簡易檢索 / 詳目顯示

研究生: 劉偉立
Wei-Li Liu
論文名稱: 歐盟與英國之個人資料保護-由執行與監督面檢視
Personal Data Protection in the European Union and United Kingdom - From the Aspects of Execution and Supervision
指導教授: 彭心儀
Shin-Yi Peng
Ian Walden
Ian Walden
口試委員:
學位類別: 碩士
Master
系所名稱: 科技管理學院 - 科技法律研究所
Institute of Law for Science and Technology
論文出版年: 2005
畢業學年度: 93
語文別: 英文
論文頁數: 251
中文關鍵詞: 個人資料保護資料保護隱私權歐盟指令95/46/EC英國個人資料保護法1998電腦處理個人資料保護法
外文關鍵詞: Personal Data Protection, Data Protection, Privacy, European Union Directive 95/46/EC, United Kingdom Data Protection Act 1998, Computer-Processed Presonal Data Protection Law, Data Controller, Data Subject, European Data Protection Supervisor, Article 29 Working Party, Information Commissioner
相關次數: 點閱:2下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 摘要
    網際網路與不斷進步之通訊科技對個人資料保護之工作造成嚴重衝擊,而近來個人資料洩密問題也對台灣社會造成巨大的損失,並引起社會大眾廣泛注意。

    此一問題在歐洲較早獲得重視,並已經建立法律規範以管制個人資料之流通。歐盟現行之個人資料保護指令為目前世上最先進之立法保障規範之一,然而,該指令生效執行十年之後,歐盟各國發現個人資料保護之工作仍有許多不足之處。在歐盟執委會所發佈的執行評估報告中,認為法律規範本身已經到達相當之水準,執行面向之問題才是個人資料保護仍有不足之主因。

    考量個人資料保護於現代社會之重要性,本文將以英國為範例,研究歐盟個人資料保護系統施行之情況,並著重於執行與監督面向,希望能找出個人資料保護之工作更有效之執行模式。

    為取得最新資訊並實地觀察個人資料保護工作之執行情況,本研究絕大部分完成於倫敦大學•皇后瑪莉學院;而研究期間係由中華民國教育部補助部份支出。

    由於歐盟個人資料保護指令 95/46/EC 以及英國個人資料保護法1998於台灣不易取得全文紙本,因此隨附在本文附錄之中,以供讀者閱讀之便,特此說明。


    Abstract
    The prevalence of internet and advanced telecommunication technology has cause a serious problem on personal data protection. In Taiwan, the problem of unwanted disclosure of personal data has caused a great social cost and drew the attention of all citizens recently.

    In Europe, the problem has been earlier noticed and certain laws and regulations have been established. The European Data Protection Directive is known as one of the most advanced regulations on the personal data protection all over the world. However, after ten years of enforcement, they still found a great insufficiency on the work of protecting personal data. In the assessment report published by the European Commission, it is indicated that the law itself indeed has an adequate level of norm, but the problems on the execution, on contrary, is the major factor caused the insufficiency.

    Concerning the importance of the personal data protection in modern society, this research would like to evaluate the personal data protection system in EU and take UK as and example on the implementation of EU Directive. We will mainly focus on the aspects of execution and supervision, and hope to find out better solutions on completing the personal data protection system.

    In order to obtain the latest information and practically observe the execution of Data Protection work, a great part of this research is done in Queen Mary, University of London, and the research program is supported by Ministry of Education of Taiwan.

    Here an explanation must be made. Due to the acquirement of EU Data Protection Directive 95/46/EC & UK Data Protection Act 1998 is relatively difficult in Taiwan, these two bills are enclosed in the appendix for readers’ convenience.

