> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Convention 108 Explained: The International Treaty That Shaped Modern Data Protection
- URL: https://www.thedelatorrereview.com/convention-108-explained-the-international-treaty-that-shaped-modern-data-protection/
- Published: 2019-06-25T15:53:00.000Z
- Updated: 2026-08-15T17:53:22.000Z
- Description: Convention 108 was the first binding international data protection treaty. Explore its origins, core principles, approach to transborder data flows, influence on European data protection law and the GDPR, and why its 1981 signing is commemorated each January 28 as Data Protection Day.
- Author: Lydia
- Tags: GDPR, International Data Transfers, Convention 108, Transparency, Accountability, European Convention on Human Rights (ECHR), European Court of Human Rights (ECtHR), Council of Europe (CoE), Organisation for Economic Co-operation and Development (OECD), Data Protection Law, Cross-Border Data Transfers, Legal History

> **Key Points:** (1) Convention 108 was the **first and only legally binding international treaty dedicated to data protection**, opened for signature by the Council of Europe on January 28, 1981\. (2) Its origins lie in the **European human rights framework** and concerns that traditional privacy law was insufficient to address emerging computerized data processing.(3) Council of Europe Resolutions (73) 22 and (74) 29 established early data protection principles for the private and public sectors and laid the groundwork for Convention 108\. (4) By the late 1970s, several European countries had adopted **national data protection laws**, but differences among those laws created challenges as personal data increasingly crossed borders. (5) Convention 108 established a **“common core” of data protection principles**, while allowing each country flexibility in implementing those principles through domestic law. (6) The Convention seeks to reconcile **two complementary objectives: protecting individuals and facilitating the free flow of information across borders**. (7) Its framework rests on three pillars: substantive data protection principles, rules for transborder data flows, and international cooperation and mutual assistance. (8) Convention 108 **helped shape the development of modern European data protection law**, and many of its core concepts are reflected today in the GDPR. (9) The Convention was modernized through **Convention 108+**, designed to strengthen its protections and respond to technological and regulatory developments.

---

## Why does Convention 108 matter?

Convention 108 matters not merely as a historical predecessor to the GDPR. It represents an important step in recognizing **data protection as a distinct legal interest at the international level** and establishing common rules governing how governments and private organizations process personal data.

More than four decades after it was opened for signature, its influence can still be seen throughout modern data protection law. And every **January 28**, Data Protection Day provides an annual reminder of the Convention's foundational role in the development of the modern right to data protection.

---

> **January 28 is celebrated as Data Protection Day because Convention 108 was opened for signature on January 28, 1981.**

---

## What is Convention 108?

Although the right to data protection is relatively young compared with other fundamental rights, it has achieved significant recognition under international law. One of the most important instruments in its development is the [CoE Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data](https://www.coe.int/en/web/data-protection/convention108-and-protocol?ref=thedelatorrereview.com), better known as Convention 108.

Convention 108 was **opened for signature on January 28, 1981**, by the [**Council of Europe (CoE)**](https://www.coe.int/en/web/portal?ref=thedelatorrereview.com)—an international organization distinct from the European Union, although all EU Member States are members of it. Convention 108 was groundbreaking because it established, at the international level, legally binding rules specifically addressing the processing of personal data.

Convention 108 can be viewed as one of the seeds from which the modern right to data protection grew. Its January 28 opening for signature is also the reason Data Protection Day is celebrated in Europe every year on January 28\. The date is now recognized more broadly as Data Privacy Day in other parts of the world, including the US.

At its core, **Convention 108 sought to ensure that the growing use of automated data processing did not weaken the rights and interests of individuals**. Computers dramatically increased the amount of information that organizations could store, retrieve, combine, and process—and the speed at which they could do so.

The Convention’s drafters recognized that this technological capability created what they called “information power.”Increasingly, decisions affecting individuals—from payroll and social security to healthcare and public administration—depended on information maintained in computerized systems. That power, they concluded, carried corresponding responsibilities for both public and private-sector data users.

