information Protection Act.

[0262] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.

[0263] Referring to Figure 12 (1210), the personal information processing policy automatic generation module (240) is described.

[0264] The personal information processing policy automatic generation module (240) corresponds to the B4 module (240).

[0265] The personal information processing policy automatic generation module (240) includes a service analysis module (241), a processing policy component generation module (242), and a processing policy template reflection automation module (243).

[0266] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It automates all processes, from service analysis to policy template implementation. This module meets legal requirements related to personal information processing and automatically generates policies tailored to the company's service characteristics and security requirements.

[0267] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It uses the service analysis module to identify service characteristics, automatically generates processing policy components, and incorporates these into a template to finalize the final processing policy. This system satisfies legal requirements arising during personal information processing and provides customized processing policies tailored to the characteristics of each service provider, effectively ensuring compliance with legal regulations related to personal information protection.

[0268] The personal information processing policy automatic generation module (240) consists of three modules, and each module efficiently performs the composition of the processing policy and automated management procedures.

[0269] Describes the flow of operations linked with other modules.

[0270] First, the status of the service is provided to the user and the requirements for processing policies related to the status, such as the relevant industry, are analyzed.

[0271] Second, the user is provided with the status of personal information processing and the requirements for processing policies related to that status are analyzed.

[0272] Third, a personal information processing policy is established based on the information provided.

[0273] Fourth, the personal information processing policy is printed by applying the template selected by the user.

[0274] The service analysis module (241) analyzes the service's size, industry, and security requirements to develop a personal information processing policy tailored to the characteristics of the company or service provider. Its main functions are as follows:

[0275] First, industry analysis.

[0276] By analyzing the industry to which the service belongs, the system automatically reflects the industry's regulatory and legal requirements. For example, financial services and healthcare services have different legal requirements, so processing policies tailored to each industry are automatically identified and generated.

[0277] Second, analysis of service scale.

[0278] The complexity and requirements of a privacy policy vary depending on the size of the business. This module analyzes the size of the service provider—large corporations, small and medium-sized enterprises, and startups—and selects an appropriate privacy policy. Large-scale services can apply complex data processing policies, while smaller services can adopt simplified policies.

[0279] Third, there is the analysis of other variables (ETC).

[0280] We analyze various factors, including the service provider's business model, customer base, and whether or not international data transfers are involved. For example, if you provide a global service, legal requirements for cross-border data transfers are reflected in your processing policy.

[0281] The processing policy component generation module (242) automatically generates key components of the processing policy based on data provided by the service analysis module. This module designs each item of the processing policy in detail and can be tailored to the company's operational policies. Its main functions are as follows:

[0282] First, it is the collection, use, and provision of personal information.

[0283] It defines the purpose of collecting personal information, the types of information collected, and whether or not consent is required from the data subject. This includes the scope of use of the personal information collected by the company and how it is provided to third parties, and is designed to ensure clear disclosure to the data subject.

[0284] Second, whether or not pseudonymized information is processed.

[0285] For companies using pseudonymized information, the scope of use and processing methods for pseudonymized personal information are automatically defined. This provision is tailored to the type of data requiring pseudonymization and its intended use, and legal justification is provided where necessary.

[0286] Third, there is the information retention and destruction policy.

[0287] Define how long collected personal information will be retained and how it will be destroyed when no longer needed. This section automatically generates information retention periods and destruction procedures, and includes data retention and destruction policies tailored to specific legal regulations (e.g., GDPR or CCPA).

[0288] Fourth, entrustment of personal information and provision to third parties.

[0289] When personal information is outsourced or provided to a third party, all necessary legal procedures and consent forms are managed. Clearly define the legal requirements for entrusting personal information, the method of data sharing with third parties, and notify the data subject and obtain their consent.

[0290] Fifth, overseas relocation and security personnel.

[0291] When personal information is transferred internationally, it reflects the security and legal requirements that arise during the process. Furthermore, it is designed to strengthen data protection by specifying the deployment of security personnel within the company and their roles.

[0292] The Processing Policy Template Reflection Automation Module (243) reflects the generated personal information processing policy components into templates and automates their implementation. This module automatically maps each component to a predefined template to complete the processing policy. Its main functions are as follows:

[0293] First, there is the management of processing policy templates.

[0294] We provide predefined templates for each item in our privacy policy, and we customize and optimize these templates to meet the needs of each service provider. For example, financial institutions may provide templates that incorporate more stringent security requirements, while smaller services may offer simpler policies.

[0295] Second, there is automatic template mapping.

[0296] Data generated by the service analysis module and processing policy component generation module is automatically mapped to templates. This process is performed without manual intervention, and processing policies tailored to the characteristics of each service are automatically generated.

[0297] Third, it reflects legal requirements.

[0298] Automated rules are set up within templates to ensure legal requirements are reflected. For example, if regulations such as GDPR or CCPA are included, applicable items are automatically added and information specifying the rights and responsibilities of data subjects is included.

[0299] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.

[0300] Referring to FIG. 13 (1310), the personal information subject token and consent history hash generation module (250) is described.

[0301] The personal information subject token and consent history hash generation module (250) corresponds to the B5 module (250).

[0302] The personal information subject token and consent history hash generation module (250) includes a third-party DID module (251), a personal information subject token generation module (252), and a consent history hash generation module (253).

[0303] The Personal Information Subject Token and Consent History Hash Generation Module (250) is responsible for generating and managing the data subject's token and the consent history hash value in the personal information protection system. This module handles data subject authentication in various ways, securely stores data generated during the consent process, and maintains record integrity through hash values. Furthermore, it collaborates with third parties (DIDs) to provide various authentication methods and ensure information reliability.

[0304] The Personal Information Subject Token and Consent History Hash Generation Module (250) automates all procedures required for data subject token generation and consent history management. This module securely authenticates the data subject's identity, converts consent history into a hash value to ensure integrity, and thoroughly manages submitted personal information. This module effectively meets legal requirements related to personal information protection.

[0305] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.

[0306] Referring to FIG. 14 (1410), the compliance and security risk analysis unit (300) is described.

[0307] The compliance and security risk analysis unit (300) includes a personal information risk scoring module (310).

[0308] The personal information risk scoring module (310) includes a personal information flow risk identification scoring module (311), a third-party (trustee) cooperation scoring module (312), a personal information destruction scoring module (313), a personal information consistency scoring module (314), a consent history management scoring module (315), a registration and processing policy maintenance scoring module (316), and an overall integrated scoring module (317).

[0309] The Compliance and Security Risk Analysis Department (300) automatically evaluates the risk of personal information within the system to meet personal information protection and compliance requirements, and performs a comprehensive risk assessment through various scoring methods.

[0310] The Compliance and Security Risk Analysis Department (300) evaluates security risks that may arise at all stages of personal information collection, processing, storage, and destruction, and supports the implementation of appropriate protective measures.

[0311] The Compliance and Security Risk Analysis Department (300) analyzes the risk of personal information through various scoring methods, and each scoring is performed based on the following criteria.

[0312] Describes the flow of operations linked with other modules.

[0313] First, each scoring function operates independently.

[0314] Second, the risk is analyzed based on the scoring results.

[0315] The Personal Information Flow Risk Identification Scoring Module (311) assesses potential risks that may arise during the process of personal information being collected and then transferred within the system. Its main functions include:

[0316] First, data movement path analysis.

[0317] Track and analyze where personal information moves within the system and how it is processed. Identify potential data leaks and unauthorized access that may occur during the information transfer process, and assess the risk.

[0318] Second, access rights analysis.

[0319] Analyze the level of user access to personal information to assess whether appropriate permissions have been granted. If permissions are unnecessarily broad or illegal access attempts are detected, the risk is assessed as high.

[0320] Third, data encryption status analysis.

[0321] Ensure that appropriate encryption is applied during data transfer. If encryption is not applied or the encryption level is low, the risk score increases.

[0322] The Third-Party (Trustee) Collaboration Scoring Module (312) assesses the risks associated with sharing personal information with external trustees or third parties. It analyzes potential security risks when personal information is processed by trustees. Its main functions include:

[0323] First, it is an evaluation of the trustee's security level.

[0324] Assess the security policies and management status of the trustee handling personal information. If the trustee is not implementing appropriate security measures or has not obtained security certification, the risk is assessed as high.

[0325] Second, data transmission security evaluation.

[0326] Analyze the security protocols used when personal information is transmitted to third parties. For example, assess whether data is transmitted encrypted and whether security certificates are valid to determine the level of risk.

[0327] Third, third-party access control analysis.

[0328] Analyze the permissions and access control methods of third parties who have access to personal information. Risk increases if unnecessary access is granted or management is poor.

[0329] The Personal Information Destruction Scoring Module (313) evaluates the process of appropriately destroying collected personal information when it is no longer needed or the legal retention period has expired. Its main functions include:

[0330] First, it is an evaluation of compliance with the destruction policy.

[0331] Evaluate whether your personal information destruction policy complies with relevant laws and regulations. For example, ensure that personal information is destroyed promptly according to legal requirements such as the GDPR and CCPA.

[0332] Second, the destruction method is evaluated.

[0333] Assess whether personal information has been completely deleted or recovered appropriately. If secure data deletion methods (e.g., digital shredding, overwriting, etc.) were not applied, the risk is assessed as high.

[0334] Third, the transparency of the destruction procedure is assessed.

[0335] Assess whether the destruction process is transparently managed and recorded. If the destruction process is unclear or records are incomplete, the risk increases.

[0336] The Personal Information Integrity Scoring Module (314) evaluates whether collected personal information is used for its intended purpose and whether the collected information is accurate. Its main functions are as follows:

[0337] First, it is an evaluation of whether it matches the purpose of collection.

[0338] We analyze whether personal information is being used for the originally agreed-upon purposes. If personal information is used for purposes other than those agreed upon, the risk is assessed as high.

[0339] Second, it is an assessment of the accuracy of personal information.

[0340] Assess the accuracy of collected personal information and whether any inaccurate information has been entered. Risks increase when inaccurate information is processed or errors occur.

[0341] Third, it is an evaluation of the protection of the rights of the information subject.

[0342] Assess whether the data subject can appropriately exercise their right to correct, delete, or suspend the use of their personal information. If the data subject's request is ignored or not processed, the risk is assessed as high.

[0343] The Consent History Management Scoring Module (315) evaluates whether appropriate consent was obtained from the data subject when personal information was collected and whether that consent was legally managed. Its main functions are as follows:

[0344] First, it is an evaluation of compliance with the consent procedure.

[0345] Assess whether clear consent has been obtained from the data subject for the collection and use of personal information. If personal information is collected or used without proper consent, the risk is assessed as high.

[0346] Second, it is an evaluation of the management status of consent records.

[0347] Assess whether consent records are securely stored and whether withdrawals are promptly reflected upon the data subject's request. Risks increase if consent records are damaged or withdrawal requests are not reflected.

[0348] The Registration and Processing Policy Maintenance Scoring Module (316) evaluates whether personal information processing policies are properly registered and maintained. Its main functions are as follows:

[0349] First, it is an evaluation of the latest processing policy.

[0350] Evaluate whether your privacy policy is continuously updated to reflect the latest legal requirements. If your privacy policy is not updated despite legal changes, the risk is assessed as high.

[0351] Second, it is an evaluation of the transparency of the processing policy.

[0352] Evaluate whether the processing policy is easily accessible to the data subject and whether it is clear and understandable. If the processing policy is unclear or difficult for the data subject to access, the risk increases.

[0353] The overall integrated scoring module (317) synthesizes the risks generated from each individual scoring module to calculate the overall integrated risk of the personal information processing process. The overall integrated scoring includes the following elements:

[0354] First, weighting is applied.

[0355] The overall risk is calculated by applying weights based on the importance of each scoring module. For example, if the personal information destruction scoring is weighted heavily, a flaw in the destruction process will significantly impact the overall risk.

[0356] Second, it is the calculation of comprehensive risk.

[0357] Based on the individual scoring results, a final overall risk assessment is calculated. The overall risk assessment indicates the overall security level of personal information processing and can be used to suggest additional security measures or management strategies.

[0358] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.

[0359] Referring to Figure 15 (1510), the service-specific personal information analysis unit (400) is described.

[0360] The service-specific personal information analysis unit (400) includes a service-specific personal information analysis module (410).

[0361] The service-specific personal information analysis unit (400) is a system that analyzes personal information collected during service provision by pseudonymizing and anonymizing it, and based on this, classifies the answers provided by users into keywords and determines the meaning of positive or negative.

[0362] The service-specific personal information analysis unit (400) performs pseudonymization and anonymization processing for personal information protection, and analyzes personal information in various stages to support functions necessary for service provision. The service-specific personal information analysis unit (400) of the present invention primarily consists of the following processing steps.

[0363] Step 1 is the pseudonymization step.

[0364] Pseudonymization is the process of protecting personally identifiable information by pseudonymizing it. Pseudonymization is a key method for strengthening privacy protection while using personal information for data analysis and service optimization. Its key functions include:

[0365] First, the personal information identification elements are separated.

[0366] Personal information provided by users, such as name, resident registration number, and email address, is replaced with the minimum information necessary for data analysis. This ensures that data is processed in a way that does not identify specific individuals.

[0367] Second, the application of a pseudonymization algorithm.

[0368] Pseudonymization involves replacing personal information using algorithms such as randomization or hash functions. For example, a user's name is pseudonymized by replacing it with a randomly generated ID. This ID can identify the same individual, but cannot be directly traced back to the original data.

[0369] Third, pseudonymized data management for data analysis.

[0370] Pseudonymized personal information is managed for analysis purposes and stored separately from the original data. After analysis, the original data can be set to not be restored.

[0371] The second step is the anonymization step.

[0372] Anonymization is the process of removing all personally identifiable information from personal data, rendering it completely anonymous. Anonymization completely obscures an individual's identity and is primarily used in statistical analysis and large-scale data analysis. Its main functions are as follows:

[0373] First, the complete removal of personal identification factors.

[0374] All identifiable information, such as name, resident registration number, and address, is deleted or replaced from personal information so that specific individuals cannot be traced during data analysis.

[0375] Second, it is to strengthen statistical safety.

[0376] Anonymized data is used as aggregated data, not individual information. For example, only non-identifiable information, such as a user's age or gender, is retained for statistical analysis.

[0377] Third, there are measures to prevent re-identification.

[0378] Anonymized data is subject to additional security measures to prevent re-identification. Various security technologies are employed to prevent data recombining to restore the original data.

[0379] Step 3 is the question and multiple answer merge processing step.

[0380] The question and multiple answer merge process analyzes and merges multiple user-provided answers to derive a consistent answer. This process integrates multiple answers to generate final data, and based on that data, it provides results appropriate for the service. Key features include:

[0381] First, there is question analysis.

[0382] The content of user-entered questions and the resulting responses are analyzed. Natural language processing (NLP) technology is used to understand the meaning of the question and extract and process relevant responses.

[0383] Second, multiple answers are merged.

[0384] When multiple answers are provided for the same question, duplicate or ambiguous answers are merged to produce a consistent answer. This improves the quality of the response data and provides consistent results.

[0385] Third, response optimization.

[0386] We refine data by optimizing merged responses to provide optimal answers when providing services.

[0387] Step 4 is the response content analysis step.

[0388] The response content analysis step analyzes user-provided response data and determines the keywords and meaning of the response, whether positive or negative. This step utilizes natural language processing (NLP) technology to analyze the response, extract key keywords, and determine the sentiment of the response through sentiment analysis. Key features include:

[0389] First, keyword extraction.

[0390] This step extracts important keywords from user-provided responses. Frequently occurring or contextually significant words in the text data are identified and categorized as keywords. For example, keywords like "satisfied," "dissatisfied," "fast," and "slow" are extracted.

[0391] Second, there are positive and negative judgments.

[0392] Based on extracted keywords, responses are automatically classified as positive or negative. A sentiment analysis algorithm is used to determine whether keywords carry positive or negative connotations. For example, the keyword "satisfied" is classified as positive, while "dissatisfied" is classified as negative.

[0393] Third, keyword weighting.

[0394] Extracted keywords are weighted to determine their importance in providing services. Different weights are assigned based on importance, increasing the accuracy of analysis results.

[0395] Explains the keywords in the response content and the method of judging whether it is positive or negative.

[0396] First, NLP-based text preprocessing is performed.

[0397] The response data is input into a natural language processing model, where unnecessary words are removed and the data is converted into an analyzable form. This includes preprocessing tasks such as tokenization, stopword removal, and stemming.

[0398] Second, extract keywords.

[0399] Extract important keywords based on preprocessed data. Using techniques like TF-IDF and Word2Vec, we identify high-frequency, context-sensitive words.

[0400] Third, perform sentiment analysis.

[0401] Based on the extracted keywords, the sentiment of the responses is analyzed and classified as positive, negative, or neutral. The sentiment analysis algorithm uses a pre-trained dictionary of positive and negative words to evaluate the sentiment of each keyword.

[0402] Fourth, derive results.

[0403] Finally, the extracted keywords and sentiment analysis results are combined to derive the meaning of the answer and generate the information necessary for providing the service.

[0404] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.

[0405] Referring to Figure 16 (1610), the personal information destruction unit (500) will be described.

[0406] The personal information destruction unit (500) includes a personal information destruction automation and hash generation module (510).

[0407] The personal information destruction automation and hash generation module (510) includes a destruction history hash generation module (511).

[0408] The personal information destruction unit (500) is a system that safely destroys personal information when the collection and storage period of the information ends, and creates a destruction history generated in the process as a hash value to ensure integrity.

[0409] The Personal Information Destruction Department (500) automates the personal information destruction process, ensuring compliance with legal requirements and transparently managing the data destruction process. The Personal Information Destruction Department (500) destroys personal information through the following key steps.

[0410] Step 1: Create a personal information destruction scheduler.

[0411] The Personal Information Destruction Scheduler creation step automatically creates and executes a destruction schedule when personal information no longer needs to be retained. This applies when the personal information retention period has expired or when immediate destruction is required at the data subject's request. Key features include:

[0412] First, review the holding period.

[0413] We review the retention period for each personal information item and determine whether the retention period established by legal or service requirements has been exceeded. Personal information is reviewed based on the preset retention period, and any data exceeding the retention period is designated for destruction.

[0414] Second, the destruction schedule is automatically set.

[0415] When personal information is designated for destruction, a destruction scheduler is automatically created and a destruction schedule is set. The destruction schedule can be adjusted to optimize time, taking into account legal requirements and system resources.

[0416] Third, immediate processing of the request for destruction.

[0417] If the data subject requests immediate destruction of personal information, the scheduler immediately sets a destruction schedule and quickly executes the data destruction process.

[0418] Step 2 is the personal information destruction step.

[0419] The personal information destruction stage is the process of actually destroying personal information according to a schedule set by the scheduler. This stage securely destroys data through physical or logical means, and the destroyed information is processed so that it cannot be recovered. Key features include:

[0420] First, it is a logical breakdown.

[0421] Destruction involves deleting personal information stored within the system. This removes the personal information from files or databases, rendering it inaccessible or retrievable. Logical destruction is performed by removing all indexes and references to the data within the system.

[0422] Second, there is physical destruction.

[0423] Completely destroy data by shredding or deleting disks or other storage media containing personal information stored on physical storage devices. This method physically destroys the disk or media, rendering the data unrecoverable.

[0424] Third, data overwriting.

[0425] To ensure that logically deleted data cannot be recovered, the space where the data was stored is repeatedly overwritten with random data to ensure its destruction. This process is a secure method for completely erasing digital data, preventing any possibility of recovery.

[0426] Step 3 is the destruction history hash generation step.

[0427] The destruction history hash generation step records the history of personal information destruction and generates a hash value to ensure integrity. This step records information about the destroyed personal information and the destruction process, and generates a hash value to prevent tampering with this information. Its main functions are as follows:

[0428] First, it is the collection of destruction history data.

[0429] After personal information is destroyed, all data generated during the destruction process is collected. This includes information such as the personal information subject token, authentication method, authentication date, collection form ID, consent ID, and processing policy ID. This data is crucial for ensuring the reliability of the destruction history.

[0430] Second, hash value generation.

[0431] A unique hash value is generated by applying a hash algorithm (such as SHA256) based on the collected destruction history data. This hash value ensures the integrity of the destruction history and protects the data from tampering during the subsequent verification process.

[0432] Third, storage and management of destruction history.

[0433] The generated hash values ​​are securely stored along with the history of destroyed personal information and are managed so that their integrity can be verified by certification authorities or audit processes. The logs and hash values ​​of destroyed data are protected from external access and can be referenced for data verification when necessary.

[0434] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.

[0435] Referring to FIG. 17 (1710), the authentication management unit (600) is described.

[0436] The authentication management unit (600) includes a personal information protection authentication management module (610).

[0437] The certification management department (600) is a system that manages and maintains certifications related to personal information protection, and performs the role of obtaining and maintaining various international and domestic standard certifications based on compliance logs generated within the company.

[0438] The authentication management unit (600) safely processes data generated during the authentication acquisition process and is comprised of steps to verify compliance with authentication standards. The authentication management unit (600) of the present invention primarily manages authentication through the following steps.

[0439] Step 1 is to create an in-house compliance log.

[0440] The internal compliance log generation step involves recording all activities occurring within the system to ensure compliance with privacy and related legal regulations. These logs contain data related to personal information processing, access control, and security incident response, primarily collecting and storing the following information:

[0441] First, there is a record of personal information processing activities.

[0442] All activities, including the collection, storage, processing, and destruction of personal information, are recorded in internal compliance logs. Each record includes the time of the activity, the person responsible, and related information.

[0443] Second, there is an access control log.

[0444] Prevent illegal access or abuse of authority by recording the users who accessed personal information, their authority level, and the time of access.

[0445] Third, there is a record of security incident response.

[0446] If a security incident involving personal information occurs, we record the response to the incident. For example, this includes incident response records for hacking attempts or internal information leaks.

[0447] The logs collected at this stage will be used as data required for subsequent certification applications, and all personal information processing activities occurring within the company will be transparently recorded.

[0448] Step 2 is to create an in-house compliance log hash.

[0449] The in-house compliance log hash generation step generates a hash value to ensure the integrity of the collected compliance log data. The hash value plays a crucial role in protecting the data and verifying whether the log has been tampered with during subsequent authentication procedures. Its main functions are as follows:

[0450] First, the hash algorithm is applied.

[0451] A cryptographic hash algorithm, such as SHA256, is applied to the collected log data to generate a unique hash value. This proves that the log data has not been tampered with.

[0452] Second, log integrity is guaranteed.

[0453] The generated hash value ensures the integrity of the compliance log and provides credibility when the log is subsequently reviewed by a certification authority. This hash value can be provided to external certification authorities to help verify the log's authenticity.

[0454] Third, hash value storage.

[0455] The generated hash value is stored in a secure database and can be referenced during subsequent authentication procedures. The stored hash value serves as a crucial element in verifying that log data has not been tampered with.

[0456] Step 3 is the certification application and management stage.

[0457] The certification application and management stage involves applying for and maintaining international and domestic personal information protection-related certifications based on internally generated compliance logs and hash values. Key certifications are managed in accordance with ISO standards and domestic and international regulations. The process for obtaining these certifications is as follows.

[0458] First, ISO 27701.

[0459] ISO 27701, a Personal Information Management System (PIMS) certification, is an international standard for personal information protection. The certification management department reviews compliance with the ISO 27701 certification criteria and prepares the necessary documents and log data to apply for certification. ISO 27701 certification evaluates compliance with the standard for personal information protection policies, risk management, and personal information processing activities.

[0460] Second, ISO 27001.

[0461] ISO 27001, an Information Security Management System (ISMS) certification, is an international standard for information security. This standard assesses whether an organization has established the management systems necessary to maintain the confidentiality, integrity, and availability of information. The certification management department manages internal information security policies and procedures in accordance with ISO 27001 standards and generates essential log data to maintain certification.

[0462] Third, ISMS-P.

[0463] As a domestic personal information protection and information security management certification, ISMS-P assesses compliance with domestic legal requirements. This certification requires a management system that satisfies both information protection and personal information protection, and the certification management department collects and manages data to maintain ISMS-P certification.

[0464] Fourth, other certifications.

[0465] Other certifications related to privacy and information security (e.g., country-specific privacy certifications, industry-specific regulatory certifications, etc.) are also managed by the Certification Management Department. The department manages internal data in accordance with the requirements of each certification, prepares the necessary documents and materials, and applies for certification.

[0466] At this stage, the certification management department (600) manages all matters necessary for maintaining certification, starting from the application process, and continuously performs certification maintenance and renewal procedures in cooperation with the certification agency.

[0467] For example, FIG. 18 shows the status of a consignee according to the present disclosure (1810), FIG. 19 shows the status of personal information processing (1910), and FIG. 20 shows the status of a subcontractor (2010).

[0468] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.

[0469] Referring to Figure 21 (2110), the inspection items of the inspection checklist are described.

[0470] Inspection items are categorized by order, area, category, inspection item, inspection item details, related evidence, and evaluation criteria.

[0471] The area includes administrative safeguards.

[0472] The division includes an internal management plan.

[0473] Inspection items include establishment and implementation of internal management plans.

[0474] Relevant evidence includes the full text of the internal management plan.

[0475] The evaluation criteria are as follows:

[0476] Y - Contains all essential elements of the internal management plan.

[0477] P - Some items in the internal management plan are missing.

[0478] N - Internal management plan not collected.

[0479] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners and individual organizations.

[0480] The details of the inspection items, related evidence, and evaluation criteria are as follows.

[0481] First, the details of the first inspection item, related evidence, and evaluation criteria.

[0482] Question) Are you including all of the following in your personal information protection documents (internal management plan and related regulations)?

[0483] 1. Matters concerning the composition and operation of the personal information protection organization.

[0484] 2. Matters concerning the qualifications and designation of the personal information protection manager

[0485] 3. Matters concerning the roles and responsibilities of the personal information protection officer and personal information handler.

[0486] 4. Matters concerning management, supervision, and education of personal information handlers

[0487] 5. Matters concerning management of access rights

[0488] 6. Matters concerning access control

[0489] 7. Matters concerning encryption of personal information

[0490] 8. Matters concerning storage and inspection of connection records

[0491] 9. Matters concerning the prevention of malicious programs, etc.

[0492] 10. Matters concerning vulnerability inspection to prevent personal information leakage or theft.

[0493] 11. Matters concerning physical safety measures

[0494] 12. Matters concerning the establishment and implementation of a plan to respond to personal information leaks.

[0495] 13. Matters concerning risk analysis and management

[0496] 14. Matters concerning the management and supervision of the trustee when entrusting personal information processing work.

[0497] 15. Matters concerning the establishment, amendment, and approval of the internal personal information management plan.

[0498] 16. Other matters necessary for personal information protection"

[0499] The relevant evidence is as follows.

[0500] 1. Full text of the Personal Information Protection Policy Document (Internal Management Plan and Personal Information Protection-Related Regulations)

[0501] The evaluation criteria are as follows:

[0502] Y - Contains all required elements within the policy document

[0503] P - Some details are missing from the policy document.

[0504] N - No policy document established

[0505] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners, individuals, and organizations.

[0506] Second, the details of the second inspection item, related evidence, and evaluation criteria.

