透過您的圖書館登入
IP:18.216.124.8
  • 期刊

從個人資料保護立法談cookie之定位、應用爭議與規範課題

Study on Issues of application and regulation of cookies under Data Protection laws

摘要


對身處數位時代的吾輩來說,cookie無疑是時下多數人聽聞過的名詞,但人們對於cookie的認識仍十分有限。在善加使用下,任何人可得輕易地將cookie與透過cookie取得的資料加以結合或比對,從而識別出特定自然人並進行商業運用。儘管網路使用者似已司空見慣允許網站或第三方蒐集有關個人的相關數據,藉以換取免費的網路服務,為合理規範cookie使用產生的個人資料保護爭議,歐盟電子隱私指令明確要求cookie使用上應事先取得使用者之同意。惟指令本身並未規定同意有效與否的判斷標準,係以資料保護指令同意規定為準,並於2018年5月後轉換為GDPR之對應規範。但實務操作上歷來持續存在紊亂情形與爭議作法,成員國之間的見解亦不盡相同,本文研究發現除英國與奧地利對於cookie方案和退出選擇有無違反GDPR看法歧異外,英、法兩國近期發布的cookie指引在分析cookie界線劃分以及cookie牆機制合法性亦見解迥異。惟歐盟成員國共通強調明確化有效同意的內涵與判斷標準之必要性,並就「自主性、具體及明確」等要件說明主管機關採納的尺度以及相對將視為無效同意之可能情形,不啻具有重要參考價值。本文並就國內個人資料保護法進行比較,發現個資法相關規定在cookie問題因應上尚有不足之處並對應提出後續法規調適之建議。

並列摘要


In technical terms, cookies are small computer files and stored in the web browser in order to remember information about the users and facilitate the website operators to track users' browsing activities and preferences. The EU ePrivacy Directive requires website operators to ask for a website user's consent when placing certain kinds of cookie on their devices for the first time. The law states that it should be informed consent and sufficient plain-language information should be provided to users. The e-Privacy regulation also harmonized with GDPR since Data Protection Directive was replaced in 2018. GDPR requires that consent for data processing be freely given, specific, informed and unambiguous, and can be withdrawn. An exception to this requirement is that users' consent is not required for cookies that are essential to delivering the service that users have requested. Prior to the introduction of the GDPR, it was widely accepted that consent could be obtained through using the cookie walls, p re-ticked boxes and other similar mechanisms. But with the announcement of two cookie guidelines enacted by UK and France in July 2019 and the preliminary ruling made by Court of Justice of the European Union in December 2019, the mere continued use of a website, pre-ticked checkbox or other implied consent schemes are no longer sufficient and should not constitute consent. This article will first discuss cookies generally and analysis the main normative challenges imposed by the use of cookies. Then examines the current EU cookie laws, points out the related questions about the application of ePrivacy Directive and GDPR and finally puts forward suggestions toward domestic legislation.

參考文獻


江耀國、黃子宴,個人資料的概念與匿名化:一個認識論的觀點,東海大學法學研究,第58 期,2019 年,頁 1-62。
李世德,GDPR與我國個人資料保護法之比較分析,臺灣經濟論衡,第 16 卷第 3 期,2018年,頁 69-93。
林玫君,論個人資料保護法之「當事人同意」,東海大學法學研究,第51期,2017年,頁121-170。
林玫君,大數據時代的個人資料保護,興大法學,第 24 期,2018 年,頁 1-45。
翁清坤,告知後同意與消費者個人資料之保護,臺北大學法學論叢,第87期,2017年,頁217-322。

延伸閱讀