Privacy, Big Data, and the Public Good: Monitoring, Datafication, and Consent: Legal Approaches to Privacy in the Big Data Context

Privacy, Big Data, and the Public Good: Monitoring, Datafication, and Consent: Legal Approaches to Privacy in the Big Data Context
复制标题

隐私、大数据和公共利益:监控、数据化和同意:大数据背景下隐私的法律途径

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
K. Strandburg
K. Strandburg
中科院分区:
--
文献类型:
--
作者:
K. Strandburg

文献摘要

被引文献

相似文献

引言 知识就是力量。“大数据”具有造福社会的巨大潜力。同时,其可用性为个人信息的错误、误导或恶意使用创造了重大可能性。法律面临的难题是为大数据提供空间以实现其对社会有益的潜力,同时充分保护公民免受相关的个人和社会危害。当前的隐私法是为解决不同的问题而发展起来的,必须加以调整以应对大数据的挑战。本章仅涉及隐私法的一个方面:对私营部门获取、汇总和转移个人信息的监管。它对现行法律进行了概述和分类,强调了现行法律与大数据环境之间的不匹配,目的是为关于如何使大数据实践和隐私监管达到最佳和谐的讨论提供信息。 第一部分简要描述了美国的隐私监管是如何随着技术和社会环境的变化而演变的。 第二部分基于以下特征介绍了与数据获取相关的隐私法分类:(1)法律提供的是基于规则的标准还是基于事实的标准;(2)从下文所定义的意义上说,法律是实体性的还是程序性的;(3)法律涵盖哪些数据获取模式。它还认为,将信息记录、汇总和组织成可用于数据挖掘的形式(在此称为“数据化”)具有独特的隐私影响,而现行法律往往没有认识到这些影响。 第三部分根据该分类对相关隐私法进行了有选择的概述。A节讨论了最像标准的法律制度,如隐私侵权,对于这些制度,确定责任通常涉及对数据主体以及获取或转移数据的人(“数据处理者”)的行为进行基于事实的具体分析。B节讨论了联邦贸易委员会(FTC)的“不公平和欺骗性贸易行为”标准,该标准取决于对数据处理者行为的基于事实的具体调查,但对数据主体做出了一般性假设。
Introduction Knowledge is power. ‘Big data’ has great potential to benefit society. At the same time, its availability creates significant potential for mistaken, misguided, or malevolent uses of personal information. The conundrum for law is to provide space for big data to fulfill its potential for societal benefit, while protecting citizens adequately from related individual and social harms. Current privacy law evolved to address different concerns and must be adapted to confront big data’s challenges. This chapter addresses only one aspect of privacy law: the regulation of private sector acquisition, aggregation, and transfer of personal information. It provides an overview and taxonomy of current law, highlighting the mismatch between current law and the big data context, with the goal of informing the debate about how to bring big data practice and privacy regulation into optimal harmony. Part I briefly describes how privacy regulation in the United States has evolved in response to a changing technological and social milieu. Part II introduces a taxonomy of privacy laws relating to data acquisition, based on the following features: (1) whether the law provides a rule- or a fact-based standard; (2) whether the law is substantive or procedural, in a sense defined below; and (3) which mode(s) of data acquisition are covered by the law. It also argues that the recording, aggregation, and organization of information into a form that can be used for data mining, here dubbed ‘datafication’, has distinct privacy implications that often go unrecognized by current law. Part III provides a selective overview of relevant privacy laws in light of that taxonomy. Section A discusses the most standards-like legal regimes, such as the privacy torts, for which determining liability generally involves a fact-specific analysis of the behavior of both data subjects and those who acquire or transfer the data (‘data handlers’). Section B discusses the Federal Trade Commission’s (FTC’s) ‘unfair and deceptive trade practices’ standard, which depends on a fact-specific inquiry into the behavior of data handlers, but makes general assumptions about data subjects.