Blockchain and General Data Protection Regulation (GDPR) compliance issues (2019)

Blockchain and General Data Protection Regulation (GDPR) compliance issues (2019)

I. Brief

  Blockchain technology can solve the problem of trust between data demanders and data providers. In other words, in a centralized mode, data demanders can only choose to believe that the centralized platform will not contain the false information. However, in the decentralized mode, data isn’t controlled by one individual group or organization[1], data demanders can directly verify information such as data source, time, and authorization on the blockchain without worrying about the correctness and authenticity of the data.

  Take the “immutable” for example, it is conflict with the right to erase (also known as the right to be forgotten) in the GDPR.With encryption and one-time pad (OTP) technology, data subjects can make data off-chain storaged or modified at any time in a decentralized platform, so the problem that data on blockchain not meet the GDPR regulation has gradually faded away.

II. What is GDPR?

  The purpose of the EU GDPR is to protect user’s data and to prevent large-scale online platforms or large enterprises from collecting or using user’s data without their permission. Violators will be punished by the EU with up to 20 million Euros (equal to 700 million NT dollars) or 4% of the worldwide annual revenue of the prior financial year.

  The aim is to promote free movement of personal data within the European Union, while maintaining adequate level of data protection. It is a technology-neutral law, any type of technology which is for processing personal data is applicable.

  So problem about whether the data on blockchain fits GDPR regulation has raise. Since the blockchain is decentralized, one of the original design goals is to avoid a large amount of centralized data being abused.

  Blockchain can be divided into permissioned blockchains and permissionless blockchains. The former can also be called “private chains” or “alliance chains” or “enterprise chains”, that means no one can join the blockchain without consent. The latter can also be called “public chains”, which means that anyone can participate on chain without obtaining consent.

  Sometimes, private chain is not completely decentralized. The demand for the use of blockchain has developed a hybrid of two types of blockchain, called “alliance chain”, which not only maintains the privacy of the private chain, but also maintains the characteristics of public chains. The information on the alliance chain will be open and transparent, and it is in conflict with the application of GDPR.

III. How to GDPR apply to blockchain ?

  First, it should be determined whether the data on the blockchain is personal data protected by GDPR. Second, what is the relationship and respective responsibilities of the data subject, data controller, and data processor? Finally, we discuss the common technical characteristics of blockchain and how it is applicable to GDPR.

1. Data on the blockchain is personal data protected by GDPR?

  First of all, starting from the technical characteristics of the blockchain, blockchain technology is commonly decentralized, anonymous, immutable, trackable and encrypted. The other five major characteristics are immutability, authenticity, transparency, uniqueness, and collective consensus.

  Further, the blockchain is an open, decentralized ledger technology that can effectively verify and permanently store transactions between two parties, and can be proved.

  It is a distributed database, all users on the chain can access to the database and the history record, also can directly verify transaction records. Each nodes use peer-to-peer transmission for upload or transfer information without third-party intermediation, which is the unique “decentralization” feature of the blockchain.

  In addition, the node or any user on the chain has a unique and identifiable set of more than 30 alphanumeric addresses, but the user may choose to be anonymous or provide identification, which is also a feature of transparency with pseudonymity[2]; Data on blockchain is irreversibility of records. Once the transaction is recorded and updated on the chain, it is difficult to change and is permanently stored in the database, that is to say, it has the characteristics of “tamper-resistance”[3].

  According to Article 4 (1) of the GDPR, “personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

  Therefore, if data subject cannot be identified by the personal data on the blockchain, that is an anonymous data, excluding the application of GDPR.

(1) What is Anonymization?

  According to Opinion 05/2014 on Anonymization Techniques by Article 29 Data Protection Working Party of the European Union, “anonymization” is a technique applied to personal data in order to achieve irreversible de-identification[4].

  And it also said the “Hash function” of blockchain is a pseudonymization technology, the personal data is possible to be re-identified. Therefore it’s not an “anonymization”, the data on the blockchain may still be the personal data stipulated by the GDPR.

  As the blockchain evolves, it will be possible to develop technologies that are not regulated by GDPR, such as part of the encryption process, which will be able to pass the court or European data protection authorities requirement of anonymization. There are also many compliance solutions which use technical in the industry, such as avoiding transaction data stored directly on the chain.

2. International data transmission

  Furthermore, in accordance with Article 3 of the GDPR, “This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union”.[5]

  In other words, GDPR applies only when the data on the blockchain is not anonymized, and involves the processing of personal data of EU citizens.

3. Identification of data controllers and data processors

  Therefore, if the encryption technology involves the public storage of EU citizens' personal data and passes it to a third-party controller, it may be identified as the “data controller” under Article 4 of GDPR, and all nodes and miners of the platform may be deemed as the “co-controller” of the data, and be assumed joint responsibility with the data controller by GDPR. For example, the parties can claim the right to delete data from the data controller.

  In addition, a blockchain operator may be identified as a “processor”, for example, Backend as a Service (BaaS) products, the third parties provide network infrastructure for users, and let users manage and store personal data. Such Cloud Services Companies provide online services on behalf of customers, do not act as “data controllers”. Some commentators believe that in the case of private chains or alliance chains, such as land records transmission, inter-bank customer information sharing, etc., compared to public chain applications: such as cryptocurrencies (Bitcoin for example), is not completely decentralized, and more likely to meet GDPR requirements[6]. For example, in the case of a private chain or alliance chain, it is a closed platform, which contains only a small number of trusted nodes, is more effective in complying with the GDPR rules.

4. Data subject claims

  In accordance with Article 17 of the GDPR, The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay under some grounds.

  Off-chain storage technology can help the blockchain industry comply with GDPR rules, allowing offline storage of personal data, or allow trusted nodes to delete the private key of encrypted information, which leaving data that cannot be read and identified on the chain. If the data is in accordance with the definition of anonymization by GDPR, there is no room for GDPR to be applied.

