在安全和发展的平衡中构建《网络安全法》数据跨境安全评估的总体框架 (Building A Framework for Security Review of the Cross-border Data Flow)
40 Pages Posted: 18 Jun 2019
Date Written: June 10, 2019
Abstract
Chinese Abstract: 数据本地化存储极富争议,反对者认为其构成贸易壁垒,甚至还将破坏互联网全球互联互通的特性。支持者指出世界范围内有不少国家都做出数据本地化存储的规定,其中不乏发达国家。为弥合分歧,本文从中外数据本地化存储实践中,抽象出描述数据本地化存储的严苛度模型,并以目的和手段之间的适当性和必要性为指针,构建出一套“数据本地化存储合理界限理论”。文章从该理论出发,检视《网络安全法》相关规定并给出基本评价。最后,文章以“数据本地化存储合理界限理论”为主体,提出数据跨境安全评估办法的总体框架。
English Abstract: Lot of controversies surround Data localization. The opponents regard it as trade barriers and will break the interconnectivity of the Internet. Whereas its supporters point out that there are many countries that have adopted such measures, quite a few of which are advanced countries. To bridge the gaps, this article takes stock of current practices of data localization around the world, builds up a model of strictness for data localization measure. Then guided by the requirements of appropriateness and necessity between purposes and means, this article construct a theory on the reasonable limits for data localization. Based on this theory, this article offers comments on the Article 37 of the Cybersecurity Law of China. In the final part, departing from the theory on the reasonable limits for data localization, this article puts forward a general framework for security review of cross-border data flow which is required by the Cybersecurity Law.
Note: Downloadable document is in Chinese.
Keywords: 数据本地化存储、适当性、必要性、数据跨境安全评估
Suggested Citation: Suggested Citation