Apparatus for automating analysis and inspection of compliance requirements and control method thereof
An automated compliance requirements analysis and inspection device addresses the challenges of global networks in responding to diverse information protection regulations by automating the analysis and inspection of compliance requirements, improving user convenience, and reducing the risk of information security leaks and compliance failures.
Patent Information
- Application Number
- PCT/KR2024/019753
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-11-29
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-12
AI Technical Summary
Global networks face challenges in responding to diverse information protection regulations due to differences in legal systems, local employees' understanding, and limitations in information security technologies, leading to potential information security leaks and compliance issues.
An automated compliance requirements analysis and inspection device that collects country-specific personal information regulations, automatically classifies and re-learns policy tags, analyzes a company's terms and conditions and processing policies, and displays security requirements on a screen, while also checking compliance and managing risk assessment and risk action status.
The device improves user convenience by automating the analysis and inspection of compliance requirements, enhancing the ability to respond to information security regulations, and reducing the risk of information security leaks and compliance failures.
Smart Images

Figure KR2024019753_12062025_PF_FP_ABST
Abstract
Description
Compliance requirements analysis and inspection automation device and its control method
[0001] The present disclosure relates to an automated analysis and inspection device. More specifically, it relates to an automated compliance requirements analysis and inspection device and a control method thereof.
[0002] Recently, many companies and organizations have established headquarters in Korea and operate global networks or branches (hereinafter collectively referred to as "global networks") that provide services to customers residing overseas. However, realistically, there are limitations in responding to various information security regulations arising within these global networks. In Korea, information security officers exist, can understand changes in relevant information security regulations, and can establish and respond to them by establishing an information security management system based on this understanding.
[0003] However, in the case of overseas branches that manage and operate global information security with a focus on the headquarters, there are deficiencies in regulatory response due to differences in the legal systems of each country, local employees' understanding of information security regulations, and limitations in responding to information security technologies. This leads to a qualitative decline in the level of information security, which in the long term leads to problems such as failure to respond to information security regulations and deterioration of information security.
[0004] To address these issues, the global network has designated a global information security officer to carry out procedures such as responding to information security regulations and operating information security.
[0005] However, in the case of conventional technology, even global information security managers have limitations in managing regulatory changes, monitoring information security, and maintaining information security levels at the home country level, which can lead to information security leaks.
[0006] In addition, in the case of conventional technology, network equipment is used as a solution to this, and consulting on regulatory response for each country is performed, but even global information security regulation consulting has the problem of users feeling inconvenienced due to the lack of a unified information security regulation management methodology and difficulties in maintaining outputs such as information security regulation contents and various audit data.
[0007] The embodiment disclosed in this disclosure aims to provide an automated compliance requirements analysis and inspection device that collects country-specific personal information regulations and automatically classifies and relearns tags of policies.
[0008] The purpose of the embodiment disclosed in this disclosure is to provide an automated compliance requirements analysis and inspection device that analyzes a company's terms and conditions and processing policies, classifies security requirements into personal information life cycle and security control items, and displays them on a screen.
[0009] The purpose of the embodiment disclosed in this disclosure is to provide a compliance requirements analysis and inspection automation device that automatically checks compliance and manages risk assessment and risk action status based on the inspection results.
[0010] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.
[0011] An automated compliance requirement analysis and inspection device according to the present disclosure comprises: an input module for collecting regulatory data on personal information by country; an external device including a mobile device and a communication module for transmitting and receiving the regulatory data; a memory storing at least one process for performing an automated compliance requirement analysis and inspection operation and storing input and data of a regulatory compliance manager; and a processor for performing an operation according to the process, wherein the processor classifies and relearns a tag of a policy based on the regulatory data collected through the input module, analyzes at least one of a contract, terms and conditions, policy, guideline, and personal information processing policy of a company included in the regulatory data, classifies the security requirements of the company into personal information lifecycle and security control items, verifies compliance with the security requirements, and manages a risk assessment and a risk measure status based on the verified result.
[0012] At this time, the processor may perform at least one of crawling, uploading, link registration, and inputting of the regulatory data, derive main keywords for each provision of the regulatory data, assign tags of personal information regulations, and calculate the similarity of the tag contents.
[0013] Additionally, when an update of the regulatory data occurs, the processor can assign a tag to the updated regulatory data and calculate the similarity between the updated provisions and existing provisions in the updated regulatory data.
[0014] Additionally, the processor may research privacy regulations by country and categorize the researched privacy regulations into micro-regulations or common regulations.
[0015] In addition, the processor may map the security requirements and the result values for the previously analyzed security risks, compare the result values with the reference values of the security requirements, and, if the result values are greater than or equal to the reference values, classify the result as compliance or a matter requiring verification, and, if the result values are less than the reference values, classify the result as non-compliance or a matter requiring verification.
[0016] Additionally, the processor may calculate by mapping the result values of other modules or receive input values from the compliance manager, if the verification is required.
[0017] In addition, the processor maps the security requirements and the results of the analyzed security risks, calculates the risk based on the mapped results, and the risk may include at least one of the possibility of fines, the risk of regulatory violations, and the risk of personal information leakage.
[0018] Additionally, the processor may receive a person in charge of performing a risk action corresponding to the risk level, a deadline, a priority, and a risk level, and transmit a message including the risk action details to the device of the compliance manager.
[0019] At this time, the processor can manage the risk level by changing the status to risk action completed when a risk action trigger occurs.
[0020] In addition, a method for automating compliance requirement analysis and inspection performed by a processor of a device according to the present disclosure may include the steps of collecting regulatory data on personal information by country; classifying and relearning tags of policies based on the collected regulatory data; analyzing at least one of a contract, terms and conditions, policy, guideline, and personal information processing policy of a company included in the regulatory data to classify the company's security requirements into personal information lifecycle and security control items; verifying compliance with the security requirements; and managing a risk assessment and risk response status based on the verification result.
[0021] In addition, a computer program stored in a computer-readable recording medium may be further provided to execute a method for implementing the present disclosure.
[0022] In addition, a computer-readable recording medium recording a computer program for executing a method for implementing the present disclosure may be further provided.
[0023] According to the present invention, user convenience can be improved by collecting country-specific personal information regulations and automatically classifying and relearning policy tags.
[0024] According to the present invention, the company's terms and conditions and processing policy can be analyzed to classify security requirements into personal information life cycle and security control items and display them on the screen, thereby improving user convenience.
[0025] According to the present invention, user convenience can be improved by automatically checking compliance and managing risk assessment and risk action status based on the check results.
[0026] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.
[0027] Figure 1 is a configuration diagram of the entire system according to the present disclosure.
[0028] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.
[0029] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.
[0030] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.
[0031] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.
[0032] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.
[0033] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.
[0034] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.
[0035] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.
[0036] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.
[0037] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.
[0038] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.
[0039] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.
[0040] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.
[0041] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.
[0042] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.
[0043] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.
[0044] Figure 18 is a drawing showing the status of consignment companies according to the present disclosure.
[0045] Figure 19 is a diagram illustrating the status of personal information processing according to the present disclosure.
[0046] Figure 20 is a drawing showing the status of subcontracting companies according to the present disclosure.
[0047] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.
[0048] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.
[0049] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.
[0050] FIG. 24 is a diagram illustrating a configuration of an automated compliance requirement analysis and inspection device according to the present disclosure.
[0051] FIG. 25 is a flowchart illustrating a method for automating compliance requirement analysis and inspection according to the present disclosure.
[0052] Figure 26 is a drawing illustrating the core concept of the present invention according to the present disclosure.
[0053] Figure 27 is a diagram illustrating an example of deriving main keywords for each clause according to the present disclosure.
[0054] FIG. 28 is a diagram illustrating an embodiment of verifying compliance with security requirements according to the present disclosure.
[0055] FIG. 29 is a diagram illustrating an embodiment of calculating risk and executing risk measures according to the present disclosure.
[0056] FIG. 30 is a drawing illustrating an embodiment that explains a problem of the prior art according to the present disclosure.
[0057] FIG. 31 is a diagram illustrating an embodiment of a simple review function of a processing policy according to the present disclosure.
[0058] Figure 32 is a diagram illustrating a flowchart of a simple review method of a processing policy according to the present disclosure.
[0059] Throughout this disclosure, the same reference numerals denote the same components. This disclosure does not describe all elements of the embodiments, and any content that is common in the technical field to which this disclosure pertains or that overlaps between embodiments is omitted. The terms "part, module, element, block" used in the specification may be implemented in software or hardware, and depending on the embodiments, multiple "parts, modules, elements, blocks" may be implemented as a single component, or a single "part, module, element, block" may include multiple components.
[0060] Throughout the specification, when a part is said to be "connected" to another part, this includes not only direct connection but also indirect connection, and indirect connection includes connection via a wireless communication network.
[0061] Additionally, when a part is said to "include" a component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.
[0062] Throughout the specification, when we say that an element is "on" another element, this includes not only cases where the element is in contact with the other element, but also cases where another element exists between the two elements.
[0063] The terms first, second, etc. are used to distinguish one component from another, and the components are not limited by the aforementioned terms.
[0064] Singular expressions include plural expressions unless the context clearly indicates otherwise.
[0065] The identification codes for each step are used for convenience of explanation and do not describe the order of each step. Each step may be performed in a different order than specified unless the context clearly indicates a specific order.
[0066] The operating principle and embodiments of the present disclosure are described below with reference to the attached drawings.
[0067] The present invention can be implemented not only in a server system but also in various devices capable of performing computational processing and providing results to a user. For example, the present invention can include a computer, a server device, and a mobile terminal, or can be implemented in any one of these forms.
[0068] Here, the computer may include, for example, a notebook, desktop, laptop, tablet PC, slate PC, etc. equipped with a web browser.
[0069] The above server device is a server that processes information by communicating with an external device, and may include an application server, a computing server, a database server, a file server, a game server, a mail server, a proxy server, and a web server.
[0070] The above portable terminal may include, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as a PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), WiBro (Wireless Broadband Internet) terminal, a smart phone, and a wearable device such as a watch, a ring, a bracelet, an anklet, a necklace, glasses, contact lenses, or a head-mounted device (HMD).
[0071] The artificial intelligence-related functions according to the present disclosure are operated through a processor and memory. The processor may be composed of one or more processors. In this case, one or more processors may be a general-purpose processor such as a CPU, an AP, a DSP (Digital Signal Processor), a graphics-only processor such as a GPU or a VPU (Vision Processing Unit), or an artificial intelligence-only processor such as an NPU. One or more processors control the processing of input data according to predefined operation rules or artificial intelligence models stored in memory. Alternatively, if one or more processors are artificial intelligence-only processors, the artificial intelligence-only processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.
[0072] The predefined operation rules or artificial intelligence models are characterized by being created through learning. Here, being created through learning means that the basic artificial intelligence model is learned by a learning algorithm using a plurality of learning data, thereby creating a predefined operation rules or artificial intelligence model set to perform a desired characteristic (or purpose). This learning may be performed in the device itself on which the artificial intelligence according to the present disclosure is performed, or may be performed through a separate server and / or system. Examples of the learning algorithm include, but are not limited to, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning.
[0073] An artificial intelligence model may be composed of multiple neural network modules. Each of the multiple neural network modules has multiple weight values, and performs neural network operations through operations between the operation results of the previous module and the multiple weights. The multiple weights of the multiple neural network modules may be optimized based on the learning results of the artificial intelligence model. For example, the multiple weights may be updated so that the loss value or cost value obtained from the artificial intelligence model is reduced or minimized during the learning process. The artificial neural network may include a deep neural network (DNN), and examples thereof include, but are not limited to, a convolutional neural network (CNN), a deep neural network (DNN), a recurrent neural network (RNN), a restricted boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), or deep Q-networks.
[0074] The processor can create a neural network, train (or learn) a neural network, perform computations based on received input data, and generate information signals based on the results of the computations, or retrain the neural network.
[0075] Neural networks include CNN (Convolutional Neural Network), RNN (Recurrent Neural Network), perceptron, multilayer perceptron, FF (Feed Forward), RBF (Radial Basis Network), DFF (Deep Feed Forward), LSTM (Long Short Term Memory), GRU (Gated Recurrent Unit), AE (Auto Encoder), VAE (Variational Auto) Encoder), DAE (Denoising Auto Encoder), SAE (Sparse Auto Encoder), MC (Markov Chain), HN (Hopfield Network), BM (Boltzmann Machine), RBM (Restricted Boltzmann Machine), DBN (Depp Belief Network), DCN (Deep Convolutional Network), DN (Deconvolutional Network), DCIGN (Deep Convolutional Inverse Graphics Network), Generative Adversarial Network (GAN), Liquid State Machine (LSM), Extreme Learning Machine (ELM), It will be understood by those skilled in the art that any neural network may be included, including but not limited to ESN (Echo State Network), DRN (Deep Residual Network), DNC (Differentiable Neural Computer), NTM (Neural Turning Machine), CN (Capsule Network), KN (Kohonen Network), and AN (Attention Network).
[0076] According to an exemplary embodiment of the present disclosure, the processor may be configured to perform a process for generating a CNN (Convolution Neural Network) such as GoogleNet, AlexNet, VGG Network, Region with Convolution Neural Network (R-CNN), Region Proposal Network (RPN), Recurrent Neural Network (RNN), Stacking-based deep Neural Network (S-DNN), State-Space Dynamic Neural Network (S-SDNN), Deconvolution Network, Deep Belief Network (DBN), Restrcted Boltzman Machine (RBM), Fully Convolutional Network, Long Short-Term Memory (LSTM) Network, Classification Network, Generative Modeling, eXplainable AI, Continual AI, Representation Learning, AI for Material Design, BERT, SP-BERT, MRC / QA for natural language processing, Text Analysis, Dialog System, GPT-3, GPT-4, Visual Analytics for vision processing, Visual Understanding, Video Synthesis, ResNet for data intelligence, Anomaly Detection, Prediction, Time-Series Forecasting, Various artificial intelligence structures and algorithms, including optimization, recommendation, and data creation, can be utilized, but are not limited thereto. Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.
[0077] Figure 1 is a configuration diagram of the entire system according to the present disclosure.
[0078] Referring to Fig. 1(10), the configuration of the entire system is described.
[0079] The system (10) is briefly composed of part A (100), part B (200), part C (300), part D (400), part E (500), part F (600), and a processor (50).
[0080] Part A (100) may be referred to as the Compliance Collection and Registration Department.
[0081] Part B (200) may be named the Personal Information Collection and Use and Analysis Department.
[0082] Part C (300) may be named the Compliance and Security Risk Analysis Department.
[0083] Department D (400) may be called a service-specific personal information analysis department.
[0084] Part E (500) may be called a personal information destruction part.
[0085] Part F (600) may be called the authentication management department.
[0086] The processor (50) controls section A (100), section B (200), section C (300), section D (400), section E (500), and section F (600).
[0087] At least one detailed function among Part A (100), Part B (200), Part C (300), Part D (400), Part E (500), and Part F (600) can be stored in memory as software, and the processor (50) can execute the detailed function of each part by referring to the memory.
[0088] Define key terms of the present invention.
[0089] Compliance typically encompasses legal compliance, compliance monitoring, and internal control. A compliance program is a set of systems designed to ensure companies voluntarily comply with relevant laws and regulations during their business operations. Compliance also includes security regulations.
[0090] Regulations include laws, enforcement decrees, notices, guides, etc.
[0091] Inspection means construction, and investigation means the act of creating and configuring control items for investigation, that is, the act of establishing standards.
[0092] Control items refer to items that an organization must comply with to protect personal information.
[0093] A trigger is a condition for an occurrence.
[0094] Tags represent main keywords.
[0095] Internal compliance refers to internal rules.
[0096] Security requirements refer to the security standards and security rules requested by each organization (company) or service situation to protect information assets.
[0097] Common regulations are commonalities among national regulations, including national common regulations and industry-specific common regulations.
[0098] Common regulations by country refer to regulations that exist in common among the regulations that exist in each country selected by the institution or company.
[0099] Common regulations by industry refer to regulations that exist in common among the regulations required for the industry, industry, and scale selected by the organization or company.
[0100] Microregulations are regulations that differ among multiple regulations.
[0101] For example, micro-regulations may be regulations that institutions or companies choose to comply with individually, or may be regulations that are not specifically stipulated in the law or have no specific timing or method.
[0102] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.
[0103] Referring to FIG. 2 (210), the compliance collection and registration unit (100) is described.
[0104] The Compliance Collection and Registration Department (100) is abbreviated as Department A (100).
[0105] The A1 module (110) may be named a compliance collection automation module, the A2 module (120) may be named a compliance inspection automation module, and the A3 module may be named a company-specific security requirements analysis automation module.
[0106] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.
[0107] Referring to FIG. 3 (310), the compliance collection automation module (110) is described.
[0108] The compliance collection automation module (110) finds regulations related to personal information by country, classifies the regulatory provisions, and analyzes the ‘subject’, ‘object’, and ‘predicate’ appearing in the provisions by dividing them into main text and clauses.
[0109] The compliance collection automation module (110) sets keywords based on the analysis and creates tags using these.
[0110] The compliance collection automation module (110) includes a compliance collection module (111) and a compliance analysis-refinement ML module (112).
[0111] The compliance collection module (111) includes a Crawler, Scraper, and API.
[0112] The Compliance Analysis-Refinement ML module (112) sets keywords based on the analysis and converts them into tags. It includes Vision AI, NLP AI, and ETC.
[0113] The Compliance Analysis-Refinement ML module (112) performs the following:
[0114] First, determine your priorities.
[0115] 1) Determine whether it is the main text or a proviso, 2) the priority of regulations based on whether it is a general law or a special law, and 3) the priority of application of regulations based on the legal system.
[0116] Second, it performs subject, object, and verb judgment and tagging.
[0117] 1) Defining the ‘subject of law’ for each clause means judging what corresponds to the subject of a legal provision based on the citation relationship of the legal provision.
[0118] 2) Defining the ‘object of law’ for each provision means judging what corresponds to the object of a legal provision based on the citation relationship of the legal provision.
[0119] 3) Define ‘verb’.
[0120] Third, legal differences are judged and tagging is performed.
[0121] 1) Determine differences between countries regarding specific regulations (laws, enforcement decrees, enforcement rules, notices, instructions, rules, etc.).
[0122] Here, the regulations include:
[0123] An Act (or Law, or Statute) is a law enacted through the legislative process of the National Assembly. It is translated into English as "Act," "Law," or "Statute." For example, "Civil Act" can be translated as "Civil Law."
[0124] An Enforcement Decree is a presidential decree to specifically enforce a law, and is translated into English as "Enforcement Decree."
[0125] Enforcement Rule refers to a regulation of a ministry that provides more detailed regulations for enforcement ordinances, and is translated into English as "Enforcement Rule."
[0126] A public notice (notification) is issued to inform of specific matters and is translated as "Public Notice" or "Notification".
[0127] A directive (or instruction) is an administrative order that gives instructions from a higher authority to a lower authority, and is translated as "directive" or "instruction."
[0128] Regulations (Official Instructions) contain rules regarding procedures or work within an administrative agency and can be translated as "Regulation" or "Official Instruction."
[0129] The country-specific personal information laws (laws, enforcement decrees, rules, notices, instructions, and regulations) management module (not shown) processes personal information-related regulations by country to enable quick assessment.
[0130] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.
[0131] Referring to FIG. 4 (410), the compliance inspection module (120) is described.
[0132] The compliance inspection module (120) builds and creates customized control items related to personal information protection that the organization must comply with.
[0133] The compliance inspection module (120) creates control items by considering 1) the ‘country compliance’ collected and refined in the A1 module (110) and 2) the security requirements.
[0134] The compliance inspection module (120) includes a country-specific compliance inspection trigger automation module (121) and an internal regulation generation module (122).
[0135] The country-specific compliance inspection trigger automation module (121) investigates personal information protection regulations (compliance) by country (the method is to attach an appropriate tag to each provision) and classifies the investigated regulatory tags as micro-regulations or common regulations.
[0136] The internal regulation generation module (122) selects micro-regulations in accordance with internal compliance and generates internal regulations based on the selected micro-regulations.
[0137] The internal regulation creation module (122) allows the internal security officer to review the values from the primary module, select micro-regulations that fit the internal regulations, and create internal regulations using the selected regulations.
[0138] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.
[0139] Referring to FIG. 5 (510), the in-house compliance inspection automation module (123) is described.
[0140] The in-house compliance inspection automation module (123) creates internal regulations as inspection automation modules (as inspection items) so that inspection can be turned on or off.
[0141] The in-house compliance inspection automation module (123) can be connected to the B2 module (220).
[0142] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.
[0143] Referring to Figure 6 (610), the company-specific security requirements analysis automation module (130) is described.
[0144] The company-specific security requirements analysis automation module (130) includes a business security requirements analysis module (131). Here, the company also includes an institution.
[0145] The company-specific security requirements analysis automation module (130) obtains agency information and service information.
[0146] Obtain country information from the location, company name, size, company identification number, and service information.
[0147] The business security requirements analysis module (131) determines which regulation applies based on the acquired information.
[0148] Specifically, the business security requirements analysis module (131) determines which regulations will be applied based on the (obtained) organization / service information.
[0149] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.
[0150] Referring to Figure 7 (710), the personal information collection and use and analysis unit (200) will be described.
[0151] The personal information collection and use and analysis department (200) corresponds to Department B (200).
[0152] Part B (200) includes a B1 module (210), a B2 module (220), a B3 module (230), a B4 module (240), and a B5 module (250).
[0153] The B1 module (210) may be named a collection form creation and response automation module, the B2 module (220) may be named a personal information collection detection automation module, the B3 module (230) may be named a collection and use consent form automatic creation module, the B4 module (240) may be named a personal information processing policy automatic creation module, and the B5 module (250) may be named a personal information subject token and consent history hash creation module.
[0154] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.
[0155] Referring to FIG. 8 (810), the collection form creation and response automation module (210) is described.
[0156] The collection form creation and response automation module (210) allows the administrator to create an input form and collect personal information from the information subject.
[0157] The collection form creation and response automation module (210) includes a personal information collection form creation module (211), a personal information collection detection module (212), an in-house compliance establishment module (213), a processing basis creation module (214), and a personal information processing policy creation module (215).
[0158] The personal information collection form creation module (211) collects content (text, image, video), determines the response method (electronic signature, identity verification), and creates a list and type of information to be collected.
[0159] The personal information collection detection module (212) determines whether the personal information collected in the form for collecting personal information is actual personal information, and if the collected information corresponds to personal information, it transmits the information to the ‘Collection Behavior Management Department’ in charge of personal information collection detection.
[0160] The in-house compliance building module (213) investigates in-house compliance.
[0161] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts an investigation, it can be considered an inspection.
[0162] The processing basis generation module (214) automatically generates a personal information collection and use consent form.
[0163] The processing basis generation module (214) automatically generates personal information collection / provision and use consent forms, as well as processing basis forms. Because the consent forms are generated based on institutional and service information, they can be customized. The consent forms can be modified, such as by tailoring them based on the information of the data subject providing the personal information.
[0164] The grounds for processing are as follows:
[0165] 1. In case the consent of the information subject has been obtained.
[0166] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.
[0167] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.
[0168] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.
[0169] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.
[0170] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the legitimate interests of the personal information processor are significantly related and do not exceed a reasonable scope.
[0171] 7. In cases where it is for public safety and well-being, such as public health.
[0172] The personal information processing policy creation module (215) automatically creates a personal information processing policy.
[0173] The personal information processing policy creation module (215) automatically generates a personal information processing policy based on institutional and service information. It can also create a customized personal information processing policy based on the information of the data subject providing the personal information. The generated personal information processing policy is then transferred to the "Processing Policy Management Department" for management.
[0174] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.
[0175] Figure 9 includes Figures 9(a), 9(b) and 9(c).
[0176] Figure 9(a)(910) is a drawing illustrating a personal information collection form creation module (211).
[0177] Figure 9(b)(920) is a diagram illustrating a personal information collection detection module (212), an in-house compliance establishment module (213), and a processing basis generation module (214).
[0178] Figure 9(c)(930) is a diagram illustrating a personal information processing policy creation module (215).
[0179] As shown in Fig. 9(a)(910), the personal information collection form generation module (211) generates a form for importing personal information, which can be selected by the in-house service manager based on organization information and service information, and automatically generates a personal information collection form (S1).
[0180] As shown in Fig. 9(b)(920), the personal information collection detection module (212) determines whether the information collected in the form for collecting personal information is personal information or not, and if the collected information corresponds to personal information, it transmits the information to the ‘collection behavior management department’ in charge of personal information collection detection (S2).
[0181] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts investigations, it conducts inspections (S3).
[0182] The processing basis generation module (214) automatically generates a consent form for the collection / provision of personal information or a basis for processing (S4). Because it generates a consent form based on institutional and service information, it can be customized. The consent form can be modified, such as by tailoring it based on the information of the data subject providing the personal information.
[0183] The grounds for processing are as follows:
[0184] 1. In case the consent of the information subject has been obtained.
[0185] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.
[0186] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.
[0187] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.
[0188] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.
[0189] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the legitimate interests of the personal information processor are significantly related and do not exceed a reasonable scope.
[0190] 7. For public safety and well-being, including public health.
[0191] As illustrated in Fig. 9(c)(930), the personal information processing policy creation module (215) automatically creates a personal information processing policy based on institutional information and service information, and manages it by transferring it to the ‘processing policy management department’ (S5).
[0192] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.
[0193] Referring to FIG. 10 (1010), the personal information collection detection automation module (220) includes an AI inspection module (221) for detecting whether personal information collection is requested and an AI inspection module (222) for detecting whether personal information is submitted.
[0194] The personal information collection detection automation module (220) is linked with the personal information collection detection module (212) of the B1 module (210).
[0195] The personal information collection detection automation module (220) is linked with the in-house compliance inspection automation module (123).
[0196] The personal information collection detection automation module (220) detects whether a personal information collection request has occurred and manages the collected information by determining whether it corresponds to actual personal information. Personal information includes sensitive information, unique identification numbers, and resident registration numbers.
[0197] The AI Inspect module (221) detects whether a request for personal information collection has been made and automatically classifies the type of information being collected (e.g., personal information, sensitive information, unique identification number, etc.) according to the type of personal information, and automatically applies the appropriate processing procedure for each type.
[0198] The AI Inspect module (222) detects whether personal information has been submitted, and determines whether the information provided by the user is personal information through AI-based analysis (e.g. Vision AI, NLP AI, etc.) to prevent unwanted, unnecessary, and unintended collection of personal information, and detects whether it has been collected.
[0199] The AI Inspect module (222) that detects whether personal information has been submitted analyzes the user's input data using various artificial intelligence technologies such as Vision AI and NLP AI, and determines in real time whether the input information corresponds to personal information.
[0200] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.
[0201] Referring to FIG. 11 (1110), the automatic collection and use consent form generation module (230) is described.
[0202] The automatic collection and use consent form generation module (230) corresponds to the B3 module (230).
[0203] The automatic collection and use consent form automatic generation module (230) includes a processing guide, an automatic collection and use consent form generation module (231), an automatic consent form type template reflection module (232), and a personal information collection purpose analysis module (233).
[0204] The automatic collection and use consent form generation module (230) is a system that automatically generates and manages consent forms required during the collection and processing of personal information. It analyzes the type and purpose of personal information collection to automatically apply an appropriate consent form template. It also generates customized consent forms that reflect legal requirements, automating the process of obtaining consent from data subjects, thereby complying with personal information protection regulations.
[0205] The operational flow of the present invention is described.
[0206] First, the type of personal information consent form is selected according to the type of personal information classified by the B2 module (220).
[0207] Second, the information that should be included in the consent form is directly entered by the personal information processor.
[0208] 1. If the purpose of processing personal information falls under the conditions that do not require the creation of a consent form, a basis for consent is created.
[0209] 2. In the case of creating a consent form, the purpose of processing personal information in the consent form is proposed in the personal information collection purpose analysis module by referring to the value of the personal information collection form creation module.
[0210] 3. Create a consent form using the above information and the template selected by the personal information processor.
[0211] The automated processing guide, collection and use consent form generation module (231) automatically generates consent forms and processing guides related to personal information, sensitive information, and unique identification information. Consent forms and guides are categorized into the following formats.
[0212] 1) In the case of a consent form for collection and use of personal information, it is created when collecting general personal information (name, phone number, email, etc.) and includes the items collected, purpose, retention period, right to refuse consent, and disadvantages thereof.
[0213] 2) In the case of consent to collection and use of sensitive information, it is used when collecting sensitive personal information such as health information and financial information, and includes notifications and requests for additional consent in accordance with relevant laws.
[0214] 3) In the case of a consent form for the collection and use of unique identification information, it is created when collecting unique identification numbers such as alien registration number, passport number, and driver's license number, and includes a request for notification and additional consent items in accordance with relevant laws.
[0215] 4) In the case of the Resident Registration Number Processing Guide, it is a guide provided when processing a unique identification number such as the Resident Registration Number, and the purpose of processing and legal basis are clearly notified.
[0216] 5) In the case of an optional consent form, it is created when personal information is collected selectively rather than for essential purposes such as advertising, and includes the collected items, purpose, retention period, right to refuse consent, and disadvantages thereof.
[0217] The automated module for creating a processing guide, collection and use consent form (231) provides an intuitive interface so that the data subject can understand the consent form and easily choose whether to consent, and each item of the consent form is updated in accordance with relevant laws and regulations.
[0218] The automated consent form template reflection module (232) predefines various types of consent forms and processing guide templates and automatically reflects the appropriate template based on the user's selected personal information collection purpose and legal requirements. The main functions of this module are as follows:
[0219] First, consent form template management.
[0220] Different templates are provided depending on the type of personal information collected, and customized consent forms are created based on the service purpose. For example, different templates can be applied depending on the personal information required for online service registration and offline transactions.
[0221] Second, there are template reflection rules.
[0222] It operates based on rules that automatically select the appropriate template when a specific type of information is entered, as well as the preferences of the personal information handler. For example, when collecting health information, a sensitive information template is applied, while when collecting simple contact information, a personal information template is applied.
[0223] Third, it is an automatic reflection of legal regulations.
[0224] Consent form templates reflect country-specific and industry-specific legal regulations according to predefined rules. For example, consent forms are tailored to the application of the GDPR (European General Data Protection Regulation) and the CCPA (California Consumer Privacy Act).
[0225] The consent form type template reflection automation module (232) is continuously updated, and when new laws or regulations are announced, the corresponding contents can be immediately reflected in the template.
[0226] The personal information collection purpose analysis module (233) utilizes Vision AI, NLP AI, and other artificial intelligence technologies to analyze user-entered information and automatically classify and process the personal information collection purpose accordingly. Its main functions are as follows:
[0227] First, it is Vision AI-based image analysis.
[0228] If the personal information collection form includes an image, the subject matter within the text or image is extracted and analyzed to suggest an appropriate purpose. For example, if the subject matter of an event is extracted from an event poster image, a corresponding purpose is recommended.
[0229] Second, it is NLP AI-based text analysis.
[0230] We analyze text data entered by users to determine the purpose of collection. For example, we analyze information entered by users to create an online registration page and suggest that the purpose is to sign up for a service.
[0231] Third, it is recommended to provide consent forms for each purpose.
[0232] Based on the collected information, we analyze which legal requirements the information must meet and recommend a suitable purpose. For example, if a resident registration number is collected on a prize winner's personal information collection form, we recommend tax reporting purposes.
[0233] The personal information collection purpose analysis module (233) accurately analyzes the purpose of processing collected personal information and helps to notify and obtain consent from the data subject by applying an appropriate processing method in accordance with the Personal Information Protection Act.
[0234] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.
[0235] Referring to Figure 12 (1210), the personal information processing policy automatic generation module (240) is described.
[0236] The personal information processing policy automatic generation module (240) corresponds to the B4 module (240).
[0237] The personal information processing policy automatic generation module (240) includes a service analysis module (241), a processing policy component generation module (242), and a processing policy template reflection automation module (243).
[0238] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It automates all processes, from service analysis to policy template implementation. This module meets legal requirements related to personal information processing and automatically generates policies tailored to the company's service characteristics and security requirements.
[0239] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It uses the service analysis module to identify service characteristics, automatically generates processing policy components, and incorporates these into a template to finalize the final processing policy. This system satisfies legal requirements arising during personal information processing and provides customized processing policies tailored to the characteristics of each service provider, effectively ensuring compliance with legal regulations related to personal information protection.
[0240] The personal information processing policy automatic generation module (240) consists of three modules, and each module efficiently performs the composition of the processing policy and automated management procedures.
[0241] Describes the flow of operations linked with other modules.
[0242] First, the status of the service is provided to the user and the requirements for processing policies related to the status, such as the relevant industry, are analyzed.
[0243] Second, the user is provided with the status of personal information processing and the requirements for processing policies related to that status are analyzed.
[0244] Third, a personal information processing policy is established based on the information provided.
[0245] Fourth, the personal information processing policy is printed by applying the template selected by the user.
[0246] The service analysis module (241) analyzes the service's size, industry, and security requirements to develop a personal information processing policy tailored to the characteristics of the company or service provider. Its main functions are as follows:
[0247] First, industry analysis.
[0248] By analyzing the industry to which the service belongs, the system automatically reflects the industry's regulatory and legal requirements. For example, financial services and healthcare services have different legal requirements, so processing policies tailored to each industry are automatically identified and generated.
[0249] Second, analysis of service scale.
[0250] The complexity and requirements of a privacy policy vary depending on the size of the business. This module analyzes the size of the service provider—large corporations, small and medium-sized enterprises, and startups—and selects an appropriate privacy policy. Large-scale services can apply complex data processing policies, while smaller services can adopt simplified policies.
[0251] Third, there is the analysis of other variables (ETC).
[0252] We analyze various factors, including the service provider's business model, customer base, and whether or not international data transfers are involved. For example, if you provide a global service, legal requirements for cross-border data transfers are reflected in your processing policy.
[0253] The processing policy component generation module (242) automatically generates key components of the processing policy based on data provided by the service analysis module. This module designs each item of the processing policy in detail and can be tailored to the company's operational policies. Its main functions are as follows:
[0254] First, it is the collection, use, and provision of personal information.
[0255] It defines the purpose of collecting personal information, the types of information collected, and whether or not consent is required from the data subject. This includes the scope of use of the personal information collected by the company and how it is provided to third parties, and is designed to ensure clear disclosure to the data subject.
[0256] Second, whether or not to process pseudonymized information.
[0257] For companies using pseudonymized information, the scope of use and processing methods for pseudonymized personal information are automatically defined. This provision is tailored to the type of data requiring pseudonymization and its intended use, and legal justification is provided where necessary.
[0258] Third, there is the information retention and destruction policy.
[0259] Define how long collected personal information will be retained and how it will be destroyed when no longer needed. This section automatically generates information retention periods and destruction procedures, and includes data retention and destruction policies tailored to specific legal regulations (e.g., GDPR or CCPA).
[0260] Fourth, entrustment of personal information and provision to third parties.
[0261] When personal information is outsourced or provided to a third party, all necessary legal procedures and consent forms are managed. Clearly define the legal requirements for entrusting personal information, the method of data sharing with third parties, and notify the data subject and obtain their consent.
[0262] Fifth, overseas relocation and security personnel.
[0263] When personal information is transferred internationally, it reflects the security and legal requirements that arise during the process. Furthermore, it is designed to strengthen data protection by specifying the deployment of security personnel within the company and their roles.
[0264] The Processing Policy Template Reflection Automation Module (243) reflects the generated personal information processing policy components into templates and automates their implementation. This module automatically maps each component to a predefined template to complete the processing policy. Its main functions are as follows:
[0265] First, there is the management of processing policy templates.
[0266] We provide predefined templates for each section of our privacy policy, and we customize and optimize these templates to meet the needs of our service providers. For example, financial institutions may provide templates that incorporate more stringent security requirements, while smaller services may offer simpler policies.
[0267] Second, there is automatic template mapping.
[0268] Data generated by the service analysis module and processing policy component generation module is automatically mapped to templates. This process is performed without manual intervention, and processing policies tailored to the characteristics of each service are automatically generated.
[0269] Third, it reflects legal requirements.
[0270] Automated rules are set up within templates to ensure legal requirements are reflected. For example, if regulations such as GDPR or CCPA are included, applicable items are automatically added and information specifying the rights and responsibilities of data subjects is included.
[0271] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.
[0272] Referring to FIG. 13 (1310), the personal information subject token and consent history hash generation module (250) is described.
[0273] The personal information subject token and consent history hash generation module (250) corresponds to the B5 module (250).
[0274] The personal information subject token and consent history hash generation module (250) includes a third-party DID module (251), a personal information subject token generation module (252), and a consent history hash generation module (253).
[0275] The Personal Information Subject Token and Consent History Hash Generation Module (250) is responsible for generating and managing the data subject's token and the consent history hash value in the personal information protection system. This module handles data subject authentication in various ways, securely stores data generated during the consent process, and maintains record integrity through hash values. Furthermore, it collaborates with third parties (DIDs) to provide various authentication methods and ensure information reliability.
[0276] The Personal Information Subject Token and Consent History Hash Generation Module (250) automates all procedures required for data subject token generation and consent history management. This module securely authenticates the data subject's identity, converts consent history into a hash value to ensure integrity, and thoroughly manages submitted personal information. This module effectively meets legal requirements related to personal information protection.
[0277] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.
[0278] Referring to FIG. 14 (1410), the compliance and security risk analysis unit (300) is described.
[0279] The compliance and security risk analysis unit (300) includes a personal information risk scoring module (310).
[0280] The personal information risk scoring module (310) includes a personal information flow risk identification scoring module (311), a third-party (trustee) cooperation scoring module (312), a personal information destruction scoring module (313), a personal information consistency scoring module (314), a consent history management scoring module (315), a registration and processing policy maintenance scoring module (316), and an overall integrated scoring module (317).
[0281] The Compliance and Security Risk Analysis Department (300) automatically evaluates the risk of personal information within the system to meet personal information protection and compliance requirements, and performs a comprehensive risk assessment through various scoring methods.
[0282] The Compliance and Security Risk Analysis Department (300) evaluates security risks that may arise at all stages of personal information collection, processing, storage, and destruction, and supports the implementation of appropriate protective measures.
[0283] The Compliance and Security Risk Analysis Department (300) analyzes the risk of personal information through various scoring methods, and each scoring is performed based on the following criteria.
[0284] Describes the flow of operations linked with other modules.
[0285] First, each scoring function operates independently.
[0286] Second, the risk is analyzed based on the scoring results.
[0287] The Personal Information Flow Risk Identification Scoring Module (311) assesses potential risks that may arise during the process of personal information being collected and then transferred within the system. Its main functions include:
[0288] First, data movement path analysis.
[0289] Track and analyze where personal information moves within the system and how it is processed. Identify potential data leaks and unauthorized access that may occur during the information transfer process, and assess the risk.
[0290] Second, access rights analysis.
[0291] Analyze the level of user access to personal information to assess whether appropriate permissions have been granted. If permissions are unnecessarily broad or illegal access attempts are detected, the risk is assessed as high.
[0292] Third, data encryption status analysis.
[0293] Ensure that appropriate encryption is applied during data transfer. If encryption is not applied or the encryption level is low, the risk score increases.
[0294] The Third-Party (Trustee) Collaboration Scoring Module (312) assesses the risks associated with sharing personal information with external trustees or third parties. It analyzes potential security risks when personal information is processed by trustees. Its main functions include:
[0295] First, it is an evaluation of the trustee's security level.
[0296] Assess the security policies and management status of the trustee handling personal information. If the trustee is not implementing appropriate security measures or has not obtained security certification, the risk is assessed as high.
[0297] Second, data transmission security evaluation.
[0298] Analyze the security protocols used when personal information is transmitted to third parties. For example, assess whether data is transmitted encrypted and whether security certificates are valid to determine the level of risk.
[0299] Third, third-party access control analysis.
[0300] Analyze the permissions and access control methods of third parties who have access to personal information. Risk increases if unnecessary access is granted or management is poor.
[0301] The Personal Information Destruction Scoring Module (313) evaluates the process of appropriately destroying collected personal information when it is no longer needed or the legal retention period has expired. Its main functions include:
[0302] First, it is an evaluation of compliance with the destruction policy.
[0303] Evaluate whether your personal information destruction policy complies with relevant laws and regulations. For example, ensure that personal information is destroyed promptly according to legal requirements such as the GDPR and CCPA.
[0304] Second, the destruction method is evaluated.
[0305] Assess whether personal information has been completely deleted or recovered appropriately. If secure data deletion methods (e.g., digital shredding, overwriting, etc.) were not applied, the risk is assessed as high.
[0306] Third, the transparency of the destruction procedure is assessed.
[0307] Assess whether the destruction process is transparently managed and recorded. If the destruction process is unclear or records are incomplete, the risk increases.
[0308] The Personal Information Integrity Scoring Module (314) evaluates whether collected personal information is used for its intended purpose and whether the collected information is accurate. Its main functions are as follows:
[0309] First, it is an evaluation of whether it matches the purpose of collection.
[0310] We analyze whether personal information is being used for the originally agreed-upon purposes. If personal information is used for purposes other than those agreed upon, the risk is assessed as high.
[0311] Second, it is an assessment of the accuracy of personal information.
[0312] Assess the accuracy of collected personal information and whether any inaccurate information has been entered. Risks increase when inaccurate information is processed or errors occur.
[0313] Third, it is an evaluation of the protection of the rights of the information subject.
[0314] Assess whether the data subject can appropriately exercise their right to correct, delete, or suspend the use of their personal information. If the data subject's request is ignored or not processed, the risk is assessed as high.
[0315] The Consent History Management Scoring Module (315) evaluates whether appropriate consent was obtained from the data subject when personal information was collected and whether that consent was properly managed. Its main functions are as follows:
[0316] First, it is an evaluation of compliance with the consent procedure.
[0317] Assess whether clear consent has been obtained from the data subject for the collection and use of personal information. If personal information is collected or used without proper consent, the risk is assessed as high.
[0318] Second, it is an evaluation of the management status of consent records.
[0319] Assess whether consent records are securely stored and whether withdrawals are promptly reflected upon the data subject's request. Risks increase if consent records are damaged or withdrawal requests are not reflected.
[0320] The Registration and Processing Policy Maintenance Scoring Module (316) evaluates whether personal information processing policies are properly registered and maintained. Its main functions are as follows:
[0321] First, it is an evaluation of the latest processing policy.
[0322] Evaluate whether your privacy policy is continuously updated to reflect the latest legal requirements. If your privacy policy is not updated despite legal changes, the risk is assessed as high.
[0323] Second, it is an evaluation of the transparency of the processing policy.
[0324] Evaluate whether the processing policy is easily accessible to the data subject and whether it is clear and understandable. If the processing policy is unclear or difficult for the data subject to access, the risk increases.
