info@josefelgueroso.com
2021-07-28
The Council of Europe adopted in 1981 the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, also known as Convention 108. It was the first binding international treaty on data protection, and its signatories include countries from three continents. In 2018, the Council of Europe adopted a protocol that will amend the Convention once it enters into force.
This article provides a summary of the Convention as amended by the 2018 protocol.
Given the development of information technology in the preceding decades, the countries of the Council of Europe negotiated and adopted the Convention in 1981 to ensure the protection of fundamental rights in connection with the processing of personal data, and in particular the right to privacy. The purpose of the Convention is to protect all individuals within the jurisdiction of the signatory countries regarding the processing of their personal data, regardless of their nationality or place of residence.
The Convention applies to the processing of personal data by private and public entities. Although the Convention is binding on the countries that have ratified it, it is not subject to the jurisdiction of the European Court of Human Rights.
The Convention covers the automated and non-automated processing of personal data. Manual processing may fall under the scope of the Convention if the processing is structured in a way that allows searching by individual.
51 countries have ratified the Convention, including all member states of the Council of Europe and the European Union. Because the Convention is open to ratification by countries that are not members of the Council of Europe, it has also been ratified by Uruguay, Mauritius, Senegal, and Tunisia.
In the decades that followed the adoption of the Convention, information technology has become widespread and more advanced, the processing of personal data has become global, and the volume of data flows has increased. The Council of Europe adopted the 2018 Protocol to modernize the Convention to address the privacy challenges emerging from new information and communication technologies.
The modernization aims to preserve the technologically-neutral nature of the Convention and its compatibility with other legal frameworks. It also maintains the open character of the Convention, as countries outside the Council of Europe can ratify it.
The modernized Convention adds genetic and biometric data to the list of sensitive data. The original Convention already mandated additional safeguards for the processing of personal data regarding racial origin, political opinions, beliefs, health, sexual life, and criminal convictions.
The Convention recognizes the data processing principles of transparency, lawfulness, proportionality, accountability, data minimization, privacy by design, privacy by default, and data security. It also requires data controllers to notify the supervisory authorities if a data breach has occurred; the data controller may also have to notifiy individuals if the data breach can lead to discrimination, identify theft, financial loss, damage to reputation, or loss of confidentiality of data protected by professional secrecy.
The processing of personal data must have a legal basis. If the basis is the individual's consent, it must be free, specific, informed, and unambiguous. Other valid bases are a contract, the individual's vital interest, and a legal obligation of the controller.
Personal data must be collected for explicit, specified, and legitimate purposes, and must not be processed in a manner incompatible with those purposes. Personal data must not be preserved longer than necessary for the processing.
Controllers must inform individuals of:
A key purpose of the Convention is to allow individuals to have knowledge and control over the processing of personal data related to them.
The Convention recognizes that individuals have the right:
Transfers to signatory countries
Signatory countries must not prohibit or subject to special authorization the transfer of personal data to a recipient subject to the jurisdiction of a signatory country. The Convention contains two exceptions to that principle: a signatory country may prohibit the transfer if (1) the transfer would lead to a circumvention of the Convention or (2) if the signatory country is bound by the data protection rules of a regional international organization.
Transfers to third countries
If the recipient of the personal data is located in a third country, the transfer of personal data must provide an appropriate level of protection. An appropriate level of protection can be achieved by the law of the third country or by contracts or other binding instruments adopted by the persons involved in the transfer and processing of personal data. The following factors indicate whether a transfer provides an appropriate level of protection:
The Convention allows signatory countries to allow the transfer of personal data to a third country if:
The Convention allows certain exceptions to its provisions, if they are provided by law, respect the essence of fundamental rights, and are necessary and proportionate to protect a legitimate interest, such as national security, criminal investigations, and freedom of expression.
In addition, the Convention recognizes exceptions for archiving in the public interest, scientific or historical research purposes, or statistical purposes, when there is no risk of infringement of fundamental rights.
Given that countries from three continents have ratified it, the Convention is the closest thing to an international standard on data protection that currently exists.
The Convention complements other legal frameworks, in particular the European Union's. The European Data Protection Regulation mentions accession to and implementation of the Convention as criteria to determine whether a third country offers an adequate level of data protection.
Given the technologically-neutral nature of the Convention and the updates provided by the 2018 protocol, the Convention is likely to remain an international reference for the protection of rights in the context of data processing.
Original Convention 108 (1981)
Convention 108 - Amending Protocol (2018)
Modernized Convention 108 - Explanatory Report
Handbook on European Data Protection Law (2018)