Blockchain and General Data Protection Regulation (GDPR) compliance issues (2019)
I. Brief
Blockchain technology can solve the problem of trust between data demanders and data providers. In other words, in a centralized mode, data demanders can only choose to believe that the centralized platform will not contain the false information. However, in the decentralized mode, data isn’t controlled by one individual group or organization[1], data demanders can directly verify information such as data source, time, and authorization on the blockchain without worrying about the correctness and authenticity of the data.
Take the “immutable” for example, it is conflict with the right to erase (also known as the right to be forgotten) in the GDPR.With encryption and one-time pad (OTP) technology, data subjects can make data off-chain storaged or modified at any time in a decentralized platform, so the problem that data on blockchain not meet the GDPR regulation has gradually faded away.
II. What is GDPR?
The purpose of the EU GDPR is to protect user’s data and to prevent large-scale online platforms or large enterprises from collecting or using user’s data without their permission. Violators will be punished by the EU with up to 20 million Euros (equal to 700 million NT dollars) or 4% of the worldwide annual revenue of the prior financial year.
The aim is to promote free movement of personal data within the European Union, while maintaining adequate level of data protection. It is a technology-neutral law, any type of technology which is for processing personal data is applicable.
So problem about whether the data on blockchain fits GDPR regulation has raise. Since the blockchain is decentralized, one of the original design goals is to avoid a large amount of centralized data being abused.
Blockchain can be divided into permissioned blockchains and permissionless blockchains. The former can also be called “private chains” or “alliance chains” or “enterprise chains”, that means no one can join the blockchain without consent. The latter can also be called “public chains”, which means that anyone can participate on chain without obtaining consent.
Sometimes, private chain is not completely decentralized. The demand for the use of blockchain has developed a hybrid of two types of blockchain, called “alliance chain”, which not only maintains the privacy of the private chain, but also maintains the characteristics of public chains. The information on the alliance chain will be open and transparent, and it is in conflict with the application of GDPR.
III. How to GDPR apply to blockchain ?
First, it should be determined whether the data on the blockchain is personal data protected by GDPR. Second, what is the relationship and respective responsibilities of the data subject, data controller, and data processor? Finally, we discuss the common technical characteristics of blockchain and how it is applicable to GDPR.
1. Data on the blockchain is personal data protected by GDPR?
First of all, starting from the technical characteristics of the blockchain, blockchain technology is commonly decentralized, anonymous, immutable, trackable and encrypted. The other five major characteristics are immutability, authenticity, transparency, uniqueness, and collective consensus.
Further, the blockchain is an open, decentralized ledger technology that can effectively verify and permanently store transactions between two parties, and can be proved.
It is a distributed database, all users on the chain can access to the database and the history record, also can directly verify transaction records. Each nodes use peer-to-peer transmission for upload or transfer information without third-party intermediation, which is the unique “decentralization” feature of the blockchain.
In addition, the node or any user on the chain has a unique and identifiable set of more than 30 alphanumeric addresses, but the user may choose to be anonymous or provide identification, which is also a feature of transparency with pseudonymity[2]; Data on blockchain is irreversibility of records. Once the transaction is recorded and updated on the chain, it is difficult to change and is permanently stored in the database, that is to say, it has the characteristics of “tamper-resistance”[3].
According to Article 4 (1) of the GDPR, “personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Therefore, if data subject cannot be identified by the personal data on the blockchain, that is an anonymous data, excluding the application of GDPR.
(1) What is Anonymization?
According to Opinion 05/2014 on Anonymization Techniques by Article 29 Data Protection Working Party of the European Union, “anonymization” is a technique applied to personal data in order to achieve irreversible de-identification[4].
And it also said the “Hash function” of blockchain is a pseudonymization technology, the personal data is possible to be re-identified. Therefore it’s not an “anonymization”, the data on the blockchain may still be the personal data stipulated by the GDPR.
As the blockchain evolves, it will be possible to develop technologies that are not regulated by GDPR, such as part of the encryption process, which will be able to pass the court or European data protection authorities requirement of anonymization. There are also many compliance solutions which use technical in the industry, such as avoiding transaction data stored directly on the chain.
2. International data transmission
Furthermore, in accordance with Article 3 of the GDPR, “This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union”.[5]
In other words, GDPR applies only when the data on the blockchain is not anonymized, and involves the processing of personal data of EU citizens.
3. Identification of data controllers and data processors
Therefore, if the encryption technology involves the public storage of EU citizens' personal data and passes it to a third-party controller, it may be identified as the “data controller” under Article 4 of GDPR, and all nodes and miners of the platform may be deemed as the “co-controller” of the data, and be assumed joint responsibility with the data controller by GDPR. For example, the parties can claim the right to delete data from the data controller.
In addition, a blockchain operator may be identified as a “processor”, for example, Backend as a Service (BaaS) products, the third parties provide network infrastructure for users, and let users manage and store personal data. Such Cloud Services Companies provide online services on behalf of customers, do not act as “data controllers”. Some commentators believe that in the case of private chains or alliance chains, such as land records transmission, inter-bank customer information sharing, etc., compared to public chain applications: such as cryptocurrencies (Bitcoin for example), is not completely decentralized, and more likely to meet GDPR requirements[6]. For example, in the case of a private chain or alliance chain, it is a closed platform, which contains only a small number of trusted nodes, is more effective in complying with the GDPR rules.
4. Data subject claims
In accordance with Article 17 of the GDPR, The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay under some grounds.
Off-chain storage technology can help the blockchain industry comply with GDPR rules, allowing offline storage of personal data, or allow trusted nodes to delete the private key of encrypted information, which leaving data that cannot be read and identified on the chain. If the data is in accordance with the definition of anonymization by GDPR, there is no room for GDPR to be applied.
