Feeds

When cookie spewers single you out, it IS personal, barks watchdog

Identifiers should be classed as 'personal data' – EU body

The essential guide to IT transformation

Information that can lead to individuals being "singled out and treated differently" should generally be classed as "personal data", an EU privacy body has recommended.

The Article 29 Working Party has outlined changes (45-page/410KB PDF) to how it wants 'personal data' to be defined, and to what information the term should apply to, within the European Commission's proposed General Data Protection Regulation. The draft text was published in January.

Whether information is deemed to be "personal data" is a fundamental issue in relation to data protection laws because the framework of rules governing data protection issues only apply to information that qualifies as personal data.

The Working Party's plans to change how "personal data" is defined by altering the definition, in the Commission's draft text, for the term "data subject". The definition of "personal data" is dependent on how "data subject" is defined. Under the draft Regulation "personal data" is defined as "any information relating to a data subject".

The Working Party recommended that the term "data subject" refer to: "an identified natural person or a natural person who can be identified, directly or indirectly, or singled out and treated differently, by means reasonably likely to be used by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person."

The draft Regulation also contains "recitals" which, although themselves not legally binding, flesh out in more detail what is to be meant by the definitions and other terms contained in the text.

The Working Party said that organisations should generally have to treat "cookie identifiers" and "Internet Protocol addresses" as personal data, according to changes it wants to make to one of the draft recitals.

It wants one of the recitals to read: "When using online services, individuals may be associated with online identifiers provided by their devices, applications, tools and protocols, such as Internet Protocol addresses or cookie identifiers. This may leave traces which, combined with unique identifiers and other information received by the servers, may be used to create profiles of the individuals and identify or single them out. It follows that identification numbers, location data, online identifiers or other specific factors as such should as a rule be considered personal data."

The Working Party's proposals differ markedly from the tone of what has been proposed by the Commission. The same recital it had drafted stated that "identification numbers, location data, online identifiers or other specific factors as such need not necessarily be considered as personal data in all circumstances."

In its opinion the Working Party defended the "new and positive elements" that have been drafted into the proposed new Regulation on rules around "consent". Obtaining individuals' consent to the processing of their personal data is one way in which organisations can legitimately conduct such activities.

Under the draft Regulation organisations would be required to obtain a "freely given specific, informed and explicit indication" of individuals' wishes through either a "statement or by clear affirmative action" in order to be said to have obtained that person's consent to the processing of their personal data.

The Working Party said that although others had challenged how feasible it is to obtain "explicit" consent, imposing such a requirement was "necessary to truly enable data subjects to exercise their rights". This is especially the case "on the internet where there is now too much improper use of consent," it said, claiming that it would be "highly undesirable should this important clarification be deleted from the text".

Under the draft reforms the European Commission would be able to draft a series of "implementing" or "delegating" acts in order to provide more detail on the precise workings of some of the measures included in the Regulation text. The Working Party said, though, that it has "some reservations with regard to the extent the Commission would be empowered to adopt such acts".

It has suggested that, whilst some implementing or delegated acts may be justified for some aspects of the Regulation, it may be better for the body that is set to replace it following the reforms – the European Data Protection Board (EDPB) – to instead issue "guidelines" on how organisations should interpret those aspects of the legislative text.

The EDPB should be tasked with producing guidance that helps set out when organisations can claim to have an overriding "legitimate interest" in processing personal data, even where individuals have not consented to the activity, the Working Party suggested. Guidance on the issue, it said, would provide for "the necessary flexibility" and be instead of a "delegated act".

"It would seem more appropriate that the EDPB issues guidelines regarding in which circumstances the ground ‘legitimate interest’ can be invoked and how to assess whether such interests are overridden by the interests or fundamental rights and freedoms of the data subject, amongst others by providing concrete examples," the Working Party said.

A further example of guidance the EDPB could issue, the watchdog said, would be on what is meant by "safeguards" organisations would have to have in place, under the terms of the draft Regulation, in order to process sensitive personal information, such as individuals' health records.

"Since establishing what constitute appropriate safeguards can only be done on a case by case basis, it would be impossible to provide further guidance in a legally binding document," the Working Party said. "Therefore a more flexible instrument would be most appropriate to provide further guidance on what could be appropriate safeguards."

The privacy body said that "non-exhaustive examples" of the safeguards could also be written into one of the recitals of the Regulation, whilst the legislative text should also set out more detail on the circumstances in which it would be said to be legitimate to process sensitive personal data when that processing is in the public interest, it added.

This is the second time the Working Party has published its views on the Commission's proposed data protection reforms. EU ministers, business groups and regulators have been among those to raise concerns with aspects of what the Commission has drafted.

Copyright © 2012, Out-Law.com

Out-Law.com is part of international law firm Pinsent Masons.

The essential guide to IT transformation

More from The Register

next story
6 Obvious Reasons Why Facebook Will Ban This Article (Thank God)
Clampdown on clickbait ... and El Reg is OK with this
Banking apps: Handy, can grab all your money... and RIDDLED with coding flaws
Yep, that one place you'd hoped you wouldn't find 'em
No, thank you. I will not code for the Caliphate
Some assignments, even the Bongster decline must
Barnes & Noble: Swallow a Samsung Nook tablet, please ... pretty please
Novelslab finally on sale with ($199 - $20) price tag
Ballmer leaves Microsoft board to spend more time with his b-balls
From Clippy to Clippers: Hi, I see you're running an NBA team now ...
Video of US journalist 'beheading' pulled from social media
Yanked footage featured British-accented attacker and US journo James Foley
Primetime precrime? Minority Report TV series 'being developed'
I have to know. I have to find out what happened to my life
Broadband slow and expensive? Blame Telstra says CloudFlare
Won't peer, will gouge for Internet transit
Netflix swallows yet another bitter pill, inks peering deal with TWC
Net neutrality crusader once again pays up for priority access
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?