Adopting Flexible Mechanism to Promote Public Procurement of Innovation—the Amendment of Article 27 of the Statute for Industrial Innovation

Adopting Flexible Mechanism to Promote Public Procurement of Innovation—the Amendment of Article 27 of the Statute for Industrial Innovation

I.Introduction

  To further industrial innovation, improve industrial environment, and enhance industrial competitiveness through a systematic long-term approach, the Statute for Industrial Innovation (hereinafter referred to as the Statute) has been formulated in Taiwan. The central government authority of this Statute is the Ministry of Economic Affairs, and the Industrial Development Bureau of the Ministry of Economic Affairs (henceforth referred to as the IDB) is the administrative body for the formulation of this Statute.  Since its formulation and promulgation in 2010, the Statute has undergone four amendments. The latest amendment, passed by the Legislative Yuan on November 3, 2017, on the third reading, is a precipitate of the international industrial development trends. The government is actively encouraging the investment in industrial innovation through a combination of capital, R&D, advanced technologies and human resources to help the promotion of industrial transformation, hence this large scale amendment is conducted. The amendment, promulgated and enacted on November 22, 2017, focuses on eight key points, which include: state-owned businesses partaking in R&D (Article 9-1 of the amended provisions of the Statute), the tax concessions of the limited partnership venture capital businesses (Article 2, Article 10, Article 12-1 and Article 23-1 of the amended provisions of the Statute), the tax concessions of Angel Investors (Article 23-2 of the amended provisions of the Statute), applicable tax deferral of employees' stock compensation (Article 19-1 of the amended provisions of the Statute), tax deferral benefit of stocks given to research institution creators (Article 12-2 of the amended provisions of the Statute), the promotion of flexible mechanism for innovation procurement (Article 27 of the amended provisions of the Statute), the establishment of evaluation mechanism for intangible assets (Article 13 of the amended provisions of the Statute), and forced sale auction of idled land for industrial use (Article 46-1 of the amended provisions of the Statute).  This paper focuses on the amendment of Article 27 of the Fourth Revision of the Statute, which is also one of the major focuses of this revision—promoting flexible mechanism for innovation procurement, using the mass-market purchasing power of the government as the energetic force for the development of industrial innovation. 

II.Explanation of the Amendment of Article 27 of the Statute

1.Purposes and Descriptions of the Amendment of Article 27 of the Statute

  The original intent of Article 27 (hereinafter referred to as the Article) of the Statute, prior to the latest amendment (content of the original provisions is shown in Table 1), was to encourage government agencies and enterprises to give a priority to using green products through the "priority procurement" provisions of Paragraph 2, which allow government agencies to award contracts to green product producers using special government procurement procedures, so as to increase the opportunities for government agencies to use green products, and thereby promote the sustainable development of the industry. In view of the inherent tasks of promoting the development of industrial innovation, and considering that, using the large-scale government procurement demand to guide industrial innovation activities, has become the policy instrument accepted by most advanced countries, the IDB expects that, with the latest amendment of Article 27, the procurement mechanism policy for software, innovative products and services, in addition to the original green products, may become influential, and that "innovative products and services" may be included in the scope of "Priority Procurement" of this Article namely, make “priority procurement of innovative products and services” as one of the flexible mechanisms for promoting innovation procurement.  A comparison of the amended provisions and the original provisions is shown in Table 1, and an explanation of the amendment is described as follows:[1]

Table 1 A Comparison of Article 27 Amendment of the Statute for Industrial Innovation

Amended Provisions

Original Provisions

Article 27

  (I) Each central government authority in charge of end enterprises of a specific industry shall encourage government organizations (agencies) and enterprises to procure software, innovative and green products or services.

  (II) To enhance the procurement efficiencies, as effected by supply and demand, the central government authority shall offer assistance and services to the organizations (agencies) that handle these procurements as described in the preceding paragraph; wherein, Inter-entity Supply Contracts that are required for the aforesaid procurements, the common requirements shall be decided, in accordance with policy requirements, upon consultation between the central government authority and each central government authority in charge of end enterprises of a specific industry.   

  (III) Where the software, innovative and green products or services, as described in Paragraph 1, must be tested, audited, accredited and certified, their associated fees and charges may be reduced, exempted, or suspended.

  (IV) Government organizations (agencies) may specify in the tender document the priority procurement of innovative and green products or services that have been identified to meet the requirements of paragraph 1. However, such a specification shall not violate treaties or agreements that have been ratified by the Republic of China.

  The measures concerning specifications, categories, and identification procedures of software, innovative and green products or services as prescribed in Paragraph 1; the testing, auditing criteria, accreditation and certification as prescribed in paragraph 3; and the Priority Procurement in paragraph 4 and other relevant items, shall be established by each central government authority in charge of end-enterprises of a specific industry. 

Article 27

  (I) Each central government authority in charge of end enterprises shall encourage government agencies and enterprises to give priority to green products that are energy/resources recyclable/renewable, energy and water saving, non-toxic, less-polluting, or able to reduce the burden on the environment.

  (II) Agencies may specify in the tender documents that priority is given to green products meeting the requirement set forth in the preceding Paragraph.

  (III) The regulations governing the specifications, categories, certification procedures, review standards, and other relevant matters relating to the green products as referred to in the preceding Paragraph shall be prescribed by the central government authorities in charge of end enterprises.

Source: The Ministry of Economic Affairs

(I).Paragraph 1

  In order to compel each central government authority in charge of end enterprises of a specific industry to motivate industrial innovation activities and sustainable development on the basis of requirements, and to support the development of the software industry in Taiwan, the provision, that such an authority should encourage government organizations (agencies) and enterprises to procure software and innovative products and services, is added in paragraph 1.

(II).Paragraph 2

  This procurement, as described in paragraph 1, is different from the property or services procurement of general affairs as handled by various organizations. To enhance procurement efficiencies, as effected by supply and demand, the central government authority, i.e., the Ministry of Economic Affairs, shall provide relevant assistance and services to organizations (agencies) handling these procurements, hence the added provisions in paragraph 2. For purchases using inter-entity supply contracts, which are bound by the requirements of this Article, due to their prospective nature, and that the common demand of each organization is difficult to make an accurate estimate by using a demand survey or other method, the Ministry of Economic Affairs shall discuss the issues with each central government authority in charge of end-enterprises of a specific industry, who consult or promote policies, and are in charge of end enterprises of a specific industry, and then make decisions in accordance with the policy promotion requirements. 

(III).Paragraph 3

  The fee schedule for testing, auditing, accrediting and certifying software, innovative and green products or services is covered by Article 7, Administrative Fees of the Charges And Fees Act. The authorities in charge should determine relevant fee standards.However, considering that the test, audit, accreditation and certification may be conducted during a trial or promotional period, or circumstances dictate that it is necessary to motivate tenderer participation, the fee may be reduced, waived or suspended; hence, paragraph 3 is added.

(IV).Paragraph 4

  Paragraph 2 of the original provision is moved to paragraph 4 with the revisions made to paragraph 1, accordingly, and the provision for using Priority Procurement to handle innovative products or services is added. However, for organizations covered by The Agreement on Government Procurement (GPA), due to Taiwan's accession to the WTO, ANZTEC, and ASTEP, their procurement of items covered in the aforesaid agreements with a value reaching the legislated threshold, shall be handled in accordance with the regulations stipulated in the aforesaid agreements; hence the stipulation in the proviso that the procurement must not violate the provisions of treaties or agreements ratified by the Taiwan government.

(V).Paragraph 5

  Paragraph 3 of the original Article is moved to paragraph 5 with the revisions made to paragraph 1, accordingly, and the provision, that authorizes each central government authority in charge of end enterprises of a specific industry to determine appropriate measures concerning the methods of defining software, innovative and green products and services, as well as matters relating to test, accreditation, certification and priority procurement, is added.

