Data Protection Issues from a Practical Perspective Balázs Fazekas Réczicza White & Case LLP VIII. Annual Conference on ICT Law April 20, 2007, Pécs.

Slides:



Advertisements
Similar presentations
FERPA - Sharing Student Information
Advertisements

©2008 Perkins Coie LLP Game Industry Roundtable Privacy Developments for the Game Industry Thomas C. Bell September 24, 2008.
Confidentiality and HIPAA
The Problem Solvers TM Privacy Rights: Minors and Parents Michael J. Hewitt Marcel Daigle Singleton Urquhart LLP.
The Advisers Act Custody Rule
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
FERPAFERPA Family Educational Rights and Privacy Act.
Charles E. Constantin Director, Senior Bank Regulatory Compliance Officer Royal Bank of Canada, RBC Capital Markets Institute of International Bankers.
Hong Kong Privacy Code on Human Resource Management
EU: Bilateral Agreements of Member States. Formerly concluded international agreements of Member States with third countries Article 351 TFEU The rights.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Per Anders Eriksson
Anomalous Aspects of Transfer of Personal Data from the E.U. to the U.S. Stephen R. Bell Willkie Farr & Gallagher ABA Section of International Law New.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Keeping on top of the Cloud - Compliance from a Regulator’s Perspective Henry Chang, IT Advisor Office of the Privacy Commissioner for Personal Data, Hong.
Tina Kraigher and Milena Podjed-Fabjančič 18 April 2010 Processing of Telephone Traffic Data of Employees ( a Case Study )
Vendor Risk: Effective Management is Essential
House Committee on Business and Industry House Bill Implementation of Closed Account Notification System Texas Department of Banking April 22, 2008.
LAW SEMINARS INTERNATIONAL New Developments in Internet Marketing & Selling November 13 & 14, 2006 San Francisco, California Moderator : Maureen A. Young.
13 July 2006Susan Joseph Health Privacy It’s My Business Health Records Act 2001 (Vic) eReferral Service Co-ordination System.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
Attorney-Client Privilege and Privacy Considerations Between US Corporations & Foreign Affiliates General Counsel Conference, Washington, D.C. October.
Ide kerülhet az előadás címe CCTV operation at work Belgrade, 11 th April 2013.
Advanced HIPAA Issues for Biotech and Life Sciences Companies: Mark E. Schreiber Palmer & Dodge LLP 111 Huntington Avenue Boston, MA
Advice for Internal Compliance Programmes Billy Au Principal Trade Officer Head of Strategic Trade Controls Branch Trade and Industry Department The Government.
LOGO The collective agreement. The labour contract.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
Data Protection Act AS Module Heathcote Ch. 12.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
International Investigations: Issues to Consider When Conducting or Defending Against an FCPA Investigation Outside the United States Presented by: Sandee.
The Framework for Privacy Policies in the UK: Is telling people what information is gathered about them part of the framework? Does it need to be? Emma.
FAMIS CONFERENCE Mari M. Presley, Assistant General Counsel Florida Department of Education June 12, 2012.
Supervision SICOR Securities, Inc.. Why? NASD 3110 requires the firm to “…establish and maintain a system to supervise the activities of each registered.
Unit 9 Seminar Business Organizations. Things to do this unit: UNIT 9 – Read Chapter 13 and 14 – Respond to the Discussion Board – Attend the Weekly Seminar.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Connecting for Health Common Framework: the Model Contract for Health Information Exchange Gerry Hinkley com July 18, 2006 Davis Wright.
1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.
Data protection—training materials [Name and details of speaker]
Protection of Personal Information Act An Analysis on the impact.
Improving Compliance with ISAs Presenters: Al Johnson & Pat Hayle.
František Nonnemann Skopje, 10th October 2012 JHA Data protection and re-use of PSI as a tool for public control–CZ approach.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Welcome to Workforce 3 One U.S. Department of Labor Employment and Training Administration Webinar Date: Thursday, October 23, 2014 Presented by: Division.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
TRANSBORDER TRANSFER OF PERSONAL DATA OUT OF THE REPUBLIC OF SERBIA Milica Basta Senior Adviser DPA Serbia Sarajevo May 2016.
Nassau Association of School Technologists
DOL Employee Benefit Plan Audits & How to Prepare
Surveillance around the world
INTERCONNECTION GUIDELINES
Whistleblower Program
General Data Protection Regulations: what you really need to know
Data Protection The Current Regime
General Data Protection Regulation
Information Governance and Data Privacy: A World of Risk
Data Protection Legislation
Data Protection & Freedom of Information- An Introduction
Bob Siegel President Privacy Ref, Inc.
The Mutual Recognition Regulation
Current Privacy Issues That May Affect Your Credit Union
Data Archives and the ethics of Research Data
General Data Protection Regulation
Bonnie Weiss McLeod Cooley LLP
Data transfers to non-EU countries under the new GDPR
General Date Protection Regulation
PRESENTATION OF MONTENEGRO
General Data Protection Regulation (GDPR)
EU Data Protection Legislation
Presentation transcript:

Data Protection Issues from a Practical Perspective Balázs Fazekas Réczicza White & Case LLP VIII. Annual Conference on ICT Law April 20, 2007, Pécs

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 2 Issues Raised  Incomplete harmonization of community law  Personal data, privacy, company interest  Data Transfers  Within group  between authorities  Chain of transfers  Rights of data subjects to enforce agreement  Law office as data controller  Online environment  Miscellaneous issues

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 3 1.Incomplete harmonization of community law  Terms, definitions  Data controller – “adatkezelő” really?  Data processor – “adatfeldolgozó” really?  What does a data controller/processor do exactly?  Decisive element should be: Who is in charge of making decisions on the use (processing) of the personal data  Relaxation of primary rules (examples)  Hungarian law: title for controlling: consent or law Directive: additional legitimate titles for data controlling (Article 7 of 95/46/EC Directive)  Hungarian law: information to data subject should be very specific to be eligible for a consent Directive: Softer information provision requirements (e.g., “categories” pf recipients of personal data – Article 10(c) of Directive)  What is realistically acceptable under Hungarian law? What is reasonably expected from data controller?  Example: existing client base, change of data processor. New consent?  Never tested before court

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 4 2.Personal data, privacy, company interest  What are the boundaries of personal data / private information / business information? Example: company needs to research in employee files (e.g., due to internal audit, responding to authority request, etc.). Files may contain (often in a single document or ):  personal data (own and third party)  private information (private secrets)  business information  Company has the right to access business information (only).  Common practical solution: company policy prohibits private use of office equipment  Is it enough? Still room for privacy? Objection on the basis of personal data of third parties?  Data protection commissioner’s position…

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 5 3.Data transfers – intra group transfers  Hungarian law does not recognize a group as a single entity. Some jurisdictions do.  In reality, multinational companies regularly transfer personal data within group (payroll functions, administration)  Recent phenomenon: shared services centers (outsourced administrative functions) – recipient and transferor of vast amount of personal data  Aim of data protection regulation is to protect data subjects. In the event of intra group transfer, the aim is not jeopardized  clear purpose of use  transparent flow of data  established interfaces between employee and company  But in Hungary, consent is required for such transfer  Practical solution:  Information: appropriate company policies  with proper provision of information to data subjects (employees)  remedy mechanism protecting data subjects (employees)  Consent: consent together with employment agreement, consent forms for third parties (e.g. customers, marketing  Problems: transfer requirement is triggered – painful, difficult to implement:  transfer of already existing third party personal data (e.g., escalation of consumer complaints to head office)  or database (e.g., pharmaceutical industry: marketing databases)

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 6 4.Data transfers – foreign authorities  Hungarian and foreign authorities are often not certain as to under what circumstances, and what scope of personal data may be transferred for purposes of mutual legal assistance  e.g. US listed/traded Hungarian companies: PSZAF – SEC (US maintains extra terrestrial jurisdiction in some cases)  Relevant bilateral agreements are not always clear. Inquiry should be made through Ministry of Justice  Under Hungarian law, the consent of data subject should be specific (including exact definition of the recipient authority). Reference to „foreign authorities” in general is not sufficient.

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 7 5.Data transfers – chain of transfers  Example: International network of offices, including Budapest, London New York, Singapore.  London office collects and aggregates personal data, forwards to New York or Singapore for further use (billing, administration).  Is London a controller or a processor?  London is within EEA, „level of protection” rules are not triggered  Does the Budapest office need to confirm if New York is registered as a Safe Harbour? What about Singapore?  Does Budapest need to be party to a data processing agreement under the EC standard contractual claues?

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 8 6.Rights of data subjects to enforce agreement  Standard contractual clauses (for transfer of personal data for data processing in other (non-EEA) country) provide remedies for the benefit of data subjects.  Does the agreement need to be registered by / notified to the data protection commissioner?  In some countries, yes.  Does the agreement need to be consented by or disclosed to the data subjects?  The agreement covers data subjects even withouth knowing about the agreement  Information on or an extract of the agreement should be provided upon request.

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 9 7.Law office as data controller  Under the Act on Attorneys, the attorney (law office) is de facto a data controller.  Co-existence of attorney regime and data protection regime:  Are there collisions between the two regimes? (E.g. security measures)  Attorney Act recognizes special forms, such as association of offices  Are associated offices data controllers? Are they entitled to receive personal data?  Transfer to foreign associated offices is a transfer to abroad?  Level of protection under other attorney secret regimes?  Client data vs third party data  Law office collects and uses various personal data:  client data – primarily for administration and billing purposes  third party data – counterparty in litigation, contact details in agreements, etc.  Is level of protection under the “attorney secret” regime sufficient, or consent?

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 10 8.Online environment  Consent together with registration or sign up.  Minors under 18 do not have legal capacity to make statements concerning their personal rights  Consent of parent is required  How to verify parent consent in online environment? How to act in a prudent manner?  Privacy policy, Terms of Use of online service  Service available in Hungary / Targeted to Hungarian users  Often not fully compliant with Hungarian data protection and online consumer protection laws.  More attention is required, more prudent localization practice  Jurisdiction issues: how to enforce anything against foreign online service?

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 11 9.Miscellaneous issues  Non direct marketing companies may be considered as direct marketing entities under Act CXIX of 1995 (e.g., pharmaceutical companies)  Should be prepared for opt-out requests, maintaning lists  Where is the right balance in practice?  Position of Data Protection Commissioner often liberal to the extreme, requires unreasonable efforts or compromise to implement in practice  Companies try to comply formally but with least burdens  Real-life practical solutions never tested before court, great amount of legal uncertainty (becomes extra cost)

WHITE & CASE LLP Data Protection Issues from a Practical Perspective 12 Worldwide. For Our Clients. White & Case, a New York State registered limited liability partnership, is engaged in the practice of law directly and through entities compliant with regulations regarding the practice of law in the countries and jurisdictions in which we have offices. Thank you for your attention! Balázs Fazekas Réczicza White & Case LLP 1061 Budapest, Andrássy út 11. Tel.: