Data Privacy Law: The Person Behind the Data
Every click, purchase, journey, and heartbeat recorded by a connected device leaves a trace, and those traces, aggregated, can reveal a life more intimately than any diary. Data privacy law is the legal system's response to this new transparency. It proceeds from a simple conviction: information about an identifiable person is not mere raw material for commerce or government but an extension of that person's dignity, to be handled under law and with regard for the individual it describes.
The intellectual roots lie in the older right of privacy, famously articulated in American legal writing as early as 1890, and in the reaction of post-war Europe against the surveillance states it had suffered. Early data protection statutes of the 1970s addressed the mainframe computers of government; today's comprehensive laws, led by the European Union's General Data Protection Regulation of 2018, govern every organization that processes personal data for almost any purpose.
The model has proved contagious. From Brazil to India, Japan to California, legislators have adopted its vocabulary of controllers, processors, lawful bases, and data subject rights.
Key Points
- Processing of personal data requires a lawful basis such as consent or legitimate interest.
- Individuals hold rights of access, rectification, erasure, and portability.
- Data must be collected for specified purposes and kept no longer than needed.
- Controllers bear accountability: impact assessments, security, and breach notification.
- Transfers abroad are restricted unless the destination ensures adequate protection.
Principles and Individual Rights
Data protection law governs any processing of personal data, from collection to deletion, and it distinguishes the controller, who decides why and how data is used, from the processor, who acts on the controller's instructions. Processing is unlawful by default unless justified: by the individual's freely given and informed consent, by contractual necessity, by legal obligation, by the protection of vital interests, by a public task, or by legitimate interests balanced against the rights of the individual. Special categories of data, such as health, biometric, and political information, demand still stronger justification.
Foundational principles discipline every stage: data must be handled lawfully, fairly, and transparently; collected for specified purposes; minimized to what is necessary; kept accurate; stored no longer than needed; and secured against breach. Around these principles stand enforceable rights of the data subject: to know what is held, to correct errors, to demand erasure in defined cases, to restrict or object to processing, to receive data in portable form, and not to be subject to wholly automated decisions with serious effects.
Accountability and the Global Web
Modern statutes shift the burden of proof onto organizations. Controllers must document their processing, appoint protection officers when required, assess the impact of risky operations such as large-scale profiling, bake privacy into product design, and report serious breaches to regulators, typically within days, and to affected individuals when harm is likely. Supervisory authorities wield investigatory powers and fines that, in the European regime, can reach four percent of worldwide turnover, giving privacy a boardroom salience it never previously enjoyed.
Because data flows ignore borders, transfer rules form the regime's outer wall: personal data may leave the protected zone only for destinations offering adequate safeguards, through official adequacy decisions, standard contractual clauses, or binding corporate rules. The continuing negotiation between open data flows and personal dignity, and between innovation and restraint, defines the frontier of this young and rapidly maturing field. This overview is educational and not legal advice.
← Back to the library