A “light touch” regime, which establishes a minimum data protection standard,
has been adopted in Singapore.
22 Other countries, such as South Africa, are still in
the process of adopting general data protection legislation.
23
Data protection rules, contained in the abovementioned legislative instruments,
mostly have a mixed nature, covering both Public and Private Law issues. In fact, as
noted earlier, a fundamental right to data protection has been enshrined in several
countries, which enjoys the corresponding constitutional status. The enforcement of
that right, and the overall supervision of the application of data protection rules, is
entrusted not only to judicial, but also to administrative authorities; as a consequence
thereof, a considerable number of Administrative Law rules on this topic have
emerged. Liability for the breach of data protection rules, however, is to a large
extent still governed by Tort Law rules. And the territorial scope of application of
data protection rules is a matter essentially pertaining to the realm of Private
International Law.
At the international level, a number of relevant multilateral initiatives aiming at
the protection of personal data have also been undertaken by several organizations,
among which the Council of Europe,
24 the United Nations,
25 and the OECD.
26 The
subject is also addressed in several bilateral trade agreements.
27
The most accomplished international instrument providing for a right to personal
data protection is, however, the Charter of Fundamental Rights of the European
Union, Article 8 of which provides, under the heading “protection of personal data”,
that:
(1) Everyone has the right to the protection of personal data concerning him or her.
(2) Such data must be processed fairly for specified purposes and on the basis of the consent
of the person concerned or some other legitimate basis laid down by law. Everyone has
the right of access to data which has been collected concerning him or her, and the right
to have it rectified.
(3) Compliance with these rules shall be subject to control by an independent authority.
Three major trends can be inferred from the existing data protection legal
framework, as described above: (1) the trend to adopt specialized legislation covering several areas of the law; (2) the trend to constitutionalize rules on data protection;
and (3) the trend to internationally harmonize its regime.
The first of these trends has, however, different expressions across the world. In
fact, European legal systems, as well as those more closely influenced by them,
22 See the Singaporean National Report, Sect. 1.
23 See the South African National Report, Sect. 2.
24 See the Convention for the Protection of Individuals with regard to Automatic Processing of
Personal Data, adopted in Strasbourg, on 28 January 1981.
25 See Guidelines for the Regulation of Computerized Personal Data Files, adopted by the Resolution of the General Assembly 45/95 of 14 December 1990; and the Policy on the Protection of
Personal Data of Persons of Concern to UNHCR, of 27 November 2015.
26 See OECD Privacy Guidelines (revised in 2013).
27 See the International Trade Law Special Report.
6
D. Moura Vicente and S. de Vasconcelos Casimiro
Précédent

- 15/540

Suivant