Data Protection Regulations as Disinformation Resilience
摘要
The regulation of personal data serves a dual purpose. While intended to protect personal privacy, it also constrains a bad actor’s ability to access the core resource required for online disinformation campaigns: personal data. This chapter discusses the origins of online disinformation campaigns, tracing their development through marketing and advertising methods to their reliance on social media with its tendency to facilitate disinformation and its dissemination. Taking the general data protection regulations (GDPR) as a point of departure and referring to real-world examples, the chapter posits that data protection regulations constrain the scope and intensity of disinformation by implanting constraints into the processes of private enterprises. The characteristics of GDPR and similar data protection regulations are considered from the perspective of the checks that they impose on the exploitation of personal data and the chapter maintains that together such checks constitute a key aspect of a state’s resilience to disinformation. As such, the chapter concludes that in addition to their personal privacy purpose, data protection regulations also carry strategic implications that ought to be given specific consideration in questions of doctrine and policy.