江西财经大学学报 ›› 2022, Vol. 0 ›› Issue (3): 126-136.

• 法与经济 • 上一篇    下一篇

个人信息保护风险规范的建构机理与实现路径

张璐   

  1. 清华大学 法学院,北京 100084
  • 收稿日期:2021-11-17 修回日期:2022-03-17 出版日期:2022-05-25 发布日期:2022-06-15
  • 作者简介:张璐,清华大学、牛津大学联合培养博士研究生,主要从事民商法学、计算法学、数据法学研究,联系方式zhang-118@mails.tsinghua.edu.cn.
  • 基金资助:
    国家社会科学基金重大项目“互联网经济的法治保障研究”(18ZDA149); 中国法学会民法学研究会青年学者项目“我国个人私密信息的界分与保护研究”(2020MFXH007)

The Construction Mechanism and Realization Path of Risk Specifications for Personal Information Protection

ZHANG Lu   

  1. Tsinghua University, Beijing 100084, China
  • Received:2021-11-17 Revised:2022-03-17 Online:2022-05-25 Published:2022-06-15

摘要: 数字时代的个人信息制度是一种前置性保护规范,旨在防范因个人信息被滥用而可能产生的抽象危险。个人信息保护的风险规范路径符合数字经济发展现实,是数字时代个人信息保护的最佳范式。个人信息处理行为引发的风险可以通过“结果”和“行为”两种角度予以评估,对个人权益侵害“高风险”的判断包括风险发生可能性和风险严重程度两个方面。可归责性原则是风险规范路径的基本原则,中国个人信息保护制度综合“自下而上”和“自上而下”两种风险规制的实现路径,在差异化风险、类型化平台、分层级义务等方面仍存在问题,应从宏观上整体把控风险路径,中观上强化信息处理者的规范引导,微观上细化不同场景下的风险规范,形成一整套风险可控、高效全面的保护机制。

关键词: 个人信息保护, 风险影响评估, 风险规范, 隐私权, 数据合规

Abstract: The personal information system in the digital age is a pre-emptive protection norm, which aims to prevent the abstract danger that may arise from the abuse of personal information. The risk specification path of personal information protection is in line with the reality of the development of the digital economy and is the best paradigm for personal information protection in the digital age. Risks triggered by personal information processing behaviors can be assessed from the two perspectives of “results” and “behaviors”. The judgment of “high risk” in personal rights violations includes two aspects: the possibility of risk occurrence and the severity of risks. The principle of accountability is the basic principle of the risk regulation path. China’s personal information protection system integrates the two risk regulation paths, i.e., “bottom-up” and “top-down”, but there still exist such problems as differentiated risks, categorized platforms, hierarchical obligations, etc. It is necessary to control the risk path as a whole from the macro level, strengthen the normative guidance of information processors from the meso level, and detail the risk norms under different scenarios on the micro level, so as to form a set of risk controllable, highly efficient and comprehensive protection mechanism.

Key words: personal information protection, risk impact assessment, risk specifications, privacy right, data compliance

中图分类号: