Skip to main content
Top
Published in: Business & Information Systems Engineering 3/2020

Open Access 09-03-2020 | Discussion

The Role of IS in the Conflicting Interests Regarding GDPR

Authors: Dr. Timo Jakobi, Prof. Dr. Maximilian von Grafenstein, Prof. Dr. Christine Legner, Clément Labadie, Prof. Dr. Dr. hc. mult. Peter Mertens, Dr. Ayten Öksüz, Prof. Dr. Gunnar Stevens

Published in: Business & Information Systems Engineering | Issue 3/2020

Log in

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Excerpt

Timo Jakobi, Information Systems esp. IT-Security and Privacy, University of Siegen

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Show more products
Literature
go back to reference Albrecht JP (2016) How the GDPR will change the world. Eur Data Prot Law Rev 2:287–289CrossRef Albrecht JP (2016) How the GDPR will change the world. Eur Data Prot Law Rev 2:287–289CrossRef
go back to reference Alizadeh F, Jakobi T, Boldt J, Stevens G (2019) GDPR-reality check on the right to access data: claiming and investigating personally identifiable data from companies. In: Proceedings of Mensch und Computer 2019. ACM, New York, pp 811–814 Alizadeh F, Jakobi T, Boldt J, Stevens G (2019) GDPR-reality check on the right to access data: claiming and investigating personally identifiable data from companies. In: Proceedings of Mensch und Computer 2019. ACM, New York, pp 811–814
go back to reference Alvarez SA, Barney JB (2007) Discovery and creation: alternative theories of entrepreneurial action. Strateg Entrep J 1:11–26CrossRef Alvarez SA, Barney JB (2007) Discovery and creation: alternative theories of entrepreneurial action. Strateg Entrep J 1:11–26CrossRef
go back to reference Berg-Larsen E (2015) The issue of privacy in the European Union – controversies of the General Data Protection Regulation. Master’s Thesis, University of Oslo Berg-Larsen E (2015) The issue of privacy in the European Union – controversies of the General Data Protection Regulation. Master’s Thesis, University of Oslo
go back to reference Crocoll S (2019) Der Schatz aus der Maschinenhalle. In: Wirtschaftswoche No. 13, 22 Mar 2019, pp 29–31 Crocoll S (2019) Der Schatz aus der Maschinenhalle. In: Wirtschaftswoche No. 13, 22 Mar 2019, pp 29–31
go back to reference Cvik ED, Pelikánová RM, Malỳ M (2018) Selected issues from the dark side of the General Data Protection Regulation. Rev Econ Perspekt 18:387–407CrossRef Cvik ED, Pelikánová RM, Malỳ M (2018) Selected issues from the dark side of the General Data Protection Regulation. Rev Econ Perspekt 18:387–407CrossRef
go back to reference De Hert P, Papakonstantinou V (2016) The new General Data Protection Regulation: still a sound system for the protection of individuals? Comput Law Secur Rev 32:179–194CrossRef De Hert P, Papakonstantinou V (2016) The new General Data Protection Regulation: still a sound system for the protection of individuals? Comput Law Secur Rev 32:179–194CrossRef
go back to reference Degeling M, Utz C, Lentzsch C et al (2018) We value your privacy… Now take some cookies: measuring the GDPR’s impact on web privacy. arXiv:180805096 Degeling M, Utz C, Lentzsch C et al (2018) We value your privacy… Now take some cookies: measuring the GDPR’s impact on web privacy. arXiv:​180805096
go back to reference Diker Vanberg A, Ünver MB (2017) The right to data portability in the GDPR and EU competition law: odd couple or dynamic duo? Eur J Law Technol 8(1):1–22 Diker Vanberg A, Ünver MB (2017) The right to data portability in the GDPR and EU competition law: odd couple or dynamic duo? Eur J Law Technol 8(1):1–22
go back to reference EDPB (2016) Guidelines on data protection impact assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of regulation. Data Protection Working Party 2016/679, 5:10. Accessed 9 Feb 2020 EDPB (2016) Guidelines on data protection impact assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of regulation. Data Protection Working Party 2016/679, 5:10. Accessed 9 Feb 2020
go back to reference Eifert M, Hoffmann-Riem W, Schmidt-Aßmann E, Voßkuhle A (2012) Regulierungsstrategien. In: Grundlagen des Verwaltungsrechts. Bd. I „Methoden – Maßstäbe – Aufgaben – Organisation“, 2nd edn. Beck, München Eifert M, Hoffmann-Riem W, Schmidt-Aßmann E, Voßkuhle A (2012) Regulierungsstrategien. In: Grundlagen des Verwaltungsrechts. Bd. I „Methoden – Maßstäbe – Aufgaben – Organisation“, 2nd edn. Beck, München
go back to reference European Parliament and Council (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council. Off J Eur Union Law 119/2016, vol 59 European Parliament and Council (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council. Off J Eur Union Law 119/2016, vol 59
go back to reference Fox G, Tonge C, Lynn T, Mooney J (2018) Communicating compliance: developing a GDPR privacy label. In: 24th Americas conference on information systems, New Orleans Fox G, Tonge C, Lynn T, Mooney J (2018) Communicating compliance: developing a GDPR privacy label. In: 24th Americas conference on information systems, New Orleans
go back to reference Gartner WB (1985) A conceptual framework for describing the phenomenon of new venture creation. Acad Manag Rev 10:696–706CrossRef Gartner WB (1985) A conceptual framework for describing the phenomenon of new venture creation. Acad Manag Rev 10:696–706CrossRef
go back to reference Gellert R (2018) Understanding the notion of risk in the General Data Protection Regulation. Comput Law Secur Rev 34:279–288CrossRef Gellert R (2018) Understanding the notion of risk in the General Data Protection Regulation. Comput Law Secur Rev 34:279–288CrossRef
go back to reference Hartog C, Van Stel A, Storey DJ (2011) Institutions and entrepreneurship: the role of the rule of law; levie, autio, regulatory burden, rule of law, and entry of strategic entrepreneurs: an international panel study. J Manag Stud 48(6):1392–1419CrossRef Hartog C, Van Stel A, Storey DJ (2011) Institutions and entrepreneurship: the role of the rule of law; levie, autio, regulatory burden, rule of law, and entry of strategic entrepreneurs: an international panel study. J Manag Stud 48(6):1392–1419CrossRef
go back to reference Heide D, Neuerer D (2018) Parteiübergreifende Kritik am neuen Datenschutz. Handelsblatt 13 June 2018, p 9 Heide D, Neuerer D (2018) Parteiübergreifende Kritik am neuen Datenschutz. Handelsblatt 13 June 2018, p 9
go back to reference Hey J (ed) (2019) Digitalisierung im Steuerrecht. Schmidt, Köln Hey J (ed) (2019) Digitalisierung im Steuerrecht. Schmidt, Köln
go back to reference Hintze M, El Emam K (2018) Comparing the benefits of pseudonymisation and anonymisation under the GDPR. J Data Prot Priv 2(2):145–158 Hintze M, El Emam K (2018) Comparing the benefits of pseudonymisation and anonymisation under the GDPR. J Data Prot Priv 2(2):145–158
go back to reference Hoffmann-Riem W (2006) Innovationsoffenheit und Innovationsverantwortung durch Recht: Aufgaben rechtswissenschaftlicher Innovationsforschung. Archiv des öffentlichen Rechts 131:255–277CrossRef Hoffmann-Riem W (2006) Innovationsoffenheit und Innovationsverantwortung durch Recht: Aufgaben rechtswissenschaftlicher Innovationsforschung. Archiv des öffentlichen Rechts 131:255–277CrossRef
