信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2022, Vol. 48 ›› Issue (4): 25-30.doi: 10.12267/j.issn.2096-5931.2022.04.005

产业与政策 上一篇    下一篇

金融数据合规管理研究

The research on financial data compliance management

张夕夜   

  1. 中国信息通信研究院知识产权与创新发展中心,北京 100191
  • 收稿日期:2022-01-17 出版日期:2022-04-15 发布日期:2022-05-09
  • 作者简介:
    张夕夜: 中国信息通信研究院知识产权与创新发展中心研究员,主要从事企业合规治理及数据安全、个人信息保护等研究工作

ZHANG Xiye   

  1. Intellectual Property Center, China Academy of Information and Communications Technology, Beijing 100191, China
  • Received:2022-01-17 Online:2022-04-15 Published:2022-05-09

摘要:

金融数据天然具有保密、资质等方面的要求,同时还需满足一般法意义上的数据合规义务。依据数据相关法律法规及金融行业规定及标准,明晰了金融数据合规的应为、可为及可不为。金融数据全面合规由基础性面向、主要性面向及辅助性面向合规构成,其中,基础性面向的合规要点包括保密要求、资质要求、关键信息基础设施安全,重要性面向的合规要点包括个人金融信息保护和重要数据安全,辅助性面向的合规要点包括采取技术措施、全流程管理、开展教育培训、加强风险监测等。纵观金融数据合规体系,个人金融信息保护及重要数据安全是重中之重。

关键词: 金融数据, 合规, 个人金融数据保护, 重要数据安全

Abstract:

Financial data naturally has the requirements of confidentiality and qualifications. At the same time, it also needs to meet the data compliance obligations in the sense of general law. In accordance with data-related laws and regulations, as well as the financial industry regulations and standards, clarify what should be done, what can be done and what can not be done in compliance with financial data. Comprehensive financial data compliance consists of basic compliance, materiality compliance and auxiliary compliances. Among them, basic compliance includes confidentiality requirements, qualification requirements, critical information infrastructure security, materiality compliance includes personal financial information protection and critical data security. Auxiliary compliance includes taking technical measures, full-process management, education and training, strengthening risk monitoring. Throughout the financial data compliance system, personal financial information protection and critical data security are the top priorities.

Key words: financial data, compliance, personal financial information protection, critical data security

中图分类号: