박철성 대기자 〈리서치센터 국장·칼럼니스트〉
〈팩트해부〉 휴대전화, 선진국은 회선을 조였고, 한국은 국민 얼굴을 세웠다
■ 대포폰 차단 명분으로 7월 6일 휴대전화 개통 안면인증 단계적 시행
■ 개인정보위·인권위는 법적 근거와 선택권, 생체정보 보호를 먼저 물었다
■ 중국도 ‘안면인식 강제’엔 제동…인도네시아는 5일 앞서 얼굴 SIM 등록
■ EU는 생체식별에 금지선, 미국은 주법·소송으로 압박
■ 대포폰의 뿌리는 회선인데, 검문은 왜 얼굴에서 시작됐나
▲휴대전화 개통 창구에 얼굴 인증이 들어왔다. 정부는 대포폰과 명의도용을 막기 위한 다중 본인확인이라고 설명한다. 그러나 개인정보위와 인권위는 법적 근거와 선택권, 생체정보 보호 문제를 먼저 물었다. 일러스트=AI 생성
휴대전화 개통 창구에 얼굴이 섰다. 정부는 대포폰을 막겠다고 했다. 그러나 질문은 남는다. 대포폰은 범죄조직과 부정개통 유통망, 허술한 회선 관리에서 나왔다. 그런데 왜 첫 부담은 국민 얼굴로 향했는가.
7월 6일부터 휴대전화 신규 개통과 번호이동 과정에 안면인증을 포함한 다중 본인확인 체계가 단계적으로 적용됐다. 과학기술정보통신부는 지난 6월 30일 ‘휴대전화 부정사용 방지 종합대책’을 발표했다. 명의도용, 대포폰, 보이스피싱을 막기 위해 개통 단계의 신원확인 절차를 강화하겠다는 내용이다.
정부 설명은 분명하다. 휴대전화는 금융거래와 본인인증의 핵심 수단이 됐다. 타인 명의로 개통된 휴대전화는 보이스피싱과 스미싱, 불법 대출, 명의도용 범죄의 입구가 될 수 있다. 그래서 개통 단계에서 신분증 사진과 실제 얼굴을 대조하겠다는 것이다.
명분은 대포폰 차단이다. 그러나 제도는 신분증 확인을 넘어 생체정보 확인으로 간다. 휴대폰 하나를 개통하기 위해 국민이 자신의 얼굴을 실시간으로 증명해야 하는 시대가 열린 것이다.
■ 대포폰은 회선에서 뚫렸는데, 검문은 얼굴에서 시작됐다
문제는 안면인증이라는 기술 하나가 아니다. 문제는 책임의 순서다. 대포폰은 국민이 얼굴을 내지 않아서 생긴 것이 아니다. 도난 신분증, 위조 신분증, 불법 유통점, 법인폰 악용, 알뜰폰 부정개통, 내구제폰 구조, 다회선 관리 허점이 겹치며 만들어졌다.
범죄자는 회선을 돌렸다. 정부는 국민 얼굴을 불렀다. 대포폰을 막으려면 먼저 조여야 할 것은 얼굴인가, 회선인가.
정부 대책에는 통신사와 유통점 단속, 법인폰 악용 대응, 부정개통 사업자 제재 강화도 포함돼 있다. 그렇다면 더 묻지 않을 수 없다. 왜 제도의 첫 장면은 통신사의 책임이 아니라 국민의 얼굴인가. 왜 회선 관리의 실패가 생체정보 제출의 문턱으로 바뀌었는가.
정부는 “안면인증만 강제하는 것은 아니다”라고 설명한다. 안면인증이 어렵거나 원하지 않는 경우에는 모바일신분증, 주민등록초본 등 대체수단을 활용할 수 있다는 것이다. 그러나 그 설명은 또 다른 질문을 낳는다. 대체수단으로도 충분히 본인확인이 가능하다면, 왜 얼굴 인증을 개통 창구의 전면에 세웠는가.
■ 개인정보위와 인권위는 먼저 제동을 걸었다
개인정보보호위원회는 지난 5월 27일 전체회의에서 휴대전화 개통 시 안면인증과 관련해 과기정통부에 개선을 권고했다. 핵심은 생체인식정보의 민감성이다. 얼굴은 비밀번호처럼 바꿀 수 없다. 한 번 유출되면 새로 발급받을 수도 없다. 그래서 생체정보를 다루는 제도는 목적보다 절차가 먼저 검증돼야 한다.
