EPDP policy issues - [adding Kathy]

Mueller, Milton L milton at GATECH.EDU
Tue Apr 27 14:35:42 EEST 2021


Mark,
Thanks for your intervention. Here is the complete definition of personal data in GDPR:
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Alas, this raises more questions than it answers. It is not entirely clear what “relating to” means in this construct. E.g., if the name of my company is Milton Mueller’s Porkbelly Diner, is the name relating to me as a person, or to my business? Strictly speaking it’s a business name. But it could be used to identify me. An overly broad interpretation of this definition would classify ANY data about ANYTHING as “personal data” because at some point it could be “related to” an “identifiable natural person.” So suddenly the business name becomes personal data. Or a bunch of obscure technical indicators inherent in your use of the internet, such as port numbers, browser config, etc., could be “related” to your ISP account number, and then used to identify you, personally. But does that mean that every website and hosting service in the world that uses that technical data in the course of their operations cannot process that info without your explicit permission, because it’s “personal data?” I hope not, because the internet would cease to function if so.

>Therefore, info at myorg.org<mailto:info at myorg.org> is personal data if someone behind it is identifiable.

My point is that whether the user of info at myorg.org<mailto:info at myorg.org> is identifiable does not depend on that chunk of data, but on a bunch of activities that relate that data to other things. And in a digital world with powerful processing capabilities, no one can fully control those correlations and searches. Any attempt to do so simply cripples the entire information economy. So the idea of looking at a registration record and saying “is there personal data in here or not” is a completely invalid test.

There is an eerie similarity between these exaggerated applications of privacy law and the copyright maximalists of the 1990s. The IP interests thought you needed permission to transmit a copyrighted work over the internet, a claim that would have crippled ISPs who had no idea what packets were parts of copyrighted material or not. Privacy maximalists have reached the same point of absurdity, but they don’t seem to realize it. They are no longer protecting a tangible privacy interest of internet users, they are trying to give individuals rigid control over information exchanges and imposing largely meaningless consent requirements that do no one any good.

>The confusion comes from Recital 14 of the GDPR which states that it only applies to natural persons and does not cover the processing of personal data concerning legal persons, in particular undertakings established as legal persons or legal entities. This also includes the name of the legal person, the form, and the contact details of the legal person. But the second you start adding identifiers to these details, it stops becoming the data of a 'legal person' and starts becoming personal data.

Yes, indeed, the GDPR is confused on this score. Unfortunately, you don’t escape that confusion by saying “adding identifiers” is the problem. Your argument fails because names of legal persons and contact details ARE “identifiers,” they are just identifiers of legal persons. As I pointed out they can easily overlap with, or be used to identify, natural persons.

So my basic point is that we do not solve this problem by reference to GDPR definitions. In fact if GDPR is taken literally no one can ever publish and share any kind of information without absurd overhead and legal bureaucracy, because ALL of it can be used to identify you in some way. These kinds of interpretations actually discredit privacy laws and protections, by taking them to counterproductive lengths. We have to make common sense-based, practical distinctions between what data needs protection, what data can be easily shared at the registrants’ choice.

Secondly, I find this statement, "I think it is simplest to just say to the registrant, if you’re a company and don’t mind (or even want) your data to be published, check this box. If you’re not, or you do mind, don’t check it."  to be BOTH perplexing and inaccurate.  Whether someone checks the box, or does not check the box is completely irrelevant for determining whether it is personal data. Whether someone checks the box is a question of CONSENT to processing AND publication, not whether this amounts to personal data.

We actually seem to agree here, more than you think. I am saying that the user, the registrant, gets to decide what is personal data or not, because THERE IS NO OBJECTIVE, CLEAR LEGAL DEFINITION. So the user can decide whether they want to be classified as a legal person and “consent” to publishing their data or not. As an example, that if I decide that publishing the name of “Milton Mueller’s Porkbelly Diner” is not a violation of my privacy, it isn’t. It doesn’t matter what the European Union says, it’s my choice.

And let’s not overlook the embarrassing fact that the European Union is now one of the key players pushing hard for publication of legal person data. But I’ll leave that one to later.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210427/10977743/attachment.htm>


More information about the Ncsg-discuss mailing list