The possibilities that information-processing technologies offer in terms of speed,
ease and quantity of data processing intensify the potential harm caused by its
unauthorized use. These possibilities have caused alarm in relation to certain types
of data, leading several countries to react through the enactment of specific legislation or, whenever specific legislation is absent, giving rise to significant, and often
controversial, case law. Personal data has been in the center of these concerns.
It isn’t possible to address in detail all topics related to personal data processed by
electronic means, as there are countless relevant ones in this regard. The exact
configuration of the right to be forgotten in the electronic context, the process for
obtaining a valid consent for personal data processing online, the operation of the
information right by electronic means, the meaning of the “privacy by design” and
the “privacy by default” concepts in this same context, profiling and portability, are
just some of those topics. Some decisions had to be taken in order to select the topics
which are addressed in more detail. The selected topics are, thus, those with a wider
scope, which comprise many of the other topics,
52 as well as those which have been
in the spotlight of important case law or new legislation. In this regard, topics such as
portability or profiling aren’t dealt with, autonomously, in a separate section.
Some brief lines should be dedicated, though, to the challenge of data portability
and its potential impact in the economy and in the protection of the data subjects.
Data portability grants the data subject a right to have the personal data transmitted
directly to him or to another entity, through electronic means. Data portability,
inasmuch as it requires the adoption of technical standards to ensure interoperability
between the different entities that process those data, promotes the free movement of
personal data and, consequently, works as an inducement or a driving force to the
economy. The easiness of personal data transfer may promote competition, improving innovation and service variety. Although there is sectorial legislation granting
data portability, dating back from the 1990s,
53 the general right to data portability
provided by the GDPR, which is applicable in all contexts, with minor exceptions, is
noteworthy.
54
Also noteworthy are the GDPR provisions on profiling. The ability to build a very
complete psychological profile of the data subject has been made possible by current
technologies,
55 and the possibilities keep evolving. Taking into account the particular risks posed to the data subjects by profiling, some legal systems have adopted
specific rules to deal with these risks. Swiss law is one of those legal systems, since it
requires the controller to conduct an impact assessment in case of profiling, given the
fact that this form of data processing may pose a threat to the data subject’s
privacy.
56 The GDPR also addresses profiling. Besides setting out particular
52 Security obligations, for example, cover concepts such as “privacy by design”, which represents a
deepening and an extension of those obligations. On privacy by design, see Orrù (2017).
53 See, for instance, the United States of America’s Health Insurance Portability and Accountability
Act of 1996.
54 See article 20 of the GDPR.
55 See the International Trade Law Special Report, Sect. 4.
56 See the Swiss National Report, Sect. 2.8.
12
D. Moura Vicente and S. de Vasconcelos Casimiro
ease and quantity of data processing intensify the potential harm caused by its
unauthorized use. These possibilities have caused alarm in relation to certain types
of data, leading several countries to react through the enactment of specific legislation or, whenever specific legislation is absent, giving rise to significant, and often
controversial, case law. Personal data has been in the center of these concerns.
It isn’t possible to address in detail all topics related to personal data processed by
electronic means, as there are countless relevant ones in this regard. The exact
configuration of the right to be forgotten in the electronic context, the process for
obtaining a valid consent for personal data processing online, the operation of the
information right by electronic means, the meaning of the “privacy by design” and
the “privacy by default” concepts in this same context, profiling and portability, are
just some of those topics. Some decisions had to be taken in order to select the topics
which are addressed in more detail. The selected topics are, thus, those with a wider
scope, which comprise many of the other topics,
52 as well as those which have been
in the spotlight of important case law or new legislation. In this regard, topics such as
portability or profiling aren’t dealt with, autonomously, in a separate section.
Some brief lines should be dedicated, though, to the challenge of data portability
and its potential impact in the economy and in the protection of the data subjects.
Data portability grants the data subject a right to have the personal data transmitted
directly to him or to another entity, through electronic means. Data portability,
inasmuch as it requires the adoption of technical standards to ensure interoperability
between the different entities that process those data, promotes the free movement of
personal data and, consequently, works as an inducement or a driving force to the
economy. The easiness of personal data transfer may promote competition, improving innovation and service variety. Although there is sectorial legislation granting
data portability, dating back from the 1990s,
53 the general right to data portability
provided by the GDPR, which is applicable in all contexts, with minor exceptions, is
noteworthy.
54
Also noteworthy are the GDPR provisions on profiling. The ability to build a very
complete psychological profile of the data subject has been made possible by current
technologies,
55 and the possibilities keep evolving. Taking into account the particular risks posed to the data subjects by profiling, some legal systems have adopted
specific rules to deal with these risks. Swiss law is one of those legal systems, since it
requires the controller to conduct an impact assessment in case of profiling, given the
fact that this form of data processing may pose a threat to the data subject’s
privacy.
56 The GDPR also addresses profiling. Besides setting out particular
52 Security obligations, for example, cover concepts such as “privacy by design”, which represents a
deepening and an extension of those obligations. On privacy by design, see Orrù (2017).
53 See, for instance, the United States of America’s Health Insurance Portability and Accountability
Act of 1996.
54 See article 20 of the GDPR.
55 See the International Trade Law Special Report, Sect. 4.
56 See the Swiss National Report, Sect. 2.8.
12
D. Moura Vicente and S. de Vasconcelos Casimiro
