Insights on Data Sensitivity from the Technical, Legal and the Users’ Perspectives

Eva-Maria Schomakers, Chantal Lidynia, Dirk Müllmann, Roman Matzutt, Klaus Wehrle, Indra Spiecker gen. Döhmann, Martina Ziefle

Social media, cloud computing, and the Internet of Things connect people around the globe, offering manifold benefits. However, the technological advances and increased user participation generate novel challenges for users’ privacy. From the users’ perspective, the consequences of data disclosure depend on the perceived sensitivity of that data. But in light of the new technological opportunities to process and combine data, it is questionable whether users can adequately evaluate risks of data disclosures. As mediating authority, data protection laws such as the European General Data Protection Regulation try to protect user data, granting enhanced protection to “special categories” of data. This article assesses the legal, technological, and users’ perspectives on information sensitivity and their interplay. Technologically, all data can be referred to as “potentially sensitive.” The legal and users’ perspective on information sensitivity deviate from this standpoint, as some data types are granted special protection by law but are not perceived as very sensitive by users and vice versa. The key findings here suggest the GDPR adequately protecting users’ privacy but for small adjustments.