Data Protection Takes a Business-Friendly Twist

1. The right to data protection is not an absolute right but must be balanced with other fundamental rights, including the freedom to conduct a business, in a proportionate way.

2. Direct marketing is recognised as a legitimate interest in the collection and processing of data. This allows businesses to use legitimate interest as a legal basis for processing personal information, along with preventing and monitoring fraud and pseudonymising personal data.

3. Unambiguous consent replaces explicit consent. Marketers won’t have to use an opt-in tick box to obtain consent. Individuals could give consent orally, in writing, and browser settings or other application where this is technically feasible and effective.

4. Compulsory appointment of a data protection officer (DPO) left at the discretion of individual Member States. The UK Government has a track record of doing the minimum required to comply with EU data protection legislation so UK businesses probably won’t be required to appoint a dedicated DPO. Even if the UK Government did go for the appointment of a DPO, the Irish draft text allows businesses to appoint somebody who was already working in a legal or compliance or IT security function. This is because the draft text clarifies that the DPO can fulfil other obligations, provided there is no conflict of interest.

5. A risk-based approach to data security breaches notifications. Businesses won’t have to notify individuals of every single data security breach, especially if there is little or no risk to personal data. If, for example, the data controller implemented technological protection measures to make sure the data was anonymised and those measures were applied to the data affected by the data security breach, there would be no need to notify the individual about the breach. Other obligations on data controllers and data processors in Chapter 4 make reference to a risk-based approach. So the requirement to carry out a data protection assessment is only required where any processing operations are likely to present specific risks. Source DMA – Read the full story here:

Comments are closed.