Skip to main content icon/video/no-internet

European Union Directive on Privacy and Electronic Communications

The 2002 European Union Directive on Privacy and Electronic Communications (“the Privacy Directive”) and its predecessor, the 1995 Directive on the Protection of Individuals With Regard to the Processing of Personal Data (“the Personal Data Directive”), are legislative acts that work together to protect European citizens' and employees' e-commerce privacy. Since the first of the two directives became effective in 1998, they have affected U.S. companies attempting to do business with existing or potential customers and employees in the European Union (EU). Because of underlying philosophical differences between the United States and the EU concerning the scope and purpose of legislation and privacy interests, the EU directives' legal requirements do not mesh well with U.S. laws. A “Safe Harbor” for U.S. companies doing e-business in Europe has had mixed results, but according to an official EU study, U.S. companies are not fully complying with the Safe Harbor requirements.

Scope and Requirements of the European Privacy Directive

The directives' dual goals are (1) to ensure a high level of protection for individuals' privacy in all EU member states and (2) to enable the free movement of personal data within the EU. The directives protect four aspects of individuals' private data: (1) data quality, (2) legitimate processing of data, (3) rights of the individual whose data are being collected (the “data subject”), and (4) security of data. Data quality means that personal data must be processed fairly and lawfully; collected for explicit, legitimate, and specified purposes; relevant; accurate; and erased automatically when no longer needed. Legitimate processing means that personal data can be obtained only if the individual concerned has given his or her unambiguous consent. The data subject has a right of access to the information, the right to correct or block information that does not comply with the directive, and the right to object to the processing of data for compelling reasons. Finally, personal data must be secure. It must be protected from accidental or unlawful destruction or loss and against unauthorized alteration, disclosure, or access. Of concern to U.S. business interests is Article 25 of the 1995 Directive, which prohibits data transfers to any country that lacks an adequate level of personal data protection. In the EU's opinion, U.S. law does not provide the requisite level of protection.

Differences in Legal Philosophy

European Union

Both the United States and the EU strive to protect human rights, but they differ in terms of what type of entity is likely to present a threat to those rights: The United States has typically viewed overgrown governmental power as the most likely threat to civil liberties. Thus, in the United States, laws protecting human rights usually focus on limiting governmental powers. In contrast, the EU focuses more on potential threats from private entities. The EU's historical foundation for this concern was the misuse of data collected by private industries in pre–World War II Germany, industries that subsequently aided the Nazi attempt to eliminate targeted groups. Thus, data protection laws in Europe are focused more on limiting the powers of private entities to collect and keep data, while limiting governmental power to do the same is of lesser importance than it is in the United States.

...

  • Loading...
locked icon

Sign in to access this content

Get a 30 day FREE TRIAL

  • Watch videos from a variety of sources bringing classroom topics to life
  • Read modern, diverse business cases
  • Explore hundreds of books and reference titles

Sage Recommends

We found other relevant content for you on other Sage platforms.

Loading