개인정보 삭제권 시대의 도래 Delete Act가 미국·한국 기업에 던지는 새로운 법적 책임
개인정보 삭제권 시대의 도래
Delete Act가 미국·한국 기업에
던지는 새로운 법적 책임
The Age of the Right to Delete:
New Legal Accountability for U.S.
and Korean Businesses Under the Delete Act
Meta·Google·Equifax·Clearview AI. 실제 소송에서 기업들이 지불한 대가는 수억 달러였습니다. Delete Act는 그 다음 챕터입니다.
Meta. Google. Equifax. Clearview AI. The price these companies paid in actual litigation ran into hundreds of millions of dollars. The Delete Act is the next chapter.
- 개인정보는 이제 기업의 자산이 아니라 법적 책임(Legal Liability)입니다
- Delete Act는 한 번 삭제하고 끝나는 법이 아니라 45일마다 반복 삭제를 요구하는 지속 의무입니다
- 삭제해도 문제(증거 훼손), 거부해도 문제(규제 위반) — 두 의무 사이의 균형이 핵심입니다
- Meta·Google·Equifax·Clearview AI 실제 소송 — 수억 달러가 걸린 선례들
- 한국 기업도 미국 소비자를 상대하면 캘리포니아·텍사스 개인정보법이 적용될 수 있습니다
언론은 Delete Act를 "개인정보를 한 번에 삭제할 수 있는 법"이라고 소개합니다. 그러나 미국 기업법을 다루는 변호사의 시각에서 보면, 이번 법의 의미는 그보다 훨씬 큽니다. Delete Act는 단순히 소비자에게 새로운 권리를 부여한 법이 아닙니다. 기업이 개인정보를 수집하고, 보관하며, 공유하고, 삭제하는 전 과정에 대해 법적 책임(Accountability)을 요구하는 새로운 기준입니다.
개인정보는 '자산'이 아니라 '법적 책임'이 되었습니다
과거 기업들은 고객 정보를 많이 확보할수록 경쟁력이 높아진다고 생각했습니다. 회원정보가 많을수록 마케팅이 쉬워지고, 광고 수익도 증가하며, 기업가치도 높아질 것이라는 인식이 일반적이었습니다. 그러나 최근 미국의 법률 환경은 완전히 달라지고 있습니다.
"정보를 많이 보유하는 것이 경쟁력이었던 시대에서, 불필요한 정보를 얼마나 적절하게 관리하고 삭제하는지가 기업 경쟁력이 되는 시대로 변화하고 있습니다."
기업이 보유한 개인정보는 이제 자산인 동시에 잠재적인 법적 위험(Legal Liability)이 되었습니다. 고객 정보가 유출되면 기업은 단순한 평판 하락을 넘어 규제기관 조사, 소비자 집단소송(Class Action), 계약상 손해배상, 그리고 투자자 책임 문제까지 직면할 수 있습니다. 이것은 이론이 아닙니다. 실제 판례가 증명합니다.
실제 소송이 말해주는 것 — 수억 달러의 선례들
Delete Act가 등장한 배경을 이해하려면, 미국에서 이미 반복되고 있는 개인정보 소송의 현실을 먼저 봐야 합니다. 개인정보 침해는 단순한 IT 사고가 아닙니다. 기업가치, 주주 책임, 규제 조사, 집단소송, 브랜드 신뢰도까지 동시에 영향을 미치는 기업의 핵심 법률 리스크입니다.
Delete Act의 핵심은 '삭제'가 아니라 '지속적인 관리'입니다
8월 1일부터 캘리포니아에서는 Delete Act에 따른 개인정보 삭제 절차가 본격적으로 시행됩니다. 소비자는 주정부가 운영하는 DROP(Data Broker Requests and Opt-Out Platform)을 통해 단 한 번의 신청만으로 여러 데이터 브로커에게 개인정보 삭제를 요청할 수 있습니다. 이미 수십만 명의 캘리포니아 주민이 삭제를 신청한 것으로 알려져 있습니다.