IV. Conclusion
In summary, it’s seem that the application of blockchain to GDPR may include: (a) being difficulty to identified the data controllers and data processors after the data subject upload their data. (b) the nature of decentralized storage is transnational storage, and Whether the country where the node is located, is meets the “adequacy decision” of Article 45 of the GDPR.
If it cannot be met, then it needs to consider whether it conforms to the transfers subject to appropriate safeguards of Article 46, or the derogations for specific situations of Article 49 of the GDPR.
Reference:
[1] How to Trade Cryptocurrency: A Guide for (Future) Millionaires, https://wikijob.com/trading/cryptocurrency/how-to-trade-cryptocurrency
[2] DONNA K. HAMMAKER, HEALTH RECORDS AND THE LAW 392 (5TH ED. 2018).
[3] Iansiti, Marco, and Karim R. Lakhani, The Truth about Blockchain, Harvard Business Review 95, no. 1 (January-February 2017): 118-125, available at https://hbr.org/2017/01/the-truth-about-blockchain
[4] Article 29 Data Protection Working Party, Opinion 05/2014 on Anonymisation Techniques (2014), https://www.pdpjournals.com/docs/88197.pdf
[5] Directive 95/46/EC (General Data Protection Regulation), https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN
[6] Queen Mary University of London, Are blockchains compatible with data privacy law? https://www.qmul.ac.uk/media/news/2018/hss/are-blockchains-compatible-with-data-privacy-law.html
The Tax Benefit of “Act for Establishment and Administration of Science Parks” and the Relational Norms for Innovation “Act for Establishment and Administration of Science Parks” was promulgated in 1979, and was amended entirely in May 15, 2018, announced in June 6. The title was revised from “Act for Establishment and Administration of Science ‘Industrial’ Parks” to “Act for Establishment and Administration of Science Parks” (it would be called “the Act” in this article). It was a significant transition from traditional manufacture into technological innovation. For encouraging different innovative technology enter into the science park, there is tax benefit in the Act. When the park enterprises import machines, equipment, material and so on from foreign country, the import duties, commodity tax, and business tax shall be exempted; moreover, when the park enterprises export products and services, it will have given favorable business and commodity tax free.[1] Furthermore, the park bureaus also exempt collection of land rent.[2] If they have approval for importing or exporting products, they do not need to apply for permission.[3] In the sub-law, there is also regulations of bonding operation.[4] To sum up, for applying the benefit of the act, enterprises approved for establishment in science parks still require to manufacture products. Such regulations are confined to industrial industry. Innovative companies dedicate in software, big data, or customer service, rarely gain benefits from taxation. In other norms,[5] there are also tax deduction or exemption for developing innovative industries. Based on promoting innovation, the enterprises following the laws of environmental protection, laborers’ safety, food safety and sanitation,[6] or investing in brand-new smart machines for their own utilize,[7] or licensing their intellectual property rights,[8] can deduct from its taxable income. In addition, the research creators from academic or research institutions,[9] or employee,[10] can declare deferral of the income tax payable for the shares distributed. In order to assist new invested innovative enterprises,[11] there are also relational benefit of tax. For upgrading the biotech and new pharmaceuticals enterprises, when they invest in human resource training, research and development, they can have deductible corporate income tax payable.[12] There is also tax favored benefits for small and medium enterprises in using of land, experiment of research, technology stocks, retaining of surplus, and additional employees hiring.[13] The present norms of tax are not only limiting in space or products but also encouraging in “research”. In other word, in each steps of the research of innovation, the enterprises still need to manufacture products from their own technology, fund and human resources. If the government could encourage open innovation with favored taxation, it would strengthen the capability of research and development for innovative enterprises. Supporting the innovation by taxation, the government can achieve the goal of scientific development more quickly and encourage them accepting guidance. “New York State Business Incubator and Innovation Hot Spot Support Act” can be an example, [14]the innovative enterprises accepting the guidance from incubators will have the benefit of tax on “personal income”, “sales and use” and “corporation franchise”. Moreover, focusing on key industries and exemplary cases, there are also the norms of tax exemption and tax abatement in China for promoting the development of technology.[15]The benefit of tax is not only in research but also in “the process of research”. To sum up, the government of Taiwan provides the benefit of tax for advancing the competition of outcomes in market, and for propelling the development of innovation. In order to accelerate the efficiency of scientific research, the government could draw lessons from America and China for enacting the norms about the benefit of tax and the constitution of guidance. [1] The Act §23. [2] Id. §24. [3] Id. §25. [4] Regulations Governing the Bonding Operations in Science Parks. [5] Such as Act for Development of Small and Medium Enterprises, Statute for Industrial Innovation, Act for the Development of Biotech and New Pharmaceuticals Industry. [6] Statute for Industrial Innovation §10. [7] Id. §10-1. [8] Id. §12-1. [9] Id. §12-2. [10] Id. §19-1. [11] Id. §23-1, §23-2, §23-3. [12] Act for the Development of Biotech and New Pharmaceuticals Industry §5, §6, §7. [13] Act for Development of Small and Medium Enterprises Chapter 4: §33 to §36-3. [14] New York State Department of Taxation and Finance Taxpayer Guidance Division, New York State Business Incubator and Innovation Hot Spot Support Act, Technical Memorandum TSB-M-14(1)C, (1)I, (2)S, at 1-6 (March 7, 2014), URL:http://www.wnyincubators.com/content/Innovation%20Hot%20Spot%20Technical%20Memorandum.pdf (last visited:December 18, 2019). [15] Enterprise Income Tax Law of the People’s Republic of China Chapter 4 “Preferential Tax Treatments”: §25 to §36 (2008 revised).