2.The Focus of the Amendment of Article 27 of the Statute—Promoting a Flexible Mechanism for Innovation Procurement

  As previously stated, the amendment of this Article aims to stimulate activities of industrial innovation by taking advantage of the huge demand from government agencies. With the government agencies being the users of the innovative products or services, government's procurement market potential is tapped to support the development of industrial innovation. The original intention of amendment is to incorporate the spirit of Public Procurement of Innovation[2] into this Article, and to try to introduce EU's innovation procurement mechanism[3] into our laws. So that, a procurement procedure, that is more flexible and not subject to the limitation of procurement procedures currently stipulated by the Government Procurement Act, may be adopted to facilitate government sector action in taking the lead on adopting innovative products or services that have just entered their commercial prototype stage, or utilizing the demand for innovation in the government sector to drive industry's innovative ideas or R&D (that can not be satisfied with the existing solutions in the marketplace).  However, while it is assessing the relevant laws and regulations of our government procurement system and the practice of implementation, the use of the current government procurement mechanism by organizations in the public sector to achieve the targets of innovation procurement is still in its infancy. It is difficult to achieve the goal, in a short time, of establishing a variety of Public Procurement of Innovation Solutions (PPI Solutions) as disclosed in the EU's Directive 2014/24 / EU, enacted by the EU in 2014, in ways that are not subject to current government procurement legislation.  Hence, the next best thing: Instead of setting up an innovative procurement mechanism in such a way that it is "not subject to the restrictions of the current government procurement law", we will focus on utilizing the flexible room available under the current system of government procurement laws and regulations, and promoting the "flexible mechanism for innovation procurement” paradigm. With the provisions now provided in Article 27 of the Statute for Industrial Innovation, the government sector is authorized to adopt the "Priority Procurement" method on innovative products and services, thus increasing the public sector's access to innovative products and services.

  With this amendment, in addition to the "green products" listed in the original provisions of paragraph 1 of the Statute, "software" and "innovative products or services"[4] are now incorporated into the target procurement scope and each central government authority in charge of end enterprises of a specific industry should now encourage government organizations and enterprises to implement; however, the provisions of this paragraph do not have the specific effect of law, they are declaratory provisions.  Two priorities are the1 primary focus of the provisions of paragraph 2 and paragraph 4 of this Article for promoting flexible mechanism for innovation procurement:

(I)The procurement of software, innovative and green products or services that uses Inter-entity Supply Contracts may rely on the "policy requirement" to establish the common demand.

  According to the first half of the provisions of paragraph 2 of this Article, the Ministry of Economic Affairs, being the central government authority of the Statute, may provide assistance and services to organizations dealing with the procurement of software, innovative and green products and services.This is because the procurement subjects, as pertaining to software, products or services that are innovative and green products (or services), usually have the particularities (especially in the software) of the information professions; different qualities (especially in innovative products or services), and are highly profession-specific. They are different from the general affairs goods and services procured by most government agencies. Hence, the Ministry of Economic Affairs may provide assistance and service to these procurement agencies, along with the coordination of relevant organizations, in matters relating to the aforesaid procurement process in order to improve procurement efficiency as relates to supply and demand.

  Pursuant to the second half of Paragraph 2 of this Article, if the inter-entity supply contract method is used to process the procurement of software, innovative products and services, green products (or services) and other related subjects, there could be "Commonly Required" by two or more organizations concerning the procurement subjects, so in accordance with the stipulations of Article 93 of the Government Procurement Act, and Article 2 of the Regulations for The Implementation of Inter-entity Supply Contracts[5], an investigation of common requirements should be conducted first. However, this type of subject is prospective and profession-specific (innovative products or services in particular), and government organizations are generally not sure whether they have demand or not, which makes it difficult to reliably estimate the demand via the traditional demand survey method[6], resulting in a major obstacle for the procurement process. Therefore, the provisions are now revised to allow the Ministry of Economic Affairs to discuss procurement with each central government authority in charge of end enterprises of a specific industry, who consult or promote policies (such as the National Development Council, or central government authority in charge of end enterprises of a specific industry relevant to the procurement subjects), and then make decisions based on the quantities of goods and services of common requirements in accordance with the demand for promoting the policy. The provisions explicitly stipulate such flexibility in adopting methods other than the "traditional demand survey" method, as is required by laws for the common demand of Inter-entity Supply Contracts. Thus, agencies currently handling procurement of prospective or innovative subjects using inter-entity supply contracts, may reduce the administrative burden typically associated with conducting their own procurement. In addition, with a larger purchase quantity demand, as generated from two or more organizations, the process can more effectively inject momentum into the industry, and achieve a win-win situation for both supply and demand.

(II)Government organizations may adopt "Priority Procurement" when handling procurement of innovative and green products or services.

  Prior to the amendment, the original provision of paragraph 2 of this Article stipulates that organizations may specify in the tender document Priority Procurement of certified green products; Additionally, a provision of paragraph 3 of the original Article stipulates that each central government authority in charge of end enterprises of a specific industry is authorized to establish the specifications, categories and other relevant matters of the green products[7] (according to the interpretation of the original text, it should include "Priority Procurement" in paragraph 3 of the Article).After the amendment of the Article, paragraph 2 of the original Article is moved to paragraph 4. In addition to the original green products, "innovative products or services" are included in the scope of "Priority Procurement" that organizations are permitted to adopt (but, the "software" in paragraph 1 was not included[8]). However, for organizations covered by The Agreement on Government Procurement (GPA), due to Taiwan's accession to the WTO, ANZTEC, and ASTEP, their procurement of items covered by the aforesaid agreements with a value reaching the stated threshold, shall be handled in accordance with the regulations stipulated in the aforesaid agreements; hence the stipulation in the proviso that the procurement must not violate the provisions in treaties or agreements ratified by the Taiwan government. Additionally, paragraph 3 of the original Article is moved to paragraph 5. Each central government authority in charge of end enterprises of a specific industry is authorized to use their own judgment on matters concerning the specifications, categories, certification processes of software, innovative and green products or services and the method for Priority Procurement of paragraph 4.

  In accordance with the authorization in paragraph 5 of the amended provision of this Article, each central government authority in charge of end enterprises of a specific industry may, depending on the specific policy requirement that promotes innovation development of its supervised industry, establish methods of identification and the processes of Priority Procurement for “Specific categories of innovative products or services", especially on products or services fitting the requirements of the method of using the demands of government organizations to stimulate industrial innovation. The established "Regolations for priority procurement of Specific categories of innovative products or services" is essentially a special regulation of the government procurement legislation, which belongs to the level of regulations, that is, it allows the organizations to apply measures other than the government procurement regulations and its related measures to the procurement process, and adopt "Preferential Contract Awarding" for qualified innovative products or services.  Any government agency that has the need to procure a particular category of innovative product or service may, in accordance with the provisions of paragraph 4 of this Article, specify the use of Priority Procurement in the tender document, and administer the procurement, in accordance with the process of this particular category of innovative products, or priority procurement. The agency is now enabled to follow a more flexible procurement process than that of the government procurement regulations to more smoothly award contracts for qualified innovative products or services. 

  Citing two examples of this applied scenario: Example one, "innovative information services": The central government authority in charge of information services is IDB. Thus, IDB may, according to the authorization provided for in paragraph 5 of the Article, establish the identification methods for innovative information services (the purpose of which is to define the categories and specifications of innovative services covered in the scope of priority procurement) and priority procurement processes, pertaining to emerging information services that are more applicable to the requirements of government agencies, such as: cloud computing services, IoT services, and Big Data analysis services.Example two, "Innovative construction or engineering methods": The central government authority in charge of construction affairs is the Construction and Planning Agency of the Ministry of the Interior. Since the agency has already established the "Guidelines for Approval of Applications for New Construction Techniques, Methods, Equipment and Materials", the agency may establish a priority procurement process for new construction techniques, methods or equipment, in accordance with the stipulations in paragraph 5 of the Article. Government agencies may conduct procurement following any of these priority procurement practices, if there is a requirement for innovative information services, or new construction techniques, methods or equipment.

