Skip to main content

刪除個人資料的權利

Europe proposes a "right to be forgotten"
By Peter Bright European Union Justice Commissioner Viviane Reding has proposed a sweeping reform of the EU's data protection rules, claiming that the proposed rules will both cost less for governments and corporations to administer and simultaneously strengthen online privacy rights.

The 1995 Data Protection Directive already gives EU citizens certain rights over their data. Organizations can process data only with consent, and only to the extent that they need to fulfil some legitimate purpose. They are also obliged to keep data up-to-date, and retain personally identifiable data for no longer than is necessary to perform the task that necessitated collection of the data in the first place. They must ensure that data is kept secure, and whenever processing of personal data is about to occur, they must notify the relevant national data protection agency.

The new proposals go further than the 1995 directive, especially in regard to the control they give citizens over their personal information. Chief among the new proposals is a "right to be forgotten" that will allow people to demand that organizations that hold their data delete that data, as long as there is no legitimate grounds to hold it.

It's not 1995 anymore

The 1995 Directive was written in a largely pre-Internet era; back then, fewer than one percent of Europeans were Internet users. The proposed directive includes new requirements designed for the Internet age: EU citizens must be able to both access their data and transfer it between service providers, something that the commission argues will increase competition. Citizens will also have to give their explicit permission before companies can process their data; assumptions of permission won't be permitted, and systems will have to be private by default.

These changes are motivated in particular by the enormous quantities of personal information that social networking sites collect, and the practical difficulties that users of these services have in effectively removing that information. Reding says that the new rules "will help build trust in online services because people will be better informed about their rights and in more control of their information."

Where do the claimed savings come from? EU member states currently comply with the 1995 Directive, but each of the 27 states has interpreted and applied these rules differently. The European Commission argues that this incurs unnecessary administrative burdens on all those involved with handling data. The new mandate would create a single set of rules consistent across the entire EU, with projected savings for businesses of around €2.3 billion (US$2.98 billion) per year.

With rules streamlined throughout the trading bloc, companies would in turn only have to deal with the data protection authorities in their home country, rather than in every state in which they trade.

The new rules would also reduce the routine data protection notifications that businesses must currently send to national data protection authorities, allowing further savings of €130 million (US$169 million). However, organizations that handle data will have greater obligations in the event of data breaches: they will have to notify data protection authorities as soon as possible, preferably within 24 hours.

The rules will also apply to companies that process data abroad, if those companies serve the EU market and EU citizens.

Non-compliance will be punishable by the national data protection authorities, and they will be able to apply penalties of up to €1 million (US$1.3 million) or two percent of global annual turnover.

The proposal will undergo discussion in the European Parliament. Once the rules are adopted, they will take effect within two years.

A mixed response

Industry responses to the proposals have been varied. While the harmonization and reduction of routine notifications is welcomed, some have rubbished Reding's claim that the new directive will reduce costs. For example, the Business Software Alliance's European government affairs director, Thomas Boué said, "The Commission's proposal today errs too far in the direction of imposing prescriptive mandates for how enterprises must collect, store, and manage information."

Supporters of the new proposals argue that the new directive will force companies to do things that they should already be doing. Christian Toon, head of information security at document management firm Iron Mountain, says, "Many businesses of all sizes are falling short of what is required to manage information responsibly. [...] Regardless of turnover, sector or country of operation, making sure that employee and customer information is protected should be common practice, not a reaction to new legislation."

Indeed, many of the provisions of the new directive have similar counterparts in the existing directive, and others are features of national law of some, but not all, EU member states. For example, current law gives citizens the right to have inaccurate data about them corrected. In some countries, such as the UK, this extends to a right to have that inaccurate data deleted outright. In others, such as Belgium, Germany, and Sweden, it does not. The new rules would make that right to delete universal, and would make it apply even for accurate data that is no longer necessary.

This is the so-called "right to be forgotten". The proposal does not create a right to be thrown down the memory hole or rewrite the past; news reports and similar material would be a legitimate reason to retain personal information, and this would override a demand to have data deleted. But sites like Facebook—which has had difficulties with the concept of deletion—and Google would likely be required to purge any such personal data should someone demand that they do so.

A strict "opt-in" requirement for the use of personal data could make advertising-funded services that rely on that personal data to properly target advertisements difficult to operate. The requirement to report breaches in 24 hours might also be difficult to fulfil, since it can take much longer for a breach to even be detected.

The new rules would create an interesting predicament for a company like Google. The search giant has just announced its new privacy policy that enables it to collect and aggregate data from almost all Google services, with no provision to opt out or restrict the processing the company performs to private data. This is the opposite of the "private by default" policy that the proposed rules require, and the only way that Google users will attain that privacy is by not creating or using a Google account.

When asked about the impact of the new rules, a Google spokesperson told Ars: "We support simplifying privacy rules in Europe to both protect consumers online and stimulate economic growth. It is possible to have simple rules that do both. We look forward to debating the proposals over the coming months."

But still, this is not a fundamental shift in the demands placed on data-holding organizations. They must already be able to identify personal data, they must already store it securely, and they must already be able to provide it on-demand. Doing these things requires that systems are designed appropriately, and this can certainly incur costs—but they are costs that should already exist today.

Photograph by Matt May

Comments

Popular posts from this blog

購屋糾紛多 預售屋是申訴榜首行政院消費者保護委員會統計,房屋糾紛為去年國人所有申訴糾紛排行榜第一名,3030件糾紛案已佔所有申訴糾紛一成,其中尤以「預售屋」糾紛最為嚴重。發現六大缺失,包括:建商未提供驗收條款或未記載交屋保留款、未明確記載開工日期及取得使用執照期限、未記載地價稅、房屋稅分擔比例、未經買方同意更換主要建材及廠牌規格及交屋期限不明確、未記載建物第一次登記的稅費負擔約定,以及未記載賣方對廣告之義務而且違約金收取過高。 消保官莊惠媛指出,消費者購買預售屋基本上就像購買一個夢想,且大部分消費者必須要花掉一生積蓄才能買回一個窩,但因為預售屋不像成屋,有實體房屋可供檢視,就得預先和房屋業者訂契約先行付款,最後往往因期待有落差而陷入糾紛成為惱人之痛。 莊惠媛呼籲,民眾購屋前為了維護權益,應先瞭解內政部先前訂定的「預售屋買賣契約書範本及預售屋買賣定型化契約應記載及不得記載事項」,尤其針對預售屋挑購提出「八大提醒」,包括:一、確認並履勘預售屋位址;二、攜帶捲尺、相機參觀樣品屋;三、看建築執照影本、執照核准圖說;四、審閱契約並瞭解契約內容;五、索取並保留廣告文案;六、詳實紀錄銷售現場建材資訊;七、洞悉成交紅單、假客戶等銷售手法;八、選擇合法代銷業者,以免受騙上當。 【2009/03/16 聯合晚報】
科技擠壓 原生種子快滅絕 2009/05/15【米千因/文】《聖經‧創世紀》:上帝說:我要將所造的人和走獸並昆蟲以及空中的飛鳥都從地上消滅。 於是上帝在罪惡滿貫的人類中揀選恪守本分的義人諾亞一家,諾亞夫婦、三個兒子及其媳婦,作為新一代人類種子來保存下來。上帝告訴他們,七天之後就要實施大毀滅,而命他們造一只方舟,一間一間地造,裡外抹上松香。諾亞一家立即照辦,等方舟造好之後,上帝說了:看哪!我要使洪水在地上氾濫,毀滅天下,凡地上有血肉、有氣息的活物無一不死。我卻要與你立約,你同你的妻子、兒子、兒媳都要進入方舟。凡潔淨的畜類,你要帶七公七母;不潔淨的畜類,你要帶一公一母;空中的飛鳥也要帶七公七母。這些都可以留種,將來在地上生殖。2月17日當天,諾亞六百歲生辰,海洋裂開,巨大的水柱從地下噴射而出,大雨下不停,整整降了四十天,水無處可流,迅速上漲,淹沒了高山,最後凡是在陸地上靠肺呼吸的動物都死了,只剩下方舟上的人、動物及種子安然無恙。 目前有一群歷史學家與考古學家正在熱衷地尋找證據,來證明諾亞方舟的存在,而部分社會學家與環保人士卻將關注的眼光投向原生種子的培育與保留上。理由是工業革命以至基改科技發達的今日,原生植物種子滅絕了大半而不復得。比方,世界上原有二百多萬種食用性植物,稻米種類至少也有十二萬種之多,如今普遍種植的不到數百種。十九世紀,美洲大陸至少有七千多種不同種類的蘋果,現在則僅剩約三百種,且大都是雜交,原生種如鳳毛麟角;加上企業一手主宰的廣大單作,以及隨後而至的基改技術,雜食性的人類於是被迫成為挑食、偏食、速食的怪物。而糧食分配不均的問題不但未能因而獲得解決,甚且因企業的壟斷而更形惡化。雖有科技的介入而全球饑餓人口不減反增,糧食價格高漲不下,人類身心健康因飲食習慣的改變而為過胖、糖尿病、心臟病、憂鬱症等文明病所苦。人類以科技萬能的傲慢插手上帝的傑作導致這樣的結果,不待歷史學家及考古學家的證明,全球暖化將引發大洪水的理論或會成為事實,那麼,一個有效而力量龐大的逆轉運動若非於此時出現,人難道只能坐以待斃? 義大利人Carlo Petrini首先發難,組成了國際慢食會,且一觸即發,如洪水漫過大地地延燒成一股運動,沒幾年,慢食所講求的良好、公平、乾淨的主旨與精神傳染了全球各角落,因而衍生出林林種種反應在慢活態度的活動與主張,於是慢食之後,慢活、慢設計、慢診斷、慢建築、慢手工、...

司法部要細究微軟/Yahoo搜尋交易

為何美司法部要細究微軟/Yahoo搜尋交易? ZDNET新聞專區:2009/09/14 微軟與Yahoo的搜尋交易,不但實行之日遙遙無期,現在更可能無疾而終。 兩家公司都預期美國聯邦司法部會詳細審查微軟接手Yahoo網搜業務的交易,而兩家公司也在上週五(11日)證實,司法部已要求他們提供更多相關資訊。這代表主管機關對此案的興趣已不只是一般程序的合法性。 針對此案,司法部可能從兩個不同的面向切入。其一,當局將調查廣告主是否因失去一個廣告通路而受損,以及此後Google會否在搜尋市場缺乏改善的動力,因為少了一個最大的競爭者。 就某些方面而言,司法部的調查幾乎是一項反射動作。紐約Constantine Cannon反托辣斯律師Matthew Cantor表示,當某個市場只有三家主要公司,而其中兩家決定合作,自然會引發調查。他說:「這件交易將在一個高門檻,且原本只有三個主角的市場,消滅其中一個競爭者。」他用1960年代的美國媒體市場為例,假如當時僅有的三大電視網有其中兩家決定合併,政府絕對會採取行動。 但這件醞釀多年的交易,卻沒有趕在較不排斥企業併購和收購的前朝政府任內提出。華盛頓州Robbin Russell事務所合夥人Donald Russell指出,經過多年的放任管理,司法部對企業併購活動的興趣又逐漸升高。經濟狀況不佳已減少了企業併購活動,但歐巴馬總統主政之下的司法部,可能開始扮演更強勢的管理角色。 Cantor認為,司法部將強迫微軟和 Yahoo將Yahoo的搜尋技術資產公開標售,換取該案通過。此舉將可引進第三方到搜尋市場,僅管這個新手必須挑起吸引搜尋者的重擔:Yahoo曾表示,絕大部分Yahoo搜尋的使用者,都是透過某個Yahoo網頁進行,這兩者的結合,是網路上流量最高的網頁。然而,微軟看上的不是這部分。該公司已投入龐大的資源推出Bing搜尋引擎,他們想要的是Yahoo搜尋技術的特定面向,更別說某些才華洋溢的工程師。 有鑑於微軟和Google兩大巨人多年來在華府的遊說角力,造成Google近年的交易飽受刁難,這次也可能是Google趁機扳回一城。Google拒絕評論司法部的動作,但有以下聲明:「線上(市場)的競爭一向激烈,而我們的經驗是,競爭為使用者造就了更好的東西。我們有意進一步瞭解這件交易。」(陳智文/譯)