<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>edisclosure myth or reality? &#187; GDPR</title>
	<atom:link href="https://jollyvip.com/edisclosure/category/gdpr/feed/" rel="self" type="application/rss+xml" />
	<link>https://jollyvip.com/edisclosure</link>
	<description>From litigation to the arbitration regime</description>
	<lastBuildDate>Tue, 01 Jul 2025 10:14:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<item>
		<title>Updated page on my contributions</title>
		<link>https://jollyvip.com/edisclosure/2021/10/27/updated-page-on-my-contributions/</link>
		<comments>https://jollyvip.com/edisclosure/2021/10/27/updated-page-on-my-contributions/#comments</comments>
		<pubDate>Wed, 27 Oct 2021 15:26:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2021]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[ICO]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=1072</guid>
		<description><![CDATA[I have updated my various contributions.]]></description>
			<content:encoded><![CDATA[<p><a href="https://jollyvip.com/edisclosure/contribution/" title="My various contributions" target="_blank">I have updated my various contributions.</a></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2021/10/27/updated-page-on-my-contributions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My presentation on the Children&#8217;s Code</title>
		<link>https://jollyvip.com/edisclosure/2021/06/23/dpforum/</link>
		<comments>https://jollyvip.com/edisclosure/2021/06/23/dpforum/#comments</comments>
		<pubDate>Wed, 23 Jun 2021 16:56:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2021]]></category>
		<category><![CDATA[Children]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=1060</guid>
		<description><![CDATA[As part of my secondee role as an Engagement Specialist at the ICO, I presented the Children&#8217;s Code at the Data Protection Forum on 1st June 2021. I&#8217;m sharing the slides here. Children&#8217;s Code slides presented at the Data Protection Forum, June 2021]]></description>
			<content:encoded><![CDATA[<p>As part of my secondee role as an Engagement Specialist at the ICO, I presented the Children&#8217;s Code at the Data Protection Forum on 1st June 2021. I&#8217;m sharing the slides here.<br />
<a href='http://jollyvip.com/edisclosure/files/2021/06/DPForum-1-June-2021-final-v1.0-01.06.2021.pdf'>Children&#8217;s Code slides presented at the Data Protection Forum, June 2021</a></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2021/06/23/dpforum/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>From noyb.eu (Schrems): steps for EU companies</title>
		<link>https://jollyvip.com/edisclosure/2020/07/28/step/</link>
		<comments>https://jollyvip.com/edisclosure/2020/07/28/step/#comments</comments>
		<pubDate>Tue, 28 Jul 2020 20:25:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2020]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=1013</guid>
		<description><![CDATA[Following from the CJEU&#8217;s judgment on EU-US data transfers (SchremsII), Schrems has posted comprehensive steps and FAQs on noyb.eu. I tweeted the news on 24th July 2020: From #Schrems &#38; https://t.co/c7eI7oxpgT &#8211; Next Steps for EU companies &#38; FAQs https://t.co/GPsRPP03L7 &#8212; cher devey (@datachainrisk) July 24, 2020]]></description>
			<content:encoded><![CDATA[<p>Following from the CJEU&#8217;s judgment on EU-US data transfers (SchremsII), Schrems has posted comprehensive steps and FAQs on <a href="https://bit.ly/2WONpUr" title="https://noyb.eu/en/next-steps-eu-companies-faqs" target="_blank">noyb.eu.</a></p>
<p>I tweeted the news on 24th July 2020:<br />
<blockquote class="twitter-tweet">
<p lang="en" dir="ltr">From <a href="https://twitter.com/hashtag/Schrems?src=hash&amp;ref_src=twsrc%5Etfw">#Schrems</a> &amp; <a href="https://t.co/c7eI7oxpgT">https://t.co/c7eI7oxpgT</a> &#8211; Next Steps for EU companies &amp; FAQs <a href="https://t.co/GPsRPP03L7">https://t.co/GPsRPP03L7</a></p>
<p>&mdash; cher devey (@datachainrisk) <a href="https://twitter.com/datachainrisk/status/1286652857492611078?ref_src=twsrc%5Etfw">July 24, 2020</a></p></blockquote>
<p> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2020/07/28/step/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>International data transfer</title>
		<link>https://jollyvip.com/edisclosure/2020/07/17/international-data-transfer/</link>
		<comments>https://jollyvip.com/edisclosure/2020/07/17/international-data-transfer/#comments</comments>
