Ahead of Data Privacy Day on Thursday (28th January) I’ve gone back in time to look at the evolution of data protection rights to try and identify how we got to where we are.
In 1890 the Harvard Law Review carried an article by Warren and Brandeis (largely written by the latter) on ‘The Right to Privacy’ which is regarded as one of the most influential essays in American legal history, extolling the ‘right to be let alone’. The trigger apparently was the invasion of journalists onto a society wedding, which reassuringly reminds us of Hacked Off on these shores in more recent times.
1948 saw the adoption of the universal declaration of human rights, with the right to privacy coming in at number 12. By 1950, the right to respect for private and family life [including].. his correspondence was promoted to Article 8 in the European Convention of Human Rights.
It was the US that led the way regarding the right to request documents containing personal data from public bodies, with the Freedom of Information Act (not to be confused with our own FOI law) in 1967. Other countries followed suit in this area. In 1970, the German state of Hesse enacted the world’s first Data Protection Act (ahead of the federal act in 1978). Sweden passed the Data Act in 1973, making it illegal for any person or company to use information systems of any kind to handle personal data without a license. It was the proliferation of these ‘information systems’ that led the OECD to issue guidelines on data protection in 1980, with a statement of principles that are still relevant some 40 years on. These principles highlight collection limitation, purpose limitation, data quality, use limitation, security safeguards, openness and the individual participation (which today would be regarded as data subject rights).
A year later, on the 28th January 1981, the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data is opened for signature which, in time, had 47 signatories and 55 ratifiers. It recognises that data can flow across national borders and seeks protection for citizens. It was operative from 1985, some 10 years before Directive 95/46/EC,
In the meantime there was a couple of interesting cases. In 1983, the attempts by the German government to conduct the census through electronic data processing were undone by the Federal Constitutional Court upholding individuals rights to ‘informational self-determination’ finding certain aspects of the law as unconstitutional. In R v Brown, consideration was given to whether the access to data on the National Police Computer for private reasons was unlawful, with significant discussion around the term ‘use’.
In 1995, the European Data Protection Directive emerged to regulate the free movement of data and its processing within the European Union. This led to the 1998 Data Protection Act in the UK, with definitions for personal and sensitive personal data. It would be eventually replaced by the GDPR and was a signficant effort at harmonising the landscape across the EU.
In 2002, the EU also adopted the directive on Privacy and Electronic Communications, building on the earlier efforts in the ’95 directive and covering the “right to privacy in the electronic communication sector” and free movement of data, communication equipment and services. This directive was embodied in the 2003 Privacy and Electronic Communications Regulations (PECR) – regulations which have been updated 6 times since (including twice in 2018) and are chiefly of importance to anyone involved in electronic marketing, especially ensuring compliance with both PECR & GDPR. In 2009 they evolved to consider the principle ways of communicating with customers – email addresses and mobile phone numbers.
In 2006 a further directive, this time on data retention came in to regulate the time member states had to store details of telecommunications data. Police and security services could request this data (subject to court approval) This directive however, was found by the CJEU to violate the EUs charter of fundamental rights regarding privacy.
Wikileaks first started publishing data in 2006, but it was in 2010 that it came to prominence publishing diplomatic cables, footage from the Collatterel Murder airstrike in Baghdad that killed journalists from Reuters and the Iraqi War Logs (records of US Army field reports on Iraq, including some 66,000 civilian deaths). Obviously their efforts are not well received by national governments (though one could conclude their objections weren’t based on ‘citizen privacy’!)
2013 saw the adoption of a regulation on the notification of personal data breaches (again building on the 2002 directive). Telecommunications companies were obliged to let authorities and individuals of breaches. In the UK of course, 2010 saw the ICO have the power to fine organisations up to £500,000 under the Data Protection Act (1998 as was) and PECR, but there was no compulsion to notify of breaches. This changed for all organisations under GDPR in 2018.
The right to be forgotten came into focus in 2014, when the court ruled that internet search engines (such as Google) are responsible for the content they point to and if a request comes in for personal data to be removed then it needs to comply with EU data privacy law. This ruling however doesn’t have global reach as Google won a case in 2019 effectively meaning that only people in the EU will forget you!
After four years of discussion, the General Data Protection Regulation was adopted in 2016 and came into practical being on 25th May 2018. With the UK falling out of the EU, a UK GDPR was created with the same provisions, and the Data Protection Act 2018 passed to cover the areas of nation state divergence permitted (including the personal data issues around law and enforcement). What happens next in terms of UK adequacy and the development of AI remains to be seen.