개인정보위는 이용자가 사실상 안면인증을 거부하기 어려운 구조에서는 동의의 실효성을 인정하기 어렵다고 지적했다. 휴대전화 개통 과정에서 안면정보를 처리하려면 민감정보 처리 근거를 분명히 해야 하고, 대체수단 또는 법령상 근거도 마련해야 한다는 취지였다.
국가인권위원회도 앞서 제동을 걸었다. 인권위는 3월 11일 과기정통부 장관에게 휴대전화 개통 시 안면인증 의무화 정책을 신중히 재검토하라고 권고했다. 생체인식정보 유출 시 회복이 어렵고, 고령자·장애인·디지털 취약계층·거부자를 위한 대체수단이 필요하다고 봤다.
인권위는 법적 근거 문제도 지적했다. 출입국관리법이나 전자금융거래법에는 생체정보 수집·이용의 법적 근거가 있다. 그러나 전기통신사업법에는 휴대전화 개통 과정에서 안면정보를 본인확인 수단으로 활용할 명확한 규정이 없다는 취지다.
휴대전화는 이제 사치품이 아니다. 은행, 병원, 공공서비스, 택배, 일자리까지 생활의 출입문이 됐다. 그 문 앞에 얼굴 인증을 세우는 것은 단순한 본인확인 절차가 아니다. 통신 접근권의 문턱을 생체정보와 연결하는 일이다.
■ 중국은 제동, 인도네시아는 강행
안면인증을 휴대전화 개통에 먼저 올린 대표 사례는 중국이다. 중국은 2019년 통신사기 근절을 명분으로 신규 휴대전화 서비스 등록 과정에 얼굴 스캔을 요구했다. 그러나 얼굴정보 유출과 거래, 생체정보 남용, 디지털 취약계층 배제 논란이 이어졌다.
중국 당국도 최근에는 안면인식을 유일한 신원확인 수단으로 강제하는 방식에 제동을 걸었다. 서비스 제공자가 안면인식을 요구하더라도 합리적이고 편리한 대체 신원확인 방법을 제공해야 한다는 방향으로 규제를 정비한 것이다.
반면 인도네시아는 얼굴 인증을 활용한 SIM 카드 등록 제도를 7월 1일부터 시행했다. 신규 번호 등록 시 얼굴 인증 생체정보 등록이 의무화됐고, 등록자의 얼굴 정보는 내무부 인구·주민등록국 데이터베이스와 대조되는 구조다. 명분은 한국과 닮은 디지털 사기 방지다.
2026년 7월, 아시아 두 나라가 닷새 간격으로 휴대전화 개통 창구에 얼굴을 세웠다. 인도네시아는 7월 1일, 한국은 7월 6일이었다. 한국이 중국과 같다고 단정할 수는 없다. 그러나 정책 수단만 놓고 보면 한국은 미국·영국·캐나다식 모델보다 중국·인도네시아식 생체 SIM 등록 흐름에 더 가까운 질문 앞에 서 있다.
■ EU는 금지선, 미국은 소송
유럽연합은 생체식별 기술에 강한 금지선을 그었다. AI Act는 공공장소에서의 실시간 원격 생체식별 시스템 사용을 원칙적으로 금지하거나 극히 제한된 예외에서만 허용하는 구조다. 다만 휴대전화 개통 창구의 1대1 본인확인과 공공장소 실시간 원격 생체식별은 법적 성격이 다르다. 그럼에도 EU가 생체식별을 기본권과 직결된 고위험 영역으로 보고 강하게 통제한다는 점은 분명하다.
GDPR 역시 생체정보를 개인을 고유하게 식별하기 위한 목적으로 처리할 경우 특별범주 정보로 분류한다. 원칙적으로 처리를 제한하고, 명시적 동의나 중대한 공익 등 예외 요건을 요구한다. 유럽이 얼굴을 가볍게 보지 않는 이유다.
미국은 국가 차원의 생체정보 수집 의무화 대신, 기업의 무단 수집과 남용을 소송 리스크로 억제하는 구조가 강하다. 대표 사례가 일리노이주의 생체정보 보호법, BIPA다. 페이스북은 얼굴 인식 기능과 관련해 6억5000만 달러 규모 합의에 이르렀고, 구글과 인스타그램도 각각 대규모 배상 또는 합의 사례를 남겼다.
휴대전화 범죄 대응도 마찬가지다. 미국은 안면인증 전면 도입보다 SIM 스와프, 번호이동 사기, 고객 통지, 통신사 인증 절차 강화에 초점을 맞춰왔다. 범죄가 번호 탈취에서 발생하면 번호이동 절차를 조이고, 통신사의 책임을 묻는 식이다.
