委托处理个人信息的私法规制
作者:
中图分类号:

D923;D922.16;D922.294

基金项目:

司法部国家法治与法学理论研究资助项目"人工智能产品法律责任研究"(18SFB039);中国政法大学大健康法治政策创新研究项目资助(Y2020005)


Civil law regulation of entrusted processing of personal information
Author:
  • 摘要
  • | |
  • 访问统计
  • |
  • 参考文献 [23]
  • |
  • 相似文献 [20]
  • | | |
  • 文章评论
    摘要:

    委托处理个人信息是信息流动、共享与利用的必然选择。《个人信息保护法》第21条专门为委托处理个人信息提供了规范基础,填补了《民法典》《电子商务法》《网络安全法》等规范空白,但就该条的规范内容如何解释适用,对委托处理私法规制的目的、对象及方式等要素的具体展开,仍需藉由解释论予以完善。由于司法实践中,信息处理者通常会援引其与第三人之间存在合同或其他交易安排,系由他人造成了损害而与自身的处理行为无关,给信息主体的权益保护带来了挑战,这构成了委托处理私法规制的核心。作为对委托处理进行私法规制的基础论证,委托处理的法律结构不同于共同处理,信息处理者与受托人之间为从属关系,信息处理者决定了处理的目的、方式,受托人只能按信息处理者的指示处理个人信息。为了更好地保障信息主体的合法权益,委托处理关系内部合同应当包含必备条款以确保受托人合法处理数据,且信息处理者可以检查受托人是否遵守这些规定。相较于《个人信息保护法》第20条由内部主体约定各方的权利义务,第21条第1款详细列举委托处理的目的、期限、处理方式、个人信息的种类、保护措施以及双方的权利和义务等事项,是值得肯定的立法选择。结合《个人信息保护法》第21条第2款以及域外法的通常规则,受托人应当承担依指示处理、服务结束后的返还(或删除)、保密三项法定义务。此外,在转委托、告知同意以及适当化任命与监督上不能适用委托合同的一般规则,其目的在于确保受托人正确、合适地履行职责,遵守个人信息保护法规。对于各方的责任承担,《个人信息保护法》第69条规定了损害赔偿责任,同时,依靠《民法典》规范实现体系拓展,使信息主体的权益救济不仅可以通过人格权编加以解决,还可以通过侵权责任编进行兜底保护。然而,《个人信息保护法》第21条并未规定信息处理者与受托人之间如何进行责任划分,构成法律漏洞。为消解委托处理中责任主体不明的救济困境,应当通过连带责任规则实现信息主体的权益救济。具体而言,在漏洞填补上可以借助共同危险行为理论,类推适用《民法典》第1170条的规定,除非能够证明损害确实是由对方引起,否则要求信息处理者与受托人就同一处理中的损害承担连带责任。

    Abstract:

    Entrusted processing of personal information is an inevitable option of information flowing, sharing, and using. Article 21 of the Personal Information Protection Law (PIPL) specifically provides a regulatory basis for entrusted processing of personal information, filling the normative gaps of the Civil Code, the Electronic Commerce Law and the Network Security Law. However, how to interpret and apply the regulatory content of this article, and the specific development of the purpose, objects, methods and other elements of the entrusted processing still needs to be improved through interpretation. In judicial practice, information processors often cite the existence of contracts or other transaction arrangements with a third party, in which the damage is caused by others rather than their own processing behaviors, which brings challenges to the protection of the rights and interests of information subjects. This is the core of civil law regulation of entrusted processing. As the basic argument of private law regulation of entrusted processing, the legal structure of entrusted processing is different from joint processing, in which there is a subordinate relationship between the information processor and the entrusted party. The information processor decides the purpose and method of processing, and the entrusted party can process the personal information only as instructed by the information processor. In order to better safeguard the rights of information subjects, the internal contract of entrusted processing relationship must include mandatory provisions to ensure that the entrusted party legally processes data and the information processor can check whether the entrusted party has complied with these provisions. Compared with Article 20 of the PIPL which stipulates the rights and obligations of each party shall be agreed upon by an internal person, Article 21.1 that lists in detail the purpose, duration, and method of the entrustment, types of personal information, protection measures as well as the rights and obligations of the parties is a positive legislative choice. In accordance with Article 21.2 of the PIPL and the general rules of foreign law, the entrusted party shall bear three statutory obligations, including process as instructions, return or deletion, and keep confidentiality. In addition, the general rules of entrustment contracts cannot apply to sub-entrustment, notification of consent, as well as appropriate appointment and supervision, which are for the purpose of ensuring that the entrusted party can correctly and appropriately perform its duties and comply with the regulations on the protection of personal information. As for the assumption of liability of the parties, Article 69 of the PIPL provides for the liability for damages. Meanwhile, the system is expanded by relying on the norms of the Civil Code. Therefore, the remedy of the rights and interests of the information subject can not only be solved through the Personality Rights Part, but also be protected through the Tort Liability Part. However, Article 21 of the PIPL does not provide for the division of responsibilities between the information processor and the entrusted party, which constitutes a legal loophole. In order to alleviate the relief predicament of liability subject, the rights relief of the information subject should be realized through joint and several liability rules. Specifically speaking, the theory of joint dangerous acts may be used, and by analogy the provisions of Article 1170 of the Civil Code may be applied, which requires the information processor and the entrusted party to be jointly liable for damages in the same transaction, unless it can be proved that the damages are actually caused by the other parties.

    参考文献
    [1] KRZYSZTOFEK M.GDPR:General Data Protection Regulation (EU) 2016/679:Post-reform personal data protection in the European Union[M].Holland:Kluwer Law International BV,2018:148.
    [2] 东芝(中国)有限公司.个人信息收集、使用同意书[EB/OL].[2021-02-17].http://www.toshiba.com.cn/service/personal_home/agreement.html.
    [3] 王晓锦.人工智能对个人信息侵权法保护的挑战与应对[J].海南大学学报(人文社会科学版),2019(5):126-134.
    [4] 齐爱民,张哲.识别与再识别:个人信息的概念界定与立法选择[J].重庆大学学报(社会科学版),2018(2):119-131.
    [5] 克里斯托弗·库勒.欧洲数据保护法:公司遵守与管制[M].旷野,杨会永,译.北京:法律出版社,2008:74.
    [6] 张新宝.从隐私到个人信息:利益再衡量的理论与制度安排[J].中国法学,2015(3):38-59.
    [7] 王利明.民法典人格权编的亮点与创新[J].中国法学,2020(4):5-25.
    [8] 何俊志,孙婧婧.个人信息应用的保护设计与实证进路:基于《民法典》同意原则的博弈分析[J].贵州社会科学,2020(9):74-81.
    [9] 齐爱民.信息法原论:信息法的产生与体系化[M].武汉:武汉大学出版社,2010:76.
    [10] 张新宝.个人信息收集:告知同意原则适用的限制[J].比较法研究,2019(6):1-20.
    [11] ZUIDERVEEN BORGESIUS F J.Improving privacy protection in the area of behavioural targeting[M].Holland:Kluwer Law International BV,2015:303.
    [12] 郭北南.个人信息的民事法保护与救济[J].国家检察官学院学报,2021,29(2):151-161.
    [13] KUNER C,BYGRAVE L A,DOCKSEY C,et al.The EU General Data Protection Regulation (GDPR):A Commentary[M].New York:Oxford University Press,2020:1084,1967.
    [14] 陈际红,蔡鹏,韩璐,等. EDPB《GDPR下数据控制者及数据处理者概念的指南》解读兼谈《个人信息保护法(草案)》关于处理者的定义[EB/OL].(2020-11-17) [2021-02-11].http://www.zhonglun.com/Content/2020/11-17/1408315833.html.
    [15] 袁立志,潘舒然.关于个人信息保护法草案的七个疑问[EB/OL].(2020-11-09)[2020-12-24].http://www.jingtian.com/Content/2020/11-09/1729311245.html.
    [16] 崔建远.合同法[M].第6版.北京:法律出版社,2016:442.
    [17] 王洪亮.《民法典》与信息社会:以个人信息为例[J].政法论丛,2020(4):3-14.
    [18] 张新宝,葛鑫.《个人信息保护法(专家建议稿)》重磅首发[EB/OL].(2019-10-17)[2021-03-15].https://www.civillaw.com.cn/gg/t/?id=36127#.
    [19] 肖少启.个人信息法律保护路径分析[J].重庆大学学报(社会科学版),2013(4):119-126.
    [20] 叶名怡.个人信息的侵权法保护[J].法学研究,2018(4):83-102.
    [21] 尹志强.侵权法的地位及与民法典各编关系的协调[J].华东政法大学学报,2019(2):25-40.
    [22] 张新宝.《民法总则》个人信息保护条文研究[J].中外法学,2019(1):54-75.
    [23] 阮神裕.民法典视角下个人信息的侵权法保护:以事实不确定性及其解决为中心[J].法学家,2020(4):29-39,192.
    引证文献
    网友评论
    网友评论
    分享到微博
    发 布
引用本文

曹明德,赵峰.委托处理个人信息的私法规制[J].重庆大学学报社会科学版,2022,28(4):203-215. DOI:10.11835/j. issn.1008-5831. fx.2022.03.003

复制
分享
文章指标
  • 点击次数:838
  • 下载次数: 809
  • HTML阅读次数: 1693
  • 引用次数: 0
历史
  • 在线发布日期: 2022-09-30
文章二维码