Article navigation
Purpose

The purpose of this paper is to outline the risks and issues libraries face when using a next-generation library services platform (LSP) from the perspective of current data protection requirements. By examining the specific legal obligations in the context of LSP, approaches will be considered to achieve compliance and ways of ensuring patrons’ data protection rights.

Design/methodology/approach

The methods authors applied in this research observe standard legal research methodology, including analysis of legal practice and comparative legal analysis methods to identify key normative elements of library management system (LMS) or LSP compliance with applicable EU data protection requirements. A systematic overview of personal data processing activities usually performed by library services platforms is given with an overview of risks and possible applicable technical or organizational protection measures.

Findings

To ensure the rights of library patrons, an LSP needs to meet a number of data protection requirements: provide tools and techniques to provide the patron with insight into his personal data, enable the patron to independently edit their own data in the online interface of the LSP, enable the control of unauthorized access, enable the anonymization of data about the patron and his activities for the purpose of creating statistical reports, enable the library to define mandatory and optional data collected about the patron, provide a function for deleting patron data and/or patron records after a certain period of time. There are also obligations for libraries, like contractual obligations with vendors, privacy by design and by default and data protection impact assesment.

Practical implications

Since libraries as data controllers are required to ensure that personal data collected through these platforms is processed in strict accordance with General Data Protection Regulation (GDPR) principles, the research results can be practically applied to adapt the library service platform or to evaluate options when procuring a new platform.

Originality/value

The research contributes to understanding the implementation of specific technical and organizational measures for the protection of library patrons’ personal data processed within library services platforms, including the exercise of data subjects’ rights and privacy by design and by default.

Licensed re-use rights only
You do not currently have access to this content.
Don't already have an account? Register

Purchased this content as a guest? Enter your email address to restore access.

Pay-Per-View Access
$39.00
Rental

or Create an Account

Close Modal
Close Modal