EU data protection regulation – right to be forgotten

70% of EU citizens are worried about misuse of their personal data according to EU justice department. One might think are the remainin 30% in groups of ignoranda and unaware. Naturally nobody wants misuse of personal data.

source: European Commission

One way to give control to indiciduals is the defined “right to be forgotten”- rule.  Tricky part is how that can be implemented.

From individual point of view it is impossible to know where you have left some information about yourself while wondering through web. All systems are storing huge amounts of information in their logs. Picking and deleting few individuals out of that might prove to be tricky. Easy answer would be that no-one is allowed to store any logs, but that would be quite huge change effort for all systems running in web. For example my blog remembers you visiting here and staying on this page, which is basic functionality for all web based applications.

From company point of view this rule would have big impacts on need to invest renewal of systems so that unwated data can be deleted. It would impact also on business models: imagine what amazon would look like without any memory of your earlier visits.

On the other hand, if right to be forgotten would be limitted on registrations into services like Facebook and such, what would be the benefit? Your information will be collected into different web services which are crawling the content all the time and you do not know from whom you should request you information removal. Check out Way Back Machine, it shows nicely what i mean.

So nice attempt to increase individual control on personal privacy, but naturally there are some minor details to be considered while implementing it.

 

Leave a Reply