Font Size: a A A

Research On The Personal Information Security Obligation Of The Information Processor

Posted on:2023-06-29Degree:MasterType:Thesis
Country:ChinaCandidate:Z LiFull Text:PDF
GTID:2556306767453784Subject:Civil and Commercial Law
Abstract/Summary:
Article 1038 of the civil code establishes the information security protection obligation of information processors,which has become an important content of information protection.Theoretically,there are still some problems to be clarified,such as different concepts of obligation subjects,unclear boundary of obligation content,incomplete coverage of responsibility and so on.The subject of information security obligation is the information processor,including "personal information processor" and "trustee",excluding the natural person who processes information for personal or family affairs.The object of information security obligation is personal information,and its definition standard should adopt the dual progressive mode of "identification before Association".There are differences between information security obligation and security guarantee obligation in terms of obligation subject,content and basis,which have unique value.The legitimacy of the complex information security obligations undertaken by the information processor lies in that the personality attribute of personal information makes it related to the development of personality,and the property attribute makes the information processor profit.As the opener of dangerous situations,the information processor should take measures to prevent the occurrence of danger.The dominant position of the information processor makes the information subject lose control over the information,thus forming a special trust relationship,which becomes the basis for the establishment of information security obligations.The use of information is related to the development of public interests,so the obligation of information security has become an effective way to balance the use of information and information protection.The content of information security obligations can be divided into four categories:one is to provide safe information processing services.Including basic obligations such as using safe information processing hardware facilities,security training and not abusing information;Second,provide special protection for sensitive information rather than private information,and increase the obligations of information processors on dynamic risk management and regular risk notification of sensitive information;The third is to reduce the obligation of information identifiability.In the selection of specific measures,anonymization measures should be abandoned and the standards of de identification measures should be improved;Fourth,after the third party obtains the information,the obligation to prevent the third party from abusing the information.The behavior of the information processor increases the risk of information abuse and has considerable ability to control downstream damage.Therefore,it should bear the obligation to supervise the trustee and prevent the third party from abusing information.In order to balance the interests of both sides of information processing,the information security obligation only needs to reach the necessary limit.The judgment of necessity should comprehensively consider the legal,industrial and agreed standards,and the actual situation of the information subject and the information processor in the case.Through empirical investigation,it is found that the cases in which the information processor violates the information security obligation and assumes responsibility face the problems of different imputation principles,difficult identification of damage and unclear form of tort liability.In order to solve the practical dilemma,the principle of presumption of fault should be uniformly applied to the tort liability of all information processors.When determining the injurious behavior,the proof standard of the information subject should be appropriately reduced.When dealing with plural persons,if the causality cannot be judged,the joint dangerous act shall apply.In order to ensure that the information subject obtains compensation,the minimum compensation limit should be used.The form of tort liability of information processors for downstream damage is as follows: joint and several liability under the scenario of personal information processors jointly processing information;In the case of entrusted processing,due to the actual establishment of the contract,the Contractor shall bear the responsibility by share;Under their respective treatment scenarios,they shall bear the share responsibility according to Article 1172 of the civil code;In the case of infringement of the third party’s illegal access to information,article 1198 of the Civil Code shall be applied by analogy,bearing supplementary liability and enjoying the right of recourse.
Keywords/Search Tags:information processor, Information security protection obligations, Downstream damage, Liability for damages
Related items