Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection...

43
Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli, PhD [email protected] @1lucabelli

Transcript of Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection...

Page 1: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

Big Data and Personal Data ProtectionChallenges and Opportunities

11 September 2018

CIRET pre-Conference Workshop

Luca Belli, [email protected]@1lucabelli

Page 2: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

1. Big Data: Big Legal Uncertainty?

2. Principles of Data Protection

3. Emerging Regional Tendencies

2Luca Belli, PhD

Page 3: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

1. Big Data: Big Legal

Uncertainty?

3Luca Belli, PhD

Page 4: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

4

Term utilised since the 1990s and features in

numerous officialdocuments

Luca Belli, PhD

Page 5: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

5

Big Data analytics

Capture, aggregate and process large amounts of data to uncover hidden patterns, correlations and other insights

Luca Belli, PhD

Page 6: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

6

rely on powerful processorsand algorithms

characterised by high Velocity, Variety and

Volume in order to extract high Value

Page 7: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

Definitional Vagueness

7Luca Belli, PhD

Page 8: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

8Luca Belli, PhD

Page 9: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

9

valuable insight

By combining personal and non-personal data, Big Data analytics can uncover patterns and predict e.g. what individuals will do

Luca Belli, PhD

Page 10: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

10

1. Personal data frequently feed big data analytics

2. Patterns and correlationsare inferred ex post

Luca Belli, PhD

Page 11: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

11

not possible to communicate the reason and purpose of the

analyticsn in order to request CONSENT ex ante

Luca Belli, PhD

Page 12: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

12Luca Belli, PhD

2. Principles of Data Protection

Page 13: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

13

Data Privacy

legal protection to individuals

against the inappropriate use of technology for processing information

relating to them

Luca Belli, PhD

Page 14: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

14

Goal

Strike fair balance between individual privacy and the free

flow of information

Luca Belli, PhD

Page 15: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

15

The goal is not to prevent the processing of personal data

BUT

To provide safeguards whenever information technology is used for personal data processing

Luca Belli, PhD

Page 16: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

16

The Notice and Consent approach

Luca Belli, PhD

Page 17: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

17

First designed in the 1970s

Growing use of automated systems aimed at collecting and processing data about individuals

Luca Belli, PhD

Page 18: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

18

1974 U.S. Privacy Act

Fair Information Practice Principles

Page 19: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

19

1978:

French Loi Informatique et libertés

Luca Belli, PhD

Page 20: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

20Luca Belli, PhD

Page 21: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

21

“Census” DecisionGerman Constitutional Federal Court, 1983

Luca Belli, PhD

Page 22: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

22

"Informational Self-determination"

Individual right to oversight andcontrol on what personal informationabout us is accessible and how can be

used

Luca Belli, PhD

Page 23: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

23

IBM supplied Hollerith punched card devices to Nazis for census management, to

“report every individual characteristic on a little card”

and

“sort cards according to certain characteristics”

Willy Heidinger

Luca Belli, PhD

Page 24: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

24

Privacy self-management

Implementation of InformationalSelf-determination

Luca Belli, PhD

Page 25: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

25

Only those who are properly notified of the reason, context, and purpose of their personal data collection and processing will be able decide freely whether to

consent or not to such activities

Luca Belli, PhD

Page 26: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

26Luca Belli, PhD

Page 27: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

27

free, specific, informed and unambiguousconsent?

purpose limitation?

transparency?

Luca Belli, PhD

Page 28: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

28Luca Belli, PhD

3. Emerging Regional Tendencies

Page 29: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

29Luca Belli, PhD

Big Problem:

Big Data collection and analysis can happenwithout the knowledge, consent, or understandingof data subjects.

Page 30: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

30Luca Belli, PhD

USA:

no comprehensive federal data protection law

Sectoral laws e.g. Fair Credit Reporting Act; Equal Credit Opportunity Act

Data privacy is under the general protection of Courts

Page 31: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

31Luca Belli, PhD

Europe:

Personal data protection is a specific fundamental right

General Data Protection Regulation2016/679

Page 32: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

32Luca Belli, PhD

• Transparency,

• data minimisation,

• proportionality,

• purpose limitation,

• consent,

• accountability,

• data security,

• rights of data access, correction and

erasure,

• Enforcement through economic sanctions

Page 33: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

GDPR compliance demands clear insight

on what personal data are managed,

where and how

33Luca Belli, PhD

Page 34: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

A challenge but also an opportunity:

updating data governance means more

insight on one’s data assets

34Luca Belli, PhD

Page 35: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

35Luca Belli, PhD

Brazil:

New general data protectionlegislation

law 13.709/2018

Largely based on GDPR

Page 36: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

36Luca Belli, PhD

Page 37: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

Both GDPR and the Brazilian law (LGPD) do

not apply to data that have been anonymised

37Luca Belli, PhD

Page 38: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

38Luca Belli, PhD

GDPR recital 26:

data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable

Page 39: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

39Luca Belli, PhD

GDPR Recital 26

This Regulation does nottherefore concern the processingof such anonymous information, including for statistical orresearch purposes.

Page 40: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

40Luca Belli, PhD

LPDP art 5.III

anonymised data: data relating to a data subject that can not be identified, considering the use of reasonable technical means available at the time of treatment

Page 41: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

41Luca Belli, PhD

LPDP art 7.

The processing of personal data mayonly be carried out in the followingcases: [...]IV to carry out studies by a research body, guaranteed, wheneverpossible, the anonymisation of personal data;

Page 42: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

42

Luca Belli, Molly Schwartz, Luiza Louzada. (2017)

Selling your soul while negotiating the conditions: from notice and consent to data control by design.

Health and Technology. Special Issue on Privacy and Security of Medical Data

tinyurl.com/BelliDataControl

Luca Belli, PhD

Page 43: Big Data and Personal Data Protection Challenges and ......Big Data and Personal Data Protection Challenges and Opportunities 11 September 2018 CIRET pre-Conference Workshop Luca Belli,

Thank you for yourattention!

Luca Belli, [email protected]

@1lucabelli

43Luca Belli, PhD