Personal Data Protection in Digital Libraries

Author(s):  
Ioannis Iglezakis

Digital libraries provide many advantages compared with traditional libraries, such as wide and round the clock availability of resources, lack of physical boundaries, etc. However, the disclosure of personally identifiable information in the course of processing activities may lead to an invasion of privacy of library users, without their being aware of it. In fact, privacy threats are increased in the digital environment, in which digital libraries operate. The right to privacy in the library is “the right to open inquiry without having the subject of one’s interest examined or scrutinized by others” (ALA, 2005). Users of digital libraries have similar privacy expectations when making use of their services. The issues concerning the privacy of digital libraries’ patrons are thus addressed in comparative perspective, in this chapter. In more particular, the legal regulations with regard to data protection in digital libraries in the EU and the US are presented. The comparative analysis of the two legal orders shows differences and similarities, but also highlights loopholes of protection.

Author(s):  
Agnese Reine-Vītiņa

Mūsdienās tiesības uz privāto dzīvi nepieciešamas ikvienā demokrātiskā sabiedrībā, un šo tiesību iekļaušana konstitūcijā juridiski garantē fiziskas personas rīcības brīvību un vienlaikus arī citu – valsts pamatlikumā noteikto – cilvēka tiesību īstenošanu [5]. Personas datu aizsardzības institūts tika izveidots, izpratnes par tiesību uz personas privātās dzīves neaizskaramību saturu paplašinot 20. gadsimta 70. gados, kad vairāku Eiropas valstu valdības uzsāka informācijas apstrādes projektus, piemēram, tautas skaitīšanu u. c. Informācijas tehnoloģiju attīstība ļāva arvien vairāk informācijas par personām glabāt un apstrādāt elektroniski. Viena no tiesību problēmām bija informācijas vākšana par fizisku personu un tiesību uz privātās dzīves neaizskaramību ievērošana. Lai nodrošinātu privātās dzīves aizsardzību, atsevišķas Eiropas valstis pēc savas iniciatīvas pieņēma likumus par datu aizsardzību. Pirmie likumi par personas datu aizsardzību Eiropā tika pieņemti Vācijas Federatīvajā Republikā, tad Zviedrijā (1973), Norvēģijā (1978) un citur [8, 10]. Ne visas valstis pieņēma likumus par datu aizsardzību vienlaikus, tāpēc Eiropas Padome nolēma izstrādāt konvenciju, lai unificētu datu aizsardzības noteikumus un principus. Nowadays, the right to privacy is indispensable in every democratic society and inclusion of such rights in the constitution, guarantees legally freedom of action of a natural person and, simultaneously, implementation of other human rights established in the fundamental law of the state. The institute of personal data protection was established by expanding the understanding of the content of the right to privacy in the 70’s of the 19th century, when the government of several European countries initiated information processing projects, such as population census etc. For the development of information technology, more and more information on persons was kept and processed in electronic form. One of the legal problems was gathering of information on natural persons and the right to privacy. In order to ensure the protection of privacy, separate European countries, on their own initiative, established a law on data protection. The first laws on the protection of personal data in Europe were established in the Federal Republic of Germany, then in Sweden (1973), Norway (1978) and elsewhere. Not all countries adopted laws on data protection at the same time, so the Council of Europe decided to elaborate a convention to unify data protection rules and principles.


2019 ◽  
pp. 245-259
Author(s):  
Bernard Łukanko

The study is concerned with the issue of mutual relationship between the failure to comply with the laws on personal data protection and regulations relating to the protection of personal interests, including in particular the right to privacy. The article presents the views held by the Supreme Court with respect to the possibility of considering acts infringing upon the provisions of the Personal Data Protection Act of 1997 (after 24 May 2018) and of the General Data Protection Regulation (after 25 May 2018) as violation of personal interests, such as the right to privacy. The author shared the view of the case law stating that, if in specifc circumstances the processing of personal data violates the right to privacy, the party concerned may seek remedy on the grounds of Articles 23 and 24 of the Polish Civil Code. This position isalso relevant after the entry into force of the GDPR which, in a comprehensive and exhaustive manner, directly applicable in all Member States, regulates the issue of liability under civil law for infringements of the provisions of the Regulation, however, according to the position expressed in professional literature, it does not exclude the concurrence of claims and violation of the provisions on the protection of personal interests caused by a specifc event. In case of improper processing of personal data, the remedies available under domestic law on the protection of personal interests may be of particular importance outside the subject matter scope of the GDPR applicability. 


