透過您的圖書館登入
IP:3.16.44.204
  • 期刊

個人資料去識別化(匿名與假名)國際規範趨勢與我國法制發展建議

International Trends in Personal Data De-identification (Anonymization and Pseudonymization) Regulations and Recommendations for Legal Development in Taiwan

摘要


個人資料商業價值提升衍生急遽增加的個人資料侵害行為與外洩問題,為確保民眾個人資料獲得妥適保障,主要國家無不正視制定個人資料保護專法的必要,並持續強化有關個人資料蒐集、利用、共享與國際傳輸之規範。另一方面,在個人資料成為當前數位經濟發展不可或缺的重要助力之下,主要國家也開始高揭「強化個人資料之活用」的重要性,並陸續採納「個人資料去識別化」此一嶄新概念,期透過技術措施藉以衡平個人資料之保護與活用。個人資料去識別化簡言之係指「透過技術方法使資料本身無從識別特定自然人」,當前並區分為個人資料的「匿名化」「假名化」,前者要求去識別化處理必須達到無從識別特定自然人且「不可復原」之程度,而後者則仍保有再識別之可能。本文詳加比較主要國家個人資料去識別化(匿名與假名)規範設計,特別是針對匿名化與假名化推動訂有專門規定之日本進行分析,並立於比較法之基礎上,相應觀察我國個人資料保護法制規範現況,本文建議我國針對匿名化及假名化在內之個人資料去識別化機制推動,初期宜以發布指引方式進行規範,中長期再視實務現況評估於個人資料保護法制定專門規範。

並列摘要


The increasing commercial value of personal data has led to a surge in privacy violations and data leaks. To ensure adequate protection of personal data, major countries recognize the necessity of enacting comprehensive data protection legislation and continually strengthening regulations surrounding data collection, usage, sharing, and international transfer. On the other hand, as personal data becomes an indispensable driver of today's digital economy, major countries are also emphasizing the importance of enhancing the utilization of personal data. Many have adopted the novel concept of "de-identification" through technical measures to strike a balance between data protection and utilization. In short, de-identification refers to the process of making data non-identifiable to any specific individual through technical means. Currently, this concept is categorized into "anonymization" and "pseudonymization." Anonymization requires that de-identified data cannot identify any specific individual and is "irreversible," while pseudonymization retains the potential for re-identification. This article provides a detailed comparison of de-identification regulations (anonymization and pseudonymization) in major countries, with a focus on Japan, where specific provisions on anonymization and pseudonymization have been enacted. Based on comparative law, it also examines the current regulatory framework in Taiwan. The author suggests that, initially, Taiwan should promote de-identification mechanisms, including anonymization and pseudonymization through guidelines. In the medium to long term, it would be advisable to assess practical developments and consider establishing dedicated regulations under Personal Data Protection Act.

參考文獻


江耀國,黃子宴(2019).個人資料的概念與匿名化:一個認識論的觀點.東海大學法學研究.58,1-62.
吳全峰,許慧瑩(2018).健保資料目的外利用之法律爭議-從去識別化作業工具談起.月旦法學雜誌.272,45-62.
郭戎晉(2016).日本個人資料保護法修正重點與去識別化推動剖析.科技法律透析.28(6),43-52.
郭戎晉(2022).從美國兒童線上隱私保護法檢視數位時代兒童個人資料保護法制推動課題.交大法學評論.10,131-193.
郭戎晉(2022).競爭法與隱私法之界線暨判斷標準之研究.公平交易季刊.30(4),1-55.

延伸閱讀