CHAPTER 2. Aims and Scope of Data Protection Laws

2.1. Introduction

This part of the thesis surveys the content of legal (and some non-legal) instruments on data protection on both international and domestic planes. The presentation here is aimed at fleshing out the short description of data protection laws' distinguishing features given in Chapter 1 (section 1.1. At the same time, it should be stressed that my intention in this Part is not to provide an exhaustive analysis of data protection laws; rather, it is to sketch these laws' central, primarily formal characteristics so as to create a platform for closer analysis of their rationale, logic and limits in the remainder of the thesis.

Part I leaves largely unexamined the now considerable number of data protection instruments that are of sectoral application only.[129] This is because their basic principles are broadly similar to, and largely derived from, the principles set down in the generally applicable instruments. Also left unexamined are the rules governing national data protection laws' territorial reach and concomitant choice-of-law problems. I skip over these rules as issues of jurisdiction and choice of law are marginal to the focus of the thesis.[130]

This chapter surveys the aims and ambits of data protection laws, using three international instruments on data protection as primary points of reference (see section 2.2). It looks first at data protection laws' respective aims (section 2.3), then at their respective ambits (section 2.4).

2.2. Primary Points of Reference

The emergence of data protection laws is recent. The first pieces of legislation in the field were not enacted until the early 1970s. At present, however, a large range of legal and quasi-legal instruments on data protection are to be found. There are now well over twenty countries which have enacted data protection statutes at national or federal level, and the number of such countries is steadily growing. Various legal instruments on data protection have also been introduced at the inter- and supranational plane and at provincial and municipal levels.

To describe, even briefly, each of these instruments one after the other would make for an exceedingly long exegesis. It would also be tedious since, as shown further on, these instruments are broadly similar on a large number of points. Hence, three international data protection instruments are used as primary points of reference in this chapter and the other chapters in Part I. These instruments are:

1. the CoE Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (hereinafter termed "CoE Convention"),[131] adopted by the CoE Committee of Ministers on 28.1.1981;

2. the EC Directive on the Protection of Individuals with Regard to the Processing of Personal Data and on the Free Movement of Such Data (hereinafter termed "EC Directive"),[132] adopted by the European Parliament and the Council on 24.10.1995; and

3. the OECD Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data (hereinafter termed "OECD Guidelines"),[133] adopted by the OECD Council on 23.9.1980.

These instruments are focused upon for two main reasons. First, the instruments contain relatively clear distillations of the basic principles of data protection which are present (though not always obvious) in domestic data protection laws. Secondly, they serve as influential models for national and international initiatives on data protection.

Of these instruments, the EC Directive is the most comprehensive and complex. It is also likely to constitute the most important point of departure for new data protection initiatives, both in and outside the EU. Member states of the EU were given until 24.10.1998 to bring their respective legal systems into conformity with the provisions of the Directive (see Art 32(1) of the latter).[134] Although the Directive's scope is delimited in several respects,[135] its general thrust is to establish a set of rules capable of broad application and impact. The Directive and later EC legislation on data protection also apply to the processing of personal data by the Community's own institutions as of 1.1.1999.[136] If - as is likely - the Directive is incorporated into the 1992 Agreement on the European Economic Area (EEA), then states that are not members of the EU but party to the EEA Agreement (ie, Norway, Iceland and Liechtenstein) will also become legally bound to bring their respective laws into conformity with the Directive.[137] In addition, the Directive is likely to exercise some political and legal influence over other countries outside the EU, not least because Art 25(1) of the Directive prohibits the transfer of personal data to these countries if they do not provide "adequate" levels of data protection.[138] Accordingly, in the following, the Directive is treated in considerably more detail than the other international instruments.

Despite the Directive's adoption, the CoE Convention and OECD Guidelines are still important to study at the present time because they have influenced, and/or embody, the basic principles of most countries' current data protection laws, along with the EC Directive itself.[139] The Convention is the hereto sole international treaty dealing specifically with data protection. It entered into force on 1.10.1985. As of 23.4.1999, it had been ratified by 20 CoE member states, the latest being Hungary, which ratified on 8.10.1997.[140] The Convention is potentially open for ratification by states that are not members of the CoE (Art 23); concomitantly, it is also envisaged to be potentially more than an agreement between European states.[141] As yet, though, it has not been ratified by any non-member state.

