
\n \n \n
在過去的十年中,我們觀察到世界各地越來越傾向於保護網際網路,並樹立新的屏障以阻止國際資料流動(尤其是個人資料)。在某些情況下,這會導致數位產品和服務使用者的選擇減少和效能降低。在其他情況下,它會限制對資訊的自由存取,並且——矛盾的是——在某些情況下,這實際上會降低資料安全性和隱私性,完全違背了資料保護法規的基本原理。這些令人擔憂的事態發展的動機是多種多樣的,從對於第三國/地區的隱私權保護缺乏信任、主張國家安全,到尋求經濟自主。
過去幾年中,在歐盟,即使是最注重隱私權的公司(如 Cloudflare)也面臨著一些強硬派資料保護機構、隱私權積極分子和其他人持續不斷的猜測和擔憂,他們懷疑美國雲端服務提供者是否真正能夠以遵循 GDPR 的方式處理資料。通常,這些擔憂純粹是法律層面的,並未考慮到與特定資料傳輸相關聯的實際風險,以及在 Cloudflare 的案例中,我們的服務為數百萬個歐洲網際網路使用者的安全性和隱私權做出的重要貢獻。實際上,歐洲資料保護委員會 (EDPB) 的官方指導已確認歐盟個人資料仍然可以在美國處理,但情況已變得相當複雜,這是因為歐洲法院暫停了[隱私護盾]框架,於 2020 年做出 Schrems II 判決:資料控制者必須使用合法的傳輸機制,例如歐盟制式化契約條款以及大量的其他法律、技術和組織防護措施。
但是,最終將由法定資料保護機構決定這些措施是否足以解釋個別案例。由於這些案例通常非常複雜,由於每個案例各不相同,並且由於僅在歐洲就有 45 個資料保護機構,因此,這種方法根本無法擴展。此外,當涉及第三國/地區傳輸時,DPA——有時甚至在同一個歐盟國家(德國)內——對法律的解釋也會存在異議。當涉及到實際的法院裁決時,我們的經驗是,法院在資料保護方面比 DPA 更注重實效,考量更加周全。但是,在資料保護案件最終提交到法院之前,需要花費很長時間和大量資源。這對於那些無力承擔漫長的法律訴訟的小型企業來說,尤其成問題。因此,DPA 的巨額罰款作為理論上的威脅,可能會造成足夠的威懾力,使他們完全停止使用涉及第三國/地區資料傳輸的服務,即使這些服務為他們所處理的個人資料提供了更高的安全性和隱私性,並提高了生產力。這顯然不符合歐洲經濟的利益,並且很可能也不是決策者在 2016 年採用 GDPR 時的意圖。
\n儘管最近的事態發展並不能解決上述所有挑戰,但去年 12 月,經過歷時多年的複雜談判,國際決策者採取了兩個重要步驟,以恢復與個人資料跨境流動相關的法律確定性和信任。
2022 年 12 月 13 日,歐盟委員會發佈了令人期待已久的初步評估,即歐盟將認為依據未來的歐盟-美國資料隱私權框架 (DPF) 從歐盟傳輸到美國的個人資料在美國享有足夠的保護。最近,就在該評估發佈前,美國總統拜登簽署了 14086 號行政命令,全面解決了歐洲法院(ECJ)在 2020 年 Schrems II 裁定中表達的擔憂。值得注意的是,美國政府將對美國當局針對非美國公民使用批量監視方法施加額外限制,並在美國建立一個獨立的賠償機制,允許歐盟資料主體行使資料保護權利。儘管委員會的初步評估只是歐盟審批流程的開始,該流程預計需要約 4-6 個月,但專家們非常樂觀地認為最終將會予以採用。
就在一天之後,美國與其他 37 個經合組織 (OECD) 國家/地區和歐盟採用了首個同類協議,透過闡明在政府以國家安全和執法為由存取私人機構所持有的個人資料時,用於保護隱私和其他人權和自由的共同保障原則,以加強對法治民主制度之間跨境資料流動的信任。如果法律框架要求跨境資料流動受到保護,例如歐盟的 GDPR,參與者同意「考慮到目的地國家/地區有效實施這些原則,作為促進跨境資料流動在這些規則中應用的積極貢獻。」(同樣值得注意的是,與 Cloudflare 幫助構建更好的網際網路的使命一致,OECD 宣告回顧了成員國對「全球、開放、可存取、互連、可通、可靠且安全的網際網路」的共同承諾)。
\n歐盟-美國的 DPF 和 OECD 宣言互為補充,兩者都標誌著採取了重要的步驟,來恢復對具有民主和法治等共同價值觀的國家/地區之間跨境資料流動的信任,從而保護隱私權以及其他人權和自由。但是,這兩種方法都有自己的局限性:DPF 僅限於從歐盟到美國的個人資料傳輸。此外,不能排除在幾年後 ECJ 再次將其作廢,因為隱私權積極分子已經宣佈將再次對其提出法律質疑。另一方面,OECD 宣言在範圍上是全球性的,但僅限於政府的一般原則,這在實踐中可能會有截然不同的解釋。
這就是為什麼,除了這些努力之外,我們還需要一個穩定的多邊框架,其中包含特定的隱私權保護要求,不能單方面作廢。單一的全球認證應該足以讓參與的公司在全球參與的國家/地區之間安全地傳輸個人資料。新興的全球跨境隱私規則 (CBPR) 認證已得到來自北美和亞洲的幾個政府的支持,看起來在這方面大有希望。
歐洲決策者最終將需要決定是否要繼續走目前的道路,這有可能會使歐洲成為一座孤立的資料島。或者,歐盟可以修改隱私法規,以防止歐洲許多國家和地區的資料保護機構以與現實脫節的方式對其進行解釋。它還可以基於共同價值觀和相互信任,使其與全球性跨境資料流動框架互通。
Cloudflare 將繼續積極與全球各地的決策者交流,提高人們對我們產業所面臨的實際挑戰的認識,並為更加隱私和安全的開放互連的網際網路開發永續的政策解決方案。
明天的資料隱私權保護日為我們所有人提供了一個獨特的機會,以慶祝迄今為止在保護使用者線上隱私方面取得的重大進展。與此同時,我們應該利用這一天來反思如何改編或執行法規,以便更有意義地保護隱私權,特別是透過優先使用安全性和隱私增強技術,而不是採用成本高昂的方法,不但損害經濟,也享受不到實在的隱私權益。
