Data Protection: EU & International

Slides:



Advertisements
Similar presentations
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Advertisements

1 Enforcement Powers of National Data Protection Authorities and Experience gained of the Data Protection Directive Safe Harbour Conference Washington.
European CommissionDirectorate-General Justice, Freedom and Security Data Protection 1 Conference on Cross Border Data Flows & Privacy October 15-16, 2007.
NATIONAL INFORMATION GOVERNANCE BOARD
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Data Protection and Records Management
1 Data Protection and Research – Implications for a National Out-of-Hospital Cardiac Arrest Register NUI Galway Dept of General Practice Lunchtime seminar.
Privacy and security: Is Europe going banana? Jean-Marc Van Gyseghem Head of Unit « Liberties in the information society » CRID – University.
A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.
Anomalous Aspects of Transfer of Personal Data from the E.U. to the U.S. Stephen R. Bell Willkie Farr & Gallagher ABA Section of International Law New.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Class 13 Internet Privacy Law European Privacy.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Human Rights Search: Basic Documents United Nations Charter 1945 Article 55United Nations Charter Universal Declaration of Human Rights 1948Universal Declaration.
Technology– the Data Protection Challenge Billy Hawkes Data Protection Commissioner HEAnet Conference Kilkenny, 13 November 2009.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
Health research and the protection of personal information rights in international ethics and human rights law Colin M Harper Promoting Health Research.
European Standards on Confidentiality and Privacy in Healthcare Dr Colin M Harper Division of Psychiatry & Neuroscience Queen’s University.
Data Protection Privacy in the Digital Age: the UN General Assembly Resolution Sophie Kwasny, 16 October th International Conference, Mauritius.
Access to Public Information in Slovenia Nataša Pirc Musar, LL.B. Commissioner for Access to Public Information The Hague – 24 th -25 th November, 2004.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection and the Voluntary Sector: Respecting the Rights of the Individual Billy Hawkes Data Protection Commissioner Carmichael Centre Dublin, 2.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
European Data Protection Supervisor Pharmaceutical Regulatory & Compliance Congress, Brussels, 7 June 2007 European Privacy and Data Protection Policy.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
An Overview of International Regulation of Data Protection AFIN- DRI 2002 Lecture Stephen K. Karanja.
Data protection and European citizens’ initiatives
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
SKK - NCHR AFIN- DRI 1010 Lecture Stephen K. Karanja Senior Researcher Norwegian Centre for Human Rights Data Protection.
WHOIS Public safety and data protection requirements.
Data Protection – the Lisbon Effect Billy Hawkes Data Protection Commissioner Institute of International and European Affairs Dublin, 17 September 2009.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
European Data Protection Supervisor TAIEX Seminar - Belgrade 9 February 2009 Principles of data protection and international legal framework Alfonso Scirocco.
Privacy and ‘Big Data’: the European perspective Human Subjects’ Protections in the Digital Age: IRB, Privacy and Big Data Peter Elias, University of Warwick.
Privacy in the Digital Age: the UN General Assembly Resolution
Convention 108 and the EU framework: Differing while Converging
Privacy as a societal value
Luca De Matteis Justice counsellor (criminal law, data protection)
Data Protection: The Law
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Treatment of Foreigners under International Law
General Data Protection Regulation
Where is the harm? Calculating the damages afforded in privacy cases by the European Court of Human Rights Bart van der Sloot May 14th 2017, Haifa, Israel.
Data Protection and Freedom of expression Sophie Kwasny
Data Protection Legislation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Human Rights
The Future of Big Data, Equality and Privacy
Article 10 – Freedom of expression
Privacy: a work in progress
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
ESF Monitoring & Evaluation and Data Protection in Spain
Cybercrime and Data Protection
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
Data Protection and Justice and Home Affairs
European Data Supervisor
Data transfers to non-EU countries under the new GDPR
The activity of Art. 29. Working Party György Halmos
The Modernisation of Convention108
GDPR & Accountability ISACA Ireland Annual Conference 2018
Is Data Protection a Fundamental Right Protecting the Individual?
The Treaty of Lisbon and Administrative Cooperation
FUNDAMENTAL SOCIAL RIGHTS IN EU
EU Data Protection Legislation
Presentation transcript:

