UNHRDB › Special Procedures reports › SR Privacy

A/HRC/61/48

International collection of personal data

SR Privacy · 2026 · Mandate-holder: Ana Brian Nougrères · 62 paragraphs

Search and read in the UNHRDB app · Official text (UN Documents)

I. Introduction

¶1

Every day, the personal data of private citizens are collected and processed by companies, individuals or entities that do not have a physical presence in the respective territories. These international data collectors often argue that, because they are not domiciled in the country of the data subject, local data protection legislation does not apply to them. They also consider that the authorities of that country do not have legal or judicial jurisdiction to investigate them, apply guidelines or impose punishments on them, as the case may be.

¶2

This leaves unprotected the rights of millions of people, whose personal data are continuously obtained by international collectors located outside the territory of the data subjects’ countries.

¶3

In addition, technological tools such as cookies are used to collect personal data from millions of individuals in every country. The actions of international data collectors have a significant and large-scale impact on the lives of many people. A situation of impunity with regard to human rights on the Internet must not be “normalized” or “tolerated”, especially when data collectors do not comply with the laws of the countries in which they obtain the information.

¶4

The present report examines the international collection of personal data, with the aim of highlighting the challenges that this practice presents at the global level and proposing solutions to ensure the proper handling of the personal data of any individual in the world.

II. National and international collection of personal data

¶5

Local and international regulations mainly refer to the national collection of personal data but contain little or no mention of the international collection thereof.

¶6

The national collection of personal data takes place when the data collector (data controller or processor) is domiciled in the same country (country A) as the data subject (country A). In this case, the collection and processing of such data are governed by the regulations of country A.

¶7

The international collection of personal data, on the other hand, takes place when the data collector (data controller or processor) is domiciled in a different country (country A) from the data subject (country B).

¶8

The foregoing can be summarized as set out below:
National collection of personal data International collection of personal data
Is the data collector domiciled in the same country as the data subject? Yes No
Is there certainty about the law applicable to the collection and processing of personal data? Yes Noa1
Is there certainty regarding which authority is competent with regard to protecting the rights of the data subject? Yes Noa

  1. As a general rule, it is considered that there is no certainty, but this answer may vary depending on the country and the scope of its regulations. ↩
¶9

No international documents, and very few countries, expressly refer to the international collection of data. In Brazil, international collection of personal data is defined in Resolution CD/ANPD No. 19, dated 23 August 2024, as the direct collection of a data subject’s personal data by a data controller located in another country.2 It should be noted that a characteristic element of the definition of the international collection of personal data is that the collector is located or domiciled in a country other than that of the data subject.

  1. National Data Protection Authority of Brazil, Regulations on International Data Transfer, art. 3: “For the purposes of the present Regulations, the following definitions are used: V. International data collection: collection of the personal data of the data subject, carried out directly by a processing agent located abroad.” The official text of the Regulations is available at https://dspace.mj.gov.br/bitstream/1/13458/2/RES_ANPD_2024_19.pdf. ↩
¶10

In Colombia, international collection of personal data is not defined, but Statutory Act No. 1581 of 2012 sets out the following rule for the personal data protection authority: “The Office of the Superintendent of Trade and Industry shall exercise the following functions: … (j) Request the collaboration of international or foreign entities when the rights of data subjects located outside Colombian territory are affected, including, inter alia, in the case of international collection of personal data.”3

  1. Colombia, Statutory Act No. 1581 of 2012 establishing general provisions for the protection of personal data. The official text is available at http://www.secretariasenado.gov.co/senado/basedoc/ley_1581_2012.html. ↩
¶11

In summary, regulations on the collection of personal data are focused primarily at the national level, while the international collection of personal data receives little attention. National collection occurs when both the collector and the data subject are located in the same country and is governed by the regulations of that country. In contrast, international collection occurs when the collector is in a different country from the data subject.

