That may not apply, because of the clever (evil too, but also clever) way they are doing this.
If they were asking as data subjects where the data came from (which data subjects have a right to under Article 15 1(g)), then journalism and public interest exceptions should apply.
But that's not what they are doing. They aren't coming in as data subjects asking about the data held on them. They are coming in as an Article 51 supervisory authority in charge monitoring GDPR in their country. They are claiming to be doing the tasks Article 57 assigns to the supervisory authority, and exercising the powers Article 58 gives them for that.
Presumably, someone who the journalists wrote about alleged that the journalists were not complying with GDPR in how they obtained and used the data.
And so now the supervisory authority is investigating that. Article 58 gives them power "to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks". They can probably argue that in order to decide if a journalism or public interest exception applies, they have to know where the data came from and how it was obtained.
Assuming things are as corrupt as people have claimed, I'd expect they will go in, and if they obtain the information on the sources, they will rule that a journalism or public interest exception applies, and dismiss whatever sham GDPR complaint they had someone file to set this off.
That somebody is the chief of the ruling party, Liviu Dragnea, president of one houses of parliament, who almost got to be named prime minister if not for an earlier conviction for electoral fraud.
He was now found guilty in a second unrelated criminal probe, and is appealing the sentence while at the same time trying to steer the legislative process and pressure his own party to decriminalize a large swath of offenses pertaining to his case, namely abuse of public office.
The journalists have recovered a large trove of damaging documents that are related to yet another criminal case (3rd, if you're counting) in which he is being investigated.
The head of the data protection agency is a former colleague from the same party and is herself under criminal investigation for fraud. Yeah, so these are the watchers.
Compare Romania's one sentence implementation of the journalism exception (translated by the EU website so perhaps not the best):
>In order to ensure a balance between the right to the protection of personal data, freedom of expression and the right to information, processing for journalistic purposes or for the purpose of academic, artistic or literary expression, it may be carried out if it concerns personal data which have been made manifestly publicly disclosed by the data subject or closely related to the public personality of the person concerned or the public nature of the facts in which he is involved
With the U.K.'s implementation of that same exception [at Part 5]: http://www.legislation.gov.uk/ukpga/2018/12/schedule/2
If so, that is a pretty nasty unintended consequence.
When cheering on such laws, we should always ask ourselves whether we're cheering on the intent or the practical/potential effect. When viewed in the latter context, one might instead cheer on a much smaller, incremental approach towards such legislation (if at all).
The latter is often appropriate; people should be free to do what they want unless others are affected significantly. But when it comes to privacy and freedom of speech, I don't think so.
This cannot be generalized and is different depending upon the circumstance. In this case, I wholeheartedly disagree.
If we took into account the uncertainty properly, I think the balance would look very different, and many laws wouldn't pass simply because no-one would be able to vouch for the actual effects.
Even so, there are not the same "downsides and unintended consequence" to every option, nor they have the same impact for every option chosen.
So, this is not some "6 of one, half a dozen of the other" case.
>The question is, do we want that power to be controlled democratically or to be arbitrarily exercised by the most powerful?
Whatever we want, in practice, and for pragmatic reasons, we usually get just a mix of both. So it makes sense to have laws that don't give so much possibility for arbitrary execution, or don't give too much power when arbitrary executed.
You can remember whatever you want, about anyone or anything.
"This Regulation does not apply to the processing of personal data:
* "in the course of an activity which falls outside the scope of Union law;
* "by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;
* "by a natural person in the course of a purely personal or household activity;
* "by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security."
I thought the GDPR sign at the butcher shop was a joke?
What if this person had a hobby of simply collecting and cataloging information bout people they come in contact with?
Then they are a data controller.
"A data controller is the individual or the legal person who controls and is responsible for the keeping and use of personal information on computer or in structured manual files.
(...)
In essence, you are a data controller if you can answer YES to the following question: Do you keep or process any information about living people?"
https://www.dataprotection.ie/docs/Are-you-a-Data-Controller...
https://www.occrp.org/en/16-other/other-articles/8876-englis...
Hopefully this'll go to court and set a precedent that more in line with the spirit of the gdpr.
Of the western world we have the US, UK, and Canada that employ common law where precedent really matters.
In most of the EU the system of civil law is used, where the judiciary is expected to be much more literal and to not perform much interpretation or reference to previous interpretations.
It's still secondary to the statute and not 100% binding, but nevertheless it is a real part of the system.
Also, both the US and Canada have a civil law jurisdiction: Louisiana and Quebec, respectively.
Both do make some use of common law as well, but private law (governing relations between non-state parties) is even now predominantly civil law in both places.
If the original actors in this case were non-state parties, I expect that civil law would be applicable to a hypothetical Quebec version of this dispute. In Louisiana, same thing if the relevant law was at the state level rather than federal. (In Quebec, even federal laws are interpreted using civil law principles when covering private law topics.)
