Presented by Mrs Drudeisha Madhub (Data Protection Commissioner) Tel: +230 201 36 04 Helpdesk: +230 203 90 76 Fax: +230 201.

Slides:



Advertisements
Similar presentations
Module N° 4 – ICAO SSP framework
Advertisements

Division: EIDD WTO TBT Workshop on Good Regulatory Practice March 2008 Focus on Transparency and Consultation.
The Equality and Human Rights Agenda and the Possible Implications for Regulation David Darton, Director of Foresight, Equality and Human Rights Commission.
1 The Data Protection Officer at work Experience, good practices and lessons learnt Pierre Vernhes – former DPO at the Council of the EU Workshop on Data.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Child Safeguarding Standards
SEMINAR NAIC/ASSAL/SVS REGULATION & SUPERVISION OF MARKET CONDUCT © 2014 National Association of Insurance Commissioners Overview and Purpose of Market.
Cyber Security and Data Protection Presented by Mrs Drudeisha Madhub (Data Protection Commissioner ) Tel: Helpdesk:+230.
BIOMETRICS, CCTV & DATA PROTECTION By Drudeisha Madhub Data Protection Commissioner Date:
Training on Data Protection Functions of the Data Protection Office.
ICS 417: The ethics of ICT 4.2 The Ethics of Information and Communication Technologies (ICT) in Business by Simon Rogerson IMIS Journal May 1998.
Domestic Workers Research Project Presentation to: Parliamentar y Portfolio Committee on Labour 2 August 2011.
Children’s Social Care Workload Management System (WMS) A Two-fold approach DSLT 16 th November 2010 Updated with new SWRB standards.
Scoping study for Improving Transparency through Citizen Charters in Serbia Transparency Serbia Presentation September 27 th 2010.
Introducing Regulatory Impact Analysis into the Turkish Legal Framework Prime Minister’s Office, Better Regulation Group The Project Implementation Team.
6/1/2015MINISTRY OF ENERGY, COMMUNICATIONS AND MULTIMEDIA 1 PRESENTATION OF PERSONAL DATA PROTECTION BILL PRESENTATION OF PERSONAL DATA PROTECTION BILL.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
TITLE:- “How To Ensure Effective compliance with the Data Protection Act” PRESENTED BY:- The Commissioner, {Mrs D. Madhub} TO:- Lamco Insurance Ltd ON.
James Ennis, Department of State, USA ITU-D Question 22/1 Rapporteur.
Jasminka Dzumhur, Ombudsperson of BiH “Role of national human rights institutions” Ljubljana, 1. December 2014.
DATA PROTECTION OFFICE
A Common Immigration Policy for Europe Principles, actions and tools June 2008.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
Guidance for AONB Partnership Members Welsh Member Training January 26/
OUTLINE Introduction Background of Securities Regulation Objective of Securities Regulation Violations under the Securities Industry Law The Securities.
Emtel 4G LTE NETWORK. “ The DPO Regulatory Perspective about Cloud Solutions” Presented by Mrs Drudeisha Madhub (The Commissionner )
VICTIMS’ RIGHTS New EU Directive establishing minimum standards on the rights, support and protection of victims of crime 20 September 2012 CABVIS Conference.
1 February 2005 Briefing Sessions Draft Regulations Using Water for Recreational Purposes.
EU perspective on occupational health and safety - role and place of unions Károly György Kiev, December December Károly György, MSZOSZ.
1 Building the Privacy culture, starts with the youngsters and their education 20 th and 21 st June 2013 Zagreb, Croatia.
Environmental Management System Definitions
Regulatory Institutions in Turkey. Regulatory Institutions Central Bank of Turkey Banking Supervision and Regulatory Institutions Capital Markets Board.
European Commission Rita L’ABBATE Legal aspects linked to internal market DG Enterprise and Industry MARKET SURVEILLANCE COMMUNITY FRAMEWORK UNECE “MARS”
State Agency on Public Procurement and Material Reserves under the Government of the Kyrgyz Republic Public Procurement System of the Kyrgyz Republic.
State of implementation of the decision III/6f regarding Ukraine (MOP 2, June, , 2008, Riga, Latvia)
16-17 November 2005 COSCAP – NA Project Steering Group Guangzhou, China 1 Co-operating with the European Aviation safety Agency.
Eurostat/UNSD Conference on International Outreach and Coordination in National Accounts for Sustainable Development and Growth 6-8 May, Luxembourg These.
International Atomic Energy Agency Roles and responsibilities for development of disposal facilities Phil Metcalf Workshop on Strategy and Methodologies.
PRESENTED AT THE STAKEHOLDERS FORUM ON QUALITY OF SERVICE AND CONSUMER EXPERIENCE LAICO REGENCY HOTEL Creating Space for Consumer Rights in.
OFFICIAL – SENSITIVE English Language Requirement for Public Sector Workers Draft Code of Practice Consultation.
Regulatorna agencija za komunikacije Регулаторна агенција за комуникације Communications Regulatory Agency Accessibility and ICT in Bosnia and Herzegovina.
Women Inclusion in decision making structures for public sector Tilitonse Thematic call guidance session Fannie Nthakomwa December 2015.
The EU and Access to Environmental Information Unit D4 European Commission, Directorate General for the Environment 1.
TEQSA The Tertiary Education Quality and Standards Agency.
Future needs for capacity building and recommendations to the OIE Dr Sarah Kahn Consultant to the OIE
APEC Engineers Workshop Legal Considerations - Central Register Sept 2015 Angela Frawley, General Counsel.
1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Council of Europe Child Participation Assessment Tool Agnes von Maravic Children’s Rights Division Council of Europe Based on slides prepared by Gerison.
New approach in EU Accession Negotiations: Rule of Law Brussels, May 2013 Sandra Pernar Government of the Republic of Croatia Office for Cooperation.
Reforms in the Albanian Public Procurement System 7 th Regional Public Procurement Forum Tbilisi, Georgia May 16-19, 2011 PUBLIC PROCUREMENT AGENCY 1.
Harmonised use of accreditation for assessing the competence of various Conformity Assessment Bodies Dr Andreas Steinhorst, EA ERA workshop 13 April 2016,
TAIEX-REGIO Workshop on Applying the Partnership Principle in the European Structural and Investment Funds Bratislava, 20/05/2016 Involvement of Partners.
7/7/20161 The Public Sector Equality Duty for Schools in England Jonathan Timbers – Policy Manager, PSED Team, Equality and Human Rights Commission.
Data Protection Officer’s Overview of the GDPR
INTERNAL AUDIT SERVICE of the REPUBLIC OF CYPRUS
(Portfolio Committee on Justice and Correctional Services)
General Data Protection Regulation
Threats and Challenges to Data Protection and Privacy :-
Establishing the Infrastructure for Radiation Safety Preparatory Actions and Initial Regulatory Activities.
GDPR support January GDPR support January 2018.
The Public Sector Equality Duty
General Data Protection Regulation
Council of Europe Child Participation Assessment Tool
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
The role of the ECCP (1) The involvement of all relevant stakeholders – public authorities, economic and social partners and civil society bodies – at.
The Public Sector Equality Duty
AERODROME CERTIFICATION COURSE
General Data Protection regulation (GDPR)
The e-government Conference main issues
Presentation transcript:

Presented by Mrs Drudeisha Madhub (Data Protection Commissioner) Tel: Helpdesk: Fax: Website: Address: 4th Floor, Emmanuel Anquetil Building, Port Louis

The ICT Sector in Mauritius ICT Sector as the 3 rd pillar of Mauritius economy Aim is to make the ICT sector the first pillar Reinforces the importance of the country to have an efficient and internationally recognised data protection framework for securing the right investment with a growing ITES-BPO sector.

Data Protection Law Right to privacy is expressed in sections 3 and 9 of the Constitution and article 22 of the Civil Code Hence, the Data Protection Act (DPA) was enacted in 2004 and proclaimed in DPA provides the legal framework to ensure that personal information is handled properly

Data Protection Office Vision  A society where Data Protection is understood and practiced by all  The right to privacy and data protection is primordial to the sanctity of any modern democracy  The adoption of clear procedures for the collection and use of personal data in a responsible, secure, fair and lawful manner, by all data controllers and data processors

Role of the Data Protection Office a) Ensure compliance with the Data Protection Act and its regulations b) Issue or approve codes of practice/guidelines for the purposes of this Act c) Create and maintain a register of all data controllers; and data processors

Role of the Data Protection Office d) Exercise control on all data processing activities e) Promote self-regulation among data controllers and data processors f) Investigate any complaint or information which give rise to a suspicion that an offence, under this Act may have been, is being or is about to be committed g) Bring to the knowledge of the general public the provisions of this Act

Role of the Data Protection Office h) Undertake research into, and monitor developments in, data processing i) Examine any proposal for data matching or data linkage that may involve an interference with, or may otherwise have adverse effects on the privacy of individuals j) Co-operate with supervisory authorities of other countries, to the extent necessary for the performance of its duties

Role of the Data Protection Office k) Carry out periodical security checks and compliance audits

Steps being taken by Mauritius Government for an improved regulatory framework Consideration for the signing and/or ratification of the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) Currently, being analysed.

