
作者:Patrick Gunning,Ian Hargreaves,Rob Bolgar-Smith以及Urszula McCormack, 金杜律师事务所
Data security breaches have been on the rise for many years now, with governments and regulators responding in many ways. One element of the response is to require organisations who experience a data security breach to notify relevant regulators and, most importantly, the people whose data has been compromised.
多年以来,数据安全泄密问题一直呈上升趋势,政府和监管部门也采取了多种应对方式。其中一种应对方式为要求遭受数据安全泄密的组织机构向相关监管部门通报,最重要的是,通知数据遭到破坏的人士。
In a previous edition of Red Tape, we canvassed a broad range of legal issues associated with cyber security incidents. SEC Chair Mary-Jo White has recently described cybersecurity as the biggest risk facing the financial system. China has also recognised the importance of cybersecurity to national security, and is in the process of reforming its cybersecurity laws, as reported last year. In late May 2016, Hong Kong’s banking regulator launched a “Cybersecurity Fortification Initiative”, following a blight of recent regional and local scandals involving banks.
在此前的一期Red Tape中,我们详细讨论了与网络安全事件有关的一系列法律问题。美国证券交易委员会(SEC)主席玛丽-乔怀特近来把网络安全称作金融系统面临的最大隐患。中国也承认了网络安全对于国家安全的重要性,据去年的报道,中国正在改革自己的网络安全法。2016年5月末,鉴于近期发生多起涉及银行的地区和本地丑闻,香港银行监管机构推出了“网络防卫计划”。
In this article, we look at recent developments in the EU and Australia in relation to one of those legal issues, namely data breach notification laws.
本文考查了欧盟以及澳大利亚在其中一项法律问题上的新进展,即数据泄密通知法。
Mandatory data security breach reporting laws have been in place in the United States of America for many years now. Canada, Korea and, more recently, South Africa also have enacted such laws. In the EU, the requirement currently applies only to businesses in certain sectors (electronic communications providers). Breach reporting in Hong Kong is not strictly required under law, but is expected under guidelines issued by both the Privacy Commissioner for Personal Data and by financial regulators.
美国在许多年前就已制定强制性数据安全泄密通报法律。加拿大、韩国以及近期的南非也制定了此类法律。在欧盟,当前只对某些部门的企业有此要求(电讯公司)。泄密通报在香港并不是严格的法律要求,但个人资料私隐专员公署和金融监管机构发布的准则对此作出了规定。
European Union – 72 hour notification/欧盟 – 72小时通知
One of the most significant recent developments has been the adoption of the General Data Protection Regulation (GDPR) by the European Union. On 4 May 2016, the European Parliament and the European Council published the GDPR in the Official Journal of the European Union. This has been the final step of a legislative process spanning over five years. The GDPR will enter into force on 25 May 2018.
近期最显著的一项进展为欧盟采纳了《一般数据保护条例》(GDPR)。2016年5月4日,欧洲议会和欧洲理事会在欧盟政府公报上发布了《一般数据保护条例》。这是历时五年的立法程序的最后一步。该条例将于2018年5月25日生效。
The GDPR contains an obligation to notify:
GDPR规定了以下通知义务:
the relevant data protection supervisory authority of a personal data breach “without undue delay and, where feasible, not later than 72 hours after having become aware of it” (Article 33); and
向相关数据保护监管机构通知个人数据泄露,“不得无故拖延,并且在可行的情况下,在知悉泄密之后72小时之内作出”(第33条);以及
the data subject without undue delay “when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons” (Article 34).
“当个人数据泄露可能对自然人的权利和自由造成高风险时”,立即通知数据当事人(第34条)。如果机构认为不存在这样的高风险,但监管机构不同意,则后者有权要求该机构通知数据当事人。
If an organisation considers that there is not such a high risk, the supervisory authority will have the power to require the organisation to notify data subjects if it disagrees. If an organisation fails to notify, it may be liable to an administrative fine of up to €10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)) (for certain other breaches of the GDPR, the fine can be up €20 million or 4% of total worldwide turnover). This is in addition to any liability that the organisation may have to affected individuals.
未履行通知义务的机构可能遭受最高1,000万欧元或其上一财政年全球年度营业收入的2%(两者取数额较高的)的行政罚款(第83条第4款)(对于其他违反GDPR的某些行为,罚款可达2,000万欧元或全球营收的4%)。上述责任是该机构对受影响的个人可能负有的任何责任的附加责任。
Based on our experience, we anticipate that many organisations will take the view that it is not feasible to report sensibly to the regulator within 72 hours of becoming aware of a data breach. In many instances, only the basic information about the extent of the breach and the manner in which it occurred will be known within this period.
根据我们的经验,我们预计许多机构会认为在获知数据泄露72小时之内向监管机构作出合理通报不可行。在许多案例中,在该等时限内只能获知数据泄露的程度以及泄露方式的基本信息。
If the breach is a result of a sophisticated hacker, the hacker will likely have been exploring the organisation’s systems for weeks or months before the organisation became aware of the breach (or part of it). So while obvious causes for the breach will have been identified and contained within the initial 72 hour period, response teams will frequently spend more time assessing whether the hacker has identified other vulnerabilities. This may lead to staggered notifications to the relevant regulator, culminating in a later notification to data subjects once the degree of risk has been more clearly assessed.
