HACIA UN NUEVO DERECHO EUROPEO DE PROTECCIÓN DE DATOS TOWARDS A NEW EUROPEAN DATA PROTECTION REGIME
Artemi Rallo Lombarte Rosario García Mahamut Editores
Valencia, 2015
Copyright ® 2015 Todos los derechos reservados. Ni la totalidad ni parte de este libro puede reproducirse o transmitirse por ningún procedimiento electrónico o mecánico, incluyendo fotocopia, grabación magnética, o cualquier almacenamiento de información y sistema de recuperación sin permiso escrito de los autores y del editor. En caso de erratas y actualizaciones, la Editorial Tirant lo Blanch publicará la pertinente corrección en la página web www.tirant.com (http://www. tirant.com).
© Artemi Rallo Lombarte Rosario García Mahamut
© TIRANT LO BLANCH EDITA: TIRANT LO BLANCH C/ Artes Gráficas, 14 - 46010 - Valencia Telfs.: 96/361 00 48 - 50 Fax: 96/369 41 51 Email:tlb@tirant.com http://www.tirant.com Librería virtual: http://www.tirant.es ISBN: 978-84-9086-391-6 MAQUETA: Tink Factoría de Color
Si tiene alguna queja o sugerencia, envíenos un mail a: atencioncliente@tirant.com. En caso de no ser atendida su sugerencia, por favor, lea en www.tirant.net/index.php/empresa/politicas-deempresa nuestro Procedimiento de quejas.
ÍNDICE PRESENTACIÓN........................................................................................... 13 Artemi Rallo Lombarte y Rosario García Mahamut Catedráticos de Derecho Constitucional Universidad Jaume I de Castellón PRÓLOGO..................................................................................................... 15 Peter Hustinx Ex Supervisor Europeo de Protección de Datos (2004-2014)
I. ESTUDIO INTRODUCTORIO DATA PROTECTION PACKAGE Y PARLAMENTO EUROPEO.............. 29 Juan Fernando López Aguilar Catedrático de Derecho Constitucional Ex Presidente de la Comisión de Libertades, Justicia e Interior Parlamento Europeo
II. UNA VISIÓN GLOBAL DATA ORIGIN AND THE PROPOSED REGULATION............................ 85 Martin Abrams Executive Director The Information Accountability Foundation
“DIRITTO ALLA PROTEZIONE DEI DATI DI CARATTERE PERSONALE”: APPUNTI DI UN VIAGGIO NON ANCORA CONCLUSO........ Roberto Lattanzi
103
Direttore del Servizio Studi e Documentazione Garante per la Protezione dei Dati Personali
REFORMING DATA PROTECTION IN EUROPE AND BEYOND: A CRITICAL ASSESSMENT OF THE SECOND WAVE OF GLOBAL PRIVACY LAWS..................................................................................................... Omer Tene Associate Professor College of Management Haim Striks School of Law (Israel) Vice President of Research and Education International Association of Privacy Professionals
143
8
Índice
SEPARATED BY COMMON GOALS: A U.S. PERSPECTIVE ON NARROWING THE U.S.- EU PRIVACY DIVIDE................................................ 207 David Vladeck Professor of Law Georgetown University Law Center
III. ANÁLISIS DE LAS CLAVES DE LA REFORMA EL DATA PROTECTION OFFICER EN EL MARCO DE LA RESPONSABILIDAD PENAL DE LAS PERSONAS JURÍDICAS....................................... 247 José R. Agustina Universitat Internacional de Catalunya Consultor en Molins & Silva Defensa Penal y Corporate Defense
Axel-Dirk Blumenberg Abogado en Molins & Silva Defensa Penal y Corporate Defense
EL PODER DEL USUARIO DIGITAL.......................................................... 275 Cecilia Álvarez Rigaudias Abogada de Uría Menéndez
REFORZANDO EL EJERCICIO DEL DERECHO A LA PROTECCIÓN DE DATOS PERSONALES: VIEJAS Y NUEVAS FACULTADES................. 311 Mónica Arenas Ramiro Profesora Contratada Doctora de Derecho Constitucional Universidad de Alcalá
LA PROTEZIONE DEI DATI PERSONALI NELLA “SOCIETÀ IN RETE”............................................................................................................. 373 Salvatore Bonfiglio Università degli Studi Roma Tre
THE ACCOUNTABILITY CULTURE IN ITS EUROPEAN UNION DRESS. STICKS BUT NO CARROTS TO MAKE THE PROPOSED DATA PROTECTION REGULATION WORK............................................ 389 Paul de Hert Vrije Universiteit Brussel & Tilburg University
Dimitra Stefanatou Tilburg University
Índice
9
EL INTERÉS LEGÍTIMO COMO PRINCIPIO PARA LEGITIMAR EL TRATAMIENTO DE DATOS................................................................................ 411 Javier Fernández-Samaniego Paula Fernández-Longoria Abogados Bird & Bird LLP
ON DIGITAL IDENTITY: CONSIDERATIONS FROM THE ITALIAN EXPERIENCE................................................................................................. 463 Giusella Finocchiaro Full Professor of Civil Law and Internet Law University of Bologna
