§1 THE NEW EU DATA PROTECTION FRAMEWORK — STRONGER PROTECTION and NEW OPPORTUNITIES
The Regulation continues to follow the approach of the Data Protection Directive, but, building on 20 years of EU data protection legislation and relevant case law, it clarifies and modernises the data protection rules; it introduces a number of novel elements that strengthen the protection of individual rights and open opportunities for companies and business, in particular: ·A harmonised legal framework leading to a uniform application of rules to the benefit of the EU digital single market. This means one single set of rules for citizens and businesses. This will address today’s situation where EU Member States have implemented the Directive’s rules differently. To ensure a uniform and consistent application in all Member States, a one-stop-shop mechanism is introduced; ·A level-playing field for all companies operating in the EU market. The Regulation requires companies based outside the EU to apply the same rules as companies based in the EU if they are offering goods and services related to the personal data or are monitoring the behaviour of individuals in the Union. Companies operating from outside the EU and active in the Single market must, in certain circumstances, appoint a representative in the EU that citizens and authorities can address in addition to or instead of the company based abroad; ·The principles of data protection by design and by default creating incentives for innovative solutions to address data protection issues from the start; ·Stronger individuals’ rights: The Regulation introduces new transparency requirements; strengthened rights of information, access and erasure (‘right to be forgotten’); silence or inactivity will no longer be considered as valid consent as a clear affirmative action to express the consent is required; protecting children online; ·More control over personal data for individuals. The Regulation establishes a new right to data portability, allowing citizens to ask a company or an organisation to receive back personal data he/she provided to that company or organisation on the basis of consent or contract; it will also allow for such personal data to be transmitted directly to another company or organisation, when it is technically feasible. Since it allows the direct transmission of personal data from one company or organisation to another, this right will also support the free flow of personal data in the EU, avoid the 'lock-in' of personal data, and encourage competition between companies. Making it easier for citizens to switch between different service providers will encourage the development of new services in the context of the digital single market strategy; ·Stronger protection against data breaches. The Regulation lays down a comprehensive set of rules on personal data breaches. It clearly defines what is a ‘personal data breach’, it introduces an obligation to notify the supervisory authority at the latest within 72 hours when the data breach is likely to pose a risk to the individual’s rights and freedoms. In certain circumstances, it obliges to inform the person whose data is concerned by the breach. This greatly reinforces the protection compared to the current situation in the EU, in which only electronic communication service providers, operators of essential services and digital service providers are obliged to notify data breaches under the Directive on privacy and electronic communications ('ePrivacy Directive') 7 and the Directive on the security of network and information systems (NIS) Directive 8 respectively; ·The Regulation gives all data protection authorities the power to impose fines on controllers and processors. Currently not all of them have this power. This will allow for better implementation of the rules. The fines can go up to EUR 20 million or, in the case of a company, 4% of the worldwide annual turnover; ·More flexibility for controllers and processors processing personal data due to unambiguous provisions on responsibility (the accountability principle). The Regulation moves away from a system of notification to the principle of accountability. This latter is implemented through scalable obligations depending on risk (e.g. the presence of a Data Protection Officer or the obligation to conduct data protection impact assessments). A new tool is introduced in order to help to assess the risk before one starts with the processing: the data protection impact assessment. The latter is required whenever processing is likely to result in a high risk to the rights and freedoms of individuals. Three situations are specifically mentioned as such under the Regulation: when a company evaluates systematically and extensively personal aspects of an individual (including profiling), when it processes sensitive data on a large scale or systematically monitors public areas on a large scale. National data protection authorities will have to make public the lists of cases requiring a data protection impact assessment 9 ; ·More clarity on the obligations of processors and the responsibility of controllers when selecting a processor; ·A modern governance system to ensure that the rules are enforced more consistently and strongly. This includes harmonised powers for the data protection authorities including on fines and new mechanisms for these authorities to cooperate in a network; ·The protection of the personal data guaranteed by the Regulation travels with the data outside the EU ensuring a high level of protection 10 . While the architecture of the rules on international transfers in the Regulation remains essentially the same as that of the 1995 Directive, the reform clarifies and simplifies their use and introduces new tools for transfers. As regards adequacy decisions the Regulation introduces a precise and detailed catalogue of elements that the Commission must take into account when assessing whether a foreign system adequately protects personal data. The Regulation also formalises and expands on the number of alternative transfer instruments, such as standard contractual clauses and binding corporate rules. The revised Regulation for EU institutions, bodies and offices and agencies 11 and the Regulation on Privacy and Electronic Communications ('ePrivacy Regulation') 12 which are currently being negotiated, once adopted, will ensure that the EU is equipped with a strong and comprehensive set of data protection rules 13 .
Source: EUR-Lex (Cellar) · retrieved 2026-09-07