Khaleej Times

Europe’s data privacy law puts Big Tech in a spot

- — Reuters SEE BUSINESS

brussels — New European privacy regulation­s went into effect on Friday that will force companies to be more attentive to how they handle customer data.

The ramificati­ons were visible from day one, with major USmedia outlets including the LA

Times and Chicago Tribune were forced to shutter their websites in parts of Europe.

People in the bloc have been bombarded with dozens of emails asking for their consent to keep processing their data, and a privacy activist wasted no time in taking action against US tech giants for allegedly acting illegally by forcing users to accept intrusive terms of service or lose access.

“You have to have a ‘yes or no’ option,” Austrian Max Schrems said before filing complaints in European jurisdicti­ons. “A lot of these companies now force you to consent to the new privacy policy, which is totally against the law.”

Critics say the new rules are overly burdensome.

brussels — New European privacy regulation­s went into effect on Friday that will force companies to be more attentive to how they handle customer data.

The ramificati­ons were visible from day one, with major US-media outlets including the LA Times and Chicago Tribune were forced to shutter their websites in parts of Europe.

People in the bloc have been bombarded with dozens of e-mails asking for their consent to keep processing their data, and a privacy activist wasted no time in taking action against US tech giants for allegedly acting illegally by forcing users to accept intrusive terms of service or lose access. “You have to have a ‘yes or no’ option,” Austrian Max Schrems said before filing complaints in European jurisdicti­ons. “A lot of these companies now force you to consent to the new privacy policy, which is totally against the law.”

The European Union General Data Protection Regulation (GDPR) replaces the bloc’s patchwork of rules dating back to 1995 and heralds an era where breaking privacy laws can result in fines of up to 4 per cent of global revenue or €20 million ($23.5 million), whichever is higher, as opposed to a few hundred thousand euros.

For many companies it was a huge wakeup call because they never did their homework Patrick Van Eecke, Partner at law firm DLA Piper I think the data portabilit­y rights are pretty significan­t David Hoffman, Director of security policy and global privacy officer at Intel

Many privacy advocates have hailed the new law as a model for personal data protection in the internet era and called on other countries to follow the European model.

Critics say the new rules are overly burdensome, especially for small businesses, while advertiser­s and publishers worry it will make it harder for them to find customers.

The GDPR clarifies and strengthen­s existing individual rights, such as the right to have one’s data erased and the right to ask a company for a copy of one’s data.

But it also includes entirely new mandates, such as the right to transfer data from one service provider to another and the right to restrict companies from using personal data.

“It’s a gradual and not a revolution­ary kind of thing... However for many companies it was a huge wakeup call because they never did their homework. They never took the data protection directive seriously,” said Patrick Van Eecke, partner at law firm DLA Piper.

Activists are already planning to use the right to access their data to turn the tables on internet platforms whose model relies on processing people’s personal informatio­n. That means companies are having to put in place processes for dealing with such requests and educating their workforce because any non-compliance could lead to stiff sanctions.

Studies suggest that many companies are not ready for the new rules.

The Internatio­nal Associatio­n of Privacy Profession­als found that only 40 per cent of companies affected by the GDPR expected to be fully compliant by May 25.

It is unclear how many provisions of GDPR will be interprete­d and enforced. European regulatory authoritie­s, many of whom say they are under-funded, will oversee the new law, with a central body to resolve conflicts.

One key provision of GDPR, the right to data portabilit­y, is causing particular confusion.

“I think the data portabilit­y rights are pretty significan­t and are going to take a while for people to figure out what the bounds of them are and how to go about complying with them,” said David Hoffman, director of security policy and global privacy officer at Intel.

For example, music streaming services such as Spotify create playlists for users based on their music preference­s. While a user seeking to exercise the data portabilit­y right would be able to move playlists he or she created, the situation becomes fuzzy if the playlists are created by the streaming service using algorithms.

EU data protection authoritie­s said individual­s should be able to transfer data provided by them but not “derived data” created by the service provider such as algorithmi­c results.

“It’s not obvious that you can necessaril­y migrate the data from your system to somebody else’s system,” Tanguy Van Overstraet­en, of Linklaters, said.

On the business side, companies are rushing to renegotiat­e contracts with suppliers and service providers because GDPR increases their liability if something goes wrong.

Data processors which only process or store the data on behalf of their clients, for example cloud computing providers, will be directly liable for sanctions and could face lawsuits from individual­s, and that needs to be reflected in contracts.

“After 20 years of data protection legislatio­n in place, it’s only now with the GDPR they (companies) start to think about ‘what’s my role in the whole story? Am I a data controller or data processor?’” Van Eecke said. —

 ?? KHALEEJ TIMES GRAPHIC • SOURCES: KPMG, REUTERS, AFP ??
KHALEEJ TIMES GRAPHIC • SOURCES: KPMG, REUTERS, AFP
 ??  ??
 ??  ??

Newspapers in English

Newspapers from United Arab Emirates