  In addition to the two aforementioned flexible mechanisms for innovation procurement, where government agencies are granted flexible procedures to handle the procurement of innovative products or services via the use of the flexible procurement mechanism, paragraph 3, concerning the incentive measures of concessionary deductions, is added to the Article to reduce the bidding costs for tenderers participating in the tender.  For the Procurement of software, innovative and green products or services encouraged by each central government authority in charge of end-enterprises of a specific industry (not limited to those handled by the authorities themselves, using inter-entity supply contracts or priority procurement methods), if the procurement subjects are still required to be tested, audited, accredited and certified by the government agencies, such a process falls under the scope of administrative fees collection, pursuant to paragraph 1 Article 7 of the Charges And Fees Act. However, considering that the item subject to test, audit, accreditation and certification may be in a trial or promotional period, or that it may be necessary to motivate tenderer participation, the provisions of paragraph 3 are thusly added to the Article to reduce, waive, or suspend the collection of aforementioned fees. Executive authorities in charge of collecting administrative fees shall proceed to reduce, waive, or suspend the collection pursuant to the stipulations of paragraph 3 of the Article and Article 12 subparagraph 7 of the Charges And Fees Act.[9]

III.The direction of devising supporting measures of flexible mechanism for innovation procurement

  The latest amendment of the Statute for Industrial Innovation was promulgated and enacted on November 22, 2017, it is imperative that supporting measures pertaining to Article 27 of the Statute be formulated. As previously stated, the flexible mechanism for innovation procurement, as promoted in this Article, is designed specifically for the products or services that are pertinent to the government procurement requirements and are capable of stimulating industrial innovation, and providing a more flexible government procurement procedure for central authorities in charge of a specific industry as a policy approach in supporting industry innovation. Thus, the premise of devising relevant supporting measures is dependent on whether the specific industry, as overseen by the particular central authority, has a policy in place for promoting the development of industrial innovation, and on whether it is suitable in promoting the flexible mechanism for innovation procurement as described in this Article.

  The purpose of this Article is to promote the flexible mechanism for innovation procurement. Supporting measures pertaining to this Article will focus on the promotion of devising an "Innovation Identification Method", and of the "Priority Procurement Process" of the innovative products or services of each industry that central government authorities oversee. The former will rely on each central government authority in charge of a specific industry to charter an industry-appropriate and profession-specific planning scheme; while, for the latter, the designing of a priority procurement process, in accordance with the nature of the various types of innovative products or services, does not have to be applicable to all.  However, regardless what type of innovative products or services the priority procurement process is designed for, the general direction of consideration should be given to - taking the different qualities of innovative products or services as the core consideration. Additionally, the attribute of the priority procurement procedures focusing specifically on the different qualities of the innovative subjects relates to the special regulation relevant to the government procurement regulations. Thus, the procurement procedures should follow the principle that if no applicable stipulation is found in the special regulation, the provisions of the principal regulation shall apply.

  The so-called "Priority Procurement" process refers to the "Preferential Contract Awarding" on tenders that meet certain criteria in a government procurement procedure.  The existing Government Procurement Act (GPA, for short) and its related laws that have specific stipulations on "Priority Procurement" can be found in the "Regulations for Priority Procurement of Eco-Products" (Regulations for Eco-Products Procurement, for short), and the "Regulations for Obliged Purchasing Units / Institutions to Purchase the Products and Services Provided by Disabled Welfare Institutions, Organizations or Sheltered Workshops" (Regulations for Priority Procurement of Products or Services for Disabled or Shelters, for short). After studying these two measures, the priority procurement procedures applicable to criteria-conformed subjects can be summarized into the following two types:

1.The first type: Giving preferential contract awarding to the tenderer who qualifies with "the lowest tender price”, as proposed in the tender document, and who meets a certain criteria (for example, tenderers of environmental products, disabled welfare institutions, or sheltered workshops).  There are two scenarios: When a general tenderer and the criteria-conformed tenderer both submit the lowest tender price, the criteria-conformed tenderer shall obtain the right to be the "preferential winning tender" without having to go through the Price Comparison and Reduction Procedures. Additionally, if the lowest tender price is submitted by a general tenderer, then the criteria-conformed tenderers have the right to a "preferential price reduction” option, that is, the criteria-conformed tenderers can be contacted, in ascending order of the tender submitted, with a one time option to reduce their bidding prices. The first tenderer who reduces their price to the lowest amount shall win the tender. Both the Regulations for Eco-Products Procurement[10] and Regulations for Priority Procurement of Products or Services for Disabilities or Shelters[11] have such relevant stipulations. 

2.The second type: It is permitted to give Preferential Contract Awarding to a criteria-conformed tenderer, when the submitted tender is within the rate of price preference.  When the lowest tenderer is a general tenderer, and the tender submitted by the criteria-conformed tenderer is higher than the lowest tender price, the law permits that if the tender submitted is "within the rate of price preference ", as set by the procuring entity, the procuring entity may award the contract preferentially to "the tender submitted by the criteria-conformed tenderer." The premise for allowing this method is that the tender submitted by the criteria-conformed tenderer must be within the preferential price ratio. If the submitted tender is higher than the preferential price ratio, then the criteria-conformed tenderer does not have the right to preferential contract awarding. The contract will be awarded to theother criteria-conformed tenderer, or to a general tenderer.  This method is covered in the provisions of the Regulations for Eco-Products Procurement[12].

  However, the important premise for the above two priority procurement methods is that the nature of the subject matter of the tender is suitable for adopting the awarding principle of the lowest tender (Article 52, Paragraph 1, Subparagraphs 1 and 2 of the Procurement Act), that is, it is difficult to apply these methods to the subjects if they are different qualities. Pursuant to the provisions of Article 66 of the Enforcement Rules of the Government Procurement Act, the so-called "different qualities" refers to the construction work, property or services provided by different suppliers that are different in technology, quality, function, performance, characteristics, commercial terms, etc. Subjects of different qualities are essentially difficult to compare when based on the same specifications. If just looking at pricing alone it is difficult to identify the advantages and disadvantages of the subjects, hence, the awarding principle of the lowest tender is not appropriate. The innovative subjects are essentially subjects of different qualities, and under the same consideration, they are not suitable for applying the awarding principle of the lowest tender. Therefore, it is difficult to adopt the lowest-tender-based priority procurement method for the procurement of innovative subjects.

  In the case of innovative subjects with different qualities, the principle of the most advantageous tender should be adopted (Article 52 Paragraph 1 Subparagraph 3 of the Procurement Act) to identify the most qualified vender of the subjects through open selection. Therefore, the procedure for the priority procurement of innovative subjects with different qualities should be based on the most advantageous tender principle with focus on the "innovativeness" of the subjects, and consideration on how to give priority to tenderers, who qualify with the criteria of innovation. Pursuant to the provisions of Article 56 Paragraph 4 of the Procurement Act, the Procurement and Public Construction Commission has established the "Regulations for Evaluation of the Most Advantageous Tender". The tendering authorities adopting the most advantageous tender principle should abide by the evaluation method and procedures delineated in the method, and conduct an open selection of a winning tender. According to the Regulations for Evaluation of the Most Advantageous Tender, in addition to pricing, the tenderers' technology, quality, function, management, commercial terms, past performance of contract fulfillment, financial planning, and other matters pertaining to procurement functions or effectiveness, maybe chosen as evaluation criteria and sub-criteria. According to the three evaluation methods delineated in the provisions of Article 11 of the Regulations for Evaluation of the Most Advantageous Tender (overall evaluation score method, price per score point method, and ranking method), pricing could not been included in the scoring. That is, "the prices of the subjects" is not the absolute criterion of evaluation of the most advantageous tender process.

  The priority procurement procedures designed specifically for innovative subjects with different qualities may adopt an evaluation method that excludes "pricing" as part of the scoring criterion so as to give innovative subject tenderers the opportunity to be more competitive in the bidding evaluation process, and due to the extent of their innovativeness, obtain the right to preferential tenders. If it must be included in the scoring, the percentage of the total score for pricing should be reduced from its usual ratio[13], while stipulating explicitly that "innovation" must be included as part of the evaluation criteria. In addition, its weight distribution should not be less than a ratio that highlights the importance of innovation in the evaluation criteria.  Furthermore, when determining how to give preference to tenderers who meet certain innovation criteria in the contract awarding procedures, care should be taken to stay on focus with the degree of innovation of the subject (the higher the degree of innovation, the higher the priority), rather than giving priority to arbitrary standards. In summary, with consideration of priority procurement procedures designed specifically for innovative subjects with different qualities, this paper proposes the following preliminary regulatory directions:

1.Adopt the awarding principle of the most advantageous tender.

2.Explicitly stipulate the inclusion of "innovation" in the evaluation criteria and sub-criteria, and its ratio, one that indicates its importance, should not be less than a certain percentage of the total score (for example 20%).

3.Reduce the distributed ratio of "price" in the scoring criteria in the open selection.

4.After the members of the evaluation committee have concluded the scoring, if more than two tenderers have attained the same highest overall evaluated score or lowest quotient of price divided by overall evaluated score, or more than two tenderers have attained the first ranking, the contract is awarded preferentially to the tenderer who scores the highest in the "innovation" criterion.

5.When multiple awards (according to Article 52 Paragraph 1 Subparagraph 4 of the Procurement Act) are adopted, that is, there is more than one final winning tender, the procuring entity may select the tenderers with higher innovation scores as the price negotiation targets for contract awarding, when there are more than two tenderers with the same ranking.

  Using the above method to highlight the value of innovative subjects will make these suppliers more competitive, because of their innovativeness ratings in the procurement procedures, and not confine them to the limitation of price-determination.  So that, subject suppliers with a high degree of innovation, may attain the right to the preferential contract awarding that they deserve due to their innovativeness, and the procuring entity can purchase suitable innovative products in a more efficient and easy process. It also lowers the threshold for tenderers with innovation energy to enter the government procurement market, thus achieving the goal of supporting industrial innovation and creating a win-win scenario for supply and demand.


[1] Cross-reference Table of Amended Provisions of the Statute for Industrial Innovation, The Ministry of Economic Affairs, https://www.moea.gov.tw/MNS/populace/news/wHandNews_File.ashx?file_id=59099 (Last viewed date: 12/08/2017).

[2] According to the Guidance for public authorities on Public Procurement of Innovation issued by the Procurement of Innovation Platform in 2015, the so-called innovation procurement in essence refers to that the public sector can obtain innovative products, services, or work  by using the government procurement processes, or that the public sector can administer government procurement with a new-and-better process. Either way, the implementation of innovation procurement philosophy is an important link between government procurement, R & D and innovation, which shortens the distance between the foresighted emerging technologies/processes and the public sector/users.

[3] The EU's innovative procurement mechanism comprises the "Public Procurement of Innovation Solutions" (PPI Solutions) and "Pre-Commercial Procurement" (PCP). The former is one of the government procurement procedures, explicitly regulated in the new EU Public Procurement Directive (Directive 2014/24 / EU), for procuring solutions that are innovative, near or in preliminary commercial prototype; The latter is a procurement process designed to assist the public sector in obtaining technological innovative solutions that are not yet in commercial prototype, must undergo research and development process, and are not within the scope of EU Public Procurement Directive.

[4] The "software, innovative and green products or services", as described in paragraph 1 of Article 27 of the amended Statute for Industrial Innovation, refers to, respectively, "software", "innovative products or services", and "green products or services" in general. There is no co-ordination or subordination relationship between the three; the same applies to "innovative and green products or services" in paragraph 4.

[5] Article 93 of the Government Procurement Act stipulates: "An entity may execute an inter-entity supply contract with a supplier for the supply of property or services that are commonly needed by entities." Additionally, Article 2 of the Regulations for The Implementation of Inter-entity Supply Contracts stipulates: "The term 'property or services that are commonly needed by entities' referred to in Article 93 of the Act means property or services which are commonly required by two or more entities. The term 'inter-entity supply contract (hereinafter referred to as the “Contract”)' referred to in Article 93 of the Act means that an entity, on behalf of two or more entities, signs a contract with a supplier for property or services that are commonly needed by entities, so that the entity and other entities to which the Contract applies can utilize the Contract to conduct procurements." Therefore, according to the interpretation made by the Public Construction Commission, the Executive Yuan (PCC, for short), organizations handling inter-entity supply contracts should first conduct a demand investigation.

[6] In general, organizations in charge of handling the inter-entity supply contracts will disseminate official documents to applicable organizations with an invitation to furnish information online about their interests and estimated requirement (for budget estimation) at government's e-procurement website. However, in the case of more prospective subjects (such as cloud services of the emerging industry), it may be difficult for an organization to accurately estimate the demand when filling out the survey, resulting in a mismatch of data between the demand survey and actual needs.

[7] In accordance with the authorization of paragraph 3 of the Article, the IDB has established "Regulations Governing Examination and Identification of Advanced Recycled Products by Ministry of Economic Affairs" (including an appendix: Identification Specification for Resource Regenerating Green Products), except that the priority procurement process was not stipulated, because the Resource Regenerating Green Products, that meet the requirements of the Ministry of Economic Affairs, are covered by the "Category III Products" in the provisions of Article 6 of the existing "Regulations for Priority Procurement of Eco-Products", set forth by the PPC and The Environmental Protection Administration of the Executive Yuan. Hence, organizations that have the requirement to procure green products, may proceed with priority procurement by following the regulations in the "Regulations for Priority Procurement of Eco-Products".     

[8] After the amendment of the Article, the "software" in the provisions of paragraph 1 was excluded in paragraph 4, because the objective of paragraph 4 is to promote industry innovation and sustainable development with the use of a more flexible government procurement procedure. Thus, the subjects of the priority procurement mechanism are focused on "innovative" and "green" products or services, which exclude popular "software" that has a common standard in the market. However, if it is an "innovative software", it may be included in the "innovative products or services" in the provisions of paragraph 4.

[9] According to the provisions of Article 12 of the Charges And Fees Act: "In any of the following cases, the executive authority in charge of the concerned matters may waive or reduce the amount of the charges and fees, or suspend the collection of the charges and fees: 7. Waiver, reduction, or suspension made under other applicable laws."

[10] Refer to Article 12, Paragraph 1, Subparagraphs 1 and Article 13, Paragraph 1 and 2 of Regulations for Priority Procurement of Eco-Products.

[11] Refer to Article 4 of Regulations for Obliged Purchasing Units / Institutions to Purchase the Products and Services Provided by Disabled Welfare Institutions, Organizations or Sheltered Workshops.

[12] Refer to Article 12, Paragraph 1, Subparagraphs 2 and Article 13, Paragraph 3 of Regulations for Priority Procurement of Eco-Products.

[13] The provisions of paragraph 3 Article 16 of the Regulations for Evaluation of the Most Advantageous Tender stipulates: Where price is included in scoring, its proportion of the overall score shall be not less than 20% and not more than 50%.

