Data protection in the EU - European Commission

Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

9/24/24, 5:55 PM Data protection in the EU - European Commission

Data protection in the EU


The General Data Protection Regulation (GDPR), the Data Protection Law
Enforcement Directive and other rules concerning the protection of personal data.

Fundamental rights
The EU Charter of Fundamental Rights (/aid-development-cooperation-fundamental-rights/your-rights-
eu/eu-charter-fundamental-rights_en) stipulates that EU citizens have the right to protection of
their personal data.

Protection of personal data (/aid-development-cooperation-fundamental-rights/your-rights-eu/know-your-


rights/freedoms/protection-personal-data_en)

Legislation
The data protection package adopted in May 2016 aims at making Europe fit for the digital
age. More than 90% of Europeans say they want the same data protection rights across
the EU and regardless of where their data is processed.

The General Data Protection Regulation (GDPR)

Regulation (EU) 2016/679 (https://eur-lex.europa.eu/legal-content/EN/AUTO/?uri=CELEX:02016R0679-


20160504&qid=1532348683434) on the protection of natural persons with regard to the
processing of personal data and on the free movement of such data. This text includes the
corrigendum published in the OJEU of 23 May 2018.

The regulation is an essential step to strengthen individuals' fundamental rights in the


digital age and facilitate business by clarifying rules for companies and public bodies in the
digital single market. A single law will also do away with the current fragmentation in
different national systems and unnecessary administrative burdens.

The regulation entered into force on 24 May 2016 and applies since 25 May 2018. More
information for companies and individuals (https://ec.europa.eu/commission/priorities/justice-and-
fundamental-rights/data-protection/2018-reform-eu-data-protection-rules_en).

Information about the incorporation of the General Data Protection Regulation (GDPR) into
the EEA Agreement (http://www.efta.int/About-EFTA/news/Incorporation-General-Data-Protection-
Regulation-GDPR-EEA-Agreement-and-continued-application-Directive-9546EC-508856).

EU Member States notifications to the European Commission under the GDPR (/law/law-
topic/data-protection/data-protection-eu/eu-member-states-notifications-european-commission-under-gdpr_en)

The Data Protection Law Enforcement Directive

Directive (EU) 2016/680 (http://eur-lex.europa.eu/legal-content/EN/TXT/?


on the protection of
uri=uriserv%3AOJ.L_.2016.119.01.0089.01.ENG&toc=OJ%3AL%3A2016%3A119%3ATOC)
natural persons regarding processing of personal data connected with criminal offences or
the execution of criminal penalties, and on the free movement of such data.

The directive protects citizens' fundamental right to data protection whenever personal
data is used by criminal law enforcement authorities for law enforcement purposes. It will
in particular ensure that the personal data of victims, witnesses, and suspects of crime are
duly protected and will facilitate cross-border cooperation in the fight against crime and
terrorism.

The directive entered into force on 5 May 2016 and EU countries had to transpose it into
their national law by 6 May 2018.

30 APRIL 2018

Factsheet - How will the data protection reform help fight international crime?

English
(125.47 KB - )
Download (/document/download/f4e7ef46-db4f-4f4f-b151-338f094120f1_en)

https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en#:~:text=The European Data Protection Board,Data Protection … 1/4


9/24/24, 5:55 PM Data protection in the EU - European Commission

National data protection authorities


EU countries have set up national bodies (https://edpb.europa.eu/about-
edpb/board/members_en)responsible for protecting personal data in accordance with Article
8(3) of the Charter of Fundamental Rights of the EU.

The GDPR procedural regulation aims to streamline cooperation between data protection
authorities (DPAs) when enforcing the GDPR in cross-border cases. It supplements the
GDPR in a targeted way by specifying procedural rules to be followed by DPAs when
applying the GDPR in cases which affect individuals in more than one Member State.

European Data Protection Board


The European Data Protection Board (EDPB) (https://edpb.europa.eu/) is an independent
European body which shall ensure the consistent application of data protection rules
throughout the European Union. The EDPB has been established by the General Data
Protection Regulation (GDPR) (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679).

The EDPB is composed of the representatives of the national data protection authorities of
the EU/EEA countries and of the European Data Protection Supervisor. The European
Commission participates in the activities and meetings of the Board without voting right.
The secretariat of the EDPB is provided by the EDPS. The secretariat performs its tasks
exclusively under the instructions of the Chair of the Board.

The EDPB tasks consist primarily in providing general guidance on key concepts of the
GDPR and the Law Enforcement Directive, advising the European Commission on issues
related to the protection of personal data and new proposed legislation in the European
Union, and adopting binding decisions in disputes between national supervisory
authorities.

Data Protection in the EU Institutions and


Bodies
Legislation

Regulation 2018/1725 (https://eur-lex.europa.eu/legal-content/EN/TXT/?


qid=1552577087456&uri=CELEX:32018R1725)sets forth the rules applicable to the processing of
personal data by European Union institutions, bodies, offices and agencies. It is aligned
with the General Data Protection Regulation and the Data Protection Law Enforcement
Directive. It entered into application on 11 December 2018.

European Data Protection Supervisor

Regulation 2018/1725 (http://eur-lex.europa.eu/legal-content/EN/TXT/?


qid=1552642506978&uri=CELEX:32018R1725) established a European data protection supervisor
(EDPS) (https://europa.eu/european-union/about-eu/institutions-bodies/european-data-protection-
supervisor_en). (http://ec.europa.eu/justice/data-protection/bodies/supervisor/index_en.htm)The EDPS is an
independent EU body responsible for monitoring the application of data protection rules
within European Institutions and for investigating complaints.

Data Protection Officer in the European Commission

The European Commission has appointed a Data Protection Officer (/about-european-


commission/departments-and-executive-agencies/data-protection-officer_en) who is responsible for
monitoring and the application of data protection rules in the European Commission. The
data protection officer independently ensures the internal application of data protection
rules in cooperation with the European data protection supervisor.

Standard Contractual Clauses


Following the adoption in June 2021 of two sets of Standard Contractual Clauses (SCC)
(one for the use between controllers and processors within the European Economic Area
(EEA) (/publications/standard-contractual-clauses-controllers-and-processors-eueea_en)and one for the
transfer of personal data to countries outside of the EEA (/publications/standard-contractual-clauses-
international-transfers_en)), the European Commission published on 25 May 2022 Questions and
Answers (Q&As) to provide practical guidance on the use of the SCCs and assist
stakeholders in their compliance efforts under the General Data Protection Regulation
(GDPR). These Q&As are based on feedback received from various stakeholders on their
experience with using the new SCCs in the first months after their adoption. The Q&As are
intended to be a ‘dynamic’ source of information and will be updated as new questions
arise.

25 MAY 2022

Questions and Answers for the two sets of Standard Contractual Clauses

https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en#:~:text=The European Data Protection Board,Data Protection … 2/4


9/24/24, 5:55 PM Data protection in the EU - European Commission
English
(435.42 KB - PDF)
Download (/document/download/b9d3d16b-9003-45e7-acef-409562b4bf8b_en?
filename=questions_answers_on_sccs_en.pdf)

Funding
Funding & tender opportunities (SEDIA) (https://ec.europa.eu/info/funding-
tenders/opportunities/portal/screen/home)

Rights, Equality and Citizenship Programme (2014-2020 (/funding-tenders/find-funding/eu-funding-


programmes/citizens-equality-rights-and-values-programme/citizens-equality-rights-and-values-programme-
overview_en))

Documents
General publications 25 July 2024 Directorate-General for Justice and Consumers

Reports on the application of the GDPR (/publications/reports-application-gdpr_en)


Reports on the GDPR

Proposal for a regulation 4 July 2023 Directorate-General for Justice and Consumers

Proposal for a Regulation laying down additional procedural


rules relating to the enforcement of GDPR (/publications/proposal-regulation-laying-
down-additional-procedural-rules-relating-enforcement-gdpr_en)

Find all documents about the Proposal for a Regulation on GDPR

4 June 2021 Directorate-General for Justice and Consumers

Standard contractual clauses for controllers and processors in


the EU/EEA (/publications/standard-contractual-clauses-controllers-and-processors-eueea_en)
New Data Protection Contractual Clauses based on Art 28 GDPR and Art 29 Regulation
2018/1725

Communication 25 July 2022 Directorate-General for Justice and Consumers

First report on application and functioning of the Data Protection


Law Enforcement Directive (EU) 2016/680 (LED) (/publications/first-report-
application-and-functioning-data-protection-law-enforcement-directive-eu-2016680-led_en)

A report on the application and functioning of the Law Enforcement Data Protection
Directive.

Communication 24 June 2020 Directorate-General for Justice and Consumers

Communication from the Commission to the European


Parliament and the Council (/publications/communication-commission-european-parliament-
and-council_en)

Way forward on aligning the former third pillar acquis with data protection rules.

Communication 24 July 2019 Directorate-General for Justice and Consumers

Communication from the Commission to the European


Parliament and the Council (/publications/communication-commission-european-parliament-
and-council-0_en)

Data protection rules as a trust-enabler in the EU and beyond - taking stock.

Communication 24 January 2018 Directorate-General for Justice and Consumers

Communication from the Commission to the European


Parliament and the Council (/publications/communication-commission-european-parliament-
and-council-1_en)

Stronger protection, new opportunities - Commission guidance on the direct application of


the General Data Protection Regulation as of 25 May 2018.

Study 12 March 2019 Directorate-General for Justice and Consumers

Study on Data Protection Certification Mechanisms (/publications/study-


data-protection-certification-mechanisms_en)

Study on Articles 42 and 43 of the General Data Protection Regulation (GDPR) (EU)
2016/679.

https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en#:~:text=The European Data Protection Board,Data Protection … 3/4


9/24/24, 5:55 PM Data protection in the EU - European Commission
27 APRIL 2016

Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR)

English
(1013.17 KB - HTML)
Download (/document/download/318a6a64-46bc-4d10-8170-94f4b23c3032_en)

20 SEPTEMBER 2017

Directive (EU) 2016/680 on the protection of natural persons regarding processing of personal data connected
with criminal offences or the execution of criminal penalties, and on the free movement of such data

English
(506.95 KB - HTML)
Download (/document/download/a3c38ffb-7d37-473d-b6a8-f09bc973d445_en)

15 MARCH 2019

Regulation (EU) 2018/1725 on the protection of natural persons with regard to the processing of personal data
by the EU institutions, bodies, offices and agencies

English
(798.81 KB - HTML)
Download (/document/download/dccacd31-047a-46a2-b289-fc8eeeedcc74_en)

Related links
Pilot Project on the Fundamental Rights Review of EU Data
Collection instruments and Programmes
(http://www.fondazionebrodolini.it/en/projects/pilot-project-fundamental-rights-review-eu-data-collection-
instruments-and-programmes)

A Europe Fit for the Digital Age (/strategy-and-policy/priorities-2019-2024/europe-fit-digital-


age_en)

https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en#:~:text=The European Data Protection Board,Data Protection … 4/4

You might also like