档案法规标准2026年第40卷第1期《档案学研究》

档案个人信息全生命周期风险治理研究

Study on Risk Governance of Archival Personal Information Throughout Its Lifecycle

李雪健

LI Xuejian

华东理工大学法学院 上海 210000

出版日期2026-02-28卷期第40卷 第1期页码104-113DOI10.16065/j.cnki.issn1002-1620.2026.01.010

摘要

规制档案个人信息处理行为,治理档案个人信息风险,对档案事业的高质量发展具有重要意义。结合信息生命周期理论,档案个人信息风险的识别需基于档案工作中的个人信息处理行为逐步展开。根据《中华人民共和国个人信息保护法》所确立的规则,档案个人信息风险贯穿于档案工作的各个阶段。档案个人信息风险的成因具有复杂性,在法律层面表现为条款效力不敷、核心概念混乱、保护规则缺失,在组织层面表现为风险监管主体不明、风险审查阻断机制匮乏、工作人员保护意识淡薄,在技术层面表现为内外部技术保护孱弱、匿名化技术标准混乱、信息用途控制困难。为此,有必要根据档案个人信息风险架构和塑造规制体系,形成法律供给充足、组织供给充分、技术供给完善的治理框架。

关键词:档案个人信息风险治理全生命周期档案法

Abstract

Regulating the processing of personal information within archival management and mitigating the attendant risks are crucial for the high-quality development of the archival sector. Combined with the theory of information lifecycle, the identification of risks should align with the sequential stages of personal information processing in archival practices. Under Personal Information Protection Law of the People's Republic of China, the risks associated with personal information in archives run through all stages of archival work. The causes of personal information risks in archives are complex, manifesting in the following aspects: ineffective clauses, confusion of core concepts and absence of protection rules at the legal level; unknown risk supervision subjects, lack of a risk review blocking mechanism, and weak awareness of staff protection at the organizational level; weak internal and external technical protection, confusion of anonymous technical standards, and difficulty in controlling information use at the technical level. Therefore, it is imperative to construct a governance framework with robust legal safeguards, well-defined organizational mechanisms, and sound technical measures according to the risk structure of archival personal information and the regulatory system.

Key words: archival personal information; risk governance; full life cycle; Archives Law

引用格式

李雪健. 档案个人信息全生命周期风险治理研究[J]. 档案学研究, 2026, 40(1): 104-113.
LI Xuejian. Study on Risk Governance of Archival Personal Information Throughout Its Lifecycle. Archives Science Study, 2026, 40(1): 104-113.