※Adopting Flexible Mechanism to Promote Public Procurement of Innovation—the Amendment of Article 27 of the Statute for Industrial Innovation,STLI, https://stli.iii.org.tw/en/article-detail.aspx?no=55&tp=2&i=168&d=7969 (Date:2024/04/25)
Quote this paper
You may be interested
New Version of Personal Information Protection Act and Personal Information Protection & Administration System

I.Summary In 1995, the Computer-Processed Personal Data Protection Law was implemented in the Republic of China. With the constant development of information technology and the limitations in the application of the legislation, the design of the original legal system is no longer consistent with practical requirements. Considering the increasing number of incidents of personal data leaks, discussions were carried out over a long period of time and the new version of the Personal Information Protection Act was passed after three readings in April, 2010. The title of the law was changed to Personal Information Protection Act. The new system has been officially implemented since 1 October, 2012. The new Act not only revised the provisions of the law in a comprehensive way, but also significantly increased the obligations and responsibilities of enterprises. In terms of civil liability, the maximum amount of compensation for a single incident is 200 Million NTD. For domestic industries, how to effectively respond to the requirements under the Personal Information Protection Act and adopt proper corresponding measures to lower the risk has become a key task for enterprise operation. II. Main Points 1. Implementation of the Enforcement Rules of the Personal Information Protection Act Personal information protection can be said the most concerned issue in Taiwan recently. As a matter of fact, the Computer-Processed Personal Data Protection Law was established in Taiwan as early as August 1995. After more than 10 years of development, computer and information technology has evolved significantly, and many emerging business models such as E-commerce are extensively collecting personal data. It has become increasingly important to properly protect personal privacy. However, the previous Computer-Processed Personal Data Protection Law was only applicable to certain industries, i.e. the following 8 specific industries: the credit investigation business, hospital, school, telecommunication business, financial business, securities business, insurance business, and mass media. And other business was designated by the Ministry of Justice and the central government authorities in charge of concerned enterprises. In addition, the law only protected personal information that was processed by “computer or automatic equipment”. Personal information that was not computer processed was not included. There were clearly no sufficient regulations for the protection of personal data privacy and interest. There were numerous incidents of personal data leaks. Among the top 10 consumer news issued by the Consumer Protection Committee of the Executive Yuan in 2007, “incidents of personal data leaks through E-commerce and TV shopping” was on the top of the list. This provoked the Ministry of Justice and the Ministry of Economic Affairs to “jointly designate” the retail industry without physical boutique (including 3 transaction models: online shopping, catalogue shopping and TV shopping) to be governed by the Computer-Processed Personal Data Protection Law since 1 July 2010. To allow the provisions of the personal information protection legal system to meet the environment of rapid change, the Executive Yuan proposed a Draft Amendment to the Computer-Processed Personal Data Protection Law very early and changed the title to the Personal Information Protection Act. The draft was discussed many times in the Legislative Yuan. Personal Information Protection Act was finally passed after three readings in April 2010, which was officially published by the Office of the President on 26 May. Although the new law was passed in April 2010, to allow sufficient time for enterprises and the public to understand and comply the new law, the new version of the personal information protection law was not implemented on the date of publication. In accordance with Article 56 of the Act, the date of implementation was to be further established by the Executive Yuan. After discussions over a long period of time, the Executive Yuan decided for the Personal Information Protection Act to be officially implemented on 1 October 2012. However, the implementation of two articles is withheld: Article 6 of the Act about the principal prohibition against the collection, processing and use of special personal information and Article 54 about the obligation to notice the Party within one year for personal information indirectly acquired before the implementation of the new law. In terms of the personal data protection legal system, other than the most important Personal Data Protection Act, the enforcement rules established in accordance with the main law also play a key role. The previous Enforcement Rules of the Computer-Processed Personal Data Protection Law were published and implemented on 1 May, 1996. Considering that the Computer-Processed Personal Data Protection Law was amended in 2010 and that its title has been changed to the Personal Data Protection Act, the Ministry of Justice also followed the amended provisions under the new law and actively studied the Draft Amendment to the Enforcement Rules of the Computer-Processed Personal Data Protection Act. After it was confirmed that the new version of the Personal Data Protection Act would be officially launched on 1 October 2012, the Ministry of Justice announced officially the amended enforcement rules on 26 September, 2012. The title of the enforcement rules was also amended to the Enforcement Rules of the Personal Data Protection Act. The new version of personal data protection law and enforcement rules was thus officially launched, creating a brand new era for the promotion of personal data protection in Taiwan. II. Personal Data Administration System and Information Privacy Protection Charter Before the amendment to the Personal Data Protection Act was passed, the Legislative Yuan made a proposal to the government in June 2008 to promote a privacy administration and protection certification system in Taiwan, in reference to foreign practices. In August of the following year, the Strategic Review Board of the Executive Yuan passed a resolution to promote the E-Commerce Personal Data Administration and Information Security Action Plan. In December of the same year, approval was granted for the plan to be included in the key government promotion plans from 2010 to 2013. Based on this action plan, since October 2010, the Ministry of Economic Affairs has asked the Institution for Information Industry to execute an E-Commerce Personal Data Administration System Setup Plan. Since 2012, the E-Commerce Personal Data Administration System Promotion Plan and the Taiwan Personal Information Protection and Administration System (TPIPAS) have been established and promoted, with the objective of procuring enterprises to, while complying with the personal data protection legal system, properly protect consumers’ personal information through the establishment of an internal administration mechanism and ensuring that the introducing enterprises meet the requirements of the system. The issuance of the Data Privacy Protection Mark (dp.mark) was also used as an objective benchmark for consumers to judge the enterprise’s ability to maintain privacy. Regarding the introduction of the personal data administration system, enterprises should establish a content administration mechanism step by step in accordance with the Regulations for Taiwan Personal Information Protection and Administration System. Such system also serves as the review benchmark to decide whether domestic enterprises can acquire the Data Privacy Protection Mark (dp.mark). Since domestic enterprises did not have experience in establishing internal personal data administration system in the past, starting 2011, under the Taiwan Personal Information Protection and Administration System, enterprises received assistance in the training of system professionals such as Personal Data Administrators and Personal Data Internal Appraisers. Quality personal data administrators can help enterprises establish complete internal systems. Internal appraisers play the role of confirming whether the systems established by the enterprises are consistent with the system requirements. As of 2012, there are almost 100 enterprises in Taiwan that participate in the training of system staff and a total of 426 administrators and 131 internal appraisers. In terms of the introduction of TPIPAS, in additional to the establishment and introduction of administration systems by qualified administrators, enterprises can also seek assistance from external professional consulting institutions. Under the Taiwan Personal Information Protection and Administration System, applications for registration of consulting institutions became available in 2012. Qualified system consulting institutions are published on the system website. Today 9 qualified consulting institutions have completed their registrations, providing enterprises with personal data consulting services. After an enterprise completes the establishment of its internal administration system, it may file an application for certification under the Taiwan Personal Information Protection and Administration System. The certification process includes two steps: “written review” and “site review”. After the enterprise passing certification, it is qualified to use the Data Privacy Protection Mark (dp.mark). Today 7 domestic companies have passed TPIPAS certification and acquired the dp.mark: 7net, FamiPort, books.com.tw, LOTTE, GOHAPPY, PAYEASY and Sinya Digital, reinforcing the maintenance of consumer privacy information through the introduction of personal data administration system. III. Event Analysis The Taiwan Personal Information Protection and Administration System (TPIPAS) is a professional personal data administration system established based on the provisions of the latest version of the domestic Personal Data Protection Act, in reference to the latest requirements of personal data protection by international organizations and the experience of main countries in promoting personal data administration system. In accordance with the practical requirements to protect personal data by industries, TPIPAS converted professional legal conditions into an internal personal data administration procedure to effectively assist industries to establish a complete and proper personal data administration system and to comply with the requirements of personal data legislations. With the launch of the new version of the Personal Data Protection Act, introducing TPIPAS and acquiring dp.mark are the best strategies for enterprises to lower the risk from the personal data protection law and to upgrade internal personal data administration capability.

