SlideShare ist ein Scribd-Unternehmen logo
1 von 33
The Valetta Effect
(formerly Portarlington Effect
but they told us on t’Twitter
they’re really serious about
enforcement now)
Gikii Vienna 14 September 2018
Chris & Michael
Portarlington?  Irish DPC since 2006
 Now shared with Dublin
 Max Schrems’ video
 Tractors/DPC/corner shop
 Unprepossessing
 28 pubs & no cinema
 Pebbledash
 Zuckerberg’s choice of DPA
https://www.youtube.com/watch?v=cjzu4juQUcs
Vienna: home of Schrodinger & (Rigsby’s) cat
http://www.pbs.org/wgbh/nova/blogs/physics/2015/04/schrodingers-menagerie/
Schrodinger’s data protection equivalency
Not another Brexit
presentation…
 Though will apply after 29 March
 UK a 3rd party like China
 Our golden neo-imperial future
 They don’t hold a grudge?
Regulatory Arbitrage: “Race to the Bottom”
 Academic literature on subject from 1970s to 1990s: public choice theory
 In a world of 220 nation states with 220 sets of rules
 50 US states too – e.g. Nevada/Delaware for tax evaders
 Multinationals get states to ‘compete’ for business with lighter rules
 Or less enforcement of existing rules, accompanied by ‘self-regulation’
Though pushback by New Institutional Economics:
“It is no accident that economic models of the
polity developed in the public choice literature
make the state into something like the mafia ”
 North, Douglass C. (1990) Institutions, Institutional Change and Economic
Performance, Cambridge University Press at 140
Continued interest by regulatory scholars
 John Ruggie (2017) Multinationals as global institution: Power, authority and
relative autonomy, 12 Regulation and Governance 3 Pages: 317-333
 https://onlinelibrary.wiley.com/toc/17485991/2018/12/3 (open access!)
 Charles Sabel, Gary Herrigel, Peer Hull Kristensen (2017) Regulation under uncertainty: The
coevolution of industry and regulation, 12 Regulation and Governance 3 Pages: 371-394
 This is where much of net neutrality regulatory theory comes from
 You know, that information law area Gikii used to feature when it was sexy….
 But now that we’re all GDPR
 Time to look at DPAs not telco regulators!
But it’s about enforcement!
28 NRAs, 28 chances for enforcement..or not
Malta: a case study
 GDP 146th/ 200 in world
 475,000 people
 15th in income per capita in EU
 Like Iceland in pop. Size/wealth but sandwiched between Italy and Tunisia
 Originally benefitted from British traditional exports: Piracy and kidnapping
 Heroic resistance to Luftwaffe in WW2 – George Cross
 Now a major off/onshore financial centre
 Cross-over of financial homes and DP homes (e.g. famous Irish and Dutch tax efficiencies).
Is there equivalency inside the black box of
national info surveillance and sousveillance?
 Or are our private lives all Schrodingers’ cats,
 poking each other invisibly and intangibly?
 Frankly, is anyone going to enforce GDPR?
Look to competition to enforce DP by Design:
$5b fine to Google
But that’s DP heretics invading competition empire!
As we’ve been saying for 10 years…
but who is the
designated survivor…?
 Proactive investigation of infringements is a pipe-dream in
most jurisdictions.
 Some higher capacity actors (e.g. NL) trying random
sectoral spot-checks.
 Some countries have Art 80(2) ‘class action lite’
 Most agencies will be chasing data breaches, data rights
problems or media cataclysms.
 Some sectors and actors more immune to these pathways.
 Many case-workers simply do not understand the law
(e.g. ICO); likely to be challenging everywhere.
 All DPAs can take complaints, will often pass them to a
‘lead supervisory authority’, which may be of low capacity
Identification
Investigative Powers
Investigation
 Exact powers of DPAs subject largely to MS law
 Joint Operations
 DPAs have “right” to be involved, yet have to be formally invited. Seconding staff is at
the discretion of the host DPA, and they must always work “under the guidance and in
the presence” of the host DPA.
 Mutual Assistance
 DPAs shall “put in place measures” to accept requests to carry out investigations… but
with what skill, particularly where data is encrypted and difficult to understand.
Investigating
together
Deciding Together
 Regulatory cooperation under the EDPB is more ‘binding’ than
similar instruments.
 Ultimately, through the consistency mechanism, binding rather than
advisory decisions can be made by vote by the EDPB. How this
interacts with member state law (e.g. claiming that mutual
assistance may not be sufficient) may well be a future CJEU area.
 Likely only the case for the very largest players as it stands: providing
the largest players don’t relocate to Valetta.
Deciding together
 Amidst underfunded and undersized regulators for the task at hand,
 EDPB needs to develop significant expertise and investigative power
 for dealing with arcane and technologically complex complaints (geek law….)
 Few experts will complain about occasional work stints on Mediaterranean islands.
 Who are these investigators that knock down doors to find data harms?
 What skills do they have,
 particularly when most large-scale processing is and will be done in the cloud?
 Likely need for cooperation with large cloud ‘processors’: but what provision for that?
Doom and gloom? Send for the geek lawyers!
Valetta has detectives as well as pirates!
Gikii & CBGBs to the rescue!
Annex: This is serious
Panama Papers and EU27
 Pilatus Bank: short client list includes Kieth Schembri, the chief-of-staff of
Malta's prime minister, and members of the ruling Azerbaijani regime.
 Political operatives, Keith Schembri and Konrad Mizzi, Iranian-owned Pilatus
Bank, accountancy firm called Nexia BT,
 exposed by the Panama Papers and reports from Malta's anti-money
laundering agency (the FIAU) as involved in money laundering.
 Governing party suppressed the work of investigators to prevent Maltese law
from being enforced
 Assassination of investigative journalist Daphne Caruana Galizia
Daphne Project
 Schembri and Mizzi were planning to receive €150,000 per month into their
once-secret Panamanian companies from a Dubai company called 17 Black.
 Mizzi and Schembri behind Malta's new gas-fired power station
 gas-supply agreement with Azerbaijan: Malta pay €40m above market rates for gas.
 This archipelago is a full EU member
 Exposed by David Casa MEP https://euobserver.com/opinion/142642
What has this to do with data protection?
 Horrendous breach at Mossack Fonseca 2016
 Led to final closure of law firm in Panama in 2018
https://www.theguardian.com/world/2018/mar/14/mossack-fonseca-shut-down-panama-papers

