New Chapter One
New Chapter One
Introduction
After the invention of computers in the 19th century and the Internet in the late 1960s,
the vast majority of our work is done online. The dependence on online platforms has
increased over the years, and people have begun using diverse online platforms for
various purposes, including learning, business, entertainment, socialization, etc. The
growing advancement in information and communication technology (ICT) has
brought a radical transformation in the communicating process making life easier,
faster, and smarter. This landscape also poses tremendous challenges to privacy, as
numerous actors collect, store, and share our personal data with numerous third
parties, mostly without our knowledge Over the last couple of decades, the collection,
retention, use, and transfer of personal data have become rampant chiefly by
government agencies and businesses. To indicate governments’ aptitude toward data
processing, George Orwell once warned in his dystopian novel Nineteen Eighty-
Four that Big Brother (government authorities) is always watching you. This trend of
government-sponsored data processing has increased significantly over time,
especially after September 11, [Link] business’s data processing has also
become evident by new business models that are mostly grounded on personal data. In
course of time, the personal data market has become global due to the constant
increase of the access and use of the Internet. Eventually, personal data has evolved as
the main fuel of the 4th Industrial Revolution era. In such an atmosphere, ordinary
citizens, being private individuals, or consumers desire to have adequate legal
protections for their privacy rights. Thus, the worldwide debate on privacy concerns
has become apparent. Keeping this in mind, this article aims to explore some basic
aspects of privacy, including the meaning, value, historical development, challenges,
and legal protections as ensured in international, regional, and national legal
frameworks.
2. Meaning of Privacy
Privacy is an elusive and poorly defined conception Thus, much ink has been spilt in
an attempt to define the term ‘privacy.’ In the era of information, privacy and
technology shape and mold each other, and hence, privacy protection mechanisms
would not work unless that is designed looking at the technological development.
This context widens the trivial Cooley’s explanation of privacy ‘the right to be let
alone’ to capture more complexities around privacy and allied economic, social,
political, psychological and legal concerns. Generally, privacy refers to the condition
or moral claim over others requiring abstaining from doing some specific activities.
Some scholars attempted to explain the notion of privacy demonstrating its synonym.
Ruth Gavison, for instance, shares that privacy has some constituent components,
such as anonymity, solitude and secrecy. Whereas Helen Nissenbaum classified
privacy as a dynamic and complex issue, and the sensitivity to the data in terms of the
purpose, context, and trust. Westin attempted to articulate privacy in terms of social,
personal, and regulatory dimensions. While Anita Allen concludes, privacy appears in
the multifaceted denominations, e.g., physical, proprietary, decisional, informational,
and so on. Probably, one of the most referred definitions of privacy was given by D.
W. Prosser in [Link] explained, privacy is a group of the following four torts:
(1) intrusion upon the plaintiff’s seclusion or solitude, or into his private affairs; (2)
public disclosure of embarrassing private facts about the plaintiff; (3) publicity which
places the plaintiff in a false light in the public eye; and (4) appropriation, for the
defendant’s advantage, of the plaintiff’s name or likeness. Being abstract, privacy
encompasses numerous other issues, including the freedom of thought against
surveillance; bodily integrity; protection of personal data; seclusion in residence;
capacity of protecting reputation; safeguard against searches and questionings, etc. In
sum, privacy means one’s right to keep his/ her personal affairs and relationships
away from the reach of others. A state of being alone, and thus, not to be interrupted
or watched by [Link], the notion of privacy is full of disarray, and hence, there
is hardly any definition of privacy that can satisfy everybody. At the same time, the
evaluation and justification of privacy in society play a crucial role in rendering
dimensions to the definition, and hence, an attempt of defining privacy would always
be incomplete. Nonetheless, the following definition can satisfy many who searches
for an inclusive definition of [Link] is control over when and by whom the
various parts of us can be sensed by others. By ‘sensed’ is meant simply seen, heard,
touched, smelled, or tasted. By ‘parts of us’ is meant the part of our bodies, our
voices, and the products of our bodies. ‘Parts of us’ also includes objects very closely
associated with us. By ‘closely associated’ is meant primarily what is spatially
associated. The objects which are ‘parts of us’ are objects we usually keep with us or
locked up in a place accessible only to us. Privacy is a sweeping concept. Thus, over
centuries, scholars from various disciplines aimed at defining privacy in diverse ways.
Among all definitions, probably the simplest and most discussed legal definition of
privacy is- ‘the right to be let alone’. Arguably, in the digital age, this typical
definition of privacy cannot ensure the desired protection unless associated with
control over information. Hence, many other authors used to define privacy in terms
of information control. The modern construction of privacy can be summarized by the
following six headings: (1) the right to be let alone; (2) limited access; (3) secrecy; (4)
control of personal information; (5) personhood, and (6) intimacy. From the above
discussion.
it has become explicit that the underlying meaning of the term ‘privacy’ is not
generally unified, rather varies in diverse features, scopes, nature, culture, custom,
moral value, etc. Although there are disagreements among scholars about the meaning
of privacy, certain things are common in almost all discourses. All privacy-related
discourses acknowledge- privacy is an intrinsic human right that facilitates individuals
to exile outsiders from their intimate zones; uplifts the dignity of human beings, along
with their other constitutional guarantees.
3. Value of Privacy
The evolving information age is transforming our lives in such a way that we could
never imagine. In a data-based economy, privacy appears as one of the pressing
concerns due to numerous reasons, such as globalization of human communication;
commercial importance of data; interest of governments in accessing and processing
of data; voluntary data sharing by people in social media; commercialization of
personal data; usage of cloud computing, and recognition of privacy as one of the
fundamental human rights, e.g., freedom of speech. In a networked world, diverse
actors always monitor or track our activities, and consequently, our privacy witnesses
tremendous threats. Indeed, privacy is indispensable, and hence, no one can violate
privacy unless there remains a compelling State interest. Privacy is inevitable for not
only human beings but also other animals. The basic outcomes of animal and cultural
studies reveal that each of the animal species searches for privacy in a small group
intimacy. The ecological studies also show that the lack of intimate space, due to
congestion and the like, causes tremendous threats to survival. Adam Moore
concluded that in the case of the absence of privacy, beasts could kill each other or be
involve in suicidal reductions of their populations. While conducting experiments on
rats in cages, Calhoun witnessed that a certain portion of free space is crucial for each
of the breeds. Any shortage thereof leads to splitting in amicable relations and causes
illnesses, such as an increase of blood pressure, heart failure, etc. Being a part of
animal families, human beings also carry the same [Link] is crucial for
democracy too, although the relationship between democracy and privacy is a
complex and dynamic one. Even there remain disagreements also between them in
terms of meaning, dimensions, types, etc. In recent years, the manipulation of voter’s
psychology in social media by polling agents and eventually influences the result of
the election have appeared as an issue of huge debate in the global political
discourses. There are allegations against former US President Donald Trump that his
election campaigns used the voter suppression strategy in the 2016 US election by
sending negative messages, (dark posts) based on race, ethnicity and socio-economic
status, using the advertising tools of Facebook. The issue of voter suppression strategy
is no longer restricted to the privacy of the individual voter, rather correlates to
greater trends in democratic politics as [Link] all, privacy matters because we all
love to have an intimate life and like to share our stories and memories with only
those whom we believe. Moreover, in pure democratic culture, personal liberty
includes the autonomy and freedom of individuals from the unauthorized access of the
business, and public and private actors. It would be disastrous, if any of these actors
leak, in any way, our sensitive personal data. The losses will be unthinkable, as most
of them are irreparable and admit no substitutes or compensations. Rotenberg
remarked back in 1996 that ‘[p]rivacy will be to the information economy of the next
century what consumer protection and environmental concerns have been to the
industrial society of the 20th century’. His anticipation has widely been explicit, as
privacy emerges as one of the most desired interests in the contemporary world. Thus,
from the cradle to grave, privacy requires to be duly respected.
4. Historical Development
Living life to the fullest, rights are inevitable. Thus, over time, numerous rights have
been recognized as the natural outcomes of the economic, social, and political
reforms. Although earlier, the law acknowledged a few rights only, such as the right
to life, the right to property, etc., later, the law started acknowledging human feelings,
emotions, intellects, etc. Gradually, the notion ‘right to life’ has been widened to
cover ‘the right to enjoy life’, and ‘the right to be let alone’, which is alternatively
known as ‘the right to privacy’. The notion of privacy has not matured overnight. It is
argued that the discourse over privacy concerns is as old as human beings. Aristotle
was considered the first philosopher who distinguished the private spheres from the
public spheres. While the Romans advanced the notion of privacy and attempted to
protect it judicially. The notion can also be drawn back from several ancient codes as
well, such as the Greek, Roman, and Anglo-Saxon codes. Indeed, the notion of
privacy has had long historical roots in both anthropological and sociological
discourses. Aristotle’s demarcation on the public-private spheres of politics, i.e.,
the polis and oikos, is often identified as the formal reference to privacy. It is believed
that innovation and people’s inclination toward individualism are two responsible
factors that cause a radical shift of privacy from the public to private and social
domains, precisely known as the horizontal approach. Whereas the vertical
construction restricts the notion in between the State-citizen’s relationship only.
Although started with the view of protecting one’s bodily integrity and home from
unwarranted intrusion, the notion of privacy turned soon toward control over personal
information. Despite having a long history of evolution, the right to privacy has just
been evident in the late 19th century. While the public attention encircling privacy has
just escalated dramatically in the past centenary. In particular, the modern
construction of the notion was surfaced first in 1890 by Louis Brandeis and Samuel
Warren’s scholarly piece ‘The Right to Privacy. Henceforth, the notion of ‘privacy’
has become very popular; widely recognized and began to evolve as one of the
fundamental human rights. The main concerns as depicted in the work of Warren and
Brandeis were the offensiveness and invasiveness in US journalism from the 1900s
onwards. However, the essence of their article illustrated that technological
advancement caused grave concern over privacy. Warren and Brandeis identified the
press, instantaneous photography, newspaper, and numerous mechanical devices as
the new threats to privacy. Referring to the growing increase of the press and its
threats to privacy, a study covering the periods 1850-1890 reveals that the circulation
of the newspaper increased nearly 1000 per cent; from 100 papers with 800,000
readers to 900 papers with more than 8,000,000 readers. It may be argued that
privacy, as we mean it today, is nearly a 150-year-old conception. The history of
privacy can be summarized as follows: (1) people began to build internal walls within
a premise in nearly 1500 AD to ensure separate room for everyone; (2) praying and
reading silently had been started as a popular habit from 1215 era; (3) people started
using single bed from 1700 era; (4) people had been cautious about the privacy of
information since the 1900s, especially, after the publication of Warren and Brandeis’
‘The Right to Privacy’, and (5) privacy is about to finish again as it was in the early
society after 1990s.[33]In TechPrivacy, Professor Solove has interestingly chosen the
use of cartoons to describe the history of privacy. Metaphorically, he demonstrates
that the death of privacy has already started and will be continuing because of several
scientific inventions, such as the portable cameras in the 1880s; telephone wiretapping
in the 1890s; mainframe computers in the 1960s; personal computers in the 1980s;
portable phones in the 1990s; portable computers in the 2000s; smartphones in the
2010s, and holographic life projection in the 2070s. It may be relevant to share that
Westin classified contemporary privacy development into four phases, e.g., the first
phase 1945–60; the second phase 1961–1979; the third phase 1980–1989, and the
fourth phase 1990– 2002, respectively. In line with Westin, the fifth phase (2003-
ongoing) can be shown as the age of the Internet of things (IoT), ubiquitous
computing, social media, Google and WikiLeaks, when the use of personal data has
increased to an unprecedented level posing tremendous challenges to information
privacy. Despite having references to privacy in diverse fields of study, and even in
ancient texts, formal legal discourse over privacy had started and popularized just
after Warren and Brandeis’s premier work, ‘The Right to Privacy’, as evidenced by
numerous scholarly writings.
