There are several national data protection authorities across the world, tasked with protecting information privacy. In the
European Union
The European Union (EU) is a supranational union, supranational political union, political and economic union of Member state of the European Union, member states that are Geography of the European Union, located primarily in Europe. The u ...
and the
EFTA
The European Free Trade Association (EFTA) is a regional trade organization and free trade area consisting of four European states: Iceland, Liechtenstein, Norway and Switzerland. The organization operates in parallel with the European Union ...
member countries, their status was formalized by the
Data Protection Directive
The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, was a European Union directive which regulated the processing of personal data within the European Union (EU) and the free movement of such data. The Data ...
and they were involved in the Madrid Resolution.
This project is a part of the work of the
International Law Commission
The International Law Commission (ILC) is a body of experts responsible for helping develop and codify international law. It is composed of 34 individuals recognized for their expertise and qualifications in international law, who are elected by t ...
of the
United Nations
The United Nations (UN) is the Earth, global intergovernmental organization established by the signing of the Charter of the United Nations, UN Charter on 26 June 1945 with the stated purpose of maintaining international peace and internationa ...
.
Authorities by group of states
* On the European level, it is the G29 and the
European Data Protection Supervisor
The European Data Protection Supervisor (EDPS) is an independent supervisory authority whose primary objective is to monitor and ensure that European institutions and bodies respect the right to privacy and data protection when they process p ...
(EDPS). The process was backed in 2005 by the
Council of Europe
The Council of Europe (CoE; , CdE) is an international organisation with the goal of upholding human rights, democracy and the Law in Europe, rule of law in Europe. Founded in 1949, it is Europe's oldest intergovernmental organisation, represe ...
, during the
World Summit on the Information Society
The World Summit on the Information Society (WSIS) was a two-phase United Nations-sponsored summit on information, communication and, in broad terms, the information society that took place in 2003 in Geneva and in 2005 in Tunis. WSIS Forums hav ...
(Tunis, November 2005), and in 2006/2007 within forums on Internet governance (Athens 2006, Rio 2007).
* On 12 June 2007,
OECD
The Organisation for Economic Co-operation and Development (OECD; , OCDE) is an international organization, intergovernmental organization with 38 member countries, founded in 1961 to stimulate economic progress and international trade, wor ...
issued a recommendation entitled "OECD Recommendation on Cross-border Co-operation in the Enforcement of Laws Protecting Privacy". It aimed to improve national
Privacy law
Privacy law is a set of regulations that govern the collection, storage, and utilization of personal information from healthcare, governments, companies, public or private entities, or individuals.
Privacy laws are examined in relation to an ind ...
enforcement so national authorities can better cooperate with foreign authorities and put in place efficient international mechanisms to ease trans-frontier cooperation for legislation protecting privacy. This recommendation was implemented with the 2010 founding of the Global Privacy Enforcement Network.
* An Ibero-American network of data protection exists. In May 2008, during its 6th meeting, in Colombia, its declaration asking international conferences on data protection and privacy to "pursue their efforts, regardless of their geographical location, in order to adopt common legal instruments".
* Another network is that of the Central and Eastern data protection authority (CEDPA). This network has expressed its will to pursue and strengthen its activities within the CEDPA, notably to elaborate common solutions and assist new members with the establishment of data protection legislation. That was during the June 2008 meeting in Poland.
List of national data protection authorities
European Economic Area
* :
Austrian Data Protection Authority ()
* :
Belgian Data Protection Authority (, , ), also known as APD-GBA
* :
Bulgarian Data Protection Authority ()
* :
Office of the Commissioner for Personal Data Protection ()
* : Office for Personal Data Protection ()
* :
Danish Data Protection Agency ()
* :
Estonian Data Protection Inspectorate ()
* :
Office of the Data Protection Ombudsman ()
* : (
lit. 'National Commission on Informatics and Liberty'), also known as CNIL
* :
()
** Note: Competent supervisory authorities for the enforcement of data protection in the private sector are the respective state authorities.
* :
Hellenic Data Protection Authority (), also known as HDPA
* :
Hungarian National Authority for Data Protection and Freedom of Information ()
* :
Data Protection Authority ()
* :
Data Protection Commissioner (), also known as DPC
* :
Italian Data Protection Authority (), also known as Italian DPA
* :
Data State Inspectorate (, )
* :
Datenschutzstelle
* :
State Data Protection Inspectorate ()
* :
National Commission for Data Protection (, ), also known as CNPD
* :
Office of the Information and Data Protection Commissioner, also known as IDPC
* :
Dutch Data Protection Authority ()
* :
Norwegian Data Protection Authority ()
* :
Polish Data Protection Commissioner ()
* :
National Commission Data Protection (), also known as NCDP
* :
National Authority for the Supervision of Personal Data Processing (), also known as ANSPDCP
* :
Office for Personal Data Protection of the Slovak Republic ()
* :
Information Commissioner of the Republic of Slovenia
Information is an abstract concept that refers to something which has the power to inform. At the most fundamental level, it pertains to the interpretation (perhaps formally) of that which may be sensed, or their abstractions. Any natur ...
()
* :
Spanish Data Protection Agency
The Spanish Data Protection Agency (AEPD, ) is an independent agency of the government of Spain which oversees the compliance with the legal provisions on the protection of personal data. The agency is headquartered in the city of Madrid and i ...
()
**: Transparency and Data Protection Council of Andalusia ()
** :
Basque Data Protection Authority (, )
** :
Catalan Data Protection Authority ()
* :
Swedish Data Protection Authority (), also known as Swedish DPA
* :
Information Commissioner's Office
The Information Commissioner's Office (ICO) is a non-departmental public body which reports directly to the Parliament of the United Kingdom and is sponsored by the Department for Science, Innovation and Technology. It is the independent regu ...
, also known as ICO
Europe
*
Information and Data Protection Commissioner (IDP)Komisionerit për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale(KDIMDP))
* :
Data Protection Agency of Andorra ()
* :
Croatian Personal Data Protection Agency ()
* :
Personal Data Protection Service ( ka, პერსონალურ მონაცემთა დაცვის სამსახური)
* :
Data Protection Office
* :
Directorate for Personal Data Protection ()
* :
Office of the Data Protection Supervisor
* : ''
Commission de contrôle des informations nominatives'' (
lit. 'Personal Data Control Board'), also known as CCIN
* :
Federal Service for Supervision in the Sphere of Telecom, Information Technologies and Mass Communications (''Roskomnadzor'')
* :
Commissioner for Information of Public Importance and Personal Data Protection ()
* :
Federal Data Protection and Information Commissioner
The Federal Data Protection and Information Commissioner (FDPIC) is responsible to advise, educate and ensure the protection of personal data in Switzerland. It is established by the Federal Act on Data Protection and by the Federal Act on Freed ...
(, , ), also known as FDPIC
* :
Turkish Data Protection Authority ()
*
Ukrainian Parliament Commissioner for Human Rights()
Africa
* :
Data Protection Agency (), known as APD
* : No national authority is responsible for data protection.
* :
Data Protection Commission
* : ''
Commission nationale de contrôle de la protection des données à caractère personnel'' (
lit. 'National Commission for the Control of the Protection of Personal Data'), also known as CNDP
* : No national authority is responsible for data protection.
* :
National Information Technology Development Agency (NITDA) and
Nigerian Communications Commission (NCC) provide services regarding data protection.
* : ''Commission de protection des Données Personnelles'' (
lit. 'Commission for the protection of Personal Data'), also known as CDP
* :
Information Regulator
* :
National Authority for Protection of Personal Data (), known as INPDP
* : There is currently no data protection authority but the
Zimbabwe Media Commission comments on the degree of protection of privacy from public bodies programs.
Asia
* :
Cyberspace Administration of China
The Cyberspace Administration of China (CAC; ) is the national internet regulator and censor of the People's Republic of China.
The agency was initially established in 2011 by the State Council as the State Internet Information Office (SIIO) ...
(CAC)
* :
Office of the Privacy Commissioner for Personal Data (PCPD)
* :
Data Protection Board of India
* :
Personal Data Protection Authority Institute
* : The Privacy Protection Authority ()
* :
Personal Information Protection Commission (Japan)
The is a Japanese government commission charged with the protection of personal information. It was established on January 1, 2016 to replaces the Specific Personal Information Protection Commission. The commission consisted of eight commissione ...
(PPC)
* : Data protection is regulated by the state.
* :
Office for Personal Data Protection, known as OPDP
* : There is a Personal Data Protection Commissioner
* :
National Commission for Personal Data Protection
* :
National Privacy Commission
* :
Qatar Ministry of Transport and Communications
* : No national authority is responsible for data protection.
* : A Personal Data Protection Commission is created following the
Personal Data Protection Act 2012 (Singapore)
* :
Personal Information Protection Commission (South Korea) (PIPC)
* : No national authority is responsible for data protection.
* :
Office of the Personal Data Protection Committee
* : No national authority is responsible for data protection.
* : Regulators for data protection are sector-specific.
Oceania
* :
Office of the Australian Information Commissioner
* :
Privacy Commissioner (New Zealand)
The Office of the Privacy Commissioner (New Zealand) administers the Privacy Act 2020. The Privacy Commissioner is entrusted to protect Personally identifiable information, personal information of New Zealanders in accordance with the Privacy ...
North America
* :
Office of the Privacy Commissioner of Canada
The privacy commissioner of Canada () is a non-partisan ombudsman and officer of the Parliament of Canada. The commissioner investigates complaints regarding violations of the federal ''Privacy Act'', which deals with personal information held ...
()
* :
()
* : There is no single national authority.
South America
* :
Dirección Nacional de Protección de Datos Personales (
lit. 'National Directorate for Personal Data Protection'), known as PDP
* : No national authority is responsible for data protection.
*
National Data Protection Authority (ANPD)* : There is no dedicated authority.
* :
Superintendency of Industry and Commerce (SIC)
* :
Ministerio de Justicia y Derechos Humanos (Perú) (
lit. 'Ministry of Justice and Human Rights')
* : Personal Data Control and Regulatory Unit.
* : No national authority is responsible for data protection.
Central America
* :
Agency for the Protection of Individual's Data (), known as PRODHAB
* : No national authority is responsible for data protection.
* :
National Civil Registry () and
Institute for the Access to Public Information ()
* : No national authority is responsible for data protection.
See also
General aspects
*
Behavioural targeting
Targeted advertising or data-driven marketing is a form of advertising, including online advertising, that is directed towards an audience with certain traits, based on the product or person the advertiser is promoting.
These traits can either ...
*
Biometric Information Privacy Act
The Biometric Information Privacy Act (BIPA) is a law set forth on October 3, 2008 in the U.S. state of Illinois, in an effort to regulate the collection, use, and handling of biometrics, biometric identifiers and information by private entiti ...
*
CNIL
*
Cookies (Internet)
*
Data security
Data security or data protection means protecting digital data, such as those in a database, from destructive forces and from the unwanted actions of unauthorized users, such as a cyberattack or a data breach.
Technologies
Disk encryption
...
*
Database
In computing, a database is an organized collection of data or a type of data store based on the use of a database management system (DBMS), the software that interacts with end users, applications, and the database itself to capture and a ...
*
Digital identity
A digital identity is data stored on Computer, computer systems relating to an individual, organization, application, or device. For individuals, it involves the collection of personal data that is essential for facilitating automated access to ...
*
Geolocation Privacy and Surveillance Act
*
Health data
Health data is any data "related to health conditions, reproductive outcomes, Cause of death, causes of death, and Quality of life (healthcare), quality of life" for an individual or population. Health data includes clinical metrics ...
*
Identity (psychology)
Identity is the set of qualities, beliefs, personality traits, appearance, or expressions that characterize a person or a group.
Identity emerges during childhood as children start to comprehend their self-concept, and it remains a consistent ...
*
Identity (social science)
Identity is the set of qualities, beliefs, personality traits, appearance, or expressions that characterize a person or a social group, group.
Identity emerges during childhood as children start to comprehend their self-concept, and it remains ...
*
Information leakage
Information leakage happens whenever a system that is designed to be closed to an eavesdropper reveals some information to unauthorized parties nonetheless. In other words: Information leakage occurs when secret information correlates with, or ca ...
*
Information security
Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
*
Obfuscation
Obfuscation is the obscuring of the intended meaning of communication by making the message difficult to understand, usually with confusing and ambiguous language. The obfuscation might be either unintentional or intentional (although intent ...
*
On the Internet, nobody knows you're a dog
"On the Internet, nobody knows you're a dog" is an adage and Internet meme about Internet anonymity which began as a caption to a cartoon drawn by Peter Steiner, published in the July 5, 1993 issue of the American magazine ''The New Yorker'' ...
*
Passenger name record
A passenger name record (PNR) is a record in the database of a computer reservation system (CRS) that contains the itinerary for a passenger or a group of passengers travelling together. The concept of a PNR was first introduced by airlines that ...
*
Social web
The social web is a set of social relations that link people through the World Wide Web. The social web encompasses how websites and software are designed and developed in order to support and foster social interaction. These online social int ...
*
User profile
A user profile is a collection of settings and information associated with a user. It contains critical information that is used to identify an individual, such as their name, age, portrait photograph and individual characteristics such as kn ...
*
Violation of privacy
Technical aspects
*
Digital certificate
In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the validity of a public key. The certificate includes the public key and information about it, informa ...
*
OpenID
OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. It allows users to be authenticated by co-operating sites (known as relying parties, or RP) using a third-party identity provi ...
*Strong authentication
*
:Identity management
Legal aspects
*
Escrow
An escrow is a contractual arrangement in which a third party (the stakeholder or escrow agent) receives and disburses money or property for the primary transacting parties, with the disbursement dependent on conditions agreed to by the transact ...
*
Identity document
An identity document (abbreviated as ID) is a documentation, document proving a person's Identity (social science), identity.
If the identity document is a plastic card it is called an ''identity card'' (abbreviated as ''IC'' or ''ID card''). ...
*
Identity theft
Identity theft, identity piracy or identity infringement occurs when someone uses another's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. ...
*
Personal identity verification
*
Protection Profile
A Protection Profile (PP) is a document used as part of the certification process according to ISO/IEC 15408 and the Common Criteria (CC). As the generic form of a Security Target (ST), it is typically created by a user or user community and provi ...
References
External links
List of national data protection authorities in EuropeInternational Conference of Data Protection and Privacy CommissionersHandbook on European data protection law
{{Portal bar, European Union, Law
Information privacy