Data Protection: ITRE Opinion : Différence entre versions
(→Consent) |
(→Pseudonymous data) |
||
Ligne 41 : | Ligne 41 : | ||
**(a) the data subject has given consent to the processing of their personal data for one or more specific purposes; | **(a) the data subject has given consent to the processing of their personal data for one or more specific purposes; | ||
**... | **... | ||
− | (fa) processing is limited to pseudonymised data, where the data subject is adequately protected and the recipient of the service is given a right to object pursuant to Article 19 (3a). | + | **(fa) processing is limited to pseudonymised data, where the data subject is adequately protected and the recipient of the service is given a right to object pursuant to Article 19 (3a). |
}} | }} | ||
Version du 3 avril 2013 à 15:35
ITRE is the European Parliament committee on Industry, Research and Energy issues.
On 20 February 2013, it issued an opinion on the Proposal for a Data Protection Regulation aimed to assist LIBE committee in the drafting of its own report.
You can find a detailed list of its members on Memopol or visit its official website.
Its opinion proposes many amendment which would severely weaken personal data protection.
This page lists and analyses the most dangerous of them.
Sommaire
- 1 Consent
- 2 Pseudonymous data
- 3 Purpose limitation
- 4 Data subjects' rights
- 4.1 Amendment 134
- 4.2 Amendment 146
- 4.3 Amentdment 162
- 4.4 Amendment 166
- 4.5 Amendment 181
- 4.6 Amendment 182
- 4.7 Amendment 184
- 4.8 Amendment 185
- 4.9 Amendment 190
- 4.10 Amendment 193
- 4.11 Amendment 221
- 4.12 Amendment 240
- 4.13 Amendment 245
- 4.14 Amendment 251
- 4.15 Amendment 255
- 4.16 Amendment 256
- 4.17 Amendment 323
- 4.18 Amendment 327
- 4.19 Amendment 360
- 4.20 Amendment 362
- 4.21 Amendment 366
- 4.22 Amendment 370
Consent
Amendment 82
- (8) ‘the data subject's consent’ means any freely given specific, informed and
explicitunambiguous indication of his or her wishes by which the data subject, either by a statement or by a clear affirmative action,signifies agreement to personal data relating to them being processed. Silence or inactivity does not in itself indicate consent ;
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
If the required consent must not be explicit, data subjects might give it by a 'passive action' - by not opposing to the process of their data. This amendment only proposes that consent must be 'unambiguous': that mere 'silence or inactivity does not in itself indicate consent' but does when occurring in a specific context - when data subjects can understand the consequences of their silence or inactivity.
That is the current state of the law. And it has showed not to fit anymore the information society at all. Users are loosing trust in Internet services as many websites are collecting their personal data without explicitly warn them about it. They are only stating they collect such data on a distant page of their site and it is not enough at all to regain users' trust: users must have entire control on the processing of their own data.
Pseudonymous data
Amendment 77
- (2a) 'pseudonymous data' means any personal data that has been collected, altered or otherwise processed so that it of itself cannot be attributed to a data subject without the use of additional data which is subject to separate and distinct technical and organisational controls to ensure such non attribution;
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 101
- 1. Processing of personal data shall be lawful only if and to the extent that at least one of the following applies:
- (a) the data subject has given consent to the processing of their personal data for one or more specific purposes;
- ...
- (fa) processing is limited to pseudonymised data, where the data subject is adequately protected and the recipient of the service is given a right to object pursuant to Article 19 (3a).
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
These two amendments provide that data which are not directly collected or processed together with the data subject's name may be collected or processed without the data subject's consent, even though these data are tied to an unique identifier - which may be linked to the data subject's name in another dataset - or may otherwise be easilly linked back to the data subject, as sudies on recent re-identification advances show.
Purpose limitation
Amendment 95
- 1.Processing of personal data shall be lawful only if and to the extent that at least one
of the following applies:
- (a) the data subject has given consent to the processing of their personal data
for one or more specific purposes;
- (a) the data subject has given consent to the processing of their personal data
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
The initial Proposal provided that consent must be given for each processing's purpose. Thus, data subjects might exactly control where their data will go and what for. This amendment proposes that users give their consent once for all, no matter the purpose for which or the number of time their data will be processed. Once users have give their consent, controllers are free to collect, process and transfer any personal data to any ends. Data subjects would only be informed of these processing and might object to them afterwards.
Amendment 100
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 102
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 110
- 4. Where the purpose of further processing is not compatible with the one for which the personal data have been collected, the processing must have a legal basis at least in one of the grounds referred to in points (a) to
(e)(f) of paragraph 1. This shall in particular apply to any change of terms and general conditions of a contract.
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Data subjects' rights
Amendment 134
- 4. The information and the actions taken on requests referred to in paragraph 1 shall be free of charge. Where requests are manifestly excessive, in particular
because ofowing to their high volume, complexity or their repetitive character, the controller may chargeaan appropriate, not for profit, fee for providing the information or taking the action requested, or the controller maynotdecline to take the action requested. In that case, the controller shall bear the burden of proving the manifestly excessive character of the request.
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
This amendment would allow controllers to charge users who would ask information on their personal data - what of their data are processed, for what purpose, who can access to them and for how long will they be stored ? -, who would ask for the rectification or the erasure of these data or who would object to their processing where these requests would be 'excessively complex'. Thus, whenever controllers would decide that it would be too complex for them, users would have to pay to know and control who knows what about them.
Amendment 146
5.
(da) the data originates from publicly available sourceslawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amentdment 162
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 166
3.
(ea) for prevention or detection of fraud, confirming identity, and/or determining creditworthiness, or ability to pay.lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 181
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 182
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 184
2.
(aa) is based on pseudonymous data;lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 185
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 190
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 193
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 221
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 240
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 245
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 251
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 255
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 256
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Justification: Procedures requiring prior authorisation are costly and time-consuming for the controller, and their added value compared to a system of prior notification can be questioned from the point of view of data protection. Prior notifications, which would give the supervising authority the possibility to react and act, is sufficient and also provides for a user-friendly data protection procedure.
Amendment 323
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 327
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 360
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude> Justif: Minimum funding and a representative membership structure are necessary in order to guarantee that collective actions are not misused and avoid a situation where associations are set up specifically for this purpose, as well as to ensure minimum cover for lawyers' fees and court costs.
Amendment 362
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 366
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
Amendment 370
lawbox|title=Amendment 100|rate=-|1=Vive la liberté d'expression !|2=Vive la liberté d'expression ! d'entreprise
Modèle en boucle détecté : Modèle:Lawbox</noinclude>
370-397 delete 3.-6.