개인정보 삭제권 시대의 도래 Delete Act가 미국·한국 기업에 던지는 새로운 법적 책임

개인정보 삭제권 시대의 도래 — Delete Act가 미국·한국 기업에 던지는 새로운 법적 책임 | Chris Chong 변호사
Law Office of Chris W. Chong
기업법무 · 개인정보 법률 칼럼 Business Law · Privacy Compliance Column
Delete Act
CCPA · TDPSA
📋 2026.08.01 시행
캘리포니아 Delete Act · DROP 플랫폼 본격 시행 — 수십만 명의 삭제 신청이 이미 접수됐습니다. 귀사는 준비되어 있습니까? California Delete Act & DROP Platform now in effect — Hundreds of thousands of deletion requests already filed. Is your business prepared?
기업법무 · 개인정보 법률 분석 · CA · TX · UT Business Law · Privacy Compliance · CA · TX · UT

개인정보 삭제권 시대의 도래
Delete Act가 미국·한국 기업에
던지는 새로운 법적 책임

The Age of the Right to Delete:
New Legal Accountability for U.S.
and Korean Businesses Under the Delete Act

정보 보유가 경쟁력이었던 시대는 끝났습니다. 이제는 왜 보유하는지, 언제 지워야 하는지를 증명해야 합니다.
Holding data was once a competitive advantage. Now, businesses must prove why they hold it — and when it must go.

Meta·Google·Equifax·Clearview AI. 실제 소송에서 기업들이 지불한 대가는 수억 달러였습니다. Delete Act는 그 다음 챕터입니다.

Meta. Google. Equifax. Clearview AI. The price these companies paid in actual litigation ran into hundreds of millions of dollars. The Delete Act is the next chapter.

CC
Chris Chong, Esq.
기업법무 · 민사소송 · CA · TX · UT Business Law · Civil Litigation · CA · TX · UT
2026.07
이 칼럼의 핵심 포인트
  • 개인정보는 이제 기업의 자산이 아니라 법적 책임(Legal Liability)입니다
  • Delete Act는 한 번 삭제하고 끝나는 법이 아니라 45일마다 반복 삭제를 요구하는 지속 의무입니다
  • 삭제해도 문제(증거 훼손), 거부해도 문제(규제 위반) — 두 의무 사이의 균형이 핵심입니다
  • Meta·Google·Equifax·Clearview AI 실제 소송 — 수억 달러가 걸린 선례들
  • 한국 기업도 미국 소비자를 상대하면 캘리포니아·텍사스 개인정보법이 적용될 수 있습니다

언론은 Delete Act를 "개인정보를 한 번에 삭제할 수 있는 법"이라고 소개합니다. 그러나 미국 기업법을 다루는 변호사의 시각에서 보면, 이번 법의 의미는 그보다 훨씬 큽니다. Delete Act는 단순히 소비자에게 새로운 권리를 부여한 법이 아닙니다. 기업이 개인정보를 수집하고, 보관하며, 공유하고, 삭제하는 전 과정에 대해 법적 책임(Accountability)을 요구하는 새로운 기준입니다.

개인정보는 '자산'이 아니라 '법적 책임'이 되었습니다

과거 기업들은 고객 정보를 많이 확보할수록 경쟁력이 높아진다고 생각했습니다. 회원정보가 많을수록 마케팅이 쉬워지고, 광고 수익도 증가하며, 기업가치도 높아질 것이라는 인식이 일반적이었습니다. 그러나 최근 미국의 법률 환경은 완전히 달라지고 있습니다.

"정보를 많이 보유하는 것이 경쟁력이었던 시대에서, 불필요한 정보를 얼마나 적절하게 관리하고 삭제하는지가 기업 경쟁력이 되는 시대로 변화하고 있습니다."

— Chris Chong, Esq. · 기업법무 · 민사소송 · CA · TX · UT

기업이 보유한 개인정보는 이제 자산인 동시에 잠재적인 법적 위험(Legal Liability)이 되었습니다. 고객 정보가 유출되면 기업은 단순한 평판 하락을 넘어 규제기관 조사, 소비자 집단소송(Class Action), 계약상 손해배상, 그리고 투자자 책임 문제까지 직면할 수 있습니다. 이것은 이론이 아닙니다. 실제 판례가 증명합니다.

