A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.

Slides:



Advertisements
Similar presentations
Legal & Regulatory Compliance. Overview What types of information should be included? What issues or problems might there be? What benefits could be obtained?
Advertisements

Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
Administrative Systems and the Law What you need to know to produce an oral presentation for Unit 7 When the presentations will take place Resources you.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
The Data Protection (Jersey) Law 2005.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection & Freedom of Information The Practical Implications of Data Protection and Freedom of Information Caroline Dominey Data Protection Officer.
University of Sunderland Professionalism and Personal Skills Unit 11 Professionalism and Personal Skills Computer Legislation.
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Per Anders Eriksson
Transborder dataflows Flow of information across national borders Much of this data involves personal information.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The Data Protection Act
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
The Information Commissioner’s Office David Evans.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
The Data Protection Act 1998 The Eight Principles.
Professional Values and Basic Business Legislation.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
Data Protection Act AS Module Heathcote Ch. 12.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
What is personal data? Personal data is data about an individual which they consider to be private.
The Data Protection Act - Confidentiality and Associated Problems.
Why the Data Protection Act was brought in  The 1998 Data Protection Act was passed by Parliament to control the way information is handled and to give.
BTEC ICT Legal Issues Data Protection Act (1998) Computer Misuse Act (1990) Freedom of Information Act (2000)
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
Tad and Terry Legal Issues in ILP. 28 CFR Part 23 The federal rule that governs or provides guidance for these issues. § 23.3 Applicability: These policy.
ICT and the Law: We are going to look at 3 areas.  The Copyright, Design, and Patents Act controls Illegal Copying  The Computer Misuse Act prevents.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Twelve Guiding Principles for the Regulation of Surveillance Camera Systems Presented by: Alastair Thomas Date: 23 rd October 2013.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
THE DATA PROTECTION ACT Data Protection Act 1998 DPA 1. Reasons2. People3. Principles 4. Exemptions 4 key points you need to learn/understand/revise.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Data Protection Act (1998).
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
What is the Data Protection Act (DPA)? 1998 The Data Protection Act 1998 seeks to strike a balance between the rights of individuals and the sometimes.
Data Protection Philip Reed. Introduction What is data? What is data protection? Who needs your data? Who wants your data? Who does not need your data?
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Workshop on Privacy of Public Figures and Freedom of Information - Skopje, 9-10 October 2012.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Uses of brain imaging data: privacy and governance implications Dr. Hester Ward Medical Director, Information Services Division, (ISD) Consultant in Public.
European Data Protection Supervisor TAIEX Seminar - Belgrade 9 February 2009 Principles of data protection and international legal framework Alfonso Scirocco.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
HIPSSA Project PRESENTATION ON SADC DATA PROTECTION MODEL LAW
Data Protection Officer’s Overview of the GDPR
Data Protection: The Law
Data Protection: EU & International
General Data Protection Regulation
Data Protection Legislation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
Data Protection Act.
Data Protection and You
Identify the laws and guidelines that affect day-to-day use of IT.
What is the Data Protection Act (DPA)? 1998
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Presentation transcript:

A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal Justice Information Washington D.C. 31 May - 1 June 2000

A European View of Privacy Protection Information privacy - the European approach Some criminal justice case studies Relevance to the US The SEARCH Task Force Conclusion

The view from Manchester The UK Data Protection Commissioner : –is a statutory regulatory body –deals with information privacy –covers both public and private sectors –is based near Manchester UK

The view from Manchester The UK Data Protection Commissioner : –is a statutory regulatory body –deals with information privacy –covers public and private sectors –is based near Manchester UK Wilmslow London

The view from Manchester Member of the Task Force on Privacy and Criminal Justice Information Experience with: –general law on information privacy –its application in the criminal justice sphere –a proactive supervisory role –the European approach

The European approach to information privacy General law to protect personal data: –set of principles –rules for processing (including transfer overseas) –rights for individuals –legal remedies –independent supervision –enforcement mechanism

The European approach to information privacy General law to protect personal data: –set of principles –rules for processing (including transfer overseas) –rights for individuals –legal remedies –independent supervision –enforcement mechanism Personal data shall be processed fairly and lawfully processed only for specified, lawful and compatible purposes adequate, relevant and not excessive accurate and up to date kept for no longer than necessary processed in accordance with the rights of data subjects kept secure transferred outside the EU only if there is adequate protection

The European approach to information privacy General law to protect personal data: –set of principles –rules for processing (including transfer overseas) –rights for individuals –legal remedies –independent supervision –enforcement mechanism

The European approach to information privacy General law to protect personal data: –set of principles –rules for processing (including transfer overseas) –rights for individuals –legal remedies –independent supervision –enforcement mechanism Access Correction, blocking, deletion, destruction Preventing processing and automated decisions Compensation

The European approach to information privacy General law to protect personal data Underpins the approach to information privacy across all sectors

The European approach to information privacy General law to protect personal data Underpins the approach to information privacy across all sectors Business Commerce Finance Marketing Employment Taxation Social security Health Police Criminal Justice

The European approach to information privacy The EU Data Protection Directive: –applies to processing of personal data –establishes individual rights and legal remedies –sets out rules for legitimacy of processing, transfers to third countries, data quality, confidentiality and security –requires independent supervision

Balancing rights Individual’s rights: –to private life –to know –to freedom of expression Rights of others (other individuals, business, the state) Interests of society

Privacy and criminal justice - case studies Retention of criminal records Disclosures to the media Accuracy of criminal records HIV warning signals DNA database AFR fingerprint database

Information privacy protection Europe –omnibus law –harmonisation across the EU –sector specific codes –powerful supervisory authority –human rights issue US –sector specific law –federal and state initiatives –industry self- regulation –private right of action –commercial free speech issue

The practical questions What level of protection can I expect? How can I find out? Do I have any choice? Can I secure change? What remedies do I have? Can I safeguard my private life?

European approach - relevance to the US Globalisation International cooperation EU restriction on transfers of data –adequacy of protection –safe harbors?

The SEARCH Task Force Benefits from: –mix of interests –privacy advocates –privacy regulators –international participation A different perspective on the issues

Why does Europe not want to exchange records with the US?

“This is a free country, madam. We have a right to share your privacy in a public place.” Peter Ustinov

“This is a free country, madam. We have a right to share your privacy in a public place.” Peter Ustinov Not under European law!