5. Challenges of Privacy
Although the challenges of privacy have already been mani fest, the current contexts
require more detail on the issue. The nature, type, and extent of privacy invasions
vary in ages, as ‘privacy law in general, and information privacy, in particular, have
always been closely tied with technological development’. The constant progress in
diverse technologies, an increasing usage thereof, along with the large-scale
processing of personal data, etc., immensely affect the conventional notion of privacy
and the way of its invasion. Consequently, from the matters of secrecy, seclusion,
bodily integrity, or inviolability of home, communication and correspondence, the
worldwide focus of privacy issues has shifted nowadays to information privacy.
Interestingly, throughout centuries, several Privacy Enhancing Technologies (PETs),
such as encryption, metadata, application programming, system development
governance, user interface, etc., are also being used for the protection of privacy. In
the data-based economy, the production and promotion of technological devices and
services largely rest on sharing data between individuals and businesses. Since most
of our activities have become digitalized nowadays, numerous public-private actors
can easily collect, retain, and analyze more data than in preceding periods. This milieu
presents a chain interaction among technology, data, and privacy for this day and the
days to come. It is not an exaggeration to say that ‘today’s world runs on personal
data’. Presumably, this landscape poses huge threats to privacy. Having regard to the
close connectivity between privacy intrusion and the use of technology of the ages,
privacy challenges can be shown on different ages. The major privacy concerns in the
past were mostly relating to trespass to house, correspondence, and communication,
or intrusion against seclusion, mostly caused by the press, instantaneous photography,
or the newspapers. Whereas the data breach incident appears as the major privacy
concern this day, which is mostly caused by some technologies, such as wiretapping
technology, lie detection technology, and the Internet. Hence, although trespassing
and intrusion upon seclusion were the major privacy dilemmas in the recent past, this
has been shifted to the data breach incident this day and in the future. Some authors
share, our age relied too much on some extractive technologies, such as
spectrographs, video lenses, transmitters, and computers, and all these technologies
extracted mostly the personal data. Whereas other groups of authors identified six
emerging technologies, e.g., drones, human enhancement technologies, RFID-enabled
travel documents, second-generation biometrics, second-generation DNA sequencing,
and whole-body scanners that entail enormous impacts on privacy. Apart from those,
a recent exciting development is face-to-data (F2D), i.e., advanced face recognition
technology that accesses to and processes the personal data of the individuals
automatically based on the facial images linked with the names. Additionally, due to
the growing adoption of some other technologies, such as cloud computing, big data
analytics, and the Internet of things (IoT), privacy witnesses imminent danger. Indeed,
in the digital age, there are countless factors, technologies, and actors that are liable to
cause privacy intrusion. Hence, preparing a list of those factors, actors, and
technologies is quite an impossible task. Nonetheless, some authors identify several
other technologies that may cause major privacy challenges for today and coming
days. These privacy-intrusive technologies include, inter alia, ubiquitous computing;
IoT; smart cities; satellite data; blockchain; cryptocurrency; machine learning;
Artificial Intelligence (AI); automation; ambient technology; neurolinguistics
technology; memetic technology, and grid technology. These days and in the coming
days, people may also suffer due to identity theft, data mining, smart cards, key
logger, and wireless networking. Above all, the constant advancement in science and
technology and increasing dependence thereof is, among others, the main cause of
privacy invasions for today and future days. Posner remarked, the constant progress of
science and technology in the last few decades has led us to the edge of the Orwellian
nightmare. These privacy and technological conditions may be regarded as the
‘technocratic modernism’ that poses huge threats to privacy and freedom. The trend
continues since most modern technologies run primarily on personal data. While
technology operates mostly on personal data, there remains anxiety of usage of that
data in an unlawful, unfair and untransparent manner. Additionally, the collected
personal data may be used other than the original purposes, inaccurately, and stored
for a long period than usual. Moreover, there exist always apprehensions regarding
the integrity and confidentiality of the processed and stored data. In all these cases,
our valuable personal data is prone to be compromised, lost, or damaged. Arguably, it
is impossible to predict all possible privacy invasions that may be caused by modern
and future scientific technologies, and hence, the policymakers cannot prepare legal
rules for each of the scientific innovations. The policymakers should establish an
adequate data protection regime, equipped with specific rules, policies, or
mechanisms to strike the balance among the interests of the key stakeholders, e.g.,
public agencies, businesses, and data subjects.
6. Legal Recognition and Protection of Privacy
The secret data leakage of Julian Assange in 2010; Snowden’s revelation in 2013;
Panama Papers leakage in 2016; Paradise Papers disclosure in 2017, and Facebook
Cambridge Analytica’s scandal in 2018 have shocked the global community. In 2019,
another data leakage of above 540 million Facebook users was revealed, and until
April 2019, nearly 1. 885 million customers’ financial data was leaked from First
American Financial Corporation. In March 2020, around 5.2 million guests’
information was leaked from hotel Marriott International. In April 2021, the sensitive
personal data of around 500 million users of LinkedIn was allegedly scraped. All
these incidents make people worried and aware of their privacy interests. Therefore,
privacy appears as one of the pressing dilemmas in the contemporary globe that
requires holistic solutions. In response, the United Nations (UN), the European Union
(EU), and other international and regional entities along with individual States have
adopted numerous legal and policy measures. At the domestic level, a total of 145
countries have already passed data privacy laws, while others are attempting to amend
their existing ones. However, the legal recognition and protection of privacy can be
discussed under the following sub-heads: privacy in the international legal
instruments; privacy in the regional instruments, and privacy in the national legal
regimes.
To compare with the national and regional instruments, privacy was first recognized
by Article 12 of the Universal Declaration of Human Rights, 1948 (UDHR). Other
than the UDHR, numerous other international instruments also contain isolated
privacy provisions. The international instruments that incorporate isolated privacy
provisions can be classified into two sub-heads, such as (1) the UN instruments and
(2) the OECD instruments. Hence, the international instruments with privacy
provisions include, among others- (a) Universal Declaration of Human Rights, 1948
(UDHR); (b) International Covenant on Civil and Political Rights, 1966 (ICCPR); (c)
Convention on the Rights of the Child, 1989 (CRC); (d) International Convention on
the Protection of the Rights of All Migrant Workers and Members of Their Families,
1990; (e) UN General Assembly Guidelines Concerning Computerized Personal Data
Files, 1990; (f) Reports of the UN Special Rapporteur on the Right to Privacy (2016-
2020); (g) UN Personal Data Protection and Privacy Principles, 2018; (h) OECD
Guidelines on the Protection of Privacy, 1980, and (i) Revised OECD Privacy
Framework, [Link] UDHR, 1948: The UDHR is the first UN instrument that
recognizes privacy as one of the most important human rights, although subsequently,
the right has been recognized by numerous other international, regional, and domestic
legal and human rights instruments. It can be argued that through the UDHR, the
‘right to privacy’ became an international human right before it was constitutionally
recognized as a fundamental right. To recognize privacy as one of the human
rights, Article 12 of the UDHR is worded as follows: “No one shall be subjected to
arbitrary interference with his privacy, family, home or correspondence, nor to attacks
upon his Honor and reputation. Everyone has the right to the protection of the law
against such interference or attacks.”
The ICCPR, 1966: 18 years later since the adoption of the UDHR, privacy was
recognized in Article 17 of the ICCPR using a similar language to Article 12 of the
UDHR. The only difference between the two documents lies in the fact that Article 17
of the ICCPR adds the word ‘unlawful’ two times; before the term ‘interference’ and
‘attacks’ in the texts of Article 12 of the UDHR. Article 17 of the ICCPR, for
example, affirms that “No one shall be subjected to arbitrary or unlawful interference
with his privacy, family, home or correspondence, nor to unlawful attacks on his
Honor and reputation. Everyone has the right to the protection of the law against such
interference or attacks.”
The CRC, 1989: The Convention on the Rights of the Child, 1989 (CRC) is another
important UN document that attempts to ensure, among others, a child’s privacy
interest. Being adopted by the UN General Assembly (UNGA) Resolution number
44/25 of 20 November 1989, the CRC pledges for the protection of the diverse rights
of the children, including the right to privacy. The privacy provisions of this
convention are also comparable with Article 12 of the UDHR and Article 17 of the
ICCPR. For example, Article 16 of the CRC affirms that “ No child shall be subjected
to arbitrary or unlawful interference with his or her privacy, family, home or
correspondence, nor to unlawful attacks on his or her Honor and reputation. The child
has the right to the protection of the law against such interference or attacks.”
The statements in the above box are some selective remarks taken from the
observations, concluding remarks, or recommendations of five UN Reports of the
Special Rapporteur on the Right to Privacy (2016-2020). All these as shown here
neither describe the whole idea presented in those five documents nor the sum total
thereof, these are only some selected remarks that are compiled by the researcher. For
details, see UNHRHC, ‘Annual Reports’, United Nations Human Rights Office of the
High Commissioner.
The Personal Data Protection and Privacy Principles, 2018: The United Nation’s
firm conviction on privacy and personal data protection has been made explicit by
another notable initiative thereof, such as the ‘Personal Data Protection and Privacy
Principles’, 2018. On 11 October 2018, the UN High-Level Committee on
Management (HLCM), at its 36th Meeting, adopted a set of ‘Personal Data Protection
and Privacy Principles’, which set forth the essential basis for the processing of
personal data by, or on behalf of any organization of the UN while performing their
scheduled activities.
The aims of those principles include, inter alia, (i) harmonization of standards for the
protection of personal data among organizations of the UN; (ii) facilitating
responsible data processing for implementing the mandates of the organizations of
UN; and (iii) securing respect for human rights, fundamental freedoms, and
especially, the right to privacy. The said document further notes that the principles
contained therein will apply to personal data of any kind and be processed in any way.
The detailed contents of those principles can be seen at CEB: UN System Chief
Executives Board for Coordination, Personal Data Protection and Privacy Principles,
2018.
The Guidelines on the Protection of Privacy and Transborder Flows of Personal
Data, 1980 (OECD Privacy Guidelines): During the 1970s, it was speculated that
the data security rendered in national regimes were likely to be bypassed in trans-
border data processing activities. This ground reality made it compelling that certain
principles, rules or guidelines were to be farmed and agreed upon at the international
level. Eventually, two international organizations, such as the Organization for
Economic Cooperation and Development (OECD) and the Council of Europe (CoE)
had attempted to formulate the guiding principles for the protection of privacy and
harmonized data protection standards. On 23 September 1980, the OECD Council
formally ratified the Guidelines on the Protection of Privacy and Trans-Border Flows
of Personal Data that proceeded with the following objectives:To reduce differences
to a minimum degree among Member Nations regarding relevant national laws and
practices;To extend cooperation among the Member States concerning the protection
of personal data, avoiding undue interference regarding trans-national data flows, etc.
andTo eliminate all possible obstacles that may induce Member Nations to restrict
transborder data flows on the ground of correlated risks. he OECD Privacy Guidelines
was the first Trans-Atlantic agreement devised to protect data privacy that blended the
policies of national legal regimes to international legal standards concerning flows of
data. Although the Guidelines did not have any compelling authority over its Member
Nations but generated consensus concerning appropriate principles for data privacy.
