The GDPR: A game changer for electronic identification schemes? The case study of Gov.UK Verify
The GDPR: A game changer for electronic identification schemes? The case study of Gov.UK Verify
The article offers an interdisciplinary analysis of the General Data Protection Regulation (GDPR) in the context of electronic identification schemes. Gov.UK Verify, the UK Government’s electronic identification scheme, and its compatibility with some important aspects of EU data protection law are reviewed. An in-depth examination of Gov.UK Verify’s architecture and the most significant constituent elements of both the Data Protection Directive and the imminent GDPR – notably the legitimising grounds for the processing of personal data and the doctrine of joint controllership, highlight several flaws inherent in the Gov.UK Verify’s development and mode of operation. The article advances the argument that Gov.UK Verify is incompatible with some major substantive provisions of the EU Data Protection Framework. It also provides some general insight as to how to interpret the requirement of a legitimate legal basis and the doctrine of joint controllership and ultimately suggests that the choice of the appropriate legal basis should depend upon a holistic approach to the relationship between the actors involved in the processing activities.
electronic identity, data protection, GDPR, privacy by design, Gov.UK Verify
784-805
Stalla-Bourdillon, Sophie
c189651b-9ed3-49f6-bf37-25a47c487164
Pearce, Henry
cac95ad0-190d-4f58-bf3d-c79d8cf5aad7
Tsakalakis, Niko
eae42e98-58b8-45b9-8c11-35a798cc9671
August 2018
Stalla-Bourdillon, Sophie
c189651b-9ed3-49f6-bf37-25a47c487164
Pearce, Henry
cac95ad0-190d-4f58-bf3d-c79d8cf5aad7
Tsakalakis, Niko
eae42e98-58b8-45b9-8c11-35a798cc9671
Stalla-Bourdillon, Sophie, Pearce, Henry and Tsakalakis, Niko
(2018)
The GDPR: A game changer for electronic identification schemes? The case study of Gov.UK Verify.
Computer Law and Security Review: The International Journal of Technology Law and Practice, 34 (4), .
(doi:10.1016/j.clsr.2018.05.012).
Abstract
The article offers an interdisciplinary analysis of the General Data Protection Regulation (GDPR) in the context of electronic identification schemes. Gov.UK Verify, the UK Government’s electronic identification scheme, and its compatibility with some important aspects of EU data protection law are reviewed. An in-depth examination of Gov.UK Verify’s architecture and the most significant constituent elements of both the Data Protection Directive and the imminent GDPR – notably the legitimising grounds for the processing of personal data and the doctrine of joint controllership, highlight several flaws inherent in the Gov.UK Verify’s development and mode of operation. The article advances the argument that Gov.UK Verify is incompatible with some major substantive provisions of the EU Data Protection Framework. It also provides some general insight as to how to interpret the requirement of a legitimate legal basis and the doctrine of joint controllership and ultimately suggests that the choice of the appropriate legal basis should depend upon a holistic approach to the relationship between the actors involved in the processing activities.
Text
Bourdillon Pearce Tsakalakis 08.05.18-ssb7vsc.2
- Accepted Manuscript
More information
Accepted/In Press date: 11 May 2018
e-pub ahead of print date: 28 July 2018
Published date: August 2018
Keywords:
electronic identity, data protection, GDPR, privacy by design, Gov.UK Verify
Identifiers
Local EPrints ID: 421193
URI: http://eprints.soton.ac.uk/id/eprint/421193
ISSN: 2212-4748
PURE UUID: 0c37904d-4bc4-4612-944e-de9c3631b2c8
Catalogue record
Date deposited: 24 May 2018 16:30
Last modified: 16 Mar 2024 06:37
Export record
Altmetrics
Contributors
Author:
Henry Pearce
Download statistics
Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.
View more statistics