Directive 95/46/EC
Directive 95/46/EC, commonly called the Data Protection Directive, was a European Union law adopted on 24 October 1995 that set rules for how personal data of individuals should be handled across the EU. It required EU member states to protect people's fundamental rights and freedoms, in particular their right to privacy, when personal data was processed. It has since been replaced and no longer applies.
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 concerned the protection of individuals with regard to the processing of personal data and the free movement of such data. As a directive, it required transposition into national law by EU member states rather than applying directly, which contributed to variation in national implementations across the EU. Its subject matter covered protection of privacy, data protection, cross-frontier data flows, and related access and disclosure of information. Per Article 94 of the General Data Protection Regulation (Regulation (EU) 2016/679), Directive 95/46/EC was repealed with effect from 25 May 2018, and references to the repealed Directive are to be construed as references to the GDPR. Practitioners should note that the Directive is no longer in force and its provisions should not be applied to current processing; the specific transposition and any surviving national derogations should be verified against the relevant member state law and the current official text.
Why it matters
Directive 95/46/EC established the first comprehensive EU-wide framework for the protection of personal data and, in particular, the right to privacy of natural persons. For roughly two decades it shaped how organizations across the European Union approached the processing of personal data, and it laid the conceptual groundwork that the General Data Protection Regulation (GDPR) later built upon. Understanding the Directive matters because much of the vocabulary and many of the structural ideas that appear in current law originated in this instrument.
A key practical significance lies in the Directive's legal form. As a directive rather than a regulation, it required transposition into the national law of each EU member state, which contributed to variation in how its principles were implemented across the EU. This fragmentation is part of the reason the EU later moved to a directly applicable regulation. Practitioners reviewing older contracts, legacy compliance documentation, or historical enforcement matters may still encounter references to the Directive or to national laws that transposed it, and interpreting those references correctly requires knowing what the Directive did and did not govern.
Because the Directive is repealed and no longer in force, its provisions should not be applied to current processing activities. Per Article 94 of the GDPR, references to the repealed Directive are to be construed as references to the GDPR. Where surviving national implementing measures or derogations may still be relevant, the specific member state law and the current official text should be verified rather than relying on the Directive itself.
Who it's relevant to
Inside DPD
Common questions
Answers to the questions practitioners most commonly ask about DPD.