ELECCIONES Y PROTECCIÓN DE DATOS: LOS GRANDES DESAFÍOS PARA LA UNIÓN EUROPEA......................................................... 481 Rosario García Mahamut Catedrática de Derecho Constitucional Universidad Jaume I de Castellón Ex Vocal de la Junta Electoral Central
CURTAILING A RIGHT IN FLUX: RESTRICTIONS OF THE RIGHT TO PERSONAL DATA PROTECTION........................................................ 513 Gloria González Fuster Vrije Universiteit Brussel
EL ROL DE LOS PROFESIONALES DE LA PRIVACIDAD....................... 539 Ricard Martínez Martínez Universidad de Valencia Presidente de la Asociación Profesional Española de Privacidad
LA ACTIVIDAD PERIODÍSTICA EN LOS ORDENAMIENTOS NACIONALES Y EUROPEO SOBRE PROTECCIÓN DE DATOS........................ 571 Cristina Pauner Chulvi Profesora Titular de Derecho Constitucional Universitat Jaume I de Castellón
LA PROTECCIÓN DE LOS DATOS DE SALUD........................................ 621 José María Pérez Gómez Letrado de la Administración de la Seguridad Social
10
Índice
LA REGULACIÓN DE LAS MEDIDAS DE SEGURIDAD........................... 669 Javier Puyol Montero Abogado. Socio de ECIX GROUP Magistrado excedente Consultor TIC
EL DEBATE EUROPEO SOBRE EL DERECHO AL OLVIDO EN INTERNET.......................................................................................................... 703 Artemi Rallo Lombarte Catedrático de Derecho Constitucional Universidad Jaume I de Castellón Ex Director de la Agencia Española de Protección de Datos
COOPERACIÓN Y COORDINACIÓN ENTRE AUTORIDADES DE PROTECCION DE DATOS........................................................................... 739 Artemi Rallo Lombarte Catedrático de Derecho Constitucional
Rosario García Mahamut Catedrática de Derecho Constitucional
Jorge Viguri Cordero Investigador del Área de Derecho Constitucional Universidad Jaume I de Castellón
LA NOTIFICACIÓN DE BRECHAS DE SEGURIDAD............................... 771 Carlos Alberto Sáiz Peña Socio de Ecix Group Director del Data Privacy Institute (ISMS Forum)
TRANSPARENCIA Y PROTECCIÓN DE DATOS: NUEVOS DESAFÍOS PARA LA GARANTÍA EUROPEA DE LOS DERECHOS FUNDAMENTALES.............................................................................................................. 819 Beatriz Tomás Mallén Profesora Titular de Derecho Constitucional Universidad Jaume I de Castellón
THE EUROPEAN DATA PROTECTION ADEQUACY DECISION AND ITS EFFECTS ON THIRD COUNTRIES. A FAILED AND INADEQUATE STANDARD FOR LATIN AMERICA.............................................. 853 Cristos Velasco Founder of Protección Datos México (ProtDataMx)
Índice
LOS MECANISMOS DE CERTIFICACIÓN (CÓDIGOS DE CONDUCTA, SELLOS Y MARCAS).............................................................................. Jorge Viguri Cordero
11 901
Investigador del Área de Derecho Constitucional Universitat Jaume I de Castellón
PRIVACY IMPACT ASSESSMENT POLICY ISSUES.................................. 959 David Wright Inga Kroener Trilateral Research & Consulting
Presentación El 25 de Enero de 2012 la Comisión Europea lanzaba su Proyecto de Reglamento General de Protección de Datos y, con ello, iniciaba un largo camino —hoy, tres años más tarde, todavía inconcluso— de discusión y análisis sobre las necesidades de revisión del marco legal europeo de protección de datos. Este libro se enmarca en la voluntad de un muy reconocido y prestigioso elenco de casi treinta expertos españoles, europeos y mundiales de contribuir, desde sus diferentes orígenes (instituciones legislativas, autoridades de supervisión, academia, think tanks, asesoramiento y consultoría, etc.) y pericias teórico-prácticas, a perfeccionar el iter legislativo de tan ambiciosa iniciativa legislativa y a avanzar una vanguardista primera valoración sobre una normativa de inminente aprobación y singular impacto. El origen de esta propuesta editorial hay que buscarlo en los proyectos de investigación financiados por el Ministerio de Economía y Competitividad (DER 2012-34764) y la Universidad Jaume I (P1-1B2012-12) sobre “La reforma del sistema europeo de protección de datos” en los que se integran numerosos investigadores de las Universidades Jaume I, Valencia, Alcalá, Oxford, Roma Tres y Bruselas. En particular, la preparación de esta obra colectiva y monográfica tuvo su arranque en la Jornada Internacional sobre el Proyecto de Reglamento General Europeo de Protección de Datos: Los principales retos actuales de la privacidad