A Before and After Impact Comparison of Applying Statute for Industrial Innovation Article 23-1 Draft on Venture Capital Limited PartnershipsA Before and After Impact Comparison of Applying Statute for Industrial Innovation Article 23-1 Draft on Venture Capital Limited Partnerships I. Background Because the business models adopted by Industries, such as venture capital, film, stage performance and others, are intended to be temporary entities, and the existing business laws are not applicable for such industries,[1] the Legislature Yuan passed the “Limited Partnership Act” in June 2015,[2] for the purpose of encouraging capital injection into these industries. However, since the Act was passed, there are currently only nine limited partnerships listed on the Ministry of Economic Affairs' limited partnership information website. Among them, “Da-Zuo Limited Partnership (Germany) Taiwan Branch” and “Stober Antriebstechnik Limited Partnership (Germany) Taiwan Branch”, are branch companies established by foreign businesses, the remaining seven companies are audio video production and information service businesses. It is a pity that no venture capital company is adopting this format.[3] In fact, several foreign countries have set up supporting measures for their taxation systems targeting those business structures, such as limited partnerships. For example, the pass-through taxation method (or referred to as single entity taxation) is adopted by the United States, while Transparenzprinzip is used by Germany. These two taxation methods may have different names, but their core ideas are to pass the profits of a limited partnership to the earnings of partners.[4] However, following the adoption of the Limited Partnership Act in Taiwan, the Ministry of Finance issued an interpretation letter stating that because the current legal system confers an independent legal entity status to the business structure of a limited partnership, it should be treated as a profit-seeking business and taxed with Profit-Seeking Enterprise Income Tax.[5] Therefore, to actualize the legislative objective of encouraging innovative businesses organized under tenets of the Limited Partnership Act, the Executive Yuan presented a draft amendment for Article 23-1 of the Statute for Industrial Innovation (hereinafter referred to as the Draft), introducing the "Pass Through Taxation Principle" as adopted by several foreign countries. That is, a Limited Partnership will not be levied with the Profit-Seeking Enterprise Income Tax, but each partner will file income tax reports based on after-profit-gains from the partnership that are passed through to each partner. It is expected that the venture capital industry will now be encouraged to adopt the limited partnership structure, and thus increase investment capital in new ventures. II. The Pass Through Taxation Method is Applicable to Newly Established Venture Capital Limited Partnerships 1. The Requirements and Effects (1) The Requirements According to the provisions of Article 23-1 Paragraph 3 of the Draft, to be eligible for Pass Through Taxation, newly established venture capital limited partnerships must meet the following requirements: 1. The venture capital limited partnerships are established between January 1, 2017 and December 31, 2019. 2. Investment threshold of the total agreed capital contribution, total received capital contribution, and accumulated total capital contribution, within five years of the establishment of venture capital limited partnerships: Total Agreed Capital Contribution in the Limited Partnership Agreement Total Received Capital Contribution Accumulated Investment Amount for Start-up Companies The Year of Establishment 3 hundred million ✕ ✕ The Second Year ✕ ✕ The Third Year 1 hundred million ✕ The Fourth Year 2 hundred million Reaching 30 percent of the total received capital contribution of the year or 3 hundred million NT dollars. The Fifth Year 3 hundred million 3. The total amount, that an overseas company applies in capital and investments in actual business operations in Taiwan, reaches 50% of its total received capital contribution of that year. 4. In compliance with government policies. 5. Reviewed and approved by the central competent authority each year. (2) The Effects The effects of applying the provisions of Article 23-1 Paragraph 3 of the Draft are as follows: 1. Venture capital limited partnerships are exempt from the Profit-Seeking Enterprise Income Tax. 2. Taxation method for partners in a limited partnership after obtaining profit gains: (1) Pursuant to the Income Tax Act, Individual partners and for-profit business partners are taxed on their proportionally-calculated, distributed earnings. (2) Individual partners and foreign for-profit business partners are exempt from income tax on the stock earnings distributed by a limited partnership. 2. Benefit Analysis Before and After Applying Pass Through Taxation Method A domestic individual A, a domestic profit-making business B, and a foreign profit-making business C jointly form a venture capital limited partnership, One. The earnings distribution of the company One is 10%, 80% and 10% for A, B, and C partners, respectively. The calculated earnings of company One are one million (where eight hundred thousand are stock earnings, and two hundred thousand are non-stock earnings). How much income tax should be paid by the company One, and partners A, B, and C? (1) Pursuant to the Income Tax Act, before the amended draft: 1. One Venture Capital Limited Partnership Should pay Profit-Seeking Enterprise Income Tax = (NT$1,000,000 (earning) - NT$500,000[6])x12% (tax rate[7])=NT$60,000 2. Domestic Individual A Should file a comprehensive income report with business profit income =(NT$1,000,000-NT$60,000) x 10% (company One draft a voucher for net amount for A) + NT$60,000÷2×10% (deductible tax rate)= NT$97,000 Tax payable on profit earnings=NT$91,500×5%(tax rate)=NT$4,850 Actual income tax paid=NT$4,850 - NT$60,000÷2×10% (deductible tax rate) =NT$1,485 3. Domestic For-Profit Business B Pursuant to the provisions of Article 42 of the Income Tax Act, the net dividend or net income received by a profit-seeking company is not included in the income tax calculation. 4. Foreign For-Profit Business C Tax paid at its earning source=(NT$1,000,000 - NT$60,000) ×10% (earning distribution rate) ×20% (tax rate at earning source)=NT$18,800 (2) Applying Pass Through Taxation Method After Enacting the Amendment 1. One Venture Capital Limited Partnership No income tax. 2. Domestic Individual A Should pay tax=NT$800,000 (non-stock distributed earnings)×10% (earning distribution rate)×5% (comprehensive income tax rate)=NT$1,000 3. Domestic For-Profit Business B Pursuant to the provisions of Article 42 of the Income Tax Act, the net dividend or net income received by a profit-seeking company is not included in the income tax calculation. 4. Foreign For-Profit Business C Tax paid at its earning source=NT$800,000 (non-stock distributed earnings)×10%(earning distribution rate)×20% (tax rate at earning source)=NT$4,000 The aforementioned example shows that under the situation, where the earning distribution is the same and tax rate for the same taxation subject is the same, the newly-established venture capital limited partnerships and their shareholders enjoy a more favorable tax benefit with the adoption of pass through taxation method: Before the Amendment After the Amendment Venture Capital Limited Partnership NT$60,000 Excluded in calculation Shareholders Domestic Individual NT$1,850 NT$1,000 Domestic For-Profit Business Excluded in calculation Excluded in calculation Foreign For-Profit Business NT$18,800 NT$4,000 Sub-total NT$80,650 NT$5,000 III. Conclusion Compared to the corporate taxation, the application of the pass through taxation method allows for a significant reduction in tax burden. While developing Taiwan’s pass through tax scheme, the government referenced corporate taxation under the U.S. Internal Revenue Code (IRC), where companies that meet the conditions of Chapter S can adopt the “pass through” method, that is, pass the earnings to the owner, with the income of shareholders being the objects of taxation;[8] and studied the "Transparenzprinzip" adopted by the German taxation board for partnership style for-profit businesses. Following these legislative examples, where profits are identified as belonging to organization members,[9] the government legislation includes the adoption of the pass through taxation scheme for venture capital limited partnerships in the amended draft of Article 23-1 of the Statute for Industrial Innovation, so that the legislation is up to international standards and norms, while making an important breakthrough in the current income tax system. This is truly worthy of praise. [1] The Legislative Yuan Gazette, Vol. 104, No. 51, page 325. URL:http://misq.ly.gov.tw/MISQ//IQuery/misq5000Action.action [2] A View on the Limited Partnership in Taiwan, Cross-Strait Law Review, No. 54, Liao, Da-Ying, Page 42. [3] Ministry of Economic Affairs - Limited Partnership Registration Information URL: http://gcis.nat.gov.tw/lmpub/lms/dir.jsp?showgcislocation=true&agencycode=allbf [4] Same as annotate 2, pages 51-52. [5] Reference Letter of Interpretation dated December 18, 2015, Tai-Cai-Shui Zi No. 10400636640, the Ministry of Finance [6] First half of Paragraph 1 of Article 8 of the Income Basic Tax Act [7] Second half of Paragraph 1 of Article 8 of the Income Basic Tax Act [8] A Study on the Limited Partnership Act, Master’s degree thesis, College of Law, Soochow University, Wu, Tsung-Yeh, pages 95-96. [9] Reference annotate 2, pages 52.
Impact of Government Organizational Reform to Scientific Research Legal System and Response Thereto (2) – For Example, The Finnish Innovation Fund (“SITRA”)Impact of Government Organizational Reform to Scientific Research Legal System and Response Thereto (2) – For Example, The Finnish Innovation Fund (“SITRA”) III. Comparison of Strength and Weakness of Sitra Projects 1. Sitra Venture Capital Investment Model In order to comprehend how to boost innovation business development to upgrade innovation ability, we analyze and compare the innovation systems applied in Sweden, France and Finland[1] . We analyze and compare the characteristics, strength and weakness of innovation promotion models in terms of funding, networking and professional guidance. Generally, the first difficulty which a start-up needs to deal with when it is founded initially is the funding. Particularly, a technology company usually requires tremendous funding when it is founded initially. Some potentially adequate investors, e.g., venture capitals, seldom invest in small-sized start-up (because such overhead as supervision and management fees will account for a high percentage of the investment due to the small total investment amount). Networking means how a start-up integrates such human resources as the management, investors, technical advisors and IP professionals when it is founded initially. Control over such human resources is critical to a new company’s survival and growth. Professional guidance means how professional knowledge and human resource support the start-up’s operation. In order to make its product required by the market, an enterprise usually needs to integrate special professional knowledge. Notwithstanding, the professional knowledge and talents which are available from an open market theoretically often cannot be accessed, due to market failure[2]. Assuming that Sitra’s funding is prioritized as Pre-seed-Initiation stage, Seed-Development stage and Follow-up – Growth stage, under Finland model, at the Pre-seed-Initiation stage, Sitra will provide the fund amounting to EUR20,000 when Tekes will also provide the equivalent fund, provided that the latter purely provides subsidy, while the fund provided by Sitra means a loan to be repaid (without interest) after some time (usually after commercialization), or a loan convertible to shares. Then, the loan would be replaced by soft or convertible (to shares) investment and the source of funding would turn to be angel investors or local seed capital at the Seed-Development stage. At this stage, the angel investors, local seed capital and Sitra will act as the source of funding jointly in Finland, while Tekes will not be involved at this stage. At the Follow-up-Growth stage, like the Sweden model, Sitra will utilize its own investment fund to help mitigate the gap between local small-sized funding and large-sized international venture capital[3]. How to recruit professional human resources is critical to a start-up’s success. Many enterprises usually lack sufficient professional human resources or some expertise. DIILI service network set up by Sitra is able to provide the relevant solutions. DILLI is a network formed by product managers. Its members actively participate in starts-up and seek innovation. They also participate in investment of starts-up independently sometimes. Therefore, they are different from angel investors, because they devote themselves to the starts-up on a full-time basis[4]. In other words, they manage the starts-up as if the starts-up were their own business. 2. Key to Public Sector’s Success in Boosting Development of Innovation Activity Business In terms of professional guidance, voluntary guidance means the direct supply of such professional resources as financing, human resource and technology to starts-up, while involuntary guidance means the supply of strategic planning in lieu of direct assistance to help the enterprises make routine decisions[5]. The fractured and incomplete professional service attendant market generates low marginal effect. Therefore, it is impossible for the traditional consultation service to mitigate such gap and the investment at the pre-seed initiation stage will be excessive because of the acquisition of the professional services. Meanwhile, professional advisors seldom are involved in consultation services at the pre-seed initiation stage of a start-up because of the low potential added value. Therefore, at such stage, only involuntary professional guidance will be available usually. Under Sitra model, such role is played by an angel investor. Upon analysis and comparison, we propose six suggested policies to boost innovation activities successfully as the reference when observing Sitra operation. First of all, compared with the French model, Finland Sitra and Sweden model set more specific objectives to meet a start-up’s needs (but there is some defect, e.g., Sitra model lacks voluntary professional guidance). Second, structural