2021 ◽  
Vol 16 (2) ◽  
pp. 63-75
Author(s):  
Denitza Toptchiyska

During the pandemic of COVID-19 in April 2020 the Ministry of Health in Bulgaria began the administration of the Virusafe contact tracking application. With the Law on Emergency Measures and Actions, declared by a decision of the National Assembly of 13th March 2020 amendments to the Electronic Communications Act were adopted. The purpose of the legislative amendments was to provide access of the competent authorities to the localization data from the public electronic communication networks of the individuals, who have refused or do not fulfill the obligatory isolation or treatment under art. 61 of the Health Act. This publication aims to analyze the main features of mobile applications for tracking the contacts of infected persons, as well as the adopted legislative changes, comparing them with the standards of personal data protection provided in the EU General Data Protection Regulation 2016/679 and Directive 2002/58/EC on the right to privacy and electronic communications.


Author(s):  
NATALIA V. VARLAMOVA

Among the digital rights, besides the right for internet access that was the subject of consideration in the first part of the article, there are also a right to per-so nal data protection and a right to be forgotten (right to erasure).The right to personal data protection is usually enshrined at the supranational and national levels and is protected by the courts as an aspect of the right to privacy. As an independent fundamental right of a constitutional nature the right to personal data protection is enshrined in EU law. Nevertheless, all attempts to doctrinally justify the existence of certain aspects of this right, beyond the claims to the right to privacy, can not be considered successful. The Court of Justice of the EU, while dealing with the relevant cases in order to determine whether certain methods of processing personal data are legitimate, also refers to the right to privacy, considering these rights to be closely interrelated. The right to personal data protection provides additional (including procedural) guarantees of respect for privacy, human dignity and some other rights, but the purpose of these guarantees is precisely the content of the providing rights. The right to be forgotten (right to erasure) is one of the positive obligations with regard to the personal data protection. This right implies correction, deletion or termination of the processing of personal data at the request of their subject in the presence of a reason for this (when the relevant actions are carried out in violation of the principles of data processing or provisions of the legislation). Analogs of this right are the Latin American orders of habeas data, as well as the right of a person to demand the refutation of information discrediting his honor, dignity and business reputation, in case of their inconsistency with reality under civil law and the legislation on mass media. In digital age the importance of this right is increased by the fact that information posted on the Internet remains easily accessible for an indefinite, almost unlimited, time.This caused the extension of the right to be forgotten to information that is consistent to reality, but has lost its relevance and significance, however, continues to have an adverse impact on the reputation of the person concerned. At the same time, the realization of the right to be forgotten in respect of information posted online is connected with a number of technical problems that require legal solutions.In general, digitalization does not create new human rights of a fundamentally different legal nature. It only actualizes or smooths certain aspects of long-recognized rights, transfers their operation into the virtual space, creates new opportunities for their realization and generates new threats to them. Ensuring human rights in modern conditions involves the search for adequate legal solutions, taking into account the opportunities and limitations generated by digital technologies.


