Data-Related Legal, Ethical and Social Issues
Total Page:16
File Type:pdf, Size:1020Kb
Data-related legal, ethical and social issues Privacy & Data Protection (Cyber)-Security Breach-related obligations Supply of Digital Content & Free Flow of Data Intellectual Property Rights Services Data Sharing Obligations Data Ownership Data Sharing Agreements Anonymisation & Open Data Liability Pseudonymisation Trust, Surveillance, Discrimination Competition and Free Will Transparency, Consent, Control and Personal Data Ownership August 2019 Updated version Contents EU-funded projects 1 Foreword 2 Glossary 3 General Overview 6 Privacy and Data Protection 10 Anonymisation/ pseudonymisation 17 (Cyber-)security 24 Breach-related obligations 31 Supply of digital content 36 Free flow of data 40 Liability 46 Intellectual property rights 52 Open data 59 Sharing obligations 65 Data ownership 71 Data sharing agreements 77 Competition 84 Trust, Surveillance and Free Will 88 Discrimination 94 Transparency, Consent, Control and Personal Data Ownership 99 Looking beyond 105 EU-funded projects This publication was written in the context of the LeMO Project (www.lemo-h2020.eu). Certain chapters have also been based on the findings of the DEFeND, THREAT-ARREST and TOREADOR projects under the Horizon 2020 programme, of which Bird & Bird LLP is also a partner. The LeMO (Leveraging Big Data to Manage Transport Operations) project aims to provide recommendations on the prerequisites of effective big data implementation in the transport sector. Transport researchers and policy makers today face various challenges including legal and ethical ones as they work to build tomorrow's transportation systems. LeMO addresses these issues by investigating the implications of the use of big data to enhance the economic sustainability and competitiveness of the European transport sector. Grant agreement number 770038. The DEFeND (Data Governance for Supporting GDPR) project aims to deliver a unique organisational data privacy governance platform to empower organisations from different sectors to assess and comply with the General Data Protection Regulation. The project's main focus is on building a platform driven by market needs and based on a new paradigm called Model-Driven Privacy Governance. Grant agreement number 773701. The THREAT-ARREST (Cyber Security Threats and Threat Actors Training - Assurance Driven Multi-Layer, end-to-end Simulation and Training) project aims to develop an advanced training platform to adequately prepare stakeholders from different sectors in defending high-risk cyber systems and organisations to counter advanced, known and new cyber-attacks. The platform will deliver security training based on a model driven approach, incorporating among others emulation and simulation. Grant agreement number 786890. The TOREADOR project was set up bearing in mind that many companies and organisations in Europe have become aware of the potential competitive advantage they could get by timely and accurate Big Data analytics, but lack the IT expertise and budget to fully exploit that potential. To overcome this hurdle, TOREADOR provides a model-based big data analytics-as-a-service (MBDAaaS) approach, providing models of the entire Big Data analysis process and of its artefacts. Grant agreement number 688797. The above projects have received funding from the European Union’s Horizon 2020 research and innovation programme. The information given in this document concerning technical, legal or professional subject matter is for guidance only and does not constitute legal or professional advice. The content of this publication reflects only the authors’ views. The European Commission and Innovation and Networks Executive Agency (INEA) are not responsible for any use that may be made of the information it contains. EU-funded projects & 01 Foreword This publication presents the main legal, ethical and social issues predominantly relevant in an EU data- driven context. It is particularly pertinent in the context of big data, but the findings also apply to other disruptive technologies that heavily rely on data, such as the Internet of Things or Artificial Intelligence. In order to provide practical examples or to contextualise our theoretical observations, several illustrations related to the transport sector are included throughout this publication. The findings however apply to many other sectors. The issues related to data in the EU are constantly developing and will continue to evolve as the data economy remains at the centre of attention in the next EU legislature. Therefore, although the different Chapters of this publication are likely to require regular updates, they nonetheless aim to serve as a basis for further discussions on the 16 topics covered, with the ultimate aim of improving the general framework related to data. We would like to thank the other authors who have contributed to this publication, as well as Marie Thirot who coordinated its content and without whom this tremendous work would have been impossible. Julien Debussche Jasmien César Senior Associate Associate [email protected] [email protected] 02 & Foreword Glossary AI Artificial Intelligence AIS Automatic Identification System B2B Business-to-Business B2C Business-to-Consumer B2G Business-to-Government BMVI Bundesministerium für Verkehr und digitale Infrastruktur C-ITS Cooperative Intelligent Transport System CJEU Court of Justice of the European Union CMA UK's Competition & Market Authority Critical Council Directive 2008/114/EC of 8 December 2008 on the identification and Infrastructure designation of European critical infrastructures and the assessment of the need to Directive improve their protection CSIRT Computer Security Incident Response Team Data Breach Commission Regulation (EU) No 611/2013 of 24 June 2013 on the measures applicable Notification to the notification of personal data breaches under Directive 2002/58/EC of the Regulation European Parliament and of the Council on privacy and electronic communications DPIA Data Protection Impact Assessment Digital Content Directive (EU) 2019/770 of the European Parliament and of the Council of 20 May Directive 2019 on certain aspects concerning contracts for the supply of digital content and digital services [2019] OJ L 136/1 DSA Data Sharing Agreement DSM Directive Proposal for a Directive of the European Parliament and of the Council on copyright in the Digital Single Market DSP Digital Service Provider e-Commerce Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 Directive on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market EEA European Economic Area ENISA European Union Agency for Network and Information Security e-Privacy Directive Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector EU European Union Glossary & 03 EULF European Union Location Framework EU Charter EU Charter of Fundamental Rights FOT Field Operational Test Free Flow Regulation (EU) 2018/1807 of the European Parliament and of the Council of 14 Regulation November 2018 on a framework for the free flow of non-personal data in the European or the Regulation Union GDPR General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC [2016] OJ L 119/1) ICO Information Commissioner's Office IEC International Electrotechnical Commission INSPIRE Directive Directive 2007/2/EC of the European Parliament and of the Council of 14 March 2007 establishing an Infrastructure for Spatial Information in the European Community IoT Internet of Things ISO International Standards Organisation ITS Intelligent Transport System LINC Laboratoire d'Innovation Numérique de la CNIL MaaS Mobility as a Service NCA National Competent Authority NIS Directive Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union OES Operators of Essential Services PECS providers Publicly Available Electronic Communication Service Providers Platform-to- Proposal for a regulation of the European Parliament and of the Council on promoting Business fairness and transparency for business users of online intermediation services Regulation PSI Public Sector Information PSI Directive Directive 2003/98/EC of the European Parliament and of the Council of 17 November 2003 on the re-use of public sector information Recast Proposal Proposal for a directive of the European Parliament and of the Council on the re-use of public sector information RMI Repair and Maintenance Information Trade Secrets Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 Directive on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure 04 & Glossary Unfair Commercial Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 Practices Directive concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004