The new data protection convention 108+ and its importance for Asia
The article evaluates the potential for 18 Asian countries with data privacy laws to join the new global data protection convention 108+, which aims to modernize the 1981 Convention. Seven countries are identified as candidates, contingent on more flexible accession standards, highlighting the convention's limited current Asian participation despite the continent's extensive data privacy laws.
Abstract Over 40 years in the making, a new global data privacy agreement will soon come into force. The Council of Europe’s 1981 Convention for the Protection of Individuals with Regard to the Processing of Personal Data (Convention 108) will be superseded by a ‘modernized’ Convention ‘108+’. The Parties to Convention 108, as a potentially global treaty, include three countries from Latin America, and five from Africa, but none from Asia, the continent with the next highest concentration of data privacy laws. This article considers which of the 18 Asian countries with data privacy laws could accede to 108+. Each country is assessed against five impediments to accession: Jurisdictions which are not States; States which are not democratic; Laws of inadequate scope; Laws lacking an independent and effective data protection authority; and Laws with substantive provisions falling short of 108+ ‘accession standards’. The analysis shows that seven countries deserve consideration, but only if the ‘accession standards’ for 108+ become more flexible.
- Research Article
2
- 10.2139/ssrn.3530870
- Feb 3, 2020
- SSRN Electronic Journal
How Far Can Convention 108+ ‘Globalise’?: Prospects for Asian Accessions
- Research Article
5
- 10.1016/j.clsr.2020.105414
- May 12, 2020
- Computer Law & Security Review
How far can Convention 108+ ‘globalise’? Prospects for Asian accessions
- Research Article
10
- 10.1145/1897816.1897848
- Feb 1, 2011
- Communications of the ACM
Three decades have passed since the Organisation for Economic Co-operation and Development (OECD) promulgated Guidelines on the Transborder Flows of Personal Data, and still the issue of transborde...
- Book Chapter
3
- 10.1007/978-3-319-25047-2_7
- Jan 1, 2016
The following chapter refers to the evolution of data protection systems in Latin America during the last decade or so. Only 10 years ago in the region, privacy was considered as a fundamental right and no further developments were made on the subject. Nowadays, laws attending data protection have appeared all around Latin America, in Argentina (2000), Uruguay (2008), Costa Rica (2011), Colombia (2012), Mexico (2010), Peru (2011), the Dominican Republic (2013) and Nicaragua (2012) and other Latin American countries such as Brazil and Chile are working hard towards this model. The influence of the Ibero-American network, guided by Spain and Portugal, has been important in this process. In this sense, the system that was adopted by the Latin American countries follows the model based on Directives 1995/46/EC and 2002/58/EC that appear as instruments that give special importance to harmonisation and subordinate the free movement of personal data to the existence of a minimum equal level of protection among the states. Special reference is made to the Uruguayan system of data protection. This country, with the approval of law 18.331 on 11 August 2008 and its regulation Number 414/009 of 31 August 2009 became the second Latin American country to be declared by the European Commission as a country that ensures an adequate level of data protection within the meaning of section 25(6) of the Directive 95/46/EC. Uruguay also ratified the Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data (Convention 108) of the Council of Europe and its Additional Protocol, which entered into force on 1 August 2013, making it the 45th country to be party to the Convention and the first non-European country acceding to Convention 108. Thus, it can be positioned as a leader for other Latin American countries. With respect to enforcement, we focus on three points of view: educating and generating awareness; the imposition of administrative sanctions such as warnings, fines, suspension or closure of data bases, civil penalties and criminal proceedings and, finally, we refer to international co-operation.