실제 소송이 말해주는 것 — 수억 달러의 선례들

Delete Act가 등장한 배경을 이해하려면, 미국에서 이미 반복되고 있는 개인정보 소송의 현실을 먼저 봐야 합니다. 개인정보 침해는 단순한 IT 사고가 아닙니다. 기업가치, 주주 책임, 규제 조사, 집단소송, 브랜드 신뢰도까지 동시에 영향을 미치는 기업의 핵심 법률 리스크입니다.

실제 미국 개인정보 소송 사례
Meta (Facebook)
집단소송 2022년 합의 · FTC 행정합의 2019년
$725M
+ FTC $5B
Cambridge Analytica · 8,700만 명 데이터 무단 활용
약 8,700만 명의 Facebook 사용자 데이터가 사용자 동의 없이 제3자에 활용된 사건. Meta는 미국 이용자 집단소송에서 7억 2,500만 달러에 합의했으며, 이와 별도로 FTC와 50억 달러 규모의 개인정보 보호 관련 행정 합의를 체결했습니다. 민사책임과 규제 리스크가 동시에 현실화된 대표적 사례입니다.
시사점: 제3자 정보 공유 시 계약 조항과 내부 통제가 없으면, 집단소송과 규제 제재가 동시에 발생할 수 있습니다.
Google
40개 주 법무장관 합의 · 2022년 11월
$391.5M
합의금
위치기록 비활성화 후에도 위치정보 계속 수집
사용자가 위치기록(Location History)을 꺼도 Web & App Activity를 통해 위치정보를 계속 수집했다는 사실이 드러난 사건. 미국 40개 주 법무장관이 공동으로 합의를 이끌어냈으며, 개인정보 처리 방식의 투명성 개선도 함께 요구되었습니다.
시사점: 처리방침과 실제 데이터 수집 방식이 다를 때 발생하는 리스크. "설정에서 껐다"는 것이 수집 중단을 의미하지 않을 수 있습니다.
Equifax
2017년 유출 → 2019년 합의
$575M+
최대 $700M+
사이버 공격으로 1억 4,700만 명 신용정보 유출
미국 최대 신용정보 회사가 사이버 공격을 받아 이름·주민번호·운전면허번호 등 약 1억 4,700만 명의 정보가 유출됐습니다. FTC·CFPB·50개 주 법무장관과 최소 5억 7,500만 달러(최대 7억 달러 이상 가능)에 합의했습니다. 미국 사이버보안 컴플라이언스의 대표 판례입니다.
시사점: 보유한 데이터의 양만큼 보안 책임도 커집니다. 사이버 보안 실패는 단순 IT 사고가 아니라 기업 전체의 법적 생존을 위협합니다.
Clearview AI
BIPA 위반 합의 · 2022년
민간 판매
대규모 제한
수십억 장 사진 무단 수집 · 일리노이 BIPA 위반
인터넷상 수십억 장의 사진을 동의 없이 수집해 얼굴 인식 데이터베이스를 구축한 사건. 일리노이주 BIPA(Biometric Information Privacy Act) 위반으로, 합의 결과 미국 대부분의 민간기업에 얼굴 인식 데이터베이스를 판매·제공하는 행위가 크게 제한되었습니다. 미국 생체정보 개인정보 소송의 대표 판례입니다.
시사점: 금전 제재를 넘어 핵심 사업 모델 자체가 제한될 수 있습니다. AI·생체정보 수집은 특히 높은 법적 리스크를 수반합니다.

Delete Act의 핵심은 '삭제'가 아니라 '지속적인 관리'입니다

8월 1일부터 캘리포니아에서는 Delete Act에 따른 개인정보 삭제 절차가 본격적으로 시행됩니다. 소비자는 주정부가 운영하는 DROP(Data Broker Requests and Opt-Out Platform)을 통해 단 한 번의 신청만으로 여러 데이터 브로커에게 개인정보 삭제를 요청할 수 있습니다. 이미 수십만 명의 캘리포니아 주민이 삭제를 신청한 것으로 알려져 있습니다.

