The “Riskification” of European Data Protection Law through a two-fold Shift

Milda MACENAITE
DOI: https://doi.org/10.1017/err.2017.40
2017-09-01
European Journal of Risk Regulation
Abstract:The importance of the concept of risk and risk management in the data protection field has grown explosively with the adoption of the General Data Protection Regulation (2016/679). The article explores the concept and the role of risk, as well as associated risk regulation mechanisms in EU data protection law. It shows that with the adoption of the General Data Protection Regulation there is evidence of a two-fold shift: first on a practical level, a shift towards risk-based data protection enforcement and compliance, and second a shift towards risk regulation on the broader regulatory level. The article analyses these shifts to enhance the understanding of the changing relationship between risk and EU data protection law. The article also discusses associated potential challenges when trying to manage multiple and heterogeneous risks to the rights and freedoms of individuals resulting from the processing of personal data.
What problem does this paper attempt to address?