Tuesday, 25 July 2023

Project "Monitoring and Assessment of the Transparency and Accountability of the Labor Inspection Office"

Donor organization: Open Society Georgia Foundation

Budget: 8,272 USD

Duration: 30 June 2023 - 30 December 2023

Project aim: The project aims to monitor and assess the transparency and accountability of the Labor Inspection Office, and propose and advocate relevant recommendations.

Thursday, 6 July 2023

ადამიანის უფლებათა ევროპული სასამართლოს 2023 წლის 4 ივლისის გადაწყვეტილება სახის ამომცნობი ტექნოლოგიების გამოყენებასთან დაკავშირებით

ავტორი: ქეთევან კუკავა

ადამიანის უფლებათა ევროპულმა სასამართლომ (შემდგომ - სასამართლო) 2023 წლის 4 ივლისს მიიღო გადაწყვეტილება საქმეზე გლუხინი რუსეთის წინააღმდეგ, სადაც პირველად განიხილა სახის ამომცნობი ტექნოლოგიების გამოყენების კონვენციასთან შესაბამისობის საკითხი.

საქმის ფაქტობრივი გარემოებების მიხედვით, პოლიციამ მომჩივანი დააკავა მეტროში, რადგან ის წინასწარი შეტყობინების გარეშე მშვიდობიანი დემონსტრაციის ჩატარებისთვის ძებნილად იყო გამოცხადებული. თავდაპირველად მისი იდენტიფიცირება მოხდა  ტელეგრამ არხზე განთავსებული ფოტოების და ვიდეოს მეშვეობით, სადაც ჩანდა, რომ ის მარტო ატარებდა დემონსტრაციას. სავარაუდოდ, პოლიციამ მისი იდენტიფიცირებისთვის სახის ამომცნობი ტექნოლოგია გამოიყენა. მომჩივნის იდენტიფიცირებისთვის ასევე გამოყენებულ იქნა მეტროში არსებული სახის ამომცნობი კამერები. პროცესის მიმდინარეობისას მტკიცებულებად წარდგენილ იქნა ტელეგრამ არხიდან და ვიდეო ჩანაწერიდან ამოღებული ფოტომასალა. მომჩივანს ადმინისტრაციული სამართალდარღვევის ჩადენისთვის, კერძოდ, შეტყობინების გარეშე დემონსტრაციის ჩატარებისთვის პასუხისმგებლობის სახით ჯარიმა დაეკისრა.

სასამართლოს გადაწყვეტილებით, მოცემულ საქმეში დაირღვა ადამიანის უფლებათა ევროპული კონვენციის მე-10 მუხლით გარანტირებული გამოხატვის თავისუფლება, რადგან მომჩივნის მიმართ გამოყენებული სამართლებრივი ნორმა არ იყო საკმარისად განჭვრეტადი და ვერ აკმაყოფილებდა კანონის ხარისხობრივ მოთხოვნას. იმ შემთხვევაშიც კი, თუ გამოხატვის თავისუფლებაში ჩარევას სასამართლო კანონის შესაბამისად ლეგიტიმური მიზნის მიღწევის საშუალებად მიიჩნევდა, ამგვარი ჩარევა არ იყო აუცილებელი დემოკრატიულ საზოგადოებაში.

სასამართლომ ხაზი გაუსვა იმ გარემოებას, რომ პოლიტიკურ შეხედულებებთან დაკავშირებული პერსონალური მონაცემები განსაკუთრებულ კატეგორიას მიეკუთვნება და დაცულობის მეტი ხარისხით სარგებლობს. 

სახის ამომცნობ ტექნოლოგიებთან დაკავშირებით უნდა არსებობდეს დეტალური წესები, რომლებიც ამგვარი ზომების გამოყენებას არეგულირებს, ასევე აუცილებელია მყარი გარანტიების არსებობა უფლებამოსილების ბოროტად გამოყენების და თვითნებობის თავიდან ასაცილებლად. ამგვარი გარანტიების არსებობა განსაკუთრებით მნიშვნელოვანია, როდესაც გამოიყენება რეალურ დროში სახის ამომცნობი ტექნოლოგიები.

კანონის ნორმა, რომელიც მართლმსაჯულების განხორციელების კონტექსტში ბიომეტრიული მონაცემების დამუშავების შესაძლებლობას ითვალისწინებდა, სასამართლომ ფართოდ ფორმულირებულად მიიჩნია. ამავე დროს, კანონი არ ითვალისწინებდა პროცედურულ გარანტიებს, მაგალითად, ნებართვის გაცემას, მონაცემების გამოკვლევის, გამოყენების, შენახვის პროცედურებს, კონტროლის მექანიზმს და სამართლებრივი დაცვის საშუალებებს.

სასამართლოს თანახმად, მნიშვნელოვნად ინვაზიური სახის ამომცნობი ტექნოლოგიების გამოყენებით მშვიდობიანი პროტესტის მონაწილეების იდენტიფიცირებას და დაკავებას შესაძლოა „მსუსხავი ეფექტი“ ჰქონდეს გამოხატვისა და შეკრების თავისუფლებით სარგებლობაზე.

სასამართლომ აღნიშნა, რომ სახის ამომცნობი ტექნოლოგიის გამოყენება მომჩივნის მიმართ, რომელიც კონვენციით გარანტირებული გამოხატვის თავისუფლებით სარგებლობდა, შეუთავსებელი იყო დემოკრატიული საზოგადოების იდეალებსა და ღირებულებებთან, რასაც კონვენცია იცავს და მხარს უჭერს. სახის ამომცნობი ტექნოლოგიის გამოყენებით მომჩივნის პერსონალური მონაცემების დამუშავება, ტელეგრამზე გამოქვეყნებული ფოტოების და ვიდეოს მეშვეობით მისი იდენტიფიცირების, ასევე მეტროთი მგზავრობისას მისი ადგილმდებარეობის დადგენისა და დაკავების მიზნით, არ იყო „აუცილებელი დემოკრატიულ საზოგადოებაში.“

შესაბამისად, სასამართლომ ადამიანის უფლებათა ევროპული კონვენციის მე-8 მუხლით გარანტირებული პირადი და ოჯახური ცხოვრების პატივისცემის უფლების დარღვევა დაადგინა.

მიუხედავად იმისა, რომ რუსეთის ფედერაცია 2022 წლის 16 სექტემბრიდან აღარ არის ადამიანის უფლებათა ევროპული კონვენციის მონაწილე მხარე, სასამართლომ ეს საქმე განიხილა, რადგან მისი იურისდიქცია ვრცელდებოდა ამ თარიღამდე მომხდარ ფაქტებზე.

იხილეთ სასამართლოს გადაწყვეტილება სრულად.


Monday, 20 March 2023

Project "Promoting Open Justice in Georgia"

Donor Organization: Open Government Partnership, EU for Integrity Programme for the Eastern Partnership

Budget: 14,819.50 EUR

Duration: 1 April 2023 - 31 January 2024

Project aim: The overall aim of the project is to promote open justice and citizen-oriented court services. The project is focused on the assessment of the use of technologies and innovation in providing court services and their role in ensuring open justice.

პროექტი "ღია მართლმსაჯულების მხარდაჭერა საქართველოში"

დონორი ორგანიზაცია: ღია მმართველობის პარტნიორობა, ევროკავშირი

ბიუჯეტი: 14,819.50 ევრო

ხანგრძლივობა: 1 აპრილი 2023 - 31 იანვარი 2024

პროექტის მიზანი: პროექტის მიზანია ღია მართლმსაჯულების და მოქალაქეებზე ორიენტირებული სერვისების მხარდაჭერა. პროექტის გუნდი შეისწავლის ტექნოლოგიებისა და ინოვაციების გამოყენებას სასამართლო სისტემაში და მათ როლს ღია მართლმსაჯულების უზრუნველყოფაში. 

Tuesday, 7 March 2023

Conference “Law, Technologies and Personal Data Protection”

 ქართულენოვანი ვერსია ხელმისაწვდომია აქ.

On 28 February 2023, Internet Society Georgia Chapter organized a conference “Law, Technologies and Personal Data Protection.” The speakers focused on various data protection challenges and discussed these issues from legal and technological perspectives.

