透過您的圖書館登入
IP:18.191.157.186
  • 期刊

科技智慧防疫與個人資料保護:陌生但關鍵的資料保護影響評估程序

Smart Technologies for COVID-19 Contact Tracing and Personal Data Protection: An Unfamiliar but Critical Data Protection Impact Assessment Process

摘要


社交距離App作為COVID-19的防疫科技利器,成功關鍵在於能否有超過半數以上之人口下載使用,因此如何取得人們對於此款App於個資保護作為上的信任而選擇下載使用,乃資料管控者無可迴避之任務。本文主張歐盟一般性個人資料保護規則(GDPR)第35條之資料保護影響評估(DPIA)程序,係該App提升個資保護信任的良方。DPIA程序除了能有資料管控者遵法責任滿足的確認、提供檢驗之後所進行的資料蒐用行為是否有按照規劃進行、提供主管機關監管內容的基礎之作用外,還能累積資料管控者就個資保護提升的底蘊,最終達到提升資料主體自由權利保護的作用。即便現行臺灣個人資料保護法並無明文規定DPIA,臺灣政府仍應藉此機會引入,樹立創新科技研發與個資保護雙贏之典範。DPIA即便於歐盟亦仍屬為人所陌生的個資保護程序,更遑論在臺灣。筆者希冀能藉由本文論述,讓國內得以熟悉DPIA程序於個資保護上扮演的角色,亦盼能在未來個資法修法時,提供導入此個資保護程序的參考。

並列摘要


A Taiwanese government agency charged with technology development has announced that it has successfully developed a new mobile software application named "social distance app" as a tool to prevent COVID-19 infection. For the App to be fully functional, it requires that at least 60% of persons living in Taiwan download to use the App. Given the high population required to use the App and the privacy concerns arising out of the contact tracing function, it is therefore an unavoidable task to provide a sufficient level of comport to users to ease their data protection concerns for using the App. This article has identified a feasible approach-Data Protection Impact Assessment (DPIA), a process for the developer to identify and to mitigate the data protection risks before launching the App. DPIA process provides the data protection officer with a mechanism for ensuring that the agreed actions are delivered within agreed timescales. Although Taiwan's data protection law has not made it mandatory for a DPIA to be put in place before the App is launched, it is advisable that the App developer take the initiative to implement the DPIA to set a model that the users can enjoy the benefits of technological innovation while their rights and freedoms are well protected. For the counterpart in the EU, DPIA has been introduced into the General Data Protection Regulation (GDPR) but it is still a new and unfamiliar process to most people, not to mention that DPIA has not been included into Taiwan's personal data protection laws. This article provides insights into the role of DPIA and examines why DPIA can serve as an effective tool of enhancing user's trust in using the App; furthermore, the article provides suggestions to introduce DPIA mechanism into Taiwan's personal data protection laws for the legislators to consider in a regulatory reform in the near future.

參考文獻


張陳弘(2016),〈個人資料之認定:個人資料保護法適用之啟動閥〉,《法令月刊》,67 卷 5 期,頁 67-101。https://doi.org/10.6509/TLM.2016.6705.04
許宗力(2012),〈論法律明確性之審查:從司法院大法官相關解釋談起〉,《臺大法學論叢》,41 卷 4 期,頁 1685-1742。https://doi.org/10.6199/NTULJ.2012.41.04.02
Gellert, R. (2017). The Article 29 Working Party’s Provisional Guidelines on Data Protection Impact Assessment. European Data Protection Law Review, 3(2), 212-217. https://doi.org/10.21552/edpl/2017/2/11
IT Governance Privacy Team (2019). EU General Data Protection Regulation (GDPR): An Implementation and Compliance Guide (3rd ed.). IT Governance Publishing. https://doi.org/10.2307/j.ctvr7fcwb
Mulligan, D. K., & Bamberger, K. A. (2019). Procurement as Policy: Administrative Process for Machine Learning. Berkeley Technology Law Journal, 34(3), 773-852. https://doi.org/10.2139/ssrn.3464203

延伸閱讀