本文基于信息生命周期理论,对15款疫情防控App和小程序的隐私政策进行文本分析,研究发现:用户数据产生前的信息创建阶段,与App端服务相比,小程序端普遍存在隐私政策未制定或未公开、张贴位置不明显、用户查找不便利的情形;用户数据产生后的信息收集、存储与保护、共享与流动和使用四个阶段中,也均有不完全合规的情形出现,大部分应用在信息收集规则、信息存储时限、信息共享与跨境传输问题以及用户的信息支配权方面,存在说明不完整的情况。因此,本文基于信息生命周期理论视角,从数据创建、数据收集、数据存储、数据共享、数据清理五个阶段对疫情防控移动应用的隐私政策提出建议,并倡导从多角度构建多利益相关方的个人信息保护模式。
<<Based on information lifecycle theory,the paper analyzes the privacy policies of 15 mobile applications and mini apps,which are closely related to COVID-19 prevention and control. In information created stage,when users have not produced data yet,most mini apps lack of privacy policies and the posting locations are not obvious compared with apps,which make users find it inconvenient. After users’ data creating,there are still some problems in next four stage,including information collecting,storing,sharing and using. Most applications are incomplete in their descriptions of information collection rules,retention time,data sharing,cross-border transmission issues,and users’ information control rights.
<<