Papers1 provider · 1 record
July 28, 2021· International Data Privacy Law
article
Open access

Cobwebs of control: the two imaginations of the data controller in EU law

Abstract

Article 4(7) of the General Data Protection Regulation1 (‘GDPR’) defines the data controller as the natural or legal person that determines the purposes (the ‘why’) and the means (the ‘how’) of personal data processing.2 Article 24 provides that ‘[w]here two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers’. These legislative definitions seem to indicate that the controller decides why and how data is processed. Over time, however, regulatory guidance and judicial interpretations have significantly reduced the threshold of influence that is required. Whereas the determination of the purposes remains a condition (almost always fulfilled as any product or service’s use is motivated by a given objective3) even the most marginal influence over the means, such as enabling someone else’s processing, suffices to be a controller. Ever more parties intervene in the personal data value chain as a consequence of technical and economic factors and the draft Data Governance Act also pushes in that direction.4 As a consequence, parties with no access to the data or the software used to process it are controllers. The mellow definition of control, coupled with the restrictive reach of the household exemption and the growing decentralization of data collection, storage, and processing entails that ever more parties are controllers. This includes data subjects, which increasingly qualify as controllers both in relation to others’ data as well as their own, something that is antithetical to the GDPR’s objectives and indeed the very structure of the law. The conception of control in EU data protection law, coupled with the restrictive reach of the household exemption and growing decentralization of data collection, storage, and processing entail that ever more parties are controllers. This includes data subjects, which can be controllers in relation to others’ data as well as their own despite this being antithetical to the GDPR’s objectives. The expansive approach towards controllership has been motivated by an assumption that the more parties are responsible for compliance, the more protection data subjects enjoy. This article rejects that assumption by highlighting that (i) broad definitions of control fail to achieve the stated objective of the complete and effective protection of data subjects; (ii) are undesirable from a political economy perspective; and (iii) undermine the law’s effectiveness. In parallel to the prevailing interpretation of controllership, however, a parallel imagination of the controller, which presupposes meaningful influence over the techno-organizational elements of processing, can be made out. The article closes by suggesting a new test of control that returns to the etymological and conceptual origins of concept by requiring a de minimis threshold of influence over the means of processing. The growing pulversization of control in fact sacrifices two of the GDPR’s underlying objectives. First, complicated networks of responsibility lack transparency and impede the effectiveness of the law and thus lower the protection of data subjects. Secondly, a political economy perspective reveals that this legal interpretation supports intensifying forms of private power and this despite the law’s intention to address power asymmetries. This is particularly problematic as it enables the design of complex cobwebs of control the principal purpose of which is to complicate enforcement. The current definition of control incentivizes ‘real’ data controllers to design their systems that data subjects, have control to qualify as controllers to influence how data is processed. this control controllers to legal it to and the of data Article 4(7) and interpretations are the imagination of a parallel which to have the of and that natural and legal that are to influence data processing effective and control over the data and software used to process are controllers. This of control is in 24 and and presupposes meaningful influence over the techno-organizational elements of processing. The article closes by suggesting a new legal which returns to the etymological and conceptual origins of controllership and presupposes influence over the techno-organizational structure of data processing by requiring a de minimis threshold of influence over the The two of data subjects and is an assumption that of the always is data and data The data is the or natural person to which personal data The definition of control is more complex and has been to Article 4(7) provides a and definition of defines the controller the natural or legal or or jointly with determines the purposes and means of the processing of personal the purposes and means of such processing are by or law, the controller or the for be for by or law natural or legal person is thus a controller (i) they are as such by law, or (ii) by of their This is with the and most determine the it is to determines the purposes and and the more the purposes and means they are joint This approach is to the influence an as to be as a controller it Article 4(7) as the means and purposes are two factors of Over time, however, law and regulatory guidance have the of the purposes guidance has that the purposes of the processing in any the as controller, the means control the determination the elements of the to the the of and the means such as data is the of the processing, of and data the time, the that the to use and joint controllership of the can the processing of data to be can be a controller meaningful influence over the processing. the to use a given or a given to a determination of the of from and that the threshold of influence over the means for joint controllers is very This that as more they also are the for a broad interpretation of control to a of protection of data The that are two controllers in relation to a First, as it determines the purposes and means for and of Secondly, as they to of to determine the purposes (the objective of a and the means by of data collection, the that a by it as a controller even they data in In the that control access to that controllers to be to personal data and the as a controller in relation to data by even it that 24 In a a which a to data from the and data to that (the as a controller even as it to influence the The the to the of control to a of protection of data The to data of to of or the is a of the it influence over the and the no access to the data by to can be a joint controller is an objective to process the data (the even (i) access to the and (ii) marginal influence over the means, such as in to use a given very marginal influence over means of the that the person in it for personal data to be and coupled with that such a joint controller has as to the is of This the of is controller that is to with The law however, the of for joint controllers. Article the the controller to and with the The is controllers are to with of the or of and which In law, the that responsibility controllers and that their responsibility be with to the in of the the the to determine responsibility that the that broad broad can be First, control be the of the The of a the is a and with controller indeed has a to that they have a legal The however, that as that controller have no access to the it determine the elements of the processing or that is this is the legal As a consequence, such the thus be address and and this personal data to with the such of the that controllers in the most of the processing in relation to purpose controllers that have no access to the data or software are in no to any such These are of joint to with the Secondly, the be as that a controller to to the that it Whereas this be more in of the value of such responsibility can be is the of controllership also in of which a a of the law the Data Protection the an in the of Article that joint controllers shall determine their particularly as and data means of an which has to a for data subjects. Whereas the a it can be that the to be in as to be made to the data This that joint controllers are of their and to such an also for that parties are to This however, the as be and the is to controller to for the of the or or controllers are of their to the of the law for the of it is an to that any the design of responsibility have or of lack the and and even in they are by power as and of use are made in a particularly has the they to their Article is a of the a of joint and that data subjects to any of their any of the controllers the The can thus or the design of data processing systems data data subjects can that the to a Article which they of control over the This be however, the or the an of controller being with a for it an with that controllers to with data protection law in the of their and however, it also stated that they the and complete protection of data law more the and Article law the of controller are or they have the more and more the law controllers to something they are to Article controller to a of processing This to the and the of a have of or how are to determine the purposes their data and the data protection by design and by Whereas to or that processing (i) is to in a for data subjects; (ii) is and (iii) includes of data of elements being in the law the of controllers is with is Article which provides that any person or as a of an have the to from the controller or controllers that have to the are from they can that they are any with influence are This the of the of law to means that a has a to others’ of use or the processing of or an to the and the The and have which shall be and This for an of the particularly a an of the or and the of This that controllers influence over the data protection be to ‘real’ data controllers to from broad definitions of In increasingly data a that influence over the processing of personal is a joint even it has no access to the data or In a with ever more and data more and more or or the processing of personal both of and it has and been that the the of control is to a of protection to data in General that any interpretation complete control over of data processing in of however, be a broad definition of control is in the of data subjects as it responsibility a of that be to the law. to the this broad definition of control is as personal data of also processed. a Data protection is an of the law and is no for a with a controller a data can as the design 24 and even data subjects a controller has no In General effective protection is is made that the current test even and be controllers as they the This of control is a that ‘real’ controllers structure their that the have control to be a controller to have any meaningful influence over the processing. it to complicate the of data protection by data subjects from their As the controller to the law and is the of a broad definition of control being the of and a of data The current of the law incentivizes responsible and from the processing to cobwebs of control in to by controllership to data subjects. As a consequence of the of control, the restrictive reach of the household and even data subjects be controllers both in relation to others’ data and their This has thus indeed the new legal are controllers and this despite the of natural data processing. it has always been that a data can be a controller as the Data subjects their own purposes in systems and also increasingly control over the means the processing As such their as controllers is the of the and indeed the of that This the that data subjects can be controllers by the of the household exemption and the law to the of and by highlighting the that responsibility for data protection in the be to data subjects to with design over the from to Article the to the processing of personal data by a natural person the of personal or household that processing personal or household it has to a or such as private and the of also and the of such The has and that this exemption has to be that the exemption to which are in the of private or of which is the with the processing of personal data in the that data are made to an of law the that to a of the exemption be and that it to that the data to an of that a to personal data to an of and of the The of forms an to that in the legislative (the of the the exemption can be the to controllers or that the means for processing the The Article the household exemption in networks in that (i) are controllers as they determine the means and they determine the purposes and (ii) the also be and (iii) are controllers the household exemption they a political or or they the the of it is the of the to can determine also they are to the by of the in such as have indeed that of qualify as This however, no in the Whereas a data thus be a data controller the also in The is of The of is to to by an to to can be with the consequence that more data is being and processed. In such complex networks data is in and in the of the is This can be the of has that the of the household coupled with an definition of control and of determine the purpose use a to and and in also the means the to use an a technical perspective is a that enables data and a a that data the that can be controllers has of both to and is is the controller, such as a the and a is the or the These definitions of control a that can in undesirable such as even they Article that controllers their and to data subjects. This the use of a data of is a in relation to the also has been the and the of controllership as have that data subjects can be controllers in relation to their own This has been in the and a that be both data for the personal data that they to the and data by of a of the their own In the de a suggesting that a natural person a to process personal data in a that no to a or as for their own this person to be as a controller by of the of the household In of the law it however, the household exemption can personal data is a and it is made to an of The exemption thus be by someone a for private purposes which is it the as the of be by the data is used for the and are to data the household exemption be the to the that the data is a data controller in relation to own are a of with in to the of data the to and the and personal data are increasingly as a technical to address data and to of is to use a for in the of technical means to data in that enables the and of data as well as and and transparency for and an of data protection by design and by are no First, as be in more the of is and the of and Secondly, data has the of a over that data as the to control any the and power that has that of be a is used in a of in a they use of such systems in their in the of or for their their or even the being as a joint can be for that to from the that with personal data their own as they to value from data responsibility for the that with and processing. As they also being a of to the of processing to data subjects. Data subjects increasingly being controllers both in relation to others’ personal data and their The growing decentralization of the and of data in a of This can even be a by the ‘real’ controllers to complicate the structure of and enforcement. a data is a controller in relation to others’ data an to a complex the fact that they can have a influence over the techno-organizational This transparency and legal and for data subjects and and the effectiveness of the law. a data is a controller in relation to own the legal is that the data and controller be the person that be with of processing that is a be as in most an with for person to that process the that the data subjects and controller are to be with These are that that data protection law with a data controller in The of data protection law can be by the fact that data subjects and controllers have a more of the of data subjects, which the law’s objectives. This that a data controller is also the law’s underlying and a political economy The and of a data controller be in of the law’s no EU data protection law, which is the of a of and to Data protection in In data protection has in the concept of In it from the concept of in it to the to it to objectives. First, it is to the to data as by Article of the of The GDPR’s even that data protection is to to of natural and to the an to the of personal data from to and by that the economy to natural have control of their own personal an objective that is in the also to to the of an of and the can be as a to the that personal data is processed. The in fact to the to the processing of personal and data protection as a for that data are and that the of are In data protection to achieve objectives that in to This can be an of the two objectives that are most for the and data objective of data protection law is to data subjects control over The control is an of the of that has data protection law. In a this is as an as from to In with this be to determine to to influence of data protection is no to control in Article of the this in law In the to the GDPR’s the to that the new control to which to that the control a of the In the GDPR’s of data enables data subjects control over This also has a as it a the most of the control the time, in a to the of data and however, growing that are no in a to the of data that is the which this the that have access and the has thus in of data as control presupposes an that can no be of the or even the of they fail to for and data the in a has that this a that data to is the of the data that a use of data be as data it be with and how data Data subjects also from the and from the of such as data of which have been given and data subjects be from the data that they and how be data subjects to complex data processing economic from their and the towards that are to in a it this is Article that the they can is to use a given product or The control can also be for for such as that the processing of data personal data can have for data subjects. the for processing that is used is and fail to they be the of data by with can thus be the of data protection law. Data protection to data subjects from to the processing of personal to Article the and of natural and in their to the protection of personal and that is to a and of This is also by the fact that the from they qualify as a or a First, a data such as a or The to be by or power Article of the that has a to data of this or that have This that data protection is an enabling and a of in law, also law or that to a of their are in an with Article of the which a in that personal data can be for a the controllers to for the of the data also for of the increasingly of data processing and the of to be this also has that are to even their This can in of the the is to such as or and economic data the of personal The is as to their which has been to such as the of or to data protection to impede the which is why law to even a data to any of for controllers In the that a in that it as a for the and by of the personal this is can be As that the has a of the and of data are that data is they have no of the perspective reveals that data protection law a power and The in the of to the of the the time, personal data in which be in a time, and by the person control over the of data processing the time, it that the controller always have assumption the the Protection of and of which the controller as the is to the and use of personal which be in processing personal data and have access to data