HIPSSAPROJECT Support for Harmonization of the ICT Policies in Sub-Sahara Africa Meeting with Data Protection Law Stakeholders 28/29 th August, 2013 PRESENTATION.

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa Meeting with Data Protection Law Stakeholders 02 April 2013 PRESENTATION.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
DATA PROTECTION BILL PRESENTED BY GERTRUDE M. IMBWAE National Legal Expert On Data Protection.
HIPSSA Support for Harmonization of the ICT Policies in Sub-Sahara Africa 28/29 August, 2013, Swaziland.
International Telecommunication Union HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Tanzanian ICT.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
International Telecommunication Union HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Namibia ICT Ministry.
The Data Protection (Jersey) Law 2005.
Data Protection.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
6/1/2015MINISTRY OF ENERGY, COMMUNICATIONS AND MULTIMEDIA 1 PRESENTATION OF PERSONAL DATA PROTECTION BILL PRESENTATION OF PERSONAL DATA PROTECTION BILL.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
THE PERSONAL DATA PROTECTION ACT 2010: ISSUES & IMPLICATIONS
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
The Protection of Personal Information Bill 13 February
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
Data protection—training materials [Name and details of speaker]
Sharing Information Legally Lindsay Ould London Borough of Lewisham.
Privacy and Personal Information. WHAT YOU WILL LEARN: What personal information is. General guidelines for the collection of personal information. Your.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Understanding Privacy An Overview of our Responsibilities.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Personal Data Protection
Monique Jefferson & Nadine Mather
HIPSSA Project PRESENTATION ON SADC DATA PROTECTION MODEL LAW
Data Protection: The Law
Privacy principles Individual written policies
Issues of personal data protection in scientific research
General Data Protection Regulation (GDPR)
IT Applications Theory Slideshows
Data Protection The Current Regime
General Data Protection Regulation
Data Protection Act 1988 and Data Protection (Amendment) Act 2003
PERSONAL DATA PROTECTION ACT 2010
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
New Data Protection Legislation
G.D.P.R General Data Protection Regulations
Data Protection principles
HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Namibia ICT Ministry and Data Protection Stakeholders.
Relocation CARNIVAL come one…come all
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
The activity of Art. 29. Working Party György Halmos
Data Protection Act 1988 and Data Protection (Amendment) Act 2003
Information Handling Research Student Induction Day
PERSONAL INFORMATION BILL
The EDPS: competences and processing of personal data in EU funds
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
Presentation transcript:

HIPSSAPROJECT Support for Harmonization of the ICT Policies in Sub-Sahara Africa Meeting with Data Protection Law Stakeholders 28/29 th August, 2013 PRESENTATION ON SWAZILAND DATA PROTECTION LAW (TRANSPOSITION) Kuena Mophethe ITU International Legal Expert on Data Protection Gcinaphi Mndzebele ITU National Legal Expert: Data Protection

Summary of the Content Background to Data Protection Law and Transposition (Mission 1) Overview of National Assessment(Mission 1) Transposition Process Overview of Data Protection Bill Points for Discussion Points for Discussion

Purpose of Data Protection Law Harmonised approaches Give effect to the right to privacy ICT technology developments impacts on the right to the protection of personal data. Illegitimate and unlawful monitoring of individuals Automated decision making Data protection regulation - strike a balance in ensuring that the benefits of using information and communication technologies do not translate into weakened protection of personal data Data Protection Authority establishment Regulation of trans border flow

Objectives of SADC Model Law Give effect to principles of data protection Place limitations on the processing of personal data Provide for the rights of the data subject Define the responsibilities of the Data Controller Establishment of the Data Protection Authority  Combat violations of privacy likely to arise from the collection, processing, transmission, storage and use of personal dataactivities

National Assessment The local expert gave and overview of existing laws and policies Account taken that no specific legislation on data protection exists

Data Protection Bill Approach to Transposition Drafting of a new Bill Customised to Swaziland without departing from the Model law Harmonization Clarity of definitions and concepts; Modifications pertaining to the Authority;

PART I - PRELIMINARY Citation and commencement Interpretation Application of the Act: To data controllers, to all forms of personal information Exemptions: The Act does not apply to the processing of personal information – in the course of a purely personal or household activity which has been de-identified to the extent that it cannot be re-identified; or by or on behalf of the State and involves national security and defence or public safety; which has been exempted under this Act or sector specific legislation

Part I Interpretation/Definitions Defining personal information: information about an identifiable individual that is recorded in any form, including, without restricting the generality of the foregoing:- information relating to the race, national or ethnic origin, religion, age or marital status of the individual; information relating to the education or the medical, criminal or employment history of the individual or information relating to financial transactions in which the individual has been involved; any identifying number, symbol or other particular assigned to the individual; the address, fingerprints or blood type of the individual; the name of the individual where it appears with other personal information relating to the individual or where the disclosure of the name itself would reveal information about the individual; correspondence sent to a data controller by the individual that is explicitly or implicitly of a private or confidential nature, and replies to such correspondence that would reveal the contents of the original correspondence; and the views or opinions of any other person about the individual.

