首页 | 本学科首页   官方微博 | 高级检索  
     检索      

欧盟数据保护官制度研究
引用本文:肖冬梅,成思雯.欧盟数据保护官制度研究[J].图书情报工作,2019,63(2):144-152.
作者姓名:肖冬梅  成思雯
作者单位:湘潭大学法学院 湘潭 411105
基金项目:本文系国家社会科学基金重点项目"云环境下数字学术信息资源安全的法律保障体系研究"(项目编号:14AZD076)研究成果之一。
摘    要:目的/意义]欧盟数据保护新规(GDPR)中的数据保护官(DPO)制度颇受关注。追溯DPO制度演进路径,剖析DPO的设置与具体职责,考察欧盟DPO制度实施与影响,不止关乎中国企业对欧贸易,更是我国相关规则体系构建的重要参考。方法/过程]通过梳理GDPR中有关DPO的条款及相关过程文本,发现在GDPR规定的3种情形下,数据控制者/处理者应设置数据保护官。DPO的职责包括对数据控制者相关工作人员的告知和建议、监督数据处理的合规性、联络数据主体、同监管机构合作、数据处理活动的记录与归档、培训以及保密等。结果/结论]设置DPO对于确保数据控制者的合规、减轻监管机构负担影响深远。欧盟DPO制度对中国企业/机构的启示在于:应按GDPR的规定设置DPO,并设计完整的数据保护监督流程;对中国数据保护监督及机制建设的启示包括:明确规定数据控制者应设置数据保护专门岗位和专业人员、对不合规的数据控制者给予相应的责任追究和惩罚、加强数据监管机构的建设。

关 键 词:数据保护官  个人数据保护  合规性
收稿时间:2018-06-09

EU Data Protection Officer: Responsibility,Impact and Enlightenment
Xiao Dongmei,Cheng Siwen.EU Data Protection Officer: Responsibility,Impact and Enlightenment[J].Library and Information Service,2019,63(2):144-152.
Authors:Xiao Dongmei  Cheng Siwen
Institution:Law School of Xiangtan University, Xiangtan 411105
Abstract:Purpose/significance] The data protection officer (DPO) in the new regulation of EU data protection(GDPR) has attracted considerable attention.Tracing the evolution path of DPO,analyzing the settings and specific responsibilities of it. Studying on DPO system is not only related to trade between China and Europe, but also an important reference for the construction of relevant rules system in China.Method/process] By teasing out the terms of DPO in the GDPR and related texts,in the three cases specified by GDPR, the data controllers or processors should set up DPO.The responsibilities of the DPO include that informing and advising to the data controller's relevant staff, monitoring the compliance of data processing, contacting with data subject, cooperating with the supervisory authority, maintaining records and documentation of data processing, training, and confidentiality obligation.Result/conclusion] Setting up DPO has far-reaching influence on ensuring the compliance of data controllers and reducing the burden of the supervisory authority. The enlightenment of DPO for Chinese enterprises or institutions is that DPO should be set up according to the provisions of GDPR, and a complete data protection supervision system should be designed as soon as possible. As for the data protection supervision system and mechanism construction in China, it should be clearly stipulated that the data controllers have to set up special posts and professionals for data protection, and investigate and punish non-compliant data controllers with corresponding responsibilities. Meanwhile the construction of data supervisory authority should be strengthened.
Keywords:data protection officer  personal data protection  compliance  
本文献已被 维普 等数据库收录!
点击此处可从《图书情报工作》浏览原始摘要信息
点击此处可从《图书情报工作》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号