SlideShare a Scribd company logo
Dr David Erdos
Faculty of Law
University of Cambridge
Disclosure
Exposure
Introduction
 Google Spain described as a “clear victory for the protection of
personal data of Europeans” (Reding, 2014).
 Over 1.5m URLs have be delisted by Google alone to date.
 But are concerns that not fully/properly implemented.
 Presentation seeks to interrogate Google’s practice of notifying
deindexing decisions/URLs to webmasters (& also removals of
personal data to Lumen ‘research’ database & end users.)
DPA Action on Webmaster Notification
 A29 Working Party Guidelines (2014):
 Routine webmaster notification illegal (confirmed by EDPB 2019).
 In “particularly difficult cases” may be legitimate ex ante.
 Must be “all necessary measures” to safeguard subject rights.
 Spanish DPA Resolución R/02232/2016:
 Followed-up specific complaint about disclosure.
 Confirmed illegality.
 Issued €150K fine & injunction against future repeat.
 Google mounted legal challenge to this Resolution.
Google’s Legal Challenge
 Administrative Law Claim:
 Sanctioning Procedure wrongly established general position.
 Substantive Law Claims:
 No (new) personal data disclosed.
 Notification done with data subject consent.
 Even if not, has overriding legitimacy.
 Notification is anyway a legal obligation under DP.
 2019 (April): Spanish High Court supports admin claim.
 2020: Likely appeal to Spanish Supreme Court (& ?CJEU).
No (New) Personal Data & Have Consent?
 Google’s Claims:
 URL strings generally don’t include identified details.
 Even if do, would be known to webmaster (so not new).
 Anyway get subject’s agreement on webform.
 Why Claims are Wrong:
 Personal data covers identifiable not just identified data.
 Need to look at all means reasonably likely including use of
“additional information” (GDPR, Recital 26).
 Very simple means will identify including fact of deindexing.
 Finally, agreement not consent as tie to exercise of fundamental
right is clearly not “freely given” (GDPR, art. 4(11)).
Overriding Legitimacy of Notification?
 Focus has been on finding (another) ordinary legal basis.
 But purpose limitation principle (GDPR, art. 5(1)(b); 6(4))
most critical as data collected for a very particular purpose.
 Also may need to consider:
 Special legal basis where sensitive/special data (Ibid, art. 9-10)
 Data transfer legal basis where trans-border flow (Ibid, Ch. V)
Purpose Limitation = Purpose Quality Plus:
Compatible
Processing
(art. 6(4))
Link between
purposes
Context of
Collection
Nature of data
Possible
Consequences
Safeguards
Context of Collection & Nature of Data
 Context of Collection (GDPR, art. 6(4)(b)):
 Means to exercise fundamental right (& discharge legal duty).
 Massive power imbalance.
 No genuine freedom of choice.
 Nature of Personal Data (GDPR, art. 6(4)(c)):
 May be sensitive/special e.g. if concern health, sex life or crime.
 Even if not then highly likely to be stigmatic and/or misleading.
 Furthermore, deindexing claim itself is clearly private.
Link between Purposes? Core Purpose
 Purpose of notification is not defined.
 But webform (from Sept. 2015) implicitly suggests core purpose
is to help ensure deindexing decision correct.
 Would appear to be strong link with initial purpose but:
 Is this legitimate where ex post rather than ex ante?
 Is this credible where blanket notification – shouldn’t Google show
that necessary and proportionate case-by-case?
 Even where valid, would still need safeguards to protect
from adverse consequences.
Link between Purposes? Other Purposes
 At least some webmasters may desire to use data to:
 Exact revenge on data subject.
 Damage reputation of data subject.
 Publicize nature of deindexing decisions.
 With exception of safeguarded research, clearly not compatible:
 No positive link with initial purpose at all.
 Likely to directly undermine chances of data “sink[ing] into oblivion”.
 May even result in re-indexing of material.
 Wave of new publicity likely worse & may well chill use of right.
 Unfortunately, plenty of evidence of such processing eventuating with
clear adverse consequences for data subjects.
Webmaster notification  New Publicity
Appropriate Safeguards (GDPR, art. 6(4)(e))?
 Purpose limitations must clearly be specified to webmaster and
disclosure only following legal agreement to abide by these.
 Given risk of grave & irreparable damage must also consider specific
measures to counter deliberate disclosure.
 Suspension of cooperation for period may work for big players such as
the BBC and Facebook.
 Small players e.g. amateur blogs present greater challenge.
Ordinary Legal Basis for Processing (art. 6(1))
 In principle additional to compliance with DP Principles but
GDPR Recital 50 states that if purpose compatibility satisfied
