Current nanotechnology regulation is focussed on risks. On the other hand, technical guidelines and other soft law tools are increasingly replacing hard law. This risk reduction approach does not seem to be fully aligned with open principles like sustainable nanotechnology. Indeed, risk optimization tends to be rather a continuous process than a way to settle ultimate lists of risks. There is therefore a need for a more dynamic view: Life cycle assessment contributes to add momentum and context to the models. However, a complementary perspective is here suggested, based on information technologies: nanotechnology platforms. Platforms for nanotechnology governance are supposed to complement and enhance the nano-regulation, adding risk assessment and management. These platforms are mainly offering information, coordination, and context or situational awareness. More recently, some informal platforms appear to play a, certainly limited but still clear, co-regulatory role. Can these informal platforms play a relevant role in nanotechnology governance? In the context of the EU Better Regulation strategy, why not envision some of these informal platforms as future co-regulation tools? The main goal of this paper is to start a discussion on the requirements these informal co-regulatory platforms should fulfill before their hypothetical inclusion in a future better regulation toolbox.
WP29 has recently adopted Guidelines on Automated Individual Decision-making and Profiling for the purposes of General Data Protection Regulation 2016/679 (GDPR). Article 22 GDPR bans all decisions that affect the data subject which have been based solely on automated processing. The Article eventually allows automatic processing, conditional on application of suitable safeguards for data subject rights. These safeguards might vary substantially depending on automated processing technologies. This article describes, firstly, the general safeguards to embed legal requirements. Secondly, the article explores solutions for automatic processing based on data analysis. It is argued that, although the data controller can put in place safeguards that respect data subject rights, a parallel empowerment of external authorities will be necessary to reach both: an informed external oversight, and the full application of this right. This article seeks to provide an analysis of Article 22 GDPR in the hope that this will inform the policy debate. Keywords: Article 22 GDPR; automated processing; data analysis; agreement technologies; multi-agent systems; internal/external oversight
The aim of this paper is to establish the grounds for a future regulatory framework for Person Carrier Robots, which includes legal and ethical aspects. Current industrial standards focus on physical human–robot interaction, i.e. on the prevention of harm. Current robot technology nonetheless challenges other aspects in the legal domain. The main issues comprise privacy, data protection, liability, autonomy, dignity, and ethics. The paper first discusses the need to take into account other interdisciplinary aspects of robot technology to offer complete legal coverage to citizens. As the European Union starts using impact assessment methodology for completing new technologies regulations, a new methodology based on it to approach the insertion of personal care robots will be discussed. Then, after framing the discussion with a use case, analysis of the involved legal challenges will be conducted. Some concrete scenarios will contribute to easing the explanatory analysis.
Technological threats to privacy are not limited to data protection. Social Network Applications (SNA) and ubiquitous computing or Ambient Intelligence face other privacy risks. The business model of SNA and the improvement of data mining allow social computation. SNA Regulation should then favor privacy-by design and Privacy Enhancing Technologies (PET). Default friendly-privacy policies should also be adopted. The data portability of the applications shifts SNA into a new field of ubiquitous computing. Therefore, the solutions of the Ambient Intelligence should be also analyzed in the context of SNA.
This paper describes the analysis of the requirements and the knowledge acquisition process for the development of a legal ontology for the representation of data protection knowledge in the framework of the NEURONA project. This modular ontology is used in the NEURONA application to reason about the correctness of the measures of protection applied to these data files by an organization. In this sense the use of legal ontologies could not only provide legal professionals and citizens with better access to legal information, but could also support data protection and privacy compliance in organizations and administrations.
The technological risks for privacy and anonymity are not limited to the problems of databases. Social networks, RFID tags, ubiquitous data processing and robotics, for example, are other examples of risk. Social networks have an economic value and search engines increasingly try to access their users' personal information. In contrast, the study of privacy in social networks is a new area. Experts in information technology generally consider privacy as a quantifiable attribute which can be negotiated and probably exchanged between individuals for certain benefits. We believe, on the other hand, that regulation should favour the socalled Privacy Enhancing Technologies (PET) to guarantee privacy, and that these are particularly necessary