2018-08-01 11:48:00

近年來(lái),企業(yè)也越來(lái)越注重?cái)?shù)據(jù)處理合規(guī)問(wèn)題的解決。360、螞蟻金服等先覺(jué)的企業(yè)接連設(shè)立了首席隱私官(Chief privacy officer簡(jiǎn)稱CPO)以實(shí)現(xiàn)對(duì)用戶隱私信息的保護(hù)。
GDPR生效之后,一種新型角色被推上風(fēng)口浪尖,成為世界范圍內(nèi)各大互聯(lián)網(wǎng)、廣告媒體、新聞企業(yè)競(jìng)相追逐的“香餑餑”。此角色被稱作數(shù)據(jù)保護(hù)官(Data Protection Officer簡(jiǎn)稱DPO),GDPR第37至第39條對(duì)DPO的委任、職位和任務(wù)做出了專門的規(guī)定。作為數(shù)據(jù)規(guī)制新時(shí)代下的新產(chǎn)物,如何對(duì)DPO進(jìn)行全面、準(zhǔn)確的理解從而將其更好地應(yīng)用于實(shí)踐中,是企業(yè)及其他機(jī)構(gòu)都需要關(guān)注的重要話題。
一、DPO是什么
——數(shù)據(jù)合規(guī)的監(jiān)督者與協(xié)調(diào)者
數(shù)據(jù)保護(hù)官是GDPR明確指出的企業(yè)內(nèi)承擔(dān)數(shù)據(jù)保護(hù)合規(guī)相關(guān)職責(zé)的職能角色。對(duì)DPO的專門規(guī)定體現(xiàn)了GDPR規(guī)制范圍的擴(kuò)大化:數(shù)據(jù)規(guī)制不僅表現(xiàn)在具體的數(shù)據(jù)處理過(guò)程中,也反映為對(duì)機(jī)構(gòu)組織結(jié)構(gòu)的干預(yù)。
從外部合規(guī)的角度而言, DPO的設(shè)立是GDPR框架下的強(qiáng)制性要求。若上述機(jī)構(gòu)未設(shè)立DPO或具體設(shè)計(jì)違反GDPR的明確規(guī)定,則將被認(rèn)定為是對(duì)控制者與處理者責(zé)任的違背。
從內(nèi)部執(zhí)行的視角上看,DPO這一專門職能角色將在企業(yè)具體的數(shù)據(jù)合規(guī)過(guò)程中發(fā)揮統(tǒng)籌各方的核心作用。因此在對(duì)企業(yè)內(nèi)部進(jìn)行數(shù)據(jù)合規(guī)制度設(shè)計(jì)時(shí),應(yīng)當(dāng)對(duì)DPO給予足夠的重視。
二、你需不需要設(shè)立DPO?
對(duì)于以下情形,GDPR要求其必須設(shè)立DPO:①數(shù)據(jù)處理由公共機(jī)構(gòu)或機(jī)關(guān)主導(dǎo)(除了司法機(jī)關(guān))的情形;如作為政府單位的UK home office已經(jīng)明確設(shè)立了DPO對(duì)數(shù)據(jù)合規(guī)進(jìn)行指導(dǎo)監(jiān)督。②核心業(yè)務(wù)需要對(duì)數(shù)據(jù)主體定期進(jìn)行大規(guī)模處理的情形;對(duì)于本情形下“核心業(yè)務(wù)”的判斷可以參考企業(yè)的性質(zhì)、營(yíng)業(yè)范圍與商業(yè)目的等因素。③機(jī)構(gòu)對(duì)敏感數(shù)據(jù)(生物特征、性取向等)進(jìn)行大規(guī)模處理的情形。值得注意的是,GDPR對(duì)必須設(shè)立DPO的標(biāo)準(zhǔn)中采取了一些具有不確定性的表述(如“核心業(yè)務(wù)”“大規(guī)模處理”),因此若企業(yè)在進(jìn)行判斷時(shí)應(yīng)當(dāng)盡量向監(jiān)管機(jī)構(gòu)明確自身的設(shè)立要求。若經(jīng)過(guò)評(píng)估決定不設(shè)立DPO,則應(yīng)該對(duì)企業(yè)性質(zhì)、數(shù)據(jù)處理情況等相關(guān)考量因素予以詳細(xì)記錄,以備監(jiān)管機(jī)構(gòu)的調(diào)查。
當(dāng)然,無(wú)論是經(jīng)過(guò)判斷認(rèn)定不屬于或明顯不屬于上述三種類型的企業(yè)、機(jī)構(gòu),其在符合自身情況的基礎(chǔ)上自發(fā)地設(shè)立DPO,是為GDPR所鼓勵(lì)的。
三、DPO的選任與構(gòu)成
——選誰(shuí)呢?
(1)資質(zhì)要求
在確認(rèn)要設(shè)立DPO之后的第一個(gè)問(wèn)題在于,應(yīng)當(dāng)如何選任DPO。
GDPR第37條規(guī)定了對(duì)于DPO選任的首要考量因素,即專業(yè)性的素質(zhì)。一名合格的DPO不僅需要有豐富的數(shù)據(jù)保護(hù)法律知識(shí)、實(shí)踐經(jīng)驗(yàn),還需要有較強(qiáng)的溝通協(xié)調(diào)能力與統(tǒng)籌能力;另外,為了能夠合理地將具體數(shù)據(jù)處理行為與法律規(guī)制聯(lián)系起來(lái)并做出有效的風(fēng)險(xiǎn)評(píng)估,DPO應(yīng)當(dāng)盡可能地熟悉公司業(yè)務(wù)、了解相關(guān)技術(shù)知識(shí)。
(2)角色構(gòu)成
DPO最大的職位特點(diǎn)在于其獨(dú)立性:一方面,DPO的履職行為不受數(shù)據(jù)控制者與處理者的指示和干預(yù),后者不得因合規(guī)活動(dòng)對(duì)DPO進(jìn)行懲罰或解雇;相反的,后者應(yīng)當(dāng)為其提供良好的工作環(huán)境與資源。另一方面,DPO自身不得從事與其履職相沖突的工作,以保障自身的獨(dú)立判斷。具體表現(xiàn)為,DPO不得兼任COO(首席運(yùn)營(yíng)官)、CEO(首席執(zhí)行官)等可能帶來(lái)利益沖突的職位。

(3)實(shí)踐中的若干問(wèn)題
GDPR文本中并未對(duì)DPO的具體構(gòu)成做出詳細(xì)規(guī)定,以致于在實(shí)際操作中可能存在一定疑惑,對(duì)此筆者將以Q&A形式予以解答:
Q1:DPO是指單個(gè)自然人抑或是一個(gè)特定機(jī)構(gòu)/委員會(huì)
A:GDPR并未對(duì)DPO的組織構(gòu)成進(jìn)行直接的要求。雖然第38條在引指DPO時(shí)使用了“he/she”這一指向自然人的表述方式,但這不意味著DPO只能由單個(gè)的自然人擔(dān)任。筆者認(rèn)為,DPO的職責(zé)包括完成一系列較為復(fù)雜、全面的工作任務(wù),既有法律合規(guī)的部分,也有具體業(yè)務(wù)評(píng)估、各方聯(lián)系協(xié)調(diào)等內(nèi)容。出于全面履職的考慮,以有明確分工的特定機(jī)構(gòu)作為完成DPO工作的主體是比較可取的。因此企業(yè)在決定自身DPO的人員構(gòu)成時(shí),可以充分考慮自身的情況而做出靈活的選擇。
Q2:DPO是否可以委任企業(yè)外部人員擔(dān)任?
A:GDPR第37條規(guī)定DPO既可以由企業(yè)內(nèi)部員工組成,也可基于服務(wù)合同完成任務(wù)。由此可見(jiàn)GDPR對(duì)外聘人員擔(dān)任DPO是認(rèn)可的。然而就具體的外聘方向上看,提供合規(guī)服務(wù)的律所似乎是不錯(cuò)的選擇,但DPO的職能要求其不僅要有專業(yè)的數(shù)據(jù)合規(guī)法律知識(shí),也對(duì)數(shù)據(jù)處理技術(shù)等非法律內(nèi)容有足夠的了解。筆者認(rèn)為外聘DPO同樣不適合“單兵種作戰(zhàn)”,而需要由擁有不同技能背景的人員諸如律師、技術(shù)人員、會(huì)計(jì)師等共同組成、相互協(xié)助。而當(dāng)此類業(yè)務(wù)發(fā)展足夠成熟時(shí),市場(chǎng)中甚至可能形成專門提供此類業(yè)務(wù)的特定機(jī)構(gòu),那時(shí)合規(guī)業(yè)務(wù)的規(guī)范化與專業(yè)化便將更上一個(gè)臺(tái)階。
Q3:DPO可以兼職嗎?
A:GDPR第36條認(rèn)可了兼職DPO的情形,但前提所兼任崗位與DPO履職之間不得沖突。實(shí)踐中企業(yè)可能直接將數(shù)據(jù)合規(guī)工作交給內(nèi)部的法務(wù)人員,但這種工作安排一定要慎之又慎:一方面內(nèi)部法務(wù)由于自身經(jīng)驗(yàn)、知識(shí)結(jié)構(gòu)的局限,較難充分的完成GDPR提出的合規(guī)要求,且在時(shí)間精力一定的情況下,工作量的提升將可能導(dǎo)致處理單項(xiàng)業(yè)務(wù)的精細(xì)度降低;另一方面,作為法務(wù)人員的目標(biāo)追求與DPO的價(jià)值取向是存在一定的差異的,不加考慮地讓其兼任將造成利益沖突的風(fēng)險(xiǎn)。
總體而言,企業(yè)對(duì)DPO的選任要基于自身的情況。對(duì)于數(shù)據(jù)處理行為較為簡(jiǎn)單、部門間溝通較為便捷的企業(yè),可以考慮只設(shè)單名DPO;而對(duì)于像騰訊、360等業(yè)務(wù)復(fù)雜的企業(yè),一個(gè)人員數(shù)量足、技術(shù)水平高、合作能力強(qiáng)的DPO團(tuán)隊(duì)則是更為合理的選擇。
四、DPO的職權(quán)
GDPR所規(guī)定的DPO的主要職責(zé)與權(quán)利歸納如下:
(1)DPO的主要職責(zé)

(2)DPO的主要權(quán)利

五、DPO為核心的合規(guī)路徑
(1)方法與思路
當(dāng)下我國(guó)企業(yè)整體的數(shù)據(jù)合規(guī)程度較低,甚至有很多企業(yè)在此問(wèn)題上“身處囹圄而不知”。基于此筆者建議企業(yè)采用缺口分析(Gap Analysis)的方法,在全面調(diào)查了解自身數(shù)據(jù)合規(guī)狀況的基礎(chǔ)上,對(duì)存在的問(wèn)題與缺陷進(jìn)行補(bǔ)正。
結(jié)合DPO工作的內(nèi)容與特點(diǎn)。數(shù)據(jù)合規(guī)可以參照以下思路:
①全面貫穿:數(shù)據(jù)合規(guī)工作要貫穿數(shù)據(jù)處理相關(guān)的所有活動(dòng)、各個(gè)階段。
②獨(dú)立監(jiān)督:充分發(fā)揮DPO這一獨(dú)立職能角色,對(duì)數(shù)據(jù)合規(guī)狀況進(jìn)行客觀的評(píng)價(jià)與監(jiān)督。
③有據(jù)可依:從應(yīng)對(duì)合規(guī)檢查的角度來(lái)說(shuō),企業(yè)內(nèi)部的合規(guī)工作應(yīng)全面落實(shí)
(2)具體制度設(shè)計(jì)
從制度操作層面上看,具體的合規(guī)方法包括:
①充分利用加密、數(shù)據(jù)脫敏、去標(biāo)識(shí)化等技術(shù)措施,保障用戶數(shù)據(jù)安全,為數(shù)據(jù)合規(guī)奠定技術(shù)基礎(chǔ)。
② 建立起全面的數(shù)據(jù)處理行為備案體系,特定數(shù)據(jù)處理行為必須記錄決策者、DPO、操作者三方意見(jiàn),并將DPO對(duì)數(shù)據(jù)合規(guī)的評(píng)估情況進(jìn)行專門記錄。
③為DPO配備相應(yīng)的財(cái)政(獨(dú)立預(yù)算)、人事(不因履職而被解雇)、通訊(各方聯(lián)系渠道)、學(xué)習(xí)以及監(jiān)管權(quán)限方面的資源,打通DPO與決策者、操作者的交流途徑。尤其應(yīng)當(dāng)通過(guò)平臺(tái)內(nèi)部告知、設(shè)置專門客服等方式簡(jiǎn)化數(shù)據(jù)主體與DPO取得聯(lián)系、解決相關(guān)問(wèn)題的渠道。
④對(duì)內(nèi)部員工展開(kāi)定期的數(shù)據(jù)合規(guī)培訓(xùn)。同時(shí)建立各部門定期述職機(jī)制:數(shù)據(jù)處理相關(guān)部門應(yīng)定期(季度報(bào)告、半年報(bào)、年報(bào)等)向DPO提交數(shù)據(jù)合規(guī)執(zhí)行報(bào)告,對(duì)于緊急事件應(yīng)當(dāng)盡快提交臨時(shí)報(bào)告,從而實(shí)現(xiàn)“問(wèn)題早實(shí)現(xiàn)、早解決”
⑤.為解決內(nèi)部員工缺乏意識(shí)的問(wèn)題,可以將數(shù)據(jù)合規(guī)情況納入員工的績(jī)效考察體系當(dāng)中,通過(guò)對(duì)獎(jiǎng)金、福利等員工利益的影響,督促相關(guān)人員配合DPO工作,履行自身義務(wù)。
六、結(jié)語(yǔ)
扎克伯格提醒著大家“不要認(rèn)為我們已經(jīng)完成了GDPR的要求”。面對(duì)GDPR的挑戰(zhàn),留待我國(guó)企業(yè)完成的工作還有很多。而DPO這一GDPR框架下的結(jié)構(gòu)設(shè)計(jì)在一定意義上將成為企業(yè)內(nèi)部合規(guī)工作體系化的標(biāo)志。
近日來(lái)東航已經(jīng)成為了首個(gè)設(shè)立DPO的國(guó)內(nèi)企業(yè),可以看出DPO的設(shè)置絕非紙上談兵,而是相關(guān)企業(yè)必須要謹(jǐn)慎考慮而應(yīng)用于實(shí)踐的重要制度。
注:感謝實(shí)習(xí)生黃宇哲為這篇文章做的支持工作。
附錄:GDPR對(duì)于DPO的規(guī)定原文與翻譯:
Art. 37
1.The controller and the processor shall designate a data protection officer in any case where:
在以下任一情形中,數(shù)據(jù)控制者與處理者應(yīng)當(dāng)委任數(shù)據(jù)保護(hù)官:
(a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
數(shù)據(jù)處理是由公共機(jī)構(gòu)或公共實(shí)體進(jìn)行的,法庭履行其司法職責(zé)的除外
(b) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
數(shù)據(jù)控制者或處理者的核心處理活動(dòng)天然性地需要大規(guī)模對(duì)數(shù)據(jù)主體進(jìn)行常規(guī)和系統(tǒng)化地監(jiān)控;或者
(c) the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10.
數(shù)據(jù)控制者或管理者地核心活動(dòng)包含了GDPR第9條所規(guī)定的對(duì)某種特殊類型數(shù)據(jù)進(jìn)行的大規(guī)模處理以及第10條所規(guī)定的對(duì)定罪和違法相關(guān)的個(gè)人數(shù)據(jù)的處理。
2. A group of undertakings may appoint a single data protection officer provided that a data protection officer is easily accessible from each establishment.
如果一組企業(yè)的任一機(jī)構(gòu)都能容易地與數(shù)據(jù)保護(hù)官取得聯(lián)系,那么這組企業(yè)可以任命一位單獨(dú)的數(shù)據(jù)保護(hù)官。
3.Where the controller or the processor is a public authority or body, a single data protection officer may be designated for several such authorities or bodies, taking account of their organizational structure and size.
當(dāng)數(shù)據(jù)控制者或處理者是一個(gè)公共機(jī)構(gòu)或公共實(shí)體,基于它們的組織機(jī)構(gòu)與規(guī)模,多個(gè)此類公共機(jī)構(gòu)或?qū)嶓w可以共同委任一位數(shù)據(jù)保護(hù)官。
4.In cases other than those referred to in paragraph 1, the controller or processor or associations and other bodies representing categories of controllers or processors may or, where required by Union or Member State law shall, designate a data protection officer. The data protection officer may act for such associations and other bodies representing controllers or processors.
除了第一段所規(guī)定的情形,在歐盟或成員國(guó)法律要求的情形下,數(shù)據(jù)控制者或處理者、或代表某類控制者或處理者的協(xié)會(huì)與其他實(shí)體可以委任一名數(shù)據(jù)保護(hù)官。對(duì)于此類協(xié)會(huì),或代表控制者或處理者的其他實(shí)體的活動(dòng),數(shù)據(jù)保護(hù)官有權(quán)代表它們進(jìn)行活動(dòng)。
5.The data protection officer shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39.
數(shù)據(jù)保護(hù)官的委任必須基于其專業(yè)性的素質(zhì),其需要具有數(shù)據(jù)保護(hù)法律與實(shí)踐的專業(yè)知識(shí),以及完成第39條所規(guī)定任務(wù)的能力。
6.The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract.