celebrada el 13 de noviembre de 2013 en la Universidad Jaume I que contó con el apoyo financiero de la Generalitat Valenciana (AORG/2013/086) y en la que ya participaron buena parte de los autores de esta obra. Conscientes de sus muchos quehaceres y compromisos, a los editores no nos resta sino reconocer y agradecer la disponibilidad de todos los autores para participar en esta obra colectiva y, además, hacerlo con la inequívoca voluntad de ofrecer al lector un estudio presidido por la calidad y autoridad de sus contenidos y por el indudable interés de los temas objeto de análisis. Artemi Rallo Lombarte Rosario García Mahamut Catedráticos de Derecho Constitucional Universidad Jaume I
Prólogo EUROPEAN LEADERSHIP IN PRIVACY AND DATA PROTECTION
Peter Hustinx European Data Protection Supervisor (2004-2014) This book with contributions on the proposed European General Data Protection Regulation offers an excellent opportunity to highlight Europe’s leading role in privacy and personal data protection. This role has evolved over decades, at European level notably first in the context of the Council of Europe, and later mainly in the context of the European Union. In this respect, we have seen a growing distinction between “privacy” and “data protection” as separate concepts, most recently also in the EU Charter of Fundamental Rights. At the same time, we have seen a growing emphasis on stronger and more effective protection of personal data and on more consistent protection across all EU Member States. These different lines all come together in the proposed General Data Protection Regulation. Of course, the need for strong, effective and consistent protection of personal data has never been greater and will probably only grow in the future. 1. Privacy and data protection —more precisely: the right to respect for private life and the right to the protection of one’s personal data— are both fairly recent expressions of a universal idea with quite strong ethical dimensions: the dignity, autonomy and unique value of every human being. This also implies the right of every individual to develop their own personality and to have a fair say on matters that may have a direct impact on them. It explains two features that frequently appear in this context: the need to prevent undue interference in private matters, and the need to ensure adequate control for individuals over matters that may affect them.
16
Peter Hustinx
The concept of “data protection” was developed four decades ago in order to provide legal protection to individuals against the inappropriate use of information technology for processing information relating to them. It was not designed to prevent the processing of such information or to limit the use of information technology per se. Instead, it was designed to provide safeguards whenever information technology would be used for processing information relating to individuals. This was based on the early conviction that the extensive use of information technology for this purpose could have far reaching effects for the rights and interests of individuals. 2. It was only after the Second World War that the concept of a “right to privacy” emerged in international law. This first arose in a rather weak version in Article 12 of the Universal Declaration of Human Rights, according to which no one shall be subjected to arbitrary interference with his privacy, family, home or correspondence. A more substantive protection followed in Article 8 of the European Convention on Human Rights (ECHR), according to which everyone has the right to respect for his private and family life, his home and his correspondence, and no interference by a public authority with the exercise of this right is allowed except in accordance with the law and where necessary in a democratic society for certain important and legitimate interests. The mentioning of “home” and “correspondence” could build on constitutional traditions in many countries around the world, as a common heritage of a long development, sometimes during many centuries, but the focus on “privacy” and “private life” was new, and an obvious reaction to what had happened in the Second World War. The scope and consequences of this protection have been explained by the European Court of Human Rights in a series of judgments. In all these cases, the Court considers - briefly put - whether there was an interference with the right to respect for private life, and if so whether it had an adequate legal basis - i.e.
