Facebook Pixel

Data Protection by Design

From Abstract Principles to Implementation
ISBN:
978-3-03-242895-0
Verlag:
Springer International Publishing
Land des Verlags:
Schweiz
Erscheinungsdatum:
13.03.2027
Reihe:
Issues in Privacy and Data Protection, Law, Governance and Technology Series
Format:
Hardcover
Ladenpreis
175,99 EUR (inkl. MwSt. zzgl. Versand)
Beim Kauf dieses Artikels handelt es sich um eine Vorbestellung. Der angegebene Preis kann sich gegebenenfalls noch ändern.
Updates zu dieser Vorbestellung erhalten?
Hinweis: Da dieses Werk nicht aus Österreich stammt, ist es wahrscheinlich, dass es nicht die österreichische Rechtslage enthält. Bitte berücksichtigen Sie dies bei ihrem Kauf.

This book examines the obligation of data protection by design and provides practical guidance on complying with Article 25 of the General Data Protection Regulation (GDPR). The GDPR significantly reshaped EU data protection law and introduced, for the first time, a legal requirement that data controllers implement technical and organisational measures to embed data protection principles into the design and operation of digital systems. While related concepts such as Privacy Enhancing Technologies (PETs) predated the GDPR, Article 25 established a binding obligation to ensure data protection by design and by default.
The book analyses the requirements of Article 25 GDPR and explains how organisations can comply with this broadly framed provision. Particular attention is given to the risk-based approach adopted by the GDPR, under which the level of protection must correspond to the risks posed to data subjects. This approach creates uncertainty because Article 25 does not specify which safeguards are sufficient in practice. Similar ambiguity exists regarding anonymisation techniques, which the author identifies as important measures for achieving compliance with the principle of data minimisation.
To address these challenges, the book examines officially approved Codes of Conduct and certification requirements in data protection law. These instruments provide detailed guidance on implementing data protection by design and help translate the GDPR’s abstract requirements into concrete compliance measures. The analysis further demonstrates that the EU law principle of legitimate expectations can protect organisations that rely on officially approved standards.
Adopting an interdisciplinary perspective, the book also explores Knowledge Graphs (KGs) as tools for embedding data protection requirements into technological systems. Focusing on Knowledge Graphs developed through Semantic Web technologies, it shows how legal rules can be expressed in machine-readable formats that support compliance by design. The monograph concludes by proposing best practices for the development of vocabularies and ontologies that represent data protection obligations in a structured, machine-readable way.

Biografische Anmerkung

Dr Efstratios Koulierakis is a postdoctoral researcher at the Law School of the National and Kapodistrian University of Athens (NKUA), where he is a member of the Laboratory of Law, Informatics and Artificial Intelligence. He lectures on Technology Law, Data Protection, and Artificial Intelligence Regulation. He completed his PhD on data protection by design and Knowledge Graphs at the Law Faculty of the University of Groningen. He holds a bachelor's degree from the Law School of the NKUA and an LL.M. in International and European Public Law from KU Leuven, awarded with distinction. Dr Koulierakis is also a practicing lawyer registered with the Athens Bar Association, representing clients before courts and advising public and private organisations on technology law compliance.