银保监会开展侵害个人信息权益乱象专项整治新规速递(中英双语版)

来源:金诚同达

文章摘要
2022年8月,银保监会办公厅向各银保监局,各大型银行、股份制银行、外资银行、直销银行、理财公司,各保险集团(控股)公司、保险公司下发《关于开展银行保险机构侵害个人信息权益乱象专项整治工作的通知》。

2022年8月,银保监会办公厅向各银保监局,各大型银行、股份制银行、外资银行、直销银行、理财公司,各保险集团(控股)公司、保险公司下发《关于开展银行保险机构侵害个人信息权益乱象专项整治工作的通知》。通知要求各银行保险机构对照通知所附“银行保险机构侵害个人信息权益乱象主要表现形式”,全面摸排本机构2021年以来与消费者个人信息处理活动相关的经营行为和管理情况,深入查找本机构个人信息保护方面存在的问题,进行相应整改。
In August 2022, the General Office of CBIRC issued the Circular on Carrying out the Special Rectification of Irregularities of Banking and Insurance Institutions Infringing upon Personal Information Rights and Interests to all CBIRC local bureaus, all large banks, joint-stock banks, foreign-funded banks, direct-selling banks, wealth management companies, and all insurance group (holding) companies and insurance companies. The Circular requires that banking and insurance institutions refer to its attachment “Main Forms of Irregularities of Banking and Insurance Institutions Infringing upon Personal Information Rights and Interests”, comprehensively sort through their business and management activities related to the processing of consumers’ personal information since 2021, thoroughly identify the problems in their personal information protection work, and carry out rectification accordingly.
本次专项整治工作有三个阶段:一、自查整改阶段。2022年8-9月,各银保监局组织辖内银行保险机构(含保险专业中介机构)认真开展对照自查,在自查基础上及时完成整改。各银行保险机构应于2022年9月20日前完成自查整改并书面报告属地银保监局,银保监会直接监管的银行保险机构应于9月20日前将自查整改报告及有关自查发现问题及整改情况附表报送银保监会消费者权益保护局,抄送对口机构监管部门。二、监管抽查阶段。2022年9-11月,各银保监局在机构自查基础上开展监管抽查。抽查对象和抽查数量由各银保监局根据辖区情况自行决定。三、总结汇报阶段。各银保监局应于2022年12月20日前,向银保监会消费者权益保护局报送银行保险机构侵害个人信息权益乱象专项整治工作报告及相关附表。
The special rectification will be carried out in three phases: 1.Self-inspection and rectification phase. From August 2022 through September 2022, all CBIRC local bureaus should organize banking and insurance institutions (including professional insurance intermediaries) within their respective jurisdictions to conduct self-inspection thoroughly and complete rectification timely. Banking and insurance institutions are required to submit a written report on the self-inspection and rectification, together with the completed exhibits of identified problems and status of rectification, to their local CBIRC bureaus or, in the case of those institutions directly supervised by CBIRC headquarters, to the Consumer Rights Protection Bureaus of CBIRC, with a copy to their corresponding institutional supervisory departments, by September 20, 2022. 2.Random regulatory inspection phase. From September 2022 through November 2022, all CBIRC local bureaus should conduct random regulatory inspection on the basis of the self-inspection. The sampling targets and numbers should be determined by each CBIRC local bureau in light of its actual circumstances. 3.Concluding and reporting phase. Each CBIRC local bureau should submit a work report on the special rectification, together with certain completed exhibits, to the Consumer Rights Protection Bureau of CBIRC by December 20, 2022.
通知要求,对短期无法整改完成的问题,要建立整改台账,明确整改措施,逐步逐项推进。通知要求强化整治问责,出现泄露个人信息等产生侵害消费者信息安全权问题的,要问责到人。通知要求银行保险机构和各银保监局成立专项工作组,制定专门工作方案。相关整改要全面覆盖与消费者个人信息处理相关的业务环节、员工行为和管理流程。
The Circular requires that, for problems identified but not rectifiable within a short time, the banking and insurance institutions should maintain a log book, specify rectification measures and carry out rectification on a step-by-step and item-by-item basis. The Circular requires accountability, and the relevant individuals should be held accountable for leaks of personal information and other serious infringement upon consumers’ information security rights. The Circular requires banking and insurance institutions and all CBIRC local bureaus to establish a working group and formulate a work plan for the special rectification. The Circular requires the special rectification to comprehensively cover all the business and management processes as well as employee behaviors related to the processing of consumers’ personal information.
通知列举的银行保险机构侵害个人信息权益乱象表现形式主要有:
The Circular has listed, among other things, the following main forms of irregularities of banking and insurance institutions infringing upon personal information rights and interests:
个人信息收集。在未取得消费者同意的情况下,利用移动互联网应用程序(App)获取手机通讯录、监测输入内容、监听语音收集消费者个人信息;未在官网、App主动披露隐私政策;通过非法途径盗取或购买消费者个人信息等。超出业务办理所必需的范围收集个人信息。强制要求同意使用信息。要求给予不合理的授权。要求概括授权。消费者信息审核不严谨。
