EPDP policy issues - [adding Kathy]

Mark Leiser markleiser at GMAIL.COM
Tue Apr 27 15:40:32 EEST 2021


Hi Milton,

First let me say I completely agree with you on your statements about
European data privacy. I feel like I've dedicated most of my professional
life arguing about the dangers of privacy and data protection maximalism -
yet almost always feel like my arguments on deaf ears. While people are
arguing that 'everything is personal data', I've been arguing that this
makes the regime unmanageable.

So let me try to explain 'relating to' with reference to 'Milton Mueller's
Porkbelly Diner'. Because of Recital 14, this would amount to a legal
person. It's pretty clear that the intention of the GDPR's drafters was to
exclude legal persons. However, let's say you have registered 'MM Porkbelly
Diner' in the register of companies. I think you would agree that this
would amount to information about a legal person. But say someone searched
the company register and discovered Milton Mueller was the principal
shareholder of MM Porkbelly Diner. This is an identifier which would *tie
nformation about Milton Mueller to* 'MM PorkBelly Diner'. Therefore, this
is 'any information' 'relating to' an identified or identifiable living
person. It would be reasonable to infer that MM registered in the registrar
database under MM PorkBelly Diner is the same as the Milton Mueller that is
in the register of companies. The fact that someone can combine the
knowledge from the company register with the knowledge from the registrar
database could make 'MM Porkbelly Diner' personal data under Article 4(1)
of the GDPR. Someone who did not disclose their identity at all could still
be identifiable; hence, the perceived need for protection in the EU data
protection regime.

 "I am saying that the user, the registrant, gets to decide what is
personal data or not, because THERE IS NO OBJECTIVE, CLEAR LEGAL
DEFINITION" is, on the surface, problematic. It doesn't matter whether the
user says NO or YES or the registrar says no or yes, or whether it is
objective or clear, the test is whether any information can be combined
with other information to reveal an identifiable living person. I would
argue, absent a wholesale change in the reasoning used by the CJEU, this
would remain the case for the foreseeable future. This is not intended as a
Mark Leiser argument or an attempt to discredit what you are saying, but an
honest account of how I think the Courts and the EU data protection Board
would react to what you are proposing.

You asked about IP addresses
<https://iapp.org/news/a/are-ip-addresses-generated-when-users-visit-websites-personal-information/#:~:text=Under%20the%20EU%20General%20Data,header%20information%20that%20website%20hosts>,
'port numbers', 'browser config', etc could be used to identify you
personally. Yes, absolutely. This is personal data in the EU - if it can
relate to a living person. What your writing here reveals, is that you are
a little confused about how the GDPR works - the GDPR does not rely on
'consent' or 'explicit permission' as the only basis for processing
personal data. Remember the GDPR has six grounds of processing
<https://gdpr-info.eu/art-6-gdpr/>. It is a prohibitive regulation. You
cannot process personal data in the EU unless you satisfy one of those six
grounds. Most companies will NOT be processing on the basis of 'consent'
but on 'legitimate interests' (Article 6(1)(f)) or performance of a
contract (Article 6(1)(b)). Don't worry, this is an extremely common
mistake among American attorneys! As most of these items are "technical', I
would also imagine that there is a 'legal requirement' (another ground) or
a lawful basis. All ISPs will be processing personal data through 'IP
addresses', 'port browsers', and 'browser config' because of the legal
basis found in Article 15 of the e-Privacy Directive
<https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN>
which
provides Member States with a specific exemption for the purposes of
national security. If not covered by this, I would imagine they would rely
on 'legitimate interests' as their ground instead.

Finally, even if a registrar has a legitimate interest in processing
someone's personal data, this does not address the *privacy *requirements
that i indicated in my previous email. Unless there is a specific provision
put into law, I do not know how the registrar can remain compliant with the
GDPR and the EU's privacy requirements. In fact, I don't know how the EU
can even comment on this, because, of course, the EU Charter is a legal
framework completely distinct from the European Convention of Human Rights.

One more thing to consider - if you choose to disclose your name, address,
and designate as the contact person of a legal person, what happens when
that person exercises their 'right to be forgotten' right under Article 17
GDPR. Maybe Milton Mueller the person chooses to leave the legal entity MM
Porkbelly Diner, adopts a vegan lifestyle, and wants no affiliation with
the business? If it's published, he can demand a correction of the database
thereof. So what then?

