Data protection issues in regulatory investigations

Slides:



Advertisements
Similar presentations
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Advertisements

Data Protection Information Management / Jody McKenzie.
The Problem Solvers TM Privacy Rights: Minors and Parents Michael J. Hewitt Marcel Daigle Singleton Urquhart LLP.
The Data Protection (Jersey) Law 2005.
JURISDICTION Arie Afriansyah. Definition The extent to which international law permits a state to exercise its jurisdiction over persons or things in.
The Australian Privacy Principles Protecting information rights –­ advancing information policy.
Data Protection and Records Management
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
National Smartcard Project Work Package 8 – Information Law Report.
Data Protection Act Description The Data Protection Act controls how your personal information can be used and protects from the misuse of your.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
Protecting information rights –­ advancing information policy Privacy law reform for APP entities (organisations)
The Information Commissioner’s Office David Evans.
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
1 driven by knowledge and experience 1 CHARITIES ACT 2009 ELECTORAL ACTS 1997 – 2002 PRESENTATION BY JOE O’MALLEY Partner At OPEN on 29 June 2011.
Protecting information rights –­ advancing information policy The Australian Privacy Principles.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
International Investigations: Issues to Consider When Conducting or Defending Against an FCPA Investigation Outside the United States Presented by: Sandee.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data Protection and Records Management. Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Technology and Brand Law Implementing The New EU Data Protection Regulations.
Information Security TechLink Seminar, 17 April 2013 James Knapton, Information Compliance Officer, Registrary’s Office.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Nassau Association of School Technologists
Actions for damages under the Data Protection Directive and the GDPR
GDPR (General Data Protection Regulation)
Data Protection: The Law
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Privacy principles Individual written policies
Issues of personal data protection in scientific research
Data Protection: EU & International
Microsoft 365 Get help with regulatory compliance
Obligations of Educational Agencies: Parents’ Bill of Rights
General Data Protection Regulation
APP entities (organisations)
Information Governance and Data Privacy: A World of Risk
Data Protection Act 1988 and Data Protection (Amendment) Act 2003
Data Protection Legislation
HIPAA Pros - Disclosures
PERSONAL DATA PROTECTION ACT 2010
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection: Your Rights as a Data Subject
G.D.P.R General Data Protection Regulations
The GDPR & Schools - An Introduction -
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
How is the GDPR enforced ?
General Data Protection Regulations 2018
Data Protection Act 1988 and Data Protection (Amendment) Act 2003
Recording Clinical Data
Recording Clinical Data
Fines, Sanctions and Compensation The teeth in the GDPR & Data Protection Act 2018 by Simon McGarr, CIPP/E Data Compliance Europe.
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
DATA PROTECTION AND THE IMPACT OF BREXIT   29 NOVEMBER 2016   Robin White Old Square Chambers
Data protection & FOIA considerations
GDPR Workshop – Partnerships for Jewish Schools
Getting Ready For GDPR Simon Marks Director
Presentation transcript:

Data protection issues in regulatory investigations Colin Rooney Partner, Technology and Innovation Group 20 October 2017

Introduction Law enforcement, regulators & courts voracious appetite for access to personal data Sometimes such data not held / controlled in same jurisdiction as regulator requesting it cross border issues Regulatory requests must navigate legal minefield

Compliance risk Compliance with request from regulatory authority for personal data could lead to breach of data protection rules Must assess sanctions for: breaching relevant data protection laws Against failing to comply with a request received from a regulatory authority Some thoughts on this follow…

Cross-border issues Foreign authorities requesting information held overseas Example: Microsoft Case Increasingly organisations resist exercise of extraterritorial jurisdiction by foreign courts and law enforcement agencies

Legal framework Europe Ireland General Data Protection Regulation (the “GDPR”) (date of implementation: 25 May 2018) Heads of Bill (General Scheme) DP Directive 95/46/EC Data Protection Acts 1988 and 2003