■ 선진권은 얼굴보다 회선을 본다
▲주요국 휴대전화 개통 본인확인 비교. 미국·영국·캐나다는 전면 얼굴 인증 의무와 거리가 있고, 일본·호주·싱가포르는 신분확인과 회선 관리 중심이다. 중국은 얼굴 스캔을 도입했지만 최근 강제성에 제동을 걸었고, 인도네시아는 2026년 7월 신규 SIM 얼굴 인증 의무화에 들어갔다. 자료=각국 규제기관·관련 보도 종합ㆍAI 생성
선진권의 제도는 나라별로 다르다. 독일·프랑스·스페인·이탈리아처럼 선불 SIM 등록과 신분확인을 요구하는 나라도 있고, 미국·영국·캐나다처럼 의무적 SIM 등록 체계 밖에 있는 것으로 분류되는 나라도 있다. 중요한 것은 생체정보를 휴대전화 개통의 기본 관문으로 세우느냐의 문제다.
미국·영국·캐나다는 휴대전화 개통 때 국민 얼굴을 전면적으로 요구하는 구조와 거리가 있다. 일본은 휴대전화 부정이용 방지법을 통해 가입자 신원확인을 요구해왔다. 호주도 선불 모바일 활성화 때 이름, 주소, 생년월일 등 정보를 받고 신분을 확인한다. 싱가포르는 개인 명의 회선 수 제한과 본인 명의 회선 확인 도구로 명의도용과 다회선 악용을 줄이는 방향으로 간다.
선진국의 흐름을 하나로 단정할 수는 없다. 그러나 공통된 질문은 보인다. 범죄가 회선에서 발생하면 회선을 조인다. 번호가 탈취되면 번호이동 절차를 조인다. 신분증 위조가 문제이면 신분증 검증을 강화한다. 다회선이 문제이면 회선 수와 유통망을 관리한다.
한국은 그 모든 조치와 함께 국민 얼굴을 전면에 세웠다. 그래서 질문은 더 날카로워진다. 대포폰의 책임은 어디에 있는데, 제도의 첫 부담은 왜 소비자 얼굴로 향했는가.
■ 대포폰 책임을 얼굴로 덮을 수는 없다
대포폰의 뿌리는 국민 얼굴이 아니다. 부정개통 유통망이다. 명의도용 구조다. 법인폰 악용이다. 다회선 관리 부실이다. 알뜰폰 시장의 허술한 보안 체계다. 신분증 위·변조와 번호이동 사기의 빈틈이다.
그렇다면 먼저 조일 곳은 얼굴이 아니라 회선이다. 통신사는 개통 책임을 져야 한다. 유통점은 부정개통 책임을 져야 한다. 정부는 회선 관리와 사후 추적 체계를 촘촘히 만들어야 한다. 범죄조직은 더 강하게 처벌해야 한다.
순서가 바뀌면 안 된다. 범죄자는 대포폰을 돌렸고, 정부는 국민 얼굴을 불렀다. 휴대전화는 국민 생활의 출입문이다. 그 문 앞에 얼굴 검문소를 세울 것인가. 아니면 회선의 뒷문을 먼저 막을 것인가.
중국도 안면인식 강제에는 제동을 걸었다. 인도네시아는 같은 시기 얼굴 SIM 등록으로 들어갔다. EU는 생체식별에 법적 금지선을 그었다. 미국은 기업을 상대로 소송이라는 채찍을 든다. 한국은 그 사이 어딘가, “선택”이라는 이름의 회색지대에 서 있다.
대포폰의 뿌리는 회선인데, 검문은 왜 얼굴에서 시작됐나. 이 질문에 정부가 답해야 한다.
제보 및 반론: pcseong@naver.com
아래는 위 기사를 영문으로 옮긴 전문입니다. 이해를 돕기 위한 참고용 번역으로, 일부 표현에는 원문의 뉘앙스와 차이가 있을 수 있습니다.
Below is a reference English translation of the article. Some nuances may differ from the original Korean text.
〈Fact Dissection〉 Advanced Countries Tightened the Lines; Korea Put Citizens’ Faces at the Front
■ Facial authentication for mobile phone activation began in stages on July 6, under the stated goal of blocking burner phones
■ The Personal Information Protection Commission and the National Human Rights Commission first raised questions about legal grounds, user choice, and biometric data protection
■ China has also put the brakes on “forced facial recognition”… Indonesia introduced facial SIM registration five days earlier
■ The EU drew a line on biometric identification; the U.S. uses state laws and lawsuits as pressure
■ If burner phones originate from the line system, why does the checkpoint begin with the face?