"],"published_at":[0,"2023-01-27T14:00:00.000+00:00"],"updated_at":[0,"2024-10-09T23:22:41.854Z"],"feature_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/29sGskrisDlglLlJfGWLIW/de71f587de1451bf223a5f08de2ce1df/towards-a-global-framework-for-cross-border-data-flows-and-privacy-protection.png"],"tags":[1,[[0,{"id":[0,"5IXtiuWfVLTauUbRVKANYX"],"name":[0,"Data Privacy Day"],"slug":[0,"data-privacy-day"]}],[0,{"id":[0,"3BWeMuiOShelE7QM48sW9j"],"name":[0,"Privacy"],"slug":[0,"privacy"]}]]],"relatedTags":[0],"authors":[1,[[0,{"name":[0,"Sebastian Hufnagel"],"slug":[0,"sebastian-hufnagel"],"bio":[0,null],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5Gnw21z58iGs9iXZZfPg2R/3aca1f7c1636c619607710fcd802d77a/sebastian-hufnagel.jpeg"],"location":[0,"Berlin, Germany"],"website":[0,null],"twitter":[0,"@horatio2000"],"facebook":[0,null]}]]],"meta_description":[0,"In our third and final blog post leading up to Data Privacy Day, we drill down into the challenges for cross-border data flows, in particular personal data transfers from the EU to the US. While recent international agreements promise some relief, we advocate for a comprehensive global framework for cross-border personal data transfers, which will be critical for an open, more secure and more private Internet. "],"primary_author":[0,{}],"localeList":[0,{"name":[0,"Towards a global framework for cross-border data flows and privacy protection Config"],"enUS":[0,"English for Locale"],"zhCN":[0,"Translated for Locale"],"zhHansCN":[0,"No Page for Locale"],"zhTW":[0,"Translated for Locale"],"frFR":[0,"Translated for Locale"],"deDE":[0,"Translated for Locale"],"itIT":[0,"No Page for Locale"],"jaJP":[0,"No Page for Locale"],"koKR":[0,"No Page for Locale"],"ptBR":[0,"Translated for Locale"],"esLA":[0,"No Page for Locale"],"esES":[0,"No Page for Locale"],"enAU":[0,"No Page for Locale"],"enCA":[0,"No Page for Locale"],"enIN":[0,"No Page for Locale"],"enGB":[0,"No Page for Locale"],"idID":[0,"No Page for Locale"],"ruRU":[0,"No Page for Locale"],"svSE":[0,"No Page for Locale"],"viVN":[0,"No Page for Locale"],"plPL":[0,"No Page for Locale"],"arAR":[0,"No Page for Locale"],"nlNL":[0,"No Page for Locale"],"thTH":[0,"No Page for Locale"],"trTR":[0,"No Page for Locale"],"heIL":[0,"No Page for Locale"],"lvLV":[0,"No Page for