Authority
L2 specialized data-rights law under Constitutional Supremacy, Fundamental Rights, Knowledge/Memory/Data Governance Law, Civil Code, Identity Law, Evidence Code and Mental Sovereignty baseline.
Purpose
建立個資、身份、biometric、neurodata、memory data、derived psychological inference、model-training reuse 與跨系統資料處理的可執行權利。
PART I|DATA CLASSES
1. Personal Data
可識別或合理關聯至 personhood / legal identity 的資料。
2. Sensitive Identity Data
biometric template、credential history、high-assurance authentication events。
3. Cognitive / Neurodata
raw or derived neural signal、memory content、mental-state inference、psychological profile、affect traces where linked to a person。
4. Institutional / Public Record
依法須保存的公共/法律/Canon/治理紀錄;仍需 access and purpose rules。
5. Derived / Inferred Data
模型推論不是「因為不是原始資料」就脫離權利保護。
PART II|LAWFUL PROCESSING
6. Lawful Basis
處理必須有 consent、contract necessity、legal duty、vital interest、public authority 或其他明確法定基礎。
7. Purpose Limitation
身份驗證、醫療、研究、就業、教育、保險、治理用途不得默認互通。
8. Data Minimization
只處理完成合法目的所需資料。
9. Accuracy / Correction
materially wrong identity/risk/provenance/psychological labels must be correctable and propagated.
10. Storage Limitation
保存期限依目的、法律義務、風險與 public-record exception 明定;「未來可能有用」不是無限保存理由。
PART III|CONSENT & CONTROL
11. Separate Purpose Consent
record/store/share/train/infer/modify/reconstruct/public-display 分別處理。
12. Withdrawal
撤回對未來處理生效;已合法完成處理、公共紀錄與法定保存依規則處理,不以「刪除一切歷史」假裝事件未發生。
13. Refusal Efficacy
essential service 不得以不必要的 cognitive/neurodata sharing 作強迫 consent。
PART IV|COGNITIVE / NEURODATA SPECIAL RULES
14. No General Mind Dump
司法、僱傭、保險、平台或治理不得把完整 mind dump 作一般條件。
15. Mental-State Inference
從行為/生理/語言推論心理狀態屬 sensitive processing;必須標示 model/status/scope,不得把 inference 冒充 direct observation。
16. Emotion / Personality Secondary Use
不得因原本為 wellness/therapy/education 收集資料,就自動轉作 criminal risk、credit、employment or political screening。
17. Neurodata Write Access
任何 write/modification 權限另受 Mental Sovereignty / Neurotechnology law 管制。
PART V|MODEL TRAINING & DERIVATIVES
18. Training Reuse
原資料合法收集不等於自動授權模型訓練;需 lawful basis / license / statutory rule。
19. Model Memorization / Extraction
若模型可實質重現私人內容,應視為資料風險而非「已進模型所以不再是個資」。
20. Synthetic / Anonymous Data
去識別化降低風險但不是魔法;可合理再識別或可連回 person 時,保護規則仍適用。
PART VI|FORK / MERGE / SUCCESSOR
21. Fork
origin consent 不自動授權所有 independent Fork 的未來私人資料;shared-origin history 與 post-fork data 分開。
22. Merge
Merge 不得以技術整合為由抹除 constituent privacy restrictions / secrets / purpose limits。
23. Successor
successor may inherit lawful institutional records, but does not automatically inherit unrestricted access to predecessor private mind/memory.
PART VII|RIGHTS / REMEDIES
24. Access
person may obtain legally available data/processing categories, sources and purposes.
25. Correction
incorrect material data and provenance labels are correctable with immutable correction trail.
26. Deletion / Restriction
where no overriding legal/archive basis applies, data may be deleted or processing restricted; history of a lawful public act need not be falsified to implement privacy.
27. Portability / Interoperability
where technically and legally applicable, person may obtain data in usable format without transferring third-party rights by accident.
28. Breach / Unauthorized Access
material cognitive/biometric/neurodata breach requires containment, audit, affected-person remedy and downstream credential/risk response.
29. Civil / Public Enforcement
unlawful processing may create Civil Code damages, administrative orders and, where intentional and grave, criminal consequences.