29 May 2018

Compensation and Indemnity Insurance

The Queensland Civil and Administrative Tribunal (QCAT) has awarded $5,000 compensation under the Information Privacy Act 2009 (Qld) for a breach by WorkCover Pty Ltd of the state's Information Privacy Principles.

In PB v WorkCover Pty Ltd (2018] QCAT 138 WorkCover conceded that it breached IPPs 1, 3 and 11 regarding the collection and disclosure of PB’s medical records in relation to a workers’ compensation claim. QCAT stated that 'WorkCover made a litany of errors in the course of processing his claim. Many of these errors were trivial, although some had more serious consequences'. QCAT concluded that there had also been breaches of IPPs 2 and 4. It ordered WorkCover to pay $5,000 to the complainant. In the event that WorkCover holds any of the original medical records it was return them to the respective medical practices.

QCAT characterised WorkCover’s breaches as ‘careless rather than malicious’.

In relation to costs QCAT states
I am not prepared to order WorkCover to reimburse PB for his expenses. The manner in which the proceeding has been run before the Tribunal has stemmed in large measure from the extravagant and exorbitant compensation claim made by PB. PB initially claimed compensation in the vicinity of $4 million, notwithstanding the statutory maximum of $100,000 clearly set out in s 178(a)(v). Had PB applied an element of sobriety to his claim, or at least claimed compensation within the statutory limit, it is likely that he and WorkCover would have been spared considerable expense in the conduct of the proceeding.
QCAT notes that this is the second case in the Queensland privacy jurisdiction with an award of financial compensation by QCAT. In RM v Queensland Police Service, QCAT described the Service’s breach as having been ‘careless rather than malicious’. It ordered compensation of $5,000.

The report of the First Principles Review of the Medical Indemnity Insurance Fund for the Department of Health states 

In May 2002, the largest Medical Defence Organisation (MDO) in Australia was placed into provisional liquidation, which resulted in a potential lack of indemnity cover for many medical practitioners. At this time, insurers were also experiencing increased claims costs, uncertainty about the way courts were determining negligence cases (increasing the risk in setting premiums), reduced profitability and a fall in investment returns. As a result, medical practitioners were also experiencing significant increases in premiums (with some reportedly paying over a third of their incomes for indemnity cover), while others considered leaving the profession or ceasing high-risk procedures. If the MDO had gone into liquidation, it was estimated that approximately 60% of Australia’s medical practitioners would have been without medical indemnity cover and patients may not have been able to obtain redress for medical negligence. 
 
Against this backdrop, the Australian Government announced in October 2002, a range of measures including premium subsidies, government assistance for high-cost claims and improved regulation of the medical indemnity industry. In announcing the measures, the Prime Minister and the Assistant Treasurer stated that the arrangements would be monitored and that “in the long term hopefully these subsidies can be phased out". 
 
Since 2002, the Australian Government has expended over $400 million to 30 June 2016 on the schemes. Expenditure for the 2016-2017 financial year was $62.1 million, across seven discrete schemes, all of which form part of what is now known as the Indemnity Insurance Fund (IIF). xx Collectively the schemes comprising the IIF are designed to subsidise those privately practising medical practitioners with high premiums compared to their income (or practising as procedural general practitioners (GPs) in rural and remote areas) and to meet part or all of the claims costs associated with high or exceptional claims, or claims made when a privately practising medical practitioner or midwife has ceased practice. 
 
Consistent with the Terms of Reference, the purpose of this First Principles Review (FPR) is to answer three questions: 
 
1. To what degree has Commonwealth intervention been successful in providing stability to the medical indemnity insurance industry, availability of affordable indemnity insurance, and viability for professions, and patients, particularly in relation to high cost claims? 
 
2. What is the appropriate level of Commonwealth support needed to continue stability, affordability and accessibility of indemnity insurance for medical practitioners and eligible midwives? 
 
3. Are the seven schemes that collectively comprise the IIF fit for purpose or might improvements be made? 

 The Review's recommendations are summarised as

Should the Government wish to continue its current contribution to medical indemnity, a number of changes could be made to the schemes to improve efficiency, better target the schemes, increase transparency, better enable monitoring and reduce unnecessary burden on insurers and medical practitioners. ... 
 
If Government is seeking to gradually reduce the level of Commonwealth support (and achieve cost savings), further changes could be considered following the implementation of the monitoring framework and taking into account the outcomes of further consultation. Consideration could be given to:
  • restricting eligibility for the PSS such that medical practitioners earning over a certain income in annual private billings (for example, $500,000) would not be eligible for the PSS 
  • whether there is an ongoing need to cap premiums paid by privately practising midwives and to subsidise the cost of high claims (noting the absence of any high claims to date and the potential for other insurers to enter the market), and 
  • introducing a levy in association with the HCCS such that the Commonwealth’s contribution is steadily reduced, without increasing volatility to insurers and without disproportionately impacting smaller insurers and new entrants.
Should Government agree to the Review recommendations, it is proposed that:
  • the Department work closely with the sector to co-design the implementation detail. The Department could convene a regular meeting of key stakeholders (for example, every three months) to discuss implementation options for the reforms, review progress on the reforms and consider any changes needed to legislation and/or contracts (noting standard Government constraints relating to sharing of information subject to Government/Parliamentary consideration), and 
  • the changes arising from the Thematic Review progress as part of the reforms recommended by this First Principles Review
As legislation will require amendment (and an IT system will require development), a 12 to 24 month timeframe for some reform elements would be realistic. A reform package could commence from mid-2019, with some phasing-in of changes depending on the Government’s preferred reform package.

