scholarly journals The Right to Privacy—A Fundamental Right in Search of Its Identity: Uncovering the CJEU’s Flawed Concept of the Right to Privacy

2019 ◽  
Vol 20 (05) ◽  
pp. 722-733 ◽  
Author(s):  
Valentin M. Pfisterer

AbstractIn recent years, the CJEU has impressively brought to bear the protection of the fundamental rights to privacy and protection of personal data as contained in the CFREU. The Court’s decisions in the Digital Rights, Schrems, Tele2, and PNR cases have reshaped the political and legal landscape in Europe and beyond. By restricting the powers of the governments of EU Member States and annulling legislative acts enacted by the EU legislator, the decisions had, and continue to have, effects well beyond the respective individual cases. Despite their strong impact on privacy and data protection across Europe, however, these landmark decisions reveal a number of flaws and inconsistencies in the conceptualization of the rights to privacy and protection of personal data as endorsed and interpreted by the CJEU. This Article identifies and discusses some of the shortcomings revealed in the recent CJEU privacy and data protection landmark decisions and proposes to the CJEU a strategy aimed at resolving these shortcomings going forward.

2014 ◽  
Vol 63 (3) ◽  
pp. 569-597 ◽  
Author(s):  
Orla Lynskey

AbstractArticle 8 of the EU Charter of Fundamental Rights sets out a right to data protection which sits alongside, and in addition to, the established right to privacy in the Charter. The Charter's inclusion of an independent right to data protection differentiates it from other international human rights documents which treat data protection as a subset of the right to privacy. Its introduction and its relationship with the established right to privacy merit an explanation. This paper explores the relationship between the rights to data protection and privacy. It demonstrates that, to date, the Court of Justice of the European Union (CJEU) has consistently conflated the two rights. However, based on a comparison between the scope of the two rights as well as the protection they offer to individuals whose personal data are processed, it claims that the two rights are distinct. It argues that the right to data protection provides individuals with more rights over more types of data than the right to privacy. It suggests that the enhanced control over personal data provided by the right to data protection serves two purposes: first, it proactively promotes individual personality rights which are threatened by personal data processing and, second, it reduces the power and information asymmetries between individuals and those who process their data. For these reasons, this paper suggests that there ought to be explicit judicial recognition of the distinction between the two rights.


2017 ◽  
Vol 19 (5) ◽  
pp. 765-779 ◽  
Author(s):  
Milda Macenaite

The new European Union (EU) General Data Protection Regulation aims to adapt children’s right to privacy to the ‘digital age’. It explicitly recognizes that children deserve specific protection of their personal data, and introduces additional rights and safeguards for children. This article explores the dilemmas that the introduction of the child-tailored online privacy protection regime creates – the ‘empowerment versus protection’ and the ‘individualized versus average child’ dilemmas. It concludes that by favouring protection over the empowerment of children, the Regulation risks limiting children in their online opportunities, and by relying on the average child criteria, it fails to consider the evolving capacities and best interests of the child.


Author(s):  
Agnese Reine-Vītiņa

Mūsdienās tiesības uz privāto dzīvi nepieciešamas ikvienā demokrātiskā sabiedrībā, un šo tiesību iekļaušana konstitūcijā juridiski garantē fiziskas personas rīcības brīvību un vienlaikus arī citu – valsts pamatlikumā noteikto – cilvēka tiesību īstenošanu [5]. Personas datu aizsardzības institūts tika izveidots, izpratnes par tiesību uz personas privātās dzīves neaizskaramību saturu paplašinot 20. gadsimta 70. gados, kad vairāku Eiropas valstu valdības uzsāka informācijas apstrādes projektus, piemēram, tautas skaitīšanu u. c. Informācijas tehnoloģiju attīstība ļāva arvien vairāk informācijas par personām glabāt un apstrādāt elektroniski. Viena no tiesību problēmām bija informācijas vākšana par fizisku personu un tiesību uz privātās dzīves neaizskaramību ievērošana. Lai nodrošinātu privātās dzīves aizsardzību, atsevišķas Eiropas valstis pēc savas iniciatīvas pieņēma likumus par datu aizsardzību. Pirmie likumi par personas datu aizsardzību Eiropā tika pieņemti Vācijas Federatīvajā Republikā, tad Zviedrijā (1973), Norvēģijā (1978) un citur [8, 10]. Ne visas valstis pieņēma likumus par datu aizsardzību vienlaikus, tāpēc Eiropas Padome nolēma izstrādāt konvenciju, lai unificētu datu aizsardzības noteikumus un principus. Nowadays, the right to privacy is indispensable in every democratic society and inclusion of such rights in the constitution, guarantees legally freedom of action of a natural person and, simultaneously, implementation of other human rights established in the fundamental law of the state. The institute of personal data protection was established by expanding the understanding of the content of the right to privacy in the 70’s of the 19th century, when the government of several European countries initiated information processing projects, such as population census etc. For the development of information technology, more and more information on persons was kept and processed in electronic form. One of the legal problems was gathering of information on natural persons and the right to privacy. In order to ensure the protection of privacy, separate European countries, on their own initiative, established a law on data protection. The first laws on the protection of personal data in Europe were established in the Federal Republic of Germany, then in Sweden (1973), Norway (1978) and elsewhere. Not all countries adopted laws on data protection at the same time, so the Council of Europe decided to elaborate a convention to unify data protection rules and principles.


Author(s):  
Araz Poladov

Purpose of research: define the general characteristics of the protection of personal data; analysis of legislation and case law.Methods of research: analysis and study of regulatory documents containing provisions on protection of personal data.Results: normative and practical importance of personal data protection provisions in various legal acts has been underscored.The right to privacy strengthened its position in the United States in the late 19th century and is now recognized by most States.Although the right to privacy in the United States was originally a British political legacy, judicial decisions in England were more conservativeand cautious than those of U.S. courts. One of the important features of this law in the Anglo-Saxon legal system is that itwas previously formed by judicial precedents and legal doctrine. Also, the right to privacy was not among the rights provided for in theBill of Rights. In general, there is an industry-wide approach to data privacy in the United States. There is no specific federal law thatwould guarantee the confidentiality and protection of personal data. Instead, legislation at the federal level is dispersed and aims to protectdata in certain sectors. Judicial practice and court decisions taken at different times play an important role in regulating personaldata protection in the United States. It is also worth mentioning that until the 1970s, decisions of the U.S. courts did not provide thenecessary privacy protection safeguards.Discussion: offering a comprehensive and detailed study and use of this practice in other states.


2017 ◽  
Vol 107 ◽  
pp. 11-25
Author(s):  
Marta De Bazelaire De Ruppierre

THE RIGHT TO PRIVACY OF LEGAL PERSONS DURING THE EUROPEAN COMMISSION’S INSPECTIONSThe paper aims to discuss the application of the Charter of Fundamental Rights by the EU institutions in competition law proceedings, showing as an example the respect for the right to privacy of undertakings during the inspections carried out by the European Commission. Although exercising the control powers of the Commission potentially collides with a number of fundamental rights expressed in the Charter, it is the analysis of Art. 7 CFR that allows to depict the evolution of the EU’s approach to privacy of legal persons, showing the accompanying judicial dialogue, or lack thereof, between the European Court of Human Rights and the Court of Justice of the EU. The article short-defines the dawn raids, examines the application of Article 7 CFR to legal persons, highlighting the aspects of protection of domicile and secrecy of correspondence, compares the standards provided by ECHR and EU law, pondering also on how the CFR guarantees can be provided and effectively controlled. It also reflects on the issue whether the Court of Justice has a forerunner role in promoting fundamental rights of undertakings in matters of competition law.


2019 ◽  
pp. 245-259
Author(s):  
Bernard Łukanko

The study is concerned with the issue of mutual relationship between the failure to comply with the laws on personal data protection and regulations relating to the protection of personal interests, including in particular the right to privacy. The article presents the views held by the Supreme Court with respect to the possibility of considering acts infringing upon the provisions of the Personal Data Protection Act of 1997 (after 24 May 2018) and of the General Data Protection Regulation (after 25 May 2018) as violation of personal interests, such as the right to privacy. The author shared the view of the case law stating that, if in specifc circumstances the processing of personal data violates the right to privacy, the party concerned may seek remedy on the grounds of Articles 23 and 24 of the Polish Civil Code. This position isalso relevant after the entry into force of the GDPR which, in a comprehensive and exhaustive manner, directly applicable in all Member States, regulates the issue of liability under civil law for infringements of the provisions of the Regulation, however, according to the position expressed in professional literature, it does not exclude the concurrence of claims and violation of the provisions on the protection of personal interests caused by a specifc event. In case of improper processing of personal data, the remedies available under domestic law on the protection of personal interests may be of particular importance outside the subject matter scope of the GDPR applicability. 


Author(s):  
NATALIA V. VARLAMOVA

Among the digital rights, besides the right for internet access that was the subject of consideration in the first part of the article, there are also a right to per-so nal data protection and a right to be forgotten (right to erasure).The right to personal data protection is usually enshrined at the supranational and national levels and is protected by the courts as an aspect of the right to privacy. As an independent fundamental right of a constitutional nature the right to personal data protection is enshrined in EU law. Nevertheless, all attempts to doctrinally justify the existence of certain aspects of this right, beyond the claims to the right to privacy, can not be considered successful. The Court of Justice of the EU, while dealing with the relevant cases in order to determine whether certain methods of processing personal data are legitimate, also refers to the right to privacy, considering these rights to be closely interrelated. The right to personal data protection provides additional (including procedural) guarantees of respect for privacy, human dignity and some other rights, but the purpose of these guarantees is precisely the content of the providing rights. The right to be forgotten (right to erasure) is one of the positive obligations with regard to the personal data protection. This right implies correction, deletion or termination of the processing of personal data at the request of their subject in the presence of a reason for this (when the relevant actions are carried out in violation of the principles of data processing or provisions of the legislation). Analogs of this right are the Latin American orders of habeas data, as well as the right of a person to demand the refutation of information discrediting his honor, dignity and business reputation, in case of their inconsistency with reality under civil law and the legislation on mass media. In digital age the importance of this right is increased by the fact that information posted on the Internet remains easily accessible for an indefinite, almost unlimited, time.This caused the extension of the right to be forgotten to information that is consistent to reality, but has lost its relevance and significance, however, continues to have an adverse impact on the reputation of the person concerned. At the same time, the realization of the right to be forgotten in respect of information posted online is connected with a number of technical problems that require legal solutions.In general, digitalization does not create new human rights of a fundamentally different legal nature. It only actualizes or smooths certain aspects of long-recognized rights, transfers their operation into the virtual space, creates new opportunities for their realization and generates new threats to them. Ensuring human rights in modern conditions involves the search for adequate legal solutions, taking into account the opportunities and limitations generated by digital technologies.