그러나 기업이 주목해야 하는 부분은 따로 있습니다. Delete Act는 한 번 삭제하고 끝나는 제도가 아닙니다. 삭제 요청 이후에도 새롭게 수집되는 개인정보를 지속적으로 관리해야 하며, 동일 소비자의 개인정보를 45일마다 반복적으로 삭제해야 합니다. 이는 기업이 사용하는 CRM, 이메일 마케팅 시스템, 광고 플랫폼, 클라우드 서버, 분석도구 등 전체 데이터 생명주기(Data Lifecycle)를 다시 점검해야 한다는 의미입니다.
진짜 법적 위험 — 삭제해도 문제, 안 해도 문제
실무상 기업들이 가장 많이 오해하는 부분이 있습니다. "삭제 요청이 오면 삭제하면 된다"는 생각입니다. 그러나 미국에서 개인정보 분쟁은 그렇게 단순하지 않습니다.
기업이 소송을 예상하거나 이미 분쟁이 진행 중인 상황에서 관련 자료를 삭제한다면, 미국 법원은 이를 Spoliation of Evidence(증거 훼손)로 판단할 가능성이 있습니다. 법원은 이러한 경우 해당 증거가 기업에 불리한 내용을 담고 있었다고 추정(Adverse Inference)하거나, 소송에서 제재(Sanctions)를 가할 수 있습니다.
반대로 소비자의 삭제 요청을 적법한 이유 없이 거부하거나, 개인정보 처리방침에는 "일정 기간 후 삭제"라고 적어놓고 실제로는 수년간 보관하고 있었다면, 규제기관 조사와 민사소송의 대상이 될 수 있습니다. Google이 위치정보 설정과 실제 수집 간의 불일치로 3억 9,100만 달러를 합의한 사례가 대표적입니다.
한국 기업도 예외가 아닙니다
많은 한국 기업들은 "우리는 한국 회사니까 미국 개인정보법은 적용되지 않는다"고 생각합니다. 그러나 실제 미국법은 그렇게 단순하지 않습니다. 미국 소비자에게 상품을 판매하고, 회원가입을 받고, 뉴스레터를 보내며, 온라인 광고를 운영한다면 캘리포니아 소비자의 개인정보를 처리하는 사업자로 평가될 가능성이 있습니다.
AI 시대, 개인정보 리스크는 더욱 커지고 있습니다
최근 기업들은 ChatGPT를 비롯한 생성형 AI를 업무에 적극 활용하고 있습니다. 그러나 직원이 고객 정보를 AI 서비스에 입력하는 순간 새로운 법적 문제가 발생할 수 있습니다. Clearview AI 사례는 AI와 개인정보가 결합할 때 얼마나 심각한 법적 결과가 발생할 수 있는지를 보여주는 대표적인 사례입니다. 이제 기업은 AI 사용 정책, 직원 접근 권한, 데이터 보존 기간, 외부 벤더 계약, 개인정보 삭제 절차까지 포함한 종합적인 컴플라이언스 체계를 갖추어야 합니다.
지금 점검해야 할 것들
불일치가 있다면 지금이 정리할 시점입니다.
변호사의 법률 분석 — 경영 패러다임의 변화입니다
캘리포니아, 유타, 텍사스에서 기업법무와 민사소송 업무를 수행하면서 공통적으로 느끼는 점은 분명합니다. 대부분의 기업은 개인정보를 수집하는 방법에는 익숙하지만, 언제 삭제해야 하는지, 무엇을 보존해야 하는지에 대해서는 아직 충분한 준비가 되어 있지 않습니다.
Delete Act는 개인정보 보호법의 변화가 아니라 기업 경영 패러다임의 변화를 의미합니다. 앞으로 기업의 경쟁력은 얼마나 많은 개인정보를 보유하고 있는지가 아니라, 개인정보를 얼마나 투명하고 안전하며 법률에 맞게 관리할 수 있는가에 의해 평가될 가능성이 높습니다.
공식 출처 및 참고자료
지금 점검하시겠습니까?