그러나 기업이 주목해야 하는 부분은 따로 있습니다. Delete Act는 한 번 삭제하고 끝나는 제도가 아닙니다. 삭제 요청 이후에도 새롭게 수집되는 개인정보를 지속적으로 관리해야 하며, 동일 소비자의 개인정보를 45일마다 반복적으로 삭제해야 합니다. 이는 기업이 사용하는 CRM, 이메일 마케팅 시스템, 광고 플랫폼, 클라우드 서버, 분석도구 등 전체 데이터 생명주기(Data Lifecycle)를 다시 점검해야 한다는 의미입니다.

캘리포니아
CCPA · CPRA · Delete Act
삭제권·열람권·정정권·판매 거부권. DROP 플랫폼 일괄 삭제 요청. 45일마다 반복 삭제 의무.
텍사스
TDPSA
2024년 7월 시행. 소비자 삭제·열람·이의권. 주 법무장관 집행. 소규모 기업도 적용.
연방
FTC 개인정보 지침
불공정·기만적 관행 규제. 50억 달러 Meta 과징금 집행 기관. 업종별 추가 규정.

진짜 법적 위험 — 삭제해도 문제, 안 해도 문제

실무상 기업들이 가장 많이 오해하는 부분이 있습니다. "삭제 요청이 오면 삭제하면 된다"는 생각입니다. 그러나 미국에서 개인정보 분쟁은 그렇게 단순하지 않습니다.

01
삭제했을 때 — 증거 훼손(Spoliation of Evidence)

기업이 소송을 예상하거나 이미 분쟁이 진행 중인 상황에서 관련 자료를 삭제한다면, 미국 법원은 이를 Spoliation of Evidence(증거 훼손)로 판단할 가능성이 있습니다. 법원은 이러한 경우 해당 증거가 기업에 불리한 내용을 담고 있었다고 추정(Adverse Inference)하거나, 소송에서 제재(Sanctions)를 가할 수 있습니다.

⚠ 소비자의 삭제 요청이 왔더라도, 현재 분쟁이 진행 중이거나 예상되는 경우에는 반드시 법무 검토 후 처리 방식을 결정해야 합니다.
02
삭제하지 않았을 때 — 규제 위반 + 민사소송

반대로 소비자의 삭제 요청을 적법한 이유 없이 거부하거나, 개인정보 처리방침에는 "일정 기간 후 삭제"라고 적어놓고 실제로는 수년간 보관하고 있었다면, 규제기관 조사와 민사소송의 대상이 될 수 있습니다. Google이 위치정보 설정과 실제 수집 간의 불일치로 3억 9,100만 달러를 합의한 사례가 대표적입니다.

⚠ 처리방침과 실제 운영의 불일치가 발견되면, 그 문서 자체가 기업에 불리한 증거가 됩니다.

한국 기업도 예외가 아닙니다

많은 한국 기업들은 "우리는 한국 회사니까 미국 개인정보법은 적용되지 않는다"고 생각합니다. 그러나 실제 미국법은 그렇게 단순하지 않습니다. 미국 소비자에게 상품을 판매하고, 회원가입을 받고, 뉴스레터를 보내며, 온라인 광고를 운영한다면 캘리포니아 소비자의 개인정보를 처리하는 사업자로 평가될 가능성이 있습니다.

한국 기업이 특히 주의해야 할 상황
적용 기준은 기업의 설립지나 서버 위치가 아닙니다. 소비자의 거주지와 개인정보 처리 방식이 기준입니다. 한국 개인정보보호법(PIPA) 준수가 미국 주법 준수를 의미하지 않습니다. 두 법은 요건이 다릅니다.

AI 시대, 개인정보 리스크는 더욱 커지고 있습니다

최근 기업들은 ChatGPT를 비롯한 생성형 AI를 업무에 적극 활용하고 있습니다. 그러나 직원이 고객 정보를 AI 서비스에 입력하는 순간 새로운 법적 문제가 발생할 수 있습니다. Clearview AI 사례는 AI와 개인정보가 결합할 때 얼마나 심각한 법적 결과가 발생할 수 있는지를 보여주는 대표적인 사례입니다. 이제 기업은 AI 사용 정책, 직원 접근 권한, 데이터 보존 기간, 외부 벤더 계약, 개인정보 삭제 절차까지 포함한 종합적인 컴플라이언스 체계를 갖추어야 합니다.

