首页|个人信息泄露风险损害的赔偿责任

个人信息泄露风险损害的赔偿责任

扫码查看
《个人信息保护法》第 69 条确立了侵害个人信息权益损害赔偿的请求权基础,但并未明确规定应予救济的损害类型.当个人信息泄露并未实际造成次生损害时,其侵害后果具有无形性、不确定性、风险导向性,统一损害概念难以完全涵盖,有必要重构原生损害概念及其赔偿责任.个人信息泄露原生损害赔偿对象并非计算差额或个人信息的市场价值减损,而是面向未来的实质性风险.风险损害应采用动态体系的评价方法,落实于第三人动机、信息敏感性、安全技术措施、滥用证据等要素,其结论取决于诸要素协动后的综合权衡.风险损害的赔偿范围包括风险预防费用、使用利益丧失、内心焦虑损害、维权合理开支等,应建立其数额量化的酌定因素和区间.
Compensation Liability of Risk Damage Caused by Personal Information Breach
Article 69 of the Personal Information Protection Law establishes the basis of the claim for damages for infringement of personal information rights and interests,but does not specify the types of damage that should be remedied.When the personal information breach does not actually cause secondary damage,its infringement consequences are intangible,uncertain and risk-oriented,which is difficult to be fully covered by the unified damage concept.It is necessary to reconstruct the concept of primary damage and its compensation liability.The object of compensation for the primary damage caused by the personal information breach is not the difference in calculation or the diminution of the market value of personal information,but the future-oriented substantial risks.Risk damage should adopt a flexible system evaluation method,which is implemented in the elements of the third party's motivation,information sensitivity,security technology measures,and evidence of abuse.The conclusion depends on the comprehensive balance after the coordination of the elements.The scope of compensation for risk damage includes risk prevention costs,loss of use benefits,inner anxiety damage,and reasonable expenses for safeguarding rights,and discretionary factors and intervals for quantifying their amounts should be established.

personal informationdata breachrisk damageflexible systemdiscretionary

时诚

展开 >

中国社会科学院 法学研究所,北京 100720

个人信息 数据泄露 风险损害 动态体系 酌定

国家社会科学基金重大项目

23&ZD155

2024

现代法学
西南政法大学

现代法学

CSTPCDCSSCICHSSCD北大核心
影响因子:2.725
ISSN:1001-2397
年,卷(期):2024.46(2)
  • 52