Importantly, the principles enshrined in the OECD Guidelines laid down the founding
stones of modern data protection norms and principles. Greenleaf, for example,
remarked, together with Convention 108 of Council of Europe 1981, the OECD
Privacy Principles, 1980 placed the first-generation international data protection
standards. The Directive 95/46/EC represents the second-generation standards,
whereas the GDPR appears as the third-generation international data protection
standards. From its inception, the OECD Privacy Guidelines had notable impacts on
data privacy laws all over the world. Although it was a voluntary instrument, some
basic principles have become parts of the law later. One of the basic features of the
OECD Guidelines was that it applied to personal data of both the public and private
sectors. Part Two of the OECD Privacy Guidelines contains basic (privacy) principles
of national application. It includes eight data privacy principles, which form the basis
of the privacy principles of both Directive 95/46/EC, and the EU GDPR, 2018. The
precise titles of those principles include (1) collection limitation principle; (2) data
quality principle; (3) purpose specification principle; (4) use limitation principle; (5)
security safeguards principle; (6) openness principle; (7) individual participation
principle; and (8) accountability principle. For details, see OECD, Guidelines on the
Protection of Privacy and Transborder Flows of Personal Data, 1980.
The Revised OECD Privacy Framework, 2013: Being the first global initiative for
the core data protection regulations, the OECD Privacy Guidelines 1980 generated
huge implications throughout decades. In the words of Justice M. Kirby, the chair of
the OECD specialist team, ‘the continual acceptance of the OECD for a long period of
30 years have proved the utility of the Guidelines, and it was anticipated
too’. Notwithstanding the overwhelming attainment, an accord was growing to revise
the Guidelines. The modernization was required, as there raised inevitable questions
as to the effectiveness of the Guidelines due to the evolution of the Internet; world
wide web; search engines; social networking sites; location tracking technology;
biometrics and other technologies, etc. Finally, after conducting a rigorous review
process, the OECD adopted the Revised Guidelines on 9 September 2013. The
Revised Guidelines offers the following novel strategies:National privacy strategies:
While adequate laws are imperative, the strategic importance of privacy in this day
entails a multi-layered national strategy in association with the highest level of
[Link] management programmes: This mechanism works as the central
operational tool by which the organizations enforce the privacy [Link]
security breach notification: This provision comprises notices both to the authority
and the individuals affected by the security breach of personal data.[66]Above all, the
Revised OECD Guidelines, 2013 approaches the transborder data flow and details the
key elements that make it appear as a more responsible organization capable of
enhancing privacy enforcement. Being a move toward a continuous process, this
revised version of the Guidelines leaves the ‘basic principles’ intact of its original
version. To know some more details, see OECD, OECD Privacy Framework, 2013.
The regional legal and human rights instruments that contain privacy provisions may
be classified into two sub-groups, such as the non-EU instruments, and the EU
instruments. Usually, most of the non-EU instruments do not hold any binding effect
on the Member States, but the EU initiatives are generally binding on their Member
Nations. The EU instruments have had immense implications not only on the data
protection regimes of the Member States but also on other jurisdictions outside the
EU.
The major non-EU legal and human rights instruments, which comprise privacy
provisions, include, among others, (a) American Declaration of the Rights and Duties
of Man, 1948; (b) American Convention on Human Rights, 1969; (c) APEC Privacy
Framework, 2004; (d) Updated APEC Privacy Framework, 2015; (e) Madrid
Resolution, 2009; (f) ASEAN Human Rights Declaration, 2012, and ASEAN
Framework on Personal Data Protection, [Link] Declaration of the Rights
and Duties of Man, 1948: With several specific objectives, especially, the regional
unity and collaboration within the Member Nations, the Organization of American
States (OAS) emerged in 1948 by signing the Charter of the OAS in Bogotá,
Colombia that came into effect in December 1951. On 2 May 1948, the OAS adopted
the American Declaration of the Rights and Duties of Man, which contains some
provisions relevant to the protection of privacy. Affirming the right to protection of
Honor, personal reputation, private and family life, etc, Article V of the said
document states, ‘[e]very person has the right to the protection of the law against
abusive attacks upon his honor, his reputation, and his private and family life’.
Whereas Article IX and X guarantees the right to inviolability of the home and
transmission of correspondence. Article IX states, ‘[e]very person has the right to the
inviolability of his home’, while Article X asserts, ‘[e]very person has the right to the
inviolability and transmission of his correspondence’. It may be relevant to share that
this Declaration, otherwise referred to as the Bogota Declaration, was the world’s
second international human rights instrument of a general nature that was adopted less
than one year after the adoption of the UDHR.
American Convention on Human Rights, 1969: The American Convention on
Human Rights, 1969, otherwise known as the Pact of San José, was another notable
initiative of the Latin-American developments in human rights, which was adopted on
22 November 1969 at the Inter-American Specialized Conference on Human Rights,
San José, Costa Rica. The document came into effect nine months later, i.e., after the
11th ratification instrument was placed on 18 July 1978. It is a massive instrument
comprising a total of 82 articles, which affirms a plethora of civil and political
rights, including the right to privacy. For the protection of privacy, Article 11 of the
said document states that “Everyone has the right to have his honor respected, and his
dignity recognized. No one may be the object of arbitrary or abusive interference with
his private life, his family, his home, or his correspondence, or of unlawful attacks on
his honor or reputation. Everyone has the right to the protection of the law against
such interference or attacks.”]In 1979, an agreement was signed to create the Inter-
American Court of Human Rights and the Inter-American Commission on Human
Rights (IACHR), although the decisions of such Court are not mandatory on the
Member Economies. It is worth noting that both the American Convention on Human
Rights, 1969, and the European Convention on Human Rights and Fundamental
Freedoms, 1950 affirm the protection of privacy in the same language as enshrined in
the ICCPR.
