What could possibly go wrong?

The risk-based approach is a pillar of EU data protection law, mandating data controllers to adapt their obligations to the risks to the rights and freedoms of natural persons. Despite aiming to strengthen data protection and provide flexibility, it presents conceptual and practical challenges, suc...

Full description

Saved in:
Bibliographic Details
Main Authors: Dariusz Kloza, Thibaut D'hulst, Malik Aouadi
Format: Article
Language:English
Published: openjournals.nl 2025-01-01
Series:Technology and Regulation
Subjects:
Online Access:https://techreg.org/article/view/19503
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1832586464709312512
author Dariusz Kloza
Thibaut D'hulst
Malik Aouadi
author_facet Dariusz Kloza
Thibaut D'hulst
Malik Aouadi
author_sort Dariusz Kloza
collection DOAJ
description The risk-based approach is a pillar of EU data protection law, mandating data controllers to adapt their obligations to the risks to the rights and freedoms of natural persons. Despite aiming to strengthen data protection and provide flexibility, it presents conceptual and practical challenges, such as comprehending and assessing risk. This paper seeks to elucidate these issues to enhance legal compliance and safeguard fundamental rights. Section 2 scrutinizes the nature of risk and its assessment, examines related concepts like damage, and explores inherent problems. Section 3, after illustrating such risks, expands their understanding by introducing ‘negative consequences’ and proposing their typology. Section 4 presents a method for efficiently identifying these consequences, i.e., an inventory with a complimentary classification criteria.
format Article
id doaj-art-7cf338dfc44e4018912af33eaa4efa0e
institution Kabale University
issn 2666-139X
language English
publishDate 2025-01-01
publisher openjournals.nl
record_format Article
series Technology and Regulation
spelling doaj-art-7cf338dfc44e4018912af33eaa4efa0e2025-01-25T12:29:10Zengopenjournals.nlTechnology and Regulation2666-139X2025-01-01202410.26116/techreg.2024.023What could possibly go wrong?Dariusz Kloza0https://orcid.org/0000-0003-0819-8130Thibaut D'hulst1Malik Aouadi2Universiteit GentVan Bael & BellisVan Bael & Bellis The risk-based approach is a pillar of EU data protection law, mandating data controllers to adapt their obligations to the risks to the rights and freedoms of natural persons. Despite aiming to strengthen data protection and provide flexibility, it presents conceptual and practical challenges, such as comprehending and assessing risk. This paper seeks to elucidate these issues to enhance legal compliance and safeguard fundamental rights. Section 2 scrutinizes the nature of risk and its assessment, examines related concepts like damage, and explores inherent problems. Section 3, after illustrating such risks, expands their understanding by introducing ‘negative consequences’ and proposing their typology. Section 4 presents a method for efficiently identifying these consequences, i.e., an inventory with a complimentary classification criteria. https://techreg.org/article/view/19503data protectionrisk-based approachrisk to the rightsdata protection impact assessment
spellingShingle Dariusz Kloza
Thibaut D'hulst
Malik Aouadi
What could possibly go wrong?
Technology and Regulation
data protection
risk-based approach
risk to the rights
data protection impact assessment
title What could possibly go wrong?
title_full What could possibly go wrong?
title_fullStr What could possibly go wrong?
title_full_unstemmed What could possibly go wrong?
title_short What could possibly go wrong?
title_sort what could possibly go wrong
topic data protection
risk-based approach
risk to the rights
data protection impact assessment
url https://techreg.org/article/view/19503
work_keys_str_mv AT dariuszkloza whatcouldpossiblygowrong
AT thibautdhulst whatcouldpossiblygowrong
AT malikaouadi whatcouldpossiblygowrong