Skip to main content
Category: Legal Framework & Instruments

Convention 108

Also known as: Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data, Council of Europe Convention No. 108, Convention 108+ (modernised version)
Simply put

Convention 108 is a 1981 Council of Europe treaty that protects individuals' privacy in relation to the automatic processing of their personal data, including where such data flows across national borders. It sets out core principles and rules for handling personal data and establishes certain rights for individuals. The treaty was later updated by a modernised version, commonly referred to as Convention 108+, to address newer data protection challenges.

Formal definition

Convention 108 is a Council of Europe treaty, adopted in 1981, described in the evidence as the only legally binding international instrument dedicated to the protection of personal data. It lays down principles and rules governing the automatic processing of personal data, articulates safeguards for the right to protection of personal data, and confers certain rights on individuals (data subjects), with particular attention to transborder data flows. It was subsequently modernised (Convention 108+) to meet new challenges; the evidence does not specify the modernised instrument's operative provisions or entry-into-force details, which should be verified against the current official Council of Europe text. Convention 108 is distinct from the EU GDPR: it originates from the Council of Europe rather than the European Union, and its relationship to GDPR adequacy assessments is a matter addressed in commentary rather than settled by this evidence and should be independently confirmed.

Why it matters

Convention 108 is described in the evidence as the only legally binding international treaty dedicated to the protection of personal data. This distinguishes it from many other privacy frameworks that operate as guidance, principles, or non-binding standards. For organisations and advisors mapping the international data protection landscape, it represents a rare instance of cross-border legal commitment on personal data handling, adopted by the Council of Europe rather than the European Union.

Its significance lies partly in its attention to transborder data flows, a concern present since its adoption in 1981 and one that remains central to modern privacy practice. Because the Convention operates independently of the EU GDPR, understanding its origin and scope helps practitioners avoid conflating Council of Europe instruments with EU law. The two frameworks emerge from different institutions and serve overlapping but distinct functions.

The relationship between Convention 108 and GDPR adequacy assessments is discussed in commentary but is not settled by the evidence available here. Practitioners should treat any claim that ratification of Convention 108 or Convention 108+ automatically supports a favourable adequacy position as a matter to be independently verified against current Council of Europe and European Commission sources, rather than a fixed rule.

Who it's relevant to

Data protection officers and compliance leads
DPOs assessing an organisation's exposure across multiple jurisdictions may need to understand Convention 108 as a binding international baseline distinct from the EU GDPR. It is particularly relevant when mapping obligations in states that are Council of Europe members but not EU member states.
Privacy lawyers and policy advisors
Lawyers advising on cross-border data protection should distinguish Convention 108 as a Council of Europe treaty from EU instruments, and treat questions about its interaction with GDPR adequacy as matters requiring independent confirmation against current official sources rather than settled law.
Organisations engaged in transborder data flows
Because the Convention gives particular attention to data crossing national borders, organisations transferring personal data internationally may encounter it as part of the broader legal context, though the specific mechanisms and their current status should be verified against the applicable official texts.
Policymakers and regulators outside the EU
For authorities in Council of Europe states, Convention 108 and its modernised version can serve as a reference framework for national data protection arrangements, though the practical effect depends on national implementation and any applicable derogations.

Inside Convention 108

Council of Europe instrument
Convention 108 is a treaty adopted under the auspices of the Council of Europe, not an instrument of the European Union. It is distinct from the GDPR, though both address the protection of personal data. Readers should verify the current status and text against official Council of Europe sources.
Automatic processing of personal data
The Convention concerns the protection of individuals with regard to the automatic processing of their personal data. Its core aim is to secure respect for rights and fundamental freedoms, in particular the right to privacy, in relation to such processing.
Core data protection principles
It sets out foundational principles for the fair and lawful handling of personal data, such as data quality and purpose limitation, which have influenced later frameworks. The precise formulation should be checked against the operative text, as it has been subject to modernisation.
Modernised version (often referred to as Convention 108+)
A modernising protocol has updated the original Convention to reflect newer data protection developments. The status of ratification and entry into force varies by signatory, so practitioners should verify which version applies to a given state and whether it is in force there.
International, non-EU-specific reach
As a Council of Europe treaty, it is open to signature beyond EU member states, giving it a broader potential geographic reach than the GDPR. The binding effect in any particular country depends on that country's signature and ratification.

Common questions

Answers to the questions practitioners most commonly ask about Convention 108.

Is Convention 108 the same thing as the GDPR?
No. Convention 108 is a Council of Europe treaty on data protection, not an EU Regulation. It is a distinct legal instrument from the GDPR, with a different origin, membership, and enforcement structure. While both address the protection of personal data and share underlying principles, ratifying or being bound by Convention 108 does not equate to GDPR compliance, and vice versa. Organizations should assess each instrument separately against their circumstances.
Does Convention 108 only apply to European Union countries?
No. Convention 108 is a Council of Europe treaty, and the Council of Europe has a broader membership than the EU. The treaty is also open to accession by states beyond that membership, so its reach is not limited to EU member states. The precise list of parties changes over time as states ratify or accede, so readers should verify the current status against the official Council of Europe records rather than assume a fixed set of participating countries.
How does Convention 108 relate to an organization's GDPR compliance program?
Convention 108 and the GDPR are separate instruments that can apply in parallel depending on where an organization and the relevant individuals are located. Convention 108 does not displace GDPR obligations. In practice, organizations typically treat GDPR compliance as their primary EU framework and consider Convention 108 obligations where they operate in or transfer data to states bound by the treaty. Each instrument should be mapped separately, and a compliance assessment should identify which obligations arise from which source.
What should we check before relying on Convention 108 status in a cross-border data transfer analysis?
You should verify the current status of the relevant state as a party to the treaty, including which version or protocol it is bound by, and confirm whether that status has independent legal effect for your transfer scenario. A state being a party to Convention 108 is not, by itself, equivalent to an EU adequacy decision. Transfer mechanisms, adequacy determinations, and supplementary measures evolve, so this should be checked against current official sources and assessed on the specific facts rather than treated as a settled shortcut.
Which internal stakeholders should be involved when assessing Convention 108 obligations?
Assessment typically involves legal or privacy counsel to interpret the treaty and any national implementing law, the data protection officer or privacy lead to map obligations against existing controls, and relevant business or engineering owners where processing operations and data flows are affected. Because national implementing measures can vary, involving local or jurisdiction-specific advisers is often appropriate where the organization operates across multiple states bound by the treaty.
How should Convention 108 be documented within a compliance program?
Where relevant, it is generally advisable to record which of your operations engage Convention 108, the specific obligations you have identified, and the source of those obligations, keeping this distinct from GDPR-derived records. Because the treaty's application can depend on national implementing law and the evolving status of parties, documentation should note where positions are subject to verification against current official text and where regulator or guidance divergence may affect interpretation.

Common misconceptions

Convention 108 is an EU law or part of the GDPR framework.
It is a Council of Europe treaty, which is a separate international organisation from the European Union. While it and the GDPR share data protection aims and have influenced one another, they are distinct instruments with different legal bases and mechanisms.
Compliance with the GDPR automatically satisfies Convention 108, or vice versa.
The two instruments are not interchangeable. Obligations differ, and the applicable version of the Convention (original or modernised) and its in-force status vary by state. Each framework should be assessed on its own terms for the relevant jurisdiction.
Convention 108 applies uniformly across all its signatories in the same form.
Application depends on whether a state has signed and ratified the Convention and, where relevant, the modernising protocol. Entry into force and national implementation can diverge, so the position must be checked country by country.

Best practices

Confirm which version of the Convention (original or the modernised text) applies to the state in question, and verify its ratification and in-force status against official Council of Europe sources.
Treat Convention 108 and the GDPR as distinct instruments; do not assume that compliance with one satisfies the other, and assess obligations separately for each relevant jurisdiction.
When operating across multiple signatory states, check each country's signature, ratification, and national implementation rather than assuming uniform application.
Where a matter turns on the precise wording of the Convention's principles, consult the current operative text directly rather than relying on summaries.
Monitor developments in the modernisation process and ratification progress, since the applicable position can change over time.
Document, in your compliance program, which data protection frameworks apply to a given processing activity, distinguishing EU-derived obligations from Council of Europe treaty obligations.