The speakers of the conference were:

Ketevan Kukava, Founder and Director of “Law and Public Policy Center”, the Head of the Personal Data Protection Special Interest Group at Internet Society Georgia Chapter, and Invited Lecturer at the University of Georgia.
Nino Oragvelidze, Senior lawyer at the legal department of the Personal Data Protection Service.
Zviad Gabisonia, Professor of the Business and Technology University, Director of the BTU research center, and the Head of the Doctoral Program “Digital Governance and Artificial Intelligence in the Public Sector.”
Kakhaber Goshadze, Ph.D. in Law, Associate Professor of European University, Leading Specialist at the Human Rights and Civic Integration Committee of the Parliament of Georgia.
Giorgi Giorganashvili, Invited Lecturer at the University of Georgia, Head of the Information Technologies and Information Security Department at Compulsory Insurance Center, Information Security Auditor at the Personal Data Protection Service.
Giorgi Gurgenidze, President of Georgian Information Security Association.

Ketevan Kukava talked about the development of the European data protection law, discussed the standards relating to a data protection impact assessment and proposed recommendations for Georgia. Her study is available here.


 

კონფერენცია „სამართალი, ტექნოლოგიები და პერსონალურ მონაცემთა დაცვა“

The English version is available here.

2023 წლის 28 თებერვალს, „ინტერნეტ საზოგადოება საქართველოს“ ორგანიზებით გაიმართა კონფერენცია თემაზე „სამართალი, ტექნოლოგიები და პერსონალურ მონაცემთა დაცვა.“ მომხსენებლებმა ყურადღება გაამახვილეს მონაცემთა დაცვის გამოწვევებზე და განიხილეს ამ საკითხთან დაკავშირებული სამართლებრივი და ტექნოლოგიური ასპექტები.

კონფერენციის მომხსენებლები იყვნენ:

ქეთევან კუკავა, „სამართლისა და საჯარო პოლიტიკის ცენტრის“ დამფუძნებელი და დირექტორი, „ინტერნეტ საზოგადოება საქართველოს” პერსონალურ მონაცემთა დაცვის თემატური ჯგუფის ხელმძღვანელი, საქართველოს უნივერსიტეტის მოწვეული ლექტორი

ნინო ორაგველიძე, პერსონალურ მონაცემთა დაცვის სამსახურის იურიდიული დეპარტამენტის უფროსი იურისტი.

ზვიად გაბისონია, ბიზნესისა და ტექნოლოგიების უნივერსიტეტის პროფესორი, კვლევების ცენტრის დირექტორი,  „ციფრული მმართველობა და ხელოვნური ინტელექტი საჯარო სექტორში” სადოქტორო პროგრამის ხელმძღვანელი.

კახაბერ გოშაძე, სამართლის დოქტორი, ევროპის უნივერსიტეტის ასოცირებული პროფესორი, საქართველოს პარლამენტის ადამიანის უფლებათა დაცვისა და სამოქალაქო ინტეგრაციის კომიტეტის აპარატის წამყვანი სპეციალისტი.

გიორგი გიორგანაშვილი, საქართველოს უნივერსიტეტის მოწვეული ლექტორი, „სავალდებულო დაზღვევის ცენტრის“ ინფორმაციული ტექნოლოგიების და ინფორმაციული უსაფრთხოების დეპარტამენტის უფროსი, პერსონალურ მონაცემთა დაცვის სამსახურის ინფორმაციული უსაფრთხოების აუდიტორი.

გიორგი გურგენიძე, საქართველოს ინფორმაციული უსაფრთხოების ასოციაციის პრეზიდენტი.

ქეთევან კუკავამ ისაუბრა მონაცემთა დაცვის ევროპული სამართლის განვითარების ძირითად ტენდენციებზე, დეტალურად განიხილა მონაცემთა დამუშავების ზეგავლენის შეფასებასთან დაკავშირებული სტანდარტები და წარმოადგინა რეკომენდაციები საქართველოსთვის. 

ქეთევან კუკავას კვლევა ხელმისაწვდომია აქ. მისი მოხსენების ვიდეო ჩანაწერი ხელმისაწვდომია აქ

 

 

 

Friday, 3 March 2023

მონაცემთა დამუშავების ზეგავლენის შეფასება – ევროპული სტანდარტები და რეკომენდაციები საქართველოსთვის

The English version is available here.

ავტორი: ქეთევან კუკავა

სწრაფი ტექნოლოგიური განვითარების შედეგად, პერსონალურ მონაცემთა შეგროვებისა და მიმოცვლის მასშტაბი მნიშვნელოვნად გაიზარდა, რამაც ადამიანის უფლებების დარღვევის ახალი რისკები და საფრთხეები წარმოშვა. ტექნოლოგია როგორც კერძო, ისე საჯარო დაწესებულებებს თავიანთი საქმიანობის განხორციელებისას პერსონალური მონაცემების უპრეცედენტო მასშტაბით გამოყენების შესაძლებლობას აძლევს.[1]
მონაცემთა დაცვის ევროპული სამართალი მიზნად ისახავს ერთგვაროვანი და თანმიმდევრული სამართლებრივი ჩარჩოს შექმნას და მონაცემთა თავისუფალი და დაუბრკოლებელი მიმოცვლის უზრუნველყოფას. ტექნოლოგიების ეპოქაში არსებული მზარდი გამოწვევების ფონზე, ევროკავშირის და ევროპის საბჭოს სამართლებრივი ინსტრუმენტებით ადამიანის უფლებების დასაცავად მნიშვნელოვანი მექანიზმები დაინერგა. როგორც საჯარო, ისე კერძო სექტორში პერსონალური მონაცემების უპრეცედენტო მასშტაბით დამუშავების გათვალისწინებით, მონაცემთა სუბიექტების უფლებების და ინტერესების დაცვის მყარი გარანტიების შექმნა განსაკუთრებულ მნიშვნელობას იძენს.
მონაცემთა დამუშავების ზეგავლენის შეფასება ევროპული სამართლით გათვალისწინებული ერთ-ერთი მნიშვნელოვანი სიახლეა, რომელიც რისკების წინასწარი იდენტიფიცირებით, მონაცემთა დამმუშავებლებს ადამიანის უფლებების დარღვევის თავიდან აცილების შესაძლებლობას აძლევს. ამგვარი შეფასება აუცილებელია მხოლოდ იმ შემთხვევაში, როდესაც ფიზიკური პირის უფლებებისა და თავისუფლებების შელახვის მაღალი რისკი იქმნება.
მონაცემთა დამუშავების ზეგავლენის შეფასება დამმუშავებლების ანგარიშვალდებულებას და მონაცემთა სუბიექტების უფლებების დაცვას ემსახურება. ის შესაძლოა განხილულ იქნას, როგორც მონიტორინგს დაქვემდებარებული თვითრეგულირების ფორმა.[2] ეს მექანიზმი მონაცემთა დამმუშავებლებს ავალდებულებს პრობლემების იდენტიფიცირებას და გამოსავლის ძიებას, შიდა კონტროლითა და მცირედი გარე ჩართულობით, რასაც თან ახლავს მინიმალური მარეგულირებელი ზედამხედველობა.[3]
მონაცემთა დაცვის ზოგადი რეგულაცია ადგენს ძირითად მოთხოვნებსა და კრიტერიუმებს, თუმცა შეიცავს მცირე მითითებას თვითონ პროცესის შესახებ და არაფერს ამბობს მეთოდოლოგიაზე. შესაბამისად, მონაცემთა დამმუშავებლები სარგებლობენ გარკვეული თავისუფლებით და შესაძლებლობა აქვთ, თავად განსაზღვრონ ამ მექანიზმის ფორმა და სტრუქტურა. მთავარია, რომ ამ პროცესის შედეგი იყო რისკების რეალური იდენტიფიცირება.
მონაცემთა დამუშავების ზეგავლენის შეფასება აღქმულ უნდა იქნეს არა როგორც შესასრულებლად სავალდებულო სავარჯიშო, არამედ როგორც სასარგებლო ინსტრუმენტი.[4] რისკების სისტემატური იდენტიფიცირება ღირებულ საფუძველს ქმნის შესაბამისი აქტორების მხრიდან სტრატეგიული ზომების მისაღებად, პროდუქტებისა და მომსახურების მუდმივი გაუმჯობესების მიზნით.[5]
საქართველოში დღეს მოქმედი კანონმდებლობა სრულად არ შეესაბამება მონაცემთა დაცვის ევროპული სამართლის მოთხოვნებს და არ ითვალისწინებს ევროპის საბჭოს და ევროკავშირის სამართლებრივი ინსტრუმენტებით დანერგილ მნიშვნელოვან სიახლეებს.
მნიშვნელოვანია ქართული კანონმდებლობა პასუხობდეს ციფრულ ეპოქაში არსებულ გამოწვევებს და ითვალისწინებდეს მონაცემთა სუბიექტების უფლებების, თავისუფლებების და ინტერესების დაცვის სათანადო გარანტიებს. ევროპულ სტანდარტებთან დაახლოება და მონაცემთა დაცვის ევროპული სამართლით გათვალისწინებული სიახლეების დანერგვა ევროინტეგრაციის კუთხით მნიშვნელოვანი წინგადადგმული ნაბიჯი იქნება და ამავდროულად, ხელს შეუწყობს ადამიანის უფლებების დაცვის განმტკიცებას საქართველოში.