- Research Article
2
- 10.2139/ssrn.3633976
- Jan 1, 2020
- SSRN Electronic Journal
Personal Data Processing by and for Political Campaigns: The Application of the Council of Europe's Modernised Convention 108
- Book Chapter
2
- 10.1007/978-3-319-05023-2_4
- Jan 1, 2014
By the end of the 1970s, two important international organisations started to prepare international instruments on the processing of information about individuals: the Organisation for Economic Co-operation and Development (OECD) and the Council of Europe. This chapter considers their early involvement, and examines in detail how OECD’s 1980 Guidelines on the Protection of Privacy and Transborder Flows of Personal Data, on the one hand, and Council of Europe’s 1981 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108), on the other, marked crucial steps in the evolution of the terms ‘data protection’ and ‘privacy’ in Europe. It shows that this institutionalised international cooperation resulted in the labelling of all existing and upcoming European rules on the processing of data as concerned with ‘data protection’, as well as in their progressive linkage with the word ‘privacy’. The embroilment between these expressions was later transferred into European Union (EU) law, and is instrumental to understand the emergence of the EU fundamental right to the protection of personal data.KeywordsData protectionPrivacyOECDCouncil of EuropeConvention 108Transborder data flows
- Research Article
3
- 10.2139/ssrn.3442428
- Aug 29, 2019
- SSRN Electronic Journal
A Study on the Extraterritorial Application of the General Data Protection Regulation with a Focus on Computing
- Research Article
2
- 10.2139/ssrn.1852623
- Jun 16, 2011
- SSRN Electronic Journal
The Right to the Protection of Personal Data (Dreptul la Protecţia Datelor cu Caracter Personal)
- Research Article
6
- 10.1093/idpl/ipv012
- Jul 6, 2015
- International Data Privacy Law
The Italian Marxist theorist Antonio Gramsci once wrote (in translation) that ‘the old is dying and the new cannot be born; in this interregnum, a great variety of morbid symptoms appear’. Although Gramsci was not speaking about data privacy, it seems to us that this statement could apply to the current state of data protection regulation around the world, which is marked by a realization that existing regulatory models are not working effectively, the lack of political will to explore alternatives, and general frustration about how to improve the situation. This has led to a credibility gap between the objectives of data protection law and how personal data are protected in practice. It should not be this way. The importance of data privacy has never been greater, and countries and regional organizations around the world are enacting legislation in an attempt to protect it. Much of this legislation has been based on the EU Data Protection Directive 95/46, which will be replaced by the proposed EU General Data Protection Regulation if the EU can ever finalize its interminable legislative process. Even the White House, which for years had seemed to oppose any large-scale federal legislation to deal with data processing in the private sector, has called for enactment of a Consumer Privacy Bill of Rights Act to grant increased protection to the online processing of personal data. Regional organizations such as Asia-Pacific Economic Cooperation, the Council of Europe, the Organization of American States, the Economic Community of West African States, the Organisation for Economic Co-operation and Development, and others have also done extensive work to enact new privacy instruments or amend their existing ones. All this activity has also had an effect at the global level, with the UN General Assembly passing a resolution that affirms the ‘right to privacy in the digital age’. But the increasing amount of new data protection regulation raises an important point: is all of this making any difference in increasing the protection of data privacy in practice? There are three aspects to this question that we would like to discuss briefly here. First of all, there is general confusion about the correct approach to regulating the collection, processing, and use of personal data. Among the issues about which there is no global consensus are how effective the law can be in regulating online data processing; the correct balance between legal regulation and private sector selfregulation; and how best to enforce the law. To a large extent, these questions are not unique to data protection and tend to arise in any area that involves the regulation of technology. But coming to a consensus about them has proved intractable, as they often reflect differences in national and regional laws and cultures. Secondly, the globalization of data processing creates major problems for applying and enforcing the law. The fact that it is increasingly difficult to determine the location where data are collected and processed gives rise to confusion on the part of individuals about what their rights are and how they can exercise control over their data in a meaningful way. Data controllers are similarly frustrated by the application of multiple laws to a particular database or online service, and regulators and governments are often unable to apply and enforce their laws across national borders, which can lead to international tensions. Thirdly, questions arise about how data protection regulation is enforced. Recent years have witnessed what could be called the ‘FTC-ization’ of data privacy enforcement, which reflects the strategy of the US Federal Trade Commission to concentrate on enforcement in highprofile cases, in order to make examples of the corporations involved and frighten others into compliance. Other regulators, such as European data protection authorities, have adopted a similar approach, at least in part because they lack the resources to enforce the law on a more widespread scale. However, while this may generate enforcement efficiencies, it raises questions
- Research Article
- 10.2139/ssrn.2464488
- Jul 10, 2014
- SSRN Electronic Journal
Reflections Upon the Interaction between Domestic and European Personal Data Protection Legislation
- Research Article
3
- 10.1017/s2194607800000181
- Jan 1, 2008
- Asian Journal of Comparative Law
The dialogue on data protection has so far been dominated by European and American voices. There are currently a few international conventions in place such as the Council of Europe's 1981 Convention for the Protection of Individuals with regard to the Automatic processing of personal data, the 1980 OECD Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data , which apply to 30 OECD countries, and the EU Directive 95/46/EC on the protection of individuals with regard to the processing of personal data, which binds EU member states but has had some impact on non-European countries due to the restriction on cross border flow of information.This has changed with the emergence of the APEC Privacy Framework in 2004 which focuses on the importance of the free flow of information in the digital age. Does the APEC Privacy Framework have anything of value to add or does it dilute the standards already in place? This article will examine these questions and argue that perhaps the APEC Privacy Framework is the first step towards a truly global standard for data protection.