Author(s):  
Tigran D. Oganesian

The article considers the legality of mass surveillance and protection of personal data in the context of the international human rights law and the right to respect for private life. Special attention is paid to the protection of data on the Internet, where the personal data of billions of people are stored. The author emphasizes that mass surveillance and technology that allows the storage and processing of the data of millions of people pose a serious threat to the right to privacy guaranteed by Article 8 of the ECHR of 1950. Few companies comply with the human rights principles in their operations by providing user data in response to requests from public services. In this regard, States must prove that any interference with the personal integrity of an individual is necessary and proportionate to address a particular security threat. Mandatory data storage, where telephone companies and Internet service providers are required to store metadata about their users’ communications for subsequent access by the law enforcement and intelligence agencies, is neither necessary nor proportionate. The author analyses the legislation of some countries in the field of personal data protection, as well as examples from practice. Practice in many States is evidence of the lack of adequate national legislation and enforcement, weak procedural safeguards and ineffective oversight, which contributes to widespread impunity for arbitrary or unlawful interference with the right to privacy. In conclusion, we propose a number of measures aimed at improving the level of personal data protection in accordance with the international standards. In order to provide guarantees and a minimum level of adequate data protection in the face of new challenges to human rights in an ever-changing digital environment, the author proposes to solve a number of pressing issues. Firstly, States should not have the right to ask companies for and have absolute access to user data without a court order. Secondly, the process of sending a request and receiving data from a telecommunications company should be regulated in detail and transparent. The availability of specialized judges with technical expertise shall be valuable


2018 ◽  
Vol 21 (7) ◽  
pp. 27-44
Author(s):  
Ewa Kulesza

The right to the protection of personal data, which is part of the right to privacy, is a fundamental human right. Thus, its guarantees were included in the high-level regulations of the European Union as well as the legal norms of the EU Member States. The first Polish law regulating the protection of personal data was adopted in 1997 as the implementation of EU Directive 95/46. The law imposed a number of obligations on public and private entities which process personal data in order to protect the rights of data subjects and, in particular, to guarantee them the ability to control the correctness of processing of their personal data. Therefore, the law obliged data controllers to process data only on the basis of the premises indicated in the legislation, to adequately secure data, and to comply with the disclosure obligation concerning data subjects, including their right to correct false or outdated data or to request removal of data processed in violation of the law. However, as complaints directed by citizens to the supervisory body—the Inspector General for Personal Data Protection—showed, personal data controllers, especially those operating in the private sector, did not comply with the law, acting in a manner that violated their customers’ rights. In the hitherto existing unfair business practices of entrepreneurs, the violations of the data protection provisions that were the most burdensome for customers were related to preventing them from exercising their rights, including the right to control the processing of data, as well as the failure to provide the controller’s business address, which made it impossible for subjects whose data were used in violation of the law or for the inspecting authorities to contact the company, a lack of data security and a failure to follow the procedures required by law, the failure to secure documents containing personal data or their abandonment, a lack of updating customer data, the use of unverified data sets and sending marketing offers to deceased people or incorrect target recipients, and excessive amounts of data requested by controllers. The violations of the rights of data subjects recorded in Poland and other EU Member States—among other arguments—provided inspiration for the preparation of a new legal act in the form of the EU General Data Protection Regulation (GDPR) (which entered into force on 25 May 2018). The extension of the rights of people whose data are processed was combined in the GDPR with the introduction of new legal instruments disciplining data controllers. Instruments in the form of administrative fines and the strongly emphasised possibility to demand compensation for a violation of the right to data protection were directed in particular against economic entities violating the law.


2020 ◽  
Vol 92 (3) ◽  
pp. 347-378
Author(s):  
Miloš Sekulić ◽  
Gordan Grujić

The right to privacy is one of the fundamental human rights that serves to realize a man as a social being and protect the private spheres of their life. Even though this right can be looked at in different ways, due to the modern development of information and communication technologies, it is largely related to personal data and their availability to other persons. In that sense, the right to privacy is also protected via personal data protection. The basis for such protections in Serbian law has already been implemented in the Constitution of Serbia, and by adopting a new Personal Data Protection Law, the legislator has shown their determination to intensify and expand that protection. As it relates to criminal justice protection, a separate criminal offence of unauthorized collection of personal data is prescribed in Article 146 of the Criminal Code. The authors of this scientific paper will try to expose the threat to the right to privacy and personal data, and to give a clearer picture of how criminal justice protection of these values is realized in the Serbian law by presenting the elements of the aforementioned crime.


Sign in / Sign up

Export Citation Format

Share Document