[0325] The overall integrated scoring module (317) synthesizes the risks generated from each individual scoring module to calculate the overall integrated risk of the personal information processing process. The overall integrated scoring includes the following elements:
[0326] First, weighting is applied.
[0327] The overall risk is calculated by applying weights based on the importance of each scoring module. For example, if the personal information destruction scoring is weighted heavily, a flaw in the destruction process will significantly impact the overall risk.
[0328] Second, it is the calculation of comprehensive risk.
[0329] Based on the individual scoring results, a final overall risk assessment is calculated. The overall risk assessment indicates the overall security level of personal information processing and can be used to suggest additional security measures or management strategies.
[0330] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.
[0331] Referring to Figure 15 (1510), the service-specific personal information analysis unit (400) is described.
[0332] The service-specific personal information analysis unit (400) includes a service-specific personal information analysis module (410).
[0333] The service-specific personal information analysis unit (400) is a system that analyzes personal information collected during service provision by pseudonymizing and anonymizing it, and based on this, classifies the answers provided by users into keywords and determines the meaning of positive or negative.
[0334] The service-specific personal information analysis unit (400) performs pseudonymization and anonymization processing for personal information protection, and analyzes personal information in various stages to support functions necessary for service provision. The service-specific personal information analysis unit (400) of the present invention primarily consists of the following processing steps.
[0335] Step 1 is the pseudonymization step.
[0336] Pseudonymization is the process of protecting personally identifiable information by pseudonymizing it. Pseudonymization is a key method for strengthening privacy protection while using personal information for data analysis and service optimization. Its key functions include:
[0337] First, the personal information identification elements are separated.
[0338] Personal information provided by users, such as name, resident registration number, and email address, is replaced with the minimum information necessary for data analysis. This ensures that data is processed in a way that does not identify specific individuals.
[0339] Second, the application of a pseudonymization algorithm.
[0340] Pseudonymization involves replacing personal information using algorithms such as randomization or hash functions. For example, a user's name is pseudonymized by replacing it with a randomly generated ID. This ID can identify the same individual, but cannot be directly traced back to the original data.
[0341] Third, pseudonymized data management for data analysis.
[0342] Pseudonymized personal information is managed for analysis purposes and stored separately from the original data. After analysis, the original data can be set to not be restored.
[0343] The second step is the anonymization step.
[0344] Anonymization is the process of removing all personally identifiable information from personal data, rendering it completely anonymous. Anonymization completely obscures an individual's identity and is primarily used in statistical analysis and large-scale data analysis. Its main functions are as follows:
[0345] First, the complete elimination of personal identification factors.
[0346] All identifiable information, such as name, resident registration number, and address, is deleted or replaced from personal information so that specific individuals cannot be traced during data analysis.
[0347] Second, it is to strengthen statistical safety.
[0348] Anonymized data is used as aggregated data, not individual information. For example, only non-identifiable information, such as a user's age or gender, is retained for statistical analysis.
[0349] Third, there are measures to prevent re-identification.
[0350] Anonymized data is subject to additional security measures to prevent re-identification. Various security technologies are employed to prevent data recombining to restore the original data.
[0351] Step 3 is the question and multiple answer merge processing step.
[0352] The question and multiple answer merge process analyzes and merges multiple user-provided answers to derive a consistent answer. This process integrates multiple answers to generate final data, and based on that data, it provides results appropriate for the service. Key features include:
[0353] First, there is question analysis.
[0354] The content of user-entered questions and the resulting responses are analyzed. Natural language processing (NLP) technology is used to understand the meaning of the question and extract and process relevant responses.
[0355] Second, multiple answers are merged.
[0356] When multiple answers are provided for the same question, duplicate or ambiguous answers are merged to produce a consistent answer. This improves the quality of the response data and provides consistent results.
[0357] Third, response optimization.
[0358] We refine data to optimize merged responses and provide optimal answers when providing services.
[0359] Step 4 is the response content analysis step.
[0360] The response content analysis step analyzes user-provided response data and determines the keywords and meaning of the response, whether positive or negative. This step utilizes natural language processing (NLP) technology to analyze the response, extract key keywords, and determine the sentiment of the response through sentiment analysis. Key features include:
[0361] First, keyword extraction.
[0362] This step extracts important keywords from user-provided responses. Frequently occurring or contextually significant words in the text data are identified and categorized as keywords. For example, keywords like "satisfied," "dissatisfied," "fast," and "slow" are extracted.
[0363] Second, there are positive and negative judgments.
[0364] Based on extracted keywords, responses are automatically classified as positive or negative. A sentiment analysis algorithm is used to determine whether keywords carry positive or negative connotations. For example, the keyword "satisfied" is classified as positive, while "dissatisfied" is classified as negative.
[0365] Third, keyword weighting.
[0366] Extracted keywords are weighted to determine their importance in providing services. Different weights are assigned based on importance, increasing the accuracy of analysis results.
[0367] Explains the keywords in the response content and the method of judging whether it is positive or negative.
[0368] First, NLP-based text preprocessing is performed.
[0369] The response data is input into a natural language processing model, where unnecessary words are removed and the data is converted into an analyzable form. This includes preprocessing tasks such as tokenization, stopword removal, and stemming.
[0370] Second, extract keywords.
[0371] Extract important keywords based on preprocessed data. Using techniques like TF-IDF and Word2Vec, we identify high-frequency, context-sensitive words.
[0372] Third, perform sentiment analysis.
[0373] Based on the extracted keywords, the sentiment of the responses is analyzed and classified as positive, negative, or neutral. The sentiment analysis algorithm uses a pre-trained dictionary of positive and negative words to evaluate the sentiment of each keyword.
[0374] Fourth, derive results.
[0375] Finally, the extracted keywords and sentiment analysis results are combined to derive the meaning of the answer and generate the information necessary for providing the service.
[0376] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.
[0377] Referring to Figure 16 (1610), the personal information destruction unit (500) will be described.
[0378] The personal information destruction unit (500) includes a personal information destruction automation and hash generation module (510).
[0379] The personal information destruction automation and hash generation module (510) includes a destruction history hash generation module (511).
[0380] The personal information destruction unit (500) is a system that safely destroys personal information when the collection and storage period of the information ends, and creates a destruction history generated in the process as a hash value to ensure integrity.
[0381] The Personal Information Destruction Department (500) automates the personal information destruction process, ensuring compliance with legal requirements and transparently managing the data destruction process. The Personal Information Destruction Department (500) destroys personal information through the following key steps.
[0382] Step 1: Create a personal information destruction scheduler.
[0383] The Personal Information Destruction Scheduler creation step automatically creates and executes a destruction schedule when personal information no longer needs to be retained. This applies when the personal information retention period has expired or when immediate destruction is required at the data subject's request. Key features include:
[0384] First, review the holding period.
[0385] We review the retention period for each personal information item and determine whether the retention period established by legal or service requirements has been exceeded. Personal information is reviewed based on the preset retention period, and any data exceeding the retention period is designated for destruction.
[0386] Second, the destruction schedule is automatically set.
[0387] When personal information is designated for destruction, a destruction scheduler is automatically created and a destruction schedule is set. The destruction schedule can be adjusted to optimize time, taking into account legal requirements and system resources.
[0388] Third, immediate processing of the request for destruction.
[0389] If the data subject requests immediate destruction of personal information, the scheduler immediately sets a destruction schedule and quickly executes the data destruction process.
[0390] Step 2 is the personal information destruction step.
[0391] The personal information destruction stage is the process of actually destroying personal information according to a schedule set by the scheduler. This stage securely destroys data through physical or logical means, and the destroyed information is processed so that it cannot be recovered. Key features include:
[0392] First, it is a logical breakdown.
[0393] Destruction involves deleting personal information stored within the system. This removes the personal information from files or databases, rendering it inaccessible or retrievable. Logical destruction is performed by removing all indexes and references to the data within the system.
[0394] Second, there is physical destruction.
[0395] Completely destroy data by shredding or deleting disks or other storage media containing personal information stored on physical storage devices. This method physically destroys the disk or media, rendering the data unrecoverable.
[0396] Third, data overwriting.
[0397] To ensure that logically deleted data cannot be recovered, the space where the data was stored is repeatedly overwritten with random data to ensure its destruction. This process is a secure method for completely erasing digital data, preventing any possibility of recovery.
[0398] Step 3 is the destruction history hash generation step.
[0399] The destruction history hash generation step records the history of personal information destruction and generates a hash value to ensure integrity. This step records information about the destroyed personal information and the destruction process, and generates a hash value to prevent tampering with this information. Its main functions are as follows:
[0400] First, it is the collection of destruction history data.
[0401] After personal information is destroyed, all data generated during the destruction process is collected. This includes information such as the personal information subject token, authentication method, authentication date, collection form ID, consent ID, and processing policy ID. This data is crucial for ensuring the reliability of the destruction history.
[0402] Second, hash value generation.
[0403] A unique hash value is generated by applying a hash algorithm (such as SHA256) based on the collected destruction history data. This hash value ensures the integrity of the destruction history and protects the data from tampering during the subsequent verification process.
[0404] Third, storage and management of destruction history.
[0405] The generated hash values are securely stored along with the history of destroyed personal information and are managed so that their integrity can be verified by certification authorities or audit processes. The logs and hash values of destroyed data are protected from external access and can be referenced for data verification when necessary.
[0406] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.
[0407] Referring to FIG. 17 (1710), the authentication management unit (600) is described.
[0408] The authentication management unit (600) includes a personal information protection authentication management module (610).
[0409] The certification management department (600) is a system that manages and maintains certifications related to personal information protection, and performs the role of obtaining and maintaining various international and domestic standard certifications based on compliance logs generated within the company.
[0410] The authentication management unit (600) safely processes data generated during the authentication acquisition process and is comprised of steps to verify compliance with authentication standards. The authentication management unit (600) of the present invention primarily manages authentication through the following steps.
[0411] Step 1 is to create an in-house compliance log.
[0412] The internal compliance log generation step involves recording all activities occurring within the system to ensure compliance with privacy protection and related legal regulations. These logs contain data related to personal information processing, access control, and security incident response, primarily collecting and storing the following information:
[0413] First, there is a record of personal information processing activities.
[0414] All activities, including the collection, storage, processing, and destruction of personal information, are recorded in internal compliance logs. Each record includes the time of the activity, the person responsible, and related information.
[0415] Second, there is an access control log.
[0416] Prevent illegal access or abuse of authority by recording the users who accessed personal information, their authority level, and the time of access.
[0417] Third, there is a record of security incident response.
[0418] If a security incident involving personal information occurs, a record of the response to the incident is kept. For example, this includes incident response records for hacking attempts or internal information leaks.
[0419] The logs collected at this stage will be used as data required for subsequent certification applications, and all personal information processing activities occurring within the company will be transparently recorded.
[0420] Step 2 is to create an in-house compliance log hash.
[0421] The in-house compliance log hash generation step generates a hash value to ensure the integrity of the collected compliance log data. The hash value plays a crucial role in protecting the data and verifying whether the log has been tampered with during subsequent authentication procedures. Its main functions are as follows:
[0422] First, the hash algorithm is applied.
[0423] A cryptographic hash algorithm, such as SHA256, is applied to the collected log data to generate a unique hash value. This proves that the log data has not been tampered with.
[0424] Second, log integrity is guaranteed.
[0425] The generated hash value ensures the integrity of the compliance log and provides credibility when the log is subsequently reviewed by a certification authority. This hash value can be provided to external certification authorities to verify the log's legitimacy.
[0426] Third, hash value storage.
[0427] The generated hash value is stored in a secure database and can be referenced during subsequent authentication procedures. The stored hash value serves as a crucial element in verifying that log data has not been tampered with.
[0428] Step 3 is the certification application and management stage.
[0429] The certification application and management stage involves applying for and maintaining international and domestic personal information protection-related certifications based on internally generated compliance logs and hash values. Key certifications are managed in accordance with ISO standards and domestic and international regulations. The process for obtaining these certifications is as follows.
[0430] First, ISO 27701.
[0431] ISO 27701, a Personal Information Management System (PIMS) certification, is an international standard for personal information protection. The certification management department reviews compliance with the ISO 27701 certification criteria and prepares the necessary documents and log data to apply for certification. ISO 27701 certification evaluates compliance with the standard for personal information protection policies, risk management, and personal information processing activities.
[0432] Second, ISO 27001.
[0433] ISO 27001, an Information Security Management System (ISMS) certification, is an international standard for information security. This standard assesses whether an organization has established the management systems necessary to maintain the confidentiality, integrity, and availability of information. The certification management department manages internal information security policies and procedures in accordance with ISO 27001 standards and generates essential log data to maintain certification.
[0434] Third, ISMS-P.
[0435] As a domestic personal information protection and information security management certification, ISMS-P assesses compliance with domestic legal requirements. This certification requires a management system that satisfies both information protection and personal information protection, and the certification management department collects and manages data to maintain ISMS-P certification.
[0436] Fourth, other certifications.
[0437] Other certifications related to privacy and information security (e.g., country-specific privacy certifications, industry-specific regulatory certifications, etc.) are also managed by the Certification Management Department. The department manages internal data in accordance with the requirements of each certification, prepares the necessary documents and materials, and applies for certification.
[0438] At this stage, the certification management department (600) manages all matters necessary for maintaining certification, starting from the application process, and continuously performs certification maintenance and renewal procedures in cooperation with the certification agency.
[0439] For example, FIG. 18 shows the status of a consignee according to the present disclosure (1810), FIG. 19 shows the status of personal information processing (1910), and FIG. 20 shows the status of a subcontractor (2010).
[0440] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.
[0441] Referring to Figure 21 (2110), the inspection items of the inspection checklist are described.
[0442] Inspection items are categorized by order, area, category, inspection item, inspection item details, related evidence, and evaluation criteria.
[0443] The area includes administrative safeguards.
[0444] The division includes an internal management plan.
[0445] Inspection items include establishment and implementation of internal management plans.
[0446] Relevant evidence includes the full text of the internal management plan.
[0447] The evaluation criteria are as follows:
[0448] Y - Contains all essential elements of the internal management plan.
[0449] P - Some items in the internal management plan are missing.
[0450] N - Internal management plan not collected.
[0451] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners and individual organizations.
[0452] The details of the inspection items, related evidence, and evaluation criteria are as follows.
[0453] First, the details of the first inspection item, related evidence, and evaluation criteria.
[0454] Question) Are you including all of the following in your personal information protection documents (internal management plan and related regulations)?
[0455] 1. Matters concerning the composition and operation of the personal information protection organization.