- Research Article
6
- 10.2202/1932-0205.1071
- Jan 1, 2008
- Asian Journal of Comparative Law
The dialogue on data protection has so far been dominated by European and American voices. There are currently a few international conventions in place such as the Council of Europe's 1981 Convention for the Protection of Individuals with regard to the Automatic processing of personal data, the 1980 OECD Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data , which apply to 30 OECD countries, and the EU Directive 95/46/EC on the protection of individuals with regard to the processing of personal data, which binds EU member states but has had some impact on non-European countries due to the restriction on cross border flow of information.This has changed with the emergence of the APEC Privacy Framework in 2004 which focuses on the importance of the free flow of information in the digital age. Does the APEC Privacy Framework have anything of value to add or does it dilute the standards already in place? This article will examine these questions and argue that perhaps the APEC Privacy Framework is the first step towards a truly global standard for data protection.
- Research Article
92
- 10.2139/ssrn.2784123
- May 25, 2016
- SSRN Electronic Journal
Privacy for the Homo Digitalis: Proposal for a New Regulatory Framework for Data Protection in the Light of Big Data and the Internet of Things
- Research Article
- 10.37772/2518-1718-2023-3(43)-12
- Sep 25, 2023
- Law and innovations
Problem setting. In order to build an innovative society, it is necessary to develop legal norms and regulators aimed at protecting privacy and controlling personal data. In addition, the need to ensure effective and reliable protection of personal data in the conditions of rapid technological development, globalization and the growing threat of cybercrime is becoming more urgent. The need for the development of legal norms, the introduction of innovative technologies and the raising of public awareness become important tasks for ensuring privacy and protection of personal data. The study also aims to identify and analyze the main challenges facing the field of personal data protection, such as cybercrime, hacker attacks, globalization and cross borders. Legal norms and regulations aimed at protecting privacy are also analyzed, as well as the potential opportunities of new technologies that can increase the level of protection of personal data. Аnalysis of recent researches and publications. The problems of legal protection of personal data have recently become the subject of research by an increasing number of scientists, both lawyers and representatives of other fields of knowledge. In particular, such scientists as: S. Hlibko, T. Egorova-Lutchenko, K. Yefremova, O. Korvat, V. Kokhan, M. Haustova devote their attention to the study of these issues. etc. Purpose of the research is to develop possible ways of legal protection of personal data in view of today’s challenges related to this issue. The article aims to consider the development of technologies and the growth of the volume of personal data as the main factors affecting the need for effective protection of privacy and security of this data. The article is aimed at expanding the understanding of the problem and providing recommendations for improving the protection of privacy and security of personal data in the future. article’s main body. According to the preamble to the Agreement between Ukraine and the European Union on the participation of Ukraine in the European Union program “Digital Europe” (2021-2027), the important supporting role of digital infrastructure, including in the field of cyber security, is recognized to ensure inextricably linked transformation processes and digital leadership of the European Union. The purpose of concluding the Agreement is to establish mutually beneficial cooperation in order to strengthen and support the deployment of reliable and secure digital capabilities in the Union in the field, including cyber security. It is recognized that mutual participation in each other’s programs for the implementation of digital technologies should ensure mutual benefits for the Parties, while observing a high level of data protection, digital rights, etc. In accordance with paragraph 12 of Article 2 of Annex III to the Agreement, the exchange of information between the European Commission or OLAF and the competent state authorities of Ukraine must take place with due consideration of confidentiality requirements. Personal data included in the exchange of information must be transferred in accordance with the current legal norms on data protection of the Party making the transfer. According to paragraph 49 of the preamble of Regulation (EU) 2021/694 of the European Parliament and of the Council of April 29, 2021 on the establishment of the Digital Europe Program, digital transformation should allow citizens to access, use and securely manage their personal data across borders, regardless of their location or data location. According to point 60 of the preamble, by providing a single set of rules that are directly applicable in the legal systems of the Member States, Regulation (EU) 2016/679 guarantees the free flow of personal data between Member States and strengthens the trust and security of individuals, two indispensable elements of a true Digital Single Market . All actions taken within the framework of the Program, which involve the processing of personal data, must contribute to