Blogs
An overhaul of European Privacy Standards may be afoot
30 Mar 2010Author: Adrian Bannon
In her recent speech ‘Next Steps for Justice, Fundamental Rights and Citizenship in the EU’, on March 18, the newly appointed Commissioner for Justice, Fundamental Rights and Citizenship, Viviane Reding emphasised the need, amongst other things, to (a) substantively overhaul European privacy legislation, particularly the Data Protection Directive; and (b) foster more effective e-commerce by harmonising European contract law.
Reding said a legislative draft of a new Directive will be published in the autumn of this year. This announcement of legislative reform is timely – the Data Protection Directive has governed our privacy for a decade and a half now, and while it is a forward looking piece of legislation, it has attracted increasing attention from some quarters for being unwieldy, complex, bureaucratic, too broad in scope and costly.
Areas for consideration will include: (I) the changes brought about to the Directive as a result of the Lisbon Treaty; (II) the fact that there have been major advances in technology since the introduction of the Directive in 1995, and its accompanying implementing legislation; and (III) issues of enforcement and resources. Other areas for consideration could potentially include the exemptions currently provided for under the Directive, as well as the definitions of some important terms. For example, one of the most important, yet misunderstood, definitions of the Directive is that of ‘personal data’.
Data Protection and the Lisbon Treaty
As noted in her speech, the entry into force of the Lisbon Treaty significantly affects the data protection framework in a number of ways. First, under Lisbon, the protection of personal data is recognised as a fundamental right.
As stated in Article 16 of the Treaty:
Everyone has the right to the protection of personal data concerning them. (2) The European Parliament and the Council, acting in accordance with the ordinary legislative procedure, shall lay down the rules relating to the protection of individuals with regard to the processing of personal data by Union institutions, bodies, offices and agencies, and by the Member States when carrying out activities which fall within the scope of Union law, and the rules relating to the free movement of such data. Compliance with these rules shall be subject to the control of independent authorities.
Second, the European Charter of Fundamental Rights affords every EU citizen the right to personal data protection. It states that personal data should be processed fairly, with the individual’s consent and for relatively specific purposes. With the coming into force of the Lisbon Treaty, the Charter of Fundamental Rights is now a legally enforceable document not only on the EU institutions, but also on the member states as regards the implementation of European law.
Third, an additional change brought about by the Lisbon Treaty is the elimination of the three pillar structure. In practical terms, the abolition of the third pillar introduces qualified majority voting and co-decision with the European Parliament. This has positive implications for the enforcement of privacy and data protection legislation, although the legislative process becomes more complex.
Reding Reforms – European Privacy Legislation
In her speech, Commissioner Reding made reference to the public consultation on data protection already in operation. Some 160 submissions have already been received. Significantly, the Commissioner has voiced her own preference for the introduction of a ‘Privacy by Design’ (PbD) model.
Privacy by design (PbD) was developed in Canada by Ontario’s Information and Privacy Commissioner, Dr. Anna Cavoukian, in the 1990’s. PbD is an approach where privacy and data protection compliance is designed from the offset into systems holding information, rather than being subsequently added on or ignored. At the heart of the PbD model are seven core privacy principles. These include:
- Proactive not reactive; preventative not remedial
- Privacy as the default model of protection
- Privacy embedded into the design
- Full functionality – positive sum, not zero-sum
- End-to-End lifecycle protection
- Visibility and transparency
- Respect for user privacy
PbD is something that is already gaining significant traction within the EU. A prime example is that of the UK, and the Information Commissioner’s Office, which has already published literature on privacy impact assessment (PIA), and briefing notes on privacy enhancing technologies (PETs).
(b) More effective E-Commerce by Harmonising European Contract Law
In addition to the measures proposed above, Commissioner Reding has proposed a second area of reform that impacts on the digital future, specifically e-commerce and the introduction of a harmonised European contract law. If such a European contract law, were to be introduced, it could significantly boost trade and commerce, reduce litigation and relieve much of the trans-border disputes that inevitably accrue through member state trade.
While the Reding reforms appear to be very ambitious, they will be contentious. Eyes will be firmly fixed on the legislative proposals due for publication at the end of this year.
As an independent forum, the Institute does not express any opinions of its own. The views expressed in the article are the sole responsibility of the author.
Tags:
Posted in: | 1 comment
Latest Entries
- Leaders Gather for Munich Security Conference
- Why Legislate? Designing a Climate Law for Ireland
- Euro Crisis Working Papers 7 and 8
- Ireland’s Banking Debt: Explaining the Cost of Anglo and Irish Nationwide
Sort by Theme
- All themes
- Economics and Finance
- Future of Europe
- Justice & Law
- Energy and Climate Change
- Digital Future
- Foreign and Defence Policy
- The Wider Europe
- E View Project
- China
Sort by Authors
- All authors
- Brendan Halligan
- David Walker
- Gina Hanrahan
- Gina Hanrahan & Keith Doyle
- Gina Hanrahan and Keith Doyle
- IIEA
- James Kilcourse
- Johnny Ryan
- Joseph Curtin
- Joseph Curtin and Gina Hanrahan
- Keith Doyle
- Kevin Leydon
- Linda Barry
- Pat McArdle
- Peadar o Broin
- Prof. Karl Whelan
- Shane Fitzgerald
- Tony Brown
Sort by Tags
Search Blog Archive
- All entries
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- March 2009
- May 2008

Comments 1-1 of 1
On Friday April 9, Commissioner Reding and the European Commission have announced the publishing of a negotiating mandate in June 2010 for an overarching agreement with the United States on data protection. It is expected that this agreement will cover all information exchange deals between the EU and the United States.