Under the European Union’s Charter of Fundamental Rights and the E-Privacy Directive 2002/58/EC, privacy is considered a constitutional right.
In May 2016, the European Parliament and the Council formally adopted the General Data Protection Regulation (‘GDPR’). The GDPR entered into force on the 24th May 2016. Now law, there will be a two-year implementation period before the GDPR comes into effect, and businesses will need to comply with its provisions as of May 25, 2018.
The EU had a comprehensive privacy protection ruling starting with The Data Protection Directive (1995) and The Internet Privacy Law of 2002. It was shared by every Member State.
Certain EU countries have their own privacy laws, which can be more or less restrictive than the EU regulations.
Within the EU, a part France, Germany is considered the strictest about privacy regulations. Germany’s Bundesdatenschutzgesetz (BDSG), Germany’s federal data protection act, was revised in 2009 to be in alignment with new digital data protection and security practices. Germany’s 16 states are required to establish a state-run Data Protection Authority as well as operate under state data protection laws and privacy policies.
Still, the EU laws and the GDPR go further than the US privacy laws, but in many ways are not comparable to HIPAA privacy legislation.
The EU privacy protections are far more wide-ranging than those in the United States. They were developed to protect privacy across all areas, while many privacy laws in the U.S. were a response to a certain industry’s bad practices. In the U.S. some privacy legislation in some states is more protective than others.
HIPAA was a complicated reworking of healthcare insurance regulations with a focus on allowing employees to transfer (make portable) their employer-granted health insurance from one job to another. This is why it was called “The Health Insurance Portability and Accountability Act of 1996.” Before this, if you lost your job, something that happens frequently in the U.S., you lost your family’s healthcare insurance coverage. The privacy laws about how healthcare data would be handled were an add-in to the regulation, not the primary focus.
Moreover, there are U.S. laws at the federal level governing all 50 states and some states also have additional strict privacy laws like the California Online Privacy Protection Act.