Skip to content
Literature · International Data Privacy Law EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

GDPR codes of conduct and their (extra)territorial features: a tale of two systems

Carl Vander Maelen — International Data Privacy Law

Carl Vander Maelen — International Data Privacy Law

International Data Privacy Law
DOI

How it connects

Full text

While the European Union’s 1995 Data Protection Directive1 (hereafter: DPD or 1995 Directive) was an important regulatory innovation to create a data protection framework, it was drafted during a time when the data controller, data processor, data subject, and the means for data processing operations were usually located in the same country.2 Rapid technical advancements in the years after the adoption of the 1995 Directive meant that the techniques for the collection, storage, processing, and sharing of personal data changed or evolved.3 Crucially, data flows became increasingly global and important to businesses.4 A clear challenge for the European legislator came into focus: how could the follow-up to the DPD remain effective in protecting European citizens while acknowledging these new (technical) realities? The General Data Protection Regulation (GDPR)5 and its Article 3 form the EU’s answer to that question. It largely codifies the case law of the Court of Justice of the European Union (CJEU) that had extended the reach of the application of the 1995 Directive, such as through the Google Spain judgment.6 However, it also introduces new elements since the text of the GDPR is directly applicable in all EU Member States7 and it loosens ‘[t]he territorial restriction of application’.8