Lohan, Alén-Savikko, Chen, Järvinen, Leppäkoski, Kuusniemi, and Korpisaari
306
objectives noted above, while consistency with the GDPR is pursued. The purpose is to
adopt a Regulation that extends the rules to non‐traditional services, such as internet
calls [124,125].
13.11.2 Legal Aspects Related to the Processing of Location Data
Processing of location data is considered a delicate issue and, thus, both general and
specific instruments provide the legal framework for different aspects of processing
location data. In the context of geo-location, there may be several controllers and processors, that is those determining “the purposes and means of the processing” and those
processing on their behalf (art 2 DPD; art 4 GDPR) of data [35].
Processing of, including any operation performed upon, personal data requires a legal
ground. Consent is one such ground (art 6 (1 a) GDPR; art 7 DPD), and it is applicable
in the context of personal smart devices and geo‐positioning data. Consent must be
informed, freely given, specific with regard to the different purposes of processing,
unambiguous and withdrawable (arts 4(11), 6, 7(3); preamble, 32 GDPR). A “clear
affirmative act” is required, including ticking boxes or choosing settings (GDPR preamble, 32), while consent must also be “clearly distinguishable from the other matters” in
the context of some wider declaration (art 7 GDPR). Thus, it is not sufficient to accidentally “consent” by lack of action or by accepting general terms and conditions of particular service [38,40].
Furthermore, processing of sensitive data (art 9 GDPR), as well as children’s consent
(art 8 GDPR), are under specific requirements which, in the former case, refer to the
explicit nature of the consent and in the latter, to parental authorization. Information on
the details of processing must be provided to data subjects in understandable and accessible form, while taking children especially into account (preamble, 39, 58; arts 13‐14
GDPR). Users must also remain informed and be reminded of their device being
located – this could be best done in cooperation between app providers and developers
of operating systems [38,40].
Furthermore, individuals as data subjects have rights (arts 16‐22 GDPR; art 12 DPD),
which need to be fulfilled. This means, for instance, access to location data in human
readable format, as well as the possibility to rectify and erase data (incl. art 17 GDPR on
“the right to be forgotten”), preferably online [32,40].
13.11.3 Privacy Protection by Design and Default
The GDPR includes explicit provisions on so‐called data protection by design and
default (art 25). This means that systems and services are to be designed so as to implement the principles of processing personal data, including data minimization and security (art 5). Technological and organizational measures are to be executed with a view
on “the state–of‐the‐art, the cost of implementation and the nature, scope, context and
purposes of processing”. while the risks for individuals’ rights and freedoms must also
be taken into account (art 25(1)). These measures include pseudonymization as an
example. Similarly, default settings should also support the principles, especially to
ensure processing of necessary data only as well as appropriate storage (art 25(2)).
The Article 29 Working Party [36] has recommended that location services be
switched off by default, that the scope of consent is limited in time (with a reminder
306
objectives noted above, while consistency with the GDPR is pursued. The purpose is to
adopt a Regulation that extends the rules to non‐traditional services, such as internet
calls [124,125].
13.11.2 Legal Aspects Related to the Processing of Location Data
Processing of location data is considered a delicate issue and, thus, both general and
specific instruments provide the legal framework for different aspects of processing
location data. In the context of geo-location, there may be several controllers and processors, that is those determining “the purposes and means of the processing” and those
processing on their behalf (art 2 DPD; art 4 GDPR) of data [35].
Processing of, including any operation performed upon, personal data requires a legal
ground. Consent is one such ground (art 6 (1 a) GDPR; art 7 DPD), and it is applicable
in the context of personal smart devices and geo‐positioning data. Consent must be
informed, freely given, specific with regard to the different purposes of processing,
unambiguous and withdrawable (arts 4(11), 6, 7(3); preamble, 32 GDPR). A “clear
affirmative act” is required, including ticking boxes or choosing settings (GDPR preamble, 32), while consent must also be “clearly distinguishable from the other matters” in
the context of some wider declaration (art 7 GDPR). Thus, it is not sufficient to accidentally “consent” by lack of action or by accepting general terms and conditions of particular service [38,40].
Furthermore, processing of sensitive data (art 9 GDPR), as well as children’s consent
(art 8 GDPR), are under specific requirements which, in the former case, refer to the
explicit nature of the consent and in the latter, to parental authorization. Information on
the details of processing must be provided to data subjects in understandable and accessible form, while taking children especially into account (preamble, 39, 58; arts 13‐14
GDPR). Users must also remain informed and be reminded of their device being
located – this could be best done in cooperation between app providers and developers
of operating systems [38,40].
Furthermore, individuals as data subjects have rights (arts 16‐22 GDPR; art 12 DPD),
which need to be fulfilled. This means, for instance, access to location data in human
readable format, as well as the possibility to rectify and erase data (incl. art 17 GDPR on
“the right to be forgotten”), preferably online [32,40].
13.11.3 Privacy Protection by Design and Default
The GDPR includes explicit provisions on so‐called data protection by design and
default (art 25). This means that systems and services are to be designed so as to implement the principles of processing personal data, including data minimization and security (art 5). Technological and organizational measures are to be executed with a view
on “the state–of‐the‐art, the cost of implementation and the nature, scope, context and
purposes of processing”. while the risks for individuals’ rights and freedoms must also
be taken into account (art 25(1)). These measures include pseudonymization as an
example. Similarly, default settings should also support the principles, especially to
ensure processing of necessary data only as well as appropriate storage (art 25(2)).
The Article 29 Working Party [36] has recommended that location services be
switched off by default, that the scope of consent is limited in time (with a reminder
