Data protection versus Corona?

How did our privacy brave the slings and arrows of the COVID19-pandemic? Actually, it could be worse, according to the speakers at the Privacy Focus Group session. However…

‘How do data protection rights fare in Corona times?’ was the subject of the Privacy Focus Group session on the very day of the GDPR’s third implementation anniversary. Clearly, there have been plenty of sticky situations, but privacy professionals have rising to the challenge and have proven to be able to cope and help!

Not that there weren’t problems galore. Mrs. Alexandra Jaspar, director of the ‘knowledge centre’ of the Belgian Data Protection Authority (DPA) sketched an overview of the often uphill battle to defend the privacy rights of the Belgian citizens against weakly defined and all too broad COVID19-decrees and -measures of governments at all levels. All laws and decrees must be submitted to the DPA’s knowledge centre for mandatory advice, but this was on quite a few occasions evaded. Furthermore, this advice is non-binding, and till today there is no agreement in the management committee of the DPA to launch inquiries into practices of governments that breach the privacy regulation!

Mrs. Jaspar illustrated her frustrated efforts with examples from the 32 pieces of advice on ‘Corona’ draft-bills and –regulations (all of them published on the site of the DPA, along with other key COVID19-privacy information). The DPA also published sorely needed guidelines, without being requested to do so (e.g., the ‘horeca’ contact tracing data gathering). Several examples concern the ‘vaccination’ laws and measures, with among others a one-article law (‘fully delegating powers to the government’ – Antigenics law of December 22nd 2020) and the royal decree of December 24th 2020 (e.g., ‘vaguely defined purpose’, ‘no relation between data and purposes’, ‘no necessity and proportionality test possible’, ‘retention period too long’…). Or consider the objections to the ‘Pandemic’-law. Advice? Do check this presentation for some eye-openers.

Employers, too, had to strike a balance between their obligations regarding the welfare of their employees and privacy protection. In her presentation ‘Data protection in Corona times, an HR perspective’, Mrs. Sara Cockx, partner at Schoups, provided some examples of the tension between these obligations (with potential criminal convictions, if neglected) and privacy. Indeed, processing of health-related data is basically not allowed, and asking employees for consent is not acceptable. That leaves the employer with challenges regarding COVID19-classics as for example taking temperature measurements (a ‘no go’, unless temperature values and other data are not registered/kept), or learning whether an employee has taken ill (no obligatory reporting to the employer, but employees have responsibilities towards their co-workers) and more. Regarding vaccination, employers cannot demand vaccination (fundamental freedom of choice), but they are encouraged to inform employees about the advisability of vaccination. A differential treatment of vaccinated and non-vaccinated personnel is also not allowed (non-discrimination) though possibilities perhaps exist in the realm of absenteeism bonuses. Other COVID19-induced challenges include rules regarding teleworking (e.g., teleworking from somebody’s holiday residence; teleworking from abroad with possible data transfers outside EU), work monitoring (beware of CBA 81), and smart office initiatives (reservation data processing). Nevertheless, “privacy and employer obligations can be reconciled!” Indeed, this was yet another interesting presentation with plenty of practical pointers.

Perhaps the strongest concerns were expressed in the presentation ‘How do data protection rights fare in Corona times’ of Prof. Paul De Hert (VUB/U Tilburg, and co-organizer of the CPDP privacy event). Yes, “the discussion on the COVID19 tracing-app was a golden one for the data protection community, since it allowed to do the things we like to do: checking on legality and appropriate safeguards.” Or, “everybody as DPAs, DPOs, etc. didn’t do too badly.” But…

Laws as the GDPR are too vague about technologies, with plenty of exceptions, particularly favouring all kinds of data processing by authorities. A major danger is governments getting away with the introduction of privacy threatening technologies in a covert way, often without asking for privacy-related advice. That is particularly problematic when done by people with less affinity with privacy laws. As a result, previous technocratic-oriented governments and authorities at all levels have already taken initiatives that create a surveillance architecture in our society. It worries Prof. De Hert that warnings expressed in articles in, for example, Le Soir are barely considered worthy of attention in other parts of the country. While denying intentions for a ‘surveillance society’, authorities at a lower and decentralized level are encouraged to install technology such as cameras through hefty subsidizing (cf. the 2017 Camera Law of Jambon).

How was this possible? Few understand what’s happening, it is a highly technocratic matter, and much is implemented by non-political and little known organizations… Clearly, there is a need for a ‘broader democratic testing’ of what is happening, with more political governance of technology, and laws with less technology-neutral language. Clearly, this is another presentation demanding your attention.

Nos autres articles

30 November: Computer Security Day: Ada Lovelace

On computer security day we pay tribute to Ada Lovelace, the forgotten mother of the computer. Often described as the first computer programmer — before computers were even invented — Ada was a real visionary. Imagine what she might have achieved had Babbage actually built his “computer” and she hadn’t died at the age of 36.

Privacy Focus Group: AI and Data Protection

The second webinar of the Privacy Focus Group on the subject of ‘Artificial Intelligence’ (AI) tackles a major challenge: how to reconcile the use of AI with the demands of GDPR, particularly regarding data protection? It is still very much unknown territory for developers, users and privacy protection officers. This webinar helps you find your way!

API Security

API’s (Application Programming Interfaces) are ubiquitous and used to interconnect all our popular web applications. Without API’s, applications cannot communicate and we would simply not be able to use the majority of the current cloud and web applications. But at the same time, because of these API’s, security threats are greater than ever. API attacks are different compared to traditional attacks: they target vulnerabilities in the business logic, and hackers exploit these zero-day vulnerabilities.

Privacy Focus Group: AI : Basic concepts and regulatory trends

This webinar organized by the Privacy Focus Group in cooperation with KU Leuven helps you gain a much-needed insight in the hot topic of Artificial Intelligence (AI). It gives an overview of the different types of AI applications and points to the ethical and societal implications of the use of such applications. It is a splendid starting point to delve deeper into the fascinating world of AI.

Partagez ce contenu avec votre réseau :