Collection of personal information. Without the consent of consumers, acquiring cellphone contact lists, monitoring input contents or monitoring voice information to collect consumers’ personal information via mobile applications (Apps); failing to actively disclose its privacy policy on its official website and App; or stealing or purchasing consumers’ personal information through illegal channels, etc. Collecting personal information beyond the necessary scope for handling business. Mandatory consent to use of information. Requesting unreasonable authorizations. Requesting general authorizations. Careless review of consumer information.
个人信息存储和传输。如电子数据存储管理混乱,违反规定下载、存储、记录消费者敏感个人信息;纸质材料保存管理混乱;通过不安全渠道传输个人信息;因系统或操作原因导致信息外泄。
Storage and transmission of personal information. For example, lousy management of electronic data storage, and downloading, storing or recording consumers’ sensitive personal information in violation of regulations; lousy management of paper file storage; transmitting personal information through insecure channels; and leaking personal information due to system or operational problems.
个人信息查询。如银行账户信息查询业务操作不规范,存在未按规定留存查询授权材料、未经消费者同意私自查询、虚构理由和业务背景查询信息等问题;保险公司未对查询权限严格限制,导致不具备权限的员工可以查询完整的保单号、投保人和被保险人证件号码、联系电话、联系地址等未经脱敏处理的个人信息等。
Inquiry of personal information. For example, bank account information inquiry is not well-managed, failing to retain authorization files required for inquiries, information inquiring without the consent of consumers, and fabricating reasons and business backgrounds for information inquiring; and insurance companies failing to strictly limit the inquiring authority, with the result that employees without the authority have access to personal information not desensitized, such as policy numbers, ID numbers of insurance applicants and the insured, contact telephone numbers and addresses in their entireties.
个人信息使用。如个人信息被用于不当营销、不当催收、消费者撤回同意后继续使用,以及在未经消费者同意的情况下,利用已获得的消费者个人信息,擅自为消费者办理业务或冒充消费者办理业务等。
Use of personal information. For example, using personal information for improper marketing and improper debt collection, and continuously using personal information after consumers’ withdrawal of consent, and using consumers’ personal information already obtained to, without the consumers’ consent, handle business for the consumer or impersonate the consumer to handle business.
个人信息提供。如未经同意向他人或外部机构提供信息。在无法定事由,且未获得消费者同意的情况下,将消费者个人信息提供给外部机构或其他个人;向外部机构或个人贩卖消费者个人信息;违反法律法规和相关规定向境外提供个人信息。
Provision of personal information. For example, providing information to other individuals or external institutions without consent. Without a legal cause and the consent of consumers, providing consumers’ personal information to external institutions or other individuals; selling consumers’ personal information to external institutions or individuals; providing personal information to overseas parties in violation of laws, regulations and relevant rules.
个人信息删除。如未对各类消费者个人信息电子数据和纸质材料规定保存期限和到期删除、销毁要求,未明确删除、销毁的程序和方式;未及时删除个人信息。
Deletion of personal information. For example, failing to specify the retention period for various electronic data and paper files of the consumers' personal information of failing to specify the requirements for deleting and destroying such data and files upon expiry of the retention period, or failing to specify the procedures and methods for deletion and destruction; failing to delete the personal information in a timely manner.
第三方合作。如向第三方合作机构提供个人信息超出合作业务必须范围、未进行必要脱敏;未使用有效加密方式通过互联网等不安全渠道向第三方合作机构传输个人信息等。
Cooperation with third parties. For example, providing third-party cooperation institutions with personal information beyond the necessary scope of the cooperating business or without necessary desensitization; transmitting personal information without effective encryption to third-party cooperating institutions in an insecure way such as the internet, etc.
如需该通知附件“银行保险机构侵害个人信息权益乱象主要表现形式” 全文的中英文版本,请邮件联系我们jtninsurance@jtn.com。
If you need a bilingual version of the full text of the “Main Forms of Irregularities of Banking and Insurance Institutions Infringing upon Personal Information Rights and Interests” attached to the Circular, please contact us at jtninsurance@jtn.com.

技术驱动法律,专业成就未来