		<pubDate>Fri, 17 Jul 2020 21:57:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2020]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Privacy Shield]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=1001</guid>
		<description><![CDATA[I just browsed #Schrems on my twitter streams. We now have a sequel to SchremsI – SchremsII came into force on 16 July 2020. Never a dull day when it comes to human rights and fundamental freedoms especially when such inalienable rights shine as actionable rights against other &#8216;rights&#8217;. The CJEU&#8217;s judgment and the press [...]]]></description>
			<content:encoded><![CDATA[<p>I just browsed #Schrems on my twitter streams. We now have a sequel to SchremsI – SchremsII came into force on 16 July 2020. Never a dull day when it comes to human rights and fundamental freedoms especially when such inalienable rights shine as actionable rights against other &#8216;rights&#8217;.</p>
<p>The CJEU&#8217;s <a href="https://noyb.eu/files/CJEU/judgment.pdf" title="judgment" target="_blank">judgment</a> and the <a href="https://curia.europa.eu/jcms/upload/docs/application/pdf/2020-07/cp200091en.pdf" title="press release" target="_blank">press release</a> have been summarised by various folks. The <a href="https://bit.ly/2ZSh0hV" title="https://cdt.org/" target="_blank">essence of #SchremsII</a> – extracted from Center for Democracy &#038; Technology: </p>
<li>The safeguards provided by U.S. laws on the access and use by public authorities of data transferred from the European Union do not satisfy the requirements of EU law because, among other things, they do not grant European citizens actionable rights against the U.S. authorities.
<li>Even if the Standard Contractual Clauses (SCCs) remain valid, the competent national data protection authorities are required to suspend or prohibit a transfer of personal data to the U.S. where U.S. law fails to appropriately protect Europeans’ personal data.</li>
<p>No doubt international data transfer or international trade will continue to flow (and flourish) even without Privacy Shield as there is still GDPR Article 49. Data transfer has to be read in terms of adequacy, derogation, surveillance and also trade politics.</p>
<p>For now, our inalienable rights shine until another round of drama in the courts.</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2020/07/17/international-data-transfer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My PhD Thesis</title>
		<link>https://jollyvip.com/edisclosure/2019/06/21/my-phd-thesis/</link>
		<comments>https://jollyvip.com/edisclosure/2019/06/21/my-phd-thesis/#comments</comments>
		<pubDate>Fri, 21 Jun 2019 13:51:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2019]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=891</guid>
		<description><![CDATA[My PhD #Thesis. pic.twitter.com/B8MsesgU0O &#8212; cher devey (@datachainrisk) June 18, 2019]]></description>
			<content:encoded><![CDATA[<blockquote class="twitter-tweet"><p lang="en" dir="ltr">My PhD <a href="https://twitter.com/hashtag/Thesis?src=hash&amp;ref_src=twsrc%5Etfw">#Thesis</a>. <a href="https://t.co/B8MsesgU0O">pic.twitter.com/B8MsesgU0O</a></p>
<p>&mdash; cher devey (@datachainrisk) <a href="https://twitter.com/datachainrisk/status/1141002344244625408?ref_src=twsrc%5Etfw">June 18, 2019</a></p></blockquote>
<p> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2019/06/21/my-phd-thesis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Post #GDPR webinar: my talk on &#8216;Rights of the Data Subject&#8217;</title>
		<link>https://jollyvip.com/edisclosure/2018/06/26/post-gdpr-webinar-my-talk-on-rights-of-the-data-subject/</link>
		<comments>https://jollyvip.com/edisclosure/2018/06/26/post-gdpr-webinar-my-talk-on-rights-of-the-data-subject/#comments</comments>
		<pubDate>Tue, 26 Jun 2018 16:39:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=845</guid>
		<description><![CDATA[For those who missed the Post #GDPR webinar hosted by @InfosecurityMag &#038; @DanRaywood, replay/watch via: Post GDPR, Is it Too Late to Comply? You will need to register an account to login to view the webinar at www.infosecurity-magazine.com I did my 10 mins talk on &#8216;Rights of the Data Subject&#8217;. The sound wasn&#8217;t too brilliant [...]]]></description>
			<content:encoded><![CDATA[<p>For those who missed the Post #GDPR webinar hosted by @InfosecurityMag &#038; @DanRaywood, replay/watch via:<br />
<a href="https://www.infosecurity-magazine.com/webinars/post-gdpr-will-it-be-too-late-to/" title="Post GDPR, Is it Too Late to Comply?" target="_blank">Post GDPR, Is it Too Late to Comply?</a></p>
