Skip to main content

刪除個人資料的權利

Europe proposes a "right to be forgotten"
By Peter Bright European Union Justice Commissioner Viviane Reding has proposed a sweeping reform of the EU's data protection rules, claiming that the proposed rules will both cost less for governments and corporations to administer and simultaneously strengthen online privacy rights.

The 1995 Data Protection Directive already gives EU citizens certain rights over their data. Organizations can process data only with consent, and only to the extent that they need to fulfil some legitimate purpose. They are also obliged to keep data up-to-date, and retain personally identifiable data for no longer than is necessary to perform the task that necessitated collection of the data in the first place. They must ensure that data is kept secure, and whenever processing of personal data is about to occur, they must notify the relevant national data protection agency.

The new proposals go further than the 1995 directive, especially in regard to the control they give citizens over their personal information. Chief among the new proposals is a "right to be forgotten" that will allow people to demand that organizations that hold their data delete that data, as long as there is no legitimate grounds to hold it.

It's not 1995 anymore

The 1995 Directive was written in a largely pre-Internet era; back then, fewer than one percent of Europeans were Internet users. The proposed directive includes new requirements designed for the Internet age: EU citizens must be able to both access their data and transfer it between service providers, something that the commission argues will increase competition. Citizens will also have to give their explicit permission before companies can process their data; assumptions of permission won't be permitted, and systems will have to be private by default.

These changes are motivated in particular by the enormous quantities of personal information that social networking sites collect, and the practical difficulties that users of these services have in effectively removing that information. Reding says that the new rules "will help build trust in online services because people will be better informed about their rights and in more control of their information."

Where do the claimed savings come from? EU member states currently comply with the 1995 Directive, but each of the 27 states has interpreted and applied these rules differently. The European Commission argues that this incurs unnecessary administrative burdens on all those involved with handling data. The new mandate would create a single set of rules consistent across the entire EU, with projected savings for businesses of around €2.3 billion (US$2.98 billion) per year.

With rules streamlined throughout the trading bloc, companies would in turn only have to deal with the data protection authorities in their home country, rather than in every state in which they trade.

The new rules would also reduce the routine data protection notifications that businesses must currently send to national data protection authorities, allowing further savings of €130 million (US$169 million). However, organizations that handle data will have greater obligations in the event of data breaches: they will have to notify data protection authorities as soon as possible, preferably within 24 hours.

The rules will also apply to companies that process data abroad, if those companies serve the EU market and EU citizens.

Non-compliance will be punishable by the national data protection authorities, and they will be able to apply penalties of up to €1 million (US$1.3 million) or two percent of global annual turnover.

The proposal will undergo discussion in the European Parliament. Once the rules are adopted, they will take effect within two years.

A mixed response

Industry responses to the proposals have been varied. While the harmonization and reduction of routine notifications is welcomed, some have rubbished Reding's claim that the new directive will reduce costs. For example, the Business Software Alliance's European government affairs director, Thomas Boué said, "The Commission's proposal today errs too far in the direction of imposing prescriptive mandates for how enterprises must collect, store, and manage information."

Supporters of the new proposals argue that the new directive will force companies to do things that they should already be doing. Christian Toon, head of information security at document management firm Iron Mountain, says, "Many businesses of all sizes are falling short of what is required to manage information responsibly. [...] Regardless of turnover, sector or country of operation, making sure that employee and customer information is protected should be common practice, not a reaction to new legislation."

Indeed, many of the provisions of the new directive have similar counterparts in the existing directive, and others are features of national law of some, but not all, EU member states. For example, current law gives citizens the right to have inaccurate data about them corrected. In some countries, such as the UK, this extends to a right to have that inaccurate data deleted outright. In others, such as Belgium, Germany, and Sweden, it does not. The new rules would make that right to delete universal, and would make it apply even for accurate data that is no longer necessary.

This is the so-called "right to be forgotten". The proposal does not create a right to be thrown down the memory hole or rewrite the past; news reports and similar material would be a legitimate reason to retain personal information, and this would override a demand to have data deleted. But sites like Facebook—which has had difficulties with the concept of deletion—and Google would likely be required to purge any such personal data should someone demand that they do so.

A strict "opt-in" requirement for the use of personal data could make advertising-funded services that rely on that personal data to properly target advertisements difficult to operate. The requirement to report breaches in 24 hours might also be difficult to fulfil, since it can take much longer for a breach to even be detected.

