Personal information management automation device and control method therefor

The personal information management automation device addresses the challenges of excessive data collection and consent issues by classifying personal information, proposing processing purposes, and ensuring secure storage and deletion, thereby reducing the risk of leakage and misuse.

WO2025121888A1PCT designated stage expired Publication Date: 2025-06-12O NE PEOPLE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/019769
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-12-03
Filing Date
2024-12-04
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Current personal information management systems face challenges in ensuring that personal information is collected and used minimally, securely, and with proper consent, leading to increased risks of leakage and misuse.

Method used

A personal information management automation device and method that includes an input module for collecting data, a communication module for transmitting and receiving data, a memory for storing processes, and a processor for controlling operations. The processor classifies personal information, proposes processing purposes, determines access levels, records logs, establishes destruction policies, and ensures secure storage and deletion of personal information.

Benefits of technology

The solution enables users to track the distribution of their personal information, determine when and to whom it is shared, and obtain consent for changes in purpose, thereby reducing unnecessary collection and preventing information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024019769_12062025_PF_FP_ABST
    Figure KR2024019769_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a personal information management automation device and a control method therefor, the device being capable of: searching for an item that may contain personal information in a sentence included in first data collected through an input module, thereby classifying the personal information; suggesting a personal information processing purpose on the basis of a title and content of a form that is input by a personal information handler; determining whether to allow the personal information handler to access a system according to the security level of the personal information handler; controlling access according to the role and authority of the personal information handler according to the determination result; recording a log for processing the personal information; establishing a destruction policy of the personal information; and deleting or separably storing the personal information according to the established destruction policy.
Need to check novelty before this filing date? Find Prior Art

Description

Personal information management automation device and its control method

[0001] The present disclosure relates to a personal information management device, and more specifically, to a device and method for automating personal information management, obtaining consent from a data subject for a change in purpose during the process of transferring personal information to a third party, and creating a personal information flow map for the data subject.

[0002] With the recent advancements in IT technology, personal authentication and the collection of personal information are becoming essential procedures when using many IT devices. Pursuant to Article 16, Paragraph 1 of the Personal Information Protection Act, personal information processors must collect the minimum amount of personal information necessary for the purpose of collecting personal information. In this case, the burden of proof lies with the personal information processor, who has collected the minimum amount of personal information.

[0003] Currently, the purpose of personal information collection is often unclear, or unnecessary information is collected for that purpose. According to the 2015 Personal Information Protection Survey, approximately 64% of data subjects cited unnecessary and excessive collection of personal information as the primary cause of personal information leaks, and 72% of the public responded that personal information processors currently collect excessive amounts of personal information. However, the minimum necessary scope can vary depending on the industry of the personal information processor, the circumstances of collection, and the purpose of the data collection, making it practically difficult for individuals to determine this.

[0004] At this time, the possibility of personal information leaks increased due to excessive collection of personal information, and it was difficult to determine whether the personal information was the minimum necessary, so personal information was indiscriminately leaked to the outside, causing inconvenience to users.

[0005] Additionally, when the purpose of using personal information changed, there was a problem in which personal information was indiscriminately leaked to external parties because there was no process to obtain the consent of the information subject, causing inconvenience to users.

[0006] In addition, when personal information was provided with the consent of the data subject, there was a problem in which the personal information was indiscriminately leaked to the outside because the consent history and usage status of the personal information could not be known, causing inconvenience to the user.

[0007] The purpose of the embodiments disclosed in this disclosure is to provide a device and method that allows a personal information subject to check the route through which his or her personal information is distributed and whether or not it is distributed.

[0008] In addition, the embodiments disclosed in this disclosure aim to provide a device and method that enable a personal information subject to determine when and to whom his or her personal information was entrusted, and to whom and for what purpose it was distributed.

[0009] In addition, the embodiment disclosed in this disclosure aims to provide a device and method that can request the data subject to consent to the change when the purpose of using personal information changes and use personal information according to the agreed content.

[0010] In addition, the embodiment disclosed in this disclosure aims to provide a device and method for checking the consent history and usage status of personal information to determine the usage history of personal information when personal information is provided with the consent of the data subject.

[0011] In addition, the embodiment disclosed in this disclosure aims to provide a device and method that can retrieve inappropriate use of personal information by checking the consent history and usage status of personal information when personal information is provided with the consent of the data subject.

[0012] The problems to be solved by the present disclosure are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.

[0013] An automated personal information management device according to the present disclosure comprises: an input module for collecting first data including a sentence entered by a personal information handler; a communication module for transmitting and receiving the first data with an external device including a mobile device; a memory for storing at least one process for automating personal information management; and a processor for controlling an operation according to the process, wherein the processor finds an item likely to collect personal information in the sentence included in the first data collected through the input module and classifies the personal information, proposes a purpose of personal information processing based on the title and content of a form entered by the user, determines whether to allow the personal information handler to access the system based on the security level of the personal information handler, controls access based on the role and authority of the personal information handler based on the result of the determination, records a log for processing the personal information, establishes a destruction policy for the personal information, and deletes or separately stores the personal information based on the established destruction policy.

[0014] In addition, a method for automating personal information management performed by a processor of a device according to the present disclosure may include the steps of collecting first data including a sentence entered by a personal information handler through an input module; finding items likely to collect personal information in the collected sentences and classifying the personal information; proposing a purpose of personal information processing based on the title and content of a form entered by the personal information handler; determining whether to allow the personal information handler to access the system based on the security level of the personal information handler; controlling access based on the role and authority of the personal information handler based on the result of the determination; recording a log for processing the personal information; establishing a policy for destroying the personal information; and deleting or separately storing the personal information based on the established policy for destroying the personal information.

[0015] In addition, a computer program stored in a computer-readable recording medium may be further provided to execute a method for implementing the present disclosure.

[0016] In addition, a computer-readable recording medium recording a computer program for executing a method for implementing the present disclosure may be further provided.

[0017] According to this disclosure, the subject of personal information can check the distribution route and whether his or her personal information is being distributed, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0018] In addition, according to the present disclosure, the personal information subject can determine when and to whom his or her personal information was entrusted, and to whom and for what purpose it was distributed, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0019] In addition, according to this disclosure, if the purpose of using personal information changes, the data subject can be requested to consent to the change and the personal information can be used in accordance with the agreed upon content, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0020] In addition, according to the present disclosure, if the data subject consents to the provision of personal information, the consent history and usage status of the personal information can be checked to determine the usage history of the personal information, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0021] In addition, according to the present disclosure, if the data subject consents to the provision of personal information, the consent history and usage status of the personal information can be checked to withdraw inappropriate use of the personal information, thereby suppressing unnecessary collection of personal information and preventing personal information leakage.

[0022] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

[0023] Figure 1 is a configuration diagram of the entire system according to the present disclosure.

[0024] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.

[0025] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.

[0026] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.

[0027] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.

[0028] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.

[0029] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.

[0030] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.

[0031] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.

[0032] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.

[0033] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.

[0034] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.

[0035] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.

[0036] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.

[0037] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.

[0038] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.

[0039] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.

[0040] Figure 18 is a drawing showing the status of consignment companies according to the present disclosure.

[0041] Figure 19 is a diagram illustrating the status of personal information processing according to the present disclosure.

[0042] Figure 20 is a drawing showing the status of subcontracting companies according to the present disclosure.

[0043] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.

[0044] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.

[0045] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.

[0046] Figure 24 is a diagram illustrating a configuration of a personal information management automation device according to the present disclosure.

[0047] Figure 25 is a diagram illustrating a flowchart of a personal information management automation method according to the present disclosure.

[0048] Figure 26 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0049] Figure 27 is a diagram illustrating an example of personal information verification according to the present disclosure.

[0050] Figure 28 is a diagram illustrating the setting of destruction information and execution of a scheduler according to the present disclosure.

[0051] Figure 29A is a diagram illustrating a flowchart of a personal information management automation method according to the present disclosure.

[0052] FIG. 29B is a diagram illustrating an example of visualizing the scope of consent according to the present disclosure.

[0053] FIG. 29C is a diagram illustrating an embodiment of PI third-party visualization according to the present disclosure.

[0054] Figure 30 is a diagram illustrating a flowchart of a method of utilizing personal information according to the present disclosure.

[0055] Figure 31 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0056] Figure 32 is a diagram illustrating a flowchart 1 of a method of utilizing personal information according to the present disclosure.

[0057] Figure 33 is a diagram illustrating a flowchart 2 of a method of utilizing personal information according to the present disclosure.

[0058] Figure 34 is a diagram illustrating an example in which the purpose of use of personal information according to the present disclosure has changed.

[0059] FIG. 35 is a diagram illustrating an example of obtaining consent from a data subject when the purpose of use according to the present disclosure is changed.

[0060] FIG. 36 is a diagram illustrating an embodiment of converting a first message according to the present disclosure into clear and concise language.

[0061] Figure 37 is a diagram illustrating a flow chart of a method for creating a personal information flow map according to the present disclosure.

[0062] Figure 38 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[0063] Figure 39 is a diagram illustrating a flowchart 1 of a method for creating a personal information flow map according to the present disclosure.

[0064] Figure 40 is a diagram illustrating a flowchart 2 of a method for creating a personal information flow map according to the present disclosure.

[0065] Figure 41 is a drawing illustrating the basic concept of a keychain according to the present disclosure.

[0066] Figure 42 is an example of creating a visualized report on the personal information consent history and personal information usage status according to the present disclosure.

[0067] Throughout this disclosure, the same reference numerals denote the same components. This disclosure does not describe all elements of the embodiments, and any content that is common in the technical field to which this disclosure pertains or that overlaps between embodiments is omitted. The terms "part, module, element, block" used in the specification may be implemented in software or hardware, and depending on the embodiments, multiple "parts, modules, elements, blocks" may be implemented as a single component, or a single "part, module, element, block" may include multiple components.

[0068] Throughout the specification, when a part is said to be "connected" to another part, this includes not only direct connection but also indirect connection, and indirect connection includes connection via a wireless communication network.

[0069] Additionally, when a part is said to "include" a component, this does not mean that it excludes other components, but rather that it may include other components, unless otherwise specifically stated.

[0070] Throughout the specification, when we say that an element is "on" another element, this includes not only cases where the element is in contact with the other element, but also cases where another element exists between the two elements.

[0071] The terms first, second, etc. are used to distinguish one component from another, and the components are not limited by the aforementioned terms.

[0072] Singular expressions include plural expressions unless the context clearly indicates otherwise.

[0073] The identification codes for each step are used for convenience of explanation and do not describe the order of each step. Each step may be performed in a different order than specified unless the context clearly indicates a specific order.

[0074] The operating principle and embodiments of the present disclosure are described below with reference to the attached drawings.

[0075] The present invention can be implemented not only in a server system but also in various devices capable of performing computational processing and providing results to a user. For example, the present invention can include a computer, a server device, and a mobile terminal, or can be implemented in any one of these forms.

[0076] Here, the computer may include, for example, a notebook, desktop, laptop, tablet PC, slate PC, etc. equipped with a web browser.

[0077] The above server device is a server that processes information by communicating with an external device, and may include an application server, a computing server, a database server, a file server, a game server, a mail server, a proxy server, and a web server.

[0078] The above portable terminal may include, for example, a wireless communication device that ensures portability and mobility, and may include all kinds of handheld-based wireless communication devices such as a PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handyphone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), WiBro (Wireless Broadband Internet) terminal, a smart phone, and a wearable device such as a watch, a ring, a bracelet, an anklet, a necklace, glasses, contact lenses, or a head-mounted device (HMD).

[0079] The artificial intelligence-related functions according to the present disclosure are operated through a processor and memory. The processor may be composed of one or more processors. In this case, one or more processors may be a general-purpose processor such as a CPU, an AP, a DSP (Digital Signal Processor), a graphics-only processor such as a GPU or a VPU (Vision Processing Unit), or an artificial intelligence-only processor such as an NPU. One or more processors control the processing of input data according to predefined operation rules or artificial intelligence models stored in memory. Alternatively, if one or more processors are artificial intelligence-only processors, the artificial intelligence-only processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0080] The predefined operation rules or artificial intelligence models are characterized by being created through learning. Here, being created through learning means that the basic artificial intelligence model is learned by a learning algorithm using a plurality of learning data, thereby creating a predefined operation rules or artificial intelligence model set to perform a desired characteristic (or purpose). This learning may be performed in the device itself on which the artificial intelligence according to the present disclosure is performed, or may be performed through a separate server and / or system. Examples of the learning algorithm include, but are not limited to, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning.

[0081] An artificial intelligence model may be composed of multiple neural network modules. Each of the multiple neural network modules has multiple weight values, and performs neural network operations through operations between the operation results of the previous module and the multiple weights. The multiple weights of the multiple neural network modules may be optimized based on the learning results of the artificial intelligence model. For example, the multiple weights may be updated so that the loss value or cost value obtained from the artificial intelligence model is reduced or minimized during the learning process. The artificial neural network may include a deep neural network (DNN), and examples thereof include, but are not limited to, a convolutional neural network (CNN), a deep neural network (DNN), a recurrent neural network (RNN), a restricted boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), or deep Q-networks.

[0082] The processor can create a neural network, train (or learn) a neural network, perform computations based on received input data, and generate information signals based on the results of the computations, or retrain the neural network.

[0083] Neural networks include CNN (Convolutional Neural Network), RNN (Recurrent Neural Network), perceptron, multilayer perceptron, FF (Feed Forward), RBF (Radial Basis Network), DFF (Deep Feed Forward), LSTM (Long Short Term Memory), GRU (Gated Recurrent Unit), AE (Auto Encoder), VAE (Variational Auto) Encoder), DAE (Denoising Auto Encoder), SAE (Sparse Auto Encoder), MC (Markov Chain), HN (Hopfield Network), BM (Boltzmann Machine), RBM (Restricted Boltzmann Machine), DBN (Depp Belief Network), DCN (Deep Convolutional Network), DN (Deconvolutional Network), DCIGN (Deep Convolutional Inverse Graphics Network), Generative Adversarial Network (GAN), Liquid State Machine (LSM), Extreme Learning Machine (ELM), It will be understood by those skilled in the art that any neural network may be included, including but not limited to ESN (Echo State Network), DRN (Deep Residual Network), DNC (Differentiable Neural Computer), NTM (Neural Turning Machine), CN (Capsule Network), KN (Kohonen Network), and AN (Attention Network).

[0084] According to an exemplary embodiment of the present disclosure, the processor may be configured to perform a process for generating a CNN (Convolution Neural Network) such as GoogleNet, AlexNet, VGG Network, Region with Convolution Neural Network (R-CNN), Region Proposal Network (RPN), Recurrent Neural Network (RNN), Stacking-based deep Neural Network (S-DNN), State-Space Dynamic Neural Network (S-SDNN), Deconvolution Network, Deep Belief Network (DBN), Restrcted Boltzman Machine (RBM), Fully Convolutional Network, Long Short-Term Memory (LSTM) Network, Classification Network, Generative Modeling, eXplainable AI, Continual AI, Representation Learning, AI for Material Design, BERT, SP-BERT, MRC / QA for natural language processing, Text Analysis, Dialog System, GPT-3, GPT-4, Visual Analytics for vision processing, Visual Understanding, Video Synthesis, ResNet for data intelligence, Anomaly Detection, Prediction, Time-Series Forecasting, Various artificial intelligence structures and algorithms, including optimization, recommendation, and data creation, can be utilized, but are not limited thereto. Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.

[0085] Figure 1 is a configuration diagram of the entire system according to the present disclosure.

[0086] Referring to Fig. 1(10), the configuration of the entire system is described.

[0087] The system (10) is briefly composed of part A (100), part B (200), part C (300), part D (400), part E (500), part F (600), and a processor (50).

[0088] Part A (100) may be referred to as the Compliance Collection and Registration Department.

[0089] Part B (200) may be named the Personal Information Collection and Use and Analysis Department.

[0090] Part C (300) may be named the Compliance and Security Risk Analysis Department.

[0091] Department D (400) may be called a service-specific personal information analysis department.

[0092] Part E (500) may be called a personal information destruction part.

[0093] Part F (600) may be called the authentication management department.

[0094] The processor (50) controls section A (100), section B (200), section C (300), section D (400), section E (500), and section F (600).

[0095] At least one detailed function among Part A (100), Part B (200), Part C (300), Part D (400), Part E (500), and Part F (600) can be stored in memory as software, and the processor (50) can execute the detailed function of each part by referring to the memory.

[0096] Define key terms of the present invention.

[0097] Compliance typically encompasses legal compliance, compliance monitoring, and internal control. A compliance program is a set of systems designed to ensure companies voluntarily comply with relevant laws and regulations during their business operations. Compliance also includes security regulations.

[0098] Regulations include laws, enforcement decrees, notices, guides, etc.

[0099] Inspection means construction, and investigation means the act of creating and configuring control items for investigation, that is, the act of establishing standards.

[0100] Control items refer to items that an organization must comply with to protect personal information.

[0101] A trigger is a condition for an occurrence.

[0102] Tags represent main keywords.

[0103] Internal compliance refers to internal rules.

[0104] Security requirements refer to the security standards and security rules requested by each organization (company) or service situation to protect information assets.

[0105] Common regulations are commonalities among national regulations, including national common regulations and industry-specific common regulations.

[0106] Common regulations by country refer to regulations that exist in common among the regulations that exist in each country selected by the institution or company.