Prólogo
17
clear, accessible and foreseeable - and whether it was necessary and proportionate for the legitimate interests at stake. 3. In the early 1970’s the Council of Europe concluded that Article 8 ECHR had a number of shortcomings in the light of new developments, particularly in view of the growing use of information technology: the uncertainty as to what was covered by “private life”, the emphasis on protection against interference by “public authorities”, and the lack of a more pro-active approach, also dealing with the possible misuse of personal information by companies or other relevant organisations in the private sector. This resulted in the adoption in January 1981 of the Data Protection Convention, also known as Convention 108, which has so far been ratified by 46 countries, including all EU Member States, most Member States of the Council of Europe and one non-Member State1. The purpose of the Convention is to secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him (“data protection”). The concept of “personal data” is defined as “any information relating to an identified or identifiable individual (“data subject”). This means that “data protection” is broader than “privacy protection” because it also concerns other fundamental rights and freedoms, and all kinds of data regardless of their relationship with privacy, and at the same time more limited because it merely concerns the processing of personal information, with other aspects of privacy protection being disregarded. In this context, it should be noted that many activities in the public or the private sector are nowadays connected, in one way or another, with the collection and processing of personal
1
Uruguay was the first non-Member State to ratify the Convention in April 2013.
18
Peter Hustinx
information. The real objective of the Convention is therefore to protect individuals (citizens, consumers, workers, etc.) against unjustified collection, recording, use and dissemination of their personal details. This may also concern their participation in social relations, whether or not in public, and involve protecting freedom of expression, preventing unfair discrimination and promoting “fair play” in decision-making processes. 4. The Convention contains a few basic principles for data protection to which each Party must give effect in its domestic law. These principles still form the core of any national legislation in this area. The Convention’s approach is not that processing of personal data should always be considered as an interference with the right to privacy, but rather that for the protection of privacy and other fundamental rights and freedoms, any processing of personal data must always observe certain legal conditions. Such as the principle that personal data may only be processed for specified legitimate purposes, where necessary for these purposes, and not used in a way incompatible with those purposes. Under this approach, the core elements of Article 8 ECHR, such as interference with the right to privacy only on an adequate legal basis, and where required for a legitimate purpose, have been transferred into a broader context. This only works well in practice, if the system of checks and balances, as set out in the Convention - consisting of substantive conditions, individual rights, procedural provisions and independent supervision - is sufficiently flexible to take account of variable contexts, and is applied with pragmatism and an open eye for the interests of data subjects and other relevant stakeholders. In this approach, the right to respect for private life set out in Article 8 ECHR continues to play an important role in the background, inter alia to determine the legitimacy of specific, more intrusive measures. The Convention has played a major role in most Member States of the Council of Europe in setting out legislative policy. In this context, the issue of “data protection” has been regarded from the outset as a matter of great structural importance for a modern
Prólogo
19
society, in which the processing of personal data is assuming an increasingly important role. 5. Only a few years after Convention 108 had been adopted, the German Constitutional Court delivered a decision in which it formulated a right to “informational self-determination” as an expression of the right to free development of the personality as laid down in Article 2(1) of the German Constitution. In this approach, any processing of personal data is in principle regarded as an interference with the right to informational self-determination, unless the data subject has consented. This should be clearly distinguished from the approach followed in Convention 108, and on that basis - as we will see - in Directive 95/46/EC and the relevant provisions of the EU Charter. A few months before Convention 108 was adopted, the OECD adopted Privacy Guidelines which, although not-binding, have also been very influential, particularly in countries outside Europe, such as the United States, Canada, Australia and Japan. The Guidelines contained a set of basic principles drawn up in close coordination with the Council of Europe and were therefore consistent with the principles for data protection in Convention 108. However, there were also quite subtle, but meaningful differences in details. The scope of the Guidelines was limited to personal data “which because of the manner in which they are processed, or because of their nature or the context in which they are used, pose a danger to privacy and individual liberties”. This implied the notion of “risk” as a threshold condition for protection which was not entirely compatible with the fundamental rights based approach of the Council or Europe. Moreover, the need for a legitimate purpose and a lawful basis for processing of personal data per se was absent in the Guidelines. Both points are still highly relevant in global discussions. 6. Although the Council of Europe was very successful in putting “data protection” on the agenda and setting out the main elements of a legal framework, it was less successful in terms of
20
Peter Hustinx
ensuring sufficient consistency across its Member States. Some Member States were late in implementing Convention 108, and those who did so arrived at rather different outcomes, in some cases even imposing restrictions on data flows to other Member States. The European Commission was therefore quite concerned that this lack of consistency could hamper the development of the internal market in a range of areas - involving free circulation of people and services - where the processing of personal data was to play an increasingly important role. At the end of 1990, it therefore submitted a proposal for a Directive in order to harmonise the national laws on data protection in the private and most parts of the public sector. After four years of negotiation, this resulted in the adoption of the current Directive 95/46/EC which has a double objective: ensuring an equivalent high level of protection of personal data in all Member States and ensuring a free flow of information between Member States subject to agreed safeguards. In that respect, the Directive started from the basic principles of data protection, as set out in Convention 108 of the Council of Europe. At the same time, it specified those principles and supplemented them with further requirements and conditions. However, since the Directive adopted generally formulated concepts and open standards, it still allowed Member States fairly broad discretion on its transposition. The result is that the Directive has led to a much greater consistency between Member States, but certainly not to identical or fully consistent solutions. Moreover, as the Directive was adopted when the Internet was still barely visible, it should be clear that the need for stronger protection and more consistency has only increased in recent years. On both points, the proposed General Data Protection Regulation is aimed to take the next steps. 7. Although the Directive was adopted to ensure the well functioning of the internal market, its history and background also carried a broader message. Since then the European Court of
Prólogo
21
Justice has repeatedly held that it has a wide scope and also applies to the public sector of the Member States.2 This fundamental rights origin has become more visible over the years. The adoption of the EU Charter of Fundamental Rights, initially as a political document, in December 2000, allowed further developments to take place along this line. One of the novel elements of the Charter was that in addition to the right to respect for private life, it also contained an explicit recognition of the right to the protection of personal data in a separate provision. Article 7 concerning “Respect for private and family life” states that “everyone has the right to respect for his or her private and family life, home and communications”. Article 8 on “Protection of personal data” provides, in its first paragraph, that “everyone has the right to the protection of personal data concerning him or her”. In the second paragraph, it provides that “such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law”, and that “everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified”. In the third paragraph, it states that “compliance with these rules shall be subject to control by an independent authority”. 8. The rights guaranteed in Article 7 of the Charter correspond to those guaranteed by Article 8 ECHR. Both are typical examples of classical fundamental rights, where interference is subject to strict conditions. Article 8 is largely based on Directive 95/46/EC and the Council of Europe Convention 108. As said, the right to the protection of personal data was conceived by the Council of Europe and set out in Convention 108 in order to provide a proactive protection of the rights and
2
Joined Cases C-465/00, C-138/01 and C-139/01, Österreichischer Rundfunk, [2003] ECR I-04989, at 41-43, and Case C-101/01, Bodil Lindqvist, [2003] ECR I-12971, at 39-41. See also Case C-524/06, Huber, [2008] ECR I-09705 and Case C-553/07, Rijkeboer, [2009] ECR I-03889.