The Institutionalization of the Taiwan Personal Data Protection Committee - Triumph of Digital Constitutionalism: A Legal Positivism Analysis

The Institutionalization of the Taiwan Personal Data Protection Committee - Triumph of Digital Constitutionalism: A Legal Positivism Analysis 2023/07/13 The Legislative Yuan recently passed an amendment to the Taiwan Personal Data Protection Act, which resulted in the institutionalization of the Taiwan Personal Data Protection Commission (hereunder the “PDPC”)[1]. This article aims to analyze the significance of this institutionalization from three different perspectives: legal positivism, digital constitutionalism, and Millian liberalism. By examining these frameworks, we can better understand the constitutional essence of sovereignty, the power dynamics among individuals, businesses, and governments, and the paradox of freedom that the PDPC addresses through governance and trust. I.Three Layers of Significance 1.Legal Positivism The institutionalization of the PDPC fully demonstrates the constitutional essence of sovereignty in the hands of citizens. Legal positivism emphasizes the importance of recognizing and obeying (the sovereign, of which it is obeyed by all but does not itself obey to anyone else, as Austin claims) laws that are enacted by legitimate authorities[2]. In this context, the institutionalization of the PDPC signifies the recognition of citizens' rights to control their personal data and the acknowledgment of the sovereign in protecting their privacy. It underscores the idea that the power to govern personal data rests with the individuals themselves, reinforcing the principles of legal positivism regarding sovereign Moreover, legal positivism recognizes the authority of the state in creating and enforcing laws. The institutionalization of the PDPC as a specialized commission with the power to regulate and enforce personal data protection laws represents the state's recognition of the need to address the challenges posed by the digital age. By investing the PDPC with the authority to oversee the proper handling and use of personal data, the state acknowledges its responsibility to protect the rights and interests of its citizens. 2.Digital Constitutionalism The institutionalization of the PDPC also rebalances the power structure among individuals, businesses, and governments in the digital realm[3]. Digital constitutionalism refers to the principles and norms that govern the relationship between individuals and the digital sphere, ensuring the protection of rights and liberties[4]. With the rise of technology and the increasing collection and use of personal data, individuals often find themselves at a disadvantage compared to powerful entities such as corporations and governments[5]. However, the PDPC acts as a regulatory body that safeguards individuals' interests, rectifying the power imbalances and promoting digital constitutionalism. By establishing clear rules and regulations regarding the collection, use, and transfer of personal data, the PDPC may set a framework that ensures the protection of individuals' privacy and data rights. It may enforce accountability among businesses and governments, holding them responsible for their data practices and creating a level playing field where individuals have a say in how their personal data is handled. 3.Millian Liberalism The need for the institutionalization of the PDPC embodies the paradox of freedom, as raised in John Stuart Mill’s “On Liberty”[6], where Mill recognizes that absolute freedom can lead to the infringement of others' rights and well-being. In this context, the institutionalization of the PDPC acknowledges the necessity of governance to mitigate the risks associated with personal data protection. In the digital age, the vast amount of personal data collected and processed by various entities raises concerns about privacy, security, and potential misuse. The institutionalization of the PDPC represents a commitment to address these concerns through responsible governance. By setting up rules, regulations, and enforcement mechanisms, the PDPC ensures that individuals' freedoms are preserved without compromising the rights and privacy of others. It strikes a delicate balance between individual autonomy and the broader social interest, shedding light on the paradox of freedom. II.Legal Positivism: Function and Authority of the PDPC 1.John Austin's Concept of Legal Positivism: Sovereignty, Punishment, Order To understand the function and authority of the PDPC, we turn to John Austin's concept of legal positivism. Austin posited that laws are commands issued by a sovereign authority and backed by sanctions[7]. Sovereignty entails the power to make and enforce laws within a given jurisdiction. In the case of the PDPC, its institutionalization by the Legislative Yuan reflects the recognition of its authority to create and enforce regulations concerning personal data protection. The PDPC, as an independent and specialized committee, possesses the necessary jurisdiction and competence to ensure compliance with the law, administer punishments for violations, and maintain order in the realm of personal data protection. 2.Dire Need for the Institutionalization of the PDPC There has been a dire need for the establishment of the PDPC following the Constitutional Court's decision in August 2022, holding that the government needed to establish a specific agency in charge of personal data-related issues[8]. This need reflects John Austin's concept of legal positivism, as it highlights the demand for a legitimate and authoritative body to regulate and oversee personal data protection. The PDPC's institutionalization serves as a response to the growing concerns surrounding data privacy, security breaches, and the increasing reliance on digital platforms. It signifies the de facto recognition of the need for a dedicated institution to safeguard the individual’s personal data rights, reinforcing the principles of legal positivism. Furthermore, the institutionalization of the PDPC demonstrates the responsiveness of the legislative branch to the evolving challenges posed by the digital age. The amendment to the Taiwan Personal Data Protection Act and the subsequent institutionalization of the PDPC are the outcomes of a democratic process, reflecting the will of the people and their desire for enhanced data protection measures. It signifies a commitment to uphold the rule of law and ensure the protection of citizens' rights in the face of emerging technologies and their impact on privacy. 3.Authority to Define Cross-Border Transfer of Personal Data Upon the establishment of the PDPC, it's authority to define what constitutes a cross-border transfer of personal data under Article 21 of the Personal Data Protection Act will then align with John Austin's theory on order. According to Austin, laws bring about order by regulating behavior and ensuring predictability in society. By granting the PDPC the power to determine cross-border data transfers, the legal framework brings clarity and consistency to the process. This promotes order by establishing clear guidelines and standards, reducing uncertainty, and enhancing the protection of personal data in the context of international data transfers. The PDPC's authority in this regard reflects the recognition of the need to regulate and monitor the cross-border transfer of personal data to protect individuals' privacy and prevent unauthorized use or abuse of their information. It ensures that the transfer of personal data across borders adheres to legal and ethical standards, contributing to the institutionalization of a comprehensive framework for cross-border data transfer. III.Conclusion In conclusion, the institutionalization of the Taiwan Personal Data Protection Committee represents the convergence of legal positivism, digital constitutionalism, and Millian liberalism. It signifies the recognition of citizens' sovereignty over their personal data, rebalances power dynamics in the digital realm, and addresses the paradox of freedom through responsible governance. By analyzing the PDPC's function and authority in the context of legal positivism, we understand its role as a regulatory body to maintain order and uphold the principles of legal positivism. The institutionalization of the PDPC serves as a milestone in Taiwan's commitment to protect individuals' personal data and safeguard the digital rights. In essence, the institutionalization of the Taiwan Personal Data Protection Committee represents a triumph of digital constitutionalism, where individuals' rights and interests are safeguarded, and power imbalances are rectified. It also embodies the recognition of the paradox of freedom and the need for responsible governance in the digital age in Taiwan. [1] Lin Ching-yin & Evelyn Yang, Bill to establish data protection agency clears legislative floor, CNA English News, FOCUS TAIWAN, May 16, 2023, https://focustaiwan.tw/society/202305160014 (last visited, July 13, 2023). [2] Legal positivism, Stanford Encyclopedia of Philosophy, https://plato.stanford.edu/entries/legal-positivism/?utm_source=fbia (last visited July 13, 2023). [3] Edoardo Celeste, Digital constitutionalism: how fundamental rights are turning digital, (2023): 13-36, https://doras.dcu.ie/28151/1/2023_Celeste_DIGITAL%20CONSTITUTIONALISM_%20HOW%20FUNDAMENTAL%20RIGHTS%20ARE%20TURNING%20DIGITAL.pdf (last visited July 3, 2023). [4] GIOVANNI DE GREGORIO, DIGITAL CONSTITUTIONALISM IN EUROPE: REFRAMING RIGHTS AND POWERS IN THE ALGORITHMIC SOCIETY 218 (2022). [5] Celeste Edoardo, Digital constitutionalism: how fundamental rights are turning digital (2023), https://doras.dcu.ie/28151/1/2023_Celeste_DIGITAL%20CONSTITUTIONALISM_%20HOW%20FUNDAMENTAL%20RIGHTS%20ARE%20TURNING%20DIGITAL.pdf (last visited July 13, 2023). [6]JOHN STUART MILL,On Liberty (1859), https://openlibrary-repo.ecampusontario.ca/jspui/bitstream/123456789/1310/1/On-Liberty-1645644599.pdf (last visited July 13, 2023). [7] Legal positivism, Stanford Encyclopedia of Philosophy, https://plato.stanford.edu/entries/legal-positivism/?utm_source=fbia (last visited July 13, 2023). [8] Lin Ching-yin & Evelyn Yang, Bill to establish data protection agency clears legislative floor, CNA English News, FOCUS TAIWAN, May 16, 2023, https://focustaiwan.tw/society/202305160014 (last visited, July 13, 2023).

