Skip to main content

2019 | OriginalPaper | Buchkapitel

The GDPR and Its Application in IoT and Connected Cars Opportunities for Business and Competitivity

verfasst von : Gaëlle Kermorgant, Michèle Guilbot

Erschienen in: Electronic Components and Systems for Automotive Applications

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The General Data Protection Regulation (GDPR) is in force since May 25 2018. This has an important impact on the design and development of new technologies based on exploitation of data, in particular private data. Not complying with the requirements can have high financial consequences up to 4% of the worldwide turnover of a company as a fine. At first glance, GDPR seems to be a constraint. However the, this regulation offers also the opportunity to develop new services based on big data processing and become competitive in a domain, which is considered being the petroleum of the 21st century. The paper describes the impact and opportunities of the GDPR on the Internet of things (IoT) and connected cars by highlighting two examples:
  • the first aims at improving road safety by calculating a risk factor based on analysis of driver behaviour, data collection and artificial intelligence
  • the second aims at improving road infrastructure by detecting road deficiencies or risk zone through in car data collection.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Anhänge
Nur mit Berechtigung zugänglich
Fußnoten
1
GDPR 2016/679 which follow the Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
 
2
REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications) which will replace the DIRECTIVE 2002/58/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications).
 
3
See in particular for France the revision of the Act n°78-17 of the 6th January 1978 amended by Act n°2018-493 of the 20th June 2018.
 
5
Presentation of Félicien VALLET: GDPR—general introduction.
 
6
This clarification had already been stated in Resolution (délibération) 2006-066 of the 16th March 2016 adopting a recommendation on the implementation of devices to geolocate motor vehicles used by employees of a private or public body. See also GDPR, art.4.1.
 
7
A third scenario, IN-OUT-IN, is not illustrated in our article. According to this scenario, data is transmitted outside the vehicle before returning to it, in order to trigger an action. For example, a dynamic navigation system that allows you to send back live information on the state of road congestion in order to calculate a new route.
 
8
See in particular the Decision (délibération) n°2005-278 of the 17th November 2005 refusing the implementation by MAAF Assurances SA of automated processing of personal data based on the geolocation of vehicles.
 
9
Op. cit.: French Act n°78-17, article 34.
 
10
Op. cit.: Decision n°2005-278.
 
11
Free translation of the Resolution (Délibération) n° 2010-096 of the 8th April 2010 on the implementation by insurance companies and car manufacturers of in-vehicle geolocation devices.
 
12
A French Institut Le Centre d’Etudes et d’expertises sur les Risques, l’Environnement, la Mobilité et l’Aménagement est un établissement public administratif français. Adresse site.
 
13
S_VRAI: Saving lives through incident analysis feedback. DYMOA: infrastructure diagnosis and vehicle dynamics for motorcycles and cars. For a presentation see the attached appendices.
 
14
RDR or Road data recorders.
 
15
The collection for DYMOA being carried out using equipment embedded on private vehicles.
 
16
On the main measures adopted see Guilbot et al. (2016a, 2016b, 2017, 2018).
 
17
A Joint Technical Committee includes staff representatives and management.
 
18
Below is a link to the results of the experimental phase in 2015. The new phase, currently in the process of collecting consent, already shows that a sufficient number of drivers will volunteer:
 
19
The WP29 is the former grouping of European regulatory authories that has been replaced by the EDPS with the implementation of the GDPR.
 
20
ISO standard 29100:2011, taken over by the opinion 05/2014 of the WP29, p. 6.
 
21
Op. cit.: GDPR, recital 26.
 
22
. A vehicle authentication may be required to provide a service or to provide evidence in the event of an accident.
 
23
ECJ, Judgment C-553/07, 7 May 2009 College van burgemeester en wethouders van Rotterdam/M.E.E. Rijkeboer.
 
24
Op. cit.: Compliance Package, p. 7.
 
25
WP29, 2014.
 
26
Op. cit.: GDPR, recital 28.
 
27
Directive 95/46, article 6-c.
 
28
This even though these would not be the initial purposes for which the data were collected, but subsequent purposes authorized by law, such as scientific or historical research or research for statistical purposes. The GDPR, which also admits the subsequent use of data for purposes that are "not incompatible" with the original purposes [Art. 5 (1) (b)], recalls that "appropriate guarantees for the rights and freedoms of the data subject" must nevertheless be put in place (recital 156). Data controllers must therefore develop "technical and organisationnel measures" to comply with the principles imposed by the Regulation and ensure respect for the rights and freedoms enshrined in the Regulation.
 
29
GDPR article 5-1-c.
 
30
IP address IP of authorised remote computers, login et password for authorised people.
 
31
Op. cit.: Compiance Package p. 26.
 
32
The rights of third parties are preserved since the license plates and faces of pedestrians who may be in the field of the camera are blurred.
 
Literatur
Zurück zum Zitat CNIL (2017). Connected vehicles and personal data CNIL (2017). Connected vehicles and personal data
Zurück zum Zitat Guilbot M, Serre T, Ledoux V (2016a) Quelle protection pour les données personnelles des conducteurs? Revue TEC n°231, novembre 2016 pp 44–45 Guilbot M, Serre T, Ledoux V (2016a) Quelle protection pour les données personnelles des conducteurs? Revue TEC n°231, novembre 2016 pp 44–45
Zurück zum Zitat Guilbot M, Serre T, Naude C, Ledoux V (2016b) Legal conditions for implementing EDRs in public fleets of vehicles. In: 11th ITS European Congress. Glasgow, Scotland, June 6–9, 2016, 10p Guilbot M, Serre T, Naude C, Ledoux V (2016b) Legal conditions for implementing EDRs in public fleets of vehicles. In: 11th ITS European Congress. Glasgow, Scotland, June 6–9, 2016, 10p
Zurück zum Zitat Guilbot M, Serre T, Ledoux V (2017) Concilier la collecte des données de conduite individuelles et les droits fondamentaux des conducteurs. Chap. 3 dans Evaluation des politiques de sécurité routière. Nouvelles technologies, enjeux économiques et communication. Coord. par Blanchard G. et Carnis L. Ed. Le Harmattan, déc. 2017 pp 57–74 Guilbot M, Serre T, Ledoux V (2017) Concilier la collecte des données de conduite individuelles et les droits fondamentaux des conducteurs. Chap. 3 dans Evaluation des politiques de sécurité routière. Nouvelles technologies, enjeux économiques et communication. Coord. par Blanchard G. et Carnis L. Ed. Le Harmattan, déc. 2017 pp 57–74
Zurück zum Zitat Guilbot M, Vaslin V, Arrègle E (2018) Véhicule connecté, communicant et protection des données à caractère personnel des usagers. Les Rencontres de la mobilité intelligente, ATEC, 24 janvier 2018, 13p Guilbot M, Vaslin V, Arrègle E (2018) Véhicule connecté, communicant et protection des données à caractère personnel des usagers. Les Rencontres de la mobilité intelligente, ATEC, 24 janvier 2018, 13p
Metadaten
Titel
The GDPR and Its Application in IoT and Connected Cars Opportunities for Business and Competitivity
verfasst von
Gaëlle Kermorgant
Michèle Guilbot
Copyright-Jahr
2019
DOI
https://doi.org/10.1007/978-3-030-14156-1_22

    Premium Partner