Journal of Northeastern University(Social Science) ›› 2025, Vol. 27 ›› Issue (6): 90-99.DOI: 10.15936/j.cnki.1008-3758.2025.06.010

Previous Articles     Next Articles

Theoretical Clarification and Legal Realization of Security Obligations in Personal Financial Data Sharing

Shaokai RUAN1,2   

  1. 1.Guanghua School of Law,Zhejiang University,Hangzhou 310008,China
    2.School of Economic Law,East China Uiniversity of Political Science and Law,Shanghai 201620,China
  • Received:2024-06-10 Online:2025-11-25 Published:2025-12-03

Abstract:

Faced with the dilemma of personal financial data sharing, the data trust theory introduced at the theoretical level improperly aggravates the obligations of data controllers, and it is necessary to clarify that the legal basis of data controllers’ responsibility is the obligation of security. At the institutional level, the absence of pre-entry qualification review standards, the conflict between data sharing and personal information protection during operations along with the risk of ineffective contractual constraints, and the trend toward joint liability in the allocation of post-event civil liability due to the conflation of “joint handling” and “joint infringement” have essentially distorted the the security obligation from “monitoring of risk sources” to “protection of legal interests.” In order to promote the legal realization of personal financial data sharing, it is necessary to realize the return of security obligation of “monitoring of risk sources” by clarifying the industrial pre-entry qualification review standards, implementing the restraint mechanism of “public-private cooperation” during operations and distinguishing the responsibility allocation according to the personal financial data sharing mode and subjective state afterwards. Meanwhile, mechanisms such as insurance can replace the “protection of legal interests” approach to security obligations, thereby achieving the legal effect of favorably protecting data subjects.

Key words: data trust, personal information protection, digital platform, financial data, duty of care

CLC Number: