Privacy, Data Protection and Lex Informatica -- lecture 7 Dr. Lee A. Bygrave, 3.3.2006.

Slides:



Advertisements
Similar presentations
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Advertisements

Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Purpose MLA and extradition (and other forms of international judicial cooperation) with 3rd countries is part of the external policy of the Union Purpose.
Protection of Personal Data, Historical context In 1982, Iceland signed the Council of Europe Convention nr. 108 from 1981 for the Protection.
1 “Introduction to EU Trade Policy” – July 2008 How We Make Trade Policy n Contents n Part I: EU Trade Powers n Part II: The evolving scope of Trade Policy.
Integration measures or conditions ? Dr. Jürgen Bast.
Sarah Branam Mehmet MunurDino Tsibouris
The European Union legal framework for clinical data access: The European Union legal framework for clinical data access: potential challenges and opportunities.
EU: Bilateral Agreements of Member States
EU: Bilateral Agreements of Member States. Formerly concluded international agreements of Member States with third countries Article 351 TFEU The rights.
Legal European Aspects of Digital Rights Management © Abdullah Sherbini 2006 بسم الله الرحمن الرحيم.
Lecture to Carleton University, Center for European Studies, December 1, 2010.
Transborder dataflows Flow of information across national borders Much of this data involves personal information.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Class 13 Internet Privacy Law European Privacy.
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Ole Kr. Fauchald Categories of treaties n Treaties, conventions, covenants, memoranda of understanding, exchange of letters – irrelevance of.
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
RESPECT Guidelines regarding data protection aspects whithin socio-economic research Y. Poullet, K. Rosier, I. Vereecken CRID-FUNDP in cooperation with.
Privacy, Data Protection and Lex Informatica -- lecture 4 Dr. Lee A. Bygrave,
Privacy, TBDF and E.U: Beyond the frontiers Yves Poullet Prof. at the Univ. of Namur, Director of the CRID St John’s CBA Conference August 15, 2006.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
Seminar on Migration Legislation Ministry of Foreign Affairs of Guatemala 15 – 16 February 2007.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
European Data Protection Supervisor Pharmaceutical Regulatory & Compliance Congress, Brussels, 7 June 2007 European Privacy and Data Protection Policy.
Privacy, Data protection and Lex Informatica -- lecture 2 Dr. Lee A. Bygrave,
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
Isabelle Mihoubi Deputy Regional Representative UNHCR RR Kyiv Return/Readmission.
Determining the applicable national social security scheme An overview of the main rules in Regulations n° 883/2004 & 987/2009,
An Overview of International Regulation of Data Protection AFIN- DRI 2002 Lecture Stephen K. Karanja.
Privacy, Data Protection and Lex Informatica -- lecture 6 Dr. Lee A. Bygrave,
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
Préposé fédéral à la protection des données et à la transparence PFPDT Federal Data Protection and Information Commissioner FDPIC Les impératifs d’une.
Dr Marek Porzycki.  the debtor has some assets abroad  the debtor has creditors abroad  the debtor carries out his activities on a cross-border basis.
1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.
Data protection—training materials [Name and details of speaker]
Thomas Kramler DG Competition, European Commission (The views expressed are not necessarily those of the European Commission) E-commerce and EU competition.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Ethical, legal and social aspects of public health genomics Mark Taylor, School of Law, University of Sheffield 7 th November 2014.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
European Data Protection Supervisor TAIEX Seminar - Belgrade 9 February 2009 Principles of data protection and international legal framework Alfonso Scirocco.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
HIPSSA Project PRESENTATION ON SADC DATA PROTECTION MODEL LAW
Convention 108 and the EU framework: Differing while Converging
GDPR (General Data Protection Regulation)
The Law Applicable to Companies in the EU: Status quaestionis
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Data Protection: EU & International
Lee A. Bygrave, Norwegian Research Center for Computers and Law
Interactive Gaming Council Board Meeting I-Gaming Legal status
General Data Protection Regulation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Human Rights
Bob Siegel President Privacy Ref, Inc.
Introduction to GDPR 09/11/2018.
Transfers of personal data
GDPR Overview and Use Cases.
HIPSSA Project Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Meeting with the Namibia ICT Ministry and Data Protection Stakeholders.
Data transfers to non-EU countries under the new GDPR
The Modernisation of Convention108
The EDPS: competences and processing of personal data in EU funds
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Private and Public law lesson 5 The impact of EU law on the domestic legal system; implementation of EU law into national legislations; Italy (and EU)
Privacy, Data Protection and Lex Informatica -- lecture 5
International Organisations – General Issues, Part 1
EU Data Protection Legislation
Data Privacy and GDPR Jane Shvets
Presentation transcript:

Privacy, Data Protection and Lex Informatica -- lecture 7 Dr. Lee A. Bygrave,

Lecture overview Rules on applicable law –Focus on DPD Art 4 –Problems in Internet environment Rules on transborder data flow (TBDF) –Rules in early national laws –Rules in early international instruments –Rules in DPD Art 25 Art 26 –Main policy making bodies –Safe Harbor agreement

Applicable law (1) Main rule prior to DPD –Applicable law = law of State where data file/register located –Some exceptions, giving national laws considerable extra- territorial scope (eg Belgian law) Main rule in DPD Art 4(1) –Applicable law = law of State where data controller is established (Art 4(1)(a)) –Establishment “implies effective and real exercise of activity through stable arrangements” (recital 20; cf. Case C-221/89 Factortame); legal form not decisive (recital 19) –Importance of distinguishing between “controller” and “processor”

Applicable law (2) Secondary rules in DPD Art 4(1) –These apply law of State when data controller not established there -- Arts 4(1)(b) & (c) –Art 4(1)(b): State’s law applies “by virtue of international public law” –Art 4(1)(c): State’s law applies if data controller (which is not established within EU) uses data-processing “equipment” situated in State (but not for mere transit)

Applicable law (3) Problems –Conflict of laws because there might be more than one controller, each established in different States –What = place of establishment in Internet context? –Regulatory overreaching in Internet environment – eg use of cookies may invoke rule in Art 4(1)(c) –How will data subject enforce his/her rights when foreign law applies and controller established in other State? Cf. DPD Arts 4(2) & 28(6)

TBDF (1) Background: –National data protection laws of 1970s –fear of “data havens” –fear that data protection would hinder TBDF and hence trade –(American) assertions that data protection = economic protectionism assertions refuted subsequently

TBDF (2) International instruments: –CoE Convention (1981) Art “equivalent” protection –OECD Guidelines (1980) Para “equivalent” protection –UN Guidelines (1990) Principle 9 -- “comparable” / “reciprocal” protection –Cf. APEC Privacy Framework (2004/05)

TBDF (3) DPD: –TBDF within EU/EEA –Art 1(2) -- prohibition on restricting TBDF for privacy protection reasons –TBDF from EU/EEA to “third countries” –Art 25(1) -- TBDF permitted if third country offers “adequate” protection –all circumstances to be taken into account –Exceptions pursuant to Art 26 »consent, legal duty, contract with ds, protect vital interests of ds, protect important public interests, etc

TBDF (4) DPD Arts 25 and problems of legal interpretation: –What = adequate? –What = necessary? –What = legal obligation? –What = transfer? Cf. ECJ decision in Lindqvist, Case 101/01,

TBDF (5) DPD Arts 25 and who determines what? –Data controller –DPA –EU Commission (with Art 31 Committee) –Article 29 Wkg Gp –European Parliament

TBDF (6) Conflict with GATS (1994)? –Exception for privacy in Art XIV(c)(ii) Safe Harbor -- USA as legitimate “data haven”?