月旦知識庫
月旦知識庫 會員登入元照網路書店月旦品評家
 
 
  1. 熱門:
首頁 臺灣期刊   法律   公行政治   醫事相關   財經   社會學   教育   其他 大陸期刊   核心   重要期刊 DOI文章
当代法学 本站僅提供期刊文獻檢索。
  【月旦知識庫】是否收錄該篇全文,敬請【登入】查詢為準。
最新【購點活動】


篇名
論公司董事的數據安全保障義務
並列篇名
On the Data Security Protection Obligations of Company Directors
中文摘要
在數字經濟時代,公司數據安全已經成為影響公司利益和公司可持續發展的重要因素之一。由位於公司治理中心位置的董事們負擔數據安全保障義務,可以最大限度地降低數據安全風險的治理成本。然而,我國數據治理體系呈現組織法邏輯的缺失、負擔數據安全保障義務的主體不明以及對應責任的模糊,這導致我國並未續造出追究董事數據安全保障責任的司法與執法經驗,難以實現數據安全風險的終局性消解。觀察域外經驗發現,董事對公司數據安全負有保障義務已成為數據治理的共識,這對我國具有重要的啟示意義。首先,董事數據安全保障義務衍生於董事的信義義務,包括建置數據安全體系的義務、保障體系有效運行的義務、補救的義務、信息披露的義務以及推動公司建立匹配數據安全要求的董事會結構的義務,而且董事的數據安全保障義務與公司的數據安全保障義務並不等同;其次,對董事數據安全保障義務的審查應當配置較為嚴格的且體現差異的審查標準;最後,採納網絡安全保險以及董事責任保險機制,在鼓勵董事積極探索數據利用新模式與防範數據安全風險之間尋求平衡。
英文摘要
In the era of the digital economy, data has become another crucial factor of production following land, capital, technology, and management. As the primary organizational form for converting data into value, ensuring the data security of a company is one of the important factors affecting the company's interests and its sustainable development. Imposing the obligation to ensure data security on directors, who are positioned at the core of corporate governance, can minimize the governance costs of data security risks, prevent data violations by insiders within the company, and fill the loopholes in data laws. Moreover, this is also an inevitable requirement and an integral part of directors' fiduciary duties and duties of diligence. However, legislators and scholars in China have mostly emphasized the company's obligation to ensure data security, lacking regulations on the individual obligations and liabilities of members of corporate organs. The characteristics such as the absence of organizational law logic in the data governance system, the ambiguity of specific obligation subjects, and the vagueness of corresponding liabilities have led to the fact that China has not accumulated judicial and law enforcement experiences in holding directors accountable for data security, making it difficult to ultimately eliminate data security risks and failing to achieve a significant deterrent effect on lawbreakers. Observing foreign experiences, it has become a consensus in the comparative law that company directors have an obligation to ensure data security. Whether in common law countries or civil law countries, they are constantly exploring the connection paths between corporate law and data security laws, attempting to achieve the shift of the focus from organizations under behavioral law norms to individuals under organizational law norms under the provisions of directors' obligations, actively presenting the connotations of directors' obligations to ensure data security, and creating directors' liabilities for ensuring data security. This has important implications for China. Firstly, the directors' obligation to ensure data security is a redistribution at the corporate governance level of the company's obligation to ensure data security, and this obligation is part of the directors' duty of diligence. Secondly, directors' obligation to ensure data security can be categorized into the obligation to establish a data security system, the obligation to ensure the effective operation of this system, the obligation to remedy after data security incidents occur, the obligation to disclose information, and the obligation to promote the company to establish and shape a board of directors structure that matches data security requirements. Thirdly, the general negligence standard should be applied to the review standard for directors' violations of the obligation to ensure data security, breaking away from the traditional loose mode of reviewing directors' violations of the duty of diligence, assisted by the cost-benefit analysis method, and simultaneously configuring the review standards differently according to the types of companies and the identities of directors. Finally, adopting the mechanisms of cyber security insurance and directors' liability insurance to seek a balance between encouraging directors to actively explore new models of data utilization and preventing data security risks. In general, the coordinated linkage between corporate law and data law can achieve the closed loop of the data governance logic of ''data subject - data company - corporate organ'' and achieve a fundamental and symptomatic treatment of data risks.
起訖頁 57-69
關鍵詞 數據安全董事義務安全保障義務數據治理
刊名 当代法学  
期數 202503 (2025:2期)
出版單位 吉林大學
該期刊-上一篇 企業數據出資的法理邏輯與制度設計
該期刊-下一篇 國家治理體系中《民法典》制度的守正與創新
 

新書閱讀



最新影音


優惠活動




讀者服務專線:+886-2-23756688 傳真:+886-2-23318496
地址:臺北市館前路28 號 7 樓 客服信箱
Copyright © 元照出版 All rights reserved. 版權所有,禁止轉貼節錄