    TABLE OF CONTENTS ABSTRACT 2 CHAPTER ONE 7 INTRODUCTION OF EUROPEAN UNION AND DATA PROTECTION 7 I. INTEGRATION OF EUROPE 7 II. BRIEF INTRODUCTION OF EUROPEAN COMMUNITY LAW 9 1. Legislative Institutes and law-making procedure 9 2. Forms of Laws 11 III. DATA PROTECTION IN EUROPE 12 IV. TERMS AND DEFINITIONS 13 CHAPTER TWO 16 PRINCIPLES OF DATA PROTECTION IN EU AND UK 16 I. EIGHT PRINCIPLES IN UK DATA PROTECTION ACT 1998 17 1. First Principle 17 2. Second Principle 23 3. Third Principle 24 4. Fourth Principle 24 5. Fifth Principle 25 6. Sixth Principle 26 7. Seventh Principle 27 8. Eighth Principle 28 CHAPTER THREE 31 SUBSTANTIVE ISSUES OF DATA PROTECTION LAWS 31 I. RIGHTS OF INDIVIDUALS 32 1. Passive Right 32 2. Positive Rights of Individuals and Issues on the Enforcement 36 II. THE CHOICE OF INTEREST (LEGITIMATE INTEREST AND PUBLIC INTEREST) 48 1. EU Level 49 2. UK Level 50 3. Brief summary 51 4. Public interest in public law area 52 III. TRANSBORDER DATA FLOW AND OTHER ISSUES 53 1. Adequate Level of Protection 53 2. Issues in the Transborder Dataflow 56 3. Safe Harbor 57 CHAPTER FOUR 61 MAJOR SUPERVISORY ISSUES IN EUROPEAN AND UNITED KINGDOM DATA PROTECTION REGIME 61 I. SUPERVISORY AUTHORITIES 61 1. Supervisory Authority in EU & UK 62 2. Supervisory Power and Functions in UK 66 II. SUPERVISORY REGIME 71 1. Regulatory Models 71 2. Notification and the Budget Resource 72 3. Risk of Insufficient Supervision 73 III. CONCLUDING REMARKS AND LESSONS TO TAIWAN 74 2. Choice of Regulatory Model 75 CONCLUSION 79 APPENDIX 80 I. DIRECTIVE 95/46/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL 80 II. UNITED KINGDOM DATA PROTECTION ACT 1998 100 III. UNITED KINGDOM, THE DATA PROTECTION (PROCESSING OF SENSITIVE PERSONAL DATA) ORDER 2000 234 IV. REFERENCES 242

    References
    Legislations:
    1. Directive 95/46/EC of the European Parliament and of the Council
    2. United Kingdom Data Protection Act 1998
    3. United Kingdom Freedom of Information Act 2000
    4. UK Anti-terrorism, Crime and Security Act 2001
    5. The Data Protection (Subject access) (Fees and Miscellaneous Provisions)
    Regulations 2000, SI 2000 No. 191
    6. 電腦處理個人料保護法, 1995年
    7. 個人資料保護法修正草案, 2004年

    Books:
    1. CHRIS REED AND JOHN ANGEL, COMPUTER LAW, 5th Edition, Oxford University Press 2003
    2. PETER CAREY, DATA PROTECTION- A PRACTICAL GUIDE TO UK AND EU LAW, 2nd Edition, Oxford University Press 2004
    3. IAN LLOYD, INFORMATION TECHNOLOGY LAW, 4th Edition, Oxford University Press, 2004
    4. DAMIAN CHALMERS AND EIRKA SZYSZCZAK, EUROPEAN UNION LAW VOLUME ONE, Darmouth Publishing Company 1998
    5. DAMIAN CHALMERS AND EIRKA SZYSZCZAK, EUROPEAN UNION LAW VOLUME TWO, Darmouth Publishing Company 1998
    6. NICHOLAS MOUSSIS, ACCESS TO EUROPEAN UNION – LAW, ECONOMICS, POLICIES 8th edition, European Study Service
    7. DENIS KELLEHER AND KAREN MURRAY, IT LAW IN THE EUROPEAN UNION, Sweet & Maxwell Limited, 1999
    中文書籍:
    1. 黃偉峰主編, 歐洲聯盟的組織與運作, 五南圖書, 2003年4月
    2. 袁發強譯, 歐盟法, 武漢大學出版社, 2003年4月
    3. 邱晃泉,張炳煌合著, 歐洲共同體解讀, 月旦出版社, 1993年10月
    4. 郭秋慶, 歐洲聯盟概論, 五南圖書, 1999年9月
    5. 陳麗娟,歐洲共同體法導論, 五南圖書, 1996 年
    6. F. Boucher, J. Echkenazi 著,吳錫德譯, 認識歐洲聯盟, 中央圖書出版社,□ 1992年4月
    7. 電腦處理個人資料保護法暨相關規定, 財團法人金融聯合徵信中心,1996年8月
    8. 許文義, 個人資料保護法論, 三民書局, 2001 年1月
    9. 李惠宗, 憲法要義, 元照出版, 2004年8月
    10. 吳庚, 行政法之理論與實用七版, 自版, 2001 年八月
    18. 湯德宗,《權力分立新論》,三民書局,2000年二版

    Journal Articles:
    1. SHIN-YI PENG, PRIVACY AND THE CONSTRUCTION OF LEGAL MEANING IN TAIWAN, 37 INTLLAW 1037-1054
    2. ANDREW CHARLESWORTH, INFORMATION PRIVACY LAW IN THE EUROPEAN UNION: E PLURIBUS UNUM OR EX UNO PLURES?, 54 Hastings L.J. 931-969, 943
    3. Aileen McColgan, DO PRIVACY RIGHTS DISAPPEAR IN THE WORKPLACE, (Special issue: privacy 2003), European Human Rights Law Review, E.H.R.L.R. 2003, , 120-140, 128
    4. David Bainbridge and Graham Pearce, TILTING THE WINDMILLS – HAS THE NEW DATA PROTECTION LAW FAILED TO MAKE A SIGNIFICANT CONTRIBUTION TO RIGHTS OF PRIVACY, 2000 (2) The Journal of Information, Law and Technology (JILT),section 3.2, available at http://www2.warwick.ac.uk/fac/soc/law/elj/jilt/2000_2/bainbridge/ , Last Visit 16/Jul/2005
    5. Peter Blume, THE CITIZENS' DATA PROTECTION, 1998 (1) The Journal of Information, Law and Technology (JILT), available at http://www2.warwick.ac.uk/fac/soc/law/elj/jilt/1998_1/blume/ , Last Visit 16/Jul/2005
    6. University of Edinburgh, Guidance notes on Research and the Data Protection Act 1998, 5, available at http://www.recordsmanagement.ed.ac.uk/InfoStaff/DPstaff/DP_Research/DPResearch/Research%20and%20DPAV2.rtf , Last Visit 30/Apr/05
    7. Tanguy Van Overstraeten, “DATA PROTECTION AND PRIVACY ON THE INTERNET: TECHNICAL CONSIDERATIONS AND EUROPEAN LEGAL FRAMEWORK”. Computer and Telecommunications Law Review 2001, 56-65, 62
    8. Bruce Legorburu, DOING BUSINESS BETWEEN THE E.U. AND NEW ZEALAND: WHAT DO YOU HAVE OT DO TO PROTECT PERSONAL INFORMATION THESE DAYS, C.T.L.R. 2000, 6(4), 94-100, 96
    9. Elizabeth Bowes, NONE OF YOUR BUSINESS, C.T.L.R. 2003, 9(3), 87-91, 90
    10. PETER BLUME, TRANSBORDER DATA FLOW: IS THERE A SOLUTION IN SIGHT?, International Journal of Law and Information Technology, Vol.8, No.1, 65-86, 72
    11. XUAN-THAO N. NGUYEN, COLLATERALIZING PRIVACY, 78 Tul. L. Rev. 553-602
    12. TANGUY VAN OVERSTRAETEN, DATA PROTECTION AND PRIVACY ON THE INTERNET: TECHNICAL CONSIDERATION AND EUROPEAN LEGAL FRAMEWORK, Computer and Telecommunications Law Review, 2001
    13. YAMEN AKDENIZ, NEW PRIVACY CONCERN: ISPS, CRIME PREVENTION AND CONSUMERS’ RIGHTS, INTERNATIONAL REVIEW OF LAW COMPUTERS & TECHNOLOGY, Volume 14, No.1, 55-61
    中文期刊資料:
    1. 林安邦,〈德國『資訊自主權』之概念在我國法律上之應用〉,公民訓育學報第十二輯,2002年7月,頁112

