پژوهشنامه پردازش و مدیریت اطلاعات

پژوهشنامه پردازش و مدیریت اطلاعات

دامنه و آثار تعهد محرمانگی در مدیریت اطلاعات در عصر هوش مصنوعی رویکرد تطبیقی در حقوق ایران ، اتحادیه اروپا و ایالات متحده آمریکا در پرتو رویه قضایی

نوع مقاله : مقاله پژوهشی

نویسندگان
1 گروه حقوق خصوصی دانشکده حقوق و علوم سیاسی، دانشگاه فردوسی ، مشهد، ایران
2 دانشجو کارشناسی ارشد حقوق خصوصی ، دانشکده حقوق و علوم سیاسی دانشگاه فردوسی مشهد ، ایران
10.22034/jipm.2026.2081814.2174
چکیده
در اقتصاد دانش‌بنیان معاصر، داده‌ها به حیاتی‌ترین سرمایه شرکت‌ها بدل شده‌اند و تعهد به حفظ محرمانگی نقشی بنیادین در صیانت از داده ها ایفا می‌کند. این پژوهش با اتخاذ رویکردی تحلیلی-تطبیقی، نظام های حقوقی ایران، ایالات متحده و اتحادیه اروپا را در مواجهه با چالش‌های نوین مدیریت اطلاعات، به‌ویژه ظهور هوش مصنوعی مولد، چالش های دستور دهی به هوش مصنوعی، حق فراموشی داده،شناخت خالق داده های پژوهشی و موارد مشابه بررسی می نماید. یافته‌ها نشان می‌دهد که نظام حقوقی ایالات متحده ، رویکردی «مالکیت‌محور و قراردادی» را برگزیده که در آن حمایت قانونی منوط به اثبات «اقدامات معقول حفاظتی» و مدیریت ریسک است. با محدودیت‌های اخیر بر قراردادهای عدم رقابت در سال ۲۰۲۴، بار اصلی حفاظت در آمریکا بر دوش قراردادهای عدم افشا و اثبات عدم ورود داده به مدل‌های عمومی قرار گرفته است. در مقابل، اتحادیه اروپا با تلفیق دستورالعمل ۲۰۱۶/۹۴۳ و مقررات حفاظت از داده، پارادایمی «تنظیم‌گرانه و حق‌محور» را اتخاذ کرده که در آن محرمانگی بخشی از حقوق بنیادین و نظم عمومی تلقی شده و نقض آن منجر به ضمانت‌اجراهای سنگین اداری می‌گردد. ورود داده به مدل‌های زبانی بزرگ با داده‌های حساس، در رویه‌های نوین به مثابه «انصراف عملی» از حق محرمانگی تفسیر می‌شود؛ چراکه مالک با ورود داده به پلتفرم‌های غیرقابل‌کنترل، شرط «اقدامات معقول حفاظتی» را نقض کرده است. در حقوق ایران، تعهد محرمانگی به‌عنوان بخشی از اصل وفای به عهد و قواعد مسئولیت مدنی، دامنه‌ای گسترده دارد و نقض آن می‌تواند حسب مورد هم ضمانت اجرای قراردادی (مانند خسارت و فسخ) و هم مسئولیت قهری به‌دنبال داشته باشد؛ در عصر هوش مصنوعی، ورود داده‌های حساس به سامانه‌های غیرقابل‌کنترل عملاً وصف محرمانگی را زایل کرده و حمایت قانونی از اسرار تجاری را منتفی می‌سازد.این پژوهش با نقد دکترین سنتی، راهکارهای نوینی همچون دکترین «تعهد مراقبت دیجیتال» و «محرمانگی تفکیکی» را پیشنهاد می‌دهد. همچنین قابلیت اعمال «استرداد الگوریتمی که بر اساس آن، مدلی که با داده‌های غصبی یا محرمانه آموزش دیده، باید به‌طور کامل امحا شود.به همراه امکان پذیرش دکترین «از دست رفتن کنترل» به‌عنوان معیار جدید افشا در حقوق ایران ,بازتعریف ماهیت تعهد محرمانگی(گذار از تعهد منفی به تعهد مراقبتی تشدیدشده)، تغییر بار اثبات به نفع متضرر و شناسایی «تعهد به نتیجه» در مدیریت داده‌های حساس نشان می دهد حقوق ایران فاقد ظرفیت حمایتی نیست، بلکه دچار فقر تفسیر فناورانه است. مفاهیمی مانند مالیت، منفعت عقلایی، ید، امانت و تفریط قابلیت انطباق با داده، الگوریتم و خروجی‌های هوش مصنوعی را دارند.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

The Scope and Effects of Confidentiality Obligations in Information Management in the Age of Artificial Intelligence: A Comparative Approach in Iranian, European Union, and United States Law in Light of Judicial Practice

نویسندگان English

Ali Saatchi 1
Javad Fahimitabar 2
1 Department of Private Law, Faculty of Law and Political Science, Ferdowsi University of Mashhad, Iran
2 Master's student in private law, Faculty of Law and Political Science, Ferdowsi University of Mashhad, Iran
چکیده English

In the contemporary knowledge-based economy, data has become the most vital asset of companies, and the obligation to maintain confidentiality plays a fundamental role in safeguarding it; this study, adopting an analytical-comparative approach, examines the legal systems of Iran, the United States, and the European Union in addressing modern challenges of information management—particularly the rise of generative artificial intelligence, the complexities of AI prompting, the right to be forgotten, the recognition of the creator of research data, and similar issues—and finds that the U.S. legal system has embraced a property- and contract-based approach in which legal protection is contingent upon demonstrating reasonable protective measures and risk management, with the recent restrictions on non-compete agreements in 2024 shifting the burden of protection onto non-disclosure agreements and proof of non-entry of sensitive data into public AI models, while the European Union, through Directive 2016/943 and data protection regulations, has adopted a regulatory and rights-based paradigm in which confidentiality is treated as part of fundamental rights and public order, with breaches leading to severe administrative sanctions and the introduction of sensitive data into large language models increasingly interpreted as a practical waiver of confidentiality rights; in Iranian law, confidentiality obligations are considered part of the principle of pacta sunt servanda and civil liability rules, with breach potentially giving rise to both contractual remedies and tort liability, and in the era of artificial intelligence, the submission of sensitive data to uncontrolled systems effectively nullifies confidentiality and eliminates legal protection for trade secrets, prompting this study to critique traditional doctrines and propose innovative solutions such as digital duty of care, segmented confidentiality, algorithmic restitution requiring destruction of models trained on misappropriated data, and recognition of loss of control as a new disclosure criterion, while also suggesting a redefinition of confidentiality obligations from a negative duty to an intensified duty of care, shifting the burden of proof in favor of the injured party, and recognizing a duty of result in managing sensitive data, thereby demonstrating that Iranian law is not devoid of protective capacity but suffers from a lack of technological interpretation, with concepts such as property value, rational benefit, possession, trust, and negligence being adaptable to data, algorithms, and AI outputs.

Keywords:
Commitment, confidentiality, non-disclosure, data, information management, artificial intelligence

کلیدواژه‌ها English

Commitment
confidentiality
non-disclosure
data
information management
artificial intelligence

مقالات آماده انتشار، پذیرفته شده
انتشار آنلاین از 15 شهریور 1405

  • تاریخ دریافت 02 دی 1404
  • تاریخ بازنگری 15 مرداد 1405
  • تاریخ پذیرش 31 مرداد 1405