Personal Data Protection in Russia: Trends of the Last Decade State University – Higher School of Economics, Russia Software Engineering Department Alexandra.

Slides:



Advertisements
Similar presentations
CcTLD Meetings Rome 2004 WHOIS & Data Privacy Jean-Christophe Vignes Registry Liaison Manager.
Advertisements

Becoming Social: Developing social media policy for government Theresa A. Pardo, Ph.D. Bahrain International eGovernment Forum April 10, 2013 © 2011 The.
Federal Budget Process Steve Kidd and Allison Boehm Budget and Program Analysis Staff April 2009.
Panel themes of the International Conference “Europe against Counterfeit Medicines” G.N. Gildeeva, Deputy head of the Department of Registration of Medicines.
6/1/2015MINISTRY OF ENERGY, COMMUNICATIONS AND MULTIMEDIA 1 PRESENTATION OF PERSONAL DATA PROTECTION BILL PRESENTATION OF PERSONAL DATA PROTECTION BILL.
Legal Issues and Export Controls Career-Ending Opportunities and Ways to Get Fitted for an Orange Jumpsuit David Lombard Harrison, Associate Vice President.
EU Information and Publicity Policy Claudia Salvi e Anna Claudia Abis Formez 8 May 2007.
Workshop on registered electronic mail policies and implementation Ankara, March 2015 Davide Mula REM country practice in legal infrastructure,
Ministry for Economic Development of the Russian Federation March 2010 Oleg Pak, Head of the Department for State Regulation of the Economy Formation of.
SEMINAR NAIC/ASSAL/SVS REGULATION & SUPERVISION OF MARKET CONDUCT © 2014 National Association of Insurance Commissioners Complaint Handling.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
1 China Internet Network Information Center ( CNNIC ) Administrative Practice of.CN Domain Names.
Ministry of Industry, Trade & Labor Head of Section in Charge of Foreign Workers Rights at Work The Role of a Governmental Ombudsman In Charge of Foreign.
Use of Electronic Digital Signature in the Russian Federation.
Technical Regulating in the Russian Federation and Adoption into Its National Laws of the Global Technical Regulations Established under 1998 Agreement.
Evgeny A. Gorbunov, General Director, Union of Aviation Industrialists
COMMISSION FOR PERSONAL DATA PROTECTION 14 TH Meeting, CEEDPA may, Kyiv LEGAL FRAMEWORK FOR DATA PROTECTION, COMPETENCES AND PRIORITIES OF THE COMMISSION.
COMMISSION FOR PERSONAL DATA PROTECTION, BULGARIA Central Eastern Europe Data Protection Authorities (CEEDPA) 15 th Meeting, th of April 2013, Belgrade.
Supporting Compliance: Effective Guidance and Advice to Business Giedrius Kadziauskas, Consultant, Inspection Reform and Better Regulation.
1 When hate speech tangles privacy... When hate speech tangles privacy...
STATUTORY STATEMENTS OF ACTUARIAL OPINION – Changes for Today and Tomorrow Tomorrow’s Model Law 2003 CLRS Chicago, IL.
Audit of Public Procurement
Intangible Technology Transfer and Catch-All Controls June 18, 2003 Timothy Clinton Export Policy Analyst U.S. Department of Commerce.
INTERNATIONAL COOPERATION PUBLIC CONSULTATION FIRST OVERVIEW EXPORTIC 27 March 2008 JF SOUPIZET HEAD OF INTERNATIONAL RELATIONS DG INFSO These view are.
The State Procurement Agency of the Republic of Azerbaijan Welcomes the participants of the 11 th Public Procurement Knowledge Exchange Forum “Procurement.
Judgment of the Court of the European Union (Grand chamber) Retention of Telecommunications Data Holly Raiche Director, Internet Society of Australia.
A.ABDULLAEV, Director of the Public Fund for Support and Development of Print Media and Information Agencies of Uzbekistan.
National Statistical Committee of the Kyrgyz Republic Science, technology and innovation statistics in the Kyrgyz Republic Training workshop for ECO countries.
How SAIs influence Good Governance in the Public Administration: an experience of the Accounts Chamber of the Russian Federation The Accounts Chamber of.
Trade Union Training on Social Security and Social Protection INTRODUCTION TO INTERNATIONAL LABOUR STANDARDS Turin, 5 May 2004.
Regulatory requirements in the current programming period Funchal, 18 November 2010.
Ministry of Energy, Development and Environmental Protection of the Republic of Serbia Development of the Ecoregister, a national metaregister for environmental.
1 Information Sharing Environment (ISE) Privacy Guidelines Jane Horvath Chief Privacy and Civil Liberties Officer.
1 Ensuring the protection of bidders’ rights.  The Federal Law of № 94-FZ "On placing orders for goods, works and services for state and municipal.
STATE OF ARIZONA BOARD OF CHIROPRACTIC EXAMINERS Mission Statement The mission of the Board of Chiropractic Examiners is to protect the health, welfare,
The State Procurement Agency of the Republic of Azerbaijan Welcomes the participants of the 9 th Public Procurement Exchange Platform “Efficient Implementation.
STATE COMMITTEE for STANDARDIZATION of the REPUBLIC of BELARUS.
Director of the General Department for Analysis and Regulation of Foreign Economic Activity of the Ministry of Economic Development of the Russian Federation.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
The role of REGULATORY IMPACT ASSESSMENT in Technical Regulation and Standards Houston, April 2-4, 2014 THE MINISTRY OF ECONOMIC DEVELOPMENT OF THE RUSSIAN.
1 Sibiu, Romania June 2008 Development of National IP Strategies Sibiu, Romania June 2012.
Ivan Pavlov The Freedom of Information Foundation Freedom of information and Open Data - interaction and contradiction: the Russian example.
MOT Dr. Dinh Thi My Loan Director General, Competition Administration Department MINISTRY OF TRADE STRENGTHENING THE TASK OF CONSUMER PROTECTION IN VIETNAM.
Preston Alderman MSDE, Director of Audit.  As recipients of federal and state funds we are charged with ensuring that the funds are adequately accounted.
Presentation “Green Investment Schemes – greenhouse gas emissions quotas trading mechanisms in Ukraine according to the Kyoto Protocol to the Convention.
Capacity building workshop on environment and health Public participation and the right to know: Aarhus Convention and PRTR Protocol Monica Guarinoni Sofia,
U.S. Department of Transportation Pipeline and Hazardous Materials Safety Administration Part 190 NPRM: Administrative Procedures - 1 -
INTRODUCTION TO THE INTERNATIONAL LABOUR STANDARDS (ILS) SYSTEM Trade Union Training on Occupational Safety, health and the Environment, with Special Attention.
Trade Union Training on Economic and Financial Analyses of Enterprises INTERNATIONAL LABOUR STANDARDS: PROCEDURES AND SUPERVISION Turin, 9 August 2005.
National Information Communication Technologies Strategy Vasif Khalafov “National strategy” working group - Web -
FEDERAL ANTIMONOPOLY SERVICE Moscow 2006 New Antimonopoly Law of the Russian Federation.
© International Training Centre of the ILO Training Centre of the ILO 1 International Labour Standards (ILS) and their.
In September of 2012 the RA Government made amendments in the Resolution No 168 on ‘Regulation of Procurement Procedures". 1. It is the responsibility.
Lecturer: Lina Vladimirovna Zhornyak, associated professor.
Deputy Head of Federal Accreditation Service Sergey V. Migin Approximation of accreditation systems of European Union and Russia.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
1 Export Control of Dual-Use Items and Arms: Industry Outreach Sofia, May, 2006 POLAND’S EXPERIENCES INDUSTRY OUTREACH and PERSONNEL TRAINING JACEK.
You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 27 – Environment Bilateral screening:
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Co-ordination and Co-operation.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
NRC’s 10 CFR Part 37 Program Review of Radioactive Source Security
PRESENTATION OF MONTENEGRO
Table of contents Foundation for support of reforms in Ukraine. Initiation……………………….3 Structure of the Foundation …………………………………………………………4 Areas of Activities …………………………………………………….5.
ROLE OF AUTHORIZED ENTITIES
Dashboard eHealth services: actual mockup
International Training Centre of the ILO
PUBLIC PROCUREMENTS IN THE REPUBLIC OF SERBIA
POPULATION AND HOUSING CENSUS ROUND 2021
Presentation transcript:

