The new General Data Protection Regulation: Still a sound system for the protection of individuals?

被引:74
作者
de Hert, Paul [1 ,2 ]
Papakonstantinou, Vagelis [1 ]
机构
[1] Free Univ Brussels VUB LSTS, Brussels, Belgium
[2] Tilburg Univ Tilt, Tilburg, Netherlands
关键词
EU General Data Protection; Regulation; Controller-processor relationship; Internet of things; Individual consent; DPIAs; The right to be forgotten; Data portability; Personal data breach notifications;
D O I
10.1016/j.clsr.2016.02.006
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
The five-year wait is finally over; a few days before expiration of 2015 the "trilogue" that had started a few months earlier between the Commission, the Council and the Parliament suddenly bore fruit and the EU data protection reform package has finally been concluded. As planned since the beginning of this effort a Regulation, the General Data Protection Regulation is going to replace the 1995 Directive and a Directive, the Police and Criminal Justice Data Protection Directive, the 2008 Data Protection Framework Decision. In this way a long process that started as early as in 2009, peaked in early 2012, and required another three years to pass through the Parliament's and the Council's scrutiny is finished. Whether this reform package and its end-result is cause to celebrate or to lament depends on the perspective, the interests and the expectations of the beholder. Four years ago we published an article in this journal under the title "The proposed data protection Regulation replacing Directive 95/46/EC: A sound system for the protection of individuals". This paper essentially constitutes a continuation of that article: now that the General Data Protection Regulation's final provisions are at hand it is possible to present differences with the first draft prepared by the Commission, to discuss the issues raised through its law-making passage over the past few years, and to attempt to assess the effectiveness of its final provisions in relation to their declared purposes. (C) 2016 Paul de Hert, Vagelis Papakonstantinou. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:179 / 194
页数:16
相关论文
共 12 条
  • [1] [Anonymous], 2012, COMPUTER LAW SECURIT, V28
  • [2] [Anonymous], 2015, THE ECONOMIST
  • [3] [Anonymous], 2013, EJC NEWS JUL, V49
  • [4] Blume P, 2013, CAMBRIDGE YB EUROPEA, V1, P34
  • [5] Burton C, 2013, PVLR, V12, P99
  • [6] Gayrel C, 2015, ERA DAT PROT C 11 MA
  • [7] Hornung G, 2012, SCRIPTED, V9, P67
  • [8] Masing J, 2012, SUDDEUTSCHE ZEITUNG
  • [9] Papakonstantinou V, 2015, NEW J EUROPEAN CRIMI, V6
  • [10] The European data protection framework for the twenty-first century
    Reding, Viviane
    [J]. INTERNATIONAL DATA PRIVACY LAW, 2012, 2 (03) : 119 - 129