[1] პერსონალურ მონაცემთა დამუშავებისას ფიზიკურ პირთა დაცვის, ასეთი მონაცემების თავისუფალი მიმოცვლის და 95/46/EC დირექტივის გაუქმების შესახებ ევროპარლამენტისა და საბჭოს 2016 წლის 27 აპრილის 2016/679 რეგულაცია (მონაცემთა დაცვის ზოგადი რეგულაცია), პრეამბულის პუნქტი 6. ხელმისაწვდომია: https://bit.ly/2vHVeNC (წვდომის თარიღი: 01.12.2022).
[2] Kaminski M, E., Malgieri, G., Algorithmic impact assessments under the GDPR: producing multi-layered explanations, International Data Privacy Law, 2021, Vol. 11, No. 2, გვ.131.
[3] იქვე.
[4] Friedewald, M., Schiering, I., Martin, N., Hallinan, D. (2022). Data Protection Impact Assessments in Practice. In: Computer Security. ESORICS 2021 International Workshops. ESORICS 2021. Lecture Notes in Computer Science, vol 13106. Springer, Cham. https://doi.org/10.1007/978-3-030-95484-0_25 გვ. 439.
[5] იქვე.

Data Protection Impact Assessment – European Standards and Recommendations for Georgia

ქართულენოვანი ვერსია ხელმისაწვდომია აქ.

Author: Ketevan Kukava

As a result of rapid technological development, the scale of the collection and sharing of personal data has significantly increased, which has posed new risks and threats to human rights. Technology allows both private companies and public authorities to make use of personal data on an unprecedented scale when carrying out their activities.[1]

European data protection law aims to create a uniform and consistent legal framework and to ensure the free and unhindered movement of personal data. In response to the increasing challenges in the age of technologies, the EU and the Council of Europe legal instruments established important mechanisms for the protection of human rights. Considering an unprecedented scale of data processing both in the public and private sectors, providing appropriate safeguards for the protection of data subjects’ rights and interests gains crucial importance.

A data protection impact assessment is one of the important novelties foreseen by European law, which enables data controllers to prevent human rights violations by identifying the risks in advance. Such assessment is mandatory when there is a high risk to the rights and freedoms of natural persons.    

A data protection impact assessment is an important tool directed towards the accountability of the data controllers and protection of the data subjects’ rights. It can be considered as a form of monitored self-regulation.[2] It obliges companies to identify problems and find solutions, with internal oversight and some external input, accompanied by minimal regulatory supervision.[3]

The General Data Protection Regulation lays down the main requirements and criteria with regard to the data protection impact assessment. It includes only a brief description of this process and does not specify the methodology. Therefore, data controllers are given certain leeway and are allowed to determine the form and structure of the DPIA. What matters most is that the outcome of this process should be a real identification of risks.

Data protection impact assessment should not be regarded as a compulsory exercise but as a useful tool.[4] “The systematic identification of risks is a valuable basis for strategic action by implicated actors for the continuous improvement of products and services.”[5]

Georgian legislation currently in force is not fully compliant with the requirements of the European data protection law and does not foresee important novelties introduced by the Council of Europe and the EU legal instruments.

The Georgian legislation should respond to the challenges existing in the digital age and should provide appropriate safeguards for the protection of data subjects’ rights, freedoms and interests.  Harmonization with European standards and implementation of the novelties foreseen by the European data protection law will be an important step forward in terms of European integration and, at the same time, will facilitate strengthening human rights protection in Georgia.

The full study is available here.

 



[1] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), Recital 6, available at: https://bit.ly/2vHVeNC (accessed 01.12.2022).

[2] Kaminski M, E., Malgieri, G., Algorithmic impact assessments under the GDPR: producing multi-layered explanations, International Data Privacy Law, 2021, Vol. 11, No. 2, p. 131.

[3] Ibid.