Interestingly, several proposals have been made that the EC itself ratify the Convention.[142] The legal viability of these proposals is doubtful as accession pursuant to Art 23 of the Convention seems only open for states proper.[143] The competence of the EC to accede to such a treaty is also in doubt, particularly after the European Court of Justice (ECJ) recently held that the EC does not have the competence to accede to the European Convention on Human Rights on the basis of Art 308 (formerly 235) of the EC Treaty.[144] However, the impact of this ruling on consideration of the legal viability of the Community acceding to the CoE Convention is lessened by the fact that the institutional framework set up by that Convention, along with its institutional implications for the Community, are extremely modest in comparison with the framework established by the ECHR. In any case, with the data protection Directive in place and preparedness on the part of EC institutions to apply its principles to their own data-processing activities,[145] there is now reduced need for Community accession to the CoE Convention.

As for the OECD Guidelines, despite the fact that they are not legally binding on OECD member states,[146] they have been highly influential on the enactment and content of data protection legislation in non-European jurisdictions, particularly Japan, Australia, New Zealand and Hong Kong. For example, the Preamble to Australia's federal Privacy Act lists the Guidelines and the accompanying OECD Council Recommendation as part of the reasons for the passing of the Act. Similarly, the Preamble to New Zealand's Privacy Act of 1993 states that the Act is to "promote and protect individual privacy in general accordance with the Recommendation [of the OECD Council] ...". In North America, the Guidelines have been formally endorsed by numerous companies and trade associations.[147] They have additionally constituted the basis for the first comprehensive set of data protection standards to be developed by a national standards association: the Model Code for the Protection of Personal Information, adopted by the Canadian Standards Association (CSA) in March 1996.[148]

Some account is also taken in this and the following chapters of a fourth international data protection instrument: the United Nations' (UN) Guidelines Concerning Computerized Personal Data Files (hereinafter termed "UN Guidelines"),[149] adopted by the UN General Assembly on 14.12.1990. The Guidelines have their roots in, ia, a 1968 resolution of the General Assembly inviting the UN Secretary-General to examine the impact of technological developments on human rights, including consideration of individuals' right to privacy "in the light of advances in recording and other techniques".[150] The resulting study by the Secretary-General led to, ia, the publication of a report in 1976 urging states to adopt data protection legislation covering computerized personal data systems in the public and private sectors, and listing minimum standards for such legislation.[151]

The basic intention of the Guidelines is to encourage those UN member states that do not have data protection legislation in place, to take steps to enact such legislation, based on the Guideline's principles. The Guidelines are also aimed at encouraging governmental and non-governmental international organisations to process personal data in a responsible, fair and privacy-friendly manner. The Guidelines are not legally binding. Furthermore, they seem to have had little practical effect relative to the other three international instruments on data protection canvassed in this chapter. Indeed, it is my impression that the Guidelines tend to be overlooked in much data protection discourse, at least in Scandinavia.[152] This is unfortunate as their adoption demonstrates that concern for data protection can no longer be assumed to be confined to the Western democracies of the so-called First World. Moreover, as shown further on, the UN Guidelines do not merely repeat what is set out in other international instruments on data protection but supplement some of these instruments in several respects.

When considering both the descriptive and prescriptive character of the above instruments with respect to domestic data protection laws, two related points need to be kept in mind. First, all of the above instruments give the states to which they are adressed a significant amount of leeway in terms of how their rules are to be implemented in national legislation. This is obviously the case with the two sets of Guidelines since neither are legally binding. But also the two other instruments allow for flexibility. As Simitis points out, the CoE wanted its data protection Convention to be a catalyst and guide for states' legislative initiatives rather than to short-circuit these initiatives by providing a completed package of directly applicable, material rules.[153] Thus, the CoE Convention is not intended to be self-executing. Article 4(1) of the Convention simply obliges contracting states to incorporate the Convention's principles into their domestic legislation; "individual rights cannot be derived from it".[154] It should also be noted that the Convention does not establish a body to enforce its implementation. Moreover, it allows for derogations on significant points (see, eg, Arts 3, 6 and 9, described further below). This seriously hampers its ability to harmonise the data protection regimes of the contracting states.[155]

