1 TAIEX JHA 52182 - Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.

Slides:



Advertisements
Similar presentations
Transborder Data Flows & Privacy Contractual clauses in the practice Tanguy Van Overstraeten Washington DC October 16, 2007.
Advertisements

1 Agencia Española de Protección de Datos AUDITING AND ENFORCEMENT AT THE SPANISH DPA. EXPERIENCE WITH OUTSOURCING TO COUNTRIES WITH A NON ADEQUATE LEVEL.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
The Gathering Cloud computing - Legal considerations David Goodbrand, Partner 28 February 2013 Aberdeen Edinburgh Glasgow.
Sarah Branam Mehmet MunurDino Tsibouris
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
International Treaty in EU PIL
EU: Bilateral Agreements of Member States
EU: Bilateral Agreements of Member States. Formerly concluded international agreements of Member States with third countries Article 351 TFEU The rights.
Per Anders Eriksson
Anomalous Aspects of Transfer of Personal Data from the E.U. to the U.S. Stephen R. Bell Willkie Farr & Gallagher ABA Section of International Law New.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Draft EU Privacy Regulation Corporate Privacy Forum January 26, 2012.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
M. ANGELA JIMENEZ 1 UNIT 5. REGULATION OF EXTERNAL AUDIT IFAC AND E.C.
TAIEX Seminar on the Directive on Services in the Internal Market Warsaw, Freedom to Provide Services Clause Article 16 Sophie Malétras.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
ENTERPRISE AND INDUSTRY DIRECTORATE GENERAL European Commission 1 PECAs David Eardley DG Enterprise and Industry European Commission Tel: 032 (2)
Processing on behalf of the controller Joint control under Regulation 45/2001.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
WHOIS data The EU legal principles ICANN - GNSO meeting 2 March 2004 George Papapavlou, European Commission ICANN - GNSO meeting 2 March 2004 George Papapavlou,
The Framework for Privacy Policies in the UK: Is telling people what information is gathered about them part of the framework? Does it need to be? Emma.
Undertakings for collective investment in transferable securities (UCITS) Worldbank Global Development Learning Network The Advanced Program in Accounting.
DG Information Society The EU and Data Retention Data Retention Meeting London, 14 May 2003 Philippe GERARD, DG Information Society The positions.
European Aviation Safety Agency Head of Aircraft Product Certification
Personal data processed in cloud infrastructures: main legal aspects Avv. Enrico Pelino Attorney at Law at Bologna Bar, Italy Senior Associate at ICTlegalconsulting.
Vienna 14 March 2006 Andrew J. Popham Vice-President of FEE Partner, PricewaterhouseCoopers LLP The New Directive on Statutory Audit in the EU.
Dino Tsibouris (614) Updates on Cloud, Contracting, Privacy, Security, and International Privacy Issues Mehmet Munur (614)
Presentation Title Data Protection The new EU Regulation Insert your logo here.
1 Agencia Española de Protección de Datos The Use of Contracts and BCRs to Transfer Personal Data The European Union – United States Safe Harbor framework:
Data protection—training materials [Name and details of speaker]
1.State foreign trade regulation 2. Rules of Russian private international law applicable to international contracts.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Freedom to Provide Services Clause Why does the Country of Origin Principle not exist anymore? Martin Frohn.
ROMANIA NATIONAL NATURAL GAS REGULATORY AUTHORITY Public Service Obligations in Romanian Gas Sector Ligia Medrea General Manager – Authorizing, Licensing,
-1- WORKSHOP ON DATA PROTECTION AND DATA TRANSFERS TO THIRD COUNTRIES Technical and organizational security measures Skopje, 16 May - 17 May 2011 María.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
© CENTER FOR INFORMATION TECHNOLOGY SERVICES UNIVERSITY OF OSLO USIT Page 1 Re: Study on the privacy issues arising with the public pan-European White.
Convention 108 and the EU framework: Differing while Converging
Industry 4.0 – New ways of cooperative working – are we prepared?
GDPR (General Data Protection Regulation)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
General Data Protection Regulation (GDPR)
Data Protection: EU & International
WORLD OF CLOUD COMPUTING AFTER GDPR challenges, opportunities and the unknown Matjaž Drev, MA. National Supervisor for Personal Data Protection, Information.
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
Information Governance and Data Privacy: A World of Risk
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Bob Siegel President Privacy Ref, Inc.
Processing on behalf of the controller
The GDPR and research data
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.
ESF Monitoring & Evaluation and Data Protection in Spain
GDPR Overview and Use Cases.
How is the GDPR enforced ?
Welcome!.
Data transfers to non-EU countries under the new GDPR
The activity of Art. 29. Working Party György Halmos
Data Protection: The new EU Regulation
The EDPS: competences and processing of personal data in EU funds
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Session 4: Data Mapping and Data Subject Rights
Session 4: Data Mapping and Data Subject Rights
Processing on behalf of the controller
Presentation transcript:

1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Data transfers to third countries and standard contractual clauses Manuel Villaseca CISA, CISM Spanish Data Protection Agency

2 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014  International data transfers  Legal status of participants in a typical cloud scenario  Changes in a cloud model  Alternatives for international data transfers in the cloud

3 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 INTERNATIONAL DATA TRANSFERS  TO THIRD COUNTRIES WITH AN ADEQUATE LEVEL OF PROTECTION  US organisations adhering to Safe Harbour Agreement  TO THIRD COUNTRIES WITHOUT AN ADEQUATE LEVEL OF PROTECTION