参考文献

展开查看参考文献(40 条)
[1] 黄霄羽, 靳文君. 档案高质量服务的内涵解读—基于《“十四五”全国档案事业发展规划》的文本分析[J]. 档案学通讯, 2022(3):4-11. [2] 何渊. 数据法学[M]. 北京: 北京大学出版社,2020:42-43. [3] MCCOY T S. Surveillance, privacy and power: information trumps knowledge[J]. Communication, 1991(1):33-47. [4] DANIESON E S. The ethical archivist[M]. Chicago: Society of American Archivists, 2010:9. [5] 谢小红. 民生档案工作中个人信息权利保护问题[J]. 档案学研究, 2020(4):81-86. [6] 苗运卫. 档案利用场景中个人信息的分类保护研究[J]. 档案学研究, 2022(5):51-58. [7] 胡大伟. 国有档案开放中个人信息处理活动的法理逻辑及规范架构[J]. 档案学研究, 2023(2):59-66. [8] 张罡. 论《个人信息保护法》在档案工作中的规范适用[J]. 档案学通讯, 2022(5):56-63. [9] 张涛. 风险预防原则在个人信息保护中的适用与展开[J]. 现代法学, 2023(5):52-72. [10] HORTON F W. Infromation resources management[M]. London: Prentice Hall, 1985: 80-122. [11] 娄海婷. 档案形成问题的法理性与学理性分析[J]. 档案管理, 2024(4):48-49. [12] SAMONAS S, COSS D. The CIA strikes back: redefining confidentiality, integrity and availability in security[J]. Journal of Information System Security, 2014(3):21-45. [13] 国家档案局. 各级国家综合档案馆电子文件与电子档案管理系统在档案信息利用过程中安全保护功能需求与实现方式的研究第一部分[EB/OL].[2023-09-10]. https://www.saac.gov.cn/daj/kjcgtg/202101/a5f0199e646241df9c049b598868433a.shtml. [14] 新华网. 广州市房地产档案馆:个人住房信息系统确实存在薄弱环节[EB/OL].[2022-04-03]. http://www.xinhuanet.com/politics/2012-12/21/c_114117250.htm. [15] 新华网. 7名辅警售卖万余条车辆档案信息获刑[EB/OL].[2021-04-06]. https://www.xinhuanet.com/legal/2021-02/06/c_1127072777.htm. [16] 上海法治报. “专业做鸡十年”征信受辱事件最新进展,警方介入调查[EB/OL].[2022-4-03]. https://baijiahao.baidu.com/s?id=1701144274414799196&wfr=spider&for=pc. [17] 唐长乐, 王明明. 我国档案数据开放研究—基于政府数据开放平台的调查[J]. 浙江档案, 2022(1):44-47. [18] 冯伯群. 利用档案引发的一场官司—《陈寅恪的最后二十年》出版以后[J]. 北京档案, 2003(1):22-26. [19] 商希雪, 韩海庭. 政府数据开放中个人信息保护路径研究[J]. 电子政务, 2021(6):113-124. [20] The National Archives. Guide to archiving personal data[EB/OL].[2023-04-03]. https://cdn.nationalarchives.gov.uk/documents/information-management/guide-to-archiving-personal-data.pdf. [21] OHM P. Broken promises of privacy: responding to the surprising failure of anonymization[J]. UCLA Law Review, 2009(6):1701-1778. [22] SWEENEY L. Only you, your doctor, and many others may know[EB/OL].[2022-04-03]. https://techscience.org/a/2015092903/#Citation. [23] 李震山. 人性尊严与人权保障[M]. 台北: 元照出版公司,2000:13-14. [24] 冉克平. 论《民法典》视野下个人隐私信息的保护与利用[J]. 社会科学辑刊, 2021(5):103-111. [25] 孙清白. 国家机关处理个人信息的特殊风险及其法律规制[J]. 安徽大学学报(哲学社会科学版), 2022 (3):88-97. [26] 邓辉. 我国个人信息保护行政监管的立法选择[J]. 交大法学, 2020(2):140-152. [27] 崔聪聪. 个人信息保护的行政监管及展开[J]. 苏州大学学报(哲学社会科学版), 2022(5):73-84. [28] 金波, 杨鹏. 大数据时代档案数据安全治理策略探析[J]. 情报科学, 2020(9):30-35. [29] 李润生. 个人信息匿名化的制度困境与优化路径—构建“前端宽松+过程控制”规制模式之探讨[J]. 江淮论坛, 2022(5):112-121. [30] CUSTERS B, URŠIČ H. Big data and data reuse: a taxonomy of data reuse for balancing big data benefits and personal data protection[J]. International data privacy law, 2016(1):4-15. [31] 罗英. 个人信息在国家机关之间传输的类型化治理[J]. 法学, 2023(9):33-47. [32] ČTVRTNÍK M. Archives and records:privacy, personality rights, and access[M]. London: Palgrave Macmillan Cham, 2023: 206. [33] 黄霄羽. 外国档案鉴定理论的历史发展及其规律[J]. 中国档案, 2003(9):28-30. [34] Netherlands National Archief. Stichting 1940-1945[EB/OL].[2025-04-02]. https://www.nationaalarchief.nl/onderzoeken/zoekhulpen/stichting-1940-1945. [35] 白路浩, 姚静. 如何保障档案中隐私信息的规范获取?[N]. 中国档案报,2024-03-25(3). [36] 南通市档案馆. 强化举措牢筑个人信息“保护墙”[EB/OL].[2025-04-03]. https://daj.nantong.gov.cn/ntsdaj/bmdt/content/165d6d7e-f104-49ee-88af-6d95c185c6e4.html. [37] SYED N F, SHAH S W, SHAGHAGHI A, et al. Zero trust architecture(ZTA): a comprehensive survey[J]. IEEE access, 2022(10):57143-57179. [38] 许可. 复活僵尸法条:个人信息匿名化制度的再造[J]. 财经法学, 2024(4):160-177. [39] HSU J, GABOARDI M, HAEBERLEN A, et al. Differential privacy: an economic method for choosing epsilon[C]//2014 IEEE 27th Computer Security Foundations Symposium. IEEE, 2014: 398-410. [40] 张涵, 于航, 周继威, 等. 面向隐私计算的可信执行环境综述[J]. 计算机应用, 2025(2):467-481.