← All articles
law and citizenshipdata protectionprivacyregulationSeptember 17, 20264 min read

What Is Data Protection Law? Rules About Using Information, Not Hiding It

By the BrainSnail editorial team. How these articles are written and checked, and how to tell us when one is wrong.

Data protection law is widely assumed to be about keeping information secret. It is mostly about the conditions under which organisations may use information about people at all, who decides, and what the person concerned can require afterwards. Security is one obligation among several, and it is not the one that generates most of the arguments.

The principles

Modern regimes descend from principles set out in the 1980s and codified most influentially in European law, and the same set recurs across jurisdictions:

  • Lawfulness, fairness and transparency, meaning there must be a legal basis for using the data and people must be told what is happening in language they can understand
  • Purpose limitation, meaning data collected for one purpose may not simply be reused for an unrelated one
  • Data minimisation, collecting only what is necessary for the stated purpose rather than everything that might be useful later
  • Accuracy, with an obligation to correct errors
  • Storage limitation, meaning data must not be kept indefinitely once the purpose is fulfilled
  • Integrity and confidentiality, which is the security obligation
  • Accountability, requiring organisations to demonstrate compliance rather than merely assert it, which is what produces records, assessments and designated officers

Consent is not the main route

A widespread misunderstanding is that organisations need consent to process personal data, which produced the reflex of asking for it everywhere. Consent is one lawful basis among several and is frequently the weakest, because it must be freely given, specific, informed and as easy to withdraw as to give, which is difficult to achieve in an employment relationship or where a service cannot be used without agreeing. The other bases are usually more appropriate: performing a contract covers the data needed to deliver a service someone asked for, legal obligation covers what the law requires an organisation to keep, vital interests covers emergencies, public task covers public authorities, and legitimate interests covers processing an organisation reasonably needs to do provided it does not override the individual's rights, which requires a documented balancing assessment. Choosing the right basis matters because the individual's rights differ depending on which applies, and because a basis cannot be switched later if the first choice proves inconvenient.

What individuals can require

The rights available are the part most people encounter directly. A subject access request entitles a person to a copy of the data an organisation holds about them and information about how it is used, usually free and within a set period, and it is used heavily in employment disputes. Rectification allows correction of inaccurate data. Erasure, frequently called the right to be forgotten, applies in defined circumstances rather than universally and was established in a 2014 European ruling requiring search engines to delist results that are inadequate, irrelevant or excessive, which is a delisting from search rather than deletion of the underlying page. Portability allows data to be taken to another provider in a usable format. Objection allows a person to require processing to stop in certain cases, with direct marketing being absolute. And there are rights concerning automated decisions producing legal or similarly significant effects, including a right to human intervention, which is becoming the contested frontier as automated systems make decisions about credit, employment and benefits.

Enforcement and the arguments

European rules apply to any organisation processing the data of people in the region regardless of where it is based, which is what gave them global reach, and penalties are set as a percentage of worldwide turnover, which made compliance a board-level matter rather than an administrative one. Several very large fines have been issued. The criticisms are substantial on both sides. Businesses argue that compliance costs fall hardest on small organisations, that the rules are interpreted inconsistently between national regulators, and that enforcement against the largest companies has been slow. Privacy advocates argue that the consent banner regime has produced fatigue rather than control, that legitimate interests is used to justify almost anything, and that enforcement against the dominant platforms has been too slow to change behaviour. The transfer of data across borders remains genuinely unsettled, with successive arrangements between Europe and the United States struck down by courts over government access to data, and an underlying conflict between surveillance powers and data protection that no legal drafting has resolved.

The takeaway

Data protection governs whether and how organisations may use personal information, through principles requiring a lawful basis, a stated purpose, minimal collection, limited retention, security and demonstrable accountability. Consent is only one basis and frequently the weakest, since it must be genuinely free, with contract, legal obligation and legitimate interests usually more appropriate. Individuals can obtain copies, correct errors, object, port data and contest significant automated decisions. Cross-border transfer remains legally unresolved.

Practise this

The Law & Citizenship track

Rules, rights, courts and how countries govern themselves - from playground fairness to constitutional law, one tiny step at a time.

12 units and 1,302 questions, each with a written explanation. Every unit page shows what it covers and real example questions before you start.