28 May 2018

Imaging

'Offensive but not Invasive? Imaging and Privacy in the ACT' by Bruce Baer Arnold in (2018) 15(3) Privacy Law Bulletin 47 comments
A recent ACT Supreme Court judgment has demonstrated the limits of the 2014 amendments to the Crimes Act 1900 (ACT) meant to protect privacy by prohibiting upskirting and downblousing. The ACT has grappled with balancing dignity and practicality regarding privacy as a matter of freedom from interference in public and private places. The territory government has also grappled, less successfully, with difficulties in statutory drafting and policy development. Those challenges are evident in a number of recent court decisions, particularly Stroop v Harris in which the court concluded that photographing the clothed genital area of women in a public area was not an invasion of privacy. This article considers that judgment and its implications for privacy protection in public spaces across Australia.

27 May 2018

Doctoral Mental Health Problems

'Work organization and mental health problems in PhD students' by Katia Levecque, Frederik Anseelab, Alain De Beuckelaer, Johan Van der Heyden and Lydia Gisle in (2017) 46(4) Research Policy comments
Research policy observers are increasingly concerned about the potential impact of current academic working conditions on mental health, particularly in PhD students. The aim of the current study is threefold. First, we assess the prevalence of mental health problems in a representative sample of PhD students in Flanders, Belgium (N = 3659). Second, we compare PhD students to three other samples: (1) highly educated in the general population (N = 769); (2) highly educated employees (N = 592); and (3) higher education students (N = 333). Third, we assess those organizational factors relating to the role of PhD students that predict mental health status. Results based on 12 mental health symptoms (GHQ-12) showed that 32% of PhD students are at risk of having or developing a common psychiatric disorder, especially depression. This estimate was significantly higher than those obtained in the comparison groups. Organizational policies were significantly associated with the prevalence of mental health problems. Especially work-family interface, job demands and job control, the supervisor’s leadership style, team decision-making culture, and perception of a career outside academia are linked to mental health problems.
Salient findings are
  • One in two PhD students experiences psychological distress; one in three is at risk of a common psychiatric disorder.
  • The prevalence of mental health problems is higher in PhD students than in the highly educated general population, highly educated employees and higher education students.
  • Work and organizational context are significant predictors of PhD students’ mental health.
In answering 'Why is the mental health of PhD students important for research policy?' the authors comment
While a genuine concern for individual well-being is probably the most important reason why policymakers should pay attention to mental health problems, we argue that mental health of PhD students should be of concern for three additional main reasons. First, the work of PhD students themselves constitutes a major source of scientific advancement, as a doctoral dissertation requires an original contribution to the scientific knowledge base. Furthermore, the publication of dissertation results is a prerequisite for an academic career (Roach and Sauermann, 2010), making dissertation work a major contributor to academic output (Hagen, 2010; Miller, 2013). Given the compelling evidence for the effects of mental health problems on individuals’research output (Danna and Griffin, 1999), it is to be expected that a sizable cohort of PhD students suffering from mental health problems may affect the overall quality and quantity of individuals’ research output. Second, as most PhD students are part of larger research teams, whose composition determines scientific impact (Leeetal., 2015), PhD students with mental health issues may pose a considerable cost to research institutions and teams. To date, research policy efforts seemed to have focused more on‘hard outcomes’ such as publications, impact factors and patents,while ignoring the health effects of‘soft’policy outcomes, such as stress. However, soft outcomes may create serious financial costs for research institutions,and they will impact the functioning of the larger research teams that the individual researchers are part of, thus also determining ‘hard’ outcomes (see eg. Goh et al., 2015a,b). Third, mental health problems of PhD students impact both the supply and entrance to the research industry.Organizational policies that are linked to mental health problems will lead individuals to quit their PhD studies or leave the research industry altogether (Podsakoff et al., 2007). Several studies of PhD students suggest that the dropout numbers range from 30 to 50 percent, depending on the scientific discipline and country (Stubb et al., 2012). Such high turnover will make it difficult for the industry to attract new talent (Lievens and Highhouse, 2003), thus threatening the viability and quality of the academic research industry. Because economic competition between countries is heavily dependent on the nation’s scientific advancement and cognitive ability (Rindermann and Thompson, 2011), the prospects of having trained academic researchers not further pursuing a research career because of mental health problems should be a major concern for research policy. In sum, given the potential importance of mental health problems for research policy,there is an urgent need for systematic empirical data rather than anecdotal information on their prevalence and the organizational policies that are linked to them. Given the current lack of an empirical basis for mental health concerns and solutions, the current study has three aims. First, we aim to inform research policy by assessing mental health prevalence in a large-scale representative sample of PhD students in Flanders, Belgium. Second, to assess the scope of the problem, we compared the mental health of PhD students with that of three other samples, a group of highly educated adults in the general population, a group of highly educated employees and a group of higher education students. Third, with the aim of better understanding how research and organizational policies may relate to mental health, we examined PhD students’ perceptions of the academic environment and linked them to mental health problems.