The Updated APEC Privacy Framework, 2015 emphasizes the ‘interoperability’ in the
privacy frameworks among the Member Economies. The APEC Economies recognize
that personal data flows should not be stopped within the region, and accordingly, the
Member States should promote and encourage interoperability in diverse privacy
instruments to give effect to the APEC Privacy Framework itself. Moreover, the
leaders of the APEC Economies are in the belief that the global interoperability of the
privacy framework may also help individuals in asserting their right to privacy in a
global context and assist the authorities to strengthen cross-border privacy
enforcement. To compare with the OECD Privacy Guidelines, the APEC Privacy
Framework is manifestly weaker due to, inter alia, the lack of some principles, such as
the ‘purpose specification principle’ and the ‘openness’ principle. Contrarily, the
APEC Privacy Framework introduced some new principles, absent in the OECD
Privacy Guidelines, such as ‘preventing harm’, ‘choice’, and ‘due diligence in
transfers’ features of the ‘accountability principle’. Some notable criticisms of the
APEC Privacy Framework are- (1) APEC Privacy Framework imposes the burden of
proof on the consumers, (2) APEC privacy principles apply only to natural persons,
(3) the instrument speaks nothing about the automatic data collection processing or
tools, such as the usage of cookies. In fine, the APEC Privacy Framework cannot
achieve the desired goals unless the provisions of the Framework are enforced by the
Member Economies, although neither the Framework fixes any date of
commencement, nor it inflicts any penalty for infringement.
Madrid Resolution, 2009: The Madrid Resolution is another privacy and data
protection instrument that was adopted by the national data protection authorities of
50 countries on 5 November 2009 through an international conference held in Madrid.
The instrument introduced new values emphasizing the global nature of the right to
privacy, along with the underlying principles and guarantees by rendering better
protection for the rights of the individuals, especially in cross-border data flows. The
Resolution comprised two folded purposes in specific terms, such as (a) defining a
group of principles and rights ensuring an active and globally harmonized protection
for the privacy of personal information, and (b) facilitating the transborder flows of
personal data, essential for the interconnected world. Like all other typical data
protection instruments, the Resolution incorporated both the rights of the data
subjects, e.g., the right of access, right to rectify, right to object, etc., and the duties of
the controllers. However, unlike other data privacy instruments, the Resolution
required the data controllers to notify the data subjects about their data breach
incidents. The Document contained the following data protection principles (Basic
Principles): (1) the principle of lawfulness and fairness; (2) purpose specification
principle; (3) proportionality principle; (4) data quality principle; (5) openness
principle, and (6) accountability principle. There are also novelties in the Resolution
as put forward with the proactive measures, which was enumerated in Article 22 of
the Resolution. These include (1) procedures to prevent and detect breaches; (2)
appointment of data protection officers (DPOs); (3) periodic training, education and
awareness programs; (4) periodic audits; (5) adaptation of information systems and/or
technologies; (6) conducting privacy impact assessments; (7) adoption of codes of
practice, and (8) implementation of a response [Link], after the adoption of the
Madrid Resolution, numerous global giant corporations, such as Accenture, General
Electric, Google, Hewlett Packard, IBM, Intel, Microsoft, Oracle, Procter & Gamble,
and Walt Disney, endorsed a declaration welcoming this instrument.[84] The said
declaration also affirmed that the Madrid Resolution incorporated such principles,
procedures, rights, and obligations that any data protection regime should satisfy.
Thus, the Resolution appeared as a pioneering step toward making an internationally
binding data protection instrument and standard for data protection legislation.
Europe is the home for the world’s oldest, comprehensive, and massive data privacy
regulations ensuring at both national and regional levels. Through its transnational
bodies, the EU establishes itself as a stepping-stone in the development of the global
data protection framework. The EU data protection legal frameworks can be shown
by four distinct periods, such as (1) national data protection regimes (1970-1980); (2)
internationalization (1980-1981); (3) national implementation (1982-1994), and (4)
European harmonization (1995-2016/ 2018). It is noteworthy that through its
approach to adopting comprehensive privacy regulations, the EU challenges the US
dominance in the field. The notable EU instruments with immense global implications
include, inter alia, (a) European Convention on Human Rights and Fundamental
Freedoms, 1950; (b) Convention of Council of Europe, 1981; (c) Modernized
Convention of Council of Europe (Convention 108+), 2018; (d) Directive 95/46/EC,
1995, and (e) General Data Protection Regulation, 2018 (GDPR).
Convention 108 of the Council of Europe, 1981: The Convention for the Protection
of Individuals with regard to Automatic Processing of Personal Data, 1981,
[94] popularly known as the Convention 108 of the Council of Europe is deemed as
one of the crucial data protection instruments to be known as the ‘crowning
achievement in the domain of data protection after OECD Guidelines’. Convention
108 was adopted and opened for signature in 1981, and it became effective from
1985. Although the Convention was adopted within a regional arrangement, turned
later into the first binding international treaty. This has been witnessed through the
accession of Convention 108 by the non-EU Member States since [Link] central
focus of the Convention 108 was not to interpret privacy or personal data, rather
impose certain limitations on the processing of some sort of sensitive personal data.
Such limitations are needed because of the increasing use of computers in
organizational activities resulting in tremendous challenges to data privacy.
