Data Protection Convention 108 and the EU framework

  • Slides: 20
Download presentation
Data Protection Convention 108 and the EU framework: Differing while Converging Sophie Kwasny Hong

Data Protection Convention 108 and the EU framework: Differing while Converging Sophie Kwasny Hong Kong University, 27 September 2017

Data Protection Council of Europe ≠ EU

Data Protection Council of Europe ≠ EU

Data Protection Council of Europe (Strasbourg - France)

Data Protection Council of Europe (Strasbourg - France)

Data Protection Data protection : an enabling right ECHR Article 1 – Obligation to

Data Protection Data protection : an enabling right ECHR Article 1 – Obligation to respect human rights Article 8 – Right to private life Article 9 – Freedom of thought, conscience and religion Article 10 – Freedom of expression Article 11 – Freedom of assembly and association

Data Protection Convention 108 (28/01/1981) UNIQUE (no other international legally binding instrument in the

Data Protection Convention 108 (28/01/1981) UNIQUE (no other international legally binding instrument in the field) OPEN (any country in the world with a complying data protection legislation can request invitation to accede) INFLUENTIAL (its principles = data protection principles taken up in all regions of the world)

Data Protection Convention 108 today currently 50 Parties (including Uruguay, Mauritius, Senegal) Pending: Morocco,

Data Protection Convention 108 today currently 50 Parties (including Uruguay, Mauritius, Senegal) Pending: Morocco, Tunisia, Cape Verde Burkina-Faso, Argentina, Mexico + observers (USA, Canada, Australia, Korea, Indonesia, Japan and Philippines) = TOTAL OF OVER 60 COUNTRIES

Data Protection Convention 108 Committee Standard setting body (latest documents : Guidelines on Big

Data Protection Convention 108 Committee Standard setting body (latest documents : Guidelines on Big Data, Opinion on data protection implications of PNR). Open Forum of cooperation between 60 countries and non State actors.

Data Protection Convention 108 today Based on ”Global Tables of Data Privacy Laws and

Data Protection Convention 108 today Based on ”Global Tables of Data Privacy Laws and Bills”, 5 th Ed, compiled by Graham Greenleaf, Privacy Laws & Business International Report, February 2017 www. privacylaws. com/Publications/special_reports/

Data Protection Convention 108 - Modernisation Current modernisation to: Ø reinforce the individuals’ protection

Data Protection Convention 108 - Modernisation Current modernisation to: Ø reinforce the individuals’ protection Modernisation trends : • promote as a universal standard • preserve general, simple, flexible and pragmatic character • ensure coherence with other relevant frameworks (EU, OECD, APEC)

Data Protection Convention 108 and the EU 95/46 EU Directive Preamble, Recital 11: “Whereas

Data Protection Convention 108 and the EU 95/46 EU Directive Preamble, Recital 11: “Whereas the principles of the protection of the rights and freedoms of individuals, notably the right to privacy, which are contained in this Directive, give substance to and amplify those contained in the Council of Europe Convention”

Data Protection Convention 108

Data Protection Convention 108

Data Protection Convention 108 and the EU GDPR Recital 105 the Commission should take

Data Protection Convention 108 and the EU GDPR Recital 105 the Commission should take account of obligations arising from the third country's […] participation in multilateral or regional systems […]. In particular, the third country's accession to Convention 108 should be taken into account.

Data Protection Convention 108 and the EU

Data Protection Convention 108 and the EU

Data Protection Convention 108 and the EU Section 3. 3. 1 (page 11) second

Data Protection Convention 108 and the EU Section 3. 3. 1 (page 11) second paragraph : “In particular, the Commission encourages accession by third countries to Council of Europe Convention 108 and its additional Protocol. […] It is currently in the process of being revised and the Commission will actively promote the swift adoption of the modernised text with a view to the EU becoming a Party. standards. ”

Data Protection Convention 108 and the EU It will reflect the same principles as

Data Protection Convention 108 and the EU It will reflect the same principles as those enshrined in the new EU data protection rules and thus contribute to the convergence towards a set of high data protection standards.

Data Protection Modernisation and the EU May 2013 – mandate adopted by the Council

Data Protection Modernisation and the EU May 2013 – mandate adopted by the Council Decision authorising COM to negotiate on behalf of the EU and its member states: Ø Negotiate the modernisation proposals Ø Negotiate the conditions and modalities of accession of the EU to Convention 108 (see amending protocol of 1999)

Data Protection Convention 108 modernised Transborder dataflows • [Limitation to free flow between Parties

Data Protection Convention 108 modernised Transborder dataflows • [Limitation to free flow between Parties where bound by harmonised rules of protection shared by States belonging to a regional international organisation. ] • Means to secure and approriate level of protection (ad hoc or approved standardised safeguards provided by legally binding instruments) • Possibilities to transfer where consent, specific interests of the data subject, prevailing legitimate interests provided for by law and are necessary

Data Protection Convention 108 modernised Definitions (personal data, processing…) Scope (public and private sector)

Data Protection Convention 108 modernised Definitions (personal data, processing…) Scope (public and private sector) Legitimacy and quality of data Sensitive data Security Transparency Rights of data subjects Additional obligations Exceptions Transborder data flows Supervisory authorities

Data Protection Convention 108: From Regional to Global 47 + Uruguay Mauritius Senegal Tunisia

Data Protection Convention 108: From Regional to Global 47 + Uruguay Mauritius Senegal Tunisia Morocco Cabo Verde Burkina Faso Argentina Mexico ….

Data Protection Thank you for your attention www. coe. int/dataprotection@coe. int

Data Protection Thank you for your attention www. coe. int/dataprotection@coe. int