[0107] Common regulations by industry refer to regulations that exist in common among the regulations required for the industry, industry, and scale selected by the organization or company.

[0108] Microregulations are regulations that differ among multiple regulations.

[0109] For example, micro-regulations may be regulations that institutions or companies choose to comply with individually, or may be regulations that are not specifically stipulated in the law or have no specific timing or method.

[0110] FIG. 2 is a diagram illustrating a compliance collection and registration unit according to the present disclosure.

[0111] Referring to FIG. 2 (210), the compliance collection and registration unit (100) is described.

[0112] The Compliance Collection and Registration Department (100) is abbreviated as Department A (100).

[0113] The A1 module (110) may be named a compliance collection automation module, the A2 module (120) may be named a compliance inspection automation module, and the A3 module may be named a company-specific security requirements analysis automation module.

[0114] FIG. 3 is a diagram illustrating a compliance collection automation module according to the present disclosure.

[0115] Referring to FIG. 3 (310), the compliance collection automation module (110) is described.

[0116] The compliance collection automation module (110) finds regulations related to personal information by country, classifies the regulatory provisions, and analyzes the ‘subject’, ‘object’, and ‘predicate’ appearing in the provisions by dividing them into main text and clauses.

[0117] The compliance collection automation module (110) sets keywords based on the analysis and creates tags using these.

[0118] The compliance collection automation module (110) includes a compliance collection module (111) and a compliance analysis-refinement ML module (112).

[0119] The compliance collection module (111) includes a Crawler, Scraper, and API.

[0120] The Compliance Analysis-Refinement ML module (112) sets keywords based on the analysis and converts them into tags. It includes Vision AI, NLP AI, and ETC.

[0121] The Compliance Analysis-Refinement ML module (112) performs the following:

[0122] First, determine your priorities.

[0123] 1) Determine whether it is the main text or a proviso, 2) the priority of regulations based on whether it is a general law or a special law, and 3) the priority of application of regulations based on the legal system.

[0124] Second, it performs subject, object, and verb judgment and tagging.

[0125] 1) Defining the ‘subject of law’ for each clause means judging what corresponds to the subject of a legal provision based on the citation relationship of the legal provision.

[0126] 2) Defining the ‘object of law’ for each provision means judging what corresponds to the object of a legal provision based on the citation relationship of the legal provision.

[0127] 3) Define ‘verb’.

[0128] Third, legal differences are judged and tagging is performed.

[0129] 1) Determine differences between countries regarding specific regulations (laws, enforcement decrees, enforcement rules, notices, instructions, rules, etc.).

[0130] Here, the regulations include:

[0131] An Act (or Law, or Statute) is a law enacted through the legislative process of the National Assembly. It is translated into English as "Act," "Law," or "Statute." For example, "Civil Act" can be translated as "Civil Law."

[0132] An Enforcement Decree is a presidential decree to specifically enforce a law, and is translated into English as "Enforcement Decree."

[0133] Enforcement Rule refers to a regulation of a ministry that provides more detailed regulations for enforcement ordinances, and is translated into English as "Enforcement Rule."

[0134] A public notice (notification) is issued to inform of specific matters and is translated as "Public Notice" or "Notification".

[0135] A directive (or instruction) is an administrative order that gives instructions from a higher authority to a lower authority, and is translated as "directive" or "instruction."

[0136] Regulations (Official Instructions) contain rules regarding procedures or work within an administrative agency and can be translated as "Regulation" or "Official Instruction."

[0137] The country-specific personal information laws (laws, enforcement decrees, rules, notices, instructions, and regulations) management module (not shown) processes personal information-related regulations by country to enable quick assessment.

[0138] FIG. 4 is a diagram illustrating a compliance inspection module according to the present disclosure.

[0139] Referring to FIG. 4 (410), the compliance inspection module (120) is described.

[0140] The compliance inspection module (120) builds and creates customized control items related to personal information protection that the organization must comply with.

[0141] The compliance inspection module (120) creates control items by considering 1) the ‘country compliance’ collected and refined in the A1 module (110) and 2) the security requirements.

[0142] The compliance inspection module (120) includes a country-specific compliance inspection trigger automation module (121) and an internal regulation generation module (122).

[0143] The country-specific compliance inspection trigger automation module (121) investigates personal information protection regulations (compliance) by country (the method is to attach an appropriate tag to each provision) and classifies the investigated regulatory tags as micro-regulations or common regulations.

[0144] The internal regulation generation module (122) selects micro-regulations in accordance with internal compliance and generates internal regulations based on the selected micro-regulations.

[0145] The internal regulation creation module (122) allows the internal security officer to review the values ​​from the primary module, select micro-regulations that fit the internal regulations, and create internal regulations using the selected regulations.

[0146] FIG. 5 is a diagram illustrating an in-house compliance inspection automation module according to the present disclosure.

[0147] Referring to FIG. 5 (510), the in-house compliance inspection automation module (123) is described.

[0148] The in-house compliance inspection automation module (123) creates internal regulations as inspection automation modules (as inspection items) so that inspection can be turned on or off.

[0149] The in-house compliance inspection automation module (123) can be connected to the B2 module (220).

[0150] Figure 6 is a diagram illustrating an automated security requirements analysis module for each company according to the present disclosure.

[0151] Referring to Figure 6 (610), the company-specific security requirements analysis automation module (130) is described.

[0152] The company-specific security requirements analysis automation module (130) includes a business security requirements analysis module (131). Here, the company also includes an institution.

[0153] The company-specific security requirements analysis automation module (130) obtains agency information and service information.

[0154] Obtain country information from the location, company name, size, company identification number, and service information.

[0155] The business security requirements analysis module (131) determines which regulation applies based on the acquired information.

[0156] Specifically, the business security requirements analysis module (131) determines which regulations will be applied based on the (obtained) organization / service information.

[0157] Figure 7 is a diagram illustrating a personal information collection and use and analysis unit according to the present disclosure.

[0158] Referring to Figure 7 (710), the personal information collection and use and analysis unit (200) will be described.

[0159] The personal information collection and use and analysis department (200) corresponds to Department B (200).

[0160] Part B (200) includes a B1 module (210), a B2 module (220), a B3 module (230), a B4 module (240), and a B5 module (250).

[0161] The B1 module (210) may be named a collection form creation and response automation module, the B2 module (220) may be named a personal information collection detection automation module, the B3 module (230) may be named a collection and use consent form automatic creation module, the B4 module (240) may be named a personal information processing policy automatic creation module, and the B5 module (250) may be named a personal information subject token and consent history hash creation module.

[0162] FIG. 8 is a diagram illustrating a collection form creation and response automation module according to the present disclosure.

[0163] Referring to FIG. 8 (810), the collection form creation and response automation module (210) is described.

[0164] The collection form creation and response automation module (210) allows the administrator to create an input form and collect personal information from the information subject.

[0165] The collection form creation and response automation module (210) includes a personal information collection form creation module (211), a personal information collection detection module (212), an in-house compliance establishment module (213), a processing basis creation module (214), and a personal information processing policy creation module (215).

[0166] The personal information collection form creation module (211) collects content (text, image, video), determines the response method (electronic signature, identity verification), and creates a list and type of information to be collected.

[0167] The personal information collection detection module (212) determines whether the personal information collected in the form for collecting personal information is actual personal information, and if the collected information corresponds to personal information, it transmits the information to the ‘Collection Behavior Management Department’ in charge of personal information collection detection.

[0168] The in-house compliance building module (213) investigates in-house compliance.

[0169] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts an investigation, it can be considered an inspection.

[0170] The processing basis generation module (214) automatically generates a personal information collection and use consent form.

[0171] The processing basis generation module (214) automatically generates personal information collection / provision and use consent forms, as well as processing basis forms. Because the consent forms are generated based on institutional and service information, they can be customized. The consent forms can be modified, such as by tailoring them based on the information of the data subject providing the personal information.

[0172] The grounds for processing are as follows:

[0173] 1. In case the consent of the information subject has been obtained.

[0174] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.

[0175] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.

[0176] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.

[0177] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.

[0178] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the rights are significantly related to the legitimate interests of the personal information processor and do not exceed a reasonable scope.

[0179] 7. In cases where it is for public safety and well-being, such as public health.

[0180] The personal information processing policy creation module (215) automatically creates a personal information processing policy.

[0181] The personal information processing policy creation module (215) automatically generates a personal information processing policy based on institutional and service information. It can also create a customized personal information processing policy based on the information of the data subject providing the personal information. The generated personal information processing policy is then transferred to the "Processing Policy Management Department" for management.

[0182] Figure 9 is a diagram illustrating a personal information collection form creation module according to the present disclosure.

[0183] Figure 9 includes Figures 9(a), 9(b) and 9(c).

[0184] Figure 9(a)(910) is a drawing illustrating a personal information collection form creation module (211).

[0185] Figure 9(b)(920) is a diagram illustrating a personal information collection detection module (212), an in-house compliance establishment module (213), and a processing basis generation module (214).

[0186] Figure 9(c)(930) is a diagram illustrating a personal information processing policy creation module (215).

[0187] As shown in Fig. 9(a)(910), the personal information collection form generation module (211) generates a form for importing personal information, which can be selected by the in-house service manager based on organization information and service information, and automatically generates a personal information collection form (S1).

[0188] As shown in Fig. 9(b)(920), the personal information collection detection module (212) determines whether the information collected in the form for collecting personal information is personal information or not, and if the collected information corresponds to personal information, it transmits the information to the ‘collection behavior management department’ in charge of personal information collection detection (S2).

[0189] The internal compliance building module (213) determines whether corporate and service information violates the organization's internal regulations. Because it conducts investigations, it conducts inspections (S3).

[0190] The processing basis generation module (214) automatically generates a consent form for the collection / provision of personal information or a basis for processing (S4). Because it generates a consent form based on institutional and service information, it can be customized. The consent form can be modified, such as by tailoring it based on the information of the data subject providing the personal information.

[0191] The grounds for processing are as follows:

[0192] 1. In case the consent of the information subject has been obtained.

[0193] 2. In cases where there are special provisions in the law or it is unavoidable to comply with statutory obligations.

[0194] 3. In cases where it is unavoidable for a public institution to perform its duties as prescribed by laws and regulations.

[0195] 4. When necessary to perform a contract concluded with the data subject or to take action at the request of the data subject during the process of concluding a contract.

[0196] 5. In cases where it is clearly deemed necessary to protect the life, body, or property of the information subject or a third party.

[0197] 6. When necessary to achieve the legitimate interests of the personal information processor and clearly overrides the rights of the data subject. This applies only when the rights are significantly related to the legitimate interests of the personal information processor and do not exceed a reasonable scope.

[0198] 7. For public safety and well-being, including public health.

[0199] As illustrated in Fig. 9(c)(930), the personal information processing policy creation module (215) automatically creates a personal information processing policy based on institutional information and service information, and manages it by transferring it to the ‘processing policy management department’ (S5).

[0200] FIG. 10 is a diagram illustrating an automated personal information collection detection module according to the present disclosure.

[0201] Referring to FIG. 10 (1010), the personal information collection detection automation module (220) includes an AI inspection module (221) for detecting whether personal information collection is requested and an AI inspection module (222) for detecting whether personal information is submitted.

[0202] The personal information collection detection automation module (220) is linked with the personal information collection detection module (212) of the B1 module (210).

[0203] The personal information collection detection automation module (220) is linked with the in-house compliance inspection automation module (123).

[0204] The personal information collection detection automation module (220) detects whether a personal information collection request has occurred and manages the collected information by determining whether it corresponds to actual personal information. Personal information includes sensitive information, unique identification numbers, and resident registration numbers.

[0205] The AI ​​Inspect module (221) detects whether a request for personal information collection has been made and automatically classifies the type of information being collected (e.g., personal information, sensitive information, unique identification number, etc.) according to the type of personal information, and automatically applies the appropriate processing procedure for each type.

[0206] The AI ​​Inspect module (222) detects whether personal information has been submitted, and determines whether the information provided by the user is personal information through AI-based analysis (e.g. Vision AI, NLP AI, etc.) to prevent unwanted, unnecessary, and unintended collection of personal information, and detects whether it has been collected.

[0207] The AI ​​Inspect module (222) that detects whether personal information has been submitted analyzes the user's input data using various artificial intelligence technologies such as Vision AI and NLP AI, and determines in real time whether the input information corresponds to personal information.

[0208] FIG. 11 is a diagram illustrating an automatic collection and use consent form generation module according to the present disclosure.

[0209] Referring to FIG. 11 (1110), the automatic collection and use consent form generation module (230) is described.

[0210] The automatic collection and use consent form generation module (230) corresponds to the B3 module (230).

[0211] The automatic collection and use consent form automatic generation module (230) includes a processing guide, an automatic collection and use consent form generation module (231), an automatic consent form type template reflection module (232), and a personal information collection purpose analysis module (233).

[0212] The automatic collection and use consent form generation module (230) is a system that automatically generates and manages consent forms required during the collection and processing of personal information. It analyzes the type and purpose of personal information collection to automatically apply an appropriate consent form template. It also generates customized consent forms that reflect legal requirements, automating the process of obtaining consent from data subjects, thereby complying with personal information protection regulations.

[0213] The operational flow of the present invention is described.

[0214] First, the type of personal information consent form is selected according to the type of personal information classified by the B2 module (220).

[0215] Second, the information that should be included in the consent form is directly entered by the personal information processor.

[0216] 1. If the purpose of processing personal information falls under the conditions that do not require the creation of a consent form, a basis for consent is created.

[0217] 2. In the case of creating a consent form, the purpose of processing personal information in the consent form is proposed in the personal information collection purpose analysis module by referring to the value of the personal information collection form creation module.

[0218] 3. Create a consent form using the above information and the template selected by the personal information processor.

[0219] The automated processing guide, collection and use consent form generation module (231) automatically generates consent forms and processing guides related to personal information, sensitive information, and unique identification information. Consent forms and guides are categorized into the following formats.

[0220] 1) In the case of a consent form for collection and use of personal information, it is created when collecting general personal information (name, phone number, email, etc.) and includes the items collected, purpose, retention period, right to refuse consent, and disadvantages thereof.

[0221] 2) In the case of consent to collection and use of sensitive information, it is used when collecting sensitive personal information such as health information and financial information, and includes notifications and requests for additional consent in accordance with relevant laws.

[0222] 3) In the case of a consent form for the collection and use of unique identification information, it is created when collecting unique identification numbers such as alien registration number, passport number, and driver's license number, and includes a request for notification and additional consent items in accordance with relevant laws.

[0223] 4) In the case of the Resident Registration Number Processing Guide, it is a guide provided when processing a unique identification number such as the Resident Registration Number, and the purpose of processing and legal basis are clearly stated.

[0224] 5) In the case of an optional consent form, it is created when personal information is collected selectively rather than for essential purposes such as advertising, and includes the collected items, purpose, retention period, right to refuse consent, and disadvantages thereof.

[0225] The automated module for creating a processing guide, collection and use consent form (231) provides an intuitive interface so that the data subject can understand the consent form and easily choose whether to consent, and each item of the consent form is updated in accordance with relevant laws and regulations.

[0226] The automated consent form template reflection module (232) predefines various types of consent forms and processing guide templates and automatically reflects the appropriate template based on the user's selected personal information collection purpose and legal requirements. The main functions of this module are as follows:

[0227] First, consent form template management.

[0228] Different templates are provided depending on the type of personal information collected, and customized consent forms are created based on the service purpose. For example, different templates can be applied depending on the personal information required for online service registration and offline transactions.

[0229] Second, there are template reflection rules.

[0230] It operates based on rules that automatically select the appropriate template when a specific type of information is entered, as well as the preferences of the personal information handler. For example, when collecting health information, a sensitive information template is applied, while when collecting simple contact information, a personal information template is applied.

[0231] Third, it is an automatic reflection of legal regulations.

[0232] Consent form templates reflect country-specific and industry-specific legal regulations according to predefined rules. For example, consent forms are tailored to the application of the GDPR (European General Data Protection Regulation) and the CCPA (California Consumer Privacy Act).

[0233] The consent form type template reflection automation module (232) is continuously updated, and when new laws or regulations are announced, the corresponding contents can be immediately reflected in the template.

[0234] The personal information collection purpose analysis module (233) utilizes Vision AI, NLP AI, and other artificial intelligence technologies to analyze user-entered information and automatically classify and process the personal information collection purpose accordingly. Its main functions are as follows:

[0235] First, it is Vision AI-based image analysis.

[0236] If the personal information collection form includes an image, the subject matter within the text or image is extracted and analyzed to suggest an appropriate purpose. For example, if the subject matter of an event is extracted from an event poster image, a corresponding purpose is recommended.

[0237] Second, it is NLP AI-based text analysis.

[0238] We analyze text data entered by users to determine the purpose of collection. For example, we analyze information entered by users to create an online registration page and suggest that the purpose is to sign up for a service.

[0239] Third, it is recommended to provide consent forms for each purpose.

[0240] Based on the collected information, we analyze which legal requirements the information must meet and recommend a suitable purpose. For example, if a resident registration number is collected on a prize winner's personal information collection form, we recommend tax reporting purposes.

[0241] The personal information collection purpose analysis module (233) accurately analyzes the purpose of processing collected personal information and helps to notify and obtain consent from the data subject by applying an appropriate processing method in accordance with the Personal Information Protection Act.

[0242] Figure 12 is a diagram illustrating a module for automatically generating a personal information processing policy according to the present disclosure.

[0243] Referring to Figure 12 (1210), the personal information processing policy automatic generation module (240) is described.

[0244] The personal information processing policy automatic generation module (240) corresponds to the B4 module (240).

[0245] The personal information processing policy automatic generation module (240) includes a service analysis module (241), a processing policy component generation module (242), and a processing policy template reflection automation module (243).

[0246] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It automates all processes, from service analysis to policy template implementation. This module meets legal requirements related to personal information processing and automatically generates policies tailored to the company's service characteristics and security requirements.

[0247] The automatic personal information processing policy generation module (240) automatically generates and manages personal information processing policies. It uses the service analysis module to identify service characteristics, automatically generates processing policy components, and incorporates these into a template to finalize the final processing policy. This system satisfies legal requirements arising during personal information processing and provides customized processing policies tailored to the characteristics of each service provider, effectively ensuring compliance with legal regulations related to personal information protection.

[0248] The personal information processing policy automatic generation module (240) consists of three modules, and each module efficiently performs the composition of the processing policy and automated management procedures.

[0249] Describes the flow of operations linked with other modules.

[0250] First, the status of the service is provided to the user and the requirements for processing policies related to the status, such as the relevant industry, are analyzed.

[0251] Second, the user is provided with the status of personal information processing and the requirements for processing policies related to that status are analyzed.

[0252] Third, a personal information processing policy is established based on the information provided.

[0253] Fourth, the personal information processing policy is printed by applying the template selected by the user.

[0254] The service analysis module (241) analyzes the service's size, industry, and security requirements to develop a personal information processing policy tailored to the characteristics of the company or service provider. Its main functions are as follows:

[0255] First, industry analysis.

[0256] By analyzing the industry to which the service belongs, the system automatically reflects the industry's regulatory and legal requirements. For example, financial services and healthcare services have different legal requirements, so processing policies tailored to each industry are automatically identified and generated.

[0257] Second, analysis of service scale.

[0258] The complexity and requirements of a privacy policy vary depending on the size of the business. This module analyzes the size of the service provider—large corporations, small and medium-sized enterprises, and startups—and selects an appropriate privacy policy. Large-scale services can apply complex data processing policies, while smaller services can adopt simplified policies.

[0259] Third, there is the analysis of other variables (ETC).

[0260] We analyze various factors, including the service provider's business model, customer base, and whether international data transfers are involved. For example, if you provide a global service, legal requirements for cross-border data transfers are reflected in your processing policy.

[0261] The processing policy component generation module (242) automatically generates key components of the processing policy based on data provided by the service analysis module. This module designs each item of the processing policy in detail and can be tailored to the company's operational policies. Its main functions are as follows:

[0262] First, it is the collection, use, and provision of personal information.

[0263] It defines the purpose of collecting personal information, the types of information collected, and whether or not consent is required from the data subject. This includes the scope of use of the personal information collected by the company and how it is provided to third parties, and is designed to ensure clear disclosure to the data subject.

[0264] Second, whether or not pseudonymized information is processed.

[0265] For companies using pseudonymized information, the scope of use and processing methods for pseudonymized personal information are automatically defined. This provision is tailored to the type of data requiring pseudonymization and its intended use, and legal justification is provided where necessary.

[0266] Third, there is the information retention and destruction policy.

[0267] Define how long collected personal information will be retained and how it will be destroyed when no longer needed. This section automatically generates information retention periods and destruction procedures, and includes data retention and destruction policies tailored to specific legal regulations (e.g., GDPR or CCPA).

[0268] Fourth, entrustment of personal information and provision to third parties.

[0269] When personal information is outsourced or provided to a third party, all necessary legal procedures and consent forms are managed. Clearly define the legal requirements for entrusting personal information, the method of data sharing with third parties, and notify the data subject and obtain their consent.

[0270] Fifth, overseas relocation and security personnel.

[0271] When personal information is transferred internationally, it reflects the security and legal requirements that arise during the process. Furthermore, it is designed to strengthen data protection by specifying the deployment of security personnel within the company and their roles.

[0272] The Processing Policy Template Reflection Automation Module (243) reflects the generated personal information processing policy components into templates and automates their implementation. This module automatically maps each component to a predefined template to complete the processing policy. Its main functions are as follows:

[0273] First, there is the management of processing policy templates.

[0274] We provide predefined templates for each item in our privacy policy, and we customize and optimize these templates to meet the needs of each service provider. For example, financial institutions may provide templates that incorporate more stringent security requirements, while smaller services may offer simpler policies.

[0275] Second, there is automatic template mapping.

[0276] Data generated by the service analysis module and processing policy component generation module is automatically mapped to templates. This process is performed without manual intervention, and processing policies tailored to the characteristics of each service are automatically generated.

[0277] Third, it reflects legal requirements.

[0278] Automated rules are set up within templates to ensure legal requirements are reflected. For example, if regulations such as GDPR or CCPA are included, applicable items are automatically added and information specifying the rights and responsibilities of data subjects is included.

[0279] FIG. 13 is a diagram illustrating a personal information subject token and consent history hash generation module according to the present disclosure.

[0280] Referring to FIG. 13 (1310), the personal information subject token and consent history hash generation module (250) is described.

[0281] The personal information subject token and consent history hash generation module (250) corresponds to the B5 module (250).

[0282] The personal information subject token and consent history hash generation module (250) includes a third-party DID module (251), a personal information subject token generation module (252), and a consent history hash generation module (253).

[0283] The Personal Information Subject Token and Consent History Hash Generation Module (250) is responsible for generating and managing the data subject's token and the consent history hash value in the personal information protection system. This module handles data subject authentication in various ways, securely stores data generated during the consent process, and maintains record integrity through hash values. Furthermore, it collaborates with third parties (DIDs) to provide various authentication methods and ensure information reliability.

[0284] The Personal Information Subject Token and Consent History Hash Generation Module (250) automates all procedures required for data subject token generation and consent history management. This module securely authenticates the data subject's identity, converts consent history into a hash value to ensure integrity, and thoroughly manages submitted personal information. This module effectively meets legal requirements related to personal information protection.

[0285] FIG. 14 is a diagram illustrating a compliance and security risk analysis unit according to the present disclosure.

[0286] Referring to FIG. 14 (1410), the compliance and security risk analysis unit (300) is described.

[0287] The compliance and security risk analysis unit (300) includes a personal information risk scoring module (310).

[0288] The personal information risk scoring module (310) includes a personal information flow risk identification scoring module (311), a third-party (trustee) cooperation scoring module (312), a personal information destruction scoring module (313), a personal information consistency scoring module (314), a consent history management scoring module (315), a registration and processing policy maintenance scoring module (316), and an overall integrated scoring module (317).

[0289] The Compliance and Security Risk Analysis Department (300) automatically evaluates the risk of personal information within the system to meet personal information protection and compliance requirements, and performs a comprehensive risk assessment through various scoring methods.

[0290] The Compliance and Security Risk Analysis Department (300) evaluates security risks that may arise at all stages of personal information collection, processing, storage, and destruction, and supports the implementation of appropriate protective measures.

[0291] The Compliance and Security Risk Analysis Department (300) analyzes the risk of personal information through various scoring methods, and each scoring is performed based on the following criteria.

[0292] Describes the flow of operations linked with other modules.

[0293] First, each scoring function operates independently.

[0294] Second, the risk is analyzed based on the scoring results.

[0295] The Personal Information Flow Risk Identification Scoring Module (311) assesses potential risks that may arise during the process of personal information being collected and then transferred within the system. Its main functions include:

[0296] First, data movement path analysis.

[0297] Track and analyze where personal information moves within the system and how it is processed. Identify potential data leaks and unauthorized access that may occur during the information transfer process, and assess the risk.

[0298] Second, access rights analysis.

[0299] Analyze the level of user access to personal information to assess whether appropriate permissions have been granted. If permissions are unnecessarily broad or illegal access attempts are detected, the risk is assessed as high.

[0300] Third, data encryption status analysis.

[0301] Ensure that appropriate encryption is applied during data transfer. If encryption is not applied or the encryption level is low, the risk score increases.

[0302] The Third-Party (Trustee) Collaboration Scoring Module (312) assesses the risks associated with sharing personal information with external trustees or third parties. It analyzes potential security risks when personal information is processed by trustees. Its main functions include:

[0303] First, it is an evaluation of the trustee's security level.

[0304] Assess the security policies and management status of the trustee handling personal information. If the trustee is not implementing appropriate security measures or has not obtained security certification, the risk is assessed as high.

[0305] Second, data transmission security evaluation.

[0306] Analyze the security protocols used when personal information is transmitted to third parties. For example, assess whether data is transmitted encrypted and whether security certificates are valid to determine the level of risk.

[0307] Third, third-party access control analysis.

[0308] Analyze the permissions and access control methods of third parties who have access to personal information. Risk increases if unnecessary access is granted or management is poor.

[0309] The Personal Information Destruction Scoring Module (313) evaluates the process of appropriately destroying collected personal information when it is no longer needed or the legal retention period has expired. Its main functions include:

[0310] First, it is an evaluation of compliance with the destruction policy.

[0311] Assess whether your personal information destruction policy complies with relevant laws and regulations. For example, ensure that personal information is destroyed promptly according to legal requirements such as the GDPR and CCPA.

[0312] Second, the destruction method is evaluated.

[0313] Assess whether personal information has been completely deleted or recovered appropriately. If secure data deletion methods (e.g., digital shredding, overwriting, etc.) were not applied, the risk is assessed as high.

[0314] Third, the transparency of the destruction procedure is assessed.

[0315] Assess whether the destruction process is transparently managed and recorded. If the destruction process is unclear or records are incomplete, the risk increases.

[0316] The Personal Information Integrity Scoring Module (314) evaluates whether collected personal information is used for its intended purpose and whether the collected information is accurate. Its main functions are as follows:

[0317] First, it is an evaluation of whether it matches the purpose of collection.

[0318] We analyze whether personal information is being used for the originally agreed-upon purposes. If personal information is used for purposes other than those agreed upon, the risk is assessed as high.

[0319] Second, it is an assessment of the accuracy of personal information.

[0320] Assess the accuracy of collected personal information and whether any inaccurate information has been entered. Risks increase when inaccurate information is processed or errors occur.

[0321] Third, it is an evaluation of the protection of the rights of the information subject.

[0322] Assess whether the data subject can appropriately exercise their right to correct, delete, or suspend the use of their personal information. If the data subject's request is ignored or not processed, the risk is assessed as high.

[0323] The Consent History Management Scoring Module (315) evaluates whether appropriate consent was obtained from the data subject when personal information was collected and whether that consent was properly managed. Its main functions are as follows:

[0324] First, it is an evaluation of compliance with the consent procedure.

[0325] Assess whether clear consent has been obtained from the data subject for the collection and use of personal information. If personal information is collected or used without proper consent, the risk is assessed as high.

[0326] Second, it is an evaluation of the management status of consent records.

[0327] Assess whether consent records are securely stored and whether withdrawals are promptly reflected upon the data subject's request. Risks increase if consent records are damaged or withdrawal requests are not reflected.

[0328] The Registration and Processing Policy Maintenance Scoring Module (316) evaluates whether personal information processing policies are properly registered and maintained. Its main functions are as follows:

[0329] First, it is an evaluation of the latest processing policy.

[0330] Evaluate whether your privacy policy is continuously updated to reflect the latest legal requirements. If your privacy policy is not updated despite legal changes, the risk is assessed as high.

[0331] Second, it is an evaluation of the transparency of the processing policy.

[0332] Evaluate whether the processing policy is easily accessible to the data subject and whether it is clear and understandable. If the processing policy is unclear or difficult for the data subject to access, the risk increases.

[0333] The overall integrated scoring module (317) synthesizes the risks generated from each individual scoring module to calculate the overall integrated risk of the personal information processing process. The overall integrated scoring includes the following elements:

[0334] First, weighting is applied.

[0335] The overall risk is calculated by applying weights based on the importance of each scoring module. For example, if the personal information destruction scoring is weighted heavily, a flaw in the destruction process will significantly impact the overall risk.

[0336] Second, it is the calculation of comprehensive risk.

[0337] Based on the individual scoring results, a final overall risk assessment is calculated. The overall risk assessment indicates the overall security level of personal information processing and can be used to suggest additional security measures or management strategies.

[0338] Figure 15 is a diagram illustrating a personal information analysis unit for each service according to the present disclosure.

[0339] Referring to Figure 15 (1510), the service-specific personal information analysis unit (400) is described.

[0340] The service-specific personal information analysis unit (400) includes a service-specific personal information analysis module (410).

[0341] The service-specific personal information analysis unit (400) is a system that analyzes personal information collected during service provision by pseudonymizing and anonymizing it, and based on this, classifies the answers provided by users into keywords and determines the meaning of positive or negative.

[0342] The service-specific personal information analysis unit (400) performs pseudonymization and anonymization processing for personal information protection, and analyzes personal information in various stages to support functions necessary for service provision. The service-specific personal information analysis unit (400) of the present invention primarily consists of the following processing steps.

[0343] Step 1 is the pseudonymization step.

[0344] Pseudonymization is the process of protecting personally identifiable information by pseudonymizing it. Pseudonymization is a key method for strengthening privacy protection while using personal information for data analysis and service optimization. Its key functions include:

[0345] First, the personal information identification elements are separated.

[0346] Personal information provided by users, such as name, resident registration number, and email address, is replaced with the minimum information necessary for data analysis. This ensures that data is processed in a way that does not identify specific individuals.

[0347] Second, the application of a pseudonymization algorithm.

[0348] Pseudonymization involves replacing personal information with algorithms such as randomization or hash functions. For example, a user's name is pseudonymized by replacing it with a randomly generated ID. This ID can identify the same individual, but cannot be directly traced back to the original data.

[0349] Third, pseudonymized data management for data analysis.

[0350] Pseudonymized personal information is managed for analysis purposes and stored separately from the original data. After analysis, the original data can be set to not be restored.

[0351] The second step is the anonymization step.

[0352] Anonymization is the process of removing all personally identifiable information from personal data, rendering it completely anonymous. Anonymization completely obscures an individual's identity and is primarily used in statistical analysis and large-scale data analysis. Its main functions are as follows:

[0353] First, the complete removal of personal identification factors.

[0354] All identifiable information, such as name, resident registration number, and address, is deleted or replaced from personal information so that specific individuals cannot be traced during data analysis.

[0355] Second, it is to strengthen statistical safety.

[0356] Anonymized data is used as aggregated data, not individual information. For example, only non-identifiable information, such as a user's age or gender, is retained for statistical analysis.

[0357] Third, there are measures to prevent re-identification.

[0358] Anonymized data is subject to additional security measures to prevent re-identification. Various security technologies are employed to prevent data recombining to restore the original data.

[0359] Step 3 is the question and multiple answer merge processing step.

[0360] The question and multiple answer merge process analyzes and merges multiple user-provided answers to derive a consistent answer. This process integrates multiple answers to generate final data, and based on that data, it provides results appropriate for the service. Key features include:

[0361] First, there is question analysis.

[0362] The content of user-entered questions and the resulting responses are analyzed. Natural language processing (NLP) technology is used to understand the meaning of the question and extract and process relevant responses.

[0363] Second, multiple answers are merged.

[0364] When multiple answers are provided for the same question, duplicate or ambiguous answers are merged to produce a consistent answer. This improves the quality of the response data and provides consistent results.

[0365] Third, response optimization.

[0366] We refine data by optimizing merged responses to provide optimal answers when providing services.

[0367] Step 4 is the response content analysis step.

[0368] The response content analysis step analyzes user-provided response data and determines the keywords and meaning of the response, whether positive or negative. This step utilizes natural language processing (NLP) technology to analyze the response, extract key keywords, and determine the sentiment of the response through sentiment analysis. Key features include:

[0369] First, keyword extraction.

[0370] This step extracts important keywords from user-provided responses. Frequently occurring or contextually significant words in the text data are identified and categorized as keywords. For example, keywords like "satisfied," "dissatisfied," "fast," and "slow" are extracted.

[0371] Second, there are positive and negative judgments.

[0372] Based on extracted keywords, responses are automatically classified as positive or negative. A sentiment analysis algorithm is used to determine whether keywords carry positive or negative connotations. For example, the keyword "satisfied" is classified as positive, while "dissatisfied" is classified as negative.

[0373] Third, keyword weighting.

[0374] Extracted keywords are weighted to determine their importance in providing services. Different weights are assigned based on importance, increasing the accuracy of analysis results.

[0375] Explains the keywords in the response content and the method of judging whether it is positive or negative.

[0376] First, NLP-based text preprocessing is performed.

[0377] The response data is input into a natural language processing model to remove unnecessary words and transform them into an analyzable format. This includes preprocessing tasks such as tokenization, stopword removal, and stemming.

[0378] Second, extract keywords.

[0379] Extract important keywords based on preprocessed data. Using techniques like TF-IDF and Word2Vec, we identify high-frequency, context-sensitive words.

[0380] Third, perform sentiment analysis.

[0381] Based on the extracted keywords, the sentiment of the responses is analyzed and classified as positive, negative, or neutral. The sentiment analysis algorithm uses a pre-trained dictionary of positive and negative words to evaluate the sentiment of each keyword.

[0382] Fourth, derive results.

[0383] Finally, the extracted keywords and sentiment analysis results are combined to derive the meaning of the answer and generate the information necessary for providing the service.

