2015International Data Privacy LawOpen access

Risk management in data protection

Christopher Kuner, F. H. Cate, C. Millard, Dan Jerker B. Svantesson, Orla Lynskey

Open full text 18 citations

Abstract

Data protection has long relied on risk management as a critical tool for ensuring that data are processed appropriately and that the fundamental rights of individuals are protected effectively. Risk management is an explicit requirement of many data protection laws. For example, the 1988 US Computer Matching and Privacy Protection Act requires government agencies to perform a cost–benefit analysis of proposed data matching.1 Security breach notification laws often link notice to an assessment of the risk to individuals posed by the breached information. As the Article 29 Data Protection Working Party has noted, for notification to be effective ‘it is important to have an appropriate risk management framework in place …’.2 And risk management is the goal of Privacy Impact Assessments. The EU Data Protection Directive 95/46/EC requires that security measures must ‘ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected’ (Article 17); that ‘processing operations likely to present specific risks to the rights and freedoms of data subjects’ be subject to ‘prior checking’ by Member States (Article 12); that personal data may be processed when ‘necessary for the purposes of the legitimate interest pursued by the controller or by the third party or parties to whom data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subjects …’ (Article 7(f)); and that access rights to data processed for scientific research may be limited ‘where there is clearly no risk of breaching the privacy of the data subject’ (Article 13(2)).

About this research paper

What this paper is about

Data protection has long relied on risk management as a critical tool for ensuring that data are processed appropriately and that the fundamental rights of individuals are protected effectively. Risk management is an explicit requirement of many data protection laws. For example, the 1988 US Computer Matching and Privacy Protection Act requires government agencies to perform a cost–benefit analysis of proposed data matching.1 Security breach notification laws often link notice to an assessment of the risk to individuals posed by the breached information. As the Article 29 Data Protection Working Party has noted, for notification to be effective ‘it is important to have an appropriate risk management framework in place …’.2 And risk management is the goal of Privacy Impact Assessments. The EU Data Protection Directive 95/46/EC requires that security measures must ‘ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected’ (Article 17); that ‘processing operations likely to present specific risks to the rights and freedoms of data subjects’ be subject to ‘prior checking’ by Member States (Article 12); that personal data may be processed when ‘necessary for the purposes of the legitimate interest pursued by the controller or by the third party or parties to whom data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subjects …’ (Article 7(f)); and that access rights to data processed for scientific research may be limited ‘where there is clearly no risk of breaching the privacy of the data subject’ (Article 13(2)).

Why it matters

OpenAlex reports 18 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Data protection has long relied on risk management as a critical tool for ensuring that data are processed appropriately and that the fundamental rights of individuals are protected effectively. Risk management is an explicit requirement of many data protection laws. For example, the 1988 US Computer Matching and Privacy Protection Act requires government agencies to perform a cost–benefit analysis of proposed data matching.1 Security breach notification laws often link notice to an assessment of the risk to individuals posed by the breached information. As the Article 29 Data Protection Working Party has noted, for notification to be effective ‘it is important to have an appropriate risk management framework in place …’.2 And risk management is the goal of Privacy Impact Assessments. The EU Data Protection Directive 95/46/EC requires that security measures must ‘ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected’ (Article 17); that ‘processing operations likely to present specific risks to the rights and freedoms of data subjects’ be subject to ‘prior checking’ by Member States (Article 12); that personal data may be processed when ‘necessary for the purposes of the legitimate interest pursued by the controller or by the third party or parties to whom data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subjects …’ (Article 7(f)); and that access rights to data processed for scientific research may be limited ‘where there is clearly no risk of breaching the privacy of the data subject’ (Article 13(2)).

Key concepts: Data Protection Act 1998, Risk management, Computer science, Business, Computer security, Risk analysis (engineering), Finance

Related papers

Back to paper searchBrowse research topicsOriginal source
Risk management in data protection — Research Paper | ScholarLens