节点文献

大数据时代的个人信息问题治理

Governance of the Issue of Personal Information in the Era of Big Data

【作者】 马磊

【导师】 郭春镇;

【作者基本信息】 厦门大学 , 法学理论, 2021, 博士

【副题名】从“个人控制”到“回应型治理”

【摘要】 大数据时代,随着数据量的激增以及数据收集、存储和分析技术的飞速进步,数据成为当前社会重要的生产要素。其中,反映个体身份属性和社会活动情况的个人信息成为重要的数据类型。海量的个人信息以及高效的数据分析技术极大地改变了政府公共管理、社会技术创新、企业商业经营以及个人工作生活的方式,成为推动社会进步的重要元素。然而,大数据技术及其应用在增加个体和社会福利的同时,也引发了一些亟待解决的问题。一方面,个人信息面临着极大的安全风险,不合法的个人信息收集行为以及数据控制者的安全漏洞可能会导致海量的个人信息泄漏,给信息主体的人身和财产权利带来极大的威胁。伴随着个人信息泄漏所带来的诸多“下游犯罪”和“二次犯罪”更加剧了个体人身权益和财产权益所面临的危险。另一方面,数据控制者对于个人信息的滥用也可能会给数据主体的权利带来损害,特别是算法的“自动化决策”机制可能会给用户带来歧视性待遇,对用户的个人自治和平等权造成侵害。面对这些个人信息问题,当前各国的个人信息法律制度所采用的是“个人控制”的治理模式,这种模式以信息主体的“知情-同意”为基本实现机制,以信息主体的删除权、被遗忘权、数据携带权等个人信息权利为基本保障,力图通过增强信息主体对于个人信息的控制能力来保护个人信息的安全和信息主体的相关权益。“个人控制”模式的基本理论假设在于,处于个人信息实践中的信息主体是拥有完全理性的个体,他们能够通过数据控制者所提供的“隐私政策”完整而准确地了解数据控制者处理其个人信息的范围、目的和方式,并在这些信息的基础上理性地评估其个人信息可能面临的风险,最后做出符合其自身利益最大化的决策。“个人控制”模式在面对复杂的个人信息问题时存在着缺陷,一方面其“理性人”假设不能准确地反映信息主体在面对复杂信息情况下的有限理性特征,数据控制者所提供的隐私政策所存在的形式冗杂、内容晦涩难懂等问题也加剧了信息主体的有限理性,因而将个人信息保护寄托在信息主体对于个人信息的个人控制上并不现实。另一方面,个人信息本身既具有私人属性又具有公共属性,在个人信息上附着着复杂的利益机构,涉及到了信息主体的个人权利、企业的商业利益、政府的公共管理利益以及社会公共利益,同时个人信息处理行为本身也会给第三方带来“负外部性”影响。“个人控制”模式将关注点过于聚焦在信息主体的权利保护上,忽略了与个人信息处理相关的其他主体的权利,一方面不利于个人信息的合理使用和自由流动,另一方面也会最终影响到个人信息保护目标的实现。“回应型”治理模式是一种针对“个人控制”模式的缺陷以及个人信息问题的特征所提出的新型治理模式,它以“回应型法”和现代治理理论中的相关理论洞见为理论渊源,并针对二者所存在共同点和不同点进行有效整合,形成一种因应大时代特征的个人信息问题治理模式。个人信息问题的“回应型“治理模式将治理的焦点从信息主体的个人控制权转移到数据控制者和监管机构的责任上来,提出了一种以“责任”为核心,以“数据正义”为目标,具有整体性、回应性的个人信息问题治理框架。在该模式下,解决个人信息问题的关键在于数据控制者和监管机构切实地履行好各自的相应责任,通过搭建一个多主体、多层次、多领域、多手段的具有整体性的治理网络,实现个人信息处理的相关成本和收益在诸参与者之间的合理分配。在具体的实现路径上,个人信息问题治理首先应促进多元主体之间的合作,建立不同政府部门之间以及公私主体之间的合作网络。其次,应加强政府在个人信息问题治理中的内部保护和外部监管责任,推动公共领域的个人信息问题治理以及政府对个人信息保护的“助推”。再次,应强化企业和互联网平台的内部治理责任,推动企业在生产与管理环节贯彻“通过设计的隐私保护”和数据保护影响评估等制度。最后,个人信息问题治理应综合采用法律、社会规范、技术以及算法规制等多元手段。

