Vagelis Papakonstantinou

dblp:127/3261 · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
4since 2021 · last 2023
0000-0002-2536-2951ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2023 A preliminary study on artificial intelligence oracles and smart contracts: A legal approach to the interaction of two novel technological breakthroughs
abstract
Artificial Intelligence and Smart Contracts are two cutting-edge technological achievements of the so-called 4th Industrial Revolution era. Both have already had a significant impact on various aspects of modern life, including transactions, and each one has already been under scientific investigation. Instead, their interaction has not become the subject of a debate, although it can further (positively) affect the transactions. This interconnection takes place through specific mechanisms, called Oracles, which can be, among others, highly sophisticated Artificial Intelligence systems (autonomous systems). The present article aims to present the role of the Artificial Intelligence Oracles throughout the ‘smart contractual procedure’, as well as to shed light on the potential (new) legal issues this interconnection may raise. The main result of this article is to indicate the appropriate legal directions in case of Artificial Intelligence Oracles’ failures, based on the most prevalent current approaches to AI's (the user's) contractual and/or non-contractual liability. The major research's conclusion is that the Artificial Intelligence Oracle's failures may result in one of the following situations: (a) breach of a (smart) contract, (b) unjust enrichment, (c) conclusion of a (voidable) smart contract that should not have been concluded, or (d) non-conclusion of a smart contract that should have been concluded. The responsibility of each person participating in the ‘smart contractual procedure’, i.e. the contractual parties, the blockchain platform and the Artificial Intelligence user/owner (or even the Artificial Intelligence system itself), as well as the AI provider or designer, is examined in each of the afore-mentioned situations separately. Given that legislative initiatives have already begun, the present article aspires to contribute to the consistent address of the newly raised legal issues.
Vasiliki Papadouli, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2022 Cybersecurity as praxis and as a state: The EU law path towards acknowledgement of a new right to cybersecurity?
abstract
The end of the second decade of the 21st century has been the best of times for EU's cybersecurity law and policy: Its NIS Directive has been transposed into all Member States’ national law, creating a new administrative structure at EU and Member State level and mandating relevant policies and strategies to update and harmonise those that were already in place. Its Cybersecurity Act of 2019 incorporated the EU Agency for Cybersecurity (ENISA), and promises to install a new European cybersecurity certification scheme. To support policy with funding, large sums of research money have been spent on the development of cybersecurity tools and the relevant framework. However, EU's significant regulatory activity is faced with substantial difficulties. While cybersecurity concerns are placed high on the list of issues that worry Europeans making a regulatory response pressing, the cybersecurity theoretical framework is far from concluded: Difficulties start as early as when attempting to define the term, ultimately divulging a lack of common understanding. Different actors understand cybersecurity differently under different circumstances. A distinction that could perhaps prove useful in creating clarity as to its exact meaning would distinguish between cybersecurity as praxis and cybersecurity as a state. Cybersecurity as praxis would then be understood as the activities and measures that need to be undertaken in order to accomplish cybersecurity's aims and objectives. Accordingly, cybersecurity as a state would mean the condition that is achieved once cybersecurity as praxis has succeeded; Within cybersecurity as a state persons need to be protected against any cyber threat. A distinction between cybersecurity as praxis and cybersecurity as a state would not only be useful in delineating the term's content but could also constitute the necessary theoretical groundwork for development, ultimately, of a new right to cybersecurity. EU law has already taken positive steps towards acknowledgement of a new right to cybersecurity. However, a lot more needs to be done; Past progress needs to be continued and updated. A conceivable next step could take the form of formal acknowledgement of such a new right in EU law, in a future amendment of the Act's provisions or otherwise.
