| 英文摘要 |
Government platforms are, in essence, constructs of public law. Their core lies in the exercise of administrative service powers and platform governance powers, accompanied by auxiliary elements of rights participation. Accordingly, their privacy policies should be governed by the principle of“necessity for the performance of statutory duties,”with mechanisms such as informed consent functioning only as exceptions. However, an empirical examination of thirty-three privacy policies reveals that government platforms generally misapply a private-law-dominated paradigm: informed consent is established as the basic principle and central rule, while the performance of statutory duties is downgraded and restricted to an exceptional circumstance. The formation of this paradigm stems from the combined influence of civil-law reasoning and security-oriented thinking, and it has profoundly shaped both the Personal Information Protection Law and the practical development of government platforms. To achieve a reconstruction grounded in public law, the key lies in clarifying the relationship between public-law and private- law norms governing personal information processing—norms that differ in detail and emphasis but are equal in normative force. Each government platform should establish a dual-structure“Notice on Personal Information Processing Rules”grounded in public law, while retaining, as a subsidiary instrument, a private-law-based“Privacy Policy.”A public-law-dominated model does not exclude the application of private law; rather, it can effectively overcome the dilemma of“symbolic legislation”and, by leveraging the characteristics of power aggregation and risk filtering inherent in government platforms, provide a general public-law framework for personal information processing within the construction of a digital rule-of-law government. |