Convention 108 sought to fill that gap by translating broader protections into specific rules governing the processing of personal data and corresponding rights for individuals. In doing so, it helped establish the basic architecture that continues to characterize modern data protection law.

**Convention 108 did not emerge in isolation.** It was the product of a broader realization that traditional privacy protections needed to be supplemented by specific rules governing the processing of personal data in an increasingly computerized society.

Convention 108 was also part of a **broader international movement toward common privacy and data protection standards**. While the CoE pursued a legally binding treaty, its work developed alongside—and in dialogue with—parallel efforts at the OECD and within the European Communities.

### Convention 108 Is an International—Not an EU—Instrument

Convention 108 is sometimes discussed alongside EU data protection law, but it is important to distinguish the two systems. The Convention was adopted under the CoE, not the European Union.

This distinction also gives Convention 108 a reach beyond the EU. The Convention was eventually opened to accession by countries outside the CoE, allowing it to develop into a genuinely international data protection framework rather than one confined to EU or even European states.

All EU Member States have ratified Convention 108, but participation is not limited to them. Countries outside Europe have also joined the Convention, extending its principles beyond the geographic boundaries of the CoE.

### Is Convention 108 Enforceable?

Convention 108 is a **legally binding international treaty for states that become parties to it**. Those states are responsible for implementing its requirements within their domestic legal systems.

However, Convention 108 should not be confused with the European Convention of Human Rights. Individuals cannot bring a claim before the European Court of Human Rights. simply alleging a violation of Convention 108\. The courts's jurisdiction instead concerns rights protected by the European Convention of Human Rights—including, importantly, the right to respect for private and family life under Article 8.

## Origins of Convention 108

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-10_21_51-AM.png)

The origins of Convention 108 can be traced to the broader European system for protecting fundamental rights established after the Second World War. The CoE was founded in 1949 to promote human rights, democracy, and the rule of law. One of its most important early achievements was the adoption of the [**European Convention on Human Rights (ECHR)**](https://www.coe.int/en/web/human-rights-convention?ref=thedelatorrereview.com) in 1950, which entered into force in 1953.

The ECHR imposes international obligations on its Contracting Parties, and compliance is subject to judicial supervision by the [**European Court of Human Rights (ECtHR**](https://www.echr.coe.int/?ref=thedelatorrereview.com)). Importantly for privacy law, Article 8 of the ECHR protects the right to respect for private and family life, the home, and correspondence. The Convention, however, does not expressly recognize a separate right to the protection of personal data.

Because the ECHR protects privacy but does not expressly recognize a separate right to the protection of individuals in the context of computerized processing of personal data, the emergence of computers exposed an important gap in the European human rights framework. A separate legal instrument was therefore needed to translate the broader protection of ECHR into **specific data protection principles, obligations, and individual rights**. Convention 108 was designed to fill that gap.

The CoE’s work on data protection did not occur in isolation. **During the 1970s, European countries increasingly began adopting their own national data protection laws** in response to the growing use of computerized information systems.

### Technology Creates a Need for Data Protection Rules

By the 1960s, the increasing use of computers and automated data banks raised concerns that traditional privacy protections might not be sufficient to address the collection, storage, use, and exchange of personal information made possible by new technologies.

In 1968, the Parliamentary Assembly of the CoE adopted [**Recommendation 509**](https://pace.coe.int/en/files/14546/html?ref=thedelatorrereview.com), asking the Committee of Ministers to examine whether the ECHR and the domestic laws of Member States adequately protected personal privacy against the risks created by modern science and technology.

The resulting study identified an important gap: **existing national laws did not provide sufficient protection for individual privacy and other rights and interests affected by automated data banks**.