¶12

Few countries have specific provisions on the international collection of personal data. In Brazil, for example, it is defined in the aforementioned resolution, with a focus on the collector being located abroad. In Colombia, although there is no exact definition of international collection of personal data, the law states that the personal data protection authority must request assistance from foreign entities to protect the rights of Colombian nationals when they are violated by data collectors located outside Colombian territory.

III. The rules on international data transfer do not cover the international collection of personal data

¶13

Several decades ago, it became clear that the disparities in regulations on the protection of personal privacy were a barrier to the cross-border flow of personal data. A process of regulatory harmonization was therefore begun during the twentieth century with the aim of achieving global consensus on how to facilitate the international free movement of personal data while also protecting individuals’ rights, especially in terms of privacy, when their personal data are processed.

¶14

Privacy and international transfers of personal data were the main drivers for harmonization and regulation of the processing of personal information. However, international collection of data was not among the reasons for or the objectives of the harmonization processes. In other words, the current regulations were designed with international data transfer in mind, rather than international collection of personal data.

¶15

Regulations on international data transfers or cross-border data flows4 seek to ensure that the level of protection accorded to the personal data of citizens of a country does not diminish or disappear when such data must be exported or transferred to another country or countries. This rule is known as the “principle of continuity of data protection,” which is based on the idea that international data transfers should not affect the protection of data subjects with regard to the processing of their personal data. Therefore, regulations impose obligations on data exporters who intend to send such information from one country to another country or countries.

  1. “Cross-border data flow” and “international data movement” are other expressions used to refer to international transfers of personal data. ↩
¶16

The exporting of personal information must not result in situations where the level of protection afforded to the data subject in the country from which personal data is exported is reduced. In the performance of these activities, violations of individuals’ rights and any erosion of the safeguards they enjoy in the country from which the data is exported must not be facilitated, permitted or tolerated.

¶17

The focus of current international documents is on requiring data exporters to comply with certain requirements that must be met in the country of origin of the export. This is intended to protect people’s rights by ensuring prior verification of certain conditions in that country. If the destination country does not meet the minimum protection standards, international data transfers are generally not permitted from the country of origin.

¶18

In the case of international transfers of personal data, responsibility for the transfer lies with the sender of the information, and checks are carried out in the country of origin of the data to be transferred. In other words, regulations on international data transfers are focused on the export of that information and on its exporter.

¶19

Although privacy and international data transfer remain two important and ongoing issues, the international collection of personal data has joined them. The rules on cross-border transfer of personal data do not cover the phenomenon of international collection of personal data. When the international collection of personal data takes place, the data leave one country and arrive in another not because someone exports them from country A to country B, but because a collector located in country B extracts citizens’ data from country A.

¶20

In summary, the terms “international collection of data” and “international data transfer” refer to two different legal institutions that have in common the cross-border flow of personal data. In both cases, people’s information leaves the territorial borders of one State and enters the territory of another State. However, the way in which this happens is different in the two cases.

IV. Background and recommendations of the United Nations on the international collection of personal data

¶21

In her 2024 report,5 the Special Rapporteur presented a proposal for the updating of General Assembly resolution 45/95, entitled “Guidelines for the regulation of computerized personal data files”. The Special Rapporteur highlighted that current technology allows data to be collected anywhere in the world from individuals domiciled or residing in other countries. This phenomenon, known as “international data collection”,6 is not envisaged in General Assembly resolution 45/95. As the means by which data are most frequently collected from individuals worldwide, it should be incorporated into international documents.

  1. A/79/173. ↩
  2. See Nelson Remolina Angarita, Recolección internacional de datos personales: un reto del mundo post-internet (International collection of personal data: a challenge in the post-Internet world) (Madrid, Official Gazette, 2015). ↩
¶22

The proposal to update General Assembly resolution 45/95 therefore included the following text:

¶23

International collection of personal data
States shall adopt appropriate, useful and timely measures to ensure the proper processing of personal data and the effective protection of the rights of individuals whose information is collected by data controllers or data processors which are located in countries other than the country of domicile or residence of the subject of the personal data and which have no physical headquarters or establishment in the country of domicile or residence of the subject of the personal data (international data collector).
In addition, States shall cooperate with one another, with data protection authorities and with data subjects to ensure the achievement of the objective set forth in the preceding paragraph.
The fact that the international data collector is not present in and does not have a physical headquarters or establishment in the country of the data subject should not generate or facilitate impunity or a lack of protection of the rights of individuals.

