上海大学学报(社会科学版) ›› 2022, Vol. 39 ›› Issue (4): 124-140.

• 法律学研究 • 上一篇    

信托关系视角下个人信息处理行为规则的类型化

  

  1. 上海交通大学 凯原法学院
  • 出版日期:2022-07-16 发布日期:2022-11-27

Classifying Rules of Behavior for Personal Information Processing in the Perspective of Trust Relationship

  • Online:2022-07-16 Published:2022-11-27

摘要: 个人信息处理是覆盖信息流动全过程的多种不同行为,具体信息处理行为的风险因场景变化存在差异,增加了形成具有统一标准之行为规则的难度。解决个人信息处理行为标准不统一问题需要纠正目前对个人信息处理行为规则缺乏类型化的错误导向,以重构个人与个人信息处理者之间的信托关系。个人信息处理行为规则应以法律规则的效力实现方式作为类型化标准,信息关系中具体信义义务的内容和范围作为考量因素,具体包括应为模式、勿为模式、可为模式三种规则类型。个人信息处理行为规则类型化在我国《个人信息保护法》中的解释需要明确个人信息处理者在应为模式下的覆盖信息处理全过程的告知义务和安全保护义务,勿为模式下的自动化决策要求和可为模式下的弹性化、场景化引导和激励措施,由此形成规则、标准、行业习惯的多元共治。

关键词: 个人信息处理, 行为规则, 信托, 类型化, 行为模式

Abstract: Given that personal information processing involves a variety of different behaviors throughout the process of information flow and that the risks of specific information processing behaviors change as processing scenes vary, the difficulty of forming a unified standard of rules of behavior increases. To formulate a unified standard, it is necessary to correct the misleading orientation that the current rules of behavior for personal information processing lack classification so as to reconstruct the trust relationship between individuals and personal information processors. In formulating rules of behavior for personal information processing, we should take the ways of realizing the validity of legal rules as the standard of classification while taking into consideration the content and scope of specific fiduciary duties in information relationships. The rules of behavior should include three types: should-do mode, not-to-do mode and can-do mode. The interpretation of the typology of the rules of behavior for personal information processing in The Personal Information Protection Law of China should see that throughout the process of information processing, personal information processors should take the obligations of notification and security protection under the should-do mode, meet the automatic decision-making requirements under the not-to-do mode and make flexible, scene-based guidance and incentive measures under the can-do mode, thus forming a multi-law co-governance under rules, standards and industrial conventions.

Key words: personal information processing, rules of behavior, trust, classification, behavioral mode