Weitere ähnliche Inhalte

Was ist angesagt?

Obama moves forward with internet id plan by batteryfast
Obama moves forward with internet id plan by batteryfastObama moves forward with internet id plan by batteryfast
Obama moves forward with internet id plan by batteryfast
battery-fast. com
 
Nov 2013 Whos who International article
Nov 2013 Whos who International articleNov 2013 Whos who International article
Nov 2013 Whos who International article
Carl Frank
 
Memo: European policy: Gallo report
Memo: European policy: Gallo reportMemo: European policy: Gallo report
Memo: European policy: Gallo report
Steven Lauwers
 
Privacy law and policy 2 - LIS550
Privacy law and policy 2 - LIS550 Privacy law and policy 2 - LIS550
Privacy law and policy 2 - LIS550
Brian Rowe
 
Organised Crime in the Digital Age
Organised Crime in the Digital AgeOrganised Crime in the Digital Age
Organised Crime in the Digital Age
YogeshIJTSRD
 
Regulating Code - EUI Workshop
Regulating Code - EUI WorkshopRegulating Code - EUI Workshop
Regulating Code - EUI Workshop
Chris Marsden
 

Was ist angesagt? (20)

Obama moves forward with internet id plan by batteryfast
Obama moves forward with internet id plan by batteryfastObama moves forward with internet id plan by batteryfast
Obama moves forward with internet id plan by batteryfast
 
Marsden #icis2013
Marsden #icis2013Marsden #icis2013
Marsden #icis2013
 
2017 Legal Update on Digital Accessibility Cases with Lainey Feingold
2017 Legal Update on Digital Accessibility Cases with Lainey Feingold2017 Legal Update on Digital Accessibility Cases with Lainey Feingold
2017 Legal Update on Digital Accessibility Cases with Lainey Feingold
 
An Internet of Governments
An Internet of GovernmentsAn Internet of Governments
An Internet of Governments
 
Cyber Libertarianism - Real Internet Freedom (Thierer & Szoka)
Cyber Libertarianism - Real Internet Freedom (Thierer & Szoka)Cyber Libertarianism - Real Internet Freedom (Thierer & Szoka)
Cyber Libertarianism - Real Internet Freedom (Thierer & Szoka)
 
Nov 2013 Whos who International article
Nov 2013 Whos who International articleNov 2013 Whos who International article
Nov 2013 Whos who International article
 
Memo: European policy: Gallo report
Memo: European policy: Gallo reportMemo: European policy: Gallo report
Memo: European policy: Gallo report
 
Privacy law and policy 2 - LIS550
Privacy law and policy 2 - LIS550 Privacy law and policy 2 - LIS550
Privacy law and policy 2 - LIS550
 
2021 Digital Accessibility Legal Update with Lainey Feingold
2021 Digital Accessibility Legal Update with Lainey Feingold2021 Digital Accessibility Legal Update with Lainey Feingold
2021 Digital Accessibility Legal Update with Lainey Feingold
 
Convergence legal aspects- regulatory framework - patrick van eecke
Convergence   legal aspects- regulatory framework - patrick van eeckeConvergence   legal aspects- regulatory framework - patrick van eecke
Convergence legal aspects- regulatory framework - patrick van eecke
 
Police surveillance of social media - do you have a reasonable expectation of...
Police surveillance of social media - do you have a reasonable expectation of...Police surveillance of social media - do you have a reasonable expectation of...
Police surveillance of social media - do you have a reasonable expectation of...
 
Organised Crime in the Digital Age
Organised Crime in the Digital AgeOrganised Crime in the Digital Age
Organised Crime in the Digital Age
 
Marsden #Regulatingcode MIT
Marsden #Regulatingcode MITMarsden #Regulatingcode MIT
Marsden #Regulatingcode MIT
 
Net Neutrality in Education
Net Neutrality in EducationNet Neutrality in Education
Net Neutrality in Education
 
Regulating Code - EUI Workshop
Regulating Code - EUI WorkshopRegulating Code - EUI Workshop
Regulating Code - EUI Workshop
 
Cst group project#2, intro++
Cst group project#2, intro++Cst group project#2, intro++
Cst group project#2, intro++
 
Surveillance Capitalism
Surveillance  CapitalismSurveillance  Capitalism
Surveillance Capitalism
 
Internet Freedom and its Discontents
Internet Freedom and its DiscontentsInternet Freedom and its Discontents
Internet Freedom and its Discontents
 
Cnil 35th activity report 2014
Cnil 35th activity report 2014Cnil 35th activity report 2014
Cnil 35th activity report 2014
 
Freedom or Control in Virtual Worlds
Freedom or Control in Virtual WorldsFreedom or Control in Virtual Worlds
Freedom or Control in Virtual Worlds
 

Ähnlich wie The Valetta Effect: GDPR enforcement for Gikii Vienna 14 Sept

DCB1309 - F2_Dark_Net
DCB1309 - F2_Dark_NetDCB1309 - F2_Dark_Net
DCB1309 - F2_Dark_Net
Paul Elliott
 
Law state liability
Law state liabilityLaw state liability
Law state liability
mohdali66
 
Tor and BitCoin
Tor and BitCoinTor and BitCoin
Tor and BitCoin
Eric Kenny
 
Cyber Crime in Government
Cyber Crime in GovernmentCyber Crime in Government
Cyber Crime in Government
Jacqueline Fick
 
Data protection may be sidelined as eu and us talk trade
Data protection may be sidelined as eu and us talk tradeData protection may be sidelined as eu and us talk trade
Data protection may be sidelined as eu and us talk trade
John Davis
 

