Personal Data in Data Value Chains – Is Data Protection Law Fit for the Data Economy?

Author(s):  
Christiane Wendehorst
2017 ◽  
Vol 2017 (1) ◽  
pp. 35-44
Author(s):  
Dawid Zadura

Abstract In the review below the author presents a general overview of the selected contemporary legal issues related to the present growth of the aviation industry and the development of aviation technologies. The review is focused on the questions at the intersection of aviation law and personal data protection law. Massive processing of passenger data (Passenger Name Record, PNR) in IT systems is a daily activity for the contemporary aviation industry. Simultaneously, since the mid- 1990s we can observe the rapid growth of personal data protection law as a very new branch of the law. The importance of this new branch of the law for the aviation industry is however still questionable and unclear. This article includes the summary of the author’s own research conducted between 2011 and 2017, in particular his audits in LOT Polish Airlines (June 2011-April 2013) and Lublin Airport (July - September 2013) and the author’s analyses of public information shared by International Civil Aviation Organization (ICAO), International Air Transport Association (IATA), Association of European Airlines (AEA), Civil Aviation Authority (ULC) and (GIODO). The purpose of the author’s research was to determine the applicability of the implementation of technical and organizational measures established by personal data protection law in aviation industry entities.


Author(s):  
Raphaël Gellert

The main goal of this book is to provide an understanding of what is commonly referred to as “the risk-based approach to data protection”. An expression that came to the fore during the overhaul process of the EU’s General Data Protection Regulation (GDPR)—even though it can also be found in other statutes under different acceptations. At its core it consists in endowing the regulated organisation that process personal data with increased responsibility for complying with data protection mandates. Such increased compliance duties are performed through risk management tools. It addresses this topic from various perspectives. In framing the risk-based approach as the latest model of a series of regulation models, the book provides an analysis of data protection law from the perspective of regulation theory as well as risk and risk management literatures, and their mutual interlinkages. Further, it provides an overview of the policy developments that led to the adoption of such an approach, which it discusses in the light of regulation theory. It also includes various discussions pertaining to the risk-based approach’s scope and meaning, to the way it has been uptaken in statutes including key provisions such as accountability and data protection impact assessments, or to its potential and limitations. Finally, it analyses how the risk-based approach can be implemented in practice by providing technical analyses of various data protection risk management methodologies.


Significance Such programmes contribute not only to Indonesia’s efforts to boost the cyber readiness of its booming digital economy, but are also designed to maintain China's friendly relations with South-east Asia’s largest economy amid the intensifying technology tensions between China and the United States. Impacts The Personal Data Protection Law would need to clarify key provisions and concepts to be effective. The BSSN’s extensive powers will fuel civil society concerns about excessive state surveillance. Turning down Chinese technology suppliers carries cost and wider economic ramifications for Jakarta.


Significance The experience of surfing the net is vastly different for women, who have been disproportionately at the receiving end of cybercrimes that undermine their safety online. As elsewhere, the forms of online offence included bullying, stalking, impersonation and non-consensual pornography. Impacts Lack of online safety will limit the female customer base of digital platforms. Entrenched weaknesses of the judicial systems impede reporting and conviction of cybercrime. Civil society demands for a personal data protection law will rise.


Author(s):  
Tibor Tajti

Chapter VI is a new chapter in the EIR. Its presence signals the importance that data protection law has gained in Europe since the adoption of the Data Protection Directive 95/46/EC (DPD) and Regulation 45/2001. Although the DPD is not—though it comes close to—a maximum harmonisation directive, its implementation by Member States by the end of 1998 increased data protection standards on national levels as well. Yet the concrete reason that led to the addition of this Chapter is the expanded scope of the EIR as far as the exchange and publication of personal data is concerned. The expansion and thus the enhanced need for data protection is due in particular to the provision made in the recast EIR for newly established interconnected national insolvency registers, accessible via the European e-Justice Portal. This provision has been made at a time when data protection law is increasingly recognised as a ‘stand-alone’ subject, emancipated from privacy law, as expressed indirectly also by the popularisation of the ‘data protection’ nomenclature originating in the German term ‘Datenschutz’. This has clear implications for private and commercial law, including insolvency law.


Sign in / Sign up

Export Citation Format

Share Document