Steps being taken by Mauritius Government for an improved regulatory framework To achieve adequacy with the European Union An EU consultant was appointed by the European Commission to identify the deficiencies in the DPA through the CRID report A second EU consultant was appointed by the European Delegation in Mauritius on the amendments to be brought to the DPA. A draft amendment bill has been finalised.

Steps being taken by Mauritius Government for an improved regulatory framework Inclusion of data protection in the draft e-government strategy Formulate and Implement Data Sharing Policy Extract below: ‘’G4: Formulate and Implement Data Sharing Policy G5: Set up Government Service Platform and sharing of citizens’ data with Government Agencies Government holds huge quantities of data on citizens, businesses and land which will benefit from being organized centrally and shared among Government Agencies. As an example, citizen data will be captured once at the Civil Status Division and shared among Government systems. The sharing of data will be governed by a policy that ensures compliance with Data Protection Act and appropriate IT security requirements. One of the instruments of the Policy is the Government Service Platform that will specifically address sharing of citizen data. ’’

Steps being taken by the DPO for an improved regulatory framework Participation in Projects The Data Protection Commissioner has submitted her views on the enactment of a Child Online Safety Bill, enactment of an anti-spam legislation, introduction of cryptographic laws in Mauritius and the Mauritius National Identity Card (MNIC), amonsgt many others.

Steps being taken by the DPO for an improved regulatory framework Co-operation with other countries The Data Protection Commissioner is a member of the Francophone Association of Data Protection Authorities (AFAPDP) and is finalising membership with the GPEN group. The office has been accredited on 23 September 2013 in Warsaw, Poland at the 35 th International Conference for Privacy and Data Protection Commissioners Has been chosen to host the 36 th Edition of the Conference from 13 to 16 October 2014 and the first conference in Africa

Steps being taken by the DPO for an improved regulatory framework Ongoing Sensitisation Carrying out mass sensitisation programmes on MBC television to promote data protection awareness Organising and participating in workshops Conducting presentations in Ministries and organisations Preparation of booklet on data protection for primary school and course materials for a Certificate course at tertiary level and guidelines

Steps being taken by the DPO for an improved regulatory framework Envisaging to purchase forensic software tools to assist investigations for the creation of a forensic lab for research purposes and treatment of forensic evidence Computerising our services.

New technological advancements Concept of Cloud Technology and Open Data Becoming more common and the choice of many organisations because they can be rapidly provisioned and released with minimal management effort Caution : Accountability for security and privacy in public clouds remains in principle with the organisation, the data controller. The data processor, the cloud provider is also bound by the obligations of the data controller by a written contract. Privacy by design approach should be adopted by cloud providers to protect data

New technological advancements Precautions from a data protection perspective: Identify security, privacy and organisational requirements to be met by the cloud provider Perform risk and privacy impact assessments Establish a Service Level Agreement (SLA) on the expected level of service to be delivered including privacy and security provisions to secure the responsibility of cloud providers Put in place audit mechanisms to ensure that organisational practices are followed

New technological advancements Precautions from a data protection perspective: Ensure availability of critical data during an intermediate or prolonged disruption or a serious disaster Ensure that resources made available to the cloud provider under the SLA are returned in a usable form and confirm with evidence that information has been properly expunged

Guideline Privacy Enhancing Technologies – An absolute Necessity for Effective Compliance with Data Protection Laws, Volume 7

Strength Builds trust for safe and secure processing of personal data and protects the human right to privacy. However, data protection laws, although technologically neutral, should be relevant, up to date and applicable to the current technological world, user friendly with simple terms to avoid interpretation complexities.

Limitation Some sections are still vague and subject to confusion – thus amendments have been proposed to the local DPA. The DPA applies only for the protection of personal data. A freedom of information legislation is required to ensure that all types of information are protected. An Information Commissioner will have more enlarged powers.