¶23

It was highlighted in the report that around the world, reviews are being conducted of relevant international documents on data processing and of local laws, with a view to modernizing them.

¶24

The work of the Global Privacy Assembly was cited as an example. In 2023, the Assembly adopted a resolution aimed at achieving global data protection standards,7 in which, among other issues, it resolved to advocate for, promulgate and promote the principles, rights and other elements set out in the resolution, to ensure that they could be effectively implemented and applied in all contexts, particularly in the processing of data with new and emerging technologies and innovations. Specifically, the Assembly emphasized the importance of providing for the protection of personal data across borders to ensure that protection “travels” with the data when the data cross borders.

  1. Global Privacy Assembly, Achieving global data protection standards: Principles to ensure high levels of data protection and privacy worldwide, adopted at the forty-fifth Annual Meeting of the Assembly in October 2023. The text of the resolution is available at https://globalprivacyassembly.com/document-archive/adopted-resolutions/. ↩
¶25

International collection of data is more prevalent in cyberspace, which comprises the following elements: (a) technological infrastructure (technological resources) composed of countless pieces of equipment (servers, computers, mobile telephones, tablets, etc.) located in many parts of the world; (b) a worldwide platform for communications (global communications network), information and interconnected networks (Internet), known as “global information infrastructure”; (c) millions of people and organizations of diverse nationalities, based in countries with dissimilar legal systems, using, from anywhere in the world, technology, communications and information to interact with other people, and the services available on the Internet; and (d) huge amounts of information (including personal data) that are constantly circulating within countries and across borders.

¶26

Lastly, the report states that the global, international and cross-border nature of many activities conducted through the Internet, such as e-commerce, has been a key aspect that has led to the need for appropriate regulations in order to promote development and innovation and to sufficiently protect the right of individuals whose information is collected and used by companies, people and governments throughout the world.

¶27

The next section contains information on the use of cookies as a technological tool for the international collection of data.

V. The use of cookies for the international collection of personal data

¶28

Cookies are an example of technologies used to collect personal data. Data protection authorities in several countries, including Colombia, Spain, the United States of America, Ireland, Italy, the United Kingdom of Great Britain and Northern Ireland and Uruguay, as well as the Court of Justice of the European Union and other courts have defined cookies and described their purpose. On that basis, the following conclusions can be reached:
(a) Cookies are installed on personal devices (mobile telephones, tablets, computers or any other device that stores information);
(b) The purpose of cookies is to collect or store personal data (username, unique identifier, email address, the searches performed by users, their Internet browsing habits and the websites they visit) and other types of information;
(c) Cookies are a mechanism for tracking or monitoring individuals; for example, they enable detailed tracking of a user’s Internet searches or browsing habits;
(d) The collection or storage of information using cookies constitutes the processing of personal data.

¶29

In Ireland, the Data Protection Commission published guidance on cookies and other tracking technologies in 2020.8 The guidance states the following:
Cookies are usually small text files stored on a device, such as a personal computer, a mobile device or any other device that can store information. Devices that may use cookies also include so-called Internet of things devices that connect to the Internet.
Cookies serve a number of important functions, including to remember a user and their previous interactions with a website. They can be used, for example, to keep track of items in an online shopping cart or to keep track of information when you input details into an online application form. Authentication cookies are also important to identify users when they log in to banking services and other online services. […]
The information stored in cookies can include personal data, such as an IP address, a username, a unique identifier or an email address. But it may also contain non-personal data such as language settings or information about the type of device a person is using to browse the site.