    Cases & Decisions:
    1. British Gas Trading Ltd. V. Data Protection Registrar [1998] Info. T.L.R. 393
    2. Naomi Campbell v MGN Ltd. [2003] H.R.L.R. 2
    3. Douglas v Hello! [2003] EWHC 786 (Ch)

    Official Reports & Official Publications:

    1. United Kingdom Information Commissioner Office, Data Protection Act 1998 Legal Guidance, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/data%20protection%20act%201998%20legal%20guidance.pdf , Last Visit 17/Jul/2005
    2. EU Committee of the American Chamber of Commerce in Belgium, Position Paper on the review of Directive 95/46/EC on the Protection of Individuals with regard to the Processing of Personal Data, 6, available at http://europa.eu.int/comm/justice_home/fsj/privacy/docs/lawreport/paper/amcham_en.pdf , Last visit 25/Apr/2005.
    3. United Kingdom Information Commissioner Office Website, Guidance to the privacy and the electronic communications (EC Directive Regulations 2003),at 4, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/ElectronicCommunicationsGuidancePart1Ver2.pdf Last Visit 10/Apr/05
    4. United Kingdom Information Commissioner Office, DATA PROTECTION ACT FACTSHEET, 2, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/data%20protection%20act%20fact%20v2.pdf
    5. Response to Home Office Consultation on EC Data Protection Directive (95/46/EC), THE CAMPAIGN FOR FREEDOM OF INFORMATION, section of fees, http://www.cfoi.org.uk/eudpresp.html Last Visit 28/Apr/05
    6. Information Commissioner Office, Annual Track Research Findings: Individuals:2004, Conducted by Quaesor on behalf of the Information Commissioner’s Office, Question 5 at 4, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/annualtrackresearchfindingsindividuals.pdf, Last visit 20/Mar/05
    7. European Union, European Court of Justice, Analysis and impact study on the implementation of directive EC 95/46 in Member states,17, available at http://europa.eu.int/comm/justice_home/fsj/privacy/docs/lawreport/consultation/technical-annex_en.pdf , Last Visit 06/Jun/2005
    8. Information Commissioner Office, Your Rights and How to Enforce Them,10, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/1%20Data%20Protection%20Act%20Your%20Rights%20and%20How%20to%20Enforce%20Them.pdf , Last Visit 08/Apr/05
    9. European Data Protection Supervisor, Policy paper, 9, available at http://www.edps.eu.int/publications/policy_papers/policy_paper_advisor_en.pdf , Last visit 01/May/05
    10. European Commission, Communication From The Commission to the European Parliament, The Council, The European Economic and Social Committee and the Committee of The Regions – on unsolicited commercial communications or ‘spam’, at 5, available at http://europa.eu.int/eur-lex/en/com/cnc/2004/com2004_0028en01.pdf , Last visit 01/May/05
    11. Information Commissioner Office, International Transfer of Personal Data – Advice on Compliance with the 8th Data Protection Principle, 2 ,available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/international%20transfers%20of%20personal%20data.pdf, Last visit 04/May/05
    12. Information Commissioner Office, Data Protection Act 1998 – The Eighth Data Protection Principle and Transborder Dataflows, 16, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/transborder%20dataflows.pdf, Last visit 03/May/05
    13. European Data Protection Supervisor, Annual Report 2004, at 9, available at http://www.edps.eu.int/publications/annual_report/2004/Annual_Report_2004_EN.pdf , Last visit 01/May/05
    14. European Data Protection Supervisor, DUTIES OF EUROPEAN DATA PROTECTION SUPERVISOR AND DEPUTY SUPERVISOR, available at http://www.edps.eu.int/01_en_sub_fonctions.htm#Chap_2 Last Visit 04/Apr/2005
    15. Information Commissioner Office, Notification/ Registration , available at http://www.informationcommissioner.gov.uk/eventual.aspx?id=316 , Last Visit 05/Apr/2005
    16. UK Department of Constitutional Affairs, available at http://www.dca.gov.uk/foi/inftrib.htm , Last Visit 06/Apr/2005

