A Comparative Legal Study on Data Breaches in Japan, the U.S., and the U.K.

A Comparative Legal Study on Data Breaches in Japan, the U.S., and the U.K.
复制标题

日本、美国和英国数据泄露的比较法律研究

DOI:
10.1007/978-3-319-44805-3_8
复制
发表时间:
2016
期刊:
“Technology and Intimacy: Choice or Coercion”・Springer International Publishing
影响因子:
--
通讯作者:
Taro Komukai
Taro Komukai
中科院分区:
--
文献类型:
--
作者:
Kaori Ishii;Taro Komukai

文献摘要

相似文献

本文重点讨论了数据控制者在数据泄露方面的责任和义务,并比较了日本、美国、日本和美国的相关法律的制度,和英国减少或纠正数据泄露造成的损害有三种主要方法:(1)为数据泄露提供补救措施;(2)数据安全义务;(3)发生数据泄露时的通知义务。本文的目的是从上述观点出发,对数据泄露的应对措施进行比较,并提出相关问题,以寻求适当的解决方案。为了解决数据泄露相关问题,由于个人数据的全球流通,各国之间的法律的规则应该是共同的。尽管如此,通过各章节的分析,还是可以看出不同的特点。迄今为止,日本的企业即使在数据保护方面效果不佳,也积极遵守数据安全义务。进行皮亚斯是防止安全事故的另一种选择。如果引入数据泄露通知规则,则必须确定要公布的主题,并采取执法行动。此外,这些规则应有助于避免二次伤害。在美国,虽然数据泄漏的赔偿和安全漏洞通知规则显然已得到有效管理,但需要减少大规模数据泄露造成的严重危害。强制公司保持数据可追溯性可能有助于这一点。在英国,作为《通用数据保护条例》的一部分,数据泄露通知规则需要与其他有效的执行和贡献相结合,以避免二次伤害,以免变得毫无意义。我们必须协调上述差异,并不断努力提高规则的有效性。
This paper focuses on the liability and duties of data controllers regarding data leaks and compares the relevant legal schemes of Japan, the U.S., and the U.K. There are three primary approaches to reducing or redressing damages caused by data leaks: (1) providing remedies for data leaks; (2) data security obligations; and (3) notification obligations in the event of a data breach. The aim of this article is to compare the measures on data breaches from the above viewpoints and highlight the relevant issues in order to reach an appropriate solution.To address the issues related to data breaches, legal rules among countries should be common to all due to the worldwide circulation of personal data. Nonetheless, different features are recognizable through the analysis in each chapter.Companies in Japan have thus far eagerly abided by data security obligations even if they are ineffective for data protection. Conducting PIAs is another option to prevent security incidents. If data breach notification rules are introduced, the subject matters to be publicized must be identified and followed by enforcement actions. Also, such rules should contribute to the avoidance of secondary harm.In the U.S., while compensations for data leakage and security breach notification rules have apparently been effectively managed, it is needed to reduce serious harm arising from massive data breach. Obliging companies to maintain data traceability might serve this.In the U.K., data breach notification rules imposed as part of the General Data Protection Regulation need to connect with other effective enforcements and contributions to avoiding secondary harm, so as not to become meaningless.We must harmonize the above differences and make ongoing efforts to improve the effectiveness of rules.