European Data Protection Law Review · 2018 · 60 citations · 0 references
EngineeringInformation SecurityData-centric SecurityLawTechnology LawDpbdf ObligationsCompliance (Mechanical Engineering)Data SafetyData ScienceManagementData IntegrationData GovernanceDisclosureData ManagementPersonal DataPrivacy CompliancePublic PolicyFirst Glance DpbdfCompliance (Corporate Governance)Data PrivacyComputer ScienceData SecurityCryptographyEncryptionDpbdf PrinciplesAuthorization ModelsData PortabilityRegulationData Protection
The paper examines the principles of Data Protection by Design and Default as introduced in the GDPR. The study seeks to identify the elements of DPbD and DPbDf obligations under Article 25 of the GDPR, interpret and apply them in practice, and clarify ambiguous wording by translating these provisions into high‑level non‑functional design requirements. The authors build on existing knowledge of each element and the broader context of their negotiation, translating the provisions into high‑level non‑functional design requirements. The authors argue that DPbDf, though often associated with data minimisation and purpose limitation, also applies to retention, confidentiality, and accessibility, and that compliance with DPbD and DPbDf is central to GDPR compliance.
In this contribution we examine the principles of Data Protection by Design and Data Protection by Default (DPbD and DPbDf) as introduced in the General Data Protection Regulation 2016/679 (GDPR). In particular, we seek answering these questions: ‘what are the elements of DPbD and DPbDf obligations under the Article 25 of the GDPR and how could they be interpreted and applied in practice’? By reflecting on elements embedded in these two concepts we aim at contributing to the ongoing debate on the implementation of these principles and conquering the opinion that DPbD and DPbDf contain ambiguous wording and confusing legalese that cannot be digested. Considering high stakes of being GDPR (in)compliant, we focus on the translation of the two legal provisions into high-level non-functional design requirements. We build on the existing knowledge about each element and also take into account a wider context in which such obligations were negotiated and introduced. We argue that while at first glance DPbDf is mainly linked to the data minimisation and purpose limitation principles, it is also equally relevant for the principles of data retention, confidentiality and accessibility. We suggest that the entire weight of the GDPR rests on the ‘shoulders’ of Article 25 and that, theoretically at least, complying with the DPbD and DPbDf principles is the key for the GDPR compliance.