信息通信技术与政策

信息通信技术与政策

信息通信技术与政策 ›› 2023, Vol. 49 ›› Issue (3): 74-79.doi: 10.12267/j.issn.2096-5931.2023.03.012

产业与政策 上一篇    下一篇

个人信息保护合规疑难问题研究*

A probe into difficult issues of personal information protection compliance

张夕夜, 王莎   

  1. 中国信息通信研究院知识产权与创新发展中心,北京 100191
  • 收稿日期:2023-02-12 出版日期:2023-03-25 发布日期:2023-04-06
  • 作者简介:
    张夕夜,中国信息通信研究院知识产权与创新发展中心工程师,主要从事企业合规治理、数据合规、个人信息保护等方面的研究工作;
    王莎,中国信息通信研究院知识产权与创新发展中心科技市场发展部副主任,主要从事个人信息保护等方面的研究工作。
  • 基金资助:
    *中华人民共和国最高人民法院重大课题项目(ZGFYZDKT202212-01)

ZHANG Xiye, WANG Sha   

  1. Intellectual Property and Innovation Development Center, China Academy of Information and Communications Technology, Beijing 100191, China
  • Received:2023-02-12 Online:2023-03-25 Published:2023-04-06

摘要:

企业在落实《个人信息保护法》规定的合规义务时,经常会遇到规则不清晰、不明确,且无法得到合规确认等问题。此外,《个人信息保护法》并非企业个人信息保护全部合规义务来源,不同法律法规之间也存在要求不一致的情况,从而将企业置于两难的合规困境。通过对个人信息保护规则落实情况的调研,梳理企业在个人信息保护合规中遇到的疑难问题,进而分析个人信息保护合规体系构建和持续改建的可行路径。

关键词: 个人信息保护合规, 匿名化, 书面同意, 强制缔约

Abstract:

When enterprises implement obligations stipulated in the Personal Information Protection Law of the People’s Republic of China, they encounter problems such as unclear regulations, and being unable to obtain compliance confirmation. In addition, the Personal Information Protection Law is not the only source of all the compliance obligations of enterprises for the protection of personal information. There are inconsistent requirements among different laws and regulations, which puts the enterprises in a compliance dilemma. Through the investigation of the implementation of the personal information protection rules, this paper sorts out the difficult issues encountered by the enterprises in the personal information protection compliance, and then analyzes the feasible path for the construction and the continuous improvement of the compliance system.

Key words: personal information protection compliance, anonymization, written consent, compulsory contracting

中图分类号: