About the project
The goal of the project is to analyse the consequences for legal practice of the Non-Objective character of Risk to a Right, by challenging it from perspectives: legal approaches to the risk-based approach (case law), the Science and Technology Studies (STS) critique of risk, and psychology (through inter-rater reliability testing). Recital 76 of the General Data Protection Regulation (GDPR) obliges regulated entities to conduct an “objective assessment” of risk (cf. Statement of the WP29 on the role of a risk-based approach in data protection legal frameworks: “(...) provide for a reliable and relatively objective assessment of risk”).
We question the possibility of conducting an “objective” Risk to a Right assessment. The risk-based approach used in data protection can produce results that create an “illusion of scientific evidence”, which may diminish the level of protection of natural persons’ rights and freedoms. The project explores the reasons underlying this situation.
First, a conceptual clash between the logics of rights and risk—each operating differently within their respective domains—creates significant uncertainty as to how Risk to a Right assessment should be understood and operationalised.
Second, such assessments are usually conducted behind the closed doors of experts’ offices. They rely on risk management tools that are not well suited to addressing uncertainty and ignorance (i.e., situations in which both consequences and likelihood are difficult to measure). Digital regulations (GDPR, DSA, and AI Act) provide very little encouragement to involve those who might be affected in the decision-making process. As a result, risk-related decisions may fail to adequately reflect the interests of those who are at risk.
Third, in order to ensure fundamental rights protection and a basic level of legal certainty, assessments of Risk to a Right should exhibit a certain degree of consistency. We contend that this is not currently the case.
This is important because it may call into question the manner in which the risk-based approach is applied in digital regulations, and even its value for the protection of fundamental rights as such.
Research lines
- Case law analysis (CJEU, Poland, France, Germany)
- Selection of cases that relates to data protection and risk to a right
- Risk-based approach mapping – risk assessments in digital regulation
- Development of the analytical tool that would allow for comparative analysis of the risk to a right assessment legal architectures. Includes GDPR, DSA, AI Act
- Risk and digital constitutionalism (Law and STS)
- Investigating the concepts of risk in digital regulations from the STS perspective (e.g., Systemic risks)
- Analysis of the Risk to a Right decision-making in digital regulations from the perspective of the Risk Society
- Stakeholder engagement
- Engagement with stakeholders on participation in the assessments
- Engagement with other experts to deepen the understanding on risk to a right
- Inter-rater Reliability test of the risk assessments
Analysis of the consistency of the risk assessments between different data protection professionals
Financing
The Project "Risk as a subjective phenomenon. Integrating cognitive science into the concept of risk in European data protection law" is funded by the Belgian Research Foundation Flanders (FWO) [reference no. G000724N] and the Polish National Science Centre (NCN) [NCN reference no. 2022/47/I/HS5/02457] in the Weave initiative.
Graphics: themefire by Adobe Stock