Regards,

Mark

*Dr Mark Leiser | Law and Digital Technologies | FRSA FHEA |*


On Tue, 27 Apr 2021 at 20:35, Mueller, Milton L <milton at gatech.edu> wrote:

> Mark,
>
> Thanks for your intervention. Here is the complete definition of personal
> data in GDPR:
>
> ‘personal data’ means any information relating to an identified or
> identifiable natural person (‘data subject’); an identifiable natural
> person is one who can be identified, directly or indirectly, in particular
> by reference to an identifier such as a name, an identification number,
> location data, an online identifier or to one or more factors specific to
> the physical, physiological, genetic, mental, economic, cultural or social
> identity of that natural person;
>
> Alas, this raises more questions than it answers. It is not entirely clear
> what “relating to” means in this construct. E.g., if the name of my company
> is Milton Mueller’s Porkbelly Diner, is the name relating to me as a
> person, or to my business? Strictly speaking it’s a business name. But it
> could be used to identify me. An overly broad interpretation of this
> definition would classify ANY data about ANYTHING as “personal data”
> because at some point it could be “related to” an “identifiable natural
> person.” So suddenly the business name becomes personal data. Or a bunch of
> obscure technical indicators inherent in your use of the internet, such as
> port numbers, browser config, etc., could be “related” to your ISP account
> number, and then used to identify you, personally. But does that mean that
> every website and hosting service in the world that uses that technical
> data in the course of their operations cannot process that info without
> your explicit permission, because it’s “personal data?” I hope not, because
> the internet would cease to function if so.
>
>
>
> >Therefore, info at myorg.org is personal data if someone behind it is
> identifiable.
>
>
>
> My point is that whether the user of info at myorg.org is identifiable does
> not depend on that chunk of data, but on a bunch of activities that relate
> that data to other things. And in a digital world with powerful processing
> capabilities, no one can fully control those correlations and searches. Any
> attempt to do so simply cripples the entire information economy. So the
> idea of looking at a registration record and saying “is there personal data
> in here or not” is a completely invalid test.
>
>
>
> There is an eerie similarity between these exaggerated applications of
> privacy law and the copyright maximalists of the 1990s. The IP interests
> thought you needed permission to transmit a copyrighted work over the
> internet, a claim that would have crippled ISPs who had no idea what
> packets were parts of copyrighted material or not. Privacy maximalists have
> reached the same point of absurdity, but they don’t seem to realize it.
> They are no longer protecting a tangible privacy interest of internet
> users, they are trying to give individuals rigid control over information
> exchanges and imposing largely meaningless consent requirements that do no
> one any good.
>
>
>
> >The confusion comes from Recital 14 of the GDPR which states that it
> only applies to natural persons and does not cover the processing of
> personal data concerning legal persons, in particular undertakings
> established as legal persons or legal entities. This also includes the name
> of the legal person, the form, and the contact details of the legal person. But
> the second you start adding identifiers to these details, it stops becoming
> the data of a 'legal person' and starts becoming personal data.
>
>
>
> Yes, indeed, the GDPR is confused on this score. Unfortunately, you don’t
> escape that confusion by saying “adding identifiers” is the problem. Your
> argument fails because names of legal persons and contact details ARE
> “identifiers,” they are just identifiers of legal persons. As I pointed out
> they can easily overlap with, or be used to identify, natural persons.
>
>
>
> So my basic point is that we do not solve this problem by reference to
> GDPR definitions. In fact if GDPR is taken literally no one can ever
> publish and share any kind of information without absurd overhead and legal
> bureaucracy, because ALL of it can be used to identify you in some way.
> These kinds of interpretations actually discredit privacy laws and
> protections, by taking them to counterproductive lengths. We have to make
> common sense-based, practical distinctions between what data needs
> protection, what data can be easily shared at the registrants’ choice.
>
>
>
> Secondly, I find this statement, "I think it is simplest to just say to
> the registrant, if you’re a company and don’t mind (or even want) your data
> to be published, check this box. If you’re not, or you do mind, don’t check
> it."  to be BOTH perplexing and inaccurate.  Whether someone checks the
> box, or does not check the box is completely irrelevant for determining
> whether it is personal data. Whether someone checks the box is a question
> of CONSENT to processing AND publication, not whether this amounts to
> personal data.
>
>
>
> We actually seem to agree here, more than you think. I am saying that the
> user, the registrant, gets to decide what is personal data or not, because
> THERE IS NO OBJECTIVE, CLEAR LEGAL DEFINITION. So the user can decide
> whether they want to be classified as a legal person and “consent” to
> publishing their data or not. As an example, that if I decide that
> publishing the name of “Milton Mueller’s Porkbelly Diner” is not a
> violation of my privacy, it isn’t. It doesn’t matter what the European
> Union says, it’s my choice.
>
>
>
> And let’s not overlook the embarrassing fact that the European Union is
> now one of the key players pushing hard for publication of legal person
> data. But I’ll leave that one to later.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20210427/4ada9794/attachment.htm>


More information about the Ncsg-discuss mailing list