Here we are, four years since the implementation of the General Data Protection Regulation (GDPR). GDPR is having a massive impact on the technology scene as it’s changing the way companies do business. It’s not just because it’s a law-it’s because it impacts nearly every aspect of how businesses operate online, from marketing to data management to customer service. Big data, IoT, AI, and blockchain are all being impacted by the GDPR.
In this blog post, we’ll take a look at how GDPR impacts each of these areas of technology and what companies can do to comply with the regulation.
But first, a little bit about GDPR.
What is GDPR and who does it apply to?
General Data Protection Regulation (GDPR) is an EU regulation on data protection and privacy for all individuals within the European Union, as well as any organizations that process data of EU citizens. The regulation was created to protect individuals’ personal information and data.
The regulations are designed to ensure that companies can only collect and use data if they have a legitimate business reason for doing so. Companies must also be transparent about their use of personal information, providing clear notices about what data they collect and how they use it.
The goal of GDPR is to give customers more control over their personal information, while also making sure companies are responsible for protecting that information.
The GDPR applies to any organization or person in or outside the EU that offers goods or services to or monitors the behavior of, individuals within the EU. The law went into effect on May 25th, 2018.
The fine for violating GDPR can go up to 20 million or 4% of the annual revenue.
Read more about it here.
GDPR’s impact on big data
Big data refers to datasets that are so large that they cannot be processed using traditional methods like spreadsheets or databases. Big data analytics involves using computational tools such as machine learning algorithms or artificial intelligence systems to analyze large amounts of data quickly and efficiently. This allows businesses to make better decisions based on their insights into customer behavior patterns or trends within their sector – therefore improving their bottom line performance.
GDPR impacts Big Data and Analytics in many ways. The most obvious is that it requires companies to change the way they collect, process, store, and use data.
First of all, GDPR requires that companies only collect data they need for a specific purpose. They also have to be transparent about the collection of personal data and provide options for individuals to opt in and opt-out of having their data collected or used by a company. For example, cookies are one of methods used in online data collection. As per GDPR, explicit user consent to use cookies is necessary to collect or track user data.
Additionally, GDPR has strict rules about how long an organization can store customer data and which parties have access. This could mean organizations must update their security measures so that sensitive customer data cannot be accessed by unauthorized parties.
GDPR has implications for Big Data and Analytics that are not necessarily negative. However, it is a problem for companies that have no data governance in place.
GDPR’s impact on Blockchain
Blockchain is a distributed, immutable ledger that can be used for data storage, verification, and authentication. Sounds good, right? However, not so much when it comes to GDPR compliance.
Conflicts between GDPR and blockchain
Despite its potential to secure personal data and privacy, blockchain could potentially violate GDPR. Here is how:
- GDPR rights: The blockchain has immutable nature. Therefore, any data written in the blockchain, once written, cannot be erased. Any change in a single block could potentially invalidate subsequent blocks. This goes against GDPR’s right to erase, modify and port personal data granted to users.
- Data minimization: Blockchain technology can also run counter to the data minimization principle of GDPR, as it requires that data be widely distributed.
- Role of data controllers: The issue of who is responsible for data controllers also arises in blockchain-based systems. In a distributed ledger system, anyone who joins the network and runs software can access the network. This means that anyone who has access to the network becomes a controller of data. This conflicts with Article 24 of GDPR, which defines responsibilities for data controllers., i.e. who have centralized control over the data they collected.
Here’s a quick comparison between GDPR and Blockchain
Caption: Image source: https://www.101blockchains.com/
Possible solutions
According to CMS Law, one way to solve this problem is to store different types of data separately. For example, personal information could be stored in databases on servers that are not part of a blockchain, while the blockchain would merely contain references to those databases. If someone wanted their data to be deleted, it could be erased from the off-chain server, along with any link to it in the blockchain. However, there are certain disadvantages to this solution. It reduces the security and efficiency benefits of blockchain by removing your data from it and storing it off-chain.
An alternate solution is to encrypt personal data with a key or hash and delete the key if requested. This would make the information stored on the blockchain inaccessible, and thus effectively lost in the blockchain. However, this method has not been accepted officially by EU laws yet.
GDPR’s impact on IoT
The impact of GDPR on Internet of Things (IoT) systems can be difficult to determine because IoT systems can be complex. However, some key aspects must be considered when determining how the GDPR applies to an IoT system:
- Identifying data controllers: The controller is typically the developer or manufacturer who decides how personal data will be handled by their devices.
- Identifying data recipients: In addition to identifying the controller, it is also important to identify recipients of any personal data collected by an IoT system. Recipients may include companies that collect data from consumers’ devices to provide them with advertisements or other information services; individuals who have consented to share their information with third parties; and other individuals who may consent through terms-of-service agreements with recipients.
- Privacy notices: IoT systems must provide information on how they handle personal data. This can be done using either a privacy notice or policy. Both are designed to give users an understanding of how their data is collected, used, stored, and managed by entities.
- Privacy by design and by default: Designing products with privacy by default is critical.
- Minimal data collection: Manufacturers must also make sure that they’re collecting only as much information on their users as necessary, and storing that information for only as long as it’s needed. They must also ensure that the data collected isn’t being used for purposes other than what it was intended for.
There is another EU regulation, known as the ePrivacy Regulation, that will cover IoT systems. However, there is no confirmation on when it will come into force.
GDPR’s impact on AI
Artificial intelligence (AI) algorithms make decisions based on patterns they find in data. These patterns may include health information, financial information, or location data. AI can also include systems like machine learning systems that collect and analyze data to make predictions about future behavior or events.
Companies need to be aware of these sources of personal data when they build their AI systems and ensure they are GDPR-compliant as well as following other regulations. In addition, companies need to consider whether their customers want this type of personal data collected from them when using applications built using AI technology.
Article 22 of GDPR states that users have the right to object to automated decision-making, including profiling, which is the basis for AI. There are only a few exceptions to this regulation, such as:
- if they have explicit consent from users;
- if data processing is necessary for fulfilling a contract between users and company; or
- if it is subject to EU laws.
These exceptions will not apply to the processing of sensitive personal data such as those related to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, or biometric data. In this case, the users have the right to opt out of AI-based processing. Businesses must ensure that appropriate safeguards are in place for the use of AI systems to process this type of data.
Here is a checklist by CNIL for using AI systems in a compliant manner.
Data is the lifeblood of many companies’ businesses and all these emerging technologies use data. Therefore, the impact of GDPR, as we have seen, is massive. Businesses implementing these technologies must align their standards with the regulation. The key to complying with GDPR is transparency. If companies are transparent with users about how they’re using their data, they’ll be in a much stronger position to respond to complaints and protect themselves against fines. While it might seem like a lot of work, it’s better to plan these things out than risk a penalty.