Buch, Englisch, Format (B × H): 155 mm x 235 mm
From Abstract Principles to Implementation
Buch, Englisch, Format (B × H): 155 mm x 235 mm
Reihe: Issues in Privacy and Data Protection
ISBN: 978-3-032-42895-0
Verlag: Springer
This book examines the obligation of data protection by design and provides practical guidance on complying with Article 25 of the General Data Protection Regulation (GDPR). The GDPR significantly reshaped EU data protection law and introduced, for the first time, a legal requirement that data controllers implement technical and organisational measures to embed data protection principles into the design and operation of digital systems. While related concepts such as Privacy Enhancing Technologies (PETs) predated the GDPR, Article 25 established a binding obligation to ensure data protection by design and by default.
The book analyses the requirements of Article 25 GDPR and explains how organisations can comply with this broadly framed provision. Particular attention is given to the risk-based approach adopted by the GDPR, under which the level of protection must correspond to the risks posed to data subjects. This approach creates uncertainty because Article 25 does not specify which safeguards are sufficient in practice. Similar ambiguity exists regarding anonymisation techniques, which the author identifies as important measures for achieving compliance with the principle of data minimisation.
To address these challenges, the book examines officially approved Codes of Conduct and certification requirements in data protection law. These instruments provide detailed guidance on implementing data protection by design and help translate the GDPR’s abstract requirements into concrete compliance measures. The analysis further demonstrates that the EU law principle of legitimate expectations can protect organisations that rely on officially approved standards.
Adopting an interdisciplinary perspective, the book also explores Knowledge Graphs (KGs) as tools for embedding data protection requirements into technological systems. Focusing on Knowledge Graphs developed through Semantic Web technologies, it shows how legal rules can be expressed in machine-readable formats that support compliance by design. The monograph concludes by proposing best practices for the development of vocabularies and ontologies that represent data protection obligations in a structured, machine-readable way.
Zielgruppe
Research
Autoren/Hrsg.
Fachgebiete
- Rechtswissenschaften Internationales Recht und Europarecht Internationales Recht
- Rechtswissenschaften Wirtschaftsrecht Medienrecht
- Mathematik | Informatik EDV | Informatik Technische Informatik Computersicherheit Datensicherheit, Datenschutz
- Sozialwissenschaften Medien- und Kommunikationswissenschaften Medienwissenschaften Medienphilosophie, Medienethik, Medienrecht
Weitere Infos & Material
Chapter 1 – Introduction.- Chapter 2 – The Shape of Technology and Data Protection Law.- Chapter 3 – A Theoretical Analysis of article 25 GDPR.- Chapter 4 – Pseudonymisation and Anonymisation as Safeguards by Design.- Chapter 5 – Codes of Conducts and Data Protection Certificates as Guidance.- Chapter 6 – An exploration of Officially Approved Codes of Conduct and Certification Criteria.- Chapter 7 – Legitimate Expectations of Data Controllers.- Chapter 8 – Knowledge Graphs and the Design of Technology.- Chapter 9 – Conclusions and Final Remarks.