then no “separate” legal basis required, although “rights,
including the right to object, should be ensured”.
 Two possible bases have been mooted:
 “necessary for compliance with a legal obligation”
 “necessary for legitimate interests … except where … overridden”
 Both flag requirement that disclosure necessary.
 Second basis would also trigger right to object – must take
into account opposition & show really compelling grounds.
Special Legal Grounds for Processing
 Deindexing claim may well be sensitive data e.g. if it concerns a
health or sex life matter.
 This triggers a default prohibition.
 Claim clearly not made public & processing not with consent.
 Must therefore rely on ̒public interest̕grounds:
 Criminal-related data (also special data) likely governed similarly.
“ necessary for the establishment, exercise or defence of legal claims”
(GDPR, art. 9(2)(f))
“ necessary for … research purposes or statistical purposes … based on Union or
Member State law which shall be proportionate … and provide for suitable and
specific measures to safeguard” (GPDR, art. 9(2)(j))
Legal Grounds for Data Transfers
 Webmaster disclosure will often be to controller based overseas.
 Unless State deemed “adequate”, then default prohibition.
 In principle may also be lifted where:
 But Google has obligation to choose least derogatory option:
 Should therefore generally make use of Commission’s standard
contractual clauses (GDPR, art. 46(2)(d)).
“ necessary for the establishment, exercise or defence of legal claims”
(GDPR, art. 49(1)(d))
“ the controller or process should make use of solutions that provide data subjects
with enforceable and effective rights as regards the processing of their data in the
Union” (GDPR, recital 114)
Notification Obligations under DP
 Google has suggested two specific provisions require it to disclose.
 Article 19 (modified from DPD) flows generally from erasure etc.:
 Article 17(2) instantiates GDPR’s new “right to be forgotten”:
“Where the controller has made the personal data public and is obliged
pursuant to paragraph 1 to erase the personal data, the controller … shall
take reasonable steps … to inform controllers which are processing the
personal data that the data subject has requested the erasure by such
controllers”
“The controller shall communicate any rectification or erasure or personal
data or restriction of processing carried out in accordance with Article 16,
Article 17(1) and Articles 18 to whom the personal data have been disclosed,
unless this proves impossible or involves a disproportionate effort.”
Why Webmaster Notification not Obligation
 Narrow Argument:
  Article 19 as webmasters are source not recipient of data.
  Article 17(2) as webmasters not search engines make public.
  Article 17(2) only triggered where subject requests action.
 Middle Argument:
 Deindexing is best seen as exercise of right to object (art. 21).
 Broadest Argument:
 These “right of the data subject” are all aimed at protecting
autonomy and safeguarding this individual.
 Other actions always “disproportionate” (art. 19) & not a
“reasonable step” (art. 17(2)) in context.
Other Forms of Disclosure
 Disclosure to Lumen/Chilling Effects:
 Clear Google discloses personal data as regards removal under
defamation, civil/traditional privacy.
 States likely to so in the future as regards deindexing.
 Disclosure to End Users:
 Information on deindexing has been largely generic.
 But individualised disclosure including via link to Lumen
resorted to for defamation, civil/traditional privacy etc.
Other Forms of Disclosure: Legal Analysis
 Disclosure to End Users:
 Directly undermines rights & so violates purpose compatibility.
 Unlikely legitimate interest in receipt & certain not overriding.
 Shouldn’t matter if rights are in defamation, civil privacy or DP.
 Disclosure to Lumen/Chilling Effects:
 States is an “independent research project” – may be questioned!
 Scientific research can in principle satisfy purpose limitation.
 But subject to legal grounds and “appropriate safeguards”
which rule out (negative) measures against data subject.
 Google’s disclosure & Lumen’s processing clearly fails these
safeguards.
Conclusions
 Google’s blanket webmaster notification unlawful, as is
disclosure of personal data on removals to Lumen & end users.
 Targeted notification can be lawful where:
 Purpose of better resolving claim and/or scientific research.
 Processing is reasonably necessary (and strictly if objection or
special data).
 Effective measures taken to prevent re-purposing (& further
protect subject where international transfer).
 Current disclosure practices are a serious threat to the Google Spain
ruling and so resolving this should be a priority for EDPB & EU DPAs.

More Related Content

What's hot

Replacement standard contractual clauses
Replacement standard contractual clausesReplacement standard contractual clauses
Replacement standard contractual clauses
Brian Miller, Solicitor
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
David Erdos
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
legalandgeneral
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
IISPEastMids
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
David Erdos
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
IISPEastMids
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
Ulf Mattsson
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
Faidepro
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search Engines
David Erdos
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
Nordic APIs
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
Matthias Dobbelaere-Welvaert
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
Ulf Mattsson
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
Claudio Bolla, CISM
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
Agile PR
 
Fasten Your Belts for #GDPR
Fasten Your Belts for #GDPRFasten Your Belts for #GDPR
Fasten Your Belts for #GDPR
"John "Jeb"" Beckwith
 

What's hot (20)

Replacement standard contractual clauses
Replacement standard contractual clausesReplacement standard contractual clauses
Replacement standard contractual clauses
 
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?The UK and EU Personal Data Regime After Brexit: Another Switzerland?
The UK and EU Personal Data Regime After Brexit: Another Switzerland?
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Reconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data ProtectionReconciling Humanities and Social Science Research With Data Protection
Reconciling Humanities and Social Science Research With Data Protection
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
European Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search EnginesEuropean Data Protection, the Right to be Forgotten and Search Engines
European Data Protection, the Right to be Forgotten and Search Engines
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.GDPR: the legal aspects. By Matthias of theJurists Europe.
GDPR: the legal aspects. By Matthias of theJurists Europe.
 
Privacy Access Letter I Feb 5 07
Privacy Access Letter I   Feb 5 07Privacy Access Letter I   Feb 5 07
Privacy Access Letter I Feb 5 07
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 
Fasten Your Belts for #GDPR
Fasten Your Belts for #GDPRFasten Your Belts for #GDPR
Fasten Your Belts for #GDPR
 

Similar to Disclosure, Exposure and the "Right to be Forgotten" After Google Spain

GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
Angad Dayal
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
DipanjanDey12
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with Varonis
Angad Dayal
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
brunomase
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
Tim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
Tim Hyman LLB
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
dan hyde
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
Stefan Schippers
 
Are You Prepared for the GDPR?
Are You Prepared for the GDPR?Are You Prepared for the GDPR?
Are You Prepared for the GDPR?
PrivacyPolicies.com
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal Data
Renato Monteiro
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
Morris Dorfer
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
Dryden Geary
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
amirhannan
 
GDPR
GDPRGDPR
GDPR
Gopi PD
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
Lava Consult BVBA
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
Dr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
Lilian Edwards
 
Information technology law
Information technology lawInformation technology law
Information technology law
Assignment Prime
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
Joseph V. Moreno
 

Similar to Disclosure, Exposure and the "Right to be Forgotten" After Google Spain (20)

GDPR - A practical guide
GDPR - A practical guideGDPR - A practical guide
GDPR - A practical guide
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR A Practical Guide with Varonis
GDPR A Practical Guide with VaronisGDPR A Practical Guide with Varonis
GDPR A Practical Guide with Varonis
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
Are You Prepared for the GDPR?
Are You Prepared for the GDPR?Are You Prepared for the GDPR?
Are You Prepared for the GDPR?
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal Data
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Practical Guide to GDPR 2017
Practical Guide to GDPR 2017Practical Guide to GDPR 2017
Practical Guide to GDPR 2017
 
Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018Slides dr farah jameel's gdpr presentation april 2018
Slides dr farah jameel's gdpr presentation april 2018
 
GDPR
GDPRGDPR
GDPR
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Information technology law
Information technology lawInformation technology law
Information technology law
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 

More from David Erdos

Regulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionRegulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data Protection
David Erdos
 
Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPR
David Erdos
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
David Erdos
 
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
David Erdos
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
David Erdos
 
The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and Beyond
David Erdos
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
David Erdos
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EU
David Erdos
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
David Erdos
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
David Erdos
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical Perspective
David Erdos
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
David Erdos
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
David Erdos
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in Conflict
David Erdos
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data Protection
David Erdos
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
David Erdos
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
David Erdos
 

More from David Erdos (17)

Regulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data ProtectionRegulatory Enforcement of UK Data Protection
Regulatory Enforcement of UK Data Protection
 
Generative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPRGenerative AI, Search Engines and GDPR
Generative AI, Search Engines and GDPR
 
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An  EU and UK GDPR PerspectiveGoogle Spain and its Aftermath 2014-2023: An  EU and UK GDPR Perspective
Google Spain and its Aftermath 2014-2023: An EU and UK GDPR Perspective
 
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
The Brexit Isles Alter Ego? Revisiting Ireland's Commonwealth Exit 1948-49
 
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
Data Protection Post-Brexit: Can the UK Craft a Credible New Approach?
 
The GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and BeyondThe GDPR and Journalism: Enforcement and Beyond
The GDPR and Journalism: Enforcement and Beyond
 
Data Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing LandscapeData Protection and Journalism: The Changing Landscape
Data Protection and Journalism: The Changing Landscape
 
Constitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EUConstitutional Privacy and Data Protection in the EU
Constitutional Privacy and Data Protection in the EU
 
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection LawDead Ringers? Legal Persons & the Deceased in European Data Protection Law
Dead Ringers? Legal Persons & the Deceased in European Data Protection Law
 
Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...Comparing EU and Council of Europe Data Protection Standards in the Context o...
Comparing EU and Council of Europe Data Protection Standards in the Context o...
 
Data Protection and "Intermediary" Responsibility: An Historical Perspective
Data Protection and "Intermediary" Responsibility:  An Historical PerspectiveData Protection and "Intermediary" Responsibility:  An Historical Perspective
Data Protection and "Intermediary" Responsibility: An Historical Perspective
 
UK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & ChangeUK & EU Freedom of Information & Data Protection: Continuity & Change
UK & EU Freedom of Information & Data Protection: Continuity & Change
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
 
Data Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in ConflictData Protection and Academia: Fundamental Rights in Conflict
Data Protection and Academia: Fundamental Rights in Conflict
 
Regulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data ProtectionRegulation of Medical Research under European Data Protection
Regulation of Medical Research under European Data Protection
 
New Media Internet Expression and European Data Protection
New Media Internet Expression and European Data ProtectionNew Media Internet Expression and European Data Protection
New Media Internet Expression and European Data Protection
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
 

Recently uploaded

Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
Knowyourright
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
9ib5wiwt
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
Trademark Quick
 
Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...
Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...
Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...
YashSingh373746
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
9ib5wiwt
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
9ib5wiwt
 
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
anjalidixit21
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Gabe Whitley
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
BridgeWest.eu
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
Wendy Couture
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
PelayoGilbert
 
Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
johncavitthouston
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
9ib5wiwt
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
Daffodil International University
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
akbarrasyid3
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
46adnanshahzad
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
ssuser5750e1
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
MattGardner52
 
The Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptxThe Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptx
nehatalele22st
 
Bharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptxBharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptx
ShivkumarIyer18
 

Recently uploaded (20)

Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....Car Accident Injury Do I Have a Case....
Car Accident Injury Do I Have a Case....
 
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
原版仿制(aut毕业证书)新西兰奥克兰理工大学毕业证文凭毕业证雅思成绩单原版一模一样
 
Secure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark TodaySecure Your Brand: File a Trademark Today
Secure Your Brand: File a Trademark Today
 
Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...
Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...
Consolidated_Analysis_report_(Phase_1_to_7)_of_Criminal_and_Financial_backgro...
 
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
办理(waikato毕业证书)新西兰怀卡托大学毕业证双学位证书原版一模一样
 
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
1比1制作(swansea毕业证书)英国斯旺西大学毕业证学位证书托业成绩单原版一模一样
 
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptxHighlights_of_Bhartiya_Nyaya_Sanhita.pptx
Highlights_of_Bhartiya_Nyaya_Sanhita.pptx
 
Abdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal CourtAbdul Hakim Shabazz Deposition Hearing in Federal Court
Abdul Hakim Shabazz Deposition Hearing in Federal Court
 
How to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the NetherlandsHow to Obtain Permanent Residency in the Netherlands
How to Obtain Permanent Residency in the Netherlands
 
Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)Business and Corporate Case Update (2024)
Business and Corporate Case Update (2024)
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
 
Roles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John CavittRoles of a Bankruptcy Lawyer John Cavitt
Roles of a Bankruptcy Lawyer John Cavitt
 
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
怎么购买(massey毕业证书)新西兰梅西大学毕业证学位证书注册证明信原版一模一样
 
ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.ADR in criminal proceeding in Bangladesh with global perspective.
ADR in criminal proceeding in Bangladesh with global perspective.
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (28 Mei 2024).pdf
 
ALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdfALL EYES ON RAFAH BUT WHY Explain more.pdf
ALL EYES ON RAFAH BUT WHY Explain more.pdf
 
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdfDonald_J_Trump_katigoritirio_stormi_daniels.pdf
Donald_J_Trump_katigoritirio_stormi_daniels.pdf
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
 
The Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptxThe Reserve Bank of India Act, 1934.pptx
The Reserve Bank of India Act, 1934.pptx
 
Bharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptxBharatiya Nagarik Suraksha Sanhita power.pptx
Bharatiya Nagarik Suraksha Sanhita power.pptx
 

Disclosure, Exposure and the "Right to be Forgotten" After Google Spain

  • 1. Dr David Erdos Faculty of Law University of Cambridge Disclosure Exposure
  • 2. Introduction  Google Spain described as a “clear victory for the protection of personal data of Europeans” (Reding, 2014).  Over 1.5m URLs have be delisted by Google alone to date.  But are concerns that not fully/properly implemented.  Presentation seeks to interrogate Google’s practice of notifying deindexing decisions/URLs to webmasters (& also removals of personal data to Lumen ‘research’ database & end users.)
  • 3. DPA Action on Webmaster Notification  A29 Working Party Guidelines (2014):  Routine webmaster notification illegal (confirmed by EDPB 2019).  In “particularly difficult cases” may be legitimate ex ante.  Must be “all necessary measures” to safeguard subject rights.  Spanish DPA Resolución R/02232/2016:  Followed-up specific complaint about disclosure.  Confirmed illegality.  Issued €150K fine & injunction against future repeat.  Google mounted legal challenge to this Resolution.
  • 4. Google’s Legal Challenge  Administrative Law Claim:  Sanctioning Procedure wrongly established general position.  Substantive Law Claims:  No (new) personal data disclosed.  Notification done with data subject consent.  Even if not, has overriding legitimacy.  Notification is anyway a legal obligation under DP.  2019 (April): Spanish High Court supports admin claim.  2020: Likely appeal to Spanish Supreme Court (& ?CJEU).
  • 5. No (New) Personal Data & Have Consent?  Google’s Claims:  URL strings generally don’t include identified details.  Even if do, would be known to webmaster (so not new).  Anyway get subject’s agreement on webform.  Why Claims are Wrong:  Personal data covers identifiable not just identified data.  Need to look at all means reasonably likely including use of “additional information” (GDPR, Recital 26).  Very simple means will identify including fact of deindexing.  Finally, agreement not consent as tie to exercise of fundamental right is clearly not “freely given” (GDPR, art. 4(11)).
  • 6. Overriding Legitimacy of Notification?  Focus has been on finding (another) ordinary legal basis.  But purpose limitation principle (GDPR, art. 5(1)(b); 6(4)) most critical as data collected for a very particular purpose.  Also may need to consider:  Special legal basis where sensitive/special data (Ibid, art. 9-10)  Data transfer legal basis where trans-border flow (Ibid, Ch. V)
  • 7. Purpose Limitation = Purpose Quality Plus: Compatible Processing (art. 6(4)) Link between purposes Context of Collection Nature of data Possible Consequences Safeguards
  • 8. Context of Collection & Nature of Data  Context of Collection (GDPR, art. 6(4)(b)):  Means to exercise fundamental right (& discharge legal duty).  Massive power imbalance.  No genuine freedom of choice.  Nature of Personal Data (GDPR, art. 6(4)(c)):  May be sensitive/special e.g. if concern health, sex life or crime.  Even if not then highly likely to be stigmatic and/or misleading.  Furthermore, deindexing claim itself is clearly private.
  • 9. Link between Purposes? Core Purpose  Purpose of notification is not defined.  But webform (from Sept. 2015) implicitly suggests core purpose is to help ensure deindexing decision correct.  Would appear to be strong link with initial purpose but:  Is this legitimate where ex post rather than ex ante?  Is this credible where blanket notification – shouldn’t Google show that necessary and proportionate case-by-case?  Even where valid, would still need safeguards to protect from adverse consequences.
  • 10. Link between Purposes? Other Purposes  At least some webmasters may desire to use data to:  Exact revenge on data subject.  Damage reputation of data subject.  Publicize nature of deindexing decisions.  With exception of safeguarded research, clearly not compatible:  No positive link with initial purpose at all.  Likely to directly undermine chances of data “sink[ing] into oblivion”.  May even result in re-indexing of material.  Wave of new publicity likely worse & may well chill use of right.  Unfortunately, plenty of evidence of such processing eventuating with clear adverse consequences for data subjects.
  • 11. Webmaster notification  New Publicity
