肖君拥, 张雪亭. 欧盟数据保护影响评估制度及其镜鉴[J]. 电子科技大学学报社科版, 2022, 24(5): 18-29, 52. DOI: 10.14071/j.1008-8105(2022)-4005
引用本文: 肖君拥, 张雪亭. 欧盟数据保护影响评估制度及其镜鉴[J]. 电子科技大学学报社科版, 2022, 24(5): 18-29, 52. DOI: 10.14071/j.1008-8105(2022)-4005
XIAO Jun-yong, ZHANG Xue-ting. On EU’s Data Protection Impact Assessment System and Its Reference to China[J]. Journal of University of Electronic Science and Technology of China(SOCIAL SCIENCES EDITION), 2022, 24(5): 18-29, 52. DOI: 10.14071/j.1008-8105(2022)-4005
Citation: XIAO Jun-yong, ZHANG Xue-ting. On EU’s Data Protection Impact Assessment System and Its Reference to China[J]. Journal of University of Electronic Science and Technology of China(SOCIAL SCIENCES EDITION), 2022, 24(5): 18-29, 52. DOI: 10.14071/j.1008-8105(2022)-4005

欧盟数据保护影响评估制度及其镜鉴

On EU’s Data Protection Impact Assessment System and Its Reference to China

  • 摘要:
    目的/意义 欧盟《通用数据保护条例》(GDPR) 创设的数据保护影响评估( DPIA) 制度对数据风险防控具有重要意义。借鉴欧盟DPIA制度可以助益于我国企业数据合规、重要数据的保护、数据安全风险评估标准的构建。
    设计/方法 首先,通过梳理DPIA制度的演化背景、理论基础,全面剖析欧盟DPIA制度的应用场景、评估流程、保护模式及惩罚机制。其次,通过梳理相关案例,对事实层面和规范层面我国建立数据影响评估制度的必要性进行分析。再次,对比我国个人信息安全影响评估(PISIA)制度与欧盟DPIA制度在适用阶段、评估目标、评估产物等相关规定的异同,可知前者侧重于对个人信息数据泄露后会对数据主体的影响维度进行分析,后者侧重于对数据主体权益保障维度的分析。最后,以问题为导向,对我国数据保护影响评估制度的建立提出相关建议。
    结论/发现 完善数据安全风险评估标准的研制、提升数据安全风险评估质效、构建全方位的数据监管体系,不仅是构建法治化的数据安全风险评估制度的需要,更是我国经济实现数字化转型、构建数据安全保障治理体系的迫切需求。

     

    Abstract: Purpose/Significance The Data Protection Impact Assessment (DPIA) system created by the EU General Data Protection Regulation (GDPR) is of great significance to data risk prevention and control. Learning from the EU’s DPIA system can help China’s enterprise data compliance, the protection of important data, and the construction of data security risk assessment standards. Design/Methodology Firstly, by sorting out the evolution background and theoretical foundation of DPIA system, we comprehensively analyze the application scenario, assessment process, protection model and punishment mechanism of EU DPIA system. Secondly, by sorting out relevant cases, the necessity of establishing data impact assessment system in China at the factual level and normative level is analyzed. Then, comparing the similarities and differences between China’s personal information security impact assessment (PISIA) system and the EU DPIA system in terms of application stages, assessment objectives, assessment products and other relevant regulations, it can be seen that the former focuses on the analysis of the impact dimension of data subjects that will be affected by personal information data leakage, while the latter focuses on the analysis of the dimension of data subjects’ rights and interests protection. Finally, with a problem-oriented approach, relevant suggestions are made for the establishment of the data protection impact assessment system in China. Conclusions/Findings Improving the development of data security risk assessment standards, enhancing the quality and effectiveness of data security risk assessment, and building a comprehensive data supervision system are not only necessary for building a rule-of-law data security risk assessment system, but also an urgent need for China’s economy to realize digital transformation and build a data security guarantee governance system.

     

/

返回文章
返回