46
progressively recognised different aspects of privacy, regarded both as a
negative right against State intrusion and as a positive right to self-determination in a variety of contexts, including the choice of using contraceptives or terminating pregnancy (Flaherty 1991). Lacking an explicit
reference, the US Supreme Court had to find a constitutional support for
the right to privacy in the “emanations” and “penumbras” of the Bill of
Rights (Griswold v. Connecticut, 381 U.S. 484). In particular, they examined the Fourth Amendment, protecting citizens against unreasonable
search and seizures (Solove 2001), and the Fourteenth Amendment, subjecting any deprivation of life, liberty and property to due process rules
(Cate and Cate 2012).
Besides the different constitutional frameworks, the EU and the US
also developed alternative regulatory models in the field of data privacy.
Over the past few decades, the EU has introduced a fully comprehensive
set of legislation governing the processing of personal data, both in the
private and in the public sector (Fabbrini 2015). In 2016, the EU replaced
the 1995 Data Protection Directive, which represented the core piece of
legislation adopted to harmonise national statutes in the field, with a
General Data Protection Regulation (GDPR), whose provisions are
directly binding in all member states (Albrecht 2016). Conversely, the US
have rejected a similar all-encompassing approach, in favour of exclusively
regulating specific sectors which were felt to be more in need of intervention (Schwartz and Solove 2014). Although being a pioneer in the data
privacy field, having adopted the Privacy Act 1974, which regulates data
processing by federal agencies, the US never introduced a unitary and
comprehensive piece of legislation in the field of data privacy, and only few
US states have. At the federal level, US data privacy law is a mosaic of
normative instruments covering a variety of issues, spanning from children’s privacy to the use of data in financial services (Schwartz and
Solove 2014).
In Europe, the basic presumption is that processing personal data represents an interference with the right to data privacy that can be tolerated
only if it satisfies certain legal conditions. In the US, instead, data processing is considered fully legitimate in so far as it is not prohibited by law, and
a strong emphasis is placed on the role of individual consent as a basis to
process personal data (Tourkochoriti 2014). European data protection
law, in order to reduce the risk of circumvention and ensure an even level
of protection across member states, has introduced provisions extending
its application to data controllers that are not established in the EU, but
E. CELESTE AND F. FABBRINI
progressively recognised different aspects of privacy, regarded both as a
negative right against State intrusion and as a positive right to self-determination in a variety of contexts, including the choice of using contraceptives or terminating pregnancy (Flaherty 1991). Lacking an explicit
reference, the US Supreme Court had to find a constitutional support for
the right to privacy in the “emanations” and “penumbras” of the Bill of
Rights (Griswold v. Connecticut, 381 U.S. 484). In particular, they examined the Fourth Amendment, protecting citizens against unreasonable
search and seizures (Solove 2001), and the Fourteenth Amendment, subjecting any deprivation of life, liberty and property to due process rules
(Cate and Cate 2012).
Besides the different constitutional frameworks, the EU and the US
also developed alternative regulatory models in the field of data privacy.
Over the past few decades, the EU has introduced a fully comprehensive
set of legislation governing the processing of personal data, both in the
private and in the public sector (Fabbrini 2015). In 2016, the EU replaced
the 1995 Data Protection Directive, which represented the core piece of
legislation adopted to harmonise national statutes in the field, with a
General Data Protection Regulation (GDPR), whose provisions are
directly binding in all member states (Albrecht 2016). Conversely, the US
have rejected a similar all-encompassing approach, in favour of exclusively
regulating specific sectors which were felt to be more in need of intervention (Schwartz and Solove 2014). Although being a pioneer in the data
privacy field, having adopted the Privacy Act 1974, which regulates data
processing by federal agencies, the US never introduced a unitary and
comprehensive piece of legislation in the field of data privacy, and only few
US states have. At the federal level, US data privacy law is a mosaic of
normative instruments covering a variety of issues, spanning from children’s privacy to the use of data in financial services (Schwartz and
Solove 2014).
In Europe, the basic presumption is that processing personal data represents an interference with the right to data privacy that can be tolerated
only if it satisfies certain legal conditions. In the US, instead, data processing is considered fully legitimate in so far as it is not prohibited by law, and
a strong emphasis is placed on the role of individual consent as a basis to
process personal data (Tourkochoriti 2014). European data protection
law, in order to reduce the risk of circumvention and ensure an even level
of protection across member states, has introduced provisions extending
its application to data controllers that are not established in the EU, but
E. CELESTE AND F. FABBRINI
