Data rules in need of update
Or what happens to your pictures after you delete them from a social networking site? Do you know who you can turn to if your data has been stolen or misused?
Across Europe citizens are increasingly concerned about what happens to their personal data.
In Ireland 65% of social network users and 76% of online shoppers say they do not feel in complete control of their data.
With social networking sites, cloud computing, location-based services, and smart cards, we leave digital traces, details of our life, with every move we make. In this brave new digital world we need a robust set of rules.
Ireland has had legislation protecting citizens’ personal data in place since 1988 which was further updated in 2003 resulting from common European rules introduced in 1995.
But these were pre-internet times: In 1995 only 1% of Europe’s population was using the internet.
To protect personal data more effectively, in January the European Commission proposed an overhaul of the EU data protection rules.
The changes will give people more control over their personal data and make it easier to access, correct, or delete their data.
People will also be better informed about what happens to their data when they share it.
The reform will put people in control of their personal data by reinforcing the “right to be forgotten”, meaning that data is deleted when someone no longer wants their data to be processed and when there are no legitimate grounds for businesses to retain the data.
The rules will make it clear that when you consent to the handling of your data, this must happen explicitly and knowingly. If data is stolen, lost, or hacked — such as when 6m users’ passwords were recently hacked from a professional networking site — you must be informed about it as soon as possible, not weeks after the incident.
These changes will be good for consumers and good for business. In today’s world, personal data has become the currency of the digital market. And like any currency it has to be stable and it has to be trustworthy.
Only if consumers trust that their data is well protected will they continue to entrust businesses and authorities with it, buy online, and accept new services.
The rules will ensure people can be confident about going online and taking advantage of online shopping, new technologies, or sharing information with friends around the globe.
It will make no difference where you live, or where the server or headquarters of a company is located, because there will be one European rule, applicable in all 27 EU countries. This means more legal certainty and less costs for companies.
After all, businesses expect European data protection rules to provide a level playing field, regardless of where they operate in the EU. US companies, for instance, want to be able to operate in the European market without having to study 27 different rules.
The commission is proposing to establish a one-stop-shop for data protection that will make Europe — and Ireland — a more attractive place in which to do business. One single law for all of Europe, and one national data protection authority for each company — namely the EU country in which the company has its main establishment.
This will do away with the present costly arrangement in which companies have to deal with regulators in each EU nation. In addition, unnecessary reporting requirements for companies will also be removed. Overall, the reform is expected to save businesses in Europe €2.3bn a year.
The rules will make the digital single market work for the tech giants and help drive economic growth. This is important for Ireland because of the large number of global internet companies based here. Many of the world’s leading companies in the hi-tech sector have selected Ireland as their location of choice and the Silicon Docks at the heart of Dublin’s docklands have become Europe’s Silicon Valley.
The rules also specifically cater for SMEs, who won’t have to appoint a data protection officer. Small businesses account for nearly 70% of Ireland’s enterprises. These exemptions ensure they will not suffer an undue administrative burden but benefit from the elimination of barriers within the internal market, allowing them to grow.
As home to many innovative firms dealing with a lot of personal data, Ireland has a key role to play in shaping the new rules. Ireland will have the chance to gather support around these proposals and have them agreed by the European partners during its six-month stewardship of the EU next year. This will be central to making Ireland even more welcoming for business.
* Viviane Reding is vice-president of the European Commission. Billy Hawkes is the Data Protection Commissioner