<p>You will need to register an account to login to view the webinar at www.infosecurity-magazine.com</p>
<p>I did my 10 mins talk on &#8216;Rights of the Data Subject&#8217;. The sound wasn&#8217;t too brilliant as I had to put my telephone handset on speakerphone.</p>
<p>If you&#8217;ve trouble with any of the &#8216;words/sentences&#8217; welcome to drop me an email cher [at] jyutsu [dot] com.</p>
<p>The quote by Justice Louis Brandeis: <strong>If the broad light of day could be let in upon men’s actions, it would purify them as the sun disinfects.</strong><em> Essentially, sunlight is the best of disinfectants. </p>
<p>I mentioned &#8216;sensitive, nefarious data&#8217; &#038; the contentious nature of the &#8216;Right to be Forgotten&#8217;.</p>
<p>We live in interesting data privacy times!</p>
<p>Many thanks,<br />
Cher</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2018/06/26/post-gdpr-webinar-my-talk-on-rights-of-the-data-subject/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Poll on Post GDPR &#8211; I&#8217;m a speaker for a webinar on 26th June 2018</title>
		<link>https://jollyvip.com/edisclosure/2018/06/21/a-poll-on-post-gdpr-im-a-speaker-for-a-webinar-on-26th-june-2018/</link>
		<comments>https://jollyvip.com/edisclosure/2018/06/21/a-poll-on-post-gdpr-im-a-speaker-for-a-webinar-on-26th-june-2018/#comments</comments>
		<pubDate>Thu, 21 Jun 2018 14:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[GDPR]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=835</guid>
		<description><![CDATA[Please vote, share this and tune in to the webinar. Do please vote and share this tweet. I&#39;m one of the speakers https://t.co/dV38dMuKpH https://t.co/KlkFD09o5h &#8212; cher devey (@datachainrisk) June 21, 2018]]></description>
			<content:encoded><![CDATA[<p><strong>Please vote, share this and tune in to the webinar.</strong></p>
<blockquote class="twitter-tweet" data-lang="en"><p lang="en" dir="ltr">Do please vote and share this tweet. I&#39;m one of the speakers <a href="https://t.co/dV38dMuKpH">https://t.co/dV38dMuKpH</a> <a href="https://t.co/KlkFD09o5h">https://t.co/KlkFD09o5h</a></p>
<p>&mdash; cher devey (@datachainrisk) <a href="https://twitter.com/datachainrisk/status/1009780495557808128?ref_src=twsrc%5Etfw">June 21, 2018</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2018/06/21/a-poll-on-post-gdpr-im-a-speaker-for-a-webinar-on-26th-june-2018/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>@DanRaywood @InfosecurityMag interviewed me.</title>
		<link>https://jollyvip.com/edisclosure/2018/05/24/826/</link>
		<comments>https://jollyvip.com/edisclosure/2018/05/24/826/#comments</comments>
		<pubDate>Thu, 24 May 2018 13:36:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[my research]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=826</guid>
		<description><![CDATA[A couple of days after the #GDPR Press Briefing at City, University of London @DanRaywood @InfosecurityMag interviewed me. Check it out at: New on @InfosecurityMag talked to @datachainrisk about her PhD research into data privacy and the effect of breaches on people, as well as how #GDPR came along at the right time. @CityUniLondon https://t.co/lq29fQ6ans [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days after the <a href="http://jollyvip.com/edisclosure/2018/04/22/gdpr-press-briefing-in-city-university-of-london/" title="GDPR Press Briefing" target="_blank">#GDPR Press Briefing</a> at City, University of London @DanRaywood @InfosecurityMag interviewed me. </p>
<p>Check it out at:</p>
<blockquote class="twitter-tweet" data-lang="en"><p lang="en" dir="ltr">New on <a href="https://twitter.com/InfosecurityMag?ref_src=twsrc%5Etfw">@InfosecurityMag</a> talked to <a href="https://twitter.com/datachainrisk?ref_src=twsrc%5Etfw">@datachainrisk</a> about her PhD research into data privacy and the effect of breaches on people, as well as how <a href="https://twitter.com/hashtag/GDPR?src=hash&amp;ref_src=twsrc%5Etfw">#GDPR</a> came along at the right time. <a href="https://twitter.com/CityUniLondon?ref_src=twsrc%5Etfw">@CityUniLondon</a> <a href="https://t.co/lq29fQ6ans">https://t.co/lq29fQ6ans</a></p>
<p>&mdash; DanRaywood (@DanRaywood) <a href="https://twitter.com/DanRaywood/status/999638069874692096?ref_src=twsrc%5Etfw">May 24, 2018</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2018/05/24/826/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>#GDPR Press Briefing in City, University of #London</title>
		<link>https://jollyvip.com/edisclosure/2018/04/22/gdpr-press-briefing-in-city-university-of-london/</link>