[4] Friedewald, M., Schiering, I., Martin, N., Hallinan, D. (2022). Data Protection Impact Assessments in Practice. In: Computer Security. ESORICS 2021 International Workshops. ESORICS 2021. Lecture Notes in Computer Science, vol 13106. Springer, Cham. https://doi.org/10.1007/978-3-030-95484-0_25 p. 439.

[5] Ibid.

Saturday, 25 February 2023

Winter School on Social Rights

 

On 20-23 February 2023, Law and Public Policy Center organized a Winter School on Social Rights with the support of the Open Society Georgia Foundation.

16 students from 10 Georgian universities, selected based on open competition, participated in the Winter School.

Founder and Director of Law and Public Policy Center, Ketevan Kukava welcomed the students: “Our Winter School aims to create an environment where you can meet like-minded students from different universities, deepen your knowledge, engage in discussions, and express your opinions freely. I hope you will use gained knowledge effectively in the future and will promote human rights protection in our country."

The representative of the Public Defender’s Office – Beka Javakhadze and Human Rights Lawyer – Lela Gvishiani presented international standards, national legislation and policy, and existing challenges in Georgia. The program also included practical components. Based on the gained knowledge, students examined and analyzed specific cases related to adequate housing. They also participated in a simulated meeting of the inter-agency commission and discussed how to solve existing problems.

Law and Public Policy Center will continue organizing similar events on various topical issues in the future.

სოციალური უფლებების ზამთრის სკოლა

2023 წლის 20-23 თებერვალს „სამართლისა და საჯარო პოლიტიკის ცენტრის“ ორგანიზებით და საქართველოს ღია საზოგადოების ფონდის მხარდაჭერით სოციალური უფლებების ზამთრის სკოლა გაიმართა.

ზამთრის სკოლაში მონაწილეობდა ღია კონკურსის საფუძველზე შერჩეული 16 სტუდენტი საქართველოს 10 უნივერსიტეტიდან.

მონაწილეებს მისასალმებელი სიტყვით მიმართა სამართლისა და საჯარო პოლიტიკის ცენტრის დამფუძნებელმა და დირექტორმა, ქეთევან კუკავამ: „ჩვენი ზამთრის სკოლის მიზანია შევქმნათ ისეთი გარემო, სადაც გაიცნობთ თანამოაზრეებს სხვადასხვა უნივერსიტეტიდან, გაიღრმავებთ ცოდნას, ჩაერთვებით დისკუსიებში და თავისუფლად გამოხატავთ თქვენს აზრებსა და შეხედულებებს. იმედი მაქვს, მიღებულ ცოდნას ეფექტურად გამოიყენებთ მომავალში და ხელს შეუწყობთ ადამიანის უფლებების დაცვას ჩვენს ქვეყანაში.“

პროექტის ფარგლებში, სახალხო დამცველის აპარატის წარმომადგენელმა - ბექა ჯავახაძემ და ადამიანის უფლებების იურისტმა - ლელა გვიშიანმა სტუდენტებს საერთაშორისო სტანდარტები, ეროვნული კანონმდებლობა  და პოლიტიკა, ასევე საქართველოში არსებული გამოწვევები გააცნეს. პროგრამა ასევე მოიცავდა პრაქტიკულ კომპონენტებსაც. მიღებული ცოდნის საფუძველზე, სტუდენტებმა სათანადო საცხოვრებლის უფლებასთან დაკავშირებული კონკრეტული შემთხვევები შეისწავლეს და გააანალიზეს, ასევე მონაწილეობა მიიღეს უწყებათაშორისი კომისიის სიმულაციურ სხდომაში, სადაც არსებული პრობლემების გადაჭრის გზები განიხილეს.

სამართლისა და საჯარო პოლიტიკის ცენტრი მომავალშიც გააგრძელებს მსგავსი ღონისძიებების ორგანიზებას სხვადასხვა აქტუალურ საკითხზე.

Saturday, 28 January 2023

Why Data Protection Matters in a Digitized and Interconnected World

Author: Ketevan Kukava

We live in the age of ubiquitous surveillance, security cameras, big data, social networks, instant communications. The scale of the collection and sharing of personal data has significantly increased, which gives rise to multifaceted privacy-related challenges. Technological development has an impact on every aspect of people’s everyday life. Maintaining control over personal data in the increasingly digitized and interconnected world is extremely difficult. While various legal solutions have been offered, there are still doubts regarding the ability of the regulatory framework to keep pace with rapid technological advancement.