Locale"],"etEE":[0,"No Page for Locale"],"ltLT":[0,"No Page for Locale"]}],"url":[0,"https://blog.cloudflare.com/towards-a-global-framework-for-cross-border-data-flows-and-privacy-protection"],"metadata":[0,{"title":[0,"為跨境資料流動和隱私權保護打造全球性框架"],"description":[0,"In our third and final blog post leading up to Data Privacy Day, we drill down into the challenges for cross-border data flows, in particular personal data transfers from the EU to the US. While recent international agreements promise some relief, we advocate for a comprehensive global framework for cross-border personal data transfers, which will be critical for an open, more secure and more private Internet. "],"imgPreview":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6z1JUhF18IjIGsuCHQyZkR/978bd1a37b38462cc8156fb13c767bba/towards-a-global-framework-for-cross-border-data-flows-and-privacy-protection-kJAWx2.png"]}]}],"locale":[0,"zh-tw"],"translations":[0,{"posts.by":[0,"作者:"],"footer.gdpr":[0,"GDPR"],"lang_blurb1":[0,"本貼文還提供以下語言版本:{lang1}。"],"lang_blurb2":[0,"本貼文還提供以下語言版本:{lang1} 和{lang2}。"],"lang_blurb3":[0,"本貼文還提供以下語言版本:{lang1},{lang2} 和{lang3}。"],"footer.press":[0,"新聞"],"header.title":[0,"Cloudflare 部落格"],"search.clear":[0,"清除"],"search.filter":[0,"篩選"],"search.source":[0,"來源"],"footer.careers":[0,"人才招募"],"footer.company":[0,"公司"],"footer.support":[0,"支援"],"footer.the_net":[0,"theNet"],"search.filters":[0,"篩選器"],"footer.our_team":[0,"我們的團隊"],"footer.webinars":[0,"網路研討會"],"page.more_posts":[0,"更多貼文"],"posts.time_read":[0,"閱讀時間:{time} 分鐘"],"search.language":[0,"語言"],"footer.community":[0,"社群"],"footer.resources":[0,"資源"],"footer.solutions":[0,"解決方案"],"footer.trademark":[0,"商標"],"header.subscribe":[0,"訂閱"],"footer.compliance":[0,"合規性"],"footer.free_plans":[0,"免費方案"],"footer.impact_ESG":[0,"影響力/ESG"],"posts.follow_on_X":[0,"在 X 上進行關注"],"footer.help_center":[0,"幫助中心"],"footer.network_map":[0,"網路分佈圖"],"header.please_wait":[0,"請稍候"],"page.related_posts":[0,"相關貼文"],"search.result_stat":[0,"針對 {search_keyword} 的第 {search_range} 個搜尋結果(共 {search_total} 個結果)"],"footer.case_studies":[0,"案例研究"],"footer.connect_2024":[0,"Connect 2024"],"footer.terms_of_use":[0,"服務條款"],"footer.white_papers":[0,"白皮書"],"footer.cloudflare_tv":[0,"Cloudflare