go back to reference Huth D (2017) A pattern catalog for GDPR compliant data protection. In: Ralyté J, Roelens B, Demeyer S (eds): Proceedings of the doctoral consortium and industry track papers presented at the 10th IFIP WG 8.1 working conference on the practice of enterprise modelling (PoEM 2017), Leeuven, pp 34–40 Huth D (2017) A pattern catalog for GDPR compliant data protection. In: Ralyté J, Roelens B, Demeyer S (eds): Proceedings of the doctoral consortium and industry track papers presented at the 10th IFIP WG 8.1 working conference on the practice of enterprise modelling (PoEM 2017), Leeuven, pp 34–40
go back to reference Jaeckel L (2010) Gefahrenabwehrrecht und Risikodogmatik – Moderne Technologien im Spiegel des Verwaltungsrechts. Mohr Siebeck, TübingenCrossRef Jaeckel L (2010) Gefahrenabwehrrecht und Risikodogmatik – Moderne Technologien im Spiegel des Verwaltungsrechts. Mohr Siebeck, TübingenCrossRef
go back to reference Jakobi T, Stevens G, Seufert A-M, Becker M (2019b) Webtracking under the new data protection law: design potentials at the intersection of jurisprudence and HCI. In: Proceedings of Mensch und Computer 2019. ACM, New York, pp 309–319 Jakobi T, Stevens G, Seufert A-M, Becker M (2019b) Webtracking under the new data protection law: design potentials at the intersection of jurisprudence and HCI. In: Proceedings of Mensch und Computer 2019. ACM, New York, pp 309–319
go back to reference Kamara I (2017) Co-regulation in EU personal data protection: the case of technical standards and the privacy by design standardisation ‘mandate’. Eur J Law Technol 8(1):4 Kamara I (2017) Co-regulation in EU personal data protection: the case of technical standards and the privacy by design standardisation ‘mandate’. Eur J Law Technol 8(1):4
go back to reference Knodt M (2019) Hürden für Dr. Algorithmus. Handelsblatt 15 Oct 2019, p 13 Knodt M (2019) Hürden für Dr. Algorithmus. Handelsblatt 15 Oct 2019, p 13
go back to reference Koch M (2019) Wenig Gründermut. Handelsblatt 2 Sept 2019, p 8 Koch M (2019) Wenig Gründermut. Handelsblatt 2 Sept 2019, p 8
go back to reference Kremer S (2019) Ein Jahr DSGVO: Aktuelle Entwicklungen und Herausforderungen des neuen Datenschutzrechts in der Praxis. In: Der Betrieb No. 25, 24 June 2019, pp 1429–1435 Kremer S (2019) Ein Jahr DSGVO: Aktuelle Entwicklungen und Herausforderungen des neuen Datenschutzrechts in der Praxis. In: Der Betrieb No. 25, 24 June 2019, pp 1429–1435
go back to reference Lachaud E (2018) The General Data Protection Regulation and the rise of certification as a regulatory instrument. Comput Law Secur Rev 34:244–256CrossRef Lachaud E (2018) The General Data Protection Regulation and the rise of certification as a regulatory instrument. Comput Law Secur Rev 34:244–256CrossRef
go back to reference Lambrinoudakis C (2018) The General Data Protection Regulation (GDPR) era: ten steps for compliance of data processors and data controllers. In: International conference on trust and privacy in digital business. Springer, Heidelberg, pp 3–8 Lambrinoudakis C (2018) The General Data Protection Regulation (GDPR) era: ten steps for compliance of data processors and data controllers. In: International conference on trust and privacy in digital business. Springer, Heidelberg, pp 3–8
go back to reference Legner C, Eymann T, Hess T et al (2017) Digitalization: opportunity and challenge for the business and information systems engineering community. Bus Inf Syst Eng 59:301–308CrossRef Legner C, Eymann T, Hess T et al (2017) Digitalization: opportunity and challenge for the business and information systems engineering community. Bus Inf Syst Eng 59:301–308CrossRef
go back to reference Levie J, Autio E (2011) Regulatory burden, rule of law, and entry of strategic entrepreneurs: an international panel study. J Manag Stud 48:1392–1419CrossRef Levie J, Autio E (2011) Regulatory burden, rule of law, and entry of strategic entrepreneurs: an international panel study. J Manag Stud 48:1392–1419CrossRef
go back to reference Mayer-Schonberger V (2010) The law as stimulus: the role of law in fostering innovative entrepreneurship. I/S J Law Policy Inf Soc 6:153 Mayer-Schonberger V (2010) The law as stimulus: the role of law in fostering innovative entrepreneurship. I/S J Law Policy Inf Soc 6:153
go back to reference Mertens P (2013) Integrierte Informationsverarbeitung. 1. Operative Systeme in der Industrie, Chapter 3.5.2.9, 18th edn. Springer, Heidelberg Mertens P (2013) Integrierte Informationsverarbeitung. 1. Operative Systeme in der Industrie, Chapter 3.5.2.9, 18th edn. Springer, Heidelberg
go back to reference Mertens P (2019) Die Datenschutz-Grundverordnung – eine kritische Sicht. Wirtschaftsinformatik und Management 11(1):6–17CrossRef Mertens P (2019) Die Datenschutz-Grundverordnung – eine kritische Sicht. Wirtschaftsinformatik und Management 11(1):6–17CrossRef
go back to reference Mhaidli AH, Zou Y, Schaub F (2019) “We can’t live without them!” App developers’ adoption of ad networks and their considerations of consumer risks. In: Proceedings of the 15th USENIX conference on usable privacy and security. USENIX Association, pp 225–244 Mhaidli AH, Zou Y, Schaub F (2019) “We can’t live without them!” App developers’ adoption of ad networks and their considerations of consumer risks. In: Proceedings of the 15th USENIX conference on usable privacy and security. USENIX Association, pp 225–244
go back to reference Mitrou L (2017) The General Data Protection Regulation: a law for the digital age? In: Synodinou TE et al (eds) EU Internet Law. Springer, Heidelberg, pp 19–57CrossRef Mitrou L (2017) The General Data Protection Regulation: a law for the digital age? In: Synodinou TE et al (eds) EU Internet Law. Springer, Heidelberg, pp 19–57CrossRef
go back to reference Neuerer D (2019) Weniger ist mehr. Handelsblatt 20 Sept 2019, p 16 Neuerer D (2019) Weniger ist mehr. Handelsblatt 20 Sept 2019, p 16
go back to reference Politou E, Alepis E, Patsakis C (2018) Forgetting personal data and revoking consent under the GDPR: challenges and proposed solutions. J Cybersecur 4:tyy001CrossRef Politou E, Alepis E, Patsakis C (2018) Forgetting personal data and revoking consent under the GDPR: challenges and proposed solutions. J Cybersecur 4:tyy001CrossRef
go back to reference Rehaag C (2019) Neuer Geheimnisschutz. Frankfurter Allgemeine Zeitung 19 June 2019, p 18 Rehaag C (2019) Neuer Geheimnisschutz. Frankfurter Allgemeine Zeitung 19 June 2019, p 18
go back to reference Ritzer C (2019) Keine Harmonie bei Cookies. Frankfurter Allgemeine Zeitung 9 Oct 2019, p 16 Ritzer C (2019) Keine Harmonie bei Cookies. Frankfurter Allgemeine Zeitung 9 Oct 2019, p 16
go back to reference Schelter S, Kunegis J (2018) On the ubiquity of web tracking: insights from a billion-page web crawl. J Web Sci 4:53–66CrossRef Schelter S, Kunegis J (2018) On the ubiquity of web tracking: insights from a billion-page web crawl. J Web Sci 4:53–66CrossRef
go back to reference Schröder M (2019) Der risikobasierte Ansatz in der DS-GVO – Risiko oder Chance für den Datenschutz. Zeitschrift für Datenschutz 9:503–506 Schröder M (2019) Der risikobasierte Ansatz in der DS-GVO – Risiko oder Chance für den Datenschutz. Zeitschrift für Datenschutz 9:503–506
go back to reference Schumpeter J (2003) Capitalism, socialism and democracy. 5th edn. Routledge, New York Schumpeter J (2003) Capitalism, socialism and democracy. 5th edn. Routledge, New York