Similarly, in accordance with the principle of subsidiarity, EU member states have been allowed a margin for manoeuvre in implementing the Directive. This follows partly from the status of the Directive qua directive (as opposed to regulation).[156] Directives are legally binding only in terms of result; how the result is to be reached is up to the member states to determine. In practice, though, the amount of such discretion is dependant on each directive's objective and level of detail.[157] Regarding the data protection Directive, its aim of bringing about harmonisation of national data protection regimes[158] should narrow the amount of discretion accorded member states in terms of how it is to be implemented. Nevertheless, key provisions in the Directive expressly provide states a considerable margin for manoeuvre.[159] As a result of this margin, recital 9 recognises that "disparities could arise in the implementation of the Directive".[160] This is despite the assumption that the Directive's implementation will bring about an "approximation" of national laws resulting in "equivalent" levels of data protection across the member states.[161]

The second point is that many of the provisions in the international data protection instruments are diffuse, with little authoritative guidance on how they are to be interpreted. The contents of the EC Directive have yet to be analysed by the ECJ, while the other instruments lack judicial bodies for their interpretation and enforcement. It is also worth noting that case law of the European Commission of Human Rights (ECommHR) and European Court of Human Rights (ECtHR) has scarcely touched specifically upon the provisions of the CoE Convention, though breaches of the Convention's core principles could in some cases constitute interference with the "right to respect for private life" provided under Art 8 of the ECHR.[162]

Only the OECD Guidelines and CoE Convention have been issued with explanatory memoranda, but both are thin at numerous points. Moreover, the memorandum ("Explanatory Report") for the Convention is prefaced with a disclaimer stating that "[t]he report does not constitute an instrument providing an authoritative interpretation of the text of the Convention, though it might be of such nature as to facilitate the understanding of the provisions contained therein". Thus, caution needs to be exercised when using the Explanatory Report to resolve ambiguities in the Convention's text.

The same applies when attempting to resolve such ambiguities through recourse to the various sectoral recommendations on data protection which have been adopted by the CoE Committee of Ministers in the wake of the Convention. This is not to say, however, that these recommendations are without any relevance for interpreting the Convention. One of their express aims is to provide guidance on how to apply the Convention's provisions in specific contexts. In providing such guidance, they aim also to take account of technological developments. They are drafted by experts in the field, with participation from all CoE member states. While implementation of the recommendations is not legally required, member states tend to attribute considerable authority to their provisions.[163] Accordingly, the recommendations may be considered as having more than marginal weight when resolving ambiguities in the text of the Convention. Nevertheless, they can hardly be said to have an absolute determinative weight; they are just one of several relevant interpretative factors.

Also relevant are, of course, the basic principles of treaty interpretation set down in Arts 31-33 of the 1969 Vienna Convention on the Law of Treaties. The central principle here is that "[a] treaty shall be interpreted in good faith in accordance with the ordinary meaning to be given to the terms of the treaty in their context and in the light of its object and purpose" (Art 31(1)).

While these principles are not formally binding on the ECJ when it interprets EC legal instruments, contextual and purposive methods of interpretation do play a key role in the Court's jurisprudence. In practice, it is not uncommon for the ECJ to place most weight on what it sees as provisions' object and purpose, giving relatively little attention to the literal meaning of the words used[164] or to the drafters' actual intentions as found in the travaux préparatoires.165 Hence, if called upon to interpret the EC Directive, the Court is likely to devote most energy to ascertaining the Directive's policy thrust and then reading the Directive in the light of this. The Court may have regard to the recitals in this process. As for the Directive's travaux préparatoires, despite the Court's minor use of such documents generally, these can be taken into account insofar as they help to clarify textual ambiguity that the recitals otherwise are unable to resolve conclusively,[166] and insofar as they are publicly accessible. In light of the latter criterion, the Court is unlikely to place weight on the unpublished Council minutes relating to the adoption of the Common Position on the Directive (hereinafter termed "Council minutes"), despite the inclusion in these minutes of declarations by various member states, together with the Commission and Council, on how they respectively understand particular provisions of the Common Position. It should be noted, though, that an edited version of the minutes has been made publicly available in Sweden. This version is in Swedish and in a format whereby declarations of member states other than Sweden are anonymised. A Danish version of the declarations disclosed in Sweden has since been published by Peter Blume.[167] To my knowledge, an English version has not been made publicly available.

