Feeds

Hasty legislation will make a mess of Europe's 'right to be forgotten'

The ethics of online deletion

Maximizing your infrastructure through virtualization

Opinion The European Commission proposal to include a 'right to be forgotten' in data protection laws risks causing legal, technical and ethical mayhem if it is not thought through more thoroughly.

While it might seem like a good idea to give people the right to force organisations to delete their personal data, legislators should stop and think very carefully about the implications of such a rule for free speech, other people's rights and the nature of recorded fact.

The Commission is reviewing data protection legislation in a welcome update to 15-year-old laws. It plans to put forward new legislation in 2011, according to last week's 20-page paper (106KB PDF).

A Commission FAQ about the process said that individuals should have more control over their own data. "They need to know what their rights are if they want to access, rectify or delete their data," it said.

"For example, there should be a 'right to be forgotten,' which means that individuals should have the right to have their data fully removed when it is no longer needed for the purposes for which it was collected," said the FAQ. "People who want to delete profiles on social networking sites should be able to rely on the service provider to remove personal data, such as photos, completely."

You might think that you should have the right to erase that photo of yourself in that Barney Rubble costume from Facebook forever. And you might be right. But what about the right of your proud friend in the Wilma costume to have his picture displayed?

If a student who marched in London this week to protest against the raise in university tuition fees decides that they do not want to appear in photographs of it, can they insist that their face be blurred in pictures on Facebook? What about in newspapers?

There are two kinds of rights at stake here. One is the right of other individuals to have material continue to exist. If you want something deleted – a picture, an account of an event – that includes other people in any way, you are dealing with conflicting rights. Whose should win out?

The other kind of right is that of society to know what has happened. There was a protest march this week and thousands of students participated. This is important, it is part of the fabric of the nation's life. If all of those people were able to delete themselves from records of that event then how can we know in the future that it happened?

Society must have a right to record history, and history is made up of material depicting or describing individuals. Its distortion is nothing new: as Winston Churchill observed, history is written by the victors. But the information age should make it harder to lose objective records. Politicians should be careful if they pass laws that might undermine that.

Not all 'right to be forgotten' laws need to go that far, though, and some already exist.

At the restrictive end of the spectrum are laws in Germany and Switzerland. The German law was used to obtain a ruling from a German court to erase the name of a convicted killer from Wikipedia. Unsurprisingly, free speech advocates cried foul.

The Swiss law was used successfully in a claim against Journal de Genève after the Swiss newspaper reported that the subject of a current story had a past conviction for bank robbery. Even if informing the public of a criminal's past was newsworthy, the court said, naming him was not, and it interfered with the rehabilitation of convicts. (I recommend reading Professor Franz Werro's comparison of Switzerland's right to be forgotten and America's right to inform.)

The Swiss model suggests a right to be forgotten, or a right to delete, can go beyond the protection of privacy, though that rather depends on how you define privacy. The right can be used to censor information that was lawfully made public and, in effect, change someone's record in history.

Application security programs and practises

More from The Register

next story
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
US Social Security 'wasted $300 million on an IT BOONDOGGLE'
Scrutiny committee bods probe derailed database project
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
Australia floats website blocks and ISP liability to stop copyright thieves
Big Content could get the right to order ISPs to stop traffic
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.