GDPR codes of conduct and their (extra)territorial features: a tale of two systems
Carl Vander Maelen — International Data Privacy Law
Carl Vander Maelen — International Data Privacy Law
How it connects
References
Related across sources
Full text
While the European Union’s 1995 Data Protection Directive1 (hereafter: DPD or 1995 Directive) was an important regulatory innovation to create a data protection framework, it was drafted during a time when the data controller, data processor, data subject, and the means for data processing operations were usually located in the same country.2 Rapid technical advancements in the years after the adoption of the 1995 Directive meant that the techniques for the collection, storage, processing, and sharing of personal data changed or evolved.3 Crucially, data flows became increasingly global and important to businesses.4 A clear challenge for the European legislator came into focus: how could the follow-up to the DPD remain effective in protecting European citizens while acknowledging these new (technical) realities? The General Data Protection Regulation (GDPR)5 and its Article 3 form the EU’s answer to that question. It largely codifies the case law of the Court of Justice of the European Union (CJEU) that had extended the reach of the application of the 1995 Directive, such as through the Google Spain judgment.6 However, it also introduces new elements since the text of the GDPR is directly applicable in all EU Member States7 and it loosens ‘[t]he territorial restriction of application’.8