ISSN 1008-2204
CN 11-3979/C

生成式人工智能个人信息利用的规范体系

A Normative Framework for Personal Information Utilization in Generative Artificial Intelligence

  • 摘要: 生成式人工智能的发展离不开个人信息利用,应当秉持支持技术创新的基本立场。面对生成式人工智能对既有个人信息保护规范中知情同意、最小必要、透明公正及信息质量要求带来的严峻挑战,应当通过“规范调适”消解个人信息合规利用的制度阻滞,通过“规范保障”化解个人信息利用风险,构建协同治理体系。在规范调适层面,推动信息匿名化标准从绝对走向相对,厘定公开个人信息合理利用边界,实行知情同意分层分类处理,为个人信息价值释放创设制度空间。在规范保障层面,针对个人信息利用风险,完善个人信息有效获取、更正响应与合理清除等权益行使机制;明晰归责原则与损害赔偿认定规则;在权益行使与救济之外,可建立基于模型卡片的透明度披露机制,强化系统风险监管,实现个人信息预防性保护。

     

    Abstract: The development of Generative Artificial Intelligence (Generative AI) depends fundamentally on the utilization of personal information, requiring a normative stance that actively supports technological innovation. However, Generative AI poses severe challenges to existing personal information protection norms, specifically regarding informed consent, data minimization, transparency, and information quality. To address these challenges, a collaborative governance system is constructed by employing normative adaptation to remove barriers to compliant data use, and normative safeguards to mitigate utilization risks. In terms of normative adaptation, the framework advocates shifting from absolute to relative standards for anonymization, clarifying the boundaries for the reasonable use of publicly available personal information, and implementing a tiered and classified approach to informed consent. In terms of normative safeguards, mechanisms for exercising rights are refined, including effective access to data, responsive rectification, and reasonable erasure. Furthermore, principles for liability attribution and rules for assessing damages are clarified. Beyond rights exercise and remedies, establishing a transparency disclosure mechanism based on Model Cards and strengthening system risk regulation are proposed to achieve the preventive protection of personal information.

     

/

返回文章
返回