In Europe, the GDPR also encourages the drawing up of codes of conduct by
associations and other bodies representing categories of controllers or processors and
intended to contribute to the proper application of the Regulation, which take
account of the specific features of the various processing sectors and the specific
needs of micro, small and medium-sized enterprises. However, such codes are
subject to approval by national supervising authorities, which must assess whether
they provide sufficient appropriate safeguards and, in the affirmative case, shall also
register and publish them. Compliance with approved codes of conduct is to be
monitored by independent bodies with an appropriate level of expertise in relation to
the subject-matter of the code and accredited for that purpose by the competent
supervisory authority.
46 Self-regulation by data controllers or processors is thus
much more strictly allowed and controlled in the EU than in the
U.S. Unsurprisingly, self-regulation instruments are considerably less developed in
Europe than in the U.S.
47
In some non-European countries, supervising authorities have taken upon themselves the task of issuing guidelines or codes of conduct concerning personal data
protection: such is the case, e.g., of Singapore,
48 and of South Africa.
49 Whether
binding or not, and even when issued in consultation with the industry, such
instruments do not seem to qualify as self-regulation initiatives. Other
non-European countries simply lack any self-regulation instruments in this area:
thus far, that’s, for example, the case of Brazil
50 and Cape Verde.
51
3 Specific Problems Concerning Data Protection
in the Internet
3.1 Personal Data Processed by Electronic Means
Personal data protection or, as it is more commonly referred to in Anglo-Saxon
countries, data privacy, has become an increasingly central topic in the last two or
three decades due to the rapid development of information processing technologies.
These technologies, which are closely related to the so-called Information Society, are essentially aimed at optimizing information, making it available through
electronic means where and when it is necessary. The term “information” is used in
this context in a very broad sense, and comprises all types of data, independently
from its purposes, forms, contents or other criteria.
46 See the European Union Special Report, Sect. 2.6.
47 See, for instance the French National Report, Sect. 5.
48 See the Singaporean National Report, Sect. 2.4.
49 See the South African National Report, Sect. 3.3.
50 See the Brazilian National Report, Sects. 1–5.
51 See the Cape-Verdean National Report, Sect. 2.4.
Data Protection in the Internet: General Report
11
Précédent

- 20/540

Suivant