Processing of personal information processing: refers to any operation or set of operations which is performed upon personal information, whether or not by automated means, such as obtaining, recording or holding the data or carrying out any operation or set of operations on data, including – (a) organization, adaptation or alteration of the data; (b) retrieval, consultation or use of the data; or (c) alignment, combination, blocking, erasure or destruction of the data

Sensitive personal information “sensitive personal information” (a) refers to genetic data, data related to children, data related to offences, criminal sentences or, biometric data as well as, if they are processed for what they reveal, personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, affiliation, trade-union membership, gender and personal information concerning the health or sex life of the individual (b) refers also to any personal information otherwise considered by Swaziland law as presenting a major risk to the rights and interests of the data subject, in particular unlawful or arbitrary discrimination.

Part II Data Protection Authority Establishment of the Data Protection Authority Disqualification from office Functions of the Authority Tenure of office Allowances of the members of the Authority Funds of the Authority Audit of Accounts Protection of the Authority Duty of confidentiality

Part III Protection of personal information Processing of personal information Minimality: Personal information may only be processed if, given the purpose for which it is processed, it is adequate, relevant and not excessive Collection directly from the data subject Purpose specification and further processing limitation Security measures on integrity of personal information Information processed by an agent of the data controller

Part III (continued) Information processed by an agent of the data controller: process such information only with the knowledge or authorisation of the data controller; and treat such personal information as confidential. Security measures regarding information processed by an agent: A data controller ensures that a data processor processing for or on his behalf establishes and maintains the security measures referred to in the Act Contract exists between controller and processor Notification to the Authority and to the data subject Notification of security compromises: To the Authority and the data subject Quality of information: personal information to be complete, accurate, not misleading and kept up to date; Regard be had to the purpose for which personal information was collected. Access to and challenges of personal information Correction of personal information Data controller to give effect to principles Prohibition on processing of sensitive personal information

Part IV Exemptions from protection on processing of personal information Exemption on data subject’s spiritual, religious or philosophical beliefs Exemption on data subject’s race Exemption on data subject’s trade union membership Exemption on data subject’s political affiliation Exemption on data subject’s health or sexual life Exemption on data subject’s criminal behaviour General exemption on sensitive personal information Authorisation by the Authority Exemption for processing of personal data for historical, statistical and research purposes

Part V Enforcement Complaints Investigation by the Authority No action by the Authority Pre-investigations by the Authority Investigation proceedings by the Authority Matters exempt from search and seizure Parties to be informed of developments during and as a result of the investigation Enforcement notice Cancellation of an enforcement notice Reviews and appeals Civil remedies

Part VI General Provisions Unsolicited electronic communications: A data subject is entitled any time by notice to a data controller to require the data controller to cease, or not to begin, processing of personal data in respect of which he is the data subject for the purposes of direct marketing. Automated decision making: Subject to qualifications/exceptions, a person may not be subjected to a decision which has legal effect on him, or which affects him significantly, based solely on the automated processing of personal information intended to provide a profile of certain aspects of his personality or personal habits/ Notifications Codes of Conduct: The Authority may, from time to time, issue, approve, amend or revoke a code of conduct. Offences and penalties Regulations Transitional arrangements

Limitations on Trans border flow Member State with Harmonised Law recipient establishes that the data is necessary for the performance of a task carried out in the public interest pursuant to the lawful functions of a data controller legitimate interests of data subject not prejudiced subject to conditions

Limitations on Trans border flow Non-Member State with Harmonised Law/ Third Countries adequate level of protection is ensured in the country of the recipient and the data is transferred solely to permit processing otherwise authorised to be undertaken by the controller subject to due diligence assessment and further conditions

Due diligence assessment assessed in the light of all the circumstances surrounding the relevant data transfer(s), particular consideration to be given to the nature of the data, the purpose and duration of the proposed processing, the recipient’s country, the relevant laws in force in the third country and the professional rules and security measures which are complied with in that recipient’s country

Authority’s discretion The Authority may: establish the categories of processing for which and the circumstances in which the transfer of personal data to countries outside (i) Swaziland and (ii) SADC is not authorized authorize a transfer or a set of transfers of personal information to a recipient country outside Swaziland or SADC which does not in its laws ensure an adequate level of protection, if the controller satisfies the Authority that it shall ensure adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of the data subjects concerned, and regarding the exercise of the data subject’s rights such safeguards can be appropriated through adequate legal and security measures and contractual clauses in particular

Thank you Mrs. Kuena Mophethe ITU International Expert: Data Protection Law Ms. Gcinaphi Mndzebele ITU National Expert: Data Protection Law