Data workshop WhOSE DATA IS IT ANYWAY? Alexia Christie

Slides:



Advertisements
Similar presentations
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Advertisements

DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
SA Constitution Sec 14 – Privacy – RICA – POPI Sec 32 – Access to Information – PAIA – POPI.
The European Union legal framework for clinical data access: The European Union legal framework for clinical data access: potential challenges and opportunities.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
Protecting information rights –­ advancing information policy Privacy law reform for APP entities (organisations)
Human Rights and Patient Care Anahit Harutyunyan Armenia.
The Protection of Personal Information Act
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
1 Information Sharing Environment (ISE) Privacy Guidelines Jane Horvath Chief Privacy and Civil Liberties Officer.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
The Protection of Personal Information Bill 13 February
The Debt Collectors Amendment Bill 2016 Right to Confidential Treatment Marina Short Chief Executive Officer Consumer Profile Bureau (CPB)
An NZFFBS Training Module.  Objective 1  State the purpose and principles of the Privacy Act and the Code of Ethics.  Objective 2  Apply the principles.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
The EU General Data Protection Regulation Frank Rankin.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Sharing Information Legally Lindsay Ould London Borough of Lewisham.
VICTORIAN CHARTER OF HUMAN RIGHTS AND RESPONSIBILITIES.
Legal framework of telework – practical solutions for employers Dr. Jacek Męcina.
SEMINAR: Copyright 2012 All rights reserved. This presentation and/or any part thereof is intended for personal use and may not be reproduced or distributed.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Understanding Privacy An Overview of our Responsibilities.
Understanding Privacy An Overview of our Responsibilities.
Monique Jefferson & Nadine Mather
Director, Regulation and Strategy
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
Issues of personal data protection in scientific research
Data Protection: EU & International
IT Applications Theory Slideshows
General Data Protection Regulation
Human Rights and Patient Care
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
Museums + Heritage webinar, 30 November 2017
APP entities (organisations)
Nina Barakzai November 2017
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulation
New Data Protection Legislation
Appropriate Data Sharing in Health and Social Care
The GDPR and research data
Data Protection principles
OECD Guidelines Collection Limitation: should be limited to personal data, obtained by lawful and fair means, and (where appropriate) with knowledge and.
Preparing for the GDPR - What do we need to do if we process children’s personal data? Data Protection Practitioners’ Conference 2018 #DPPC2018.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
How we use Your Health Records
GDPR Workshop MEU Symposium Prague 2018
General Data Protection Regulations 2018
General Data Protection Regulations (GDPR) Training
Information Handling Research Student Induction Day
The General Data Protection Regulation: Are You Ready?
PERSONAL INFORMATION BILL
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
The EDPS: competences and processing of personal data in EU funds
Legal Basis: CRITERIA FOR MAKING DATA PROCESSING LEGITIMATE
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Data protection & FOIA considerations
Presentation transcript:

Data workshop WhOSE DATA IS IT ANYWAY? Alexia Christie Cape Town – March 2017 © Webber Wentzel 2017

OPPORTUNITY RISK The open data movement DATA SHARING SEAMLESS ACCESS DATA SHARING OPPORTUNITY POPI + PAIA + KING IV + NHA + NCA + SECRECY BILL + CYBER BILL + MORE DATA SECURITY & ACCOUNTABILITY PROTECTION OF PRIVACY RIGHTS RISK

DATA SHARING continuum Uninhibited Access No Access Data Lake?

open data? BIG DATA OPEN GOVERNMENT OPEN DATA DATA LAKE DATA WAREHOUSE

Protection of personal information act (POPI) Privacy vs free flow of information Private and public bodies "Processing" includes use and sharing Responsible party = "public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information" Personal information vs special personal information (eg health) Exclusions: de-identified data national security, prevention/detection of unlawful activities (if adequate protection) by Cabinet and committees, Executive Council of province journalistic, literary or artistic expression Government Business B2G G2B G2G

popi – CONDITIONS Accountability Processing lawful, and reasonable manner re purpose: processing must be adequate, relevant and not excessive consent (voluntary, specific and informed) or justification (eg legitimate interest) collect direct from data subject (exceptions eg public record, consent, legitimate interest, necessary) 3. Purpose specific, explicitly defined and lawful purpose ensure data subject is aware of purpose 4. Further processing for or compatible with original purpose (exceptions eg consent, public record, necessary for national security, public health/safety, historical/statistical/research purposes)

popi – CONDITIONS 5. Information quality complete, accurate, not misleading and up to date 6. Openness notification to data subject: what, where and for what purpose (exceptions eg consent, legitimate interests, necessary for national security, historical/statistical/research) 7. Security safeguards appropriate reasonable technical and organisational security measures 8. Data subject participation data subject has right to access, correct and delete Prohibits processing of special personal information, and re children. Exceptions include: consent justification (eg historical/statistical/research in public interest or impossible to ask for consent, AND adequate guarantees) Regulator authorisation (public interest and appropriate safeguards)

promotion of access to information ACT? Private and public bodies Request access Grounds for refusal Public body may not refuse if consent, or informed in advance that will/may be made public Challenges with PAIA

What's happening abroad? United Kingdom In 2014, the Cabinet Office Data Sharing Policy Team proposed following safeguards: accreditation and registration of projects and individuals having access to de-identified data establish vehicle for public sector big data compliance with Data Sharing And Anonymisation Codes of Practice Current example of G2B data sharing: Driver and Vehicle Licensing Agency sharing information about licensed drivers with insurers. United States of America 2015 Cybersecurity Information Sharing Act Homeland Security's Automated Indicator Sharing Initiative Information relating to cybersecurity is shared on a B2G basis. Australia Regulate G2G and G2B sharing via Information Sharing Agreements. Australian Bureau of Statistics' Good Practice Guide for G2G sharing. Australian government's 2016 Guidelines for Sharing Personal Information G2B.

Where to next? Data has value Review legislation and practices re open data Why? – identify benefits (for citizens) What? - identify categories of suitable "open data" Who? manage – responsibility & accountability & trust access - for what purpose? Seek opportunities to share & valid information sharing path in law: access, use and protection

Legal Notice: these materials are for training purposes only and do not constitute legal or other professional advice