budget is a key to the successful model. Sitra will receive the funds in the amount of EUR235,000,000 from the Finnish Government, but its operating expenditure is covered by its own operating revenue in whole. Third, it is necessary to provide working fund in installments and provide fund at the pre-seed-initiation stage. Under both of Finland model and Sweden model, funds will be provided at the pre-seed-initiation stage (Tekes is responsible for providing the fund in Finland). Fourth, the difficulty in networking must be solved. In Sitra, the large-sized talent network set up by it will be dedicated to recruiting human resources. Fifth, the voluntary professional guidance is indispensable at the pre-seed-initiation stage, while the same is unavailable at such stage under Sitra model. Instead, the Sweden model is held as the optimal one, as it has a dedicated unit responsible for solving the difficulty to seek profit. Sixth, soft loan[6] will be successfully only when the loan cannot be convertible to shares. At the pre-seed initiation stage or seed-development stage, a start-up is usually funded by traditional loan. Assuming that the start-up is not expected to gain profit, whether the loan may be convertible to shares will also be taken into consideration when the granting of loan is considered (therefore, the fund provider will not be changed to the “capital” provider). Besides, the government authorities mostly lack the relevant experience or knowledge, or are in no position to negotiate with international large-sized venture capital companies. For example, under the French model, the government takes advantage of its power to restrict the venture capital investment and thereby renders adverse impact to starts-up which seek venture capital. Finally, the supply of own fund to meet the enterprises’ needs at seed-development stage and follow-up-growth stage to mitigate the gap with large-sized venture capital[7] is also required by a successful funding model. IV. Conclusion-Deliberation of Finnish Sitra Experience As the leading national industrial innovation ability promoter in Finland, Sitra appears to be very characteristic in its organizational framework or operating mechanism. We hereby conclude six major characteristics of Sitra and propose the potential orientation toward deliberation of Taiwan’s industrial innovation policies and instruments. 1. Particularity of Organizational Standing In consideration of the particularity of Sitra organizational standing, it has two characteristics observable. First, Sitra is under supervision of the Finnish Parliament directly, not subordinated to the administrative organizational system and, therefore, it possesses such strength as flexibility and compliance with the Parliament’s requirements. Such organization design which acts independently of the administrative system but still aims to implement policies has been derived in various forms in the world, e.g., the agency model[8] in the United Kingdom, or the independent apparatus in the U.S.A. Nevertheless, to act independently of the administrative system, it has to deal with the deliberation of responsible political principles at first, which arouses the difficulty in taking care of flexibility at the same time. In Taiwan, the intermediary organizations include independent agencies and administrative corporations, etc., while the former still involves the participation of the supreme administrative head in the right of personnel administration and is subordinated to the ministries/departments of the Executive Yuan and the latter aims to enforce the public missions in the capacity of “public welfare” organization. Though such design as reporting to the Parliament directly is not against the responsible political principles, how the Parliament owns the authority to supervise is the point (otherwise, theoretically, the administrative authorities are all empowered by the parliament in the country which applies the cabinet system). Additionally, why some special authorities are chosen to report to the parliament directly while other policy subjects are not is also disputable. The existence of Sitra also refers to a circumstantial evidence substantiating that Finland includes the innovation policy as one of the important government policies, and also the objective fact that Finland’s innovation ability heads the first in the world. Second, Sitra is a self-sufficient independent fund, which aims to promote technical R&D and also seeks profit for itself, irrelevant with selection of adequate investment subjects or areas. Instead, for this purpose, the various decisions made by it will deal with the utility and mitigate the gap between R&D and market. Such entity is responsible for public welfare or policy projects and also oriented toward gain from investment to feed the same back to the individuals in the organization. In the administrative system, Sitra is not directed by the administrative system but reports to the Parliament directly. Sitra aims to upgrade the national R&D innovation ability as its long-term goal mission and utilizes the promotion of innovation business and development of venture capital market. The mission makes the profit-orientation compatible with the selection of investment subjects, as an enterprise unlikely to gain profit in the future usually is excluded from the national development view. For example, such industries as green energy, which is not likely to gain profit in a short term, is still worth investing as long as it meets the national development trend and also feasible (in other words, selection of marketable green technology R&D, instead of comparison of the strength and weakness in investment value of green energy and other high-polluted energy). 2. Expressly Distinguished From Missions of Other Ministries/Departments For the time being, Sitra primarily invests in starts-up, including indirect investment and direct investment, because it relies on successful new technology R&D which may contribute to production and marketability. Starts-up have always been one of the best options, as large-sized enterprises are able to do R&D on their own without the outsourcing needs. Further, from the point of view of an inventor, if the new technology is marketable, it will be more favorable to him if he chooses to start business on his own or make investment in the form of partnership, instead of transfer or license of the ownership to large-sized enterprises (as large-sized enterprises are more capable of negotiation). However, note that Sitra aims to boost innovation activities and only targets at start-up business development, instead of boosting and promoting the start-up per se. Under the requirement that Sitra needs to seek profit for itself, only the business with positive development view will be targeted by Sitra. Further, Sitra will not fund any business other than innovation R&D or some specific industries. Apparently, Sitra only focuses on the connection between innovation activities and start-up, but does not act as the competent authority in charge of small-sized and medium-sized enterprises. Meanwhile, Sitra highlights that it will not fund academic research activities and, therefore, appears to be distinguished from the competent authority in charge of national scientific research. Though scientific research and technology innovation business, to some extent, are distinguished from each other in quantity instead of quality, abstract and meaningless research is existent but only far away from the commercialization market. Notwithstanding, a lot of countries tend to distinguish basic scientific research from industrial technology R&D in the administration organization's mission, or it has to be. In term of the way in which Sitra carries out its mission, such distinguishing ability is proven directly. 3. Well-Founded Technology Foresight-Based Investment Business The corporate investments, fund investments and project funding launched by Sitra are all available to the pre-designated subjects only, e.g. ecological sustainable development, energy utilization efficiency, and social structural changes, etc. Such way to promote policies as defining development area as the first priority and then promoting the investment innovation might have some strength and weakness at the same time. First of all, the selection of development areas might meet the higher level national development orientation more therefor, free from objective environmental restrictions, e.g. technical level, leading national technology industries and properties of natural resources. Notwithstanding, an enterprise’s orientation toward innovation R&D might miss the opportunity for other development because of the pre-defined framework. Therefore, such way to promote policies as defining development areas or subjects as the first priority will be inevitably based on well-founded technology foresight-based projects[9], in order to take various subjective and objective conditions into consideration and to forecast the technology development orientation and impact to be faced by the home country’s national and social economies. That is, said strength and weakness will be taken into consideration beforehand for foresight, while following R&D funding will be launched into the technology areas pre-designated after thorough analysis. 4. Self-Interested Investment with the Same High Efficiency as General Enterprises Sitra aims to gain profit generally, and its individual investment model, e.g., DIILI, also permits marketing managers to involve business operation. The profit-sharing model enables Sitra to seek the same high efficiency as the general enterprises when purusing its innovation activity development. The investment launched by Sitra highlights that it is not “funding” (which Tekes is responsible for in Finland) or the investment not requiring return. Therefore, it has the system design to acquire corporate shares. Sitra participates in a start-up by offering its advanced technology, just like a general market investor who will choose the potential investment subject that might benefit him most upon his personal professional evaluation. After all, the ultimate profit will be retained by Sitra (or said DIILI manger, subject to the investment model). Certainly, whether the industry which requires permanent support may benefit under such model still remains questionable. However, except otherwise provided in laws expressly, said special organization standing might be a factor critical to Sitra profit-seeking model. That is, Sitra is not subordinated to the administrative system but is under supervision of the parliament independently, and how its staff deal with the conflict of interest issues in the capacity other than the public sector’s/private sector’s staff is also one of the key factors to success of the system. 5. Investment Model to Deal With Policy Instruments of Other Authorities/Agencies Sitra decides to fund a start-up depending on whether it may gain profit as one of its priorities. As aforesaid, we may preliminarily recognize that the same should be consistent with funding to starts-up logically and no “government failure” issue is involved. For example, the funding at the pre-seed-initiation stage needs to tie in with Tekes’ R&D “funding” (and LIKSA service stated herein) and, therefore, may adjust the profit-seeking orientation, thereby causing deviation in promotion of policies. The dispute over fairness of repeated subsidy/funding and rationality of resource allocation under the circumstance must be controlled by a separate evaluation management mechanism inevitably. 6. Affiliation with Enhancement of Regional Innovation Activities Regional policies cannot be separable from innovation policies, especially in a country where human resources and natural resources are not plentiful or even. Therefore, balancing regional development policies and also integrating uneven resource distribution at the same time is indispensable to upgrading of the entire national social economic benefits. The Finnish experience indicated that innovation activities ought to play an important role in the regional development, and in order to integrate enterprises, the parties primarily engaged in innovation activities, with the R&D ability of regional academic research institutions to upgrade the R&D ability effectively, the relevant national policies must be defined for adequately arranging and launching necessary resources. Sitra's approaches to invest in starts-up, release shares after specific period, integrate the regional resources, upgrade the national innovation ability and boost the regional development might serve to be the reference for universities’ centers of innovative incubator or Taiwan’s local academic and scientific sectors[10] to improve their approaches. For the time being, the organization engaged in venture capital investment in the form of fund in Taiwan like Sitra of Finland is National Development Fund, Executive Yuan. However, in terms of organizational framework, Sitra is under supervision of the Parliament directly, while National Development Fund is subordinated to the administrative system of Taiwan. Though Sitra and National Development Fund are both engaged in venture capital investments primarily, Sitra carries out its missions for the purpose of “promoting innovative activities”, while the National Development Fund is committed to achieve such diversified goals as “promoting economic changes and national development[11]” and is required to be adapted to various ministries’/departments’ policies. Despite the difference in the administrative systems of Taiwan and Finland, Sitra system is not necessarily applicable to Taiwan. Notwithstanding, Sitra’s experience in promotion and thought about the system might provide a different direction for Taiwan to think when it is conceiving the means and instruments for industrial innovation promotion policies in the future. [1] Bart Clarysse & Johan Bruneel, Nurturing and Growing Innovation Start-Ups: The Role of Policy As Integrator, R&D MANAGEMENT, 37(2), 139, 144-146 (2007). Clarysse & Bruneel analysis and comparison refers to Sweden Chalmers Innovation model, French Anvar/Banque de Developpement des PMEs model and Finland Sitra PreSeed Service model. [2] id. at 141-143. [3] id. at 141. [4] id. at 145-146. [5] id. at 143. [6] The loan to be repaid is not a concern. For example, the competent authority in Sweden only expects to recover one-fourths of the loan. [7] Clarysse & Bruneel, super note 26, at 147-148. [8] 彭錦鵬,〈英國政署之組織設計與運作成效〉,《歐美研究》,第30卷第3期,頁89-141。 [9] Technology foresight must work with the innovation policy road mapping (IPRM) interactively, and consolidate the forecast and evaluation of technology policy development routes. One study case about IPRM of the environmental sustainable development in the telecommunication industry in Finland, the IPRM may enhance the foresighted system and indicates the potential factors resulting in systematic failure. Please see Toni Ahlqvist, Ville Valovirta & Torsti Loikkanen, Innovation policy road mapping as a systemic instrument for forward-looking policy design, Science and Public Policy 39, 178-190 (2012). [10] 參見李昂杰,〈規範新訊:學界科專辦法及其法制配套之解析〉,《科技法律透析》,第23卷第8期,頁33(2011)。 [11] National Development Fund, Executive Yuan website, http://www.df.gov.tw/(tftgkz45150vye554wi44ret)/page-aa.aspx?Group_ID=1&Item_Title=%E8%A8%AD%E7%AB%8B%E5%AE%97%E6%97%A8#(Last visit on 2013/03/28)