[0507] Question) Are you obtaining approval from the CEO (or Chief Personal Information Officer) for the personal information protection policy document (internal management plan and personal information protection-related regulations) in accordance with internal personnel procedures?

[0508] - Specify approval records in groupware (deliberation) or internal management plan

[0509] Question) Is the personal information protection policy document (internal management plan and personal information protection-related regulations) published internally?

[0510] - Announcement through posting of internal management plan on groupware bulletin board

[0511] - Produce booklets, etc. and place them in accessible locations.

[0512] The relevant evidence is as follows.

[0513] 1. Approval record

[0514] 2. Publication evidence

[0515] The evaluation criteria are as follows:

[0516] Y - Approved and properly publicized

[0517] P - Approved but not published

[0518] N - Not Approved

[0519] Third, here are the details of the third inspection item.

[0520] Question) Are the personal information protection policy documents (internal management plan and personal information protection-related regulations) reviewed regularly (at least once a year)?

[0521] - Annual review history of personal information protection policy documents (internal management plan and personal information protection-related regulations)

[0522] - Details of approval and announcement of revisions

[0523] The relevant evidence is as follows.

[0524] 1. History of revisions to the Personal Information Protection Policy document (internal management plan and personal information protection-related regulations).

[0525] The evaluation criteria are as follows:

[0526] Y - Records the revision history of the privacy policy document.

[0527] N - Do not keep track of revisions to the Privacy Policy document.

[0528] Fourth, the details of the 4th inspection item.

[0529] Question) Are you inspecting and managing the implementation status of the personal information protection policy document (internal management plan and personal information protection-related regulations) at least once a year and implementing improvement measures for any deficiencies?

[0530] - The personal information protection officer shall conduct an inspection of the implementation status of the personal information protection policy document at least once a year.

[0531] - Review and approval of the inspection results by the personal information protection officer

[0532] - Required checklist when checking the status of implementation

[0533] 1. Access Rights Management

[0534] 2. Storage and inspection of connection records

[0535] 3. Encryption measures

[0536] The relevant evidence is as follows.

[0537] 1. Plan for Inspection of the Implementation Status of Personal Information Protection Policy

[0538] 2. Report on the Implementation Status of Personal Information Protection Policy

[0539] The evaluation criteria are as follows:

[0540] Y - We inspect the implementation of our privacy policy at least once a year.

[0541] P - We are checking the implementation status of the personal information protection policy, but there are some missing items among the required inspection items.

[0542] N - No verification of compliance with privacy policy

[0543] Fifth, the details of the fifth inspection item.

[0544] Question) Have you officially designated a Personal Information Protection Officer with appropriate qualifications?

[0545] - Specify the person responsible for personal information protection in the personal information protection policy, organizational chart, and personal information processing policy.

[0546] 1. Business owner or representative

[0547] 2. Executive (if there is no executive, the head of the department in charge of personal information processing)

[0548] ※ In the case of small business owners, the business owner or representative is deemed to have been designated as the personal information protection officer without separate designation.

[0549] The relevant evidence is as follows.

[0550] Official documents that confirm the appointment of a personal information protection officer, such as a personal information protection policy, organizational chart, personal information processing policy, and personnel appointments.

[0551] The evaluation criteria are as follows:

[0552] Y - Designate a personal information protection officer and meet the requirements for designating a personal information protection officer.

[0553] P - A personal information protection officer has been designated, but the requirements for designating a personal information protection officer are not met or the person has not been designated in an official document.

[0554] N - No data protection officer has been designated

[0555] Sixth, the details of the 6th inspection item.

[0556] Question) Are you collecting personal information handlers' security pledges for personal information protection?

[0557] ① Confirmation of whether a security pledge is required upon joining or leaving the company.

[0558] ② Regularly (once a year) check whether all personal information handlers are required to re-sign the security pledge.

[0559] ※ Security pledge composition

[0560] - The following content is designed to remind users of their responsibilities to prevent personal information from being leaked.

[0561] 1. Obligations of personal information handlers to protect personal information

[0562] 2. Disciplinary action in case of violation

[0563] 3. Examples of pledges: The following are relevant evidence, such as personal information security pledges and confidentiality pledges.

[0564] 1. Employee Security Pledge

[0565] 2. Security pledge for former employees

[0566] The evaluation criteria are as follows:

[0567] Y - We are regularly collecting security pledges without fail (at least once a year).

[0568] P - We are collecting security pledges, but there are missing people.

[0569] N - Not requesting a security pledge

[0570] Seventh, the details of the 7th inspection item.

[0571] Question) Do you provide personal information protection training to personal information protection officers and personal information handlers at least once a year?

[0572] - Develop a personal information protection education plan

[0573] ① Prepare an annual personal information protection education plan including the following:

[0574] 1. Educational Purpose and Target

[0575] 2. Training Content

[0576] 3. Training schedule and method

[0577] - Evidence of implementation of personal information protection job-specific training

[0578] ① Confirmation of implementation of personal information protection training for personal information handlers

[0579] ② Confirmation of training implementation evidence at least once a year

[0580] ③ Confirmation of management and supervision of those who have not completed training

[0581] ※ Personal information handler: A person who processes personal information under the direction and supervision of a personal information processor, such as an employee, dispatched worker, or part-time worker.

[0582] The relevant evidence is as follows.

[0583] 1. Personal Information Protection Education Plan

[0584] 2. Personal Information Protection Training Results

[0585] 3. Personal information protection training materials

[0586] 4. Personal information protection training completion certificate

[0587] 5. List of Personal Information Protection Training Attendees

[0588] 6. Other evidence that can confirm personal information protection education

[0589] The evaluation criteria are as follows:

[0590] Y - We have established a personal information protection education plan, provide regular education at least once a year, and supervise and manage those who have not completed the education.

[0591] P - Personal information protection training is conducted at least once a year, but no supervision is provided for those who have not completed the training.

[0592] N - Personal information protection training is not conducted at least once a year.

[0593] Eighth, the details of the 8th inspection item.

[0594] Question) Have you established response procedures and methods in case of loss, theft, or leakage of personal information?

[0595] - A personal information leak response plan must be established and implemented, including matters such as leak reporting and notification, damage report reception, and damage relief.

[0596] - Accidents must be reported to the consignor immediately.

[0597] The relevant evidence is as follows.

[0598] 1. Personal Information Leak Response Plan

[0599] The evaluation criteria are as follows:

[0600] Y - Establishing and implementing a personal information leak response plan.

[0601] N - No personal information leak response plan in place

[0602] Ninth, the details of the 9th inspection item.

[0603] Question) In principle, re-entrustment by the trustee without prior consultation is prohibited, but in cases where re-entrustment is unavoidable, is re-entrustment done according to standards?

[0604] - Re-entrustment must be done with the consent of the consignor.

[0605] - A subcontracting agreement must be prepared based on the consignor's consignment agreement.

[0606] - Personal information cannot be used or provided beyond the scope of work entrusted by the consignor.

[0607] The relevant evidence is as follows.

[0608] 1. Evidence of prior approval

[0609] 2. Contract regarding re-consignment

[0610] The evaluation criteria are as follows:

[0611] Y - Personal information is being re-entrusted according to the relevant standards.

[0612] N - Personal information is being re-entrusted without the entrustor's approval.

[0613] Tenth, here are the details of the 10th inspection item.

[0614] Question) When re-entrusting personal information, are you conducting periodic inspections and training?

[0615] The relevant evidence is as follows.

[0616] 1. Regular inspection and training plan for re-trustees

[0617] 2. Results of regular inspection and training of re-trustees

[0618] The evaluation criteria are as follows:

[0619] Y - We manage and supervise trustees through education and inspection.

[0620] N - Not managing and supervising the trustees through education and inspection.

[0621] N / A - Personal information is not re-entrusted

[0622] Eleventh, details of the 11th inspection item.

[0623] Question) Have you established a personal information processing policy that includes all of the required items below and made it publicly available in a way that is easily understandable to the data subject?

[0624] - Personal information processing policy information (Personal information processing policy drafting guidelines, Personal Information Protection Commission, April 2024)

[0625] 1. Title (required)

[0626] 2. Purpose of processing personal information (required)

[0627] 3. Items of personal information processed (required)

[0628] 4. Matters concerning the processing of personal information of children under the age of 14 (recommended when applicable)

[0629] 5. Personal information processing and retention period (required)

[0630] 6. Matters concerning the procedures and methods for destroying personal information (required)

[0631] 7. Matters regarding provision of personal information to third parties (required when applicable)

[0632] 8. Criteria for determining if additional use or provision continues (required when applicable)

[0633] 9. Matters concerning the entrustment of personal information processing (required when applicable)

[0634] 10. Matters concerning the overseas collection and transfer of personal information (required when applicable)

[0635] 11. Matters concerning measures to ensure the security of personal information (required)

[0636] 12. How to choose whether to disclose sensitive information and whether to keep it private (required if applicable)

[0637] 13. Matters concerning the processing of pseudonymized information (required when applicable)

[0638] 14. Matters concerning the installation and operation of automatic personal information collection devices and their refusal (required when applicable)

[0639] 15. Matters concerning the collection, use, and refusal of behavioral information collected by third parties through automatic personal information collection devices (recommended if applicable)

[0640] 16. Matters concerning the rights, obligations, and exercise methods of the data subject and legal representative (required)

[0641] 17. Name of the Personal Information Protection Officer, the department in charge of personal information management, and the department handling complaints (required)

[0642] 18. Matters concerning the designation of a domestic agent (required if applicable)

[0643] 19. Remedies for Infringement of the Rights of Data Subjects (Recommended)

[0644] 20. Matters concerning the operation and management of fixed-type video information processing equipment (required when applicable)

[0645] 21. Matters concerning the operation and management of mobile video information processing devices (required when applicable)

[0646] 22. Matters autonomously established by the personal information processor regarding personal information processing standards and protective measures in the personal information processing policy (recommended)

[0647] 23. Matters regarding changes to the personal information processing policy (required)

[0648] - Disclosure of personal information processing policy

[0649] ① The established or changed personal information processing policy shall be continuously posted on the operating Internet homepage so that the information subject can easily check it.

[0650] ② In cases where it cannot be posted on the Internet homepage, it can be made public through the following methods:

[0651] 1. Place it in a place where it can be easily seen, such as the personal information processor's workplace.

[0652] 2. Publication in publications, newsletters, promotional materials, or bills issued more than twice a year.

[0653] 3. “Specification in the contract with the information subject for the provision of goods or services, etc.”

[0654] The relevant evidence is as follows.

[0655] 1. Personal Information Processing Policy

[0656] 2. Disclosure of Personal Information Processing Policy"

[0657] The evaluation criteria are as follows:

[0658] Y - We have established and continuously disclose a privacy policy that includes all essential information.

[0659] P - Some of the essential provisions of the privacy policy are missing or not consistently posted.

[0660] N - No privacy policy established

[0661] N / A - Personal information will not be re-entrusted"

[0662] The twelfth, the 12th inspection item details.

[0663] Question) Do you have established and are operating access control procedures for physical storage locations where personal information is stored, such as computer rooms and archives?

[0664] - Office access control procedures

[0665] - Installation of additional control devices such as fingerprint recognition devices, card key devices, and number key devices"

[0666] The relevant evidence is as follows.

[0667] 1. Access Control Procedure Document

[0668] 2. Status of application of access control

[0669] 3. Evidence of access control operation (entrance / exit log, etc.)

[0670] The evaluation criteria are as follows:

[0671] Y - Establish and operate access control procedures for physical storage locations.

[0672] N - No access control procedures for physical storage locations are established.

[0673] The thirteenth, the 13th inspection item details.

[0674] Question) Are documents and auxiliary storage media containing personal information stored in a secure location with a lock or other locking device?

[0675] - Safely store documents and auxiliary storage media containing personal information.

[0676] The relevant evidence is as follows.

[0677] 1. Evidence materials such as documents or auxiliary storage media containing personal information are stored in a separate space with a locking device.

[0678] The evaluation criteria are as follows:

[0679] Y - Documents and auxiliary storage media containing personal information are stored in a safe place.

[0680] N - Documents and auxiliary storage media containing personal information are not stored in a secure location.

[0681] Fourteenth, the details of the 14th inspection item.

[0682] Question) Have you established and implemented a policy to control the import and export of auxiliary storage media?

[0683] - Establish procedures for bringing in / taking out auxiliary storage media within internal regulations.

[0684] ① Check if there is a procedure for bringing in / taking out auxiliary storage media.

[0685] ② Check whether there is a permit request and approval procedure for import / export

[0686] ③ Check the auxiliary storage media import / export management ledger when bringing in / out

[0687] The relevant evidence is as follows.

[0688] 1. Policy on controlling the import and export of auxiliary storage media

[0689] 2. Auxiliary storage media import / export management ledger

[0690] The evaluation criteria are as follows:

[0691] Y - Establishing standards for the import and export of auxiliary storage media and implementing control procedures.

[0692] P - The standards for exporting and importing auxiliary storage media are inadequate or there is no control over export and import.

[0693] N - There are no standards for the import and export of auxiliary storage media, and there is no control over import and export.

[0694] Fifteenth, the details of the 15th inspection item.

[0695] Question) Are you granting personal information handlers differential access to the personal information processing system to the minimum extent necessary for performing their duties?

[0696] - Issuance of accounts for each personal information handler

[0697] - No account sharing

[0698] - If account sharing is unavoidable, measures to ensure accountability are required.

[0699] - Restrictions on printing and downloading personal information

[0700] The relevant evidence is as follows.

[0701] 1. List of personal information handlers

[0702] 2. Status of access rights to personal information processing systems

[0703] The evaluation criteria are as follows:

[0704] Y - The personal information handler account is granted minimal permissions.