[0384] Figure 16 is a drawing illustrating a personal information destruction unit according to the present disclosure.

[0385] Referring to Figure 16 (1610), the personal information destruction unit (500) will be described.

[0386] The personal information destruction unit (500) includes a personal information destruction automation and hash generation module (510).

[0387] The personal information destruction automation and hash generation module (510) includes a destruction history hash generation module (511).

[0388] The personal information destruction unit (500) is a system that safely destroys personal information when the collection and storage period of the information ends, and creates a destruction history generated in the process as a hash value to ensure integrity.

[0389] The Personal Information Destruction Department (500) automates the personal information destruction process, ensuring compliance with legal requirements and transparently managing the data destruction process. The Personal Information Destruction Department (500) destroys personal information through the following key steps.

[0390] Step 1: Create a personal information destruction scheduler.

[0391] The Personal Information Destruction Scheduler creation step automatically creates and executes a destruction schedule when personal information no longer needs to be retained. This applies when the personal information retention period has expired or when immediate destruction is required at the data subject's request. Key features include:

[0392] First, review the holding period.

[0393] We review the retention period for each personal information item and determine whether the retention period established by legal or service requirements has been exceeded. Personal information is reviewed based on the preset retention period, and any data exceeding the retention period is designated for destruction.

[0394] Second, the destruction schedule is automatically set.

[0395] When personal information is designated for destruction, a destruction scheduler is automatically created and a destruction schedule is set. The destruction schedule can be adjusted to optimize time, taking into account legal requirements and system resources.

[0396] Third, immediate processing of the request for destruction.

[0397] If the data subject requests immediate destruction of personal information, the scheduler immediately sets a destruction schedule and quickly executes the data destruction process.

[0398] Step 2 is the personal information destruction step.

[0399] The personal information destruction stage is the process of actually destroying personal information according to a schedule set by the scheduler. This stage securely destroys data through physical or logical means, and the destroyed information is processed so that it cannot be recovered. Key features include:

[0400] First, it is a logical breakdown.

[0401] Destruction involves deleting personal information stored within the system. This removes the personal information from files or databases, rendering it inaccessible or retrievable. Logical destruction is performed by removing all indexes and references to the data within the system.

[0402] Second, there is physical destruction.

[0403] Completely destroy data by shredding or deleting disks or other storage media containing personal information stored on physical storage devices. This method physically destroys the disk or media, rendering the data unrecoverable.

[0404] Third, data overwriting.

[0405] To ensure that logically deleted data cannot be recovered, the space where the data was stored is repeatedly overwritten with random data to ensure its destruction. This process is a secure method for completely erasing digital data, preventing any possibility of recovery.

[0406] Step 3 is the destruction history hash generation step.

[0407] The destruction history hash generation step records the history of personal information destruction and generates a hash value to ensure integrity. This step records information about the destroyed personal information and the destruction process, and generates a hash value to prevent tampering with this information. Its main functions are as follows:

[0408] First, it is the collection of destruction history data.

[0409] After personal information is destroyed, all data generated during the destruction process is collected. This includes information such as the personal information subject token, authentication method, authentication date, collection form ID, consent ID, and processing policy ID. This data is crucial for ensuring the reliability of the destruction history.

[0410] Second, hash value generation.

[0411] A unique hash value is generated by applying a hash algorithm (such as SHA256) based on the collected destruction history data. This hash value ensures the integrity of the destruction history and protects the data from tampering during the subsequent verification process.

[0412] Third, storage and management of destruction history.

[0413] The generated hash values ​​are securely stored along with the history of destroyed personal information and are managed so that their integrity can be verified by certification authorities or audit processes. The logs and hash values ​​of destroyed data are protected from external access and can be referenced for data verification when necessary.

[0414] Figure 17 is a drawing illustrating an authentication management unit according to the present disclosure.

[0415] Referring to FIG. 17 (1710), the authentication management unit (600) is described.

[0416] The authentication management unit (600) includes a personal information protection authentication management module (610).

[0417] The certification management department (600) is a system that manages and maintains certifications related to personal information protection, and performs the role of obtaining and maintaining various international and domestic standard certifications based on compliance logs generated within the company.

[0418] The authentication management unit (600) safely processes data generated during the authentication acquisition process and is comprised of steps to verify compliance with authentication standards. The authentication management unit (600) of the present invention primarily manages authentication through the following steps.

[0419] Step 1 is to create an in-house compliance log.

[0420] The internal compliance log generation step involves recording all activities occurring within the system to ensure compliance with privacy protection and related legal regulations. These logs contain data related to personal information processing, access control, and security incident response, primarily collecting and storing the following information:

[0421] First, there is a record of personal information processing activities.

[0422] All activities, including the collection, storage, processing, and destruction of personal information, are recorded in internal compliance logs. Each record includes the time of the activity, the person responsible, and related information.

[0423] Second, there is an access control log.

[0424] Prevent illegal access or abuse of authority by recording the users who accessed personal information, their authority level, and the time of access.

[0425] Third, there is a record of security incident response.

[0426] If a security incident involving personal information occurs, we record the response to the incident. For example, this includes incident response records for hacking attempts or internal information leaks.

[0427] The logs collected at this stage will be used as data required for subsequent certification applications, and all personal information processing activities occurring within the company will be transparently recorded.

[0428] Step 2 is to create an in-house compliance log hash.

[0429] The in-house compliance log hash generation step generates a hash value to ensure the integrity of the collected compliance log data. The hash value plays a crucial role in protecting the data and verifying whether the log has been tampered with during subsequent authentication procedures. Its main functions are as follows:

[0430] First, the hash algorithm is applied.

[0431] A cryptographic hash algorithm, such as SHA256, is applied to the collected log data to generate a unique hash value. This proves that the log data has not been tampered with.

[0432] Second, log integrity is guaranteed.

[0433] The generated hash value ensures the integrity of the compliance log and provides credibility when the log is subsequently reviewed by a certification authority. This hash value can be provided to external certification authorities to verify the log's legitimacy.

[0434] Third, hash value storage.

[0435] The generated hash value is stored in a secure database and can be referenced during subsequent authentication procedures. The stored hash value serves as a crucial element in verifying that log data has not been tampered with.

[0436] Step 3 is the certification application and management stage.

[0437] The certification application and management stage involves applying for and maintaining international and domestic personal information protection-related certifications based on internally generated compliance logs and hash values. Key certifications are managed in accordance with ISO standards and domestic and international regulations. The process for obtaining these certifications is as follows.

[0438] First, ISO 27701.

[0439] ISO 27701, a Personal Information Management System (PIMS) certification, is an international standard for personal information protection. The certification management department reviews compliance with the ISO 27701 certification criteria and prepares the necessary documents and log data to apply for certification. ISO 27701 certification evaluates compliance with the standard for personal information protection policies, risk management, and personal information processing activities.

[0440] Second, ISO 27001.

[0441] ISO 27001, an Information Security Management System (ISMS) certification, is an international standard for information security. This standard assesses whether an organization has established the management systems necessary to maintain the confidentiality, integrity, and availability of information. The certification management department manages internal information security policies and procedures in accordance with ISO 27001 standards and generates essential log data to maintain certification.

[0442] Third, ISMS-P.

[0443] As a domestic personal information protection and information security management certification, ISMS-P assesses compliance with domestic legal requirements. This certification requires a management system that satisfies both information protection and personal information protection, and the certification management department collects and manages data to maintain ISMS-P certification.

[0444] Fourth, other certifications.

[0445] Other certifications related to privacy and information security (e.g., country-specific privacy certifications, industry-specific regulatory certifications, etc.) are also managed by the Certification Management Department. The department manages internal data in accordance with the requirements of each certification, prepares the necessary documents and materials, and applies for certification.

[0446] At this stage, the certification management department (600) manages all matters necessary for maintaining certification, starting from the application process, and continuously performs certification maintenance and renewal procedures in cooperation with the certification agency.

[0447] For example, FIG. 18 shows the status of a consignee according to the present disclosure (1810), FIG. 19 shows the status of personal information processing (1910), and FIG. 20 shows the status of a subcontractor (2010).

[0448] Figure 21 is a drawing illustrating inspection items of an inspection checklist according to the present disclosure.

[0449] Referring to Figure 21 (2110), the inspection items of the inspection checklist are described.

[0450] Inspection items are categorized by order, area, category, inspection item, inspection item details, related evidence, and evaluation criteria.

[0451] The area includes administrative safeguards.

[0452] The division includes an internal management plan.

[0453] Inspection items include establishment and implementation of internal management plans.

[0454] Relevant evidence includes the full text of the internal management plan.

[0455] The evaluation criteria are as follows:

[0456] Y - Contains all essential elements of the internal management plan.

[0457] P - Some items in the internal management plan are missing.

[0458] N - Internal management plan not collected.

[0459] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners and individual organizations.

[0460] The details of the inspection items, related evidence, and evaluation criteria are as follows.

[0461] First, the details of the first inspection item, related evidence, and evaluation criteria.

[0462] Question) Are you including all of the following in your personal information protection documents (internal management plan and related regulations)?

[0463] 1. Matters concerning the composition and operation of the personal information protection organization.

[0464] 2. Matters concerning the qualifications and designation of the personal information protection manager

[0465] 3. Matters concerning the roles and responsibilities of the personal information protection officer and personal information handler.

[0466] 4. Matters concerning management, supervision, and education of personal information handlers

[0467] 5. Matters concerning management of access rights

[0468] 6. Matters concerning access control

[0469] 7. Matters concerning encryption of personal information

[0470] 8. Matters concerning storage and inspection of connection records

[0471] 9. Matters concerning the prevention of malicious programs, etc.

[0472] 10. Matters concerning vulnerability inspection to prevent personal information leakage or theft.

[0473] 11. Matters concerning physical safety measures

[0474] 12. Matters concerning the establishment and implementation of a plan to respond to personal information leaks.

[0475] 13. Matters concerning risk analysis and management

[0476] 14. Matters concerning the management and supervision of the trustee when entrusting personal information processing work.

[0477] 15. Matters concerning the establishment, amendment, and approval of the internal personal information management plan.

[0478] 16. Other matters necessary for personal information protection"

[0479] The relevant evidence is as follows.

[0480] 1. Full text of the Personal Information Protection Policy Document (Internal Management Plan and Personal Information Protection-Related Regulations)

[0481] The evaluation criteria are as follows:

[0482] Y - Contains all required elements within the policy document

[0483] P - Some details are missing from the policy document.

[0484] N - No policy document established

[0485] N / A - Personal information is processed for less than 10,000 data subjects, including small business owners, individuals, and organizations.

[0486] Second, the details of the second inspection item, related evidence, and evaluation criteria.

[0487] Question) Are you obtaining approval from the CEO (or Chief Personal Information Officer) for the personal information protection policy document (internal management plan and personal information protection-related regulations) in accordance with internal personnel procedures?

[0488] - Specify approval records in groupware (deliberation) or internal management plan

[0489] Question) Is the personal information protection policy document (internal management plan and personal information protection-related regulations) published internally?

[0490] - Announcement through posting of internal management plan on groupware bulletin board

[0491] - Produce booklets, etc. and place them in accessible locations.

[0492] The relevant evidence is as follows.

[0493] 1. Approval record

[0494] 2. Publication evidence

[0495] The evaluation criteria are as follows:

[0496] Y - Approved and properly publicized

[0497] P - Approved but not published

[0498] N - Not Approved

[0499] Third, here are the details of the third inspection item.

[0500] Question) Are the personal information protection policy documents (internal management plan and personal information protection-related regulations) reviewed regularly (at least once a year)?

[0501] - Annual review history of personal information protection policy documents (internal management plan and personal information protection-related regulations)

[0502] - Details of approval and announcement of revisions

[0503] The relevant evidence is as follows.

[0504] 1. History of revisions to the Personal Information Protection Policy document (internal management plan and personal information protection-related regulations).

[0505] The evaluation criteria are as follows:

[0506] Y - Records the revision history of the privacy policy document.

[0507] N - Do not keep track of revisions to the Privacy Policy document.

[0508] Fourth, here are the details of the 4th inspection item.

[0509] Question) Are you inspecting and managing the implementation status of the personal information protection policy document (internal management plan and personal information protection-related regulations) at least once a year and implementing improvement measures for any deficiencies?

[0510] - The personal information protection officer shall conduct an inspection of the implementation status of the personal information protection policy document at least once a year.

[0511] - Review and approval of the inspection results by the personal information protection officer

[0512] - Required checklist when checking the status of implementation

[0513] 1. Access Rights Management

[0514] 2. Storage and inspection of connection records

[0515] 3. Encryption measures

[0516] The relevant evidence is as follows.

[0517] 1. Plan for Inspection of the Implementation Status of Personal Information Protection Policy

[0518] 2. Report on the Implementation Status of Personal Information Protection Policy

[0519] The evaluation criteria are as follows:

[0520] Y - We inspect the implementation of our privacy policy at least once a year.

[0521] P - We are checking the implementation status of the personal information protection policy, but there are some missing items among the required inspection items.

[0522] N - No verification of compliance with privacy policy

[0523] Fifth, the details of the fifth inspection item.

[0524] Question) Have you officially designated a Personal Information Protection Officer with appropriate qualifications?

[0525] - State the person responsible for personal information protection in the personal information protection policy, organizational chart, and personal information processing policy.

[0526] 1. Business owner or representative

[0527] 2. Executive (if there is no executive, the head of the department in charge of personal information processing)

[0528] ※ In the case of small business owners, the business owner or representative is deemed to have been designated as the personal information protection officer without separate designation.

[0529] The relevant evidence is as follows.

[0530] Official documents that confirm the appointment of a personal information protection officer, such as a personal information protection policy, organizational chart, personal information processing policy, and personnel appointments.

[0531] The evaluation criteria are as follows:

[0532] Y - Designate a personal information protection officer and meet the requirements for designating a personal information protection officer.

[0533] P - A personal information protection officer has been designated, but the requirements for designating a personal information protection officer are not met or the person has not been designated in an official document.

[0534] N - No data protection officer has been designated

[0535] Sixth, the details of the 6th inspection item.

[0536] Question) Are you collecting personal information handlers' security pledges for personal information protection?

[0537] ① Confirmation of whether a security pledge is required upon joining or leaving the company.

[0538] ② Regularly (once a year) check whether all personal information handlers are required to re-sign the security pledge.

[0539] ※ Security pledge composition

[0540] - The following content is designed to remind users of their responsibilities to prevent personal information from being leaked.

[0541] 1. Obligations of personal information handlers to protect personal information

[0542] 2. Disciplinary action in case of violation

[0543] 3. Examples of pledges: The following are relevant evidence, such as personal information security pledges and confidentiality pledges.

[0544] 1. Employee Security Pledge

[0545] 2. Security pledge for former employees

[0546] The evaluation criteria are as follows:

[0547] Y - We are regularly collecting security pledges without fail (at least once a year).

[0548] P - We are collecting security pledges, but there are missing people.

[0549] N - Not collecting security pledge

[0550] Seventh, the details of the 7th inspection item.

[0551] Question) Do you provide personal information protection training to personal information protection officers and personal information handlers at least once a year?

[0552] - Develop a personal information protection education plan

[0553] ① Prepare an annual personal information protection education plan including the following:

[0554] 1. Educational Purpose and Target

[0555] 2. Training Content

[0556] 3. Training schedule and methods

[0557] - Evidence of implementation of personal information protection job-specific training

[0558] ① Confirmation of implementation of personal information protection training for personal information handlers

[0559] ② Confirmation of training implementation evidence at least once a year

[0560] ③ Confirmation of management and supervision of those who have not completed training

[0561] ※ Personal information handler: A person who processes personal information under the direction and supervision of a personal information processor, such as an employee, dispatched worker, or part-time worker.

[0562] The relevant evidence is as follows.

[0563] 1. Personal Information Protection Education Plan

[0564] 2. Personal Information Protection Training Results

[0565] 3. Personal information protection training materials

[0566] 4. Personal Information Protection Training Completion Certificate

[0567] 5. List of Personal Information Protection Training Attendees

[0568] 6. Other evidence that can confirm personal information protection education

[0569] The evaluation criteria are as follows:

[0570] Y - We have established a personal information protection education plan, provide regular education at least once a year, and supervise and manage those who have not completed the education.

[0571] P - Personal information protection training is conducted at least once a year, but no supervision is provided for those who have not completed the training.

[0572] N - Personal information protection training is not conducted at least once a year.

[0573] Eighth, the details of the 8th inspection item.

[0574] Question) Have you established response procedures and methods in case of loss, theft, or leakage of personal information?

[0575] - A personal information leak response plan must be established and implemented, including matters such as leak reporting and notification, damage report reception, and damage relief.

[0576] - Accidents must be reported to the consignor immediately.

[0577] The relevant evidence is as follows.

[0578] 1. Personal Information Leak Response Plan

[0579] The evaluation criteria are as follows:

[0580] Y - Establishing and implementing a personal information leak response plan.

[0581] N - No personal information leak response plan in place

[0582] Ninth, the details of the 9th inspection item.

[0583] Question) In principle, re-entrustment by the trustee without prior consultation is prohibited, but in cases where re-entrustment is unavoidable, is re-entrustment done according to standards?

[0584] - Re-entrustment must be done with the consent of the consignor.

[0585] - A subcontracting agreement must be prepared based on the consignor's consignment agreement.

[0586] - Personal information cannot be used or provided beyond the scope of work entrusted by the consignor.

[0587] The relevant evidence is as follows.

[0588] 1. Evidence of prior approval

[0589] 2. Contract regarding re-consignment

[0590] The evaluation criteria are as follows:

[0591] Y - Personal information is being re-entrusted according to the relevant standards.

[0592] N - Personal information is being re-entrusted without the entrustor's approval.

[0593] Tenth, here are the details of the 10th inspection item.

[0594] Question) When re-entrusting personal information, are you conducting periodic inspections and training?

[0595] The relevant evidence is as follows.

[0596] 1. Regular inspection and training plan for re-trustees

[0597] 2. Results of regular inspection and training of re-trustees

[0598] The evaluation criteria are as follows:

[0599] Y - We manage and supervise trustees through education and inspection.

[0600] N - Not managing and supervising the trustees through education and inspection.

[0601] N / A - Personal information is not re-entrusted

[0602] Eleventh, details of the 11th inspection item.

[0603] Question) Have you established a personal information processing policy that includes all of the required items below and made it publicly available in a way that is easily understandable to the data subject?

[0604] - Personal information processing policy information (Personal information processing policy drafting guidelines, Personal Information Protection Commission, April 2024)

[0605] 1. Title (required)

[0606] 2. Purpose of processing personal information (required)

[0607] 3. Items of personal information processed (required)

[0608] 4. Matters concerning the processing of personal information of children under the age of 14 (recommended when applicable)

[0609] 5. Personal information processing and retention period (required)

[0610] 6. Matters concerning the procedures and methods for destroying personal information (required)

[0611] 7. Matters regarding provision of personal information to third parties (required when applicable)

[0612] 8. Criteria for determining if additional use or provision continues (required when applicable)

[0613] 9. Matters concerning the entrustment of personal information processing (required when applicable)

[0614] 10. Matters concerning the overseas collection and transfer of personal information (required when applicable)

[0615] 11. Matters concerning measures to ensure the security of personal information (required)

[0616] 12. How to choose whether to disclose sensitive information and whether to keep it private (required if applicable)

[0617] 13. Matters concerning the processing of pseudonymized information (required when applicable)

[0618] 14. Matters concerning the installation and operation of automatic personal information collection devices and their refusal (required when applicable)

[0619] 15. Matters concerning the collection, use, and refusal of behavioral information collected by third parties through automatic personal information collection devices (recommended if applicable)

[0620] 16. Matters concerning the rights, obligations, and exercise methods of the data subject and legal representative (required)

[0621] 17. Name of the Personal Information Protection Officer, the department in charge of personal information management, and the department handling complaints (required)

[0622] 18. Matters concerning the designation of a domestic agent (required if applicable)

[0623] 19. Remedies for Infringement of the Rights of Data Subjects (Recommended)

[0624] 20. Matters concerning the operation and management of fixed-type video information processing equipment (required when applicable)

[0625] 21. Matters concerning the operation and management of mobile video information processing devices (required when applicable)

[0626] 22. Matters autonomously established by the personal information processor regarding personal information processing standards and protective measures in the personal information processing policy (recommended)

[0627] 23. Matters regarding changes to the personal information processing policy (required)

[0628] - Disclosure of personal information processing policy

[0629] ① The established or changed personal information processing policy shall be continuously posted on the operating Internet homepage so that the information subject can easily check it.

[0630] ② In cases where it cannot be posted on the Internet homepage, it can be made public through the following methods:

[0631] 1. Place it in a place where it can be easily seen, such as the personal information processor's workplace.

[0632] 2. Publication in publications, newsletters, promotional materials, or bills issued more than twice a year.

[0633] 3. “Specification in the contract with the information subject for the provision of goods or services, etc.”

[0634] The relevant evidence is as follows.

[0635] 1. Personal Information Processing Policy

[0636] 2. Disclosure of Personal Information Processing Policy"

[0637] The evaluation criteria are as follows:

[0638] Y - We have established and continuously disclose a privacy policy that includes all essential information.

[0639] P - Some of the essential provisions of the privacy policy are missing or not consistently posted.

[0640] N - No privacy policy established

[0641] N / A - Personal information will not be re-entrusted"

[0642] The twelfth, the 12th inspection item details.

[0643] Question) Do you have established and are operating access control procedures for physical storage locations where personal information is stored, such as computer rooms and archives?

[0644] - Office access control procedures

[0645] - Installation of additional control devices such as fingerprint recognition devices, card key devices, and number key devices"

[0646] The relevant evidence is as follows.

[0647] 1. Access Control Procedure Document

[0648] 2. Status of application of access control

[0649] 3. Evidence of access control operation (entrance / exit log, etc.)

[0650] The evaluation criteria are as follows:

[0651] Y - Establish and operate access control procedures for physical storage locations.

[0652] N - No access control procedures for physical storage locations are established.

[0653] The thirteenth, the 13th inspection item details.

[0654] Question) Are documents and auxiliary storage media containing personal information stored in a secure location with a lock or other locking device?

[0655] - Safely store documents and auxiliary storage media containing personal information.

[0656] The relevant evidence is as follows.

[0657] 1. Evidence materials such as documents or auxiliary storage media containing personal information are stored in a separate space with a locking device.

[0658] The evaluation criteria are as follows:

[0659] Y - Documents and auxiliary storage media containing personal information are stored in a safe place.

[0660] N - Documents and auxiliary storage media containing personal information are not stored in a secure location.

[0661] Fourteenth, the details of the 14th inspection item.

[0662] Question) Have you established and implemented a policy to control the import and export of auxiliary storage media?

[0663] - Establish procedures for bringing in / taking out auxiliary storage media within internal regulations.

[0664] ① Check if there is a procedure for bringing in / taking out auxiliary storage media.

[0665] ② Check whether there is a permit request and approval procedure for import / export

[0666] ③ Check the auxiliary storage media import / export management ledger when bringing in / out

[0667] The relevant evidence is as follows.

[0668] 1. Policy on controlling the import and export of auxiliary storage media

[0669] 2. Auxiliary storage media import / export management ledger

[0670] The evaluation criteria are as follows:

[0671] Y - Establishing standards for the import and export of auxiliary storage media and implementing control procedures.

[0672] P - The standards for exporting and importing auxiliary storage media are inadequate or there is no control over export and import.

[0673] N - There are no standards for the import and export of auxiliary storage media, and there is no control over import and export.

[0674] Fifteenth, the details of the 15th inspection item.

[0675] Question) Are you granting personal information handlers differential access to the personal information processing system to the minimum extent necessary for performing their duties?

[0676] - Issuance of accounts for each personal information handler

[0677] - No account sharing

[0678] - If account sharing is unavoidable, measures to ensure accountability are required.

[0679] - Restrictions on printing and downloading personal information

[0680] The relevant evidence is as follows.

[0681] 1. List of personal information handlers

[0682] 2. Status of access rights to personal information processing systems

[0683] The evaluation criteria are as follows:

[0684] Y - The personal information handler account is granted minimal permissions.

[0685] P - Personal information handler account permissions are minimal, but some people are granted excessive permissions.

[0686] N - Does not restrict the permissions of the personal information handler account

[0687] Sixteenth, the details of the 16th inspection item.

[0688] Question) When a personnel change, such as a transfer or retirement, occurs, are access rights to the personal information processing system changed or deleted without delay?

[0689] - Changes in personal information processing system authority due to changes in business

[0690] - Delete retiree accounts in the personal information processing system

[0691] The relevant evidence is as follows.

[0692] 1. Retirement and Job Change Procedure

[0693] 2. History of account deletion or access rights changes

[0694] The evaluation criteria are as follows:

[0695] Y - Access rights are immediately revoked in the event of personnel transfers such as retirement.

[0696] N - Access rights are not immediately revoked upon personnel transfer, such as retirement.

[0697] Seventeenth, details of the 17th inspection item.

[0698] Q) Are you keeping a record of the granting, modification, and deletion of access rights to your personal information processing system?

[0699] - Records of changes in personal information processing system access rights are kept for at least 3 years.

[0700] - Includes minimum information to ensure accountability, such as account name, name, affiliation, and authority.

[0701] The relevant evidence is as follows.

[0702] 1. Changes to personal information processing system access rights

[0703] 2. Application for Change of Access Rights

[0704] The evaluation criteria are as follows:

[0705] Y - Records of changes in personal information handler access rights are safely stored for at least three years.

[0706] P - Records of changes in access rights of personal information handlers are being kept, but the change history cannot be clearly confirmed or is not kept for more than 3 years.

[0707] N - Does not record changes in access rights of personal information handlers

[0708] The eighteenth, detailed content of the 18th inspection item.

[0709] Question) Are you taking any measures, such as automatically blocking access to the personal information processing system if no work is done for a certain period of time?

[0710] - Personal information processing system session timeout, token expiration time setting, etc.

[0711] The relevant evidence is as follows.

[0712] 1. Evidence of setting maximum connection time limit

[0713] The evaluation criteria are as follows:

[0714] Y - Personal information processing system timeout function is applied

[0715] N - Personal information processing system timeout function is not applied

[0716] Nineteenth, the details of the 19th inspection item.

[0717] Question) When access to the personal information processing system from outside via an information and communications network is required, are secure authentication methods being applied?

[0718] - Secure authentication methods: OTP, certificate, security token, etc.

[0719] - Secure connection methods: VPN, dedicated line, etc.

[0720] The relevant evidence is as follows.

[0721] 1. Evidence of setting up a secure authentication method or connection method when accessing the personal information processing system from outside.

[0722] The evaluation criteria are as follows:

[0723] Y - Remote access to the personal information processing system from outside is restricted.

[0724] N - Does not restrict remote access to the personal information processing system from outside.

[0725] The twentieth, detailed content of the 20th inspection item.

[0726] Question) Are you restricting internet access for important terminals that process personal information?

[0727] - If the following tasks are possible, it is considered an important terminal.

[0728] 1. Personal information can be downloaded or destroyed from the personal information processing system.

[0729] 2. Access rights to the personal information processing system can be set.

[0730] The relevant evidence is as follows.

[0731] 1. Evidence of Internet blocking settings on important terminals

[0732] The evaluation criteria are as follows:

[0733] Y - Internet use on important terminals is restricted.

[0734] N - Does not restrict Internet use on important terminals

[0735] N / A - Not eligible for network separation

[0736] Twenty-first, the details of the 21st inspection item.

[0737] Question) Are you restricting access to the personal information processing system by IP address, etc.?

[0738] - Allow access only to specific IPs / MACs through firewalls, etc.

[0739] - Allow access only to specific IPs / MACs using the router's ACL function.

[0740] - Use access control solutions to allow access only to authorized personnel.

[0741] The relevant evidence is as follows.

[0742] 1. Evidence of restricted access to personal information processing systems

[0743] 2. Evidence of security solution operation

[0744] The evaluation criteria are as follows:

[0745] Y - Access control is set when accessing the personal information processing system.

[0746] P - Access control is inadequate when accessing the personal information processing system.

[0747] N - Do not set access control when accessing the personal information processing system.

[0748] Twenty-second, detailed contents of the 22nd inspection item.

[0749] Question) Are you safely applying and managing the authentication method for personal information handlers or data subjects in the personal information processing system?

[0750] - Application of authentication methods (password, OTP, etc.) according to internal management plan or guidelines

[0751] - Restrict access to the personal information processing system if authentication fails a certain number of times.

[0752] The relevant evidence is as follows.

[0753] 1. Provision of authentication methods within the internal management plan

[0754] 2. Setting the authentication method threshold

[0755] The evaluation criteria are as follows:

[0756] Y - Applying authentication methods and setting thresholds for personal information processing systems.

[0757] P - Authentication methods are applied to personal information processing systems, but thresholds are not set.

[0758] N - No authentication method applied to personal information processing system"

[0759] Twenty-third, details of the 23rd inspection item.

[0760] Question) When searching or printing personal information, are you minimizing the number of personal information items printed to only the information necessary for business purposes and applying safety measures to safely manage printouts and copies?

[0761] - Establish policies / regulations / guidelines for protecting and managing output and copies

[0762] - Safety measures such as watermarking, output history recording, and destruction confirmation

[0763] - When printing personal information (printing, displaying on screen, creating files, etc.), print it to the minimum extent possible within the scope of access rights by specifying the purpose.

[0764] - Whether to mask when viewing the entire list of personal information through the personal information processing system

[0765] The relevant evidence is as follows.

[0766] 1. Evidence of personal information masking

[0767] The evaluation criteria are as follows:

[0768] Y - Security measures are applied when viewing the full list of personal information.

[0769] N - No security measures applied when viewing the full list of personal information

[0770] The twenty-fourth, detailed inspection item 24.

[0771] Question) Are you storing and managing access records, including essential items, for the personal information processing system of the personal information handler for more than one year?

[0772] - Required items: identifier, access date and time, access location information, information on the subject of the information processed, and tasks performed.

[0773] - In the cases below, they must be stored and managed for more than 2 years.

[0774] 1. In the case of a personal information processing system that processes personal information of more than 50,000 data subjects.

[0775] 2. In the case of a personal information processing system that processes unique identification information or sensitive information.

[0776] 3. In case the personal information processor is a telecommunications service provider

[0777] ※ Explanation of required items for access log

[0778] - Identifier: Account information such as ID assigned to identify the user in the personal information processing system.

[0779] - Access date and time: Time of access or time of work performed (year-month-day, hour:minute:second)

[0780] - Access information: IP address of the computer or server of the person accessing the personal information processing system, etc.

[0781] - Processed information subject information: Identification information (ID, customer number, student number, employee number, etc.) that allows the personal information handler to determine whose personal information was processed.

[0782] - Performance tasks: Information that allows the personal information handler to know the details of personal information processed using the personal information processing system (collecting, creating, linking, connecting, recording, storing, holding, processing, editing, searching, printing, correcting, recovering, using, providing, disclosing, destroying, etc. may be considered performance tasks)

[0783] The relevant evidence is as follows.

[0784] 1. Access log of personal information processing system

[0785] The evaluation criteria are as follows:

[0786] Y - Access records of personal information processing systems are stored and managed for at least one or two years, including all required information.

[0787] P - Access records for the personal information processing system are being kept, but some information is missing or the access record retention period is not appropriate.

[0788] N - Access records of personal information processing systems are not kept.

[0789] Twenty-fifth, the 25th inspection item details.

[0790] Question) Are you checking the access records of the personal information processing system at least once a month?

[0791] - Check for excessive personal information inquiries, access outside of working hours, and reasons for downloading personal information.

[0792] - When downloading personal information, it is mandatory to check the reason for downloading.

[0793] The relevant evidence is as follows.

[0794] 1. Personal information processing system access log inspection plan

[0795] 2. Personal information processing system access log inspection report

[0796] The evaluation criteria are as follows:

[0797] Y - We are checking the appropriateness of the access records and reasons for downloading personal information from the personal information processing system (at least once a month).

[0798] P - We are checking the appropriateness of the personal information processing system access records and reasons for downloading personal information, but we do not conduct inspections more than once a month.

[0799] N - The access records of the personal information processing system and the reasons for downloading personal information are not checked for appropriateness.

[0800] Twenty-sixth, the 26th inspection item details.

[0801] Question) Are you taking necessary measures in your personal information processing system, personal information handler's computer, and mobile device to prevent personal information from being disclosed or leaked to unauthorized persons through Internet homepages, P2P, sharing settings, etc.?

[0802] - Block access to harmful sites such as P2P

[0803] - Shared folder restrictions

[0804] - Application of security solutions such as DLP and DRM

[0805] The relevant evidence is as follows.

[0806] 1. Evidence of blocking access to harmful websites on the personal information handler's terminal

[0807] 2. Evidence of shared folder restriction settings

[0808] 3. Evidence of security solution operation

[0809] The evaluation criteria are as follows:

[0810] Y - Measures are being established to prevent personal information leakage and exposure on personal information handler terminals.

[0811] N - No measures are set up on the personal information handler's terminal to prevent personal information leakage or exposure.

[0812] Twenty-seventh, the 27th inspection item details.

[0813] Question) Are you establishing and applying a password policy for personal information handlers or data subjects who access the personal information processing system?

[0814] - The minimum password length is set to 10 characters when combining at least two types of uppercase letters, lowercase letters, numbers, and special characters, or 8 characters when combining at least three types of characters.

[0815] - Set an expiration date for your password, change it at least once every six months, and prevent the use of two passwords interchangeably.

[0816] - If you enter your password incorrectly more than 5 times, access restrictions such as account locking and delay settings will be applied.

[0817] - Set passwords that are easy to guess, such as consecutive numbers, birthdays, phone numbers, or passwords that are similar to IDs, to be unavailable.

[0818] ※ Not applicable if password is not used as an authentication method"

[0819] The relevant evidence is as follows.

[0820] 1. Password policy within the internal management plan

[0821] 2. Password policy set in the personal information processing system

[0822] 3. Password change date status

[0823] The evaluation criteria are as follows:

[0824] Y - Set a secure password that meets the password standards and change it regularly.

[0825] N - You are using a weak password or your password policy settings are not being applied.

[0826] Twenty-eighth, the 28th inspection item details.

[0827] Question) Are you storing your password using one-way encryption?

[0828] - Application of a secure one-way encryption algorithm higher than SHA-2

[0829] - Refer to the latest information, such as the KISA encryption algorithm and key length usage guide.

