You are here

Protecting Your Personal Data Worldwide

Published on
12 September 2016

As the giants of the internet such as Google, Apple, Facebook and Amazon collect, analyze, store, use and share enormous quantities of personal data, the issue of data privacy continues to be a priority. The explosion of data, and in particular personal data shared by consumers, has made data protection an ever more complicated challenge. At its heart, lies a delicate balance between legal frameworks and international relations.

"The explosion of connected objects and healthcare applications is generating massive amounts of personal data whose legal framework is still unclear." says Nathalie Devillier, a professor and researcher at Grenoble Ecole de Management who specializes in e-healthcare, telemedicine, privacy rights and data protection.

One of the agreed upon legal conditions for collecting personal data is the concept of “user consent.” A user must consent to their personal data being used for the purposes of an application or other activity. “However, this is a delicate subject. For example, when you download a healthcare application, you implicitly accept a contract that approves the processing of your health-related personal data. It’s non-negotiable if you wish to use the application. In practical terms, the legal principle of ‘user consent’ doesn’t pan out.” explains Nathalie.

“Collecting sensitive personal data can result in information about a user being sold to third parties or worse yet, being used to discriminate during a job interview or when buying health insurance.” adds Nathalie. This highlights the need for both individual and collective surveillance of how personal data is used by companies. “The need to educate users is a critical part of ensuring they can give their informed consent. The risk is that the gap in understanding between users and data collectors will continue to widen.”

Europe takes a step towards tighter regulations

On April 14, 2016, the European parliament voted to overhaul the current data protection regulations. This new set of rules is designed to allow users greater control over their personal data. Key provisions include:

  • A user’s clear and affirmative consent to the processing of his or her data
  • The right to be forgotten
  • The right to access and modify your personal data
  • The right to refuse the use of your personal data for user profiling
  • The right to transfer personal data from one service provider to another
  • The creation of a central European authority for oversight
  • The possibility of administrative fines up to 4% of a company’s turnover or 20 million euros (whichever is greater)

Despite these improvements, Nathalie highlights the fact that “although the 20 million euro limit is much higher than previous European limits, we know that the maximum fine is rarely applied. In addition, if you take the US for example, fines are often agreed upon through mediation because going to court against a class action lawsuit would result in much higher penalties. And these agreements are already often in the millions of dollars!”

Data protection is still a matter of diplomacy

Ever since Edgar Snowden’s leaks about European surveillance carried out by US intelligence services in collaboration with major internet players, the EU and the US have been engaged in negotiations to protect personal data. In 2015, the 15-year-old Safe Harbour agreement, which regulated the flow of data from Europe to the US, was struck down by the Court of Justice of the European Union. In its place, a new agreement known as the Privacy Shield was set up to ensure companies such as Facebook or Google protect European users’ personal data when transferred to the US.

“However, the legal framework that was negotiated without much media attention is in fact quite similar to what was already in place. As long as the principle of ‘adequacy’ still applies, it will be hard to apply real restrictions to the transfer of data.” says Nathalie.

The ‘adequacy’ principle is the idea that to transfer data to a country outside the EU, said country must demonstrate adequate levels of protection of personal data. “The issue is that adequate doesn’t mean equivalent. As a result, this legal framework is still dependent on diplomatic negotiations. When countries are negotiating major international agreements, data protection can easily become a secondary issue.” concludes Nathalie.

On the same subject

  • Les conditions licites de la cybersurveillance du salarié
    Published on 25 January 2018

    Workplace Cyber Surveillance: Rights and Obligations

    Can a business spy on its employees? Yes, within certain limits. Discover how European courts regulate workplace cyber surveillance.

  • Published on 18 January 2018

    Technology Sourcing: How to Optimize Web Performance?

    To increase the performance of retail websites, companies should explore both internal tech development and outsourced tech services. New research confirms the advantage of mixing technology sources.

  • Caroline Cuny, GEM
    Published on 14 December 2017

    Going Digital to Improve In-Store Customer Relations

    How can digital technology help companies improve a customer’s shopping experience? We look at emerging trends such as artificial intelligence, facial recognition and olfactive marketing.

  • Published on 17 June 2017

    Nanovalor: a Platform to Evaluate the Value of New Tech

    Emerging technology can impact society and the economy in a variety of ways. Nanovalor creates a platform to analyze and learn about the value of new tech.

  • Professeur Sénior  Professeur au département Homme, Organisations et Société  Doctorate of Philosophy, Institut Universitaire Européen, Grenoble EM
    Published on 12 June 2017

    Research: Indulgences or Abuse of Indulgences, a New Perspective on Corporate Sins

    From environmental damage to product malfunctions or bribery, businesses around the world are often responsible for wrongdoing. However, assessing the moral stature of a business is considered to be a notoriously difficult task. Not only are...

  • research on Contextual Television Advertising
    Published on 28 February 2017

    Research: Questioning the Effectiveness of Contextual Television Advertising

    As businesses and marketing go digital, companies have to track the effectiveness of their advertising across many channels. The growth of online transactions has made website conversions an essential factor for many businesses. Thanks to detailed...

  • Published on 24 February 2017

    Sulitest: the first international tool to assess Sustainability Literacy worldwide

    As of 2017, Grenoble Ecole de Management is making the Sulitest, the first international tool to assess Sustainability Literacy worldwide, compulsory for all of its staff, faculty and students. This is a further step in GEM’s journey to become a...

  • Published on 19 August 2016

    NeOse™: Creating an Electronic Description of WHAT YOU SMELL?

    Nearly 10% of the world population is believed to suffer from olfactory disorders. Whether it is the inability to detect odors or an altered sense of smell, olfactory disorders can lead to depression and desocialization. In response, Aryballe...

  • Federico Pigni, Professor at Grenoble Ecole de Management
    Published on 01 July 2016

    Research: Creating Value from Digital Data Streams

    The big data era is upon us. Startups, major companies, organizations and governments are all rushing to extract essential insights from big data. Yet in doing so, many have overlooked the potential value of the digital data streams (DDS) that make...

  • Published on 30 June 2016

    Joining the UN’s International Telecommunication Union (ITU)

    Grenoble Ecole de Management becomes the first Business School in the world, and the first higher education institution in France to join the prestigious International Telecommunication Union (ITU), the United Nations specialized agency based in...

  • Published on 27 June 2016

    European CFOs are against Brexit: new Global Business Outlook survey reveals

    European CFOs are overwhelmingly against a British exit from the European Union, the latest round of the Global Business Outlook Survey reveals. More than 75 percent believe it is good for the U.K. to remain in the European Union, and a like number...

  • Published on 13 April 2016

    Biopiracy: what is this?

    Biopiracy is not a new phenomenon, but has redone about him in recent years and most recently as the advances in genetics reveal the potential of bio-resources.

  • websites such as TripAdvisor have given consumers the power to impact a company's image.
    Published on 22 March 2016

    TripAdvisor: How Companies React to Negative Ratings

    The world wide web has revolutionized the hotel, restaurant and other travel-related industries. From online bookings to customer ratings, companies have to learn how to operate in this new environment. While an organization's market identity used...

  • Research: Creating Visitor Engagement Through Music
    Published on 29 February 2016

    Research: Creating Visitor Engagement Through Music

    Digital communications have created an information overload for customers. To stand out on the world wide web, companies have to offer clients a high-impact experience. When used properly, music provides a simple yet effective means of creating a...

  • Federico Pigni, Professor at Grenoble Ecole de Management
    Published on 28 October 2015

    Congratulations Federico Pigni

    Duetto: Industry Transformation with Big Data, a case study in Harvard Business Review by Federico Pigni, Associate Professor in Information Systems in the Management of Technology and Strategy department at the Grenoble Ecole de Management (France...

  • Published on 13 October 2015

    Put Music on your Website

    Your web communication needs to offer a rich consumer experience to distinguish it from others. Nowadays, websites must evoke enjoyable and memorable feelings in their visitors in order to encourage them to revisit and recommend the website.

  • websites such as TripAdvisor have given consumers the power to impact a company's image.
    Published on 29 September 2015

    Customer reaction and Market identity

    This article, written by Tao Wang, Filippo Carlo Wezel and Bernard Forgues, examines the conditions under which organizations publicly respond to unfavorable consumer evaluations that challenge their market identity. This study relies on an analyse...