1 1 Legal aspects of incident reporting and data collection : Fear of the Dark? Meeting on “Incident Reporting in Radiotherapy” 3rd of September – Federal.

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
The Data Protection (Jersey) Law 2005.
Signature (unit, name, etc.) Introduction to biometrics from a legal perspective Yue Liu Mar NRCCL, UIO.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection and Records Management
The European Union legal framework for clinical data access: The European Union legal framework for clinical data access: potential challenges and opportunities.
ILONA GAVRONSKA GROUP IL-41 INTERNATIONAL LAW DEPARTMENT KYIV NATIONAL ACADEMY OF SCIENCES OF UKRAINE KYIV UNIVERSITY OF LAW.
Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005
Data Protection Overview
Data Protection for Church of Scotland Congregations
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
European data protection and privacy regulations Johny GASSER Orange Business Services – Consulting & Solutions Integration International Cyber Center.
HIPAA PRIVACY AND SECURITY AWARENESS.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
The Data Protection Act 1998 The Eight Principles.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection Act AS Module Heathcote Ch. 12.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
WHOIS data The EU legal principles ICANN - GNSO meeting 2 March 2004 George Papapavlou, European Commission ICANN - GNSO meeting 2 March 2004 George Papapavlou,
Ioannis Iglezakis Data Protection. Definition of Data Protection The legal protection of individuals with regard to automatic processing of personal information.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
The EU General Data Protection Regulation Frank Rankin.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
František Nonnemann Skopje, 10th October 2012 JHA Data protection and re-use of PSI as a tool for public control–CZ approach.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Personal Data Protection
Issues of personal data protection in scientific research
General Data Protection Regulation
Data Protection Legislation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
New Data Protection Legislation
State of the privacy union
G.D.P.R General Data Protection Regulations
Data Protection principles
Relocation CARNIVAL come one…come all
Report on data protection legislation Case of Romania
GDPR Workshop MEU Symposium Prague 2018
Information Handling Research Student Induction Day
PERSONAL INFORMATION BILL
Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Legal Basis: CRITERIA FOR MAKING DATA PROCESSING LEGITIMATE
Student Data Privacy: National Trends and Wyoming’s Role
Presentation transcript:

1 1 Legal aspects of incident reporting and data collection : Fear of the Dark? Meeting on “Incident Reporting in Radiotherapy” 3rd of September – Federal Agency for Nuclear Control

Clear up misunderstanding: scope of our Data Protection Act Privacy Protection of privacy(1) in relation to the processing of personal data (2) 2 Privacy (1) Data Protection (2) … …

1. Privacy: article 8 ECHR – art. 22 Const. Protection of privacy “Everyone has the right to respect for his private and family life, his home and his correspondence” Private life: cultivation, serenity, secrecy, isolation,… Family life: marriage, living together, starting a family... Direct effect – horizontally/vertically Important: protection of privacy is not absolute 3

Specific legal texts Besides the general provisions of article 8 ECHR and article 22 Constitution, there are several specific legal provisions which protects (certain aspects of) privacy F.e.: Act 10/4/1990 concerning private security, Act 18/7/1991 concerning private detectives, Data Protection Act, Camera Act, Act 30/6/1994 concerning telephone tap,... 4

2. Data Protection Act Act of 8 December 1992 on the protection of privacy in relation to the processing of personal data Protects the citizen against the use of (his) personal data States the rights and obligations of the person who’s data is being processed as of the processor Just a part of “privacy” Penal act (fines) 5

Personal data? any information relating to an identified or identifiable natural person Identifiable = one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, psychological, mental, economic, cultural or social identity No legal person (f.e.: company) F.e.: name, photo, telephone number (private/work), national register number, banc account number, adress, fingerprint, code, licence plate,... 6

Personal data versus anonymous data Anonymous data = data that cannot be related to an identified or identifiable person and that is consequently not personal data Encoded data = personal data that can only be related to an identified or identifiable person by means of a code 7

Processing? any operation or set of operations which is performed upon personal data, whether or not by automatic means F.e.: collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by means of transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction of personal data 8

Filing system? any structured set of personal data which is accessible according to specific criteria structured set of personal data Logical classification Systematic consultation of personal possible accessible according to specific criteria Name National register number... 9

