Data Protection Directive

Data Protection Directive

The Data Protection Directive (officially Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data) is a European Union directive which regulates the processing of personal data within the European Union. It is an important component of EU privacy and human rights law.



The right to privacy is a highly developed area of law in Europe. All the member states of the European Union (EU) are also signatories of the European Convention on Human Rights (ECHR). Article 8 of the ECHR provides a right to respect for one's "private and family life, his home and his correspondence," subject to certain restrictions. The European Court of Human Rights has given this article a very broad interpretation in its jurisprudence.

In 1980, in an effort to create a comprehensive data protection system throughout Europe, the Organization for Economic Cooperation and Development (OECD) issued its “Recommendations of the Council Concerning Guidelines Governing the Protection of Privacy and Trans-Border Flows of Personal Data.”[1] The seven principles governing the OECD’s recommendations for protection of personal data were:

  1. Notice—data subjects should be given notice when their data is being collected;
  2. Purpose—data should only be used for the purpose stated and not for any other purposes;
  3. Consent—data should not be disclosed without the data subject’s consent;
  4. Security—collected data should be kept secure from any potential abuses;
  5. Disclosure—data subjects should be informed as to who is collecting their data;
  6. Access—data subjects should be allowed to access their data and make corrections to any inaccurate data; and
  7. Accountability—data subjects should have a method available to them to hold data collectors accountable for following the above principles.[2]

The OECD Guidelines, however, were nonbinding, and data privacy laws still varied widely across Europe. The US, meanwhile, while endorsing the OECD’s recommendations, did nothing to implement them within the United States.[3] However, all seven principles were incorporated into the EU Directive.[4]

In 1981 the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data was negotiated within the Council of Europe. This convention obliges the signatories to enact legislation concerning the automatic processing of personal data, which many duly did.

The European Commission realised that diverging data protection legislation amongst EU member states impeded the free flow of data within the EU and accordingly proposed the Data Protection Directive.


The directive regulates the processing of personal data regardless of whether such processing is automated or not.


Personal data are defined as "any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;" (art. 2 a)

This definition is meant to be very broad. Data are "personal data" when someone is able to link the information to a person, even if the person holding the data cannot make this link. Some examples of "personal data" are: address, credit card number, bank statements, criminal record, etc.

The notion processing means "any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction;" (art. 2 b)

The responsibility for compliance rests on the shoulders of the "controller", meaning the natural or artificial person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data; (art. 2 d)

The data protection rules are applicable not only when the controller is established within the EU, but whenever the controller uses equipment situated within the EU in order to process data. (art. 4) Controllers from outside the EU, processing data in the EU, will have to follow data protection regulation. In principle, any online business trading with EU citizens would process some personal data and would be using equipment in the EU to process the data (i.e. the customer's computer). As a consequence, the website operator would have to comply with the European data protection rules. The directive was written before the breakthrough of the Internet, and to date there is little jurisprudence on this subject.


Personal data should not be processed at all, except when certain conditions are met. These conditions fall into three categories: transparency, legitimate purpose and proportionality.


The data subject has the right to be informed when his personal data is being processed. The controller must provide his name and address, the purpose of processing, the recipients of the data and all other information required to ensure the processing is fair. (art. 10 and 11)

Data may be processed only under the following circumstances (art. 7):

  • when the data subject has given his consent
  • when the processing is necessary for the performance of or the entering into a contract
  • when processing is necessary for compliance with a legal obligation
  • when processing is necessary in order to protect the vital interests of the data subject
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller or in a third party to whom the data are disclosed
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by the third party or parties to whom the data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subject. The data subject has the right to access all data processed about him. The data subject even has the right to demand the rectification, deletion or blocking of data that is incomplete, inaccurate or isn't being processed in compliance with the data protection rules. (art. 12)

Legitimate purpose

Personal data can only be processed for specified explicit and legitimate purposes and may not be processed further in a way incompatible with those purposes. (art. 6 b)


Personal data may be processed only insofar as it is adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed. The data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified; The data shouldn't be kept in a form which permits identification of data subjects for longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use. (art. 6)

When sensitive personal data (can be: religious beliefs, political opinions, health, sexual orientation, race, membership of past organisations) are being processed, extra restrictions apply. (art. 8)

The data subject may object at any time to the processing of personal data for the purpose of direct marketing. (art. 14)

A decision which produces legal effects or significantly affects the data subject may not be based solely on automated processing of data. (art. 15) A form of appeal should be provided when automatic decision making processes are used.

Supervisory authority and the public register of processing operations

Each member state must set up a supervisory authority, an independent body that will monitor the data protection level in that member state, give advice to the government about administrative measures and regulations, and start legal proceedings when data protection regulation has been violated. (art. 28) Individuals may lodge complaints about violations to the supervisory authority or in a court of law.

