Feeds

When cookie spewers single you out, it IS personal, barks watchdog

Identifiers should be classed as 'personal data' – EU body

3 Big data security analytics techniques

Information that can lead to individuals being "singled out and treated differently" should generally be classed as "personal data", an EU privacy body has recommended.

The Article 29 Working Party has outlined changes (45-page/410KB PDF) to how it wants 'personal data' to be defined, and to what information the term should apply to, within the European Commission's proposed General Data Protection Regulation. The draft text was published in January.

Whether information is deemed to be "personal data" is a fundamental issue in relation to data protection laws because the framework of rules governing data protection issues only apply to information that qualifies as personal data.

The Working Party's plans to change how "personal data" is defined by altering the definition, in the Commission's draft text, for the term "data subject". The definition of "personal data" is dependent on how "data subject" is defined. Under the draft Regulation "personal data" is defined as "any information relating to a data subject".

The Working Party recommended that the term "data subject" refer to: "an identified natural person or a natural person who can be identified, directly or indirectly, or singled out and treated differently, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person."

The draft Regulation also contains "recitals" which, although themselves not legally binding, flesh out in more detail what is to be meant by the definitions and other terms contained in the text.

The Working Party said that organisations should generally have to treat "cookie identifiers" and "Internet Protocol addresses" as personal data, according to changes it wants to make to one of the draft recitals.

It wants one of the recitals to read: "When using online services, individuals may be associated with online identifiers provided by their devices, applications, tools and protocols, such as Internet Protocol addresses or cookie identifiers. This may leave traces which, combined with unique identifiers and other information received by the servers, may be used to create profiles of the individuals and identify or single them out. It follows that identification numbers, location data, online identifiers or other specific factors as such should as a rule be considered personal data."

The Working Party's proposals differ markedly from the tone of what has been proposed by the Commission. The same recital it had drafted stated that "identification numbers, location data, online identifiers or other specific factors as such need not necessarily be considered as personal data in all circumstances."

In its opinion the Working Party defended the "new and positive elements" that have been drafted into the proposed new Regulation on rules around "consent". Obtaining individuals' consent to the processing of their personal data is one way in which organisations can legitimately conduct such activities.

Under the draft Regulation organisations would be required to obtain a "freely given specific, informed and explicit indication" of individuals' wishes through either a "statement or by clear affirmative action" in order to be said to have obtained that person's consent to the processing of their personal data.

The Working Party said that although others had challenged how feasible it is to obtain "explicit" consent, imposing such a requirement was "necessary to truly enable data subjects to exercise their rights". This is especially the case "on the internet where there is now too much improper use of consent," it said, claiming that it would be "highly undesirable should this important clarification be deleted from the text".

Under the draft reforms the European Commission would be able to draft a series of "implementing" or "delegating" acts in order to provide more detail on the precise workings of some of the measures included in the Regulation text. The Working Party said, though, that it has "some reservations with regard to the extent the Commission would be empowered to adopt such acts".

It has suggested that, whilst some implementing or delegated acts may be justified for some aspects of the Regulation, it may be better for the body that is set to replace it following the reforms – the European Data Protection Board (EDPB) – to instead issue "guidelines" on how organisations should interpret those aspects of the legislative text.

The EDPB should be tasked with producing guidance that helps set out when organisations can claim to have an overriding "legitimate interest" in processing personal data, even where individuals have not consented to the activity, the Working Party suggested. Guidance on the issue, it said, would provide for "the necessary flexibility" and be instead of a "delegated act".

"It would seem more appropriate that the EDPB issues guidelines regarding in which circumstances the ground ‘legitimate interest’ can be invoked and how to assess whether such interests are overridden by the interests or fundamental rights and freedoms of the data subject, amongst others by providing concrete examples," the Working Party said.

A further example of guidance the EDPB could issue, the watchdog said, would be on what is meant by "safeguards" organisations would have to have in place, under the terms of the draft Regulation, in order to process sensitive personal information, such as individuals' health records.

"Since establishing what constitute appropriate safeguards can only be done on a case by case basis, it would be impossible to provide further guidance in a legally binding document," the Working Party said. "Therefore a more flexible instrument would be most appropriate to provide further guidance on what could be appropriate safeguards."

The privacy body said that "non-exhaustive examples" of the safeguards could also be written into one of the recitals of the Regulation, whilst the legislative text should also set out more detail on the circumstances in which it would be said to be legitimate to process sensitive personal data when that processing is in the public interest, it added.

This is the second time the Working Party has published its views on the Commission's proposed data protection reforms. EU ministers, business groups and regulators have been among those to raise concerns with aspects of what the Commission has drafted.

Copyright © 2012, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

High performance access to file storage

More from The Register

next story
Dropbox defends fantastically badly timed Condoleezza Rice appointment
'Nothing is going to change with Dr. Rice's appointment,' file sharer promises
Audio fans, prepare yourself for the Second Coming ... of Blu-ray
High Fidelity Pure Audio – is this what your ears have been waiting for?
Did a date calculation bug just cost hard-up Co-op Bank £110m?
And just when Brit banking org needs £400m to stay afloat
MtGox chief Karpelès refuses to come to US for g-men's grilling
Bitcoin baron says he needs another lawyer for FinCEN chat
Zucker punched: Google gobbles Facebook-wooed Titan Aerospace
Up, up and away in my beautiful balloon flying broadband-bot
Apple DOMINATES the Valley, rakes in more profit than Google, HP, Intel, Cisco COMBINED
Cook & Co. also pay more taxes than those four worthies PLUS eBay and Oracle
It may be ILLEGAL to run Heartbleed health checks – IT lawyer
Do the right thing, earn up to 10 years in clink
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.