This is the problem with GDPR. Each member state decides what's clear and what's not. It may be appealable. But that's expensive, time- and attention-consuming and risky.
We need strong privacy regulation. One downside to a fragmented complain-investigate-fine regulatory structure (as opposed to strict liability or complain-mediate-investigate structures) is that these things happen, and when they happen they do so decisively.
It doesn't help to add arrows to their quiver. GDPR is a good law when a government can be trusted. It throws petrol on the fire in over-reaching states.
Literally the argument you would eventually see at the end of threads about GDPR. I don't know how many times I've said this, but it amazes me that people can feel so identified and represented by nation-state politics that they are so willing to trust their government.
And you're building a strawman with GDPR supporters, I don't think anybody said that nobody would ever try to abuse it. The GDPR has explicit provisions protecting journalists. It remains to be seen how this particular case pans out and if they truly manage to get the journalists to expose their source (or get heavily fined). If the Romanian authorities really manages to get this through and the rest of the Eurogroup doesn't react then yeah, that's quite worrying.
Also note that it's not like without the GDPR those journalists would be able to work peacefully anyway:
>Dragnea invoked the European data protection legislation last year when he threatened RISE Project with a lawsuit after journalists published stories on his connections to Tel Drum SA executives and other Romanian business people indicted for corruption and fraud.
>The president of the PSD never sued but soon after these threats were made, the Romanian Anti-Fraud Authority (ANAF) raided RISE Project’s offices, saying they suspected the organization of fraud. The investigation carried out by ANAF never uncovered any such fraud.
>RISE Project discovered that the initial complaint ANAF used to target RISE was a forgery filed by a non-existent person, with a non-existent physical address who falsely claimed that she worked as an accountant at the media house.
Due process is not really the keyword here from what I understand from this article. Something tells me that if it wasn't about the GDPR it would be something else.
I can't imagine that's true for investigative journalists reporting on corrupt governments. Big corporations do plenty of harm, but mostly in large-scale aggregate effects (like manipulating prices, tracking online behavior to deliver ads, creating filter bubbles in social networks, etc.), but governments can and do throw people in jail or worse.
I don't think the accusation is fair. All discussions I saw here about GDPR contained the line where opponents were raising the issues of trust to authorities, and supporters dismissing them.
Agreed. Just.
Stasi operated in Germany just a few decades ago. Romania had Ceaușescu. But no, it's the evil corporations that are dangerous. The governments would never abuse human rights or anything like that.
Not I when I step back and assess potential and actual harms done. This is especially true the larger-scoped the laws and power given.
> And you're building a strawman with GDPR supporters, I don't think anybody said that nobody would ever try to abuse it.
Right, and the commenter didn't assert they did. The commenter quoted a phrase I too would hear frequently and questioned the trust people place in their institutions. Is there a term for a straw man straw man?
> If the Romanian authorities really manages to get this through and the rest of the Eurogroup doesn't react then yeah
Can the use of it as a threatening tool not be enough to require reaction? Must it get through? Why so much toleration?
I wouldn't trust them even if I elected them, because people and especially politicians holding public office can and will eventually turn rogue.
But I agree with you that if it wasn't the GDPR it would be something else: alleged tax fraud, money laundering, you name it. Stuff taken out of their own playbook. It's is just blackmail and racketeering executed by state insitutions. This is why we need strong checks and balances against state institutions and time limits for holding office against politicians.
Fact of the matter is, that the GDPR is a pile of shit (it's basically an argument that only the Government should be allowed to amass and weaponise information, where I'd argue that nobody should be allowed to), but so is the mass centralisation of information in the hands of large, powerful entities that it's intended to target. And one would be entirely unnecessary and unwarranted without the other.
But it's no surprise when the press is called "the enemy of the people"
That's no so much a problem with GDPR as nation states.
As an aside, "nation state" is not a fancy way of saying country. It has a specific meaning denoting a mostly ethnically homogeneous nation. E.g. Belgium is most certainly not a nation state.
- one world government? All the problems of nation states and then some. Plus nowhere to seek refuge. It's not like a government more powerful than all todays governments would magically become less corrupted.
- no government? Has it's own problems as well.
What we have today is a mess but IMO it's the price we have to pay to avoid the worst dictatorship imaginable on this earth or going back to the dark ages.
Out of GDPR and nation states, only one can be abolished.
That was a big problem with the Data Protection Directive (which the GDPR replaced).
But now the European Data Protection Board[0] (basically, the supervisory authorities from the member states and EEA member states, plus the European Data Protection Supervisor) can make sure that each supervisory authority is - approximately - following the same standards.
Each case gets filed in a common system by the lead authority investigating it and cases gets discussed between the Board members.