Passing

With news that controversial figure Rachel Dolezal has been charged with welfare fraud I have revisited 'Reverse Passing' by Khaled A. Beydoun and Erika K. Wilson in (2017) 64 UCLA Law Review 282.

The authors comment
Throughout American history untold numbers of people have concealed their true racial identities and assumed a white racial identity in order to reap the economic, political, and social benefits associated with whiteness. This phenomenon is known as passing. While legal scholars have thoroughly investigated passing in its conventional form, the inverse process of reverse passing—the process in which whites conceal their true racial identity and present themselves as nonwhite—has not been closely investigated within legal scholarship. 
Rachel Dolezal provides a timely study of the process of reverse passing. Dolezal—an Africana Studies Instructor and head of the Spokane, Washington NAACP—was outed as being white after years of phenotypically and culturally presenting herself as a Black woman. Dolezal’s “outing” generated much popular debate and scholarly discourse, most of which tended to frame her actions as a one-off occurrence by a deviant actor. This Article argues instead that her actions were evidence of a deeper structure of incentives rooted in the U.S. Supreme Court’s affirmative action jurisprudence. Though reverse passing is often framed as deviant or irrational, this Article demonstrates how the Supreme Court’s affirmative action jurisprudence creates tangible and intangible incentives for white actors to identify as nonwhite. It suggests that the Court’s entrenchment of the diversity rationale as the primary compelling state interest that can be used to justify race-conscious affirmative action programs generated situational value in nonwhiteness. That situational value in nonwhiteness now creates incentives that previously did not exist for whites to reverse-pass in order to obtain access to opportunities in education, employment and beyond. 
This Article is the first to coin, analyze, and propose a theory of reverse passing. It also deepens the rich and rising scholarship examining performance theory and the pliability of racial identity. Finally, given the reconsideration of the diversity rationale by the Supreme Court in Fisher v. University of Texas at Austin, this Article also provides an opportunity to critically examine the merits and shortcomings of the diversity rationale.
They state
American history, and legal literature, is saturated with analysis of the customary “passing” narrative. Passing is the phenomenon whereby nonwhites present themselves as white, while their “underlying identity is not altered, but hidden.” Since the inception of slavery through the present day, passing has been prominent within the scholarly literatures, popular media, and indeed, the collective American imagination. 
Until recently, racial passing in the other direction—from white to nonwhite—has garnered little to no attention, particularly by legal scholars and commentators. Although precedents for “reverse passing” exist, Rachel Dolezal and her outing as a white woman thrust this burgeoning phenomenon and its corollary questions about and the fluidity of racial identity and the concept of “transracialism” to the forefront. Through this tragic archetype, the process of reverse passing was broadly exposed, became the subject of unprecedented attention, and sparked novel questions about the fluidity of race and the malleability of racial identity. 
To be sure, Rachel Dolezal provides a noteworthy case study. Dolezal was born a white woman. The daughter of two white parents from Lincoln County, Montana, Dolezal’s ancestry was “Czech, German and a few other things.” By her own account, Dolezal was fascinated by and identified with Black  culture from a very early age. She eventually obtained a graduate degree in fine arts with a focus on Black narrative painting from Howard University—a historically Black university in Washington, D.C. 
Despite her purported identification with Black culture, Dolezal’s tenure at Howard University was marred by controversy. She sued the University for discrimination, alleging that she was denied teaching positions and scholarship aid, received less favorable placements for her artwork, and was subject to a racially hostile environment because she was white. Dolezal’s lawsuit was ultimately dismissed after the Court of Appeals found that she failed to demonstrate that the treatment she received was because of her race, or that she was subject to a racially hostile work environment. 
After her lawsuit was dismissed, Dolezal’s relationship with Black culture shifted markedly from one of purported identification to one of full-fledged assumption. She gradually shed her white identity for one of a “light-skinned black woman,” but devoid of the ancestry, biological ties, and the “lived experience” associated with the latter. Dolezal left her past, parents, and former life behind, strategically piecing together a new identity with the experiences, opportunities, and profile “identifying as Black” offered. Exit Rachel Dolezal the white woman. 
Enter Rachel Dolezal the Black woman. Dolezal tanned her skin, rotated through several hairstyles traditionally associated with Black womanhood, helmed the Spokane chapter of the National Association for the Advancement of Colored People (NAACP), and obtained an adjunct lecturer position at Eastern Washington University in Africana Studies.19 She held herself out to the world as a Black woman. Short of explicit declarations of Blackness, her myriad roles and associations bespoke a racial identity that she was not assigned at birth. Dolezal’s racial presentation was successful until she was publicly outed on June 11, 2015 by a Spokane, Washington reporter who produced a picture of Dolezal’s parents and presented it to her on camera. This caused Dolezal to retreat from the lens, and in the coming days recoil from the racial duplicity she maintained for years. 
Even after being outed as white, Dolezal maintained—without biological or ancestral basis—that she was Black. “It’s not a costume . . . It’s not something that I can put on and take off anymore,” she proclaimed days after her public outing. On NBC’s Today Show, Dolezal stated that, “I identify as Black,” to Matt Lauer and a captive American audience, marking that her campaign to reverse pass—from white to Black—was complete. For Dolezal, Blackness is more than a racial costume. It is an identity she can fully assume on account of some deep-seated, existential affinity. Presumably, it is also an identity she can shed if her affinity towards Blackness wanes, or is trumped by a competing identity. 
The authors continue
Dolezal’s turbulent racial journey is arguably the most prominent and examined reverse passing vignette in American history. But it is hardly the only one. As illustrated in this Article, the Dolezal passage is one of many reverse passing stories and, moreover, is representative of only one form of many modalities of reverse racial deception. 
Reverse passing, this Article advances, is the process by which whites shed their white racial identity in exchange for a nonwhite racial identity. As noted by other legal scholars, most notably Cheryl I. Harris, whiteness confers tangible economic, social, and political benefits to those who are classified as white. Indeed, an institutional racial hierarchy exists “in which the closer one can approximate whiteness, the better off one is economically and socially.” Put another way, a racial hierarchy and valuation system exists in which white racial classifications are afforded the highest placement and value within the hierarchy while racial classifications that are the farthest away from whiteness, such as Blackness, are afforded the lowest placement and least value. 