數(shù)據(jù)保護(hù)官可以是數(shù)據(jù)控制者與處理者的職員或基于服務(wù)合同而完成任務(wù)。
7. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.
數(shù)據(jù)控制者或處理者應(yīng)當(dāng)公布數(shù)據(jù)保護(hù)官的具體聯(lián)系方式,并向監(jiān)管機(jī)構(gòu)進(jìn)行報(bào)告。
Art.38
1. The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.
數(shù)據(jù)控制者和處理者應(yīng)當(dāng)確保,在所有與個(gè)人數(shù)據(jù)保護(hù)有關(guān)的事項(xiàng)中,數(shù)據(jù)保護(hù)官都以一種適當(dāng)而及時(shí)的方式介入。
2.The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.
數(shù)據(jù)控制者和處理者應(yīng)當(dāng)通過(guò)提供完成任務(wù)所必須的資源、提供訪問(wèn)個(gè)人數(shù)據(jù)與進(jìn)行操作處理的權(quán)限、維持其專業(yè)性知識(shí),來(lái)支持?jǐn)?shù)據(jù)保護(hù)官履行GDPR第39條所規(guī)定的職責(zé)。
3. The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. 2He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. 3The data protection officer shall directly report to the highest management level of the controller or the processor.
數(shù)據(jù)控制者與處理者應(yīng)當(dāng)確保個(gè)人數(shù)據(jù)保護(hù)官不會(huì)受到任何關(guān)于履行職責(zé)的指示,他(她)不應(yīng)因完成其任務(wù)而被數(shù)據(jù)控制者或處理者解雇或懲罰。數(shù)據(jù)保護(hù)官有權(quán)向數(shù)據(jù)控制者或處理者的最高管理層進(jìn)行直接報(bào)告。
4. Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.
數(shù)據(jù)主題可以在所有與其自身數(shù)據(jù)處理相關(guān)的事項(xiàng),以及與行使GDPR所賦予的權(quán)利相關(guān)的事項(xiàng)中聯(lián)系數(shù)據(jù)保護(hù)官。
5.The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.
數(shù)據(jù)保護(hù)官應(yīng)當(dāng)遵守歐盟或成員國(guó)的法律,在履行自身職責(zé)時(shí)遵守保密義務(wù)。
6.The data protection officer may fulfil other tasks and duties. 2The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.
數(shù)據(jù)保護(hù)官可以完成其他的任務(wù)或職責(zé)。數(shù)據(jù)控制者或處理者應(yīng)當(dāng)確保此類任務(wù)與職責(zé)不會(huì)導(dǎo)致利益的沖突。
Art.39
1. The data protection officer shall have at least the following tasks:
數(shù)據(jù)保護(hù)官至少有以下任務(wù):
(a) to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;
對(duì)數(shù)據(jù)控制者或處理者,以及基于GDPR及其他歐盟或成員國(guó)數(shù)據(jù)保護(hù)條款所規(guī)定對(duì)自身義務(wù)進(jìn)行評(píng)估的雇員進(jìn)行告知并提供建議。
(b)to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
確保對(duì)本條例、其他歐盟或成員國(guó)數(shù)據(jù)保護(hù)條款、數(shù)據(jù)控制者或處理者關(guān)于個(gè)人數(shù)據(jù)保護(hù)政策的遵守,包括分配職責(zé)、增強(qiáng)意識(shí)、及對(duì)數(shù)據(jù)處理操作過(guò)程和相關(guān)審查中涉及的職員進(jìn)行培訓(xùn)。
(c)to provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;
當(dāng)被要求就數(shù)據(jù)保護(hù)影響評(píng)估與根據(jù)GDPR第35條對(duì)其實(shí)施進(jìn)行監(jiān)管的事項(xiàng),應(yīng)當(dāng)提供建議。
(d) to cooperate with the supervisory authority;
與監(jiān)管機(jī)構(gòu)進(jìn)行合作。
(e) to act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.
在與處理相關(guān)的事項(xiàng)中充當(dāng)監(jiān)管機(jī)構(gòu),上述事項(xiàng)包括GDPR第36條所規(guī)定的提前咨詢以及其他事項(xiàng)在適當(dāng)情況下進(jìn)行的咨詢中。
2.The data protection officer shall in the performance of his or her tasks have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.
數(shù)據(jù)保護(hù)官在履行職責(zé)時(shí),應(yīng)當(dāng)結(jié)合處理的性質(zhì)、范圍、語(yǔ)境與目的,對(duì)處理操作的風(fēng)險(xiǎn)進(jìn)行合理的考慮。