1

Доработанная редакция проекта Регламента была опубликована 30 июня 2014 г. в Интернете для публичного доступа по адресу: URL: http://register.consilium. europa.eu/doc/srv?l=EN&f=ST%2011028%202014%20INIT.

2

Ashford W. EU Data Protection Regulation to be finalised by end of 2015. URL: http://www.computerweekly.com/news/4500248164/EU-Data-Protection-Regulation-to-be-finalised-by-end-of-2015

3

Эшфорд У. Закон Евросоюза о защите персональных данных будет окончательно готов к концу 2015 г. URL: http://www.computerweekly.com/news/4500248164/ EU-Data-Protection-Regulation-to-be-finalised-by-end-of-2015. Пер. Н. Храмцовской: URL: http://rusrim.blogspot.ru/2015/06/201519. html.

4

См. подробнее: Тарасов Д.А. Суд Евросоюза отменил обязанность провайдеров хранить сведения о коммуникациях клиентов. URL: http://lexdigital. ru/2014/ПО/.

5

Opinion 1/2008 on data protection issues related to search engines. EU Article 29 Data Protection Working Party, 00737/EN WP 148. April 2008.

6

Niekerk A.J. van. The Strategic Management of Media Assets; A Methodological Approach. Allied Academies, New Orleans Congress, 2006.

7

Rosen R.J. The Government Would Like You to Write a 'Social Media Will' // The Atlantic. Retrieved 4 June 2013.

8

Официальный сайт Европейского инспектора по защите данных (European Data Protection Supervisor). URL: https://secure.edps.europa.eu/EDPSWEB/edps/ EDPS/cache/offonce?lang=en.

9

The transfer of personal data to third countries and international organisations by EU institutions and bodies, 14 July 2014. URL: https://secure.edps.europa.eu/ EDPSWEB/edps/site/mySite/Papers

10

EDPS recommendations on the Directive for data protection in the police and justice sectors. URL: https://secure.edps.europa.eu/EDPSWEB/edps/site/mySite/

Opinions C

11

WP 4 (5020/97) «Рабочий документ, содержащий первые ориентиры относительно передачи персональных данных третьим странам – возможные пути продвижения в оценке соответствия» от 26 июня 1997 г.; WP 7 (5057/97) «Оценка саморегулирования отрасли: в каких случаях она вносит значимый вклад в уровень защиты данных в третьей стране?» от 14 января 1998 г.; WP 9 (3005/98) «Предварительные мнения относительно использования договорных положений в контексте передачи персональных данных третьим странам» от 22 апреля 1998 г.; WP 12 «Передачи персональных данных третьим странам: применение статей 25 и 26 Директивы ЕС о защите данных» от 24 июля 1998 г. // Интернет-источник: URL: europa. eu.int/comm/internal_markt/en/media.dataprot/wpdocs/wpl2/en.

12

Safe Harbor Privacy Principles. URL: http://www.export.gov/safeharbor/ SHPRIN CIPLESFINAL.htm

13

Международное и зарубежное финансовое регулирование: институты, сделки, инфраструктура. В 2 ч. / под ред. А.В. Шамраева. М.: КноРус; ЦИПСиР, 2014. 4.2.

14

Official Journal L 215. 25.08.2000. Р. 0007–0047.

15

URL: http://safeharbor.export.gov/list.aspx

16

ЕескеР. van. URL: http://www.jdsupra.com/legalnews/europe-eu-commissioner-reding-introduc-85150/; http://europa.eu/rapid/press-release_SPEECH-14-62_en.pdf (пер. Н. Храмцовской) // URL: http://rusrim.blogspot.ru/2013/ll/blog-post_15.html.

17

ЕП требует расторгнуть договоры ЕС с США об обмене данными. URL: http://www.warandpeace.ru/ru/news/view/87751/.

18

Мироненко В. FTC сообщила о санкциях для нарушителей законов ЕС о конфиденциальности // Daily digital digest. URL: http://www.3dnews.ru/797428.

19

Baker J. EU will not suspend safe harbor data privacy agreement with the US // PC World. 2013. No. 11.

20

European Commission calls on the U.S. to restore trust in EU-U.S. data flows // Пресс-релиз Европейской комиссии от 27 ноября 2013 г. URL: http://europa.eu/ rapid/press-release_IP- 13-1166_en.htm.

21

Rebuilding Trust in EU-US Data Flows. COM(2013) 846 final // Документ Европейской комиссии от 27 ноября 2013 г. URL: http://europa.eu/rapid/press-release_ IP- 13-1166_en.htm.

22

Европейский суд решил, что Facebook не защищает данные пользователей // Русская служба RFI. Франция. URL: http://informburo.dn.ua/cgi-bin/iburo/ start.cgi?info58=7431

23

Рамочное соглашение IP/10/1661 «О защите информации в области полицейского и судебного сотрудничества».

24

См.: Personal data protection in the European. Union European Parliament resolution of 6 July 2011 on a comprehensive approach on personal data protection in the European Union (2011/2025 (INI)) // Official Journal С 033 E. 05.02.2013. P. 0101–0110; Directive of the European Parliament and of the Council 2012/0010 (COD) on the protection of individuals with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data. Brussels, 25.01.2012 (проект); Resolution of the 85th Conference of the Data Protection Commissioners of the Federal Government and the Bremerhaven on 13–14 March 2013 «Europe must strengthen data protection».

25

Пояснительный доклад к Конвенции № 108 «О защите прав физических лиц в отношении автоматизированной обработки персональных данных». URL: http://conventions.coe.int/Treaty/RUS/Reports/Html/108.htm.

26

Recommendation No. Rec(81)l of the Committee of Ministers to member states on regulations for automated medical data banks (adopted by the Committee of Ministers on 23 January 1981 at the 328th meeting of the Ministers' Deputies). Council of Europe, 1981. URL: http://www.coe.int/t/dg3/health/recommendations_en.asp.; Recommendation No. Rec(97)5 of the Committee of Ministers to member states on the protection of medical data (adopted by the Committee of Ministers on 13 February 1997 at the 584th meeting of the Ministers' Deputies). Council of Europe, 1997. URL: https://wcd.coe.int/ ViewDoc.jsp?id=690735& Site=CM&BackColorInternet=C3C3C3&BackColorIntrane t=EDB021&BackColorLogged=F5D383.

27

Recommendation No. Rec(83) 10 of the Committee of Ministers to member states on the protection of personal data used for scientific research and statistics (adopted by the Committee of Ministers on 23 September 1983 at the 362nd meeting of the Ministers' Deputies). Council of Europe, 1983. URL: https://wcd.coe.int/ViewDoc.jsp?id=69073 5&Site=CM&BackColorInternet=C3C3C3&BackColorIntranet=EDB021&BackColor Logged=F5D383.

28

Recommendation No. Rec(85)20 of the Committee of Ministers to member states on the protection of personal data used for the purposes of direct marketing (adopted by the Committee of Ministers on 25 October 1985 at the 389th meeting of the Ministers' Deputies). Council of Europe, 1985. URL: https://www.coe.int/t/dghl/standardsetting/ dataprotection/legalinstrumentsen.asp.

29

Recommendation No. Rec(86)l of the Committee of Ministers to member states on the protection of personal data used for social security purposes (adopted by the Committee of Ministers on 23 January 1986 at the 392nd meeting of the Ministers' Deputies). Council of Europe, 1986. URL: https://www.coe.int/t/dghl/standardsetting/dataprotec-tion/legal_instruments_en.asp.

30

Recommendation No. Rec(87)15 of the Committee of Ministers to member states on the protection of personal data used in the police sector (adopted by the Committee of Ministers on 17 September 1987 at the 410th meeting of the Ministers' Deputies). Council of Europe, 1987. URL: https://www.coe.int/t/dghl/standardsetting/dataprotection/ legalinstrumentsen. asp.

31

Recommendation No. Rec(89)2 of the Committee of Ministers to member states on the protection of personal data used for employment purposes (adopted by the Committee of Ministers on 18 January 1989 at the 423rd meeting of the Ministers' Deputies). Council of Europe, 1989. URL: https://www.coe.int/t/dghl/standardsetting/dataprotec-tion/legal_instruments_en. asp.

32

Recommendation No. Rec(90) 19 of the Committee of Ministers to member states on the protection of personal data used for payment and related operations (adopted by the Committee of Ministers on 13 September 1990, at the 443rd meeting of the Ministers' Deputies). Council of Europe, 1990. URL: https://www.coe.int/t/dghl/standardsetting/ dataprotection/legalinstrumentsen. asp.

33

Recommendation No. Rec(95)4 of the Committee of Ministers to member states on the protection of personal data collected and processed in the area of telecommunication services, with particular reference to telephone services (adopted by the Committee of Ministers on 7 February 1995 at the 528th meeting of the Ministers' Deputies). Council of Europe, 1995. URL: https://www.coe.int/t/dghl/standardsetting/dataprotection/le-galinstrumentsen. asp.

34

Recommendation No. Rec(97) 18 of the Committee of Ministers to member states on the protection of personal data collected and processed for statistical purposes (adopted by the Committee of Ministers on 30 September 1997 at the 602nd meeting of the Ministers’ Deputies). Council of Europe, 1997. URL: https://www.coe.int/t/dghl/stan-dardsetting/dataprotection/legalinstrumentsen. asp.

