从认证全过程视角理解与完善个人信息保护认证制度
网络安全与数据治理 11期
聂磊磊
(中国人民公安大学法学院,北京100038)
摘要: 个人信息保护认证与个人信息跨境提供中其他出境制度相比,可以实现个人信息安全与自由流动之间的平衡,比安全评估制度具有更自由的流动性,比标准合同具有更稳定的安全性。在全球数据经济逐渐占据主导地位的今天,个人信息保护认证制度有其巨大的实施价值。同时,认证机构作为个人信息保护认证中关键的一环,要求认证机构具有公平性和专业性的资质,在认证中保持客观中立并发挥应有的专业水平。然而,个人信息保护认证制度在我国刚刚起步不久,相关法律规定还不完善,具体落实的几个方面都存在不足,主要包括认证前启动、认证中审查和认证后担责。因此,在认证前启动要秉持自愿认证与强制认证相结合;在认证中扩大可申请认证的主体范围,并建立分级分类认证标准制度;在认证后完善私法和公法双重救济途径。
中圖分類號(hào):TP315
文獻(xiàn)標(biāo)識(shí)碼:A
DOI:10.19358/j.issn.2097-1788.2023.11.008
引用格式:聶磊磊.從認(rèn)證全過程視角理解與完善個(gè)人信息保護(hù)認(rèn)證制度[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2023,42(11):39-45.
文獻(xiàn)標(biāo)識(shí)碼:A
DOI:10.19358/j.issn.2097-1788.2023.11.008
引用格式:聶磊磊.從認(rèn)證全過程視角理解與完善個(gè)人信息保護(hù)認(rèn)證制度[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2023,42(11):39-45.
Understand and improve the personal information protection certification system from the perspective of the whole certification process
Nie Leilei
(School of Law,People′s Public Security University of China,Beijing 100038,China)
Abstract: Compared with other export systems in the cross-border provision of personal information, personal information protection certification can achieve a balance between personal information security and free flow, and has freer mobility than the security assessment system, and has more stable security than standard contracts. Today, when the global data economy is gradually dominant, the personal information protection certification system has great implementation value. At the same time, as a key part of personal information protection certification, certification bodies are required to have fair and professional qualifications, maintain objectivity and neutrality in certification and give full play to their due professional level. However, the personal information protection certification system has just started in China, and the relevant laws and regulations are not perfect, and there are deficiencies in several aspects of specific implementation, mainly including pre-certification start, certification review and post-certification responsibility. Therefore, the combination of voluntary certification and compulsory certification should be adhered to before certification; Expand the scope of subjects that can apply for certification in certification, and establish a hierarchical and classified certification standard system; Improve the dual remedies of private law and public law after certification.
Key words : personal information export; personal information protection certification; certification bodies; the whole process of certification; equity of interests
0引言
個(gè)人信息保護(hù)認(rèn)證是個(gè)人信息出境中與安全評(píng)估、標(biāo)準(zhǔn)合同并列的出境制度,除了法律等有例外規(guī)定的場合,一般個(gè)人信息出境都可以適用認(rèn)證制度。認(rèn)證制度在我國傳統(tǒng)領(lǐng)域經(jīng)常適用,但自《個(gè)人信息保護(hù)法》實(shí)施后,個(gè)人信息保護(hù)認(rèn)證制度才開始運(yùn)用于我國個(gè)人信息出境的場景。雖然運(yùn)用至今仍在不斷發(fā)布指南為其具體落實(shí)提供指引,但實(shí)施的效果差強(qiáng)人意。因此,有必要對(duì)個(gè)人信息保護(hù)認(rèn)證制度實(shí)施以來的情況進(jìn)行分析,以實(shí)現(xiàn)個(gè)人信息安全與自由流動(dòng)之間的利益衡平。
本文下載請(qǐng)點(diǎn)擊:從認(rèn)證全過程視角理解與完善個(gè)人信息保護(hù)認(rèn)證制度AET-電子技術(shù)應(yīng)用-最豐富的電子設(shè)計(jì)資源平臺(tái) (chinaaet.com)
作者信息:
聶磊磊
(中國人民公安大學(xué)法學(xué)院,北京100038)

此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。
