Menu

Summary

The General Data Protection Regulation, entering into force from 25 May 2018, should establish pan-European data processing rules, facilitating the cross-border exchange of data and thereby promoting the functioning of the internal market. In reality, the GDPR leaves several (incl. important) data protection nuances to be regulated by the member states. This means that the new reality in data protection will not be the originally advertised single harmonised set of rules, but will remain a scattered overall picture. This raises a question about the applicable law.

While Article 4 of the Data Protection Directive, valid until 25 May 2018, contains rules on the applicable law, including the law within the Union, then the new GDPR mentions the law applicable within the European Union only in one of the recitals of the introductory part of the regulation.

To discuss the dilemma of applicable law in data protection, the authors first analyse the set of rules for determining the applicable law established within the directive together with relevant case law. Then, the same problem is addressed within the context of the GDPR to be implemented in 2018. Among other things, the analysis includes the rules of conflict of private law as the possible alternative in resolving the dilemma of law in data protection law applicable within the Union.

Close

Enter