Ähnlich wie The Valetta Effect: GDPR enforcement for Gikii Vienna 14 Sept (20)

DCB1309 - F2_Dark_Net
DCB1309 - F2_Dark_NetDCB1309 - F2_Dark_Net
DCB1309 - F2_Dark_Net
 
Social media, surveillance and censorship
Social media, surveillance  and censorshipSocial media, surveillance  and censorship
Social media, surveillance and censorship
 
#DCI11 Access to Information
#DCI11 Access to Information#DCI11 Access to Information
#DCI11 Access to Information
 
Law state liability
Law state liabilityLaw state liability
Law state liability
 
Glyn Moody - TAFTA/TTIP - trade, Internet and democracy
Glyn Moody - TAFTA/TTIP - trade, Internet and democracyGlyn Moody - TAFTA/TTIP - trade, Internet and democracy
Glyn Moody - TAFTA/TTIP - trade, Internet and democracy
 
NS Civil Liberties & Security Supplement Sept 2014
NS Civil Liberties & Security Supplement Sept 2014NS Civil Liberties & Security Supplement Sept 2014
NS Civil Liberties & Security Supplement Sept 2014
 
Lgp Asia Enforcement Leave Behind Sept 09
Lgp Asia Enforcement Leave Behind Sept 09Lgp Asia Enforcement Leave Behind Sept 09
Lgp Asia Enforcement Leave Behind Sept 09
 
2600 v25 n4 (winter 2008)
2600 v25 n4 (winter 2008)2600 v25 n4 (winter 2008)
2600 v25 n4 (winter 2008)
 
2600 v19 n4 (winter 2002)
2600 v19 n4 (winter 2002)2600 v19 n4 (winter 2002)
2600 v19 n4 (winter 2002)
 
Design to Disrupt - Blockchain: cryptoplatform for a frictionless economy
Design to Disrupt - Blockchain: cryptoplatform for a frictionless economyDesign to Disrupt - Blockchain: cryptoplatform for a frictionless economy
Design to Disrupt - Blockchain: cryptoplatform for a frictionless economy
 
Manifesto of the Crypto\ICO community
Manifesto of the Crypto\ICO communityManifesto of the Crypto\ICO community
Manifesto of the Crypto\ICO community
 
feb 2018 - Sub22 - The impact of new and emerging information and communicati...
feb 2018 - Sub22 - The impact of new and emerging information and communicati...feb 2018 - Sub22 - The impact of new and emerging information and communicati...
feb 2018 - Sub22 - The impact of new and emerging information and communicati...
 
Draft data protection regn 2012
Draft data protection regn 2012Draft data protection regn 2012
Draft data protection regn 2012
 
Technology evolves so fast
Technology evolves so fast Technology evolves so fast
Technology evolves so fast
 
Tor and BitCoin
Tor and BitCoinTor and BitCoin
Tor and BitCoin
 
Cyber Crime in Government
Cyber Crime in GovernmentCyber Crime in Government
Cyber Crime in Government
 
Privacy, Surveillance & Investigatory Powers
Privacy, Surveillance & Investigatory PowersPrivacy, Surveillance & Investigatory Powers
Privacy, Surveillance & Investigatory Powers
 
Will blockchain emerge as a tool to break the poverty chain in the Global South?
Will blockchain emerge as a tool to break the poverty chain in the Global South?Will blockchain emerge as a tool to break the poverty chain in the Global South?
Will blockchain emerge as a tool to break the poverty chain in the Global South?
 