  1. Data Protection Commission of Ireland, Guidance Note: Cookies and other tracking technologies (April 2020). Available at https://www.dataprotection.ie/en/dpc-guidance/guidance-cookies-and-other-tracking-technologies. ↩
¶30

In the United Kingdom, the Information Commissioner’s Office published guidance on the use of cookies and similar technologies,9 stating that “cookies are small pieces of information, normally consisting of just letters and numbers, which online services provide when users visit them. Software on the user’s device (for example a web browser) can store cookies and send them back to the website next time they visit.” The guidance highlights that cookies are “a specific technology that stores information” and are used for the following purposes: (a) to track users’ browsing behaviour when they visit a website; (b) to analyse traffic to a website; or (c) to help users log in to a website.

  1. Information Commissioner’s Office, United Kingdom, Guidance on the use of cookies and similar technologies (2019). Available at https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/. ↩
¶31

The guidance also states that “without cookies, or some other similar method, websites would have no way to ‘remember’ anything about visitors, such as how many items are in a shopping basket or whether they are logged in.”

¶32

In Italy, the Data Protection Authority published its guidelines on the use of cookies and other tracking tools10 in 2021, which state, among other things, the following:
Cookies are, as a rule, text strings that the websites visited by the user (known as “publisher” or “first party” websites) or other websites or web servers (known as “third parties”) place and store within a terminal device in the user’s possession, either directly, in the case of publisher websites, or indirectly, in the case of third parties, using publisher websites as intermediaries.
The terminal devices referred to include, for example, a computer, a tablet, a smartphone or any other device capable of storing information. […]
Information encoded in cookies might include personal data, such as an IP address, a username, a unique identifier or an email address, and also non-personal data, such as language settings or information on the type of device a person is using to navigate within the website.
Cookies can therefore perform important and diverse functions, including monitoring sessions, storing specific server access information related to user configuration and facilitating the use of online content. For example, they can be used to keep track of the items in an online shopping basket or the information used to fill in a computer form.

  1. Italian Data Protection Authority, Guidelines on the use of cookies and other tracking tools, 10 June 2021. Available at https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677876#english. ↩
¶33

In Uruguay, the Personal Data Regulation and Monitoring Unit states the following in its guide on cookies and profiles:11 “A cookie is a type of file that stores user information and is sent by a website through a browser. The file is downloaded to computers, tablets, mobile telephones or any other device for the purpose of storing data that can be updated or retrieved by the person responsible for its installation.”

  1. Personal Data Regulation and Monitoring Unit of Uruguay, Cookies and Profiles (2018). Available at https://www.gub.uy/unidad-reguladora-control-datos-personales/comunicacion/publicaciones/guia-de-cookies-y-perfiles. ↩
¶34

The Colombian data protection authority has found that some companies that are not domiciled in Colombia collect data using cookies. It has also pointed out that in order to collect and process data in Colombia, it is not necessary to be domiciled in that country because technological progress and tools allow companies or organizations to collect data in Colombia without having a physical presence in Colombian territory. These organizations have a “technological presence” in that territory through the use of technological tools or applications that are installed on devices, including telephones, tablets and computers, located in Colombian territory.

¶35

In fact, in one case, the Colombian data protection authority concluded that WhatsApp LLC collects and processes personal data in Colombia, including through the use of cookies and the WhatsApp mobile application. According to the data protection authority, the WhatsApp application is known to be installed on millions of devices belonging to citizens residing in Colombian territory. The application collects data in Colombia during and after installation.12

  1. Personal Data Protection Authority, Office of the Superintendent of Trade and Industry of Colombia, Decision No. 15342, dated 28 March 2022. The text of the decision is available at https://www.sic.gov.co/decisiones-de-apelacion-2022. ↩
¶36

