212
A. Solanas et al.
12.4.3 Growing Importance of Legislation
Since the beginning of the twenty-first century, researchers have proposed concepts
such as data minimization to improve privacy protection. However, these ideas are
taking shape along with others such as consent as a result of the enforcement of
the Global Data Protection Regulation (GDPR) [547]. In this sense, it could be said
that the ideas were there, but it took almost 20 years to provide them with the right
embodiment to be enforced. Clearly, the role of legislation and law enforcers will be
fundamental for the protection of privacy, since technology alone can hardly protect
all privacy dimensions that affect people.
Lately, there has been a lot of controversy around the impact of the GDPR in the
technological context, affecting trendy fields such as UCS, IoT and Big Data. With
the aim to enhance individuals’ privacy and strengthen the protection of personal
data, GDPR unifies data protection laws across EU member states. Law experts
agree that GDPR has caused a major overhaul of data protection laws across EU.
Thus, to preserve individuals’ privacy and guarantee their rights, UCS need to be
designed to protect individuals data.
To prevent potential data misuse, GDPR limits the processing of personal data,
places higher importance on individuals’ consents, and strengthens the rights of
individuals to control their data. Also, it introduces reinforcements on the conditions
for processing personal data. Hence, processing is only allowed when individuals
give explicit and informed consent for such processing according to some welldefined and unambiguous purposes and uses. These requirements pose many
challenges for UCS (e.g., obtaining consent in public environments, clearly defining
the purposes of processing). In addition, GDPR introduces the right to withdraw this
consent (i.e., revocation of consent) easily and at any time, thus denying the future
processing of these data if no legal basis justifies their storage.
Also, GDPR considers the right of individuals to obtain their data in a structured,
commonly used, interoperable and machine-readable format. This is indeed very
challenging, since the heterogeneity of UCS leads to a wide spectrum of information
to be returned, ranging from health-related data, wearable trackers, and opinions to
even biometric and financial data [562].
For the processing of personal data, UCS must put in place appropriate means
to guarantee privacy. For instance, encryption and pseudonymisation could be used
to ensure confidentiality. However, despite these techniques, UCS are not free of
attacks that open the door to personal data breaches and scenarios where data is
compromised. In this context, considering that GDPR establishes the obligation
to communicate data breaches to supervisory authorities within 72 h, monitoring
systems should permanently keep track of UCS activities and look for abnormal
behavior that could compromise personal data [176].
The effect of GDPR on privacy protection will be varied, and the years to come
will see a very interesting transformation of the field of privacy protection as a result
of its deployment and enforcement.
A. Solanas et al.
12.4.3 Growing Importance of Legislation
Since the beginning of the twenty-first century, researchers have proposed concepts
such as data minimization to improve privacy protection. However, these ideas are
taking shape along with others such as consent as a result of the enforcement of
the Global Data Protection Regulation (GDPR) [547]. In this sense, it could be said
that the ideas were there, but it took almost 20 years to provide them with the right
embodiment to be enforced. Clearly, the role of legislation and law enforcers will be
fundamental for the protection of privacy, since technology alone can hardly protect
all privacy dimensions that affect people.
Lately, there has been a lot of controversy around the impact of the GDPR in the
technological context, affecting trendy fields such as UCS, IoT and Big Data. With
the aim to enhance individuals’ privacy and strengthen the protection of personal
data, GDPR unifies data protection laws across EU member states. Law experts
agree that GDPR has caused a major overhaul of data protection laws across EU.
Thus, to preserve individuals’ privacy and guarantee their rights, UCS need to be
designed to protect individuals data.
To prevent potential data misuse, GDPR limits the processing of personal data,
places higher importance on individuals’ consents, and strengthens the rights of
individuals to control their data. Also, it introduces reinforcements on the conditions
for processing personal data. Hence, processing is only allowed when individuals
give explicit and informed consent for such processing according to some welldefined and unambiguous purposes and uses. These requirements pose many
challenges for UCS (e.g., obtaining consent in public environments, clearly defining
the purposes of processing). In addition, GDPR introduces the right to withdraw this
consent (i.e., revocation of consent) easily and at any time, thus denying the future
processing of these data if no legal basis justifies their storage.
Also, GDPR considers the right of individuals to obtain their data in a structured,
commonly used, interoperable and machine-readable format. This is indeed very
challenging, since the heterogeneity of UCS leads to a wide spectrum of information
to be returned, ranging from health-related data, wearable trackers, and opinions to
even biometric and financial data [562].
For the processing of personal data, UCS must put in place appropriate means
to guarantee privacy. For instance, encryption and pseudonymisation could be used
to ensure confidentiality. However, despite these techniques, UCS are not free of
attacks that open the door to personal data breaches and scenarios where data is
compromised. In this context, considering that GDPR establishes the obligation
to communicate data breaches to supervisory authorities within 72 h, monitoring
systems should permanently keep track of UCS activities and look for abnormal
behavior that could compromise personal data [176].
The effect of GDPR on privacy protection will be varied, and the years to come
will see a very interesting transformation of the field of privacy protection as a result
of its deployment and enforcement.
