风险控制理念下我国个人信息匿名化处理的法律规制
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

D923;D922.16

基金项目:

国家社会科学基金项目"我国互联网金融市场准入与监管法制重大理论与实践问题研究"(16BFX098)


On the legal regulation of personal information anonymizationin China under the risk control concept
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    数据匿名化为数据的流通和共享提供了重要的技术助力,技术的易变性同时也对数据匿名化处理的法律规制带来诸多障碍。在当前的技术背景下,我国个人信息匿名化面临身份识别标准不确定、身份再识别可逆转等风险,个人信息匿名化处理过程中所产生的技术风险给个人隐私利益带来极大挑战。目前以结果导向为目标的规制手段在个人信息匿名化规制方面缺乏灵活性,难以缓释技术带来的不确定性风险。平衡好个人隐私利益、企业经济利益以及社会公共利益之间的冲突是个人信息匿名化处理的终极目标。风险控制导向理念的优位在理念层面上摆脱了数据保护的现实诉求与理想价值判断之间的束缚,替代结果导向理念,为信息处理者内源性的数据合规与自律监管、信息主体外向性的权利保护与数据使用提供了较为有效的弥合思维进路,为个人信息匿名化处理的法律规制提供新的可能。以风险控制理念为核心的个人信息匿名化法律规制架构以实现数据的有效性与实用性之间的动态平衡为目标,围绕降低个人信息匿名化处理过程中的风险进行法律机制设计,通过课以信息处理者相应的信息处理风险评估义务实现对个人信息匿名化规制的良善治理。在无规范性文件作理据支撑的前提下,个人信息匿名化的风险评估及评估标准于实践中难以稳定量化,故而在个人信息匿名化法律规制方面,应当提倡将保障个人信息主体权利作为个人信息匿名化处理的核心,通过赋予信息主体在信息处理过程中相应的数据权利以实现信息主体自身的权利。个人信息匿名化以个人信息可识别为前提,在个人信息概念界定上应当依据具体场景加以个案判断,因此,对于匿名数据的认定也应当采取动态场景化的方式进行理解。在个人信息匿名化处理风险控制手段的实现上,通过确立相关隐私风险评估机制为信息处理者提供明确的数据利用指引,规范信息处理者的行为。

    Abstract:

    Data anonymization provides essential technical support for the circulation and sharing of data. Technology variability also brings many obstacles to the legal regulation of data anonymization. Under the current technical background, China’s anonymization of personal information faces risks such as uncertain identification standards and reversible identity re-identification. The technical risks generated by anonymizing personal information significantly challenge personal privacy interests. The current result-oriented regulatory means lack flexibility in the regulation of personal information anonymization, and it is difficult to mitigate the uncertain risks brought about by technology. Balancing the conflict between individual privacy, corporate economic, and public social interests is the ultimate goal of anonymizing personal information. The superiority of the risk control-oriented concept eliminates the shackles between the realistic demands of data protection and ideal value judgments at the conceptual level, replacing the result-oriented concept. It provides a more practical approach to bridging thinking for the endogenous data compliance and self-regulation of information processors, the protection of rights and the use of data of information subject, and offers new possibilities for the legal regulation of the anonymization of personal information. The legal framework of personal information anonymization with the concept of risk control as the core aims to achieve a dynamic balance between the validity and practicability of data and designs legal mechanisms around reducing the risk in the process of anonymization of personal information. The excellent governance of personal information anonymization regulation can be realized by imposing corresponding information processing risk assessment obligation on information processors. Without the support of normative documents, the risk assessment and evaluation standards of anonymizing personal information are difficult to quantify stably in practice. Therefore, in terms of legal regulation of personal information anonymization, it should be advocated that the protection of the rights of personal information subjects should be the core of anonymization processing of personal information, and the rights of the information subject should be realized by giving the information subject corresponding data rights in the process of information processing. The anonymization of personal information is based on the premise that personal information can be identified, and the definition of personal information should be judged on a case-by-case basis based on specific scenarios. Therefore, the identification of anonymous data should also be understood in a dynamic and scenario-based manner. In terms of implementing risk control means for anonymizing personal information, relevant privacy risk assessment mechanism should be established to provide straightforward data utilization guidelines for information processors and regulate the behavior of information processors.

    参考文献
    相似文献
    引证文献
引用本文

张丽,许多奇.风险控制理念下我国个人信息匿名化处理的法律规制[J].重庆大学学报社会科学版,2023,(2):220-231. DOI:10.11835/j. issn.1008-5831. fx.2021.09.003

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2023-05-08
  • 出版日期: