Technology and privacy – is the GDPR already out of date?

Published: 31 Oct 2018
Type: Insight

 First published by the Cayman Financial Review, October 2018


Nothing challenges the effectiveness of privacy laws like technological innovation. As the volume of data being generated about individuals increases, technology is making it easier than ever for data to be captured and analyzed, making that data ever more valuable.

Unfortunately, technology also introduces new and previously unknown threats. As such, how companies collect, process and protect the personal data of their customers, staff and suppliers has become a key challenge.

The General Data Protection Regulation (GDPR), which came into effect on May 25, 2018, is the European Union’s legislative response to this challenge. Drafted to be “technology neutral,” the GDPR is intended to give individuals better control over their personal data and establish a single set of data protection rules across the EU, thereby making it simpler and cheaper for organisations to do business. So far, so sensible. Unfortunately, technology always runs ahead of the law and the GDPR is already starting to show some of its limitations as the law clashes with newer technologies.

Blockchain technology

Blockchain – or distributed ledger technology – replaces the centralised transaction database with a decentralised, distributed digital ledger where each and every transaction flowing through it is independently verified against other ledgers maintained by different parties, in different locations. In this way, the record of any single transaction cannot be altered without changing all subsequent transactions or “blocks” that are chained together across the entire distributed ledger. It is this immutability that ensures the reliability of the information stored on the chain.

The GDPR gives data subjects the right to request that their personal data is either rectified or deleted altogether. For blockchain projects that involve the storage of personal data, these legal rights do not mix well with the new technology. Drafted on the assumption that there will always be centralised services controlling access rights to the user’s data, the GDPR fails to take into account how a permissionless blockchain works. Ultimately, this may mean that blockchain technology cannot be used for the processing of personal data without potentially falling foul of the GDPR.

Interestingly, blockchain technology provides its own potential solution to this problem by allowing personal data to be kept off the various ledgers altogether. It does this by replacing the personal data with an encrypted reference to it – a “hash.” These hashes, or digital fingerprints, prove that the data exists, but without the data itself appearing on the chain.

Problem solved? Unfortunately not. The GDPR draws an unhelpful distinction between pseudonymised and anonymised data. Pseudonymisation occurs where personal data is subjected to technological measures (like hashing or encryption) so that it no longer directly identifies an individual without the use of additional information. Anonymisation on the other hand, results from processing personal data in order to irreversibly prevent identification. As such, anonymised personal data falls outside the scope of the GDPR, whereas pseudonymised data – including hashed data – does not.

Unlawful algorithms

Social media sites and search engines specialise in algorithms that allow them to target advertisements at users. However, the way those algorithms work makes all the difference and reveals an unintended consequence of the GDPR’s drafting.

Take the example of Bob. Bob decides to buy a new car by doing all of his research using an internet search engine. He then posts details of his new purchase on social media. The algorithms for Bob’s social media site correctly profile Bob as someone who is likely to buy car products or access car-related services in the future. Bob will therefore start to see targeted adverts on his social media page. Following his hours of online research for a new car, the algorithms used by his chosen search engine reach the same conclusion and Bob will also start to see some of those same adverts each time he goes online. While the resulting adverts Bob receives may be the same, the way the algorithms achieve this result is very different.

Social media algorithms target adverts by knowing who you are, whereas search engines target adverts by knowing what you are searching for. The who versus what dichotomy is therefore critical under the GDPR. Social media sites know which adverts to show Bob because they analyse his profile and hold personal data about him. The algorithms for most search engines, on the other hand, look only at what Bob searched for. The only data those engines need to target their advertising to Bob is to know that somebody in a particular geographic area used the search term “new car.” The engines have no idea that it was Bob searching for a new car, just that someone did. Search engines can therefore ignore personal data and still achieve the same algorithmic precision, social media sites cannot.

Should Bob be required to give his consent to this use of his data before it is used in this way? Under the GDPR, arguably yes, but only for the way the social media site uses his data. Bob has no ability to stop his chosen search engine using the data it holds because that data is not considered “personal data.”

Artificial intelligence

Artificial intelligence relies on machine learning, but for machines to learn, they need to crunch data, and lots of it. The GDPR makes it more difficult for those machines to get the data in the first place and once they have the data, rights granted to data subjects under the GDPR could also make it difficult for companies to reap the full benefits of machine learning.

The volume of data available for machine learning is not a problem, but under the GDPR, using that data lawfully often will be. This is because those developing machine learning will often be data processors rather than data controllers. Data processors are not permitted to decide for themselves how personal data is used, they can only use the data as directed to do so by the data controller and with the consent of the data subject.

Assuming consent is obtained and the machines learn from the data they consume, the output those machines then generate may also be restricted by the GDPR. This is because data subjects have a right under the GDPR not to be subject to a decision based solely on automated processing if that decision significantly affects the data subject. In other words, much of the ability to allow machines to make automated decisions will be linked to how those decisions affect our lives. Automated decisions about our shopping habits will probably be fine but automated decisions which determine a career promotion or mortgage application are likely to be challenged in the future.

Conclusion

With the GDPR now in force, not only is the long arm of EU data protection law reaching beyond the EU’s borders, potentially it is also impacting our use of new technologies.

Technology will not stop to adjust to the new laws, which means legal frameworks like the GDPR need to remain flexible enough to strike a balance between technological progress and the protection of individual privacy.

Share
More publications
Website-Code-Cayman-2
30 Jul 2026

Contingent Creditors, Standing And The Winding Up Jurisdiction: Analysing Re Petrosaudi International

The Cayman Islands Court of Appeal has delivered a highly significant judgment in Re PetroSaudi International.[1] The Court clarified the circumstances in which an alleged contingent creditor will have standing to petition to wind up a company under section 94(1)(b) of the Companies Act, and confirmed that there is no jurisdiction to make a winding up order on an ex parte without notice basis.[2] Our article analyses the Court of Appeal’s decision, and considers its implications for insolvency practitioners.

Website-Code-Cayman-1
30 Jul 2026

Final Means Final: Wei v Wang and the Common Law Enforcement of Foreign Judgments in the Cayman Islands

English Court Reaffirms Pro-Enforcement Approach to Foreign Judgments In Wei v Wang [2026] EWHC 1892 (Comm), the Court confirmed that exceptional avenues of review do not undermine the finality of a judgment and reiterated the limited scope of the natural justice defence.

JPLs, Directors and Arbitration: Grand Court Clarifies the Scope of Provisional Liquidators' Powers
28 Jul 2026

Drelle Overturned in Latest UK Supreme Court Decision

The United Kingdom Supreme Court in its recent decision in Drelle v Servis-Terminal LLC [2026] UKSC 29 (Drelle SC) has overturned the controversial decision of the English Court of Appeal in Servis-Terminal LLC v Drelle [2025] EWCA Civ 62 (Drelle CA), and in doing so has provided welcome clarity on the effect of unrecognised foreign judgments in cross-border bankruptcy and insolvency contexts. This is likely to have a wide-reaching impact – not only in the UK but also offshore – and particularly in the British Virgin Islands following the recent decision in JJW Hotels & Resorts Holding Inc v Rhodes (BVIHCM2025/0296) (JJW Hotels) (which relied heavily on Drelle CA), and in the Cayman Islands where previous authorities had recognised the ability, in the corporate context, for petitioners to present winding up petitions on the basis of an unrecognised foreign judgment.

JPLs, Directors and Arbitration: Grand Court Clarifies the Scope of Provisional Liquidators' Powers
24 Jul 2026

Thalassa Investments LP: Section 22 and Specific Discovery - Strategic Considerations for Limited Partners Seeking Information and Documents

In Thalassa Investments LP [2026] CIGC (FSD) 32, the Grand Court refused an application by limited partner petitioners for specific discovery from the general partner in just and equitable proceedings to wind up a Cayman Islands ELP. The ruling was against the backdrop of serious lack of probity allegations made against the general partner by the petitioners. Notwithstanding those allegations, the Grand Court declined to make orders requiring discovery of various categories of documents to be used at trial.   The ruling brings into focus the multiple routes potentially open to limited partners seeking information and/or documents from an ELP where there are allegations of mismanagement by the general partner. The limited partner may issue substantive proceedings (or, as in this case, present a just and equitable winding up petition) against the general partner and partnership, and then obtain documents through the usual discovery process. Alternatively, the limited partner may pursue its substantive right to true and full information under section 22 of the Exempted Limited Partnership Act first in order to help inform the bringing of a substantive claim, as was the approach in the Neoma (Abraaj) and the Port Fund litigation. Thalassa illustrates that the nature of the information sought, who holds it, and the legal basis on which disclosure is sought are all highly relevant to the outcome. The decision also highlights that section 22 and discovery serve different purposes, are governed by different legal tests and can produce different outcomes. The strategic question is not whether section 22 or the discovery process may be preferable in the abstract, but which legal framework best aligns with the limited partner’s objectives and the nature of the information sought.

