信息资源管理学报 ›› 2023, Vol. 13 ›› Issue (6): 85-98.doi: 10.13365/j.jirm.2023.06.085

• 研究论文 • 上一篇    下一篇

企业数据合规官的治理边界及其规范体系

齐鹏云   

  1. 中国人民公安大学法学院,北京,100038
  • 出版日期:2023-11-26 发布日期:2023-12-28
  • 作者简介:齐鹏云,博士生,研究方向为数据法学与刑事诉讼法学,Email:qpy32nov@126.com。

The Governance Boundary of the Enterprise Data Compliance Officer and Its Regulatory System

Qi Pengyun   

  1. School of Law, People’s Public Securicy University of China, Beijing, 100038
  • Online:2023-11-26 Published:2023-12-28

摘要: 数据合规官在企业数据治理中处于核心地位,国外已有不少国家对此进行了立法与实践方面的探索。本文通过文献分析、比较分析方法,反思当下企业数据治理中的合规困境,提出数据合规官是具有独立地位的企业战略性高级管理人员,其人员选任必须满足专业资格标准,其职能分类涵盖数据认知、数据咨询和数据处理等六大方面。在企业数据治理责任方面,必须明确数据合规官的法律责任边界,以国际经验中的特别注意标准、特定意图(默许)标准以及两种中间责任标准等归责逻辑为参考厘清我国数据合规官的治理边界。以数据合规官为中心的企业数据治理体系能够针对性地解决企业合规体系在数据治理中的困境,至少应当涵盖数据合规官在数据风险管理、数据合规交流、数据处理监督和责任激励四个方面的核心内容,引领企业数据合规治理制度的有效构建。

关键词: 企业数据治理, 数据合规官, 管理过失, 责任激励, 责任边界

Abstract: Data compliance officers play a central role in enterprise data governance, and many countries have explored relative legislations and practice. Through literature analysis and comparative analysis, this paper reflects on the current compliance dilemma in enterprise data governance, and proposes that data compliance officers are strategic senior managers with independent status, whose personnel selection must meet professional qualification standards. Their functions cover six aspects, including data cognition, data consulting and data processing and so on. In terms of enterprise data governance responsibilities, it is necessary to clarify the personal legal responsibility boundary of data compliance officers. Therefore, this paper clarifys the governance boundaries of data compliance officers in China with reference to the international experience such as the special attention standard, the specific intention (tacit consent) standard and the two intermediate responsibility standards. In order to realize the effective construction of enterprise data compliance governance, the enterprise data governance system centered on data compliance officers should cover the core content of data compliance officers in at least four aspects: data risk management, data compliance communication, data processing supervision and responsibility incentives.

Key words: Enterprise data governance, Data compliance officer, Management negligence, Responsibility incentives, Responsibility boundaries

中图分类号: