Skip to main content
Kent Academic Repository

Bridging Policy, Regulation, and Practice? A Techno-Legal Analysis of Three Types of Data in the GDPR

Hu, R. and Stalla-Bourdillon, s. and Yang, M. and Schiavo, v. and Sassone, v. (2017) Bridging Policy, Regulation, and Practice? A Techno-Legal Analysis of Three Types of Data in the GDPR. In: Leenes, r. and van Brakel, r. and Gutwirth, s. and De Hert, p., eds. Data Protection and Privacy: The Age of Intelligent Machines. Harts Publishing, Oxford and Portland, Oregon. E-ISBN 978-1-5099-3748-6. (The full text of this publication is not currently available from this repository. You may be able to access a copy if URLs are provided) (KAR id:89600)

The full text of this publication is not currently available from this repository. You may be able to access a copy if URLs are provided. (Contact us about this Publication)

Abstract

The paper aims to determine how the General Data Protection Regulation (GDPR) could be read in harmony with Article 29 Working Party’s Opinion on anonymisation techniques. To this end, based on an interdisciplinary methodology, a common terminology to capture the novel elements enshrined in the GDPR is built, and, a series of key concepts (i.e. sanitisation techniques, contextual controls, local linkability, global linkability, domain linkability) followed by a set of definitions for three types of data emerging from the GDPR are introduced.

Importantly, two initial assumptions are made:

1) the notion of identifiability (i.e. being identified or identifiable) is used consistently across the GDPR (e.g. Article 4 and Recital 26);

2) the Opinion on Anonymisation Techniques is still good guidance as regards the classification of re-identification risks and the description of sanitisation techniques.

It is suggested that even if these two premises seem to lead to an over-restrictive approach, this holds true as long as contextual controls are not combined with sanitisation techniques. Yet, contextual controls have been conceived as complementary to sanitisation techniques by the drafters of the GDPR. The paper concludes that the GDPR is compatible with a risk-based approach when contextual controls are combined with sanitisation techniques.

Item Type: Book section
Uncontrolled keywords: personal data, anonymisation, pseudonymisation, GDPR, identified
Subjects: H Social Sciences
Divisions: Divisions > Kent Business School - Division > Department of Marketing, Entrepreneurship and International Business
Depositing User: Mu Yang
Date Deposited: 03 Aug 2021 14:00 UTC
Last Modified: 03 Aug 2021 14:00 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/89600 (The current URI for this page, for reference purposes)

University of Kent Author Information

  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.