The abovementioned phenomena have not remained ignored from a legal point of
view: both at the national, supranational and international levels, an increasing
number of regulatory instruments—among which the European Union’s General
Data Protection Regulation applicable as of 25 May 2018
1
—have been adopted with
the purpose of preventing and sanctioning personal data misuse.
Nevertheless, distinct national approaches still prevail in this domain, notably
those that separate the highly comprehensive, detailed and protective rules adopted
in Europe since the 1995 Directive on the protection of individuals with regard to the
processing of personal data was enacted
2 from the more fragmented and liberal
attitude of American courts and legislators in this respect.
In a globalized world, in which personal data can instantly circulate and be used
simultaneously in communications networks that are ubiquitous by nature, these
different national and regional approaches are a major source of conflicts of laws.
These, in turn, are also the object of divergent solutions, ranging from the application
of data protection rules on a purely territorial basis to extra-territorial choice of law
regimes, according to which data protection laws may also apply to the processing of
personal data undertaken by entities established outside the jurisdiction of the data
subject’s place of habitual residence.
Ultimately, those different approaches may lead to judicial or administrative
decisions preventing the transfer of personal data to third countries that do not
provide a degree of protection deemed equivalent to that of the forum State, as has
recently occurred in the European Union.
3 The main purpose of this report is to
identify and explain these different national approaches and to determine the extent
to which they may be overcome or harmonized in the near future.
A number of national and special reports, drafted in response to a questionnaire
prepared by the authors of this general report, have been instrumental for this
purpose. Those reports provide a wealth of information regarding the legal systems
of fifteen jurisdictions from four continents, as well as those of the European Union,
the United Nations and of International Trade Law.
4
1 See Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on
the protection of natural persons with regard to the processing of personal data and on the free
movement of such data, OJ L 119, 4.5.2016, pp. 1 ff.
2 See Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the
protection of individuals with regard to the processing of personal data and on the free movement of
such data, OJ L 281, 23.11.1995, pp. 31 ff.
3 See the judgment of the CJEU of 6 October 2015, C-362/14, Schrems v. Data Protection
Commissioner, ECLI:EU:C:2015:650.
4 The abovementioned reports will be cited hereafter in an abbreviated manner, according to their
denominations in the appended list.
2
D. Moura Vicente and S. de Vasconcelos Casimiro
view: both at the national, supranational and international levels, an increasing
number of regulatory instruments—among which the European Union’s General
Data Protection Regulation applicable as of 25 May 2018
1
—have been adopted with
the purpose of preventing and sanctioning personal data misuse.
Nevertheless, distinct national approaches still prevail in this domain, notably
those that separate the highly comprehensive, detailed and protective rules adopted
in Europe since the 1995 Directive on the protection of individuals with regard to the
processing of personal data was enacted
2 from the more fragmented and liberal
attitude of American courts and legislators in this respect.
In a globalized world, in which personal data can instantly circulate and be used
simultaneously in communications networks that are ubiquitous by nature, these
different national and regional approaches are a major source of conflicts of laws.
These, in turn, are also the object of divergent solutions, ranging from the application
of data protection rules on a purely territorial basis to extra-territorial choice of law
regimes, according to which data protection laws may also apply to the processing of
personal data undertaken by entities established outside the jurisdiction of the data
subject’s place of habitual residence.
Ultimately, those different approaches may lead to judicial or administrative
decisions preventing the transfer of personal data to third countries that do not
provide a degree of protection deemed equivalent to that of the forum State, as has
recently occurred in the European Union.
3 The main purpose of this report is to
identify and explain these different national approaches and to determine the extent
to which they may be overcome or harmonized in the near future.
A number of national and special reports, drafted in response to a questionnaire
prepared by the authors of this general report, have been instrumental for this
purpose. Those reports provide a wealth of information regarding the legal systems
of fifteen jurisdictions from four continents, as well as those of the European Union,
the United Nations and of International Trade Law.
4
1 See Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on
the protection of natural persons with regard to the processing of personal data and on the free
movement of such data, OJ L 119, 4.5.2016, pp. 1 ff.
2 See Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the
protection of individuals with regard to the processing of personal data and on the free movement of
such data, OJ L 281, 23.11.1995, pp. 31 ff.
3 See the judgment of the CJEU of 6 October 2015, C-362/14, Schrems v. Data Protection
Commissioner, ECLI:EU:C:2015:650.
4 The abovementioned reports will be cited hereafter in an abbreviated manner, according to their
denominations in the appended list.
2
D. Moura Vicente and S. de Vasconcelos Casimiro