are to data be be to use are from that even it to that the controller have power over of the is to why a is to to data and as a The also such as the of and power which are by data The has indeed been as to power and that of the data controllers and are decides over and from data processing, are that use systems for their own purposes and have marginal influence over the This enabling in which responsibility is purpose or from that most from the processing and in power of data subjects and of they are with they lack the means to The GDPR’s definition of control can be as an of how the law supports intensifying forms of private enables a of responsibility the of which is to responsibility for from that control the means and purposes the of complex cobwebs of control the principal purpose is to complicate enforcement. definitions of control also the of the law’s as data subjects for of of their as a The current of the law also in with the objective in that the protection of data subjects a of the is for this that an the the for be The indeed that this is and to the data with a more and In the that the as a controller as the of a in the of thus made the for a broad definition of control also The in law, as controllers with no controllers. that to be from a political economy data protection law to and responsibility to from processing others’ data and techno-organizational Whereas this has that this is to the objective of power it also with the of control in 24 and This article has that control over the data and technical means used to process it qualify as controllers. Whereas they are to and influence the of the data processing, they are to have that this with the as well as intention to address power asymmetries. The interpretation of Article 4(7) the of control in 24 and which a that the controller the techno-organizational of processing. Article 24 is to the of the and it to and to the and purposes of processing, as well as the The controller be to that processing in with the to the effectiveness of the and to Article is to data protection by design and by and that controllers technical and such as to data protection in an effective to the GDPR’s and data be that a joint controller technical and they use software by a that has such an the of by the such as seem to that controllers are to be in a to determine this Article that a it to determine that the data to achieve the purpose is (the data This the controller to of personal data the of their processing, the of their and their to the to that in the controller is to be a legal the of an of the controller has also been made by the that controllers to they a new processing and processing, and also the of processing, by the effectiveness of the and and also the controller to use of the they be in a to determine that to controllers be in a to it that that a controller the of data processing also that they the software with however, technical and access to the data and software that be of and are no that be more 24 and for that a controller always the means indeed that they influence over the processing of personal is a of a is that it is As the is the of the concept of data protection by with the effectiveness that controllers can that the they have are controller access to data and software achieve an effective to a of responsibility and transparency the processing as well as the of of this is to achieve in such as of the for the broad conception of control in that the also data of The that it the protection to data subjects it the as a joint controller, to with data protection law that have As this it is to that that control over the data and software to controllership the is however, to that in data subjects from complete and effective of that joint controllers data subjects to their data and that is a legal they design software as to with this and is no for data subjects to have an with it for this to the of controllership the of have of complex cobwebs of control that that the is and enforcement. This is particularly that has the of the is the of of that from the of the processing, more in with the GDPR’s to address power asymmetries. to the interpretation of Article 24 and that a data controller have control over the processing of personal and (the to the of the in that in to be a data to control the data and software used to process this in be it has in interpretations of the the to qualify as a controller control over the data and software used to process of legal control, which control, can be 24 and In the for the to be a controller, it the power to with to the the to the The of that the a controller as it power in relation to the purposes and the The and the that a to use for and is to a joint In the that a data controller be the of and also that processing of personal data be from and is to that of the and processing the data In data controllers that lack control over the personal data the software used to process it process the data and the to data interpretations of control entail that the of data processing systems have to that they are or be to be controllers and to legal to their is a lack of transparency and legal for both controllers and data subjects, which in the law’s effectiveness. the current of the law the for systems to the law. Data protection law’s of a and approach to the determination of controllership is to the of responsibility from the over time, the of influence over the of processing to qualify as a controller has to be The of a given or or the fact that an enables someone to process personal data from that processing even being of an interpretation from of control and no purpose of the complete and protection of data subjects. the new of and the (the purposes and is as an influence the purposes and means of the In to the of of or to undermine the law to the origins of the concept of the controller and an exemption for parties with no meaningful influence over the data processing by requiring a threshold of influence over the law a de minimis threshold of influence over the means of processing to qualify as a data controller. to this parties that determine the purposes and the means the of a or and the enabling of someone else’s processing be controllers. This be more in with the as it transparency and legal and also is it be more in with political economy Data protection law is a that to the that personal data is processed. These be that have power over the processing of personal data and the

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.