What expectations for privacy might an individual have and what expectations should an individual have in the digital age? People proclaim that they do care about privacy and yet, whether out of ignorance or for lack of caring, many too eagerly trade their private data online in exchange for goods or services from businesses. Some individuals also feel pressured into using online services designed to collect data. Two years after the European Union passed the General Data Protection Regulation (GDPR), and even after some positive legal developments in the United States, online privacy measures remain heavily nuanced. While there are some positive signs that privacy laws to protect individuals may be slowly catching up to expectations, this is not enough.
Online businesses amass personal data when users are searching for goods or services. At some point in the search process, these businesses ask users to agree to terms which claim that the collected data may only be used for improving the business’ online services. As these terms are defined broadly, this gives the businesses leeway to collect virtually any user data. Companies that sell ads, such as Facebook or Google, are motivated to know their users’ behaviour and preferences at a granular level, which includes the collection of personal information such as geolocation, dietary needs and political beliefs. This wealth of collected personal information enables the companies to better personalise the ads and therefore target users more efficiently and effectively. This user profiling increases the value of the companies’ services for advertisers and, as the claim goes, the value for the customers, because customers supposedly enjoy the more personalized and relevant ads presented to them on their screens. However, this is not always the case. For instance, an online search for a baby shower gift may result in a user being profiled as a new parent, and for a few months the user will subsequently be bombarded with baby food advertisements because their user data has been shared with other companies and advertising partners.
Since the introduction of GDPR, the most visible change for users has been the barrage of required privacy notices on websites. GDPR also establishes transparency and data use control rights for individuals, but otherwise the impacts of the regulation are mostly concentrated on companies, where the legal requirements translate into privacy audits, incident reports and further documentation. Thus, the impact of the GDPR remains mostly unnoticed by individuals. Recognising this, the EU has announced the ambitious idea of empowering individuals to control their own data. This idea will require major paradigm shifts in online business models and practices, as well as technological innovation. The EU, as well as national lawmakers and regulators, will need to adjust the current policies and regulatory regimes in place as well as support further technological development.
Today, the United States is home to 15 of the world’s 20 most valuable tech firms, while Europe is home to just one. Silicon Valley is where smart ideas meet the smartest money, and there is no such place in the EU. The EU should pioneer a distinct technology and privacy doctrine that aims to give individuals control over their personal information, as well as the profits from it. Using Horizon 2020 and other funding schemes, the EU should encourage home-grown business models that would promote this doctrine and become competitive with the tech giants who do not want to follow it. This new doctrine would benefit millions of users in Europe and around the world, boost the EU economy and limit the tech giants’ ability to use personal data without a sense of responsibility.
The GDPR will need to be adjusted to the new doctrine. For example, today the GDPR grants a user the right to be forgotten. If a user does not wish for any given company to hold or use their personal data, they can request the deletion of this data. This implies that, unless a user explicitly requests a provider to erase the personal data, the provider is entitled to hold on to it and use it. This is not in line with the EU’s proclaimed goal of having data subjects own their personal data. Therefore, the EU should turn the tables and no company should be entitled to collect or keep a user’s data unless a user has agreed to share the data.
Businesses also share user data with governments, which do not shy away from collecting citizens’ data on their own. The governments on the one hand put pressure on companies to raise their level of privacy compliance, though at the same time push for more data collection. This manifests in different forms, such as body cameras on police officers, facial recognition software in public areas and the acquisition of banking data from other countries. There is evidence of governments using technology that allows analysts, operating with little oversight, to view at will the private emails, chats, images, and files of almost any individual with an internet connection, as well as eavesdrop using computer and communication devices and track smartphones even when they are switched off. This intrusive mass surveillance system had been developed and is used without public consent or proper supervision. It directly contradicts both the spirit and the letter of the law. The EU should rule into this. The procedures for law enforcement agencies in the digital age should be as clearly defined as they are regulated for non-online activities. Any surveillance and data gathering should be subject to a search warrant, just as police forces must first obtain search warrants before searching premises. These EU-wide rules should be designed to safeguard citizens from indiscriminate searches and invasions of their privacy.
Privacy and technology are inextricably linked and will only become more so with time. While it is true that the majority of privacy violations occur due to human error, this necessitates the question of whether the authorities investigating said violations are facing a level playing field. Tech companies are at the forefront of innovation and are known for rapid prototyping and fast product releases. This drives technology into ever newer and constantly evolving fields that, even for insiders, are hard to keep pace with. However, if the respective authorities are sincere in their mission to keep up with those they regulate and face them on equal footing, they must attract and retain the same knowledge and skillset that these companies employ. There must be an ongoing dialog and potentially even the co-creation of features – privacy by design and by default being the operating terms. If not, the risk is real that an imbalance will mount and that privacy authorities will become toothless tigers.
While it is key that companies are held accountable for their actions regarding privacy, it is equally important that users are aware of their power and rights in this regard. The EU is in a position to empower its electorate through trans-national education and awareness programs designed not only to inform, but also to enable individuals to claim their privacy rights against those who seek to infringe upon them. Without such programs, users are left to their own devices when it comes to privacy and at an even greater loss against data collectors.
Liberty and respect for individual rights may very well be the greatest achievements of democratic states. To argue that this is not the case would be a tough argument, to say the least. Yet, these privileges that individuals enjoy and cherish in the liberal world are threatened by an increasing invasion into the private sphere of citizens and users on a massive scale. And citizens accept this tacitly – it has become the new normal. The most effective way to counter this new normal is by building a stable and lasting privacy culture, and one in which businesses take pride in privacy and consider it to be of value.
If the EU fosters such a culture that takes pride in privacy and what it stands for, then the growing pains of bureaucracy and change, which are too often associated with new privacy regulation, will be willingly accepted as the bigger picture becomes more comprehensible for the individual and they embrace the spirit of privacy.
