GDPR bypass by design? Transient processing of data under the GDPR
Damian George, Kento Reutimann, Aurelia Tamò-Larrieux — International Data Privacy Law
Damian George, Kento Reutimann, Aurelia Tamò-Larrieux — International Data Privacy Law
How it connects
Related across sources
Full text
In search of privacy-friendly facial detection and autonomous driving software, data controllers are discovering that processing data merely transiently might not only be in compliance with the data minimization principle, but also exclude their activities from the General Data Protection Regulation (GDPR) altogether. The argument can be made that since transient data does not allow for re-identification it is not personal data in a legal sense. However, effect-oriented or output-based interpretations of the notion ‘personal data’ have been proposed, which in turn could lead transient data processing technologies to fall within the scope of the GDPR. An effect-oriented interpretation of the regulation would ensure that in cases where transient data...