Expert perspectives on GDPR compliance in the context of smart homes and vulnerable persons

Piasecki, S.
Information & Communications Technology Law, 2023

Abstract

This article introduces information gathered through 21 semi-structured interviews conducted with UK, EU and international professionals in the field of General Data Protection Regulation (GDPR) compliance and technology design, with a focus on the smart home context and vulnerable people using smart products. Those discussions gave various insights and perspectives into how the two communities (lawyers and technologists) view intricate practical data protection challenges in this specific setting. The variety of interviewees allowed to compare different approaches to data protection compliance topics. Answers to the following questions were provided: when organisations develop and/or deploy smart devices that use personal data, do they take into consideration the needs of vulnerable groups of people to comply with the GDPR? What are the underlying issues linked to the practical data protection law challenges faced by organisations working on smart devices used by vulnerable persons? How do experts perceive data protection law-related problems in this context?

Data protection, GDPR, Internet of Things, smart devices

RIS

Save .RIS

Bibtex

Save .bib

Annotatie Hof van Justitie van de EU 28 april 2022 (Meta Platforms Ireland / Bundesverband der Verbraucherzentralen und Verbraucherverbände) download

Nederlandse Jurisprudentie, iss. : 21, num: 194, pp: 3621-3623, 2023

Facebook, Personal data, Privacy

RIS

Save .RIS

Bibtex

Save .bib

Gemeentelijke grip op private sensorgegevens: Juridisch kader voor het gemeentelijke handelingsperspectief bij de verwerking van private sensorgegevens in de openbare ruimte download

Janssen, H., Verboeket, L.W., Meiring, A., van Hoboken, J., van Eechoud, M., van den Brink, J.E., Ortlep, R. & Bodó, B.
2023

handhaving, Privacy, sensoren, Surveillance

RIS

Save .RIS

Bibtex

Save .bib

EU copyright law round up – second trimester of 2023 external link

Trapova, A. & Quintais, J.
Kluwer Copyright Blog, 2023

Copyright

RIS

Save .RIS

Bibtex

Save .bib

Media Concentration Law: Gaps and Promises in the Digital Age

Media and Communication, vol. 11, iss. : 2, pp: 392-405, 2023

Abstract

Power concentrations are increasing in today’s media landscape. Reasons for this include increasing structural and technological dependences on digital platform companies, as well as shifts in opinion power and control over news production, distribution, and consumption. Digital opinion power and platformised media markets have prompted the need for a re-evaluation of the current approach. This article critically revisits and analyses media concentration rules. To this end, I employ a normative conceptual framework that examines ”opinion power in the platform world” at three distinct levels (individual citizen, institutional newsroom, and media ecosystem). At each level, I identify the existing legal tools and gaps in controlling power and concentration in the digital age. Based on that, I offer a unifying theoretical framework for a “digital media concentration law,” along with core concepts and guiding principles. I highlight policy goals and fields that are outside the traditional scope yet are relevant for addressing issues relating to the digital age. Additionally, the emerging European Union regulatory framework—specifically the Digital Services Act, the Digital Markets Act, and the European Media Freedom Act—reflects an evolving approach regarding platforms and media concentration. On a final note, the analysis draws from the mapping and evaluation results of a Europe-wide study on media pluralism and diversity online, which examined (national) media concentration rules.

digital platforms, editorial independence, European regulation, media concentration, Media law, media pluralism, opinion power, structural dependency

RIS

Save .RIS

Bibtex

Save .bib

Opinie: Internetproletariërs aller landen verenigt u! download

Mediaforum, iss. : 3, pp: 85, 2023

Facebook, Internet, moderators

RIS

Save .RIS

Bibtex

Save .bib

Personal Data Stores and the GDPR’s lawful grounds for processing personal data

Janssen, H., Cobbe, J., Norval, C. & Singh, J.
2019

Abstract

Personal Data Stores (‘PDSs’) entail users having a (physical or virtual) device within which they themselves can, in theory, capture, aggregate, and control the access to and the transfer of personal data. Their aim is to empower users in relation to their personal data, strengthening their opportunities for data protection, privacy, and/or to facilitate trade and monetisation. As PDS technologies develop, it is important to consider their role in relation to issues of data protection. The General Data Protection Regulation requires that the processing of user data be predicated on one of its defined lawful bases, whereby the Regulation does not favour any one basis over another. We explore how PDS architectures relate to these lawful bases, and observe that they tend to favour the bases that require direct user involvement. This paper considers issues that the envisaged architectural choices surrounding the lawful grounds may entail.

Data protection, decentralisation, lawful grounds for processing, personal data stores, Privacy, Transparency

RIS

Save .RIS

Bibtex

Save .bib

Data protection and tech startups: The need for attention, support, and scrutiny

Norval, C., Janssen, H., Cobbe, J. & Singh, J.
Policy & Internet, vol. 13, iss. : 2, pp: 278-299, 2021

Abstract

Though discussions of data protection have focused on the larger, more established organisations, startups also warrant attention. This is particularly so for tech startups, who are often innovating at the ‘cutting-edge’—pushing the boundaries of technologies that typically lack established data protection best-practices. Initial decisions taken by startups could well have long-term impacts, and their actions may inform (for better or for worse) how particular technologies and the applications they support are implemented, deployed, and perceived for years to come. Ensuring that the innovations and practices of tech startups are sound, appropriate and acceptable should therefore be a high priority. This paper explores the attitudes and preparedness of tech startups to issues of data protection. We interviewed a series of UK-based emerging tech startups as the EU's General Data Protection Regulation (GDPR) came into effect, which revealed areas in which there is a disconnect between the approaches of the startups and the nature and requirements of the GDPR. We discuss the misconceptions and associated risks facing innovative tech startups and offer a number of considerations for the firms and supervisory authorities alike. In light of our discussions, and given what is at stake, we argue that more needs to be done to help ensure that emerging technologies and the practices of the companies that operate them better align with the regulatory obligations. We conclude that tech startups warrant increased attention, support, and scrutiny to raise the standard of data protection for the benefit of us all.

RIS

Save .RIS

Bibtex

Save .bib

De toekomst van de digitale rechtsstaat. Pleidooi voor het gebruik van een mensenrechten impact assessment voor de publieke sector external link

(L)aw Matters: Blogs and Essays in Honour of prof. dr. Aalt Willem Hering, Boekenmaker, 2022, pp: 198-204

RIS

Save .RIS

Bibtex

Save .bib

Practical fundamental rights impact assessments

Janssen, H., Seng Ah Lee, M. & Singh, J.
International Journal of Law and Information, vol. 30, iss. : 2, pp: 200-232, 2022

Abstract

The European Union’s General Data Protection Regulation tasks organizations to perform a Data Protection Impact Assessment (DPIA) to consider fundamental rights risks of their artificial intelligence (AI) system. However, assessing risks can be challenging, as fundamental rights are often considered abstract in nature. So far, guidance regarding DPIAs has largely focussed on data protection, leaving broader fundamental rights aspects less elaborated. This is problematic because potential negative societal consequences of AI systems may remain unaddressed and damage public trust in organizations using AI. Towards this, we introduce a practical, four-Phased framework, assisting organizations with performing fundamental rights impact assessments. This involves organizations (i) defining the system’s purposes and tasks, and the responsibilities of parties involved in the AI system; (ii) assessing the risks regarding the system’s development; (iii) justifying why the risks of potential infringements on rights are proportionate; and (iv) adopt organizational and/or technical measures mitigating risks identified. We further indicate how regulators might support these processes with practical guidance.

RIS

Save .RIS

Bibtex

Save .bib