transactions, FACTA protects consumers from identity theft and ensures that consumers’ credit information is accurate. FACTA includes provisions on security of
card-related data and the ability to place fraud alerts. This Act grants consumers the
right to request and obtain a free credit report per year from the three main consumer
credit reporting companies in the United States. Notwithstanding the fact that
FACTA does protect personal data processed by electronic means, this Act is
designed to reduce credit fraud and improve confidence in online transactions. Its
rules are, thus, primarily aimed at protecting electronic commerce, rather than
personal data.
It is also relevant to highlight the fact that whenever regional trade agreements
contain provisions on electronic commerce, they frequently include personal data
protection rules.
73 Although these rules differ in their extent and effectiveness,
74
some of those agreements encourage the enactment of data protection rules by their
Member States. The fact that these may be required to adopt certain minimum data
protection rules in order to be able to conclude such trade agreements naturally
contributes to the expansion and enhancement of personal data protection and
encourages harmonization in this area.
As already mentioned, international organizations, such as the United Nations,
also play a significant role in setting common rules on personal data protection in the
context of services provided at a distance by electronic means.
75
3.1.2 Protection of Minors’ Personal Data Processed by Electronic
Means
In the European Union, the GDPR sets forth additional relevant rules for personal
data processing by electronic means, such as restrictions on profiling, which is
defined as a form of automated processing of personal data,
76 data breaches notification procedures, protection of minors in relation to information society services
and the right to be forgotten, among many others.
77
The protection of minors in relation to information society services is regulated
by specific provisions in several countries and, in some of them, such as the United
States, through specific laws.
In this respect, the GDPR’s main concern is to set special requirements regarding
a child’s consent in relation to information society services. Where personal data
processing is based on the consent given by the data subject, the GDPR has given
Member States the possibility to choose the age limit above which a child may give a
valid consent to operators of information society services, without the intervention of
73 See the Data Protection in International Trade Law Special Report, Sect. 8.1.
74 See the Data Protection in International Trade Law Special Report, Sects. 8.1 and 9.
75 See supra, Sect. 2.1, and the instruments mentioned therein.
76 See article 4(4) of the GDPR.
77 See the European Union Special Report, Sect. 2.
16
D. Moura Vicente and S. de Vasconcelos Casimiro
card-related data and the ability to place fraud alerts. This Act grants consumers the
right to request and obtain a free credit report per year from the three main consumer
credit reporting companies in the United States. Notwithstanding the fact that
FACTA does protect personal data processed by electronic means, this Act is
designed to reduce credit fraud and improve confidence in online transactions. Its
rules are, thus, primarily aimed at protecting electronic commerce, rather than
personal data.
It is also relevant to highlight the fact that whenever regional trade agreements
contain provisions on electronic commerce, they frequently include personal data
protection rules.
73 Although these rules differ in their extent and effectiveness,
74
some of those agreements encourage the enactment of data protection rules by their
Member States. The fact that these may be required to adopt certain minimum data
protection rules in order to be able to conclude such trade agreements naturally
contributes to the expansion and enhancement of personal data protection and
encourages harmonization in this area.
As already mentioned, international organizations, such as the United Nations,
also play a significant role in setting common rules on personal data protection in the
context of services provided at a distance by electronic means.
75
3.1.2 Protection of Minors’ Personal Data Processed by Electronic
Means
In the European Union, the GDPR sets forth additional relevant rules for personal
data processing by electronic means, such as restrictions on profiling, which is
defined as a form of automated processing of personal data,
76 data breaches notification procedures, protection of minors in relation to information society services
and the right to be forgotten, among many others.
77
The protection of minors in relation to information society services is regulated
by specific provisions in several countries and, in some of them, such as the United
States, through specific laws.
In this respect, the GDPR’s main concern is to set special requirements regarding
a child’s consent in relation to information society services. Where personal data
processing is based on the consent given by the data subject, the GDPR has given
Member States the possibility to choose the age limit above which a child may give a
valid consent to operators of information society services, without the intervention of
73 See the Data Protection in International Trade Law Special Report, Sect. 8.1.
74 See the Data Protection in International Trade Law Special Report, Sects. 8.1 and 9.
75 See supra, Sect. 2.1, and the instruments mentioned therein.
76 See article 4(4) of the GDPR.
77 See the European Union Special Report, Sect. 2.
16
D. Moura Vicente and S. de Vasconcelos Casimiro
