CIPP/US Study Guide
Chapter 1: Introduction to Privacy

Comprehensive Model of Data Protection

Comprehensive laws govern personal data across public and private sectors economy-wide, typically with an oversight DPA. Countries adopt them to remedy past injustices, ensure EU consistency (GDPR adequacy), and promote e-commerce.

Comprehensive data protection laws govern collection, use, and dissemination of personal information in both public and private sectors, generally with an official or agency (a DPA in Europe) overseeing enforcement. Enforcement and funding are two critical issues.

  • Remedy past injustices - e.g., Germany's strict regime as a reaction to the Nazi era and Stasi surveillance
  • Ensure consistency with European privacy laws - the GDPR limits transfers to countries lacking 'adequate' protection, so some countries pass laws for EU 'adequacy' or trade
  • Promote electronic commerce - reassure uneasy consumers
Criticisms

Critics say comprehensive 'one-size-fits-all' rules can impose costs that outweigh benefits, over-regulate low-risk data, and may slow innovation if they require prior regulator approval.

Key terms - quick answers

What is “Comprehensive model”?
A data protection approach where the government defines requirements across the whole economy (public and private sectors), usually overseen by a DPA.