Authority

L2 specialized data-rights law under Constitutional Supremacy, Fundamental Rights, Knowledge/Memory/Data Governance Law, Civil Code, Identity Law, Evidence Code and Mental Sovereignty baseline.

Purpose

建立個資、身份、biometric、neurodata、memory data、derived psychological inference、model-training reuse 與跨系統資料處理的可執行權利。

PART I|DATA CLASSES

1. Personal Data

可識別或合理關聯至 personhood / legal identity 的資料。

2. Sensitive Identity Data

biometric template、credential history、high-assurance authentication events。

3. Cognitive / Neurodata

raw or derived neural signal、memory content、mental-state inference、psychological profile、affect traces where linked to a person。

4. Institutional / Public Record

依法須保存的公共/法律/Canon/治理紀錄;仍需 access and purpose rules。

5. Derived / Inferred Data

模型推論不是「因為不是原始資料」就脫離權利保護。

PART II|LAWFUL PROCESSING

6. Lawful Basis

處理必須有 consent、contract necessity、legal duty、vital interest、public authority 或其他明確法定基礎。

7. Purpose Limitation

身份驗證、醫療、研究、就業、教育、保險、治理用途不得默認互通。

8. Data Minimization

只處理完成合法目的所需資料。

9. Accuracy / Correction

materially wrong identity/risk/provenance/psychological labels must be correctable and propagated.

10. Storage Limitation

保存期限依目的、法律義務、風險與 public-record exception 明定;「未來可能有用」不是無限保存理由。

PART III|CONSENT & CONTROL

11. Separate Purpose Consent

record/store/share/train/infer/modify/reconstruct/public-display 分別處理。

12. Withdrawal

撤回對未來處理生效;已合法完成處理、公共紀錄與法定保存依規則處理,不以「刪除一切歷史」假裝事件未發生。

13. Refusal Efficacy

essential service 不得以不必要的 cognitive/neurodata sharing 作強迫 consent。

PART IV|COGNITIVE / NEURODATA SPECIAL RULES

14. No General Mind Dump

司法、僱傭、保險、平台或治理不得把完整 mind dump 作一般條件。

15. Mental-State Inference

從行為/生理/語言推論心理狀態屬 sensitive processing;必須標示 model/status/scope,不得把 inference 冒充 direct observation。

16. Emotion / Personality Secondary Use

不得因原本為 wellness/therapy/education 收集資料,就自動轉作 criminal risk、credit、employment or political screening。

17. Neurodata Write Access

任何 write/modification 權限另受 Mental Sovereignty / Neurotechnology law 管制。

PART V|MODEL TRAINING & DERIVATIVES

18. Training Reuse

原資料合法收集不等於自動授權模型訓練;需 lawful basis / license / statutory rule。

19. Model Memorization / Extraction

若模型可實質重現私人內容,應視為資料風險而非「已進模型所以不再是個資」。

20. Synthetic / Anonymous Data

去識別化降低風險但不是魔法;可合理再識別或可連回 person 時,保護規則仍適用。

PART VI|FORK / MERGE / SUCCESSOR

21. Fork

origin consent 不自動授權所有 independent Fork 的未來私人資料;shared-origin history 與 post-fork data 分開。

22. Merge

Merge 不得以技術整合為由抹除 constituent privacy restrictions / secrets / purpose limits。

23. Successor

successor may inherit lawful institutional records, but does not automatically inherit unrestricted access to predecessor private mind/memory.

PART VII|RIGHTS / REMEDIES

24. Access

person may obtain legally available data/processing categories, sources and purposes.

25. Correction

incorrect material data and provenance labels are correctable with immutable correction trail.

26. Deletion / Restriction

where no overriding legal/archive basis applies, data may be deleted or processing restricted; history of a lawful public act need not be falsified to implement privacy.

27. Portability / Interoperability

where technically and legally applicable, person may obtain data in usable format without transferring third-party rights by accident.

28. Breach / Unauthorized Access

material cognitive/biometric/neurodata breach requires containment, audit, affected-person remedy and downstream credential/risk response.

29. Civil / Public Enforcement

unlawful processing may create Civil Code damages, administrative orders and, where intentional and grave, criminal consequences.