TV"],"footer.community_hub":[0,"社群中心"],"footer.compare_plans":[0,"比較各項方案"],"footer.contact_sales":[0,"連絡銷售團隊"],"header.contact_sales":[0,"連絡銷售團隊"],"header.email_address":[0,"電子郵件地址"],"page.error.not_found":[0,"找不到頁面"],"footer.developer_docs":[0,"開發人員文件"],"footer.privacy_policy":[0,"隱私權原則"],"footer.request_a_demo":[0,"請求示範"],"page.continue_reading":[0,"繼續閱讀"],"footer.analysts_report":[0,"分析報告"],"footer.for_enterprises":[0,"企業適用"],"footer.getting_started":[0,"開始使用"],"footer.learning_center":[0,"學習中心"],"footer.project_galileo":[0,"Galileo 專案"],"pagination.newer_posts":[0,"較新貼文"],"pagination.older_posts":[0,"較舊貼文"],"posts.social_buttons.x":[0,"在 X 上進行討論"],"search.icon_aria_label":[0,"搜尋"],"search.source_location":[0,"來源/地點"],"footer.about_cloudflare":[0,"關於 Cloudflare"],"footer.athenian_project":[0,"Athenian 專案"],"footer.become_a_partner":[0,"成為合作夥伴"],"footer.cloudflare_radar":[0,"Cloudflare Radar"],"footer.network_services":[0,"網路服務"],"footer.trust_and_safety":[0,"信任和安全"],"header.get_started_free":[0,"免費開始使用"],"page.search.placeholder":[0,"搜尋 Cloudflare"],"footer.cloudflare_status":[0,"Cloudflare 狀態"],"footer.cookie_preference":[0,"Cookie 喜好設定"],"header.valid_email_error":[0,"必須是有效電子郵件。"],"search.result_stat_empty":[0,"第 {search_range} 筆搜尋結果(共 {search_total} 筆)"],"footer.connectivity_cloud":[0,"全球連通雲"],"footer.developer_services":[0,"開發人員服務"],"footer.investor_relations":[0,"投資人關係"],"page.not_found.error_code":[0,"錯誤代碼:404"],"search.autocomplete_title":[0,"插入查詢。按下 Enter 鍵即可傳送"],"footer.logos_and_press_kit":[0,"標誌與新聞資料包"],"footer.application_services":[0,"應用程式服務"],"footer.get_a_recommendation":[0,"取得建議"],"posts.social_buttons.reddit":[0,"在 Reddit 上進行討論"],"footer.sse_and_sase_services":[0,"SSE 和 SASE 服務"],"page.not_found.outdated_link":[0,"您可能使用了過時的連結,或者可能輸入了錯誤的位址。"],"footer.report_security_issues":[0,"報告網路安全問題"],"page.error.error_message_page":[0,"抱歉,我們找不到您想要的頁面。"],"header.subscribe_notifications":[0,"訂閱以接收新文章的通知:"],"footer.cloudflare_for_campaigns":[0,"Cloudflare for Campaigns"],"header.subscription_confimation":[0,"訂閱已確認。感謝訂閱!"],"posts.social_buttons.hackernews":[0,"在 Hacker News 上進行討論"],"footer.diversity_equity_inclusion":[0,"多樣性、公平性和包容性"],"footer.critical_infrastructure_defense_project":[0,"關鍵基礎架構防禦專案"]}]}" ssr="" client="load" opts="{"name":"PostCard","value":true}" await-children="">2023-01-26
我們將繼續擴充並改善 Data Localization Suite,以協助支援必須遵守資料當地化要求的客戶...
2023-01-25
距離資料隱私保護日只有幾天的時間了,我們認為務必要關注安全措施和隱私增強技術如何以種種方式幫助確保個人資料私密性,以及為什麼安全措施對保護隱私更加至關重要...