### Council of Europe Resolutions (73) 22 and (74) 29

In response to [**Recommendation 509**](https://pace.coe.int/en/files/14546/html?ref=thedelatorrereview.com), the Committee of Ministers adopted two landmark resolutions in 1973 and 1974:

- [**Resolution (73) 22** ](https://rm.coe.int/1680502830?ref=thedelatorrereview.com), concerning the protection of the privacy of individuals *vis-à-vis electronic data banks in the private sector*; and
- [**Resolution (74) 29** ](https://rm.coe.int/16804d1c51?ref=thedelatorrereview.com), extending similar principles to *electronic data banks in the public sector*.

These resolutions were **not legally binding**, but they represented an important step in the development of European data protection law. Rather than addressing privacy only as a broad fundamental right, they began articulating **specific principles governing the processing of personal data**.

Those principles helped establish the conceptual foundation for what would become Convention 108, and their influence can ultimately be traced through the development of European data protection law to today's GDPR.

### Data Protection Law at the National Level

Within five years of the adoption of [**Resolution (74) 29**](https://rm.coe.int/16804d1c51?ref=thedelatorrereview.com)[,](https://docsbay.net/doc/1146122/resolution-74-29-on-the-protection-of-the-privacy-of-individuals-vis-vis-electronic?ref=thedelatorrereview.com) data protection legislation had been enacted in seven CoE member states:

- Austria
- Denmark
- France
- Federal Republic of Germany
- Luxembourg
- Norway
- Sweden

By 1981, data protection legislation was also at an advanced stage of preparation in several other countries, including Belgium, Iceland, the Netherlands, Spain, and Switzerland.

### Constitutional Recognition of a right to Data Protection

Some European countries had begun recognizing **data protection at the constitutional level**. Portugal’s 1976 Constitution, Spain’s 1978 Constitution, and Austria’s 1978 Data Protection Act provided particularly strong protections for personal data.

Reflecting this trend, in [**Recommendation 890 (1980)**](https://pace.coe.int/en/files/14924/html?ref=thedelatorrereview.com), the Parliamentary Assembly of the CoE recommended studying whether the ECHR should be supplemented with a specific provision protecting personal data. No express right to data protection, however, was ultimately added to the ECHR.

### From National Laws to the Need for an International Framework

Although national data protection laws developed independently, they shared important characteristics and generally reflected the principles established by Resolutions (73) 22 and (74) 29\. By the late 1970s, a recognizable European model of data protection was beginning to emerge.

National laws generally established similar substantive rules concerning the quality of personal data and the purposes for which data could be used. Procedural approaches varied, but there was broad agreement around two important principles:

- **Publicity:** the existence of automated personal data files should be publicly known; and
- **Control:** supervisory authorities and individuals should have mechanisms for ensuring that data users respected individuals’ rights and interests.

These concepts were early predecessors of principles that remain central to modern data protection law, including transparency, individual rights, accountability, and independent supervision.

**There were nevertheless significant differences among national regimes.** Some countries extended their laws to certain manual filing systems, while others focused on automated processing. All protected data relating to natural persons, but some also protected information concerning legal persons. National laws also differed in the restrictions and exceptions permitted for reasons of public interest.

These differences became increasingly important as personal data began to move across national borders, particularly in sectors such as banking, travel, and credit cards.

The concern was straightforward: protections that applied to personal data in one country could be lost or weakened when the data were transferred elsewhere. Organizations could potentially circumvent national requirements by moving processing to so-called “data havens”—countries with weaker data protection laws or no comparable protections.

Countries could respond by restricting data exports, but that created a different problem: stringent transfer controls could interfere with the free international flow of information and commerce.

The CoE therefore needed a Convention to reconcile two objectives: ensuring that individuals remained protected when their personal data crossed borders while preserving the free flow of information between countries. This challenge provided an important impetus for Convention 108\. **Rather than relying solely on different national regimes, the CoE sought to establish common international data protection standards that would protect individuals while facilitating transborder data flows.**

## Convention 108 

### The Need for an International Convention

As mentioned above, the challenges created by cross-border processing went beyond differences in national data protection standards. Even where countries had adopted broadly comparable laws, practical questions of jurisdiction, applicable law, and enforcement remained unresolved.

For example, if a database located in one country could be accessed through terminals in another, it was not always clear which country had jurisdiction or which national data protection law should apply. Individuals also faced practical difficulties exercising their data protection rights when the relevant files or organizations were located abroad.

The CoE therefore felt it had to move beyond non-binding principles and national approaches toward a legally binding international framework: Convention 108.

### Drafting Convention 108

The move toward a binding international agreement began early. In 1972, while preparing the CoE’s first data protection resolutions, a committee of experts concluded that national legislation should eventually be reinforced by an international treaty. The same approach was supported that year by the 7th Conference of European Ministers of Justice.

Two possible models were considered:

- **Reciprocity:** each country would continue applying its own data protection standards, while restricting processing involving residents of another country where that processing would violate the other country’s laws.
- **Common principles:** participating countries would instead agree to a **shared set of fundamental data protection principles** applicable across all parties to the treaty.

The CoE favored the second approach. A reciprocity-based system would have been difficult to administer and, more fundamentally, could result in individuals receiving different levels of protection depending on their country of residence. A treaty based on common principles, by contrast, could establish a baseline of protection for everyone within its scope.

### From Proposal to Convention

In 1976, the Committee of Ministers formally instructed its experts to prepare a convention addressing privacy in connection with data processing abroad and transborder data processing.

The Convention was developed over the following years through the work of experts from numerous CoE Member States. Between 1976 and 1979, the Committee of Experts on Data Protection developed the framework, while a working group representing several countries worked through both the underlying philosophy and the details of the proposed treaty.

A working party composed of the experts from Austria, Belgium, France, Federal Republic of Germany, Italy, Netherlands, Spain, Sweden, Switzerland and the United Kingdom, met several times between the plenary committee meetings, to work out the general philosophy as well as the details for the draft convention.

In April 1980 another committee of experts, chaired by Mr J. Voyame (Switzerland), revised and finalized the text. This was approved by the CDCJ at its 33rd meeting and adopted by the Committee of Ministers, which decided to open it for signature on 28 January 1981

**The result was Convention 108, which the CoE opened for signature on January 28, 1981.** As mentioned above, the Convention embodied the common-principles approach: rather than attempting to make different national laws operate across borders, it established shared data protection standards that participating states agreed to incorporate into their legal systems.

### International Cooperation in Drafting Convention 108

Convention 108 was developed within the CoE, but its drafting took place against a broader international effort to address the privacy implications of emerging information technologies. The CoE therefore **coordinated its work with other international organizations and non-European countries developing their own approaches to data protection**.

Particularly important was cooperation with the **Organisation for Economic Co-operation and Development (OECD)**. The two organizations maintained close contact as the OECD developed what would become its own privacy guidelines governing the protection of personal data and transborder data flows. The OECD and four of its non-European members—Australia, Canada, Japan, and the United States—participated as observers in the CoE’s work. Observers from Finland, the Hague Conference on Private International Law, and the European Communities also participated.

The **Commission of the European Communities** similarly followed the negotiations closely. It was already studying issues such as the harmonization of national data protection laws, transborder data flows, data security, and potential distortions of competition, but decided to await the outcome of the CoE’s work before determining whether additional Community action was necessary.

The **European Parliament** was also actively engaged in the emerging debate. In 1979, it adopted a resolution addressing the protection of individual rights in light of technological developments in data processing and transmitted it to the CoE.

### Chief Characteristics of Convention 108

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-10_14_15-AM.png)

Convention 108 was structured around three principal components:

- substantive data protection rules expressed as a set of **basic principles**;
- rules governing **transborder data flows**; and
- mechanisms for **mutual assistance, cooperation, and consultation** among the Parties.

Convention 108 starts from the premise that the free flow of information is itself an important principle protected under international and European human rights law, including Article 10 of the ECHR and Article 19 of the International Covenant on Civil and Political Rights (ICCPR).

At the same time, freedom of information must coexist with other rights and freedoms, particularly the right to respect for private life protected by Article 8 of the ECHR. Convention 108 therefore sought to impose restrictions or conditions on information flows only where justified by the need to protect individual rights.

**The ECHR itself was not considered an adequate vehicle for establishing this framework. Among other reasons, at the time it operated as a “closed” regional instrument that did not permit participation by non-European states outside the CoE. Convention 108 offered the possibility of developing data protection standards with a broader international reach.**

**Chapter II: A “Common Core” of Data Protection Principles**: At the heart of Convention 108 is Chapter II, which establishes the Convention’s basic principles for data protection. These principles developed from those first articulated in Resolutions (73) 22 and (74) 29, supplemented to reflect subsequent developments in national data protection legislation.

Rather than requiring every country to adopt identical legislation, Convention 108 established the objectives that national laws had to achieve while leaving each Party flexibility as to how those requirements would be implemented domestically.

This approach created what the Convention’s drafters described as a **“common core” of data protection principles**. Individuals would therefore receive a minimum level of protection in every country implementing the Convention, even though the precise structure of national data protection laws could differ.

The common core also served a broader purpose. By establishing comparable baseline protections across participating countries, Convention 108 sought to **harmonize national laws, reduce potential conflicts of law and jurisdiction, and build the trust necessary for personal data to move between countries**.

The substantive principles addressed matters that remain familiar today, including the fair and lawful collection and processing of personal data, purpose limitation, data quality, proportionality, and accuracy. In particular, personal data were expected to be adequate, relevant, and not excessive in relation to the purposes for which they were processed.

**Chapter III: Transborder Data Flows:** Chapter III addresses transborder data flows and reflects the Convention’s effort to reconcile data protection with the free movement of information.

Its basic approach was closely connected to the common core established in Chapter II: **if participating countries provided comparable fundamental protections for personal data, transfers between them generally should not require additional restrictions or special controls solely for data protection purposes**.

The Convention thus linked international data flows to a shared level of substantive protection. Rather than relying primarily on barriers to transfers, the framework sought to create sufficient consistency among national systems to allow information to move while individuals remained protected.

**Chapters IV and V: Cooperation and Mutual Assistance:** Convention 108 also recognized that common substantive principles would not be sufficient without mechanisms for international cooperation.

Chapter IV established mechanisms for cooperation between national authorities and for providing assistance to individuals seeking to exercise their rights in another country.

Chapter V established a broader framework for cooperation concerning the operation and development of the Convention itself, including through a Consultative Committee. This structure allowed the Convention to remain focused on fundamental principles while providing a mechanism through which participating states could cooperate on their interpretation and implementation.

### What Convention 108 Did Not Resolve: Applicable Law

The Convention’s drafters also considered whether to establish specific rules determining which country's law should apply when processing involved multiple jurisdictions. These questions could arise, for example, where processing occurred in more than one country or where the individual and the organization processing the data were located in different states.

The experts ultimately concluded that it was premature to establish specific choice-of-law rules in Convention 108\. Instead, they expected the common core of substantive protections—and the resulting convergence of national laws—to reduce the practical consequences of conflicts between national legal regimes.

The issue was nevertheless left open for further consideration, including the possibility that rules on applicable law could later be addressed through a protocol to the Convention.

## Convention 108 and EU Data Protection Law

Convention 108 and EU data protection law developed as **distinct but closely connected European legal frameworks**. Because EU Member States are also parties to Convention 108, considerable attention has historically been given to maintaining consistency between the CoE and EU approaches to data protection.

This relationship can be seen in the substantial alignment between Convention 108’s basic principles and those subsequently reflected in the EU Data Protection Directive and the GDPR. Concepts such as lawful and fair processing, specified purposes, data quality, proportionality, and accuracy run through both frameworks.

Convention 108 therefore did more than establish minimum international protections. Its common-core approach helped shape a shared European conception of how personal data should be processed—one that would continue to develop through later CoE instruments and EU data protection law.

### Data Protection and the Council of Europe After Convention 108

#### Non-Binding Council of Europe Recommendations

The adoption of Convention 108 did not end the CoE’s work on data protection. The Committee of Ministers continued to develop the Convention’s principles through a series of non-binding recommendations, often addressing data protection issues arising in particular sectors or contexts.

Although these recommendations are not legally binding, they have played an important role in the development and interpretation of European data protection standards. For many years, for example, [Recommendation (87)15](https://rm.coe.int/0900001680929718?ref=thedelatorrereview.com) on the use of personal data in the police sector was the principal European instrument providing specific guidance on the processing of personal data for police purposes. Concepts developed through the CoE’s work would later be reflected and further developed in European data protection legislation.

The CoE has also continued to update its guidance as technologies and processing practices have evolved. Its recommendations have addressed areas such as employment, health data, profiling, and other contexts in which the processing of personal data presents particular risks.

In this way, Convention 108 has operated not simply as a standalone treaty but as the foundation for an evolving body of CoE data protection standards, capable of responding to new technologies and uses of personal information.

## Modernizing Convention 108: Convention 108+

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-10_11_32-AM.png)

As technology and data-processing practices evolved, the CoE undertook a substantial modernization of Convention 108\. That process resulted in the **2018 Protocol amending Convention 108**, commonly associated with the modernized framework known as [**Convention 108+**](https://rm.coe.int/convention-108-convention-for-the-protection-of-individuals-with-regar/16808b36f1?ref=thedelatorrereview.com).

**The modernization strengthens the Convention's protections and brings its framework closer to contemporary data protection standards, including many concepts familiar from the GDPR**. Among other changes, it reinforces principles of transparency and accountability, strengthens individual rights, addresses the growing significance of automated processing, and enhances the independence and powers expected of supervisory authorities.

The modernization reinforces the Convention potential use as a universal instrument on data protection law. It reaffirms the data protection principles, provides for new rights aligned with the new rights under GDPR and increases the responsibilities of entities that process personal data.

Convention 108+ is particularly significant because it seeks to provide a global data protection framework capable of extending beyond the European Union, while maintaining a common set of legally binding principles for participating states.

## Additional resources

- [Resolution (73) 22 ](https://search.coe.int/cm/Pages/result%5Fdetails.aspx?ObjectID=0900001680502830&ref=thedelatorrereview.com)on the protection of the privacy of individuals vis-à-vis electronic data banks in the private sector, and
- [Resolution (74) 29](https://search.coe.int/cm/Pages/result%5Fdetails.aspx?ObjectID=09000016804d1c51&ref=thedelatorrereview.com) on the protection of the privacy of individuals vis-àvis electronic data banks in the public sector.
- [Explanatory Report to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data](https://rm.coe.int/CoERMPublicCommonSearchServices/DisplayDCTMContent?documentId=09000016800ca434&ref=thedelatorrereview.com)
- [Convention for the protection of individuals with regard to automatic processing of personal data](https://www.coe.int/en/web/conventions/full-list/-/conventions/rms/0900001680078b37?ref=thedelatorrereview.com)

#### Other

- You can find more information on Convention 108 [here](https://www.coe.int/en/web/data-protection/convention108-and-protocol?ref=thedelatorrereview.com).
- You can find information on the modernization of Convention 108 [here](https://www.coe.int/en/web/data-protection/convention108/modernised?ref=thedelatorrereview.com).

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Screenshot-2026-07-04-at-4.45.19---PM-1.jpeg)

### 

### 

###