IV. Conclusion

  In summary, it’s seem that the application of blockchain to GDPR may include: (a) being difficulty to identified the data controllers and data processors after the data subject upload their data. (b) the nature of decentralized storage is transnational storage, and Whether the country where the node is located, is meets the “adequacy decision” of Article 45 of the GDPR.

  If it cannot be met, then it needs to consider whether it conforms to the transfers subject to appropriate safeguards of Article 46, or the derogations for specific situations of Article 49 of the GDPR.

 

Reference:

[1] How to Trade Cryptocurrency: A Guide for (Future) Millionaires, https://wikijob.com/trading/cryptocurrency/how-to-trade-cryptocurrency

[2] DONNA K. HAMMAKER, HEALTH RECORDS AND THE LAW 392 (5TH ED. 2018).

[3] Iansiti, Marco, and Karim R. Lakhani, The Truth about Blockchain, Harvard Business Review 95, no. 1 (January-February 2017): 118-125, available at https://hbr.org/2017/01/the-truth-about-blockchain

[4] Article 29 Data Protection Working Party, Opinion 05/2014 on Anonymisation Techniques (2014), https://www.pdpjournals.com/docs/88197.pdf

[5] Directive 95/46/EC (General Data Protection Regulation), https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN

[6] Queen Mary University of London, Are blockchains compatible with data privacy law? https://www.qmul.ac.uk/media/news/2018/hss/are-blockchains-compatible-with-data-privacy-law.html

Links
Download
※Blockchain and General Data Protection Regulation (GDPR) compliance issues (2019),STLI, https://stli.iii.org.tw/en/article-detail.aspx?no=55&tp=2&i=168&d=8419 (Date:2024/04/27)
Quote this paper
You may be interested
Impact of Government Organizational Reform to Research Legal System and Response Thereto (2) – Observation of the Swiss Research Innovation System

