Pseudonymization and impacts of Big (personal/anonymous) Data processing in the transition from the Directive 95/46/EC to the new EU General Data Protection Regulation

被引:35
|
作者
Bolognini, Luca [1 ]
Bistolfi, Camilla [1 ]
机构
[1] Italian Inst Privacy & Data Valorizat, Rome, Italy
基金
欧盟地平线“2020”;
关键词
Pseudonymization; Big Data; General analysis; GDPR; Profiling; Impacts; Accountability;
D O I
10.1016/j.clsr.2016.11.002
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
In order to carry out the so-called "Big Data analysis", the collection of personal data seems to be inevitable. The opportunities arising from the analysis of such information need to be balanced with the risks for the data protection of individuals. In this sense, the anonymization technique might be a solution, but it seems to be inappropriate in certain circumstances, among which Big Data processing can be included. In fact, anonymization has a high degree of uncontrollability of the impacts of profiling directed to individual targets whose data has been anonymized. In this sense, pseudonymization can be used both to reduce the risks of reidentification and help data controllers and processors to respect their personal data protection obligations by keeping control over their activities. On the one hand, pseudonymization ensures the capability to reconstruct the processes of identity masking, by allowing re-identification. On the other hand the accountability of the data controller and data processor is guaranteed, thanks to the fact that there will always be a person who can re-identify subjects included in a cluster, acting as a "data keeper". (C) 2016 Luca Bolognini and Camilla Bistolfi. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:171 / 181
页数:11
相关论文
共 41 条