The new rules would create an interesting predicament for a company like Google. The search giant has just announced its new privacy policy that enables it to collect and aggregate data from almost all Google services, with no provision to opt out or restrict the processing the company performs to private data. This is the opposite of the "private by default" policy that the proposed rules require, and the only way that Google users will attain that privacy is by not creating or using a Google account.

When asked about the impact of the new rules, a Google spokesperson told Ars: "We support simplifying privacy rules in Europe to both protect consumers online and stimulate economic growth. It is possible to have simple rules that do both. We look forward to debating the proposals over the coming months."

But still, this is not a fundamental shift in the demands placed on data-holding organizations. They must already be able to identify personal data, they must already store it securely, and they must already be able to provide it on-demand. Doing these things requires that systems are designed appropriately, and this can certainly incur costs—but they are costs that should already exist today.

Photograph by Matt May

Comments

Popular posts from this blog

購屋糾紛多 預售屋是申訴榜首行政院消費者保護委員會統計,房屋糾紛為去年國人所有申訴糾紛排行榜第一名,3030件糾紛案已佔所有申訴糾紛一成,其中尤以「預售屋」糾紛最為嚴重。發現六大缺失,包括:建商未提供驗收條款或未記載交屋保留款、未明確記載開工日期及取得使用執照期限、未記載地價稅、房屋稅分擔比例、未經買方同意更換主要建材及廠牌規格及交屋期限不明確、未記載建物第一次登記的稅費負擔約定,以及未記載賣方對廣告之義務而且違約金收取過高。 消保官莊惠媛指出,消費者購買預售屋基本上就像購買一個夢想,且大部分消費者必須要花掉一生積蓄才能買回一個窩,但因為預售屋不像成屋,有實體房屋可供檢視,就得預先和房屋業者訂契約先行付款,最後往往因期待有落差而陷入糾紛成為惱人之痛。 莊惠媛呼籲,民眾購屋前為了維護權益,應先瞭解內政部先前訂定的「預售屋買賣契約書範本及預售屋買賣定型化契約應記載及不得記載事項」,尤其針對預售屋挑購提出「八大提醒」,包括:一、確認並履勘預售屋位址;二、攜帶捲尺、相機參觀樣品屋;三、看建築執照影本、執照核准圖說;四、審閱契約並瞭解契約內容;五、索取並保留廣告文案;六、詳實紀錄銷售現場建材資訊;七、洞悉成交紅單、假客戶等銷售手法;八、選擇合法代銷業者,以免受騙上當。 【2009/03/16 聯合晚報】
