导航
GDPR > Recital 26
下载PDF

Recital 26

Recital 26

(26) 個人資料保護原則應適用於有關識別或可得識別當事人之任何 資訊。已假名化之個人資料,且可透過使用額外資訊而識別出當事人 身分者,應被認為屬於可得識別之當事人的資訊。為決定當事人是否 可被識別,應考慮到所有可合理使用之方法,例如由控管者自己或透 過他人指認以直接或間接地識別該當事人。為確認何為可合理使用作 為識別當事人之方法,應考慮所有客觀因素,諸如:識別所需之成本 與時間,並考慮到資料處理當時現有之技術及科技發展。因此,資料 保護原則不適用於匿名資訊,亦即並非已識別或可識別當事人之資訊, 或以使資料主體不可或不再可識別之方式而成為匿名之個人資料。因 此,本規則無涉於此類匿名資訊之處理,包括為統計或研究目的所為 之者。

(26) The principles of data protection should apply to any information concerning an identified or identifiable natural person.

Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person.

To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly.

To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.

The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.

This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.

專家評論 相关文章 指南和案例法 发表评论
專家評論

(EN) Anonymisation should not be confused with depersonalization in the meaning adopted in the Russian Federation. In accordance with Article 3 of the Federal Personal Data Act No. 152-FZ of 27 July 2006 (in the wording of 31 January 2017) «depersonalization of personal data» means actions as a result of which it becomes impossible to determine the belonging of personal data to a specific subject of personal data without using an additional information. Under the GDPR the term «anonymisation» means…


访问全文

(EN) Author
Siarhei Varankevich
(EN) Siarhei Varankevich CIPP/E, CIPM, CIPT, MBA, FIP
FIP_IAPP
(EN) Co-Founder & CEO of Data Privacy Office LLC. Data Protection Trainer and Principal Consultant
相关文章 指南和案例法 发表评论
[js-disqus]