Between the GDPR and the Police Directive: navigating through the maze of information sharing in public–private partnerships

Nadezhda Purtova · International Data Privacy Law · 2017

... The idea that combatting cybercrime could only be effective through collaboration of state law enforcement with private actors, often called public–private partnership (PPP), has firmly entered the discourse on cybersecurity.1 While the consensus on the necessity to involve private resources, capacities, and expertise to combat cybercrime is growing,2 concerns are voiced that reliance on private parties for performing a traditionally public function of crime fighting may entail a transfer of public power to private hands, which raises a question of legitimacy of such power.3 This article will focus on one particular aspect of legitimacy of PPPs for combatting cybercrime, ie information sharing involving personal data. Before the analysis can begin, I will briefly deal with the matter of nomenclature. Although multiple definitions of the PPPs exist,4 the one used in this article is by Savas: PPP is ‘any arrangement between government and the private sector in which partially or traditionally public activities are performed by the private sector’.5 Next, the notion of ‘combatting cybercrime’ is based on the notion of policing, meaning ‘those organised forms of order-maintenance, peacekeeping, rule- or law enforcement, crime investigation and prevention and other forms of investigation and information-brokering’.6 It does not include prosecution, adjudication, and execution of criminal punishment. Hence, public–private collaboration in combatting cybercrime in the context of this article means collaboration in keeping order and enforcing law in cyberspace, in prevention and investigation of cybercrime.

Read the paper · More papers on PaperTik