Abstract
Abstract
In our data-driven society, personal data affecting individuals as data subjects are increasingly being collected and processed by sizeable and international companies. While data protection laws and privacy technologies attempt to limit the impact of data breaches and privacy scandals, they rely on individuals having a detailed understanding of the available recourse, resulting in the responsibilization of data protection. Existing data stewardship frameworks incorporate data-protection-by-design principles but may not include data subjects in the data protection process itself, relying on supplementary legal doctrines to better enforce data protection regulations. To better protect individual autonomy over personal data, this paper proposes a data protection-focused data commons to encourage co-creation of data protection solutions and rebalance power between data subjects and data controllers. We conduct interviews with commons experts to identify the institutional barriers to creating a commons and challenges of incorporating data protection principles into a commons, encouraging participatory innovation in data governance. We find that working with stakeholders of different backgrounds can support a commons’ implementation by openly recognizing data protection limitations in laws, technologies, and policies when applied independently. We propose requirements for deploying a data protection-focused data commons by applying our findings and data protection principles such as purpose limitation and exercising data subject rights to the Institutional Analysis and Development (IAD) framework. Finally, we map the IAD framework into a commons checklist for policy-makers to accommodate co-creation and participation for all stakeholders, balancing the data protection of data subjects with opportunities for seeking value from personal data.
Publisher
Cambridge University Press (CUP)
Reference107 articles.
1. Driver’s Seat (2020) Driver’s Seat. Available at https://driversseat.co/
2. Data collaboratives as “bazaars”?
3. P2P Foundation Wiki (2021). Data cooperatives. Available at https://wiki.p2pfoundation.net/Data_Cooperatives (accessed 26 August 2021).
4. Privacy as contextual integrity;Nissenbaum;Washington Law Review,2004
5. Cellan-Jones, R (2020) Coronavirus: England’s test and trace programme “breaks GDPR data law.” Available at https://www.bbc.com/news/technology-53466471 (accessed 26 August 2021).
Cited by
10 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献