Opinion Leader: Nations Begin to Cooperate to Protect Data Privacy Across Borders
The recent Facebook Cambridge Analytica scandal made us realize how much strong data protection rules are important for society as a whole, including for the very functioning of the democratic process. These and other developments have shown that the protection of privacy, as a central individual right and a democratic imperative, but also as an economic necessity, is crucial: Without consumers’ trust in the way their data is handled, our data-driven economies will not thrive.
The General Data Protection Regulation (GDPR), which entered into application May 25, is the European Union’s response to these challenges and opportunities. It seeks to create a virtuous circle between better protection of privacy as a fundamental right; enhanced confidence of consumers in how the privacy and security of their data is guaranteed, in particular in the online world; and economic growth.
While building on foundations that have been in place for more than 20 years, under a previous directive of 1995, the GDPR contains important innovations. Many of these changes are particularly relevant to foreign companies doing business in Europe. They will now offer their goods and services in a harmonized and simplified regulatory environment. Instead of having to deal with 28 different data protection laws and 28 different regulators, one set of rules will apply and will be interpreted in a uniform way throughout the continent. Obligations to notify data processing operations or obtain prior authorization from data protection authorities will be scrapped. A number of key concepts are clarified and adapted to the needs of the digital economy. International data transfers from the EU will be simplified and facilitated. All this will mean increased legal certainty and a significant reduction in compliance costs and red tape.
The GDPR is also based on a modern approach to regulation that rewards new ideas, methods and technologies to address privacy and data security. The principles of data protection “by design” and “by default” will create incentives to develop innovative solutions from the earliest stages of development. The so-called risk-based approach means that companies that limit the level of risk of their processing operations will not be subject to a number of obligations. Co-regulatory tools, such as codes of conduct or certification mechanisms, are introduced to help companies managing and demonstrating compliance. Last but not the least, new rights and safeguards, such as the right to portability or the notification of data breaches, will put individuals in better control of their data. Empowering consumers means also ensuring that they feel safer and more confident when sharing their data. These are just a few examples of how the effective protection of a fundamental right can go hand in hand with unleashing the full potential of the digital economy.
These developments are of course not limited to Europe. Today, more than 120 countries, from almost all regions of the globe, have data privacy laws in place. And many of the new or modernized laws tend to be based on common elements: a comprehensive legislation (rather than sectoral rules), a set of enforceable rights, the setting up of an independent supervisory authority, etc. While improving the level of protection of personal data when transferred abroad, this developing convergence offers new opportunities to facilitate trade as well as cooperation between public authorities, both of which increasingly rely on the exchange of personal data.
The European Commission is committed to intensifying its dialogue with its international partners in this area, to promote and further develop elements of convergence between privacy regimes. This includes the possibility of adopting adequacy findings allowing unhindered data flows, as currently being discussed with Japan and South Korea. It involves contributing to the elaboration of much-needed international standards such as in the framework of the Council of Europe’s Convention 108, which has an increasingly universal membership. Fostering convergence also means learning from each other through the exchange of experience and best practices. This type of dialogue is essential in our interconnected world if we want to address challenges that are increasingly global in nature and scope.
Věra Jourová is European commissioner for justice, consumers and gender equality.
This article is part of Caixin Global’s Opinion Leader series of commentaries on global topics we feel would be of interest to our readers.
- 1Caixin View: China Feels Chill From Trouble in Turkey
- 285-Year-Old Petitioner, in Poor Health, Denied Parole
- 3In Depth: HNA Charts New Course Back to Airline Basics
- 4On Beijing’s Orders, Tsinghua May Give Up Control of Chipmaker Units
- 5Banned From Planes and Trains, Jia Yueting Hands Over U.S. Car Startup’s China Business
- 1Power To The People: Pintec Serves A Booming Consumer Class
- 2Largest hotel group in Europe accepts UnionPay
- 3UnionPay mobile QuickPass debuts in Hong Kong
- 4UnionPay International launches premium catering privilege U Dining Collection
- 5UnionPay International’s U Plan has covered over 1600 stores overseas