지금 점검해야 할 것들

기업 개인정보 컴플라이언스 자가 점검
개인정보 처리방침이 실제 운영과 일치하는가?
불일치가 있다면 지금이 정리할 시점입니다.
삭제 요청 접수 시 내부 처리 절차가 문서화되어 있는가?
현재 분쟁 중이거나 예상되는 경우, 삭제 전 법무 검토 절차가 있는가?
벤더 계약에 개인정보 처리 조항(DPA) 및 삭제 의무가 포함되어 있는가?
직원의 AI 도구 사용 정책이 수립되어 있는가?

변호사의 법률 분석 — 경영 패러다임의 변화입니다

캘리포니아, 유타, 텍사스에서 기업법무와 민사소송 업무를 수행하면서 공통적으로 느끼는 점은 분명합니다. 대부분의 기업은 개인정보를 수집하는 방법에는 익숙하지만, 언제 삭제해야 하는지, 무엇을 보존해야 하는지에 대해서는 아직 충분한 준비가 되어 있지 않습니다.

Delete Act는 개인정보 보호법의 변화가 아니라 기업 경영 패러다임의 변화를 의미합니다. 앞으로 기업의 경쟁력은 얼마나 많은 개인정보를 보유하고 있는지가 아니라, 개인정보를 얼마나 투명하고 안전하며 법률에 맞게 관리할 수 있는가에 의해 평가될 가능성이 높습니다.

공식 출처 및 참고자료

이 칼럼은 다음 공식 자료를 바탕으로 작성되었습니다
캘리포니아
CPPA — Delete Act · DROP 공식 안내
privacy.ca.gov/drop
캘리포니아
CPPA — CCPA, CPRA, Delete Act 법령 및 규정
privacy.ca.gov/laws-and-regulations
텍사스
Texas AG — Texas Data Privacy and Security Act (TDPSA)
texasattorneygeneral.gov — TDPSA
연방
Federal Trade Commission (FTC) — Privacy & Security
ftc.gov/business-guidance/privacy-security
한국
대한민국 개인정보보호위원회 (PIPC)
pipc.go.kr
기업법무 · 개인정보 컴플라이언스 · CA · TX · UT
귀사의 개인정보 처리 구조,
지금 점검하시겠습니까?
Meta·Google·Equifax의 사례는 남의 일이 아닙니다. 개인정보 처리방침 검토, 삭제 요청 대응 절차, 벤더 계약 조항, AI 사용 정책 수립까지 — 사고 발생 전 법률 검토가 훨씬 효율적입니다. Chris Chong 변호사가 직접 상담합니다.

면책 조항 — 본 칼럼에 소개된 판례 정보는 공개된 자료를 바탕으로 작성된 것이며, 특정 사건의 법적 결론을 단정하지 않습니다. 본 칼럼은 일반적인 법률 정보를 제공하기 위한 것으로, 개별 기업에 대한 법률 자문을 구성하지 않습니다. Law Office of Chris W. Chong · cchonglaw.com · CA · TX · UT

Key Takeaways
  • Personal data is no longer just an asset — it is a Legal Liability for every business that holds it
  • The Delete Act requires ongoing deletion every 45 days — not a one-time compliance action
  • Both deleting and refusing to delete can create liability — managing the balance between these obligations is the legal challenge
  • Meta · Google · Equifax · Clearview AI — hundreds of millions of dollars in real-world precedents
  • Korean businesses serving U.S. consumers may be subject to California and Texas privacy law regardless of where they are incorporated

The media describes the Delete Act as a law that lets consumers "erase their personal data with one click." From the perspective of an attorney practicing business law in California, Utah, and Texas, this framing misses the more significant shift the law represents. The Delete Act is not simply a new consumer right. It is a new accountability standard — requiring businesses to demonstrate legal responsibility over the entire lifecycle of the personal information they collect, retain, share, and delete.

Personal Data Has Moved From Asset to Legal Liability

Businesses once operated on a straightforward premise: more customer data means better marketing, higher ad revenue, and greater enterprise value. That premise has been fundamentally disrupted by the legal environment that has emerged over the past decade in the United States.

"The competitive advantage no longer lies in how much personal data a business holds — it lies in how transparently, securely, and legally it manages the data it chooses to retain."

— Chris Chong, Esq. · Business Law · Civil Litigation · CA · TX · UT

Personal data held by a business is now simultaneously an asset and a potential legal liability. A breach or misuse exposes a company to regulatory investigation, consumer class actions, contractual damages, and investor liability claims. This is not theoretical. The precedents are in the books — and the dollar figures are significant.

What Real Litigation Looks Like — Four Precedents Every Business Should Know

To understand why the Delete Act was enacted, it helps to look at what has already happened to businesses that failed to manage personal data responsibly. These are not cautionary tales from a distant legal era — they are recent precedents that define the legal environment your business operates in today.

Actual U.S. Privacy Litigation — Key Cases
Meta (Facebook)
Class Action Settlement 2022 · FTC Consent Decree 2019
$725M
+ FTC $5B
Cambridge Analytica · ~87 Million Users' Data Misused
Personal data of approximately 87 million Facebook users was shared with and misused by Cambridge Analytica without adequate user consent. Meta settled the resulting U.S. class action for $725 million — the largest privacy class action settlement in U.S. history at the time. Separately, Meta entered into a $5 billion consent decree with the FTC covering broader privacy violations. Civil and regulatory liability materialized simultaneously.
Lesson: Third-party data sharing without contractual safeguards and internal controls creates exposure on two fronts — class action liability and regulatory enforcement — at the same time.
Google
40-State AG Settlement · November 2022
$391.5M
Settlement
Location Tracking Continued After Users Disabled It
Google continued collecting location data through Web & App Activity even after users disabled Location History — a practice users reasonably believed would stop location tracking. Forty state attorneys general joined the settlement, which also required Google to implement transparency improvements in how location data collection is disclosed.
Lesson: When what a privacy setting appears to do differs from what data is actually collected, the gap between user expectation and actual practice becomes the liability.
Equifax
Breach 2017 · Settlement 2019
$575M+
Up to $700M+
147 Million Records Exposed · Cybersecurity Compliance Failure
A cybersecurity failure at one of the largest U.S. credit reporting agencies exposed names, Social Security numbers, driver's license numbers, and credit card data of approximately 147 million individuals. Equifax settled with the FTC, CFPB, and all 50 state attorneys general for at least $575 million — potentially exceeding $700 million. This case is the definitive U.S. precedent for cybersecurity compliance failure at scale.
Lesson: The volume of personal data a business holds directly determines the scale of its security obligation — and its liability when that security fails.
Clearview AI
BIPA Settlement · 2022
Private Sales
Broadly Restricted
Billions of Photos Scraped Without Consent · Illinois BIPA Violation
Clearview AI scraped billions of photographs from the internet without consent to build a facial recognition database. Found to violate Illinois' Biometric Information Privacy Act (BIPA). Under the settlement, Clearview AI's ability to sell or provide its facial recognition database to most private businesses in the United States was substantially restricted. This case is the leading U.S. precedent on biometric data privacy.
Lesson: Privacy violations can restrict a core business model, not just impose financial penalties. AI-driven biometric data collection carries exceptionally high legal exposure when consent frameworks are absent.

The Delete Act: Ongoing Management, Not a One-Time Action

Beginning August 1, California's Delete Act deletion procedures take effect. Through the state-operated DROP platform, consumers can submit a single request to have their personal information deleted by all registered data brokers. Hundreds of thousands of California residents have already filed requests. But the provision businesses most need to understand is this: deletion is not a one-time event. After honoring a deletion request, data brokers must continue to delete newly collected information about the same consumer every 45 days. This requires a full review of every system that touches customer data — CRM platforms, email marketing tools, advertising systems, cloud storage, and analytics tools.

California
CCPA · CPRA · Delete Act
Rights to delete, access, correct, opt out. DROP platform for consolidated requests. 45-day recurring deletion obligation.
Texas
TDPSA
Effective July 2024. Consumer deletion, access, and appeal rights. Enforced by Texas AG. Broad applicability.
Federal
FTC Privacy Guidelines
Prohibits unfair and deceptive practices. Enforced Meta's $5B settlement. Sector-specific regulations apply.

