Authors
Max Von Grafenstein, Timo Jakobi, Gunnar Stevens
Publication date
2022/9/1
Journal
Computer Law & Security Review
Volume
46
Pages
105722
Publisher
Elsevier Advanced Technology
Description
While the recent discussion on Art. 25 GDPR often considers the approach of data protection by design as an innovative idea, the notion of making data protection law more effective through requiring the data controller to implement the legal norms into the processing design is almost as old as the data protection debate. However, there is another, more recent shift in establishing the data protection by design approach through law, which is not yet understood to its fullest extent in the debate. Art. 25 GDPR requires the controller to not only implement the legal norms into the processing design but to do so in an effective manner. By explicitly declaring the effectiveness of the protection measures to be the legally required result, the legislator inevitably raises the question of which methods can be used to test and assure such efficacy. In our opinion, extending the legal compatibility assessment to the real effects of the …
Total citations
20212022202320244153