Chapter 1 (Origins & Development Of European Data Protection Law) Flashcards
What concept underlies EU data protection laws?
That the right to a private life and associated freedoms is considered a fundamental human right.
When and who adopted the Universal Declaration of human rights?
The General Assembly of the United Nations on December 10, 1948.
What fundamental rights are enshrined in Articles 12, 19, and 29(2) of the 1948 Human Rights Declaration?
Article 12: right to a private life and associated freedoms.
Article 19: right to freedom of opinion and expression as well as right to seek, receive, and impart info and ideas through any media regardless of frontiers.
Article 29(2): individual rights are not absolute and there will be instances where a balance must be struck.
What is the ECHR?
The European Convention on Human Rights, an international treaty to protect human rights and fundamental freedoms enacted on September 3, 1953.
What body enforces the ECHR?
The European Court of Human Rights (ECtHR), restructured into the Court of Human Rights in 1988.
What fundamental rights are laid out in Articles 8, 10(1), and 10(2) of the ECHR?
Article 8: right to private life and associated freedoms.
Article 10(1): protects the right of freedom of expression and the right to share info and ideas across national boundaries
Article 10(2): clarifies that rights of individuals aren’t unqualified and justifiable interference OK.
What 7 countries led in implementing legislation aimed at controlling the use of PI by government agencies and large companies?
- Austria
- Denmark
- France
- Federal Republic of Germany
- Luxembourg
- Norway
- Sweden
What 3 countries incorporated data protection as a fundamental right in their constitutions?
- Spain
- Portugal
- Austria
What is the OECD?
The Organization for Economic Co-operation and Development.
What is the role of the OECD?
To promote policies designed to achieve the highest:
1. Sustainable economic growth
2. Sustainable employment
3. Rising standard of living
In both OECD member states and nonmember states, while maintaining financial stability.
What did the OECD develop in 1980?
The Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (“OECD Guidelines”)
What is the aim of the OECD Guidelines?
To strike a balance between protecting the privacy, rights, and freedoms of individuals w/o creating any barriers to trade and allowing the uninterrupted flow of personal data across national borders.
Are the OECD Guidelines legally binding?
No. They are intended to be flexible and serve either as a basis for legislation in countries that have no data protection legislation or as a set of principles that may be built into existing legislation.
What are the 8 principles set forth in the OECD Guidelines?
- Collection Limitation
- Data Quality
- Purpose Specification
- Use Limitation
- Security Safeguards
- Openness Principle
- Individual Participation
- Accountability
What is the Collection Limitation Principle outlined in the OECD Guidelines?
PI must be collected fairly and lawfully and, where appropriate, with the knowledge or consent of the individual concerned.
What is the Data Quality Principle outlined in the OECD Guidelines?
PI must be relevant, complete, accurate, and up to date.
What is the Purpose Specification Principle outlined in the OECD Guidelines?
The purpose for which the PI is to be used must be specified no later than at the time of collection, and any use must be compatible with that purpose.
What is the Use Limitation Principle outlined in the OECD Guidelines?
Any disclosure of PI must be consistent with the purpose specified unless the individual has given consent or the data controller has lawful authority to do so.
What is the Security Safeguards Principle outlined in the OECD Guidelines?
Reasonable security safeguards must be taken against risks, such as loss or unauthorized access, destruction, use, modification, or disclosure of PI.
What is the Openness Principle outlined in the OECD Guidelines?
There should be a general policy of openness with respect to the uses of PI, as well as the identity and location of the data controller.
What is the Individual Participation Principle outlined in the OECD Guidelines?
Sets out what an individual is entitled to receive from a data controller pursuant to a request for their PI.
What is the Accountability Principle outlined in the OECD Guidelines?
A data controller should be accountable for complying with measures that ensure the previously stated principles.
Of the 8 OECD Principles, which has become the most important aspect of subsequent data legislation?
The Individual Participation Principle.
What are the 5 statements the OECD Guidelines make with regard to transborder data flow?
- Consider the implications for other member countries of domestic processing and re-export of personal data.
- Take all reasonable and appropriate steps to ensure transborder data flows of personal data, including transit through a member country, are uninterrupted and secure.
- Transborder flow of data OK except with countries that don’t observe Guidelines or where re-export would circumvent domestic privacy legislation.
- A member state may impose restrictions on transborder data flow for categories of personal data protected under its domestic legislation.
- Should’t develop laws and policies that are unnecessarily restrictive to transborder data flow.