In another case, the Colombian data protection authority found that Google LLC13 uses various technologies, including web cookies, to collect personal data in Colombia. According to the authority, Google LLC collects the following personal information: names; passwords; payment information; telephone numbers; age; email addresses; payment methods; contacts; likes and preferences; IP address; location; device sensor data; Wi-Fi access points; cell towers and Bluetooth-enabled devices; search terms; views and interactions with videos, content and advertisements; voice and audio information; videos watched; purchases; people with whom a user communicates or shares content; activity on third-party sites and apps; browsing history; unique identifiers; browser type and settings; device type and settings; operating system; mobile network information; provider’s name and telephone number; and app version number.14

  1. Personal Data Protection Authority, Office of the Superintendent of Trade and Industry of Colombia, Decision No. 2389, dated 28 January 2022. The text of the decision is available at https://www.sic.gov.co/decisiones-de-apelacion-2022. ↩
  2. Google Privacy Policy. Available at https://policies.google.com/privacy?hl=en#infocollect. Cited in the decision of the Colombian data protection authority. ↩
¶37

The Colombian data protection authority concluded that Google LLC must ensure the proper processing of the personal data of children and adolescents domiciled or resident in Colombia. Neither the Internet nor the lack of physical presence or a home address in the territory are legally valid arguments to justify non-compliance with regulations on the processing of personal data.

¶38

In Spain, the Data Protection Agency states the following in its guide on use of cookies:15 “Act No. 34/2002 on Information Society and Electronic Commerce Services is applicable to cookies, which are understood in the sense stated at the beginning of this guide, namely, as being any data storage or recovery device used in a user’s terminal device for the purposes of storing information and recovering stored information, as set forth in 11 Personal Data Regulation and Monitoring Unit of Uruguay, Cookies and Profiles (2018). Available at https://www.gub.uy/unidad-reguladora-control-datos-personales/comunicacion/publicaciones/guiade-cookies-y-perfiles. 12 Personal Data Protection Authority, Office of the Superintendent of Trade and Industry of Colombia, Decision No. 15342, dated 28 March 2022. The text of the decision is available at https://www.sic.gov.co/decisiones-de-apelacion-2022. 13 Personal Data Protection Authority, Office of the Superintendent of Trade and Industry of Colombia, Decision No. 2389, dated 28 January 2022. The text of the decision is available at https://www.sic.gov.co/decisiones-de-apelacion-2022. 14 Google Privacy Policy. Available at https://policies.google.com/privacy?hl=en#infocollect. Cited in the decision of the Colombian data protection authority. 15 Spanish Data Protection Agency, Guide on use of cookies (May 2024). Available at https://www.aepd.es/guias/guia-cookies.pdf. GE.25-21171 article 22 (2) of the Act. Cookies allow the storage of data of between a few kilobytes and several megabytes on the user’s device.”

  1. Spanish Data Protection Agency, Guide on use of cookies (May 2024). Available at https://www.aepd.es/guias/guia-cookies.pdf. ↩
¶39

The United States Federal Trade Commission has stated that “cookies are small pieces of computer text that are used to collect information from computers and can be used to serve targeted advertisements to consumers. By placing a tracking cookie on a user’s computer, an advertising network can collect information about the user’s web-browsing activities and use that information to serve online advertisements targeted to the user’s interests or for other purposes.”16 Additionally, the Commission states that cookies are used to collect information about the pages people view and their activities on a website and to customize the user’s browsing experience.17 The Commission published a guide on how to protect privacy online, stating the following:18 “When you visit a website, the site may place a file called a cookie on your Internet browser or explorer. Websites use cookies to personalize your Internet browsing experience.”

  1. United States Federal Trade Commission, “Google will pay $22.5 million to settle FTC charges it misrepresented privacy assurances to users of Apple’s Safari Internet browser. Privacy settlement is the largest FTC penalty ever for violation of a Commission order” (9 August 2012). Available at https://www.ftc.gov/news-events/press-releases/2012/08/google-will-pay-225-million-settle-ftc-charges-it-misrepresented. ↩
  2. United States Federal Trade Commission, Internet Cookies. Available at https://www.ftc.gov/site-information/privacy-policy/internet-cookies. ↩
  3. The full text of the guide is available at https://www.consumidor.ftc.gov/articulos/como-proteger-su-privacidad-en-linea. ↩
¶40

The Court of Justice of the European Union stated the following in its judgment in case No. C-673/17: “Cookies aim to collect information for advertising purposes relating to the products of partners of the organizer of the promotional lottery.”19 It also pointed out that “according to the order for reference, cookies are text files which the provider of a website stores on the website user’s computer which that website provider can access again when the user visits the website on a further occasion, in order to facilitate navigation on the Internet or transactions, or to access information about user behaviour.”

  1. Court of Justice of the European Union, Case C-673/17, judgment of 1 October 2019 (Grand Chamber). Available at https://curia.europa.eu/juris/documents.jsf?language=EN&critereEcli=ECLI:EU:C:2019:801. ↩
¶41

Lastly, in a 2025 case, the Constitutional Court of Colombia recognized the use of cookies as a data collection mechanism used by companies not domiciled in Colombia. Indeed, in a dispute between a Colombian citizen and a company domiciled in the United States, the Court found that “through the Instagram platform, Meta Inc. collects and processes personal data in Colombia. Digital social networks use technological tools such as cookies to collect personal data, without needing to be domiciled or physically located in the national territory.”20

  1. This quote is from paragraph 195 and footnote 219 of judgment No. T-256 of 12 June 2025 of the Constitutional Court of Colombia (Remedy of amparo filed by a Colombian citizen against Facebook Colombia S.A.S. and Meta Platforms, Inc.): Personal Data Protection Authority, Office of the Superintendent of Trade and Industry of Colombia, Decision No. 1321 of 2019. The text of the judgment is available at https://www.corteconstitucional.gov.co/relatoria/2025/t-256-25.htm. ↩

VI. The extraterritorial application of laws as an alternative means of addressing challenges in the international collection of personal data

¶42

The international collection of personal data and the extraterritorial application of laws are different, but related or connected, issues.

¶43

As mentioned above, international collection of personal data refers to the collection, by a person or entity in one country (country A), of information from individuals residing in another country (country B) without being physically present in country B. The collector is in a different country from the data subject. 16 United States Federal Trade Commission, “Google will pay $22.5 million to settle FTC charges it misrepresented privacy assurances to users of Apple’s Safari Internet browser. Privacy settlement is the largest FTC penalty ever for violation of a Commission order” (9 August 2012). Available at https://www.ftc.gov/news-events/press-releases/2012/08/google-will-pay-225-million-settle-ftccharges-it-misrepresented. 17 United States Federal Trade Commission, Internet Cookies. Available at https://www.ftc.gov/siteinformation/privacy-policy/internet-cookies. 18 The full text of the guide is available at https://www.consumidor.ftc.gov/articulos/como-proteger-suprivacidad-en-linea. 19 Court of Justice of the European Union, Case C-673/17, judgment of 1 October 2019 (Grand Chamber). Available at https://curia.europa.eu/juris/documents.jsf?language=EN&critereEcli=ECLI:EU:C:2019:801. 20 This quote is from paragraph 195 and footnote 219 of judgment No. T-256 of 12 June 2025 of the Constitutional Court of Colombia (Remedy of amparo filed by a Colombian citizen against Facebook Colombia S.A.S. and Meta Platforms, Inc.): Personal Data Protection Authority, Office of the Superintendent of Trade and Industry of Colombia, Decision No. 1321 of 2019. The text of the judgment is available at https://www.corteconstitucional.gov.co/relatoria/2025/t-256-25.htm. GE.25-21171

¶44

Extraterritorial application of the law is a mechanism that allows for defining or establishing whether the rules or regulations of the country in which the data subject resides (country B) are binding or not for the international collector (domiciled in country A). The answer as to whether or not they are binding will depend on several factors, including the rules set out in any international documents that are binding on the parties and the scope of application of local laws.