면책 조항 — 본 칼럼에 소개된 판례 정보는 공개된 자료를 바탕으로 작성된 것이며, 특정 사건의 법적 결론을 단정하지 않습니다. 본 칼럼은 일반적인 법률 정보를 제공하기 위한 것으로, 개별 기업에 대한 법률 자문을 구성하지 않습니다. Law Office of Chris W. Chong · cchonglaw.com · CA · TX · UT
- Personal data is no longer just an asset — it is a Legal Liability for every business that holds it
- The Delete Act requires ongoing deletion every 45 days — not a one-time compliance action
- Both deleting and refusing to delete can create liability — managing the balance between these obligations is the legal challenge
- Meta · Google · Equifax · Clearview AI — hundreds of millions of dollars in real-world precedents
- Korean businesses serving U.S. consumers may be subject to California and Texas privacy law regardless of where they are incorporated
The media describes the Delete Act as a law that lets consumers "erase their personal data with one click." From the perspective of an attorney practicing business law in California, Utah, and Texas, this framing misses the more significant shift the law represents. The Delete Act is not simply a new consumer right. It is a new accountability standard — requiring businesses to demonstrate legal responsibility over the entire lifecycle of the personal information they collect, retain, share, and delete.
Personal Data Has Moved From Asset to Legal Liability
Businesses once operated on a straightforward premise: more customer data means better marketing, higher ad revenue, and greater enterprise value. That premise has been fundamentally disrupted by the legal environment that has emerged over the past decade in the United States.
"The competitive advantage no longer lies in how much personal data a business holds — it lies in how transparently, securely, and legally it manages the data it chooses to retain."
Personal data held by a business is now simultaneously an asset and a potential legal liability. A breach or misuse exposes a company to regulatory investigation, consumer class actions, contractual damages, and investor liability claims. This is not theoretical. The precedents are in the books — and the dollar figures are significant.
What Real Litigation Looks Like — Four Precedents Every Business Should Know
To understand why the Delete Act was enacted, it helps to look at what has already happened to businesses that failed to manage personal data responsibly. These are not cautionary tales from a distant legal era — they are recent precedents that define the legal environment your business operates in today.
The Delete Act: Ongoing Management, Not a One-Time Action
Beginning August 1, California's Delete Act deletion procedures take effect. Through the state-operated DROP platform, consumers can submit a single request to have their personal information deleted by all registered data brokers. Hundreds of thousands of California residents have already filed requests. But the provision businesses most need to understand is this: deletion is not a one-time event. After honoring a deletion request, data brokers must continue to delete newly collected information about the same consumer every 45 days. This requires a full review of every system that touches customer data — CRM platforms, email marketing tools, advertising systems, cloud storage, and analytics tools.
The Real Legal Risk — Liability on Both Sides
When litigation is reasonably anticipated or already underway, destroying relevant records — even in response to a deletion request — can constitute Spoliation of Evidence. Courts may impose sanctions, draw adverse inferences, or otherwise penalize the company. A deletion request does not create a blanket right to destroy records that are subject to a legal hold obligation.
Refusing a valid deletion request without legal justification, or retaining data beyond what your privacy policy promises, exposes the company to regulatory investigation and civil liability. Google's $391 million settlement arose precisely from the gap between what users believed about their settings and what data was actually being collected — a policy-versus-practice mismatch that regulators found to be deceptive.
Korean Businesses Are Not Exempt
A common assumption among Korean businesses serving U.S. markets is that U.S. state privacy law does not apply to them because they are incorporated in Korea. In practice, the applicable standard is not where a company is established — it is where the consumer is located and how their data is processed. A Korean online retailer that sells to California residents, collects their account information, and sends them marketing emails is likely processing California consumer personal information within the meaning of the CCPA.
What to Review Right Now
An Attorney's Perspective — A Paradigm Shift in Business Management
Having practiced business law and civil litigation in California, Utah, and Texas, the pattern is consistent: most businesses are familiar with how they collect personal information, but far less prepared on the questions of when to delete it, what to preserve, and how to demonstrate that their practices align with their stated policies. The Delete Act is not a technical amendment to privacy law. It is a signal that the competitive landscape has shifted — that the businesses best positioned going forward are those that manage personal data with the same rigor they apply to their financial records and contractual obligations.
Official Sources & References
for What Comes After the Delete Button?
Disclaimer — Case information presented in this column is drawn from publicly available records and is provided for illustrative purposes only. This column does not constitute legal advice or create an attorney-client relationship. Laws referenced are subject to amendment. For advice specific to your business, please consult a licensed attorney. Law Office of Chris W. Chong · cchonglaw.com · CA · TX · UT