Data Protection & Privacy
DETAIL

Council of Europe Convention 108+ (Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as amended by Protocol CETS No. 223)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

Convention 108 is the Council of Europe's Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature on 28 January 1981 as the first legally binding international instrument in the data protection field. Convention 108+ is its modernized form, created by the amending Protocol CETS No. 223 adopted in May 2018 and opened for signature on 10 October 2018, which updates the principles for today's technologies and strengthens the treaty's follow-up mechanism.

The Council of Europe publishes the treaty and its Committee of Convention 108 (T-PD) oversees implementation. The Convention binds the states that ratify it, which must apply its principles in domestic law; it is open to non-member states, and parties include Argentina, Mauritius, Uruguay, and other countries outside Europe. Convention 108+ enters into force once 38 parties to Convention 108 have ratified the Protocol; as of 26 September 2026 the Treaty Office records 34 ratifications, and the modernized text is already applied by many parties and referenced by the EU in adequacy and transfer decisions.

Organizations implement Convention 108+ indirectly, through the national data protection laws of the parties, and directly when they use it as the reference for a global privacy program. Practical implementation means lawful and proportionate processing, transparency, data minimization, protection of the expanded special categories, breach notification to the supervisory authority, privacy by design, rights for individuals including in automated decision-making, and safeguards for transborder data flows, typically run alongside GDPR and ISO/IEC 27701 controls.

Why it Matters

Convention 108+ is the one data protection instrument with global reach that states on several continents have signed, which makes it the common denominator for privacy programs that must work across many jurisdictions.

Key benefits include:

  • Anchor a global privacy baseline

Its principles underpin national laws from Europe to Latin America and Africa, so aligning with them reduces divergence across markets.

  • Support international data transfers

Parties may treat each other as providing an appropriate level of protection, and the EU references the Convention when assessing third countries.

  • Strengthen individual trust

Transparency, access, objection, and rights in algorithmic decision-making show individuals that processing is accountable.

  • Prepare for stricter enforcement

Independent supervisory authorities with reinforced powers and cooperation duties raise the cost of non-compliance.

  • Align with GDPR without duplicating work

The modernized principles mirror GDPR concepts, so one control set can evidence both.

How it Works

Convention 108+ is a treaty of principles rather than a control catalog. It sets out the purpose and scope of protection, duties of the parties, the basic principles for data processing (legitimacy, proportionality, data minimization, transparency, accuracy, storage limitation), rules for special categories of data now including genetic and biometric data, data security and breach notification, the rights of data subjects, additional obligations such as privacy by design and impact assessment, exceptions and restrictions subject to conditions, sanctions and remedies, transborder flows of personal data, supervisory authorities, and international cooperation through a convention committee.

States implement it by enacting or amending domestic data protection law, establishing an independent supervisory authority, and reporting to the Committee of Convention 108. Organizations implement it by keeping a record of processing, establishing a lawful basis and purpose for each activity, applying data minimization and retention limits, protecting sensitive data, notifying breaches, handling data subject requests, running impact assessments for high-risk processing, and documenting the safeguards that support transfers to non-parties.

Within SmartSuite, privacy teams can operationalize Convention 108+ by mapping its articles to their control library, maintaining the processing inventory and impact assessments, tracking data subject requests and breach notifications with deadlines, recording transfer safeguards for each recipient country, and reporting compliance status across jurisdictions to leadership and supervisory authorities.

Key Elements

  • Basic principles for data processing

Processing must be lawful, fair, transparent, proportionate, for legitimate purposes, accurate, and time-limited.

  • Special categories of data

Genetic data, biometric data uniquely identifying a person, and data on ethnic origin, trade union membership, and other sensitive matters require additional safeguards.

  • Security and breach notification

Controllers and processors must take appropriate security measures and notify the supervisory authority of breaches that may seriously interfere with rights and freedoms.

  • Rights of the data subject

Individuals have rights to information, access, rectification, erasure, objection, remedies, and not to be subject to purely automated decisions without their views being considered.

  • Additional obligations

Accountability, privacy by design, data protection impact assessment, and demonstrable compliance are required of controllers.

  • Transborder data flows

Data may flow freely between parties; transfers to non-parties need an appropriate level of protection assured by law or ad hoc safeguards.

  • Supervisory authorities and Convention Committee

Each party designates independent authorities with investigative and corrective powers, and the Committee of Convention 108 evaluates implementation and cooperation.

