【臺大法學論叢】個人資料合理利用模式之探析:以健康資料之學術研究為例
2020-06-30
期刊名:【臺大法學論叢】個人資料合理利用模式之探析:以健康資料之學術研究為例 |
卷數:49卷1期 |
出版時間:2020年3月 |
作者:李寧修 |
出版者:國立臺灣大學法律學院 |
I S S N:1018-3825 |
中文摘要:隨著大數據時代來臨,個人資料被視為新黑金,掌握與運用個人資料成為新興無煙囪工業,透過大量資料之匯聚、分析、應用,有效提升競爭力、強化效能,甚至有助預測、描述行為,或作為決策之參考與依憑。學術領域亦嘗試透過以健康資料(庫)為基礎之研究,提升醫藥及公共衛生品質,或預防疾病發生,而伴隨著此一發展趨勢,國家恐怕無法迴避人民於學術研究過程中運用個人資料(庫)之積極需求。然而,我國現行法制是否得涵蓋多樣的個人資料運用型態,兼顧「個人資料合理利用」與「維護當事人權利」之目的?本文以健康資料於學術研究之運用為例,首先,聚焦於個人資料自主控制權與研究自由間之折衝;進而,探究我國現行基於學術研究目的運用健康資料之規範框架,並以歐盟個人資料保護基本規則(Datenschutz-Grundverordnung)為借鏡;最後,對於健康資料之合理利用模式,提出觀察與建議,包括:應以專法確立合法運用之法制基礎;再斟酌合理利用個人資料要件,如:給予基於學術研究目的之運用較大彈性,以及當事人同意要件之調整與配套;以及建立組織與程序機制,如:納入事前之風險結果評估機制、去識別化技術、相應自律與他律監督,期待透過建立適當之法制規範與監管架構,力求締造雙贏之可能! |
英文摘要:As the era of big data approaches, personal data has been seen as the new black gold. Countries and corporations have rushed to develop this new tertiary industry that withholds and applies personal data. By accumulating, analyze and utilizing these personal data, the outcome can effectively advance competition, reinforce efficiency, and even help either predict or depict behavior or become a reference to the decision-makers. The academic field also seeks to elevate the quality of healthcare and public health, or disease prevention, based on health database research. Following this trend of use of personal data, the government has to face people's active need to use personal data(base) for academic research. However, whether the current regulatory scheme of personal data protection can comprise the varieties of the application of personal data while balancing "the reasonable use of personal data" and "protecting the right of the user" comes into question. This article aims to use the application of health data in academic research as an example. This article will focus on the compromise between the right of maintaining self-control of personal information and freedom of academic research. Further, the article will discuss Taiwan's regulatory framework on the application of health data for academic research, while drawing reference from the EU's General Data Protection Regulation (Datenschutz-Grundverordnung). At last, regarding the reasonable use of health data mode, this article will provide personal observation and advice. Firstly, the usage of health data should be promulgated through special law to establish a legal basis for lawful usage. Secondly, more thoughts should be put into the elements of reasonable use of personal data, which includes giving greater flexibility to academic research data usage, and by adjusting the elements for parties consent, to adequately balance the right between academic research and the right of parties. Eventually, corresponding measures via organizational and procedural mechanisms should be built, such as imposing beforehand data protection impact assessment, adequately applying de-identification techniques, and strengthening academic researches self-discipline and heteronomy mechanisms. The anticipation is to establish a proper regulatory scheme and supervision framework to create a win-win situation. |
年份:2020 |