The Data Protection Regulation for Europe

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
The EU General Data Protection Regulation Frank Rankin.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
General Data Protection Regulation (EU 2016/679)
Brussels Privacy Symposium on Identifiability
Key changes with the GDPR
Industry 4.0 – New ways of cooperative working – are we prepared?
The future of data protection: General Data Protection Regulation
Brussels Privacy Symposium on Identifiability
Processing for archiving purposes in the GDPR
Seamus Carroll Civil Law Reform Division
Issues of personal data protection in scientific research
General Data Protection Regulation (GDPR)
Viewing the GDPR Through a De-Identification Lens
Presentation to GTMC on GDPR
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
Museums + Heritage webinar, 30 November 2017
GDPR Overview Gydeline – October 2017
Data for Child Health: Promoting & Protecting Public Health through Custodianship EAP Brussels, 28 January 2016 Health Databases & Biobanks Promoting &
Data Protection Update – GDPR or bust
General Data Protection Regulation: Turning the black into white
GDPR Overview GDPR - General Data Protection Regulations
GDPR Overview Gydeline – October 2017
GDPR Road map to Compliance.
Data Protection & Freedom of Information- An Introduction
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
General Data Protection Regulation
Introduction to GDPR 09/11/2018.
The General Data Protection Regulation (GDPR)
New Data Protection Legislation
Introducing the General Data Protection Regulation 2016
State of the privacy union
Appropriate Data Sharing in Health and Social Care
G.D.P.R General Data Protection Regulations
The GDPR and research data
FEK årskonferanse 28. februar 2018.
The Data Protection Regulation for Europe
General Data Protection Regulation
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulation
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
Data Protection in a Tutorial Context
GDPR – Data Protection Law on Steroids?
Information Handling Research Student Induction Day
The General Data Protection Regulation: Are You Ready?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Public Privacy: juridical & ethical perspective
The EDPS: competences and processing of personal data in EU funds
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
General Data Protection Regulation (GDPR)
General Data Protection Regulation “11 months in”
European Economic Area’s General Data Protection Regulation
The EU General Data Protection Regulation
EU Data Privacy: What US Orgs Need to Do Now to Prepare for the GDPR
Presentation transcript:

The Data Protection Regulation for Europe Magnus Stenbeck, Karolinska Institutet Dept of Clinical Neuroscience and The Research Data Inquiry (U 2016:04)

The data protection regulation in the EU Old system New system The 1995 Data Directive Prescribes that member states shall implement laws and regulations in accordance with the directive Personal Data Act (1998) Swedish implementation Void by May 25, 2018 The 2016 General Data Protection Regulation Applies as from May 25, 2018 Directly applicable in member states (MS) and associated states (e.g. Norway) Needs additional union or MS legislation All national regulation is obsolete/must be removed Some Swedish additional laws Many modifications of existing regulations Namn Efternamn 1 november 2019

General Data Protection Regulation (”GDPR”) replaces the Personal Data Act (PUL) takes priority over Swedish legislation PUL was subsidiary (other legislation took priority) GDPR does not leave space for deviating national rules or special rules in specific subject matter areas But some additional new Swedish legislation is needed many articles refer to the need for union or member state regulation GDPR leaves space for some constitutional rights and obligations

Current legislation which will prevail The Freedom of the Press Act ( and The Fundamental Law on Freedom of Expression) The Law on Public Access to Information and Secrecy The Ethical Review Act Namn Efternamn 1 november 2019

The Law on Access to Public Information and Secrecy still applies Basic principle : Public access to official documents Chapter 24, 8 § Statistical secrecy Chapter 25, 1 § Secrecy in health care Different levels of secrecy, but both have ”reversed damage requirement” for research You have to show that nobody will suffer damage if you release the data Chapter 27, 1 § ”PUL” secrecy (in the future ”GDPR” secrecy) If there is reason to believe that the recipient of the data will process data at odds with PUL (GDPR), then the data cannot be released Chapter 11, 3 § The original secrecy is transferred with the data if it will be used for research purposes The recipient must apply the same rules Namn Efternamn 1 november 2019

The Law on Ethical Review still applies Review is mandatory when processing sensitive personal data , data on criminal offences and biological samples from living or deceased persons Review is mandatory even if you have consent Permission can be granted only for research in Sweden The territorial applicability differs from the GDPR and the proposal for a Swedish complementary law Namn Efternamn 1 november 2019

Sweden: Proposed new legislation The Data Protection Law (SOU 2017:39) SOU 2017:39 Ny dataskyddslag Proposition to the parliament 2017/18:105 Ny dataskyddslag The Research Data Law (SOU 2017:50) SOU 2017:50 Personuppgifter för forskningsändamål No proposition presented yet Most register laws remain, but must be adapted Ds 2017:40 Ändringar i vissa författningar inom Finansdepartementets ansvarsområde med anledning av EU:s dataskyddsreform SOU 2017:66 Dataskydd inom socialdepartementets verksamhetsområde SOU 2018:4 Framtidens biobanker

Personal data Personal data Pseudonymisation any information relating to an identified or identifiable natural person (‘data subject’) an identifiable natural person is one who can be identified, directly or indirectly Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information the additional information must be kept separately and protected by technical and organizational measures

Personal data processing is legal only when one of these apply Article 6 Consent or processing of personal data is necessary in order to: Perform a contract Comply with a legal obligation Protect the vital interests of the data subject or another person Perform a task in the public interest The interests of the controller override those of the data subject f cannot be used by public authorities c and e requires a legal basis (new requirement)

Sensitive personal data (special categories) Article 9 Race, ethnicity Political, religious, philosophical beliefs Trade union membership Genetics Biometrics for the purpose of identification Health Sexuality (sexual orientation)

Processing of sensitive personal data is forbidden Same as today but there are exemptions … if you have explicit consent from the data subject .. except where Union or Member State law provide that the prohibition … may not be lifted by the data subject Sweden: the law prescribes mandatory ethical review processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) must be based on union or MS law which is proportional, and safeguards are required

Consent Legal definition Freely given Specific Informed Unambiguous A statement or a clear affirmative action and for sensitive personal data: Explicit The controller shall be able to demonstrate that the data subject has consented Consent can be withdrawn at any time for subsequent processing Namn Efternamn 1 november 2019

Legal basis for public authorities Consent? Sometimes, but questionable Recital 43: ” In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation.” If a public authority wants to use consent it must be able to show that it is freely given Performance of a task in the public interest the default legal basis for public universities

These basic principles for personal data processing always apply These basic principles for personal data processing always apply! (Article 5) Lawful, fair and transparent (open in relation to the data subject) Limited purpose Only for a specified purpose Must not be further used for a purpose which is opposed to the original purpose Research is not opposed to the original purpose Minimum of data Accurate data Correct the errors, but exemption for archiving Not to be stored longer than necessary But long term storage possible if necessary for research Integrity and confidentiality (=protect the data) Accountability

Safeguards Mandatory in research Proposed in the Swedish research data law Ethical review Only for sensitive data Pseudonymisation (or similar level of protection) Right to opt out (if possible) Other possibilities Organisational solutions organisationally separated personal data processing Technical solutions Federated data, remote access, other distributed solutions, encryption, logging, safe authorisation procedures, etc.

Rights of the data subject In principle similar to current rules, but much more detailed Information Art 12 How to inform the registered person Art 13 Information content when data are obtained directly from the registered subject Art 14 Information content when data are obtained indirectly (e.g. from registers) Art 15: Right of access (” register excerpts”) Art 16: Right to rectification Right to erasure (”right to be forgotten”) restriction or objection to processing (Art 15-18, 21) In most of these cases, there are exemptions if necessary for research or impossible to fulfil

Accountability of the controller The controller is responsible for implementing technical and organisational measures to ensure that processing of personal data follows this regulation This may include using approved rules of conduct (Article 40) and certification procedures (Article 42) It may also include a data protection impact assessment Possible fines for breaches: administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher The Data Protection Inquiry has proposed an upper limit of 20 000 000 SEK for public authorities Namn Efternamn 1 november 2019

What is needed before May 25, 2018? Analyse whether the processing of personal data in your organisation is (still) legal You have to be able to prove this by proper documentation Document the existing processing Observe that processing includes storing old data Did you obtain consent according to the legal definition? Can you show documentation of this? Can you document that your processing is in accordance with the law defining a public interest? Analyze and adjust your documentation system Design organizational processes that will ensure the rights of the data subject be able to handle data protection incidents Namn Efternamn 1 november 2019

Important roles Controller Processor Data Protection Officer Namn Efternamn 1 november 2019

Current ongoing work in the Research Data Inquiry Main task: Propose legislation for research databases Point fo departure in proposals made by Westerberg in 2014 Additional tasks: Propose regulation for the national biobank register Add to SOU 2018:4? Luxemburg Income Study Sweden can no longer supply data to this comparative study initiated from Sweden in the 1980’s The law on the forensic psychiatric research register (Riksmedicinalverket) Final report due on May 25, 2018 Namn Efternamn 1 november 2019