Given this racial hierarchy, “passing” has traditionally been a process by which nonwhites have sought to perform and present themselves as white in order to escape slavery, circumvent racism, access new worlds of economic and employment opportunity, shop and dine, investigate lynching, and, for many passers, to seek liberation and ensure survival. Due to the tangible benefits associated with whiteness and the negative value associated with nonwhiteness, persons who are able to racially identity as white have every incentive to do so in most contexts. 
This Article suggests that there has been a shift in the valuation scheme within the racial hierarchy caused in part by modern affirmative action jurisprudence. The shift is a situational one in which — at certain times and in certain spaces — racial diversity is perceived as a valuable commodity. Importantly, within this framework, “racial diversity” is conceptualized to mean increasing the number of nonwhite persons in a particular space, particularly with respect to coveted university seats and employment opportunities. As Nancy Leong observes, the concept of racial diversity (or increasing the presence of nonwhite persons) gained widespread societal value as a result of the U.S. Supreme Court’s Fourteenth Amendment affirmative action equal protection jurisprudence. 
In particular, in the seminal affirmative action case Regents of the University of California v. Bakke, the Court held that rather than remedying the generalized lingering effects of past societal discrimination, diversity is the compelling state interest that justifies the consideration of race in college admissions programs. In reaching this conclusion, the Court extolled the virtues of racially heterogeneous groups while diminishing the relevance and propriety of using affirmative action programs as a remedial measure for historic discrimination against minority groups. Subsequent Supreme Court decisions grappling with affirmative action in higher education, namely Grutter v. Bollinger and Fisher v. University of Texas at Austin (Fisher I), reified the notion that racial diversity, rather than remedying the effects of lingering past societal discrimination, is the appropriate compelling state interest that justifies the use of race in college admissions programs. 
The Supreme Court’s affirmative action jurisprudence narrows the consideration of race, and more specifically, nonwhite racial identities, finding it compelling only for purposes of diversifying a student body. Indeed, recent Supreme Court jurisprudence addressing race generally, and affirmative action specifically, readily ignores the salience of race and the differences in lived experiences resulting from differing racial classifications. By supplanting discrimination remediation with diversity as the sole compelling state interest, the Supreme Court removed the import of actual “lived experiences,” particularly lived experiences of marginalization and discrimination experienced by people of color. The Court instead reduced nonwhite racial identity into phenotype and culture. 
Thus, identity-correlated cultural traits, along with phenotypes that appear to result in “adequate” racial representation—rather than the lived experiences marred by marginalization and discrimination—became the marker of access to the benefits afforded by affirmative action programs. Such a reduction of nonwhiteness makes it an identity that some whites can easily perform and present for purposes of capitalizing on racial identities coveted by diversity-driven programming. 
Today, because of the emphasis placed on racial diversity by the Supreme Court in its affirmative action jurisprudence, nonwhite racial classifications have increased in value to the extent they can be capitalized upon to bring about representational diversity. A critical mass of nonwhites is thought to add value through its performative contributions to classrooms, campuses, and society. These performative contributions are divorced from the broader lived and existential dimensions that remedial affirmative action programs previously took into consideration when considering nonwhite applicants for university admission. Before Bakke, university affirmative action programs for example often took measures to consider how membership in a particular racial or ethnic group affected an applicant’s life experience and opportunities. In particular, such programs sought to level the playing field by taking into consideration the effect that discrimination likely had on the applicant’s lived experience. As a result, these performative contributions flattened the meaning of nonwhite racial identities, and converted them into more accessible forms for whites to perform and into which they can pass. In short, prevailing affirmative action doctrine, by narrowing the applied definition of nonwhite racial identity, incentivizes whites who believe they can pass as nonwhites to do so to access coveted opportunities, particularly in education and employment. 
Consequently, the stakes to “reverse pass” are high for whites. Such “reverse passers” seek to access the associated (and perceived) legal and cultural benefits of nonwhite identity concomitant with increased mandates for more diversity. Although not an entirely new phenomenon, recent events—including the outing of Rachel Dolezal—highlight the possibilities for increased incidences of reverse passing. While discursively viewed in the media and by many scholars as a phenomenon born out of individual autonomy or “transracial” options and possibilities, this Article investigates the law’s—and specifically the Supreme Court’s affirmative action equal protection jurisprudence’s—role in enabling and incentivizing reverse passing. 
Notably, this Article is the first to formally define reverse passing and conceptualize its operation within the legal and cultural realms. Building on the rich legal and social science literature on traditional passing, where the “classic racial passer in the United States has been the ‘white Negro,’” this Article analyzes the process by which whites assume nonwhite identities to access valuable educational or employment opportunities, and spaces and communities preferring nonwhites, and to build nonwhite public profiles that augment political influence or social prestige. 
By introducing reverse passing—as concept and process—into the legal literature, this Article deepens the rich and rising scholarship examining performance theory and the pliability of racial identity. Several legal commentators, most notably Devon Carbado and Mitu Gulati, Kenji Yoshino, Camille Gear Rich, and Nancy Leong, have made significant contributions to the modern literature on racial performance theory. As such, their work is critical to this Article. Certainly, as affirmative action continues to be debated within the courts, including in the recent decision in Fisher v. University of Texas II, reverse passing—as a matter of scholarly, practical, and popular concern—will only become more pressing and prominent. 
This Article proceeds as follows. The construction of racial hierarchy and reverse passing theory are the focuses of Part I, which includes a description of the two primary forms of reverse passing: legal and cultural. Part II analyzes prevailing Fourteenth Amendment equal protection jurisprudence in relation to affirmative action, which extends the legal catalyst incentivizing reverse passing. Part III examines the principal forms of reverse passing—legal and cultural—through an analysis of prominent case law and pressing case studies. Part IV examines the dialectic between the law and transracialism, a theory of racial mobility that justifies reverse passing but practically restricts passing in the other direction (nonwhite to white).

