个人信息保护合规的体系构建

敬力嘉

个人信息保护合规的体系构建

Constructing a Personal Information Protection Compliance System


    期刊名称:《法学研究》
    期刊年份:
    作者:敬力嘉
    单位:
    中文关键词:个人信息保护;企业合规;合规审计;侵犯公民个人信息罪
    英文关键词:personal information protection; enterprise compliance; compliance audit; the crime of infringing on citizens’ personal information
    中文摘要:
    作为企业管理工具,个人信息保护合规也存在被滥用的体系性风险。在分配个人信息处理风险时,应遵循比例原则的要求,合理限制公民个人、企业与国家公权力机关的个人信息处理自由,并以此作为个人信息保护合规的法理依据。企业在设计个人信息保护合规计划时,应遵循目的正当原则、区分原则、均衡原则与信赖原则。对企业进行个人信息保护合规审计时,应贯彻三阶审查法,即递进式审查合规计划的一般特征、具体要素及其功能、企业成员的具体行为。企业个人信息保护合规体系的底线,由侵犯公民个人信息罪划定。以企业的个人信息处理是否合规,以及企业领导人、合规负责人是否履行监管义务作为侵犯公民个人信息罪行为不法的评价标准,可有效保障本罪作为个人信息保护合规体系之底线的功能实现。
    英文摘要:
    Personal information protection compliance, as an enterprise management tool, faces a systemic risk of abuse. For this reason, when allocating the risk of the processing of personal information, the requirements of the principle of proportionality should be followed, and the freedom of individual citizens, enterprises and public authorities in processing personal information should be reasonably restricted, both of which should be taken as a legal basis of the compliance with personal information protection. Accordingly, when designing a compliance program for the protection of personal information, enterprises should follow the principles of legitimate purpose, distinction, balance and trust. When conducting a compliance audit of an enterprise's personal information protection, a three-step review method should be adopted, i.e., a progressive review of the general characteristics of the compliance program, the specific elements and their functions, and the specific acts of members of the enterprise. The bottom line of an enterprise's personal information protection compliance system is defined by the crime of infringing on citizens' personal information. By using the compliance of an enterprise's processing of personal information and the fulfillment of the supervisory obligations by the enterprise's leaders and compliance officers as the criteria to evaluate the wrongfulness of this crime, the bottom-line function of the crime can be effectively realized.
    全文阅读:  点击下载

相关文章!
  • 中国数据跨境调取路径探析——以

    特定情况下的数据跨境调取需要在传统的司法互助协定方式基础上补充其他路径。中国在坚持以双边司法互助协定和互惠原则为主要方式的基

  • 折中主义与理想主义之辩——评西

    美国西蒙尼德斯教授在新著的《全球冲突法立法:国际比较研究》一书中,提出晚近国际私法背离了萨维尼理论所追求的理想主义,呈现折中主义

  • 离岸信托避税规制的域外经验及

    作为信托的类型之一,离岸信托是指根据外国法律设立的信托。在信托本身固有的灵活机制之上,离岸信托充分利用了离岸管辖区的税收优势,成