SlideShare ist ein Scribd-Unternehmen logo
1 von 18
Dr David Erdos
University of Cambridge
Why An Interface? GPDR Material Scope
 Personal data broadly conceived:
 So long as remains identifiable:
 And (private sector) digital processing takes place:
“wide scope … not restricted to information that is sensitive or
private, but potentially encompasses all kinds of information, not
only objective but also subjective … provided it that it ʻrelatesʼ to
the data subject … by reason of its content, purpose or effect”
Exclusion only “prohibited by law or practically impossible … so that
risk of identification appears in reality insignificant.”
“any operation … which is performed on personal data”
Luxembourg CNPD
Why A Tension? GDPR’s Wide Default Duties
Personal
Data
Processing
DP Principles
• Fair, lawful,
transparent
• Purpose quality &
limits
• Information
quality & limits
• Integrity &
confidentiality
Legal Basis
• Legitimating
Criteria
Transparency &
Control
• Proactive Direct
• Proactive Indirect
• Subject Access
• Control rights –
RtbF, objection
Sensitive Data
• Criminal Data
• Other:
• Political,
• Religious,
• Trade union
Discipline
• Demo compliance
• Security
• Record-keeping
• DP Officer
• Joint Controller
agreements
• Processor
agreements
• Impact
Assessments
• DPA Consultation
• Data Exports
Oversight
• Courts
• DP Authorities
Journalism: A Special Case in EU DP Law
 Largely mirrors previous provisions in DP Directive.
 Thus, Article 85(2) itself provides that:
 Meanwhile Recital 153 stresses:
o Should interpret journalism “broadly” to cover inter alia “news
archives and press libraries”.
o Only “certain provisions” require derogations (N.B. art. 85(2) itself
excludes chapter on remedies, liabilities & penalties).
o Only should adopt limits were “necessary for the purpose of
balancing” fundamental rights.
“For the processing carried out for journalistic purposes … Member States
shall provide exemptions or derogations … if they are necessary to reconcile
the right to the protection of personal data with the freedom of expression
and information.” (GDPR, art. 85(2))
State Law: Formal Substantive Outcomes
 Wide divergences ranging from no explicit limitation
(e.g. Spain, Croatia) to complete exemption (e.g. Sweden
and Norway).
 But vast majority do subject to journalism to qualified
DP standards, often based on modified version of the
data protection principles.
 There is evidence of broad continuity here as compared
with the DP Directive era.
Local Law: Formal Regulatory Outcomes
0%
10%
20%
30%
40%
50%
60%
70%
80%
Full Supervision Partial Supervision No Supervision
DPD GDPR (as at Autumn 2018)
DP: New Status as Fundamental Legal Right
1. Everyone has the right to the protection of personal data
concerning him or her.
2. Such data must be processed fairly for specified purposes
and on the basis of the consent of the person concerned or
some other legitimate basis laid down by law. Everyone has
the right of access to data which has been collected
concerning him or her, and the right to have it rectified.
3. Compliance with these rules shall be subject to control by an
independent authority.
Resource Constraints on DPAs
 DPAs also suffer from severe resource constraints.
 Average 2017 budget of only around 5m (including
for non-DP functions).
 Total budget of perhaps 120m & only increased by c.
15% in last five years.
 In contrast, Ofcom in UK alone had budget of 141m
in same period.
How should DPAs interface with Journalism?
 DPAs are constrained legally, financially and perhaps
also epistemically in this area.
 But they generally retain important albeit sensitive role
here as “the guardian” of data protection rights.
 Drawing on past experience, need to explore how that
role might best be discharged vis-à-vis:
 Standards-setting, and
 Enforcement.
DPAs and Standard-Setting: DPD Experience
 Around 65% national DPAs did publish guidance here
but in most cases very limited.
 2013 DPA survey probing detailed understanding found
different DP aspects approached very differently:
 Undercover journalism – permissive approach (around
60% either exempt or apply weak public interest test).
 Subject Access - much stricter (around 1/3 back full access
minus sources).
 This divergence was in turn linked to whether issue dealt
with (in some way) via self-regulatory codes.
DPAs, Standard-Setting and Self-Regulation
 Clear case for DPAs interfacing with self-regulation:
 Core exercise of freedom of expression,
 Self-regulatory expertise.
 But DPAs need to be active participants here:
 Tackle epistemic & economically-motivated bias,
 Protect children & other vulnerable data subjects,
 Ensure due attention to given to legal framework,
 Ensure coherent development regulation,
 Ensure focus on impact of new technology – algorithms,
data journalism, drones, digital archives etc.
Codes of Conduct (A 40): A Possible Approach
Ff1. The … supervisory authorities … shall encourage the drawing up of
codes of conduct intended to contribute to the proper application
of this Regulation, taking into account the specific features of the
various processing sectors …
2. Associations and other bodies representing categories of
controllers or processors may prepare or amend such codes for the
purpose of specifying the application of this Regulation ….
…
5. Association and other bodies … shall submit the draft code,
amendment or extension to the supervisory authority … The
supervisory shall provide an opinion on whether the draft …
compies with the Regulation and shall approve … if it finds it
provides sufficient appropriate safeguards.”
DPA Guidance: Need for Publicity
Targeted
Publicity
Media
Organisations
Journalists
(Freelance)
Legal &
Judicial
Community
General
Public
DPA Enforcement: Context & Experience
 Context:
 Even more sensitive area than standard-setting.
 Enforcement can also be very expensive.
 Pure “advise & persuade” strategy is clearly flawed.
 DPA Experience:
 2013 Survey suggested around ½ carried out enforcement.
 But actions generally very selective, focused on:
 Intimate private life (especially re: sensitive data),
 Data linked to key social relationships (e.g. ID numbers).
 Self-regulation cited but little evidence of strategic approach.
Monitoring Bodies: A. 41(2) Standards
FfA body … may be accredited [by the DPA] to monitor compliance with a
code of conduct where that body has:
a) Demonstrated its independence and expertise…
b) Established procedures which allow it to assess the eligibility of
controllers and processors concerned to apply the code, to monitor
their compliance with its provisions and to periodically review its
operation;
c) Established procedures and structures to handle complaints about
infringements … and to make those procedures and structures
transparent to data subjects and the public; and
d) Demonstrated … that its tasks and duties do not result in a conflict
of interests.
DPA Enforcement: How Much Deference?
No Self-Regulatory Body
- Fully independent assessment.
- “Advise and persuade” not ruled out.
- But use of formal powers more likely.
Non-Accredited Body
- Encourage use by data subjects.
- Take into account, liase and cooperate.
- But ultimately independent assessment
Accredited Body
- Meta-regulatory review.
- Reasonableness standard otherwise.
- Intervene in serious individual cases
What role for European DP Board?
 Media regulation could interface with “consistency mechanism”.
 But even if the case, “hard” intervention should be avoided:
 Local DPAs best placed to interpret widely divergent local laws,
 Media generally remains strongly locally orientated,
 Such intervention likely to be counter-productive.
 Even so, the EDPB could usefully engage in “soft” action:
 Forum for especially small DPAs to work through common issues,
 Is increasing “mutual interpenetration” of media sectors.
 Soft guidance could lead to slow development of common norms,
Conclusions
 DP interface with media is sensitive & diverse.
 Regulatory resources are also very scare.
 But DPAs almost always retain important as “the
guardian” of DP in this space.
 Argued that both re: standards & enforcement, role best
fulfilled via co-regulatory, strategic approach.
 EDPB should play “soft” role here but avoid
“hard”/coercive action.