35

Recommendation No. Rec(91)10 of the Committee of Ministers to member states on the communication to third parties of personal data held by public bodies (adopted by the Committee of Ministers on 9 September 1991 at the 461st meeting of the Ministers' Deputies). Council of Europe, 1991. URL: https://www.coe.int/t/dghl/standardsetting/ dataprotection/legalinstrumentsen.asp.

36

Recommendation No. Rec(99)5 of the Committee of Ministers to member states on the protection of privacy on the Internet (adopted by the Committee of Ministers on 23 February 1999 at the 660th meeting of the Ministers' Deputies). Council of Europe, 1999. URL: https: //www. coe.int/t/dghl/standardsetting/dataprotection/legalinstrumentsen. asp.

37

Recommendation No. Rec(2002)9 of the Committee of Ministers to member states on the protection of personal data collected and processed for insurance purposes (adopted by the Committee of Ministers on 18 September 2002 at the 808th meeting of the Ministers' Deputies). Council of Europe, 2002. URL: https://www.coe.int/t/dghl/stan-dardsetting/dataprotection/legalinstrumentsen. asp.

38

Recommendation CM/Rec(2010) 13 on the protection of individuals with regard to automatic processing of personal data in the context of profiling (adopted by the Committee of Ministers on 23 November 2010 at the 1099th meeting of the Ministers’ Deputies). Council of Europe, 2010. URL: https://www.coe.int/t/dghl/standardsetting/dataprotec-tion/legal_instruments_en. asp.

39

Мешков Ю. Ратификация Конвенции Совета Европы: защита персональных данных будет усилена // Персональные данные. 2013. № 5 (60).

40

Ad hoc Committee on Data Protection (CAHDATA). URL: https://www.coe.int/ t/dghl/standardsetting/dataprotection /TPD_documents/CAHDATA%203_Report_ CM(2015)40_En.pdf.

41

Recommendation CM/Rec(2010)13 of the Committee of Ministers to member states on the protection of individuals with regard to automatic processing of personal data in the context of profiling. URL: https://wcd.coe.int/ViewDoc.jsp?Ref=CM/ Rec(2010)13#.

42

Additional Protocol to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data regarding supervisory authorities and transborder data flows. URL: http://conventions.coe.int/Treaty/RUS/Reports/ Html/108.htm

43

Recommendation CM/Rec(2010)13 of the Committee of Ministers to member states on the protection of individuals with regard to automatic processing of personal data in the context of profiling (Adopted by the Committee of Ministers on 23 November 2010 at the 1099th meeting of the Ministers’ Deputies). URL: https://wcd.coe.int/ViewDoc. jsp?id=1710949&Site=CM#P5_189.

44

Основные положения Организации по экономическому сотрудничеству и развитию (ОЭСР) о защите неприкосновенности частной жизни и международных обменов персональными данными. URL: http://www.uipdp.com/upload/legis-lation/international/directiveoesrl.pdf

45

Data Protection Act 1998. URL: http://www.legislation.gov.uk/ukpga/1998/29/ contents

46

Freedom of Information Act 2000. URL: http://www.legislation.gov.uk/ukpga/ 2000/36/contents

47

Protection of Freedoms Act 2012. URL: http://www.legislation.gov.uk/ukpga/ 2012/9/contents/enacted

48

The Criminal Justice and Data Protection (Protocol No. 36) Regulations 2014. URL: http://www.legislation.gov.uk/ukdsi/2014/9780111122723/contents

49

The Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004. URL: http://www.legislation.gov.uk/uksi/2004/3244/pdfs/ uksi_20043244_en.pdf

50

В законе используется термин «sensitive personal data», который переводится на русский язык как «чувствительные данные». В части 1 данного закона к sensitive personal data отнесены перечисленные в абзаце категории информации. Дословно в «Акте о защите данных» указано: «In this Act “sensitive personal data” means personal data consisting of information as to…» В целях разграничения «чувствительных данных» и конфиденциальной информации в разделе по Великобритании используется термин «чувствительные данные».

51

Сайт законодательства UK. URL: http://www.legislation.gov.uk/all?title= The%20Data%20Protection%20Act

52

DCMS takes on responsibility for UK data protection policy and sponsorship of the ICO. От 18 сентября 2015 г. URL: http://www.out-law.com/en/articles/2015/sep-tember/dcms-takes-on-responsibility-for-uk-data-protection-policy-and-sponsorship-of-the-ico/

53

Елин B.M., Жарова A.K. О выделении информационных объектов в самостоятельную категорию объекта преступления // Труды Института государства и права Российской академии наук. 2009. № 5. С. 205–229; Елин В.М. Мошенничество в сфере компьютерной информации как новый состав преступления // Бизнес-информатика. 2013. № 2 (24). С. 70–76.

54

Register (notify) under the Data Protection Act. URL: https://ico.org.uk/for-organisations/register/

55

URL: http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ: L:2006:105:0 054:0063:EN: PDF

56

Официальный интернет-портал правовой информации. URL: www.pravo. gov.ru от 5 августа 2014 г.

57

Directive 2006/24/ЕС of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002/58/EC. URL: http://www.out-law.com/en/ articles/2012/may/survey-reveals-nearly-half-of-web-users-happy-with-behavioural-advertising-/

58

Guidance on the use of cloud computing. URL: https://ico.org.uk/media/1540/ cloud_computing_guidance_for_organisations.pdf

59

Register (notify) under the Data Protection Act. URL: https://ico.org.uk/for-organisations/register/

60

Personal information online code of practice on 26 May. URL: 2011 https://ico.org. uk/media/for-organisations/documents/1591/personal_information_online_cop.pdf

61

Cloud Computing. A Practical Introduction to the Legal Issues. URL: http:// www.bsigroup.com/en/sectorsandservices/Forms/BIP-0117-Sample-chapter-form/?id= 187489).

62

В настоящее время эта стратегия является недействующей.

63

Government ICT strategy. URL: http://www.cabinetoffice.gov.uk/sites/default/ files/resources/uk-government-government-ict-strategy_0.pdf

64

Жарова A.K. Условия оказания услуги по предоставлению доступа к облачным вычислениям // Государство и право. 2012. № 12. С. 86–90.

65

Information Commissioner’s Office. URL: https://ico.org.uk/

66

BVerfG, Urteil vom 15. Dezember 1983 Az.: 1 BvR 209/83, 1 BvR 484/83, 1 BvR 440/83, 1 BvR 420/83, 1 BvR 362/83, 1 BvR 269/83 (Volkszählungsurteil).

67

Fernmeldegeheimnis.

68

BVerfG, Urteil vom 27. Februar 2008 Az.: 1 BvR 370/07, 1 BvR 595/07.

69

Bundesdatenschutzgesetz.

70

URL: http://curia.europa.eu/juris/documents.jsf?num=C-293/12

71

URL: http://dip21.bundestag.de/dip21/brd/2007/0798-07.pdf

72

URL: https://www.bundesyerfassungsgericht.de/entscheidungen/rs20100302 lbvr025608.html

73

URL: http://curia.europa.eu/juris/documents.jsf?num=C-293/12

74

URL: http://curia.europa.eu/juris/documents.jsf?num=C-329/12

75

Gola/Schomerus, opa.eu/juris/d. Закон о персональных данных Германии.

76

§3.

77

Gola/Schomerus, opa.eu/juris/d. Закон о персональных данных Германии.

78

Там же.

79

Bamerger/Roth, Гражданский кодекс Германии.

80

Закон о защите персональных данных от 6 июля 2000 г. в неофициальном переводе на английский язык. URL: http://www.dutchdpa.nl/downloads_wetten/ wbp.pdf

81

Федеральный закон «О персональных данных»: научно-практический комментарий (постатейный) / Гафурова А.X., Доротенко Е.В., Контемиров Ю.Е. и др.; под ред. А.А. Приезжевой. М.: Библиотечка «Российской газеты», 2015. Вып. 11. СПС «КонсультантПлюс».

82

Официальный сайт органа: URL: https://www.cbpweb.nl/en

83

СВР issues sanction to Google for infringements privacy policy. URL: https:// cbpweb.nl/en/news/cbp-issues-sanction-google-infringements-privacy-policy

84

New Dutch Law Introduces General Data Breach Notification Obligation and

Higher Sanctions. URL: https://www.huntonprivacyblog.eom/2015/06/02/new-dutch-law-introduces-general-data-breach-notification-obligation-higher-sanctions/; NETHERLANDS – Legislation on mandatory data breach notification adopted by the Dutch Senate. URL: http://blogs.dlapiper.com/privacymatters/netherlands-legislation-on-

mandatory-data-breach-notification-adopted-by-the-dutch-senate/

85

Wet bewaarplicht telecommunicatiegegevens (Telecommunications Data Retention Act, July 30, 2009). URL: http://wetten.overheid.nl/BWBR0026191/geldigheidsdatum_ 15-02-2010

86

Dutch do a U-turn on metadata laws. URL: http://www.smh.com.au/digital-life/ consumer-security/dutch-do-a-uturn-on-metadata-laws-20150311-141rkl.html; Netherlands: Court Strikes Down Data Retention Law. URL: http://www.loc.gov/lawweb/ servlet/lloc_news?disp3_1205404345_text; Dutch court scraps telecommunications data retention law. URL: http://www.pcworld.com/article/2895356/dutch-court-scraps-tele-communications-data-retention-law.html