- 25/04/2018
- Category: Commentaries
This part will explore EU’s response to Facebook, Inc.’s alleged breach of privacy and Facebook, Inc.’s possible steps in the future to deal with this issue.
Q3. What are the EU’s attempts to improve data privacy regulations? How will this affect its citizens, businesses, and governments?
As an attempt to improve the EU citizens’ data protection, the EU Parliament is introducing General Data Protection Regulation (GDPR), which will come into effect on 25 May 2018. This new regulation is an update of its predecessor Data Protection Act (DPA) that was established in 1995. After its first regulation update proposal by the European Commission in January 2012, a change in regulation was approved in April 2016. Unlike DPA which was a directive, GDPR is now a regulation—which is a binding legislative act across the EU, not a goal that can be individually implemented by EU member states. This extended jurisdiction could be what sets GDPR apart from DPA the most.
Non-EU organizations with data subjects in the EU will require a representative from the EU. Data Processing Officers (DPOs) will be mandatory for public authorities and organizations that process large-scale data with a systematic monitoring system or data that contains sensitive information. Post-Brexit, the UK Government will create a comparable legal mechanism. GDPR also applies to all companies that process and store identifiable data of data subjects residing in the EU, including companies that are located outside of the EU. The rules apply to both data controllers (the entity that decides the purposes of the data) and processors (the entity that processes data for the controllers, such as ‘clouds’).
Consent from data subjects must be clear, legible and easy to access. Explicit consent is needed for acquiring sensitive information. Data subjects must also be able to “withdraw consents as easy as to give it.” Processing data from data subjects under the age of 16 will require parental consent, the age of consent may be lower in certain member states but not below the age of 13. Data subjects have the right to access (an electronic format of their data, and whether or not it is being processed, if so for what purpose and where), right to be forgotten (the erasure of data and the termination of data being further disseminated by the data controller and potentially any third-parties), and right to privacy by design (only necessary data being processed and limitation of personnel access to personal data).
In the case of a data breach that could pose any rights and freedom risks to individuals, the Data Protection Authorities (DPAs) must be notified within 72 hours of being aware of the breach. Affected individuals must also be contacted “without undue delay.” Breaches under GDPR can be fined “up to 4% of annual global turnover or €20 Million (whichever is greater)”—with a tiered approach to fines, depending on the type of breach.[i] Though GDPR was created to protect the privacy of data subjects, it will also benefit organizations and businesses that comply. Non-compliance could result in embarrassment, loss of reputation and decline in profit, especially if the breach is broadcasted to the public. However, for internet giants like Facebook, Twitter, and Google, preparation for compliance may mean a great increase in costs and resources.[ii]
Q4. How will Facebook, Inc. attempt to comply with EU’s new data privacy regulations?
In response to GDPR, Facebook, Inc. promises to introduce new data privacy regulations to comply with the new regulation. In a ‘Facebook Gathers’ conference in Brussels, on behalf of Facebook, Inc., Chief Operating Officer Sheryl Sandberg promises to work hard to:
- Share its privacy principles ahead of GDPR for the first time,
- Create a new privacy center to make privacy settings easier to find and manage,
- Provide educational videos on data usage on its news feed and,[iii]
- End global democratic abuse and tackle the surveillance of fake news by doubling the amount of safety and security workers to 20,000 by the end of the year.[iv]
On 17 April 2018, VP and Chief Privacy Officer Erin Egan and VP and Deputy General Counsel Ashlie Beringer, announced new privacy controls for Facebook’s platform on a blog post. They stated users, regardless of being EU residents or not, will be asked to consent (or not) to how their data will be used as listed below:
- Personalized advertisements,
- Profile information (especially sexual orientation, religious beliefs, and political views) and,
- Face recognition technology (to allow photo/video tag suggestions as well as prevent mistreatment of personal imagery).
Facebook will also launch new profile settings and privacy shortcut features that are based on GDPR. For users in Europe, this and the consent forms above will be introduced prior to the GDPR cutoff date and sometime later other regions in the world.
For users between the age of 13 and 15, Facebook’s interface will be less personalized without parental consent. This means less personalized advertisements, inability to share posts to the “public” setting and limit who can search or access personal information. Facebook also declared to introduce a global youth online center, to shed light on most asked questions regarding privacy.[v] [vi]
CONCLUSION
With our current digital culture, the Internet and all that comes with it has become such a large part of our day-to-day life. It would be a challenge not to leave any digital traces that can be mined into data, even if we aren’t active internet users. We may not be able to escape big data if we want to keep using the internet. However, using GDPR as an example, we can learn that as users we must stay educated about our privacy rights and how internet giants are accommodating this, as businesses we must respect the rights of users and take caution when processing sensitive information. Finally, governments must implement regulations that will benefit not only Internet giants, but also everyone at large.
Editors: Atin Prabandari MA(IR), Diah Ratna Pratiwi, M.Dev & Nabeel Khawarizmy Muna, S.IP
Picture: pexels
[i] The EU General Data Protection Regulation. (2016). GDPR Portal. [online]. GDPR. Available at: https://www.eugdpr.org/eugdpr.org.html [Accessed at: 17 Apr. 2018].
[ii] Crehan, F. (2018). What you can do now to protect your business under GDPR. [online]. Silicon Republic. Available at: https://www.siliconrepublic.com/enterprise/gdpr-compliance-fergal-crehan [Accessed at: 17 Apr. 2018].
[iii] Shaban, H. (2018). Facebook braces for new E.U. privacy law.[online]. The Washington Post. Available at: https://www.washingtonpost.com/news/the-switch/wp/2018/01/29/facebook-braces-for-new-e-u-privacy-law/?noredirect=on&utm_term=.f27d2d9b56f5 [Accessed at: 17 Apr. 2018].
[iv] Hern, A. (2018). Facebook to roll out new tools in response to EU privacy laws. [online]. The Guardian. Available at: https://www.theguardian.com/technology/2018/jan/23/facebook-new-privacy-tools-response-to-eu-privacy-laws-sheryl-sandberg [Accessed at: 5 Mar. 2018].
[v] Newsroom by Facebook. (2016). Data policy. [online]. Facebook, Inc. Available at: https://newsroom.fb.com/news/2018/04/new-privacy-protections/ [Accessed at: 12 Mar. 2018].
[vi] Ong, T. (2018). Facebook announces new European privacy controls, for the world. [online]. The Verge. Available at: https://www.theverge.com/2018/4/18/17250840/facebook-privacy-protections-europe-world-gdpr [Accessed at: 17 Apr. 2018].