By Park Cheol-seong, Veteran Journalist / Director of the Research Center · Columnist
▲Facial authentication has entered the mobile phone activation counter. The government says it is a multi-factor identity verification system designed to prevent burner phones and identity theft. However, the Personal Information Protection Commission and the National Human Rights Commission first asked about legal grounds, user choice, and biometric data protection. Illustration=AI-generated
A face has appeared at the mobile phone activation counter. The government said it was trying to stop burner phones. But the question remains. Burner phones came from criminal organizations, unlawful activation networks, and loose line management. Then why has the first burden fallen on citizens’ faces?
Starting July 6, a multi-factor identity verification system including facial authentication was applied in stages to new mobile phone activations and number portability. On June 30, the Ministry of Science and ICT announced its “Comprehensive Measures to Prevent the Misuse of Mobile Phones.” The stated purpose was to strengthen identity verification at the activation stage in order to prevent identity theft, burner phones, and voice phishing.
The government’s explanation is clear. Mobile phones have become a core tool for financial transactions and identity verification. A phone opened under another person’s name can become the gateway to voice phishing, smishing, illegal loans, and identity theft. That is why the government says it will compare ID photos with the user’s actual face at the activation stage.
The justification is blocking burner phones. But the direction of the system goes further. It moves beyond ID verification and into biometric verification. An era has opened in which a citizen must prove their face in real time just to activate a mobile phone.
■ Burner phones were opened through the line system, but the checkpoint began with the face
The issue is not facial authentication as a technology. The issue is the order of responsibility. Burner phones did not arise because citizens failed to show their faces. They were created through a combination of stolen IDs, forged IDs, unlawful sales outlets, abuse of corporate phones, illegal activations through budget carriers, loan-linked phone schemes, and weak management of multiple lines.
Criminals circulated phone lines. The government called in citizens’ faces. Here lies the hard question: if the goal is to stop burner phones, what should be tightened first — the face or the line?
The government’s measures also include crackdowns on telecom companies and sales outlets, responses to corporate phone abuse, and stronger penalties for businesses involved in unlawful activations. That raises another question. Why is the first image of this policy not telecom accountability, but the citizen’s face? Why has a failure of line management turned into a biometric threshold for ordinary users?
The government says facial authentication is “not the only mandatory route.” If facial authentication is difficult or unwanted, users may use alternatives such as a mobile ID or a resident registration abstract. But that explanation raises another question. If alternative methods are enough to verify identity, why place facial authentication at the front of the activation counter?
■ The Personal Information Protection Commission and the Human Rights Commission sounded the alarm first
On May 27, the Personal Information Protection Commission recommended improvements to the Ministry of Science and ICT regarding facial authentication for mobile phone activation. The core issue was the sensitivity of biometric information. A face cannot be changed like a password. Once leaked, it cannot simply be reissued. That is why systems that handle biometric information must verify procedures before purpose.
The commission pointed out that where users find it practically difficult to refuse facial authentication, the effectiveness of consent is hard to recognize. Its position was that clear grounds for processing sensitive information must be established before facial data is used in mobile phone activation. It also called for alternative methods or a clear legal basis.
The National Human Rights Commission had also raised concerns earlier. On March 11, it recommended that the Minister of Science and ICT carefully reconsider the policy of mandatory facial authentication for mobile phone activation. It viewed biometric data leakage as difficult to recover from, and stressed the need for practical alternatives for older adults, people with disabilities, digitally vulnerable groups, and those who refuse facial authentication.
The commission also pointed to the issue of legal grounds. The Immigration Act and the Electronic Financial Transactions Act contain legal grounds for collecting and using biometric information. But the Telecommunications Business Act does not clearly provide for the use of facial information as an identity verification method in the mobile phone activation process.
The more important point is the nature of the mobile phone itself. A mobile phone is no longer a luxury item. It has become the gateway to banking, hospitals, public services, delivery, and jobs. Putting facial authentication in front of that door is not merely an identity check. It links access to communication with biometric information.
■ China applied the brakes, while Indonesia pressed ahead
China is a representative example of a country that put facial authentication into mobile phone activation early. In 2019, China required facial scans in the registration process for new mobile phone services, citing the need to prevent telecom fraud. But controversy followed over facial data leaks and trading, misuse of biometric information, and exclusion of digitally vulnerable groups.
Chinese authorities have recently moved to put the brakes on making facial recognition the only compulsory method of identity verification. The regulatory direction now requires service providers to offer reasonable and convenient alternative identity verification methods even when facial recognition is requested.
