Hide metadata

dc.date.accessioned2018-10-23T08:47:29Z
dc.date.available2018-10-23T08:47:29Z
dc.date.created2017-08-25T10:07:34Z
dc.date.issued2017
dc.identifier.citationBygrave, Lee Andrew . Data Protection by Design and by Default : Deciphering the EU’s Legislative Requirements. Oslo Law Review. 2017, 4(2), 105-120
dc.identifier.urihttp://hdl.handle.net/10852/65235
dc.description.abstractIn this paper, a critical examination is conducted of Article 25 of the European Union’s General Data Protection Regulation (Regulation 2016/679). Bearing the title ʻdata protection by design and by default’, Article 25 requires that core data protection principles be integrated into the design and development of systems for processing personal data. The paper outlines the rationale and legal heritage of Article 25, and shows how its provisions proffer considerably stronger support for data protection by design and by default than is the case under the 1995 Data Protection Directive (Directive 95/46/EC). The paper further shows that this strengthening of support is in keeping with jurisprudence of the European Court of Human Rights and the Court of Justice of the European Union. Nonetheless, it is herein argued that Article 25 suffers from multiple flaws, in particular a lack of clarity over the parameters and methodologies for achieving its goals, a failure to communicate clearly and directly with those engaged in the engineering of information systems, and a failure to provide the necessary incentives to spur the ʻhardwiring’ of privacy-related interests. Taken together, these flaws will likely hinder the traction of Article 25 requirements on information systems development.en_US
dc.languageEN
dc.publisherDet juridiske fakultet, Universitetet i Oslo
dc.rightsAttribution 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.titleData Protection by Design and by Default : Deciphering the EU’s Legislative Requirementsen_US
dc.typeJournal articleen_US
dc.creator.authorBygrave, Lee Andrew
cristin.unitcode185,12,2,0
cristin.unitnameInstitutt for privatrett
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1
dc.identifier.cristin1488551
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&rft.jtitle=Oslo Law Review&rft.volume=4&rft.spage=105&rft.date=2017
dc.identifier.jtitleOslo Law Review
dc.identifier.volume4
dc.identifier.issue2
dc.identifier.startpage105
dc.identifier.endpage120
dc.identifier.doihttp://dx.doi.org/10.18261/issn.2387-3299-2017-02-03
dc.identifier.urnURN:NBN:no-67773
dc.type.documentTidsskriftartikkelen_US
dc.type.peerreviewedPeer reviewed
dc.source.issn2387-3299
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/65235/2/Data%2BProtection%2Bby%2BDesign%2Band%2Bby%2BDefault.pdf
dc.type.versionPublishedVersion
dc.relation.projectNFR/247947


Files in this item

Appears in the following Collection

Hide metadata

Attribution 4.0 International
This item's license is: Attribution 4.0 International