如果数据泄密是由老练的黑客所为,那么该黑客可能已经在机构获悉泄密之前(或部分泄密),对该机构的系统探究了数周或数月。所以,尽管在最初的72小时之内可以确定明显的泄密原因,应对小组通常需要更多的时间来评估该黑客是否发现了系统的其他漏洞。这可能导致向相关监管机构的通知滞后,一旦对风险程度作出了更清晰的评估,最终向数据当事人的通知也因此延后。
We expect that even vigilant regulators will be wary that individuals may experience counter-productive “notification fatigue” if lower risk incidents were routinely notified.
我们认为,哪怕是审慎的监管机构也要警惕,如果低风险事件被频繁通知,个人可能会产生逆效性的“通知疲劳”。
Australia/澳大利亚
In late 2015, the Australian Government released a draft of the Privacy Amendment (Notification of Serious Data Breaches) Bill for public consultation. This was against the background of public statements from both of Australia’s main political parties supporting the introduction of data breach notification laws. More than 40 submissions were received (the text of the Bill and the submissions are published here). In April 2016, the government indicated that they intended to introduce a version of the Bill into Parliament. However, they did not do so before Parliament was dissolved for an election (which is underway at the time of writing).
2015年末,澳大利亚政府公布了隐私修正案(严重数据泄密通知)法案草案向公众征询意见。这一举措映衬了澳大利亚支持引入数据泄密通知法的两大主要政党所作的公开声明。政府收到了40多份公众意见书(法案和意见书的原文见此)。2016年4月,政府表示他们计划向国会提交一份法案。不过,在国会因选举解散之前(法案草拟时解散正在进行),尚未提交。
Unlike the EU’s expectation of a 72 hour period in which to notify, the test proposed by the exposure draft of the Australian Bill was to notify “as soon as practicable” after becoming aware that there are reasonable grounds to believe that there has been a serious data breach. Further, the concept of “as soon as practicable” was clarified so as to allow the organisation to carry out a reasonable assessment of whether there are reasonable grounds to believe that a serious data breach has occurred, provided that assessment is carried out within 30 days after becoming aware.
与欧盟规定的72小时通知时限不同,澳大利亚法案的征求意见稿提出的通知时限为在获悉有合理理由相信存在严重数据泄露之后“在可行范围内尽快”。另外,“在可行范围内尽快”的概念被进一步明确,以便机构就是否有合理理由相信严重数据泄露确已发生进行合理的评估,前提是评估在获悉泄露后30日内作出。
The maximum penalty associated with a failure to notify in Australia is A$1.8 million, which is considerably lower than those in effect under the GDPR.
在澳大利亚未履行通知义务的最高罚款为180万澳元,比GDPR的规定要低得多。
Due to the Australian election, progress of this bill is now delayed, although both major parties are on the record in supporting legislation of this kind. Accordingly, organisations operating in Australia should be prepared for such laws to be implemented during the next term of government (Australia has a three year election cycle, so the next election will likely be in 2019).
目前,该法案的进程因澳大利亚大选而被推迟,但两大政党都声称支持该等立法。为此,在澳大利亚运营的机构应做好该等法律在下届政府执政期间出台实施的准备(澳大利亚大选每三年举行一次,故下届大选会在2019年)。
Will increased notification result in class action litigation? /增加通知义务会导致集体索赔纠纷吗?
Large scale data breach incidents which have been notified under US law have often led to class action litigation being commenced. However, as a percentage of the total number of reported breaches, the number of class actions is quite low. Various studies have found that approximately 5% of publicly reported breaches resulted in class action litigation.
依据美国法律,已作出通知的大规模数据泄露事件通常会引发集体索赔纠纷。不过,就其在已通知泄漏事件总数中的占比来看,集体诉讼的数量相当少。各项研究表明,只有5%左右的公开通报泄漏事件引发了集体索赔纠纷。
While some prominent class actions have resulted in substantial damages awards or settlement sums, businesses have had more success defending class action claims in recent years. This can be attributed to the 2013 decision by the US Supreme Court in the Clapper case which raised the barrier by forcing the lead plaintiff to prove that there was a substantial risk that they would suffer an injury or damage as a result of the breach.
尽管一些备受瞩目的集体诉讼导致了数额巨大的损害赔偿或和解金额,企业在近年来的集体诉讼索赔中更多地取得了胜诉。这可归因于2013年美国最高法院对Clapper案的裁决,该案提高了举证门槛,法院要求首席原告证明他们存在遭受数据泄露造成的损害或损失的实质风险。
The courts have held that mere loss of data, without evidence that it has been viewed or misused, is not an injury sufficient to confer standing. However, not all cases can be defended on this basis, because there are cases in which damage has actually transpired or where a threatened injury is “certainly impending”.
法院认为,仅仅是数据丢失而没有证据证明数据被查看或滥用,则构不成适格的损害。不过,并非所有案例都可据此提出抗辩,因为在有些案例中,损害确已发生或者先兆性损害“必然即将发生”。




