Data protection documentation – and where it fails
Data protection documentation is a comfort blanket where the means have become the ends, argues Ralph O’Brien of Serious Privacy.
There was a time when data protection was framed – at least in theory – as a means of safeguarding individuals’ fundamental rights and freedoms. The UK GDPR still reflects that ambition, placing rights, fairness, and accountability at its core. Yet, in practice, compliance has increasingly become an evidence-based exercise, where the ability to demonstrate compliance often takes precedence over the substance of actually achieving the intent of the law.
The original GDPR was designed as a law that encourages a proportionate approach, as an omnibus law that has to apply to all industry sectors and all sizes of organisations. Therefore, it cannot be specific, but requires organisations to come up with appropriate and proportionate responses – more of a risk management regime to apply technical and organisational measures than one that creates narrow and specific obligations. We do have to look at ourselves as data protection professionals. Have we prioritised the “organisational” measures? As a profession we are often simply more comfortable with contracts, policies, training and paperwork than we are with more technical measures like encryption, pseudonymisation, tokenisation and product design features.
Continue Reading
|
UK Report subscribers, please login to access the full article |
If you wish to subscribe, please see our subscription information. |