It has long been discussed whether individuals should have a "right to be forgotten" online to suppress old information that could seriously interfere with their privacy and data protection rights. In the landmark case of Google Spain v. Agencia Espafiola de Proteccion de Datos, the Court of Justice of the European Union (CJEU) addressed the particular question of whether, under EU Data Protection Law, individuals have a right to have links delisted from the list of search results in searches made on the basis of their name. It found that they do have this right--which can be best described as a "right to be delisted"--when some conditions are met. The ruling, which imposes on search engines the duty to assess and accommodate delisting requests, has proven to be highly controversial. Strong feelings have been expressed both in favor and against the ruling, in what may be seen as a clash between the values of personal data protection and freedom of expression. This Article does not delve into that underlying debate. Instead, it aims to explore the solidness of the ground on which the right is based. It begins by providing an overview of the relevant elements of EU data protection law so as to allow readers not familiar with its nuances to properly follow the discussion. After presenting the facts of Google Spain, both at national and EU level, this Article discusses how the "right to be delisted" was crafted by the CJEU. It then argues that the "right" is based on shaky ground, as it is premised on the characterization of search engines as "data controllers," which is arguably at odds with their intermediary role and--in the absence of specific safeguards--makes their activity largely incompatible with the data protection legal framework. Moreover, the Article discusses how the court failed to devise a proper balance of the different rights at stake, particularly that of freedom of expression and information. The Article further suggests that the intermediary role of generalist search engines should be adequately protected, both under the data protection legal framework as well as under the liability limitation scheme established by the E-Commerce Directive. This protection, however, is not likely to be achieved in the near future. A careful approach by national courts and data protection authorities is thus suggested as away to fix some of the shortcomings identified in the ruling.
The Shaky Ground of the Right to Be Delisted,
18 Vanderbilt Journal of Entertainment and Technology Law
Available at: https://scholarship.law.vanderbilt.edu/jetlaw/vol18/iss3/3