全球范围内隐私监管合规的数据保护要求比较与概念化
Comparing and Conceptualizing Data Protection Requirements Worldwide for Privacy Regulatory Compliance
浏览论文内容
中文总结 AI 辅助
本文从法律专家角度,通过访谈和法规分析,识别全球通用及不同的数据保护要求,回答相关问题,并转化为数据保护官故事,助力组织管理跨境个人数据流动的监管合规。
中文摘要 AI 辅助
社会数字化加剧个人数据跨国流动,促使全球数据保护框架激增。管理跨境个人数据流动面临不同司法管辖区数据保护要求差异的挑战,对需求工程至关重要。本文从数据保护法律专家角度识别并概念化全球通用的监管数据保护要求,通过对70位法律专家访谈的演绎定性分析和对相关法规的系统内容分析来回答问题。确定了如同意等通用要求和如被遗忘权等不同要求,并将结果转化为数据保护官故事以助组织管理合规。
英文摘要
The growing digitalization of society has intensified the collection, processing, and sharing of personal data, increasingly moving across national borders and regulatory jurisdictions, prompting a proliferation of data protection frameworks worldwide. These transborder personal data flows (TPDF) are essential to today's economy, but organizations managing them must reconcile data protection requirements that differ, sometimes subtly, across jurisdictions. For requirements engineering, this is the central challenge: regulatory data protection requirements (RDPRs) are complex and not directly translatable into software requirements, especially when frameworks impose similar, non-identical, or contradictory obligations. Identifying which requirements are shared and which diverge is therefore critical to managing TPDF, and addressing them late in the software development lifecycle (SDLC) causes costly rework, making early identification essential for compliance and stakeholder communication. This paper identifies and conceptualizes common RDPRs worldwide from the perspective of data protection legal experts, answering: (SQ1) which requirements are common across regulations and how are they conceptualized, and (SQ2) which requirements diverge and how do they differ conceptually. We combine deductive qualitative analysis of interviews with 70 legal experts from G20 economies and other countries and systematic content analysis of these economies' data protection regulations. We identify common requirements, such as consent, and divergent ones, such as the right to be forgotten. Given their impact across the SDLC and enterprise architecture, we translate these findings into a set of Data Protection Officer DPO (DPO) stories, using the user story notation, classified by SDLC phase and enterprise architecture layer, to help organizations manage TPDF compliance.