Council of Europe Convention 108+ (Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as amended by Protocol CETS No. 223)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
Convention 108 is the Council of Europe's Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature on 28 January 1981 as the first legally binding international instrument in the data protection field. Convention 108+ is its modernized form, created by the amending Protocol CETS No. 223 adopted in May 2018 and opened for signature on 10 October 2018, which updates the principles for today's technologies and strengthens the treaty's follow-up mechanism.
The Council of Europe publishes the treaty and its Committee of Convention 108 (T-PD) oversees implementation. The Convention binds the states that ratify it, which must apply its principles in domestic law; it is open to non-member states, and parties include Argentina, Mauritius, Uruguay, and other countries outside Europe. Convention 108+ enters into force once 38 parties to Convention 108 have ratified the Protocol; as of 26 September 2026 the Treaty Office records 34 ratifications, and the modernized text is already applied by many parties and referenced by the EU in adequacy and transfer decisions.
Organizations implement Convention 108+ indirectly, through the national data protection laws of the parties, and directly when they use it as the reference for a global privacy program. Practical implementation means lawful and proportionate processing, transparency, data minimization, protection of the expanded special categories, breach notification to the supervisory authority, privacy by design, rights for individuals including in automated decision-making, and safeguards for transborder data flows, typically run alongside GDPR and ISO/IEC 27701 controls.
Why it Matters
Convention 108+ is the one data protection instrument with global reach that states on several continents have signed, which makes it the common denominator for privacy programs that must work across many jurisdictions.
Key benefits include:
- Anchor a global privacy baseline
Its principles underpin national laws from Europe to Latin America and Africa, so aligning with them reduces divergence across markets.
- Support international data transfers
Parties may treat each other as providing an appropriate level of protection, and the EU references the Convention when assessing third countries.
- Strengthen individual trust
Transparency, access, objection, and rights in algorithmic decision-making show individuals that processing is accountable.
- Prepare for stricter enforcement
Independent supervisory authorities with reinforced powers and cooperation duties raise the cost of non-compliance.
- Align with GDPR without duplicating work
The modernized principles mirror GDPR concepts, so one control set can evidence both.
How it Works
Convention 108+ is a treaty of principles rather than a control catalog. It sets out the purpose and scope of protection, duties of the parties, the basic principles for data processing (legitimacy, proportionality, data minimization, transparency, accuracy, storage limitation), rules for special categories of data now including genetic and biometric data, data security and breach notification, the rights of data subjects, additional obligations such as privacy by design and impact assessment, exceptions and restrictions subject to conditions, sanctions and remedies, transborder flows of personal data, supervisory authorities, and international cooperation through a convention committee.
States implement it by enacting or amending domestic data protection law, establishing an independent supervisory authority, and reporting to the Committee of Convention 108. Organizations implement it by keeping a record of processing, establishing a lawful basis and purpose for each activity, applying data minimization and retention limits, protecting sensitive data, notifying breaches, handling data subject requests, running impact assessments for high-risk processing, and documenting the safeguards that support transfers to non-parties.
Within SmartSuite, privacy teams can operationalize Convention 108+ by mapping its articles to their control library, maintaining the processing inventory and impact assessments, tracking data subject requests and breach notifications with deadlines, recording transfer safeguards for each recipient country, and reporting compliance status across jurisdictions to leadership and supervisory authorities.
Key Elements
- Basic principles for data processing
Processing must be lawful, fair, transparent, proportionate, for legitimate purposes, accurate, and time-limited.
- Special categories of data
Genetic data, biometric data uniquely identifying a person, and data on ethnic origin, trade union membership, and other sensitive matters require additional safeguards.
- Security and breach notification
Controllers and processors must take appropriate security measures and notify the supervisory authority of breaches that may seriously interfere with rights and freedoms.
- Rights of the data subject
Individuals have rights to information, access, rectification, erasure, objection, remedies, and not to be subject to purely automated decisions without their views being considered.
- Additional obligations
Accountability, privacy by design, data protection impact assessment, and demonstrable compliance are required of controllers.
