首页|个人信息保护负责人履职困境和规制策略研究

个人信息保护负责人履职困境和规制策略研究

扫码查看
个人信息保护负责人集监督、代表和信息功能为一体,但作为组织成员过度依赖企业组织设计且缺乏决策权限,导致上述功能无法得到发挥.为了保障个人信息保护负责人独立履职,使个人信息保护成为企业内生机制,国家应当进一步要求企业将组织义务转化为有约束力的实施方案提交给监管机关,后者可以据此对个人信息保护负责人的监督能力进行审查,必要时采取制裁措施.对于个人信息保护负责人行政法律责任的承担,应当根据个人信息保护负责人履职过程中的实际权限大小、是否穷尽可行手段防止违法行为进行综合判断.
The dilemma of duty performance and regulatory strategies for personal information protection officers
The personal information protection officer(PIPO)integrates supervisory,representative,and informational functions.However,as a member of the organization,they are overly reliant on the corporate organizational structure and lack decision-mak-ing authority,which prevents these functions from being effectively fulfilled.To ensure that the PIPO can independently perform their duties and make personal information protection an intrinsic mechanism within the company,the state should further require enterprises to convert organizational obligations into binding implementation plans submitted to regulatory authorities.These au-thorities can then assess the supervisory capabilities of the PIPO and impose sanctions if necessary.As for the administrative legal responsibility of the PIPO,a comprehensive judgment should be made based on the actual authority of the PIPO during the per-formance of his duties and whether all feasible means have been exhausted to prevent illegal activities.

personal information protection officerpersonal information protection compliancemeta-regulationorganizational obligationssupervisory responsibilities

张冬阳、周晨宇

展开 >

中国政法大学 法学院,北京 100088

个人信息保护负责人 个人信息保护合规 元规制 组织义务 监督责任

2024

网络安全与数据治理
华北计算机系统工程研究所(中国电子信息产业集团有限公司第六研究所)

网络安全与数据治理

影响因子:0.348
ISSN:2097-1788
年,卷(期):2024.43(12)