Indonesia, by contrast, moved in the opposite direction. It launched a SIM card registration system using facial authentication on July 1. For new number registrations, facial biometric registration became mandatory, and the registrant’s facial information is compared with the database of the Ministry of Home Affairs’ Directorate General of Population and Civil Registration. The stated purpose resembles Korea’s: preventing digital fraud.
In July 2026, two Asian countries placed faces at the mobile phone activation counter just five days apart. Indonesia did so on July 1. Korea followed on July 6. Korea cannot be equated with China. But in terms of policy tools alone, Korea now stands closer to the biometric SIM registration trend seen in China and Indonesia than to the models of the U.S., the U.K., and Canada.
■ The EU drew a line; the U.S. uses lawsuits
The European Union has drawn a strong line around biometric identification technology. The AI Act generally prohibits the use of real-time remote biometric identification systems in public spaces, or allows them only under highly limited exceptions. Although one-to-one identity verification at a mobile phone counter is legally different from real-time remote biometric identification in public spaces, it is clear that the EU treats biometric identification as a high-risk area tied directly to fundamental rights.
The GDPR also classifies biometric data used to uniquely identify a person as special category data. Its processing is generally restricted and requires exceptions such as explicit consent or substantial public interest. This is why Europe does not treat the face lightly.
The United States tends to restrain the unauthorized collection and misuse of biometric information through litigation risk rather than nationwide mandatory biometric collection by the state. A leading example is Illinois’ Biometric Information Privacy Act, or BIPA. Facebook reached a $650 million settlement over its facial recognition feature, while Google and Instagram also faced major settlements or compensation cases.
The same pattern appears in mobile phone fraud response. Rather than introducing blanket facial authentication, the U.S. has focused on SIM swapping, number portability fraud, customer notification, and stronger telecom authentication procedures. When crimes occur through number theft, the procedure around number transfers is tightened and telecom companies are held accountable.
■ Advanced economies tend to look at lines before faces
▲Comparison of mobile phone activation identity verification in major countries. The U.S., U.K., and Canada are far from having blanket mandatory facial authentication. Japan, Australia, and Singapore focus more on identity verification and line management. China introduced facial scanning but has recently put the brakes on compulsion, while Indonesia made facial authentication mandatory for new SIM registration in July 2026. Source=Compiled from regulatory agencies and related reports; AI-generated
Systems differ by country. Some countries, such as Germany, France, Spain, and Italy, require prepaid SIM registration and identity verification. Others, such as the U.S., the U.K., and Canada, are classified as being outside mandatory SIM registration systems. The key question is whether biometric data is placed as the default gateway to mobile phone activation.
The U.S., the U.K., and Canada are far from systems that broadly require citizens’ faces for mobile phone activation. Japan has required subscriber identity verification under its Act on Prevention of Improper Use of Mobile Phones. Australia also requires names, addresses, dates of birth, and identity checks when activating prepaid mobile services. Singapore focuses on reducing identity theft and abuse of multiple lines through limits on individually registered lines and tools for checking lines under one’s own name.
The direction of advanced economies cannot be reduced to a single model. But a common question is visible. When crime occurs through lines, the line system is tightened. When numbers are stolen, number portability procedures are strengthened. When forged IDs are the problem, ID verification is reinforced. When multiple lines are abused, line counts and distribution networks are managed.
Korea has put citizens’ faces at the front along with those measures. That makes the question sharper. Where does responsibility for burner phones lie, and why has the first burden of the policy fallen on the consumer’s face?
■ The responsibility for burner phones cannot be covered with faces
The root of burner phones is not the citizen’s face. It is unlawful activation networks, identity theft structures, abuse of corporate phones, poor multiple-line management, weak security in the budget carrier market, forged IDs, and loopholes in number portability.
If so, the first thing to tighten is not the face, but the line. Telecom companies must bear activation responsibility. Sales outlets must bear responsibility for unlawful activations. The government must build a tighter system for line management and follow-up tracking. Criminal organizations must be punished more strongly.
The order must not be reversed. Criminals circulated burner phones, and the government called in citizens’ faces. The mobile phone is now the gateway to everyday life. Should a facial checkpoint be placed before that door, or should the back door of the line system be blocked first?
China has put the brakes on forced facial recognition. Indonesia has moved into facial SIM registration at the same time. The EU has drawn a legal line around biometric identification. The U.S. wields lawsuits as a whip against companies. Korea stands somewhere in between, in a gray zone called “choice.”
If the root of burner phones lies in the line system, why does the checkpoint begin with the face? The government must answer that question.
Tips and rebuttals: pcseong@naver.com