Brussels effect

Last updated
The Berlaymont building in Brussels, the headquarters of the European Commission Banderas europeas en la Comision Europea.jpg
The Berlaymont building in Brussels, the headquarters of the European Commission

The Brussels effect is the process of unilateral regulatory globalisation caused by the European Union de facto (but not necessarily de jure ) externalising its laws outside its borders through market mechanisms. Through the Brussels effect, regulated entities, especially corporations, end up complying with EU laws even outside the EU for a variety of reasons.

Contents

Etymology

The term Brussels effect was coined in 2012 by Professor Anu Bradford of Columbia Law School [1] [2] [3] and named after the similar California effect that can be seen within the United States. [4]

Cause

The combination of market size, market importance, [1] relatively stringent standards and regulatory capacity [5] of the European Union can have the effect that firms trading internationally find that it is not economically, legally or technically practical to maintain lower standards in non-EU markets. Non-EU companies exporting globally can find that it is beneficial to adopt standards set in Brussels uniformly throughout their business. [6] [7]

Effect

The California effect and the Brussels effect are a form of "race to the top" where the most stringent standard has an appeal to companies operating across multiple regulatory environments as it makes global production and exports easier. [8] [9] [10] The effects are the opposite of the Delaware effect, a race to the bottom where jurisdictions can purposefully choose to lower their regulatory requirements in an attempt to attract businesses looking for the least stringent standard. [11]

Scholars could so far not empirically verify the limits of the Brussels Effect in international law, especially World Trade Organization (WTO) law. [12] Furthermore, for the Brussels effect to occur, it was shown that not all prerequisites identified by Bradford have to occur cumulatively. [13] Research has indicated that the EU's regulatory power varies substantially depending on the context of the regulation involved. [14] [15]

Examples

Antitrust

The October 2000 $42 billion proposed acquisition of US-based Honeywell by US-based General Electric was blocked by the EU antitrust authorities on the grounds of risking a horizontal monopoly in jet engines. The merger could not proceed because, despite the American Department of Justice having already approved the merger between these two US-based entities, it was not legally possible to let the acquisition proceed in one important market, but not in another. [1] [16]

Chemicals

US-based multinational Dow Chemical announced in 2006 it would comply with the EU's Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH) regulation for the production and use of chemical substances across its global operation. [1] [17] [18]

Airplane emissions

In 2012 the EU included aviation into its existing Emission Trading Scheme. This means that any airline, regardless of their country of origin, has to purchase emissions permits for any flights within the European Economic Area. [19] The cost of complying with EU aviation emission regulation puts pressure on manufacturers to design airplanes with improved efficiency and reduced emissions. As major airlines would not likely purchase airplanes specifically to fly outside the EEA, the EU's stricter aviation standards have an impact on global airplane fleets, regardless of the jurisdiction of the airline. [1] [20]

Data protection and privacy

With the introduction of the Data Protection Directive in 1995 the EU had opted for a strict top-down approach to data privacy. [21] Its successor, the EU's General Data Protection Regulation (GDPR), was adopted on 14 April 2016 and had a global effect. [22] [23] In 2017, during negotiations for a new Japan-EU trade deal, Japan set up an independent agency to handle privacy complaints to conform with the EU's new privacy regulation. [24]

Facebook announced in April 2018 that it would implement parts of the GDPR globally. [25] [26] Sonos announced in April 2018 that it would implement the GDPR globally, [27] and Microsoft announced in May 2018 that it would implement GDPR compliance for all its customers globally. [28]

Exploitation of natural resources

The Brussels effect can be observed in two regulatory frameworks that regulate the exploitation of natural resources, the Conflict Minerals Regulation and Country by Country Reporting Rules for payments to governments. [29] [ clarification needed ]

Consumer electronics

In October 2022 the European Parliament adopted a directive which required many consumer electronic devices – notably mobile phones – to adopt USB-C as a universal charger by 2024. [30] This was seen as being particularly applicable to Apple and its iPhone product range which had, until then, rejected standardisation. [31] The expectation was that, due to the EU's large marketplace, the EU-specific regulation would nonetheless result a change in how products were manufactured for sale in other countries (to ensure a single global product), and that other jurisdictions would adopt equivalent legislation. [32]

See also

Related Research Articles

Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, contextual information norms, and the legal and political issues surrounding them. It is also known as data privacy or data protection.

