月旦知識庫
月旦知識庫 會員登入|元照網路書店|月旦品評家
 
 
  1. 熱門:
首頁 臺灣期刊   法律   公行政治   醫事相關   財經   社會學   教育   其他 大陸期刊   核心   重要期刊 DOI文章
生物產業科技管理叢刊 本站僅提供期刊文獻檢索。
  【月旦知識庫】是否收錄該篇全文,敬請【登入】查詢為準。
最新【購點活動】


篇名
生成式AI之個人資料保護──以資料處理事由為核心
並列篇名
Personal Data Protection in Generative AI: Focusing on the Legal Bases for Data Processing
作者 莊晏詞
中文摘要
生成式人工智慧(Generative AI)快速發展,使個人資料保護面臨前所未有之挑戰。AI模型於資料蒐集、訓練及部署等各階段,均可能涉及大量個人資料之蒐集、處理與利用,因此資料處理合法依據已成為AI治理之核心議題。本文以義大利Replika裁罰案為例,分析主管機關對生成式AI資料處理合法性之審查重點,並聚焦於模型訓練階段之個人資料處理法律依據。在大型語言模型訓練情境下,逐一取得資料主體有效同意於實務上具有高度困難,且原始蒐集目的通常亦難涵蓋後續模型訓練用途,因此以同意作為主要法律依據存在相當限制。相較之下,歐盟GDPR第6(1)(f)條所規定之正當利益,已逐漸成為歐盟主管機關及學界討論AI模型訓練之重要法律依據。然而,正當利益之適用仍須通過合法利益、必要性及利益權衡等要件之審查,並結合資料最小化、透明性、匿名化、退出機制及資料保護影響評估等措施,以降低對資料主體權益之影響。最後,我國亦可參考正當利益權衡機制,以兼顧生成式AI創新發展與個人資料保護。
英文摘要
The rapid development of Generative Artificial Intelligence (Generative AI) has posed unprecedented challenges to personal data protection. Throughout the AI lifecycle, including data collection, model training, and deployment, large volumes of personal data may be collected, processed, and used. Accordingly, the legal basis for data processing has become one of the core issues in AI governance. This article uses the Italian Replika enforcement decision as a case study to examine the supervisory authority's assessment of the lawfulness of personal data processing in Generative AI systems, with a particular focus on the legal basis for personal data processing during the model training stage. In the context of large language model (LLM) training, obtaining valid consent from every data subject is highly impracticable. Moreover, consent originally obtained for a specific purpose of data collection generally does not extend to the subsequent use of personal data for AI model training. Consequently, consent as the primary legal basis for data processing is subject to significant limitations. By contrast, legitimate interests under Article 6(1)(f) of the General Data Protection Regulation (GDPR) have gradually become an important legal basis discussed by European supervisory authorities and scholars in relation to AI model training. Nevertheless, reliance on legitimate interests must satisfy the requirements of a legitimate interest, necessity, and the balancing of interests. In addition, appropriate safeguards, including data minimization, transparency, anonymization, opt-out mechanisms, and Data Protection Impact Assessments (DPIAs), should be implemented to reduce the impact on the rights and interests of data subjects. Finally, this article suggests that Taiwan may draw upon the legitimate interests balancing mechanism under the GDPR to achieve an appropriate balance between the development of Generative AI and the protection of personal data.
起訖頁 14-25
關鍵詞 生成式AI、一般資料保護規則、個人資料保護、generative AI、GDPR、data protection
刊名 生物產業科技管理叢刊  
期數 202607 (14期)
出版單位 財團法人全球生物產業科技發展基金會
該期刊-上一篇 Revisiting the Onco-Mouse Case: Animal Patents and the Moral Boundaries of Biotechnology Patent Law
該期刊-下一篇 意定監護法律風險管理實務
 

新書閱讀



最新影音


優惠活動




讀者服務專線:+886-2-23756688 傳真:+886-2-23318496
地址:臺北市館前路28 號 7 樓 客服信箱
Copyright © 元照出版 All rights reserved. 版權所有,禁止轉貼節錄