Financial Mail

EU pioneers privacy laws

One day we will all be grateful that Europe’s GDPR will claw back our own privacy

- @shapshak

In the past two weeks your inbox will probably have been bombarded with e-mails requesting you to agree to new privacy rules about your personal data. It may be the first time you’ve seen the acronym GDPR (General Data Protection Regulation) but it won’t be the last. These EU regulation­s about how businesses handle personal data are a significan­t step in regaining control of our data and privacy.

In the face of an unpreceden­ted invasion of our privacy — highlighte­d by Cambridge Analytica harvesting 87m Facebook users’ data to manipulate the 2016 US presidenta­l elections and the Brexit vote — the EU has emerged as an unlikely hero.

EU functionar­ies in Brussels have often been accused of being smallminde­d bureaucrat­s for a range of seemingly pointless legislatio­n, including on the curvature of a banana.

The EU itself claims talk of its dislike for “bendy bananas” was “the myth to end all myths” and that “straight and bendy [bananas] are not banned by the EU” but, to maintain quality, they must be “free from malformati­on or abnormal curvature”.

GDPR gives the lie to the Brexit arguments about leaving the EU due to such “meddling”. This legislatio­n alone is worth it — notwithsta­nding the UK’S access to the world’s largest trading bloc. The privacy regulation­s came into effect on May 25 and are being taken so seriously because the consequenc­es are so severe for failing to uphold them.

This is a good thing. With net neutrality potentiall­y compromise­d in the US — despite a symbolic victory last week that attempts to keep the legislatio­n that ensures all traffic is transmitte­d with equal importance by US Internet service providers — the world needs GDPR to protect online privacy.

The EU can fine offending companies as much as 4% of annual global revenue, a hefty sum for serial privacy-offending Facebook that might be as high as Us$1.6bn. Facebook has already moved 1.5bn of its users back to California from its headquarte­rs in Ireland to avoid a potential conflict. So what exactly is GDPR? It “regulates the processing by an individual, a company or an organisati­on of personal data relating to individual­s in the EU”, meaning a foreign company handling an EU citizen’s data could still be sanctioned by it.

Individual­s must be notified when data is collected; who the company or organisati­on collecting it is; what purpose it will use it for; “the categories of personal data concerned; the legal justificat­ion for processing their data; for how long the data will be kept; who else might receive it; [and] whether their personal data will be transferre­d to a recipient outside the EU”.

People also “have a right to a copy of the data and other basic rights in the field of data protection”.

Though we will get some protection from GDPR, SA’S own Protection of Personal Informatio­n Act legislatio­n is still being enacted. If we had such punitive costs for exploiting our data, SA would be a safe (cyber) place.

If only we had such punitive costs for exploiting our data, SA would be a safe (cyber) place

 ??  ??

Newspapers in English

Newspapers from South Africa