Skip to main content

刪除個人資料的權利

Europe proposes a "right to be forgotten"
By Peter Bright European Union Justice Commissioner Viviane Reding has proposed a sweeping reform of the EU's data protection rules, claiming that the proposed rules will both cost less for governments and corporations to administer and simultaneously strengthen online privacy rights.

The 1995 Data Protection Directive already gives EU citizens certain rights over their data. Organizations can process data only with consent, and only to the extent that they need to fulfil some legitimate purpose. They are also obliged to keep data up-to-date, and retain personally identifiable data for no longer than is necessary to perform the task that necessitated collection of the data in the first place. They must ensure that data is kept secure, and whenever processing of personal data is about to occur, they must notify the relevant national data protection agency.

The new proposals go further than the 1995 directive, especially in regard to the control they give citizens over their personal information. Chief among the new proposals is a "right to be forgotten" that will allow people to demand that organizations that hold their data delete that data, as long as there is no legitimate grounds to hold it.

It's not 1995 anymore

The 1995 Directive was written in a largely pre-Internet era; back then, fewer than one percent of Europeans were Internet users. The proposed directive includes new requirements designed for the Internet age: EU citizens must be able to both access their data and transfer it between service providers, something that the commission argues will increase competition. Citizens will also have to give their explicit permission before companies can process their data; assumptions of permission won't be permitted, and systems will have to be private by default.

These changes are motivated in particular by the enormous quantities of personal information that social networking sites collect, and the practical difficulties that users of these services have in effectively removing that information. Reding says that the new rules "will help build trust in online services because people will be better informed about their rights and in more control of their information."

Where do the claimed savings come from? EU member states currently comply with the 1995 Directive, but each of the 27 states has interpreted and applied these rules differently. The European Commission argues that this incurs unnecessary administrative burdens on all those involved with handling data. The new mandate would create a single set of rules consistent across the entire EU, with projected savings for businesses of around €2.3 billion (US$2.98 billion) per year.

With rules streamlined throughout the trading bloc, companies would in turn only have to deal with the data protection authorities in their home country, rather than in every state in which they trade.

The new rules would also reduce the routine data protection notifications that businesses must currently send to national data protection authorities, allowing further savings of €130 million (US$169 million). However, organizations that handle data will have greater obligations in the event of data breaches: they will have to notify data protection authorities as soon as possible, preferably within 24 hours.

The rules will also apply to companies that process data abroad, if those companies serve the EU market and EU citizens.

Non-compliance will be punishable by the national data protection authorities, and they will be able to apply penalties of up to €1 million (US$1.3 million) or two percent of global annual turnover.

The proposal will undergo discussion in the European Parliament. Once the rules are adopted, they will take effect within two years.

A mixed response

Industry responses to the proposals have been varied. While the harmonization and reduction of routine notifications is welcomed, some have rubbished Reding's claim that the new directive will reduce costs. For example, the Business Software Alliance's European government affairs director, Thomas Boué said, "The Commission's proposal today errs too far in the direction of imposing prescriptive mandates for how enterprises must collect, store, and manage information."

Supporters of the new proposals argue that the new directive will force companies to do things that they should already be doing. Christian Toon, head of information security at document management firm Iron Mountain, says, "Many businesses of all sizes are falling short of what is required to manage information responsibly. [...] Regardless of turnover, sector or country of operation, making sure that employee and customer information is protected should be common practice, not a reaction to new legislation."

Indeed, many of the provisions of the new directive have similar counterparts in the existing directive, and others are features of national law of some, but not all, EU member states. For example, current law gives citizens the right to have inaccurate data about them corrected. In some countries, such as the UK, this extends to a right to have that inaccurate data deleted outright. In others, such as Belgium, Germany, and Sweden, it does not. The new rules would make that right to delete universal, and would make it apply even for accurate data that is no longer necessary.

This is the so-called "right to be forgotten". The proposal does not create a right to be thrown down the memory hole or rewrite the past; news reports and similar material would be a legitimate reason to retain personal information, and this would override a demand to have data deleted. But sites like Facebook—which has had difficulties with the concept of deletion—and Google would likely be required to purge any such personal data should someone demand that they do so.

A strict "opt-in" requirement for the use of personal data could make advertising-funded services that rely on that personal data to properly target advertisements difficult to operate. The requirement to report breaches in 24 hours might also be difficult to fulfil, since it can take much longer for a breach to even be detected.

The new rules would create an interesting predicament for a company like Google. The search giant has just announced its new privacy policy that enables it to collect and aggregate data from almost all Google services, with no provision to opt out or restrict the processing the company performs to private data. This is the opposite of the "private by default" policy that the proposed rules require, and the only way that Google users will attain that privacy is by not creating or using a Google account.

When asked about the impact of the new rules, a Google spokesperson told Ars: "We support simplifying privacy rules in Europe to both protect consumers online and stimulate economic growth. It is possible to have simple rules that do both. We look forward to debating the proposals over the coming months."

But still, this is not a fundamental shift in the demands placed on data-holding organizations. They must already be able to identify personal data, they must already store it securely, and they must already be able to provide it on-demand. Doing these things requires that systems are designed appropriately, and this can certainly incur costs—but they are costs that should already exist today.

Photograph by Matt May

Comments

Popular posts from this blog

工程排水量設計 與 暴雨量

  獨家/直擊大巨蛋落下「瀑布」 民眾疑惑問:排水系統呢? 14:35 2021/06/04   中時   張穎齊 中央氣象局發布豪大雨特報,有民眾直擊拍下大巨蛋從「蛋頂」沖下的瀑布影片,疑惑直呼「排水系統呢?」。(民眾提供/張穎齊台北傳真) 木柵路2段109巷口淹水。(北市府提供/張穎齊台北傳真) 南湖大橋下淹水。(北市府提供/張穎齊台北傳真) 北市消防局門口淹水。(北市府提供/張穎齊台北傳真) 六張犁信安街淹水。(北市府提供/張穎齊台北傳真) 中央氣象局發布豪大雨特報,受颱風及鋒面接近影響,北市中午12時起開始有持續性的強對流發展,市中心有瞬間強降雨,文山、大安及信義區時雨量均超過100毫米,大安及信義區最大10分鐘雨量均超過30毫米,多處積淹水。不過也有民眾直擊拍下大巨蛋從「蛋頂」沖下的瀑布影片,疑惑直呼「排水系統呢?」 北市府表示,目前測得最大累積雨量為大安區福州山站127.5毫米,水利署已發布南港區淹水一級警戒及松山區一級警戒,水利處稍早通知南港區南深陸閘門因為逼近警戒水位,可能隨時關閉。 此外,水利處也已通知各區里,因目前瞬間強降雨遠大於下水道的容量,會有積水狀況發生,如有地下室的應盡速關上防水閘門,減少積水進入地下室造成損失。而木柵路2段109巷口淹水,深約20公分,範圍約100平方公尺,南湖大橋下淹水長度約50公尺、寬度約10尺、深度約50公分。

拆除案 與都更案類似之場景 溝通或方案可能不足

緊急喊停!拆南鐵最後1戶踢鐵板 雙方對峙1小時 鐵道局:今拆除取消 07:42 2020/07/23   中時   鐵道局中工處主任工程司吳志仁宣布今天拆除喊卡。(曹婷婷攝) 字級設定: 小 中 大 特 影》緊急喊卡!拆南鐵最後一戶 雙方對峙1小時 鐵道局今不拆了! 拒拆遷戶陳致曉家門外一度聚集大批警力。(曹婷婷攝) 反對拆遷抗爭者守在大門內。(曹婷婷攝) 警方在7點多撤離,鐵道局隨後宣布取消今天拆除行動。(曹婷婷攝) 台南鐵路地下化強拆作業預計今天清晨6時拆除最後一棟拒拆遷戶、青年路陳致曉家,交通部鐵道局中工處人員和大批警力6點一到在陳宅外宣讀拆除程序於法有據,屋內上百人不斷高呼「反東移、反對徵收」口號,雙方對峙1個多小時後,鐵道局中工處7點20分宣布基於避免衍生衝突,衍生社會成本,今天拆除計畫決定取消。 交通部鐵道局中部工程處主任工程司吳志仁7點20分出面宣布,南鐵地下化是台南重大計畫,但因為考量陳宅有許多人,基於避免造成衝突及衍生不必要社會成本,決定取消。他強調,因全案只剩陳宅拒拆,接下來會傳持續跟陳致曉溝通。 針對鐵道局宣布暫緩任務,陳致曉表示,將討論戰術,「但我不會因此開心,因為今天不攻,明天、後天也會來。」並回嗆「他來我就打!」 反南鐵東移拒拆 自救會長嗆:「歡迎攻進來」 07:12 2020/07/23   中時   反南鐵東移聲援民眾守在待拆戶家中,不願撤離。(李宜杰攝) Facebook   Messenger   Line   Weibo   Twitter   Telegram   複製連結 字級設定: 小 中 大 特 警民仍持續對峙中,鐵道局也釋出善意要溝通。(李宜杰攝) 配合南鐵地下化工程,鐵道局中工處預計今日(23)清晨6時拆除東區青年路陳家。目前反南鐵東移全線自救會長陳致曉與雙親,及超過百名聲援民眾守在陳家客廳,手拉手拒絕撤退,警方及鐵道局人員被拒於門外,並提出要與陳致曉溝通,陳致曉則回嗆「絕不會交涉,歡迎攻進來!」 據悉,目前怪手已進駐陳家後院,百名警力、消防車、救護車也都部署完畢,衝突一觸即發,聲援民眾痛斥「行政訴訟還在打,不要當政黨打

司法改革心

中時社論》司法改革 制度要改心更要改 2017/6/11 下午  司法改革國是會議第1分組第4次增開會議在司法院開會。(黄世麒攝) 司法改革國是會議5個分組分別進行了3個月的會議,已全部結束。5個分組各自提出數十件改革提議,總量非常可觀,多項分組決議曾引起社會高度爭議,且司法院、法務部、律師團體間顯然有嚴重的價值觀與職務立場衝突,接下來幕僚人員如何進行議題綜整,全體會議如何達成總結性結論,事關改革成敗與國家民主發展,身為媒體必須關注,並適時對社會發出建言與警語。 分組討論議題牽涉甚廣,從金字塔式的訴訟制度、賦予大法官違憲裁判審查權、保障司法程序弱勢方權利、修復式司法法制化,到研究設立商業法院、特別勞動訴訟程序、稅務法庭,到高度政治性的增訂妨害司法公正罪,以切斷政治干擾司法的可能性。此外,還包括調整法官晉用制度、終審法院行公開言詞辯論、研議法庭直播提高司法透明度,及檢察體系的性格定位、刑事訴訟程序從起訴的方法開始改變,到改善判決文書格式以求易懂等。 司法的重要性,這裡就不必再行強調。司法的社會公信力嚴重不足,到達需要召開司法改革國是會議來開藥方治病的地步,本身就令人痛心疾首。其實司法改革大業,一方面固然有制度上需要調整的地方,另一方面也有司法人員行為、文化必須大幅檢討改進之處。改革制度需要協調立法、行政、司法甚至考試諸院配合行事,但相對司法相關人員的「革心」,還是比較容易,人的行為與文化改變更困難。台灣民主體制下司法獨立,不受行政及政治干預,為了追求司法獨立的提升而改變司法人員的行為與文化,尤其困難。 改變司法人員的行為與文化具有先天性的困難,在這次司改會議過程中已一覽無遺。這次會議特別引進了半數不具法律背景的委員參與討論,其實就是希望避免法界人士研議司法改革時,閉門造車、諱疾忌醫,甚至護短,成為改革的障礙,但諱疾忌醫甚至護短的毛病仍然不時出現,雖不令人意外,但仍然對會議的進行與成果形成負面的影響。法界人士包括官員、教授、司法從業人士,因為諱疾忌醫甚至護短而在媒體上攻訐,不惜傷害司改會議的社會形象,令人感到遺憾。 諱疾忌醫甚至護短的現象,從議題處理方式的輕重選擇,也可看得出來。關說司法,特別是政治人物包括民意代表關說司法,問題普遍而且觀念嚴重偏頗的程度,從前立法院長王金平加上前檢察總長黃世銘的訴訟案件中,就足以一覽無遺。政