4 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 SAFE HARBOUR PROVISIONS The Commission recognises that US organisations adhering to Safe Harbour principles have an adequate level of protection (Decission 2000/520/EC). It does require a service-provision contract (FAQ 10 of Decission 2000/520/EC) The service-provision contract may authorise subcontracting The Safe Harbour onward transfer principle obliges service providers to subcontract other organisations adhering to Safe Harbour principles, or to draw up a contract enforcing compliance with data protection principles (linking of safeguards) WP 29 warning on Safe Harbour certificationto companies exporting data (WP 196)

5 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 WITHOUT AN ADEQUATE LEVEL OF PROTECTION  The controller adduces ADEQUATE SAFEGUARDS with respect to the protection of the privacy and fundamental rights and freedoms of individuals and as regards the exercise of the corresponding rights (Art 26.2 Directive 95/46 CE)  One of the exceptioned situations (derogations) provided for in Article 26.1 Directive 95/46 EC takes place.

6 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 ADEQUATE SAFEGUARDS  The data exporter and data importer have concluded a contract using one of the three sets of Standard Contractual Clauses approved by the European commission.  A multinational corporation has adopted Binding Corporate Rules for transfers of personal data.  The data exporter and data importer have concluded a contract which includes appropriate contractual clauses (ad hoc) relating to data protection and the supervisory authority of the member state has accepted these clauses.

7 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Sets of Standard Contractual Clauses approved by the European commission:  Standard Contractual Clauses from controller/exporter to controller/importer (Business clauses) - European Commission Decision 2001/497EC - European Commission Decision 2004/915 EC  Standard Contractual Clauses from controller/exporter to processor/ importer -European Commission Decision 2002/16 EC (Derogated) -European Commission Decision 2010/87 EC

8 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014  Member states recognise standard clauses as providing adequate safeguards  The law of member states must be observed prior to the transfer  Additional clauses are possible as long as they do not contradit SCC  No amendments and changes are allowed  A further authorisation depends on the member states legislation  Depositi of the contract depends on the member states legislation  Prohibition or suspension of international data transfers based on SCC

9 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 STANDARD CONTRACTUAL CLAUSES FROM CONTROLLER/EXPORTER TO PROCESSOR/IMPORTER - European Commission Decision 2002/16 EC (Derogated) -European Commission Decision 2010/87 EU –Customer call centers –Online marketing –Administrative work services –Hosting activities –Technical support of the data base

10 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 STRUCTURE Decision 2010/87 EU 4 Articles 12 Standard Contractual Clauses Appendix 1: Minimun information about the transfer Appendix 2: Security Measures implemented by the data importer

11 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 STANDARD CONTRACTUAL CLAUSES CONTENT Decision 2010/87 EU Definitions Data exporter obligations Data importer obligations Sub-processing: -Prior written consent of the data exporter -Written agreement with the sub-processor -List of sub-processing agreement updated at least once a year and available to the data exporter’s data protection supervisory authority

12 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Safeguards Decision 2010/87 EU -Third party beneficiary clause -Liablility: compensation for damages -Disputes: mediation or courts in the Member State in which the data exporter is established.

13 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 PROPOSAL FOR A GENERAL DATA PROTECTION REGULATION To third countries without an adequate level of protection the transfers may take place: –Binding corporate rules –Standard Data Protection Clauses adopted by the Commission –Standard Data Protection Clauses adopted by a Supervisory Authority –Contractual Clauses between the controller or processor and the recipient of the data authorised by a Supervisory Authority

14 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 The customer as data controller: –Determines the purpose, content and use of the processing Determines whether to choose cloud computing (total or partial) Determines the type of cloud computing (especially regarding International Data Transfers) Determines the cloud computing service types –Responsible for the processing of personal data (cannot be delegated) –CCP as data processor LEGAL STATUS OF PARTICIPANTS

15 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 The traditional controller/processor relationship does not fit the cloud computing model –Instructions from the controller to the processor –Non-communication to third parties even for preservation –Specification of security measures to be implemented by the processor –Data destroyed or returned once the service has been provided

16 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Diligence required from the controller Ensure that the processor complies with the required guarantees Obtain information on contractual safeguards Diligently exercise the function of data controller vis-à- vis data subjects –Portability –Exercise of data subject rights

17 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Diligence required by the processor –Detailed information on the type of cloud computing and the services it offers (type of cloud, type of services, participants in the provision of services, IDTs) –Information on security measures (levels of security, audit, encryption, security incidents). –Information on portability

18 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Decision 2010/87 (Recital 23) Contractual framework that comprises two agreements Controller-processor agreement: –Signed on a case-by-case basis by the controller/customer (Framework contract) in acordance with the applicable data protection law –Reference to contractual safeguards authorised for IDTs Draft Ad hoc contractual clauses “EU data processor to non- EU sub-processor” WP214

19 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014 Decision 2010/87 safeguards adapted: Applicable law: Law of the controller Information on subsequent sub-processors Third-party beneficiary clause Cooperation with the DPA Possibility of authorising general contracting terms and conditions adapted to cloud-computing business models (EU main data controller, third-country main processor and third-country sub-processors) PROCESSOR - SUB-PROCESSOR SUBCONTRACTING

20 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014  Customer as controller and CSP as processor  Safeguards in an ad hoc contract based on the guaranties provided by SCC 2020/87/EU (WP 196)  Safeguards adapted to cloud business model: o A single contract by subcontractor o Transparency to the customer about sub processors. o Possibility to object new subcontractors  Security measures  Auditing  Portability Possible modalities adapted to Cloud Services