EDBT 2026 Demo / reviewers in the wild / expert
Paul de Hert
dblp:60/7602
· DBLP profile ↗
24ranked-venue papers
13as first author
3since 2021 · last 2023
0000-0003-4084-6898ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 12 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | The transformative nature of the EU Declaration on Digital Rights and Principles: Replacing the old paradigm (normative equivalency of rights)
Cristina Cocito, Paul de Hert |
Comput. Law Secur. Rev. | 2 |
| 2023 | Humans in the GDPR and AIA governance of automated and algorithmic systems. Essential pre-requisites against abdicating responsibilitiesabstractThe GDPR mandates humans to intervene in different ways in automated decision-making (ADM). Similar human intervention mechanisms can be found amongst the human oversight requirements in the future regulation of AI in the EU. However, Article 22 GDPR has become an unenforceable second-class right, following the fate of its direct precedent -Article 15 of the 1995 Data Protection Directive-. Then, why should European policymakers rely on mandatory human intervention as a governance mechanism for ADM systems? Our approach aims to move away from a view of human intervention as an individual right towards a procedural right that is part of the culture of accountability in the GDPR. The core idea to make humans meaningfully intervene in ADM is to help controllers comply with regulation and to demonstrate compliance. Yet, human intervention alone is not sufficient to achieve appropriate human oversight for these systems. Human intervention will not work without human governance. This is why DPIAs should play a key role before introducing it and throughout the life-cycle of the system. This approach fits better with the governance model proposed in the Artificial Intelligence Act. Human intervention is not a panacea, but we claim that it should be better understood and integrated into the regulatory ecosystem to achieve appropriate oversight over ADM systems. Guillermo Lazcoz, Paul de Hert |
Comput. Law Secur. Rev. | 2 |
| 2021 | Framing Big Data in the Council of Europe and the EU data protection law systems: Adding 'should' to 'must' via soft law to address more than only individual harms
Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2020 | Conducting research with school children and data in line with "ethical principles" lawyers at work in the ethics management of the H2020 mathisis project
Eugenio Mantovani, István Böröcz, Paul de Hert |
Comput. Law Secur. Rev. | 3 |
| 2020 | Big data analytics in electronic communications: A reality in need of granular regulation (even if this includes an interim period of no regulation at all)abstractOver the past few years big data analytics have forcefully entered the mainstream. Admittedly, modern life would be inconceivable without the services afforded by this type of processing in the field of electronic communications. At the same time public administrations are increasingly discovering the benefits of big data analytics afforded to them by telecommunications operators. Nevertheless, despite public attention and high volumes of expert analyses, the majority of approaches on the challenges to personal data protection by this type of data processing remains theoretical; Tellingly, the EDPS speaks of the “black box” of big data analytics . However, the authors were able to open, and stare into, the “black box” of big data analytics in the electronic communications field in 2017 and 2018 in the context of GDPR compliance assessments. Their analysis first attempts to set the legal scene today, answering two crucial questions on scope and applicable law, before presenting a typology for a scalable and granular approach that the authors feel is necessary but nevertheless is missing from the text of the draft ePrivacy Regulation. The authors therefore conclude that processing requirements and particularities , as evidenced under the big data analytics paradigm, make necessary a much more detailed approach than the one afforded by the draft ePrivacy Regulation today. Until these needs are met, through the introduction of a new, fundamentally amended text, the authors suggest that the current regulatory framework and the mechanisms afforded by it be extended for an interim period, so as to afford legislators with the necessary space and time to revise their work. Vagelis Papakonstantinou, Paul de Hert |
Comput. Law Secur. Rev. | 2 |
| 2019 | The new EU cybersecurity framework: The NIS Directive, ENISA's role and the General Data Protection RegulationabstractThe NIS Directive is the first horizontal legislation undertaken at EU level for the protection of network and information systems across the Union. During the last decades e-services, new technologies, information systems and networks have become embedded in our daily lives. It is by now common knowledge that deliberate incidents causing disruption of IT services and critical infrastructures constitute a serious threat to their operation and consequently to the functioning of the Internal Market and the Union. This paper first discusses the Directive's addressees particularly with regard to their compliance obligations as well as Member States’ obligations as regards their respective national strategies and cooperation at EU level. Subsequently, the critical role of ENISA in implementing the Directive, as reinforced by the proposal for a new Regulation on ENISA (the EU Cybersecurity Act), is brought forward, before elaborating upon the, inevitable, relationship of the NIS Directive with EU's General Data Protection Regulation. Dimitra Markopoulou, Vagelis Papakonstantinou, Paul de Hert |
Comput. Law Secur. Rev. | 3 |
| 2018 | The right to data portability in the GDPR: Towards user-centric interoperability of digital servicesabstractThe right to data portability is one of the most important novelties within the EU General Data Protection Regulation, both in terms of warranting control rights to data subjects and in terms of being found at the intersection between data protection and other fields of law (competition law, intellectual property, consumer protection, etc.). It constitutes, thus, a valuable case of development and diffusion of effective user-centric privacy enhancing technologies and a first tool to allow individuals to enjoy the immaterial wealth of their personal data in the data economy. Indeed, a free portability of personal data from one controller to another can be a strong tool for data subjects in order to foster competition of digital services and interoperability of platforms and in order to enhance controllership of individuals on their own data. However, the adopted formulation of the right to data portability in the GDPR could benefit from further clarification: several interpretations are possible, particularly with regard to the object of the right and its interrelation with other rights, potentially leading to additional challenges within its technical implementation. The aim of this article is to propose a first systematic interpretation of this new right, by suggesting a pragmatic and extensive approach, particularly taking advantage as much as possible of the interrelationship that this new legal provision can have with regard to the Digital Single Market and the fundamental rights of digital users. In sum, the right to data portability can be approximated under two different perspectives: the minimalist approach (the adieu scenario) and the empowering approach (the fusing scenario), which the authors consider highly preferable. Paul de Hert, Vagelis Papakonstantinou, Gianclaudio Malgieri, Laurent Beslay |
Comput. Law Secur. Rev. | 1 |
| 2018 | The Cybercrime Convention Committee's 2017 Guidance Note on Production Orders: Unilateralist transborder access to electronic evidence promoted via soft law
Paul de Hert, Cihan Parlar, Juraj Sajfert |
Comput. Law Secur. Rev. | 1 |
| 2018 | Structuring modern life running on software. Recognizing (some) computer programs as new "digital persons"
Vagelis Papakonstantinou, Paul de Hert |
Comput. Law Secur. Rev. | 2 |
| 2017 | The rich UK contribution to the field of EU data protection: Let's not go for "third country" status after BrexitabstractThe die is cast. At the time of drafting this paper the so-called Brexit , the exit of the UK from the EU, seems like a certainty after the poll results of 23 June 2016. Within such historic, indeed seismic, developments data protection seems but a minor issue, a footnote to a world-changing chapter waiting to be written. Yet, from our modest vantage point, undertaken after this Journal's kind invitation, we submit that data protection, although one out of the myriad legal aspects pertaining to Brexit that urgently await consideration, may prove to be a crucial issue in this process. Notwithstanding what happens in the immediate future, when attention will presumably be focused on coordinating the dates when Brexit may potentially occur and the GDPR comes into effect, long-term thinking is critical. We believe that, because developments in this field of law will be among those felt directly by individuals on both sides of the Channel, data protection has the potential to be among the issues that “ make ” or “ break ” a possibly successful Brexit – if success is perceived as minimal disturbance to an already functioning system. UK and EU data protection are intrinsically connected by now, by osmosis, after decades of mutual exchanges and intensive collaboration. If indeed, contrary to our wishes, a data protection Brexit does take place, the preferred way forward for the authors would be for the UK to unreservedly and permanently adhere to the EU data protection model. If this will not be the case, then we feel that a high-level principle-driven solution would serve data protection purposes better than a detailed and technical solution ; the latter, if ever achievable, would essentially attempt the impossible: to surgically severe what is today an integral part of a living and functioning system. Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2016 | Data protection authority perspectives on the impact of data protection reform on cooperation in the EU
David Barnard-Wills, Cristina Pauner Chulvi, Paul de Hert |
Comput. Law Secur. Rev. | 3 |
| 2016 | The new General Data Protection Regulation: Still a sound system for the protection of individuals?
Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2016 | The cloud computing standard ISO/IEC 27018 through the lens of the EU legislation on data protectionabstractIn July 2014 ISO and IEC published a standard relating to public cloud computing and data protection. The standard aims to address the down-sides of cloud computing and the concerns of the cloud clients, mainly the lack of trust and transparency, by developing controls and recommendations for cloud service providers acting as PII processors. At the same time, the standard aims to assist providers to demonstrate transparency and accountability in the handling of data and information in the cloud. This paper looks briefly at the data protection and security challenges of cloud computing. It discusses the provisions and added value of the standard in the context of the European data protection legislation and also looks at the uptake of the standard one year after its publication. Paul de Hert, Vagelis Papakonstantinou, Irene Kamara |
Comput. Law Secur. Rev. | 1 |
| 2014 | The Council of Europe Data Protection Convention reform: Analysis of the new text and critical comment on its global ambition
Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2013 | Genetic Data and the Data Protection Regulation: Anonymity, multiple subjects, sensitivity and a prohibitionary logic regarding genetic data?
Dara Hallinan, Michael Friedewald, Paul de Hert |
Comput. Law Secur. Rev. | 3 |
| 2012 | The proposed data protection Regulation replacing Directive 95/46/EC: A sound system for the protection of individuals
Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2011 | International mutual legal assistance in criminal law made redundant: A comment on the Belgian Yahoo! case
Paul de Hert, Monika Kopcheva |
Comput. Law Secur. Rev. | 1 |
| 2011 | The Patients' Rights Directive (2011/24/EU) - Providing (some) rights to EU residents seeking healthcare in other Member States
Paul Quinn, Paul de Hert |
Comput. Law Secur. Rev. | 2 |
| 2010 | Sorting out smart surveillance
David Wright 0003, Michael Friedewald, Serge Gutwirth, Marc Langheinrich, Emilio Mordini, Rocco Bellanova, Paul de Hert, Kush Wadhwa, Didier Bigo |
Comput. Law Secur. Rev. | 7 |
| 2010 | The EU PNR framework decision proposal: Towards completion of the PNR processing scene in Europe
Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2009 | Privacy, trust and policy-making: Challenges and responses
David Wright 0003, Serge Gutwirth, Michael Friedewald, Paul de Hert, Marc Langheinrich, Anna Moscibroda |
Comput. Law Secur. Rev. | 4 |
| 2009 | The data protection framework decision of 27 November 2008 regarding police and judicial cooperation in criminal matters - A modest achievement however not the improvement some have hoped for
Paul de Hert, Vagelis Papakonstantinou |
Comput. Law Secur. Rev. | 1 |
| 2009 | Legal safeguards for privacy and data protection in ambient intelligence
Paul de Hert, Serge Gutwirth, Anna Moscibroda, David Wright 0003, Gloria González Fuster |
Pers. Ubiquitous Comput. | 1 |
| 2008 | Identity management of e-ID, privacy and security in Europe. A human rights view
Paul de Hert |
Inf. Secur. Tech. Rep. | 1 |