{"title":"Algorithmic impact assessments under the GDPR: producing multi-layered explanations","authors":"Kaminski M, Malgieri G.","doi":"10.1093/idpl/ipaa020","DOIUrl":"https://doi.org/10.1093/idpl/ipaa020","url":null,"abstract":"<span><div><div>Key Points</div><ul><li>Policymakers, scholars, and commentators are increasingly concerned with the risks of using algorithms for profiling and automated decision-making.</li><li>This article addresses how a Data Protection Impact Assessment (DPIA), applied as an algorithmic impact assessment (AIA), links the two faces of the General Data Protection Regulation (GDPR) approach to algorithmic accountability: individual rights and systemic governance.</li><li>We propose that AIAs simultaneously provide systemic governance of algorithmic decision-making and serve as an important ‘suitable safeguard’ (Article 22) of individual rights.</li><li>As a nexus between the GDPR’s two approaches to algorithmic accountability, DPIAs have a heretofore unexplored link to individual transparency rights.</li><li>Our examination of DPIAs suggests that the current focus on the right to explanation is far too narrow. We call, instead, for data controllers to consciously use the mandatory DPIA process to produce what we call ‘multi-layered explanations’ of algorithmic systems.</li><li>This concept of multi-layered explanations not only more accurately describes what the GDPR is attempting to do, but also normatively fills potential gaps between the GDPR’s two approaches to algorithmic accountability.</li></ul></div></span>","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"1 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-12-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"138517015","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Autonomous transport vehicles versus the principles of data protection law: is compatibility really an impossibility?","authors":"E. Salami","doi":"10.1093/idpl/ipaa017","DOIUrl":"https://doi.org/10.1093/idpl/ipaa017","url":null,"abstract":"","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"107 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-11-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"86783681","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"The right to compensation of a competitor for a violation of the GDPR","authors":"Tim F Walree, P.T.J. Wolters","doi":"10.1093/idpl/ipaa018","DOIUrl":"https://doi.org/10.1093/idpl/ipaa018","url":null,"abstract":"","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"79 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"78132884","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
H. Janssen, Jennifer Cobbe, Chris Norval, Jatinder Singh
{"title":"Decentralized data processing: personal data stores and the GDPR","authors":"H. Janssen, Jennifer Cobbe, Chris Norval, Jatinder Singh","doi":"10.1093/idpl/ipaa016","DOIUrl":"https://doi.org/10.1093/idpl/ipaa016","url":null,"abstract":"Online services are driven by data; functionality and value are derived from its processing. However, individuals generally have little visibility—let alone control— over what, how, why, and by whom their data are captured, analysed, transferred, stored, or otherwise used. In response to this, and to the growing public discourse regarding data-related issues, there is considerable focus by the computer science and engineering communities on developing privacy-enhancing technologies (PETs), ie technical tools and measures that can assist in addressing privacy concerns. Personal data stores (PDSs) are one such technology, which aims to tackle Key Points","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"57 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"80092110","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Who is responsible for data processing in smart homes? Reconsidering joint controllership and the household exemption","authors":"Jiahong Chen, Lilian Edwards, Lachlan Urquhart, Derek McAuley","doi":"10.1093/idpl/ipaa011","DOIUrl":"https://doi.org/10.1093/idpl/ipaa011","url":null,"abstract":"The growing industrial and research interest in protecting privacy and fighting cyberattacks for smart homes has sparked various innovations in security- and privacy-enhancing technologies (S/PETs) powered by edge computing. The complex technical set-up has however raised a whole series of legal issues surrounding the regulation of smart home with data protection law. To determine how responsibility and accountability should be fairly assumed by stakeholders, there is a pressing need to first clarify the roles of these parties within the existing data protection data protection legal framework. This article focuses on two legal concepts under the GDPR as the mechanisms to (dis)assign responsibilities to various categories of entities in a domestic IoT context: joint controllership and the household exemption. A close examination of the relevant provisions and case-law shows a widening notion of joint controllership and a narrowing scope for the household exemption. While this interpretative approach may prevent evasion of accountability in specific cases, it may lead to the unintended consequence of imposing disproportionate compliance burdens on developers, contributors, and users of smart home safety technologies. By discouraging users to adopt S/PETs, data protection law may likely lead to a lower level of privacy and security protection. The differential responsibilities among joint controllers as envisaged in case-law may reconcile the tensions to some degree, but certain limitations remain. The regulatory dilemma in this regard highlights some underlying assumptions of data protection law that are no longer valid with regard to a smart home, and thus calls for further conceptual and empirical studies on fair reassignment of responsibility and accountability in a domestic IoT setting.","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":" 71","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-09-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"138494454","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Brendan Van Alsenoy, Data Protection Law in the EU: Roles, Responsibilities and Liability","authors":"Dimitra Kamarinou","doi":"10.1093/idpl/ipaa014","DOIUrl":"https://doi.org/10.1093/idpl/ipaa014","url":null,"abstract":"","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"8 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-08-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"87322889","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"The normative power of the EU: a case study of data protection laws of Turkey","authors":"B. Gur","doi":"10.1093/idpl/ipaa013","DOIUrl":"https://doi.org/10.1093/idpl/ipaa013","url":null,"abstract":"","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"85 9 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-08-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"83446745","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"How to de-identify personal data in South Korea: an evolutionary tale","authors":"Haksoo Ko","doi":"10.1093/idpl/ipaa015","DOIUrl":"https://doi.org/10.1093/idpl/ipaa015","url":null,"abstract":"In early 2020, South Korea’s legislature made amendments to major laws in the area of data protection in order to, among others, promote the utilization of pseudonymised personal data. With these amendments, pseudonymised personal data can be processed, without consent from data subjects, for archiving purposes, scientific research purposes, or statistical purposes. Arguably, these amendments are largely inspired by the relevant provisions contained in the EU GDPR, although details differ between GDPR and South Korea’s amended statutes. One unique aspect of South Korea’s amended statutes is that they introduce a scheme under which designated agencies carry out the task of combining pseudonymised data that different entities possess.","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"8 1","pages":""},"PeriodicalIF":2.1,"publicationDate":"2020-08-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"80530073","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Mere access to personal data: is it processing?","authors":"A. Schreiber","doi":"10.1093/idpl/ipaa005","DOIUrl":"https://doi.org/10.1093/idpl/ipaa005","url":null,"abstract":"","PeriodicalId":51749,"journal":{"name":"International Data Privacy Law","volume":"113 1","pages":"269-277"},"PeriodicalIF":2.1,"publicationDate":"2020-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"84900166","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"社会学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}