Vagelis Papakonstantinou
Comput. Law Secur. Rev.1
2021 Framing Big Data in the Council of Europe and the EU data protection law systems: Adding 'should' to 'must' via soft law to address more than only individual harms
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2021 The regulatory framework for the protection of critical infrastructures against cyberthreats: Identifying shortcomings and addressing future challenges: The case of the health sector in particular
abstract
The concept of "Critical Infrastructures" is constantly evolving in order to reflect current concerns and to respond to new challenges, especially in terms of (cyber)security and resilience. Protection of critical infrastructures against numerous threats has therefore developed into a high priority at national and EU level. During the last two decades a new type of threat has prevailed in the Critical Infrastructure threat landscape, that of cyberattacks; Protection against them is the primary focus of this paper. In order to do so the analysis first aims to drop some light into the differences between Critical Infrastructures and Critical Information Infrastructures, terms that are often confused, and to indicate possible inadequacies in the applicable protection regulatory regime. Finally, the health sector has been chosen as a sector-specific case in an effort to demonstrate how protection of a Critical Infrastructure, challenged as it has been with a constantly increasing number of cyber incidents, could be sufficiently protected in the new digitalised era.
Dimitra Markopoulou, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2020 Big data analytics in electronic communications: A reality in need of granular regulation (even if this includes an interim period of no regulation at all)
abstract
Over the past few years big data analytics have forcefully entered the mainstream. Admittedly, modern life would be inconceivable without the services afforded by this type of processing in the field of electronic communications. At the same time public administrations are increasingly discovering the benefits of big data analytics afforded to them by telecommunications operators. Nevertheless, despite public attention and high volumes of expert analyses, the majority of approaches on the challenges to personal data protection by this type of data processing remains theoretical; Tellingly, the EDPS speaks of the “black box” of big data analytics . However, the authors were able to open, and stare into, the “black box” of big data analytics in the electronic communications field in 2017 and 2018 in the context of GDPR compliance assessments. Their analysis first attempts to set the legal scene today, answering two crucial questions on scope and applicable law, before presenting a typology for a scalable and granular approach that the authors feel is necessary but nevertheless is missing from the text of the draft ePrivacy Regulation. The authors therefore conclude that processing requirements and particularities , as evidenced under the big data analytics paradigm, make necessary a much more detailed approach than the one afforded by the draft ePrivacy Regulation today. Until these needs are met, through the introduction of a new, fundamentally amended text, the authors suggest that the current regulatory framework and the mechanisms afforded by it be extended for an interim period, so as to afford legislators with the necessary space and time to revise their work.
Vagelis Papakonstantinou, Paul de Hert
Comput. Law Secur. Rev.1
2019 The new EU cybersecurity framework: The NIS Directive, ENISA's role and the General Data Protection Regulation
abstract
The NIS Directive is the first horizontal legislation undertaken at EU level for the protection of network and information systems across the Union. During the last decades e-services, new technologies, information systems and networks have become embedded in our daily lives. It is by now common knowledge that deliberate incidents causing disruption of IT services and critical infrastructures constitute a serious threat to their operation and consequently to the functioning of the Internal Market and the Union. This paper first discusses the Directive's addressees particularly with regard to their compliance obligations as well as Member States’ obligations as regards their respective national strategies and cooperation at EU level. Subsequently, the critical role of ENISA in implementing the Directive, as reinforced by the proposal for a new Regulation on ENISA (the EU Cybersecurity Act), is brought forward, before elaborating upon the, inevitable, relationship of the NIS Directive with EU's General Data Protection Regulation.