【Abstract】 In the era of Big Data,with the rapid advancement of technologies of data collection,data storage and data analysis and the surge in data volume,data has become an important production factor in the current society,thoese data that reflects the identities and social activities have become one of the most significant data types.Massive data and efficient data analysis technology have greatly changed the government’s public management,the business of enterprises and the pattern of personal lifestyle.One the one hand,the Internet,the Internet of Things,cloud storage,cloud computing,big data,and artificial intelligence,all of these Data-based technology forms bring great convenience to personal life,increase social production efficiency,and improve government public management methods.On the other hand,these technologies also bring a series of urgent problems to personal information.One side,personal information faces great security risks.The security vulnerabilities of data controllers may cause massive amounts of personal information to be leaked out,which brings great danger to the personal and property rights of data subjects,which is accompanied by personal information.Meanwhile,many "downstream crimes" and"secondary crimes" brought about by the leakage have exacerbated the harm and complexity of personal information leakage.On the other side,the abuse of personal information by the data controller may also damage the rights of the data subject.In particular,the algorithmic "automated decision-making" mechanism may bring discriminatory treatment to users and infringe the personal autonomy and the right to equality of users.In the face of these personal information issues,the current personal information legal systems in various countries adopt an "Individual control" governance model.This model uses the data subject’s "informed-consent" as the basic implementation mechanism,and the data subject’s personal information rights,such as the right to erase,the right to be forgotten,and the right to data portability as the basic guarantees.The governance model of "Individual control" strives to protect the security of personal information and the relevant rights and interests of the data subject by enhancing the data subject’s ability to control personal information.According to this assumption,data subjects can fully and accurately understand the scope and purpose of processing their personal information by the data controller through the "privacy policy" provided by the data controller,and based on this information they can rationally evaluate the risks that their personal information may face,and finally make decisions that are in line with their own interests.However,the model of "Individual control" model has huge shortcomings in the face of complex personal information issues.On the one hand,its "rational person"assumption cannot accurately reflect the limited rational characteristics of the data subject in the face of complex information.The privacy policy provided also has the problems of complicated form and obscure content.Therefore,it is not realistic to place the protection of personal information on the personal control of personal information by the data subject.On the other hand,personal information itself has both private and public attributes.There are complex interest institutions attached to personal information,which involve the rights of data subjects,the commercial interests of enterprises,the public management interests of the government,and the public interests of society.The personal information processing behavior itself will also have a "negative externality" impact on third parties.The "Individual control"model focuses too much on the protection of the rights of data subjects,while ignoring the rights of other subjects related to the processing of personal information.On the one hand,it is not conducive to the reasonable use and free flow of personal information,and on the other hand,it will ultimately affect the realization the goal of personal information protection.The "Responsive Governance" model takes the "Responsive Law" and relevant theoretical insights from modern governance theories as its theoretical sources,and shifts the focus of personal information governance from the personal control of data subjects to the responsibilities of data controllers and regulators.A holistic and responsive personal information governance framework with "responsibility" as the core and "data justice" as the goal is proposed.In the specific realization path,the governance of personal information issues should first promote the cooperation between multiple subjects,and establish a cooperation network between different government departments and between public and private subjects.Second,the government’s internal protection and external supervision responsibilities in the governance of personal information issues should be strengthened to promote the governance of personal information issues in the public domain and the government’s "Nudge" of personal information protection.Third,the internal governance responsibilities of enterprises and Internet platforms should be strengthened,and enterprises should be encouraged to implement systems such as "Privacy by Design" and data protection impact assessment in production and management.Finally,the governance of personal information issues should adopt multiple methods such as law,social norms,technology,and algorithm regulation.

  • 【网络出版投稿人】 厦门大学
  • 【网络出版年期】2024年 09期
  • 【分类号】D923;D922.16
节点文献中: 

本文链接的文献网络图示:

本文的引文网络