2.3. Aims

Data protection laws typically express as one of their primary aims the safeguarding of individual persons' right to privacy. The main object of the CoE Convention, for example, is set out in Art 1 as follows:

to secure in the territory of each Party for every individual, whatever his nationality or residence, respect for his rights and fundamental freedoms, and in particular his right to privacy, with regard to automatic processing of personal data relating to him ("data protection").

Article 1(1) of the EC Directive is formulated similarly:

In accordance with this Directive, Member States shall protect the fundamental rights and freedoms of natural persons, and in particular their right to privacy, with respect to the processing of personal data.

On a national plane, the objects clauses and/or titles of the data protection laws (both past and present) of several European countries expressly point to privacy as a fundamental value to be protected by the laws.[168] The privacy protection rationale also figures prominently in the data protection laws of non-European countries. For instance, Australian, Canadian, New Zealand and United States' data protection statutes enacted at the federal/national level all bear the titles "Privacy Act" and set down the safeguarding of privacy as one of their basic objects.[169]

However, many European data protection statutes (both past and present) make no explicit reference to the safeguarding of privacy. Of these, some refer instead to other related concepts, such as protection of "personality",[170] or protection of "personal integrity".[171]

Other statutes, though, do not contain objects clauses formally specifying a particular abstract interest or value which they are intended to serve. This is the case, for instance, with the national data protection statutes of Norway, Denmark, Iceland and the United Kingdom.[172] It is also the case with Sweden's first data protection statute, the Data Act of 11.5.1973.[173] Nevertheless, references to such interests or values emerge in other provisions of some of the Scandinavian countries' data protection laws,[174] and/or in some of the preparatory works to these laws.[175]

It is apparent from the above that the objects clauses of data protection laws frequently point to other values than just privacy. At the same time, these values are often left relatively unspecified. Article 1 of the CoE Convention, for instance, refers merely to "rights and fundamental freedoms". Article 1(1) of the EC Directive is pitched at a similar level of generality. Such a broad formulation of goals not only provides data protection laws with an extremely large register of values upon which their formal rationale may be grounded, it also serves to strengthen their normative links with the corpus of human rights law. Somewhat paradoxically, though, such broad goal formulation might also belie uncertainty as to exactly which values data protection laws are to serve, other than privacy. A closer analysis of such values is undertaken in Part II.

Arguably the broadest and boldest expression of basic objects at national level is found in s 1 of France's Law of 6.1.1978 Regarding Data Processing, Files and Individual Liberties.176 This provision reads:

Data processing shall be at the service of every citizen. It shall develop in the context of international co-operation. It shall infringe neither human identity, nor the rights of man, nor privacy, nor individual or public liberties.

Another relatively comprehensive objects clause has been s 1 of Finland's Personal Data Registers Act of 30.4.1987.[177] This sets out the Act's purposes as being "... to protect the privacy, interests and rights of the person, to ensure the security of the State and to maintain good data file practice ...". Especially noteworthy here is the reference to protecting not just the interests of individuals but also those of the State. Such references are rare. Indeed, the reference to State interests has been dropped from the objects clause of the new Finnish Personal Data Act[178] which entered into force 1.6.1999 and replaces the 1987 Act.

Express concern for safeguarding interests directly connected with the State is also found in some of the data protection Acts of the German Länder. These Acts aim at, ia, preserving State order based on the principle of separation of powers. For example, s 1(2) of the Hessian Data Protection Act of 11.11.1986[179] sets down as one of its purposes

to safeguard the constitutional structure of the state, in particular the relationship between the constitutional organs of the Land and those of local government, based on the principle of separation of powers, against all risks entailed by automatic data processing.