Impact of Government Organizational Reform to Research Legal System and Response Thereto (2) – Observation of the Swiss Research Innovation System I. Foreword   Switzerland is a landlocked country situated in Central Europe, spanning an area of 41,000 km2, where the Alps occupy 60% of the territory, while it owns little cultivated land and poor natural resources. In 2011, its population was about 7,950,000 persons[1]. Since the Swiss Federal was founded, it has been adhering to a diplomatic policy claiming neutrality and peace, and therefore, it is one of the safest and most stable countries in the world. Switzerland is famous for its high-quality education and high-level technological development and is very competitive in biomedicine, chemical engineering, electronics and metal industries in the international market. As a small country with poor resources, the Swiss have learnt to drive their economic and social development through education, R&D and innovation a very long time ago. Some renowned enterprises, including Nestle, Novartis and Roche, are all based in Switzerland. Meanwhile, a lot of creative small-sized and medium-sized enterprises based in Switzerland are dedicated to supporting the export-orientation economy in Switzerland.   Switzerland has the strongest economic strength and plentiful innovation energy. Its patent applications, publication of essay, frequencies of quotation and private enterprises’ innovation performance are remarkable all over the world. According to the Global Competitiveness Report released by the World Economic Forum (WEF), Switzerland has ranked first among the most competitive countries in the world for four years consecutively since 2009[2]. Meanwhile, according to the Global Innovation Index (GII) released by INSEAD and the World Intellectual Property Organization (WIPO) jointly, Switzerland has also ranked first in 2011 and 2012 consecutively[3]. Obviously, Switzerland has led the other countries in the world in innovation development and economic strength. Therefore, when studying the R&D incentives and boosting the industrial innovation, we might benefit from the experience of Switzerland to help boost the relevant mechanism in Taiwan.   Taiwan’s government organization reform has been launched officially and boosted step by step since 2012. In the future, the National Science Council will be reformed into the “Ministry of Science and Technology”, and the Ministry of Economic Affairs into the “Ministry of Economy and Energy”, and the Department of Industrial Development into the “Department of Industry and Technology”. Therefore, Taiwan’s technology administrative system will be changed materially. Under the new government organizational framework, how Taiwan’s technology R&D and industrial innovation system divide work and coordinate operations to boost the continuous economic growth in Taiwan will be the first priority without doubt. Support of innovation policies is critical to promotion of continuous economic growth. The Swiss Government supports technological research and innovation via various organizations and institutions effectively. In recent years, it has achieved outstanding performance in economy, education and innovation. Therefore, we herein study the functions and orientation of the competent authorities dedicated to boosting research and innovation in Switzerland, and observe its policies and legal system applied to boost the national R&D in order to provide the reference for the functions and orientation of the competent authorities dedicated to boosting R&D and industrial innovation in Taiwan. II. Overview of Swiss Federal Technology Laws and Technology Administrative System   Swiss national administrative organization is subject to the council system. The Swiss Federal Council is the national supreme administrative authority, consisting of 7 members elected from the Federal Assembly and dedicated to governing a Federal Government department respectively. Switzerland is a federal country consisting of various cantons that have their own constitutions, councils and governments, respectively, entitled to a high degree of independence.   Article 64 of the Swiss Federal Constitution[4] requires that the federal government support research and innovation. The “Research and Innovation Promotion Act” (RIPA)[5] is dedicated to fulfilling the requirements provided in Article 64 of the Constitution. Article 1 of the RIPA[6] expressly states that the Act is enacted for the following three purposes: 1. Promoting the scientific research and science-based innovation and supporting evaluation, promotion and utilization of research results; 2. Overseeing the cooperation between research institutions, and intervening when necessary; 3. Ensuring that the government funding in research and innovation is utilized effectively. Article 4 of the RIPA provides that the Act shall apply to the research institutions dedicated to innovation R&D and higher education institutions which accept the government funding, and may serve to be the merit for establishment of various institutions dedicated to boosting scientific research, e.g., the National Science Foundation and Commission of Technology & Innovation (CTI). Meanwhile, the Act also provides detailed requirements about the method, mode and restriction of the government funding.   According to the RIPA amended in 2011, the Swiss Federal Government’s responsibility for promoting innovation policies has been extended from “promotion of technology R&D” to “unification of education, research and innovation management”, making the Swiss national industrial innovation framework more well-founded and consistent[8] . Therefore, upon the government organization reform of Switzerland in 2013, most of the competent authorities dedicated to technology in Swiss have been consolidated into the Federal Department of Economic Affairs, Education and Research.   Under the framework, the Swiss Federal Government assigned higher education, job training, basic scientific research and innovation to the State Secretariat for Education, Research and Innovation (SERI), while the Commission of Technology & Innovation (CTI) was responsible for boosting the R&D of application scientific technology and industrial technology and cooperation between the industries and academy. The two authorities are directly subordinate to the Federal Department of Economic Affairs, Education and Research (EAER). The Swiss Science and Technology Council (SSTC), subordinate to the SERI is an advisory entity dedicated to Swiss technology policies and responsible for providing the Swiss Federal Government and canton governments with the advice and suggestion on scientific, education and technology innovation policies. The Swiss National Science Foundation (SNSF) is an entity dedicated to boosting the basic scientific R&D, known as the two major funding entities together with CTI for Swiss technology R&D. The organizations, duties, functions and operations of certain important entities in the Swiss innovation system are introduced as following. Date source: Swiss Federal Department of Economic Affairs, Education and Research official website Fig. 1 Swiss Innovation Framework Dedicated to Boosting Industries-Swiss Federal Economic, Education and Research Organizational Chart 1. State Secretariat of Education, Research and Innovation (SERI)   SERI is subordinate to the Department of Economic Affairs, Education and Research, and is a department of the Swiss Federal Government dedicated to managing research and innovation. Upon enforcement of the new governmental organization act as of January 1, 2013, SERI was established after the merger of the State Secretariat for Education and Research, initially subordinate to Ministry of Interior, and the Federal Office for Professional Education and Technology (OEPT), initially subordinated to Ministry of Economic Affairs. For the time being, it governs the education, research and innovation (ERI). The transformation not only integrated the management of Swiss innovation system but also unified the orientations toward which the research and innovation policy should be boosted.   SERI’s core missions include “enactment of national technology policies”, “coordination of research activities conducted by higher education institutions, ETH, and other entities of the Federal Government in charge of various areas as energy, environment, traffic and health, and integration of research activities conducted by various government entities and allocation of education, research and innovation resources. Its functions also extend to funding the Swiss National Science Foundation (SNSF) to enable SNSF to subsidize the basic scientific research. Meanwhile, the international cooperation projects for promotion of or participation in research & innovation activities are also handled by SERI to ensure that Switzerland maintains its innovation strength in Europe and the world.   The Swiss Science and Technology Council (SSTC) is subordinate to SERI, and also the advisory unit dedicated to Swiss technology policies, according to Article 5a of RIPA[9]. The SSTC is responsible for providing the Swiss Federal Government and canton governments with advice and suggestion about science, education and innovation policies. It consists of the members elected from the Swiss Federal Council, and a chairman is elected among the members. 2. Swiss National Science Foundation (SNSF)   The Swiss National Science Foundation (SNSF) is one of the most important institutions dedicated to funding research, responsible for promoting the academic research related to basic science. It supports about 8,500 scientists each year. Its core missions cover funding as incentives for basic scientific research. It grants more than CHF70 million each year. Nevertheless, the application science R&D, in principle, does not fall in the scope of funding by the SNSF. The Foundation allocates the public research fund under the competitive funding system and thereby maintains its irreplaceable identity, contributing to continuous output of high quality in Switzerland.   With the support from the Swiss Federal Government, the SNSF was established in 1952. In order to ensure independence of research, it was planned as a private institution when it was established[10]. Though the funding is provided by SERI, the SNSF still has a high degree of independence when performing its functions. The R&D funding granted by the SNSF may be categorized into the funding to free basic research, specific theme-oriented research, and international cooperative technology R&D, and the free basic research is granted the largest funding. The SNSF consists of Foundation Council, National Research Council and Research Commission[11]. Data source: prepared by the Study Fig. 2  Swiss National Science Foundation Organizational Chart (1) Foundation Council   The Foundation Council is the supreme body of the SNSF[12], which is primarily responsible for making important decisions, deciding the role to be played by the SNSF in the Swiss research system, and ensuring SNSF’s compliance with the purpose for which it was founded. The Foundation Council consists of the members elected from the representatives from important research institutions, universities and industries in Swiss, as well as the government representatives nominated by the Swiss Federal Council. According to the articles of association of the SNSF[13], each member’s term of office should be 4 years, and the members shall be no more than 50 persons. The Foundation Council also governs the Executive Committee of the Foundation Council consisting of 15 Foundation members. The Committee carries out the mission including selection of National Research Council members and review of the Foundation budget. (2) National Research Council   The National Research Council is responsible for reviewing the applications for funding and deciding whether the funding should be granted. It consists of no more than 100 members, mostly researchers in universities and categorized, in four groups by major[14], namely, 1. Humanities and Social Sciences; 2. Math, Natural Science and Engineering; 3. Biology and Medical Science; and 4. National Research Programs (NRPs)and National Centers of Competence in Research (NCCRs). The NRPs and NCCRs are both limited to specific theme-oriented research plans. The funding will continue for 4~5years, amounting to CHF5 million~CHF20 million[15]. The specific theme-oriented research is applicable to non-academic entities, aiming at knowledge and technology transfer, and promotion and application of research results. The four groups evaluate and review the applications and authorize the funding amount.   Meanwhile, the representative members from each group form the Presiding Board dedicated to supervising and coordinating the operations of the National Research Council, and advising the Foundation Council about scientific policies, reviewing defined funding policies, funding model and funding plan, and allocating funding by major. (3) Research Commissions   Research Commissions are established in various higher education research institutions. They serve as the contact bridge between higher education academic institutions and the SNSF. The research commission of a university is responsible for evaluating the application submitted by any researcher in the university in terms of the school conditions, e.g., the school’s basic research facilities and human resource policies, and providing advice in the process of application. Meanwhile, in order to encourage young scholars to attend research activities, the research committee may grant scholarships to PhD students and post-doctor research[16]. ~to be continued~ [1] SWISS FEDERAL STATISTICS OFFICE, Switzerland's population 2011 (2012), http://www.bfs.admin.ch/bfs/portal/en/index/news/publikationen.Document.163772.pdf (last visited Jun. 1, 2013). [2] WORLD ECONOMIC FORUM [WEF], The Global Competiveness Report 2012-2013 (2012), http://www3.weforum.org/docs/WEF_GlobalCompetitivenessReport_2012-13.pdf (last visited Jun. 1, 2013); WEF, The Global Competiveness Report 2011-2012 (2011), http://www3.weforum.org/docs/WEF_GCR_Report_2011-12.pdf (last visited Jun. 1, 2013); WEF, The Global Competiveness Report 2010-2011 (2010), http://www3.weforum.org/docs/WEF_GlobalCompetitivenessReport_2010-11.pdf (last visited Jun. 1, 2013); WEF, The Global Competiveness Report 2009-2010 (2009),. http://www3.weforum.org/docs/WEF_GlobalCompetitivenessReport_2009-10.pdf (last visited Jun. 1, 2013). [3] INSEAD, The Global Innovation Index 2012 Report (2012), http://www.globalinnovationindex.org/gii/GII%202012%20Report.pdf (last visited Jun. 1, 2013); INSEAD, The Global Innovation Index 2011 Report (2011), http://www.wipo.int/freepublications/en/economics/gii/gii_2011.pdf (last visited Jun. 1, 2013). [4] SR 101 Art. 64: “Der Bund fördert die wissenschaftliche Forschung und die Innovation.” [5] Forschungs- und Innovationsförderungsgesetz, vom 7. Oktober 1983 (Stand am 1. Januar 2013). For the full text, please see www.admin.ch/ch/d/sr/4/420.1.de.pdf (last visited Jun. 3, 2013). [6] Id. [7] Id. [8] CTI, CTI Multi-year Program 2013-2016 7(2012), available at http://www.kti.admin.ch/?lang=en&download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ad1IZn4Z2qZpnO2Yuq2Z6gpJCDeYR,hGym162epYbg2c_JjKbNoKSn6A-- (last visited Jun. 3, 2013). [9] Supra note 5. [10] Swiss National Science Foundation, http://www.snf.ch/E/about-us/organisation/Pages/default.aspx (last visited Jun. 3, 2013). [11] Id. [12] Foundation Council, Swiss National Science Foundation, http://www.snf.ch/E/about-us/organisation/Pages/foundationcouncil.aspx (last visited Jun. 3, 2013). [13] See Statutes of Swiss National Science Foundation Art.8 & Art. 9, available at http://www.snf.ch/SiteCollectionDocuments/statuten_08_e.pdf (last visited Jun. 3, 2013). [14] National Research Council, Swiss National Science Foundation, http://www.snf.ch/E/about-us/organisation/researchcouncil/Pages/default.aspx (last visted Jun.3, 2013). [15] Theres Paulsen, VISION RD4SD Country Case Study Switzerland (2011), http://www.visionrd4sd.eu/documents/doc_download/109-case-study-switzerland (last visited Jun.6, 2013). [16] Research Commissions, Swiss National Science Foundation, http://www.snf.ch/E/about-us/organisation/Pages/researchcommissions.aspx (last visted Jun. 6, 2013).

Research on Policies for building a digital nation in Recent Years (2016-2017)

Research on Policies for building a digital nation in Recent Years (2016-2017)   Recent years, the government has already made some proactive actions, including some policies and initiatives, to enable development in the digital economy and fulfill the vision of Digital Nation. Those actions are as follows: 1. CREATING THE “FOOD CLOUD” FOR FOOD SAFETY CONTROLS   Government agencies have joined forces to create an integrated “food cloud” application that quickly alerts authorities to food safety risks and allows for faster tracing of products and ingredients. The effort to create the cloud was spearheaded by the Executive Yuan’s Office of Food Safety under the leadership of Vice Premier Chang San-cheng on January 12, 2016.   The “food cloud” application links five core systems (registration, tracing, reporting, testing, and inspection) from the Ministry of Health and Welfare (MOHW) with eight systems from the Ministry of Finance, Ministry of Economic Affairs, Ministry of Education (MOE), Council of Agriculture and Environmental Protection Administration.   The application gathers shares and analyzes information in a methodical and systematic manner by employing big data technology. To ensure the data can flow properly across different agencies, the Office of Food Safety came up with several products not intended for human consumption and had the MOHW simulate the flow of those products under import, sale and supply chain distribution scenarios. The interministerial interface successfully analyzed the data and generated lists of food risks to help investigators focus on suspicious companies.   Based on these simulation results, the MOHW on September 2, 2015, established a food and drug intelligence center as a mechanism for managing food safety risks and crises on the national level. The technologies for big data management and mega data analysis will enable authorities to better manage food sources and protect consumer health.   In addition, food cloud systems established by individual government agencies are producing early results. The MOE, for instance, rolled out a school food ingredient registration platform in 2014, and by 2015 had implemented the system across 22 countries and cities at 6,000 schools supplying lunches for 4.5 million students. This platform, which made school lunch ingredients completely transparent, received the 2015 eAsia Award as international recognition for the use of information technology in ensuring food safety. 2. REVISING DIGITAL CONVERGENCE ACTS   On 2016 May 5th, the Executive Yuan Council approved the National Communications Commission's (NCC) proposals, drafts of “Broadcasting Terrestrial and Channel Service Suppliers Administration Act”, “Multichannel Cable Platform Service Administration Act”, “Telecommunications Service Suppliers Act”, “Telecommunications Infrastructure and Resources Administration Act”, “Electronic Communications Act”, also the five digital convergence laws. They will be sent to the Legislature for deliberation. But in the end, this version of five digital convergence bills did not pass by the Legislature.   However, later on, November 16, 2017, The Executive Yuan approved the new drafts of “Digital Communication Act” and the “Telecommunication Service Management Act”.   The “Digital Communication Act” and the “Telecommunication Service Management Act” focused summaries as follows:   1. The digital communication bill   A. Public consultation and participation.   B. The digital communication service provider ought to use internet resource reasonability and reveal network traffic control measures.   C. The digital communication service provider ought to reveal business information and Terms of Service.   D. The responsibility of the digital communication service provider.   2. The telecommunication service management bill   A. The telecommunication service management bill change to use registration system.   B. The general obligation of telecommunications to provide telecommunication service and the special obligation of Specific telecommunications.   C. Investment, giving, receiving and merging rules of the telecommunication service.   Telecommunications are optimism of relaxing rules and regulations, and wish it would infuse new life and energy into the market. Premier Lai instructed the National Communications Commission and other agencies to elucidate the contents of the two communication bills to all sectors of society, and communicate closely with lawmakers of all parties to build support for a quick passage of the bills. 3. FOCUSING ON ICT SECURITY TO BUILD DIGITAL COUNTRIES   The development of ICT has brought convenience to life but often accompanied by the threat of illegal use, especially the crimes with the use of new technologies such as Internet techniques and has gradually become social security worries. Minor impacts may cause inconvenience to life while major impacts may lead to a breakdown of government functions and effects on national security. To enhance the capability of national security protection and to avoid the gap of national security, the Executive Yuan on August 1st 2016 has upgraded the Office of Information and Communication Security into the Agency of Information and Communication Security, a strategic center of R.O.C security work, integrating the mechanism of the whole government governance of information security, through specific responsibility, professionalism, designated persons and permanent organization to establish the security system, together with the relevant provisions of the law so that the country's information and communication security protection mechanism will become more complete. The efforts to the direction could be divided into three parts:   First, strengthening the cooperation of government and private sectors of information security: In a sound basis of legal system, the government plans to strengthen the government and some private sectors’ information security protection abilities ,continue to study and modify the relevant amendments to the relevant provisions, strengthen public-private collaborative mechanism, deepen the training of human resources and enhance the protection of key information infrastructure of our country.   Second, improving the information and communication security professional capability: information and communication security business is divided into policy and technical aspects. While the government takes the responsibility for policy planning and coordination, the technical service lies in an outsourcing way. Based on a sound legal system, the government will establish institutionalized and long-term operation modes and plan appropriate organizational structures through the discussion of experts and scholars from all walks of life.   Third, formulating Information and Communication Safety Management Act and planning of the Fifth National Development Program for Information and Communication Security: The government is now actively promoting the Information and Communication Safety Management Act as the cornerstone for the development of the national digital security and information security industry. The main content of the Act provides that the applicable authorities should set up security protection plan at the core of risk management and the procedures of notification and contingency measures, and accept the relevant administrative check. Besides the vision of the Fifth National Development Program for Information and Communication Security which the government is planning now is to build a safe and reliable digital economy and establish a safe information and communication environment by completing the legal system of information and communication security environment, constructing joint defense system of the national Information and Communication security, pushing up the self-energy of the industries of information security and nurture high-quality human resources for elite talents for information security. 