Controller? any natural or legal person, un-associated organization or public authority which alone or jointly with others determines the purposes and means of the processing of personal data F.e.: doctor, company, local authority, non profit organisation,... Important: controller has to comply with all obligations of the Data Protection Act ( = responsability) ( processor) 10

Scope Data Protection Act Processing of personal data (wholly of partly) by automatic means Processing of personal data by non automatic means but only Which forms part of a filing system or Is intented to form part of a filing system 11

Principle of finality Personal data has to be processed for specified, explicit and legitimate purposes A further processing can (only) be considered compatible with the original purpose(s), considering The reasonable expectations of the data subject or The legal or regulatory provisions 12

Principle of proportionality Personal data has to be adequate, relevant and not excessive in relation to the purpose(s) of the processing Personal data has to be kept in a form that allows for the identification of data subjects, for no longer than necessary with a view to the purposes for which the data is collected or further processed 13

When can you proces personal data? “Normal” personal data: 6 cases (exhaustive list!): consent necessary for the performance of a contract necessary for compliance with a legal obligation necessary in order to protect the vital interests necessary for the performance of a task carried out in the public interest or in the exercise of the official authority promotion of the legitimate interests of the controller (balance of interest) 14

Special processings are prohibited… but… Special processings? Processing sensitive personal data Processing health-related personal data Processing of judicial personal data 15

Health-related personal data No definition In practice: all personal data concerning the former, present or future physical or mental state of health Processing prohibited but prohibition does not apply in some cases (exhaustive list), f.e.: the processing is necessary for the promotion and protection of public health, including medical examination of the population the processing is necessary for the prevention of imminent danger the processing is necessary for the purposes of preventive medicine or medical diagnosis, the provision of care or treatment to the data subject, or the management of health-care services in the interest of the data subject... 16

Always under the responsibility of a health-care professional, except When there is a written consent When the processing is necessary for the prevention of imminent danger or for the mitigation of a specific criminal offence Right of access Direct Through a health-care professional after a demand of the data subject or de controller 17

Notification with the Privacycommission Notification for any purpose or set of related purposes for which wholly or partly automatic operations are carried out Controller has to notify Notification prior to processing Content notification = legally determined Modification of notification if important information changes By paper (125 euro) or via internet (25 euro) List of exemptions by Royal Decree Notification is not intended to request an authorization or permission, but only to notify a processing = apart from very exceptional cases, in Belgium no authorization is needed to process personal data 18

Content of the notification the name of the processing the purposes the categories of data being processed (not the data themselves) any possible legal or regulatory basis for the processing the categories of recipients to whom the data may be disclosed the safeguards established for disclosure to third parties the way in which the data subjects are informed of the processing the person the data subjects may address to exercise their right of access and the measures taken to facilitate this 19

the categories of data intended to be transferred abroad, the countries of final destination and the reason why the data are transferred even if the destination countries do not ensure an adequate level of protection the period of time after which the data must no longer be stored used or disseminated organizational and technical security measures 20

Public register Data base of the notifications Aim: make the processings of personal data in Belgium more transparant: Data subject can look up information about a processing Privacycommission can audit Accessible to all: through the internet, in our offices, request (extract) The notification contains a description of the characteristics of the processing 21

Mission Privacycommission Since 1/01/2004: independent supervisory authority under the auspices of the Belgian House of Representatives (before that: Ministry of Justice) The Commission's mission is to ensure that privacy is respected when personal data are processed: Opinion and recommandation Authorization (by sector committees) Inspection, supervision and complaints Information and assistance 22

Authorizations – sector comittees Specific sector committees have been established Rapid evolution information society Multiplicity of questions (data subjects and governement) The rise of more complex cases Advantage Specific experts from particular domains Different sector committees (6) Important: Sector Committee of Social Security and of Health 23

Role of such a committee Grants an authorization when data is being exchanged electronically in the network of social security of health F.e.: every exchange of personal data by or to the E-health platform Checks the documents and grants yes or no an authorization 24

In practice To go through all this information again (but on your own pace): adress for questions: Internet demo Website Notification Sector committees 25