透過您的圖書館登入
IP:3.142.35.75
  • 期刊

Legal Risks and Management Implications of Big Data Transactions-Focusing on the Re-identification of Personal Data

摘要


This paper focuses on the re-identification of personal data and discusses the legal risks and management implications of big data transactions. A comprehensive empirical study of the Taiwanese courts' decisions regarding the de-identification of personal data is conducted. The findings indicate that the courts are unaware of the risk of re-identification. In the Student Information case, the university recognized that de-identified personal data poses a re-identification risk. However, the court stated that further elaboration on this concern was unnecessary, thereby missing a critical opportunity to pass a judgment that would address re-identification risk. In the Health Insurance case, the Supreme Administrative Court focused on procedural concerns regarding whether the de-identification process should be performed by the data provider or the recipient, and denied the plaintiff's argument about re-identification risk. This paper proposes that a validation measure for determining whether specific individuals may be identifiable based on partial personal data and whether this process makes the whole of their personal data obtainable would be suitable for use in assessments of re-identification risk. In light of the proposed method, the Supreme Administrative Court's complete negation of the evidentiary method proposed by the plaintiff is debatable. Regarding a possible mechanism to reduce the re-identification risk, this paper argues that for most research, absolute precision is not required, and that the ideal approach for de-identification is the 〞generalization treatment,〞 which can balance the protection of personal data privacy and data usability. In this approach, the data provider must validate the efficacy of de-identification before transactions to ensure that the de-identification process has completely eradicated or substantially reduced the re-identification risk, thereby reducing the infringement risk. To validate whether the de-identification of big data is reliable, several datasets belonging to known individuals must be examined to confirm whether the individuals may identified from the datasets.

參考文獻


吳全峰與許慧瑩(2018a),「健保資料目的外利用之法律爭議一從去識別化作業工具談起」,月旦法學雜誌,第272期(1月),頁 45-61。
吳全峰與許慧瑩(2018b),「健保資料庫行政訴訟案:個資保護與健保資料之跨機關流動及二次利用」,月旦醫事法報告,第19期(5 月),頁61-87。
郭戎晉(2016),「日本個人資料保護法修正重點與去識別化推動剖析」,科技法律透析, 第28 卷,第6期,頁43-52。
蕭奕弘(2018),「健保資料庫行政訴訟案:醫學研究與資訊隱私間的衝突」,月旦醫事法報告,第19 期(5 月),頁 88-121。
童啟晟與劉心輸(2017年10月29日),「銀行大數據淘金做好五關鍵服務」經濟日報, (取得日期: 2018年10月20日),[available at https://money.udn.com/money/story/5612/2784733]

延伸閱讀