<span class="mw-page-title-main">Data Protection Directive</span> EU directive on the processing of personal data

The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, was a European Union directive which regulated the processing of personal data within the European Union (EU) and the free movement of such data. The Data Protection Directive was an important component of EU privacy and human rights law.

A privacy policy is a statement or legal document that discloses some or all of the ways a party gathers, uses, discloses, and manages a customer or client's data. Personal information can be anything that can be used to identify an individual, not limited to the person's name, address, date of birth, marital status, contact information, ID issue, and expiry date, financial records, credit information, medical history, where one travels, and intentions to acquire goods and services. In the case of a business, it is often a statement that declares a party's policy on how it collects, stores, and releases personal information it collects. It informs the client what specific information is collected, and whether it is kept confidential, shared with partners, or sold to other firms or enterprises. Privacy policies typically represent a broader, more generalized treatment, as opposed to data use statements, which tend to be more detailed and specific.

Personal data, also known as personal information or personally identifiable information (PII), is any information related to an identifiable person.

Information privacy, data privacy or data protection laws provide a legal framework on how to obtain, use and store data of natural persons. The various laws around the world describe the rights of natural persons to control who is using its data. This includes usually the right to get details on which data is stored, for what purpose and to request the deletion in case the purpose is not given anymore.

The Agreement on the Application of Sanitary and Phytosanitary Measures, also known as the SPS Agreement or just SPS, is an international treaty of the World Trade Organization (WTO). It was negotiated during the Uruguay Round of the General Agreement on Tariffs and Trade (GATT), and entered into force with the establishment of the WTO at the beginning of 1995. Broadly, the sanitary and phytosanitary ("SPS") measures covered by the agreement are those aimed at the protection of human, animal or plant life or health from certain risks.

TrustArc Inc. is a privacy compliance technology company based in Walnut Creek, California. The company provides software and services to help corporations update their privacy management processes so they comply with government laws and best practices. Their privacy seal or certification of compliance can be used as a marketing tool.  

The Chief Privacy Officer (CPO) is a senior level executive within a growing number of global corporations, public agencies and other organizations, responsible for managing risks related to information privacy laws and regulations. Variations on the role often carry titles such as "Privacy Officer," "Privacy Leader," and "Privacy Counsel." However, the role of CPO differs significantly from another similarly-titled role, the Data Protection Officer (DPO), a role mandated for some organizations under the GDPR, and the two roles should not be confused or conflated.

Pseudonymization is a data management and de-identification procedure by which personally identifiable information fields within a data record are replaced by one or more artificial identifiers, or pseudonyms. A single pseudonym for each replaced field or collection of replaced fields makes the data record less identifiable while remaining suitable for data analysis and data processing.

Security breach notification laws or data breach notification laws are laws that require individuals or entities affected by a data breach, unauthorized access to data, to notify their customers and other parties about the breach, as well as take specific steps to remedy the situation based on state legislature. Data breach notification laws have two main goals. The first goal is to allow individuals a chance to mitigate risks against data breaches. The second goal is to promote company incentive to strengthen data security.Together, these goals work to minimize consumer harm from data breaches, including impersonation, fraud, and identity theft.

Data portability is a concept to protect users from having their data stored in "silos" or "walled gardens" that are incompatible with one another, i.e. closed platforms, thus subjecting them to vendor lock-in and making the creation of data backups or moving accounts between services difficult.

<span class="mw-page-title-main">General Data Protection Regulation</span> EU regulation on the processing of personal data

The General Data Protection Regulation is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and human rights law, in particular Article 8(1) of the Charter of Fundamental Rights of the European Union. It also governs the transfer of personal data outside the EU and EEA. The GDPR's goals are to enhance individuals' control and rights over their personal information and to simplify the regulations for international business. It supersedes the Data Protection Directive 95/46/EC and, among other things, simplifies the terminology.