  • 12. Appropriate Safeguards (GDPR, art. 6(4)(e))?  Purpose limitations must clearly be specified to webmaster and disclosure only following legal agreement to abide by these.  Given risk of grave & irreparable damage must also consider specific measures to counter deliberate disclosure.  Suspension of cooperation for period may work for big players such as the BBC and Facebook.  Small players e.g. amateur blogs present greater challenge.
  • 13. Ordinary Legal Basis for Processing (art. 6(1))  In principle additional to compliance with DP Principles but GDPR Recital 50 states that if purpose compatibility satisfied then no “separate” legal basis required, although “rights, including the right to object, should be ensured”.  Two possible bases have been mooted:  “necessary for compliance with a legal obligation”  “necessary for legitimate interests … except where … overridden”  Both flag requirement that disclosure necessary.  Second basis would also trigger right to object – must take into account opposition & show really compelling grounds.
  • 14. Special Legal Grounds for Processing  Deindexing claim may well be sensitive data e.g. if it concerns a health or sex life matter.  This triggers a default prohibition.  Claim clearly not made public & processing not with consent.  Must therefore rely on ̒public interest̕grounds:  Criminal-related data (also special data) likely governed similarly. “ necessary for the establishment, exercise or defence of legal claims” (GDPR, art. 9(2)(f)) “ necessary for … research purposes or statistical purposes … based on Union or Member State law which shall be proportionate … and provide for suitable and specific measures to safeguard” (GPDR, art. 9(2)(j))
  • 15. Legal Grounds for Data Transfers  Webmaster disclosure will often be to controller based overseas.  Unless State deemed “adequate”, then default prohibition.  In principle may also be lifted where:  But Google has obligation to choose least derogatory option:  Should therefore generally make use of Commission’s standard contractual clauses (GDPR, art. 46(2)(d)). “ necessary for the establishment, exercise or defence of legal claims” (GDPR, art. 49(1)(d)) “ the controller or process should make use of solutions that provide data subjects with enforceable and effective rights as regards the processing of their data in the Union” (GDPR, recital 114)
  • 16. Notification Obligations under DP  Google has suggested two specific provisions require it to disclose.  Article 19 (modified from DPD) flows generally from erasure etc.:  Article 17(2) instantiates GDPR’s new “right to be forgotten”: “Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller … shall take reasonable steps … to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers” “The controller shall communicate any rectification or erasure or personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Articles 18 to whom the personal data have been disclosed, unless this proves impossible or involves a disproportionate effort.”
  • 17. Why Webmaster Notification not Obligation  Narrow Argument:   Article 19 as webmasters are source not recipient of data.   Article 17(2) as webmasters not search engines make public.   Article 17(2) only triggered where subject requests action.  Middle Argument:  Deindexing is best seen as exercise of right to object (art. 21).  Broadest Argument:  These “right of the data subject” are all aimed at protecting autonomy and safeguarding this individual.  Other actions always “disproportionate” (art. 19) & not a “reasonable step” (art. 17(2)) in context.
  • 18. Other Forms of Disclosure  Disclosure to Lumen/Chilling Effects:  Clear Google discloses personal data as regards removal under defamation, civil/traditional privacy.  States likely to so in the future as regards deindexing.  Disclosure to End Users:  Information on deindexing has been largely generic.  But individualised disclosure including via link to Lumen resorted to for defamation, civil/traditional privacy etc.
  • 19. Other Forms of Disclosure: Legal Analysis  Disclosure to End Users:  Directly undermines rights & so violates purpose compatibility.  Unlikely legitimate interest in receipt & certain not overriding.  Shouldn’t matter if rights are in defamation, civil privacy or DP.  Disclosure to Lumen/Chilling Effects:  States is an “independent research project” – may be questioned!  Scientific research can in principle satisfy purpose limitation.  But subject to legal grounds and “appropriate safeguards” which rule out (negative) measures against data subject.  Google’s disclosure & Lumen’s processing clearly fails these safeguards.
  • 20. Conclusions  Google’s blanket webmaster notification unlawful, as is disclosure of personal data on removals to Lumen & end users.  Targeted notification can be lawful where:  Purpose of better resolving claim and/or scientific research.  Processing is reasonably necessary (and strictly if objection or special data).  Effective measures taken to prevent re-purposing (& further protect subject where international transfer).  Current disclosure practices are a serious threat to the Google Spain ruling and so resolving this should be a priority for EDPB & EU DPAs.