b) The notion and scope of personal data covered by the relevant legal sources,
which ranges from the very broad concept adopted in European legislation and
in several non-European legal systems closely influenced by it, which comprises
“any information relating to an identified or identifiable natural person”—the
protection of which is regarded as a fundamental, constitutionally protected
right—to the much more narrow scope of the personal data that enjoys legal
protection currently prevailing in the United States, where data protection rules
are primarily aimed at federal agencies;
c) The role and nature of supervision authorities, which in the European Union
have been entrusted with a wide range of investigative, corrective, authorization
and advisory powers, typically concentrated in a single independent public
agency, whereas in certain non-European countries such authorities are sometimes put under the control of the executive power (as happens in Singapore and
South Africa) or have their attributions dispersed among a number of distinct
public agencies, none of which is specifically devoted to data protection (as is
the case of the U.S.);
d) The protection specifically awarded to the electronic processing of personal data
pertaining to consumers and workers, in respect of which the European Union
and its Member States have also taken the lead, e.g., through the imposition of
strict rules in respect of the collection of data through the use of cookies or other
technological devices and the distribution of unsolicited commercial communications, which have no equivalent in the U.S.; and the enactment of special
provisions ensuring workers’ right to privacy which include, inter alia, a general
prohibition to use surveillance means at the workplace and to access workers’
private electronic communications, in respect of which American law allows a
far broader range of exceptions;
e) The enshrinement of the data subject’s so-called right to be forgotten, which has
been recognized in the widest terms by the case-law of the Court of Justice of the
European Union (so as to affect also information provided by search engines)
and was recently regulated in substantial detail in the GDPR, but which has so
far found no acceptance in U.S. federal or state law;
f) The existence of specific duties to secure personal data and to notify data
breaches, which European law now regulates in general terms, but which in
other legal systems have been the object of only limited or sector-specific legal
provisions;
g) The exceptions to personal data protection allowed in respect of criminal
investigations, as well as for security and defense purposes, which are considerably more far-reaching in the U.S., particularly in the context of anti-terrorist
statutory enactments, than in Europe;
h) The remedies and sanctions available for the breach of the applicable personal
data protection rules, which, albeit provided for in most legal systems, have
recently been considerably aggravated in the European Union, in particular
through the power granted to supervisory authorities to impose administrative
fines of extremely high values that have no equivalent in other jurisdictions;
Data Protection in the Internet: General Report
41
Précédent

- 50/540

Suivant