科技擠壓 原生種子快滅絕 2009/05/15【米千因/文】《聖經‧創世紀》:上帝說:我要將所造的人和走獸並昆蟲以及空中的飛鳥都從地上消滅。 於是上帝在罪惡滿貫的人類中揀選恪守本分的義人諾亞一家,諾亞夫婦、三個兒子及其媳婦,作為新一代人類種子來保存下來。上帝告訴他們,七天之後就要實施大毀滅,而命他們造一只方舟,一間一間地造,裡外抹上松香。諾亞一家立即照辦,等方舟造好之後,上帝說了:看哪!我要使洪水在地上氾濫,毀滅天下,凡地上有血肉、有氣息的活物無一不死。我卻要與你立約,你同你的妻子、兒子、兒媳都要進入方舟。凡潔淨的畜類,你要帶七公七母;不潔淨的畜類,你要帶一公一母;空中的飛鳥也要帶七公七母。這些都可以留種,將來在地上生殖。2月17日當天,諾亞六百歲生辰,海洋裂開,巨大的水柱從地下噴射而出,大雨下不停,整整降了四十天,水無處可流,迅速上漲,淹沒了高山,最後凡是在陸地上靠肺呼吸的動物都死了,只剩下方舟上的人、動物及種子安然無恙。 目前有一群歷史學家與考古學家正在熱衷地尋找證據,來證明諾亞方舟的存在,而部分社會學家與環保人士卻將關注的眼光投向原生種子的培育與保留上。理由是工業革命以至基改科技發達的今日,原生植物種子滅絕了大半而不復得。比方,世界上原有二百多萬種食用性植物,稻米種類至少也有十二萬種之多,如今普遍種植的不到數百種。十九世紀,美洲大陸至少有七千多種不同種類的蘋果,現在則僅剩約三百種,且大都是雜交,原生種如鳳毛麟角;加上企業一手主宰的廣大單作,以及隨後而至的基改技術,雜食性的人類於是被迫成為挑食、偏食、速食的怪物。而糧食分配不均的問題不但未能因而獲得解決,甚且因企業的壟斷而更形惡化。雖有科技的介入而全球饑餓人口不減反增,糧食價格高漲不下,人類身心健康因飲食習慣的改變而為過胖、糖尿病、心臟病、憂鬱症等文明病所苦。人類以科技萬能的傲慢插手上帝的傑作導致這樣的結果,不待歷史學家及考古學家的證明,全球暖化將引發大洪水的理論或會成為事實,那麼,一個有效而力量龐大的逆轉運動若非於此時出現,人難道只能坐以待斃? 義大利人Carlo Petrini首先發難,組成了國際慢食會,且一觸即發,如洪水漫過大地地延燒成一股運動,沒幾年,慢食所講求的良好、公平、乾淨的主旨與精神傳染了全球各角落,因而衍生出林林種種反應在慢活態度的活動與主張,於是慢食之後,慢活、慢設計、慢診斷、慢建築、慢手工、...
歐債危機 都是單一貨幣害的【經濟日報╱2012.02.28 03:06 am萄葡牙的局面非常嚴重,因為失業率已經超過13%。希臘、愛爾蘭甚至西班牙的情況更糟。整個歐洲似乎已經再度陷入衰退。 為什麼歐洲已經淪為全球經濟的病夫?答案似乎人盡皆知,遺憾的是人們知道的大多不是實情,而有關歐洲問題的不實說法正在扭曲我們的經濟討論。 試閱讀有關歐洲問題的討論文章,或者一篇看似符合事實的報導,則會看到兩種說法中的一種。我暫且稱之為共和黨人與德國的敘述。兩者均與事實不符。 共和黨的說法是羅姆尼競選的主軸之一。這種說法聲稱,歐洲因為對窮人伸援太多而麻煩上身;這是福利國死前的掙扎。這是右派陣營始終偏好的論點之一。1991年,瑞典因為放寬管制而面臨金融危機(似曾相識吧?)時,卡托研究所發表一項報告,聲稱這足以證明整個福利國模式行不通。 然而,仍然保留福利國制度的瑞典目前表現亮眼,經濟成長優於其他富裕國家。 我們不妨有系統評論,逐一檢視目前使用歐元的15個歐洲國家(排除馬爾他與塞浦路斯),並根據危機出現前,各國用於各種社會施政方案的預算占GDP之比予以排名。希臘、愛爾蘭、葡葡牙、西班牙、義大利是否因為福利制度過於細緻而顯得與眾不同?沒有。只有義大利可列入前五名,即使如此,它的福利制度規模仍不及德國。 換言之,龐大的福利制度並不是問題的肇因。 接下來談德國的論述,亦即把問題主要歸咎於財政不負責任。這種論調似乎與希臘的情況相符,而且也僅止於此。義大利在危機發生前數年即已出現赤字,規模卻僅略大於德國(義大利的龐大赤字主要源自多年前不負責任的政策)。葡萄牙的赤字小很多,西班牙與愛爾蘭則享有盈餘。 噢,還有。部分不是歐元國的國家似乎也能夠在未面臨任何危機的情況下,揹負龐大的赤字與債務。英國與美國可以大約2%的低利率長期舉債;日本揹負的債務遠大於含希臘在內的任何歐洲國家,利率只有1%。 換言之,「希臘化」的經濟論辯毫無事實根據。 如此說來,歐洲的問題究竟何在?真相是,問題大多與貨幣有關。歐洲國家推出單一貨幣,卻缺少確保該貨幣運作無礙所需的配套機構,無形中等於再次創造金本位制的缺失。這些缺點曾經在大蕭條形成的過程中扮演重要角色。 更確切的說,歐元使民間投資人產生虛假的安全感,並導致資金大舉湧向歐洲各邊緣國,相對又導致成本與價格大漲,製造業失去競爭力,1999年貿易大致平衡的各國並開始出現龐大的貿易赤字。...