[0830] ※ Not applicable if password is not used as authentication method

[0831] The relevant evidence is as follows.

[0832] 1. Evidence of application of encryption algorithm to password

[0833] The evaluation criteria are as follows:

[0834] Y - A secure encryption algorithm is applied when storing passwords.

[0835] N - No secure encryption algorithm is used when storing passwords.

[0836] The twenty-ninth, 29th inspection item details.

[0837] Question) Are users' resident registration numbers, passport numbers, driver's license numbers, alien registration numbers, credit card numbers, account numbers, and biometric information encrypted and stored using a secure encryption algorithm?

[0838] - Writing of applied symmetric key encryption algorithms (SEED, ARIA-128 / 192 / 256, AES-128 / 192 / 256, HIGHT, etc.)

[0839] - Writing of applied public key encryption algorithms (RSAES-OAEP, RSAES-PKCS1, etc.)

[0840] The relevant evidence is as follows.

[0841] 1. Evidence of personal information encryption application

[0842] 2. Encryption algorithm evidence

[0843] The evaluation criteria are as follows:

[0844] Y - Personal information is encrypted and stored using a secure encryption algorithm.

[0845] N - Personal information is stored without encryption using a secure encryption algorithm.

[0846] The thirtieth, detailed content of the 30th inspection item.

[0847] Question) When sending and receiving passwords, personal information, and authentication information via information and communications networks, are they encrypted?

[0848] - Apply SSL (https) or install an encryption program"

[0849] The relevant evidence is as follows.

[0850] 1. SSL certificate information

[0851] 2. Evidence of personal information encryption through encryption solutions, etc.

[0852] The evaluation criteria are as follows:

[0853] Y - Personal information and authentication information transmitted and received via information and communications networks are encrypted.

[0854] N - Personal information and authentication information transmitted and received via information and communications networks are not encrypted.

[0855] Here are the details of the thirty-first inspection item.

[0856] Question) When storing personal information on PCs, mobile devices, and auxiliary storage media, is it encrypted?

[0857] - When downloading files from the personal information processing system, they are downloaded with the password settings applied.

[0858] - Manually set a password for personal information files (such as password settings provided by office programs)

[0859] - When using auxiliary storage media, use secure USB, etc.

[0860] - DRM applied

[0861] The relevant evidence is as follows.

[0862] 1. Evidence that encryption has been applied when storing personal information files on a PC, auxiliary storage media, etc.

[0863] The evaluation criteria are as follows:

[0864] Y - Personal information is encrypted and stored.

[0865] N - Do not encrypt personal information when storing it

[0866] Thirty-second, detailed inspection item 32.

[0867] The relevant evidence is as follows.

[0868] 1. Encryption Key Management Procedure

[0869] The evaluation criteria are as follows:

[0870] Y - Establishing and implementing secure encryption key management procedures.

[0871] N - Failure to establish and implement secure encryption key management procedures

[0872] Thirty-third, details of the 33rd inspection item.

[0873] Question) Are you installing and operating a security program to check for and treat malware on your personal information handler's PC?

[0874] - Automatic update or update at least once a day

[0875] - Real-time monitoring and daily scheduled inspections

[0876] The relevant evidence is as follows.

[0877] 1. Security program installation history

[0878] 2. Security program inspection details

[0879] 3. Security program update history

[0880] The evaluation criteria are as follows:

[0881] Y - I have installed a security program, am running real-time monitoring, and am performing updates once a day.

[0882] P - Security program installed but not updated once a day or set up real-time monitoring

[0883] N - Do not install or run security programs

[0884] Thirty-fourth, details of inspection item 34.

[0885] Question) If there is a security update notice for the application or operating system software being used on the personal information handler's PC, do you apply the update immediately?

[0886] The relevant evidence is as follows.

[0887] 1. A screen where you can check for security updates on the personal information handler's PC.

[0888] 2. Evidence that can confirm whether security updates are being applied to applications installed on the PC.

[0889] 3. Update-related notice

[0890] The evaluation criteria are as follows:

[0891] Y - Applying updates immediately when security updates are announced

[0892] N - Do not apply security updates immediately

[0893] Thirty-fifth, details of inspection item 35.

[0894] Question) Do you have a crisis response manual and backup and recovery plan in place to prepare for disasters such as fire, flood, and power outages, and do you regularly review them?

[0895] ※ If it does not fall under the types below, it may be excluded from the inspection items.

[0896] - Large corporations, medium-sized enterprises, and public institutions that process personal information of more than 100,000 data subjects.

[0897] - Personal information processors that are small and medium-sized enterprises or organizations that process personal information of more than 1 million data subjects.

[0898] The relevant evidence is as follows.

[0899] 1. Crisis Response Manual (Document)

[0900] 2. Backup and Recovery Policy and Procedures (Document)

[0901] The evaluation criteria are as follows:

[0902] Y - Establishing crisis response procedures, including backup and recovery plans.

[0903] P - Crisis response procedures are in place but backup and recovery plans are missing, or backup and recovery plans are in place but crisis response procedures are inadequate.

[0904] N - No crisis response procedures established"

[0905] Thirty-sixth, details of the 36th inspection item.

[0906] Question) In addition to the personal information provided by the consignor, when collecting additional personal information for the purpose of processing the consignor's business, are you obtaining consent in an appropriate manner, such as by notifying all necessary information for consent and indicating important information?

[0907] - Required notification in consent form

[0908] 1. Purpose of collection and use of personal information

[0909] 2. Items of personal information to be collected

[0910] 3. Retention and use period of personal information

[0911] 4. The fact that you have the right to refuse consent and, if there are any disadvantages resulting from refusal of consent, the details of those disadvantages.

[0912] 5. (When provided to a third party) Recipient, purpose of use by recipient, period of use, items provided, right to refuse consent and disadvantages of consent

[0913] - How to display important information in the consent form

[0914] 1. The font size should be at least 9 points and at least 20% larger than other content to ensure easy reading.

[0915] 2. Clearly indicate the content through text color, thickness, or underlining.

[0916] 3. If there are many matters to agree on and it is difficult to clearly distinguish important matters, display them separately from other matters so that important matters can be easily identified.

[0917] The relevant evidence is as follows.

[0918] 1. Personal information collection and use consent screen

[0919] The evaluation criteria are as follows:

[0920] Y - We collect personal information by providing all required notices and obtaining consent.

[0921] N - Personal information is being collected without providing or omitting required notices.

[0922] Thirty-seventh, details of the 37th inspection item.

[0923] Question) Are you destroying personal information without delay after confirming that the retention period has expired or the business purpose has been achieved?

[0924] - Writing the conditions and cycle for destroying personal information

[0925] - Create a history of personal information destruction

[0926] - Request for the preparation of evidence of personal information destruction, such as a "Personal Information Destruction Confirmation Form"

[0927] The relevant evidence is as follows.

[0928] 1. Personal Information Destruction Procedure

[0929] 2. Setting up personal information destruction batches

[0930] 3. Personal Information Destruction Confirmation Form

[0931] 4. Personal information destruction history

[0932] The evaluation criteria are as follows:

[0933] Y - Establishing destruction criteria and procedures and managing post-destruction history.

[0934] P - Establishing destruction criteria or procedures, but not managing destruction history

[0935] N - No destruction criteria or procedures established

[0936] Thirty-eighth, details of the 38th inspection item.

[0937] Question) If personal information must be retained even after the purpose of use has been achieved, is it stored and managed separately from other personal information being operated?

[0938] - Writing the conditions and cycle for separate storage of personal information

[0939] The relevant evidence is as follows.

[0940] 1. Evidence of separate storage of personal information

[0941] The evaluation criteria are as follows:

[0942] Y - Personal information that needs to be kept even after the purpose has been achieved is kept safely separated from operational personal information.

[0943] N - Personal information that needs to be retained even after the purpose has been achieved is stored without being separated from operational personal information.

[0944] Thirty-ninth, details of inspection item 39.

[0945] Question) Are you destroying personal information in the following secure manner?

[0946] - Personal information stored in electronic file formats such as PCs, auxiliary storage media, and mailboxes is deleted in a way that makes it unrecoverable using a technical method that renders the records unrecoverable.

[0947] - In the case of personal information printed on paper, it is destroyed using a method that makes it unrecoverable, such as shredding or incineration.

[0948] The relevant evidence is as follows.

[0949] 1. Evidence of destruction of personal information stored in electronic file format

[0950] 2. Document shredder, document destruction box evidence

[0951] The evaluation criteria are as follows:

[0952] Y - Personal information is being destroyed in a secure manner.

[0953] N - Not destroying personal information

[0954] Figure 22 is a drawing illustrating the inspection status of the inspection checklist according to the present disclosure.

[0955] Referring to Figure 22 (2210), the inspection status of the inspection checklist is explained.

[0956] The inspection status is divided into inspection status, related laws and regulations, and related notices.

[0957] The relevant laws are Article 29 of the Personal Information Protection Act and Article 30 of the Enforcement Decree.

[0958] The relevant notice is Article 4 of the Personal Information Security Measures Standards.

[0959] Figure 23 is a drawing explaining the penalty provisions of the inspection checklist according to the present disclosure.

[0960] Referring to Figure 23 (2310), the penalty provisions of the inspection checklist are explained.

[0961] Penalty provisions are divided into penalties and penalty provisions.

[0962] Penalties are divided into criminal penalties and administrative measures.

[0963] Punishments are divided into imprisonment and fines.

[0964] Administrative sanctions are categorized into fines and surcharges. Surcharges can be up to 50 million won.

[0965] The penalty provision is Article 75 of the Personal Information Protection Act.

[0966] According to Article 75 of the Personal Information Protection Act, a person who falls under any of the following items shall be subject to a fine of up to 50 million won.

[0967] 5) A person who has violated Article 23, Paragraph 2, Article 24, Paragraph 3, Article 25, Paragraph 6 (including cases where it applies pursuant to Article 25-2, Paragraph 4), Article 28-4, Paragraph 1, and Article 29 (including cases where it applies pursuant to Article 26, Paragraph 8) and has not taken necessary measures to ensure safety.

[0968] Above, the entire system of the present disclosure has been described with reference to FIGS. 1 to 23. Hereinafter, the present invention will be described in detail with reference to FIGS. 24 to 42.

[0969] Figure 24 is a diagram illustrating a configuration of a personal information management automation device according to the present disclosure.

[0970] The present invention consists of three inventions.

[0971] The first invention is an automated personal information management device and its control method. This is described in FIGS. 24 to 29.

[0972] The second invention is a personal information utilization device and its control method. This is described in FIGS. 30 to 36.

[0973] The third invention is a personal information flow map generation device and its control method. This is described in FIGS. 37 to 42.

[0974] In the present invention, the object transmitted by the transmitting entity includes data, information, messages, and signals.

[0975] Data contains information.

[0976] Information contains messages.

[0977] A message contains a signal.

[0978] The first invention describes an automated personal information management device. (Figs. 24 to 29)

[0979] Referring to FIG. 24, the personal information management automation device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[0980] The input module (2410) collects first data including a sentence entered by a personal information handler.

[0981] The sensor module (2420) senses first data.

[0982] The processor (2430) performs a control method according to the process.

[0983] That is, the processor (2430) finds items that are likely to collect personal information in the sentence included in the first data collected through the input module (2410), classifies the personal information, suggests a purpose of personal information processing based on the title and content of the form entered by the user, determines whether to allow the user to access the system based on the security level of the personal information handler, controls access based on the role and authority of the user based on the result of the decision, records a log processing the personal information, establishes a destruction policy for the personal information, and deletes or separately stores the personal information based on the established destruction policy.

[0984] The processor (2430) receives a query item of the above form, compares the query item with the learned data, calculates the classification probability of the personal information item, and proposes the personal information item with the highest probability among the calculation results.

[0985] The processor (2430) receives the contents of the form, compares the entered contents with the learned data, calculates the distance, and proposes the personal information processing purpose for the closest distance among the calculated results. A detailed description of this is provided in Fig. 26.

[0986] The processor (2430) controls the personal information subject to access a site provided by a personal information service provider (hereinafter referred to as SP), verifies the identity of the personal information subject through an authentication process, controls the personal information subject to call up the history to which the personal information subject has consented using a personal information management standard protocol, and visualizes the personal information usage status of the personal information subject obtained through the personal information management standard protocol.

[0987] The authentication process includes at least one of joint authentication, simple authentication, email authentication, text authentication, QR authentication, two-channel authentication, and financial authentication.

[0988] The processor (2430) controls the personal information subject to entrust the management of his / her personal information (Personal Information, PI) to a personal information service provider (SP), and controls the personal information service provider (SP) to report changes in the status of the personal information (PI) to the personal information subject.

[0989] The processor (2430) controls the personal information service provider (SP) to report changes in the status of the personal information to the personal information subject at a predetermined periodic interval.

[0990] The processor (2430) controls the personal information service provider (SP) to report changes in the status of the personal information to the personal information subject on a case-by-case basis.

[0991] If the authentication status is confirmed from an external device that the user has not accessed within a predetermined period of time, the processor (2430) determines that a change in the status of the personal information has occurred and reports this to the personal information subject. A detailed explanation of this is provided in Fig. 29.

[0992] The second invention describes a personal information utilization device and its control method. (Figs. 30 to 36)

[0993] Referring to FIG. 24, a personal information utilization device (2400) that obtains consent from a data subject for a change in purpose includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[0994] The input module (2410) collects first data including the contents of a contract between the service provider and a third party.

[0995] The processor (2430) maps the content to be processed according to country, industry, and business type with respect to the contract content between the service provider and the third party included in the first data collected through the input module, and when the user provides personal information, classifies the personal information by applying a classification model to the mapped content according to the contract type corresponding to the contract content, requests storage of the classified personal information, transmits the personal information to the third party's device according to the contract content, and when the purpose of use of the personal information has changed, transmits a first message including a request for consent to the change of the purpose of use to the device of the information subject, and when a second message including consent to the change of the purpose of use is received from the device of the information subject, the personal information is used with the changed purpose of use.

[0996] A change in purpose of use refers to a case where the purpose of use is changed from the first purpose to the second purpose when conducting a clinical trial at a medical institution.

[0997] The first objective is to analyze the effects of a specific drug, and the second objective is to study the side effects of that specific drug. A detailed explanation of these is provided in Figure 34.

[0998] The processor (2430) transmits a first message including changes to a data subject device, receives a second message including agreement to the changes from the data subject device, verifies whether the data subject agrees to the changes, and stores the verification result in memory.

[0999] The processor (2430) confirms the consent of the information subject using at least one of a written document, electronic signature, email, and text message.

[1000] If the purpose of use of the personal information changes and there are special provisions in other laws, the processor (2430) uses the personal information in accordance with the special provisions.

[1001] The processor (2430) exceptionally uses the personal information when the purpose of use of the personal information changes or an emergency situation occurs.

[1002] The processor (2430) determines that the emergency situation is necessary to protect at least one of the life, body, and property of the information subject. A detailed description of this is provided in FIG. 35.

[1003] If the purpose of use of the personal information changes, the processor (2430) rewrites the first message, including the request for consent to the change in purpose of use, by converting it into a preset language. A detailed description of this is provided in Fig. 36.

[1004] The third invention, a personal information flow map generation device and its control method are described. (Figs. 37 to 42)

[1005] A personal information flow map is a map that allows you to visually understand the use of personal information by looking up the consent history and usage status of personal information.

[1006] Specifically, a personal information flow map is a map that visually represents how personal information is collected, stored, processed, transmitted, shared, and deleted within a system.

[1007] According to the present invention, the movement path and processing process of personal information can be clearly identified, and risk factors related to data protection can be identified and managed, thereby enabling compliance with the Personal Information Protection Act and related regulations.

[1008] The personal information flow map generation device (2400) includes an input module (2410), a sensor module (2420), a processor (2430), a display module (2440), a memory (2450), a communication module (2460), and a camera module (2470).

[1009] The processor (2430) registers the personal information and the consent for the personal information included in the first data collected through the input module into the system, transmits the personal information and the consent for the personal information to a personal information processing server, registers the history of the personal information into the system, transmits the result of the completion of the history registration of the personal information to the information subject device, and when receiving a first message including a search for the consent history of the personal information and a search for the usage status of the personal information from the information subject device, generates a report on the consent history of the personal information and the usage status of the personal information, and transmits the generated report on the consent history of the personal information and the usage status of the personal information to the information subject device.

[1010] The processor (2430) registers the personal information and the consent to the personal information in the system according to rules that conform to the standard protocol.

[1011] The processor (2430) encrypts the personal information and the consent to the personal information in a keychain suitable for the standard protocol according to rules suitable for the standard protocol and registers it in the system.

[1012] The processor (2430) transmits the personal information and consent for the personal information to the personal information processing server along with a keychain compatible with the standard protocol. A detailed description of this is provided in Fig. 39.

[1013] When the processor (2430) receives a second message including a request for withdrawal of consent to the personal information from the information subject device, it transmits a request signal requesting withdrawal of consent to the personal information to the personal information processing server, and when it receives a result of withdrawal of consent to the personal information from the personal information processing server, it generates a report on withdrawal of consent to the personal information, and transmits the generated report on withdrawal of consent to the personal information to the information subject device.

[1014] The processor (2430) destroys all personal information and keychains related to the personal information.

[1015] The processor (2430) automatically destroys the personal information and the keychain associated with the personal information after a preset period of time (6 months, 1 year, 2 years) or after a period prescribed by law. A detailed description of this is provided in FIG. 40.