Reviews on Taiwan Constitutional Court's Judgment no. 13 of 2022Reviews on Taiwan Constitutional Court's Judgment no. 13 of 2022 2022/11/24 I.Introduction In 2012, the Taiwan Human Rights Promotion Association and other civil groups believe that the National Health Insurance Administration released the national health insurance database and other health insurance data for scholars to do research without consent, which may be unconstitutional and petitioned for constitutional interpretation. Taiwan Human Rights Promotion Association believes that the state collects, processes, and utilizes personal data on a large scale with the "Personal Data Protection Law", but does not set up another law of conduct to control the exercise of state power, which has violated the principle of legal retention; the data is provided to third-party academic research for use, and the parties involved later Excessive restrictions on the right to withdraw go against the principle of proportionality. The claimant criticized that depriving citizens of their prior consent and post-control rights to medical data is like forcing all citizens to unconditionally contribute data for use outside the purpose before they can use health insurance. The personal data law was originally established to "avoid the infringement of personality rights and promote the rational use of data", but in the insufficient and outdated design of the regulations, it cannot protect the privacy of citizens' information from infringement, and it is easy to open the door to the use of data for other purposes. In addition, even if the health insurance data is de-identified, it is still "individual data" that can distinguish individuals, not "overall data." Health insurance data can be connected with other data of the Ministry of Health and Welfare, such as: physical and mental disability files, sexual assault notification files, etc., and you can also apply for bringing in external data or connecting with other agency data. Although Taiwan prohibits the export of original data, the risk of re-identification may also increase as the number of sources and types of data concatenated increases, as well as unspecified research purposes. The constitutional court of Taiwan has made its judgment on the constitutionality of the personal data usage of National Health Insurance research database. The judgment, released on August 12, 2022, states that Article 6 of Personal Data Protection Act(PDPA), which asks“data pertaining to a natural person's medical records, healthcare, genetics, sex life, physical examination and criminal records shall not be collected, processed or used unless where it is necessary for statistics gathering or academic research by a government agency or an academic institution for the purpose of healthcare, public health, or crime prevention, provided that such data, as processed by the data provider or as disclosed by the data collector, may not lead to the identification of a specific data subject”does not violate Intelligible principle and Principle of proportionality. Therefore, PDPA does not invade people’s right to privacy and remains constitutional. However, the judgment finds the absence of independent supervisory authority responsible for ensuring Taiwan institutions and bodies comply with data protection law, can be unconstitutional, putting personal data protection system on the borderline to failure. Accordingly, laws and regulations must be amended to protect people’s information privacy guaranteed by Article 22 of Constitution of the Republic of China (Taiwan). In addition, the judgment also states it is unconstitutional that Articles 79 and 80 of National Health Insurance Law and other relevant laws lack clear provisions in terms of store, process, external transmission of Personal health insurance data held by Central Health Insurance Administration of the Ministry of Health and Welfare. Finally, the Central Health Insurance Administration of the Ministry of Health and Welfare provides public agencies or academic research institutions with personal health insurance data for use outside the original purpose of collection. According to the overall observation of the relevant regulations, there is no relevant provision that the parties can request to “opt-out”; within this scope, it violates the intention of Article 22 of the Constitution to protect people's right to information privacy. II.Independent supervisory authority According to Article 3 of Central Regulations and Standards Act, government agencies can be divided into independent agencies that can independently exercise their powers and operate autonomously, and non- independent agencies that must obey orders from their superiors. In Taiwan, the so-called "dedicated agency"(專責機關) does not fall into any type of agency defined by the Central Regulations and Standards Act. Dedicated agency should be interpreted as an agency that is responsible for a specific business and here is no other agency to share the business. The European Union requires member states to set up independent regulatory agencies (refer to Articles 51 and 52 of General Data Protection Regulation (GDPR)). In General Data Protection Regulation and the adequacy reference guidelines, the specific requirements for personal data supervisory agencies are as follows: the country concerned should have one or more independent supervisory agencies; they should perform their duties completely independently and cannot seek or accept instructions; the supervisory agencies should have necessary and practicable powers, including the power of investigation; it should be considered whether its staff and budget can effectively assist its implementation. Therefore, in order to pass the EU's adequacy certification and implement the protection of people's privacy and information autonomy, major countries have set up independent supervisory agencies for personal data protection based on the GDPR standards. According to this research, most countries have 5 to 10 commissioners that independently exercise their powers to supervise data exchange and personal data protection. In order to implement the powers and avoid unnecessary conflicts of interests among personnel, most of the commissioners are full-time professionals. Article 3 of Basic Code Governing Central Administrative Agencies Organizations defines independent agency as "A commission-type collegial organization that exercises its powers and functions independently without the supervision of