透過您的圖書館登入
IP:3.135.183.89
  • 會議論文
  • OpenAccess

利用Google表單蒐集個人資料之安全管理機制

摘要


無論政府部門或私人單位多有利用雲端服務進行個資蒐集,最常見的就是利用Google表單來做報名或蒐集資料,利用雲端服務蒐集個資並非完全不符合個人資料保護法,而是有需注意之安全維護措施。本研究以個人資料保護法(以下簡稱個資法)和個人資料保護法施行細則(以下簡稱個資法施行細則)所謂安全維護措施為基礎,探討使用Google表單蒐集個資時可能發生之問題或應注意事項。使用雲端服務時應考慮到設備安全管理、使用記錄、軌跡資料及證據保存、個人資料蒐集、處理及利用之內部管理程序、個人資料之風險評估及管理機制。本研究提出如何利用Google表單、App Script設定自動提醒信件以自動管理並留存使用記錄,並分析其他在利用雲端服務時應注意之事項。

並列摘要


The usage of cloud services has become more and more convenience in government agencies and enterprises. One of the most commonly used cloud services is Google Cloud Platform (GCP). It's not prohibited to use the cloud service for collecting personal information, but we need to do more to be conformable to the Personal Information Protection Act. In this study, we will suggest what needs to be aware when using Google Cloud Platform (GCP) for collecting personal information. According to enforcement rules of the Personal Information Protection Act, there are several issues associated with cloud services concerning managing facility security, keeping records of the use, locus information and proof, establishing an internal management procedure of collecting, processing, and using personal information, and establishing the mechanism of risk evaluation and management of personal information. In this study, we will provide a automatically app script for keeping records of the use and reminding the status of the data still on cloud storage. At the end we will share several cases of personal information leakage caused by using cloud service.

延伸閱讀