2020 ◽  
pp. 99-110
Author(s):  
Arben Murtezić

The purpose of this paper is to highlight the significance of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) in the overall system of personal data protection, especially from the perspective of non-EU countries that are members of the Council of Europe. This is attempted primarily through the evaluation of correlation between the Convention 108 and ECHR and GDPR in its segment that regulates relationship between the EU and third countries. The interest for the issue of personal data protection has been increasing among legal and ICT professionals, academics, government officials and even a general public over the years. This has been particularly intensified by adopting General Data Protection Regulation (GDPR). However, the adoption of the GDPR did not diminish importance of the Convention 108. On the contrary, it seems that the 'adequacy' principle regarding the third countries proclaimed by the GDPR, stresses its importance. The paper begins with the brief overview of the Convention 108 principles and the modernization that is brought by Protocol of 2018, which coincides with the entry into force of much-mentioned GDPR. It continues with analysis of the relationship between the GDPR and Convention 108, with focus on elements decisively influencing the assessment of the adequacy of the level of protection. Even though there is no sign of equivalence between the right to privacy and personal data protection these matters inevitably intersect in practice. Therefore, the final section of the text summarizes the cases of the European Court of Human Rights invoking Convention 108, with the aim to demonstrate how it is interpreted by the highest judicial instance in Europe.


Author(s):  
Tigran D. Oganesian

The article considers the legality of mass surveillance and protection of personal data in the context of the international human rights law and the right to respect for private life. Special attention is paid to the protection of data on the Internet, where the personal data of billions of people are stored. The author emphasizes that mass surveillance and technology that allows the storage and processing of the data of millions of people pose a serious threat to the right to privacy guaranteed by Article 8 of the ECHR of 1950. Few companies comply with the human rights principles in their operations by providing user data in response to requests from public services. In this regard, States must prove that any interference with the personal integrity of an individual is necessary and proportionate to address a particular security threat. Mandatory data storage, where telephone companies and Internet service providers are required to store metadata about their users’ communications for subsequent access by the law enforcement and intelligence agencies, is neither necessary nor proportionate. The author analyses the legislation of some countries in the field of personal data protection, as well as examples from practice. Practice in many States is evidence of the lack of adequate national legislation and enforcement, weak procedural safeguards and ineffective oversight, which contributes to widespread impunity for arbitrary or unlawful interference with the right to privacy. In conclusion, we propose a number of measures aimed at improving the level of personal data protection in accordance with the international standards. In order to provide guarantees and a minimum level of adequate data protection in the face of new challenges to human rights in an ever-changing digital environment, the author proposes to solve a number of pressing issues. Firstly, States should not have the right to ask companies for and have absolute access to user data without a court order. Secondly, the process of sending a request and receiving data from a telecommunications company should be regulated in detail and transparent. The availability of specialized judges with technical expertise shall be valuable


2021 ◽  
pp. 99-109
Author(s):  
MARIJANA MLADENOV ◽  
JELENA STOJŠIĆ DABETIĆ

Should we consider the right to be forgotten as a threat to free speech or the mechanism of the right to privacy? This most controversial element of the right to privacy and personal data protection caused the global debate on privacy and freedom of speech. Despite the fact that the right to be forgotten is codified in Article 17 of the General Data Protection Regulation and that fundamental postulates of this right were defined in Google v. Spain, there still remain unresolved issues. In order to gain a clear idea of the content of the right to be forgotten, as the principle of data protection in accordance with the latest European perspective, the subject matter of the paper refers to analyses of the developments of this right in the light of relevant regulations, as well as of the jurisprudence of the Court of Justice of the European Union (CJEU). The article firstly provides an overview of the concept of the right to be forgotten, from the very early proposals that gave rise to it, to the latest ones contained in recent regulations. Furthermore, the special attention is devoted to the new standards of the concept of the right to be forgotten from the aspect of recent rulings of the CJEU, GC et al v. CNIL and CNIL v. Google. Within the concluding remarks, the authors highlight the need for theoretical innovation and an adequate legal framework of the right to be forgotten in order to fit this right within the sociotechnical legal culture. The goal of the article is to provide insight regarding the implementation of the right to be forgotten in the European Union and to identify the main challenges with respect to the issue.


