法学家 ›› 2026, Vol. 0 ›› Issue (2): 70-83.

• 主题研讨二:数字法学研究的多维视角 • 上一篇    下一篇

数据经纪的衍生风险与法律应对

唐林垚   

  • 出版日期:2026-03-15 发布日期:2026-03-23
  • 作者简介:*唐林垚,法学博士,中国社会科学院法学研究所副研究员、中国社会科学院大学副教授。
  • 基金资助:
    中国社会科学院青年人文社会科学研究中心社会调研项目“数据经纪的法律规制”(2026QNZX021)的阶段性成果。

Addressing the Derivative Harm of Data Brokerage

TANG Linyao   

  • Online:2026-03-15 Published:2026-03-23
  • About author:Tang Linyao, Ph.D. in Law, Associate Researcher of Institute of Law, Chinese Academy of Social Sciences, Associate Professor of University of Chinese Academy of Social Sciences.

摘要: 数据经纪解耦了垂直数据关系对水平数据关系的束缚,水平数据关系得以无序扩张并催生衍生损害。衍生损害既无法通过强化个人信息保护纾解,也难被传统侵权责任涵摄,具备单独规制必要。数据影响保护评估、公平数据经纪实践有望通过抽象风险损害化应对衍生损害,但须各自补全损害实质性判断标准。事前防范维度,应将兼顾匿名化水准、数据敏感度、数据集体量与推论数据占比的数据整合分析纳入数据影响保护评估,将兼顾主体重合度、属性重合度、处理目的重合度、时间重合度的数据整合分析纳入公平数据经纪实践,并综合潜在受害者数量、损害概率与损害程度酌定损害实质程度。事后归责维度,应根据数据经纪与主侵权行为的致害原因力大小科学划定责任分配。

关键词: 数据经纪, 衍生损害, 数据关系, 实质性损害, 数据整合分析

Abstract: Data brokerage decouples the constraints imposed by vertical data relationships on horizontal data relationships, giving rise to a novel type of derivative harm.Such harm is characterized by intangibility, latency, and cumulativeness.It cannot be adequately addressed solely by strengthening personal information protection nor easily subsumed under traditional tort liability frameworks, thus necessitating separate and ex-ante regulation.While data protection impact assessments (DPIAs) and fair data brokerage practices hold potential for materializing abstract risks into tangible harm, their effectiveness depends on incorporating substantive criteria for evaluating derivative harm.From an ex-ante prevention perspective, data integration analysis—considering the level of anonymization, data sensitivity, data collective volume, and the proportion of inferred data—should be embedded into DPIAs.Similarly, data integration analysis that accounts for the degree of subject overlap, embedded attribute overlap, processing purpose overlap, and temporal overlap should be integrated into fair data brokerage practices.The substantive degree of derivative harm must be comprehensively assessed based on the number of potential victims, the probability of harm occurrence, and the severity of harm.From an ex-post liability attribution perspective, responsibility allocation should be scientifically delineated according to the causal contribution of data brokerage activities and primary infringing acts to the harm.

Key words: Data Brokerage, Derivative Harm, Data Relationships, Substantive Harm, Data Integration Analysis