4. THE DIGITAL NATION AND INNOVATIVE ECONOMIC DEVELOPMENT PLAN   The Digital Nation and Innovative Economic Development Plan (2017-2025) known as “DIGI+” plan, approved by the Executive Yuan on November 24, 2016. The plan wants to grow nation’s digital economy to NT $ 6.5 trillion (US$205.9 billion), improve the digital lifestyle services penetration rate to 80 %, increase broadband connections to 2 Gbps, ensure citizens’ basic rights to have 25 Mbps broadband access, and put our nation among the top 10 information technology nations worldwide by 2025.   The plan contains several important development strategies: DIGI+ Infrastructure: Build infrastructure conducive to digital innovation. DIGI+ Talent: Cultivate digital innovation talent. DIGI+ Industry: Support cross-industry transformation through digital innovation. DIGI+ Rights: Make R.O.C. an advanced society that respects digital rights and supports open online communities. DIGI+ Cities: Build smart cities through cooperation among central and local governments and the industrial, academic and research sectors. DIGI+ Globalization: Boost nation’s standing in the global digital service economy.   The plan also highlights few efforts:   First is to enrich “soft” factors and workforce to create an innovative environment for digital development. To construct this environment, the government will construct an innovation-friendly legal framework, cultivate interdisciplinary digital talent, strengthen research and develop advanced digital technologies.   Second is to enhance digital economy development. The government will incentivize innovative applications and optimize the environment for digital commerce.   Third, the government will develop an open application programming interface for government data and create demand-oriented, one-stop smart government cloud services.   Fourth, the government will ensure broadband access for the disadvantaged and citizens of the rural area, implement the participatory process, enhance different kinds of international cooperation, and construct a comprehensive humanitarian legal framework with digital development.   Five is to build a sustainable smart country. The government will use smart network technology to build a better living environment, promote smart urban and rural area connective governance and construction and use on-site research and industries innovation ecosystem to assist local government plan and promote construction of the smart country.   In order to achieve the overall effectiveness of the DIGI + program, interdisciplinary, inter-ministerial, inter-departmental and inter-departmental efforts will be required to collaborate with the newly launched Digital National Innovation Economy (DIGI +) Promotion Team. 5. ARTIFICIAL INTELLIGENCE SCIENTIFIC RESEARCH STRATEGY   The Ministry of Science and Technology (MOST) reported strategy plan for artificial intelligence (AI) scientific research at Cabinet meeting on August 24, 2017. Artificial intelligence is a powerful and inevitable trend, and it will be critical to R.O.C.’s competitiveness for the next 30 years.   The ministry will devote NT$16 billion over the next five years to building an AI innovation ecosystem in R.O.C. According to MOST, the plan will promote five strategies:   1. Creating an AI platform to provide R&D services   MOST will devote NT$5 billion over the next four years to build a platform, integrating the resources, providing a shared high-speed computing environment and nurturing emerging AI industries and applications.   2. Establishing an AI innovative research center   MOST will four artificial intelligence innovation research centers across R.O.C. as part of government efforts to enhance the nation’s competitiveness in AI technology. The centers will support the development of new AI in the realms of financial technology, smart manufacturing, smart healthcare and intelligent transportation systems.   3. Setting up AI robot maker spaces   An NT$2 billion, four-year project assisting industry to develop the hardware-software integration of robots and innovative applications was announced by the Ministry of Science and Technology.   4. Subsidizing a semiconductor “moonshot” program to explore ambitious and groundbreaking smart technologies   This program will invest NT$4 billion from 2018 through 2021 into developing semiconductors and chip systems for edge devices as well as integrating the academic sector’s R&D capabilities and resources. the project encompasses cognitive computing and AI processor chips; next-generation memory designs; process technologies and materials for key components of sensing devices; unmanned vehicles, AR and VR; IoT systems and security.   5. Organizing Formosa Grand Challenge competitions   The program is held in competitions to engage young people in the development of AI applications.   The government hopes to extend R.O.C.’s industrial advantages and bolster the country’s international competitiveness, giving R.O.C. the confidence to usher in the era of AI applications. All of these efforts will weave people, technologies, facilities, and businesses into a broader AI innovation ecosystem. 6. INTELLIGENT TRANSPORTATION SYSTEM PLANS   Ministry of Transportation and Communications (MOTC) launched plans to develop intelligent transportation systems at March 7th in 2017. MOTC integrates transportation and information and communications technology through these plans to improve the convenience and reduce the congestion of the transportation. These plans combine traffic management systems for highways, freeways and urban roads, a multi-lane free-flow electronic toll collection system, bus information system that provides timely integrated traffic information services, and public transportation fare card readers to reduce transport accidence losses, inconvenience of rural area, congestion of main traffic arteries and improve accessibility of public transportation.   There are six plans are included: 1. Intelligent transportation safety plan; 2. Relieve congestion on major traffic arteries; 3. Make transportation more convenient in Eastern Taiwan and remote areas; 4. Integrate and share transportation resources; 5. Develop “internet-of-vehicles” technology applications; and 6. Fundamental R&D for smart transportation technology.   These plans promote research and development of smart vehicles and safety intersections, develop timely bus and traffic information tracking system, build a safe system of shared, safe and green-energy smart system, and subsidize the large vehicles to install the vision enhancement cameras to improve the safety of transportation. These plans also use eTag readers, vehicle sensors and info communication technologies to gather the traffic information and provide timely traffic guidance, reduce the congestion of the traffic flow. These plans try to use demand-responsive transit system with some measures such as combine public transportation and taxi, to improve the flexibility of the public traffic service and help the basic transportation needs of residents in eastern Taiwan and rural areas to be fulfilled. A mobile transport service interface and a platform that integrating booking and payment processes are also expected to be established to provide door-to-door transportation services and to integrate transportation resources. And develop demonstration projects of speed coordination of passenger coach fleets, vehicle-road interaction technology, and self-driving car to investigate and verify the issues in technological, operational, industrial, legal environments of internet-of-vehicles applications in our country. Last but not least, research and development on signal control systems that can be used in both two and four-wheeled vehicles, and deploy an internet-of-vehicles prototype platform and develop drones traffic applications.   These plans are expected to reduce 25% traffic congestion, 20% of motor vehicle incidence, leverage 10% using rate of public transportation, raise 20% public transportation service accessibility of rural area and create NT$30 billion production value. After accomplishing these targets, the government can establish a comprehensive transportation system and guide industry development of relating technology areas.   Through the aforementioned initiatives, programs, and plans, the government wants to construct the robust legal framework and policy environment for digital innovation development, and facilitate the quality of citizens in our society.

Taiwan Announced the Biobanks Regulations and Management Practices

Taiwan Has Passed “Statute of Human Biobank Management” to Maintain Privacy and Improve Medicine Industries Due to lack of regulations, divergent opinions abounded about the establishment of Biobanks and collection of human biological specimen. For example, a researcher in an academic research organization and a hospital-based physician collected biospecimens from native Taiwanese. Although they insisted that the collections were for research only, human rights groups, ethics researchers, and groups for natives´ benefits condemned the collections as an invasion of human rights. Consequently, the Taiwanese government recognized the need for Biobanks regulation. To investigate the relationship between disease and multiple factors and to proceed with possible prevention, The Legislative Yuan Social Welfare and Healthy Environment Committee has passed "the draft statute of human biobank management" through primary reviewing process on December 30, 2009 and subsequently passed through entire three-reading procedure on January 7, 2010. Therefore, the medical and research institute not only can set up optimal gene database for particular disease curing, but also can collect blood sample for database establishment, legally. However, the use of sample collections will be excluded from the use of judiciary purpose. In the light of to establish large scale biobank is going to face the fundamental human right issue, from the viewpoint of biobank management, it is essential not only to set up the strict ethics regulation for operational standard, but also to make the legal environment more complete. For instance, the Department of Health, Executive Yuan had committed the earlier planning of Taiwan biobank establishment to the Academic Sinica in 2006, and planned to collect bio-specimen by recruiting volunteers. However, it has been criticized by all circles that it might be considered violating the Constitution article 8 provision 1 front paragraph, and article 22 rules; moreover, it might also infringe the personal liberty or body information privacy. Therefore, the Executive Yuan has passed the draft statute of human biobank management which was drafted and reviewed by Department of Health during the 3152nd meeting, on July 16, 2009, to achieve the goal of protecting our nation’s privacy and promoting the development of medical science by management biomedical research affairs in more effective ways. Currently, the draft statute has been passed through the primary review procedure by the Legislative Yuan. About the draft statute, there are several important points as following: (1) Sample Definition: Types of collected sample include human somatic cell, tissues, body fluids, or other derivatives; (2) Biobank Establishment: It requires not only to be qualified and permitted, but also to set up the ethical reviewing mechanism to strengthen its management and application; (3)Sample Collection and Participant Protection: In accordance with the draft statute, bio-specimen collecting should respect the living ethics during the time and refer to the "Medical Law" article 64 provision 1; before sample collection, all related points of attention should be kept in written form , the participant should be notified accordingly, and samples can only be collected with the participant’s consent. Furthermore, regarding the restrained read right and setting up participants’ sample process way if there were death or lost of their capacity; (4) Biobank Management: The safety regulation, obligation of active notification, free to retreat, data destruction, confidentiality and obligation, and termination of operation handling are stipulated; and (5) Biobank Application: According to the new draft statute, that the biological data can’t be used for other purposes, for example, the use of inquisition result for the "Civil law", article 1063, provision 2, prosecution for denying the parent-child relationship law suit", or according to the "Criminal law", article 213, provision 6. This rule not only protects the participants’ body information and their privacy right, but also clearly defines application limits, as well as to set up the mechanism for inner control and avoid conflict of interests to prevent unnecessary disputes. Finally, the Department of Health noted that, as many medical researches has shown that the occurrence of diseases are mostly co-effected by various factors such as multiple genes and their living environment, rather than one single gene, developed countries have actively devoted to human biological sample collection for their national biobank establishment. The construction and usage of a large-scale human bank may bring up the critical issue such as privacy protection and ethical problems; however, to meet the equilibrium biomedical research promotion and citizen privacy issue will highly depend on the cooperation and trust between the public and private sectors. Taiwan Department of Health Announced the Human Biobanks Information Security Regulation The field of human biobanks will be governed by the Act of Human Biobanks (“Biobanks Act”) after its promulgation on February 3, 2010 in Taiwan. According to Article 13 of the Biobanks Act, a biobank owner should establish its directive rules based on the regulation of information security of biobanks announced by the competent authority. Thus the Department of Health announced the draft of the Human Biobanks Information Security Regulation (“Regulation”) for the due process requirement. According to the Biobanks Act, only the government institutes, medical institutes, academic institutes, and research institutes are competent to establish biobanks (Article 4). In terms of the collecting of organisms, the participants should be informed of the relevant matters by reasonable patterns, and the collecting of organisms may be conducted after obtaining the written consent of the participants (Article 6). The relative information including the organisms and its derivatives are not allowed to be used except for biological and medical research. After all the protection of biobanks relative information above, the most important thing is the safety regulations and directive rules of the database administration lest all the restrictions of biobanks owners and the use be in vain. The draft Regulation aims to strengthen the safety of biobanks database and assure the data, the systems, the equipments, and the web circumstances are safe for the sake of the participants’ rights. The significant aspects of the draft are described as below. At first, the regulation should refer to the ISO27001, ISO27002 and other official rules. Concerning the personnel management, the security assessment is required and the database management personnel and researchers may not serve concurrently. In case some tasks are outsourced, the contractor should be responsible for the information security; the nondisclosure agreement and auditing mechanism are required. The application system should update periodically including the anti-virus and firewall programs. The biobanks database should be separated physically form internet connection, including the prohibition of information transforming by email or any other patterns through internet. The authorizing protocol of access to the biobanks should be established and all log files should be preserved in a period. The system establishment and maintenance should avoid remote control. In case the database system is physically out of the owner’s control, the authorization of the officer in charge is required. If an information security accident occurred, the bionbanks owner should contact the competent authority immediately and inform the participants by adequate tunnel. The biobanks owner should establish annual security auditing program and the project auditing will be conducted subject to the necessity. To sum up, while the biobanks database security regulation is fully established, the biobanks owners will have the sufficient guidance in connection with the biobank information security to comply with in the future.

The opening and sharing of scientific data- The Data Policy of the U.S. National Institutes of Health

