Risk management in data protection
Christopher Kuner, F. H. Cate, C. Millard, Dan Jerker B. Svantesson, Orla Lynskey
Abstract
Christopher Kuner, F. H. Cate, C. Millard, Dan Jerker B. Svantesson, Orla Lynskey
Abstract
Data protection has long relied on risk management as a critical tool for ensuring that data are processed appropriately and that the fundamental rights of individuals are protected effectively. Risk management is an explicit requirement of many data protection laws. For example, the 1988 US Computer Matching and Privacy Protection Act requires government agencies to perform a cost–benefit analysis of proposed data matching.1 Security breach notification laws often link notice to an assessment of the risk to individuals posed by the breached information. As the Article 29 Data Protection Working Party has noted, for notification to be effective ‘it is important to have an appropriate risk management framework in place …’.2 And risk management is the goal of Privacy Impact Assessments. The EU Data Protection Directive 95/46/EC requires that security measures must ‘ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected’ (Article 17); that ‘processing operations likely to present specific risks to the rights and freedoms of data subjects’ be subject to ‘prior checking’ by Member States (Article 12); that personal data may be processed when ‘necessary for the purposes of the legitimate interest pursued by the controller or by the third party or parties to whom data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subjects …’ (Article 7(f)); and that access rights to data processed for scientific research may be limited ‘where there is clearly no risk of breaching the privacy of the data subject’ (Article 13(2)).
OpenAlex reports 18 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Data protection has long relied on risk management as a critical tool for ensuring that data are processed appropriately and that the fundamental rights of individuals are protected effectively. Risk management is an explicit requirement of many data protection laws. For example, the 1988 US Computer Matching and Privacy Protection Act requires government agencies to perform a cost–benefit analysis of proposed data matching.1 Security breach notification laws often link notice to an assessment of the risk to individuals posed by the breached information. As the Article 29 Data Protection Working Party has noted, for notification to be effective ‘it is important to have an appropriate risk management framework in place …’.2 And risk management is the goal of Privacy Impact Assessments. The EU Data Protection Directive 95/46/EC requires that security measures must ‘ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected’ (Article 17); that ‘processing operations likely to present specific risks to the rights and freedoms of data subjects’ be subject to ‘prior checking’ by Member States (Article 12); that personal data may be processed when ‘necessary for the purposes of the legitimate interest pursued by the controller or by the third party or parties to whom data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subjects …’ (Article 7(f)); and that access rights to data processed for scientific research may be limited ‘where there is clearly no risk of breaching the privacy of the data subject’ (Article 13(2)).
Key concepts: Data Protection Act 1998, Risk management, Computer science, Business, Computer security, Risk analysis (engineering), Finance