Open Access. Powered by Scholars. Published by Universities.®

Privacy Law Commons™

Open Access. Powered by Scholars. Published by Universities.®

GDPR

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 31 - 60 of 60

Full-Text Articles in Privacy Law

Algorithmic Impact Assessments Under The Gdpr: Producing Multi-Layered Explanations, Margot E. Kaminski, Gianclaudio Malgieri Jan 2021

Algorithmic Impact Assessments Under The Gdpr: Producing Multi-Layered Explanations, Margot E. Kaminski, Gianclaudio Malgieri

Publications

Policy-makers, scholars, and commentators are increasingly concerned with the risks of using profiling algorithms and automated decision-making. The EU’s General Data Protection Regulation (GDPR) has tried to address these concerns through an array of regulatory tools. As one of us has argued, the GDPR combines individual rights with systemic governance, towards algorithmic accountability. The individual tools are largely geared towards individual “legibility”: making the decision-making system understandable to an individual invoking her rights. The systemic governance tools, instead, focus on bringing expertise and oversight into the system as a whole, and rely on the tactics of “collaborative governance,” that is, …


The Gdpr And The Consequences Of Big Regulation, Matthew R. A. Heiman Jun 2020

The Gdpr And The Consequences Of Big Regulation, Matthew R. A. Heiman

Pepperdine Law Review

This Article summarizes the key features of the European Union’s General Data Privacy Regulation (GDPR) that became effective on May 25, 2018. The stated purpose of the law is to give individuals greater control over personal information that is handled by companies and organizations. The Article argues that the GDPR is fundamentally flawed. Key terms within the GDPR are undefined; the burdens of the GDPR will fall heaviest on small businesses; the GDPR disrupts a valuable business model; the GDPR will stymie growth, innovation, and information sharing; and it may be the product of protectionist impulses rather than concerns for …


What Consumers Don’T Know They’Re Giving Away (Data And Privacy Concerns), Bayleigh Reeves May 2020

What Consumers Don’T Know They’Re Giving Away (Data And Privacy Concerns), Bayleigh Reeves

Marketing Undergraduate Honors Theses

The modern world leverages technology and information captured by it in ways the inventors of these technologies likely never imagined. Phones and other devices are gathering information about consumers in the background when they do not even realize it. Pew Research Center found that about 77% of Americans own a smartphone and 88% use the internet. This mass access to technology and information tracking raises many privacy concerns. Basic demographic information is being tracked as well as more in-depth information like shopping tendencies, financial information, and information about known associates. While most of this data is being used for marketing …


Untangling The Privacy Law Web: Why The California Consumer Privacy Act Furthers The Need For Federal Preemptive Legislation, Jordan Yallen May 2020

Untangling The Privacy Law Web: Why The California Consumer Privacy Act Furthers The Need For Federal Preemptive Legislation, Jordan Yallen

Loyola of Los Angeles Law Review

No abstract provided.


Privacy's Constitutional Moment And The Limits Of Data Protection, Woodrow Hartzog, Neil M. Richards May 2020

Privacy's Constitutional Moment And The Limits Of Data Protection, Woodrow Hartzog, Neil M. Richards

Faculty Scholarship

America’s privacy bill has come due. Since the dawn of the Internet, Congress has repeatedly failed to build a robust identity for American privacy law. But now both California and the European Union have forced Congress’s hand by passing the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR). These data protection frameworks, structured around principles for Fair Information Processing called the “FIPs,” have industry and privacy advocates alike clamoring for a “U.S. GDPR.” States seemed poised to blanket the country with FIP-based laws if Congress fails to act. The United States is thus in the midst …


American Privacy Law At The Dawn Of A New Decade (And The Ccpa And Covid-19): Overview And Practitioner Critique, Kimberly Dempsey Booher, Martin B. Robins Jan 2020

American Privacy Law At The Dawn Of A New Decade (And The Ccpa And Covid-19): Overview And Practitioner Critique, Kimberly Dempsey Booher, Martin B. Robins

Marquette Intellectual Property Law Review

No abstract provided.


Do You Accept These Cookies? How The General Data Protection Regulation Keeps Consumer Information Safe, Jayne Chorpash Jan 2020

Do You Accept These Cookies? How The General Data Protection Regulation Keeps Consumer Information Safe, Jayne Chorpash

Northwestern Journal of International Law & Business

Abstract:

This note examines the General Data Protection Regulation implemented in the EU in 2018. The GDPR was the result of a long history of data privacy laws that have been met with varying levels of success. While the GDPR has retained many characteristics that have made past privacy laws successful, it has also made some important changes. Most notably, the GDPR gives generous rights to consumers to guard and protect their data, which is of growing concern in light of how easy it is to share information in our modern age. Additionally, the GDPR has a much broader territorial …


Reconciling U.S. Banking And Securities Data Preservation Rules With European Mandatory Data Erasure Under Gdpr, Ronald V. Distante Jan 2020

Reconciling U.S. Banking And Securities Data Preservation Rules With European Mandatory Data Erasure Under Gdpr, Ronald V. Distante

Fordham Journal of Corporate & Financial Law

United States law, which requires financial institutions to retain customer data, conflicts with European Union law, which requires financial institutions to delete customer data on demand. A financial institution operating transnationally cannot comply with both U.S. and EU law. Financial institutions thus face the issue that they cannot possibly delete and retain the same data simultaneously. This Note will clarify the scope and nature of this conflict.

First, it will clarify the conflict by examining (1) the relevant laws, which are Europe’s General Data Protection Regulation (GDPR), the U.S. Bank Secrecy Act, and Securities and Exchange Commission (SEC) regulations, (2) …


Privacy's Constitutional Moment And The Limits Of Data Protection, Neil M. Richards, Woodrow Hartzog Jan 2020

Privacy's Constitutional Moment And The Limits Of Data Protection, Neil M. Richards, Woodrow Hartzog

Scholarship@WashULaw

America’s privacy bill has come due. Since the dawn of the Internet, Congress has repeatedly failed to build a robust identity for American privacy law. But now both California and the European Union have forced Congress’s hand by passing the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR). These data protection frameworks, structured around principles for Fair Information Processing called the “FIPs,” have industry and privacy advocates alike clamoring for a “U.S. GDPR.” States seemed poised to blanket the country with FIP-based laws if Congress fails to act. The United States is thus in the midst …


A Relational Turn For Data Protection?, Neil M. Richards, Woodrow Hartzog Jan 2020

A Relational Turn For Data Protection?, Neil M. Richards, Woodrow Hartzog

Scholarship@WashULaw

While most approaches to privacy and data protection focus on the data, this paper explores an alternative approach that focuses on relationships. This means looking more closely at how the people who are exposing their information and the people that are inviting that disclosure relate to each other. It is concerned with what powerful parties owe to vulnerable parties–not just with their personal information, but with the things they see, the things they can click, and the decisions that are made about them. It’s less about the nature of data and more about the nature of power. And it can …


A Recent Renaissance In Privacy Law, Margot Kaminski Jan 2020

A Recent Renaissance In Privacy Law, Margot Kaminski

Publications

Considering the recent increased attention to privacy law issues amid the typically slow pace of legal change.


Towards Standard Information Privacy, Innovations Of The New General Data Protection Regulation, Ali Alibeigi, Abu Bakar Munir, Md Ershadulkarim, Adeleh Asemi Sep 2019

Towards Standard Information Privacy, Innovations Of The New General Data Protection Regulation, Ali Alibeigi, Abu Bakar Munir, Md Ershadulkarim, Adeleh Asemi

Library Philosophy and Practice (e-journal)

Protection of personal data in recent decades became more crucial affecting by emergence of the new technologies especially computer, internet, information and communications technology. However, Europeans felt this necessity at time and provided for up-to-date and supportive laws. The General Data Protection Regulation (GDPR) is the latest legislation in EU to protect personal data of individuals based on the recent technological advancements. However, its’ domestic and international output still is debatable. This doctrinal legal study by using descriptive methods, aimed to evaluate the GDPR through analyzing and interpreting its’ provisions by especial focus on its’ innovations. The results show that …