Data Protection: EU & International

Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society Not absolute: other necessary Rights on a Democratic Society ( e.g. Freedom of Expression, Rights of Others)

Privacy International UN: Guidelines (1990) - non-binding OECD: guidelines (1980) - broad agreement on principles, non-binding in practice APEC: Privacy Framework (2004)

European Convention on Human Rights (ECHR) Explicit Right to Personal Privacy under Article 8 of 1950 European Convention for the Protection of Human Rights & Fundamental Freedoms (ECHR) Convention ratified by all EU Member States and most other European countries

Council of Europe Member States

ECHR Article 8: Right to respect for Private and Family Life (1) Everyone has the right to respect for his private and family life, his home and his correspondence. (2) There shall be no interference by a public authority with the exercise of this right except as in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others [tension with Article 10: Freedom of Expression]

Council of Europe Data Protection Convention 1981 Council of Europe Convention for the Protection of Individuals with regard to the Automatic Processing of Personal Data (in force October 1985) 2001 Additional Protocol to Convention (in force July 2004)

Lisbon Treaty Article 16 Treaty on the Functioning of the Union 1. Everyone has the right to the protection of personal data concerning them. 2. The European Parliament and the Council, acting in accordance with the ordinary legislative procedure, shall lay down the rules relating to the protection of individuals with regard to the processing of personal data by Union institutions, bodies, offices and agencies, and by the Member States when carrying out activities which fall within the scope of Union law, and the rules relating to the free movement of such data. Compliance with these rules shall be subject to the control of independent authorities.

EU Charter of Fundamental Rights: Article 8 Protection of personal data 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority.

EU/EEA Directives Directive 95/46/EC Protection of Individuals with regard to the Processing of Personal Data and on the Free Movement of such Data Directive 2002/58/EC & 2009/136/EC Privacy and Electronic Communications

European Union [27 Member States, 3 EEA States, Accession States]

EU Directives Member State Law Directives must be transposed into Member State law – margin of discretion to Member States Data Protection Rules: 85% (?) in Directive, 15% (?) in Member State law Disputes: European Court of Justice (ECJ) “Article 29 Committee” (DP Commissioners): guidance & harmonisation

European Data Protection Rules: Free Flow of Personal Data Fair obtaining & processing Consent Specified purpose No disclosure unless “compatible” Safe and secure Accurate, up-to-date Relevant, not excessive Retention period Right of access Independent Supervisory Authority

Rights of individuals to fairness when giving information to get a copy of personal data “right of access” to correct data if it is wrong or to have data deleted to opt out of direct marketing to complain to the D. P. Commissioner

Electronic Communications General DP Principles apply Telecom-specific: ‘Cookies’ on PCs Caller ID (phones) Location Data (mobiles) Directories ‘SPAM’ Data Retention

Role of EU Data Protection Authorities Ombudsman Role: resolution of disputes between data subjects and data controllers or processors Enforcer Role: compliance by data controllers & processors Educational Role: Promote DP rights and good practice Registration Authority: obligation on major holders of personal data to be placed on public register

Transfers EEA International Emphasis on structured ways of protecting individual’s privacy rights. Data Transfers OK if: Approved countries: Switzerland, Canada, Argentina, Isle of Man, Guernsey, Jersey, Faroe Islands, USA [“Safe Harborites” & PNR data only] Covered by Model Contracts or Binding Corporate Rules (BCRs) Article 26 (1) Exceptions (e.g. individual consent)

APEC Privacy Principles (2004): Encourage E-Comm. Preventing Harm Notice Collection Limitation Uses of Personal Information Choice Integrity of Personal Information Security Safeguards Access and Correction Accountability APEC Data Privacy Pathfinder (Sept. 07)

OECD Guidelines/Principles (1980):Encourage Intl. Data Flows Data Quality Purpose Specification Use Limitation Security Safeguard Openness Individual Participation Accountability Recommendation on Privacy Law Enforcement (June 07)

Further Information: www.coe.int www.europa.eu.int/comm/justice_home/fsj/privacy www.dataprotection.ie