Framework Scope

Convention 108+ applies to all data processing in the public and private sectors within the jurisdiction of each party, including processing for national security purposes subject to conditions, with exceptions only where necessary and proportionate in a democratic society. It binds the states that ratify it and, through their laws, every controller and processor operating there; multinational organizations also adopt it as a reference for privacy programs that span European and non-European markets.

Framework Objectives

Convention 108+ aims to protect every individual's right to privacy and data protection while enabling lawful international flows of personal data.

Guarantee human dignity and data protection rights in every processing activity

Modernize the 1981 principles for new technologies and algorithmic decision-making

Establish independent, empowered supervisory authorities in every party

Create a clear regime for transborder data flows between parties and to third countries

Strengthen accountability through privacy by design, impact assessment, and breach notification

Provide a bridge between the data protection frameworks of different regions

Framework in Context

Convention 108+ sits alongside GDPR and UK GDPR, whose principles it mirrors, and the OECD Privacy Guidelines and APEC Privacy Framework, which it complements as the only binding treaty. National laws such as the Swiss FADP and the data protection laws of Argentina and Uruguay implement it, and ISO/IEC 27701 and the NIST Privacy Framework provide management-system and control structures for evidencing it.

Common Framework Mappings

Organizations map Convention 108+ to the regional regulations and privacy management standards they already operate so that one privacy program can evidence the treaty's principles in every party where they process data.

Mapped frameworks include:

GDPR

UK GDPR

OECD Privacy Guidelines

APEC PF

APEC CBPR System

Swiss FADP (SR 235.1)

Argentina PDPL (Law 25.326)

Uruguay PDP Law 18.331

KVKK (Law No. 6698)

ISO 27701

ISO 29100

NIST Privacy Framework v1.0

EU Law Enforcement Directive (2016/680)

At a Glance
Council of Europe Convention 108+ (Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as amended by Protocol CETS No. 223)
  • Classification
    Category
    Data Protection & Privacy
    Domain
    Privacy
    Framework Family
    Global Privacy Regulations
  • Regulatory Context
    Type
    Regulation
    Legal Instrument
    Treaty
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Europe
    Region Detail
    Council of Europe (open to non-member states)
    Publisher
    Council of Europe (CoE)
  • Versioning
    Version
    Convention 108 (ETS No. 108) as amended by Protocol CETS No. 223 (Convention 108+)
    Effective Date
    Convention 108 in force since 1 October 1985; Protocol CETS No. 223 pending (34 of 38 ratifications at 26 September 2026)
    Issue Date
    1981 (Convention 108); 2018 (Protocol CETS No. 223)
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

The treaty text, protocol, and explanatory report are published free of charge by the Council of Europe Treaty Office; SmartSuite does not include the text within the platform.

Framework text is licensed by its publisher and is included only where stated above.

SMARTSUITE

How SmartSuite Supports Convention 108+

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

Manage Convention 108+ obligations by mapping its articles to controls, keeping the processing inventory and impact assessments current, and tracking breach notifications, data subject requests, and transfer safeguards by country.

Convention 108+ Principles Library

Hold each article's obligations as controls linked to the national laws that implement them in every party where you operate.

Ownership, Cadence, and Accountability

Assign owners for processing activities and supervisory authority relationships, with scheduled reviews and re-assessments.

Processing Records and Evidence

Maintain the record of processing, lawful bases, retention limits, and impact assessments with a full audit trail.

Rights Requests and Breach Notification

Track access, rectification, objection, and automated-decision requests and breach notifications against statutory deadlines.

Transborder Flow Safeguards

Record recipient countries, party status, and the safeguards or adequacy basis that supports each transfer.

Multi-Jurisdiction Privacy Reporting

Report compliance status, open requests, incidents, and transfer inventories across parties to leadership and regulators.

Related frameworks

GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

UK GDPR

UK GDPR is the United Kingdom regulation governing processing, protection, and privacy rights of personal data.

OECD Privacy Guidelines

OECD Privacy Guidelines provide international principles for protecting personal data and enabling safe cross-border data flows.

APEC PF

APEC Privacy Framework helps organizations manage cross-border privacy risks and facilitate data flows among Asia-Pacific economies.

Swiss FADP (SR 235.1)

Switzerland's cybersecurity and data protection requirements set rules to protect personal data and ensure information security compliance.

ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

APEC CBPR System

The APEC CBPR System is a voluntary, enforceable privacy certification that lets organizations transfer personal data across participating economies, now run by the Global CBPR Forum.

ONBOARDING FAQS

Frequently Asked Questions For Convention 108+

No items found.

Operationalize Convention 108+ with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.