[1016] The processor (2430) generates a visualized report on the consent history and usage status of the personal information based on at least one of a graph, chart, map, or diagram. A detailed description of this is provided in Fig. 42.

[1017] The processor (2430) registers the personal information and consent to the personal information in a form accessible to the system regardless of the device type. A detailed description of this is provided in Fig. 39.

[1018] However, the components illustrated in FIG. 24 are not essential for implementing the present invention according to the present disclosure, and thus the present invention described in this specification may have more or fewer components than the components listed above.

[1019] Meanwhile, the processor (2430) of FIG. 24 may be identical to the processor (50) of FIG. 1 described above, and in this case, all operations and controls of FIGS. 1 to 23 described above may be performed identically by the processor (2430) of FIG. 24.

[1020] The display (2440) displays graphic images according to control commands from the processor (2430).

[1021] Memory (2450) stores at least one process for performing an operation and stores user input and data.

[1022] The communication module (2460) transmits and receives data with an external device.

[1023] Here, the external device includes an external device such as a smartphone, a PC, a laptop, a tablet PC, etc.

[1024] The camera module (2470) captures images of the front.

[1025] The camera module (2470) photographs a subject in front according to a control command from the processor (2430).

[1026] The communication module (2460) may include one or more components that enable communication with an external device, and may include, for example, at least one of a broadcast reception module, a wired communication module, a wireless communication module, a short-range communication module, and a location information module.

[1027] The input module (2410) is for inputting video information (or signals), audio information (or signals), data, or information input from a user, and may include at least one camera, at least one microphone, and at least one user input unit. Voice data or image data collected by the input module (2410) may be analyzed and processed into a user control command.

[1028] The display module (2440) displays (outputs) information processed in the present invention. For example, the present invention can display execution screen information of a running application program (e.g., an application), or UI (User Interface) or GUI (Graphical User Interface) information based on such execution screen information.

[1029] The memory (2450) can store data supporting various functions of the present invention, programs for the operation of the control unit, input / output data (e.g., music files, still images, moving images, etc.), and can store a plurality of application programs (or applications), data for the operation of the device, and commands. At least some of these application programs can be downloaded from an external server via wireless communication.

[1030] The memory (2450) may include at least one type of storage medium among a flash memory type, a hard disk type, an SSD (Solid State Disk type), an SDD (Silicon Disk Drive type), a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. In addition, the memory (2450) is separate from the present invention, but may be a database connected by wire or wirelessly, and may be implemented as a database system.

[1031] The processor (2430) may be implemented as at least one core, a memory storing data for an algorithm for controlling the operation of components within the present invention or a program reproducing the algorithm, and at least one processor (not shown) that performs the aforementioned operations using the data stored in the memory. In this case, the memory and the processor may be implemented as separate chips. Alternatively, the memory and the processor may be implemented as a single chip.

[1032] Additionally, the processor (2430) may control any one or a combination of the components described above to implement various embodiments according to the present disclosure described in FIGS. 24 to 42 below.

[1033] At least one component may be added or deleted to correspond to the performance of the components illustrated in Figure 24. Furthermore, it will be readily apparent to those skilled in the art that the relative positions of the components may be altered to correspond to the performance or structure of the system.

[1034] Meanwhile, each component illustrated in FIG. 24 refers to software and / or hardware components such as Field Programmable Gate Array (FPGA) and Application Specific Integrated Circuit (ASIC).

[1035] Figure 25 is a flowchart illustrating a method for automating personal information management according to the present disclosure. The present invention is performed by a personal information management automation device (2400) or a processor (2430) of the personal information management automation device (2400).

[1036] Referring to FIG. 25, the processor (2430) collects first data including a sentence entered by a personal information handler through an input module (S2510).

[1037] The processor (2430) finds items in the collected sentences that may collect personal information and classifies the personal information (S2520).

[1038] The processor (2430) proposes the purpose of personal information processing based on the title and content of the form entered by the personal information handler (S2530).

[1039] The processor (2430) determines whether to allow the personal information handler to access the system based on the personal information handler's security level (S2540).

[1040] The processor (2430) controls access according to the role and authority of the personal information handler based on the above decision result (S2550).

[1041] The processor (2430) records a log of processing the personal information (S2560).

[1042] The processor (2430) establishes a policy for destruction of the personal information (S2570).

[1043] The processor (2430) deletes or separates the personal information according to the established destruction policy (S2580).

[1044] Figure 26 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1045] Referring to FIG. 26 (2610), the processor (2430) includes a plurality of modules.

[1046] The processor (2430) executes the function of at least one module among a plurality of modules.

[1047] For example, the multiple modules include an AI module for classifying personal information items in a sentence (2431), an AI module for proposing personal information processing purposes (2432), an AI module for classifying personal information items in a document (2433), an access control module according to the security level of the personal information handler (2434), an access control module according to roles and permissions, a personal information access log module, and a personal information destruction rule generation module.

[1048] The AI ​​module (2431) classifies personal information items in sentences entered by users by finding items that may collect personal information and classifying the personal information.

[1049] The AI ​​module (2432) for suggesting the purpose of personal information processing suggests the purpose of personal information processing based on the title and content of the form entered by the user.

[1050] The AI ​​module (2433) for classifying personal information items in documents analyzes the context of all sentences entered by the user to find items that may directly or indirectly collect personal information and classifies the personal information.

[1051] The access control module (2434) based on the security level of the personal information handler determines whether to allow system access based on the security level of the personal information handler.

[1052] The role and permission-based access control module controls access based on the user's role and permission.

[1053] The personal information access log module records the logs of personal information processing.

[1054] The personal information destruction rule creation module establishes a personal information destruction policy and deletes or stores it separately.

[1055] The processor (2430) receives a query item of the above form, compares the query item with the learned data, calculates the classification probability of the personal information item, and proposes the personal information item with the highest probability among the calculation results.

[1056] The processor (2430) receives the contents of the form, compares the entered contents with the learned data, calculates the distance, and proposes the personal information processing purpose of the closest distance among the calculation results.

[1057] Figure 27 is a diagram illustrating an example of personal information verification according to the present disclosure.

[1058] Personal information verification is explained with reference to Figure 27 (2710).

[1059] Receive a response input from the personal information subject (S10).

[1060] The processor (2430) determines the format of the personal information entered in the response and transmits it (S20).

[1061] The processor (2430) checks whether the format is in the correct normalization format (S30).

[1062] If the data conforms to the normalization format, the processor (2430) determines that it is normal data and receives an answer (S40).

[1063] If the data does not conform to the normalization format, the processor (2430) determines that it is abnormal data and returns the input (S50).

[1064] Figure 28 is a diagram illustrating the setting of destruction information and execution of a scheduler according to the present disclosure.

[1065] Referring to Fig. 28 (2810), the destruction information setting is described.

[1066] The processor (2430) receives a response value for the response value of the template from the user.

[1067] The processor (2430) sets the destruction date and retention period information for the response.

[1068] The processor (2430) stores the destruction date and retention period information for the set answer in memory.

[1069] Referring to FIG. 28 (2810), scheduler execution is described.

[1070] The processor (2430) operates the system scheduler.

[1071] The processor (2430) distinguishes the data to be destroyed from the entire data through the destruction date.

[1072] The processor (2430) destroys the answer value, connection file, etc. through the separated destruction data.

[1073] The processor (2430) deletes consent history and advertising information through the separated destruction data.

[1074] The processor (2430) deletes the separated destruction data.

[1075] Figure 29A is a diagram illustrating a flowchart of a personal information management automation method according to the present disclosure.

[1076] Referring to FIG. 29A (2910), the processor (2430) controls the personal information subject to access a site provided by a personal information service provider (SP) (S1).

[1077] The processor (2430) verifies the identity of the personal information subject through an authentication process (S2). The authentication process includes at least one of joint authentication, simple authentication, email authentication, text authentication, QR authentication, two-channel authentication, and financial authentication.

[1078] The processor (2430) controls the personal information subject to call up the history to which he / she has consented using the personal information management standard protocol (S3).

[1079] For example, the processor (2430) can call the process of calling the consent history step by step, such as step 1, step 2, step 3, step 4, and step 5, using the personal information management standard protocol.

[1080] The processor (2430) visualizes the personal information usage status of the personal information subject obtained through the personal information management standard protocol (S4).

[1081] For example, the processor (2430) can visualize the scope of consent, PI third party.

[1082] The processor (2430) can maintain, reset, and retrieve personal information usage status.

[1083] The processor (2430) controls the personal information subject to entrust the management of his / her personal information (Personal Information, PI) to a personal information service provider (SP) (S5).

[1084] The processor (2430) controls the personal information service provider (SP) to report a change in the status of the personal information (PI) to the personal information subject (S6).

[1085] The processor (2430) controls the personal information service provider (SP) to report changes in the status of the personal information to the personal information subject at a predetermined periodic interval.

[1086] Here, the specified cycle can be 3 months, 6 months, or 1 year.

[1087] The processor (2430) controls the personal information service provider (SP) to report changes in the status of the personal information to the personal information subject on a case-by-case basis.

[1088] If the authentication status is confirmed from an external device that the user has not accessed within a predetermined period of time, the processor (2430) determines that a change in the status of the personal information has occurred and reports this to the personal information subject.

[1089] FIG. 29B is a diagram illustrating an example of visualizing the scope of consent according to the present disclosure.

[1090] Referring to Figure 29B (2920), the items include the name of the institution, purpose of consent, personal information items, date of consent, expiration date of retention and use period, input values ​​and consent contents, withdrawal of consent to receive advertising information, and withdrawal of consent to processing personal information.

[1091] A confirmation icon is displayed in the input value and consent section.

[1092] A withdrawal icon is displayed in the consent section for receiving promotional information.

[1093] The section for withdrawing consent to personal information processing displays an icon for withdrawing full consent.

[1094] Confirmation icons, withdrawal icons, and full consent withdrawal icons can be displayed in different colors depending on the properties of the icons.

[1095] For example, the confirmation icon may be displayed in purple. The withdrawal icon, or the full consent withdrawal icon, may be displayed in red.

[1096] FIG. 29C is a diagram illustrating an embodiment of PI third-party visualization according to the present disclosure.

[1097] Referring to Figure 29C (2930), A personal information processor is interconnected with B personal information processor / trustee / Korea, C personal information processor / third party provider / US, and D personal information processor / trustee / US.

[1098] For example, A personal information processor sends email marketing, name, and email to B personal information processor / trustee / Korea.

[1099] B Personal information processor / trustee / Korea checks the history of violations of personal information regulations and, if yes, checks the relevant details.

[1100] A personal information processor transmits data analysis purchase history and customer number to C personal information processor / third party provider / US.

[1101] C Personal information processor / third party provider / US checks for violations of personal information regulations.

[1102] A personal information processor sends the delivery name and email to D personal information processor / consignee / Korea.

[1103] D Personal information processor / trustee / Korea checks the history of violation of personal information regulations.

[1104] Figure 30 is a diagram illustrating a flowchart of a method of utilizing personal information according to the present disclosure.

[1105] Referring to FIG. 30, the present invention is performed by a personal information utilization device (2400) or a processor (2430) of the personal information utilization device (2400).

[1106] The processor (2430) maps the content to be processed according to country, industry, and business type with respect to the contract contents between the service provider and the third party included in the first data collected through the input module (2410) (S3010).

[1107] When a data subject provides personal information, the processor (2430) classifies the personal information by applying a classification model to the mapped content according to the contract type corresponding to the contract content (S3020).

[1108] The processor (2430) requests storage of the classified personal information (S3030).

[1109] The processor (2430) transmits the personal information to the third party's device according to the contract contents (S3040).

[1110] If the purpose of use of the personal information is changed, the processor (2430) transmits a first message including a request for consent to the change in purpose of use to the device of the information subject (S3050).

[1111] When the processor (2430) receives a second message including consent to the change in the purpose of use from the data subject's device, it uses the personal information with the changed purpose of use (S3060).

[1112] Figure 31 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1113] In the process of transferring personal information to a third party in Figure 31 (3110), the method of obtaining consent from the information subject for a change in purpose and utilizing the information is specifically explained.

[1114] Figure 32 is a diagram illustrating a flowchart 1 of a method of utilizing personal information according to the present disclosure.

[1115] Flowchart 1 of Fig. 32 is connected to flowchart 2 of Fig. 33.

[1116] The personal information utilization system consists of a data subject device (3210), a personal information utilization device (3220), and a trustee device (3230). The trustee device (3230) includes a third-party device.

[1117] The personal information utilization device (3220) performs the same function as the personal information utilization device (2400) of the present invention described above.

[1118] The personal information utilization device (3200) includes a client mapping function unit (3221) and a customer information distribution function unit (3222) by customer type.

[1119] The present invention enables the processor (2430) to perform the functions of a client mapping function unit (3221) and a customer type-specific customer information distribution function unit (3222).

[1120] The information subject device (3210) transmits a signal including a third-party provider registration and invitation request to the client mapping function (3221).

[1121] The client mapping function (3221) transmits a request signal including a third-party provider contract request to the trustee device (3230).

[1122] The trustee device (3230) transmits a request signal including a company registration and contract request to the client mapping function (3221).

[1123] The client mapping function (3221) performs contract-to-contract company mapping processing.

[1124] The client mapping function (3221) maps the contents of contracts between service providers and third parties to be processed according to country, industry, and business type.

[1125] The information subject device (3210) transmits personal information to the client mapping function (3221).

[1126] The client mapping function (3221) verifies the company and contract type based on the received personal information.

[1127] When the client mapping function receives personal information from the information subject device (3210), it classifies the personal information by applying a classification model to the mapped content according to the contract type corresponding to the contract content.

[1128] The client mapping function unit (3221) transmits a request signal including a request for storing agreed personal information to the customer information distribution function unit (3222) by customer type.

[1129] The customer information distribution function (3222) by customer type stores personal information by contract type in memory.

[1130] The customer information distribution function (3222) by customer type transmits the agreed personal information to the trustee device (3230).

[1131] The customer information distribution function (3222) by customer type transmits a message including instructions on how to withdraw consent history to the information subject device (3210).

[1132] The trustee device (3230) transmits a message including a change in the purpose of use of personal information to the client mapping function (3221).

[1133] The client mapping function (3221) transmits a message containing a change in the purpose of use of a third-party provider to the information subject device (3210).

[1134] Figure 33 is a diagram illustrating a flowchart 2 of a method of utilizing personal information according to the present disclosure.

[1135] The client mapping function (3221) transmits a first message including a request for consent to change the purpose of use to the information subject device (3210).

[1136] If the information subject device (3210) agrees to a change in the purpose of use, it transmits a second message including the agreement to the change in purpose of use to the client mapping function unit (3221).

[1137] The client mapping function (3221) transmits a request signal including a request for distribution and storage of personal information that has agreed to a change in purpose to the customer information distribution function (3222) by customer type.

[1138] The customer information distribution function (3222) by customer type stores personal information by purpose type in memory.

[1139] The customer information distribution function (3222) by customer type transmits personal information that has agreed to a change in purpose to the trustee device (3230).

[1140] According to the present invention, personal information can be used for purposes that have changed.

[1141] The customer information distribution function (3222) by customer type transmits a message including instructions on how to withdraw consent history to the information subject device (3210).

[1142] Figure 34 is a diagram illustrating an example in which the purpose of use of personal information according to the present disclosure has changed.

[1143] Referring to FIG. 34, in one embodiment of the present invention, a case where the purpose of use of personal information has changed may mean a case where the purpose has changed from the first purpose to the second purpose when conducting a clinical trial at a medical institution.

[1144] Here, the first purpose means the purpose of analyzing the effect of a specific drug.

[1145] The second purpose refers to the purpose of studying the side effects of the above specific drug.

[1146] According to one embodiment of the present invention, the purpose of use of personal information may be changed.

[1147] For example, if a person participating in a clinical trial at a hospital initially consents to providing personal information, but the purpose of using the information later changes, the procedure for obtaining consent is explained.

[1148] This is the process of changing the purpose of use of personal information of clinical trial participants.

[1149] Initial consent

[1150] 1. Participation in clinical trials

[1151] Person A decides to participate in a clinical trial at a hospital and signs a consent form for the provision of personal information. This consent form states that his personal information will be used for clinical trial data analysis purposes.

[1152] 2. Fill out the consent form

[1153] Person A signs a consent form for providing personal information, and the hospital keeps this on record.

[1154] A change in purpose of use occurs.

[1155] 3. Notification of change of purpose

[1156] While the clinical trial is ongoing, the hospital intends to use Mr. A's personal information for new research purposes. For example, while initially intended to analyze the effects of a specific drug, the purpose has now shifted to studying its long-term side effects.

[1157] 4. Notification of Changes

[1158] The hospital clearly explains to Mr. A the changed purpose of use. It specifically explains the purpose, reason, and need for new research.

[1159] 5. Request for consent

[1160] The hospital asks Mr. A for consent to the changed purpose of use. This process is explained in clear and concise language so that Mr. A can fully understand it.

[1161] 6. Confirm consent

[1162] Person A decides whether to consent to the changes. Consent can be obtained in various ways, including in writing, by electronic signature, by email, or by text message.

[1163] 7. Record keeping

[1164] The hospital records and retains Mr. A's consent. This can be used as evidence in case problems arise later.

[1165] Through this procedure, the hospital can protect the rights of data subject A when the purpose of use of personal information changes.