Catalyzing Privacy Law, Anupam Chander, Margot E. Kaminski, William Mcgeveran Aug 2019

Catalyzing Privacy Law, Anupam Chander, Margot E. Kaminski, William Mcgeveran

Georgetown Law Faculty Publications and Other Works

The United States famously lacks a comprehensive federal data privacy law. In the past year, however, over half the states have proposed broad privacy bills or have established task forces to propose possible privacy legislation. Meanwhile, congressional committees are holding hearings on multiple privacy bills. What is catalyzing this legislative momentum? Some believe that Europe’s General Data Protection Regulation (GDPR), which came into force in 2018, is the driving factor. But with the California Consumer Privacy Act (CCPA) which took effect in January 2020, California has emerged as an alternate contender in the race to set the new standard for …


The Gdpr: It Came, We Saw, But Did It Conquer?, Leila Javanshir Apr 2019

The Gdpr: It Came, We Saw, But Did It Conquer?, Leila Javanshir

Seattle University Law Review

On February 1, 2019, the Seattle University Law Review held its annual symposium at the Seattle University School of Law. Each year, the Law Review hosts its symposium on a topic that is timely and meaningful. This year, privacy and data security professionals from around the globe gathered to discuss the current and future effects of the General Data Protection Regulation (GDPR) that was implemented on May 25, 2018. The articles and essays that follow this Foreword are the product of this year’s symposium.


Confiding In Con Men: U.S. Privacy Law, The Gdpr, And Information Fiduciaries, Lindsey Barrett Apr 2019

Confiding In Con Men: U.S. Privacy Law, The Gdpr, And Information Fiduciaries, Lindsey Barrett

Seattle University Law Review

In scope, ambition, and animating philosophy, U.S. privacy law and Europe’s General Data Protection Regulation are almost diametric opposites. The GDPR’s ambitious individual rights, significant prohibitions, substantive enforcement regime, and broad applicability contrast vividly with a scattershot U.S. regime that generally prioritizes facilitating commerce over protecting individuals, and which has created perverse incentives for industry through anemic enforcement of the few meaningful limitations that do exist. A privacy law that characterizes data collectors as information fiduciaries could coalesce with the commercial focus of U.S. law, while emulating the GDPR’s laudable normative objectives and fortifying U.S. consumer privacy law with a …


General Data Protection Regulation (Gdpr): Prioritizing Resources, Jennifer Dumas Apr 2019

General Data Protection Regulation (Gdpr): Prioritizing Resources, Jennifer Dumas

Seattle University Law Review

This Article will discuss and analyze the years of preparation for the GDPR and provide recommendations for dealing with the GDPR forevermore. It will assess whether the preparation and panic were worth it. In other words, was the time, expense, and distraction my peers and I expended and experienced over the past years proportionate to the requirements and impact of the GDPR? Further, was the high level of preparation and panic many legal departments in countless companies undertook and experienced appropriate now that we have had a chance to see the initial impact of the GDPR?


Footprints: Privacy For Enterprises, Processors, And Custodians…Oh My!, Blair Witzel, Carrie Mount Apr 2019

Footprints: Privacy For Enterprises, Processors, And Custodians…Oh My!, Blair Witzel, Carrie Mount

Seattle University Law Review

Americans’ interest in privacy—as evidenced by increasing news coverage, online searches, and new legislation—has grown over the past decade. After the European Union enacted the General Data Protection Regulation (GDPR), technologists and legal professionals have focused on primary collectors of data—known under various legal regimes as the “controller” or “custodian.” Thanks to advances in computing, many of these data collectors offload the processing of data to third parties providing data-related cloud services like Amazon, Microsoft, and Google. In addition to the data they have already collected about the data subjects themselves, these companies now “hold” that data on behalf of …


Face Off: An Examination Of State Biometric Privacy Statutes & Data Harm Remedies, Maya E. Rivera Jan 2019

Face Off: An Examination Of State Biometric Privacy Statutes & Data Harm Remedies, Maya E. Rivera

