adopt a systematic approach to the regulation of data protection, consisting of
legislation that comprises most, if not all, aspects of this topic, including data
collection and treatment both by public and private entities: such is clearly the vision
underlying the GDPR. The United States instead favors a more topical approach,
which restricts data protection laws to specific aspects, notably the collection and
treatment of personal data by public agencies, and leaves broad areas of potential
conflict between data subjects and data controllers or processors to case law or selfregulation.
As for the second trend, it has also known different expressions: while a number
of countries, notably in Europe, has indeed enshrined a new fundamental right to
personal data protection, or at least derived it from other constitutionally recognized
rights, and certain international instruments have even elevated it to the status of a
human right, other countries, such as the U.S., where privacy is still essentially
regarded as the “right to be left alone”, have not taken this step.
Likewise, the third trend has experienced different degrees of accomplishment:
whilst at the worldwide level data protection rules have so far been restricted to a
limited number of highly general and abstract principles, such as quality of data,
exclusion of processing of sensitive data, data security and right of access by the data
subject, in the European Union a much more intense and detailed harmonization has
taken place, the enforcement of which is ensured through the applicability of
administrative fines to their infringement. As noted by the special rapporteur on
United Nations Law, “a single international data privacy regulatory framework is
yet to be seen”.
28
2.2 The Notion of Personal Data
The second issue to be addressed in this report concerns the notion of personal data.
In the European Union, a very broad notion of personal data has been adopted,
most recently in article 4(1) of the GDPR, which comprises:
Any information relating to an identified or identifiable natural person (data subject).
Personal data concerning legal persons are, accordingly, not included in the
notion of personal data relevant for the purposes of the said Regulation.
An identifiable natural person is, for the purposes of the abovementioned provision, “one who can be identified, directly or indirectly, in particular by reference to
an identifier such as a name, an identification number, location data, an online
identifier or to one or more factors specific to the physical, physiological, genetic,
mental, economic, cultural or social identity of that natural person”.
28 See the United Nations Special Report, Sect. 1.1.
Data Protection in the Internet: General Report
7
Précédent

- 16/540

Suivant