The opening and sharing of scientific data- The Data Policy of the U.S. National Institutes of Health Li-Ting Tsai   Scientific research improves the well-being of all mankind, the data sharing on medical and health promote the overall amount of energy in research field. For promoting the access of scientific data and research findings which was supported by the government, the U.S. government affirmed in principle that the development of science was related to the retention and accesses of data. The disclosure of information should comply with legal restrictions, and the limitation by time as well. For government-sponsored research, the data produced was based on the principle of free access, and government policies should also consider the actual situation of international cooperation[1]Furthermore, the access of scientific research data would help to promote scientific development, therefore while formulating a sharing policy, the government should also consider the situation of international cooperation, and discuss the strategy of data disclosure based on the principle of free access.   In order to increase the effectiveness of scientific data, the U.S. National Institutes of Health (NIH) set up the Office of Science Policy (OSP) to formulate a policy which included a wide range of issues, such as biosafety (biosecurity), genetic testing, genomic data sharing, human subjects protections, the organization and management of the NIH, and the outputs and value of NIH-funded research. Through extensive analysis and reports, proposed emerging policy recommendations.[2] At the level of scientific data sharing, NIH focused on "genes and health" and "scientific data management". The progress of biomedical research depended on the access of scientific data; sharing scientific data was helpful to verify research results. Researchers integrated data to strengthen analysis, promoted the reuse of difficult-generated data, and accelerated research progress.[3] NIH promoted the use of scientific data through data management to verify and share research results.   For assisting data sharing, NIH had issued a data management and sharing policy (DMS Policy), which aimed to promote the sharing of scientific data funded or conducted by NIH.[4] DMS Policy defines “scientific data.” as “The recorded factual material commonly accepted in the scientific community as of sufficient quality to validate and replicate research findings, regardless of whether the data are used to support scholarly publications. Scientific data do not include laboratory notebooks, preliminary analyses, completed case report forms, drafts of scientific papers, plans for future research, peer reviews, communications with colleagues, or physical objects, such as laboratory specimens.”[5] In other words, for determining scientific data, it is not only based on whether the data can support academic publications, but also based on whether the scientific data is a record of facts and whether the research results can be repeatedly verified.   In addition, NIH, NIH research institutes, centers, and offices have had expected sharing of data, such as: scientific data sharing, related standards, database selection, time limitation, applicable and presented in the plan; if not applicable, the researcher should propose the data sharing and management methods in the plan. NIH also recommended that the management and sharing of data should implement the FAIR (Findable, Accessible, Interoperable and Reusable) principles. The types of data to be shared should first in general descriptions and estimates, the second was to list meta-data and other documents that would help to explain scientific data. NIH encouraged the sharing of scientific data as soon as possible, no later than the publication or implementation period.[6] It was said that even each research project was not suitable for the existing sharing strategy, when planning a proposal, the research team should still develop a suitable method for sharing and management, and follow the FAIR principles.   The scientific research data which was provided by the research team would be stored in a database which was designated by the policy or funder. NIH proposed a list of recommended databases lists[7], and described the characteristics of ideal storage databases as “have unique and persistent identifiers, a long-term and sustainable data management plan, set up metadata, organizing data and quality assurance, free and easy access, broad and measured reuse, clear use guidance, security and integrity, confidentiality, common format, provenance and data retention policy”[8]. That is to say, the design of the database should be easy to search scientific data, and should maintain the security, integrity and confidentiality and so on of the data while accessing them.   In the practical application of NIH shared data, in order to share genetic research data, NIH proposed a Genomic Data Sharing (GDS) Policy in 2014, including NIH funding guidelines and contracts; NIH’s GDS policy applied to all NIHs Funded research, the generated large-scale human or non-human genetic data would be used in subsequent research. [9] This can effectively promote genetic research forward.   The GDS policy obliged researchers to provide genomic data; researchers who access genomic data should also abide by the terms that they used the Controlled-Access Data for research.[10] After NIH approved, researchers could use the NIH Controlled-Access Data for secondary research.[11] Reviewed by NIH Data Access Committee, while researchers accessed data must follow the terms which was using Controlled-Access Data for research reason.[12] The Genomic Summary Results (GSR) was belong to NIH policy,[13] and according to the purpose of GDS policy, GSR was defined as summary statistics which was provided by researchers, and non-sensitive data was included to the database that was designated by NIH.[14] Namely. NIH used the application and approval of control access data to strike a balance between the data of limitation access and scientific development.   For responding the COVID-19 and accelerating the development of treatments and vaccines, NIH's data sharing and management policy alleviated the global scientific community’s need for opening and sharing scientific data. This policy established data sharing as a basic component in the research process.[15] In conclusion, internalizing data sharing in the research process will help to update the research process globally and face the scientific challenges of all mankind together. [1]NATIONAL SCIENCE AND TECHNOLOGY COUNCIL, COMMITTEE ON SCIENCE, SUBCOMMITEE ON INTERNATIONAL ISSUES, INTERAGENCY WORKING GROUP ON OPEN DATA SHARING POLICY, Principles For Promoting Access To Federal Government-Supported Scientific Data And Research Findings Through International Scientific Cooperation (2016), 1, organized from Principles, at 5-8, https://obamawhitehouse.archives.gov/sites/default/files/microsites/ostp/NSTC/iwgodsp_principles_0.pdf (last visited December 14, 2020). [2]About Us, Welcome to NIH Office of Science Policy, NIH National Institutes of Health Office of Science Policy, https://osp.od.nih.gov/about-us/ (last visited December 7, 2020). [3]NIH Data Management and Sharing Activities Related to Public Access and Open Science, NIH National Institutes of Health Office of Science Policy, https://osp.od.nih.gov/scientific-sharing/nih-data-management-and-sharing-activities-related-to-public-access-and-open-science/ (last visited December 10, 2020). [4]Final NIH Policy for Data Management and Sharing, NIH National Institutes of Health Office of Extramural Research, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-013.html (last visited December 11, 2020). [5]Final NIH Policy for Data Management and Sharing, NIH National Institutes of Health Office of Extramural Research, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-013.html (last visited December 12, 2020). [6]Supplemental Information to the NIH Policy for Data Management and Sharing: Elements of an NIH Data Management and Sharing Plan, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-014.html (last visited December 13, 2020). [7]The list of databases in details please see:Open Domain-Specific Data Sharing Repositories, NIH National Library of Medicine, https://www.nlm.nih.gov/NIHbmic/domain_specific_repositories.html (last visited December 24, 2020). [8]Supplemental Information to the NIH Policy for Data Management and Sharing: Selecting a Repository for Data Resulting from NIH-Supported Research, Office of The Director, National Institutes of Health (OD), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-21-016.html (last visited December 13, 2020). [9]NIH Genomic Data Sharing, National Institutes of Health Office of Science Policy, https://osp.od.nih.gov/scientific-sharing/genomic-data-sharing/ (last visited December 15, 2020). [10]NIH Genomic Data Sharing Policy, National Institutes of Health (NIH), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-14-124.html (last visited December 17, 2020). [11]NIH Genomic Data Sharing Policy, National Institutes of Health (NIH), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-14-124.html (last visited December 17, 2020). [12]id. [13]NIH National Institutes of Health Turning Discovery into Health, Responsible Use of Human Genomic Data An Informational Resource, 1, at 6, https://osp.od.nih.gov/wp-content/uploads/Responsible_Use_of_Human_Genomic_Data_Informational_Resource.pdf (last visited December 17, 2020). [14]Update to NIH Management of Genomic Summary Results Access, National Institutes of Health (NIH), https://grants.nih.gov/grants/guide/notice-files/NOT-OD-19-023.html (last visited December 17, 2020). [15]Francis S. Collins, Statement on Final NIH Policy for Data Management and Sharing, National Institutes of Health Turning Discovery Into Health, https://www.nih.gov/about-nih/who-we-are/nih-director/statements/statement-final-nih-policy-data-management-sharing (last visited December 14, 2020).

TOP