Personal data protection: nuances of the European model

Available in Russian

Price 299 Rub.

Author: Elvira Talapina

DOI: 10.21128/1812-7126-2023-5-37-50

Keywords: European Union; personal data; privacy; GDPR; human rights

Abstract

The legal regulation of data protection has become a response to both governmental abuses of personal data and the challenges of technological progress. Nowadays, the right to protection of personal data has become virtually unchallengeable in many jurisdictions, including in Russian law. In many respects, this is the result of the European expansionary policy. The European Union was the first region to create a jurisdiction related to personal data protection, epitomized by the European Union’s General Data Protection Regulation (GDPR). Its norms have extraterritorial effect, as a result of which EU citizens are considered to be the most protected in the world in this respect. Other States are also attracted to the European approach: some American states are adopting innovative laws on personal data protection, and China is acting in the same direction. All this testifies to the success of the European model of data protection. At the same time, some nuances must be taken into account. For example, businesses comply with GDPR, but they need to be more actively involved in making their own real data protection decisions, including preventive ones. Most often, the personal data subject is equated by doctrine and judicial practice with the consumer, which gives him or her certain protection. But the significance of the protected values remains different. The right to the protection of personal data has no economic nature; it is classified by the EU legislation as a fundamental right. This right is protected by giving data subjects control over their personal data and by setting limits on the collection and use of personal data. It is necessary to encourage businesses to respect human rights and ensure adequate protection of personal data, basing this on the public law (rather than economic) nature of the resulting relations and emphasizing preventive mechanisms without waiting for the commission of torts. The principles of due (proper) care for human rights are enshrined in UN and OECD acts, and their observance is a socially expected responsibility of business. It is also necessary to take into account possible conflicts in the application of GDPR, which are discussed in the article using the example of data processing by financial intelligence entities. A synthesis of the positions of European regulators allows us to highlight the trend towards universalization of GDPR. At the same time, some of the shortcomings identified in the GDPR policy conflicts should be taken into account in the further improvement of data protection policy. In general, the GDPR’s focus on preventative measures against data processing breaches is carrying over to other digital acts of the EU and is called the risk-based approach. It is in line with the idea of human rights protection and has undeniable advantages over retrospective liability for breaches. Thus, detailed legislation on personal data protection designed to prevent breaches is a good tool for protection of privacy.

About the author: Elvira Talapina – Doctor of Sciences in Law, Institute of State and Law of the Russian Academy of Sciences, Moscow, Russia.

Citation: Talapina E. (2023) Zashchita personal’nykh dannykh: nyuansy evropeyskoy modeli [Personal data protection: nuances of the European model]. Sravnitel’noe konstitutsionnoe obozrenie, vol. 32, no. 5, pp. 37–50. (In Russian).

References

Delgado Echevarría M. (2023) International Report. In: Kilpatrick B., Kobel P., Këllezi P. (eds.) Аntitrust in Data Driven Markets & Legal Framework for Influencers, Native Advertising and Control over the Use of AI in Marketing, Cham: Springer, pp. 249–286.

Dowd R. (2022) The Birth of Digital Human Rights. Digitized Data Governance as a Human Rights Issue in the EU, Cham: Springer; Palgrave Macmillan.

Güneş Peschke Z.S., Peschke Ö.Ü.L. (2022) Artificial Intelligence and the New Challenges for EU Legislation. Yıldırım Beyazıt Hukuk Dergisi, no. 2, pp. 1267–1292.

Mantelero A. (2023) Fundamental Rights Impact Assessment in the DSA. In: van Hoboken J. et al. (eds.) Putting the Digital Services Act into Practice: Enforcement, Access to Justice, and Global Implications, Berlin: Verfassungsbooks, pp. 107–119.

McCorquodale R., Nolan J. (2021) The Effectiveness of Human Rights Due Diligence for Preventing Business Human Rights Abuses. Netherlands International Law Review, vol. 68, no. 3, pp. 455–478.

Picart E. (2018) L’appréhension juridique des algorithmes sous l’angle de la protection des données personnelles. Revue juridique de l’Ouest, no. 3, pp. 93–104.

Purtova N. (2018) The Law of Everything. Broad Concept of Personal Data and Future of EU Data Protection Law. Law, Innovation and Technology, vol. 10, no. 1, рр.40–81.

Quintel T. (2022) Data Protection Rules Applicable to Financial Intelligence Units: Still No Clarity in Sight. ERA Forum, vol. 23, no. 1, pp. 53–74.

Rouvroy A., Poullet Y. (2009) The Right to Informational Self-Determination and the Value of Self-Development: Reassessing the Importance of Privacy for Democracy. In: Gutwirth S., Poullet Y., de Hert P., de Terwangne C., Nouwt S. (eds.) Reinventing Data Protection? Dordrecht: Springer, pp. 45–76.

Sattler A. (2018) From Personality to Property?: Revisiting the Fundamentals of the Protection of Personal Data. In: Bakhoum M. et al. (eds.) Personal Data in Competition, Consumer Protection and Intellectual Property Law: Towards a Holistic Approach? Berlin: Springer, pp. 27–54.