Beijing and Brunei Lawyers Institute
Prepared by Mr. Djombo
In general, the compliance of the APP privacy policy is considered by the operator at the user’s point of view, how to inform users more clearly and clearly about the collection and use of personal information rules, how to put in place procedures to make the consent of the user more authentic, voluntary, and the information collected and used is essential to satisfy the APP function. When you are more honest and friendly to the user, the legal risk is far from you.
At the beginning of 1940, normative documents on how App collects and uses personal information were introduced, and specific actions of governance for violations of the law (as shown in figure 1) were opened, many of the well-known Apps were “recured” (as shown in figure 2), or were rescheduled for an order of limited duration, or were warned, fined, and some of the charges were investigated by public security authorities for alleged violations of personal information of citizens. As a result, APP has become a “cradle” of personal information protection law enforcement.
Apprenticeship policies (or “intellectual agreement”, “intellectual clause”, etc.) are statements by the application operator on how to collect and use personal information from users, as a sign of the enterprise’s system for the protection of personal information and a window for public awareness of the enterprise’s individual information protection mechanisms and practices. (b) What common mined areas need to be avoided when enterprises develop and improve their privacy policies? This is a matter of concern here.
Positive sources - privacy policies should inject personal information protection
The current irregularities in the App privacy policy include, inter alia, the lack of privacy policy, the absence of an express collection of personal information, the use of excessive collection of personal information, over-requirement, the use of mandatory user access, private sharing of user information with third parties, and the writing-off of accounts.
These violations are contrary to the principle of “advisory consent” and the “principle of necessity” that must be followed in the collection and use of personal information by network operators (operators) established by our legal norms, and reveal the misinterpretation of privacy policies by some enterprises. The most typical is the existence of an exemption clause in the name of privacy policy. Law enforcement has emerged from a variety of problems, essentially the nature and function of a policy of privacy that is not really understood and implemented.
The essence of the privacy policy is the enterprise’s personal information protection policy, with the main function being to collect, use the scope and rules of personal information by persons who control the disclosure of personal information. The personal benefit of the subject of the information, reflecting the freedom and dignity of the human person, and the collection and use of the law would seriously violate the fundamental rights of citizens. Therefore, our legal norms make it clear that any organization and individual should have access to personal information according to the law. The principle of “advising consent” and the principle of “necessity” is the principle of open collection, use of rules, express purpose, manner and scope for the collection, use of information, and, with the consent of the collector, it is simply the consent of the subject of the information; and, at the same time, limits on the scope of consent can be collected only in relation to the services provided and necessary personal information.
With regard to privacy policy, three areas of error need to be clarified: first, privacy policy is not an escape clause and should be built within the personal information protection system; secondly, privacy policy protection is aimed at personal information and is not limited to privacy information; and thirdly, privacy policy is not a rigid declaratory document, and the personal information protection systems and practices it presents are the subject of administrative regulation. It is true that the construction of personal information protection systems and the development of privacy policies require a certain cost, but the use of information would have been premised on the acquisition of voluntary concessions by users and the safeguarding of user information security, in the case of the “highest flow”. In the data age, privacy policies are both risky and opportunity, and sound privacy policies not only allow for the timely filling of loopholes, but also highlight corporate responsibility, gain user confidence and pave the way for sustained and healthy enterprise development.
Maintenance of the bottom line - “Informing consent”, “necessities”
On 28 November 1950, the National Internet Information Office, the Ministry of Industry and Informationization, the Ministry of Public Security and the Directorate-General for Market Regulation jointly developed the App methodology for the collection of personal information in violation of the law (hereinafter referred to as the “identified method”) to fine-tune the “commencement principle” with the “necessity principle” through the inclusion of violations, to give direction to the regulatory sector’s specific governance actions, and also to determine the “mined areas” of the current App operator’s own control and public scrutiny circle.
In conjunction with the Identification method, App privacy policy should avoid the following:
“Backing the bunker”, “stretching the word”, in violation of the “communication” principle
In the case of penitentiaries, most App found privacy policy at the registration/access interface, but some App used tacit consent at the entry interface or “registration is consent”, i.e. entry into the main interface (as shown in figure 3) immediately after the entry of the mobile phone number to the certification code, which made it easier for users to neglect, omit privacy policies and to safeguard the user’s informed rights.
The “unexhaustive list of the scope, purpose and manner in which personal information is collected and used in the actual operations of App” is now more common and three questions should be identified for each of the business functions of App (What/WhyHow), i.e. what types of information need to be collected, why such information needs to be gathered and how it will be used, only if the three issues are identified, it is “informed” that the “consent” on the basis of which is valid.
“How-down”, in contravention of “necessity”
App “Excessary gathering of information”, “excessive requests” (as shown in figure 4), for example, financial category App, which requires the opening of communication and location, and Atlas App, which requires the opening of short messaging powers, otherwise refuses to provide all operational functions. The above situation is the focus of specific actions to punish the high incidence of ill-treatment due to data abuse.
The collection, use and use of personal information should be guided by the principle of necessity, and only the minimum type and minimum number of personal information necessary for the use of operational functions. Information on what is necessary