The Real Legal Risk — Liability on Both Sides

01
If You Delete — Spoliation of Evidence Risk

When litigation is reasonably anticipated or already underway, destroying relevant records — even in response to a deletion request — can constitute Spoliation of Evidence. Courts may impose sanctions, draw adverse inferences, or otherwise penalize the company. A deletion request does not create a blanket right to destroy records that are subject to a legal hold obligation.

⚠ If a deletion request arrives during an active or anticipated dispute, the request cannot be processed without legal review first.
02
If You Don't Delete — Regulatory Violation + Civil Liability

Refusing a valid deletion request without legal justification, or retaining data beyond what your privacy policy promises, exposes the company to regulatory investigation and civil liability. Google's $391 million settlement arose precisely from the gap between what users believed about their settings and what data was actually being collected — a policy-versus-practice mismatch that regulators found to be deceptive.

⚠ When a privacy policy says one thing and actual data handling does another, the written policy becomes evidence against the company.

Korean Businesses Are Not Exempt

A common assumption among Korean businesses serving U.S. markets is that U.S. state privacy law does not apply to them because they are incorporated in Korea. In practice, the applicable standard is not where a company is established — it is where the consumer is located and how their data is processed. A Korean online retailer that sells to California residents, collects their account information, and sends them marketing emails is likely processing California consumer personal information within the meaning of the CCPA.

Key Risk for Korean-Headquartered Businesses
Compliance with Korea's Personal Information Protection Act (PIPA) does not satisfy California or Texas privacy law requirements. The legal standards are different, and U.S. regulators do not accept foreign law compliance as a substitute. Exposure should be assessed by U.S. counsel based on the specific nature of your U.S. consumer interactions.

What to Review Right Now

Business Privacy Compliance Self-Check
Does your Privacy Policy accurately reflect your actual data practices?
Is there a documented internal procedure for handling deletion requests?
Is there a legal review step before deletion when litigation is anticipated?
Do vendor contracts include Data Processing Agreements with deletion obligations?
Is there a written AI usage policy governing what data employees may share with external tools?

An Attorney's Perspective — A Paradigm Shift in Business Management

Having practiced business law and civil litigation in California, Utah, and Texas, the pattern is consistent: most businesses are familiar with how they collect personal information, but far less prepared on the questions of when to delete it, what to preserve, and how to demonstrate that their practices align with their stated policies. The Delete Act is not a technical amendment to privacy law. It is a signal that the competitive landscape has shifted — that the businesses best positioned going forward are those that manage personal data with the same rigor they apply to their financial records and contractual obligations.

Official Sources & References

This column is based on the following official sources
California
CPPA — Delete Act & DROP Platform
privacy.ca.gov/drop
California
CPPA — CCPA, CPRA & Delete Act Laws & Regulations
privacy.ca.gov/laws-and-regulations
Texas
Texas AG — Texas Data Privacy and Security Act (TDPSA)
texasattorneygeneral.gov — TDPSA
Federal
Federal Trade Commission (FTC) — Privacy & Security
ftc.gov/business-guidance/privacy-security
Korea
Korea Personal Information Protection Commission (PIPC)
pipc.go.kr
Business Law · Privacy Compliance · CA · TX · UT
Is Your Business Ready
for What Comes After the Delete Button?
Meta. Google. Equifax. These cases are not cautionary tales from another era — they are the legal environment your business operates in today. Privacy policy review, deletion response procedures, vendor contract analysis, AI usage policies — a proactive legal review is far more efficient than crisis response. Attorney Chris Chong provides business law consultations in California, Utah, and Texas — in Korean and English.

Disclaimer — Case information presented in this column is drawn from publicly available records and is provided for illustrative purposes only. This column does not constitute legal advice or create an attorney-client relationship. Laws referenced are subject to amendment. For advice specific to your business, please consult a licensed attorney. Law Office of Chris W. Chong · cchonglaw.com · CA · TX · UT

Next
Next

미국 손해배상 소송, 무엇을 입증해야 이길 수 있을까?