Privacy & Interfederation

Slides:



Advertisements
Similar presentations
Why do we need Government?
Advertisements

PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Innovation through participation Attributes Release Working Group European data protection directive REFEDS meeting 22th Apr, 2012
Copyright JNT Association Federated Identity and Data Protection Law Andrew Cormack, Eva Kassenaar, Mikael Linden, Walter Martin Tveter.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
FERPA: Family Educational Rights and Privacy Act.
1 Who Gets to Know? Child Welfare & Confidentiality John L. Saxon Institute of Government The University of North Carolina at Chapel Hill February, 2004.
What if my organization conducts business across borders ? Your footnote Privacy and “Personal Information” have different meanings in different countries;
4/3/20011 Ethics in Special Education Assessment and Testing and Maintenance of Student Information.
Class 13 Internet Privacy Law European Privacy.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Copyright 2006 Archistry Limited. All Rights Reserved. SOA Federated Identity Management How much do you really need? Andrew S. Townley Founder and Managing.
© 2007 The MITRE Corporation. MITRE Privacy Practice W3C Government Linked Data Working Group Michael Aisenberg, Esq. 29 June 2011 Predicate for Privacy.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
The Cal Lutheran Family and FERPA New Student Orientation 2008.
Student Confidentiality: The FERPA/HIPAA Facts AISD Policy Student Records AISD Procedure AP. 11.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Information Technology & Ethics. Impact The impact of IT on information and communication can be categorized into 4 groups: privacy, accuracy, property,
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Threat Prevention and Detection (within Critical Infrastructures) under EU Data Protection Legislation– Purpose Specification and Limitation. Laurens Naudts.
Identity Federations: Here and Now David L. Wasley Thomas Lenggenhager Peter Alterman John Krienke.
Networks ∙ Services ∙ People Nicole Harris UK federation meeting eduGAIN, REFEDS and the UK 23 June 2015 Project Development Officer GÉANT.
Business Challenges in the evolution of HOME AUTOMATION (IoT)
Designing Identity Federation Policy, the right way Marina Vermezović, Academic Network of Serbia TNC2013 conference 4 May 2013.
CONDUCTING AN ETHICAL ONLINE STUDY Janet Salmons, PhD Chapter 5.
FERPA Family Educational Rights and Privacy Act
Denise Chrysler, JD Director, Mid-States Region
Confidentiality Training
The Data Protection Act 1998
Contracts – the small print
Surveillance around the world
Data Protection GCSE ICT Mrs N Steventon-2005.
Student Privacy in an Ever-Changing Digital World
Issues of personal data protection in scientific research
Viewing the GDPR Through a De-Identification Lens
Confidentiality Training
To start the presentation, click on this button in the lower right corner of your screen. The presentation will begin after the screen changes and you.
Student Confidentiality: The FERPA/HIPAA Facts
Protection of Human Subjects In Research
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
The Data Protection Act 1998
Information Governance and Data Privacy: A World of Risk
Data Protection Legislation
GDPR - Individual’s Rights
Youngwummin: Ethics and Data Collection Methods
Managing Student Records Legally and Effectively
Data Protection principles
PASSHE InCommon & Federated Identity Workshop
Relocation CARNIVAL come one…come all
Consent and Federated Identity
National remedies and national actions
GDPR (Patrix interpretation)
Confidentiality Training
The activity of Art. 29. Working Party György Halmos
What is the Data Protection Act (DPA)? 1998
Prof. Dr. Martin Senftleben Vrije Universiteit Amsterdam
Information Handling Research Student Induction Day
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Federated Identity and Data Protection Law
General Data Protection regulation (GDPR)
What does that have to do with me?
EU Data Protection Legislation
Presented by: Steve Gerdes 26 January 2019
General Data Protection Regulation Community Councils
Student Confidentiality: The FERPA/HIPAA Facts
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Privacy & Interfederation A challenge to soup

Some topics to discuss IDENTITY vs identity Privacy and a federation’s role The JA.NET analysis of EU rules So what constitutes PII anyway? Can interfederation work? Others ?

IDENTITY vs identity Is it a pointer to your protoplasm? Is it some subset of data about you? It’s all of the above, BUT… Fundamental to the notion of privacy You decide what to reveal in any context Revealing too little may have consequences

Privacy and a federation’s role Federation sets rules for its members Protection of identity data Part of an Identity Assurance Profile? Current focus is on IdP SP/RPs are also critical Commercial interests don’t want constraints What liability might a federation incur if it tried to ‘enforce’ privacy rules?

JA.NET analysis of EU rules Places requirements on both IdP & SP Provides for predefined default release Subjects must know what that is and why Anything additional requires consent Federations aren’t enforcers “It’s the law!”

Identity Providers Must identify which services are necessary for [each recognized SP/RP] Must consider whether personally identifiable information is necessary for those services, or whether anonymous identifiers or attributes are sufficient; Must inform users what information will be released to which service providers, for what purpose(s). May release that necessary personally identifiable information to those services; May seek users’ informed, free consent to release personal data to other services that are not necessary for [a given SP/RP] Must inform users what information will be released to which service providers, for what purpose(s); Must maintain records of individuals who have consented; Must allow consent to be withdrawn at any time; Must only release personal information where consent is currently in effect. Should have a data processor/data controller agreement with all service providers to whom personally identifiable data is released. Must ensure adequate protection of any data released to services outside the European Economic Area.

Service Providers Must consider whether personally identifiable information is necessary for their service, or whether anonymous identifiers or attributes can be used; Should obtain that information from home organisations; Should have a data processor/data controller agreement with all home organisations from whom personally identifiable data is obtained; If no such agreement is in place, must inform users what personal information will be obtained, by which service providers, for what purpose(s). May request personal information from users Must inform users what information will be released to which service providers, for what purpose(s); Must ensure that users who do not provide information are not unreasonably disadvantaged; Must maintain records of individuals who have consented; Must allow consent to be withdrawn at any time; Must cease processing data when consent is withdrawn

What constitutes PII? There may be an EU analysis … Does FERPA help? Does HIPAA help? If rules or laws(!) differ what applies? Jurisdiction of the Subject? What about a Stanford student studying in Paris? Do we use the union of both rules? Do we use the common subset?

Can interfederation work? It must! (My words) It will take discussion, cooperation, work Interfederation Agreements must address this issue Can individual federations require this of their members? Depends on member agreements… Who is the enforcer? (Judge Dredd !)

Discussion …