This declaration is followed up by provisions aimed at maintaining a so-called "Informationsgleichgewicht" ("informational equilibrium")[180] between the legislature and other State organs in Hesse.[181] Similar provisions are found in the data protection statutes of Rhineland-Palatinate, Berlin, Lower Saxony and, to a lesser extent, Thuringia.[182]

A major formal aim of international data protection instruments is to stimulate the creation of adequate national data protection regimes and to prevent divergencies between them. Thus, Art 1 of the CoE Convention ("... to secure in the territory of each Party for every individual, whatever his nationality or residence ...": see above), together with the Convention's Preamble ("Considering that the aim of the Council of Europe is to achieve greater unity between its members...") indicate that the Convention is intended to harmonise contracting states' respective data protection regimes so that processing of personal data is subject to basically the same rules in all countries concerned.[183] This harmonisation is not only to strengthen data protection and thereby the right "to respect for private life" pursuant to Art 8 of the ECHR, but, somewhat paradoxically, to ensure also the free flow of personal data across national borders and thereby safeguard the right in Art 10 of the ECHR "to receive and impart information and ideas without interference by public authority and regardless of frontiers".[184] The latter concern is actualised by the existence in many countries' data protection laws of rules providing for the restriction of data flow to countries without equivalent levels of data protection.[185]

Similar concerns are manifest in both the OECD and UN Guidelines.[186] However, the concern of the OECD Guidelines in maintaining transborder data flows is specifically linked not so much to a human right in freedom of expression but to the factors of "economic and social development".[187] This is in contrast to the CoE Convention and UN Guidelines.[188]

Factors related to economic and social development also figure centrally in the aims of the EC Directive. The Directive's recitals (especially recitals 3, 5 & 7) register a concern to promote realisation of the EU's internal market, in which goods, persons, services, capital and, concomitantly, personal data are able to flow freely between member states. However, the need to ensure free flow of personal data is not rooted exclusively in commercial considerations; the pan-EU ambit of government administration also plays a role.[189]

In furtherance of the concern to promote realisation of the internal market, the main function of the Directive is to secure, pursuant to Art 95 (formerly 100a) of the EC Treaty,[190] harmonisation of member states' respective data protection laws. Thus, it is assumed in recitals 8 and 9 that implementation of the Directive will lead to an "approximation" of national laws, resulting in "equivalent" levels of data protection across the EU.[191] With implicit reference to Art 12(3)(a) of the CoE Convention,[192] recital 9 states that the achievement of such equivalency will make it legally impossible for member states to restrict the free flow of personal data to other member states "on grounds relating to protection of the rights and freedoms of individuals, and in particular the right to privacy".[193]

At the same time, though, the recitals emphasise the importance of protecting basic human rights, notably that of privacy, in the face of technological and economic developments.[194] Indeed, the Directive is amongst the first Directives to expressly accord a prominent place to the protection of human rights. As such, it reflects and reinforces the gradual incorporation of law and doctrine on human rights, particularly as embodied in the ECHR, into the EU legal system.[195] Also noteworthy here is that the Directive strives to bring about a "high" level of data protection across the EU.[196] Accordingly, it would be wrong to see the Directive as attempting merely to constitute the "lowest common denominator" of rules found in member states' pre-existing laws. Concomitantly, particularly in view of recitals 9 and 10, the Directive leaves open the possibility for member states to establish or maintain a higher level of data protection than the Directive seeks to establish, as long as this does not derogate from any of the Directive's mandatory requirements.

2.4. Ambit

2.4.1. Coverage with regard to type of data

Data protection laws' regulatory focus is centred upon "personal" data or information. Article 2(a) of the CoE Convention defines "personal data" as "any information relating to an identified or identifiable individual". Exactly the same definition is given in para 1(b) of the OECD Guidelines.[197] A similar but more comprehensive definition is provided by Art 2(a) of the EC Directive which defines "personal data" as

any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity.

