|
文章编号:1672-3104(2022)06-0041-14 |
|
在线平台企业个人信息保护的智能合约机制构建 |
|
许娟,黎浩田 |
|
(南京信息工程大学法政学院,江苏南京,210044) |
|
摘 要: 个人信息保护政策是在线平台企业为维护用户个人信息权益,根据现行法律法规制定并详细说明其在获取、管理及保护用户个人信息方面的措施及文本。智能合约作为涵盖告知同意规则并自动执行的特定代码程序,在智能化应用场景下可用于实现个人信息保护政策。进入实施层面的我国《个人信息保护法》需要通过一定的程序机制来保障企业个人信息处理行为合规,现存程序机制的非智能化难以应对个人信息处理者凭借技术优势造成的过度收集和滥用现象。因此,有必要尝试运用智能合约的技术性管理功能弥补企业个人信息保护政策的不足,具体措施为:将作为智能合约底层技术的区块链进行针对性改造,使其达到保护个人信息的要求,进而发挥智能合约个性化拟制和动态化控制特性保障告知同意规则的实现,将智能合约嵌入在线平台企业处理个人信息的全过程,构建用户与平台之间以智能合约为内核的个人信息保护政策。 |
|
关键词: 智能合约;在线平台企业;个人信息保护机制 |
|
|
|
Construction of smart contract mechanism for users’personal information protection of online platform companies |
|
XU Juan, LI Haotian |
|
(School of Law and Public Affairs, Nanjing University of Information Science &
Technology, Nanjing 210044, China) |
|
Abstract: Personal information protection policy is a general term for the text of the online platform companies' policies and measures for maintaining users' personal information, and, in accordance with existing laws and regulations, stipulating and explaining in details its acquisition, management and protection of personal information. Smart contracts, as specific code programs that cover informed consent rules and are automatically executed, can be used to implement personal information protection policies in intelligent application scenarios. China's Personal Information Protection Law, which has entered the implementation level, requires certain procedural mechanisms to ensure the compliance of personal information handling behavior of enterprises, and the non-intelligent nature of the existing procedural mechanisms makes it difficult to deal with the phenomenon of excessive collection and abuse caused by personal information handlers with technical advantages. Therefore, it is necessary to attempt to use the technical management function of smart contracts to make up the deficiency of personal information protection policy. And specific measures include targeted transformation of block-chain as bottom technology of smart contracts to meet the needs of protecting personal information so as to execute the fulfilment of the simulation of personalizing smart contracts as well as dynamic control on peculiar securing and notifying the agreement of the rules. The smart contract is embedded in the whole process of handling personal information by the online platform companies, and the personal information protection policy between the user and the platform is built with the smart contract as the core. |
|
Key words: smart contracts; online platform companies; personal information protection policies |
|
|
|