Risks and insights of EU data portability in the era of big data
Lv Siqi
(School of Law, Fudan University, Shanghai 200438, China)
Abstract: The right to data portability, introduced in the European Union in 2018, empowers data subjects to transfer personal data unimpeded to another data controller. An investigation into this emerging right contributes positively to the construction of China′s personal data protection system and propels domestic internet enterprises onto the global stage. By scrutinizing the legislative stipulations in the EU General Data Protection Regulation and examining the current status of its implementation, it is discerned that the provision essentially operates as a dormant clause, failing to deliver its intended function. As China has enshrined this right in the Personal Data Protection Law of the People′s Republic of China, it should draw upon the EU′s regulatory experiences. This includes limiting the scope of the right to data portability, strengthening hierarchical oversight by governmental departments, and actualizing the localization of data portability rights within China′s jurisdiction.
Key words : right to data portability; GDPR; data protection; personal data protection; data security governance
0 引言
大數(shù)據(jù)時(shí)代改變了人類的生活和工作方式,同時(shí)也給個(gè)人數(shù)據(jù)和隱私的保護(hù)帶來(lái)了更大的挑戰(zhàn)。2016年,歐盟出臺(tái)的“史上最嚴(yán)數(shù)據(jù)保護(hù)法律”——《一般數(shù)據(jù)保護(hù)條例》(General Data Protection Regulation,GDPR)中引入了名為“數(shù)據(jù)可攜帶權(quán)”的制度,使數(shù)據(jù)主體能夠不受阻礙地將個(gè)人數(shù)據(jù)在不同數(shù)據(jù)控制者之間傳輸。這一權(quán)利旨在促進(jìn)個(gè)人數(shù)據(jù)在歐盟內(nèi)的自由流通,避免個(gè)人數(shù)據(jù)的“鎖定”,讓用戶能在不同的數(shù)據(jù)控制者之間便捷自由地切換,以鼓勵(lì)市場(chǎng)競(jìng)爭(zhēng)。然而,制度運(yùn)行在具體實(shí)踐中卻出現(xiàn)了諸多問(wèn)題:由于條文規(guī)定含糊、標(biāo)準(zhǔn)不統(tǒng)一、技術(shù)可操作性較差等問(wèn)題,其實(shí)際上并沒(méi)有給數(shù)據(jù)安全和市場(chǎng)公平競(jìng)爭(zhēng)帶來(lái)積極意義,而最終淪為僵尸條款。本文將針對(duì)以上問(wèn)題展開(kāi)論述,探討該制度的緣起、發(fā)展及現(xiàn)實(shí)困境,以期為我國(guó)未來(lái)的立法實(shí)踐提供參考。