The Difficulty of Defining Sensitive Data-The Concept of Sensitive Data in the EU Data Protection Framework

被引:17
|
作者
Quinn, Paul [1 ]
机构
[1] Vrije Univ Brussel, Law Sci Technol & Soc, Brussels, Belgium
来源
GERMAN LAW JOURNAL | 2021年 / 22卷 / 08期
关键词
Sensitive Data; Data Protection; GDPR; Privacy; Health Data; BIG DATA; GENETIC DATA; HEALTH DATA; CONSENT; CHALLENGES; GENOMICS; PRIVACY; LAW;
D O I
10.1017/glj.2021.79
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
The concept of sensitive data has been a mainstay of data protection for a number of decades. The concept itself is used to denote several categories of data for which processing is deemed to pose a higher risk for data subjects than other forms of data. Such risks are often perceived in terms of an elevated probability of discrimination, or related harms, to vulnerable groups in society. As a result, data protection frameworks have traditionally foreseen a higher burden for the processing of sensitive data than other forms of data. The sui generis protection of sensitive data-stronger than the protection of non-sensitive personal data-can also seemingly be a necessity from a fundamental rights-based perspective, as indicated by human rights jurisprudence. This Article seeks to analyze the continued relevance of sensitive data in both contemporary and potential future contexts. Such an exercise is important for two main reasons. First, the legal regime responsible for the regulation of the use of personal data has evolved considerably since the concept of sensitive data was first used. This has been exemplified by the creation of the EU's General Data Protection Regulation (GDPR) in Europe. It has introduced a number of requirements relating to sensitive data that are likely to represent added burdens for controllers who want to process personal data. Second, the very nature of personal data is changing. Increases in computing power, more complex algorithms, and the availability of ever more potentially complimentary data online mean that more and more data can be considered of a sensitive nature. This creates various risks going forward, including an inflation effect whereby the concept loses its value, as well as the possibility that data controllers may increasingly seek to circumvent compliance with the requirements placed upon the use of sensitive data. This Article analyzes how such developments are likely to influence the concept of sensitive data and, in particular, its ability to protect vulnerable groups from harm. The authors propose a possible interpretative solution: A hybrid approach where a purpose-based definition acquires a bigger role in deciding whether data is sensitive, combined with a context-based 'backstop' based on reasonable foreseeability.
引用
收藏
页码:1583 / 1612
页数:30
相关论文
共 50 条
  • [21] Corralling sensitive data in the WildWest: supporting research with highly sensitive data
    Christopher, Jason
    Fernsler, Karen
    Hoffman, Christopher R.
    Locanas, Joleen
    Lutz, Ken
    Neeser, Amy
    Robb, George, III
    Yashar, Mark
    [J]. PRACTICE AND EXPERIENCE IN ADVANCED RESEARCH COMPUTING 2022, 2022,
  • [22] Partitioned Data Security on Outsourced Sensitive and Non-sensitive Data
    Mehrotra, Sharad
    Sharma, Shantanu
    Ullman, Jeffrey D.
    Mishra, Anurag
    [J]. 2019 IEEE 35TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2019), 2019, : 650 - 661
  • [23] Data protection and the use of biometric data in the EU
    Sprokkereef, Annemarie
    [J]. FUTURE OF IDENTITY IN THE INFORMATION SOCIETY, 2008, : 277 - 284
  • [24] Using e-government services and ensuring the protection of sensitive data in EU member countries
    Zakrzewska, Malogrzata
    Miciula, Ireneusz
    [J]. KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS (KSE 2021), 2021, 192 : 3457 - 3466
  • [25] Masking sensitive data
    Network Security, United States
    [J]. Netw. Secur., 10 (17-20):
  • [26] Dissemination Of Sensitive Data
    Susan, K. Bindu
    Babu, M. Raja
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (07): : 67 - 71
  • [27] Aggregation for Sensitive Data
    Bhowmik, Avradeep
    Ghosh, Joydeep
    Koyejo, Oluwasanmi
    [J]. 2019 13TH INTERNATIONAL CONFERENCE ON SAMPLING THEORY AND APPLICATIONS (SAMPTA), 2019,
  • [28] A machine learning framework for providing data integrity and confidentiality for sensitive data cloud applications
    Narayanan, Eswara
    Muthukumar, B.
    [J]. INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2022,
  • [29] A Data Hiding Approach for Sensitive Smartphone Data
    Luo, Chu
    Fylakis, Angelos
    Partala, Juha
    Klakegg, Simon
    Goncalves, Jorge
    Liang, Kaitai
    Seppanen, Tapio
    Kostakos, Vassilis
    [J]. UBICOMP'16: PROCEEDINGS OF THE 2016 ACM INTERNATIONAL JOINT CONFERENCE ON PERVASIVE AND UBIQUITOUS COMPUTING, 2016, : 557 - 568
  • [30] Sensitive Cloud Data Deduplication with Data Dynamics
    Wang, Yan
    Liu, Ying
    Li, Chaoling
    [J]. MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 6236 - 6240