[0456] 2. Matters concerning the qualifications and designation of the personal information protection manager
[0457] 3. Matters concerning the roles and responsibilities of the personal information protection officer and personal information handler.
[0458] 4. Matters concerning management, supervision, and education of personal information handlers
[0459] 5. Matters concerning management of access rights
[0460] 6. Matters concerning access control
[0461] 7. Matters concerning encryption of personal information
[0462] 8. Matters concerning storage and inspection of connection records
[0463] 9. Matters concerning the prevention of malicious programs, etc.
[0464] 10. Matters concerning vulnerability inspection to prevent personal information leakage or theft.
[0465] 11. Matters concerning physical safety measures
[0466] 12. Matters concerning the establishment and implementation of a plan to respond to personal information leaks.
[0467] 13. Matters concerning risk analysis and management
[0468] 14. Matters concerning the management and supervision of the trustee when entrusting personal information processing work.
[0469] 15. Matters concerning the establishment, amendment, and approval of the internal personal information management plan.
[0470] 16. Other matters necessary for personal information protection"
[0471] The relevant evidence is as follows.
[0472] 1. Full text of the Personal Information Protection Policy Document (Internal Management Plan and Personal Information Protection-Related Regulations)
[0473] The evaluation criteria are as follows:
[0474] Y - Contains all required elements within the policy document
[0475] P - Some details are missing from the policy document.
[0476] N - No policy document established
[0477] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners, individuals, and organizations.
[0478] Second, the details of the second inspection item, related evidence, and evaluation criteria.
[0479] Question) Are you obtaining approval from the CEO (or Chief Personal Information Officer) for the personal information protection policy document (internal management plan and personal information protection-related regulations) in accordance with internal personnel procedures?
[0480] - Specify approval records in groupware (deliberation) or internal management plan
[0481] Question) Is the personal information protection policy document (internal management plan and personal information protection-related regulations) published internally?
[0482] - Announcement through posting of internal management plan on groupware bulletin board
[0483] - Produce booklets, etc. and place them in accessible locations.
[0484] The relevant evidence is as follows.
[0485] 1. Approval record
[0486] 2. Publication evidence
[0487] The evaluation criteria are as follows:
[0488] Y - Approved and properly publicized
[0489] P - Approved but not published
[0490] N - Not Approved
[0491] Third, here are the details of the third inspection item.
[0492] Question) Are the personal information protection policy documents (internal management plan and personal information protection-related regulations) reviewed regularly (at least once a year)?
[0493] - Annual review history of personal information protection policy documents (internal management plan and personal information protection-related regulations)
[0494] - Details of approval and announcement of revisions
[0495] The relevant evidence is as follows.
[0496] 1. History of revisions to the Personal Information Protection Policy document (internal management plan and personal information protection-related regulations).
[0497] The evaluation criteria are as follows:
[0498] Y - Records the revision history of the privacy policy document.
[0499] N - Do not keep track of revisions to the Privacy Policy document.
[0500] Fourth, the details of the 4th inspection item.
[0501] Question) Are you inspecting and managing the implementation status of the personal information protection policy document (internal management plan and personal information protection-related regulations) at least once a year and implementing improvement measures for any deficiencies?
[0502] - The personal information protection officer shall conduct an inspection of the implementation status of the personal information protection policy document at least once a year.
[0503] - Review and approval of the inspection results by the personal information protection officer
[0504] - Required checklist when checking the status of implementation
[0505] 1. Access Rights Management
[0506] 2. Storage and inspection of connection records
[0507] 3. Encryption measures
[0508] The relevant evidence is as follows.
[0509] 1. Plan for Inspection of the Implementation Status of Personal Information Protection Policy
[0510] 2. Report on the Implementation Status of Personal Information Protection Policy
[0511] The evaluation criteria are as follows:
[0512] Y - We inspect the implementation of our privacy policy at least once a year.
[0513] P - We are checking the implementation status of the personal information protection policy, but there are some missing items among the required inspection items.
[0514] N - No verification of compliance with privacy policy
[0515] Fifth, the details of the fifth inspection item.
[0516] Question) Have you officially designated a Personal Information Protection Officer with appropriate qualifications?
[0517] - State the person responsible for personal information protection in the personal information protection policy, organizational chart, and personal information processing policy.
[0518] 1. Business owner or representative
[0519] 2. Executive (if there is no executive, the head of the department in charge of personal information processing)
[0520] ※ In the case of small business owners, the business owner or representative is deemed to have been designated as the personal information protection officer without separate designation.
[0521] The relevant evidence is as follows.
[0522] Official documents that confirm the appointment of a personal information protection officer, such as a personal information protection policy, organizational chart, personal information processing policy, and personnel appointments.
[0523] The evaluation criteria are as follows:
[0524] Y - Designate a personal information protection officer and meet the requirements for designating a personal information protection officer.
[0525] P - A personal information protection officer has been designated, but the requirements for designating a personal information protection officer are not met or the person has not been designated in an official document.
[0526] N - No data protection officer has been designated
[0527] Sixth, the details of the 6th inspection item.
[0528] Question) Are you collecting personal information handlers' security pledges for personal information protection?
[0529] ① Confirmation of whether a security pledge is required upon joining or leaving the company.
[0530] ② Regularly (once a year) check whether all personal information handlers are required to re-sign the security pledge.
[0531] ※ Security pledge composition
[0532] - The following content is designed to remind users of their responsibilities to prevent personal information from being leaked.
[0533] 1. Obligations of personal information handlers to protect personal information
[0534] 2. Disciplinary action in case of violation
[0535] 3. Examples of pledges: The following are relevant evidence, such as personal information security pledges and confidentiality pledges.
[0536] 1. Employee Security Pledge
[0537] 2. Security pledge for former employees
[0538] The evaluation criteria are as follows:
[0539] Y - We are regularly collecting security pledges without fail (at least once a year).
[0540] P - We are collecting security pledges, but there are missing people.
[0541] N - Not collecting security pledge
[0542] Seventh, the details of the 7th inspection item.
[0543] Question) Do you provide personal information protection training to personal information protection officers and personal information handlers at least once a year?
[0544] - Develop a personal information protection education plan
[0545] ① Prepare an annual personal information protection education plan including the following:
[0546] 1. Educational Purpose and Target
[0547] 2. Training Content
[0548] 3. Training schedule and methods
[0549] - Evidence of implementation of personal information protection job-specific training
[0550] ① Confirmation of implementation of personal information protection training for personal information handlers
[0551] ② Confirmation of training implementation evidence at least once a year
[0552] ③ Confirmation of management and supervision of those who have not completed training
[0553] ※ Personal information handler: A person who processes personal information under the direction and supervision of a personal information processor, such as an employee, dispatched worker, or part-time worker.
[0554] The relevant evidence is as follows.
[0555] 1. Personal Information Protection Education Plan
[0556] 2. Personal Information Protection Training Results
[0557] 3. Personal information protection training materials
[0558] 4. Personal information protection training completion certificate
[0559] 5. List of Personal Information Protection Training Attendees
[0560] 6. Other evidence that can confirm personal information protection education
[0561] The evaluation criteria are as follows:
[0562] Y - We have established a personal information protection education plan, provide regular education at least once a year, and supervise and manage those who have not completed the education.
[0563] P - Personal information protection training is conducted at least once a year, but no supervision is provided for those who have not completed the training.
[0564] N - Personal information protection training is not conducted at least once a year.
[0565] Eighth, the details of the 8th inspection item.
[0566] Question) Have you established response procedures and methods in case of loss, theft, or leakage of personal information?
[0567] - A personal information leak response plan must be established and implemented, including matters such as leak reporting and notification, damage report reception, and damage relief.
[0568] - Accidents must be reported to the consignor immediately.
[0569] The relevant evidence is as follows.
[0570] 1. Personal Information Leak Response Plan
[0571] The evaluation criteria are as follows:
[0572] Y - Establishing and implementing a personal information leak response plan.
[0573] N - No personal information leak response plan in place
[0574] Ninth, the details of the 9th inspection item.
[0575] Question) In principle, re-entrustment by the trustee without prior consultation is prohibited, but in cases where re-entrustment is unavoidable, is re-entrustment done according to standards?
[0576] - Re-entrustment must be done with the consent of the consignor.
[0577] - A subcontracting agreement must be prepared based on the consignor's consignment agreement.
[0578] - Personal information cannot be used or provided beyond the scope of work entrusted by the consignor.
[0579] The relevant evidence is as follows.
[0580] 1. Evidence of prior approval
[0581] 2. Contract regarding re-consignment
[0582] The evaluation criteria are as follows:
[0583] Y - Personal information is being re-entrusted according to the relevant standards.
[0584] N - Personal information is being re-entrusted without the entrustor's approval.
[0585] Tenth, here are the details of the 10th inspection item.
[0586] Question) When re-entrusting personal information, are you conducting periodic inspections and training?
[0587] The relevant evidence is as follows.
[0588] 1. Regular inspection and training plan for re-trustees
[0589] 2. Results of regular inspection and training of re-trustees
[0590] The evaluation criteria are as follows:
[0591] Y - We manage and supervise trustees through education and inspection.
[0592] N - Not managing and supervising the trustees through education and inspection.
[0593] N / A - Personal information is not re-entrusted
[0594] Eleventh, details of the 11th inspection item.
[0595] Question) Have you established a personal information processing policy that includes all of the required items below and made it publicly available in a way that is easily understandable to the data subject?
[0596] - Personal information processing policy information (Personal information processing policy drafting guidelines, Personal Information Protection Commission, April 2024)
[0597] 1. Title (required)
[0598] 2. Purpose of processing personal information (required)
[0599] 3. Items of personal information processed (required)
[0600] 4. Matters concerning the processing of personal information of children under the age of 14 (recommended when applicable)
[0601] 5. Personal information processing and retention period (required)
[0602] 6. Matters concerning the procedures and methods for destroying personal information (required)
[0603] 7. Matters regarding provision of personal information to third parties (required when applicable)
[0604] 8. Criteria for determining if additional use or provision continues (required when applicable)
[0605] 9. Matters concerning the entrustment of personal information processing (required when applicable)
[0606] 10. Matters concerning the overseas collection and transfer of personal information (required when applicable)
[0607] 11. Matters concerning measures to ensure the security of personal information (required)
[0608] 12. How to choose whether to disclose sensitive information and whether to keep it private (required if applicable)
[0609] 13. Matters concerning the processing of pseudonymized information (required when applicable)
[0610] 14. Matters concerning the installation and operation of automatic personal information collection devices and their refusal (required when applicable)
[0611] 15. Matters concerning the collection, use, and refusal of behavioral information collected by third parties through automatic personal information collection devices (recommended if applicable)
[0612] 16. Matters concerning the rights, obligations, and exercise methods of the data subject and legal representative (required)
[0613] 17. Name of the Personal Information Protection Officer, the department in charge of personal information management, and the department handling complaints (required)
[0614] 18. Matters concerning the designation of a domestic agent (required if applicable)
[0615] 19. Remedies for Infringement of the Rights of Data Subjects (Recommended)
[0616] 20. Matters concerning the operation and management of fixed-type video information processing equipment (required when applicable)
[0617] 21. Matters concerning the operation and management of mobile video information processing devices (required when applicable)
[0618] 22. Matters autonomously established by the personal information processor regarding personal information processing standards and protective measures in the personal information processing policy (recommended)
[0619] 23. Matters regarding changes to the personal information processing policy (required)
[0620] - Disclosure of personal information processing policy
[0621] ① The established or changed personal information processing policy shall be continuously posted on the operating Internet homepage so that the information subject can easily check it.
[0622] ② In cases where it cannot be posted on the Internet homepage, it can be made public through the following methods:
[0623] 1. Place it in a place where it can be easily seen, such as the personal information processor's workplace.
[0624] 2. Publication in publications, newsletters, promotional materials, or bills issued more than twice a year.
[0625] 3. “Specification in the contract with the information subject for the provision of goods or services, etc.”
[0626] The relevant evidence is as follows.
[0627] 1. Personal Information Processing Policy
[0628] 2. Disclosure of Personal Information Processing Policy"
[0629] The evaluation criteria are as follows:
[0630] Y - We have established and continuously disclose a privacy policy that includes all essential information.
[0631] P - Some of the essential provisions of the privacy policy are missing or not consistently posted.
[0632] N - No privacy policy established
[0633] N / A - Personal information will not be re-entrusted"
[0634] The twelfth, the 12th inspection item details.
[0635] Question) Do you have established and are operating access control procedures for physical storage locations where personal information is stored, such as computer rooms and archives?
[0636] - Office access control procedures
[0637] - Installation of additional control devices such as fingerprint recognition devices, card key devices, and number key devices"
[0638] The relevant evidence is as follows.
[0639] 1. Access Control Procedure Document
[0640] 2. Status of application of access control
[0641] 3. Evidence of access control operation (entrance / exit log, etc.)
[0642] The evaluation criteria are as follows:
[0643] Y - Establish and operate access control procedures for physical storage locations.
[0644] N - No access control procedures for physical storage locations are established.
[0645] The thirteenth, the 13th inspection item details.
[0646] Question) Are documents and auxiliary storage media containing personal information stored in a secure location with a lock or other locking device?
[0647] - Safely store documents and auxiliary storage media containing personal information.
[0648] The relevant evidence is as follows.
[0649] 1. Evidence materials such as documents or auxiliary storage media containing personal information are stored in a separate space with a locking device.
[0650] The evaluation criteria are as follows:
[0651] Y - Documents and auxiliary storage media containing personal information are stored in a safe place.
[0652] N - Documents and auxiliary storage media containing personal information are not stored in a secure location.
[0653] Fourteenth, the details of the 14th inspection item.
[0654] Question) Have you established and implemented a policy to control the import and export of auxiliary storage media?
[0655] - Establish procedures for bringing in / taking out auxiliary storage media within internal regulations.
[0656] ① Check if there is a procedure for bringing in / taking out auxiliary storage media.
[0657] ② Check whether there is a permit request and approval procedure for import / export
[0658] ③ Check the auxiliary storage media import / export management ledger when bringing in / out
[0659] The relevant evidence is as follows.
[0660] 1. Policy on controlling the import and export of auxiliary storage media
[0661] 2. Auxiliary storage media import / export management ledger
[0662] The evaluation criteria are as follows:
[0663] Y - Establishing standards for the import and export of auxiliary storage media and implementing control procedures.
[0664] P - The standards for exporting and importing auxiliary storage media are inadequate or there is no control over export and import.
[0665] N - There are no standards for the import and export of auxiliary storage media, and there is no control over import and export.
[0666] Fifteenth, here are the details of the 15th inspection item.
[0667] Question) Are you granting personal information handlers differential access to the personal information processing system to the minimum extent necessary for performing their duties?
[0668] - Issuance of accounts for each personal information handler
[0669] - No account sharing
[0670] - If account sharing is unavoidable, measures to ensure accountability are required.
[0671] - Restrictions on printing and downloading personal information
[0672] The relevant evidence is as follows.
[0673] 1. List of personal information handlers
[0674] 2. Status of access rights to personal information processing systems
[0675] The evaluation criteria are as follows:
[0676] Y - The personal information handler account is granted minimal permissions.
[0677] P - Personal information handler account permissions are minimal, but some people are granted excessive permissions.
[0678] N - Does not restrict the permissions of the personal information handler account
[0679] Sixteenth, the details of the 16th inspection item.
[0680] Question) When a personnel change, such as a transfer or retirement, occurs, are access rights to the personal information processing system changed or deleted without delay?
[0681] - Changes in personal information processing system authority due to changes in business
[0682] - Delete retiree accounts in the personal information processing system
[0683] The relevant evidence is as follows.
[0684] 1. Retirement and Job Change Procedure
[0685] 2. History of account deletion or access rights changes
[0686] The evaluation criteria are as follows:
[0687] Y - Access rights are immediately revoked in the event of personnel transfers such as retirement.
[0688] N - Access rights are not immediately revoked upon personnel transfer, such as retirement.
[0689] Seventeenth, details of the 17th inspection item.
[0690] Q) Are you keeping a record of the granting, modification, and deletion of access rights to your personal information processing system?
[0691] - Records of changes in personal information processing system access rights are kept for at least 3 years.
[0692] - Includes minimum information to ensure accountability, such as account name, name, affiliation, and authority.
[0693] The relevant evidence is as follows.
[0694] 1. Changes to personal information processing system access rights
[0695] 2. Application for Change of Access Rights
[0696] The evaluation criteria are as follows:
[0697] Y - Records of changes in personal information handler access rights are safely stored for at least three years.
[0698] P - Records of changes in access rights of personal information handlers are being kept, but the change history cannot be clearly confirmed or is not kept for more than 3 years.
[0699] N - Does not record changes in access rights of personal information handlers
[0700] The eighteenth, detailed content of the 18th inspection item.
[0701] Question) Are you taking any measures, such as automatically blocking access to the personal information processing system if no work is done for a certain period of time?
[0702] - Personal information processing system session timeout, token expiration time setting, etc.
[0703] The relevant evidence is as follows.
[0704] 1. Evidence of setting maximum connection time limit
[0705] The evaluation criteria are as follows:
[0706] Y - Personal information processing system timeout function is applied
[0707] N - Personal information processing system timeout function is not applied
[0708] Nineteenth, the details of the 19th inspection item.
[0709] Question) When access to the personal information processing system from outside via an information and communications network is required, are secure authentication methods being applied?
[0710] - Secure authentication methods: OTP, certificate, security token, etc.
[0711] - Secure connection methods: VPN, dedicated line, etc.
[0712] The relevant evidence is as follows.
[0713] 1. Evidence of setting up a secure authentication method or connection method when accessing the personal information processing system from outside.
[0714] The evaluation criteria are as follows:
[0715] Y - Remote access to the personal information processing system from outside is restricted.
[0716] N - Does not restrict remote access to the personal information processing system from outside.
[0717] The twentieth, detailed content of the 20th inspection item.
[0718] Question) Are you restricting internet access for important terminals that process personal information?
[0719] - If the following tasks are possible, it is considered an important terminal.
[0720] 1. Personal information can be downloaded or destroyed from the personal information processing system.
[0721] 2. Access rights to the personal information processing system can be set.
[0722] The relevant evidence is as follows.
[0723] 1. Evidence of Internet blocking settings on important terminals
[0724] The evaluation criteria are as follows:
[0725] Y - Internet use on important terminals is restricted.
[0726] N - Does not restrict Internet use on important terminals
[0727] N / A - Not eligible for network separation
[0728] Twenty-first, the details of the 21st inspection item.
[0729] Question) Are you restricting access to the personal information processing system by IP address, etc.?
[0730] - Allow access only to specific IPs / MACs through firewalls, etc.
[0731] - Allow access only to specific IPs / MACs using the router's ACL function.
[0732] - Use access control solutions to allow access only to authorized personnel.
[0733] The relevant evidence is as follows.
[0734] 1. Evidence of restricted access to personal information processing systems
[0735] 2. Evidence of security solution operation
[0736] The evaluation criteria are as follows:
[0737] Y - Access control is set when accessing the personal information processing system.
[0738] P - Access control is inadequate when accessing the personal information processing system.
[0739] N - Do not set access control when accessing the personal information processing system.
[0740] Twenty-second, detailed contents of the 22nd inspection item.
[0741] Question) Are you safely applying and managing the authentication method for personal information handlers or data subjects in the personal information processing system?
[0742] - Application of authentication methods (password, OTP, etc.) according to internal management plan or guidelines
[0743] - Restrict access to the personal information processing system if authentication fails a certain number of times.
[0744] The relevant evidence is as follows.
[0745] 1. Provision of authentication methods within the internal management plan
[0746] 2. Setting the authentication method threshold
[0747] The evaluation criteria are as follows:
[0748] Y - Applying authentication methods and setting thresholds for personal information processing systems.
[0749] P - Authentication methods are applied to personal information processing systems, but thresholds are not set.
[0750] N - No authentication method applied to personal information processing system"
[0751] Twenty-third, details of the 23rd inspection item.
[0752] Question) When searching or printing personal information, are you minimizing the number of personal information items printed to only the information necessary for business purposes and applying safety measures to safely manage printouts and copies?
[0753] - Establish policies / regulations / guidelines for protecting and managing output and copies
[0754] - Safety measures such as watermarking, output history recording, and destruction confirmation
[0755] - When printing personal information (printing, displaying on screen, creating files, etc.), print it to the minimum extent possible within the scope of access rights by specifying the purpose.
[0756] - Whether to mask when viewing the entire list of personal information through the personal information processing system
[0757] The relevant evidence is as follows.
[0758] 1. Evidence of personal information masking
[0759] The evaluation criteria are as follows:
[0760] Y - Security measures are applied when viewing the full list of personal information.
[0761] N - No security measures applied when viewing the full list of personal information
[0762] The twenty-fourth, detailed inspection item 24.
[0763] Question) Are you storing and managing access records, including essential items, for the personal information processing system of the personal information handler for more than one year?
[0764] - Required items: identifier, access date and time, access location information, information on the subject of the information processed, and tasks performed.
[0765] - In the cases below, they must be stored and managed for more than 2 years.
[0766] 1. In the case of a personal information processing system that processes personal information of more than 50,000 data subjects.
[0767] 2. In the case of a personal information processing system that processes unique identification information or sensitive information.
[0768] 3. In case the personal information processor is a telecommunications service provider
[0769] ※ Explanation of required items for access log
[0770] - Identifier: Account information such as ID assigned to identify the user in the personal information processing system.
[0771] - Access date and time: Time of access or time of work performed (year-month-day, hour:minute:second)
[0772] - Access information: IP address of the computer or server of the person accessing the personal information processing system, etc.
[0773] - Processed information subject information: Identification information (ID, customer number, student number, employee number, etc.) that allows the personal information handler to determine whose personal information was processed.
[0774] - Performance tasks: Information that allows the personal information handler to know the details of personal information processed using the personal information processing system (collecting, creating, linking, connecting, recording, storing, holding, processing, editing, searching, printing, correcting, recovering, using, providing, disclosing, destroying, etc. may be considered performance tasks)
[0775] The relevant evidence is as follows.
[0776] 1. Access log of personal information processing system
[0777] The evaluation criteria are as follows:
[0778] Y - Access records of personal information processing systems are stored and managed for at least one or two years, including all required information.
[0779] P - Access records for the personal information processing system are being kept, but some information is missing or the access record retention period is not appropriate.
[0780] N - Access records of personal information processing systems are not kept.
[0781] Twenty-fifth, the 25th inspection item details.
[0782] Question) Are you checking the access records of the personal information processing system at least once a month?
[0783] - Check for excessive personal information inquiries, access outside of working hours, and reasons for downloading personal information.
[0784] - When downloading personal information, it is mandatory to check the reason for downloading.
[0785] The relevant evidence is as follows.
[0786] 1. Personal information processing system access log inspection plan
[0787] 2. Personal information processing system access log inspection report
[0788] The evaluation criteria are as follows:
[0789] Y - Checking the appropriateness of the access records and reasons for downloading personal information from the personal information processing system (at least once a month)
[0790] P - We are checking the appropriateness of the personal information processing system access records and reasons for downloading personal information, but we do not conduct inspections more than once a month.
[0791] N - The access records of the personal information processing system and the reasons for downloading personal information are not checked for appropriateness.
[0792] Twenty-sixth, the 26th inspection item details.
[0793] Question) Are you taking necessary measures in your personal information processing system, personal information handler's computer, and mobile device to prevent personal information from being disclosed or leaked to unauthorized persons through Internet homepages, P2P, sharing settings, etc.?
[0794] - Block access to harmful sites such as P2P
[0795] - Shared folder restrictions
[0796] - Application of security solutions such as DLP and DRM
[0797] The relevant evidence is as follows.
[0798] 1. Evidence of blocking access to harmful websites on the personal information handler's terminal
[0799] 2. Evidence of shared folder restriction settings
[0800] 3. Evidence of security solution operation
[0801] The evaluation criteria are as follows:
[0802] Y - Measures are being established to prevent personal information leakage and exposure on personal information handler terminals.
[0803] N - No measures are set up on the personal information handler's terminal to prevent personal information leakage or exposure.
[0804] Twenty-seventh, the 27th inspection item details.
[0805] Question) Are you establishing and applying a password policy for personal information handlers or data subjects who access the personal information processing system?
[0806] - The minimum password length is set to 10 characters when combining at least two types of uppercase letters, lowercase letters, numbers, and special characters, or 8 characters when combining at least three types of characters.
[0807] - Set an expiration date for your password, change it at least once every six months, and prevent the use of two passwords interchangeably.
[0808] - If you enter your password incorrectly more than 5 times, access restrictions such as account locking and delay settings will be applied.
[0809] - Set passwords that are easy to guess, such as consecutive numbers, birthdays, phone numbers, or passwords that are similar to IDs, to be unavailable.
[0810] ※ Not applicable if password is not used as an authentication method"
[0811] The relevant evidence is as follows.
[0812] 1. Password policy within the internal management plan
[0813] 2. Password policy set in the personal information processing system
[0814] 3. Password change date status
[0815] The evaluation criteria are as follows:
[0816] Y - Set a secure password that meets the password standards and change it regularly.
[0817] N - You are using a weak password or your password policy settings are not being applied.
[0818] Twenty-eighth, the 28th inspection item details.
[0819] Question) Are you storing your password using one-way encryption?
[0820] - Application of a secure one-way encryption algorithm higher than SHA-2
[0821] - Refer to the latest information, such as the KISA encryption algorithm and key length usage guide.
[0822] ※ Not applicable if password is not used as authentication method
[0823] The relevant evidence is as follows.
[0824] 1. Evidence of application of encryption algorithm to password
[0825] The evaluation criteria are as follows:
[0826] Y - A secure encryption algorithm is applied when storing passwords.
[0827] N - No secure encryption algorithm is used when storing passwords.
[0828] The twenty-ninth, 29th inspection item details.
[0829] Question) Are users' resident registration numbers, passport numbers, driver's license numbers, alien registration numbers, credit card numbers, account numbers, and biometric information encrypted and stored using a secure encryption algorithm?
[0830] - Writing of applied symmetric key encryption algorithms (SEED, ARIA-128 / 192 / 256, AES-128 / 192 / 256, HIGHT, etc.)
[0831] - Writing of applied public key encryption algorithms (RSAES-OAEP, RSAES-PKCS1, etc.)
[0832] The relevant evidence is as follows.
[0833] 1. Evidence of personal information encryption application
[0834] 2. Encryption algorithm evidence
[0835] The evaluation criteria are as follows:
[0836] Y - Personal information is encrypted and stored using a secure encryption algorithm.
[0837] N - Personal information is stored without encryption using a secure encryption algorithm.
[0838] The thirtieth, detailed content of the 30th inspection item.
[0839] Question) When sending and receiving passwords, personal information, and authentication information via information and communications networks, are they encrypted?
[0840] - Apply SSL (https) or install an encryption program"
[0841] The relevant evidence is as follows.
[0842] 1. SSL certificate information
[0843] 2. Evidence of personal information encryption through encryption solutions, etc.
[0844] The evaluation criteria are as follows:
[0845] Y - Personal information and authentication information transmitted and received via information and communications networks are encrypted.
[0846] N - Personal information and authentication information transmitted and received via information and communications networks are not encrypted.
[0847] Here are the details of the thirty-first inspection item.
[0848] Question) When storing personal information on PCs, mobile devices, and auxiliary storage media, is it encrypted?
[0849] - When downloading files from the personal information processing system, they are downloaded with the password settings applied.
[0850] - Manually set a password for personal information files (such as password settings provided by office programs)
[0851] - When using auxiliary storage media, use secure USB, etc.
[0852] - DRM applied
[0853] The relevant evidence is as follows.
[0854] 1. Evidence that encryption has been applied when storing personal information files on a PC, auxiliary storage media, etc.
[0855] The evaluation criteria are as follows:
[0856] Y - Personal information is encrypted and stored.
[0857] N - Do not encrypt personal information when storing it
[0858] Thirty-second, detailed inspection item 32.
[0859] The relevant evidence is as follows.
[0860] 1. Password key management procedures
[0861] The evaluation criteria are as follows:
[0862] Y - Establishing and implementing secure encryption key management procedures.
[0863] N - Failure to establish and implement secure encryption key management procedures
[0864] Thirty-third, details of the 33rd inspection item.
[0865] Question) Are you installing and operating a security program to check for and treat malware on your personal information handler's PC?
[0866] - Automatic update or update at least once a day
[0867] - Real-time monitoring and daily scheduled inspections
[0868] The relevant evidence is as follows.
[0869] 1. Security program installation history
[0870] 2. Security program inspection details
[0871] 3. Security program update history
[0872] The evaluation criteria are as follows:
[0873] Y - I have installed a security program, am running real-time monitoring, and am performing updates once a day.
[0874] P - Security program installed but not updated once a day or set up real-time monitoring
[0875] N - Do not install or run security programs
[0876] Thirty-fourth, details of inspection item 34.
[0877] Question) If there is a security update notice for the application or operating system software being used on the personal information handler's PC, do you apply the update immediately?
[0878] The relevant evidence is as follows.
[0879] 1. A screen where you can check for security updates on the personal information handler's PC.
[0880] 2. Evidence that can confirm whether security updates are being applied to applications installed on the PC.
[0881] 3. Update-related notice
[0882] The evaluation criteria are as follows:
[0883] Y - Applying updates immediately when security updates are announced
[0884] N - Do not apply security updates immediately
[0885] Thirty-fifth, details of inspection item 35.
[0886] Question) Do you have a crisis response manual and backup and recovery plan in place to prepare for disasters such as fire, flood, and power outages, and do you regularly review them?
[0887] ※ If it does not fall under the types below, it may be excluded from the inspection items.
[0888] - Large corporations, medium-sized enterprises, and public institutions that process personal information of more than 100,000 data subjects.
[0889] - Personal information processors that are small and medium-sized enterprises or organizations that process personal information of more than 1 million data subjects.
[0890] The relevant evidence is as follows.
[0891] 1. Crisis Response Manual (Document)
[0892] 2. Backup and Recovery Policy and Procedures (Document)
[0893] The evaluation criteria are as follows:
[0894] Y - Establishing crisis response procedures, including backup and recovery plans.
[0895] P - Crisis response procedures are in place but backup and recovery plans are missing, or backup and recovery plans are in place but crisis response procedures are inadequate.
[0896] N - No crisis response procedures established"
[0897] Thirty-sixth, details of the 36th inspection item.
[0898] Question) In addition to the personal information provided by the consignor, when collecting additional personal information for the purpose of processing the consignor's business, are you obtaining consent in an appropriate manner, such as by notifying all necessary information for consent and indicating important information?
[0899] - Required notification in consent form
[0900] 1. Purpose of collection and use of personal information
[0901] 2. Items of personal information to be collected
[0902] 3. Retention and use period of personal information
[0903] 4. The fact that you have the right to refuse consent and, if there are any disadvantages resulting from refusal of consent, the details of those disadvantages.
[0904] 5. (When provided to a third party) Recipient, purpose of use by recipient, period of use, items provided, right to refuse consent and disadvantages of consent
[0905] - How to display important information in the consent form
[0906] 1. The font size should be at least 9 points and at least 20% larger than other content to ensure easy reading.
[0907] 2. Clearly indicate the content through text color, thickness, or underlining.
[0908] 3. If there are many matters to agree on and it is difficult to clearly distinguish important matters, display them separately from other matters so that important matters can be easily identified.
[0909] The relevant evidence is as follows.
[0910] 1. Personal information collection and use consent screen
[0911] The evaluation criteria are as follows:
[0912] Y - We collect personal information by providing all required notices and obtaining consent.
[0913] N - Personal information is being collected without providing or omitting required notices.
[0914] Thirty-seventh, details of the 37th inspection item.
[0915] Question) Are you destroying personal information without delay after confirming that the retention period has expired or the business purpose has been achieved?
[0916] - Writing the conditions and cycle for destroying personal information
[0917] - Create a history of personal information destruction
[0918] - Request for the preparation of evidence of personal information destruction, such as a "Personal Information Destruction Confirmation Form"
[0919] The relevant evidence is as follows.
[0920] 1. Personal Information Destruction Procedure
[0921] 2. Setting up personal information destruction batches
[0922] 3. Personal Information Destruction Confirmation Form
[0923] 4. Personal information destruction history
[0924] The evaluation criteria are as follows:
[0925] Y - Establishing destruction criteria and procedures and managing post-destruction history.
[0926] P - Establishing destruction criteria or procedures, but not managing destruction history
[0927] N - No destruction criteria or procedures established
[0928] Thirty-eighth, details of the 38th inspection item.
[0929] Question) If personal information must be retained even after the purpose of use has been achieved, is it stored and managed separately from other personal information being operated?
[0930] - Writing the conditions and cycle for separate storage of personal information
[0931] The relevant evidence is as follows.
[0932] 1. Evidence of separate storage of personal information
[0933] The evaluation criteria are as follows:
[0934] Y - Personal information that needs to be kept even after the purpose has been achieved is kept safely separated from operational personal information.
[0935] N - Personal information that needs to be retained even after the purpose has been achieved is stored without being separated from operational personal information.
[0936] Thirty-ninth, details of inspection item 39.
[0937] Question) Are you destroying personal information in the following secure manner?
[0938] - Personal information stored in electronic file formats such as PCs, auxiliary storage media, and mailboxes is deleted in a way that makes it unrecoverable using a technical method that renders the records unrecoverable.
[0939] - In the case of personal information printed on paper, it is destroyed using a method that makes it unrecoverable, such as shredding or incineration.
[0940] The relevant evidence is as follows.
[0941] 1. Evidence of destruction of personal information stored in electronic file format
[0942] 2. Document shredder, document destruction box evidence
[0943] The evaluation criteria are as follows:
[0944] Y - Personal information is being destroyed in a secure manner.
[0945] N - Not destroying personal information
[0946] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.
[0947] Referring to Figure 22 (2210), the inspection status of the inspection checklist is explained.
[0948] The inspection status is divided into inspection status, related laws and regulations, and related notices.
[0949] The relevant laws are Article 29 of the Personal Information Protection Act and Article 30 of the Enforcement Decree.
[0950] The relevant notice is Article 4 of the Personal Information Security Measures Standards.
[0951] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.
[0952] Referring to Figure 23 (2310), the penalty provisions of the inspection checklist are explained.
[0953] Penalty provisions are divided into penalties and penalty provisions.
[0954] Penalties are divided into criminal penalties and administrative measures.
[0955] Punishments are divided into imprisonment and fines.
[0956] Administrative sanctions are categorized into fines and surcharges. Surcharges can be up to 50 million won.
[0957] The penalty provision is Article 75 of the Personal Information Protection Act.
[0958] According to Article 75 of the Personal Information Protection Act, a person who falls under any of the following items shall be subject to a fine of up to 50 million won.
[0959] 5) A person who has violated Article 23, Paragraph 2, Article 24, Paragraph 3, Article 25, Paragraph 6 (including cases where it applies pursuant to Article 25-2, Paragraph 4), Article 28-4, Paragraph 1, and Article 29 (including cases where it applies pursuant to Article 26, Paragraph 8) and has not taken necessary measures to ensure safety.
[0960] Above, the entire system of the present disclosure has been described with reference to FIGS. 1 to 23. Below, the compliance requirement analysis and inspection automation process according to the present disclosure will be described in detail with reference to FIGS. 24 to 32.
[0961] FIG. 24 is a diagram illustrating a configuration of an automated compliance requirement analysis and inspection device according to the present disclosure.
[0962] Referring to FIG. 24, the compliance requirement analysis and inspection automation device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).
[0963] The input module (2410) collects regulatory data on personal information by country.
[0964] The sensor module (2420) senses data.
[0965] The processor (2430) performs a control method according to the process.
[0966] That is, the processor (2430) collects regulatory data on personal information by country through the input module (2410), classifies and relearns tags of policies based on the collected regulatory data, analyzes at least one of the contracts, terms and conditions, policies, guidelines, and personal information processing policies of the company included in the regulatory data to classify the security requirements of the company into personal information life cycle and security control items, controls the display (2440) to display the personal information life cycle and the security control items, verifies compliance with the security requirements, and manages risk assessment and risk action status based on the verification result.
[0967] Here, the personal information lifecycle refers to the collection, use, provision, and destruction of personal information.
[0968] Here, security control items refer to matters other than the collection-use-provision-destruction of personal information, such as policy establishment, organizational operation (personal information education, access authority management, access control, etc.), technical protection measures (authentication means management, personal information encryption, etc.), and protection of information subject rights.
[0969] The processor (2430) can investigate personal information protection regulations by country and classify the investigated personal information protection regulations into micro regulations or common regulations.
[0970] In addition, the processor (2430) performs at least one of crawling, uploading, link registration, and inputting of regulatory data, derives main keywords for each provision of the regulatory data, assigns tags of personal information regulations, and calculates the similarity of the tag contents.
[0971] When the above regulatory data is updated (regulations are added, modified, or deleted), the processor (2430) assigns a tag to the updated regulatory data and calculates the similarity between the updated provisions and existing provisions. A detailed description of this is provided in Fig. 27.
[0972] The processor (2430) maps the security requirements described below and the result value for the risk analyzed by the compliance and security risk analysis unit (300), calculates whether the result value reaches the standard value of the security requirements, and if the result value is greater than the standard value, classifies it as compliance or a matter requiring confirmation, and if the result value is less than the standard value, classifies it as non-compliance or a matter requiring confirmation.
[0973] If verification is required, the processor (2430) calculates the results of other modules by mapping them or receives input values from the compliance manager. A detailed description of this is provided in Fig. 29.
[0974] The processor (2430) maps the result values for the risk analyzed by the security requirements and compliance and security risk analysis unit (300), calculates the risk based on the mapping result, and controls the display (2440) to display the calculated risk, wherein the risk includes at least one of the possibility of a fine and the risk of personal information leakage.
[0975] The processor (2430) receives from the compliance manager the person in charge of performing the risk action corresponding to the risk level, the deadline, and the priority, and transmits a message including the risk action details to the device of the compliance manager (or the person in charge).
[0976] When a risk action trigger occurs, the processor (2430) manages the risk level by changing the status to risk action completed. A detailed description of this is provided in Fig. 28.
[0977] However, the components illustrated in FIG. 24 are not essential for implementing the present invention according to the present disclosure, and thus the present invention described in this specification may have more or fewer components than the components listed above.
[0978] Meanwhile, the processor (2430) of FIG. 24 may be identical to the processor (50) of FIG. 1 described above, and in this case, all operations and controls of FIGS. 1 to 23 described above may be performed identically by the processor (2440) of FIG. 24.
[0979] The display (2440) displays graphic images according to control commands from the processor (2430).
[0980] Memory (2450) stores at least one process for performing an operation and stores user input and data.
[0981] The communication module (2460) transmits and receives data with an external device.
[0982] Here, the external device includes an external device such as a smartphone, a PC, a laptop, a tablet PC, etc.
[0983] The camera module (2470) captures images of the front.
[0984] The camera module (2470) photographs a subject in front according to a control command from the processor (2430).
[0985] The communication module (2460) may include one or more components that enable communication with an external device, and may include, for example, at least one of a broadcast reception module, a wired communication module, a wireless communication module, a short-range communication module, and a location information module.
[0986] The input module (2410) is for inputting video information (or signals), audio information (or signals), data, or information input from a user, and may include at least one camera, at least one microphone, and at least one user input unit. Voice data or image data collected by the input module (2410) may be analyzed and processed into a user control command.
[0987] The display module (2440) displays (outputs) information processed in the present invention. For example, the present invention can display execution screen information of a running application program (e.g., an application), or UI (User Interface) or GUI (Graphical User Interface) information based on such execution screen information.
[0988] The memory (2450) can store data supporting various functions of the present invention, programs for the operation of the control unit, input / output data (e.g., music files, still images, moving images, etc.), and can store a plurality of application programs (or applications), data for the operation of the device, and commands. At least some of these application programs can be downloaded from an external server via wireless communication.
[0989] The memory (2450) may include at least one type of storage medium among a flash memory type, a hard disk type, an SSD (Solid State Disk type), an SDD (Silicon Disk Drive type), a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. In addition, the memory (2450) is separate from the present invention, but may be a database connected by wire or wirelessly, and may be implemented as a database system.
[0990] The processor (2430) may be implemented as at least one core, a memory storing data for an algorithm for controlling the operation of components within the present invention or a program reproducing the algorithm, and at least one processor (not shown) that performs the aforementioned operations using the data stored in the memory. In this case, the memory and the processor may be implemented as separate chips. Alternatively, the memory and the processor may be implemented as a single chip.
[0991] Additionally, the processor (2430) may control any one or a combination of the components described above to implement various embodiments according to the present disclosure described in FIGS. 24 to 32 below.
[0992] At least one component may be added or deleted to correspond to the performance of the components illustrated in Figure 24. Furthermore, it will be readily apparent to those skilled in the art that the relative positions of the components may be altered to correspond to the performance or structure of the system.
[0993] Meanwhile, each component illustrated in FIG. 24 refers to software and / or hardware components such as a Field Programmable Gate Array (FPGA) and an Application Specific Integrated Circuit (ASIC).
[0994] Figure 25 is a flowchart illustrating a method for automating compliance requirements analysis and inspection according to the present disclosure. The present invention is performed by a processor (2430) of an automated compliance requirements analysis and inspection device (100) or an automated compliance requirements analysis and inspection device (2400).
[0995] The processor (2430) collects regulatory data on personal information by country through the input module (2410) (S2510).
[0996] The processor (2430) classifies and relearns the policy tag based on the collected regulatory data (S2520).
[0997] The processor (2430) analyzes the company's terms and conditions and processing policies included in the regulatory data and classifies the security requirements into personal information life cycle and security control items (S2530).
[0998] The processor (2430) controls the display (2440) to display the personal information life cycle and the security control items (S2540).
[0999] The processor (2430) verifies compliance with security requirements (S2550).
[1000] The processor (2430) manages the risk assessment and risk action status based on the verification results (S2560).
[1001] Figure 26 is a drawing illustrating the core concept of the present invention according to the present disclosure.
[1002] Referring to FIG. 26 (2610), the core concept of the present invention is explained.
[1003] The processor (2430) identifies the regulatory status of companies and public institutions, extracts personal information status from terms and conditions and processing policies, and classifies and stores the information according to the personal information life cycle.
[1004] The types of regulations include e-commerce, the Information and Communications Network Act, and individual laws, and are determined differently for businesses with 100 employees and businesses with 5 employees.
[1005] Additionally, regulations may vary across individual countries, including Korea, the United States, Japan, and China.
[1006] The processor (2430) can also understand and proceed with the security status of companies and public institutions as described above.
[1007] The processor (2430) of the present invention may include four modules (2431, 2432, 2433, 2434).
[1008] That is, the processor (2430) includes a first module (2431) for collecting, analyzing, and refining compliance, a second module (2432) for automating analysis of corporate information processing status and security requirements, a third module (2433) for checking compliance, and a fourth module (2334) for assessing and managing compliance risks.