The ePrivacy Regulation (ePR) is a proposal for the regulation of various privacy-related topics, mostly in relation to electronic communications within the European Union. Its full name is "Regulation of the European Parliament and of the Council concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC ." It would repeal the Privacy and Electronic Communications Directive 2002 and would be lex specialis to the General Data Protection Regulation. It would particularise and complement the latter in respect of privacy-related topics. Key fields of the proposed regulation are the confidentiality of communications, privacy controls through electronic consent and browsers, and cookies.

<span class="mw-page-title-main">NOYB</span> European data protection advocacy group

NOYB – European Center for Digital Rights is a non-profit organization based in Vienna, Austria established in 2017 with a pan-European focus. Co-founded by Austrian lawyer and privacy activist Max Schrems, NOYB aims to launch strategic court cases and media initiatives in support of the General Data Protection Regulation (GDPR), the proposed ePrivacy Regulation, and information privacy in general. The organisation was established after a funding period during which it has raised annual donations of €250,000 by supporting members. Currently, NOYB is financed by more than 4,400 supporting members.

The gathering of personally identifiable information (PII) is the practice of collecting public and private personal data that can be used to identify an individual for both legal and illegal applications. PII owners often view PII gathering as a threat and violation of their privacy. Meanwhile, entities such as information technology companies, governments, and organizations use PII for data analysis of consumer shopping behaviors, political preference, and personal interests.

A data protection officer (DPO) ensures, in an independent manner, that an organization applies the laws protecting individuals' personal data. The designation, position and tasks of a DPO within an organization are described in Articles 37, 38 and 39 of the European Union (EU) General Data Protection Regulation (GDPR). Many other countries require the appointment of a DPO, and it is becoming more prevalent in privacy legislation.

A data economy is a global digital ecosystem in which data is gathered, organized, and exchanged by a network of companies, individuals, and institutions to create economic value. The raw data is collected by a variety of actors, including search engines, social media websites, online vendors, brick and mortar vendors, payment gateways, software as a service (SaaS) purveyors, and an increasing number of firms deploying connected devices on the Internet of Things (IoT). Once collected, this data is typically passed on to individuals or firms, often for a fee. In the United States, the Consumer Financial Protection Bureau and other agencies have developed early models to regulate the data economy.

The right of access, also referred to as right to access and (data) subject access, is one of the most fundamental rights in data protection laws around the world. For instance, the United States, Singapore, Brazil, and countries in Europe have all developed laws that regulate access to personal data as privacy protection. The European Union states that: "The right of access occupies a central role in EU data protection law's arsenal of data subject empowerment measures." This right is often implemented as a Subject Access Request (SAR) or Data Subject Access Request (DSAR).

<span class="mw-page-title-main">Anu Bradford</span> Finnish-American legal scholar

Anu H. Bradford is a Finnish-American author, law professor, and expert in international trade law. In 2014, she was named the Henry L. Moses Distinguished Professor of Law and International Organization at the Columbia Law School. She is the author of The Brussels Effect: How the European Union Rules the World.

<span class="mw-page-title-main">General Personal Data Protection Law</span> Brazilian regulation on the processing of personal data

The General Personal Data Protection Law, is a statutory law on data protection and privacy in the Federative Republic of Brazil. The law's primary aim is to unify 40 different Brazilian laws that regulate the processing of personal data. The LGPD contains provisions and requirements related to the processing of personal data of individuals, where the data is of individuals located in Brazil, where the data is collected or processed in Brazil, or where the data is used to offer goods or services to individuals in Brazil.

References

  1. 1 2 3 4 5 Bradford, Anu (2012). "The Brussels Effect". Northwestern University Law Review (PDF). Columbia Law and Economics Working Paper No. 533. 107 (1). SSRN   2770634.
  2. Lecture, March 2012 – "The Brussels Effect: The Rise of a Regulatory Superstate in Europe"
  3. Bradford, Anu (2020). The Brussels Effect: How the European Union Rules the World. Oxford University Press. doi:10.1093/oso/9780190088583.001.0001. ISBN   978-0-19-008858-3.
  4. Vogel, David (1995). Trading Up: Consumer and Environmental regulation in a global economy . Harvard University Press. ISBN   9780674900837.
  5. Bach, David; Newman, Abraham (2007). "The European regulatory state and global public policy: micro-institutions, macro-influence". Journal of European Public Policy. doi:10.1080/13501760701497659.
  6. "The Brussels Effect: The Rise of a Regulatory Superstate in Europe". Columbia Law School. 8 January 2013. Archived from the original on 4 May 2018. Retrieved 17 May 2018.
  7. "Hot U.S. Import: European Regulations". The Wall Street Journal. 7 May 2018.
  8. "Why the 'Brussels effect' will undermine Brexit regulatory push". Financial Times. July 2017.
  9. "Why the whole world feels the 'Brussels effect'". Financial Times. November 2017.
  10. Bach, David (25 May 2018). "Three Questions: Prof. David Bach on the Reach of European Privacy Regulations". Yale Insights.
  11. Wright, Robert E. (8 June 2012). "How Delaware Became the King of U.S. Corporate Charters". Bloomberg View. Archived from the original on 16 March 2016. Retrieved 18 May 2018.
  12. Sinopoli, Dominique; Purnhagen, Kai (2016). "Reversed Harmonization or Horizontalization of EU standards?: Does WTO Law Facilitate or Contrain the Brussels Effect?". Wisconsin International Law Journal: 92–119.
  13. Sinopoli, Dominique; Purnhagen, Kai (2016). "Reversed Harmonization or Horizontalization of EU standards?: Does WTO Law Facilitate or Contrain the Brussels Effect?". Wisconsin International Law Journal: 92–119.
  14. Young, Alasdair R. "The European Union as a global regulator? Context and comparison." Journal of European Public Policy 22, no. 9 (2015): 1233-1252.
  15. Young, Alasdair R. "Europe as a global regulator? The limits of EU influence in international food safety standards." Journal of European Public Policy 21, no. 6 (2014): 904-922.
  16. European Commission – Case No COMP/M.2220 – General Electric/Honeywell
  17. "Dow and REACH – Protecting human health and the environment". dow.com.
  18. "Reach External FAQs". Archived from the original on 2018-05-25. Retrieved 2018-05-17.
  19. "European Commission – Reducing emissions from aviation".
  20. Bradford, Anu (2012). "The Brussels Effect". Rochester, NY.{{cite journal}}: Cite journal requires |journal= (help)
  21. Gady, Franz-Stefan (2014). "EU/U.S. Approaches to Data Privacy and the 'Brussels Effect': A Comparative Analysis". Georgetown Journal of International Affairs: 12–23. JSTOR   43773645.
  22. "Information wars: How Europe became the world's data police". Financial Times. May 2018.
  23. International Centre for Trade and Sustainable Development (May 2018). "Europe's Data Privacy Rules Set New Global Approach to Consumer Rights". Archived from the original on 2018-08-13. Retrieved 2018-08-13.
  24. "Europe's new data protection rules export privacy standards worldwide". Politico.EU. 31 January 2018.
  25. "Facebook's commitment to data protection and privacy in compliance with the GDPR". facebook.com.
  26. "Complying With New Privacy Laws and Offering New Privacy Protections to Everyone, No Matter Where You Live".
  27. "We're Updating the Sonos Privacy Statement". sonos.com. Archived from the original on 2019-09-04. Retrieved 2018-08-13.
  28. "Microsoft's commitment to GDPR, privacy and putting customers in control of their own data". blogs.microsoft.com.
  29. Nissen, A. (11 November 2019). "The European Union as a Manager of Global 'Business and Human Rights' Regulation: Country-by-Country Reporting Rules" (PDF). UCL Journal of Law & Jurisprudence. 8 (2): 708. doi:10.14324/111.2052-1871.120.
  30. "Long-awaited common charger for mobile devices will be a reality in 2024". European Parliament. 2022-04-10. Retrieved 2022-10-06.
  31. "EU Passes Law to Switch iPhone to USB-C by End of 2024". MacRumors. Retrieved 2022-10-06.
  32. Guarascio, Francesco (2022-10-04). "Apple forced to change charger in Europe as EU approves overhaul". Reuters. Retrieved 2022-10-06.