personal data is, however, a much more recent phenomenon, which is closely linked
to the technological developments (occurred mostly in the 1980s and 1990s) that
have made those operations possible on a large scale, namely the digitization of
information, the integration of the processing functions of computers onto low-cost
microprocessors and the advent of the Internet as a global network of computer
networks.
8
Since then, data protection statutes have experienced a dramatic increase in
number and scope, and have been extended to most countries. After the adoption
of Directive 95/46/EC, virtually all European Union Member States have enacted
legislation on this topic seeking to transpose that Directive or to adapt pre-existing
statutes to it.
9 That legislation has, in turn, had a considerable influence over the law
of other regions of the world.
10
The European tendency to enact comprehensive laws on data protection has been
further enhanced by the adoption in 2016 of the General Regulation on Data
Protection (hereafter GDPR), which has replaced the 1995 Directive and is directly
applicable in all EU Member States. It contains a detailed regime, which aims at
codifying the law in this field. Notwithstanding some relevant exclusions, the
Regulation covers all fundamental topics of data protection, notably: (1) the general
principles governing this matter; (2) the rights of the data subject; (3) the status of the
data controller and processor; (4) the transfer of personal data to third countries;
(5) the supervision authorities and their reciprocal cooperation; and (6) the applicable remedies, liabilities and penalties.
11
It is important to note, however, that the adoption of the GDPR has not excluded
the relevance of the significant body of case law emanating from the Court of Justice
of the European Union (hereafter CJEU) on the interpretation of the 1995 Directive,
nor the Guidelines adopted by the so-called Article 29 Data Protection Working
Party set up under that Directive (which will become the European Data Protection
Board under articles 68 et seq. of the GDPR).
12
The GDPR will be complemented by other European legal acts concerning the
protection of personal data, among which a Regulation concerning privacy in the
electronic communications sector.
13
8 See, for recent overviews of this matter, de Miguel Asensio (2015), pp 291 ff.; Hoeren (2018), pp
445 ff.
9 See, as examples thereof, the statutes cited in the German National Report, Sect. 1.1; the French
National Report, Sect. 1; the Greek National Report, Sect. 1.1; the Italian National Report, Sect. 1;
the Portuguese National Report, Sect. 1; the Romanian National Report, Sect. 2.1; and the Spanish
National Report, Sect. 1.1.
10 As was the case, e.g., of Cape Verde: see Cape Verdean National Report, Sects. 2 and 5.2.
11 See, for a comprehensive description of this Regulation, the European Union Special Report.
12 See ibidem, Sect. 1.1.
13 See the Proposal for a Regulation of the European Parliament and of the Council concerning the
respect for private life and the protection of personal data in electronic communications and
repealing Directive 2002/58/EC (Regulation on Privacy and Electronic Communications), COM
(2017) 10 final.
4
D. Moura Vicente and S. de Vasconcelos Casimiro
Précédent

- 13/540

Suivant