[0705] P - Personal information handler account permissions are minimal, but some people are granted excessive permissions.

[0706] N - Does not restrict the permissions of the personal information handler account

[0707] Sixteenth, the details of the 16th inspection item.

[0708] Question) When a personnel change, such as a transfer or retirement, occurs, are access rights to the personal information processing system changed or deleted without delay?

[0709] - Changes in personal information processing system authority due to changes in business

[0710] - Delete retiree accounts in the personal information processing system

[0711] The relevant evidence is as follows.

[0712] 1. Retirement and Job Change Procedure

[0713] 2. History of account deletion or access rights changes

[0714] The evaluation criteria are as follows:

[0715] Y - Access rights are immediately revoked in the event of personnel transfers such as retirement.

[0716] N - Access rights are not immediately revoked upon personnel transfer, such as retirement.

[0717] Seventeenth, details of the 17th inspection item.

[0718] Q) Are you keeping a record of the granting, modification, and deletion of access rights to your personal information processing system?

[0719] - Records of changes in personal information processing system access rights are kept for at least 3 years.

[0720] - Includes minimum information to ensure accountability, such as account name, name, affiliation, and authority.

[0721] The relevant evidence is as follows.

[0722] 1. Changes to personal information processing system access rights

[0723] 2. Application for Change of Access Rights

[0724] The evaluation criteria are as follows:

[0725] Y - Records of changes in personal information handler access rights are safely stored for at least three years.

[0726] P - Records of changes in access rights of personal information handlers are being kept, but the change history cannot be clearly confirmed or is not kept for more than 3 years.

[0727] N - Does not record changes in access rights of personal information handlers

[0728] The eighteenth, detailed content of the 18th inspection item.

[0729] Question) Are you taking any measures, such as automatically blocking access to the personal information processing system if no work is done for a certain period of time?

[0730] - Personal information processing system session timeout, token expiration time setting, etc.

[0731] The relevant evidence is as follows.

[0732] 1. Evidence of setting maximum connection time limit

[0733] The evaluation criteria are as follows:

[0734] Y - Personal information processing system timeout function is applied

[0735] N - Personal information processing system timeout function is not applied

[0736] Nineteenth, the details of the 19th inspection item.

[0737] Question) When access to the personal information processing system from outside via an information and communications network is required, are secure authentication methods being applied?

[0738] - Secure authentication methods: OTP, certificate, security token, etc.

[0739] - Secure connection methods: VPN, dedicated line, etc.

[0740] The relevant evidence is as follows.

[0741] 1. Evidence of setting up a secure authentication method or connection method when accessing the personal information processing system from outside.

[0742] The evaluation criteria are as follows:

[0743] Y - Remote access to the personal information processing system from outside is restricted.

[0744] N - Does not restrict remote access to the personal information processing system from outside.

[0745] The twentieth, detailed content of the 20th inspection item.

[0746] Question) Are you restricting internet access for important terminals that process personal information?

[0747] - If the following tasks are possible, it is considered an important terminal.

[0748] 1. Personal information can be downloaded or destroyed from the personal information processing system.

[0749] 2. Access rights to the personal information processing system can be set.

[0750] The relevant evidence is as follows.

[0751] 1. Evidence of Internet blocking settings on important terminals

[0752] The evaluation criteria are as follows:

[0753] Y - Internet use on important terminals is restricted.

[0754] N - Does not restrict Internet use on important terminals

[0755] N / A - Not eligible for network separation

[0756] Twenty-first, the details of the 21st inspection item.

[0757] Question) Are you restricting access to the personal information processing system by IP address, etc.?

[0758] - Allow access only to specific IPs / MACs through firewalls, etc.

[0759] - Allow access only to specific IPs / MACs using the router's ACL function.

[0760] - Use access control solutions to allow access only to authorized personnel.

[0761] The relevant evidence is as follows.

[0762] 1. Evidence of restricted access to personal information processing systems

[0763] 2. Evidence of security solution operation

[0764] The evaluation criteria are as follows:

[0765] Y - Access control is set when accessing the personal information processing system.

[0766] P - Access control is inadequate when accessing the personal information processing system.

[0767] N - Do not set access control when accessing the personal information processing system.

[0768] Twenty-second, detailed contents of the 22nd inspection item.

[0769] Question) Are you safely applying and managing the authentication method for personal information handlers or data subjects in the personal information processing system?

[0770] - Application of authentication methods (password, OTP, etc.) according to internal management plan or guidelines

[0771] - Restrict access to the personal information processing system if authentication fails a certain number of times.

[0772] The relevant evidence is as follows.

[0773] 1. Provision of authentication methods within the internal management plan

[0774] 2. Setting the authentication method threshold

[0775] The evaluation criteria are as follows:

[0776] Y - Applying authentication methods and setting thresholds for personal information processing systems.

[0777] P - Authentication methods are applied to personal information processing systems, but thresholds are not set.

[0778] N - No authentication method applied to personal information processing system"

[0779] Twenty-third, details of the 23rd inspection item.

[0780] Question) When searching or printing personal information, are you minimizing the number of personal information items to be printed to only the information necessary for business purposes and applying safety measures to safely manage printouts and copies?

[0781] - Establish policies / regulations / guidelines for protecting and managing output and copies

[0782] - Safety measures such as watermarking, output history recording, and destruction confirmation

[0783] - When printing personal information (printing, displaying on screen, creating files, etc.), print it to the minimum extent possible within the scope of access rights by specifying the purpose.

[0784] - Whether to mask when viewing the entire list of personal information through the personal information processing system

[0785] The relevant evidence is as follows.

[0786] 1. Evidence of personal information masking

[0787] The evaluation criteria are as follows:

[0788] Y - Security measures are applied when viewing the full list of personal information.

[0789] N - No security measures applied when viewing the full list of personal information

[0790] The twenty-fourth, detailed inspection item 24.

[0791] Question) Are you storing and managing access records, including essential items, for the personal information processing system of the personal information handler for more than one year?

[0792] - Required items: identifier, access date and time, access location information, information on the subject of the information processed, and tasks performed.

[0793] - In the cases below, they must be stored and managed for more than 2 years.

[0794] 1. In the case of a personal information processing system that processes personal information of more than 50,000 data subjects.

[0795] 2. In the case of a personal information processing system that processes unique identification information or sensitive information.

[0796] 3. In case the personal information processor is a telecommunications service provider

[0797] ※ Explanation of required items for connection log

[0798] - Identifier: Account information such as ID assigned to identify the user in the personal information processing system.

[0799] - Access date and time: Time of access or time of work performed (year-month-day, hour:minute:second)

[0800] - Access information: IP address of the computer or server of the person accessing the personal information processing system, etc.

[0801] - Processed information subject information: Identification information (ID, customer number, student number, employee number, etc.) that allows the personal information handler to determine whose personal information was processed.

[0802] - Performance tasks: Information that allows the personal information handler to know the details of personal information processed using the personal information processing system (collecting, creating, linking, connecting, recording, storing, holding, processing, editing, searching, printing, correcting, recovering, using, providing, disclosing, destroying, etc. may be considered performance tasks)

[0803] The relevant evidence is as follows.

[0804] 1. Access log of personal information processing system

[0805] The evaluation criteria are as follows:

[0806] Y - Access records of personal information processing systems are stored and managed for at least one or two years, including all required information.

[0807] P - Access records for the personal information processing system are being kept, but some information is missing or the access record retention period is not appropriate.

[0808] N - Access records of personal information processing systems are not kept.

[0809] Twenty-fifth, the 25th inspection item details.

[0810] Question) Are you checking the access records of the personal information processing system at least once a month?

[0811] - Check for excessive personal information inquiries, access outside of working hours, and reasons for downloading personal information.

[0812] - When downloading personal information, it is mandatory to check the reason for downloading.

[0813] The relevant evidence is as follows.

[0814] 1. Personal information processing system access log inspection plan

[0815] 2. Personal information processing system access log inspection report

[0816] The evaluation criteria are as follows:

[0817] Y - Checking the appropriateness of the access records and reasons for downloading personal information from the personal information processing system (at least once a month)

[0818] P - We are checking the appropriateness of the personal information processing system access records and reasons for downloading personal information, but we do not conduct inspections more than once a month.

[0819] N - The access records of the personal information processing system and the reasons for downloading personal information are not checked for appropriateness.

[0820] Twenty-sixth, the 26th inspection item details.

[0821] Question) Are you taking necessary measures in your personal information processing system, personal information handler's computer, and mobile device to prevent personal information from being disclosed or leaked to unauthorized persons through Internet homepages, P2P, sharing settings, etc.?

[0822] - Block access to harmful sites such as P2P

[0823] - Shared folder restrictions

[0824] - Application of security solutions such as DLP and DRM

[0825] The relevant evidence is as follows.

[0826] 1. Evidence of blocking access to harmful websites on the personal information handler's terminal

[0827] 2. Evidence of shared folder restriction settings

[0828] 3. Evidence of security solution operation

[0829] The evaluation criteria are as follows:

[0830] Y - Measures are being established to prevent personal information leakage and exposure on personal information handler terminals.

[0831] N - No measures are set up on the personal information handler's terminal to prevent personal information leakage or exposure.

[0832] Twenty-seventh, the 27th inspection item details.

[0833] Question) Are you establishing and applying a password policy for personal information handlers or data subjects who access the personal information processing system?

[0834] - The minimum password length is set to 10 characters when combining at least two types of uppercase letters, lowercase letters, numbers, and special characters, or 8 characters when combining at least three types of characters.

[0835] - Set an expiration date for your password, change it at least once every six months, and prevent the use of two passwords interchangeably.

[0836] - If you enter your password incorrectly more than 5 times, access restrictions such as account locking and delay settings will be applied.

[0837] - Set passwords that are easy to guess, such as consecutive numbers, birthdays, phone numbers, or passwords that are similar to IDs, to be unavailable.

[0838] ※ Not applicable if password is not used as an authentication method"

[0839] The relevant evidence is as follows.

[0840] 1. Password policy within the internal management plan

[0841] 2. Password policy set in the personal information processing system

[0842] 3. Password change date status

[0843] The evaluation criteria are as follows:

[0844] Y - Set a secure password that meets the password standards and change it regularly.

[0845] N - You are using a weak password or your password policy settings are not being applied.

[0846] Twenty-eighth, the 28th inspection item details.

[0847] Question) Are you storing your password using one-way encryption?

[0848] - Application of a secure one-way encryption algorithm higher than SHA-2

[0849] - Refer to the latest information, such as the KISA encryption algorithm and key length usage guide.

[0850] ※ Not applicable if password is not used as authentication method

[0851] The relevant evidence is as follows.

[0852] 1. Evidence of application of encryption algorithm to password

[0853] The evaluation criteria are as follows:

[0854] Y - A secure encryption algorithm is applied when storing passwords.

[0855] N - No secure encryption algorithm is used when storing passwords.

[0856] The twenty-ninth, 29th inspection item details.

[0857] Question) Are users' resident registration numbers, passport numbers, driver's license numbers, alien registration numbers, credit card numbers, account numbers, and biometric information encrypted and stored using a secure encryption algorithm?

[0858] - Writing of applied symmetric key encryption algorithms (SEED, ARIA-128 / 192 / 256, AES-128 / 192 / 256, HIGHT, etc.)

[0859] - Writing of applied public key encryption algorithms (RSAES-OAEP, RSAES-PKCS1, etc.)

[0860] The relevant evidence is as follows.

[0861] 1. Evidence of personal information encryption application

[0862] 2. Encryption algorithm evidence

[0863] The evaluation criteria are as follows:

[0864] Y - Personal information is encrypted and stored using a secure encryption algorithm.

[0865] N - Personal information is stored without encryption using a secure encryption algorithm.

[0866] The thirtieth, detailed content of the 30th inspection item.

[0867] Question) When sending and receiving passwords, personal information, and authentication information via information and communications networks, are they encrypted?

[0868] - Apply SSL (https) or install an encryption program"

[0869] The relevant evidence is as follows.

[0870] 1. SSL certificate information

[0871] 2. Evidence of personal information encryption through encryption solutions, etc.

[0872] The evaluation criteria are as follows:

[0873] Y - Personal information and authentication information transmitted and received via information and communications networks are encrypted.

[0874] N - Personal information and authentication information transmitted and received via information and communications networks are not encrypted.

[0875] Here are the details of the thirty-first inspection item.

[0876] Question) When storing personal information on PCs, mobile devices, and auxiliary storage media, is it encrypted?

[0877] - When downloading files from the personal information processing system, they are downloaded with the password settings applied.

[0878] - Manually set a password for personal information files (such as password settings provided by office programs)

[0879] - When using auxiliary storage media, use secure USB, etc.

[0880] - DRM applied

[0881] The relevant evidence is as follows.

[0882] 1. Evidence that encryption has been applied when storing personal information files on a PC, auxiliary storage media, etc.

[0883] The evaluation criteria are as follows:

[0884] Y - Personal information is encrypted and stored.

[0885] N - Do not encrypt personal information when storing it

[0886] Thirty-second, detailed inspection item 32.

[0887] The relevant evidence is as follows.

[0888] 1. Password key management procedures

[0889] The evaluation criteria are as follows:

[0890] Y - Establishing and implementing secure encryption key management procedures.

[0891] N - Failure to establish and implement secure encryption key management procedures

[0892] Thirty-third, details of the 33rd inspection item.

[0893] Question) Are you installing and operating a security program to check for and treat malware on your personal information handler's PC?

[0894] - Automatic update or update at least once a day

[0895] - Real-time monitoring and daily scheduled inspections

[0896] The relevant evidence is as follows.

[0897] 1. Security program installation history

[0898] 2. Security program inspection details

[0899] 3. Security program update history

[0900] The evaluation criteria are as follows:

[0901] Y - I have installed a security program, am running real-time monitoring, and am performing updates once a day.

[0902] P - Security program installed but not updated once a day or set up real-time monitoring

[0903] N - Do not install or run security programs

[0904] Thirty-fourth, details of inspection item 34.

[0905] Question) If there is a security update notice for the application or operating system software being used on the personal information handler's PC, do you apply the update immediately?

[0906] The relevant evidence is as follows.

[0907] 1. A screen where you can check for security updates on the personal information handler's PC.

[0908] 2. Evidence that can confirm whether security updates are being applied to applications installed on the PC.

[0909] 3. Update-related notice

[0910] The evaluation criteria are as follows:

[0911] Y - Applying updates immediately when security updates are announced

[0912] N - Do not apply security updates immediately

[0913] Thirty-fifth, details of inspection item 35.

[0914] Question) Do you have a crisis response manual and backup and recovery plan in place to prepare for disasters such as fire, flood, and power outages, and do you regularly review them?

[0915] ※ If it does not fall under the types below, it may be excluded from the inspection items.

[0916] - Large corporations, medium-sized enterprises, and public institutions that process personal information of more than 100,000 data subjects.

[0917] - Personal information processors that are small and medium-sized enterprises or organizations that process personal information of more than 1 million data subjects.

[0918] The relevant evidence is as follows.

[0919] 1. Crisis Response Manual (Document)

[0920] 2. Backup and Recovery Policy and Procedures (Document)

[0921] The evaluation criteria are as follows:

[0922] Y - Establishing crisis response procedures, including backup and recovery plans.

[0923] P - Crisis response procedures are in place but backup and recovery plans are missing, or backup and recovery plans are in place but crisis response procedures are inadequate.

[0924] N - No crisis response procedures established"

[0925] Thirty-sixth, details of the 36th inspection item.

[0926] Question) In addition to the personal information provided by the consignor, when collecting additional personal information for the purpose of processing the consignor's business, are you obtaining consent in an appropriate manner, such as by notifying all necessary consent items and indicating important information?

[0927] - Required notification in consent form

[0928] 1. Purpose of collection and use of personal information

[0929] 2. Items of personal information to be collected

[0930] 3. Retention and use period of personal information

[0931] 4. The fact that you have the right to refuse consent and, if there are any disadvantages resulting from refusal of consent, the details of those disadvantages.

[0932] 5. (When provided to a third party) Recipient, purpose of use by recipient, period of use, items provided, right to refuse consent and disadvantages of consent

[0933] - How to display important information in the consent form

[0934] 1. The font size should be at least 9 points and at least 20% larger than other content to ensure easy reading.

[0935] 2. Clearly indicate the content through text color, thickness, or underlining.

[0936] 3. If there are many matters to agree on and it is difficult to clearly distinguish important matters, display them separately from other matters so that important matters can be easily identified.

[0937] The relevant evidence is as follows.

[0938] 1. Personal information collection and use consent screen

[0939] The evaluation criteria are as follows:

[0940] Y - We collect personal information by providing all required notices and obtaining consent.

[0941] N - Personal information is being collected without providing or omitting required notices.

[0942] Thirty-seventh, details of the 37th inspection item.

[0943] Question) Are you destroying personal information without delay after confirming that the retention period has expired or the business purpose has been achieved?

[0944] - Writing the conditions and cycle for destroying personal information

[0945] - Create a history of personal information destruction

[0946] - Request for the preparation of evidence of personal information destruction, such as a "Personal Information Destruction Confirmation Form"

[0947] The relevant evidence is as follows.

[0948] 1. Personal Information Destruction Procedure

[0949] 2. Setting up personal information destruction batches

[0950] 3. Personal Information Destruction Confirmation Form

[0951] 4. Personal information destruction history

[0952] The evaluation criteria are as follows:

[0953] Y - Establishing destruction criteria and procedures and managing post-destruction history.

[0954] P - Establishing destruction criteria or procedures, but not managing destruction history

[0955] N - No destruction criteria or procedures established

[0956] Thirty-eighth, details of the 38th inspection item.

[0957] Question) If personal information must be retained even after the purpose of use has been achieved, is it stored and managed separately from other personal information being operated?

[0958] - Writing the conditions and cycle for separate storage of personal information

[0959] The relevant evidence is as follows.

[0960] 1. Evidence of separate storage of personal information

[0961] The evaluation criteria are as follows:

[0962] Y - Personal information that needs to be kept even after the purpose has been achieved is kept safely separated from operational personal information.

[0963] N - Personal information that needs to be retained even after the purpose has been achieved is stored without being separated from operational personal information.

[0964] Thirty-ninth, details of inspection item 39.

[0965] Question) Are you destroying personal information in the following secure manner?

[0966] - Personal information stored in electronic file formats such as PCs, auxiliary storage media, and mailboxes is deleted in a way that makes it unrecoverable using a technical method that renders the records unrecoverable.

[0967] - In the case of personal information printed on paper, it is destroyed using a method that makes it unrecoverable, such as shredding or incineration.

[0968] The relevant evidence is as follows.

[0969] 1. Evidence of destruction of personal information stored in electronic file format

[0970] 2. Document shredder, document destruction box evidence

[0971] The evaluation criteria are as follows:

[0972] Y - Personal information is being destroyed in a secure manner.

[0973] N - Not destroying personal information

[0974] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.

[0975] Referring to Figure 22 (2210), the inspection status of the inspection checklist is explained.

[0976] The inspection status is divided into inspection status, related laws and regulations, and related notices.

[0977] The relevant laws are Article 29 of the Personal Information Protection Act and Article 30 of the Enforcement Decree.

[0978] The relevant notice is Article 4 of the Personal Information Security Measures Standards.

[0979] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.

[0980] Referring to Figure 23 (2310), the penalty provisions of the inspection checklist are explained.

[0981] Penalty provisions are divided into penalties and penalty provisions.

[0982] Penalties are divided into criminal penalties and administrative measures.

[0983] Punishments are divided into imprisonment and fines.

[0984] Administrative sanctions are categorized into fines and surcharges. Surcharges can be up to 50 million won.

[0985] The penalty provision is Article 75 of the Personal Information Protection Act.

[0986] According to Article 75 of the Personal Information Protection Act, a person who falls under any of the following items shall be subject to a fine of up to 50 million won.

[0987] 5) A person who has violated Article 23, Paragraph 2, Article 24, Paragraph 3, Article 25, Paragraph 6 (including cases where it applies pursuant to Article 25-2, Paragraph 4), Article 28-4, Paragraph 1, and Article 29 (including cases where it applies pursuant to Article 26, Paragraph 8) and has not taken necessary measures to ensure safety.

[0988] Above, the entire system of the present disclosure has been described with reference to FIGS. 1 to 23. Hereinafter, the present invention will be described in detail with reference to FIGS. 24 to 59.

[0989] Figure 24 is a diagram illustrating the configuration of a personal information risk management device according to the present disclosure.

[0990] The present invention consists of four inventions.

[0991] The first invention is a personal information risk management device and its control method. This is described in FIGS. 24 to 40.

[0992] The second invention is an access control device and its control method according to the security level of a personal information handler. This is described in FIGS. 41 to 52.

[0993] The third invention is a consulting device and its control method that performs monitoring based on a risk analysis report of a trustee. This is described in FIGS. 53 to 56.

[0994] The fourth invention is a personal information processing trustee risk assessment device and its control method. This is described in FIGS. 57 to 59.

[0995] The first invention describes a personal information risk management device (Figs. 24 to 40).

[0996] Referring to FIG. 24, the personal information risk management device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[0997] The input module (2410) collects first data including the general status of the company and the status of personal information processing.

[0998] The sensor module (2420) senses first data.

[0999] The processor (2430) performs a control method according to the process.

[1000] That is, the processor (2430) collects first data including the general status of the company and the status of personal information processing through the input module (110), assigns a purpose of personal information processing based on the collected first data, receives second data including the contents of a questionnaire form for collecting personal information, measures a first distance between the purpose of personal information processing and the contents of the questionnaire form, and determines whether or not to collect personal information based on the measured first distance.

[1001] If the user confirms the contents of the above questionnaire, the processor (2430) expands the purpose of processing the personal information.

[1002] If the first distance is below the threshold, the processor (2430) allows personal information collection. If the first distance is above the threshold, the processor (2430) disallows personal information collection or determines that user confirmation is required. A detailed description of this is provided in Fig. 26.

[1003] The processor (2430) classifies the frequency, time zone, and policy violations of specific actions corresponding to the access records of the first data, calculates the risk level by combining the classified specific actions based on a scenario, calculates the risk level of misuse of personal information based on the risk level, and displays the risk level on the screen. A detailed description of this is provided in Fig. 27.

[1004] The processor (2430) identifies the collected personal information, determines whether the identified personal information has been provided within a specific scope, calculates the risk of potential regulatory violations, displays the risk on the screen, and transmits the risk to the device corresponding to the personal information subject based on the regulations. A detailed description of this is provided in Fig. 28.

[1005] The processor (2430) receives the name of the trustee who will perform personal information processing tasks, collects information about the trustee, configures trustee inspection items based on the information received, receives personal information processing status from the trustee, calculates a risk level based on the collected trustee information and the received personal information processing status, and displays the risk level on the screen. A detailed description of this is provided in Fig. 29.

[1006] The first data item consists of the company's industry, collection purpose, personal information items, and whether the information is required to the minimum extent possible. A detailed explanation of this is provided in Figure 30.

[1007] The processor (2430) learns the minimum required purpose and item data from the first data by determining that the data is normal data, and skips the data from the first data excluding the normal data by determining that the data is abnormal samples. A detailed description of this is provided in Fig. 30.

[1008] The processor (130) learns using a formula that places the plane that distinguishes the normal data as far from the origin as possible. A detailed description of this is provided in Fig. 31.

[1009] The second invention describes an access control device based on the security level of the personal information handler. (Figures 41 to 52)

[1010] Referring to FIG. 24, an access control device (2400) according to the security level of a personal information handler includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[1011] The input module (2410) collects data including the security level status of the personal information handler.

[1012] The processor (2430) collects first data including the security level status of a personal information handler through an input module, scores the security level of education and possession evidence based on the collected first data, classifies the level according to the security level scoring score, grants access rights according to the classified level, and controls access by checking whether the level is an accessible level when the personal information handler accesses the system or executes a specific function, and if the security level of the personal information handler falls below the standard or a change in access rights is required, collects the security compliance status and changes the security level and access rights or denies access.

[1013] The processor (2430) receives a query item from the user, compares the query item with pre-learned data, calculates the classifiable likelihood of the personal information item, and proposes the personal information item with the highest classifiable likelihood. A detailed description of this is provided in Fig. 42.

[1014] The processor (2430) receives security information from the user, compares the security information with pre-learned data, calculates a first distance, and proposes a personal information processing purpose with the closest first distance. A detailed description of this is provided in Fig. 43.

[1015] The processor (2430) receives different questions from the user regarding the survey content, identifies characteristic words in the inputted questions, calculates the likelihood of personal identification based on a combination of the characteristic words, and proposes personal information items corresponding to the highest likelihood of personal identification. A detailed description of this is provided in Fig. 44.

[1016] The processor (2430) collects information on personnel training completion and security policy compliance, calculates a security compliance score based on the collected results, and determines whether to allow a user corresponding to the security compliance score access to the system based on appropriate criteria. A detailed description of this is provided in Fig. 45.

[1017] The processor (2430) designates a user's role, specifies the authority of personal information to which the user can access, specifies the authority of functions to which the user can use, verifies the role and authority when the user accesses the system, and if the user's role and authority meet the conditions, allows access to the system, and if the user's role and authority do not meet the conditions, moves to another page. A detailed description of this is provided in Fig. 46.

[1018] A consulting device that monitors based on the risk analysis report of the third inventor, the trustee, is described. (Figures 53 to 56)

[1019] The consulting device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[1020] The processor (2430) collects first data including a report applying a personal information trustee evaluation mechanism through an input module, requests consulting from a consultant device based on the collected first data, transmits a risk analysis result report to the consultant device, receives guidance including basic infrastructure information of the trustee from the consultant device, analyzes details required for consulting by applying necessary guidance among the received guidance, transmits the necessary guidance details reflecting the analysis results to the trustee device, calculates a risk level based on a reflection rate indicating whether the necessary guidance has been applied, updates the calculated risk level so that it can be monitored, and transmits a final risk analysis report reflecting the updated results to the consultant device.

[1021] The processor (2430) calculates a risk level according to function, location, and regulation based on the above reflection rate.

[1022] The processor (2430) monitors the calculated risk level by period, including daily, monthly, and yearly.

[1023] The processor (2430) repeatedly updates the above risk rating at a predetermined interval. A detailed description of this is provided in Fig. 56.

[1024] The processor (2430) registers the above analysis results for monitoring.

[1025] The processor (2430) receives company information from the trustee device and performs a check of the regulatory scope by searching the company information.

[1026] The processor (2430) additionally performs registration of the checked regulatory scope by searching the above company information.

[1027] The processor (2430) receives human system and policy infrastructure information from the trustee device, checks whether each infrastructure satisfies the necessary regulations, analyzes the risk level of each infrastructure based on the trustee company's infrastructure suitability results, calculates a risk level grade based on the analysis results, and transmits a risk analysis result report reflecting the calculated risk level grade to the trustee device.

[1028] The processor (2430) additionally registers the calculated risk level. A detailed description of this is provided in Fig. 55.

[1029] The fourth invention, a personal information processing trustee risk assessment device, is described. (Figs. 57 to 59)

[1030] The personal information processing trustee risk assessment device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[1031] The processor (2430) collects first data including company information through the input module (110), searches the company information to search for the regulatory scope corresponding to the company, registers an inspection, transmits information on necessary regulations of the trustee company, receives infrastructure information of the trustee company from the user device (5910), determines whether the infrastructure information is suitable through an access and audit mechanism, checks it, secures suitability based on security and monitoring measures in the stages of collecting, storing, transmitting and processing the first data, transmits the suitability results for each infrastructure of the trustee company to the user device (5910), and calculates a risk level by conducting a risk analysis based on the suitability results for each infrastructure.

[1032] The processor (2430) receives the general status of the company and the status of personal information processing, assigns a purpose of personal information processing based on the input, inputs the contents of a questionnaire form for collecting personal information, measures a first distance between the assigned purpose and the contents of the questionnaire form, and if the measured first distance is less than a threshold value, allows collection, and if the measured first distance is greater than or equal to the threshold value, requires confirmation or does not allow collection, and if the user has confirmed the contents, expands the purpose of personal information processing. A detailed explanation of this is described in FIG. 25.

[1033] The processor (2430) classifies the frequency, time zone, and policy violations of specific actions in the access log, calculates the risk level by combining the classified specific actions based on a scenario, and displays the level of risk of personal information misuse on the screen based on the calculated risk level. A detailed description of this is provided in Fig. 27.

[1034] The processor (2430) identifies the provided personal information, determines whether the identified personal information has been provided within a specific scope, calculates the risk of potential regulatory violations, displays the risk on the screen, and transmits the potential violation to the data subject's device based on the risk and regulations. A detailed description of this is provided in Fig. 28.

[1035] The processor (2430) receives the name of the trustee that is scheduled to perform personal information processing work, collects information about the trustee, configures trustee inspection items based on the information received, receives personal information processing status from the trustee, calculates risk based on the collected trustee information and the inputted personal information processing status, and outputs the calculated risk on the screen. A detailed description of this is provided in Fig. 29.

[1036] The processor (2430) registers whether the checked infrastructure information is suitable.

[1037] The processor (2430) generates a risk analysis result report based on the above infrastructure-specific suitability results and the above risk level.

[1038] The processor (2430) transmits the generated risk analysis result report to the user device (5910). A detailed description of this is provided in FIG. 59.

[1039] However, the components illustrated in FIG. 24 are not essential for implementing the present invention according to the present disclosure, and thus the present invention described in this specification may have more or fewer components than the components listed above.

[1040] Meanwhile, the processor (2430) of FIG. 24 may be identical to the processor (50) of FIG. 1 described above, and in this case, all operations and controls of FIGS. 1 to 23 described above may be performed identically by the processor (2430) of FIG. 24.

[1041] The display (2440) displays graphic images according to control commands from the processor (2430).

[1042] Memory (2450) stores at least one process for performing an operation and stores user input and data.

[1043] The communication module (2460) transmits and receives data with an external device.

[1044] Here, the external device includes an external device such as a smartphone, a PC, a laptop, a tablet PC, etc.

[1045] The camera module (2470) captures images of the front.

[1046] The camera module (2470) photographs a subject in front according to a control command from the processor (2430).

[1047] The communication module (2460) may include one or more components that enable communication with an external device, and may include, for example, at least one of a broadcast reception module, a wired communication module, a wireless communication module, a short-range communication module, and a location information module.

[1048] The input module (2410) is for inputting video information (or signals), audio information (or signals), data, or information input from a user, and may include at least one camera, at least one microphone, and at least one user input unit. Voice data or image data collected by the input module (2410) may be analyzed and processed into a user control command.

[1049] The display module (2440) displays (outputs) information processed in the present invention. For example, the present invention can display execution screen information of a running application program (e.g., an application), or UI (User Interface) or GUI (Graphical User Interface) information based on such execution screen information.

[1050] The memory (2450) can store data supporting various functions of the present invention, programs for the operation of the control unit, input / output data (e.g., music files, still images, moving images, etc.), and can store a plurality of application programs (or applications), data for the operation of the device, and commands. At least some of these application programs can be downloaded from an external server via wireless communication.

[1051] The memory (2450) may include at least one type of storage medium among a flash memory type, a hard disk type, an SSD (Solid State Disk type), an SDD (Silicon Disk Drive type), a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. In addition, the memory (2450) is separate from the present invention, but may be a database connected by wire or wirelessly, and may be implemented as a database system.

[1052] The processor (2430) may be implemented as at least one core, a memory storing data for an algorithm for controlling the operation of components within the present invention or a program reproducing the algorithm, and at least one processor (not shown) that performs the aforementioned operations using the data stored in the memory. In this case, the memory and the processor may be implemented as separate chips. Alternatively, the memory and the processor may be implemented as a single chip.

[1053] Additionally, the processor (2430) may control any one or a combination of the components described above to implement various embodiments according to the present disclosure described in FIGS. 24 to 59 below.

[1054] At least one component may be added or deleted to correspond to the performance of the components illustrated in Figure 24. Furthermore, it will be readily apparent to those skilled in the art that the relative positions of the components may be altered to correspond to the performance or structure of the system.

[1055] Meanwhile, each component illustrated in FIG. 24 refers to software and / or hardware components such as a Field Programmable Gate Array (FPGA) and an Application Specific Integrated Circuit (ASIC).

[1056] Figure 25 is a diagram illustrating a flowchart of a personal information risk management method according to the present disclosure.

[1057] The present invention is performed by a personal information risk management device (2400) or a processor (2430) included in the personal information risk management device (2400).

[1058] The processor (2430) collects first data including the general status of the company and the status of personal information processing through the input module (S2510).

[1059] The processor (2430) assigns a purpose for processing personal information based on the collected first data (S2520).

[1060] The processor (2430) receives second data including the contents of a questionnaire form for collecting personal information (S2530).

[1061] The processor (2430) measures the first distance between the purpose of processing the personal information and the contents of the questionnaire form (2540).

[1062] The processor (2430) determines whether to collect personal information based on the measured first distance (S2550).

[1063] FIG. 26 is a diagram illustrating an example of a first distance between the purpose of personal information processing according to the present disclosure and the contents of a questionnaire form.

[1064] Referring to Figure 26, if there is content confirmed by the user among the contents of the questionnaire form, the processor (2430) expands the purpose of processing personal information.

[1065] The processor (2430) allows personal information collection if the first distance is less than the threshold value.

[1066] If the first distance is greater than the threshold, the processor (2430) determines that collection of personal information is not permitted or that user confirmation is required.

[1067] Figure 27 is a diagram illustrating an embodiment of calculating the risk of misuse of personal information collected according to the present disclosure and displaying the risk level on the screen.

[1068] Referring to FIG. 27, the processor (2430) classifies the frequency, time zone, and policy violation cases for a specific action corresponding to the access record of the first data (S2710).

[1069] The processor (2430) calculates the risk by combining the classified specific actions based on the scenario (S2720).

[1070] The processor (2430) calculates the risk level of misuse of personal information based on the above risk level (S2730).

[1071] The processor (2430) outputs the above risk level on the screen (S2740).

[1072] Figure 28 is a diagram illustrating an embodiment of calculating the suitability of personal information provided according to the present disclosure, displaying it on a screen, and notifying it to the information subject.

[1073] The processor (2430) identifies the collected personal information (S2810).

[1074] The processor (2430) calculates the risk of possible regulatory violations by identifying whether the identified personal information has been provided within a specific scope and whether it has been agreed upon (S2820).

[1075] The processor (2430) outputs the above risk level to the screen (S2830).

[1076] The processor (2430) transmits the risk level based on the regulation to the device corresponding to the personal information subject (S2840).

[1077] Figure 29 is a diagram illustrating an embodiment of calculating the risk level according to the level of personal information management of a trustee according to the present disclosure and outputting it on the screen.

[1078] Referring to Figure 29, the processor (2430) receives the name of the trustee who will perform personal information processing work (S2910).

[1079] The processor (2430) collects information of the trustee (S2920).

[1080] The processor (2430) configures the consignee inspection items based on the input information (S2930).

[1081] The processor (2430) receives personal information processing status from the trustee (S2940).

[1082] The processor (2430) calculates the risk level based on the information of the trustee collected above and the status of processing of personal information received above (S2950).

[1083] The processor (2430) outputs the above risk level on the screen (S2960).

[1084] Figure 30 is a diagram illustrating the structure of data according to the present disclosure.

[1085] Referring to Figure 30 (3010), the structure of the data is described.

[1086] The first data of the present invention consists of the company's industry, collection purpose, personal information items, and whether or not they are the minimum necessary.

[1087] For example, a company's industry could be public data and services.

[1088] The purpose of collection may be membership registration.

[1089] Personal information items may include ID (email), password, name, mobile phone number, company / organization name, and identity verification information.

[1090] If the minimum requirement is Yes, it becomes 1.

[1091] If the minimum requirement is No, it becomes 0.

[1092] The first attribute of the data can be accurate data that has been reviewed by a personal information expert.

[1093] In one example, 18,000 training data sets were obtained.

[1094] The processor (2430) learns by judging the minimum necessary purpose and item data among the first data as normal data, and skips the data excluding the normal data among the first data as abnormal samples.

[1095] Figure 31 is a diagram illustrating the formula of OCSVM according to the present disclosure.

[1096] Referring to Figure 31 (3110), OCSVM is an abbreviation for One class support vector machine.

[1097] The processor (2430) performs learning using a formula that places the plane (classification boundary, hyper plane) that distinguishes normal data as far as possible from the origin.

[1098] The processor (2430) uses the OCSVM formula to determine whether a pair of industries, purposes, and items is minimum necessary.

[1099] OCSVM is one of the support vector-based anomaly detection methods. It maps data to an N-dimensional feature space, and then classifies the normal data among the mapped data by making them as far away from the origin as possible through the classification boundary (hyperplane).

[1100] Figure 32 is a diagram illustrating the structure of an isolation forest according to the present disclosure.

[1101] Referring to Figure 32 (3210), the Isolation Forest structure refers to an algorithm that can determine outliers by utilizing the fact that in a decision tree, normal values ​​are close to the most terminal node of the tree and outliers are close to the root node.

[1102] The processor (2430) uses the Isolation Forest structure to determine whether a pair of industries, purposes, and items is minimally necessary.

[1103] Figure 33 is a diagram illustrating a DATE learning method according to the present disclosure.

[1104] Referring to FIG. 33 (3310), CVDD (Context Vector Data Description) creates a context vector for an input sentence using a pre-learned language model, determines an anomalousness score based on the created context vector, and distinguishes between normal and anomalous data based on the anomalousness score.

[1105] The DATE learning method (Detecting Anomalies in Text via Self-Supervision of Transformers) is a model that determines outliers by learning to decompose (corrupt) sentences into two ways and then restore them.

[1106] The processor (2430) uses the DATE learning method to determine whether a pair of industries, purposes, and items is minimally necessary.

[1107] Figure 34 is a drawing illustrating a DPR structure according to the present disclosure.

[1108] Referring to Figure 34 (3410), when using an outlier detection algorithm, the experimental results of four outlier detection algorithms showed poor performance. This is because the outlier detection algorithms are judged to be inappropriate because they do not utilize the correlation between the target and the item.

[1109] In such cases, the DPR (Dense Passage Retrieval) structure can be used.

[1110] The DPR structure embeds each purpose and item, trains each embedding model to increase the similarity between the two embedding values, and retrieves the item with the highest similarity to the input purpose.

[1111] The processor (2430) calculates the similarity between the items input for the purpose and the items generated by the model, and determines that the higher the calculated similarity, the closer it is to the minimum required.

[1112] Figure 35 is a drawing illustrating an example of output according to the present disclosure.

[1113] Referring to FIG. 35 (3510), the processor (2430) generates a result using the DPR structure and outputs it.

[1114] The purpose of the input is in accordance with Article 24 of the Enforcement Decree of the Act on the Use, Provision and Identification of Beneficiaries of Social Security Benefits.

[1115] The collected item entered is the home address.

[1116] Model answers include name, date of birth, home address, mobile phone number (contact information), photo, and alien registration number.

[1117] Fig. 36 is a diagram illustrating a Cross-Encoder according to the present disclosure.

[1118] Referring to Fig. 36 (3610), the Cross-Encoder is described.

[1119] The DPR (Dense Passage Retrieval) structure has a problem in that it is difficult to properly calculate the similarity between the input items and the items generated by the model when the initial plan and direction are different.

[1120] To solve these problems, the Cross Encoder structure can be used.

[1121] The Cross Encoder model is a model that trains two texts (object, item) on one model (encoder) and classifies them based on the correlation of the trained items.

[1122] The Cross Encoder model has excellent performance because it considers the correlation between two items.

[1123] When determining whether a pair of industries, purposes, and items is minimally necessary, the processor (2430) uses the Cross Encoder model to determine the minimum.

[1124] Figure 37 is a diagram illustrating a system structure according to the present disclosure.

[1125] Referring to Figure 37 (3710), the system structure inputs the industry input when creating a service, the purpose input when creating a catch form, and the items into a classification model, and then determines whether it is the minimum necessary as O or X and extracts a probability value for it.

[1126] The processor (2430) uses the system structure to determine whether to collect the minimum amount of personal information necessary.

[1127] For example, if the minimum requirement is O, the probability is 70%.

[1128] If the minimum requirement is X, the probability becomes 30%.

[1129] Figure 38 is a drawing illustrating the concept of a personal information risk management method according to the present disclosure.

[1130] Referring to FIG. 38 (3810), the processor (2430) of the personal information risk management device (2400) includes five modules. The structure of the five modules is illustrated in FIG. 24.

[1131] Module 1 (2431) is the monitoring and guidance module for the minimum collection of personal information based on purpose (2431). This module monitors and limits the collection of personal information to the minimum required from a business perspective.

[1132] The second module (2432) is the minimum required access control management module (2432). The minimum required access control management module (2432) determines whether the user to be granted authority has appropriate authority during the process of granting roles and permissions.

[1133] The third module (2433) is the personal information misuse monitoring module (2433). The personal information misuse monitoring module (2433) calculates the risk of misuse of collected personal information and displays the level on the screen.

[1134] The fourth module (2434) is a risk management (and notification) module (2434) for the personal information provided. The risk management (and notification) module (2434) for the personal information provided calculates the suitability of the personal information provided, displays the result on the screen, and notifies the data subject.

[1135] Module 5 is the Trustee Risk Management module. This module calculates the risk level based on the trustee's level of personal information management and displays it on the screen.

[1136] FIG. 39 is a diagram illustrating a module that determines whether the authority of a user seeking to be granted authority is appropriate in the process of granting roles and authority according to the present disclosure.

[1137] Referring to Figure 39 (3910), registration of authority is described.

[1138] The processor (2430) receives a signal requesting user authorization confirmation from the user device (S10).

[1139] The processor (2430) checks whether the user has top-level administrator or administrator rights (S20).

[1140] If the processor (2430) does not recognize that the user is a top-level administrator or has administrator rights, it determines that authorization has failed (S30).

[1141] If the processor (2430) recognizes that the user has the highest level administrator or right holder authority, it verifies whether the user has the right to restrict access IP control (S40).

[1142] If the user does not have access IP control restriction rights, the processor (2430) determines that authorization has failed (S50).

[1143] If the user has access IP control restriction rights, the processor (2430) grants permission (S60).

[1144] Referring to Figure 39 (3910), the use of the service is explained.

[1145] The processor (2430) receives a signal from the user device for selecting a service (S3910).

[1146] The processor (2430) checks whether the user has access rights (S3920).

[1147] If the user's access authority is not recognized, the processor (2430) determines that access has failed (S3930).

[1148] When the user is granted access authority, the processor (2430) verifies whether the user has access IP control restriction authority (S3940).

[1149] If the user does not have access IP control restriction rights, the processor (2430) determines that access has failed (S3950).

[1150] The processor (2430) allows service access if the user has access IP control restriction rights (S3960).

[1151] Figure 40 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1152] FIG. 40 (4010) is described with reference to a plurality of modules included in the processor (2430) disclosed in FIG. 24.

[1153] Module 1 (2431) is a monitoring and guidance module for the minimum collection of personal information according to purpose.

[1154] The second module (2432) is a minimum required access control management module.

[1155] The third module (2433) is a personal information misuse monitoring module.

[1156] Module 4 (2434) is a risk management (and notification) module for the personal information provided.

[1157] The Personal Information Minimum Collection Monitoring and Guide Module (2431) monitors and limits whether the personal information collected is the minimum necessary from the company's perspective.

[1158] The personal information misuse monitoring module (2433) calculates the risk of misuse of collected personal information and displays the degree on the screen.

[1159] The risk management (and notification) module (2434) for the provided personal information calculates the suitability of the provided personal information, displays it on the screen, and notifies the information subject.

[1160] The trustee's personal information management module calculates the risk level according to the trustee's personal information management level and displays it on the screen.

[1161] For detailed functions of individual modules, see Fig. 40.

[1162] Figure 41 is a flowchart of an access control method according to the security level of a personal information handler according to the present disclosure.

[1163] The present invention is performed by an access control device (2400) according to the security level of a personal information handler or a processor (2430) of an access control device (2400) according to the security level of a personal information handler.

[1164] Referring to FIG. 41, the processor (2430) collects first data including the security level status of a personal information handler through an input module (S4110).

[1165] The processor (2430) scores the security level for the education and possession evidence based on the collected first data (S4120).

[1166] The processor (2430) classifies the grade according to the scoring score of the security level (S4130).

[1167] The processor (2430) grants access rights according to the classified grade (S4140).

[1168] The processor (2430) controls access by checking whether the level is an accessible level when a personal information handler accesses the system or executes a specific function (S4150).

[1169] If the security level of the personal information handler is below the standard or if a change in access rights is required, the processor (2430) collects the security compliance status and changes the security level and access rights (S4160).

[1170] Figure 42 is an example of classifying personal information by finding items that are likely to collect personal information in a sentence entered by a user according to the present disclosure.

[1171] Referring to FIG. 42, the processor (2430) receives a query item from the user (S4210).

[1172] The processor (2430) compares the above query items with the learned data to calculate the classification possibility of the personal information items (S4220).

[1173] The processor (2430) suggests the items of personal information with the highest possibility of being classified (S4230).

[1174] Figure 43 is an embodiment of suggesting the purpose of personal information processing based on the title and content of a form entered by a user according to the present disclosure.

[1175] Referring to Figure 43, the processor (2430) receives security information from the user (S4310).

[1176] The processor (2430) compares the above security content with the learned data and calculates the first distance (S4320).

[1177] The processor (2430) proposes the personal information processing purpose of the closest first distance (S4330).

[1178] FIG. 44 is a diagram illustrating an embodiment of classifying personal information by analyzing the context of all sentences entered by a user according to the present disclosure to find items that may directly or indirectly collect personal information.

[1179] Referring to FIG. 44, the processor (2430) receives different questions of the questionnaire from the user (S4410).

[1180] The processor (2430) identifies the characteristic words of the input query (S4420).

[1181] The processor (2430) calculates the possibility of personal identification using a combination of the above-mentioned characteristic words (S4430).

[1182] The processor (2430) proposes an item of personal information corresponding to the highest possibility of personal identification (S4440).

[1183] Figure 45 is a diagram illustrating an embodiment of determining whether to allow system access based on the security level of a personal information handler according to the present disclosure.

[1184] Referring to Figure 45, the processor (2430) collects the status of training completion and security policy compliance of the person in charge (S4510).

[1185] The processor (2430) calculates a security compliance score based on the collection results (S4520).

[1186] The processor (2430) determines whether to allow access to the system of a user corresponding to the security compliance score based on appropriate criteria (S4530).

[1187] FIG. 46 is a diagram illustrating an example of access control according to the user's role and authority according to the present disclosure.

[1188] Referring to FIG. 46, the processor (2430) specifies the user's role (S4610).

[1189] The processor (2430) specifies the authority of personal information that the user can access (S4620).

[1190] The processor (2430) specifies the authority of the functions that can be used by the user (S4630).

[1191] The processor (2430) verifies the role and authority when the user accesses the system (S4640).

[1192] If the user's role and authority meet the conditions (S4650), the processor (2430) allows access to the system (S4660).

[1193] If the user's role and authority do not meet the conditions (S4650), the processor (2430) moves to another page (S4670).

[1194] Figure 47 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1195] In Fig. 47 (4710), an access control method according to the security level of the personal information handler is specifically described.

[1196] Figure 48 is a diagram illustrating an example of recording a log for processing personal information according to the present disclosure.

[1197] Referring to Figure 48 (4810), personal information verification is explained.

[1198] When the processor (2430) receives a response from the user's device (S4810), it determines the format of the personal information entered in the response (S4820).

[1199] The processor (2430) performs format-appropriate normalization on the answer and verifies whether the normalized answer conforms to the format (S4830).

[1200] If the answer does not conform to the format (S4830), the processor (2430) determines the answer as abnormal data and returns the input (S4840).

[1201] If the answer is in the correct format (S4830), the processor (2430) determines the answer as normal data and receives the input.

[1202] Figure 49 is a diagram illustrating an example of establishing a policy for destroying personal information according to the present disclosure and deleting or storing the information separately.

[1203] Referring to Figure 49 (4910), the destruction information setting is described.

[1204] The processor (2430) receives a response to the response value of the template from the user's device (S4911).

[1205] The processor (2430) sets the destruction date and retention period information for the response (S4912).

[1206] The processor (2430) stores the destruction date and retention period information in the response in memory (S4913).

[1207] Referring to FIG. 49 (4910), scheduler execution is described.

[1208] The processor (2430) operates the system scheduler (S4921).

[1209] The processor (2430) distinguishes the data to be destroyed through the destruction date among all data (S4922).

[1210] The processor (2430) destroys answers, connection files, etc. through the separated destruction data (S4923).

[1211] The processor (2430) deletes consent history and advertising information through the separated destruction data (S4924).

[1212] The processor (2430) deletes the separated destruction data (S4925).

[1213] Figure 50 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1214] In Fig. 50 (5010), an access control method according to the security level of the personal information handler is specifically described.

[1215] Figure 51 is a diagram illustrating a flowchart 1 of an access control method according to the security level of a personal information handler according to the present disclosure.

[1216] Referring to FIG. 51, the present invention is composed of a personal information handler's device (5110) and an access control device (2400) according to the personal information handler's security level.

[1217] Flowchart 1 of Fig. 51 is connected to flowchart 2 of Fig. 52.

[1218] The processor (2430) of the access control device (2400) according to the security level of the personal information handler includes a personal information handler security level evaluation function module (2431), a personal information handler authority management function module (2432), and a personal information processing module (2433).

[1219] The personal information handler security level evaluation function module (2431) performs the function of evaluating the personal information handler security level.

[1220] The personal information handler authority management function module (2432) performs the function of managing the personal information handler authority.

[1221] The personal information processing module (2433) performs the function of processing personal information.

[1222] The personal information handler device (5110) transmits user information to the personal information handler security level evaluation function module (2431).

[1223] The personal information handler security level evaluation function module (2431) matches the security level required for user registration and request authority.

[1224] The personal information handler security level evaluation function module (2431) requests the personal information handler device (5110) to provide information on the security compliance status.

[1225] The personal information handler device (5110) checks for the presence of a certificate or diploma.

[1226] If the personal information handler device (5110) does not have a certificate or completion certificate, it watches the personal information protection training video and completes the test, and uploads the completion certificate to the personal information handler security level evaluation function module.

[1227] If the personal information handler device (5110) has a certificate or completion certificate, it transmits the certificate or completion certificate to the personal information handler security level evaluation function module (2431).

[1228] The personal information handler security level evaluation function module (2431) verifies data certificates and completion certificates and evaluates the security level.

[1229] The personal information handler security level evaluation function module (2431) transmits a personal information handler registration request message to the personal information handler authority management function module (2432).

[1230] The personal information handler's authority management function module (2432) grants authority to personal information handlers according to the security level.

[1231] The personal information handler's authority management function module (2432) transmits the personal information handler's level and authority results to the personal information handler device (5110).

[1232] Figure 52 is a diagram illustrating a flowchart 2 of an access control method according to the security level of a personal information handler according to the present disclosure.

[1233] Referring to Figure 52, the personal information handler device (5110) transmits a personal information handling task execution request message to the personal information processing module (2433).

[1234] The personal information processing module (2433) transmits an access permission request message to the personal information handler's permission management function module (2432).

[1235] The personal information handler's authority management function module (2432) transmits the personal information handler's level and authority message to the personal information processing module (2433).

[1236] The personal information processing module (2433) checks whether the personal information handler's level is accessible.

[1237] The personal information processing module (2433) executes the accessible function if the personal information handler's level is an accessible level.

[1238] If the personal information handler's level is not an accessible level, the personal information processing module (2433) transmits a security level enhancement request message to the personal information handler's device (5110).

[1239] The personal information handler's device (5110) transmits a message including training results, certificates of completion, and required qualifications to the personal information handler security level evaluation function module (2431).

[1240] The personal information handler security level evaluation function module (2431) verifies the certificate and evaluates the security level.

[1241] The personal information handler security level evaluation function module (2431) transmits a personal information handler level change request message to the personal information handler authority management function module (2432).

[1242] The personal information handler's authority management function module (2432) grants authority to personal information handlers according to the security level.

[1243] Figure 53 is a diagram illustrating a flowchart of a consulting method for monitoring based on a risk analysis report of a trustee according to the present disclosure.

[1244] The present invention is performed by a consulting device (2400) or a processor (2430) of the consulting device (2400).

[1245] Referring to FIG. 53, the processor (2430) collects first data including a report applying a personal information trustee evaluation mechanism through an input module (S5310).

[1246] The processor (2430) requests consulting from the consultant device based on the collected first data (S5320).

[1247] The processor (2430) transmits a risk analysis result report to the trustee device (S5330).

[1248] The processor (2430) receives guidance including basic infrastructure information of the trustee from the consultant device (S5340).

[1249] The processor (2430) analyzes the details required for consulting by applying the necessary guidance among the received guidance (S5350).

[1250] The processor (2430) registers the analysis results for monitoring (S5360).

[1251] The processor (2430) transmits the required guidance details to the trustee device (S5370).

[1252] The processor (2430) calculates a risk level according to function, location, and regulation based on the reflection rate indicating whether the above-mentioned necessary guides have been applied, and continuously updates it for monitoring by period (S5380).

[1253] The processor (2430) transmits a final risk analysis report reflecting the update results to the consultant device (S5390).

[1254] FIG. 54 is a drawing illustrating an embodiment of the core concept of the present invention according to the present disclosure.

[1255] The method for assessing the risk of personal information trustees is specifically described in Figure 54 (5410).

[1256] Figure 55 is a diagram illustrating a flowchart 1 of a consulting method for monitoring based on a risk analysis report of a trustee according to the present disclosure.

[1257] The present invention comprises a trustee device (5510), a consulting device (2400) that monitors based on the trustee's risk analysis report, and a consultant device (5530).

[1258] Flowchart 1 of Fig. 55 is connected to flowchart 2 of Fig. 52.

[1259] The processor (2430) of the consulting device (2400) includes a personal information regulation behavior inspection function module (2431), an infrastructure suitability inspection function module (2432), and a risk analysis function module (2433).

[1260] The personal information regulation scope check function module (2431) performs the function of checking the personal information regulation scope by searching company information.

[1261] The infrastructure suitability check function module (2432) performs the function of checking the infrastructure suitability of the necessary regulations for each infrastructure based on infrastructure information.

[1262] The risk analysis function module (2433) performs a function of analyzing the risk for each infrastructure based on the infrastructure suitability results.

[1263] The trustee device (5510) transmits company information to the personal information regulation inspection function module (2431).

[1264] The personal information regulation act inspection function module (2431) receives company information, checks the scope of regulation through inquiry of the company information, and additionally performs registration of the checked regulatory scope.

[1265] The personal information regulation act inspection function module (2431) transmits the necessary regulatory information of the trustee company to the risk analysis function module (2433).

[1266] The trustee device (5510) transmits human, system, and policy infrastructure information to the infrastructure suitability check function module (2432).

[1267] The infrastructure suitability check function module (2432) checks whether each infrastructure meets the necessary regulations and registers the same.

[1268] The infrastructure suitability check function module (2432) transmits the infrastructure suitability results of the trustee company to the risk function analysis module (2433).

[1269] The risk function analysis module (2433) analyzes the risk of each infrastructure based on the infrastructure suitability results of the trustee company.

[1270] The risk function analysis module (2433) calculates a risk grade based on the risk analysis results and additionally registers the calculated risk grade.

[1271] The risk function analysis module (2433) registers the analysis results for monitoring.

[1272] The risk function analysis module (2433) generates a risk analysis result report reflecting the above risk level and transmits the generated risk analysis result report to the trustee device (5510).

[1273] The trustee device (5510) transmits a consulting request message to the consultant device (5530).

[1274] Figure 56 is a diagram illustrating a flowchart 2 of a consulting method for monitoring based on a risk analysis report of a trustee according to the present disclosure.

[1275] Referring to FIG. 56, the risk analysis function module (2433) transmits a risk analysis result report to the consultant device (5530).

[1276] The consultant device (5530) transmits necessary guidance corresponding to the risk analysis result report to the risk analysis function module (2433).

[1277] The risk analysis function module (2433) applies the necessary guidance, monitors the reflection rate, and registers it.

[1278] The risk analysis function module (2433) transmits the required guidance report to the trustee device (5510).

[1279] The risk analysis function module (2433) monitors whether the necessary guidance of the infrastructure suitability check function module (2432) is applied.

[1280] The risk analysis function module (2433) monitors whether the necessary guidance of the personal information regulation behavior inspection function module (2431) is applied.

[1281] The risk analysis function module (2433) calculates and updates the risk grade based on the results of periodic monitoring of the application and reflection rate of required guidance.

[1282] The risk analysis function module (2433) calculates the risk level according to function, location, and regulation based on the reflection rate.

[1283] For example, the risk level can be calculated as A, B, C, and D.

[1284] If the reflection rate of the required guidance is 0 to 30%, it is evaluated as a D grade.

[1285] If the reflection rate of the required guidance is 30 to 60%, it is evaluated as a C grade.

[1286] If the reflection rate of the required guidance is 60 to 80%, it is evaluated as a B grade.

[1287] If the reflection rate of the required guidance is 80 to 100%, it is evaluated as grade A.

[1288] The risk analysis function module (2433) monitors the calculated risk level by period, including daily, monthly, and yearly.

[1289] The risk analysis function module (2433) repeatedly updates the risk rating at a predetermined interval. For example, the risk analysis function module (2433) may repeatedly update the risk rating at three-month, six-month, or one-year intervals.

[1290] The risk analysis function module (2433) generates a risk analysis result reporter based on the risk grade calculation result and transmits the generated risk analysis result report to the consultant device (5530).

[1291] Figure 57 is a diagram illustrating a flowchart of a personal information processing trustee risk assessment method according to the present disclosure.

[1292] The present invention is performed by a personal information processing trustee risk assessment device (2400) or a processor (2430) of the personal information processing trustee risk assessment device (2400).

[1293] Referring to FIG. 57, the processor (2430) collects first data including company information through the input module (110) (S5710).

[1294] The processor (2430) searches the company information above, searches for the regulatory scope corresponding to the company, and registers an inspection (S5720).

[1295] The processor (2430) conveys the necessary regulations to the trustee company (S5730).

[1296] The processor (2430) receives infrastructure information of the trustee company from the user device (200) (S5740).

[1297] The processor (2430) checks and registers the suitability of the infrastructure information through an access and audit mechanism (S5750).

[1298] The processor (2430) secures suitability based on the contents of the first data (S5760).

[1299] Specifically, the processor (2430) ensures suitability of security and monitoring measures when collecting, storing, transmitting, and processing the contents of the first data.

[1300] The processor (2430) transmits the infrastructure suitability results of the trustee company to the user device (200) (S5770).

[1301] The processor (2430) calculates a risk level by analyzing the risk based on the suitability results for each infrastructure (S5780).

[1302] FIG. 58 is a drawing illustrating an embodiment explaining the core concept of the present invention according to the present disclosure.

[1303] The method for assessing the risk of personal information trustees is specifically described in Fig. 58 (5810).

[1304] Figure 59 is a flowchart illustrating a method for assessing the risk of a personal information processing trustee combined with a server according to the present disclosure.

[1305] The system of the present invention is composed of a user device (5910) and a personal information processing trustee risk assessment device (2400).

[1306] The processor (2430) of the personal information processing trustee risk assessment device (2400) includes a personal information regulation scope inspection function module (2431), an infrastructure suitability inspection function module (2432), and a risk analysis function module (2433).

[1307] The personal information regulation scope check function module (2431) performs the function of checking the personal information regulation scope by searching company information.

[1308] The infrastructure suitability check function module (2432) performs the function of checking the infrastructure suitability of each infrastructure for necessary regulations based on infrastructure information.

[1309] The risk analysis function module (2433) performs a function of analyzing the risk for each infrastructure based on the infrastructure suitability results.

[1310] The user device (5910) transmits company information to the personal information regulation scope check function module (2431).

[1311] The personal information regulation scope check function module (2431) checks the regulation scope through company information inquiry and registers it.

[1312] The personal information regulation scope check function module (2431) transmits the necessary regulations of the trustee company to the risk function analysis module (2433).

[1313] The user device (5910) transmits human, system, and policy infrastructure information to the infrastructure suitability check function module (2432).

[1314] The infrastructure suitability check function module (2432) checks whether each infrastructure meets the necessary regulations and registers the same.

[1315] The infrastructure suitability check function module (2432) checks whether infrastructure information is suitable and registers whether the checked infrastructure information is suitable.

[1316] The infrastructure suitability check function module (2432) transmits the infrastructure suitability results of the trustee company to the risk analysis function module (2433).

[1317] The risk analysis function module (2433) analyzes the risk for each infrastructure.

[1318] The risk analysis function module (2433) calculates a risk level and registers the calculated risk level.

[1319] The risk analysis function module (2433) generates a risk analysis result report based on the calculated risk level.

[1320] The risk analysis function module (2433) generates a risk analysis result report based on the suitability results and risk grade for each infrastructure.

[1321] The risk analysis function module (2433) transmits a risk analysis result report to the user device (5910).

[1322] The various embodiments of the present disclosure are not intended to list all possible combinations but rather to illustrate representative aspects of the present disclosure, and the matters described in the various embodiments may be applied independently or in combinations of two or more.

[1323] The above-described program may include codes coded in a computer language, such as C, C++, JAVA, or machine language, that can be read by the processor (CPU) of the computer through the device interface of the computer, so that the computer reads the program and executes the methods implemented as a program. Such codes may include functional codes related to functions that define functions necessary for executing the methods, and may include control codes related to execution procedures necessary for the processor of the computer to execute the functions according to a predetermined procedure. In addition, such codes may further include memory reference-related codes regarding which location (address address) of the internal or external memory of the computer should reference additional information or media necessary for the processor of the computer to execute the functions. In addition, if the processor of the computer needs to communicate with any other computer or server located remotely in order to execute the functions, the code may further include communication-related code regarding how to communicate with any other computer or server located remotely using the communication module of the computer, and what information or media to send and receive during communication.

[1324] The above storage medium refers to a medium that stores data semi-permanently and can be read by a device, rather than a medium that stores data for a short period of time, such as a register, cache, or memory. Specifically, examples of the storage medium include, but are not limited to, ROM, RAM, CD-ROM, magnetic tape, floppy disk, and optical data storage device. That is, the program can be stored in various recording media on various servers that the computer can access or in various recording media on the user's computer. In addition, the medium can be distributed across network-connected computer systems, so that computer-readable code can be stored in a distributed manner.

[1325] The steps of a method or algorithm described in connection with the embodiments of the present disclosure may be implemented directly in hardware, implemented as a software module executed by hardware, or implemented by a combination thereof. The software module may reside in a random access memory (RAM), a read only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, a hard disk, a removable disk, a CD-ROM, or any other form of computer-readable recording medium well known in the art to which the present disclosure pertains.

[1326] While the embodiments of the present disclosure have been described with reference to the attached drawings, those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without altering the technical spirit or essential features thereof. Therefore, the embodiments described above should be understood to be illustrative in all respects and not restrictive.

Claims

1. In the personal information risk management device, Input module that collects first data including general status of the company and personal information processing status; A communication module for transmitting and receiving the first data with an external device including a mobile device; Memory where at least one process is stored and data is stored for performing operations; Including a processor that performs a personal information risk management method according to the above process, The above processor, The first data, including the general status of the company and the status of personal information processing, is collected through the input module, Based on the collected first data, the purpose of personal information processing is given, Enter the second data including the contents of the questionnaire for collecting personal information, Measure the first distance between the purpose of processing the above personal information and the contents of the above questionnaire form, Deciding whether to collect personal information based on the measured first distance, Personal information risk management device.

2. In the first paragraph, the processor, If there is any content in the above questionnaire that has been confirmed by the questionnaire administrator, the purpose of personal information processing will be expanded. Personal information risk management device.

3. In the second paragraph, the processor, If the above first distance is less than the threshold, allow personal information collection, If the above first distance is greater than the threshold, the collection of personal information is not permitted or the survey manager determines that confirmation is required. Personal information risk management device.

4. In the second paragraph, the processor, Classify the frequency, time zone, and policy violations of specific actions corresponding to the access records of the above first data, Calculate the risk by combining the above-mentioned specific actions based on the scenario, Based on the above risk level, calculate the risk level of misuse of personal information, The above risk level is displayed on the screen. Personal information risk management device.

5. In the first paragraph, the processor, Identify the personal information collected above, Calculate the risk of regulatory violations by identifying whether the identified personal information has been provided within a specific scope and whether it has been agreed upon. The above risk level is displayed on the screen, Transmitting the above risk level to the personal information subject's device based on regulations, Personal information risk management device.

6. In the first paragraph, the processor, Enter the name of the trustee who will carry out personal information processing work, Collect information from the above trustee, Based on the input information, the consignee's inspection items are organized, Receive personal information processing status from the above trustee, The risk level is calculated based on the information of the trustee collected above and the status of personal information processing entered above. Outputting the above risk level on the screen, Personal information risk management device.

7. In paragraph 1, The above first data consists of the company's business type, collection purpose, personal information items, and whether it is necessary or not. Personal information risk management device.

8. In the 7th paragraph, the processor, Among the first data, the minimum required purpose and item data are learned by judging normal data, Among the first data, data excluding the above normal data are judged as abnormal samples and skipped. Personal information risk management device.

9. In the 8th paragraph, the processor Learning using a formula that places the plane separating the above normal data as far away from the origin as possible. Personal information risk management device.

10. In paragraph 1, the processor, The survey receives different questions from users, Identify the characteristic words of the above input query, Calculate the possibility of personal identification by combining the above feature words, Suggesting items of personal information that correspond to the highest possibility of personal identification; Personal information risk management device.

11. In the first paragraph, the processor, Specify the user's role, Specify the authority to which the above user can access personal information, Specify the permissions for the functions that the above users can use, When the above user accesses the system, check the role and authority, If the above user's role and authority meet the conditions, access to the system is permitted. If the above user's role and authority do not meet the conditions, they will be moved to another page. Personal information risk management device.

12. In the first paragraph, the processor, Based on the above reflection rate, the risk level is calculated according to function, location, and regulation. Repeatedly updating the above risk level at regular intervals; Personal information risk management device.

13. In the first paragraph, the processor, Receive human, system and policy infrastructure information from trustee devices; Check whether each infrastructure satisfies the necessary regulations, Based on the results of the infrastructure suitability of the consignment company, the risk level for each infrastructure is analyzed. Based on the analysis results, the risk level is calculated, A risk analysis result report reflecting the calculated risk level is transmitted to the trustee device. Personal information risk management device.

14. In the first paragraph, the processor, Generate a risk analysis result report based on the above infrastructure suitability results and the above risk level rating, Transmitting the generated risk analysis result report to the user's device. Personal information risk management device.

15. In the personal information risk management method performed by the device processor, A step of collecting first data including general information about the company and personal information processing status through an input module; A step of assigning a purpose for processing personal information based on the collected first data; Step of entering second data including the contents of a questionnaire form for collecting personal information; A step of measuring the first distance between the purpose of processing the above personal information and the contents of the above questionnaire form; and Including a step of determining whether to collect personal information based on the measured first distance. How to manage personal information risks.

Citation Information

Patent Citations

  • Question answering system using customer information

    JP4191541B2

  • Personal information protection system based on approval of owner and method thereof

    KR101528785B1

  • Method and server for personal information management

    KR1020150006909A

  • Method and system for providing data using information related to the collection and utilization of personal information

    KR102384662B1

  • Camping stove

    KR102705816B1

Cited By

  • Personal information inspection and protection method based on large language model

    CN121093388A