EU data proposals: Must try harder
Select committee calls for rethink on “too prescriptive” EU data protection plans.


European data protection proposals have been slammed by a select committee for being "too prescriptive".
A report by the Justice Select Committee said that the proposals for a common European data protection framework did not allow for flexibility or discretion for businesses or other organisations, which hold personal data, or for data protection authorities.
The committee said that the proposals should focus on those elements that are required to achieve the Commission's objectives, while compliance should be entrusted to Member States' data protection authorities.
The MPs were responding to a request from the European Scrutiny Committee for its opinion on both the draft Regulation and draft Directive. These plans would give EU citizens new data protection rights as set out in the Charter of Fundamental Rights of the European Union and the Lisbon Treaty.
While it criticised some parts of the scheme, it welcomed the potential benefits of an updated law. Individual rights would be increased and the new framework would protect against some of the more unwelcome and often-criticised aspects of digital data processing.
The committee gave an example of the draft regulation, which sets out the rights of individuals to access their personal data, to have it rectified or erased, to object to processing and not to be subject to profiling. From a business perspective, the committee said, the benefits would mainly accrue through the effective harmonisation of laws.
Sir Alan Beith, MP and chairman of the Justice committee said that the current data protection laws for general and commercial purposes need to be updated as they do not account for the digital world.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"However, we agree with the Information Commissioner's assessment that the system set out in the draft Regulation 'cannot work' and is 'a regime which no-one will pay for'. Therefore, we believe that the Commission needs to go back to the drawing board and devise a regime which is much less prescriptive," Beith said.
It will be 2014 before any changes are made to the law in the UK. Final regulation will take effect two years after being adopted.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Forcing Apple to allow alternative app stores might cause major security risks
Analysis Apple will be forced to allow third-party marketplaces on its devices, but some experts have raised serious security concerns
By Solomon Klappholz Published
-
Why bolstering your security capabilities is critical ahead of NIS2
NIS2 regulations will bolster cyber resilience in key industries as well as improving multi-agency responses to data breaches
By ITPro Published
-
New EU vulnerability disclosure rules deemed an "unnecessary risk"
News The vulnerability disclosure rules in the Cyber Resilience Act could also cause a “chilling effect” on security researchers
By Ross Kelly Published
-
Are you ready for NIS2?
WEBINAR Find out what you should be doing to prepare for the EU’s latest data protection regulation and UK equivalent with our free webinar
By ITPro Published
-
EU regulators are digging their heels in despite big tech’s Data Act pushback
Analysis EU regulators are no strangers to big tech regulatory push back, so why do companies still persist?
By Ross Kelly Published
-
Microsoft's EU Data Boundary will begin staggered rollout in January 2023
News Public sector and commercial customers will be the first to benefit when the rollout begins on 1 January across all of Microsoft's core services
By Ross Kelly Published
-
EU watchdog fights against rules permitting Europol's ‘unlawful’ data practices
News The pushback follows allegations that Europol was allowed to write its own rules when it came to handling sensitive data
By Connor Jones Published
-
EU to introduce strict IoT security regulation
News Manufacturers will be required to assess all risks, and notify the EU of issues within 24hrs
By Rory Bathgate Published