Download presentation
Presentation is loading. Please wait.
Published byAlexandra Allen Modified over 9 years ago
1
Privacy and Data Protection III Annual Latin American Telecommunications, Technology, and Internet Public Policy Forum Geff Brown, Assistant General Counsel Microsoft Corporation May 16, 2013
2
Privacy and Data Protection Regulatory Infrastructur e Transparenc y Privacy by Design No Privacy w/o Security
3
Security DATAAPPLICATIONNETWORK HOST SECURITY IDENTITY AND ACCESS MANAGEMEN T PHYSICAL Security must be in place at every level.
4
Privacy by design Context: Personal data should be used only in the context of the relationship with the individual. Individual Choice and Control: Users should have choices about how their personal data is used. Data Portability: Customers should have the right to freely access and move their personal data.
5
Compliance management framework Policy Control Framework Standards Operating Procedures Business rules for protecting information and systems which store and process information A process or system to assure the implementation of policy System or procedural specific requirements that must be met Step-by-step procedures 5
6
Transparency What personal data goes where. Who can access the personal data and why. Privacy statements and other documentation.
7
Regulatory Infrastructure Defining bases for processing personal data: Consent; legitimate interests; contract. Implementing rights: Access, correction and deletion; data breach notification; redress. Consistent and effective enforcement: Oversight and guidance; risk-based approaches; penalties.
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.