Convention 108 binds all signatories to have certain legislative steps domestically,
and this is why Convention 108 had an influential impact on the major European legal
frameworks. Convention 108 goes on isolation with nations having no privacy laws or
data harbors. Eventually, most of the nations in the European zone have been bound
to enact the data privacy bills. Among others, Chapter II of the Convention (Articles
4-11) incorporates the basic principles for data protection. The essence of these
principles renders wider scopes to suit them in diverse legal and constitutional
practices in the region. In 2001, the Council of Europe felt necessary to amend some
provisions of Convention 108. Accordingly, it introduced some essential changes
regarding the national supervisory authorities and transborder data flows to non-
Member States. The amendment commenced with the consultative committee thereof,
which produced a report requiring the evaluation of the Convention against the
challenges of the emerging ICTs. The report also identified some issues, challenges,
or dilemmas encircling the implementation of Convention 108 to which
modernization is the only possible approach to adopt. In turn, an Additional Protocol
regarding the supervisory authorities and transborder data flows was approved in
August 2001. The Convention 108 allows the collection and processing of personal
data, but without taking adequate legal safeguards, it restricts the processing of some
sorts of sensitive data, such as one’s race, sex, or health data, data relating to one’s
sexual life, religious, or political views, criminal records, etc. The Convention also
affords individuals the right to know about the stored personal data about them and to
have it corrected if necessary. Restrictions on the exercise of this right of the
individuals are guaranteed only on questions of compelling State security, national
defense, public interests, etc. Moreover, the Convention imposes restrictions on
transborder data transfer if the third countries do not ensure adequate legal safeguards
for the protection of personal data. From November 2004, the European Council was
found enthusiastic about sharing personal data for safety and security reasons. The
Hague Program allowed the law enforcement agencies within the EU to enter into
extensive databases of personal data and biometric data. In November 2012, the T-PD
Committee adopted an updated version of Convention 108 and its additional protocol
to modernize Convention 108 entirely. The updated version of the Convention 108 is
now advancing in multiple avenues. With all Council of Europe’s data protection
efforts, with the OECD Privacy Guidelines, 1980, and the Convention 108, together
they have set the global standards for data privacy regulations.
Besides, the modernized Convention 108 added additional requirements for numerous
issues, including the sensitive data; anonymization of personal data; appointment of
the independent Data Protection Authority (DPA); remedies of courts, restrictions on
data transfer, etc. Thus, it has become evident that the standards offered by the
modernized Convention 108 are manifestly higher than the standards of the previous
Convention 108 and its Additional Protocol of [Link], based on the
provisions of Article 23 (Accession by non-Member States ) of the Convention 108;
Article 27 (Accession by non-Member States or international organizations) of the
modernized Convention 108; Recital 105 (Consideration of International Agreements
for an Adequacy Decision) of the GDPR, and coupled with the wishes of the leaders
of the Council of Europe, the modernized Convention 108 is gradually making it
manifest that it is the only viable data privacy agreement across the globe. Although
the globalization of Convention 108+ is a too ambitious goal, as evidenced by the
slow rate of adoption of the document since 2013, it is nevertheless, becoming
globalized through its accession outside Europe.
Directive 95/46/EC, 1995: The Council of Europe has had many success stories in
devising numerous initiatives for ensuring the protection of privacy, processing of
personal data, and the free flows of data. At the same time, the Council witnessed
several challenges too in terms of maintaining consistency in all its data protection
measures among the Member States. Therefore, it was essential to take an attempt for
the harmonization of the regional data protection means and measures at the national
level. After almost five years of intense initiatives and negotiations, this was
succeeded by the adoption of ‘Directive 95/46/EC on the Protection of Individuals
with regard to the Processing of Personal Data and On the Free Movement of such
Data’ (Directive 95/46/EC) on 24 October 1995.[103] The provisions of this
instrument have lost their previous status and importance due to subsequent
abolishment by the GDPR, [Link] Data Protection Regulation (GDPR),
2018: Appearing as a buzzword, the GDPR has had immense implications on global
data protection regulations. Based on omnibus legal substance, extensive
extraterritorial scope, and influential market power of the EU, the GDPR diffuses
globally as a standard for data protection law. Therefore, it has become a trend of
enacting or amending the existing data privacy legislation in conformity with GDPR
across the globe. The roles, influences, legal, textual, and contextual highness of
GDPR reach such a landmark and diffuses globally in a manner that one must have a
minimum understanding about the acronym ‘GDPR’ unless living under the rock. The
lifecycle of GDPR began in January 2012 through a proposal of the European
Commission (EC), which was approved on 27 April 2016, and finally, came into
effect on 25 May 2018. It replaced the previous Directive 95/46/EC with several
intense changes in almost everything, ranging from technology to advertising, and
medicine to banking. It is considered as one of the most comprehensive and far-
reaching pieces of Regulations, which address all possible challenges that people
might face regarding their personal data in the digital age. After the adoption of the
GDPR, it is argued that now the EU residents would know how businesses use their
data, and how can the EU utilize the best opportunities of the data-based economy.
Generally, companies required clarity to extend business operations safely throughout
the region, and recent data scandals required to have clearer and stricter data
protection regulations, and given this, the EU performed the right job. Under Article
3, the GDPR applies against any data controller or processor with an establishment in
the EU, which processes personal data of the EU residents regardless of the place of
such processing. Even the GDPR applies against foreign controllers or processors,
who process the personal data of the EU residents by offering goods or services and
monitor their behavior. Therefore, the long arm of GDPR is extended to cover the
whole world, holding the view that you are targeted by EU law if you target or
monitor EU residents. This extraterritorial application of the GDPR gives rise to
tension worldwide as non-compliance thereof leads to severe fines and penalties of up
to €20 million or 4% of annual turnover, whichever is higher.