The controller must notify the supervisory authority before he starts to process data. The notification contains at least the following information (art. 19):

  • the name and address of the controller and of his representative, if any;
  • the purpose or purposes of the processing;
  • a description of the category or categories of data subject and of the data or categories of data relating to them;
  • the recipients or categories of recipient to whom the data might be disclosed;
  • proposed transfers of data to third countries;
  • a general description of the measures taken to ensure security of processing.

This information is kept in a public register.

Transfer of personal data to third countries

Third countries is the term used in EU legislation to designate countries outside the European Union. Personal data may only be transferred to third countries if that country provides an adequate level of protection. Some exceptions to this rule are provided, for instance when the controller himself can guarantee that the recipient will comply with the data protection rules.

The Directive's Article 29 created the "Working party on the Protection of Individuals with regard to the Processing of Personal Data," commonly known as the "Article 29 Working Party". The Working Party gives advice about the level of protection in the European Union and third countries.

The Working Party negotiated with U.S. representatives about the protection of personal data, the Safe Harbor Principles were the result. According to critics the Safe Harbor Principles do not provide for an adequate level of protection, because they contain fewer obligations for the controller and allow the contractual waiver of certain rights.

In July 2007, a new, controversial,[5] Passenger Name Record agreement between the US and the EU was undersigned.[6]

In February 2008, Jonathan Faull, the head of the EU's Commission of Home Affairs, complained about the US bilateral policy concerning PNR.[7] The US had signed in February 2008 a memorandum of understanding (MOU) with the Czech Republic in exchange of a visa waiver scheme, without first consulting Brussels.[5] The tensions between Washington and Brussels are mainly caused by the lower level of data protection in the US, especially since foreigners do not benefit from the US Privacy Act of 1974. Other countries approached for bilateral Memoranda of Understandings included the United Kingdom, Estonia, Germany and Greece.[8]

Implementation by the member states

EU directives are addressed to the member states, and aren't legally binding for citizens in principle. The member states must transpose the directive into internal law. Directive 95/46/EC on the protection of personal data had to be transposed by the end of 1998. All member states have enacted their own data protection legislation.

Comparison with US data protection law

The United States prefers what it calls a 'sectoral' approach to data protection legislation, which relies on a combination of legislation, regulation, and self-regulation, rather than governmental regulation alone.[9] Former U.S. President Bill Clinton and former Vice-President Al Gore explicitly recommended in their "Framework for Global Electronic Commerce" that the private sector should lead, and companies should implement self-regulation in reaction to issues brought on by Internet technology.[10] To date, the US has no single data protection law comparable to the EU's Data Protection Directive.[11] Privacy legislation in the United States tends to be adopted on an ad hoc basis, with legislation arising when certain sectors and circumstances require (e.g., the Video Privacy Protection Act of 1988, the Cable Television Protection and Competition Act of 1992,[12] the Fair Credit Reporting Act, and the 2010 Massachusetts Data Privacy Regulations). Therefore, while certain sectors may already satisfy the EU Directive, at least in part, most do not.[13]

The reasoning behind this approach probably has as much to do with American laissez-faire economics as with different social perspectives. The First Amendment of the United States Constitution guarantees the right to free speech.[14] While free speech is an explicit right guaranteed by the United States Constitution, privacy is an implicit right guaranteed by the Constitution as interpreted by the United States Supreme Court.[15]

Europeans are acutely familiar with the dangers associated with uncontrolled use of personal information from their experiences under World War II-era fascist governments and post-War Communist regimes, and are highly suspicious and fearful of unchecked use of personal information.[16] World War II and the post-War period was a time in Europe that disclosure of race or ethnicity led to secret denunciations and seizures that sent friends and neighbors to work camps and concentration camps.[4]In the age of computers, Europeans’ guardedness of secret government files has translated into a distrust of corporate databases, and governments in Europe took decided steps to protect personal information from abuses in the years following World War II.[17] Germany and France, in particular, set forth comprehensive data protection laws.[18]