Dimitra Markopoulou, Vagelis Papakonstantinou, Paul de Hert
Comput. Law Secur. Rev.2
2018 The right to data portability in the GDPR: Towards user-centric interoperability of digital services
abstract
The right to data portability is one of the most important novelties within the EU General Data Protection Regulation, both in terms of warranting control rights to data subjects and in terms of being found at the intersection between data protection and other fields of law (competition law, intellectual property, consumer protection, etc.). It constitutes, thus, a valuable case of development and diffusion of effective user-centric privacy enhancing technologies and a first tool to allow individuals to enjoy the immaterial wealth of their personal data in the data economy. Indeed, a free portability of personal data from one controller to another can be a strong tool for data subjects in order to foster competition of digital services and interoperability of platforms and in order to enhance controllership of individuals on their own data. However, the adopted formulation of the right to data portability in the GDPR could benefit from further clarification: several interpretations are possible, particularly with regard to the object of the right and its interrelation with other rights, potentially leading to additional challenges within its technical implementation. The aim of this article is to propose a first systematic interpretation of this new right, by suggesting a pragmatic and extensive approach, particularly taking advantage as much as possible of the interrelationship that this new legal provision can have with regard to the Digital Single Market and the fundamental rights of digital users. In sum, the right to data portability can be approximated under two different perspectives: the minimalist approach (the adieu scenario) and the empowering approach (the fusing scenario), which the authors consider highly preferable.
Paul de Hert, Vagelis Papakonstantinou, Gianclaudio Malgieri, Laurent Beslay
Comput. Law Secur. Rev.2
2018 Structuring modern life running on software. Recognizing (some) computer programs as new "digital persons"
Vagelis Papakonstantinou, Paul de Hert
Comput. Law Secur. Rev.1
2017 The rich UK contribution to the field of EU data protection: Let's not go for "third country" status after Brexit
abstract
The die is cast. At the time of drafting this paper the so-called Brexit , the exit of the UK from the EU, seems like a certainty after the poll results of 23 June 2016. Within such historic, indeed seismic, developments data protection seems but a minor issue, a footnote to a world-changing chapter waiting to be written. Yet, from our modest vantage point, undertaken after this Journal's kind invitation, we submit that data protection, although one out of the myriad legal aspects pertaining to Brexit that urgently await consideration, may prove to be a crucial issue in this process. Notwithstanding what happens in the immediate future, when attention will presumably be focused on coordinating the dates when Brexit may potentially occur and the GDPR comes into effect, long-term thinking is critical. We believe that, because developments in this field of law will be among those felt directly by individuals on both sides of the Channel, data protection has the potential to be among the issues that “ make ” or “ break ” a possibly successful Brexit – if success is perceived as minimal disturbance to an already functioning system. UK and EU data protection are intrinsically connected by now, by osmosis, after decades of mutual exchanges and intensive collaboration. If indeed, contrary to our wishes, a data protection Brexit does take place, the preferred way forward for the authors would be for the UK to unreservedly and permanently adhere to the EU data protection model. If this will not be the case, then we feel that a high-level principle-driven solution would serve data protection purposes better than a detailed and technical solution ; the latter, if ever achievable, would essentially attempt the impossible: to surgically severe what is today an integral part of a living and functioning system.
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2016 The new General Data Protection Regulation: Still a sound system for the protection of individuals?
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2016 The cloud computing standard ISO/IEC 27018 through the lens of the EU legislation on data protection
abstract
In July 2014 ISO and IEC published a standard relating to public cloud computing and data protection. The standard aims to address the down-sides of cloud computing and the concerns of the cloud clients, mainly the lack of trust and transparency, by developing controls and recommendations for cloud service providers acting as PII processors. At the same time, the standard aims to assist providers to demonstrate transparency and accountability in the handling of data and information in the cloud. This paper looks briefly at the data protection and security challenges of cloud computing. It discusses the provisions and added value of the standard in the context of the European data protection legislation and also looks at the uptake of the standard one year after its publication.
Paul de Hert, Vagelis Papakonstantinou, Irene Kamara
Comput. Law Secur. Rev.2
2014 The Council of Europe Data Protection Convention reform: Analysis of the new text and critical comment on its global ambition
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2012 The proposed data protection Regulation replacing Directive 95/46/EC: A sound system for the protection of individuals
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2010 The EU PNR framework decision proposal: Towards completion of the PNR processing scene in Europe
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2
2009 The data protection framework decision of 27 November 2008 regarding police and judicial cooperation in criminal matters - A modest achievement however not the improvement some have hoped for
Paul de Hert, Vagelis Papakonstantinou
Comput. Law Secur. Rev.2