The main reasons for the frequent disclosure of personal information in the express delivery industry are that a few express delivery companies are not strict in internal control and do not pay attention to the protection of personal information. Paying attention to the protection of personal information means increasing investment, which means cost, and increasing cost means decreasing income. On the other hand, buying and selling information can also make money, which leads to the disclosure of personal information becoming the norm.
The current laws, including the Consumer Protection Law and the Cyber Security Law, all mention the protection of personal information. The key is to enhance the operability, litigation and arbitrability of the law for the protection of personal information.
□ Our reporter Du Xiao
□ Intern of this newspaper Han Wei
In order to better protect users’ personal information, YTO Express, a courier company, recently launched an "invisible face sheet".
In this regard, Weibo, the official of the State Post Bureau, announced that YTO Express implemented an "invisible face sheet", which did not show all the information of name, mobile phone number and address, but only part of it.
To what extent can the "invisible face sheet" protect personal information? In this regard, the "Legal Daily" reporter interviewed industry experts.
The meaning of "invisible face sheet" may be limited
Once the "invisible face sheet" was launched, it immediately attracted the attention of all walks of life.
According to Tan Shuhua, senior director of YTO Express R&D Center, at present, the "invisible face sheet" mainly has three "hidden functions", which can encrypt the user’s mobile phone number, name and address. For example, for the user’s mobile phone number, some numbers will be hidden by technical means.
The official Weibo of the State Post Bureau also published photos about the "Invisible Face Sheet".
How much can the "invisible face sheet" play in protecting personal information?
"For the protection of personal information, ‘ Invisible face sheet ’ It can still have a big effect. There are mainly two aspects. First, the courier can’t see all the personal mobile phone numbers and other personal information of consumers. Second, people who receive express delivery instead of consumers, such as property and security guards, can’t see the personal information of consumers. Of course, ‘ Invisible face sheet ’ Certainly not foolproof. " Liu Junhai, vice president of China Consumers Association and a professor at Renmin University of China Law School, said.
“‘ Invisible face sheet ’ Can play a role, because ‘ Invisible face sheet ’ Encrypted by technical means, it is impossible for individual courier brothers to sell express orders and collect personal information. In other words, it is becoming more and more difficult for couriers to buy and sell personal information directly. " Lawyer Qiu Baochang, a member of the Expert Committee of the China Consumers Association, said.
“‘ Invisible face sheet ’ It is already available abroad, but the amount of application is not large, mainly used for some items involving special value and special privacy. " Xu Yong, chief consultant of Express Logistics Consulting Network, said that the "invisible face sheet" is actually a two-dimensional code technology, which needs to be scanned before you can see the relevant information of the recipient.
Judging from the published photos, YTO Express’s "Invisible Face Sheet" belongs to bar code.
Xu Yong believes that bar codes belong to one-dimensional codes. The QR code has more information. The "invisible face sheet" can be a two-dimensional code or a one-dimensional code. One-dimensional code may be used to save costs, and sorting is not affected. If two-dimensional code is used, scanning equipment needs to be replaced.
"There are many links in express delivery. As far as the traditional express delivery industry is concerned, express delivery is directly received by couriers, which involves personal information, which is an unavoidable problem in the traditional express delivery industry. It is also worth considering how personal information works well in the background of the courier company and how to properly protect it. " Qiu Baochang said.
“‘ Invisible face sheet ’ Its role in protecting personal information is limited. Because from the perspective of personal information disclosure, it is too expensive to collect personal information through express delivery sheets. From the perspective of buying and selling personal information, it makes sense to buy thousands of pieces of personal information. For the problem of personal information disclosure in the express delivery industry, everyone should still treat it rationally. The courier list belongs to a single personal information and has limited value. " Xu Yong said, "‘ Invisible face sheet ’ The real significance is that it shows that our express delivery enterprises are becoming more and more mature and have a stronger sense of service, and can provide personalized services. I think ‘ Invisible face sheet ’ The significance of this aspect is greater than that of personal information protection. "
Employee training and education is the key.
News about the disclosure of personal information in the express delivery industry has been exposed in the media from time to time.
After the Xu Yuyu case, some media reported that "after the express waybill passed through many links, such as e-commerce, consignee, sorting and entry, many times personal information had already been leaked and sold on the Internet".
"The main reason why the express delivery industry has repeatedly leaked personal information is that a few express delivery companies are not strict in internal control and do not pay attention to the protection of personal information. Paying attention to the protection of personal information means increasing investment, which means cost, and increasing cost means decreasing income. On the other hand, buying and selling information can also make money, which leads to the disclosure of personal information becoming the norm. " Liu Junhai said.
Xu Yong believes that there are mainly the following channels for express delivery to disclose personal information: one is that "hackers" attack to steal personal information. In the Internet age, it has become a new illegal and criminal channel to make profits by using network loopholes and illegal operations, which is characterized by a large amount of illegal access to personal information. For example, a large express delivery company was exposed to 13 information system security vulnerabilities, and "hackers" used this to steal more than 30,000 customer information. The characteristic of this channel for obtaining customer information is that it needs technical means, and it obtains the most personal information of customers, which is difficult for ordinary people to do. Another channel is duty crimes committed by couriers and related personnel. In order to obtain illegitimate interests, some couriers and related personnel use their positions to sell customers’ personal information to so-called "buyers". The characteristic of this channel for obtaining customer information is that it is generally done by employees, and the amount of personal information obtained by them varies. The third channel is that e-commerce related personnel sell customer information. The personal information of customers held by e-commerce is consistent with the information of express waybill, and express delivery is the downstream of e-commerce. In order to increase personal income, some e-commerce workers resell customer information to their peers or through the Internet to obtain illegitimate income.
"There are also online bulk purchases or sales of customer personal information to earn the difference. The price of each courier information varies from a few cents to several yuan according to the quantity and classification. Most buyers and sellers complete transactions through the Internet, and the buyer’s transaction volume is tens of thousands or even tens of thousands. Some websites can also meet special needs such as designated receiving and delivery locations. To expand ‘ Business scale ’ Personal information wholesalers are also recruiting agents all over the country. This channel for obtaining customer information is characterized by the largest amount of customer personal information and the most profit. " Xu Yong said.
Weibo, the official of the State Post Bureau, also mentioned that companies such as SF Express and Suning had introduced similar measures through data desensitization technology. Through scientific and technological means, express delivery companies are carrying out more and more humanized, safe and informative service practices, which can effectively protect consumers’ personal privacy.
While express delivery companies are upgrading their technical means to protect personal information, industry experts generally believe that it is essential to strengthen employee education.
"Express companies should strengthen the education of employees. Sometimes express employees disclose personal information because they don’t know the law, ignorant people are fearless, and the cost of violating the law is not high. When employees join the company, it is necessary to make it clear that personal privacy must be respected and protected. It is also necessary to increase penalties for employees who violate regulations. " Liu Junhai said.
"Overall, the use of technical means by express delivery companies is more effective in protecting personal information. The focus of employee education and training is to abide by laws and regulations. If the legitimate rights and interests of consumers are harmed, there should be some penalties. Let employees know the relevant laws and regulations, not to disclose and buy or sell personal information. If such behavior occurs, in addition to punishment, it should be publicized. We know that the courier brothers are very hard now. However, the courier company can still take a little time every week to train them in laws and regulations. " Qiu Baochang said.
According to Xu Yong, as early as June 2015, "Three Links and One Reach"+SF Express entrusted Bee Network to develop the express logistics credit information system, and 30 kinds of express delivery personnel (even if they resigned) including leaking customer information have been included in the query system for untrustworthy personnel. The information in the "blacklist" of the express logistics credit information system will be kept for five years; The "blacklist" has been opened for free to express logistics credit cooperative enterprises. There are nearly 400 free open query interfaces. In the recruitment of these express delivery companies, thousands of "blacklisted" personnel were refused to be recruited through inquiry and comparison, so that these "blacklisted" personnel could not work again in the express logistics industry.
Enhance the operability of the law
As an important part of e-commerce, the express delivery industry is also becoming an important part of personal information protection.
According to media reports, the e-commerce law (draft) reviewed at the end of last year clearly defined the responsible subjects such as e-commerce platform, merchants, payment and express delivery in several chapters. According to the draft, the maximum penalty for failing to fulfill the obligation of personal information protection is a fine of 500,000 yuan, and it is ordered to suspend business for rectification until the business license is revoked. If the case constitutes a crime, criminal responsibility shall be investigated.
Xu Yong believes that although it is clearly stipulated in the Postal Law that postal enterprises and their employees are not allowed to disclose user information, otherwise, enterprises will be confiscated of their illegal income, fined between 10,000 yuan and 50,000 yuan, and may be ordered to suspend business for rectification or even revoke their business licenses; The illegal income of the relevant personnel will also be confiscated and a fine ranging from 5,000 yuan to 10,000 yuan will be imposed. If the circumstances are serious, it will be handed over to the public security organ for criminal responsibility. The criminal law also stipulates that the collection and reselling of personal information shall be investigated for criminal responsibility according to the circumstances. However, in the actual supervision, express delivery companies are faced with difficulties in finding, investigating, obtaining evidence and punishing, that is, stealing customer personal information is more difficult to find than stealing express mail, which is very concealed.
"In the e-commerce law, it is necessary to further write down the relevant clauses realistically. The current laws, including the Consumer Protection Law and the Cyber Security Law, all mention the protection of personal information. The key is to enhance the operability, litigation and arbitrability of the law for the protection of personal information. " Liu Junhai said that the relevant departments can also consider establishing a "red list" system, so that those enterprises that respect consumers’ privacy rights can get more opportunities to develop and enjoy certain convenience in financing, rating and procurement.
"From a legal point of view, it is necessary to strengthen the legal responsibility of the express delivery industry, and also enhance traceability and operability. Now a key problem is that the source of personal information leakage is not easy to find out. Personal information disclosure involves many industries, not just the express delivery industry. How to effectively combine tracing and punishment, I think this should be considered in law. " Qiu Baochang said.