A trust-based framework for the data-driven economy

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040.
Digital Agenda Unleashing the Potential of Cloud Computing in Europe Ken Ducatel Head of Unit Software and Services, Cloud European Commission (Directorate.
European Cloud Computing Conference Panel 1: What should be the legal framework to help create a market for Cloud services? Dalibor Baskovc Member Executive.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
SA Constitution Sec 14 – Privacy – RICA – POPI Sec 32 – Access to Information – PAIA – POPI.
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
RESPECT Guidelines regarding data protection aspects whithin socio-economic research Y. Poullet, K. Rosier, I. Vereecken CRID-FUNDP in cooperation with.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
Implementation of the European Statistics Code of Practice Yalta September 2009 Pieter Everaers, Eurostat.
APEC Engineers Workshop Legal Considerations - Central Register Sept 2015 Angela Frawley, General Counsel.
WHOIS Public safety and data protection requirements.
Privacy, data protection and connected cars Lilian Edwards, Professor of Internet Law University of Strathclyde Researcher in Residence, Digital Catapult.
Presentation Title Data Protection The new EU Regulation Insert your logo here.
The EU General Data Protection Regulation Frank Rankin.
CLAUDIA PANAIT TAIEX Expert – European Commission Legal Adviser Ministry of Health, ROMANIA.
Business Challenges in the evolution of HOME AUTOMATION (IoT)
Protection of Personal Information Act An Analysis on the impact.
Ethical, legal and social aspects of public health genomics Mark Taylor, School of Law, University of Sheffield 7 th November 2014.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
PHILIPPINE COMPETITION ACT
Independent Centre for Privacy Protection Schleswig-Holstein
Brussels Privacy Symposium on Identifiability
Consent and Contract under EU Data Protection Law
Data Protection Officer’s Overview of the GDPR
Key changes with the GDPR
Accountability & Structured Privacy Management
Brussels Privacy Symposium on Identifiability
GDPR (General Data Protection Regulation)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Issues of personal data protection in scientific research
Viewing the GDPR Through a De-Identification Lens
Data Protection: EU & International
Presentation to GTMC on GDPR
Operationele blik op GDPR
Obligations of Educational Agencies: Parents’ Bill of Rights
General Data Protection Regulation
Data protection issues in regulatory investigations
Nina Barakzai November 2017
Bob Siegel President Privacy Ref, Inc.
Privacy & Access to Information
Confidentiality and Interagency Sharing of Juvenile Information
The GDPR and research data
General Data Protection Regulation
HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Namibia ICT Ministry and Data Protection Stakeholders.
GDPR (General Data Protection Regulation)
Guide to overview of changes under GDPR ww.ZAKSIT.com
Data transfers to non-EU countries under the new GDPR
The activity of Art. 29. Working Party György Halmos
GDPR & Accountability ISACA Ireland Annual Conference 2018
Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
ORLA – Ireland’s Online Library for Learning Analytics
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Public Privacy: juridical & ethical perspective
Data Protection: The new EU Regulation
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Why are we processing data
Mediation Law in Austria
General Data Protection Regulation “11 months in”
EU Data Protection Legislation
THE IMPACT OF DATA PROTECTION RULES ON CORPORATE INFO SECURITY AND INCIDENT RESPONSE MANAGEMENT – The Energy sector CEER Cybersecurity Workshop Massimo.
The EU General Data Protection Regulation
Presentation transcript:

A trust-based framework for the data-driven economy Nicolo Zingales, Tilburg Institute for Law , Technology and Society (TILT) MyData 2016, Helsinki, 1 September 2016

Data is…?

Rather, data is….

The truth about data as oil leakage

The main cause of this pollution?

Legitimate interest to pollute? (…) necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where (…) overridden by the interests or fundamental rights and freedoms of the data subject requiring protection of personal data any interest that is real (non speculative), sufficiently specific and “accepted by law” Balancing factors: Nature of data Reasonable expectations Way of processing data Balance of power, including whether data subject is a child Status of the data controller and data subject Impact on data subject including less specific, broader emotional impacts

GDPR (and not only): moving away from consent Freely given- utmost account shall be taken of whether performance […] is conditional on consent […] that is not necessary for the performance of that contract (art. 7.4) Burden of proof on controller (art. 7.1) Legitimate interest Duty of controllers to explicitly inform data subjects of their asserted legitimate interests (art. 13-14) Typified cases: (1) network and information security; (2) fraud prevention; (3) direct marketing; (4) internal transfer for administrative purposes Compatibility of further processing (re-purposing) If not based on consent or statute, depends on link with original purpose, nature of data, context, possible consequences for data subject, and existence of safeguards Typified cases: (1) archiving purposes in the public interest; (2) scientific or historical research purposes; (3) statistical purposes Conflict of interest and lack of expertise

Towards a model framework

Coming to terms with “platform responsibility” Codes of conduct

Trust , but verify : a first attempt to certify HR compliance Tos and HR Project, coordinated by the Center for Technology and Society of the Fundação Getulio Vargas in partnership with the Council of Europe (i) development of benchmarks based on international human rights standards (ii) analysis of ToS of 50 platforms by three independent analysts (iii) crossing of assessments of the three analyses and computation of statistical results; Privacy, FoE & due process

Scope of the study Platform: “any web application allowing users to find, disseminate and receive information or ideas according to the terms established in the contractual agreement” Focused on the following types of services: mail, instant communication, social network, cloud storage,music/video streaming, community fora, crowdfunding

FoE issues 70% provides mechanisms to report abusive content and solicit removal 52% affirms that content removal need not be notified 88% can delete accounts without notification

Privacy & DP issues 32% platforms do not permit anonymity or pseudonymity 66% track users on other websites and 80% permit that third parties track on their sites 62% shares data with third parties for commercial purposes by default

Only 52% affirms that it aggregates across services, usually by default Only 38% affirms that it aggregates information across devices, 2% that it does not.

Due process issues 30% of platforms explicitly commits to notify users on possible alterations of terms of service 12% affirms that there will be no notification 26% require class action waiver 86% impose mandatory jurisdiction

Privacy score

FoE score

Due Process score

Not only “trust”, but “entrust” Voluntary certification schemes (e.g. trust marks or seals of approval). Scope can be extended throughout the EU by the EU DP Board (art. 42) Incorporate the crowd’s wisdom as to the clarity of terms of service