东北大学学报(社会科学版) ›› 2025, Vol. 27 ›› Issue (6): 90-99.DOI: 10.15936/j.cnki.1008-3758.2025.06.010

• 法学研究 • 上一篇    下一篇

个人金融数据共享中安全保障义务的理论廓清与法律实现

阮少凯1,2   

  1. 1.浙江大学 光华法学院,浙江 杭州 310008
    2.华东政法大学 经济法学院,上海 201620
  • 收稿日期:2024-06-10 出版日期:2025-11-25 发布日期:2025-12-03
  • 作者简介:阮少凯,浙江大学博士研究生,华东政法大学讲师。
  • 基金资助:
    国家社会科学基金项目(22BFX089)

Theoretical Clarification and Legal Realization of Security Obligations in Personal Financial Data Sharing

Shaokai RUAN1,2   

  1. 1.Guanghua School of Law,Zhejiang University,Hangzhou 310008,China
    2.School of Economic Law,East China Uiniversity of Political Science and Law,Shanghai 201620,China
  • Received:2024-06-10 Online:2025-11-25 Published:2025-12-03

摘要:

面对个人金融数据共享困境,理论层面引入的数据信托理论不当加重数据控制者义务,需要明确数据控制者责任承担的法理基础为安全保障义务。在制度层面,事前准入资格审查标准的缺失、事中数据共享与个人信息保护对立和合同约束机制失灵风险并存,以及事后民事责任配置因“共同处理”与“共同侵权”混淆而产生的连带性趋势,实质上将安全保障义务从“危险源监控型”扭曲为“法益保护型”。为促进个人金融数据共享的法律实现,有必要通过明确事前准入资格审查行业标准、事中在数据控制者履行“最大努力义务”的基础上采取“公私协同”的约束机制、事后根据数据共享模式和主观状态区分责任配置,实现“危险源监控型”安全保障义务的回归;通过保险等机制替代“法益保护型”安全保障义务发挥对数据主体倾斜保护的法律效果。

关键词: 数据信托, 个人信息保护, 数字平台, 金融数据, 注意义务

Abstract:

Faced with the dilemma of personal financial data sharing, the data trust theory introduced at the theoretical level improperly aggravates the obligations of data controllers, and it is necessary to clarify that the legal basis of data controllers’ responsibility is the obligation of security. At the institutional level, the absence of pre-entry qualification review standards, the conflict between data sharing and personal information protection during operations along with the risk of ineffective contractual constraints, and the trend toward joint liability in the allocation of post-event civil liability due to the conflation of “joint handling” and “joint infringement” have essentially distorted the the security obligation from “monitoring of risk sources” to “protection of legal interests.” In order to promote the legal realization of personal financial data sharing, it is necessary to realize the return of security obligation of “monitoring of risk sources” by clarifying the industrial pre-entry qualification review standards, implementing the restraint mechanism of “public-private cooperation” during operations and distinguishing the responsibility allocation according to the personal financial data sharing mode and subjective state afterwards. Meanwhile, mechanisms such as insurance can replace the “protection of legal interests” approach to security obligations, thereby achieving the legal effect of favorably protecting data subjects.

Key words: data trust, personal information protection, digital platform, financial data, duty of care

中图分类号: