Skip to main content

Data Protection Law and Responsible Data Science

  • Chapter
  • First Online:
Data Science for Entrepreneurship

Part of the book series: Classroom Companion: Business ((CCB))

Abstract

This chapter provides data scientists with an introduction to data protection law. The aim of this chapter is to provide some basic knowledge and understanding concerning some of the most important principles of data protection law through a general explanation of these key concepts. It will show for instance that the notion of personal data is a very broad one, which encompasses the vast majority of the data processed in contemporary data processing technologies, or that the distinction between a data controller and a data processor can be tricky. It will also show that in order to start a processing of data, one has the choice between six different grounds; however, one ground must be chosen, and when processing data, all the provisions of Art. 5 of the GDPR must be respected. On the one hand, the explanations are general and do not go into too much detail so that they are easily understandable by the reader. On the other hand, they provide for “actionable knowledge”. That is, they will allow the reader to play with and apply the data protection principles herein discussed to their data science applications, so that they can be performed in a socially responsible way.

Five key points are discussed:

  1. 1.

    What exactly is meant by data protection?

  2. 2.

    What is personal data?

  3. 3.

    Who are the actors of data protection law?

  4. 4.

    Under what conditions it is possible to start processing data?

  5. 5.

    What principles should be respected when processing data?

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

eBook
USD 16.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 64.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD 89.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Notes

  1. 1.

    While fundamental rights are only a tiny part of the EU’s competences, the Council of Europe is an international organisation that specialises in the protection of fundamental rights. It currently has 47 member states. This comprises all EU members states, but also many more; see 7 https://www.coe.int/en/web/about-us/who-we-are.

  2. 2.

    At the moment of writing this chapter, this Bill has not been adopted (yet). Last moment of writing: 29 June 2020.

  3. 3.

    See, e.g., 7 https://edps.europa.eu/press-publications/press-news/blog/facial-recognition-solution-search-problem_en, last accessed 29 June 2020.

References

  • Art. 29 WP. (2013). Opinion 03/2013 on Purpose Limitation.

    Google Scholar 

  • Art. 29 WP. (2014). Opinion 06/2014 on the Notion of Legitimate Interests of the Data Controller under Article 7 of Directive 95/46/EC.

    Google Scholar 

  • Art. 29 WP. (2007). Opinion 4/2007 on the concept of personal data.

    Google Scholar 

  • Art. 29 WP. (2010). Opinion 1/2010 on the concepts of “controller” and “processor.”

    Google Scholar 

  • Art. 29 WP. (2018a). Article 29 Working Party Guidelines on consent under Regulation 2016/679.

    Google Scholar 

  • Art. 29 WP. (2018b). Guidelines on transparency under Regulation 2016/679.

    Google Scholar 

  • Carey, P. (2018a). Data protection principles. In P. Carey (Ed.), Data protection: A practical guide to UK and EU law (5th ed., pp. 32–41). Oxford University Press.

    Google Scholar 

  • Coleman, R., & McCahill, M. (2011). Surveillance & crime. Sage.

    Google Scholar 

  • Dehon, E., & Carey, P. (2018). Fair, lawful, and transparent processing. In P. Carey (Ed.), Data protection: A practical guide to UK and EU law (5th ed., pp. 42–65). Oxford University Press.

    Google Scholar 

  • European Parliament resolution of 16 February 2017 with recommendations to the Commission on Civil Law Rules on Robotics (2015/2103(INL)).

    Google Scholar 

  • Gellman, R. (2019). FAIR INFORMATION PRACTICES: A Basic History.

    Google Scholar 

  • Gutwirth, S. (2002). Privacy and the Information Age (Rowman & Littlefield 2002).

    Google Scholar 

  • Hoofnagle, CJ., Sloot, B van der., & Zuiderveen Borgesius, F. (2019). ‘The European Union General Data Protection Regulation: What It Is and What It Mean’s. 28 Information and Communications Technology Law 65.

    Google Scholar 

  • Mourby, M., Mackey, E., Elliot, M., Gowans, H., Wallace, S. E., Bell, J., et al. (2018). Are “pseudonymised” data always personal data? Implications of the GDPR for administrative data research in the UK. Computer Law and Security Review, 34(2), 222–233.

    Article  Google Scholar 

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), [2016], OJ L 119/1.

    Google Scholar 

  • Rodway, S., & Carey, P. (2018). Outsourcing personal data processing. In P. Carey (Ed.), Data protection: A practical guide to UK and EU law (5th ed., pp. 175–183). Oxford University Press.

    Google Scholar 

  • Voigt, P., & von dem Busche, A. (2017). The EU General Data Protection Regulation (GDPR), a practical guide. Springer.

    Book  Google Scholar 

  • Welfare, D., & Carey, P. (2018). Territorial scope and terminology. In P. Carey (Ed.), Data protection: A Practical guide to UK and EU law (5th ed., pp. 1–31). Oxford University Press.

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Raphaël Gellert .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2023 Springer Nature Switzerland AG

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Gellert, R. (2023). Data Protection Law and Responsible Data Science. In: Liebregts, W., van den Heuvel, WJ., van den Born, A. (eds) Data Science for Entrepreneurship. Classroom Companion: Business. Springer, Cham. https://doi.org/10.1007/978-3-031-19554-9_17

Download citation

Publish with us

Policies and ethics