[1166] According to one embodiment of the present invention, the scope and purpose of use of personal information may be changed.

[1167] 1. Consent of the data subject

[1168] Separate consent must be obtained from the data subject (personal information subject) for any changed scope of use and purpose.

[1169] 2. Legal basis

[1170] If there are special provisions in other laws, it may be processed in accordance with those laws.

[1171] 3. Emergency situations:

[1172] In urgent situations where the consent of the data subject cannot be obtained (e.g., when necessary to protect life, body, or property), it may be processed exceptionally.

[1173] In addition, the data subject must be clearly notified of any changed scope and purpose of use of personal information, and additional protective measures must be taken if necessary.

[1174] The procedure for obtaining separate consent when the scope and purpose of use of personal information changes is as follows.

[1175] 1. Notification of changes

[1176] If the scope and purpose of personal information use changes, the data subject must be clearly informed of the changes. The reason for the change and the new scope and purpose of use must be specifically disclosed.

[1177] 2. Request for consent

[1178] Request the data subject's consent for any changes. This process must be explained in clear and concise language so that the data subject can fully understand the changes.

[1179] 3. Confirm consent

[1180] Confirm that the data subject agrees to the changes. Consent can be obtained in various ways, including in writing, via electronic signature, email, or text message.

[1181] 4. Record keeping

[1182] Record and retain the consent you received. This can serve as evidence in case problems arise later.

[1183] This procedure protects the rights of data subjects when the scope and purpose of use of personal information change.

[1184] FIG. 35 is a diagram illustrating an example of obtaining consent from a data subject when the purpose of use according to the present disclosure is changed.

[1185] Referring to FIG. 35, the processor (2430) transmits a first message containing changes to the information subject device (S3510).

[1186] The processor (2430) receives a second message including consent to the change from the information subject device (S3520).

[1187] The processor (2430) confirms whether the information subject agrees to the changed content (S3530).

[1188] The processor (2430) stores the verification result in memory (S3540).

[1189] Explains the authentication process.

[1190] The processor (2430) confirms the consent of the information subject using at least one of a written document, electronic signature, email, and text message.

[1191] According to one embodiment of the present invention, there may be special provisions in other laws.

[1192] If the purpose of use of the personal information changes and there are special provisions in other laws, the processor (2430) uses the personal information in accordance with the special provisions.

[1193] According to one embodiment of the present invention, an emergency situation may occur.

[1194] The processor (2430) exceptionally uses the personal information when the purpose of use of the personal information changes or an emergency situation occurs.

[1195] The processor (2430) determines the emergency situation as a case where it is necessary to protect at least one of the life, body, and property of the information subject.

[1196] According to one embodiment of the present invention, the user can be expanded with respect to consent to change of purpose of use.

[1197] For example, if a customer's personal information is collected for Electronics Company A, the scope of use may be expanded to include A Life & Health Company and A Chemical Company, which are affiliates of Electronics Company A.

[1198] FIG. 36 is a diagram illustrating an embodiment of converting a first message according to the present disclosure into clear and concise language.

[1199] Referring to FIG. 36 (3610), if the purpose of use of the personal information is changed, the processor (2430) converts and rewrites the first message including a request for consent to the change in purpose of use into a preset language.

[1200] For example, the processor (2430) rewrites a first message containing a request for consent to a change in purpose of use by converting it into a preset language, i.e., a clear and concise language.

[1201] In the case of Chinese characters, they are converted into Hangul.

[1202] For English, convert to Korean.

[1203] For specialized medical terms, they are converted into easy Korean terms.

[1204] For example, it explains the conversion of difficult terms within consent request messages.

[1205] Inhalation is converted into exhalation.

[1206] The will is converted into artificial limbs (prosthetic arms, legs).

[1207] Gas free is converted to remove gas.

[1208] Tenant is converted into tenant.

[1209] AOM is converted into Airport Operations Regulation (AOM).

[1210] The notice period is converted between air and ground.

[1211] Figure 37 is a diagram illustrating a flow chart of a method for creating a personal information flow map according to the present disclosure.

[1212] The present invention is performed by a personal information flow map creation device (2400) or a processor (2430) of the personal information flow map creation device.

[1213] The processor (2430) registers the personal information and consent to the personal information included in the first data collected through the input module (2410) into the system (S3710).

[1214] The processor (2430) transmits the personal information and consent to the personal information to the personal information processing server (S3720).

[1215] The processor (2430) registers the history of the above personal information in the system (S3730).

[1216] The processor (2430) transmits the result of completing the history registration of the personal information to the data subject device (S3740).

[1217] When the processor (2430) receives a first message including a search for the consent history of the personal information and a search for the usage status of the personal information from the data subject device, it generates a report on the consent history of the personal information and the usage status of the personal information (S3750).

[1218] The processor (2430) transmits the consent history of the generated personal information and the report on the usage status of the personal information to the information subject device (S3760).

[1219] Figure 38 is a drawing illustrating the core concept of the present invention according to the present disclosure.

[1220] In Fig. 38 (3810), a method for creating a personal information flow map for a personal information subject is specifically described.

[1221] Figure 39 is a diagram illustrating a flowchart 1 of a method for creating a personal information flow map according to the present disclosure.

[1222] Flowchart 1 of Fig. 39 is connected to flowchart 2 of Fig. 40.

[1223] The present invention is composed of an information subject device (3910), a personal information flow map creation device (3920), and a personal information processing server (3930).

[1224] The personal information flow map creation device (3920) includes a personal information collection function unit first server (3921) and a personal information standard management function unit second server (3922).

[1225] The personal information collection function department's first server (3921) performs the personal information collection function.

[1226] The personal information standard management function department's second server (3922) performs the personal information standard management function.

[1227] The processor (2430) of the personal information flow map creation device (2400) performs detailed functions of the personal information collection function unit 1 server (3921) and the personal information standard management function unit 2 server (3922).

[1228] The information subject device (3910) transmits first data including personal information and consent to personal information to the personal information collection function first server (3921).

[1229] The Personal Information Standard Management Function Department's second server (3922) registers personal information and consent to personal information using standard protocols. Specifically, it registers personal information and consent to personal information using rules that conform to the standard protocol.

[1230] Here, the standard protocols include ISO standards, ISO / IEC 29184: International Standard for Obtaining Consent for Personal Information, and ISO 29100: International Standard for a Privacy Framework.

[1231] The personal information standard management function department's second server (3922) encrypts the personal information and the consent to the personal information in a keychain suitable for the standard protocol according to the rules of the standard protocol and registers it in the system.

[1232] According to one embodiment of the present invention, registration can be made in a form that can be accessed regardless of the type of device.

[1233] The personal information standard management function department's second server (3922) registers the above personal information and consent to the above personal information in a form that can be accessed regardless of the type of device.

[1234] The personal information standard management function department's second server (3922) transmits personal information and personal information consent to the personal information processing server (3930).

[1235] The personal information standard management function department's second server (3922) transmits personal information and personal information consent to the personal information processing server (3930) along with a keychain suitable for the standard protocol.

[1236] The personal information standard management function department's second server (3922) registers the personal information history in the system and transmits the result of the personal information history registration completion to the personal information collection function department's first server (3921).

[1237] The personal information standard management function department's second server (3922) transmits the result of completing the personal information history registration to the information subject device (3910).

[1238] The Personal Information Standard Management Function Department's second server (3922) registers third-party and consignment keychains in the system.

[1239] Figure 40 is a diagram illustrating a flowchart 2 of a method for creating a personal information flow map according to the present disclosure.

[1240] Referring to Figure 40, the information subject device (3910) transmits a message including a personal information consent history inquiry and a personal information use status inquiry to the personal information standard management function second server (3922).

[1241] The personal information standard management function department's second server (3922) transmits the personal information consent history and usage status report to the information subject device (3910).

[1242] The information subject device (3910) transmits a second message including a request for withdrawal of consent to personal information to the personal information standard management function second server (3922).

[1243] The personal information standard management function department's second server (3922) transmits a request signal requesting withdrawal of consent to personal information to the personal information processing server (3930).

[1244] The personal information standard management function department's second server (3922) transmits a request signal requesting withdrawal of consent to personal information to the personal information processing server (3930).

[1245] The personal information processing server (3930) transmits a message including the result of withdrawal of consent to personal information to the personal information standard management function second server (3922).

[1246] The personal information standard management function department's second server (3922) generates a personal information withdrawal result report and transmits the generated personal information withdrawal result report to the information subject device (3910).

[1247] The Personal Information Standard Management Function Department's second server (3922) destroys personal information and keychains.

[1248] An embodiment of destroying personal information and a keychain related to personal information is described.

[1249] The processor (2430) destroys all personal information and keychains associated with the personal information.

[1250] According to one embodiment of the present invention, personal information and keychain can be automatically destroyed after a predetermined period of time has elapsed.

[1251] The processor (2430) automatically destroys personal information and keychains related to personal information after a preset period of time has elapsed. The preset period may be six months, one year, or two years.

[1252] According to one embodiment of the present invention, personal information and keychains can be destroyed when the period prescribed by law has elapsed.

[1253] The processor (2430) automatically destroys personal information and key chains related to personal information when the period prescribed by law has elapsed.

[1254] Figure 41 is a drawing illustrating the basic concept of a keychain according to the present disclosure.

[1255] Referring to FIG. 41 (4110), a keychain refers to a storage that safely stores small data on behalf of a user.

[1256] Users have data that needs to be kept secure. For example, many people manage numerous online accounts, including login information.

[1257] The Keychain Services API provides apps with a mechanism to store small bits of user data in an encrypted database called a Keychain.

[1258] Keychains can store multiple items, such as credit card information or short notes, or items that users may need but don't know about.

[1259] For example, it stores encryption keys managed by certificates, keys, and trust services.

[1260] To use a keychain item, you create a package with data that needs to be stored secretly and attributes that are made public to access this data.

[1261] Referring to Figure 41 (4110), data to be kept confidential is encrypted, packaged, and stored in a keychain storage. Of course, data can be retrieved using attributes, in which case the encrypted data is decrypted and retrieved.

[1262] All these encryption processes are managed by the system using the Keychain API.

[1263] Figure 42 is an example of creating a visualized report on the personal information consent history and personal information usage status according to the present disclosure.

[1264] Referring to FIG. 42 (4210), the processor (2430) generates a report on the consent history of the personal information and the status of use of the personal information by visualizing it based on at least one of a graph, chart, map, and diagram.

[1265] When the purpose of visualization is to focus on comparison, the processor (2430) visualizes a report on the personal information consent history and personal information usage status based on at least one of a bar chart, a group bar chart, and a bubble chart.

[1266] When the purpose of visualization is to focus on changes in data over time, the processor (2430) visualizes a report on the history of consent to personal information and the status of use of personal information based on at least one of a line chart, an area chart, and a timeline chart.

[1267] The various embodiments of the present disclosure are not intended to list all possible combinations but rather to illustrate representative aspects of the present disclosure, and the matters described in the various embodiments may be applied independently or in combinations of two or more.

[1268] The above-described program may include codes coded in a computer language, such as C, C++, JAVA, or machine language, that can be read by the processor (CPU) of the computer through the device interface of the computer, so that the computer reads the program and executes the methods implemented as a program. Such codes may include functional codes related to functions that define functions necessary for executing the methods, and may include control codes related to execution procedures necessary for the processor of the computer to execute the functions according to a predetermined procedure. In addition, such codes may further include memory reference-related codes regarding which location (address address) of the internal or external memory of the computer should reference additional information or media necessary for the processor of the computer to execute the functions. In addition, if the processor of the computer needs to communicate with any other computer or server located remotely in order to execute the functions, the code may further include communication-related code regarding how to communicate with any other computer or server located remotely using the communication module of the computer, and what information or media to send and receive during communication.

[1269] The above storage medium refers to a medium that stores data semi-permanently and can be read by a device, rather than a medium that stores data for a short period of time, such as a register, cache, or memory. Specifically, examples of the storage medium include, but are not limited to, ROM, RAM, CD-ROM, magnetic tape, floppy disk, and optical data storage device. That is, the program can be stored in various recording media on various servers that the computer can access or in various recording media on the user's computer. In addition, the medium can be distributed across network-connected computer systems, so that computer-readable code can be stored in a distributed manner.

[1270] The steps of a method or algorithm described in connection with the embodiments of the present disclosure may be implemented directly in hardware, implemented as a software module executed by hardware, or implemented by a combination thereof. The software module may reside in a random access memory (RAM), a read only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, a hard disk, a removable disk, a CD-ROM, or any other form of computer-readable recording medium well known in the art to which the present disclosure pertains.

[1271] While the embodiments of the present disclosure have been described with reference to the attached drawings, those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without altering the technical spirit or essential features thereof. Therefore, the embodiments described above should be understood to be illustrative in all respects and not restrictive.

Claims

1. An input module that collects first data including a sentence entered by a personal information handler; A communication module for transmitting and receiving the first data with an external device including a mobile device; A memory storing at least one process for automating personal information management; Including a processor that controls the operation according to the above process, The above processor, Find items that are likely to collect personal information in the sentences included in the first data collected through the input module and classify the personal information, Based on the title and content of the form entered by the user above, the purpose of personal information processing is proposed. Depending on the security level of the personal information handler, determine whether to allow the personal information handler to access the system. Control access according to the role and authority of the personal information handler based on the above decision result, We record logs of the processing of the above personal information, Establish a policy for destruction of the above personal information, Deleting or separating the personal information in accordance with the established destruction policy; Automated personal information management device.

2. In the first paragraph, the processor, Enter the query items in the above form, By comparing the above query items with the learned data, the classification possibility of personal information items is calculated. Suggesting the personal information item with the highest probability among the above calculation results, Automated personal information management device.

3. In the first paragraph, the processor, Enter the contents of the above product, Compare the input information above with the learned data to calculate the distance, Propose the personal information processing purpose that is closest to the above calculation results. Automated personal information management device.

4. In the first paragraph, the processor, Controls the personal information subject's access to the site provided by the personal information service provider (hereinafter referred to as SP). The identity of the above personal information subject is confirmed through the authentication process, Controls the above personal information subject to call up the history to which he / she has consented by using the personal information management standard protocol, Visualizing the status of personal information usage of the personal information subject obtained through the above personal information management standard protocol. Automated personal information management device.

5. In paragraph 4, the authentication process is as follows: Including at least one of joint authentication, simple authentication, and financial authentication. Automated personal information management device.

6. In the fourth paragraph, the processor, The above personal information subject controls the management of his / her personal information (Personal Information, PI) to a personal information service provider (SP). Controlling the above personal information service provider (SP) to report changes in the status of the above personal information (PI) to the personal information subject; Automated personal information management device.

7. In the 6th paragraph, the processor, Controlling the above personal information service provider (SP) to report changes in the status of the above personal information to the personal information subject at regular intervals; Automated personal information management device.

8. In the 6th paragraph, the processor, Controlling the above personal information service provider (SP) to report changes in the status of the above personal information to the personal information subject on a case-by-case basis; Automated personal information management device.

9. In paragraph 8, the processor If the authentication status is confirmed from an external device that the user has not accessed within a specified period of time, it is determined that a change in the status of the personal information has occurred and this is reported to the personal information subject. Automated personal information management device.

10. In the first paragraph, the processor, When a user provides personal information, the personal information is classified by applying a classification model to the mapped content according to the contract type corresponding to the contract content. Request storage of the classified personal information above, In accordance with the above contract terms, the above personal information is transmitted to the third party's device, If the purpose of use of the above personal information changes, a first message including a request for consent to the change in purpose of use is sent to the data subject's device, If a second message including consent to the change in the purpose of use is received from the data subject's device, the personal information will be used for the changed purpose of use. Automated personal information management device.

11. In Article 10, The above change in purpose of use refers to a change from the first purpose to the second purpose when conducting a clinical trial at a medical institution. Automated personal information management device.

12. In paragraph 11, The above first purpose means the purpose of analyzing the effect of a specific drug, The second purpose above means the purpose of studying the side effects of the specific drug. Automated personal information management device.

13. In the first paragraph, the processor, Registering personal information included in the first data collected through the input module and consent to the personal information in the system. Automated personal information management device.

14. In the 13th paragraph, the processor The above personal information and the consent to the above personal information are registered in the system by encrypting the keychain suitable for the above standard protocol with rules suitable for the above standard protocol. Automated personal information management device.

15. In a method for automating personal information management performed by a device, A step of collecting first data including a sentence entered by a personal information handler through an input module; A step of finding items that are likely to collect personal information in the collected sentences and classifying the personal information; A step for proposing the purpose of personal information processing based on the title and contents of the form entered by the personal information handler; A step for determining whether to allow the personal information handler to access the system based on the personal information handler's security level; A step for controlling access according to the role and authority of the personal information handler based on the above decision result; Step of recording a log of processing the above personal information; Step for establishing a policy for destruction of the above personal information; and Including the step of deleting or separating the personal information according to the established destruction policy. How to automate personal information management.

Citation Information

Patent Citations

  • Personal information management system

    JP2023121093A

  • Method and system for protecting individual information based on public key infrastructure and privilege management infrastructure

    KR101208771B1

  • Novel Peptide Having Activity of Improving Skin Condition and Uses Thereof

    KR1020250025549A

  • Method and apparatus for receiving hybrid waveform signal based on bi-level pulse position modulation

    KR102327440B1

  • KR20220146048A