Relevant Laws Data Protection Acts 1988 and 2003 (“DPA”) Section 2(1) (c) of the DPA data controller shall not further process personal data (which includes disclosure to a third party) except in ways that are compatible with the purpose for which the data were obtained Section 8 of the DPA lifts the restriction on disclosure in certain circumstances individual's right to privacy is balanced against needs of civil society

Disclosures Section 8 of the Data Protection Acts 1988 and 2003 Section 8(a) "in the opinion of the Garda Siochana not below the rank of chief superintendent or an officer of the Permanent Defence Forces who holds an army rank not below colonel and is designated by the Minister for Defence under this paragraph, required for the purpose of safeguarding the security of the State" Section 8(b) "required for the purpose of preventing, detecting or investigating offences, apprehending or prosecuting offenders or assessing or collecting any tax, duty or other moneys owed or payable to the State, a local authority or a health board, in any case in which the application of those restrictions would be likely to prejudice any of the matters aforesaid" Section 8(c) "required in the interests of protecting the international relations of the State" Section 8(d) "required urgently to prevent injury or other damage to the health of a person or serious loss of or damage to property" Section 8(e) "required by or under any enactment or by a rule of law or order of a court" Section 8(f) "required for the purposes of obtaining legal advice or for the purposes of, or in the course of, legal proceedings in which the person making the disclosure is a party or a witness" Section 8(h) "made at the request or with the consent of the data subject or to a person acting on his behalf"

Guidance from Data Protection Commissioner’s Office Section 8(b) "required for the purpose of preventing, detecting or investigating offences, apprehending or prosecuting offenders or assessing or collecting any tax, duty or other moneys owed or payable to the State, a local authority or a health board, in any case in which the application of those restrictions would be likely to prejudice any of the matters aforesaid“ DPC Guidance: The individual's right to privacy must be balanced against the need to investigate offences and collect taxes effectively. If a data controller is approached by a law enforcement authority or by a tax collecting authority, which seeks to have personal data disclosed to it under this section of the Data Protection Act, it is a matter for the data controller: (i) to satisfy itself that the provisions of this section are met, for example by establishing the bona fides of the authority and by obtaining assurances that the disclosure is actually necessary, and not merely of side interest, for the investigation of an offence; and (ii) to decide whether or not to comply with the request for disclosure. While this section of the Data Protection Act lifts the restrictions on disclosure by a data controller to a law enforcement authority or to a tax collecting authority, this section does not impose any obligation on a data controller to comply with the request for disclosure. Section 8(e) "required by or under any enactment or by a rule of law or order of a court“ DPC Guidance: If you are under a legal obligation to disclose personal data, then this obligation takes precedence over the Data Protection Act's prohibition on disclosure. However, if you have a statutory discretion to make information available, matters are not so clear-cut. The Data Protection Commissioner has found, in the past, that a statutory discretion to make information available did not come within the scope of section 8(e) of the Data Protection Act, and that accordingly the restriction on disclosure of personal data remained in force.

Data protection issues to consider on receipt of a regulatory request

Further information Evaluate purpose of the request Seek further information from requesting regulatory authority

Powers Binding legal obligation to answer request? If so, to what extent binding? Legal ability to compel disclosure? If so, have the correct procedures been followed to make a binding demand? Necessary to ask the regulator / law enforcement authority to make a binding request?

Scope of the request Negotiate scope of request?   Sometimes regulators / law enforcement authorities will agree to narrow broadly defined requests so as to target specific information required for purposes of their investigations…

Anonymization and minimisation Limit data disclosed to that which is necessary for purpose (NB for GDPR) Redact personal data from documents before they are disclosed?

International disclosure Can data be transferred via a domestic authority? Can domestic court compel disclosure of documents pursuant to Hague Convention?

Data processing agreement Is recipient acting as a data processor? Is it necessary to put in place a data processing agreement? only to process data in accordance with the instructions of the company (as data controller)   implement sufficient technical and organisational security measures to protect the personal data.

Thank you for your time today. colin.rooney@arthurcox.com 20 October 2017