par Meeùs, Sébastien
Editeur scientifique Jacquemin, Hervé
Référence Time to Reshape the Digital Society, 40th anniversary of the CRIDS, Larcier, Bruxelles, Ed. 1, page (555)
Publication Publié, 2021-11-01
Partie d'ouvrage collectif
Résumé : Data processing activities in our data-driven society involve managing conflicting values on a large scale. Striking a balance between economic interests of companies and the rights and freedoms of citizens is precisely one of the objectives sought by the General Data Protection Regulation. This legal framework is considered the world’s leading instrument in data protection, but it comes at a cost: compliance sophistication.The contributions of this paper are (i) building a conceptual model in layers encompassing all the information that must be communicated by the controllers to the data subjects through the privacy policy (that we call “Mandatory Information”) and (ii) the creation of an annotation scheme following the conceptual model to assess the existence of this mandatory information in the text of privacy policies. From a broader perspective, we aim for an interdisciplinary and neutral response that could benefit each of the stakeholders: empowering data subject to exercise their rights, limiting data controller’s compliance costs as well as the risks of non-compliance and helping the regulator verify compliance throughout the automated monitoring of the data supply chain.