¶45

Cases involving the international collection of personal data via the Internet pose a challenge to traditional rules on international conflicts of jurisdiction, which are generally based on the principle of territoriality. Therefore, there is no single answer for all countries on how these cases should be handled, as each situation must be analysed on the basis of the relevant laws and any international regulations that apply.

¶46

The current situation regarding the regulation of the processing of personal data can be described as follows:
(a) There is no international treaty or instrument that is legally binding on all countries in the world;
(b) Not all countries in the world have general regulations on the processing of personal data;
(c) There are local regulations that are strictly territorial in scope;
(d) There are local regulations with territorial and extraterritorial scope;
(e) There are regional regulations with territorial and extraterritorial scope.

¶47

The key elements of the situation described above are set out below.

A. Absence of an international treaty and lack of local regulations in all countries worldwide

¶48

This situation highlights the regulatory gaps at the global and local levels that must be filled, not only because many people are left unprotected, but also because jurisdictional problems between States are being created and “data havens” are being encouraged.

¶49

In the absence of an international treaty on the processing of personal data that is binding on all countries and defines the rules on jurisdiction, various challenges arise, which can be summarized as follows:
When defining the rules for assuming jurisdiction over Internet-related cases, legal systems face two problematic extremes. On the one hand, if the principle of territoriality is understood very strictly, conduct that does not occur in any physical location but nevertheless impacts individuals or the interests of States might go unregulated or unpunished. On the other hand, if criteria are not established for States to exercise their jurisdiction in Internet-related disputes, each State would assume a kind of universal jurisdiction simply because the conduct occurs in cyberspace. This situation would create legal uncertainty for individuals and companies, who would not know which rules to follow.
The first extreme, which consists of an unmindful application of the principle of territoriality, is problematic because it would imply the existence of areas that are off-limits for State action. In the light of the Constitution, this situation is unacceptable as the authorities cannot forgo their duty to uphold the constitutional order and the fundamental rights of individuals.21

  1. Constitutional Court of Colombia, judgment No. T-256, 12 June 2025. ↩

B. Lack of general regulations on the processing of personal data in all countries worldwide

¶50

The lack of regulation in some countries means that in those parts of the world, there is uncertainty about how to protect the rights of data subjects, or individuals are simply not protected against the improper processing of personal data. The Explanatory Report to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data22 noted that there are countries that do not have data protection laws or that have minimal protection; they are known as “data havens”, where the protection of data subjects’ rights is weak or non-existent.23

  1. Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Strasbourg, 28 January 1981). Available at https://rm.coe.int/16806c1abd. ↩
  2. The Explanatory Report reads as follows: “In practice, however, protection of persons grows weaker when the geographic area is widened. Concern has been expressed that data users might seek to avoid data protection controls by moving their operations, in whole or in part, to “data havens”, i.e. countries which have less strict data protection laws, or none at all.” The full text of the Explanatory Report (in English and French) is available at http://conventions.coe.int/Treaty/EN/Reports/HTML/108.htm. ↩
¶51

“Data havens” are countries or jurisdictions that lack data protection laws and become “attractive locations for the processing of personal data in ways that may violate other privacy laws.”24 “Data havens” not only include countries with no regulations on the processing of personal data, but are also connected to other issues such as cybercrime. For the United Nations, for example, “data havens” are “States where reducing or preventing the misuse of computer networks is not a priority, or where no effective procedural laws have been developed”.25

  1. Pablo Palazzi, “Comercio electrónico, transferencia internacional de datos personales y armonización de leyes en un mundo globalizado” (E-commerce, international transfer of personal data and harmonization of laws in a globalized world), in Derecho de Internet y Telecomunicaciones, Bogotá, Legis, 2003, p. 299. ↩
  2. A/CONF.187/10, para. 3 (c). ↩

