上海大学学报(社会科学版) ›› 2023, Vol. 40 ›› Issue (1): 32-44.

• • 上一篇    下一篇

个人信息保护社会责任的法律内涵及其实现 

  

  1. 东华大学 人文学院,上海 200051
  • 收稿日期:2020-04-29 出版日期:2023-01-15 发布日期:2023-01-15

Social Responsibility for Personal Information Protection: Legal Contents and Realization

  1. College of Humanities, Donghua University, Shanghai 200051, China
  • Received:2020-04-29 Online:2023-01-15 Published:2023-01-15

摘要: 个人信息保护社会责任有助于督促以网络平台为代表的个人信息处理者通过自我规制维护用户信息安全。根据《中华人民共和国民法典》和《公司法》相关规定,守法守德和维护交易安全是企业社会责任条款的核心内涵。在《个人信息保护法》的规范体系下,守法守德既是检验个人信息处理者有效合规的重要依据,也为其建立差异化的合规体系提供了解释空间。维护交易安全可以被《个人信息保护法》中的安全原则所吸收,其规范意义仅限于遵守道德底线。在实施个人信息保护社会责任强制报告时,应以遵守或解释的方法来分离披露指标。建立健全合规体系是落实个人信息保护社会责任的重要途径,合规义务的履行应当在董事会和监事会同步下沉,由外部专业人员组成的个人信息保护监督委员会也应嵌入公司监事会并向其负责。此外,社会责任条款作为概括性规范也可进入司法裁判。

关键词:  , 个人信息保护;网络平台;权力话语;社会责任;合规体系

Abstract: Abstract: Social responsibility for personal information protection helps to urge personal information processors represented by online platforms to maintain the security of user’s information through self-regulation. According to the relevant provisions of the Civil Code and the Company Law, compliance with the law and the maintenance of transaction security are the core contents of the clauses of corporate social responsibility. Under the regulatory system of the Personal Information Protection Law, compliance with the law and ethics provides not only an important basis for testing the effective compliance of personal information processors, but also interpretation space for the establishment of a differentiated compliance system. Maintaining the security of transactions can be included in the security principles of the Personal Information Protection Law, the normative significance of which is limited to compliance with the ethical bottom line. When implementing mandatory reporting on social responsibility for personal information protection, we should separate the disclosure indicators by the method of compliance or interpretation. The establishment of a sound compliance system is an important way to implement social responsibility for personal information protection. Compliance obligations should be sunk simultaneously by the board of directors and the supervisory board. A personal information protection supervisory committee composed of external professionals should also be embedded in and accountable to the company’s supervisory board. In addition, social responsibility provisions as general norms may also enter into judicial decisions.

Key words: personal information protection, online platforms, power discourse, social responsibility, compliance systems

中图分类号: