Academic Journal of Computing & Information Science, 2022, 5(14); doi: 10.25236/AJCIS.2022.051412.

On Data Security Protection Obligations of Internet Service Providers


Lu Dingliang1, Shan Yifei2

Lu Dingliang

1Law School, Beijing Normal University, Beijing, China

2Hillary Rodham Clinton School of Law, Swansea University, Swansea Wales, the United Kingdom


Multiple legal departments must coordinate for internet service providers to meet their data security protection duties. The data security requirement of ISPs necessitates the coordination of multiple legal entities. Observing the data protection obligations of Internet service providers through the lens of a single legal department or a single regulatory regulation is skewed. A better strategy is to concentrate on the issue at hand and to think broadly. By constructing a comprehensive and multi-level data security protection obligation system for Internet service providers based on the "behavior-consequence" model, it is possible to realize the conceptualization and systematization of norms and develop a comprehensive picture of data security. The normative framework of data security protection for ISPs must be constructed using abstract notions, legal principles, and external systems. The "rule-principle" style of legal system construction enables the synchronization of formal and substantive justice, as well as stability and correctness. The normative framework focusing on data security protection is favourable to Internet service provider compliance governance. Effective compliance governance can make ISPs more attentive to the use and security of data.


ISPs; data security; logic structure of legal norm; system constructure; compliance regulation

Lu Dingliang, Shan Yifei. On Data Security Protection Obligations of Internet Service Providers. Academic Journal of Computing & Information Science (2022), Vol. 5, Issue 14: 72-81. https://doi.org/10.25236/AJCIS.2022.051412.