Thus, the implications of GDPR are not the hypothetic possibility, rather a true reality
and these have been evidenced by the wave of GDPR-creep data protection legislation
across the globe. Besides, global tech giants are shaping their business models in
compliance with the provisions of the GDPR. Microsoft, for example, proclaimed to
treat all users under the rules of the GDPR regardless of their location and empower
them to customize their personal data accessing to the personal dashboard. Facebook
has changed their privacy settings and tools in compliance with the
GDPR. Meanwhile, Google has updated its products and privacy policies in
conformity with the GDPR. Even Google made its privacy policy simple and clearer
than earlier to conform to European law. Notably, the GDPR is a huge,
comprehensive, and complex document containing 11 chapters; 196 recitals; 99
articles, and 88 pages with 55,000 words. Chapter I includes the ‘General Provisions’
covering, inter alia, (1) subject-matter and objectives (art 1); (2) material scope (art
2); (3) territorial scope (art 3), and (4) definitions (art 4). Chapter II includes the key
privacy principles, such as (1) principles relating to the processing of personal data
(art 5); (2) lawfulness of processing (art 6); (3) conditions for consent (art 7); (4)
conditions applicable to child’s consent (art 8); (5) processing of special categories of
personal data (art 9) and (6) processing of personal data relating to criminal
convictions and offences (art 10).Chapter III includes a wide range right of the data
subjects, including- (1) right to transparent information (arts 12-14); (2) right of
access by the data subject (art 15); (3) right to rectification (art 16); (4) right to
erasure (right to be forgotten) (art 17); (5) right to restriction of processing (art 18);
(6) right to data portability (art 20); (7) right to object (art 21), and (8) right not to be
subject to automated decision making and profiling etc (art 22). The other chapters
include numerous important provisions, such as Chapter IV: the obligations of the
controllers and processors (arts 24-43); Chapter V: the transfers of personal data to
third countries or international organizations (arts 44-48); Chapter VI: independent
supervisory authorities (arts 51-54); Chapter VII: cooperation and consistency (arts
60-63); Chapter VIII: remedies, liability and penalties (arts 77-84); Chapter IX:
provisions relating to specific processing situations (arts 85-91); Chapter X: delegated
acts and implementing acts (arts 92-93), and Chapter XI: final provisions (arts 94-
99).Among others, the GDPR has tremendous effects on how data is managed within
the EU and plays a significant role in shaping global data protection regulations.
Recently, the UN Special Rapporteur on the right to privacy, for example, remarks
that ‘[t]he protection of personal information online should be a priority with the
adoption of provisions equivalent or superior to GDPR, for countries that are not
parties to the Regulation’. Consequently, many countries in Europe other than the EU
Member States, such as Iceland, Liechtenstein, Norway and Switzerland changed
their data protection laws in harmony with the GDPR. Even other than Europe,
numerous other countries from Africa, Asia, the Caribbean and Latin America are
either enacting new data privacy laws or amending previous laws in line with the
GDPR. Law firm Ius Labors show that there are at least 24 countries outside the EU
in which there exist GDPR-related legal developments, decisions, or trends of
harmonization. Even the inclination of enacting a comprehensive data privacy bill at
the US State level is very high than in previous times. Following the footstep of the
CCPA, the Maine and Nevada States have also enacted the comprehensive bill. Many
other US States, including Hawaii, Illinois, Massachusetts, Minnesota, New Jersey,
New York, Pennsylvania, Rhode Island, and Washington have either introduced the
comprehensive data privacy bills or have draft bills undergoing the examination
process. Indeed, GDPR-styled privacy standard is found not only in the ‘First World’,
but also in the ‘Second World’, and the ‘Third World’ countries. Hence, Giovanni
Buttarelli refers to the GDPR as a clarion call for a unique global data privacy gold
standard. Whereas Paul M. Schwartz remarks that “EU data protection law is playing
an increasingly prominent role in today’s global technological environment. The
The trend of collecting personal data is as old as human society. It might not be the
oldest profession, but one of the oldest habits. In particular, since the 1960s onwards,
the use of personal data has been dramatically increased because of the paradigm
shifts in socio-economic and industrial settings. In administering this bulk of reforms
activities, the governments were to process huge amounts of personal data, and this
data processing has become rampant after the emergence of the [Link], the
computer was employed in research and planning works, but subsequently, it started
operating in every sphere of human affairs. The creation of the Internet, the World
Wide Web (WWW), and the constant progress of ICT technologies facilitated the
collection, processing, and storing of large-scale personal data. Later, big data
analytics, cloud computing, data mining, artificial intelligence, machine learning, IoT
technologies, etc. have revolutionized some emerging business models that process
personal data to an unprecedented level. This atmosphere requires comprehensive
data protection regulations to strike the balance among the interests of the
government, businesses, and data [Link] respond, there has been a global trend
of adopting data privacy legislation since the 1970s. Starting from the Hessian Data
Protection Act, 1970 (Hessisches Datenschutzgesetz) of Germany, many other
Western nations, including Austria, Denmark, France, Norway, Sweden, and the USA
adopted privacy legislation in the early 1970s. Arguably, the Hessian Data Protection
Act was considered a regional endeavour, whereas Sweden was the first nation to
enact the data protection law (Datalagen 1973) in the world. In the USA, the first
federal legislative effort regarding privacy was the Privacy Act of 1974, even though
the Fair Credit Reporting Act of 1970 contains several provisions of data privacy,
e.g., provisions regarding credit reporting businesses, [Link] in the footsteps of
Western countries, there has been a remarkable development in privacy enactments
throughout decades. For instance, in the decade of 2010-2019, a total of 62 new
countries enacted data privacy laws, which was significantly higher than the previous
decade. In course of time, the per decade increase of the countries enacting data
privacy laws appears very much impressive. The per decade number of countries
enacting new data protection laws was 10 in the 1970s, 10 in the 1980s, 20 in the
1990s, 40 in the 2000s, and 62 in the 2010s.