检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:张新宝[1,2] Zhang Xinbao
机构地区:[1]中国人民大学法学院 [2]中国人民大学民商事法律科学研究中心
出 处:《中国法学》2024年第6期86-107,共22页China Legal Science
摘 要:生成式人工智能训练语料的个人信息保护应当秉持鼓励和支持创新的基本立场。为确保服务提供者的个人信息利用需求能够得到满足,可以在训练端对《个人信息保护法》作适当宽松解释或例外规定。对于已公开的个人信息,可以通过宽松解释“公开目的”将其纳入可处理的范围。对于未公开的个人信息,仍需要以个人同意作为处理行为的合法性来源,但是可以通过宽松解释目的限制原则、调整“告知—同意”的相关规则,缓解服务提供者面临的困难。技术壁垒的提高加剧了信息主体的劣势地位,需要确保个人信息保护请求权的行使,以维护个人的合法权益,但是其行使不可避免受到技术现实的限制。服务提供者应严格履行包括技术措施在内的个人信息安全保护义务,尽可能降低给个人信息带来的风险。保护机制整体上应以行政监管为主导,如果侵害个人信息权益造成损害,应允许服务提供者以“符合行政监管要求”作为不存在过错的抗辩。The personal information protection of generative AI training language material should uphold the basic stance of encouraging and supporting innovation.To ensure that the personal information utilization needs of service providers can be met,the Personal Information Protection Law can be interpreted or made exceptions at the training end.For personal information that has already been disclosed,it can be included in the scope of processing by loosely interpreting the‘purpose of disclosure'.For undisclosed personal information,it is still necessary to use the individual's consent as the legitimacy source of the processing.However,the difficulties faced by service providers can be alleviated by broadly interpreting the principle of purpose limitation and adjusting the relevant rules of‘notification-consent'.Increased technical barriers has exacerbated the disadvantageous position of information subjects,and it is necessary to ensure the exercise of the right to request personal information protection to protect the legitimate rights and interests of individuals,but its exercise is inevitably limited by technical realities.Service providers should strictly perform their obligations to protect personal information security,including technical measures,to minimize risks to personal information.The protection mechanism as a whole should be dominated by administrative supervision,and if the infringement of personal information rights and interests causes harm,the service provider should be allowed to use‘compliance with administrative supervision requirements'as a defense of non-fault.
关 键 词:生成式人工智能 训练语料 个人信息保护 行政合规抗辩
分 类 号:TP18[自动化与计算机技术—控制理论与控制工程] TP309[自动化与计算机技术—控制科学与工程] D922.16[政治法律—宪法学与行政法学] D922.17[政治法律—法学]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:18.220.50.218