- Question
- Are data rights human rights?
- Position1 of 2›
- Yes, data rights are human rights
- Argument‹2 of 2
Under the view of the ECHR everyone has the right to a private life
The argument
This argument holds that data rights are human rights because the leading human-rights framework in Europe already says so: under the European Convention on Human Rights, everyone has the right to respect for their private life, and the protection of personal data has been recognised as part of that right. Article 8 of the Convention guarantees respect for private and family life, home and correspondence. The European Court of Human Rights has interpreted this to cover personal information: it has held in a long line of cases that the collection, storage, use and disclosure of data about an individual — from police records to communications surveillance — engages Article 8, and that states must protect people against unjustified handling of their personal information. In other words, data protection is not a novel claim awaiting promotion to human-rights status; within the Convention system, it already operates as an aspect of an established human right. The argument draws out the logic behind that case law. Personal data is the modern form of the private life Article 8 was written to protect. A person's movements, communications, finances, health and associations once lived in letters and locked drawers; today they live in databases and data trails. To respect private life while leaving its digital record unprotected would empty the right of meaning in the world as it now is. The Convention's drafters protected correspondence in 1950; data is correspondence's successor. From this standpoint, the question answers itself once the existing law is consulted: Europe's foundational rights instrument treats control over personal information as part of the right to a private life. Because under the ECHR everyone has the right to a private life, and data falls within it, this argument holds, data rights are human rights.
Premises
Counter-arguments
The argument establishes that data protection is legally protected within one regional treaty system and then treats that as settling its moral status. Human rights are ordinarily claimed as universal and prior to any particular legal instrument; showing that a court has read data into an article shows what one body of jurisprudence holds, and jurisprudence can be revised, distinguished or, in principle, escaped by denouncing the treaty. If legal recognition were sufficient, the status of a right would change with the case law. The reach is also narrower than the framing suggests. The Convention binds its member states and covers a small fraction of the world's population; the universal instruments that do have global reach — the Universal Declaration and the Covenant on Civil and Political Rights — contain privacy provisions that have generated nothing like the equivalent body of data jurisprudence. A right recognised in one region is not thereby a human right. Article 8 is a qualified right besides. Interference is permitted where lawful, necessary and proportionate, and the Court has upheld extensive data collection for policing and national security. That is a weaker protection than the argument's framing implies. The rival account is that data protection is a regulatory regime serving underlying interests in privacy, dignity and autonomy — derived from human rights rather than being one. The distinction has practical bite, since data rights are routinely waived by consent in a way genuine human rights are not.
Rejecting the premises
[Rejecting P1] Article 8 is a qualified right permitting interference that is lawful, necessary and proportionate, and the Court has upheld extensive data collection for policing and security. [Rejecting P3] Recognition within one regional treaty system shows what a body of case law holds rather than that the interest is a universal human right; the global instruments with wider reach have generated no equivalent data jurisprudence.