digital | recht – Volume 33 (Civil Law) • Janina Rochon
The thesis addresses unresolved questions around PIMS, focusing on who is controller, processor, joint controller, or third party under the GDPR. Despite European Data Protection Supervisor noting the need for clarity, neither scholarship nor practice provides a unified approach. Part I defines PIMS and reviews services’ effectiveness for user rights. Part II maps service types to GDPR roles, finding inconsistent assignments that risk individuals’ rights. Part III proposes a narrower PIMS definition an looks at alternative liability models beyond the GDPR. Finally, an expansion of the stage-based approach, established by Fashion ID is suggested, based on which a chain of activities serving one overall purpose and appearing as one consolidated action to the data subject should be considered as one processing activity, where this is in line with the effet utile of the Regulation.
This book is only available in English