2021 ◽  
Vol 8 (2) ◽  
Author(s):  
Imas Novita Juaningsih ◽  
Rayhan Naufaldi Hidayat ◽  
Kiki Nur Aisyah ◽  
Dzakwan Nurirfan Rusli

AbstractThe right to privacy is a personal right of every individual which must be protected by the state in accordance with the mandate of the constitution. Along with the development of information and communication technology, the discourse regarding the right to privacy has come under the spotlight again given the high intensity of personal data utilization, especially by corporations in the digital business era. This research will further analyze the use of consumer personal data by corporations from a legal perspective. The research method used is library research through a statute approach. The results of this study indicate that there is still obesity in regulations related to personal data protection in Indonesia, where the total reaches 30 regulations in various sectors. Moreover, this reality is exacerbated by the inadequacy of the Ministry of Communication and Information Technology (Kominfo) in conducting surveillance and investigations related to personal data protection. The result of all of this is the creation of legal loopholes that are often exploited to carry out crimes in the form of hacking and theft of personal data that harm consumers and the wider community. Therefore, there is a need for legal reform accompanied by a reconception of supervisory agencies regarding the protection of personal data as an integral part of upholding privacy rights in an era of constitutional disruption. Keywords: Personal Data Protection, Privacy Rights, Corporation, Constitution. AbstrakHak privasi merupakan hak pribadi setiap individu yang wajib dilindungi oleh negara sesuai dengan amanat konstitusi. Seiring dengan perkembangan teknologi informasi dan komunikasi, diskursus perihal hak privasi kembali mendapat sorotan mengingat tingginya intensitas pemanfaatan data pribadi, terutama oleh korporasi di era bisnis digital. Penelitian kali ini akan menganalisa lebih jauh terkait penggunaan data pribadi konsumen oleh korporasi dari perspektif hukumnya. Adapun metode penelitian yang digunakan adalah penelitian kepustakaan melalui pendekatan perundang-undangan (statute approach). Hasil dari penelitian ini menunjukkan bahwa masih terjadinya obesitas regulasi terkait perlindungan data pribadi Di Indonesia, dimana totalnya mencapai 30 Undang-Undang di berbagai sektor. Terlebih, realita tersebut semakin diperburuk dengan tidak optimalnya Kementrian Komunikasi dan Informatika (Kominfo) dalam melakukan pengawasan dan investigasi terkait perlindungan data pribadi. Akibat dari semua itu ialah terciptanya celah hukum yang kerap kali dieksploitasi untuk melancarkan kejahatan berupa peretasan dan pencurian data pribadi yang merugikan konsumen serta masyarakat dalam cakupan yang lebih luas. Oleh karena itu, diperlukannya reformasi hukum yang diiringi dengan rekonsepsi lembaga pengawas terkait perlindungan data pribadi sebagai bagian integral dari penegakan hak privasi di era disrupsi berdasarkan konstitusi. Kata kunci: Perlindungan Data Pribadi, Hak Privasi, Korporasi, Konstitusi. 


2021 ◽  
Author(s):  
Zhivka Mateeva ◽  

In the age of the information society, the possibilities for problems of personal data protection related to the danger and threat of adverse consequences for the individual are extremely high. Violation of the right of the individual in connection with the disclosure of personal data is an encroachment on privacy. This paper examines the nature of the right to the protection of personal data, which is an integral part of the right to privacy. On the basis of the analysis of the right to protection of personal data, its essential features, characteristic for the basic human rights, are derived. On this basis, the role of the right to personal data protection is outlined, finding application in various spheres of modern life.


2020 ◽  
Vol 92 (3) ◽  
pp. 347-378
Author(s):  
Miloš Sekulić ◽  
Gordan Grujić

The right to privacy is one of the fundamental human rights that serves to realize a man as a social being and protect the private spheres of their life. Even though this right can be looked at in different ways, due to the modern development of information and communication technologies, it is largely related to personal data and their availability to other persons. In that sense, the right to privacy is also protected via personal data protection. The basis for such protections in Serbian law has already been implemented in the Constitution of Serbia, and by adopting a new Personal Data Protection Law, the legislator has shown their determination to intensify and expand that protection. As it relates to criminal justice protection, a separate criminal offence of unauthorized collection of personal data is prescribed in Article 146 of the Criminal Code. The authors of this scientific paper will try to expose the threat to the right to privacy and personal data, and to give a clearer picture of how criminal justice protection of these values is realized in the Serbian law by presenting the elements of the aforementioned crime.


Sign in / Sign up

Export Citation Format

Share Document