Broadly similar definitions of "personal data" or "personal information" are found in domestic data protection legislation.[198]

One can read into these definitions two cumulative conditions for data or information to be "personal": first, the data must relate to or concern a person; secondly, the data must facilitate the identification of such a person. Regarding the first condition, however, there is usually no requirement that the data relate to a particular (eg, private, intimate) sphere of a person's activity.[199] Hence, in most cases, it may not be appropriate to talk of two separate (though cumulative) conditions for making data "personal". It may be argued that the first condition can be embraced by the second, in the sense that information will normally relate to, or concern, a person if it facilitates that person's identification. In other words, the basic criterion appearing in these definitions would seem to be that of identifiability; ie, the potential of information to enable identification of a person. Such a focus makes the definitions capable in theory of embracing a great deal of data, including geographical and environmental data, which prima facie have little direct relationship to a particular person.[200]

At the same time as this capability has obvious benefits from a data protection perspective, it threatens the semantic viability of the notion of "personal data/information" and incurs a practical-regulatory risk that data protection laws will overreach themselves. Thus, in some jurisdictions, attempts have been made to delimit this capability. For example, Ulrich Dammann claims that, as a general rule in German data protection law, data over, say, material goods are "personal" only insofar as the data identify the goods and are able to relate them to the "life context" of a particular person.[201] A broadly similar, though perhaps more restrictive, line has been taken by Australia's federal Privacy Commissioner.[202] As Dammann makes clear, such delimitations are not fixed along abstract logical or semantic lines; rather, they are reached pragmatically.[203] Alternatively, the UK Data Protection Act 1984 has only applied to the processing of personal data when the processing occurs "by reference to the data subject" (s 1(7)).[204] The UK Data Protection Tribunal has read the latter phrase as excluding from the purview of the Act processing operations in which the data subject is not intended to be in focus.[205] There is, however, no corresponding phrase into which this delimitation can be read on the face of the new UK Act of 1998 - at least with regard to automated processing;[206] the same can be said with respect to the EC Directive along with the other data protection laws I have perused.

Usually, data must be capable of being linked to a particular individual person if they are to be regarded as "personal" pursuant to data protection laws. Thus, data which are linked to an aggregate of persons and which do not allow for these persons' individuation will normally fall outside the ambit of such laws. There are, however, some exceptions. The data protection laws of a handful of countries expressly extend to data on collective entities, such as private corporations, partnerships and, in some cases, groups that otherwise do not have legal identities separate from those of their members.[207] But, again, data on such entities are only covered insofar as they permit the entities' individuation. At the same time, there is some uncertainty and variation from jurisdiction to jurisdiction in terms of how stringent the requirement of individuation is applied. This issue is elaborated upon in Part III (Chapter 10, section 10.4) as it is of particular importance in working out the extent to which information relating primarily to a collective entity (eg, private corporation) may also be treated as relating to an individual person and thus fall within the ambit of those data protection laws that expressly safeguard data on individuals only. The issue is also taken up in Part IV (Chapter 18, section 18.2) in connection with analysis of the extent to which data protection laws may regulate data linked primarily to machine addresses.

Five further issues are of relevance in determining what is "personal information" pursuant to data protection laws. First of all, what exactly is meant by the concept of identification? Secondly, how easily or practicably must a person be identified from information in order for the latter to be regarded as "personal"? Thirdly, who is the legally relevant agent of identification (ie, the person who is to carry out identification)? Fourthly, to what extent must the link between a set of data and a person be objectively valid? Fifthly, to what extent is the use of auxiliary information permitted in the identification process? Is information "personal" if it allows a person to be identified only in combination with other (auxiliary) information? These issues are elaborated upon in Chapter 10 (section 10.4) and Chapter 18 (section 18.2) for the same reasons as are given with respect to the individuation issue above.

