Legal Analysis of a Personal Information Dispute Case

The plaintiff A alleged in the lawsuit that the defendant B, when sending express parcels on multiple occasions, without the plaintiff’s consent, privately used the identity card information that the plaintiff had once presented, and bound it together with the number 153XXXX and stored it in the express delivery system. After the plaintiff learned of this conduct and, at the first moment, orally expressed by telephone that he did not agree to the associated storage of the two kinds of information, B did not handle it. Therefore, the district people’s court in Beijing held that B’s continued storage and use of the plaintiff’s identity information had already infringed the plaintiff’s right of control over his personal information.

In the end, the people’s court identified the disputed focal points as follows:

  1. The practice of binding a telephone number together with an identity document number should obtain the user’s consent;

  2. B’s failure to handle the matter after the plaintiff expressly stated by telephone that he did not agree had already infringed Liu’s right of control over his personal information.

This article cites this case as a classic case for two reasons. First, the service of sending and receiving express parcels is extremely common in daily life, and the express delivery industry involves an extremely broad scope of users’ personal information, including but not limited to citizens’ identity card information, telephone numbers, home addresses, and so on. If such information is associated with each other, it can completely constitute a user’s basic profile in the express information network, and express transportation companies that keep such information should pay attention to it. Second, the plaintiff in this case was very rigorous in raising claims and in the stages of presenting and cross-examining evidence, which has high reference value for citizens using the law to safeguard their own rights and interests.

Guozun Lawyer believes that the manifestation of infringement by APPs illegally collecting users’ personal information is relatively obvious. Taking the above case as an example, when the sender places an order for the first time, B automatically associates the sender’s telephone number with the identity card in the identity security data service system, unless the sender provides a new identity document number. However, the plaintiff A did not know of the binding, and at the time of sending again had already clearly stated that he did not agree to the use of his information. Yet the three express orders involved in the lawsuit were not sent by A, but still recorded the sender information as A, greatly infringing A’s personal information rights. In this case, A preserved evidence of the defendant’s infringement, such as screenshots of the waybills, screenshots of other people placing orders on the APP, and call recordings. Through the sender shown on the waybill as “C Accountant” and screenshots of other people placing orders, it was proved that the sender was not the plaintiff, but the sender information was actually the plaintiff’s information. This powerfully proved the defendant’s infringement facts and obtained the support of the court.

In most situations, the plaintiff is unable to produce evidence, or does not have substantial evidence proving that the APP involved in the case actually called other personal data in the plaintiff’s mobile device, and the success rate in litigation is relatively low. In many situations, the plaintiff only superficially sees the association of the information, but cannot further confirm it through technological means. In addition, for example, in case D, the plaintiff could not prove that the act of calling personal information without the plaintiff’s authorization infringed the plaintiff’s lawful rights and interests. Without damage consequences, the constituent elements of infringement conduct cannot be established, and therefore it is difficult for the court to support the claim.

The main manifestation of APP infringement conduct is that, without the user’s consent, it privately collects the user’s personal information. However, its method of collection is extremely concealed and difficult to detect, while the impact caused is slight, even making people accustomed to it. For example, when carrying out mobile phone recharge in Alipay, it is only stated at the very bottom that the service is provided by the Tmall platform and its merchants, but after the recharge, the recharge order can be seen on Taobao. Because most users almost never repeatedly check their own Taobao orders, and under normal circumstances will not scroll the page to the very bottom to see which merchant provided the service, they do not notice the abnormality. At the same time, even if they discover something is wrong, very few people spend time filing a lawsuit because of “the display of a Taobao order.”

When hearing a case, the court first cited the Civil Code and the Cybersecurity Law of the People’s Republic of China to determine personal information, and determined personal information according to the standard of information that alone or in combination with other information can identify the identity of a natural person. Second, when demonstrating the infringing conduct, it did not cite statutory provisions, but continuously analyzed whether the defendant’s conduct conformed to the service contract or the user agreement, and reasoned through the contents on authorization in the User Agreement and the relevant contents in the Privacy Policy. There is no specific uniform standard, and therefore it is very easy to cause different judgments in similar cases. The final result of the case depends on the judge’s own understanding of personal information.


← Back to List