Apresentação de Jeanette Hofmann
Apresentação de Jeanette HofmannApresentação de Jeanette Hofmann
Apresentação de Jeanette Hofmann
 
Data protection may be sidelined as eu and us talk trade
Data protection may be sidelined as eu and us talk tradeData protection may be sidelined as eu and us talk trade
Data protection may be sidelined as eu and us talk trade
 

Mehr von Chris Marsden

Mehr von Chris Marsden (20)

QUT Regulating Disinformation with AI Marsden 2024
QUT Regulating Disinformation with AI Marsden 2024QUT Regulating Disinformation with AI Marsden 2024
QUT Regulating Disinformation with AI Marsden 2024
 
Aligarh Democracy and AI.pptx
Aligarh Democracy and AI.pptxAligarh Democracy and AI.pptx
Aligarh Democracy and AI.pptx
 
CPA Democracy and AI.pptx
CPA Democracy and AI.pptxCPA Democracy and AI.pptx
CPA Democracy and AI.pptx
 
Generative AI, responsible innovation and the law
Generative AI, responsible innovation and the lawGenerative AI, responsible innovation and the law
Generative AI, responsible innovation and the law
 
Evidence base for AI regulation.pptx
Evidence base for AI regulation.pptxEvidence base for AI regulation.pptx
Evidence base for AI regulation.pptx
 
Gikii23 Marsden
Gikii23 MarsdenGikii23 Marsden
Gikii23 Marsden
 
#Gikii23 Marsden
#Gikii23 Marsden#Gikii23 Marsden
#Gikii23 Marsden
 
Generative AI and law.pptx
Generative AI and law.pptxGenerative AI and law.pptx
Generative AI and law.pptx
 
2019: Regulating disinformation with artificial intelligence (AI)
2019: Regulating disinformation with artificial intelligence (AI)2019: Regulating disinformation with artificial intelligence (AI)
2019: Regulating disinformation with artificial intelligence (AI)
 
Marsden CELPU 2021 platform law co-regulation
Marsden CELPU 2021 platform law co-regulationMarsden CELPU 2021 platform law co-regulation
Marsden CELPU 2021 platform law co-regulation
 
Marsden Interoperability European Parliament 13 October
Marsden Interoperability European Parliament 13 OctoberMarsden Interoperability European Parliament 13 October
Marsden Interoperability European Parliament 13 October
 
Net neutrality 2021
Net neutrality 2021Net neutrality 2021
Net neutrality 2021
 
Marsden Regulating Disinformation Kluge 342020
Marsden Regulating Disinformation Kluge 342020Marsden Regulating Disinformation Kluge 342020
Marsden Regulating Disinformation Kluge 342020
 
Marsden Disinformation Algorithms #IGF2019
Marsden Disinformation Algorithms #IGF2019 Marsden Disinformation Algorithms #IGF2019
Marsden Disinformation Algorithms #IGF2019
 
Social Utilities, Dominance and Interoperability: A Modest ProposalGikii 2008...
Social Utilities, Dominance and Interoperability: A Modest ProposalGikii 2008...Social Utilities, Dominance and Interoperability: A Modest ProposalGikii 2008...
Social Utilities, Dominance and Interoperability: A Modest ProposalGikii 2008...
 
Marsden Net Neutrality Internet Governance Forum 2018 #IGF2018
Marsden Net Neutrality Internet Governance Forum 2018 #IGF2018Marsden Net Neutrality Internet Governance Forum 2018 #IGF2018
Marsden Net Neutrality Internet Governance Forum 2018 #IGF2018
 
Marsden Net Neutrality OII
Marsden Net Neutrality OIIMarsden Net Neutrality OII
Marsden Net Neutrality OII
 
Marsden Net Neutrality Annenberg Oxford 2018 #ANOX2018
Marsden Net Neutrality Annenberg Oxford 2018 #ANOX2018Marsden Net Neutrality Annenberg Oxford 2018 #ANOX2018
Marsden Net Neutrality Annenberg Oxford 2018 #ANOX2018
 
Human centric multi-disciplinary NGI4EU Iceland 2018
Human centric multi-disciplinary NGI4EU Iceland 2018Human centric multi-disciplinary NGI4EU Iceland 2018
Human centric multi-disciplinary NGI4EU Iceland 2018
 
Human centric multi-disciplinary @ngi4eu @nesta_uk 21 march
Human centric multi-disciplinary @ngi4eu @nesta_uk 21 marchHuman centric multi-disciplinary @ngi4eu @nesta_uk 21 march
Human centric multi-disciplinary @ngi4eu @nesta_uk 21 march
 

