EU privacy law to require opt-in and make data processors share in responsibility

Businesses breaching new privacy rules could face fines of up to 4 percent of annual revenue

The shape of future European Union privacy legislation is becoming clearer, as lawmakers closed in on an agreement late Tuesday.

Companies will have to obtain customers' consent before collecting and processing their personal data, and could be fined as much as 4 percent of annual revenue for breaches of the rules. That would put potential penalties for giants like Google and Facebook in the hundreds of millions or billions of euros, compared to the paltry fines of tens or hundreds of thousands of euros that national privacy regulators can impose even for mass data breaches today.

The new laws will also make data controllers -- typically the companies collecting personal information -- and data processors jointly liable in case of misuse. Legislators hope that will cause companies to choose their partners more carefully.

Lawmakers have so far been unable to reach agreement on a minimum age at which EU citizens can consent to their personal information being collected, enabling them to sign up for social networking accounts without parental approval, for example. Members of the European Parliament had hoped to set the age at 13, but some national representatives in the Council had held out for a minimum age of 16. It now looks as though each member state will be allowed to set its own age limit between 13 and 16, obliging businesses wanting to target minors across Europe to add a few extra lines of JavaScript to their sign-up pages.

EU laws come in the form of either directives or regulations. Regulations apply directly to EU citizens and companies doing business in the EU, but the effect of directives is indirect: The 28 member states each have two years to transpose them into national law, often resulting in subtle differences in implementation from one country to another.

Existing EU privacy rules derive from the 1995 Data Protection Directive, meaning that companies must deal with a patchwork of different interpretations across the EU.

In January 2012, the Commission drafted a new General Data Protection Regulation, which Parliament approved, with modifications, in March 2014. Representatives of EU member states have been haggling over amendments to it ever since, reaching a compromise text that should be acceptable to Parliament on Tuesday evening.

Parliament's Civil Liberties, Justice and Home Affairs Committee (LIBE) will vote on the text Thursday, and the European Council too must give its approval.

The level of fines is one of the more obvious points on which compromise was required. The original Commission proposal set the level at 2 percent of global revenue -- compared to a maximum of 10 percent in antitrust cases -- but Parliament wanted to crank that up to 5 percent.

The age limit for consent was a source of disagreement within the council: Unable to pick a number between 13 and 16, national representatives settled on allowing each country to choose its own age of majority for data protection purposes.

The negotiations over the General Data Protection Regulation ran in parallel with those on a related directive, on data protection standards for cross-border police cooperation. This is intended to allow security forces to exchange information about suspects while still protecting EU citizens' privacy.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Peter Sayer

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?