		<comments>https://jollyvip.com/edisclosure/2018/04/22/gdpr-press-briefing-in-city-university-of-london/#comments</comments>
		<pubDate>Sun, 22 Apr 2018 09:20:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[Data Protection and Privacy]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[privacy harm]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=799</guid>
		<description><![CDATA[On 17th April 2018, I was one of the speakers in the GDPR Press Briefing held at City, University of London (City). Checkout the hot off the press &#8216;City academics discuss GDPR at press briefing&#8217; My written prepared talk is shared below. Privacy and the Individual &#8211; What difference will GDPR Make? Thanks John for [...]]]></description>
			<content:encoded><![CDATA[<p>On 17th April 2018, I was one of the speakers in the GDPR Press Briefing held at City, University of London (City). Checkout the hot off the press <a href="https://www.city.ac.uk/news/2018/april/city-academics-discuss-gdpr-at-press-briefing" title="City academics discuss GDPR at press briefing" target="_blank">&#8216;City academics discuss GDPR at press briefing&#8217;</a></p>
<p><strong>My written prepared talk is shared below.</strong></p>
<p>Privacy and the Individual &#8211; What difference will GDPR Make?</p>
<p>Thanks John for the introduction. A warm welcome to all.</p>
<p>Any talk on privacy and the GDPR invariably uses terms or phrases that may be blurry or obscure. So just to set the scene, when I say the ICO I&#8217;m referring to the UK&#8217;s data protection watchdog &#8211; The Information Commissioner&#8217;s Office. When I say &#8216;data&#8217; I&#8217;m referring to personal data as described in the GDPR. </p>
<p>Although the GDPR did not reference privacy &#8211; itself a complex term, privacy is embedded as information or data privacy and expressed in phrases such as:<br />
<em>&#8216;respect for human rights and fundamental freedoms (Art. 12 &#8211; exercise of the rights of the data subject); &#8216;High risk to the rights and freedoms of natural persons&#8217; (Art. 35 -Data protection impact assessment), and &#8216;Risks to the rights and freedoms of natural persons (individuals)&#8217; (Recital 75).</em>  </p>
<p>It is no longer just about protecting personal data or processing of personal data but <strong>data privacy.</strong></p>
<p><strong>With this comes obscure or unclear terms.</strong></p>
<p>What is &#8216;high risk&#8217;? How do you express &#8216;rights and freedoms&#8217; of natural persons (individuals) especially in the context of privacy impact assessment (PIA) or data protection impact assessment (DPIA)? </p>
<p>We know that the GDPR describes DPIA (Art. 35) and also breach notification (Art. 33 &#8211; notify the ICO, and Art. 34 &#8211; communicate to the data subjects).</p>
<p>I know fresh in our minds is the recent Facebook-Cambridge Analytica scandal. Flashback to October 2015, anyone here still remembers the TalkTalk data breach incident? </p>
<p>Would you all agree that both Facebook &#038; TalkTalk responded or handled the data breach announcement or notification to affected individuals rather badly or failed to do so in the eyes of the public and the affected individuals? </p>
<p>Certainly, under the GDPR both would be required to notify the ICO within 72 hours and to affected UK individuals without undue delay or &#8216;as soon as possible&#8217; (<a href="http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612052" title="wp250rev.01" target="_blank">Guidelines on Personal data breach notification under Regulation 2016/679)</a></p>
<p>As we know the GDPR requires organisations to notify the ICO where there is a risk to the rights and freedoms of individuals, and only notify the individuals where there is high risk.</p>
<p>My research examines data incidents response, in particular, the privacy harm to individuals as a consequence of the data incident. I have designed a <strong>prototype dashboard</strong> and have conducted user evaluation study with industry practitioners. The dashboard is for assessing privacy data harm by addressing the initial breach notification question to notify or not affected individuals and to the ICO during initial data incident response. </p>
<p>There is still fear in organisations when it comes to disclosure of data incidents. However, the GDPR will held organisations accountable e.g. with the fines and penalties, and to be transparent to report data incidents. Affected individuals have the right to know.</p>