Fordham Intellectual Property, Media and Entertainment Law Journal

As biometric authentication becomes an increasingly popular method of security among consumers, only three states currently have statutes detailing how such data may be collected, used, retained, and released. The Illinois Biometric Information Privacy Act is the only statute of the three that enshrines a private right of action for those who fail to properly handle biometric data. Both the Texas Capture or Use Biometric Identifier Act Information Act and the Washington Biometric Privacy Act allow for state Attorneys General to bring suit on behalf of aggrieved consumers. This Note examines these three statutes in the context of data security …


"You Have The Data"...The Writ Of Habeas Data And Other Data Protection Rights: Is The United States Falling Behind?, Sarah L. Lode Jan 2019

"You Have The Data"...The Writ Of Habeas Data And Other Data Protection Rights: Is The United States Falling Behind?, Sarah L. Lode

Indiana Law Journal

In Part I of this Note, I will discuss the writ of habeas data that has been developed primarily, but not exclusively, in Latin American countries. I will discuss the intricacies of the writ, how it evolved, and how it is applied today. Using Argentina as an example, I will discuss how the writ would be used by an Argentine citizen to protect her personal data. Part II summarizes the previously employed data protection scheme in the European Union, the Data Protection Directive (“the Directive”), and will also discuss the new EU data protection regulation, the General Data Protection Regulation …


The Right To Explanation, Explained, Margot E. Kaminski Jan 2019

The Right To Explanation, Explained, Margot E. Kaminski

Publications

Many have called for algorithmic accountability: laws governing decision-making by complex algorithms, or AI. The EU’s General Data Protection Regulation (GDPR) now establishes exactly this. The recent debate over the right to explanation (a right to information about individual decisions made by algorithms) has obscured the significant algorithmic accountability regime established by the GDPR. The GDPR’s provisions on algorithmic accountability, which include a right to explanation, have the potential to be broader, stronger, and deeper than the preceding requirements of the Data Protection Directive. This Essay clarifies, largely for a U.S. audience, what the GDPR actually requires, incorporating recently released …


Humans Forget, Machines Remember: Artificial Intelligence And The Right To Be Forgotten, Eduard Fosch Villaronga, Peter Kieseberg, Tiffany Li Apr 2018

Humans Forget, Machines Remember: Artificial Intelligence And The Right To Be Forgotten, Eduard Fosch Villaronga, Peter Kieseberg, Tiffany Li

Faculty Scholarship

To understand the Right to be Forgotten in context of artificial intelligence, it is necessary to first delve into an overview of the concepts of human and AI memory and forgetting. Our current law appears to treat human and machine memory alike – supporting a fictitious understanding of memory and forgetting that does not comport with reality. (Some authors have already highlighted the concerns on the perfect remembering.) This Article will examine the problem of AI memory and the Right to be Forgotten, using this example as a model for understanding the failures of current privacy law to reflect the …


The Tortoise And The Hare Of International Data Privacy Law: Can The United States Catch Up To Rising Global Standards?, Matthew Humerick Jan 2018

The Tortoise And The Hare Of International Data Privacy Law: Can The United States Catch Up To Rising Global Standards?, Matthew Humerick

Catholic University Journal of Law and Technology

Technological developments spur the development of big data on a global scale. The breadth of data companies collect, maintain, process, and transmit affects nearly every country and organization around the world. Inherent to big data are issues of data protection and transfers to third countries. While many jurisdictions emphasize the importance of protecting consumer data, such as the European Union, others, like the United States, do not. To circumvent this issue, the United States and European Union contracted around data privacy standard discrepancies through the Safe Harbor Agreement, which eased cross-border data transfers. However, the Court of Justice of the …


The Gdpr’S Version Of Algorithmic Accountability, Margot Kaminski Jan 2018

The Gdpr’S Version Of Algorithmic Accountability, Margot Kaminski

Publications

No abstract provided.


