GDPR评注学习笔记(9)--条文变迁(共同处理者、处理安全)

来源:数据何规

文章摘要
1.共同处理者 GDPR Proposal第24条对共同数据控制者进行规定,要求共同控制者间达成数据保护责任分配的“安排”来明确各自责任。

1.共同处理者
GDPR Proposal第24条对共同数据控制者进行规定,要求共同控制者间达成数据保护责任分配的“安排”来明确各自责任。GDPR Proposal第25条规定,处理与向欧盟公民提供商品或服务或监督其行为有关的欧盟公民数据的非欧盟控制者须任命一名在欧盟成员国设立的代表。
Albrechet议员的报告强化了共同控制者的义务,要求以书面形式明确分配各自角色和责任,并在其隐私政策中予以披露。LIBE委员会的文本修改此要求,要求此类安排应适当反映各处理者与个人之间的角色和关系,其重点是责任分配对个体来说清晰可追责。若共同控制人间的责任分配不明确,Albrecht报告将其共同责任限制于相关个人行使权利的情况下,但折衷文本规定,他们应承担连带责任。
欧盟理事会的文本增加了共同控制者决定如何遵守通知义务的义务,该协议还应指定由哪个共同控制者作为数据主体行使其权利的单一联络点。若数据主体被适当告知由哪个共同控制者负责,则数据主体应向该控制者行使其权利。若未作相关安排或者如果该安排对数据主体不公平,其可以对任何数据控制者行使权利。此外,欧盟理事会文本取消了议会文本规定的共同控制人之间的连带责任。GDPR遵循这种安排。
GDPR的共同控制者和《个保法》的共同处理者说的是一个意思,即“共同决定处理目的”。不同之处是《个保法》保留了连带责任,而GDPR要求指定一个处理者为联络人,并在隐私政策等文本中详细披露共同控制者责任分配。《个保法》之所以未作此规定是因为个人信息主体找谁都行,而且他们对外也是承担连带责任,所以内部责任如何划分也就无需披露了。
GDPR:Art. 26 Joint Controllers
第26条共同控制者
1.Where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers. They shall in a transparent manner determine their respective responsibilities for compliance with the obligations under this Regulation, in particular as regards the exercising of the rights of the data subject and their respective duties to provide the information referred to in Articles 13 and 14, by means of an arrangement between them unless, and in so far as, the respective responsibilities of the controllers are determined by Union or Member State law to which the controllers are subject. The arrangement may designate a contact point for data subjects.
1.共同数据控制者是指共同决定数据处理目标、条件和手段的两个或两个以上数据控制者。除非欧盟和成员国已经规定了数据控制者作为主体分别负担各自的责任外,他们应当共同以一种透明的方式安排其各自的责任以履行本法所规定的各项义务,尤其涉及数据主体行使 权利和本法第13 条和第14 条规定的各自通知义务。数据控制者的安排应当包括为数据主体指定一个联络点。
2.The arrangement referred to in paragraph 1 shall duly reflect the respective roles and relationships of the joint controllers vis-à-vis the data subjects. The essence of the arrangement shall be made available to the data subject.
2.本条第1 款所规定的内部安排应当完全反映各自的职责以及面对数据主体时共同数据控制者的关系。安排的实质内容应被数据主体获知。
3.Irrespective of the terms of the arrangement referred to in paragraph 1, the data subject may exercise his or her rights under this Regulation in respect of and against each of the controllers.
3.不论第1 款所述的内部安排如何规定,数据主体都可以根据本条例相关规定向每一位数据控制者行使权利。
《个保法》:第20条两个以上的个人信息处理者共同决定个人信息的处理目的和处理方式的,应当约定各自的权利和义务。但是,该约定不影响个人向其中任何一个个人信息处理者要求行使本法规定的权利。
个人信息处理者共同处理个人信息,侵害个人信息权益造成损害的,应当依法承担连带责任。
2. 数据处理的安全措施
GDPR Proposal包含了许多关于数据安全的重要条款。第30条对控制者和处理者规定了广泛的安全义务。
欧盟议会文本增加了安全政策的一些要素。其中包括确保个人数据完整性得到验证;确保处理个人数据的系统和服务的持续保密性、完整性、可用性和灵活性;在发生物理或技术事故时,能够及时恢复个人数据的可用性和访问权限;以及定期测试、评估和评估为确保持续有效性而制定的安全政策、程序和计划的有效性的过程。
欧盟理事会版本要求控制者和处理者实施适当的技术和组织措施,例如个人数据的假名化,以确保与数据处理带来的安全风险相适应的安全水平。此类措施应考虑处理的性质、范围、背景和目的,以及个人权利和自由风险的可能性和严重性。
《个保法》在这个条款还是吸收了很多GDPR的内容,大意均为采取与处理风险相适应的安全保护措施。如去标识化、应急响应措施等等。文本的规定还是比较虚,需要根据企业实际情况进行落地。
GDPR:
Art. 32 Security of processing
第32条 处理安全
2.Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
1.考虑到各国国内发展水平、实施成本和数据处理的性质、范围、内容和目的以及对自然人权利与自由带来风险的可能性( varying likelihood )与严重性数据控制者和处理者应当实施适当的技术和组织措施以确保安全水平与风险程度相一致,尤其包括如下内容:
a.the pseudonymisation and encryption of personal data;
个人数据的假名化机制和加密措施;
b.the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
确保处理系统和服务能够持续保持自身保密性,完整性,有效性和自我修复 的能力;
c.the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
在物理性或技术性事故中及时恢复个人数据的有效性和对个人信息访问的能力;
d.a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
实施一项定期测试、评估、评价技术性和组织性措施有效性的程序以确保 处理的安全性。
2.In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
2.为评估安全性的适当水平,尤其应当考虑处理行为所表现出来的风险,尤其是意外的或非法的损毁、丢失、修改、未经授权的披露或访问转移中的、存储中的或其他处理过程中的个人数据。
3.Adherence to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate compliance with the requirements set out in paragraph 1 of this Article.
3.可以将数据控制者或处理者对第40 条规定的已被认可的行为准则或第42条规定的已被认可的认证机制的遵守情况作为证明遵守本条第1 款规定的要求的因素。
4.The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.
4.除非欧盟或各成员国法律有所要求,数据控制者和处理者应当采取措施以确保任何依据对个人数据享有访问权限的数据控制者或处理者的授权行事的自确保任何依据对个人数据享有访问权限的数据控制者或处理者的授权行事的自然人非经数据控制者的指示不得处理这些数据然人非经数据控制者的指示不得处理这些数据。
《个保法》:第51条个人信息处理者应当根据个人信息的处理目的、处理方式、个人信息的种类以及对个人权益的影响、可能存在的安全风险等,采取下列措施确保个人信息处理活动符合法律、行政法规的规定,并防止未经授权的访问以及个人信息泄露、篡改、丢失:
(一)制定内部管理制度和操作规程;
(二)对个人信息实行分类管理;
(三)采取相应的加密、去标识化等安全技术措施;
(四)合理确定个人信息处理的操作权限,并定期对从业人员进行安全教育和培训;
(五)制定并组织实施个人信息安全事件应急预案;
(六)法律、行政法规规定的其他措施。

技术驱动法律,专业成就未来