<p>The outcome of my study also revealed that it is possible to do an initial data breach assessment even with the unclear terms: &#8216;high risk&#8217; and the &#8216;rights and freedoms&#8217; of individuals. The prototype dashboard also shows notification alerts with the countdown to 72 hrs from the point of being aware of the incident. One participant remarked: &#8216;<em>It (the dashboard) provides a calm objectivity in time of panic &#038; stress. Because you&#8217;re going to be stressed, you immediately think your personal reputation and your organisation&#8217;s reputation. Would we be fined? And all these things come in rather than actual thinking of the consequences to individuals&#8217;.</em> </p>
<p>When the data incident happened, the genie was out of the bottle, out in the wild &#8211; the harm was already done. </p>
<p>The GDPR would not bring the genie back into the bottle or stop the harm. So as a matter of good business practice and in the spirit of the law, organisations should notify their customers. </p>
<p>Thank you.<br />
Cher<br />
p.s.<br />
May post a photo taken by John Stevenson (City&#8217;s Senior Communications Officer)</p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2018/04/22/gdpr-press-briefing-in-city-university-of-london/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymisation &amp; GDPR</title>
		<link>https://jollyvip.com/edisclosure/2018/03/30/anonymisation-gdpr/</link>
		<comments>https://jollyvip.com/edisclosure/2018/03/30/anonymisation-gdpr/#comments</comments>
		<pubDate>Fri, 30 Mar 2018 13:09:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[2018]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://jollyvip.com/edisclosure/?p=777</guid>
		<description><![CDATA[Yesterday evening, 29th March 2018 I attended a BCS Law Specialist Group event &#8211; GDPR: Anonymisation,re-identification risk and GDPR profiling. The talk was presented by Dr. Amandine Jambert from the French Data Authority CNIL. The anonymisation slide is interesting. I asked whether the WP29 thinking (&#038; their opinions) about the 3 properties are for the [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday evening, 29th March 2018 I attended a BCS Law Specialist Group event &#8211; GDPR: Anonymisation,re-identification risk and GDPR profiling. The talk was presented by Dr. Amandine Jambert from the French Data Authority CNIL. The anonymisation slide is interesting.<a href="http://jollyvip.com/research/files/2018/03/anonymisation.png"><img src="http://jollyvip.com/research/files/2018/03/anonymisation.png" alt="" title="anonymisation" width="500" height="355" class="aligncenter size-full wp-image-1170" /></a></p>
<p>I asked whether the WP29 thinking (&#038; their opinions) about the 3 properties are for the &#8216;direct and indirect&#8217; way of identification of the personal data. The answer was not in the method itself but that the properties are for &#8216;all data types&#8217; i.e. any dataset. Her exact wordings &#8216; use by anyone on any dataset&#8217;. Also, the DPA (DPO/Organisation?) needs to prove (or justify or show) that the dataset has indeed been anonymised (using any of the 2 options). My understanding is that the anonymisation if done (risk-based, database and/or algorithmic-driven) should not enable the direct and indirect re-identification of the individual(s).<br />
As noted on this slide:<a href="http://jollyvip.com/research/files/2018/03/evaluation-table.png"><img src="http://jollyvip.com/research/files/2018/03/evaluation-table.png" alt="" title="evaluation table" width="515" height="357" class="aligncenter size-full wp-image-1171" /></a> &#8216;No single technique eliminates all risks&#8217;. </p>
<p>It&#8217;s near impossible to identify/isolate &#8216;all the direct/indirect re-identification risks&#8217; associated with any dataset, assuming the dataset is available and not hidden in some Cloud and/or in a chain of hidden registers.</p>
<p>We really need to re-think personal data in terms of &#8216;the harm to individuals&#8217; as there&#8217;s no absolutely sure way of preventing re-identification risks (i.e. singling out, linkability or inference/deduction etc.)</p>
<p>Overall a great talk.</p>
<p>I just noticed the slides and talk are available <a href="https://bcs.cloud.panopto.eu/Panopto/Pages/Viewer.aspx?id=d8162ce3-9830-4fbb-8ecc-a89601736df8" title="BCS Law" target="_blank">online: BCS Law talk 29th March 2018</a></p>
]]></content:encoded>
			<wfw:commentRss>https://jollyvip.com/edisclosure/2018/03/30/anonymisation-gdpr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