2.4.2. Coverage with regard to type of data processing

Data protection laws typically regulate all or most stages of the data-processing cycle, including registration, storage, retrieval and dissemination of personal data. Thus, Art 2(b) of the EC Directive broadly defines "processing" as

any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

The concept of "processing" used in the CoE Convention is a little narrower: it does not cover collection of data, nor data processing carried out by entirely manual (non-automated) means.[208] However, Art 3 allows contracting states to apply the rules laid down in the Convention to data processed manually. Moreover, some of the Convention's provisions, notably Art 5(a),[209] pertain directly to the collection of data.

Some national data protection laws focus mainly on the registration, as opposed to collection, of personal data. This is the case, for instance, with Norway's Act.[210] It should be noted, though, that the Norwegian Data Inspectorate is expressly empowered to issue rules on the collection ("innsamling") of data that are to be included in a register licensed by the Inspectorate (see s 11(2)(1)). The focus of Norway's Act on the registration of data is part and parcel of a more general focus on the creation and use of personal data registers; ie, files, records and the like in which "personal information is systematically stored so that information concerning an individual person may be retrieved" (s 1(2)). This focus on registers is shared by some other data protection instruments, including the CoE Convention and UN Guidelines.[211] Also the first draft of the EC Directive was centred primarily on creation and use of "personal data files".[212]

This regulatory focus on registers and files is typical for data protection instruments drafted in the 1970s and early 1980s. It reflects a belief from those times that systematically structured collections of personal data pose the principal risks for data subjects' interests in privacy, integrity and the like.[213] It further reflects the character of computerised data processing which predominated in that period - personal computers and distributed computer networks were then in their infancy. To some extent, such a focus is also symptomatic of a concern to delimit the ambit of data protection laws so as to prevent regulatory overreaching and collision with other laws.[214]

The regulatory focus of the EC Directive as finally adopted is on the "processing" of personal data regardless (almost) of the way in which the data are organised. This is also the case with the OECD Guidelines, along with recently enacted national data protection laws.[215] Indeed, it is probable that future laws will largely dispense with the register/file concept, partly in order to avoid their marginalisation in a world of distributed computer networks,[216] and partly in order to conform with the EC Directive. The move is not only sensible in view of technological developments; it also makes for increased flexibility of the laws' application. It enhances, for example, their ability to embrace forms of data processing, such as video surveillance, which can fit uncomfortably within the register/file concept. Further, it allows for easier avoidance of complex and arbitrary line-drawing exercises in evaluating what constitutes a register and where the boundaries between one register and other registers should be fixed.

Nevertheless, the register/file concept has not been totally ditched by the Directive; it lives on with respect to manually processed data. Pursuant to the Directive, purely manual data processing is to be regulated insofar as the data form or are intended to form part of a "filing system" (Art 3(1)). By "filing system" is meant "any structured set of personal data which are accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis" (Art 2(c)). As this definition suggests, retainment of the register/file concept here is, in essence, a consequence of a concern (noted in section 2.4.1) to limit the application of data protection laws to data that can be linked to a particular person without great difficulty,[217] as it is in relation to this sort of data the risk to data protection interests primarily lies.[218] But retainment is also symptomatic of a concern to prevent data protection laws from overreaching themselves in a practical, regulatory sense.[219]

Otherwise, the provisions of the Directive are largely technology-neutral. This is in contrast to the CoE Convention and UN Guidelines which cover automated data-processing practices to the almost total exclusion of manual (non-automated) processing.[220] The data protection legislation of a large number of countries, such as Austria, Ireland, Japan, Luxembourg, Sweden and the UK, also cover, or initially covered, automated data-processing practices only. This focus on automation is symptomatic of a belief that it is the increasing usage of computers, particularly for decision-making purposes, which represents the main threat to data protection interests.[221]

However, due to the requirements of the EC Directive, data protection laws will increasingly extend to both manual and computerised processing of personal data. This broadening of focus is partly grounded on a desire to prevent the circumvention of laws that govern automated processing only.[222] It is also partly grounded on the realisation that manually processed data can have significant implications for the privacy, autonomy and integrity interests of data subjects - indeed, often the most sensitive personal data (eg, on persons' mental and physical health) are to be found in manual record systems. And it is partly technology-induced insofar as data in modern information systems tend to be processed using a mixture of automated, semi-automated and manual techniques, the line between which can often be difficult to draw.[223] This does not mean that manual and automated techniques will be uniformly regulated in all respects. The EC Directive allows for some discrimination here. For instance, Art 18 of the Directive does not require national data protection authorities to be notified of purely manual data-processing operations.[224]