other agencies, and operates autonomously unless otherwise stipulated." It is similar to Japan, South Korea, and the United States. III.Right to Opt-out The judgment pointed out that the parties still have the right to control afterwards the personal information that is allowed to be collected, processed and used without the consent of the parties or that meets certain requirements. Although Article 11 of PDPA provides for certain parties to exercise the right to control afterwards, it does not cover all situations in which personal data is used, such as: legally collecting, processing or using correct personal data, and its specific purpose has not disappeared, In the event that the time limit has not yet expired, so the information autonomy of the party cannot be fully protected, the subject, cause, procedure, effect, etc. of the request for suspension of use should be clearly stipulated in the revised law, and exceptions are not allowed. The United Kingdom is of great reference. In 2017, after the British Information Commissioner's Office (ICO) determined that the data sharing agreement between Google's artificial intelligence DeepMind and the British National Health Service (NHS) violated the British data protection law, the British Department of Health and Social Care proposed National data opt-out Directive in May, 2018. British health and social care-related institutions may refer to the National Data Opt-out Operational Policy Guidance Document published by the National Health Service in October to plan the mechanism for exercising patient's opt-out right. The guidance document mainly explains the overall policy on the exercise of the right to opt-out, as well as the specific implementation of suggested practices, such as opt-out response measures, methods of exercising the opt-out right, etc. National Data Opt-out Operational Policy Guidance Document also includes exceptions and restrictions on the right to opt-out. The Document stipulates that exceptions may limit the right to Opt-out, including: the sharing of patient data, if it is based on the consent of the parties (consent), the prevention and control of infectious diseases (communicable disease and risks to public health), major public interests (overriding) Public interest), statutory obligations, or cooperation with judicial investigations (information required by law or court order), health and social care-related institutions may exceptionally restrict the exercise of the patient's right to withdraw. What needs to be distinguished from the situation in Taiwan is that when the UK first collected public information and entered it into the NHS database, there was already a law authorizing the NHS to search and use personal information of the public. The right to choose to enter or not for the first time; and after their personal data has entered the NHS database, the law gives the public the right to opt-out. Therefore, the UK has given the public two opportunities to choose through the enactment of special laws to protect public's right to information autonomy. At present, the secondary use of data in the health insurance database does not have a complete legal basis in Taiwan. At the beginning, the data was automatically sent in without asking for everyone’s consent, and there was no way to withdraw when it was used for other purposes, therefore it was s unconstitutional. Hence, in addition to thinking about what kind of provisions to add to the PDPA as a condition for "exception and non-request for cessation of use", whether to formulate a special law on secondary use is also worthy of consideration by the Taiwan government. IV.De-identification According to the relevant regulations of PDPA, there is no definition of "de-identification", resulting in a conceptual gap in the connotation. In other words, what angle or standard should be used to judge that the processed data has reached the point where it is impossible to identify a specific person. In judicial practice, it has been pointed out that for "data recipients", if the data has been de-identified, the data will no longer be regulated by PDPA due to the loss of personal attributes, and it is even further believed that de-identification is not necessary. However, the Judgment No. 13 of Constitutional Court, pointed out that through de-identification measures, ordinary people cannot identify a specific party without using additional information, which can be regarded as personal data of de-identification data. Therefore, the judge did not give an objective standard for de-identification, but believed that the purpose of data utilization and the risk of re-identification should be measured on a case-by-case basis, and a strict review of the constitutional principle of proportionality should be carried out. So far, it should be considered that the interpretation of the de-identification standard has been roughly finalized. V.Conclusions The judge first explained that if personal information is processed, the type and nature of the data can still be objectively restored to indirectly identify the parties, no matter how simple or difficult the restoration process is, if the data is restored in a specific way, the parties can still be identified. personal information. Therefore, the independent control rights of the parties to such data are still protected by Article 22 of the Constitution. Conversely, when the processed data objectively has no possibility to restore the identification of individuals, it loses the essence of personal data, and the parties concerned are no longer protected by Article 22 of the Constitution. Based on this, the judge declared that according to Article 6, Item 1, Proviso, Clause 4 of the PDPA, the health insurance database has been processed so that the specific party cannot be identified, and it is used by public agencies or academic research institutions for medical and health purposes. Doing necessary statistical or academic research complies with the principles of legal clarity and proportionality, and does not violate the Constitution. However, the judge believes that the current personal data law or other relevant regulations still lack an independent supervision mechanism for personal data protection, and the protection of personal information privacy is insufficient. In addition, important matters such as personal health insurance data can be stored, processed, and transmitted externally by the National Health Insurance Administration in a database; the subject, purpose, requirements, scope, and method of providing external use; and organizational and procedural supervision and protection mechanisms, etc. Articles 79 and 80 of the Health Insurance Law and other relevant laws lack clear provisions, so they are determined to be unconstitutional. In the end, the judge found that the relevant laws and regulations lacked the provisions that the parties can request to stop using the data, whether it is the right of the parties to request to stop, or the procedures to be followed to stop the use, there is no relevant clear text, obviously the protection of information privacy is insufficient. Therefore, regarding unconstitutional issues, the Constitutional Court ordered the relevant agencies to amend the Health Insurance Law and related laws within 3 years, or formulate specific laws.