首页> 外文期刊>Journal of risk research >The risk-based approach under the new EU data protection regulation: a critical perspective
【24h】

The risk-based approach under the new EU data protection regulation: a critical perspective

机译:新欧盟数据保护法规下基于风险的方法:批判性观点

获取原文
获取原文并翻译 | 示例
       

摘要

The first broad reform of personal data protection legislation in the European Union entered into force in May 2018 (Regulation (EU) 2016/ 679, the General Data Protection Regulation). Remarkably, with this reform a risk-based approach has been introduced as the core data protection enforcement model, while data protection authorities see their regulatory role significantly weakened. The risk-based approach is to be implemented by the data controllers (i.e. the operators) via data protection impact assessments (evoking the established environmental impact assessment procedure) and notification of breaches, among other procedures. Hence the scope of both the concepts of risk and risk regulation spread beyond conventional domains, namely the environment, public health or safety, i.e. physical risks, to encompass risks to intangible values, i.e. individual rights and freedoms, presumably harder to assess and manage. Strikingly, the reform has been accompanied by a confident discourse by EU institutions, and their avowed belief in the reform's ability to safeguard the fundamental right to data protection in the face of evolving data processing techniques, specifically, big data, the Internet of Things, and related algorithmic decision-making. However, one may wonder whether there isn't cause for concern in view of the way the risk-based approach has been designed in the data protection legislation. In this article, the risk-based approach to data protection is analysed in the light of the reform's underlying rationality. Comparison with the risk regulatory experience in environmental law, particularly the environmental impact assessment procedure, is drawn upon to assist us in pondering the shortcomings, as well as the opportunities of the novel risk-based approach.
机译:欧洲联盟对个人数据保护立法的首次广泛改革于2018年5月生效(法规(EU)2016/679,通用数据保护条例)。值得注意的是,通过这项改革,引入了一种基于风险的方法作为核心的数据保护执行模型,而数据保护机构则认为其监管作用大大削弱了。数据控制者(即运营商)将通过数据保护影响评估(采用既定的环境影响评估程序)和违规通知等措施来实施基于风险的方法。因此,风险和风险监管概念的范围都超出了传统领域,即环境,公共卫生或安全(即自然风险),以涵盖无形价值(即个人权利和自由)的风险,可能难以评估和管理。引人注目的是,这项改革伴随着欧盟机构的自信演讲,他们坚信改革能够在面对不断发展的数据处理技术(尤其是大数据,物联网,以及相关的算法决策。但是,考虑到数据保护法规中基于风险的方法的设计方式,人们可能会担心是否值得关注。本文根据改革的基本合理性分析了基于风险的数据保护方法。我们将与环境法中的风险监管经验进行比较,尤其是环境影响评估程序,以帮助我们思考基于风险的新方法的缺点以及机遇。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号