i) The territorial scope of application of national rules on personal data protection, in respect of which the recent European GDPR has made an express option
for a mitigated form of extraterritorial applicability—comprising all situations in
which the processing of personal data, albeit undertaken by entities not
established in the Union, concerns data subjects who are in Europe and takes
place in the context of the offering of goods or services to those subjects or in the
monitoring of their behavior occurred in the Union—that has no explicit equivalent on the other side of the Atlantic;
j) The conditions applicable to the transfer of personal data to foreign jurisdictions, in respect of which the European Union, followed by other countries such
as Cape-Verde, Japan, Singapore and South Africa, has established a particular
system of control of the adequacy of the level of protection provided by the
country of destination as a condition for the lawfulness of such transfer; and
k) The law applicable to liability for damages caused by the unlawful processing
of personal data in cross-border situations, with regard to which Private International Law rules provide an array of different solutions, even within the
European Union, that vary from the (quasi) systematic application of the lex
fori to the optional applicability of the law of the wrongful activity or that of the
harmful effect.
5.2 A General Assessment
The comparison conducted above denotes a rather paradoxical situation: whilst the
Internet is by nature a global computer network and personal data processing
conducted through it is largely also a trans-border phenomenon that tends to ignore
national frontiers, the regulation of that phenomenon is still—with the notable
exception of the European Union—essentially the result of national or even private
initiatives.
What’s more, the approaches to that regulation differ widely, particularly among
the two major Western trading blocks, in what concerns its sources, contents,
remedies and scope of application.
The diversity of such approaches does not appear to constitute the mere result of
different legislative techniques or historical traditions; it is rather the fruit of deeplyrooted different perceptions of the respective roles of private ordering, the protection
of individuals’ fundamental rights and the preservation of national security in a
market economy.
182
182 This was recognized by the Irish High Court in its judgment of 3 October 2017 on The Data
Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (see note 158)
where it stated: “A central purpose of the European Union is the promotion of the peace and
prosperity of citizens of the European Union through economic and trading activity within the
single market and globally. The free transfer of data around the world is now central to economic
and social life in the union and elsewhere. The recent history of our continent has shown how
42
D. Moura Vicente and S. de Vasconcelos Casimiro
for a mitigated form of extraterritorial applicability—comprising all situations in
which the processing of personal data, albeit undertaken by entities not
established in the Union, concerns data subjects who are in Europe and takes
place in the context of the offering of goods or services to those subjects or in the
monitoring of their behavior occurred in the Union—that has no explicit equivalent on the other side of the Atlantic;
j) The conditions applicable to the transfer of personal data to foreign jurisdictions, in respect of which the European Union, followed by other countries such
as Cape-Verde, Japan, Singapore and South Africa, has established a particular
system of control of the adequacy of the level of protection provided by the
country of destination as a condition for the lawfulness of such transfer; and
k) The law applicable to liability for damages caused by the unlawful processing
of personal data in cross-border situations, with regard to which Private International Law rules provide an array of different solutions, even within the
European Union, that vary from the (quasi) systematic application of the lex
fori to the optional applicability of the law of the wrongful activity or that of the
harmful effect.
5.2 A General Assessment
The comparison conducted above denotes a rather paradoxical situation: whilst the
Internet is by nature a global computer network and personal data processing
conducted through it is largely also a trans-border phenomenon that tends to ignore
national frontiers, the regulation of that phenomenon is still—with the notable
exception of the European Union—essentially the result of national or even private
initiatives.
What’s more, the approaches to that regulation differ widely, particularly among
the two major Western trading blocks, in what concerns its sources, contents,
remedies and scope of application.
The diversity of such approaches does not appear to constitute the mere result of
different legislative techniques or historical traditions; it is rather the fruit of deeplyrooted different perceptions of the respective roles of private ordering, the protection
of individuals’ fundamental rights and the preservation of national security in a
market economy.
182
182 This was recognized by the Irish High Court in its judgment of 3 October 2017 on The Data
Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (see note 158)
where it stated: “A central purpose of the European Union is the promotion of the peace and
prosperity of citizens of the European Union through economic and trading activity within the
single market and globally. The free transfer of data around the world is now central to economic
and social life in the union and elsewhere. The recent history of our continent has shown how
42
D. Moura Vicente and S. de Vasconcelos Casimiro