go back to reference Software AG (2017) Ensuring compliance with the General Data Protection Regulation (GDPR). Software AG, Darmstadt Software AG (2017) Ensuring compliance with the General Data Protection Regulation (GDPR). Software AG, Darmstadt
go back to reference Theile G, Creutzburg D (2019) Die Deutschen scheuen das Risiko. Frankfurter Allgemeine Zeitung 16 August 2019, p 15 Theile G, Creutzburg D (2019) Die Deutschen scheuen das Risiko. Frankfurter Allgemeine Zeitung 16 August 2019, p 15
go back to reference Urbach N, Ahlemann F, Böhmann T et al (2019) The impact of digitalization on the IT department. Bus Inf Syst Eng 61:123–131CrossRef Urbach N, Ahlemann F, Böhmann T et al (2019) The impact of digitalization on the IT department. Bus Inf Syst Eng 61:123–131CrossRef
go back to reference Utz C, Degeling M, Fahl S et al (2019) (Un)informed consent: studying GDPR consent notices in the field. In: Proceedings of the ACM SIGSAC conference on computer and communications security. ACM, New York, pp 973–990 Utz C, Degeling M, Fahl S et al (2019) (Un)informed consent: studying GDPR consent notices in the field. In: Proceedings of the ACM SIGSAC conference on computer and communications security. ACM, New York, pp 973–990
go back to reference Voigt P, Von dem Bussche A (2017) The EU General Data Protection Regulation (GDPR). A practical guide. Springer, ChamCrossRef Voigt P, Von dem Bussche A (2017) The EU General Data Protection Regulation (GDPR). A practical guide. Springer, ChamCrossRef
go back to reference von Grafenstein M (2020) Co-regulation and the competitive advantage in the GDPR: data protection certification mechanisms, codes of conduct and the “state of the art” of data protection-by-design. In: González-Fuster G, van Brakel R, De Hert P (eds) Research handbook on privacy and data protection law. Values, norms and global politics. Elgar, Cheltenham von Grafenstein M (2020) Co-regulation and the competitive advantage in the GDPR: data protection certification mechanisms, codes of conduct and the “state of the art” of data protection-by-design. In: González-Fuster G, van Brakel R, De Hert P (eds) Research handbook on privacy and data protection law. Values, norms and global politics. Elgar, Cheltenham
go back to reference Waschinski G (2019) Spahn plant eigenes Datenschutzgesetz. Handelsblatt 5 July 2019, p 12 Waschinski G (2019) Spahn plant eigenes Datenschutzgesetz. Handelsblatt 5 July 2019, p 12
go back to reference Wieduwilt H (2019) Gerichtshof begrenzt das Vergessen im Internet auf die EU. Frankfurter Allgemeine Zeitung 25 Sep 2019, p 17 Wieduwilt H (2019) Gerichtshof begrenzt das Vergessen im Internet auf die EU. Frankfurter Allgemeine Zeitung 25 Sep 2019, p 17
go back to reference Wuhrmann D (2019) Plattform für den Autobau. Frankfurter Allgemeine Zeitung 19 June 2019, p 18 Wuhrmann D (2019) Plattform für den Autobau. Frankfurter Allgemeine Zeitung 19 June 2019, p 18
go back to reference Zarsky TZ (2016) Incompatible: the GDPR in the age of big data. Seton Hall Law Rev 47:995–1020 Zarsky TZ (2016) Incompatible: the GDPR in the age of big data. Seton Hall Law Rev 47:995–1020
Metadata
Title
The Role of IS in the Conflicting Interests Regarding GDPR
Authors
Dr. Timo Jakobi
Prof. Dr. Maximilian von Grafenstein
Prof. Dr. Christine Legner
Clément Labadie
Prof. Dr. Dr. hc. mult. Peter Mertens
Dr. Ayten Öksüz
Prof. Dr. Gunnar Stevens
Publication date
09-03-2020
Publisher
Springer Fachmedien Wiesbaden
Published in
Business & Information Systems Engineering / Issue 3/2020
Print ISSN: 2363-7005
Electronic ISSN: 1867-0202
DOI
https://doi.org/10.1007/s12599-020-00633-4

Other articles of this Issue 3/2020

Business & Information Systems Engineering 3/2020 Go to the issue

Premium Partner