Kürzlich hochgeladen

The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
heathfieldcps1
 

Kürzlich hochgeladen (20)

Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Google Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptxGoogle Gemini An AI Revolution in Education.pptx
Google Gemini An AI Revolution in Education.pptx
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdf
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
HMCS Max Bernays Pre-Deployment Brief (May 2024).pptx
HMCS Max Bernays Pre-Deployment Brief (May 2024).pptxHMCS Max Bernays Pre-Deployment Brief (May 2024).pptx
HMCS Max Bernays Pre-Deployment Brief (May 2024).pptx
 
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdfUnit 3 Emotional Intelligence and Spiritual Intelligence.pdf
Unit 3 Emotional Intelligence and Spiritual Intelligence.pdf
 
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
80 ĐỀ THI THỬ TUYỂN SINH TIẾNG ANH VÀO 10 SỞ GD – ĐT THÀNH PHỐ HỒ CHÍ MINH NĂ...
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptxHMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
HMCS Vancouver Pre-Deployment Brief - May 2024 (Web Version).pptx
 
Fostering Friendships - Enhancing Social Bonds in the Classroom
Fostering Friendships - Enhancing Social Bonds  in the ClassroomFostering Friendships - Enhancing Social Bonds  in the Classroom
Fostering Friendships - Enhancing Social Bonds in the Classroom
 
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
Sensory_Experience_and_Emotional_Resonance_in_Gabriel_Okaras_The_Piano_and_Th...
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
NO1 Top Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
 
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptxOn_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
On_Translating_a_Tamil_Poem_by_A_K_Ramanujan.pptx
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docx
 
Sociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning ExhibitSociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning Exhibit
 

The Valetta Effect: GDPR enforcement for Gikii Vienna 14 Sept

  • 1. The Valetta Effect (formerly Portarlington Effect but they told us on t’Twitter they’re really serious about enforcement now) Gikii Vienna 14 September 2018 Chris & Michael
  • 2.
  • 3. Portarlington?  Irish DPC since 2006  Now shared with Dublin  Max Schrems’ video  Tractors/DPC/corner shop  Unprepossessing  28 pubs & no cinema  Pebbledash  Zuckerberg’s choice of DPA
  • 5. Vienna: home of Schrodinger & (Rigsby’s) cat
  • 8. Not another Brexit presentation…  Though will apply after 29 March  UK a 3rd party like China  Our golden neo-imperial future  They don’t hold a grudge?
  • 9. Regulatory Arbitrage: “Race to the Bottom”  Academic literature on subject from 1970s to 1990s: public choice theory  In a world of 220 nation states with 220 sets of rules  50 US states too – e.g. Nevada/Delaware for tax evaders  Multinationals get states to ‘compete’ for business with lighter rules  Or less enforcement of existing rules, accompanied by ‘self-regulation’
  • 10.
  • 11. Though pushback by New Institutional Economics: “It is no accident that economic models of the polity developed in the public choice literature make the state into something like the mafia ”  North, Douglass C. (1990) Institutions, Institutional Change and Economic Performance, Cambridge University Press at 140
  • 12. Continued interest by regulatory scholars  John Ruggie (2017) Multinationals as global institution: Power, authority and relative autonomy, 12 Regulation and Governance 3 Pages: 317-333  https://onlinelibrary.wiley.com/toc/17485991/2018/12/3 (open access!)  Charles Sabel, Gary Herrigel, Peer Hull Kristensen (2017) Regulation under uncertainty: The coevolution of industry and regulation, 12 Regulation and Governance 3 Pages: 371-394  This is where much of net neutrality regulatory theory comes from  You know, that information law area Gikii used to feature when it was sexy….  But now that we’re all GDPR  Time to look at DPAs not telco regulators!
  • 13. But it’s about enforcement!
  • 14. 28 NRAs, 28 chances for enforcement..or not
  • 15. Malta: a case study  GDP 146th/ 200 in world  475,000 people  15th in income per capita in EU  Like Iceland in pop. Size/wealth but sandwiched between Italy and Tunisia  Originally benefitted from British traditional exports: Piracy and kidnapping  Heroic resistance to Luftwaffe in WW2 – George Cross  Now a major off/onshore financial centre  Cross-over of financial homes and DP homes (e.g. famous Irish and Dutch tax efficiencies).
  • 16.
  • 17. Is there equivalency inside the black box of national info surveillance and sousveillance?  Or are our private lives all Schrodingers’ cats,  poking each other invisibly and intangibly?  Frankly, is anyone going to enforce GDPR?
  • 18. Look to competition to enforce DP by Design: $5b fine to Google
  • 19. But that’s DP heretics invading competition empire! As we’ve been saying for 10 years…
  • 20. but who is the designated survivor…?
  • 21.  Proactive investigation of infringements is a pipe-dream in most jurisdictions.  Some higher capacity actors (e.g. NL) trying random sectoral spot-checks.  Some countries have Art 80(2) ‘class action lite’  Most agencies will be chasing data breaches, data rights problems or media cataclysms.  Some sectors and actors more immune to these pathways.  Many case-workers simply do not understand the law (e.g. ICO); likely to be challenging everywhere.  All DPAs can take complaints, will often pass them to a ‘lead supervisory authority’, which may be of low capacity Identification
  • 23. Investigation  Exact powers of DPAs subject largely to MS law  Joint Operations  DPAs have “right” to be involved, yet have to be formally invited. Seconding staff is at the discretion of the host DPA, and they must always work “under the guidance and in the presence” of the host DPA.  Mutual Assistance  DPAs shall “put in place measures” to accept requests to carry out investigations… but with what skill, particularly where data is encrypted and difficult to understand. Investigating together
  • 25.  Regulatory cooperation under the EDPB is more ‘binding’ than similar instruments.  Ultimately, through the consistency mechanism, binding rather than advisory decisions can be made by vote by the EDPB. How this interacts with member state law (e.g. claiming that mutual assistance may not be sufficient) may well be a future CJEU area.  Likely only the case for the very largest players as it stands: providing the largest players don’t relocate to Valetta. Deciding together
  • 26.  Amidst underfunded and undersized regulators for the task at hand,  EDPB needs to develop significant expertise and investigative power  for dealing with arcane and technologically complex complaints (geek law….)  Few experts will complain about occasional work stints on Mediaterranean islands.  Who are these investigators that knock down doors to find data harms?  What skills do they have,  particularly when most large-scale processing is and will be done in the cloud?  Likely need for cooperation with large cloud ‘processors’: but what provision for that? Doom and gloom? Send for the geek lawyers!
  • 27. Valetta has detectives as well as pirates!
  • 28. Gikii & CBGBs to the rescue!
  • 29. Annex: This is serious
  • 30. Panama Papers and EU27  Pilatus Bank: short client list includes Kieth Schembri, the chief-of-staff of Malta's prime minister, and members of the ruling Azerbaijani regime.  Political operatives, Keith Schembri and Konrad Mizzi, Iranian-owned Pilatus Bank, accountancy firm called Nexia BT,  exposed by the Panama Papers and reports from Malta's anti-money laundering agency (the FIAU) as involved in money laundering.  Governing party suppressed the work of investigators to prevent Maltese law from being enforced  Assassination of investigative journalist Daphne Caruana Galizia
  • 31.
  • 32. Daphne Project  Schembri and Mizzi were planning to receive €150,000 per month into their once-secret Panamanian companies from a Dubai company called 17 Black.  Mizzi and Schembri behind Malta's new gas-fired power station  gas-supply agreement with Azerbaijan: Malta pay €40m above market rates for gas.  This archipelago is a full EU member  Exposed by David Casa MEP https://euobserver.com/opinion/142642
  • 33. What has this to do with data protection?  Horrendous breach at Mossack Fonseca 2016  Led to final closure of law firm in Panama in 2018 https://www.theguardian.com/world/2018/mar/14/mossack-fonseca-shut-down-panama-papers