Personal Data Protection in Russia: Trends of the Last Decade State University – Higher School of Economics, Russia Software Engineering Department Alexandra A. Savelieva Prof. Sergey M. Avdoshin

Higher School of Economics Personal Data in the World of Globalization and Digitization

Higher School of Economics Main Regulations Federal laws Governmental Regulations Normative Documents of the Regulatory Authorities On Ratifying the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data The Federal Law of the Russian Federation of 19 December 2005 No. 160-FZ On Ratifying the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data On Personal Data The Federal Law of the Russian Federation of 27 June 2006 No. 152-FZ On Personal Data Government Regulation No. 781 of November 17, 2007 Government Regulation No. 687 of September 15, 2008 Government Regulation No. 512 of July 6, 2008 Supervision Agency for Information Technologies and Communications (aka Roskomnadzor) Federal Service for Technical and Export Control Federal Security Service

Higher School of Economics Major Provisions of the Law  Operator should take the appropriate security measures to ensure personal data protection against accidental or unauthorized access, alteration, destruction or dissemination.  Personal Data subject has an excusive right to decide whether to submit their personal data to an operator for processing  A documentary evidence of data subject’s agreement on their personal data processing should be in operator’s disposal  Data subject has a full authority to access their personal data stored within any operator’s information system.  The State creates a designated authority to ensure the data subject rights protection