Appleby-Website-Banking-and-Asset-Finance
13 Jul 2026

Guide to Loans & Secured Financing in the Cayman Islands 2026

This guide provides local insights into the legal and regulatory framework governing bank lending and finance. It covers key topics including bank loans versus debt securities, common forms of bank loan facilities, bridge financing, the roles of agents, trustees and lenders, and governing laws. It also examines the regulatory landscape, including capital, liquidity and disclosure requirements, the use of loan proceeds, cross-border lending, and interest rate and currency restrictions. In addition, the guide explores security interests and guarantees, the impact of fraudulent conveyance and similar doctrines on bank loan financing structures, intercreditor arrangements, loan terms and structures, and recent market developments.

Appleby-Website-Insolvency-and-Restructuring
9 Jul 2026

A Warning to Litigants Seeking Funding: English High Court Clarifies the Limits of Litigation Privilege

Important for Cayman litigants, funders and attorneys given the growing use of third-party funding in disputes.

Appleby-Website-Fraud-and-Asset-Tracing
8 Jul 2026

A Cautionary Tale in Interim Injunctive Relief: Lessons from Dixon v Seymour

In a recent judgment of Chief Justice Ramsay-Hale, the Cayman Grand Court provided guidance on the necessary components of an application for interim injunctive relief. The ruling illustrates how an ex parte application may fail to satisfy the American Cyanamid test when unsupported by proper evidence.

Appleby-Website-Regulatory-Practice
7 Jul 2026

CIMA’s 2026 Reinsurance Thematic Review: Focus Points for Boards

The Cayman Islands Monetary Authority (CIMA) has published its 2026 Thematic Review of Reinsurance Companies (Thematic Review). This reflects fieldwork conducted by CIMA between mid-2025 and Q1 2026 at selected Class B(iii) and Class D licensed reinsurers. The focus being on compliance with the Insurance Act (as revised) and other applicable legislation, regulations, rules and statements of guidance as issued by CIMA centering around stress-testing, cash flow testing frameworks, capital and collateral adequacy management, and corporate governance. Corporate governance weaknesses account for 68% of all findings with the remaining 32% spread across stress-testing, cash flow testing capital and collateral adequacy. Notwithstanding these findings, CIMA has noted several good practices across all areas including, importantly, comprehensive risk management frameworks covering key risk areas and strong capital and collateral adequacy monitoring processes. With Cayman’s reinsurance sector having grown to an institutional scale, and over 110 licensed reinsurers writing in the order of US$30 billion in annual premiums against over US$100 billion in assets, this latest Thematic Review demonstrates development in CIMA’s supervisory expectations of Cayman’s licensed reinsurers. It represents a reflection of the jurisdiction’s increasingly sophisticated and maturing reinsurance market and reinforces that CIMA’s expectations align closely with the standards that onshore counterparty cedants, rating agencies and US state regulators already expect. We take this opportunity to review certain of the key findings alongside CIMA’s cross-sectoral 2026 Thematic Review on Outsourcing, note some of the good practices highlighted by CIMA and make some associated recommendations for Cayman reinsurers.

Appleby-Website-Regulatory-Practice
25 Jun 2026

CIMA Enforcement Action in Focus: Reminders and Recommendations

The Cayman Islands Monetary Authority (CIMA) has recently published a number of Enforcement Notices that provide helpful context for regulated entities, including Licensees and Registered Persons under the Securities Investment Business Act (Revised) (SIBA), seeking to understand and meet their ongoing regulatory obligations in the Cayman Islands. In early June 2026, CIMA exercised its enforcement powers under SIBA Section 17 to cancel the registrations of several SIBA Registered Persons on the basis that it had reasonable grounds to believe that such Registered Persons had failed to meet certain key regulatory obligations. The Appleby Team takes this opportunity to review the relevant findings and CIMA enforcement action; and to highlight certain key obligations that attach to regulated entities in the Cayman Islands.