(as of September 2025)
, Origins and Historical Context of European Data Protection Laws
❖ Data Protection Laws
➢ Universal Declaration of Human Rights (1948)
▪ Not legally binding
▪ Principles enshrined provided the basis for subsequent data
protection laws and standards
▪ Relevant articles
• Article 12: no arbitrary interference with privacy, family, home
or correspondence
• Article 19: right to freedom of opinion and expression
• Article 29: individual rights are not absolute and balance must
be struck
➢ European Convention on Human Rights (1950)
▪ International treaty that applies to member states of Council of
Europe
▪ Enforced by the European Court of Human Rights
▪ Relevant articles
• Article 8: right to respect for private and family life, home and
correspondence
• Article 10: right to freedom of expression and to share
information and ideas across national boundaries
• Article 10(2): qualifies Article 10 with Article 8
➢ Sweden introduced the first national data protection laws (1973)
➢ OECD1 Guidelines (1980)
▪ Aim: protection of privacy; transborder flow of personal data;
facilitate harmonisation of data protection law between countries
▪ Not legally binding
▪ No distinction between public and private sector
▪ Technology neutral (no distinction for personal data gathered
electronically or otherwise)
▪ Principles
• Collection limitation: collection must be fair and lawful, with
knowledge and consent where appropriate
• Data quality: data must be relevant, complete, accurate and
updated
• Purpose specification: purpose must be specified not later
than at the time of data collection
• Use limitation: use must be consistent with specified purpose
• Security safeguards: reasonable security safeguard against
loss or unauthorised access, destruction, use, modification,
or disclosure
• Openness: general policy regarding uses and the identity and
location of the controller
1 Organisation for Economic Co-operation and Development
1
, • Individual participation: right to access and challenge
accuracy of data
• Accountability: controller should be accountable
➢ The Convention for the Protection of Individuals with regard to
Automatic Processing of Personal Data (Convention 108) (1981)
▪ First legally binding international instrument
▪ Open for signatures outside of Europe
▪ Purpose: to achieve greater unity between the signatory states and
extend safeguards for individuals’ rights and freedom
• Requires signatories to apply the principles in domestic law
• Only a small number of states ratified and took fragmented
approaches to their national data protection laws
▪ Three main parts
• Substantive law provisions (basic principles)
• Rules on transborder data flow
Article 12: where transfers are made between
signatories, the countries shall not impose any
prohibitions or require special authorisations for the
purpose of the protection of privacy before such
transfers can take place.
Additional Protocol introduced concept of “adequate”
protection for transfer of personal information to non-
signatories
• Mechanisms for mutual assistance and consultation between
the parties
➢ Directive 95/46/EC (The Data Protection Directive)
▪ Aim: free movement of personal data and consistent provisions to
ensure the protection of privacy
▪ Set out general principles and left the member states to implement
them (lead to divergence)
▪ Applied to controllers established in an EU member state or where
the organisation used data processing equipment on a member
states territory (in which case, a representative shall be designated)
▪ Provisions
• Key principles: fair and lawful processing; specified and
legitimate purpose; adequate, relevant and not excessive;
accuracy; technical and organisational measures to prevent
unauthorised access; transfer to third countries in case of
adequate protection
• Special categories of data
• Establishment of Data Protection Authorities
▪ Unlike the Council of Europe, the EU is unable to make standalone
human rights laws; must base its laws on a specific provision under
the Treaty of Rome
▪ Repealed by GDPR (however, where processed based on consent
pursuant to directive – not necessary to give consent again if
consent was given in line with conditions of GDPR)
2
, ➢ Madrid Resolution (2009)
▪ Resolution by the International Conference of Data Protection and
Privacy Commissioners
▪ Proposes international standards on the protection of privacy with
regard to the processing of personal data
➢ GDPR (2016)
▪ Entered into force in May 2016; fully enforceable by 25 May 2018
▪ Govern data controllers and processors
▪ The GDPR is binding directly, but member states may make further
legislative provisions for clarifications or exceptions:-
• Where sector-specific laws already in place
• Archiving purposes in the public interest, scientific or
historical research purposes or statistical purposes
• Processing of special categories of personal data
• Processing in compliance with legal obligation
▪ Introduces new right to data portability
▪ GDPR is incorporated into the European Economic Area2 through
agreement followed by required regulations on the national level.
As a result, the GDPR applies in Norway, Leichtenstein and
Iceland3, and no adequacy decision is needed
▪ Brexit: provisions of GDPR incorporated directly into UK law as UK
GDPR
➢ Convention 108+ (2018)
▪ Increase standard of protection and update in light of emergent
regulatory framework like the GDPR
❖ Other data related legislations
➢ Directive 2000/31/EC (E-commerce Directive)
▪ Scope: information society services; cross-border services
▪ Key Provisions
• Service providers are regulated primarily by the laws of the
EU country in which they are established; member states may
not impose additional requirements on foreign providers
• Providers must clearly display details like their name, contact
information, registration number, and trade licenses.
• Promotional materials must be identifiable as advertising.
• Limits liability for intermediary service providers
• Prohibition of general monitoring obligations
➢ Directive 2002/58/EC (ePrivacy Directive)
▪ Applies to the processing of personal data in connection with the
provision of publicly available electronic communications services
in public communications networks in the EU.
▪ Provisions
• Providers of publicly available electronic communications
services must take appropriate technical and organisational
measures to safeguard the security of their services
2 Decision No. 154/2018
3 The European Economic Area includes EU countries plus Iceland, Liechtenstein and Norway
3