See also


  1. ^ See The Organization for Economic Co-Operation and Development, Guidelines on the Protection of Privacy and Transborder Flows of Personal Data, available at,2340,en_2649_34255_1815186_1_1_1_1,00.html (last modified January 5, 1999)
  2. ^ Anna Shimanek, Note, Do you Want Milk with those Cookies?: Complying with Safe Harbor Privacy Principles, 26 Iowa J. Corp. L. 455, 462–463 (2001)
  3. ^ Id. at 463
  4. ^ a b Id.
  5. ^ a b A divided Europe wants to protect its personal data wanted by the US, Rue 89, 4 March 2008 (English)
  6. ^ See [1].
  7. ^ Brussels attacks new US security demands, EUobserver. See also Statewatch newsletter February 2008
  8. ^ Statewatch, March 2008
  9. ^ See William J. Clinton & Albert Gore, Jr., A Framework for Global Electronic Commerce, July 1, 1997, available at; See also Robert R. Schriver, You Cheated, You Lied: the Safe Harbor Agreement and Its Enforcement By the Federal Trade Commission, 70 Fordham L. Rev. 2777, 2779 (2002)
  10. ^ Clinton & Gore, supra
  11. ^ See Julia M. Fromholz, The European Union Data Privacy Directive, 15 Berkeley Tech. L.J. 471, 472 (2000); Dean William Harvey & Amy White, The Impact of Computer Security Regulation on American Companies, 8 Tex. Wesleyan L. Rev. 505 (2002); Kamaal Zaidi, Harmonizing U.S.-EU Online Privacy Law: Toward a U.S. Comprehensive Regime For the Protection of Personal Data, 12 Mich.St. J. Int’l L. 169 (2003).
  12. ^ Legislation, USA (1992). [ "CABLE TELEVISION CONSUMER PROTECTION AND COMPETITION ACT OF 1992"]. Retrieved 18 March 2010. 
  13. ^ Fromholz, supra
  14. ^ U.S. Const. amend. I
  15. ^ See, for example, Roe v. Wade, 410 U.S. 113 (1973)
  16. ^ See Ryan Moshell, ...And Then There was one: The Outlook for a Self-Regulatory United States Amidst a Global Trend Toward Comprehensive Data Protection, 37 Tex. Tech. L. Rev. 357, 358; See also The History of Place, Kristallnacht, available at & Jason Kotzker, The Great Cookie Caper: Internet Privacy and Target Marketing at Home and Abroad, 15 St. Thomas L. Rev. 727, 748 (2003)
  17. ^ See Marsha Cope Huie, Stephen F. Laribee & Stephen D. Hogan, The Right to Privacy and Person Data: The EU Prods the U.S. and Controversy Continues, 9 Tulsa J. Comp. & Int'l L. 391, 441 (2002)
  18. ^ Id. at footnote 4.

External links

Wikimedia Foundation. 2010.

Игры ⚽ Нужно сделать НИР?

Look at other dictionaries:

  • EU Data Protection Directive — USA, EU A directive adopted by the European Commission in 1995 that sets out the framework for data protection regulation in the European Union (EU) (Directive 95/46/EC). The directive regulates the processing (including the collection, use,… …   Law dictionary

  • Data Protection Act 1998 — The Data Protection Act 1998 is a United Kingdom Act of Parliament which defines UK law on the processing of data on identifiable living people. It is the main piece of legislation that governs the protection of personal data in the UK. Although… …   Wikipedia

  • Data Retention Directive — European Union directive: Directive 2006/24/EC Directive on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks Made by …   Wikipedia

  • Data Protection Act — The Data Protection Act (DPA) is a United Kingdom Act of Parliament. It defines a legal basis for the handling in the UK of information relating to living people. It is the main piece of legislation that governs protection of personal data in the …   Wikipedia

  • data protection — safeguards relating to the use and storage of personal information about a living person, which is legally covered in the UK by the Data Protection Act 1998 (which implements a European Directive, 95/46/EC). Under the Act individuals have a basic …   The new mediacal dictionary

  • Marketing and data protection legislation — Marketing and data protection Establishing, accessing, sharing and using personal data are essential to successful “direct marketing” practices. These are concerned with identifying and meeting people’s needs and preferences directly, ie through… …   Wikipedia

  • Directive du 12 juillet 2002 sur la protection de la vie privée dans le secteur des communications électroniques — Directive vie privée et communications électroniques Titre Directive du 12 juillet 2002 sur la protection de la vie privée dans le secteur des communications électroniques Abréviation Directive 2002/58/CE Code CELEX : 32002L0058 Organisation …   Wikipédia en Français

  • European Data Protection Supervisor — The European Data Protection Supervisor was set up under Article 286 of the Treaty establishing the European Communities within the context of harmonising data protection legislation in the European Union. While Directive 95/46/EC addresses… …   Wikipedia

  • Directive 95/46/CE sur la protection des données personnelles — Directive sur la protection des données personnelles Titre directive 95/46/CE du Parlement européen et du Conseil, du 24 octobre 1995, relative à la protection des personnes physiques à l égard du traitement des données à caractère personnel et à …   Wikipédia en Français

  • Danish Data Protection Agency — Following the implementation of EU Directive 95/46/EC, regarding the protection of individuals with regards to the process of personal information and the movement of such, the Danish Data Protection Agency was created. The agency exercises… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”