Feeds

When cookie spewers single you out, it IS personal, barks watchdog

Identifiers should be classed as 'personal data' – EU body

The Essential Guide to IT Transformation

Information that can lead to individuals being "singled out and treated differently" should generally be classed as "personal data", an EU privacy body has recommended.

The Article 29 Working Party has outlined changes (45-page/410KB PDF) to how it wants 'personal data' to be defined, and to what information the term should apply to, within the European Commission's proposed General Data Protection Regulation. The draft text was published in January.

Whether information is deemed to be "personal data" is a fundamental issue in relation to data protection laws because the framework of rules governing data protection issues only apply to information that qualifies as personal data.

The Working Party's plans to change how "personal data" is defined by altering the definition, in the Commission's draft text, for the term "data subject". The definition of "personal data" is dependent on how "data subject" is defined. Under the draft Regulation "personal data" is defined as "any information relating to a data subject".

The Working Party recommended that the term "data subject" refer to: "an identified natural person or a natural person who can be identified, directly or indirectly, or singled out and treated differently, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person."

The draft Regulation also contains "recitals" which, although themselves not legally binding, flesh out in more detail what is to be meant by the definitions and other terms contained in the text.

The Working Party said that organisations should generally have to treat "cookie identifiers" and "Internet Protocol addresses" as personal data, according to changes it wants to make to one of the draft recitals.

It wants one of the recitals to read: "When using online services, individuals may be associated with online identifiers provided by their devices, applications, tools and protocols, such as Internet Protocol addresses or cookie identifiers. This may leave traces which, combined with unique identifiers and other information received by the servers, may be used to create profiles of the individuals and identify or single them out. It follows that identification numbers, location data, online identifiers or other specific factors as such should as a rule be considered personal data."

The Working Party's proposals differ markedly from the tone of what has been proposed by the Commission. The same recital it had drafted stated that "identification numbers, location data, online identifiers or other specific factors as such need not necessarily be considered as personal data in all circumstances."

In its opinion the Working Party defended the "new and positive elements" that have been drafted into the proposed new Regulation on rules around "consent". Obtaining individuals' consent to the processing of their personal data is one way in which organisations can legitimately conduct such activities.

Under the draft Regulation organisations would be required to obtain a "freely given specific, informed and explicit indication" of individuals' wishes through either a "statement or by clear affirmative action" in order to be said to have obtained that person's consent to the processing of their personal data.

The Working Party said that although others had challenged how feasible it is to obtain "explicit" consent, imposing such a requirement was "necessary to truly enable data subjects to exercise their rights". This is especially the case "on the internet where there is now too much improper use of consent," it said, claiming that it would be "highly undesirable should this important clarification be deleted from the text".

Under the draft reforms the European Commission would be able to draft a series of "implementing" or "delegating" acts in order to provide more detail on the precise workings of some of the measures included in the Regulation text. The Working Party said, though, that it has "some reservations with regard to the extent the Commission would be empowered to adopt such acts".

It has suggested that, whilst some implementing or delegated acts may be justified for some aspects of the Regulation, it may be better for the body that is set to replace it following the reforms – the European Data Protection Board (EDPB) – to instead issue "guidelines" on how organisations should interpret those aspects of the legislative text.

The EDPB should be tasked with producing guidance that helps set out when organisations can claim to have an overriding "legitimate interest" in processing personal data, even where individuals have not consented to the activity, the Working Party suggested. Guidance on the issue, it said, would provide for "the necessary flexibility" and be instead of a "delegated act".

"It would seem more appropriate that the EDPB issues guidelines regarding in which circumstances the ground ‘legitimate interest’ can be invoked and how to assess whether such interests are overridden by the interests or fundamental rights and freedoms of the data subject, amongst others by providing concrete examples," the Working Party said.

A further example of guidance the EDPB could issue, the watchdog said, would be on what is meant by "safeguards" organisations would have to have in place, under the terms of the draft Regulation, in order to process sensitive personal information, such as individuals' health records.

"Since establishing what constitute appropriate safeguards can only be done on a case by case basis, it would be impossible to provide further guidance in a legally binding document," the Working Party said. "Therefore a more flexible instrument would be most appropriate to provide further guidance on what could be appropriate safeguards."

The privacy body said that "non-exhaustive examples" of the safeguards could also be written into one of the recitals of the Regulation, whilst the legislative text should also set out more detail on the circumstances in which it would be said to be legitimate to process sensitive personal data when that processing is in the public interest, it added.

This is the second time the Working Party has published its views on the Commission's proposed data protection reforms. EU ministers, business groups and regulators have been among those to raise concerns with aspects of what the Commission has drafted.

Copyright © 2012, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

Build a business case: developing custom apps

More from The Register

next story
iPad? More like iFAD: We reveal why Apple fell into IBM's arms
But never fear fanbois, you're still lapping up iPhones, Macs
Sonos AXES support for Apple's iOS4 and 5
Want to use your iThing? You can't - it's too old
Philip K Dick 'Nazi alternate reality' story to be made into TV series
Amazon Studios, Ridley Scott firm to produce The Man in the High Castle
Too many IT conferences to cover? MICROSOFT to the RESCUE!
Yet more word of cuts emerges from Redmond
Joe Average isn't worth $10 a year to Mark Zuckerberg
The Social Network deflates the PC resurgence with mobile-only usage prediction
Chips are down at Broadcom: Thousands of workers laid off
Cellphone baseband device biz shuttered
Feel free to BONK on the TUBE, says Transport for London
Plus: Almost NOBODY uses pay-by-bonk on buses - Visa
Amazon says Hachette should lower ebook prices, pay authors more
Oh yeah ... and a 30% cut for Amazon to seal the deal
Twitch rich as Google flicks $1bn hitch switch, claims snitch
Gameplay streaming biz and search king refuse to deny fresh gobble rumors
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.