1 option
Data Subject Rights under the GDPR.
- Format:
- Book
- Author/Creator:
- Vrabec, Helena U., 1989-
- Language:
- English
- Subjects (All):
- European Parliament. General Data Protection Regulation.
- European Parliament.
- Data protection--Law and legislation--European Union countries.
- Data protection.
- European Union countries.
- Physical Description:
- 1 online resource (xx, 268 pages)
- Edition:
- 1st ed.
- Place of Publication:
- Oxford : Oxford University Press, Incorporated, 2021.
- Summary:
- In 2018, the GDPR started a revolution in the data protection world. One of the most far-reaching developments of the new regulation was the chapter on data subject rights. Old rights were strengthened and extended, and several new rights were introduced. For data subjects who felt overwhelmed with the information overload, the GDPR meant a promise of more individual control over data. In combination with severe financial penalties, the revised rights brought the potential to become a vehicle of data protection law enforcement. However, there are still many uncertainties related to data subject rights due to the fact that the GDPR only recently entered into force. The Court of Justice of the EU and other EU governmental authorities have not yet had the time to provide thorough and updated guidance (although the court has been actively adjudicating on these individual rights ever since the GDPR was adopted). Not only is the lack of guidance a problem, the applicability of data subject rights is strongly influenced by the economic and social (data-driven) context. This book provides a thorough analysis of data subject rights under the new GDPR framework and their legal operation. The goal is to help individuals (lawyers and others) to navigate the subject area and/or possibly pursue claims. Its additional value is that it considers the rights in a big data environment and therefore more accurately points out inefficiencies and provides criticism where needed.
- Contents:
- cover
- Half title
- Data Subject Rights under the GDPR
- Copyright
- Dedication
- Table of Contents
- Table of Cases
- Table of Legislation
- List of Abbreviations
- 1 Introduction
- 1.1 The lack of individual control in the data-driven economy
- 1.2 The individual in the data-driven (big-data) economy
- 1.2.1 Compromised privacy
- 1.2.2 Lack of transparency
- 1.2.3 Limited choice and autonomy
- 1.2.4 Discrimination
- 1.2.5 Power and control asymmetries
- 1.3 The need for enhanced data subject control and rights-regulatory response and the motivation for this book
- 1.4 A cautionary remark regarding scope
- 1.5 Introducing the main concepts
- 1.6 Structure
- 2 Safeguarding Individuals in the Data-driven Economy-EU Data Protection Framework in a Nutshell
- 2.1 Introduction
- 2.2 EU primary law
- 2.2.1 Introduction
- 2.2.2 The protection of an individual and her data in the EU system of fundamental rights
- 2.2.2.1 The ECHR system of protection of personal data and private life
- 2.2.2.1.1 The right to private life under Article 8 of the ECHR
- 2.2.2.1.2 Protection of personal data under Article 8 of the ECHR
- 2.2.2.2 Privacy and data protection as part of the EU framework of fundamental rights
- 2.2.2.2.1 The right to private life and protection of privacy of personal data under Article 7 of the EU Charter
- 2.2.2.2.2 The right to data protection in Article 8 of the EU Charter
- 2.2.2.2.2.1 The reasons to codify data protection as a human right
- 2.2.2.2.2.2 Differences between the data protection right and the right to privacy
- 2.3 EU secondary law
- 2.3.1 Introduction
- 2.3.2 Data protection law
- 2.3.2.1 General data protection
- 2.3.2.1.1 Personal data at the heart of data protection law
- 2.3.2.1.2 Protection-oriented duties of commercial data users.
- 2.3.2.1.2.1 Definitions of data users
- 2.3.2.1.2.2 Personal data protection principles for personal data users
- 2.3.2.1.3 Control-enhancing rights of data subjects
- 2.3.2.1.3.1 Definition of data subjects
- 2.3.2.1.3.2 Data subject rights
- 2.3.2.2 Protection of privacy in public communication networks (ePrivacy)
- 2.3.3 Cybersecurity provisions
- 2.3.4 Competition law
- 2.3.5 Consumer protection law
- 2.4 Conclusions
- 3 Control as a Central Notion in the Discussion on Data Subject Rights
- 3.1 Introduction
- 3.2 Individual control over data and fundamental rights
- 3.2.1 Control over personal data and the right to informational self-determination
- 3.2.2 Control over personal data and the right to privacy
- 3.2.3 Control over personal data and the right to data protection
- 3.2.4 Control over personal data and the right to property
- 3.3 Control and EU data protection law
- 3.3.1 Policy vision for individual control in the data-driven economy
- 3.3.2 Reflections of control in the GDPR
- 3.3.3 Clustering control rights in the GDPR
- 3.4 Practical challenges
- 3.5 Conclusions
- 4 The Right to Information
- 4.1 Introduction
- 4.2 The link to fundamental values
- 4.3 Regulatory framework under the GDPR
- 4.3.1 The content of the communicated information
- 4.3.1.1 The information catalogue
- 4.3.1.1.1 Information about legal bases
- 4.3.1.1.2 Information about the length of the storage period
- 4.3.1.1.3 Information about third parties and recipients of data
- 4.3.1.1.4 Information about new (other) purposes of data processing
- 4.3.1.1.5 Information about the sources of data
- 4.3.1.2 The right to explanation
- 4.3.1.2.1 Information about automated decision-making in Articles 13 and 14
- 4.3.2 The quality of communication
- 4.3.3 The form of communicating information provisions.
- 4.3.3.1 Privacy policies and/or notices
- 4.3.3.1.1 Icons and other visualisations
- 4.3.3.1.2 Standardised privacy policies
- 4.3.3.1.3 Information incorporated in standard terms and conditions
- 4.3.4 Timing
- 4.3.4.1 When in time?
- 4.3.4.2 How often in time?
- 4.3.5 Restrictions
- 4.4 The right to information in the electronic communication sector
- 4.4.1 Privacy of electronic communication
- 4.4.2 Informing about storing/accessing information in the terminal equipment of a subscriber
- 4.4.3 Informing users about collecting the information emitted by terminal equipment (such as geolocation information)
- 4.5 Conclusions and a short commentary through the lens of the data-driven economy
- 5 The Right of Access under EU Data Protection Law
- 5.1 Introduction
- 5.2 The right of access under the GDPR
- 5.3 The interface to submit requests and provide a copy of personal data
- 5.4 Regulatory boundaries to the right of access
- 5.4.1 Verification of identity
- 5.4.1.1 Timeline
- 5.4.1.2 Limitations of the right to access
- 5.4.1.3 Cost, frequency, and scope of data access requests
- 5.4.1.4 Conflict of rights
- 5.4.1.4.1 Conflict with the data controller's rights
- 5.4.1.4.2 Conflict with the right of other data subjects
- 5.4.1.4.3 Further exemptions
- 5.5 Challenges to the application of the right of access in the data-driven economy
- 5.5.1 The right of access on a continuum between personal and anonymised data
- 5.5.2 Accessing shared data and coupled databases
- 5.5.3 Access to information on automated decision-making
- 5.6 Conclusions and a short commentary through the lens of the data-driven economy
- 6 The Right to Be Forgotten
- 6.1 Introduction
- 6.2 Values underpinning the RTBF
- 6.3 Towards the GDPR's version of the RTBF
- 6.3.1 The right to oblivion in criminal law.
- 6.3.2 The RTBF under the Data Protection Directive
- 6.3.3 The CJEU paving the way towards the GDPR in line with the 2012 proposal
- 6.3.3.1 Google Spain
- 6.3.3.2 Manni
- 6.4 The RTBF under the GDPR
- 6.4.1 The grounds to apply Article 17
- 6.4.1.1 'processing is no longer necessary in relation to the purposes for which it was collected'
- 6.4.1.2 'the data subject withdraws consent . . . and where there is no other legal ground for the processing'
- 6.4.1.3 'the data subject objects to the processing'
- 6.4.1.4 'personal data was collected in relation to the offer of information society services directly to a child'
- 6.4.1.5 'erased for compliance with a legal obligation' or because 'the personal data was unlawfully processed'
- 6.4.2 Exceptions to the right to erasure
- 6.4.2.1 'processing is necessary for exercising the right of freedom of speech and information'
- 6.4.2.2 'processing is necessary for compliance with a legal obligation . . . or for the performance of a task carried out in the public interest or in the exercise of official authority'
- 6.4.2.3 Other reasons
- 6.4.3 The meaning of 'informing third parties'
- 6.5 Options to operationalise the RTBF beyond the GDPR
- 6.5.1 My Account by Google and Privacy Basics by Facebook
- 6.5.1.1 Deletion by default
- 6.5.1.2 Expiration dates
- 6.5.1.3 Down-ranking
- 6.5.1.4 Deletion in the AI world
- 6.5.1.4.1 Unlearning of algorithms
- 6.5.1.4.2 Obfuscation
- 6.6 Conclusions and a short commentary through the lens of the data-driven economy
- 7 Data Portability as a Data Subject Right
- 7.1 Introduction
- 7.2 How and when the idea of data portability emerged
- 7.2.1 Commercial initiatives
- 7.2.2 Regulatory initiatives
- 7.3 Personal data portability under the GDPR
- 7.3.1 Three components of the right.
- 7.3.1.1 'The . . . right to receive the personal data . . . in a structured, commonly used and machine-readable format'
- 7.3.1.2 'the right to transmit those data to another controller without hindrance'
- 7.3.1.3 'the right to have the personal data transmitted directly from one controller to another, where technically feasible'
- 7.3.2 The restrictive definition of the right to data portability
- 7.3.2.1 'data provided'
- 7.3.2.2 'concerns a data subject'
- 7.3.2.3 'The processing is based on consent . . . or on a contract'
- 7.3.2.4 'the processing is carried out by automated means'
- 7.3.2.5 'The right should not apply to processing necessary for the performance of a task . . . in the public interest or in the exercise of official authority'
- 7.3.2.6 'That right shall not adversely affect the rights and freedoms of others'
- 7.4 Data portability versus other data subject rights
- 7.4.1 The right of access
- 7.4.2 The right to erasure (the RTBF)
- 7.4.3 The right to information
- 7.5 Data portability in other legal fields
- 7.5.1 Data portability as a competition law measure
- 7.5.2 Data portability as another aspect of the right to access industrial data
- 7.5.3 Personal data portability at the intersection between consumer and data protection
- 7.6 Unfolding the right to personal data portability as a control-affording entitlement
- 7.6.1 Data portability as a control-affording entitlement
- 7.6.1.1 Control over personal data transfers
- 7.6.1.2 Enabling control over (re)uses of data
- 7.6.1.3 Enabling control over multi-level data flows and complexity
- 7.6.1.4 Enabling free development of personality and equality
- 7.6.2 Data portability as a hindrance to data subject control
- 7.7 Conclusions
- 8 Data Subject Rights in Relation to Profiling
- 8.1 Introduction.
- 8.2 Profiling as a building block of the data-driven value chain.
- Notes:
- Description based on publisher supplied metadata and other sources.
- ISBN:
- 9780192655202
- 0192655205
- 9780192655196
- 0192655191
- 9780191904851
- 0191904856
- OCLC:
- 1480169439
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.