Jose Felgueroso
Abogado | Attorney

  • Home
  • Blog


Summary of the Council of Europe's Convention for the Protection of Personal Data (Convention 108)

info@josefelgueroso.com

Versión en español

2021-07-28

The Council of Europe adopted in 1981 the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, also known as Convention 108. It was the first binding international treaty on data protection, and its signatories include countries from three continents. In 2018, the Council of Europe adopted a protocol that will amend the Convention once it enters into force.

This article provides a summary of the Convention as amended by the 2018 protocol.



Source: National Archives and Records
Administration (Wikimedia Commons)

Background

Given the development of information technology in the preceding decades, the countries of the Council of Europe negotiated and adopted the Convention in 1981 to ensure the protection of fundamental rights in connection with the processing of personal data, and in particular the right to privacy. The purpose of the Convention is to protect all individuals within the jurisdiction of the signatory countries regarding the processing of their personal data, regardless of their nationality or place of residence.

The Convention applies to the processing of personal data by private and public entities. Although the Convention is binding on the countries that have ratified it, it is not subject to the jurisdiction of the European Court of Human Rights.

The Convention covers the automated and non-automated processing of personal data. Manual processing may fall under the scope of the Convention if the processing is structured in a way that allows searching by individual.

51 countries have ratified the Convention, including all member states of the Council of Europe and the European Union. Because the Convention is open to ratification by countries that are not members of the Council of Europe, it has also been ratified by Uruguay, Mauritius, Senegal, and Tunisia.

Modernization of the Convention

In the decades that followed the adoption of the Convention, information technology has become widespread and more advanced, the processing of personal data has become global, and the volume of data flows has increased. The Council of Europe adopted the 2018 Protocol to modernize the Convention to address the privacy challenges emerging from new information and communication technologies.

The modernization aims to preserve the technologically-neutral nature of the Convention and its compatibility with other legal frameworks. It also maintains the open character of the Convention, as countries outside the Council of Europe can ratify it.

The modernized Convention adds genetic and biometric data to the list of sensitive data. The original Convention already mandated additional safeguards for the processing of personal data regarding racial origin, political opinions, beliefs, health, sexual life, and criminal convictions.

Principles

The Convention recognizes the data processing principles of transparency, lawfulness, proportionality, accountability, data minimization, privacy by design, privacy by default, and data security. It also requires data controllers to notify the supervisory authorities if a data breach has occurred; the data controller may also have to notifiy individuals if the data breach can lead to discrimination, identify theft, financial loss, damage to reputation, or loss of confidentiality of data protected by professional secrecy.

The processing of personal data must have a legal basis. If the basis is the individual's consent, it must be free, specific, informed, and unambiguous. Other valid bases are a contract, the individual's vital interest, and a legal obligation of the controller.

Personal data must be collected for explicit, specified, and legitimate purposes, and must not be processed in a manner incompatible with those purposes. Personal data must not be preserved longer than necessary for the processing.

Controllers must inform individuals of:

  • their identity and place of residence or establishment;
  • the legal basis for the processing;
  • the categories of personal data processed;
  • the recipients or categories of recipients of the personal data; and
  • the means of exercising rights.

Rights

A key purpose of the Convention is to allow individuals to have knowledge and control over the processing of personal data related to them.

The Convention recognizes that individuals have the right:

  • not to be subject to a decision significantly affecting the individual based solely on an automated processing of data without having the views of the individual taken into consideration;
  • to request and obtain confirmation of the processing of personal data relating to the individual and any other information that the controller is required to provide in order to ensure the transparency of processing;
  • to request and obtain information about the reasoning underlying data processing if the results of that processing are applied to the individual;
  • to object at any time to the processing of personal data concerning the individual, unless the controller demonstrates legitimate grounds for the processing that override the individual's interests or rights;
  • to request and obtain rectification or erasure of personal data if the processing violates the provisions of the Convention;
  • to have a remedy if the individual's rights under the Convention have been violated; and
  • to benefit from the assistance of a national supervisory authority in the exercise of the individual's rights under the Convention.

International Transfers of Personal Data

Transfers to signatory countries

Signatory countries must not prohibit or subject to special authorization the transfer of personal data to a recipient subject to the jurisdiction of a signatory country. The Convention contains two exceptions to that principle: a signatory country may prohibit the transfer if (1) the transfer would lead to a circumvention of the Convention or (2) if the signatory country is bound by the data protection rules of a regional international organization.

Transfers to third countries

If the recipient of the personal data is located in a third country, the transfer of personal data must provide an appropriate level of protection. An appropriate level of protection can be achieved by the law of the third country or by contracts or other binding instruments adopted by the persons involved in the transfer and processing of personal data. The following factors indicate whether a transfer provides an appropriate level of protection:

  • the type of data;
  • the purpose and duration of processing;
  • the respect for the rule of law by the third country;
  • the third country's compliance with the principles of the Convention;
  • the individual's ability to defend his or her interests;
  • the general and sectoral rules applicable in the third country; and
  • the applicable professional and security rules.

The Convention allows signatory countries to allow the transfer of personal data to a third country if:

  • the individual has given explicit, specific, and free consent;
  • the individual's interests require it;
  • the law indicates legitimate interests in a necessary and proportional manner; or
  • the transfer is a necessary and proportionate exercise of freedom of expression.

Limitations

The Convention allows certain exceptions to its provisions, if they are provided by law, respect the essence of fundamental rights, and are necessary and proportionate to protect a legitimate interest, such as national security, criminal investigations, and freedom of expression.

In addition, the Convention recognizes exceptions for archiving in the public interest, scientific or historical research purposes, or statistical purposes, when there is no risk of infringement of fundamental rights.

Conclusion

Given that countries from three continents have ratified it, the Convention is the closest thing to an international standard on data protection that currently exists.

The Convention complements other legal frameworks, in particular the European Union's. The European Data Protection Regulation mentions accession to and implementation of the Convention as criteria to determine whether a third country offers an adequate level of data protection.

Given the technologically-neutral nature of the Convention and the updates provided by the 2018 protocol, the Convention is likely to remain an international reference for the protection of rights in the context of data processing.

Sources

Original Convention 108 (1981)

Convention 108 - Amending Protocol (2018)

Modernized Convention 108

Modernized Convention 108 - Explanatory Report

Handbook on European Data Protection Law (2018)