“The next great financial crisis could come from a cyber attack”: 5 critical cybersecurity measures you should put in place today

The 2021 Report on the SolarWinds Cyber Espionage Attack and Institutions’ Response published by the New York State Department of Financial Services (“Report”) commences with a stark warning: “The next great financial crisis could come from a cyber attack.” “The SolarWinds Attack is, to date, the most visible, widespread, and intrusive information technology (‘IT’) software supply chain attack – i.e., a ...

How data minimization, data quality, and storage limitation can help in the fight against climate change

Over the last 20 years, access to cheap computational capacity has increasingly led to the harvesting of more and more personal data, without having to worry too much about costs related to data storage and processing activities. For this very reason (and all too often), data sets are offhandedly replicated, databases are left unmanaged, and the same ...

“PUBLIC HEALTH AND PRIVACY” AND NOT “PUBLIC HEALTH OR PRIVACY”: Surveillance in the fight against COVID-19

“Hopefully COVID-19 will be gone at some point, but tracking technologies may stay for longer and permanently hamper the rights and freedoms of individuals” As part of my blog series on #PublicHealthANDprivacy in light of the COVID-19 pandemic, this short reflection will focus on digital surveillance. There is no doubt that data and technology have the ...

EU Commission and Parliament take stock on Data Protection in the EU

Today, 25 July 2019, the European Commission and the European Parliament published a Communication outlining the state of data protection in the EU. The document touches on consistent implementation of the GDPR, how the new governance system is working, and the impact that it has had, also in a global level, in terms of citizens ...

Personal Data Protection as the New Competitive Edge: Generating Socially Responsible Corporate Behaviour

Last Friday I held my inaugural lecture as Professor of Privacy, Cybersecurity, and IT Contract Law at the Faculty of Law - European Centre for Privacy & Cybersecurity at Maastricht University. During my lecture I introduced the research activities that I would like to further develop at Maastricht University in a multidisciplinary setting that includes ...

BIG DATA, SMART DATA, MY DATA, YOUR DATA: SMART DATA PROTECTION BY DESIGN (PART 4)

Part 4. Core International Data Protection Principles: Collection limitation, lawfulness and fairness The principle of collection limitation with respect to personal data establishes that data should be collected by way of fair and lawful means, with the knowledge and when appropriate, the consent of the data subject as so to limit indiscriminate data collection. In the Smart ...

Big data, smart data, my data, your data: Smart data protection by design (Part 1)

“The oil of the 21st century”, “the fuel of the digital economy”, the “data gold rush”. There’s no doubt that data is playing an ever-more important role in both the global society and the economy. The former Article 29 Working Party, renamed European Data Protection Board on 25 May 2018, when the GDPR became directly applicable ...