As of May 26th, the new European GDPR law is supposed to protect our personal data, stored online and beyond. It took millions of personal data losses and hundreds of hours in courts worldwide to make the obvious a reality: Ordinary citizens should be able to protect their personal data from the big companies that operate and thrive off that data.
But how feasible is it?
GDPR For our own good
If 20 years ago we had talked about the impact that interconnection and data collection have on people's personal, social, and professional lives, we would have been labeled as excessive and anti-technology.
Today, when the monitoring and identification of even our toasters is now a reality, the European GDPR law comes to protect what we have not protected for at least twenty years.
Do you think that the thousands of phone calls that call us for advertising purposes will stop? These phone calls come from transfers of personal data or customer lists.
The advertising approach of Google, YouTube, and Facebook has been, is, and no one knows for how long it will continue to be an informal collection of personal data. The GDPR tells us what we already know, and asks us once again a little more formally for our explicit consent. The difference is the imposition of very high fines, something that should have been in place for a very long time.
Violations
But will this specific measure with very high fines in case of non-compliance with the law, or in case of data leakage, facilitate timely warning by a company that has been breached to its customers?
Until now, it had been observed that companies that were breached kept the fact under wraps so as not to tarnish their reputation. Usually we received the information when it was too late, that is, after the data had been leaked to underground forums.
Today, in addition to this, the bogeyman of a very high fine for the inability to protect data, but also for the failure to report the breach in a timely manner...
What do you think will happen?
Right to be forgotten
Of course, it is worth mentioning that it allows the deletion of our data from a company's list and supports the right to be forgotten...
Associate Professor of Law at the Aristotle University of Thessaloniki, Ioannis Igglezakis, presented the conflicting views on the "right to be forgotten" introduced by the new General Data Protection Regulation.
Critics of the regulation question its necessity and express the view that it will be the biggest threat to freedom of speech on the internet in the coming years, while the responsible Commissioner for Justice and Vice-President of the European Commission, Viviane Reding, argues that it is a modest extension of the right to privacy.
The good news for now is that there seems to be a consensus that the “right to be forgotten” cannot lead to the erasure of history and transform modern society into a “lotus-eating society,” nor can it function as a pretext for imposing censorship in cyberspace. Conversely, however, invoking freedom of expression cannot be an excuse for preserving absolute digital memory.
GDPR Questions
Of course, the new law was created to make things better for the end user. Here are some questions, however:
For companies, things seem to be a bit more complicated. All companies were and are obliged to protect the personal data they hold so that it does not leak. 
Will the GDPR be certified? Will it become another ISO, or HASP? Who will provide it and for what price? The same applies more or less to intermediaries. Who certifies our certification authority? Will all the data eventually end up in the “secure” reservoirs of a state authority for the protection of personal data? Does it
remind you of George Orwell’s 1984?
Image: iapp.org
___________________________________
- Mark Zuckerberg: should he be fired?
- Tails 3.7: for your anonymous browsing on the Internet
- Smsfoto.net: Phishing sms messages about the Sklavenitis supermarket