EU Data Protection Handbook

A new edition of the Handbook on European data protection law from the Council of Europe, European Union Agency for Fundamental Rights (FRA) and European Data Protection Supervisor (EDPS) is now online.

It is particularly valuable for coverage of the modernisation of Convention 108, the applicability of the new data protection framework of the European Union (GDPR and Police and Justice Directive), and recent judgments of the European Court of Human Rights and Court of Justice of the European Union.

In discussing the GDPR the Handbook comments
European Union data protection law is composed of primary and secondary EU law. The treaties, namely the Treaty on European Union (TEU) and the Treaty on the Functioning of the European Union (TFEU), have been ratified by all EU Member States; they form ‘primary EU law’. The regulations, directives and decisions of the EU have been adopted by the EU institutions that have been given such authority under the treaties; they constitute ‘secondary EU law’.
Data protection in primary EU law
The original treaties of the European Communities did not contain any reference to human rights or their protection, given that the European Economic Community was initially envisaged as a regional organisation focused on economic integration and the establishment of a common market. A fundamental principle underpinning the creation and development of the European Communities – and one which is equally valid today – is the principle of conferral. According to this principle, the EU acts only within the limits of the competences conferred upon it by the Member States, as reflected in the EU treaties. In contrast to the Council of Europe, the EU treaties include no explicit competence on fundamental rights matters. As cases came before the CJEU alleging human rights violations in areas within the scope of EU law, however, the CJEU provided an important interpretation of the treaties. To grant protection to individuals, it brought fundamental rights into the so-called general principles of European law. According to the CJEU, these general principles reflect the content of human rights protection found in national constitutions and human rights treaties, in particular the ECHR. The CJEU stated that it would ensure compliance of EU law with these principles. In recognising that its policies could have an impact on human rights and in an effort to make citizens feel ‘closer’ to the EU, the EU in 2000 proclaimed the Charter of Fundamental Rights of the European Union (Charter). It incorporates the whole range of civil, political, economic and social rights of European citizens, by synthesising the constitutional traditions and international obligations common to the Member States. The rights described in the Charter are divided into six sections: dignity, freedoms, equality, solidarity, citizens’ rights and justice.
Originally only a political document, the Charter became legally binding27 as EU primary law (see Article 6(1) of the TEU) when the Lisbon Treaty came into force on 1Decembe 2009.The provisions of the Charter are addressed to EU institutions and bodies, obliging them to respect the rights listed therein while fulfilling their duties. The Charter’s provisions also bind Member States when they implement EU law.
The Charter not only guarantees the respect for private and family life (Article 7), but also establishes the right to the protection of personal data (Article 8). The Charter explicitly raises the level of this protection to that of a fundamental right in EU law. EU institutions and bodies must guarantee and respect this right, as do Member States when implementing Union law (Article 51 of the Charter). Formulated several years after the Data Protection Directive, Article 8 of the Charter must be understood as embodying pre-existing EU data protection law. The Charter, therefore, not only explicitly mentions a right to data protection in Article 8(1), but also refers to key data protection principles in Article  (2). Finally, Article 8(3) of the Charter requires an independent authority to control the implementation of these principles. The adoption of the Lisbon Treaty is a landmark in the development of data protection law, not only for elevating the Charter to the status of a binding legal document at the level of primary law, but also for providing for the right to personal data protection. This right is specifically provided for in Article 16 of the TFEU, under the part of the treaty dedicated to the general principles of the EU. Article 16 also creates a new legal basis, granting the EU the competence to legislate on data protection matters. This is an important development because EU data protection rules – notably the Data Protection Directive – were initially based on the internal market legal basis, and on the need to approximate national laws so that the free movement of data within the EU was not inhibited. Article 16 of the TFEU now provides an independent legal basis for a modern, comprehensive approach to data protection, which covers all matters of EU competence, including police and judicial cooperation in criminal matters. Article 16 of the TFEU also affirms that compliance with data protection rules adopted pursuant to it must be subject to the control of independent supervisory authorities. Article 16 served as a legal basis for the adoption of the comprehensive reform of data protection rules in 2016, i.e. the General Data Protection Regulation and the Data Protection Directive for Police and Criminal Justice Authorities (see below).
The General Data Protection Regulation
From 1995 until May 2018, the principal EU legal instrument on data protection was Directive 95/46/EC of the European Parliament and the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (Data Protection Directive).It was adopted in 1995, at a time when several Member States had already adopted national data protection laws, and emerged from the need to harmonise these laws to ensure a high level of protection and the free flow of personal data among the different Member States. Free movement of goods, capital, services and people within the internal market required the free flow of data, which could not be realised unless the Member States could rely on a uniform high level of data protection.
The Data Protection Directive reflected the data protection principles already contained in national laws and in Convention 108, while often expanding them. It drew on the possibility, provided for in Article 11 of Convention 108, of adding on instruments of protection. In particular, the introduction in the directive of independent supervision as an instrument for improving compliance with data protection rules proved to be an important contribution to the effective functioning of European data protection law. Consequently, this feature was incorporated into CoE law in 2001 by the Additional Protocol to Convention 108. This illustrates the close interaction and positive influence of the two instruments upon one another over the years.
The Data Protection Directive established a detailed and comprehensive data protection system in the EU. However, in accordance with the EU legal system, directives do not apply directly and must be transposed into the national laws of the Member States. Inevitably, Member States have a margin of discretion in transposing the directive’s provisions. Even though the directive was meant to provide complete harmonisation31 (and a full level of protection), in practice it was transposed differently in the Member States. This resulted in the establishment of diverse data protection rules across the EU, with definitions and rules interpreted differently in national laws. The levels of enforcement and the severity of sanctions also varied across the Member States. Finally, there were significant changes in information technology since the drafting of the directive in the mid-1990s. Taken together, these reasons prompted the reform of EU data protection legislation.
The reform led to the adoption of the General Data Protection Regulation in April 2016, after years of intense discussion. The debates on the need to modernise EU data protection rules began in 2009, when the Commission launched a public consultation about the future legal framework for the fundamental right to personal data protection. The proposal for the regulation was published by the Commission in January 2012, starting a long legislative process of negotiations between the European Parliament and the Council of the EU. After adoption, the General Data Protection Regulation provided for a two year-transitional period. It became fully applicable on 25 May 2018, when the Data Protection Directive was repealed.
The adoption of the General Data Protection Regulation in 2016 modernised EU data protection legislation, making it fit for protecting fundamental rights in the context of the digital age’s economic and social challenges. The GDPR preserves and develops the core principles and rights of the data subject provided for in the Data Protection Directive. In addition, it introduced new obligations requiring organisations to implement data protection by design and by default; to appoint a Data Protection Officer in certain circumstances; to comply with a new right to data portability; and to comply with the principle of accountability. Under EU law, regulations are directly applicable; there is no need for national implementation. The General Data Protection Regulation thus provides for a single set of data protection rules across the EU. This creates consistent data protection rules throughout the EU, establishing an environment of legal certainty from which economic operators and individuals as “data subjects” may benefit.
However, even though the General Data Protection Regulation is directly applicable, Member States are expected to update their existing national data protection laws to fully align with the regulation, while also reflecting a margin of discretion for specific provisions in recital 10. The main rules and principles established in the regulation, and the strong rights it affords to individuals, form a large part of the handbook and are presented in the following chapters. The regulation has comprehensive rules on territorial scope. It applies to businesses established in the EU, and also applies to controllers and processors not established in the EU that offer goods or services to data subjects in the EU or monitor their behaviour. As several overseas technology businesses have a key share in the European market and millions of EU customers, subjecting these organisations to EU data protection rules is important to ensure the protection of individuals, as well as to ensure a level playing field.