2.4.3. Coverage with regard to public and private sectors

All of the international data protection instruments are intended to apply to the processing of personal data in both the public and private sectors. Not surprisingly, a majority of national data protection laws have a similar ambit. In some of these laws, however, there is differentiated regulation for each sector,[225] with the processing practices of public sector bodies typically being subjected to more stringent regulation than those of private sector bodies.[226] Such differentiation is expected to diminish considerably in the future national legislation of EU member states, given its absence from the EC Directive.

A handful of countries - Australia, Canada, USA, Japan and the Republic of Korea (South Korea) - have national/federal data protection laws which, with minor exceptions,[227] regulate the data-processing activities of national/federal government agencies only. Constitutional limitations on the legislative powers of the federal governments partly account for the restricted ambit of these laws, but other factors are often more significant. In the USA, for example, there is a general distrust of State dirigism, accompanied by scepticism towards legislative regulation of the private sector except where there are proven to exist flagrant imbalances of power between private parties which cannot be corrected otherwise than by legislative intervention.[228] In the field of privacy/data protection, this scepticism has resulted in the eschewal of "omnibus" legislative solutions in favour of ad hoc enactment of sectoral laws dealing with, in the words of Joel Reidenberg, "narrowly identified" problems.[229] The coverage these laws offer with respect to processing of personal data by private sector bodies remains haphazard and incomplete.[230]

Much the same can be said of the coverage currently offered by equivalent legislative regimes for data protection with respect to the Australian and Canadian private sectors.[231] In Quebec, though, a comprehensive, "European-style" data protection regime has been established pursuant to the enactment in 1993 of the Act on Protection of Personal Information in the Private Sector. There is also a proposal in Canada for the introduction in the near future of federal data protection legislation giving comprehensive coverage of the private sector.[232]

In Australia, the policy direction of the federal government with respect to introducing similar legislation has been peripatetic. In March 1997, the government reversed its earlier support for the enactment of such legislation, on the grounds that extensive regulation of the private sector would result in overly burdensome compliance costs for Australian business.[233] The government then decided to extend coverage of the federal Privacy Act to private companies that are contracted to process personal data under outsourcing agreements with federal government agencies.[234] In December 1998, the government again warmed to the enactment of comprehensive legislation, declaring that it would establish a "light touch" legislative regime based on industry codes of practice.[235] Victoria also appears intent on introducing data protection legislation covering both the state government and private sectors.[236] Setting an important precedent in this regard is the recent enactment by the Australian Capital Territory of its Health Records (Privacy and Access) Act 1997 which regulates both public and private sector processing of personal health information.

With the adoption of the EC Directive and the resultant threat that EU countries will prevent, pursuant to Art 25 of the Directive, transfers of personal data to countries without "adequate" levels of data protection,[237] there is now greater legal (and economic) pressure on countries like the USA, Canada, Japan and Australia to enact comprehensive data protection laws to regulate the private sector. At the same time, one should not overlook the possibility of one or more of the latter countries' governments (particularly that of the USA) thumbing their noses at the EU in defiance of the "adequacy" criterion laid down in the Directive.[238] The extent to which this might occur is likely to depend on how stringently and consistently the "adequacy" criterion is applied, together with the extent to which implementation of Art 25 (and Art 26) is found to conflict with the 1994 General Agreement on Trade in Services.239 Other factors might also prove significant, not least the extent to which business enterprises in, say, the USA tire of having to cope with the patchy, sometimes uncertain and inconsistent legal regimes for data protection in that country.

Finally, it should be emphasised that data protection laws covering the private and/or public sectors rarely regulate all processing of personal data. For example, exemptions from the laws in their entirety or from their central provisions are often made with respect to data-processing operations of national security services,[240] data-processing operations of the mass media for journalistic purposes,[241] and/or data processing for purely personal or domestic purposes.[242]

