03/02/2020
CURIA - Documents
... data-processing systems are designed to serve man; … they must, whatever the nationality or residence of
natural persons, respect their fundamental rights and freedoms, notably the right to privacy, and contribute to …
the well-being of individuals;
… the object of the national laws on the processing of personal data is to protect fundamental rights and
freedoms, notably the right to privacy, which is recognised both in Article 8 of the European Convention for the
Protection of Human Rights and Fundamental Freedoms[, signed in Rome on 4 November 1950,] and in the general
principles of Community law; …, for that reason, the approximation of those laws must not result in any lessening
of the protection they afford but must, on the contrary, seek to ensure a high level of protection in the Community;
… cross-border flows of personal data are necessary to the expansion of international trade; … the protection of
individuals guaranteed in the Community by this Directive does not stand in the way of transfers of personal data
to third countries which ensure an adequate level of protection; … the adequacy of the level of protection afforded
by a third country must be assessed in the light of all the circumstances surrounding the transfer operation or set
of transfer operations;
… on the other hand, the transfer of personal data to a third country which does not ensure an adequate level of
protection must be prohibited;
… in any event, transfers to third countries may be effected only in full compliance with the provisions adopted by
the Member States pursuant to this Directive, and in particular Article 8 thereof;
… the establishment in Member States of supervisory authorities, exercising their functions with complete
independence, is an essential component of the protection of individuals with regard to the processing of personal
data;
… such authorities must have the necessary means to perform their duties, including powers of investigation and
intervention, particularly in cases of complaints from individuals, and powers to engage in legal proceedings; ...’
Articles 1, 2, 25, 26, 28 and 31 of Directive 95/46 provide:
‘Article 1
Object of the Directive
1.
In accordance with this Directive, Member States shall protect the fundamental rights and freedoms of
natural persons, and in particular their right to privacy with respect to the processing of personal data.
...
Article 2
Definitions
For the purposes of this Directive:
“personal data” shall mean any information relating to an identified or identifiable natural person (“data subject”);
an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an
identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or
social identity;
“processing of personal data” (“processing”) shall mean any operation or set of operations which is performed
upon personal data, whether or not by automatic means, such as collection, recording, organisation, storage,
adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making
available, alignment or combination, blocking, erasure or destruction;
“controller” shall mean the natural or legal person, public authority, agency or any other body which alone or
jointly with others determines the purposes and means of the processing of personal data; where the purposes and
means of processing are determined by national or Community laws or regulations, the controller or the specific
criteria for his nomination may be designated by national or Community law;
...
Article 25
Principles
1.
The Member States shall provide that the transfer to a third country of personal data which are undergoing
processing or are intended for processing after transfer may take place only if, without prejudice to compliance with
the national provisions adopted pursuant to the other provisions of this Directive, the third country in question
ensures an adequate level of protection.
2.
The adequacy of the level of protection afforded by a third country shall be assessed in the light of all the
circumstances surrounding a data transfer operation or set of data transfer operations; particular consideration
shall be given to the nature of the data, the purpose and duration of the proposed processing operation or
operations, the country of origin and country of final destination, the rules of law, both general and sectoral, in
force in the third country in question and the professional rules and security measures which are complied with in
that country.
3.
The Member States and the Commission shall inform each other of cases where they consider that a third
country does not ensure an adequate level of protection within the meaning of paragraph 2.
4.
Where the Commission finds, under the procedure provided for in Article 31(2), that a third country does not
ensure an adequate level of protection within the meaning of paragraph 2 of this Article, Member States shall take
the measures necessary to prevent any transfer of data of the same type to the third country in question.
5.
At the appropriate time, the Commission shall enter into negotiations with a view to remedying the situation
resulting from the finding made pursuant to paragraph 4.
curia.europa.eu/juris/document/document.jsf;jsessionid=9ea7d2dc30dd5b610279af57461688cfc1d680446584.e34KaxiLc3qMb40Rch0SaxuRbN90?text=&doc…
2/14