22
Peter Hustinx
freedoms of individuals with regard to all processing of personal data, regardless of whether such processing was an interference with the right to respect for private life or not. This was intended as a system of “checks and balances” to provide a structural protection to individuals in a wide range of situations, both in the public and in the private sector. Directive 95/46/EC has used Convention 108 as a starting point for the harmonisation of data protection laws in the EU, and specified it in different ways. This involved the substantive principles of data protection, the obligations of controllers, the rights of data subjects, and the need for independent supervision as main structural elements of data protection. However, the nature of data protection as a system of “checks and balances” to provide protection whenever personal data are processed was not changed. In other words: Articles 7 and 8 do not have the same character and must be clearly distinguished. 9. The Convention which prepared the Charter before it was adopted, also considered including a right to informational self-determination in Article 8, but this was rejected. Instead, it decided to include a right to the protection of personal data, to preserve the main elements of Directive 95/46/EC. Thus the essential elements set out in Article 8(2) and 8(3) correspond with the key principles of Directive 95/46/EC, such as fair and lawful processing, purpose limitation, rights of access and rectification, and independent supervision. Moreover, it cannot be excluded that the Court of Justice might find other main elements of data protection which have not been expressed in Article 8(2) and 8(3), but are available in Directive 95/46/EC and may be seen as implied in Article 8(1) of the Charter. Such elements might also help to reinforce the elements which have already been made explicit and further develop the impact of the general right expressed in Article 8(1). In any case, this means that the scope of Article 8 - involving all processing of personal data - should not be confused with the question whether the fundamental right of Article 8 has been
Prólogo
23
interfered with. An interference with Article 8 does not arise from the mere fact that personal data are processed. Such interference can only be established if one or more of the main elements of the right to data protection - such as the need for a “legitimate basis laid down by law” or “independent supervision” - have not been respected. 10. The entry into force of the Lisbon Treaty in December 2009 had an enormous impact on the development of EU data protection law. In the first place, the Charter was given the same legal value as the Treaties in Article 6(1) of the Treaty on European Union. It thus became a binding instrument, not only for the EU institutions and bodies, but also for the Member States acting within the scope of EU law. The right to the protection of personal data was moreover specifically mentioned in Article 16(1) of the Treaty on the Functioning of the European Union (TFEU) among the general principles of the EU. This meant that some of the main elements of Directive 95/46/EC have now reached the level of EU primary law. In the second place, Article 16(2) TFEU now provides a general legal basis for the adoption of rules by the European Parliament and the Council, acting in the normal legislative procedure, “relating to the protection of individuals with regard to the protection of personal data” by EU institutions and bodies and by the Member States acting within the scope of EU law, and “the free movement of such data”. Finally, like Article 8(3) of the Charter, Article 16(2) also underlines that compliance with these rules should be subject to the control of independent authorities. The terminology used in the main text recalls Directive 95/46/ EC, but the scope of this new legal basis, which has been formulated as an obligation, goes in reality far beyond the internal market and covers in principle all EU policy areas. The term “rules” allows the use of directives and directly applicable regulations, and the choice between the two now largely seems a political one.
24
Peter Hustinx
11. The general basis for the review of the current legal framework in Article 16 TFEU offers a historic opportunity to deliver the main components of Article 8 Charter in a more effective and consistent set of rules across the EU. The proposed General Data Protection Regulation, which is to replace Directive 95/46/EC in due course, is a combination of continuity and innovation. All basic concepts and principles have been confirmed, usually only subject to some clarification. The Regulation will continue to have a broad scope, very likely also involving the public sector, and provide for stronger rights for data subjects, stronger obligations for data controllers, and stronger arrangements for supervision and enforcement, including administrative fines of millions of euro. This is in recognition of the growing importance of data protection in the digital economy. A directly binding Regulation will in principle bring much greater consistency, but in practice probably also allow some flexibility for interaction with national law, especially in the public sector. The greatest innovation is expected in larger responsibilities for controllers, although the impact of this shift will depend on the “progressive risk based approach� currently under discussion. Innovation can also be expected in the area of supervision and enforcement, especially in relation to the details of one-stopshops for citizens and business and in other mechanisms to ensure consistent outcomes of independent supervisory authorities. The territorial scope of the Regulation is likely to include companies that are operating on the European market from an establishment elsewhere in the world. In a recent judgment, on the basis of the current Directive, the Court of Justice has already made an interesting step in that direction, by linking the commercial activities of an establishment of a major search engine in Spain with those of the search engine itself established in the United States3.
3
Case C-131/12, Google Spain, 13 May 2014, at 55-56.
Prólogo
25
12. The proposed Regulation has of course not been prepared in isolation. Both the Council of Europe and the OECD have also been involved in a review of their legal frameworks, and the results all appear to go in the same direction of making data protection more effective in practice. The Regulation —once adopted probably in the course of 2015— is therefore likely to have a strong impact as a major benchmark, both for other countries around the world, and for operators whose success may depend on their capacity to ensure an effective protection of their clients’ privacy and personal data.