Book Title: Data Protection and Interoperability in EU External Relations: Guaranteeing Global Data Transfers in the Area of Freedom, Security and Justice
Author: Francesca Tassinari
Publisher: Brill | Nijhoff
Publication Year: 2025
Against the backdrop of rapid developments in information technology, the globalization of the digital environment, and the ever-expanding processing and exchange of personal data, cross-border interoperability among the European Union’s information systems has emerged as a major challenge at the intersection of technology, security, and fundamental rights. At the heart of the discussion is the question of whether such interoperability is compatible with the European Union’s standards and requirements governing the protection and transfer of personal data. These requirements are rooted in the principles and values enshrined in the EU’s founding Treaties and shape both its internal data protection regime and the manner in which the Union conducts its external relations. Within this framework, particular attention is devoted to the interoperability regulations adopted in 2019 and to the effort to establish connections among six large-scale IT systems operating within the Area of Freedom, Security and Justice: the Schengen Information System (SIS), the Visa Information System (VIS), the Entry/Exit System (EES), the European Travel Information and Authorisation System (ETIAS), the European Asylum Dactyloscopy Database (Eurodac), and the European Criminal Records Information System for Third-Country Nationals (ECRIS-TCN). Examining this architecture sheds light on how the European Union seeks to strike a balance between the imperatives of border management, freedom of movement, and the prevention and combating of crime and terrorism, on the one hand, and the protection of individuals’ fundamental rights—particularly the rights to privacy and to the protection of personal data—on the other.
In this context, Data Protection and Interoperability in EU External Relations: Guaranteeing Global Data Transfers in the Area of Freedom, Security and Justice, in addition to addressing the foregoing issues, examines the legal boundaries and limitations governing the processing of personal data within these systems and their external implications, particularly with regard to the transfer and sharing of data with third countries, international organizations, and bodies such as Interpol. The use of diagrams, tables, and explanatory figures further contributes to clarifying the complex architecture of the interoperability framework and the legal requirements governing it.
Structure and Chapters Content
- Introduction: The External Reach of Interoperability in the European Union’s Area of Freedom, Security and Justice
The Introduction sets out the theoretical and legal framework of the study and situates the book’s central question within the context of the continuing expansion of the European Union’s large-scale IT systems. Against the background of the adoption of Regulations (EU) 2019/817 and (EU) 2019/818 and the establishment of a mechanism for interoperability among information systems in the fields of borders, visas, migration, asylum, and police and judicial cooperation, the author turns her attention to the cross-border dimension of this development—that is, to circumstances in which personal data stored, processed, or accessible through these systems may become involved in interactions with third countries and international organizations. The central question addressed in the Introduction is the extent to which the external reach of interoperability is compatible with EU legal requirements concerning privacy, personal data protection, and cross-border data transfers. To address this question, the author explains the legal framework of the study, its principal research questions, the existing state of scholarship, and its methodology. Interoperability is therefore treated not merely as a technical matter, but as a legal issue connected with the limits of the European Union’s external competence, the protection of fundamental rights, and the Union’s obligation to uphold its values and principles in its external relations. The Introduction concludes by outlining the overall structure of the book and laying the groundwork for examining the relationship between the EU data protection regime, large-scale IT systems, and the external dimensions of the Area of Freedom, Security and Justice.
- Chapter One: The Elaboration of Data Protection Standards in International Privacy Law: A European Human-Centric Approach to Digital Technology
Chapter One examines the development of personal data protection standards within international privacy law. At the outset, the author explains that, before information and communication technologies acquired the capacity to interfere seriously with individual privacy, the international discussion surrounding the protection of personal data remained relatively limited. The Snowden revelations dramatically intensified global attention to the effects of digital surveillance on privacy and personal data protection, while also bringing divergent approaches to the challenges posed by emerging technologies into sharper focus. In 1981, the Council of Europe adopted Convention 108, thereby establishing the first legally binding international instrument devoted to the protection of individuals with regard to the automatic processing of personal data. Following the adoption of the Convention, Article 8 of the European Convention on Human Rights was also reinterpreted in light of the contemporary digital environment, giving rise to new safeguards for the protection of privacy. Continued technological developments, however, led during the 1990s to the emergence of new parameters intended to reinforce the protections established under Convention 108 and contributed to closer cooperation between the European Union and the Council of Europe in the field of data protection.
Alongside the legally binding approaches pursued by the Council of Europe and the European Union, other actors turned to soft-law approaches in responding to the challenges posed by new technologies. One such approach is “privacy interoperability,” which emphasizes the possibility of self-regulation and compatibility among differing interests in the field of data governance. The author also notes that certain countries, including the United States and its allies within the Five Eyes alliance, have pursued approaches based on self-regulation while placing particular emphasis on the economic value of personal data processing. Ultimately, the chapter demonstrates that divergent governmental views on human rights and data protection have slowed the development of common global standards, and it is within this context that interoperability is examined as one of the proposed responses to the challenges facing privacy in the information age.