C. Existence of regional rules with territorial and extraterritorial scope

¶52

This scenario provides partial answers to the challenges of international collection of personal data because it encompasses the classic rules of territoriality but at the same time opens the door to the extraterritorial application of its regulations. An example of this would be article 3 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), which states the following:
Article 3. Territorial scope
(1) This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
(2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
(3) This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

¶53

It should be noted that article 3 (2) provides for the extraterritorial application of the Regulation in certain specific situations and not in all cases involving the international collection of personal data. 22 Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Strasbourg, 28 January 1981). Available at https://rm.coe.int/16806c1abd. 23 The Explanatory Report reads as follows: “In practice, however, protection of persons grows weaker when the geographic area is widened. Concern has been expressed that data users might seek to avoid data protection controls by moving their operations, in whole or in part, to “data havens”, i.e. countries which have less strict data protection laws, or none at all.” The full text of the Explanatory Report (in English and French) is available at http://conventions.coe.int/Treaty/EN/Reports/HTML/108.htm. 24 Pablo Palazzi, “Comercio electrónico, transferencia internacional de datos personales y armonización de leyes en un mundo globalizado” (E-commerce, international transfer of personal data and harmonization of laws in a globalized world), in Derecho de Internet y Telecomunicaciones, Bogotá, Legis, 2003, p. 299. 25 A/CONF.187/10, para. 3 (c). GE.25-21171

VII. Conclusions

¶54

In the light of the foregoing, and taking into account specialized studies on international collection of personal data,26 the following conclusions can be drawn.

  1. For this report, the Special Rapporteur took into account the doctoral research of Professor Nelson Remolina Angarita of the University of the Andes (Bogotá), author of Recolección internacional de datos personales: un reto del mundo post-internet (Madrid, Official Gazette, 2015). ↩
¶55

The international collection of personal data – understood as the collection of personal data from abroad by a person who is not domiciled or resident in the country of the data subject – has not been defined as a legal phenomenon in international documents, and there is a lack of comprehensive and legally binding responses aimed at protecting the rights of individuals from violations that might occur as a result of, or in connection with, the international collection of personal data.

¶56

In this regard, the international collection of personal data is a problem for States and for the law because it creates national and global challenges that require responses of the same nature, namely national and international. In the face of this phenomenon, unilateral and isolated efforts by individual countries are insufficient. While national problems are solved with national solutions, global problems will usually require global solutions.

¶57

The global technological landscape has changed dramatically since the need to protect individuals’ rights against the improper processing of their personal data first began to emerge. The Internet has “empowered” citizens, businesses and governments around the world insofar as, through the Internet, personal data can be collected and processed from individuals of any nationality, who may be domiciled virtually anywhere on the planet. The Internet has unleashed a wave of challenges to the law, including those relating to the international collection of personal data.

¶58

Every person with Internet access is a potential international collector of personal data, and as the number of individuals with Internet access increases, the potential number of data collectors will rise proportionately in every location in the world where there is Internet access.

¶59

In addition to the foregoing, a significant portion of the activities that take place on the Internet have a multinational and cross-border component which, depending on the specific case, can pose various international and even global challenges to the different legal systems currently in place.

¶60

The guidelines governing international data transfers do not apply to international collection of personal data, because in the latter case there is no data sender who can be controlled by the local authorities in the data’s country of origin. In international collection of data, billions of people with Internet access, anywhere in the world, collect data from other people located in countries other than that of the collector. That is, in a nutshell, the scale of one of the challenges of the international collection of personal data.

VIII. Recommendations

¶61

In the light of the foregoing, and in addition to the recommendations made in her 2024 report,27 the Special Rapporteur respectfully urges States to:
(a) Develop an international treaty that is legally binding on all countries worldwide and that properly and comprehensively addresses the challenges that the international collection of personal data poses to the protection of individuals’ rights;
(b) Modify the scope of application of general and local regulations on the processing of personal data to encompass extraterritorial situations such as the international collection of personal data.

  1. A/79/173. ↩