Observations on the regulatory effectiveness of Article 25 GDPR

Nimród Mike · 2022 45th Jubilee International Convention on Information, Communication and Electronic Technology (MIPRO) · 2022

Article 25 of GDPR is relatively novel to Europe in terms of being a legal stipulation. This article refers to the well-known data protection principles. Yet, its role should be more than just a reiteration of the sacred chalices provided by Article 5 of GDPR. This applied research paper is meant to discover the role that EU data protection authorities are giving to the concept of data protection by design and by default. The analysis applies machine learning on the forty-nine cases in which this article has been referred to as a reason for a fine. Machine learning is used to find the potential correlation between the severity of infringements and the number of fines within the presence of Article 25. The argument is that while there is not yet a single case in which the monetary fine was issued because of a sole infringement of Article 25, as time progresses, the authorities are developing a more detail-oriented approach in the investigation and fining practices. Hence, the hypothesis is constructed around the statement that data protection by design and by default is for now only a complementary article, where the controller infringed other ones. As we know, "all models are wrong, but some of them are useful." Therefore, the result might be subject to criticism due to the relative data-poor environment in which the model is generated. However, future work is potentially promising with growing case-count that fuels such modelling efforts. This will support researchers to become not only data-rich but also information-smart.

Read the paper · More papers on PaperTik