Weitere ähnliche Inhalte

Was ist angesagt?

Developing a communications plan
Developing a communications planDeveloping a communications plan
Developing a communications planFairfax County
 
Message appeals and endorser - traditional advertising and internet advertising
Message appeals and endorser - traditional advertising and internet advertisingMessage appeals and endorser - traditional advertising and internet advertising
Message appeals and endorser - traditional advertising and internet advertisingsunnysidemochi
 
Chapter 5 PUBLIC RELATION
Chapter 5 PUBLIC RELATION Chapter 5 PUBLIC RELATION
Chapter 5 PUBLIC RELATION Shadina Shah
 
Online defamation through social media an attempt to reconcile conflicts bet...
Online defamation through social media  an attempt to reconcile conflicts bet...Online defamation through social media  an attempt to reconcile conflicts bet...
Online defamation through social media an attempt to reconcile conflicts bet...International Islamic University Malaysia
 
Strategic Communications Bootcamp May 5 English
Strategic Communications Bootcamp May 5 English Strategic Communications Bootcamp May 5 English
Strategic Communications Bootcamp May 5 English CarolineKealey
 

Was ist angesagt? (7)

Developing a communications plan
Developing a communications planDeveloping a communications plan
Developing a communications plan
 
Crisis Communication ppt
Crisis Communication pptCrisis Communication ppt
Crisis Communication ppt
 
Message appeals and endorser - traditional advertising and internet advertising
Message appeals and endorser - traditional advertising and internet advertisingMessage appeals and endorser - traditional advertising and internet advertising
Message appeals and endorser - traditional advertising and internet advertising
 
Chapter 5 PUBLIC RELATION
Chapter 5 PUBLIC RELATION Chapter 5 PUBLIC RELATION
Chapter 5 PUBLIC RELATION
 
Online defamation through social media an attempt to reconcile conflicts bet...
Online defamation through social media  an attempt to reconcile conflicts bet...Online defamation through social media  an attempt to reconcile conflicts bet...
Online defamation through social media an attempt to reconcile conflicts bet...
 
Stakeholder Analysis
Stakeholder AnalysisStakeholder Analysis
Stakeholder Analysis
 
Strategic Communications Bootcamp May 5 English
Strategic Communications Bootcamp May 5 English Strategic Communications Bootcamp May 5 English
Strategic Communications Bootcamp May 5 English
 

Ähnlich wie GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope

The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondDavid Erdos
 
Presentation_on_protection_of_reporting_persons_UNCAC_LP.ppt
Presentation_on_protection_of_reporting_persons_UNCAC_LP.pptPresentation_on_protection_of_reporting_persons_UNCAC_LP.ppt
Presentation_on_protection_of_reporting_persons_UNCAC_LP.pptFranciscoJoaoVitug
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR FrameworkDavid Erdos
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpraudrey miguel
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
Brussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACKBrussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACKTrilateral Research
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulationFahad Ameen
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeDavid Erdos
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkPECB
 
Time to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisisTime to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisismrleiser
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?David Erdos
 
CCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptCCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptSamir Jha
 
Personal Data Breach Notification
Personal Data Breach Notification Personal Data Breach Notification
Personal Data Breach Notification TALOSCommunications
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 

Ähnlich wie GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope (20)

The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and Beyond
 
Presentation_on_protection_of_reporting_persons_UNCAC_LP.ppt
Presentation_on_protection_of_reporting_persons_UNCAC_LP.pptPresentation_on_protection_of_reporting_persons_UNCAC_LP.ppt
Presentation_on_protection_of_reporting_persons_UNCAC_LP.ppt
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
Data Protection and Academic Research: The New GDPR Framework
Data Protection and Academic Research:  The New GDPR FrameworkData Protection and Academic Research:  The New GDPR Framework
Data Protection and Academic Research: The New GDPR Framework
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Brussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACKBrussels Privacy Hub: SATORI and iTRACK
Brussels Privacy Hub: SATORI and iTRACK
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
 
Why GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC FrameworkWhy GDPR Must Be an Integral Part of Your GRC Framework
Why GDPR Must Be an Integral Part of Your GRC Framework
 
Time to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisisTime to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisis
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
Pwc gdpr survey 2018
Pwc gdpr survey 2018Pwc gdpr survey 2018
Pwc gdpr survey 2018
 
DAMA Ireland - GDPR
DAMA Ireland - GDPRDAMA Ireland - GDPR
DAMA Ireland - GDPR
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
 
CCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptCCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.ppt
 
Personal Data Breach Notification
Personal Data Breach Notification Personal Data Breach Notification
Personal Data Breach Notification
 
IDC on 10 myths regarding GDPR
IDC on 10 myths regarding GDPRIDC on 10 myths regarding GDPR
IDC on 10 myths regarding GDPR
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Ann Ox09 Presentation
Ann Ox09 PresentationAnn Ox09 Presentation
Ann Ox09 Presentation
 

Mehr von David Erdos

Regulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionRegulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionDavid Erdos
 
Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRDavid Erdos
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR PerspectiveDavid Erdos
 
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49David Erdos
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?David Erdos
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUDavid Erdos
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?David Erdos
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDavid Erdos
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDavid Erdos
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...David Erdos
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical PerspectiveDavid Erdos
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social NetworkingDavid Erdos
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeDavid Erdos
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictDavid Erdos
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesDavid Erdos
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionDavid Erdos
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionDavid Erdos
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionDavid Erdos
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowDavid Erdos
 

Mehr von David Erdos (19)

Regulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionRegulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data Protection
 
Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPR
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
 
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
 
UK GDPR: What New Direction?
UK GDPR:  What New Direction?UK GDPR:  What New Direction?
UK GDPR: What New Direction?
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EU
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
 
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google SpainDisclosure, Exposure and the "Right to be Forgotten" After Google Spain
Disclosure, Exposure and the "Right to be Forgotten" After Google Spain
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical Perspective
 
European Data Protection and Social Networking
European Data Protection and Social NetworkingEuropean Data Protection and Social Networking
European Data Protection and Social Networking
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in Conflict
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search Engines
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data Protection
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
 

Kürzlich hochgeladen

一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...Finlaw Associates
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxca2or2tx
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxRRR Chambers
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptzainabbkhaleeq123
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptxpnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptxPSSPRO12
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptxPamelaAbegailMonsant2
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书SS A
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxfilippoluciani9
 
INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxnyabatejosphat1
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书E LSS
 
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...SUHANI PANDEY
 
Clarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo forClarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo forRoger Valdez
 
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxMunicipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxSHIVAMGUPTA671167
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsAurora Consulting
 
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdflaysamaeguardiano
 
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptxPresentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptxRRR Chambers
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxRRR Chambers
 

Kürzlich hochgeladen (20)

一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .ppt
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptxpnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptx
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书
 
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
Independent Call Girls Pune | 8005736733 Independent Escorts & Dating Escorts...
 
Clarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo forClarifying Land Donation Issues Memo for
Clarifying Land Donation Issues Memo for
 
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxMunicipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
 
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptxPresentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 

GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope

  • 2. Why An Interface? GPDR Material Scope  Personal data broadly conceived:  So long as remains identifiable:  And (private sector) digital processing takes place: “wide scope … not restricted to information that is sensitive or private, but potentially encompasses all kinds of information, not only objective but also subjective … provided it that it ʻrelatesʼ to the data subject … by reason of its content, purpose or effect” Exclusion only “prohibited by law or practically impossible … so that risk of identification appears in reality insignificant.” “any operation … which is performed on personal data” Luxembourg CNPD
  • 3. Why A Tension? GDPR’s Wide Default Duties Personal Data Processing DP Principles • Fair, lawful, transparent • Purpose quality & limits • Information quality & limits • Integrity & confidentiality Legal Basis • Legitimating Criteria Transparency & Control • Proactive Direct • Proactive Indirect • Subject Access • Control rights – RtbF, objection Sensitive Data • Criminal Data • Other: • Political, • Religious, • Trade union Discipline • Demo compliance • Security • Record-keeping • DP Officer • Joint Controller agreements • Processor agreements • Impact Assessments • DPA Consultation • Data Exports Oversight • Courts • DP Authorities
  • 4. Journalism: A Special Case in EU DP Law  Largely mirrors previous provisions in DP Directive.  Thus, Article 85(2) itself provides that:  Meanwhile Recital 153 stresses: o Should interpret journalism “broadly” to cover inter alia “news archives and press libraries”. o Only “certain provisions” require derogations (N.B. art. 85(2) itself excludes chapter on remedies, liabilities & penalties). o Only should adopt limits were “necessary for the purpose of balancing” fundamental rights. “For the processing carried out for journalistic purposes … Member States shall provide exemptions or derogations … if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.” (GDPR, art. 85(2))
  • 5. State Law: Formal Substantive Outcomes  Wide divergences ranging from no explicit limitation (e.g. Spain, Croatia) to complete exemption (e.g. Sweden and Norway).  But vast majority do subject to journalism to qualified DP standards, often based on modified version of the data protection principles.  There is evidence of broad continuity here as compared with the DP Directive era.
  • 6. Local Law: Formal Regulatory Outcomes 0% 10% 20% 30% 40% 50% 60% 70% 80% Full Supervision Partial Supervision No Supervision DPD GDPR (as at Autumn 2018)
  • 7. DP: New Status as Fundamental Legal Right 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority.
  • 8. Resource Constraints on DPAs  DPAs also suffer from severe resource constraints.  Average 2017 budget of only around 5m (including for non-DP functions).  Total budget of perhaps 120m & only increased by c. 15% in last five years.  In contrast, Ofcom in UK alone had budget of 141m in same period.
  • 9. How should DPAs interface with Journalism?  DPAs are constrained legally, financially and perhaps also epistemically in this area.  But they generally retain important albeit sensitive role here as “the guardian” of data protection rights.  Drawing on past experience, need to explore how that role might best be discharged vis-à-vis:  Standards-setting, and  Enforcement.
  • 10. DPAs and Standard-Setting: DPD Experience  Around 65% national DPAs did publish guidance here but in most cases very limited.  2013 DPA survey probing detailed understanding found different DP aspects approached very differently:  Undercover journalism – permissive approach (around 60% either exempt or apply weak public interest test).  Subject Access - much stricter (around 1/3 back full access minus sources).  This divergence was in turn linked to whether issue dealt with (in some way) via self-regulatory codes.
  • 11. DPAs, Standard-Setting and Self-Regulation  Clear case for DPAs interfacing with self-regulation:  Core exercise of freedom of expression,  Self-regulatory expertise.  But DPAs need to be active participants here:  Tackle epistemic & economically-motivated bias,  Protect children & other vulnerable data subjects,  Ensure due attention to given to legal framework,  Ensure coherent development regulation,  Ensure focus on impact of new technology – algorithms, data journalism, drones, digital archives etc.
  • 12. Codes of Conduct (A 40): A Possible Approach Ff1. The … supervisory authorities … shall encourage the drawing up of codes of conduct intended to contribute to the proper application of this Regulation, taking into account the specific features of the various processing sectors … 2. Associations and other bodies representing categories of controllers or processors may prepare or amend such codes for the purpose of specifying the application of this Regulation …. … 5. Association and other bodies … shall submit the draft code, amendment or extension to the supervisory authority … The supervisory shall provide an opinion on whether the draft … compies with the Regulation and shall approve … if it finds it provides sufficient appropriate safeguards.”
  • 13. DPA Guidance: Need for Publicity Targeted Publicity Media Organisations Journalists (Freelance) Legal & Judicial Community General Public
  • 14. DPA Enforcement: Context & Experience  Context:  Even more sensitive area than standard-setting.  Enforcement can also be very expensive.  Pure “advise & persuade” strategy is clearly flawed.  DPA Experience:  2013 Survey suggested around ½ carried out enforcement.  But actions generally very selective, focused on:  Intimate private life (especially re: sensitive data),  Data linked to key social relationships (e.g. ID numbers).  Self-regulation cited but little evidence of strategic approach.
  • 15. Monitoring Bodies: A. 41(2) Standards FfA body … may be accredited [by the DPA] to monitor compliance with a code of conduct where that body has: a) Demonstrated its independence and expertise… b) Established procedures which allow it to assess the eligibility of controllers and processors concerned to apply the code, to monitor their compliance with its provisions and to periodically review its operation; c) Established procedures and structures to handle complaints about infringements … and to make those procedures and structures transparent to data subjects and the public; and d) Demonstrated … that its tasks and duties do not result in a conflict of interests.
  • 16. DPA Enforcement: How Much Deference? No Self-Regulatory Body - Fully independent assessment. - “Advise and persuade” not ruled out. - But use of formal powers more likely. Non-Accredited Body - Encourage use by data subjects. - Take into account, liase and cooperate. - But ultimately independent assessment Accredited Body - Meta-regulatory review. - Reasonableness standard otherwise. - Intervene in serious individual cases
  • 17. What role for European DP Board?  Media regulation could interface with “consistency mechanism”.  But even if the case, “hard” intervention should be avoided:  Local DPAs best placed to interpret widely divergent local laws,  Media generally remains strongly locally orientated,  Such intervention likely to be counter-productive.  Even so, the EDPB could usefully engage in “soft” action:  Forum for especially small DPAs to work through common issues,  Is increasing “mutual interpenetration” of media sectors.  Soft guidance could lead to slow development of common norms,
  • 18. Conclusions  DP interface with media is sensitive & diverse.  Regulatory resources are also very scare.  But DPAs almost always retain important as “the guardian” of DP in this space.  Argued that both re: standards & enforcement, role best fulfilled via co-regulatory, strategic approach.  EDPB should play “soft” role here but avoid “hard”/coercive action.