In the digital era, governmental mass surveillance has emerged “as a dangerous habit rather than an exceptional measure.”[1] Consequently, restricting civil liberties affects anyone, not just potentially dangerous persons.

Apart from surveillance by states, surveillance by private companies also raises significant concerns. Today, the economy, society, and individuals are largely dependent on the internet and internet-based services. Users of these services disclose a vast amount of information about themselves. Information has become an asset and “in two-sided business models personal data have become a currency for individuals to pay for services.”[2]

The aims of the companies monitoring their customers are different from the ones pursued by the state. They are willing to attract more users and increase their profits. In this case, private data collection cannot be regarded as a zero-sum manipulation of the individual as people are offered the services they highly value, such as free email, or an easy way to connect to social networks.[3] Indeed, individuals voluntarily surrender previously private information to have digital access to goods, services, and information. On the other hand, considering the state of technological dependency, refusing the use of electronic means of communication would actually mean giving up significant social interaction,[4] and leading a non-digital life while still being able to participate in society would make less sense.[5]

CCTV cameras have altered modern notions of privacy in public places as “the mere chance that one's public movements are being monitored is enough to alter an individual's behavior, regardless of whether anyone is actually watching.”[6] Besides, thanks to advances in technology, it is becoming increasingly possible to integrate digital features into everyday objects which were previously predominantly offline and to weave them into the Internet of Things, which also creates risks for users’ privacy.[7]

The Internet offers the opportunity of storing a vast amount of information indefinitely. While it brought about huge benefits in terms of access to a wide range of information, content creation, and public dissemination, it also resulted in a reduction of control over our personal data. As a result, “we - individually and as a society – have begun to unlearn forgetting”.[8]

A democratic society can only function if individuals have a certain degree of autonomy and privacy. There is no doubt that technological development has brought about significant benefits in many respects. We can easily retrieve information, connect globally, use e-services, etc. Data collection created opportunities for research and innovation, and digital communications can be seen as an engine of various opportunities. The use of advanced technologies makes data a universal resource in the digital age.

However, such benefits come with their downsides. Digital progress and sophisticated technologies create an unprecedented opportunity for surveillance and monitoring, which is sometimes compared to a contemporary “panopticon.”[9] This negatively affects an individual’s ability to enjoy liberty, personal autonomy, and individuality. It seems we are paying a high price for the benefits brought by digital progress. The significant question we should try to answer in an increasingly digitized and interconnected world is whether we are witnessing the demise of privacy or whether we can still find solutions to modern technological intrusions.

 

 



[1] The Right to Privacy in the Digital Age, Report of the Office of the United Nations High Commissioner for Human Rights, 2014, § 3, available at: https://bit.ly/3HmMCSu

[2] Hielke Hijmans (2016), The European Union as Guardian of Internet Privacy, The Story of Art. 16 TFEU, Springer International Publishing Switzerland, p. 96.

[3] Sarah Horowitz (2017), Foucault’s Panopticon, A Model for NSA Surveillance? Edited by Russell A. Miller, Cambridge University Press, p. 60.

[4] Yael Ronen, Big Brother's Little Helpers: The Right to Privacy and the Responsibility of Internet Service Providers, 31 Utrecht Journal of International and European Law, 72 (2015), p. 73.

[5] Murat Karaboga, Tobias Matzner, Hannah Obersteller, and Carsten Ochs (2017), Is there a Right to Offline Alternatives in a Digital World? in Data Protection and Privacy: (In)visibilities and Infrastructures, edited by Ronald Leenes, Rosamunde Van Brakel, Serge Gutwirth, Paul De Hert, Springer International Publishing AG, p. 54.

[6] Jon L. Mills (2008), Privacy: The Lost Right, Oxford University Press, p. 72.

[8] Viktor Mayer-Schőnberger (2009), Delete: The Virtue of Forgetting in the Digital Age, Princeton University Press, p. 92.

[9] Jon L. Mills (2008), Privacy: The Lost Right, Oxford University Press, p. 13.

 

Project "Assessment of the Transparency and Accountability of the Security Sector"

Donor Organization: Innovations and Reforms Center, European Union Budget: 14,000 EUR Duration: 3 June 2024 - 3 February 2025 Project aim:...