Data Analytics and the GDPR: Friends or Foes? A Call for a Dynamic Approach to Data Protection Law

In R. Leenes, R. van Brakel, S. Gutwirth, & P. De Hert (Eds.), Data Protection and Privacy: The Internet of Bodies Hart (2018)

22 Pages Posted: 7 Oct 2018 Last revised: 21 Oct 2018

See all articles by Sophie Stalla-Bourdillon

Sophie Stalla-Bourdillon

Vrije Universiteit Brussel (VUB); University of Southampton

Alison Knight

University of Southampton

Date Written: September 13, 2018

Abstract

In this paper, we aim to help overcome a perceived paradox (and attendant tensions) between the two objectives of innovation and privacy/data protection, in particular in relation to data scenarios where organisations are open to personal data they control to be reused (internally within their corporate group, or externally via a third party) for innovative purposes. We argue that to do this requires better defining key notions in data protection law, acknowledging the interdependence of data protection requirements or principles, and relying upon ongoing data management processes in order to control complex data environments. These are the pillars of a dynamic approach to data protection law.

We start our demonstration by suggesting that the conceptualisation of data analytics by policy makers has not helped to produce clear guidance for practices going beyond the mere production of statistics. On the contrary, by drawing a distinction between the production of statistics and the rest, this approach has indirectly formed the seedbed for the view that EU data protection law and in particular the GDPR is antithetic to data analytics. We then revisit this critique of EU data protection law to show its limits and build the argument that a more constructive interpretation of the GDPR is possible, this on the basis of a dynamic approach to data protection law. Finally, we unfold the main tenets of such a dynamic approach and ultimately suggest that the GDPR does not undermine the logic of data analytics as a form of ‘data-driven general analysis,’ which implies a re-purposing or secondary processing of data legitimately hold by a data controller over a limited period of time and with no consequences defined prior to the analysis, although consequences could be attached in the future but only once a second impact assessment has been undertaken.

Keywords: GDPR, Big Data, Data Analytics, Legitimate Interest, Consent

JEL Classification: K19, K29, K39

Suggested Citation

Stalla-Bourdillon, Sophie and Knight, Alison, Data Analytics and the GDPR: Friends or Foes? A Call for a Dynamic Approach to Data Protection Law (September 13, 2018). In R. Leenes, R. van Brakel, S. Gutwirth, & P. De Hert (Eds.), Data Protection and Privacy: The Internet of Bodies Hart (2018), Available at SSRN: https://ssrn.com/abstract=3248976

Sophie Stalla-Bourdillon (Contact Author)

Vrije Universiteit Brussel (VUB) ( email )

Pleinlaan 2
http://www.vub.ac.be/
Brussels, 1050
Belgium

University of Southampton ( email )

University Rd.
Southampton SO17 1BJ, Hampshire SO17 1LP
United Kingdom

Alison Knight

University of Southampton ( email )

University Rd.
Southampton SO17 1BJ, Hampshire SO17 1LP
United Kingdom

Do you have negative results from your research you’d like to share?

Paper statistics

Downloads
384
Abstract Views
1,761
Rank
141,536
PlumX Metrics