A/79/173
9.
All of the above has led to a review, across the world, of relevant international
documents on data processing and of local laws, with a view to modernizing them. In
that regard, in October 2023, the Global Privacy Assembly (GPA) adopted a
resolution aimed at achieving global data protection standards, in which it set forth
principles to ensure high levels of data protection and privacy worldwide and
emphasized a decades-old idea, namely, that there should be global standards on data
protection and privacy. In the resolution, GPA therefore promoted certain principles,
rights and other elements as important for achieving high levels of data protection
and privacy, and resolved to advocate, promulgate and promote the principles, rights
and other elements set out in the resolution, to ensure that they could be effectively
implemented and applied in all contexts, particularly in the processing of data with
new and emerging technologies and innovations. 9
10. In the resolution, GPA emphasized the importance of providing for the
protection of personal data across borders with a range of transfer mechanisms, such
as adequacy, model clauses, certifications and administrative arrangements, to ensure
that protection travels with the data when the data cross borders. It also noted the
benefits of building on commonalities, complementarities and elements of
convergence in order to foster future interoperability between existing regulatory
approaches and mechanisms enabling safe, trustworthy cross-border data flows. 10
11. Such international regulatory harmonization began in the twentieth century,
with the Council of Europe, OECD, the United Nations, the European Parliament and
the Council of the European Union as the main stakeholders. In the twenty -first
century, they were joined by the Asia-Pacific Economic Cooperation forum (APEC),
the Ibero-American Data Protection Network and GPA, formerly known as the
International Conference of Data Protection and Privacy Commissioners .
12. In that connection, the Ibero-American Data Protection Network has stated that
the “establishment of a harmonized framework for data protection at the global level
has been the main basis for the adoption of the various current international
instruments on data protection. The aim is to ensure that the development of global
commerce is compatible with the protection of the rights of individuals, especially
with regard to the protection of information concerning them”. 11
13. Lastly, mention should be made of cyberspace as the milieu in which millions
of people in the world coexist.
14. Personal data circulate daily in cyberspace. However, the regulation of data
processing arose in an environment in which cyberspace was not yet being discussed.
In other words, the current socio-technological reality is not the socio-technological
reality that existed when the first regulations on personal data protection were issued.
__________________
9
10
11
24-13146
GPA, resolution entitled “Achieving global data protection standards: Principles to ensure high
levels of data protection and privacy worldwide”, October 2023. Available at
https://globalprivacyassembly.org/document-archive/adopted-resolutions/.
Ibid.
Ibero-American Data Protection Network, “Guidelines for Harmonization of Data Protection in
the Ibero-American Community”, p. 1 (2007). The Ibero-American Data Protection Network goes
on to state that “therefore, the establishment of a homogeneous framework for the regulation of
the right to data protection, either through the adoption of binding supranational instruments or
of national laws enshrining the essential content of that right, will ensure the development of
commerce in the area, facilitating the exchange of information between the various operators
located in the Ibero-American States and between those States and third countries, in particular
the States members of the European Union, without restrictions resulting from differences in the
level of protection of the fundamental right to the protection of personal data”.
5/23