Governance and Digital Constitutionalism

'Saving Governance-by-Design' by Deirdre K. Mulligan and Kenneth A. Bamberger in (2018) 106 California Law Review 697 comments
 Governing through technology has proven irresistibly seductive. Everything from the Internet backbone to consumer devices employs technological design to regulate behavior purposefully by promoting values such as privacy, security, intellectual property protection, innovation, and freedom of expression. Legal and policy scholarship has discussed individual skirmishes over the political impact of technical choices—from whether intelligence and police agencies can gain access to privately encrypted data to debates over digital rights management. But it has failed to come to terms with the reality that “governance-by-design”—the purposeful effort to use technology to embed values—is becoming a central mode of policymaking, and that our existing regulatory system is fundamentally ill-equipped to prevent that phenomenon from subverting public governance.
Far from being a panacea, governance-by-design has undermined important governance norms and chipped away at our voting, speech, privacy, and equality rights. In administrative agencies, courts, Congress, and international policy bodies, public discussions about embedding values in design arise in a one-off, haphazard way, if at all. Constrained by their structural limitations, these traditional venues rarely explore the full range of other values that design might affect, and often advance, a single value or occasionally pit one value against another. They seldom permit a meta-discussion about when and whether it is appropriate to enlist technology in the service of values at all. And their policy discussions almost never include designers, engineers, and those that study the impact of socio-technical systems on values.
When technology is designed to regulate without such discussions—as it often is—the effects can be even more insidious. The resulting technology often hides government and corporate aims and the fundamental political decisions that have been made. In this way, governance-by-design obscures policy choices altogether. Such choices recede from the political as they become what “is” rather than what politics has determined ought to be.
This Article proposes a detailed framework for saving governance-by-design.
Through four case studies, the Article examines a range of recent battles over the values embedded in technology design and makes the case that we are entering an era of policymaking by “design war.” These four battles, in turn, highlight four recurring dysfunctions of governance-by-design:
First, governance-by-design overreaches by using overbroad technological fixes that lack the flexibility to balance equities and adapt to changing circumstances. Errors and unintended consequences result. 
Second, governance-by-design often privileges one or a few values while excluding other important ones, particularly broad human rights. 
Third, regulators lack the proper tools for governance-by-design. Administrative agencies, legislatures, and courts often lack technical expertise and have traditional structures and accountability mechanisms that poorly fit the job of regulating technology. 
Fourth, governance-by-design decisions that broadly affect the public are often made in private venues or in processes that make technological choices appear inevitable and apolitical.
If we fail to develop new rules of engagement for governance-by design, substantial and consequential policy choices will be made without effective public participation, purposeful debate, and relevant expertise. Important values will be sacrificed—sometimes inadvertently, because of bad decisions, and sometimes willfully, because decisions will be captured by powerful stakeholders.
To address these critical issues, this Article proposes four rules of engagement. It constructs a framework to help decision makers protect values and democratic processes as they consider regulating by technology. Informed by the examination of skirmishes across the battlefields, as well as relevant Science and Technology Studies (STS), legal, design, and engineering literatures, this framework embraces four overarching imperatives:
1. Design with Modesty and Restraint to Preserve Flexibility 
2. Privilege Human and Public Rights 
3. Ensure Regulators Possess the Right Tools: Broad Authority and Competence, and Technical Expertise 
4. Maintain the Publicness of Policymaking
These rules of engagement offer a way toward surfacing and resolving value disputes in technological design, while preserving rather than subverting public governance and public values.
'The limits of (digital) constitutionalism: Exploring the privacy-security (im)balance in Australia' by Monique Mann, Angela Daly, Michael Wilson  and Nicolas Suzor in (2018) 80(4) International Communication Gazette 369 comments
This article explores the challenges of digital constitutionalism in practice through a case study examining how concepts of privacy and security have been framed and contested in Australian cyber security and telecommunications policy-making over the last decade. The Australian Government has formally committed to ‘internet freedom’ norms, including privacy, through membership of the Freedom Online Coalition (FOC). Importantly, however, this commitment is non-binding and designed primarily to guide the development of policy by legislators and the executive government. Through this analysis, we seek to understand if, and how, principles of digital constitutionalism have been incorporated at the national level. Our analysis suggests a fundamental challenge for the project of digital constitutionalism in developing and implementing principles that have practical or legally binding impact on domestic telecommunications and cyber security policy. Australia is the only major Western liberal democracy without comprehensive constitutional human rights or a legislated bill of rights at the federal level; this means that the task of ‘balancing’ what are conceived as competing rights is left only to the legislature. Our analysis shows that despite high-level commitments to privacy as per the Freedom Online Coalition, individual rights are routinely discounted against collective rights to security. We conclude by arguing that, at least in Australia, the domestic conditions limit the practical application and enforcement of digital constitutionalism’s norms.

Populism

'The Legal Face of Populism: From the Classroom to the Courtroom' (Jean Monnet Working Paper 9/17) by Myriam Hunter-Henin comments
This article examines the normative-conceptual contrast between populism and radical democracy against the specific backdrop of two case-studies – the Fundamental British Values discourse in the UK and the French burqa ban. The goals of the article are twofold. First, to enrich the understanding of populism by analysing the interactions between populism, democracy and legal reasoning. Secondly, to offer ways of resisting a populist turn in legal reasoning. I will argue that law’s response to populism should embrace the ideals of radical democracy, namely deliberation and inclusiveness. In order to enhance deliberation and ensure its inclusiveness, I will submit that law should both retreat (from the classroom) and actively riposte against populism (in the courtroom). 
Hunter-Henin argues
Donald Trump’s victory in the US and the Brexit referendum in the UK have been praised or criticised as a populist turn. Both expressed the voices of those who feel let down by the so-called elites and think that the solution is an authoritarian figure strong enough not to care what a biased establishment thinks about him. Flamboyant and extreme, populism has attracted the attention of many scholars. For most, populism can best be approached in relation to what it rejects: populism has thus been described as anti-elitist, anti-constitutionalist, anti-institutional, antirepresentative and anti-democratic. A debate has ensued as to whether this hostile stance is inherently harmful or can act as a corrective to democracy, or at least as a useful barometer of democracy’s (ill) health. Despite the great divergence of approaches to capture populism, most scholars converge on one point: namely that populism is short-lived in its individual manifestations. Even if it is inherently hostile to democracy, ts damaging effects should not therefore, the argument goes, be exaggerated. Once in power, populist leaders would not be likely to change institutions and their policies would not outlive the populist leader. Moreover populist leaders, once in power, may struggle more than others to maintain their popularity. Amongst these reassuring authors, a notable exception is Jan-Werner Müller, whose work has demonstrated how populist leaders and parties may use the language of democratic values to deform democracy.
However, little attention has been paid thus far to the full implications of populism on law. Most recent scholarship has revealed that populism cannot be properly understood as a (mere) reaction against representative democracy and institutional constitutionalism. It is more positively an ideology which seeks to curtail pluralist political debate. Yet the broader definition of populism as an ideology, rather than as an anti-institutional stance, has so far had little impact on how the consequences of populism are assessed. The consequences of populism are still too often measured in light of their relative low impact on representative mechanisms and institutions. But if populism is, beyond representative politics, about conveying a monolithic discourse and muffling the voices of those who are characterized as “outsiders”, its consequences as I will argue, cannot merely be measured in institutional and representative terms. The assessment must include, more broadly, considerations of how populism might undermine access to and freedom of the political debate. As this article will demonstrate, the concept of populism (as well as its implications) is therefore best understood by contrast to a radical conception of democracy, which goes beyond majority rules and aggregation of interests, to include broader conditions of participation and deliberation. Against this background of radical democracy, it will be argued that if individual instances of populism can be short-lived, their implications are nevertheless likely to have long-lasting and damaging effects, both on law and democracy. By restraining its deliberative and inclusive characters, populism threatens both the very core of democracy and legal reasoning itself. 
The main aims of the article are twofold. First, it will seek to enrich the understanding of populism by analysing the interactions between populism, legal reasoning and democracy Secondly, having identified the full facets of populism, it will suggest ways of resistance. Scholarship thus far has paid little attention to the issue, either because populism has been seen as part of democracy itself or because fighting populism would paradoxically seem to be anti-democratic. When remedies have been sought, the focus has been on reforms to the electoral system. However, it will be argued that as populism manifests itself in a myriad of ways, well beyond issues of representation, a much broader reaction is required. A deliberative conception of democracy will be used to offer ways of reacting against populism and ensure that civil society and courts are more protective of the inclusiveness of the political landscape. The article will be structured as follows. In a first part, I will select two recent legal manifestations of populism in two distinct European countries: the rhetoric of “Fundamental British Values” in the UK and the French 2010 legislative ban on the full covering of the face in the public sphere. These examples have been selected because they deal with areas which are not immediately associated with populism: they do not relate to issues of political representativeness nor do they directly embody the antiimmigration agenda which has become symptomatic of populism in Europe. The Fundamental British Value (FBV) discourse indirectly relates to anti-terrorism (which the fight against extreme ideologies, through the teaching of FBV is supposed to bolster) and education (as schools, universities and nurseries are now under a duty to actively promote FBV). The French ban on the full covering of the face deals with religious freedom and an extensive conception of secularism. Through the broad spectrum of areas that they touch upon, and the distinct legal cultures and constitutional orders that they emanate from, these examples illustrate that populism can take many forms, across legal disciplines.
Having identified how these two examples can be characterized as instances of a populist turn of law and analysed their implications for law and democracy, I will then, in a second part, suggest ways of resistance, building on theories of deliberative democracy.