Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

EC Data Protection Directive described as "dead"

by The Gurus
June 17, 2020
in Editor's News
Share on FacebookShare on Twitter

The European Data Protection Directive is effectively dead, due to the infringement upon European citizens’ human rights.

Speaking to IT Security Guru, privacy consultant Martin Hoskins said that the European Commission’s justice and home affairs legal team has deemed it to be “unlawful” as it breaches the human rights of customers as they may have to go to a foreign jurisdiction rather than their national privacy commissioner.

“If the lead regulator was in Ireland, then someone in the UK who had a problem wouldn’t be able to complain to the UK Information Commissioner, they would have to complain to Dublin,” he explained.

“What would happen if someone in Poland or Portugal complained to a Lithuanian regulator? How would they know what the rulings were? Can they speak Lithuanian?  It is fine if you are Lithuanian, but what if you are Polish? It is not good enough for citizens. Why can’t companies be subject to one regulator rather than the whims of all 28?”

Hoskins doubted that the regulation will survive in its current format. “It will be interesting to see what happens; next time it will be a directive and not a regulation. It has got to be a directive, as the concept of a regulation is that it is a detailed law but it applies everywhere. Data protection is based on principles and local cultures, and you have got to meet local attitudes to privacy, which are different in local cultures”, he said.

“So effectively the current proposal is dead – what they want to do is bank the progress that has gone on with the member states and Home Affairs council, and bring the draft into the new European parliament when it meets.”

Stewart Room, partner at Field Fisher Waterhouse, said that the current directive is built around a “one stop shop” principle, which is intended to streamline regulation by having a data controller in each country, so that controllers can be subject to regulation in every country where it does business. However, this one stop shop principle may actually breach the fundamental rights of individuals, because it may make access to justice much harder, according to EC lawyers.

“Basically, if you have to complain to a regulator in a different country, and perhaps in a foreign language, that will make it harder for you to pursue a complaint about bad data processing, hence access to justice is harder,” he said.

“So, if this point is correct, the regulation might be in real trouble. It would be brave to say right now that the regulation is dead, but time is running out for it to be adopted by the initial cut-off point in May. It will take a big effort by the EU and the Member States to get it over the line by then, but that’s not impossible.”
Hoskins claimed that the problem is that the EC has never had such a large piece of legislation fail, and this faces a race to be passed before the European Parliament changes at the end of April.

Hoskins said: “The issue is who is making decisions next time. It will be a Euro sceptic parliament, so you wonder if a Euro sceptic parliament will be happy with more power going to the centre. In the UK, some would prefer to stick with the ICO than lots of power going to a European institution. There is too much to do and the structure is not there to be able to consider such huge issues.”

Room said that the European Union may go for a new directive instead, but said that would be a humiliating climb down for the writers of the report.

The directive was originally announced in January 2012 by Viviane Reding, vice-president of the European Commission in charge of justice, fundamental rights and citizenship. She said it was intended as a single set of rules on data protection that would be valid across the EU’s 27 member states and would create “one data protection authority for one company” and “one authorisation for the whole of the EU”.

Major changes were announced in November around the size of the fines and to the “right to be forgotten”, while in December the directive was described as being “incompatible” with the Charter of Fundamental Right due to the absence of sufficient regulation of the guarantees governing access to the data collected and retained, and because member states have exercised their powers with moderation with respect to the maximum period of data retention.

Tags: Data Protectionprivacy
ShareTweet
Previous Post

The new Guru website

Next Post

Verizon’s identity services give FrieslandCampina secure, anytime, Global information access

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol