Prioritising Command-and-Control Over Collaborative Governance: The Role of the Information Regulator Under the Protection of Personal Information Act

Prioritising Command-and-Control Over Collaborative Governance: The Role of the Information Regulator Under the Protection of Personal Information Act
复制标题

指挥控制优先于协作治理:《个人信息保护法》下信息监管者的角色

DOI:
--
复制
发表时间:
2022
影响因子:
--
通讯作者:
V. Bronstein
V. Bronstein
中科院分区:
--
文献类型:
--
作者:
V. Bronstein

文献摘要

被引文献

相似文献

尽管《2013 年第 4 号个人信息保护法》(POPIA) 全心全意采用了欧盟《通用数据保护条例》(GDPR) 的命令和控制功能,但 POPIA 并未包含 GDPR 中的许多协作治理机制。 POPIA 淡化了 GDPR 中的问责要求。它很少要求责任方生成或保存文件,并且南非法案中没有相当于欧洲数据保护影响评估的内容。这会影响涉及分析的自动化处理的监管。欧洲认证体系也不包含在 POPIA 中。 POPIA 包括一套行为准则体系,但即使它们也具有更强制性的性质。 POPIA 缺乏协作治理机制,导致南非错失了建立加强数据保护文化的机会。信息监管机构的任务是根据该法案给予许多豁免和事先批准。新成立的信息监管机构将发现自己面临着特别困难的任务。
Although the Protection of Personal Information Act 4 of 2013 (POPIA) wholeheartedly adopts the command-and-control features of the EU General Data Protection Regulation (GDPR), POPIA does not include many of the collaborative governance mechanisms in the GDPR. POPIA dilutes the accountability requirements in the GDPR. It rarely requires responsible parties to generate or keep documentation and there is no equivalent of European Data Protection Impact Assessments in the South African Act. This affects the regulation of automated processing that involves profiling. The European system of certifications is also not included in POPIA. POPIA includes a system of codes of conduct but even they have a more peremptory nature. The absence of collaborative governance mechanisms in POPIA constitutes a missed opportunity to build a culture of enhanced data protection in South Africa. The Information Regulator has the task of giving many exemptions and prior-approvals under the Act. The newly constituted Information Regulator will find itself exposed as it faces a particularly difficult mandate.