2020-06-15
自2018年5月25日生效以来,欧盟数据保护条例(GDPR)已经走过了2年历程。这期间,围绕条例实施效果,存在问题,已有许多第三方开展了相关的评估报告(如:来自美国国家经济研究局(NBER)的报告)。相比之下,来自执法第一线欧盟各成员国监管机构的声音较少。
相比1995年数据指令,GDPR尤为显著的变化是极大扩展了适用范围。GDPR第2条规定,即使机构在欧盟以外,但只要在提供产品或者服务的过程中(不论是否收费)处理了欧盟境内个体的个人数据,将同样适用于条例。域外效力的延伸,显然能够为欧盟用户带来更为完整的保护,但在实践中却给监管部门带来难题。
注释: [1]欧盟理事会已将这19个报告汇总在一起,下文提到的各国报告都可通过查阅汇总报告获得。Preparation of the Council position on the evaluation and review of the General Data Protection Regulation (GDPR) - Comments from Member States,https://data.consilium.europa.eu/doc/document/ST-12756-2019-REV-1/en/pdf. [2] Council position and findings on the application of the General Data Protection Regulation (GDPR) – Adoption,https://data.consilium.europa.eu/doc/document/ST-14994-2019-REV-1/en/pdf. [3] https://edpb.europa.eu/news/news/2019/1-year-gdpr-taking-stock_en [4] https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COMMITTEES/LIBE/DV/2019/02-25/9_EDPB_report_EN.pdf [5] Harris M, Patten K, Regan E, Fjermestad J, Harris M (2012) Mobile and connected device security considerations : a dilemma for small and medium enterprise business mobility? In: AMCIS 2012 [6] See Lothar Determann , Representatives under Art. 27 of the GDPR: All your questions answered,https://tmt.bakermckenzie.com/-/media/minisites/tmt/files/2018/10/representatives-under-art-27-of-the-gdpr-iapp-2018.pdf?la=en [7] https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en [8] Se https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_ene Bulgaria, fines in millions for personal data breaches, https://www.lexology.com/library/detail.aspx?g=6356ed78-03c2-48d0-add2-c8848bfc60c9. [9] https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COMMITTEES/LIBE/DV/2019/02-25/9_EDPB_report_EN.pdf [10]零知识证明技术指的是证明者能够在尽可能少向验证者提供甚至不提供任何有用的信息的情况下,使验证者相信某个论断是正确的。AHN Gail-Joon, “Zero-knowledge proofs of retrievability”, Science China (Information Sciences), Vol.10(8), 2011, pp.1608-1617. [11]差异隐私技术指的是从统计数据库查询时,最大化数据查询的准确性,同时最大限度减少识别其记录的机会,这种机制的核心是给查询的结果增加一定的噪点。Mannhardt, Felix, “Privacy-Preserving Process Mining”, Business & information systems engineering, Vol.61(5), 2019, pp.595-614. [12] See European Commission, White Paper on Artificial Intelligence: a European approach to excellence and trust,https://ec.europa.eu/info/publications/white-paper-artificial-intelligence-european-approach-excellence-and-trust_en 作者 | 王 融 腾讯研究院资深专家
作者 | 朱军彪 腾讯研究院助理研究员