    Other Electronic Resources:
    1. United States International Information Programs, available at
    http://usinfo.state.gov/usa/infousa/facts/democrac/57.htm ,
    Last Visit 24/Jun/2005
    2. Organization for Economic Cooperation and Development, available at http://www.oecd.org/document/18/0,2340,en_2649_201185_2068050_1_1_1_1,00.html#what , Last Visit 28/Jun/2005
    3. European Union Website, European Commission, Enlargement, available at http://www.eurunion.org/legislat/agd2000/agd2000.htm , Last Visit 09/Jul/2005
    4. European Union Website, European Commission, The European Commission at Work, available at http://europa.eu.int/comm/atwork/basicfacts/index_en.htm , Last visit 05/Jul/2005
    5. The Council of European Union Website, available at
    http://ue.eu.int/cms3_fo/showPage.ASP?lang=en , Last Visit 09/Jul/2005
    6. Council of European Union Website, available at http://ue.eu.int/cms3_fo/showPage.asp?id=426&lang=en , Last Visit 09/Jul/2005
    7. European Court of Justice Website, available at http://europa.eu.int/eur-lex/lex/LexUriServ/LexUriServ.do?uri=CELEX:31995L0046:EN:HTML , Last Visit 09/Jul/2005
    8. European Union Website, European Commission, Section of Data Protection, available at http://europa.eu.int/comm/justice_home/fsj/privacy/docs/studies/adequat_en.pdf , Last Visit 30/May/2005
    9. European Union Website, European Commission, Section of External Relations, available at http://europa.eu.int/comm/external_relations/eea/, Last Visited 02/Apr/2005
    10. European Union Website, EUR-LEX, available at http://europa.eu.int/cgi-bin/eur-lex/udl.pl?REQUEST=Service-Search&LANGUAGE=en&GUILANGUAGE=en&SERVICE=eurlex&COLLECTION=com&DOCID=503PC0265 , Last visit 01/May/05
    11. Decision of United Kingdom Information Commissioner Office, available at http://www.informationcommissioner.gov.uk/cms/DocumentUploads/LinguaphoneInstituteLtdvTheDataProtectionRegistrarAppealDecision.pdf , Last visit 20/Apr/05
    12. Garante Per La Protezione Dei Dati Personali, Implementation of Directive 95/46/EC in Italy, Section 26 at 30 & Article 9 at 149, available at http://www.garanteprivacy.it/garante/document?ID=311066, Last Visit 25/Apr/2005
    13. European Union, European Commission, Data Protection, http://europa.eu.int/comm/justice_home/fsj/privacy/thridcountries/index_en.htm, Last visit 05/May/05
    14. European Union , http://europa.eu.int/comm/justice_home/fsj/privacy/modelcontracts/index_en.htm, Last visit June 11, 2005
    15. European Data Protection Supervisor, available at http://www.edps.eu.int/01_en_presentation.htm , Last Visit 04/Apr/2005

    Speech:
    1. The speech of Peter J. Hustinx, the European Data Protection Supervisor, on Public Seminar “Data Protection and Citizens’ Security: What Principles for the European Union?” , 3, available at http://www.edps.eu.int/legislation/Seminar_LIBE_EN.pdf Last Visited 04/Apr/2005

    無法下載圖示 全文公開日期 本全文未授權公開 (校內網路)
    全文公開日期 本全文未授權公開 (校外網路)

    QR CODE