EU updates data protection rules
Data Protection Regulation expands EU's jurisdiction
March 26, 2012 at 08:00 PM
19 minute read
In 1995, AOL still charged by the hour for dial-up Internet access, Stanford Ph.D. candidates Larry Page and Sergey Brin were a year away from launching the research project that would become Google, and Mark Zuckerberg celebrated his 11th birthday. Fewer than 1 percent of European Union residents were Internet users.
That was the year the EU adopted its Data Protection Directive, which regulates the collection, processing and storage of personal information in Europe. Fast forward to the age of cloud computing, social networking and online behavioral advertising, and the antiquated rules were in need of a face-lift. After more than two years of consultations with industry, governments and individuals, on Jan. 25 the European Commission (EC) released its draft General Data Protection Regulation, an Internet-era revision that will replace the 1995 directive.
The proposed regulation takes rapid technological development and the dramatic increase of data-sharing and collection into account and tightens requirements, introducing a host of new concepts and new corporate responsibilities.
On Feb. 23, the Obama administration released its own framework for privacy protections, the Consumer Privacy Bill of Rights, which marks another step toward omnibus privacy legislation in the U.S. But traditionally, the EU has taken a much more stringent approach to data protection, and its new proposed regulation is no different.
The update presents big challenges to affected companies, but it also offers one huge improvement over the 1995 directive. While the EC has framed the new rules as a way to build a level of trust in consumers that will give Europe a market advantage, the real advantage for companies will be uniformity.
Streamlined Rules
While the 1995 directive instructed each of the 27 member states to incorporate and implement the requirements into law, the update comes in the form of a regulation, which overrides national laws. Companies no longer will have to deal with 27 different interpretations of the 1995 directive. There will be one set of rules, and companies will only work with the national authority of the member state in which the company has its main establishment.
“Having one centralized set of rules is a huge step forward,” says Mary Hildebrand, a member of Lowenstein Sandler.
Much of the EC's literature on the new regulation focuses on how the new certainty of the streamlined rules will spur innovation and make the EU a friendlier place for businesses that operate in the cloud.
That's yet to be seen, but it will make Binding Corporate Rules (BCRs) easier for companies to adopt as an alternative to the Safe Harbor mechanism for transferring Europeans' personal data to the U.S. Now, U.S. companies must satisfy just one data protection authority instead of the authorities in every country in which they operate.
“Right now BCRs are an option but extremely difficult to do—only about 12 companies have successfully done it,” says William Baker, of counsel at Wiley Rein. “My sense is the EU thinks BCRs can be an effective way to make data transfers, and it would like to streamline the process to make life easier for American businesses.”
New Challenges
While it offers important benefits, the 91 articles of the proposed regulation will present numerous new challenges for companies.
The regulation has expanded extraterritorial application: Companies that process EU residents' personal data are subject to the requirements if they offer goods or services to data subjects in the EU or if they monitor those subjects' behavior. Under the prior directive, the rules applied to companies only if they had some physical presence in Europe, such as an office, a data processing point or space in a server farm.
“You can see how this is really reaching its tentacles outside of Europe into the U.S. corporate world,” says Susan Foster, a member of Mintz Levin in London.
Companies without a physical presence in Europe now must appoint a representative in Europe—a person or company that “acts and may be addressed by any supervisory authority and other [EU bodies]” in the place of the company.
Companies with 250 employees or more would have to appoint a senior data protection officer in an auditor role.
“Only a small handful of very forward-looking companies have implemented accountability-type frameworks,” says Lisa Sotto, a partner at Hunton & Williams. “You can't underestimate how significant this change is going to be.”
Another new requirement creates what Foster calls “the toughest data breach notification requirements I'm aware of anywhere,” which requires companies to notify authorities of a personal data breach “where feasible, within 24 hours.”
The new regulation also raises consent standards, requiring companies to get explicit, rather than implied, consent to process personal data. It includes a provision that suggests consent would not be valid “where there is a significant imbalance between the position of the data subject” and the company, language Foster says is troubling.
One of the other major changes addresses fines for noncompliance. The new regulation gives national data protection authorities the right to impose fines totaling up to 2 percent of a company's global revenues. Previously, fines have been rare and low in this area given the scale of data processing in Europe.
Social Networking Rights
One of the regulation's most controversial new provisions is the right to be forgotten, or the right to “erasure without delay” of personal data upon request if there is no legitimate reason for keeping it. A related provision is the right to data portability, which gives users to the right to move their personal data and to obtain copies of it from companies that process it in a common format.
“I'm slightly worried that we might not have Facebook in Europe if this regulation actually goes into effect,” Foster says. “I think [authorities] have really underestimated the potential burden on these companies.”
Both provisions look burdensome in the context of social networking—imagine a request that a Facebook user's every post, “like” and photo tag be deleted or transferred to another service. Foster says that the final regulation might include something like a balancing test between the importance to the individual versus the burden on the company.
While there's still time for discussion and revision as the EC presents the bill for consideration to the European Parliament and European Council, the draft regulation already has been through two years of formal, extensive consultation (or comment) processes.
“Companies should probably assume that we'll end up with something pretty similar to what we have in the draft regulation,” Foster says.
In 1995, AOL still charged by the hour for dial-up Internet access, Stanford Ph.D. candidates Larry Page and Sergey Brin were a year away from launching the research project that would become
That was the year the EU adopted its Data Protection Directive, which regulates the collection, processing and storage of personal information in Europe. Fast forward to the age of cloud computing, social networking and online behavioral advertising, and the antiquated rules were in need of a face-lift. After more than two years of consultations with industry, governments and individuals, on Jan. 25 the European Commission (EC) released its draft General Data Protection Regulation, an Internet-era revision that will replace the 1995 directive.
The proposed regulation takes rapid technological development and the dramatic increase of data-sharing and collection into account and tightens requirements, introducing a host of new concepts and new corporate responsibilities.
On Feb. 23, the Obama administration released its own framework for privacy protections, the Consumer Privacy Bill of Rights, which marks another step toward omnibus privacy legislation in the U.S. But traditionally, the EU has taken a much more stringent approach to data protection, and its new proposed regulation is no different.
The update presents big challenges to affected companies, but it also offers one huge improvement over the 1995 directive. While the EC has framed the new rules as a way to build a level of trust in consumers that will give Europe a market advantage, the real advantage for companies will be uniformity.
Streamlined Rules
While the 1995 directive instructed each of the 27 member states to incorporate and implement the requirements into law, the update comes in the form of a regulation, which overrides national laws. Companies no longer will have to deal with 27 different interpretations of the 1995 directive. There will be one set of rules, and companies will only work with the national authority of the member state in which the company has its main establishment.
“Having one centralized set of rules is a huge step forward,” says Mary Hildebrand, a member of
Much of the EC's literature on the new regulation focuses on how the new certainty of the streamlined rules will spur innovation and make the EU a friendlier place for businesses that operate in the cloud.
That's yet to be seen, but it will make Binding Corporate Rules (BCRs) easier for companies to adopt as an alternative to the Safe Harbor mechanism for transferring Europeans' personal data to the U.S. Now, U.S. companies must satisfy just one data protection authority instead of the authorities in every country in which they operate.
“Right now BCRs are an option but extremely difficult to do—only about 12 companies have successfully done it,” says William Baker, of counsel at
New Challenges
While it offers important benefits, the 91 articles of the proposed regulation will present numerous new challenges for companies.
The regulation has expanded extraterritorial application: Companies that process EU residents' personal data are subject to the requirements if they offer goods or services to data subjects in the EU or if they monitor those subjects' behavior. Under the prior directive, the rules applied to companies only if they had some physical presence in Europe, such as an office, a data processing point or space in a server farm.
“You can see how this is really reaching its tentacles outside of Europe into the U.S. corporate world,” says Susan Foster, a member of
Companies without a physical presence in Europe now must appoint a representative in Europe—a person or company that “acts and may be addressed by any supervisory authority and other [EU bodies]” in the place of the company.
Companies with 250 employees or more would have to appoint a senior data protection officer in an auditor role.
“Only a small handful of very forward-looking companies have implemented accountability-type frameworks,” says Lisa Sotto, a partner at
Another new requirement creates what Foster calls “the toughest data breach notification requirements I'm aware of anywhere,” which requires companies to notify authorities of a personal data breach “where feasible, within 24 hours.”
The new regulation also raises consent standards, requiring companies to get explicit, rather than implied, consent to process personal data. It includes a provision that suggests consent would not be valid “where there is a significant imbalance between the position of the data subject” and the company, language Foster says is troubling.
One of the other major changes addresses fines for noncompliance. The new regulation gives national data protection authorities the right to impose fines totaling up to 2 percent of a company's global revenues. Previously, fines have been rare and low in this area given the scale of data processing in Europe.
Social Networking Rights
One of the regulation's most controversial new provisions is the right to be forgotten, or the right to “erasure without delay” of personal data upon request if there is no legitimate reason for keeping it. A related provision is the right to data portability, which gives users to the right to move their personal data and to obtain copies of it from companies that process it in a common format.
“I'm slightly worried that we might not have Facebook in Europe if this regulation actually goes into effect,” Foster says. “I think [authorities] have really underestimated the potential burden on these companies.”
Both provisions look burdensome in the context of social networking—imagine a request that a Facebook user's every post, “like” and photo tag be deleted or transferred to another service. Foster says that the final regulation might include something like a balancing test between the importance to the individual versus the burden on the company.
While there's still time for discussion and revision as the EC presents the bill for consideration to the European Parliament and European Council, the draft regulation already has been through two years of formal, extensive consultation (or comment) processes.
“Companies should probably assume that we'll end up with something pretty similar to what we have in the draft regulation,” Foster says.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllCrypto Industry Eyes Legislation to Clarify Regulatory Framework
SEC Official Hints at More Restraint With Industry Bars, Less With Wells Meetings
4 minute readTrump Fires EEOC Commissioners, Kneecapping Democrat-Controlled Civil Rights Agency
Trending Stories
- 1AIAs: A Look At the Future of AI-Related Contracts
- 2Litigators of the Week: A $630M Antitrust Settlement for Automotive Software Vendors—$140M More Than Alleged Overcharges
- 3Litigator of the Week Runners-Up and Shout-Outs
- 4Linklaters Hires Four Partners From Patterson Belknap
- 5Law Firms Expand Scope of Immigration Expertise, Amid Blitz of Trump Orders
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250