The opening and sharing of scientific data- The Data Policy of the U.S. National Institutes of Health

The opening and sharing of scientific data- The Data Policy of the U.S. National Institutes of Health Li-Ting Tsai   Scientific research improves the well-being of all mankind, the data sharing on medical and health promote the overall amount of energy in research field. For promoting the access of scientific data and research findings which was supported by the government, the U.S. government affirmed in principle that the development of science was related to the retention and accesses of data. The disclosure of information should comply with legal restrictions, and the limitation by time as well. For government-sponsored research, the data produced was based on the principle of free access, and government policies should also consider the actual situation of international cooperation[1]Furthermore, the access of scientific research data would help to promote scientific development, therefore while formulating a sharing policy, the government should also consider the situation of international cooperation, and discuss the strategy of data disclosure based on the principle of free access.   In order to increase the effectiveness of scientific data, the U.S. National Institutes of Health (NIH) set up the Office of Science Policy (OSP) to formulate a policy which included a wide range of issues, such as biosafety (biosecurity), genetic testing, genomic data sharing, human subjects protections, the organization and management of the NIH, and the outputs and value of NIH-funded research. Through extensive analysis and reports, proposed emerging policy recommendations.[2] At the level of scientific data sharing, NIH focused on "genes and health" and "scientific data management". The progress of biomedical research depended on the access of scientific data; sharing scientific data was helpful to verify research results. Researchers integrated data to strengthen analysis, promoted the reuse of difficult-generated data, and accelerated research progress.[3] NIH promoted the use of scientific data through data management to verify and share research results.   For assisting data sharing, NIH had issued a data management and sharing policy (DMS Policy), which aimed to promote the sharing of scientific data funded or conducted by NIH.[4] DMS Policy defines “scientific data.” as “The recorded factual material commonly accepted in the scientific community as of sufficient quality to validate and replicate research findings, regardless of whether the data are used to support scholarly publications. Scientific data do not include laboratory notebooks, preliminary analyses, completed case report forms, drafts of scientific papers, plans for future research, peer reviews, communications with colleagues, or physical objects, such as laboratory specimens.”[5] In other words, for determining scientific data, it is not only based on whether the data can support academic publications, but also based on whether the scientific data is a record of facts and whether the research results can be repeatedly verified.   In addition, NIH, NIH research institutes, centers, and offices have had expected sharing of data, such as: scientific data sharing, related standards, database selection, time limitation, applicable and presented in the plan; if not applicable, the researcher should propose the data sharing and management methods in the plan. NIH also recommended that the management and sharing of data should implement the FAIR (Findable, Accessible, Interoperable and Reusable) principles. The types of data to be shared should first in general descriptions and estimates, the second was to list meta-data and other documents that would help to explain scientific data. NIH encouraged the sharing of scientific data as soon as possible, no later than the publication or implementation period.[6] It was said that even each research project was not suitable for the existing sharing strategy, when planning a proposal, the research team should still develop a suitable method for sharing and management, and follow the FAIR principles.   The scientific research data which was provided by the research team would be stored in a database which was designated by the policy or funder. NIH proposed a list of recommended databases lists[7], and described the characteristics of ideal storage databases as “have unique and persistent identifiers, a long-term and sustainable data management plan, set up metadata, organizing data and quality assurance, free and easy access, broad and measured reuse, clear use guidance, security and integrity, confidentiality, common format, provenance and data retention policy”[8]. That is to say, the design of the database should be easy to search scientific data, and should maintain the security, integrity and confidentiality and so on of the data while accessing them.   In the practical application of NIH shared data, in order to share genetic research data, NIH proposed a Genomic Data Sharing (GDS) Policy in 2014, including NIH funding guidelines and contracts; NIH’s GDS policy applied to all NIHs Funded research, the generated large-scale human or non-human genetic data would be used in subsequent research. [9] This can effectively promote genetic research forward.   The GDS policy obliged researchers to provide genomic data; researchers who access genomic data should also abide by the terms that they used the Controlled-Access Data for research.[10] After NIH approved, researchers could use the NIH Controlled-Access Data for secondary research.[11] Reviewed by NIH Data Access Committee, while researchers accessed data must follow the terms which was using Controlled-Access Data for research reason.[12] The Genomic Summary Results (GSR) was belong to NIH policy,[13] and according to the purpose of GDS policy, GSR was defined as summary statistics which was provided by researchers, and non-sensitive data was included to the database that was designated by NIH.[14] Namely. NIH used the application and approval of control access data to strike a balance between the data of limitation access and scientific development.   For responding the COVID-19 and accelerating the development of treatments and vaccines, NIH's data sharing and management policy alleviated the global scientific community’s need for opening and sharing scientific data. This policy established data sharing as a basic component in the research process.[15] In conclusion, internalizing data sharing in the research process will help to update the research process globally and face the scientific challenges of all mankind together. [1]NATIONAL SCIENCE AND TECHNOLOGY COUNCIL, COMMITTEE ON SCIENCE, SUBCOMMITEE ON INTERNATIONAL ISSUES, INTERAGENCY WORKING GROUP ON OPEN DATA SHARING POLICY, Principles For Promoting Access To Federal Government-Supported Scientific Data And Research Findings Through International Scientific Cooperation (2016), 1, organized from Principles, at 5-8, https://obamawhitehouse.archives.gov/sites/default/files/microsites/ostp/NSTC/iwgodsp_principles_0.pdf (last visited December 14, 2020). [2]About Us, Welcome to NIH Office of Science Policy, NIH National Institutes of Health Office of Science Policy, https://osp.od.nih.gov/about-us/ (last visited December 7, 2020). [3]NIH Data Management and Sharing Activities Related to Public Access and Open Science, NIH National Institutes of Health Office of Science Policy, https://osp.od.nih.gov/scientific-sharing/nih-data-management-and-sharing-activities-related-to-public-access-and-open-science/ (last visited December 10, 2020). [4]Final NIH Policy for Data Management and Sharing, NIH National Institutes of Health Office of Extramural Research, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-013.html (last visited December 11, 2020). [5]Final NIH Policy for Data Management and Sharing, NIH National Institutes of Health Office of Extramural Research, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-013.html (last visited December 12, 2020). [6]Supplemental Information to the NIH Policy for Data Management and Sharing: Elements of an NIH Data Management and Sharing Plan, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-014.html (last visited December 13, 2020). [7]The list of databases in details please see:Open Domain-Specific Data Sharing Repositories, NIH National Library of Medicine, https://www.nlm.nih.gov/NIHbmic/domain_specific_repositories.html (last visited December 24, 2020). [8]Supplemental Information to the NIH Policy for Data Management and Sharing: Selecting a Repository for Data Resulting from NIH-Supported Research, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-016.html (last visited December 13, 2020). [9]NIH Genomic Data Sharing, National Institutes of Health Office of Science Policy, https://osp.od.nih.gov/scientific-sharing/genomic-data-sharing/ (last visited December 15, 2020). [10]NIH Genomic Data Sharing Policy, National Institutes of Health (NIH), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-14-124.html (last visited December 17, 2020). [11]NIH Genomic Data Sharing Policy, National Institutes of Health (NIH), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-14-124.html (last visited December 17, 2020). [12]id. [13]NIH National Institutes of Health Turning Discovery into Health, Responsible Use of Human Genomic Data An Informational Resource, 1, at 6, https://osp.od.nih.gov/wp-content/uploads/Responsible_Use_of_Human_Genomic_Data_Informational_Resource.pdf (last visited December 17, 2020). [14]Update to NIH Management of Genomic Summary Results Access, National Institutes of Health (NIH), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-19-023.html (last visited December 17, 2020). [15]Francis S. Collins, Statement on Final NIH Policy for Data Management and Sharing, National Institutes of Health Turning Discovery Into Health, https://www.nih.gov/about-nih/who-we-are/nih-director/statements/statement-final-nih-policy-data-management-sharing (last visited December 14, 2020).

