By commenting, you agree to the
The right to privacy and data protection framework are intertwined precepts, becoming the new normal in the cyber world. Privacy is a gateway right to buttress a bundle of other rights. India became the first nation to explicitly declare privacy as the fundamental right, under the aegis of right to life under Article 21 of the Indian Constitution. However, other jurisdictions like the United States, Germany, South Africa, Canada etc. provide greater importance to protect privacy rights specially to protect the right to self-determination. In the modern era of the gigantic digital world, data has become the most precious but vulnerable commodity. COVID-19 pandemic became a turning point for digital dependency mainly on ‘Anything-as-a-Service”. Due to exponential growth of computing power, internet penetration, cloud storage, and AI, data protection increasingly became a global challenge and priority. The data protection framework largely has four stages – collection, processing, storage and sharing of data.Evolution of Data Protection Framework
Historically the data protection regime ranges from paper files to the digital era. Earlier, data protection was more confined to government bureaucracy revolving largely around administrative control and privacy concerns in terms of surveillance. The Hessian Data Protection Act, 1970 in the German State of Hesse became the first statute globally on data protection. The Sweden’s Data Protection Act was promulgated in 1973, followed by the Federal Data Protection, 1977 in Germany, the Informatique et Libertés, 1978 in France and the Data Protection Act, 1984 in the United Kingdom. In Europe, OECD Guidelines on Protection of Privacy and Transborder Flows of Personal Data in 1980 became pivotal to laid down foundation principles of data security including purpose specification, collection and use limitations, security safeguards, accountability etc. These guidelines largely inspired subsequent legal lexicon and framework on data security. In 1995, European Data Protection Directives 95/46/EC harmonized national laws and introduced the idea of adequate protection for cross-border transfers and established core rights for data principals such as access and correction and creation of independent data protection authorities. Under this Directive, the EU and US negotiated the Safe Harbour Agreement in 2000. In fact, by the 2000s, personal data was not limited to government files, rather it spread its wings by fuelling entire business models leading to massive risks like identity theft, data selling, opaque profiling and targeted misinformation.
Home
United States
USA — IT The digital age dilemma: A look at data protection framework and legality...