VLDB 2026 Research / reviewers in the wild / expert
Marcin Rojszczak
dblp:274/9242
· DBLP profile ↗
5ranked-venue papers
5as first author
3since 2021 · last 2025
0000-0003-2037-4301ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Preventing the dissemination of child sexual abuse material (CSAM) with surveillance technologies: The case of EU Regulation 2021/1232
Marcin Rojszczak |
Comput. Law Secur. Rev. | 1 |
| 2022 | Online content filtering in EU law - A coherent framework or jigsaw puzzle?abstractWith the spread of global digital services, the need to establish effective barriers to the dissemination of illegal content has also grown. Online services, instead of supporting the building of social relationships and allowing the free exchange of ideas, are increasingly becoming platforms for spreading hate speech or promoting extremist behaviour. The commitment to respect fundamental rights on which the Union has been built also requires those rights to be protected in cyberspace. Increasingly, one measure implemented to achieve this goal is filtering or blocking illegal content. In recent years, as a result of both the jurisprudence of European courts and the activity of the EU legislature, content filtering measures are increasingly used in an automatic and often also preventive manner. The freedom to use them on the part of digital service providers raises obvious concerns about compliance with human rights standards, often leading to allegations of implementing a new form of ``digital censorship''. Assuming that content filtering will be a measure that will be increasingly used in an automatic manner, it is particularly important to establish adequate standards of legal safeguards to protect against the risk of their abuse. The purpose of this article is to explain why the regulations currently being introduced do not create a coherent regulatory model and de facto hamper the effective protection of end-user rights and public security objectives, by introducing a series of often overlapping legal requirements. In this respect, the mosaic of various regulations does not facilitate the definition of a coherent standard of legal safeguards, which in turn delimits the boundaries of the application of automatic content filtering measures. Marcin Rojszczak |
Comput. Law Secur. Rev. | 1 |
| 2021 | The uncertain future of data retention laws in the EU: Is a legislative reset possible?abstractThe article discusses the CJEU's most important case law, including interpretations presented in recent cases relating to data retention for both national security purposes (Privacy International, La Quadrature du Net) and the fight against serious crime (H.K). The analysis is a starting point for discussing the draft e-Privacy Regulation, in particular a controversial proposal introduced by the EU Council that may limit the Court's jurisdiction in cases involving data retention rules that cover state security. Negotiated over the past five years, the draft e-Privacy Regulation fleshes out EU data protection rules governing electronic communication services. As a result, the way in which obligations under the Regulation are defined is critical in setting a standard for retention rules consistent with CJEU case law for decades to come. At the same time, succumbing to pressure from Member States may have the opposite result – the emergence of new ambiguities concerning not only the admissibility of data retention but also the competence of EU institutions to regulate this area of the telecommunications sector. Marcin Rojszczak |
Comput. Law Secur. Rev. | 1 |
| 2020 | OTT regulation framework in the context of CJEU Skype case and European Electronic Communications CodeabstractThe telecommunications services sector is one of the most dynamically developing segments of the contemporary economy. At the same time, it is undergoing constant change, the result of its adaptation to the needs of modern digital services and the expectations of users. In practice, traditional telecommunications services are being increasingly replaced by those that offer equivalent functionality but are provided via the Internet. Examples of this type of service are VoIP telephony, instant messengers and online chat. This group of services is collectively referred to as OTT. The growing popularity of OTT services not only affects the shape of the telecommunications market, but, from the point of view of legislatures and market regulators, has also led to a number of practical problems. One of them is how to apply a EU regulatory framework established for the electronic communications sector to modern OTT services. Recently, this problem has become an object of interest to both the CJEU and the EU legislature. The purpose of this article is to discuss the effects of the recent Skype adjudication on the regulation of the OTT sector, including the pending entry into force of the European Electronic Communications Code. The analysis considers the technical and regulatory background of issues relating to the judgment, the ongoing legislative work and the importance of the judgment in practice. Ambiguities in interpretation are also identified and discussed, in particular those relating to the attempt to apply the Skype judgment and the entire regulatory framework to OTT services. These aspects will be discussed from the perspective of the protection of users' privacy, an important part of the provision of electronic communications services. The choice of this aspect of OTT services regulation would seem to be particularly apt in light of the ongoing reform of the EU data protection model, which will include the new e-privacy regulation currently being drafted. Marcin Rojszczak |
Comput. Law Secur. Rev. | 1 |
| 2020 | CLOUD act agreements from an EU perspectiveabstractFor many years, transatlantic cooperation between the EU and the US in the area of personal data exchange has been a subject of special interest on the part of lawmakers, courts – including supranational ones – NGOs and the public. When implementing recent reform of data protection law, the European Union decided to further strengthen guarantees of the protection of privacy in cyberspace. At the same time, however, it faced the practical problem of how to ensure compliance with these principles in relation to third countries. The approach proposed in the GDPR, which is based on a newly-defined territorial scope of application, clearly indicates an attempt to apply EU rules extraterritorially in relation to data processors in third countries. Irrespective of EU activity, the United States has also introduced its own regulations addressing the same problem. An example is the federal law adopted in 2018, specifying how to execute national court orders for the transfer of electronic data. The CLOUD Act was established in response to legal doubts raised in the Microsoft v United States case regarding the transfer of electronic data stored in the cloud by US obliged entities to law enforcement authorities, as well as in cases where this data is physically located in another country and its transfer could result in violating the legal norms of a foreign jurisdiction. The CLOUD Act also facilitates bilateral international agreements that enable the cross-border transfer of e-evidence for the purposes of ongoing criminal proceedings. Both the content of the new regulations and the model proposed by the US legislature for future agreements concluded on the basis of the CLOUD Act can be seen as an alternative to regulations arising from EU law. The purpose of this paper is to analyse the CLOUD Act and CLOUD Act Agreements from the perspective of EU law and, in particular, attempt to answer the question as to whether this new legal mechanism brings the EU and the USA closer to finding common ground with regard to a coherent model of exchange and protection of personal data. Marcin Rojszczak |
Comput. Law Secur. Rev. | 1 |