The Risk-Based Approach to Personal Data Protection and the Response of the International Trade Law
- 1 School of International Law, China University of Political Science and Law, Beijing, China
Abstract
Data processing and transferring activities by businesses often result in increased risks to the rights and freedoms of data subjects, whereas the prescriptive and right-based approach, the dominating approach employed by lawmakers, fails to protect personal data as expected due to its inherent defects in managing risks. Accordingly, the risk-based approach, which endows businesses to calibrate their obligations of protecting personal data in terms of risks to enhance compliance with the principles and rules of personal data protection law, is introduced to the national and regional legislation as well as the international trade law to better manage risks so as to enhance the effectiveness of personal data protection. This paper investigates the backgrounds, meanings, functions, and advantages of the risk-based approach to personal data protection, and its embodiments in the EU, US, and China legislation, as well as in the international trade law such as USMCA and WTO members’ consolidated negotiating texts produced in the Joint Statement Initiative on e-commerce. The paper then explores the mysterious and complicated “necessary and proportionate” test inherently contained in the risk-based approach, and whether data localization measures could pass such a test.
- Article 29 Data Protection Working Party (2014). Statement on the Role of a Risk-Based Approach in Data Protection Legal Frameworks (14/EN WP 218) (p. 2).
- Barak, A. (2012). Proportionality: Constitutional Rights and Their Limitations (p. 356). Cambridge University Press. https://doi.org/10.1017/CBO9781139035293
- Casalini, F., & López González, J. (2019). Trade and Cross-Border Data Flows (p. 8). OECD Trade Policy Papers No. 220.
- Cate, F. H. (2006). The Failure of Fair Information Practice Principles. In K. J. Winn (Ed.), Consumer Protection in the Age of the “Information Economy” (pp. 343-375). Routledge.
- Centre for Information Policy Leadership (2014). A Risk-Based Approach to Privacy: Improving Effectiveness in Practice. https://www.huntonak.com/files/upload/Post-Paris_Risk_Paper_June_2014.pdf
- Eduarda Gonçalves, M. (2020). The Risk-Based Approach under the New EU Data Protection Regulation: A Critical Perspective. Journal of Risk Research, 23, 140-143. https://doi.org/10.1080/13669877.2018.1517381
- EPIC (2021). What the FTC Could Be Doing (But Isn’t) to Protect Privacy—The FTC’S Unused Authorities. https://epic.org/wp-content/uploads/2021/10/EPIC-FTC-Unused-Authorities-Report-June2021.pdf
- EPIC (2022). Hearing on Big Data: Privacy Risks and Needed Reforms in the Public and Private Sectors. https://epic.org/documents/hearing-on-big-data-privacy-risks-and-needed-reforms-in-the-public-and-private-sectors
- EPIC (2023). The US Sector-Specific Federal Privacy Laws. https://epic.org/issues/privacy-laws/united-states
- Fazlioglu, M. (2022). US Federal Privacy Legislation Tracker. https://iapp.org/resources/article/us-federal-privacy-legislation-tracker
- Gellert, R. (2016). We Have Always Managed Risks in Data Protection Law: Understanding the Similarities and Differences between the Rights-Based and the Risk-Based Approaches to Data Protection. European Data Protection Law Review, 2, 481-492. https://doi.org/10.21552/EDPL/2016/4/7
- Kuner, C. et al. (2017). The Rise of Cybersecurity and Its Impact on Data Protection. International Data Privacy Law, 7, 73-75. https://doi.org/10.1093/idpl/ipx009
- Lively, K. T. (2022). US State Privacy Legislation Tracker. https://iapp.org/resources/article/us-state-privacy-legislation-tracker
- López González, J., & Jouanjean, M. (2017). Digital Trade: Developing a Framework for Analysis (p. 10). OECD Trade Policy Papers No. 205.