Blockchain and General Data Protection Regulation (GDPR) compliance issues (2019)

Blockchain and General Data Protection Regulation (GDPR) compliance issues (2019) I. Brief   Blockchain technology can solve the problem of trust between data demanders and data providers. In other words, in a centralized mode, data demanders can only choose to believe that the centralized platform will not contain the false information. However, in the decentralized mode, data isn’t controlled by one individual group or organization[1], data demanders can directly verify information such as data source, time, and authorization on the blockchain without worrying about the correctness and authenticity of the data.   Take the “immutable” for example, it is conflict with the right to erase (also known as the right to be forgotten) in the GDPR.With encryption and one-time pad (OTP) technology, data subjects can make data off-chain storaged or modified at any time in a decentralized platform, so the problem that data on blockchain not meet the GDPR regulation has gradually faded away. II. What is GDPR?   The purpose of the EU GDPR is to protect user’s data and to prevent large-scale online platforms or large enterprises from collecting or using user’s data without their permission. Violators will be punished by the EU with up to 20 million Euros (equal to 700 million NT dollars) or 4% of the worldwide annual revenue of the prior financial year.   The aim is to promote free movement of personal data within the European Union, while maintaining adequate level of data protection. It is a technology-neutral law, any type of technology which is for processing personal data is applicable.   So problem about whether the data on blockchain fits GDPR regulation has raise. Since the blockchain is decentralized, one of the original design goals is to avoid a large amount of centralized data being abused.   Blockchain can be divided into permissioned blockchains and permissionless blockchains. The former can also be called “private chains” or “alliance chains” or “enterprise chains”, that means no one can join the blockchain without consent. The latter can also be called “public chains”, which means that anyone can participate on chain without obtaining consent.   Sometimes, private chain is not completely decentralized. The demand for the use of blockchain has developed a hybrid of two types of blockchain, called “alliance chain”, which not only maintains the privacy of the private chain, but also maintains the characteristics of public chains. The information on the alliance chain will be open and transparent, and it is in conflict with the application of GDPR. III. How to GDPR apply to blockchain ?   First, it should be determined whether the data on the blockchain is personal data protected by GDPR. Second, what is the relationship and respective responsibilities of the data subject, data controller, and data processor? Finally, we discuss the common technical characteristics of blockchain and how it is applicable to GDPR. 1. Data on the blockchain is personal data protected by GDPR?   First of all, starting from the technical characteristics of the blockchain, blockchain technology is commonly decentralized, anonymous, immutable, trackable and encrypted. The other five major characteristics are immutability, authenticity, transparency, uniqueness, and collective consensus.   Further, the blockchain is an open, decentralized ledger technology that can effectively verify and permanently store transactions between two parties, and can be proved.   It is a distributed database, all users on the chain can access to the database and the history record, also can directly verify transaction records. Each nodes use peer-to-peer transmission for upload or transfer information without third-party intermediation, which is the unique “decentralization” feature of the blockchain.   In addition, the node or any user on the chain has a unique and identifiable set of more than 30 alphanumeric addresses, but the user may choose to be anonymous or provide identification, which is also a feature of transparency with pseudonymity[2]; Data on blockchain is irreversibility of records. Once the transaction is recorded and updated on the chain, it is difficult to change and is permanently stored in the database, that is to say, it has the characteristics of “tamper-resistance”[3].   According to Article 4 (1) of the GDPR, “personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.   Therefore, if data subject cannot be identified by the personal data on the blockchain, that is an anonymous data, excluding the application of GDPR. (1) What is Anonymization?   According to Opinion 05/2014 on Anonymization Techniques by Article 29 Data Protection Working Party of the European Union, “anonymization” is a technique applied to personal data in order to achieve irreversible de-identification[4].   And it also said the “Hash function” of blockchain is a pseudonymization technology, the personal data is possible to be re-identified. Therefore it’s not an “anonymization”, the data on the blockchain may still be the personal data stipulated by the GDPR.   As the blockchain evolves, it will be possible to develop technologies that are not regulated by GDPR, such as part of the encryption process, which will be able to pass the court or European data protection authorities requirement of anonymization. There are also many compliance solutions which use technical in the industry, such as avoiding transaction data stored directly on the chain. 2. International data transmission   Furthermore, in accordance with Article 3 of the GDPR, “This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union”.[5]   In other words, GDPR applies only when the data on the blockchain is not anonymized, and involves the processing of personal data of EU citizens. 3. Identification of data controllers and data processors   Therefore, if the encryption technology involves the public storage of EU citizens' personal data and passes it to a third-party controller, it may be identified as the “data controller” under Article 4 of GDPR, and all nodes and miners of the platform may be deemed as the “co-controller” of the data, and be assumed joint responsibility with the data controller by GDPR. For example, the parties can claim the right to delete data from the data controller.   In addition, a blockchain operator may be identified as a “processor”, for example, Backend as a Service (BaaS) products, the third parties provide network infrastructure for users, and let users manage and store personal data. Such Cloud Services Companies provide online services on behalf of customers, do not act as “data controllers”. Some commentators believe that in the case of private chains or alliance chains, such as land records transmission, inter-bank customer information sharing, etc., compared to public chain applications: such as cryptocurrencies (Bitcoin for example), is not completely decentralized, and more likely to meet GDPR requirements[6]. For example, in the case of a private chain or alliance chain, it is a closed platform, which contains only a small number of trusted nodes, is more effective in complying with the GDPR rules. 4. Data subject claims   In accordance with Article 17 of the GDPR, The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay under some grounds.   Off-chain storage technology can help the blockchain industry comply with GDPR rules, allowing offline storage of personal data, or allow trusted nodes to delete the private key of encrypted information, which leaving data that cannot be read and identified on the chain. If the data is in accordance with the definition of anonymization by GDPR, there is no room for GDPR to be applied. IV. Conclusion   In summary, it’s seem that the application of blockchain to GDPR may include: (a) being difficulty to identified the data controllers and data processors after the data subject upload their data. (b) the nature of decentralized storage is transnational storage, and Whether the country where the node is located, is meets the “adequacy decision” of Article 45 of the GDPR.   If it cannot be met, then it needs to consider whether it conforms to the transfers subject to appropriate safeguards of Article 46, or the derogations for specific situations of Article 49 of the GDPR. Reference: [1] How to Trade Cryptocurrency: A Guide for (Future) Millionaires, https://wikijob.com/trading/cryptocurrency/how-to-trade-cryptocurrency [2] DONNA K. HAMMAKER, HEALTH RECORDS AND THE LAW 392 (5TH ED. 2018). [3] Iansiti, Marco, and Karim R. Lakhani, The Truth about Blockchain, Harvard Business Review 95, no. 1 (January-February 2017): 118-125, available at https://hbr.org/2017/01/the-truth-about-blockchain [4] Article 29 Data Protection Working Party, Opinion 05/2014 on Anonymisation Techniques (2014), https://www.pdpjournals.com/docs/88197.pdf [5] Directive 95/46/EC (General Data Protection Regulation), https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN [6] Queen Mary University of London, Are blockchains compatible with data privacy law? https://www.qmul.ac.uk/media/news/2018/hss/are-blockchains-compatible-with-data-privacy-law.html

TOP