Alexa, Who Owns My Pillow Talk? Contracting, Collaterizing, And Monetizing Consumer Privacy Through Voice-Captured Personal Data, Anne Logsdon Smith Jan 2018

Alexa, Who Owns My Pillow Talk? Contracting, Collaterizing, And Monetizing Consumer Privacy Through Voice-Captured Personal Data, Anne Logsdon Smith

Catholic University Journal of Law and Technology

With over one-fourth of households in the U.S. alone now using voice-activated digital assistant devices such as Amazon’s Echo (better known as “Alexa”) and Google’s Home, companies are recording and transmitting record volumes of voice data from the privacy of people’s homes to servers across the globe. These devices capture conversations about everything from online shopping to food preferences to entertainment recommendations to bedtime stories, and even phone and appliance use. With “Big Data” and business analytics expected to be a $203 billion-plus industry by 2020, companies are racing to acquire and leverage consumer data by selling it, licensing it, …


Remarks On Patient Privacy: Problems, Perspectives, And Opportunities, Stacey A. Tovino Jan 2018

Remarks On Patient Privacy: Problems, Perspectives, And Opportunities, Stacey A. Tovino

Faculty Articles

No abstract provided.


The Case Against Idealising Control, Woodrow Hartzog Jan 2018

The Case Against Idealising Control, Woodrow Hartzog

Faculty Scholarship

Seemingly everyone, from scholars, industry, and privacy advocates to lawmakers, regulators, and judges seems to have settled on the idea that the key to privacy is control over personal information. But in practice, there is only so much a person can do. Control is far too precious and finite of a concept to meaningfully scale. It will never work for personal data mediated by technology.

Now we have an entire empire of data protection built around the crumbling edifice of control. The idealisation of control in modern data protection regimes like the GDPR and the ePrivacy Directive creates a pursuit …


The Hipaa Privacy Rule And The Eu Gdpr: Illustrative Comparisons, Stacey A. Tovino Jan 2017

The Hipaa Privacy Rule And The Eu Gdpr: Illustrative Comparisons, Stacey A. Tovino

Faculty Articles

In this Article, Professor Tovino compares and contrasts three illustrative concepts and rights in the Privacy Rule and/or the GDPR, including the concepts of authorization and consent, the rights of amendment and rectification, and the right to erasure. Identified similarities reflect the core values of HHS and the EU with respect to maintaining the confidentiality and privacy of personal data and protected health information, respectively. Identified differences reflect the Privacy Rule's original, narrow focus on health industry participants and individually identifiable health information compared to the GDPR's broad focus on data controllers and personal data. Other differences reflect, perhaps, the …


Machine Learning With Personal Data: Is Data Protection Law Smart Enough To Meet The Challenge?, Fred H. Cate, Christopher Kuner, Dan Jerker B. Svantesson, Orla Lynskey, Christopher Millard Jan 2017

Machine Learning With Personal Data: Is Data Protection Law Smart Enough To Meet The Challenge?, Fred H. Cate, Christopher Kuner, Dan Jerker B. Svantesson, Orla Lynskey, Christopher Millard

Articles by Maurer Faculty

No abstract provided.


Balancing A Right To Be Forgotten With A Right To Freedom Of Expression In The Wake Of Google Spain V. Aepd, Shaniqua Singleton Sep 2016

Balancing A Right To Be Forgotten With A Right To Freedom Of Expression In The Wake Of Google Spain V. Aepd, Shaniqua Singleton

Georgia Journal of International & Comparative Law

No abstract provided.


Data Protection In The European Union: A Closer Look At The Current Patchwork Of Data Protection Laws And The Proposed Reform That Could Replace Them All, Christina Glon Jan 2014

Data Protection In The European Union: A Closer Look At The Current Patchwork Of Data Protection Laws And The Proposed Reform That Could Replace Them All, Christina Glon

Faculty Articles

Laws protecting a European's right to control the flow of their own personal data (also known as "data privacy") date back as early as 1950. In the 65 years since the Council of Europe declared that every person has the fundamental "right to respect for his private and family life, his home and his correspondence," a patchwork of conventions, directives, treaties and communications have been created to ensure the ongoing protection of this right. However, in recent years, this patchwork approach has been unable to keep up with the pace of technology and has created confusion and concern for the …