- Chapter Two: The European Union as a Normative Power in the Field of Personal Data Protection: A New Reading of the European Union’s Regime on Personal Data Transfer
Chapter Two examines the emergence and expansion of the European Union’s role in developing data protection rules. The author explains that, by distinguishing the regulation of personal data from the fundamental right to privacy and through the adoption of the Data Protection Directive in the 1990s, the European Union paved the way for recognition of a new fundamental right. The Treaty of Lisbon, signed in 2007 and entering into force in 2009, provided a more explicit basis for EU competence in the field of personal data protection and the free movement of such data, while Article 16(2) of the Treaty on the Functioning of the European Union (TFEU) became a legal foundation for the further development of the Union’s legal regime in this field. This regime, comprising the General Data Protection Regulation (GDPR), the Law Enforcement Directive (LED), and the European Union Data Protection Regulation (EUDPR), extends across virtually all areas of EU policy and establishes a body of binding rules governing the processing of personal data by the Member States as well as by EU institutions and bodies.
The author then turns to the European Union’s external role, explaining that Article 16(2) TFEU enables the Union to pursue its normative activity in the field of data protection as a global actor. Under the doctrine of implied external powers, the European Union may conclude international agreements concerning data protection with third countries and international organizations. The chapter also traces the gradual expansion of EU competence in the field of personal data protection, beginning with the Union institutions’ concerns over the regulation of data exchange and protection in the 1970s and continuing through the development of comprehensive legal frameworks and pioneering rules on international data transfers. The author emphasizes that the European Union’s normative role is not grounded solely in the domestic constitutional traditions of its Member States, but is also rooted in principles of international human rights law, particularly Council of Europe Convention 108.
- Chapter Three: The European Union’s Clause on Privacy and Personal Data Protection: Conditioning Personal Data Transfers to the European Union’s Fundamental Rights System
Chapter Three examines the role of privacy and data protection clauses in the European Union’s external agreements and arrangements. The author begins by referring to the common values of the European Union set out in Article 2 of the Treaty on European Union (TEU), which include respect for human dignity, freedom, democracy, equality, the rule of law, and human rights, including the rights of persons belonging to minorities. Under Article 21 TEU, the European Union is required to respect, safeguard, and promote these values and its interests in its external action. Within this framework, the Union makes use of its treaty-based instruments to ensure that strategic agreements and external arrangements remain consistent with its fundamental principles. The author explains that, even before the adoption of Article 16(2) TFEU, the European Union had sought, through the development of privacy and data protection clauses, to align flows of personal data to and from the Member States with international legal principles, particularly those deriving from Council of Europe law.
Beginning in 1997, the Article 29 Data Protection Working Party emphasized that the Union’s data protection message should be extended through “general agreements” with third countries by incorporating clauses relating to privacy and personal data protection. Such clauses have been included, directly or indirectly, in instruments concluded under Article 218 TFEU, particularly in the context of EU enlargement and the European Neighbourhood Policy. The chapter further shows that the European Union expects such clauses to be incorporated into other agreements and arrangements concluded on the basis of sector-specific competences for the achievement of particular objectives. Finally, the author examines the European Union’s policy of “digital conditionality,” based on privacy and personal data protection clauses in both general and sectoral agreements, and considers the role of agreements relating to the Area of Freedom, Security and Justice as well as trade agreements in this regard.
- Chapter Four: The Processing of Personal Data within the European Union’s Large-Scale IT Systems: Balancing Data Protection Rights with Freedom, Security and Justice Objectives
Chapter Four examines the processing of personal data within the European Union’s large-scale IT systems and the manner in which a balance is sought between data protection rights and the objectives of the Area of Freedom, Security and Justice. The author explains that these systems facilitate the exchange of information, including personal data, among the Member States and play an important role in the implementation of EU policies concerning freedom, security, and justice. Since the EU founding Treaties did not expressly provide a specific competence concerning shared computerized systems containing personal data, these systems were established on particular legal bases and in response to needs arising from competences conferred upon the European Union. In areas such as borders, migration, and asylum, the legal architecture was particularly complex: while the Treaties conferred legislative powers on the Union, operational cooperation between the Member States and the European Union was governed by separate legal instruments.
The chapter explains that, notwithstanding the conferral of competence upon the European Union to establish rules governing the processing of personal data in the fields of police and judicial cooperation, each of the large-scale IT systems incorporates important safeguards for data subjects. Since the 1990s, these systems have undergone several rounds of reform. These changes have resulted, first, from rapid technological developments, which have expanded the functions of the systems beyond the simple transmission of information and have prompted discussion of automated processing and AI-based capabilities within certain components and processes; and second, from political decisions adopted within the Area of Freedom, Security and Justice. The author also discusses the Schengen Information System (SIS) as one of the earliest large-scale systems, operational since 1995 and regarded as a forerunner of subsequent EU information systems. By connecting national databases with a central component, SIS enables the exchange of actionable alerts among Member States. The chapter ultimately examines the rules governing the six large-scale IT systems, their evolution, and the expansion of their operational scope within the Area of Freedom, Security and Justice.
- Chapter Five: The Interoperability between Large-Scale IT Systems in the Area of Freedom, Security and Justice: Context, Content, and Purposes of Regulations (EU) 817 and 818 of 2019
Chapter Five examines the context, content, and objectives of Regulations (EU) 2019/817 and (EU) 2019/818. These two Regulations establish a framework for achieving interoperability among six large-scale EU information systems that are either already operational or are intended to become operational within the Area of Freedom, Security and Justice. Their purpose is to connect these six systems through a new infrastructure designed to support their functioning. The author explains that interoperability refers to the capacity of systems to communicate with one another, exchange data, and make use of available information. This concept can be considered at several levels, including technical, syntactic, semantic, and organizational interoperability. Technical interoperability concerns communication between devices; syntactic interoperability concerns the ability of different systems to communicate and exchange data; semantic interoperability concerns the ability to interpret and make effective use of data; and organizational interoperability concerns the interconnection of administrative procedures and institutions.
The chapter also addresses criticisms directed at the interoperability regulations, including concerns that their technical complexity and the addition of further layers to EU regulation may make their scope difficult to understand and may raise questions regarding their impact on fundamental rights, privacy, and data protection principles. At the same time, the author notes that some scholars question the accuracy of these criticisms and instead emphasize the cautious approach taken by EU legislators in designing and implementing the data protection framework. Finally, by tracing the historical development of interoperability, the chapter presents it as part of the European Union’s broader project of reforming the Area of Freedom, Security and Justice—a project that includes the expansion of the powers of EU institutions and the establishment of a new generation of large-scale IT systems.
- Chapter Six: Global Interoperability in the European Union’s Area of Freedom, Security and Justice: Sharing Personal Data Stored in, Processed, or Accessed by the Interoperability Components
Chapter Six examines the transfer and sharing of personal data stored in, processed by, or accessible through the interoperability components. The author explains that, since the concept of interoperability entered discussions concerning the Area of Freedom, Security and Justice, a central question has been whether the European Union’s large-scale IT systems may extend beyond the Union’s borders. Earlier approaches assumed that such forms of cooperation should occur only in exceptional circumstances and on the basis of reciprocity, and that transfers of data between police authorities should take place on an ad hoc basis in accordance with agreements on criminal cooperation and applicable data protection rules. More recent developments in information technology, however, have demonstrated that global forms of interoperability may provide an effective means of facilitating information exchange between different legal systems.
The author emphasizes that the central issue in establishing interoperable systems lies in determining the appropriate degree of interoperability and identifying the areas in which systems should interact with one another or, alternatively, remain separate. The chapter then turns to Article 50 of Regulations (EU) 2019/817 and (EU) 2019/818, concerning the communication of personal data to third countries, international organizations, and private parties. Under these Regulations, such personal data must not, in principle, be transferred or made available to third countries, international organizations, or private parties, except in the circumstances provided for within the applicable legal framework. The author explains that the transfer of personal data itself constitutes a form of data processing and, because it may affect individuals’ fundamental rights, must comply with the limitations laid down in the Charter of Fundamental Rights of the European Union (CFR). Finally, the chapter examines the scope of the legal regime governing transfers of personal data to third countries and international organizations and assesses its compatibility with the rules and principles that the European Union is required to observe in its external action.
Conclusion
In light of the discussions developed throughout the book, global interoperability within the European Union’s Area of Freedom, Security and Justice must remain consistent with the principles and rules that bind the Union in the conduct of its external action. Transfers of personal data in the absence of standardized mechanisms and adequate safeguards may undermine individual rights, particularly the rights to privacy and to the protection of personal data. The author emphasizes that any form of EU external cooperation involving data must be grounded in values such as human dignity, democracy, the rule of law, and fundamental rights. The implementation of interoperability solutions at the global level must likewise be accompanied by an assessment of their impact on individual rights.
The book demonstrates that, with the development of technology, the protection of personal data has increasingly been strengthened as a right distinct from the traditional concept of privacy. Drawing upon human rights instruments and legal frameworks such as Council of Europe Convention 108, the General Data Protection Regulation (GDPR), the Law Enforcement Directive (LED), and the European Union Data Protection Regulation (EUDPR), the European Union has developed a comprehensive system of data protection. Ultimately, the book emphasizes the need to strike a balance between security requirements and international cooperation, on the one hand, and the effective protection of individuals’ fundamental rights, on the other.
Note
Tassinari, F. (2025). Data protection and interoperability in EU external relations: Guaranteeing global data transfers in the area of freedom, security and justice. Brill | Nijhoff.