the smooth implementation of this Regulation, for example, in the field of artificial intelligence and distributed ledger technologies (for example, blockchain). These actions should support the development of digital technologies that meet data protection obligations both by design and by default. In addition, according to paragraph 69 of the preamble, this Regulation respects fundamental rights and adheres to the principles recognized in the Charter of Fundamental Rights of the European Union, in particular regarding the protection of personal data, etc. In the Charter of Fundamental Rights of the European Union (2016/C 202/02) dated June 7, 2016, Chapter II “Freedoms” contains Article 8, which is entitled “Protection of personal data”, according to which it is assumed that everyone has the right to the protection of personal data data concerning him. Such data must be processed fairly for specific purposes and on the basis of the consent of the person concerned or on another legal basis established by law. Everyone has the right to access the data that has been collected about him and the right to correct it. Compliance with these rules is subject to control by an independent body. In addition, Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data establishes rules relating to the protection of natural persons with regard to the processing of personal data, as well as rules, relating to the free movement of personal data, and protects the fundamental rights and freedoms of natural persons and, in particular, their right to protection of personal data. Today in Ukraine, the main legislative act in this area is the Law of June 1, 2010 No. 2997-VI “On the Protection of Personal Data”. Article 11 of the Law of Ukraine “On Information” specifies what information about a natural person (personal data) is. In turn, the legal and organizational bases for ensuring the protection of the vital interests of a person and citizen, society and the state, national interests of Ukraine in cyberspace, the main goals, directions and principles of state policy in the field of cyber security, the powers of state bodies, enterprises, institutions, organizations, individuals and citizens in this area, the basic principles of coordination of their cyber security activities are defined in the Law of Ukraine “On Basic Principles of Cyber Security of Ukraine”. In addition, relations in the field of information protection in information, electronic communication and information and communication systems are regulated by the Law of Ukraine “On the Protection of Information in Information and Communication Systems”. In turn, the Concept of the development of e-governance in Ukraine, as well as the Law of Ukraine “On the National Informatization Program” defines e-governance. In addition, in 2021, the Law of Ukraine “On Public Electronic Registers” was adopted, which defines the State electronic platform for maintaining public electronic registers. On April 18, 2023, by a resolution of the Cabinet of Ministers of Ukraine, the Regulation on the information system “Software platform for the deployment and support of state electronic registers” was approved, as well as the Procedure for using the software “Software platform for the deployment and support of state electronic registers”. conclusions and prospects for the development. The protection of digital personal data requires the development of appropriate technical and regulatory tools, as well as judicial practice of prosecution for violations of the order of their use. It is possible to create a database or registry for private electronic/digital platforms, with the help of which or which would control their activities, including regarding the protection of personal data. At the same time, at the regulatory and legal level, it is necessary to provide that a mandatory condition for the creation and functioning of an Internet platform is its registration in such a database / such a register, and a mandatory condition for registration is confirmation of technical capabilities to ensure the protection of personal data of platform users. It is necessary to define at the regulatory level the list and mechanisms of acquisition of digital rights, their implementation, protection, compensation and responsibility for their violation. The protection of personal data should be considered one of the digital rights of a person and a citizen. The development of digitalization in a legal state must inevitably be accompanied by the development of the legal framework, in particular, the emergence, consolidation, definition and protection of digital rights of individuals and legal entities. Digital rights are a multifaceted category, they become connected and interwoven with other rights defined and established in the norms of different branches of law. The multifaceted nature of the “digital rights” category implies the separation and delimitation of various categories of digital rights, their distribution into appropriate types, for example, “personal digital rights”, “financial digital rights”, etc. It should be quite natural to form a separate element in the general system of law, such as digital law, as a set of legal norms regulating social relations related to the circulation of (including personal) data in digital networks.
- Research Article
1
- 10.2139/ssrn.2921264
- Jan 1, 2017
- SSRN Electronic Journal
How Both the EU and the U.S. Are 'Stricter' than Each Other for the Privacy of Government Requests for Information