Higher School of Economics Affected Domains Business IT Individuals FinanceEducation Security

Higher School of Economics Social Networking % Reach of Country’s Total Internet Audience * Research of Russian Social Media – 2010 // ROSE agency in cooperation with HeadHunters.ru, March – April ** 2010 Social Networking Report // Experian Simmons, June networking-report.htmlhttp:// networking-report.html *** Social Networking Has Banner Year in France, Growing 45 Percent // ComScore Press Release, February *** Steven Van Belleghem. Social Media around the world // InSites Consulting, Dec 2009 – Jan

Higher School of Economics Web Search for ‘Personal Data’ Blue: ‘персональные данные’, Region: Russia Grey: ‘personal data’, Region: Worldwide Source:

Higher School of Economics Designated Authority for Protection of Personal Data Subject’s Rights is obliged:  to organize protection of the rights of subjects of personal data  to control that protection of personal data is in accordance with the requirements of the present Federal Law and other Federal Laws  to consider the complaints and applications of citizens or legal entities on questions connected with the processing of personal data  to keep the Register of Operators  to take measures aimed at improving protection of the rights of subjects of personal data;

Higher School of Economics Number of Appeals from Personal Data Subjects Sources:  Roskomnadzor. Public summary report – 2009 //Ministry of Communications and Mass Communications of the Russian Federation, Federal Service for Supervision in the Sphere of Communications, Information Technology and Mass Communications  Report on the activities of Designated Authority for Protection of Personal Data Subject’s Rights in 2008 //Ministry of Communications and Mass Communications of the Russian Federation, Federal Service for Supervision in the Sphere of Communications, Information Technology and Mass Communications

Higher School of Economics Operators of Personal Data – ‘Leaders’ by the Number of Complaints Source: Roskomnadzor. Public summary report – 2009 //Ministry of Communications and Mass Communications of the Russian Federation, Federal Service for Supervision in the Sphere of Communications, Information Technology and Mass Communications

Higher School of Economics Appeals from ‘bad guys’  Tax-dodgers and debtors failing to pay rent can prosecute media that publish personal data

Higher School of Economics Operator’s Responsibilities Within 3 days! Destroy the Personal Data Detection of inadequate personal data Detection of operator misconduct with regard to personal data Processing of personal data after the revocation of subject’s consent Eliminate the Violation Within 7 days Motivated Refusal Request from Personal Data Subject about the presence and contents of their data in Operator’s information system Detailed Response Within 10 days

Higher School of Economics Violation of the Law  Civil, criminal, administrative and disciplinary liability of physical and legal entities  Penalty up to RUR (~$17K)  Suspension of operator business activities for a period of up to 90 days  Arrest for a period of up to 6 months / corrective labor for a period of up to 1 year  Discharge / Revocation of the right to hold a position for a period of up to 5 years

Higher School of Economics FZ in IT Industry Source: Personal Data in Russia – 2008 // Perimetrix Research Paper IT Staff and Management Awareness Influence on Personal Data Protection

Higher School of Economics Justification of Investments in Security  “Up to 5% of IT budget in western companies is allocated to information security, while in Russia it is only 0.5%” [2008 ]  “If we used the same language with CFO to explain them why Information Security investments are important, we would be able to reach the 5% level of expenditures” Vladimir Mamykin Microsoft Director on information security at Microsoft Russian Federation

Higher School of Economics Conclusions  The awareness of people about their rights for personal data has significantly improved  The State designated an authority to ensure the data subject rights protection  CSOs received a sound argument to justify investments into information security  Lawyers became involved in IT projects focused on personal data protection  The law acts as a powerful stimulus for the development of information security culture in Russia in accordance with international standards

Higher School of Economics References  The Federal Law of the Russian Federation of 19 December 2005 No. 160-FZ On Ratifying the European Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data  Roskomnadzor. Public summary report – 2009 //Ministry of Communications and Mass Communications of the Russian Federation, Federal Service for Supervision in the Sphere of Communications, Information Technology and Mass Communications  Report on the activities of Designated Authority for Protection of Personal Data Subject’s Rights in 2008 //Ministry of Communications and Mass Communications of the Russian Federation, Federal Service for Supervision in the Sphere of Communications, Information Technology and Mass Communications  Portal on Personal Data // Designated Authority for Protection of Personal Data Subject’s Rights  Research of Russian Social Media – 2010 // ROSE agency in cooperation with HeadHunters.ru, March – April  2010 Social Networking Report // Experian Simmons, June  Social Networking Has Banner Year in France, Growing 45 Percent // ComScore Press Release, February  Steven Van Belleghem. Social Media around the world // InSites Consulting, Dec 2009 – Jan  Personal Data in Russia – 2008 // Perimetrix Research Paper

Personal Data Protection in Russia: Trends of the Last Decade