The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040.

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Identifying Data Protection Issues Developing Lifelong Learner Record Systems and ePortfolios in FE and HE: Planning for, and Coping with, Legal Issues.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
CcTLD Meetings Rome 2004 WHOIS & Data Privacy Jean-Christophe Vignes Registry Liaison Manager.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
TEAM 4 Case Study Mauritius: Mrs Nandini Kissoon-Luckputtya
E-government programme of the Belgian social sector for small and medium-sized enterprises Frank Robben General manager Crossroads Bank for Social Security.
BIOMETRICS, CCTV & DATA PROTECTION By Drudeisha Madhub Data Protection Commissioner Date:
The Data Protection (Jersey) Law 2005.
Getting data sharing right for every child
Signature (unit, name, etc.) Introduction to biometrics from a legal perspective Yue Liu Mar NRCCL, UIO.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
1 Pertemuan 7 Points of Exposure Matakuliah:A0334/Pengendalian Lingkungan Online Tahun: 2005 Versi: 1/1.
A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Per Anders Eriksson
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
The role of privacy in the security landscape
1st MODINIS workshop Identity management in eGovernment Frank Robben General manager Crossroads Bank for Social Security Strategic advisor Federal Public.
Company Confidential How to implement privacy and security requirements in practice? Tobias Bräutigam, OTT Senior Legal Counsel, Nokia 8 October
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
The Data Protection Act 1998 The Eight Principles.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection Act AS Module Heathcote Ch. 12.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
WHOIS data The EU legal principles ICANN - GNSO meeting 2 March 2004 George Papapavlou, European Commission ICANN - GNSO meeting 2 March 2004 George Papapavlou,
Legal issues The Data Protection Act Legal issues What the Act covers The misuse of personal data By organizations and businesses.
Data Protection Property Management Conference. What’s it got to do with me ? As a member of a management committee responsible for Guiding property you.
The Data Protection Act What the Act covers The misuse of personal data by organisations and businesses.
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
The EU General Data Protection Regulation Frank Rankin.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
The Data Protection Act 1998
The Data Protection Act 1998
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Issues of personal data protection in scientific research
General Data Protection Regulation
Data Protection Act.
The Data Protection Act 1998
Data Protection Legislation
GDPR Overview GDPR - General Data Protection Regulations
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
6 Principles of the GDPR and SQL Provision
G.D.P.R General Data Protection Regulations
FEK årskonferanse 28. februar 2018.
General Data Protection Regulation
Data Protection principles
Identify the laws and guidelines that affect day-to-day use of IT.
GDPR Workshop MEU Symposium Prague 2018
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
Hot Topic 1: GDPR and Traffic Data Systems
Presentation transcript:

The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040 Brussels Belgium Website:

2 Frank RobbenBrussels, 5th October 2006 Data retention directive n conflicting interests -society fight against crime trust in information society – no digital divide competitiveness of the Belgian service providers -citizen privacy protection limited costs -service providers trust of clients acceptable risk and liability technical feasibility n need to find the right balance between the interests, with a clear division of tasks between the several parties involved and in a sufficiently coordinated way throughout countries

3 Frank RobbenBrussels, 5th October 2006 Basic principles of data protection n purpose limitation n proportionality n accuracy n transparency n security n export to non-EU-countries

4 Frank RobbenBrussels, 5th October 2006 Purpose limitation n principle -data must be collected for specified, explicit and legitimate purposes and -not further processed in a way incompatible with those purposes n consequences -the type of service providers the regulation applies to has to be specified (also content providers ?) -the type of crime in the fraud against which the data can be processed must be specified -data must in principle only be used for reactive investigation, and not for proactive investigation (except specific procedures) -the instances that can access the data for those purposes must be well defined -the procedures that have to be followed (a.o. authorization by judicial authorities) must be specified

5 Frank RobbenBrussels, 5th October 2006 Proportionality n principle -data must be adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed -data must be kept no longer than is necessary for the purposes for which the data were collected or for which they are further processed n consequences -the list of data that has to be kept has to be well specified (no content !) -the retention period has to be defined in relation to the periods of prescription -data have to be really destroyed after the retention period -a division of tasks has to be defined between the parties involved in order to prevent superfluous multiple storage of data (preferentially no central DB) -the persons regarding to whom data are accessed have to be suspected of involvement in crime in the fight against which the data can be processed

6 Frank RobbenBrussels, 5th October 2006 Accuracy n principle -data must be accurate and, where necessary, kept up to date n consequences -data must guarantee a sufficiently correct identification of the parties involved in the communication – what about dynamic IP-addresses ?

7 Frank RobbenBrussels, 5th October 2006 Transparency n principle -the data subject has to be informed about a.o. the purposes of the processing for which the data are intended or used the (categories of) recipients of the data the existence of the right of access to and the right to rectify the data regarding his person n consequences -the clients of the service providers need to be informed about which categories of data can be processed for the fight against which types of crime the possible recipients of those data and the procedures according to which they can be processed the right of access and the right to rectify the data regarding their person -either in the contract or via collective information procedures

8 Frank RobbenBrussels, 5th October 2006 Security n principle -appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, and all other unlawful forms of processing -having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected n consequences -service providers need to take sufficient measures in order to guarantee the availability of the data the confidentiality of the data (only accessible when appropriate procedures have been applied) the integrity of the data the traceability of the processing of the data

9 Frank RobbenBrussels, 5th October 2006 Export to non-EU-countries n principle -the transfer to a third country of personal data which are undergoing processing or are intended for processing after transfer may take place only if the third country in question ensures an adequate level of protection n consequences -service providers must check whether it has been decided according to the procedures foreseen in Directive 95/46/EC that the third country ensures an adequate level of protection -if not, service providers must meet the conditions provided by the Directive 95/46/EC

10 Frank RobbenBrussels, 5th October 2006 Conclusion n need for clarification of the scope of the Data Retention Directive n transposition of the Data Retention Directive into Belgian law needs quite concrete regulation n need to coordinate the concrete regulation in an international perspective: most appropriated consultative body ? n Belgian Privacy Commission should be involved

11 Frank RobbenBrussels, 5th October 2006 More information n Belgian Privacy Commission n Crossroads Bank for Social Security n personal website of the speaker

you ! Questions ? 12 Frank RobbenBrussels, 5th October 2006