Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Critics: EU's proposed data protection rules could hinder Internet

The proposed rules, including the right to be forgotten, get a mixed reaction from U.S. observers

Data protection and online privacy rules proposed for the European Union could hinder the development of new Web-based business models and bog down companies with regulations, some U.S. critics said Wednesday.

The proposal, released Wednesday, "goes precisely in the wrong direction," said Thomas Lenard, president of the Technology Policy Institute, a free-market think tank. "If adopted, it will stifle the development of the Internet, which depends critically on the use of individual data to develop, improve, and fund services and content."

The rules, proposed by E.U. Justice Commissioner Viviane Reding, include the so-called "right to be forgotten," allowing Internet users to have data about them deleted if there are no legitimate reasons for retaining it. The proposal would require companies with more than 250 employees to appoint data protection officers, and it would require companies to report data breaches within 24 hours.

The proposal is not in consumers' interests, Lenard said. It would impose "significant costs" on them, in the form of less useful Web services, with no evidence of comparable offsetting benefits, he said.

Asked if privacy is a benefit, Lenard said it can be, but there's been little evidence showing significant harm to consumers because of current online data privacy practices. "Consumers willingly trade their information for services and content all the time," he said.

The proposal's right to be forgotten raises technical and free speech questions, added Emma Llanso, policy counsel with the Center for Democracy and Technology, a digital rights group. Personal information online can get copied and reposted on multiple websites, and the E.U. should look "very carefully" before creating regulations for sites where the information didn't originate, she said.

Privacy advocates applauded the proposal.

The proposal is a "serious and thoughtful effort," said Marc Rotenberg, executive director of the Electronic Privacy Information Center. "It simplifies compliance for business and it strengthens rights for users."

Jeffrey Chester, executive director of the Center for Digital Democracy, praised the right-to-be-forgotten proposal.

"The E.U. has raised the digital bar protecting user privacy online by proposing a new right to control their information," he said in an email. "Through new ways for consumers to ensure their information is 'forgotten' and 'erased' online, online marketers will not be able to readily build a treasure trove of data profiles."

The proposal will help consumers better respond to the "ever-growing" data collection practices of Facebook, Google and other Internet giants, he added.

Facebook, in a statement, called the proposal "an important opportunity to develop regulation that both protects privacy and supports the creation and growth of modern services over the global Internet."

Two U.S. technology trade groups, the Business Software Alliance and the Software and Information Industry Association, raised concerns about the proposal, saying it could limit the growth of the Internet.

The proposal " errs too far in the direction of imposing prescriptive mandates for how enterprises must collect, store, and manage information," Thomas Boué, BSA's director of European affairs, said in a statement.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: BSA, Business Software Alliance, Electronic Privacy Information Center, EU, Facebook, Google, IDG, IIA, Software and Information Industry Association, Technology
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: business software alliance, Center for Democracy and Technology, Center for Digital Democracy, Electronic Privacy Information Center, Emma Llanso, Facebook, Google, government, Jeffrey Chester, Marc Rotenberg, privacy, Regulation, security, Software and Information Industry Association, Technology Policy Institute, Thomas Boué, Thomas Lenard, Viviane Reding
Latest Blog Posts
Whitepapers
  • Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
    A revolutionary new video collaboration device, the Avaya Desktop Video Device has been making waves in the communications industry ever since Avaya introduced the product in the fall of 2010. Avaya’s own employees have been among the earliest users and have seen first-hand how the product can improve collaboration and make people more efficient and effective. Read more.
    Learn more »
  • Providing effective endpoint management at the lowest total cost
    Endpoints, otherwise known as servers, workstations, laptops, mobile devices, and virtually any other network-connected device, are critical components that enable business to be transacted. Properly implemented, endpoint management ensures continuous compliance with IT policies, regardless of where the machines are located and what type of network they are connected to.
    Learn more »
  • Spear Phishing Attacks - Why they are successful and how to stop them
    There's been a rapid shift from broad, scattershot attacks to advanced target attacks that have had serious consequences for victim organisations. The increased use of spear phishing is directly related to the fact that it works, as traditional security defences simply do not stop these types of attacks. This paper provides a detailed look at how spear phishing is used within advanced attacks and the key capabilities organisations need in order to effectively combat these emerging and evolving threats.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments