About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



4 J. Cybersecurity 1 (2018)

handle is hein.journals/jnlocybrs4 and id is 1 raw text is: 





h'3  I~A


Journal of Cybersecurity, 2018, 1-20
        doi: 10.1093/cybsec/tyy001
                  Review article


Review article


Forgetting personal data and revoking consent

under the GDPR: Challenges and proposed

solutions


Eugenia Politou, Efthimios Alepis and Constantinos Patsakis*

Department of Informatics, University of Piraeus, Piraeus, Greece

Corresponding address: Department of Informatics, University of Piraeus, 80, M. Karaoli & A. Dimitriou St., 18534 Piraeus,
Greece. Email: kpatsak@unipi.gr

Received 23 June 2017; revised 8 November 2017; accepted 16 February 2018


Abstract

Upon   the  General  Data  Protection  Regulation's  (GDPR)  application  on  25  May  2018  across  the
European   Union, new  legal requirements  for the protection of personal data will be enforced  for data
controllers operating  within the EU  territory. While the principles encompassed by the GDPR were
mostly  welcomed,   two  of them, namely  the  right to withdraw consent  and  the right to be forgotten,
caused  prolonged  controversy  among privacy scholars, human rights advocates and business world
due  to their pivotal impact on the way   personal data  would  be handled   under the  new  legal provi-
sions and  the drastic consequences   of enforcing  these new  requirements   in the era of big data and
internet of things. In this work, we firstly review all controversies around the new stringent definitions
of consent  revocation  and the  right to be forgotten in reference to their implementation   impact  on
privacy and  personal data  protection, and secondly, we  evaluate  existing methods,  architectures and
state-of-the-art technologies in terms  of fulfilling the technical practicalities for the implementation
and  effective integration of the new  requirements  into current computing   infrastructures. The latter
allow us to argue  that such enforcement   is indeed feasible provided  that implementation   guidelines
and  low-level business  specifications are put in place in a clear and cross-platform  manner  in order
to cater for all possible exceptions and complexities.


Key words: GDPR; privacy; the right to be forgotten; data protection


Introduction

On 27 April 2016, after four years of drafting, lobbying and negoti-
ations among the EU Member  States and many affected organiza-
tions,1 the EU General Data Protection Regulation (GDPR) has been
agreed and finalized, whereas on 4 May 2016 its final text published
in the Official Journal of the European Union [1]. Following a two-
year implementation period, the GDPR will be applied across the
European Union from 25 May 2018.
   The GDPR's  introduction aimed at replacing the Data Protection
Directive 95/46/EC (DPD) [2] introduced in 1995 and, being a
directive, left some room for interpretation during its transposition into

1  http://www.eugdpr.org/gdpr-timeline.html; https://edps.europa.eu/data-
   protection/data-protection/legislation/history-general-data-protection-regu


individual national laws. In addition, the rapid change in data landscape
caused by the explosion of ubiquitous and mobile computing and the
big data era, had led to the necessity for another update to the regula-
tory environment within the EU. Yet, the radical changes brought in by
the GDPR  are impacting severely businesses operating within and
outside the EU territory. Most importantly, as a regulation and not a
directive, it will immediately become an enforceable law in all Member
States and hence, it will contribute to the harmonization of current data
protection laws across the EU, enhancing at the same time both data
protection rights and business opportunities in the digital single market.
   The regulation accomplishes its objectives, on the one hand by
strengthening the well-established data protection principles already

    lation\_en; http://www.jimmcguigan.co.uk/EJCNews\_July2013DATA\
    %20protection\_bothstories.pdf (28 February 2018, date last accessed).


OThe Author(s) 2018. Published by Oxford University Press.


This is an Open Access article distributed under the terms of the Creative Commons Attribution Non-Commercial License (http://creativecommons.org/licenses/by-nc/4.0/),
which permits non-commercial re-use, distribution, and reproduction in any medium, provided the original work is properly cited. For commercial re-use, please contact
journals.permissions@oup.com