45
proposition that data localisation does not represent a panacea for resolving tensions between competing jurisdictions in the field of cloud computing, and that transnational cooperation and effective international
agreements are needed now, more than ever.
3.2 data PrIvacy across the atlantIc
In Europe and the US, data privacy law emerged almost simultaneously in
the 1970s (Jones 2017). Both legal systems recognise the importance of
protecting personal data and the potential risks deriving from a misuse of
such data. Yet, on the two sides of the Atlantic, two different regulatory
models have emerged in the field of data privacy (Schwartz and Solove
2014; Tourkochoriti 2014).
In Europe, the respect of privacy and the protection of personal data
are recognised as fundamental rights. In 1950, as a reaction to intrusive
surveillance practices of totalitarian regimes that afflicted Europe in the
first half of the twentieth century, the European Convention on Human
Rights enshrined the individual right of respect for private and family life,
home and correspondence (Article 8). In its case law, the European Court
of Human Rights, which is the competent jurisdiction for the interpretation of the Convention, has affirmed that the concept of private life must
be construed broadly in order to protect all aspects of human personality,
including individual personal data (Council of Europe 2019; Fabbrini
2015). In 2000, the EU Charter of Fundamental Rights explicitly
enshrined the right to privacy and data protection in two distinct provisions, Articles 7 and 8, respectively. Although originally lacking binding
legal value with the transposition of the Lisbon Treaty in 2009, the Charter
was recognised as having a primary legal status in the hierarchy of EU legal
sources, at the same level of EU founding treaties (Fabbrini 2015).
The US is often referred to as the cradle of the right to privacy. Back in
1890, Samuel Warren and Louis Brandeis authored a seminal article published on the Harvard Law Review in which they advocated for the recognition of a broad conceptualisation of the right to privacy and the
protection of the individual against external intrusions (Warren and
Brandeis 1890). However, in contrast to the EU, in the US, at least at
federal level, there is no explicit constitutional provision protecting the
right to privacy or data protection. Indeed, the US Constitution dates to
1787 and its Bill of Rights was added only three years later, so well before
privacy became an issue. The case law of the US Supreme Court
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
proposition that data localisation does not represent a panacea for resolving tensions between competing jurisdictions in the field of cloud computing, and that transnational cooperation and effective international
agreements are needed now, more than ever.
3.2 data PrIvacy across the atlantIc
In Europe and the US, data privacy law emerged almost simultaneously in
the 1970s (Jones 2017). Both legal systems recognise the importance of
protecting personal data and the potential risks deriving from a misuse of
such data. Yet, on the two sides of the Atlantic, two different regulatory
models have emerged in the field of data privacy (Schwartz and Solove
2014; Tourkochoriti 2014).
In Europe, the respect of privacy and the protection of personal data
are recognised as fundamental rights. In 1950, as a reaction to intrusive
surveillance practices of totalitarian regimes that afflicted Europe in the
first half of the twentieth century, the European Convention on Human
Rights enshrined the individual right of respect for private and family life,
home and correspondence (Article 8). In its case law, the European Court
of Human Rights, which is the competent jurisdiction for the interpretation of the Convention, has affirmed that the concept of private life must
be construed broadly in order to protect all aspects of human personality,
including individual personal data (Council of Europe 2019; Fabbrini
2015). In 2000, the EU Charter of Fundamental Rights explicitly
enshrined the right to privacy and data protection in two distinct provisions, Articles 7 and 8, respectively. Although originally lacking binding
legal value with the transposition of the Lisbon Treaty in 2009, the Charter
was recognised as having a primary legal status in the hierarchy of EU legal
sources, at the same level of EU founding treaties (Fabbrini 2015).
The US is often referred to as the cradle of the right to privacy. Back in
1890, Samuel Warren and Louis Brandeis authored a seminal article published on the Harvard Law Review in which they advocated for the recognition of a broad conceptualisation of the right to privacy and the
protection of the individual against external intrusions (Warren and
Brandeis 1890). However, in contrast to the EU, in the US, at least at
federal level, there is no explicit constitutional provision protecting the
right to privacy or data protection. Indeed, the US Constitution dates to
1787 and its Bill of Rights was added only three years later, so well before
privacy became an issue. The case law of the US Supreme Court
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