- Transborder data flows
Data may flow freely between parties; transfers to non-parties need an appropriate level of protection assured by law or ad hoc safeguards.
- Supervisory authorities and Convention Committee
Each party designates independent authorities with investigative and corrective powers, and the Committee of Convention 108 evaluates implementation and cooperation.
Framework Scope
Convention 108+ applies to all data processing in the public and private sectors within the jurisdiction of each party, including processing for national security purposes subject to conditions, with exceptions only where necessary and proportionate in a democratic society. It binds the states that ratify it and, through their laws, every controller and processor operating there; multinational organizations also adopt it as a reference for privacy programs that span European and non-European markets.
Framework Objectives
Convention 108+ aims to protect every individual's right to privacy and data protection while enabling lawful international flows of personal data.
Guarantee human dignity and data protection rights in every processing activity
Modernize the 1981 principles for new technologies and algorithmic decision-making
Establish independent, empowered supervisory authorities in every party
Create a clear regime for transborder data flows between parties and to third countries
Strengthen accountability through privacy by design, impact assessment, and breach notification
Provide a bridge between the data protection frameworks of different regions
Framework in Context
Convention 108+ sits alongside GDPR and UK GDPR, whose principles it mirrors, and the OECD Privacy Guidelines and APEC Privacy Framework, which it complements as the only binding treaty. National laws such as the Swiss FADP and the data protection laws of Argentina and Uruguay implement it, and ISO/IEC 27701 and the NIST Privacy Framework provide management-system and control structures for evidencing it.
Common Framework Mappings
Organizations map Convention 108+ to the regional regulations and privacy management standards they already operate so that one privacy program can evidence the treaty's principles in every party where they process data.
Mapped frameworks include:
GDPR
UK GDPR
OECD Privacy Guidelines
APEC PF
APEC CBPR System
Swiss FADP (SR 235.1)
Argentina PDPL (Law 25.326)
Uruguay PDP Law 18.331
KVKK (Law No. 6698)
ISO 27701
ISO 29100
NIST Privacy Framework v1.0
EU Law Enforcement Directive (2016/680)
- ClassificationCategoryData Protection & PrivacyDomainPrivacyFramework FamilyGlobal Privacy Regulations
- Regulatory ContextTypeRegulationLegal InstrumentTreatySectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionEuropeRegion DetailCouncil of Europe (open to non-member states)PublisherCouncil of Europe (CoE)
- VersioningVersionConvention 108 (ETS No. 108) as amended by Protocol CETS No. 223 (Convention 108+)Effective DateConvention 108 in force since 1 October 1985; Protocol CETS No. 223 pending (34 of 38 ratifications at 26 September 2026)Issue Date1981 (Convention 108); 2018 (Protocol CETS No. 223)
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The treaty text, protocol, and explanatory report are published free of charge by the Council of Europe Treaty Office; SmartSuite does not include the text within the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports Convention 108+
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Manage Convention 108+ obligations by mapping its articles to controls, keeping the processing inventory and impact assessments current, and tracking breach notifications, data subject requests, and transfer safeguards by country.
Convention 108+ Principles Library
Hold each article's obligations as controls linked to the national laws that implement them in every party where you operate.
Ownership, Cadence, and Accountability
Assign owners for processing activities and supervisory authority relationships, with scheduled reviews and re-assessments.
Processing Records and Evidence
Maintain the record of processing, lawful bases, retention limits, and impact assessments with a full audit trail.
Rights Requests and Breach Notification
Track access, rectification, objection, and automated-decision requests and breach notifications against statutory deadlines.
Transborder Flow Safeguards
Record recipient countries, party status, and the safeguards or adequacy basis that supports each transfer.
Multi-Jurisdiction Privacy Reporting
Report compliance status, open requests, incidents, and transfer inventories across parties to leadership and regulators.
Related frameworks

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

UK GDPR is the United Kingdom regulation governing processing, protection, and privacy rights of personal data.

OECD Privacy Guidelines provide international principles for protecting personal data and enabling safe cross-border data flows.

APEC Privacy Framework helps organizations manage cross-border privacy risks and facilitate data flows among Asia-Pacific economies.

Switzerland's cybersecurity and data protection requirements set rules to protect personal data and ensure information security compliance.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.
Frequently Asked Questions For Convention 108+
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

