月旦知識庫
 
  1. 熱門:
 
首頁 臺灣期刊   法律   公行政治   醫事相關   財經   社會學   教育   其他 大陸期刊   核心   重要期刊 DOI文章
國立臺灣大學法學論叢 本站僅提供期刊文獻檢索。
  【月旦知識庫】是否收錄該篇全文,敬請【登入】查詢為準。
最新【購點活動】


篇名
個人資料之去識別化與再識別化風險:法律之觀點
並列篇名
The Deidentification of Personal Data and its Risk of Reidentification: A Legal Perspective
作者 翁清坤
中文摘要
當前盛行以大數據技術進行資料研究分析,導出各種創新性推論或發現,以造福社會。惟資料廣泛運用時,亦漸形成隱私風險。
面對隱私保護與資料效用的衝突,倘將個資去識別化、匿名化,則不受個人資料保護法拘束,可移作原始蒐集目的外之利用或與第三人分享,以供各種運用。
惟大數據時代,有眾多資料來源可供交叉比對,不論去識別化或匿名化資料均難以維持不可逆、不可還原的狀態,而不可避免均有被再識別化風險,乃形成隱私等人格與經濟損害、表意自由的寒蟬效應。
一些知名的再識別化事件,使得去識別化的有效性漸受質疑。但有反駁,被再識別出來的比例實屬微小,去識別化仍屬有效機制。對此,美國法院見解亦相當分歧。
對於去識別化與再識別化的衝突,建議可採下列因應措施:(一)去識別化資料仍可能與其他資料相結合而再識別化,故較務實解決之道,應非在於完全排除再識別化風險,而應著重於減緩風險至極低程度。類似此風險忍
英文摘要
The concept of “personal data” as the cornerstone for information privacy laws seems workable. Any data relating to an identified or identifiable natural person will trigger the mechanism of personal data protection.
The operation of big data is to derive or infer hidden value from the structured and unstructured raw data through novel reuse. However, the reuse of personal data will be likely beyond the scope of original collection purpose, in violation of the principle of purpose limitation. Furthermore, the ubiquitous use of personal data will lead to privacy risk. As a consequence, one of the solutions is to deidentify personal data in order to use for further purposes or share with third parties.
However, in the age of big data, as the deidentified or anonymized data may be combined with other datasets from various sources, it is not likely to absolutely ensure “a person cannot be identified from a dataset.” The reidentification will cause damages to privacy, personality or property, and the chilling effect on freedom of expression.
As there were several famous reidentification cases in the past two decades, the effectiveness of deidentification or anonymization is gradually criticized. However, some scholars insist that the deidentification or anonymization is still effective in protecting privacy because the rate of reidentification is very small. Similarly, the U.S. courts are also divided in their effectiveness.
In facing the conflict between deidentification and reidentification, there could be some solutions. Firstly, the key point is to adopt a reasonable deidentification standard, thus reducing the risk of reidentification to a not important degree, rather absolutely ruling out its risk. Secondly, data controllers shall evaluate the risk of reidentification and thus adopt the technical, legal, and organizational safeguards subject to the principle of proportionality. Finally, statutes shall include civil and criminal liabilities in order to prohibit improper reidentification.
起訖頁 619-739
關鍵詞 個人資料隱私大數據識別符號去識別化匿名化再識別化表意自由風險忍受一般資料保護規則personal dataprivacybig dataidentifierdeidentificationanonymizationreidentificationfreedom of expressiontolerant of riskGeneral Data Protection Regulation
刊名 國立臺灣大學法學論叢  
期數 202309 (52:3期)
出版單位 國立臺灣大學法律學系
該期刊-下一篇 以生父認領推翻婚生推定:比較法上的觀察
 

新書閱讀



最新影音


優惠活動




讀者服務專線:+886-2-23756688 傳真:+886-2-23318496
地址:臺北市館前路28 號 7 樓 客服信箱
Copyright © 元照出版 All rights reserved. 版權所有,禁止轉貼節錄