[1009] The functions of each module are explained.
[1010] First, the first module (2431) collects personal information regulations by country and automatically classifies and relearns policy tags. The detailed operation is as follows.
[1011] 1. Perform at least one of the following: crawling, uploading, linking, and entering data related to national privacy regulations.
[1012] 2. By deriving the main keywords for each provision of the above regulatory data, tags are assigned to each personal information regulation, and the similarity of tag contents between the tags is calculated.
[1013] 3. When an update of the above regulatory data occurs, a tag is assigned to the updated regulatory data, and the similarity between the updated provisions and existing provisions in the updated regulatory data is calculated.
[1014] 4. Research privacy regulations in each country.
[1015] 5. Assign tags to each investigated personal information protection regulation.
[1016] 6. Check the assigned tags one by one and classify the personal information protection regulations investigated above into micro-regulations or common regulations.
[1017] Second, the second module (2432) analyzes the company's terms and conditions and processing policy, classifies the security requirements into personal information life cycle and security control items, and displays them on the screen. The detailed operation is as follows.
[1018] 1. Enter the company's general status and personal information processing status.
[1019] Register the personal information processing policy and terms of use for the subject of the inspection. Specifically, extract personal information status from the policy and terms of use, categorize it according to its lifecycle, and store it.
[1020] 2. Based on the input information, the compliance collection automation module (110) searches for similar tags.
[1021] 3. Classify the results into personal information lifecycle and security control items.
[1022] 4. Display it on the screen and use it for navigation.
[1023] Third, the third module (133) automatically checks compliance, and the detailed operation is as follows.
[1024] 1. Load the security requirements derived from the compliance inspection module (120).
[1025] 2. Retrieve the result values of each module of the compliance and security risk analysis department (300).
[1026] 3. Map the results and requirements.
[1027] 4. Calculate whether the result value reaches the standard value of the requirement.
[1028] 5. If the standard value is not reached, it is classified as non-compliant or requires verification.
[1029] 6. If the standard value is reached, it is classified as either complied with or requires confirmation.
[1030] 7. For items requiring verification, calculate them by mapping the results of other modules or receive input from the user.
[1031] 8. The inspection results are displayed on the screen.
[1032] Fourth, the fourth module (2334) manages the risk assessment and risk response status based on the inspection results, and the detailed operations are as follows.
[1033] 1. Load the security requirements derived from the compliance inspection module (120).
[1034] 2. The result of reaching the standard value for each requirement derived from the company-specific security requirement analysis automation module (130) is retrieved.
[1035] 3. If the standard value is not reached, the requirement is selected as risky.
[1036] 4. Calculate the level of risk selected. This could include factors such as the possibility of fines or the risk of personal information leakage.
[1037] 5. Enter the person in charge, deadline, priority, etc. for risk management.
[1038] 6. Notify the person in charge of the risk action and repeat periodically until the action trigger occurs.
[1039] 7. When a risk action trigger occurs, the status is changed to Action Complete to manage the risk level.
[1040] Figure 27 is a diagram illustrating an example of deriving main keywords for each clause according to the present disclosure.
[1041] Referring to Figure 27 (2710), an example of deriving main keywords for each clause is described.
[1042] The processor (2430) performs at least one of crawling, uploading, link registration, and inputting of the above regulatory data, derives main keywords for each provision of the above regulatory data, assigns tags of personal information regulations, and calculates the similarity of the tag contents.
[1043] Explains how to create tags.
[1044] For example, based on the content contained in the provisions of the Electronic Commerce Act, if the provisions are about ‘personal information’, correspond to a life cycle, and are about ‘collection’, the processor (2430) creates tags called [personal information], [life cycle], and [collection].
[1045] For example, if the regulatory data is the Electronic Commerce Act, the processor (2430) derives key keywords for each provision. Key keywords include "mail order sales," "mail order seller," "mail order brokerage," "personal information," "life cycle," and "collection."
[1046] When an update (addition, modification, deletion of regulation) of the above regulatory data occurs, the processor (2430) assigns a tag to the updated regulatory data and calculates the similarity between the updated provisions and existing provisions.
[1047] FIG. 28 is a diagram illustrating an embodiment of verifying compliance with security requirements according to the present disclosure.
[1048] Referring to FIG. 28 (2810), an embodiment of verifying compliance with security requirements is described.
[1049] The processor (2430) maps the result values for the risk analyzed by the security requirements and compliance and security risk analysis unit (300) (S2810).
[1050] The processor (2430) calculates whether the result value reaches the reference value of the security requirement (S2820).
[1051] The processor (2430) compares the result value with the reference value (S2830).
[1052] If the result value is less than the reference value, the processor (2430) classifies it as not complying with compliance or as requiring verification (S2840).
[1053] If the result value is greater than or equal to the reference value, the processor (2430) classifies it as a matter requiring compliance or verification (S2850).
[1054] If the processor (2430) requires verification, it calculates by mapping the result values of other modules or receives input values from the compliance manager (S2860).
[1055] FIG. 29 is a diagram illustrating an embodiment of calculating risk and executing risk measures according to the present disclosure.
[1056] Referring to FIG. 29 (2910), an embodiment of calculating risk and executing risk measures is described.
[1057] The processor (2430) maps the result values for the risk analyzed by the security requirements and compliance and security risk analysis unit (300) (S2910).
[1058] The processor (2430) calculates the risk level based on the mapping result (S2920).
[1059] The processor (2430) controls the display (2440) to display the calculated risk level (S2930).
[1060] Here, the risk includes at least one of the possibility of fines and the risk of personal information leakage.
[1061] The processor (2430) receives the person in charge, deadline, and priority for risk measures corresponding to the above risk level from the compliance manager (S2940).
[1062] The processor (2430) transmits a message including risk measures to the device of the compliance manager (or the person in charge) (S2950).
[1063] When a risk action trigger occurs, the processor (2430) changes the status to risk action completed to manage the risk level (S2960).
[1064] FIG. 30 is a drawing illustrating an embodiment that explains a problem of the prior art according to the present disclosure.
[1065] Referring to Fig. 30 (3010), the problems of the prior art are explained.
[1066] Users entering the system of this disclosure for the first time may have their own unique processing policy. However, in the case of the prior art, there is a problem in that even if an incorrect processing policy is uploaded, as shown in Figure 30 (3010), there is no response, making it impossible for the user to know whether their processing policy is correct.
[1067] The technical features of the present invention compared to prior art are described.
[1068] In the case of conventional technology, only PDF files are uploaded.
[1069] The technical features of the present invention are described.
[1070] When you upload a previous processing policy, it reads the file of that processing policy, determines whether the file contains text that requires the processing policy, and notifies you step by step.
[1071] First, there are cases where it is a strange file that has nothing to do with the processing policy.
[1072] It will ask you if you want to continue using the file, and if you click No, it will be deleted.
[1073] Second, if it is a processing policy, but an incorrect processing policy, a survey is conducted.
[1074] Third, based on the survey results, the customer's service is identified and the customer is informed of any missing information in the processing policy or any information that is not related to the customer's current service. The customer is also informed of the consent form to be completed and the data to be entered on the processing policy creation page.
[1075] FIG. 31 is a diagram illustrating an embodiment of a simple review function of a processing policy according to the present disclosure.
[1076] Referring to Figure 31 (3110), the simple review function of the processing policy is described.
[1077] Upload the file.
[1078] First, if the uploaded file is a processing policy but is an incorrect file.
[1079] 1. Conduct a survey.
[1080] 2. Based on the survey results, we will provide you with the necessary consent form and processing policy data.
[1081] Second, if the uploaded file is completely incorrect.
[1082] 1. It notifies you of incorrect files or warnings that they should not be used.
[1083] 2. The system of the present invention guides the user to write a consent form and processing method.
[1084] Third, if the uploaded file is a well-written processing policy file.
[1085] 1. By using the system of the present invention, it continuously informs users of advantages such as ease of history management and modification, thereby inducing paid payment.
[1086] Figure 32 is a diagram illustrating a flowchart of a simple review method of a processing policy according to the present disclosure.
[1087] Referring to Figure 32, a flowchart of a simple review method for processing policy is described.
[1088] The present invention includes a Front (terminal, 3220), a Back (server, 3210), and a storage server (3230).
[1089] When a file upload click button is received from the user, the terminal (3220) uploads the file to the server (3210).
[1090] The server (3210) transmits the file to the storage server (3230).
[1091] The storage server (3230) transmits the file to the server (3210).
[1092] The server (3210) analyzes the file and transmits the analysis results to the terminal (3220).
[1093] Terminal (3220) displays the file analysis value on the screen. In this case, the file analysis value can be displayed on the screen in three cases.
[1094] The terminal (3220) transmits the survey results to the server (3210).
[1095] The server (3210) transmits the necessary consent form and processing policy data to the terminal (3220).
[1096] The terminal (3220) moves to the consent form creation page and displays a guide on the screen from consent form creation to processing policy writing.
[1097] The various embodiments of the present disclosure are not intended to list all possible combinations but rather to illustrate representative aspects of the present disclosure, and the matters described in the various embodiments may be applied independently or in combinations of two or more.
[1098] The above-described program may include codes coded in a computer language, such as C, C++, JAVA, or machine language, that can be read by the processor (CPU) of the computer through the device interface of the computer, so that the computer reads the program and executes the methods implemented as a program. Such codes may include functional codes related to functions that define functions necessary for executing the methods, and may include control codes related to execution procedures necessary for the processor of the computer to execute the functions according to a predetermined procedure. In addition, such codes may further include memory reference-related codes regarding which location (address address) of the internal or external memory of the computer should reference additional information or media necessary for the processor of the computer to execute the functions. In addition, if the processor of the computer needs to communicate with any other computer or server located remotely in order to execute the functions, the code may further include communication-related code regarding how to communicate with any other computer or server located remotely using the communication module of the computer, and what information or media to send and receive during communication.
[1099] The above storage medium refers to a medium that stores data semi-permanently and can be read by a device, rather than a medium that stores data for a short period of time, such as a register, cache, or memory. Specifically, examples of the storage medium include, but are not limited to, ROM, RAM, CD-ROM, magnetic tape, floppy disk, and optical data storage device. That is, the program can be stored in various recording media on various servers that the computer can access or in various recording media on the user's computer. In addition, the medium can be distributed across network-connected computer systems, so that computer-readable code can be stored in a distributed manner.
[1100] The steps of a method or algorithm described in connection with the embodiments of the present disclosure may be implemented directly in hardware, implemented as a software module executed by hardware, or implemented by a combination thereof. The software module may reside in a random access memory (RAM), a read only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, a hard disk, a removable disk, a CD-ROM, or any other form of computer-readable recording medium well known in the art to which the present disclosure pertains.
[1101] While the embodiments of the present disclosure have been described above with reference to the attached drawings, those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without altering the technical spirit or essential features thereof. Therefore, the embodiments described above should be understood to be illustrative in all respects and not restrictive.
Claims
1. Input module for collecting regulatory data on personal information by country; An external device including a mobile device and a communication module for transmitting and receiving the regulatory data; A memory storing at least one process for performing an automated operation of analyzing and checking compliance requirements, and storing input and data of a compliance manager; and Including a processor that performs operations according to the above process, The above processor, Based on the regulatory data collected through the above input module, the policy tag is classified and re-learned, Analyze at least one of the company's contracts, terms and conditions, policies, guidelines and privacy policies included in the above regulatory data to classify the company's security requirements into personal information lifecycle and security control items. Verify compliance with the above security requirements, Based on the above confirmed results, manage the risk assessment and risk measures status. A device that automates compliance requirements analysis and inspection.
2. In the first paragraph, the processor, Perform at least one of crawling, uploading, link registration, and inputting of the above regulatory data, By deriving key words for each clause of the above regulatory data, tags for personal information regulations are assigned. Calculating the similarity of the above tag contents, A device that automates compliance requirements analysis and inspection.
3. In the second paragraph, the processor, When an update of the above regulatory data occurs, a tag is assigned to the updated regulatory data, Calculating the similarity between the updated provisions and existing provisions within the above updated regulatory data; A device that automates compliance requirements analysis and inspection.
4. In the first paragraph, the processor, Research privacy regulations by country, A compliance requirements analysis and inspection automation device that classifies the above-mentioned personal information protection regulations into micro-regulations or common regulations.
5. In the first paragraph, the processor, Mapping the above security requirements and the results of the previously analyzed security risks, Compare the above result value with the standard value of the above security requirement, If the above result value is higher than the above standard value, it is classified as compliance or as something requiring verification. If the above result value is below the above standard value, it is classified as non-compliant or requires verification. A device that automates compliance requirements analysis and inspection.
6. In the fifth paragraph, the processor, If the above verification is required, the results of other modules are mapped and calculated or the input values are received from the above compliance manager. A device that automates compliance requirements analysis and inspection.
7. In the first paragraph, the processor, Mapping the above security requirements and the results of the previously analyzed security risks, Calculate the risk based on the above mapped results, The above risk includes at least one of the following: the possibility of fines, the risk of regulatory violations, and the risk of personal information leakage. A device that automates compliance requirements analysis and inspection.
8. In the 7th paragraph, the processor, Receive the person in charge of performing risk measures corresponding to the above risk level, deadline, priority, and risk level; Sending a message containing risk action items to the device of the above compliance manager; A device that automates compliance requirements analysis and inspection.
9. In the 8th paragraph, the processor, When a risk action trigger occurs, the status is changed to risk action completed to manage the risk level. A device that automates compliance requirements analysis and inspection.
10. A method for automating compliance requirement analysis and inspection performed by a processor of a device, Steps to collect regulatory data on personal information by country; A step of classifying and relearning policy tags based on the collected regulatory data; A step of analyzing at least one of the contracts, terms and conditions, policies, guidelines and personal information processing policies of the company included in the above regulatory data and classifying the security requirements of the company into personal information life cycle and security control items; Step for verifying compliance with the above security requirements; and Including the steps of managing risk assessment and risk measures based on the verification results. How to automate compliance requirements analysis and inspection.
Citation Information
Patent Citations
Risk driven compliance management
KR1020080059610A
A used car verification service brokerage platform that allows technicians to accompany.
KR1020230067100A
Intelligent Transportation Systems for Automatic Driving of Drone linkage having the third view
KR1020230122827A
Method and system for providing data compliance
KR102345748B1
Legal compliance, electronic discovery and electronic document handling of online and offline copies of data
US20110093471A1