农业大数据学报 ›› 2025, Vol. 7 ›› Issue (3): 357-370.doi: 10.19788/j.issn.2096-6369.000077

• 数据管理 • 上一篇    下一篇

开放科学背景下数据馆员处理个人信息的挑战、规范与安全管理体系研究

顾立平1,2,*(), 张广寅1,2, 万益嘉3   

  1. 1.中国科学院文献情报中心, 北京 100190
    2.中国科学院大学经济与管理学院信息资源管理系, 北京 100190
    3.山东大学图书馆,济南 250100
  • 收稿日期:2024-10-31 接受日期:2025-06-19 出版日期:2025-09-26 发布日期:2025-09-28
  • 通讯作者: 顾立平,E-mail: gulp@mail.las.ac.cn
  • 基金资助:
    国家社会科学基金项目“开放科学环境中数据馆员服务模式研究(Data Librarian Service Models in open science environment)”(21BTQ005)

Processing Personal Information by Data Librarians under Open Science: Challenges, Guidelines, and Security Management Systems

GU LiPing1,2,*(), ZHANG GuangYin1,2, WAN YiJia3   

  1. 1. National Science Library, Chinese Academy of Sciences, Beijing 100190; China
    2. Department of Information Resources Management, School of Economics and Management, University of Chinese Academy of Science, Beijing 100190, China
    3. Shandong University Library, Jinan 250100, China
  • Received:2024-10-31 Accepted:2025-06-19 Published:2025-09-26 Online:2025-09-28

摘要:

在开放科学深化科研数据管理实践的背景下,数据馆员处理个人信息需应对法律、伦理与实践挑战以平衡开放与保护,本研究旨在提供相应规范与策略。本研究首先系统梳理了个人信息保护相关的法律法规体系及相关核心概念,探讨了科研活动中独特的伦理考量与实践特殊性。随后,深入分析了数据馆员在个人信息获取、组织、共享与发布等关键环节中应遵循的操作规范、面临的主要风险与实践挑战。在此基础上,参照相关法律要求与标准,提出了一个涵盖组织、人员、物理和技术四个维度的、面向数据馆员的个人信息综合安全管理体系框架。研究发现,数据馆员在实践中面临多重困境:将法律原则应用于复杂科研场景时的操作难点;满足高于法律底线的伦理要求;调和开放科学与个人信息保护之间的内在矛盾。研究强调个人信息风险贯穿数据全生命周期,并呈现显著的学科差异性,凸显了构建系统化、多维度综合安全管理体系的必要性与紧迫性。本研究为数据馆员处理个人信息提供了清晰的法律边界、伦理指引和风险识别框架。提出的综合安全管理体系可作为实践参考,有助于提升数据馆员及所在机构的个人信息保护能力与合规水平,从而在保障数据主体权益的基础上,推动负责任、可持续的开放科学发展。

关键词: 数据馆员, 个人信息保护, 开放科学, 科研数据管理, 安全管理体系

Abstract:

In the context of open science deepening research data management practices, data librarians processing personal information need to address legal, ethical, and practical challenges to balance openness and protection. This study aims to provide corresponding guidelines and strategies. This study first systematically reviews the legal and regulatory framework related to personal information protection, as well as relevant core concepts, and explores the unique ethical considerations and practical particularities in research activities. Subsequently, the study conducts an in-depth analysis of the operational norms that data librarians should follow, the major risks they face, and the practical challenges encountered in key processes such as the collection, organization, sharing, and release of personal information. On this basis, and with reference to relevant legal requirements and standards, the study proposes a comprehensive personal information security management framework for data librarians, covering four dimensions: organizational, personnel, physical, and technical. The study finds that data librarians face multiple dilemmas in practice: operational difficulties in applying legal principles to complex research scenarios; meeting ethical requirements that often exceed legal minimums; and reconciling the inherent conflicts between open science and personal information protection. The research highlights that personal information risks permeate the entire data lifecycle and exhibit significant disciplinary differences, underscoring the necessity and urgency of establishing a systematic, multi-dimensional, comprehensive security management system. This study provides data librarians with clear legal boundaries, ethical guidance, and a risk identification framework for processing personal information. The proposed comprehensive security management system can serve as a practical reference, helping to enhance the personal information protection capabilities and compliance levels of both data librarians and their institutions. Thereby, on the basis of safeguarding the rights and interests of data subjects, it promotes the development of responsible and sustainable open science.

Key words: data librarian, personal information protection, open science, research data management, security management system