Surveillance around the world

Slides:



Advertisements
Similar presentations
EU Privacy Directive. What is a directive? A piece of European legislation, passed by bureaucrats, addressed to member states Member states must ensure.
Advertisements

Confidentiality and HIPAA
IS BIG DATA GIVING YOU A BIG HEADACHE? Risk Reduction - Transactional, International and Liability Issues Oregon State Bar Corporate Counsel Section Fall.
The Problem Solvers TM Privacy Rights: Minors and Parents Michael J. Hewitt Marcel Daigle Singleton Urquhart LLP.
The Data Protection (Jersey) Law 2005.
The Patriot Act And computing. /criminal/cybercrime/PatriotAct.htm US Department of Justice.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
Workshop on Harmonizing Cyberlaw in the ECOWAS region ( Procedural Law in the Budapest Convention ) Ghana, Accra 17 – 21 March 2014, Kofi Annan International.
Policing the Internet: Higher Education Law and Policy Rodney Petersen, Policy Analyst Wendy Wigen, Policy Analyst EDUCAUSE.
Data Protection and Records Management
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
The role of the Office of the Privacy Commissioner in telecommunications Andrew Solomon Director, Policy.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Per Anders Eriksson
Transborder dataflows Flow of information across national borders Much of this data involves personal information.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
Data Protection Act. Lesson Objectives To understand the data protection act.
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
13 July 2006Susan Joseph Health Privacy It’s My Business Health Records Act 2001 (Vic) eReferral Service Co-ordination System.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
CLOUD AND SECURITY: A LEGISLATOR'S PERSPECTIVE 6/7/2013.
© Copyright 2011, Vorys, Sater, Seymour and Pease LLP. All Rights Reserved. Higher standards make better lawyers. ® CISO Executive Network Executive Breakfast.
EU Data Protection IT Governance view Ger O’Mahony 12 th October 2011.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Chapter 22: Organization and Coordination of Counterterrorism Investigations.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
Data Protection and Records Management. Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for.
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Data Protection Guidance for Principals and Deputy Principals Anne Lyne Partner & Breda O’Malley Partner Kilkenny - 3 October 2015.
Yes. You’re in the right room.. Hi! I’m David (Hi David!)
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device.
CHAPTER SIXTEEN The Right to Privacy and Other Protections from Employer Intrusions.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
The Data Protection Act 1998
Data Protection Officer’s Overview of the GDPR
Clash of jurisdictions in the area of data protection
Protection of CONSUMER information
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Privacy principles Individual written policies
Data Protection: EU & International
Investigating Shipping Pollution Violations
General Data Protection Regulation
Data protection issues in regulatory investigations
International Regulatory Trends
The Data Protection Act 1998
Information Governance and Data Privacy: A World of Risk
Data Protection Legislation
The European Union General Data Protection Regulation (GDPR)
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
U.S. Department of Justice
Protection of News Sources
G.D.P.R General Data Protection Regulations
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Patrick Sefton | Principal, Brightline Lawyers
Pre-Trial Procedures Search and Seizure.
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
The title: The implementation of Data Protection
Government Data Practices & Open Meeting Law Overview
Electronic Surveillance, Post 9/11
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Government Data Practices & Open Meeting Law Overview
EU Data Protection Legislation
Presentation transcript:

Surveillance around the world

Where can I safely store my data? Percentage of population using the internet (0-100: light to dark)

“Safe Harbor” principles -> “Privacy Shield” principles Notice - Individuals must be informed that their data is being collected and how it will be used. The organization must provide information about how individuals can contact the organization with any inquiries or complaints. Choice - Individuals must have the option to opt out of the collection and forward transfer of the data to third parties. Onward Transfer - Transfers of data to third parties may only occur to other organizations that follow adequate data protection principles. Security - Reasonable efforts must be made to prevent loss of collected information. Data Integrity - Data must be relevant and reliable for the purpose it was collected. Access - Individuals must be able to access information held about them, and correct or delete it, if it is inaccurate. Enforcement - There must be effective means of enforcing these rules.

USA? Intelligence services and law enforcement operate surveillance programs, but not for an economic purpose Court orders, warrants, and subpoenas govern who must provide what data Subjects of surveillance by intelligence agencies are not notified, but subjects of law enforcement surveillance are usually notified Most U.S. privacy laws protect individuals without regard to citizenship and courts will generally take jurisdiction against U.S. companies regardless where plaintiff is located. 4th Amendment protections are limited to searches on U.S. territory, but the California Constitution and most statutes, torts and other privacy laws are not so limited.

United Kingdom? “Snooper’s Charter” (12/30/2016) Requires communication service providers to store websites visited for 1 year Allows police, intelligence officers and other government officials to see these records without a warrant Allows targeted equipment interference by police and intelligence agencies (hacking) and bulk interference for national security matters Legally obligates communication service providers to assist with targeted interception of data and with interference Requires communication service providers in the UK to have the ability to remove encryption; foreign companies are not required to remove encryption Creates new crimes of unlawfully accessing internet records, and of working for a communication service provider and revealing that data has been requested

Australia? Allows surveillance for economic purposes (e.g., US does not) Access to metadata does not require a warrant. Mandatory data retention requires that metadata be collected by ISPs and stored for 2 years No constitutional rights to privacy No reciprocal Safe Harbor program as between US and EU

Canada? Intelligence services not required to notify other government bodies of surveillance actions taken Companies allowed to voluntarily disclose information to the government where they think it may pose a security risk, without notifying customers

China? No court order needed for the Public Security Bureau to intercept data or compel access to data stored by private companies (some exceptions for cloud storage) Disclosure of personal data to the government is not considered a leakage of personal data, and is generally not objectionable. Liability may arise if personal data is divulged to third parties which causes damages to the data subject. The operation and working procedures of intelligence services are top secret. There is virtually no public information of how they function, and as a matter of reality, their work is generally outside of judicial review. No right to be forgotten

France? Economic surveillance is authorized, and court orders are not necessary to intercept calls, emails, or other communications It is a criminal offense in France for someone involved in a surveillance program to reveal the existence of this surveillance Privacy rights are applicable on a territorial basis, not on a citizenship basis. Therefore, French and US citizens have the same protection on French territory. On November 30, 2015 France adopted a new law that allows French Intelligence Services to conduct surveillance programs targeting communications issued from and received outside of France. This law was adopted to provide a legal ground to existing intelligence services practices e.g., surveillance of under-sea internet cables).

Germany? No court order required for intelligence agencies to obtain data Telecommunications providers are required to enable monitoring and recording. Providers of telecommunications services are required to technically implement surveillance measures and to allow surveillance services to set up respective devices at their premises Data subjects are notified of surveillance after its completion U.S. companies or the U.S. government are not covered by German data protection rules as long as they refrain from collecting, processing and using data within Germany. “Right to be forgotten” applies (in EU generally)

India? The right to privacy has been recognized as a fundamental right by Indian courts. Law enforcement authorities and intelligence agencies do not need court orders to intercept communications

Japan? Intelligence services do not operate surveillance programs. Only law enforcement may seek warrants to intercept communications Subjects whose data are accessed by law enforcement or whose communications are wiretapped must be notified of this surveillance

For your protest projects… Civil Disobedience - Know Your Rights Training Wednesday, February 8, 2017 12:45-2:00pm Room 190, Stanford Law School