Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

Public Sector Information & Data Protection: A plea for personal privacy settings for the re-use of PSI Bart van der Sloot Institute for Information Law.
PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
European CommissionDirectorate-General Justice, Freedom and Security Data Protection 1 Conference on Cross Border Data Flows & Privacy October 15-16, 2007.
Data Protection & Human Rights. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040.
1 The Data Protection Officer at work Experience, good practices and lessons learnt Pierre Vernhes – former DPO at the Council of the EU Workshop on Data.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
The Data Protection (Jersey) Law 2005.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
The Information Commissioner’s Office David Evans.
The role of privacy in the security landscape
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
The Data Protection Act 1998 The Eight Principles.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection Act AS Module Heathcote Ch. 12.
European Data Protection Supervisor Pharmaceutical Regulatory & Compliance Congress, Brussels, 7 June 2007 European Privacy and Data Protection Policy.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
WHOIS data The EU legal principles ICANN - GNSO meeting 2 March 2004 George Papapavlou, European Commission ICANN - GNSO meeting 2 March 2004 George Papapavlou,
Ioannis Iglezakis Data Protection. Definition of Data Protection The legal protection of individuals with regard to automatic processing of personal information.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data protection and European citizens’ initiatives
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
The EU General Data Protection Regulation Frank Rankin.
Getting data sharing right for every child Maureen H Falconer Senior Policy Officer Information Commissioner’s Office.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
HIPSSA Project PRESENTATION ON SADC DATA PROTECTION MODEL LAW
DIRECTIVE (EU) 2016/680 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing.
Trevor Ellis Trainee Programmer (1981 – 28 years ago)
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Issues of personal data protection in scientific research
Data Protection: EU & International
GDPR – Legal Aspects Desislava Krusteva, Attorney-at-Law, CIPP/E
General Data Protection Regulation
Data Protection Legislation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
Bob Siegel President Privacy Ref, Inc.
GENERAL DATA PROTECTION REGULATION (GDPR)
The General Data Protection Regulation (GDPR)
State of the privacy union
G.D.P.R General Data Protection Regulations
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
How is the GDPR enforced ?
Bart van der Sloot Data Protection 2.0 The proposal for a General Data Protection Regulation Bart van.
GDPR Workshop MEU Symposium Prague 2018
European Data Supervisor
GDPR & Accountability ISACA Ireland Annual Conference 2018
Is Data Protection a Fundamental Right Protecting the Individual?
Welcome IITA Inbound Insider Webinar: An Introduction to GDPR
The EDPS: competences and processing of personal data in EU funds
Data Protection in Law Enforcement Area Chapter 9a of the draft law
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
Presentation transcript:

Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari

8 June 2011 European Data Protection Legal Framework INTERNATIONALEUNATIONAL European Convention on Human Rights – art. 8 EU Charter on Fundamental Rights – art. 8 Transposition of Directives to national laws Council of Europe Convention n “Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data” former First Pillar: Directive 95/46, Directive 2002/58 (e- privacy), Directive on Data Retention For EU Institutions : Regulation 45/2001 Sector specific laws and codes of conduct

8 June 2011 Charter of Fundamental Rights of the European Union Article 8 - Protection of personal data 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority.

8 June 2011 What is “Data Protection”? Obligations (data controller): - data quality, lawfulness of processing, transfer of personal data, sensitive data, information to be provided, adoption of security measures, etc. Rights (data subject): - access, rectification, blocking, erasure, right to object, automated individual decisions, etc. Exemptions and restrictions Remedies Independent Supervisory Authority

8 June 2011 Compliance with the Regulation: Layered approach Institutions and bodies Controllers Data Protection Officer EDPS

8 June 2011 What is the EDPS? The EDPS is an independent supervisory authority devoted to protecting personal data and privacy and promoting good practice in the EU institutions and bodies. A number of specific duties of the EDPS are laid down in Regulation 45/2001. The three main fields of work are: Supervisory tasks Consultative tasks: to advise EC institutions and bodies on proposals for new legislation as well as on implementing measures. Technical advances, notably in the IT sector, with an impact on data protection are monitored as part of this activity. Cooperative tasks: involving work in close collaboration with national data protection authorities and acting as a member of the Article 29 Working Party.

8 June 2011 Supervision main activities Prior check: specific risks Complaints: data processed by EU institutions and bodies Consultations on Administrative Measures Inspections: own initiative or on the basis of a complaint

8 June 2011 Raising awareness Targeted monitoring and reporting exercises General monitoring and reporting exercises Inspections EDPS compliance monitoring tools

8 June 2011 Powers: article 47 Give advice Refer matter to controller and make proposals to remedy breach Warn or admonish controller Order rectification, blocking, erasure Impose temporary or definitive ban Refer matter to institution or EP, Council, COM Refer matter to ECJ

8 June 2011 Scope of application of Directive 95/46/EC and Regulation 45/2001 Material scope: processing of personal data wholly or partly by automatic means or which form part of a filling system Personal data: “any information relating to an identified or identifiable natural person”, that is the ‘data subject’; An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity” Art. 29 Working Party: where the criteria of "content", "purpose" or "result" allow the information on the legal person or on the business to be considered as "relating" to a natural person, it should be considered as personal data, and the data protection rules should apply.

8 June 2011 Data quality criteria Processed fairly and lawfully Collected for specified, explicit and legitimate purpose Adequate, relevant and non excessive Accurate and kept up to date Kept in a form which permits identification of data subjects for no longer than necessary

8 June 2011 When is data processing “lawful”? Article 5: –a) public interest on the basis of EU law / official authority vested in EU institution/body –b) compliance with legal obligation –c) performance of a contract –d) unambiguous consent –e) vital interests

8 June 2011 Change of purpose Article 4.1.b “not processed in a way incompatible with the purposes for which data was collected” Article 6.1.”personal data shall only be processed for purposes other than those for which have been collected if change of purpose is expressly permitted by internal rules of the EU institution or body”

8 June 2011 When is data processing “fair”? Rights of data subject Information (no excessive delay/expense) on whether data are processed, purpose, recipient, Information on rights of data subject, legal basis / time limit / recourse to EDPS Access and rectification, erasure or blocking

8 June 2011 Data transfers under Regulation 45/2001 Transfer from EU institution to recipients subject to Dir. 95/46 (national authorities): yes if recipient establishes that transfer necessary for public interest task or subject to public authority Transfer from EU institution to recipients not subject to Dir. 95/46: adequacy + solely to allow tasks of controller´s competence

8 June 2011 Security of processing To prevent unauthorised disclosure or access, unlawful destruction, accidental loss or alteration or other unlawful processing, controller to implement appropriate technical and organisational measures to ensure security Specific requirements for automated means of processing (art Reg. 45/2001)

8 June 2011 Restrictions (article 20) May restrict application of certain principles (conservation period, rights of data subjects, …) when necessary for - Prevention, investigation, detection, prosecution of criminal offences - Important financial or economic interest - Protection of data subject or rights and freedoms of others - National security, public security or defence MS

8 June 2011 Restrictions (cont) If apply restriction: -Inform reasons and recourse EDPS -May defer this information for as long as would deprive the restriction of its effect (20.5) -Indirect access through EDPS (art 20.4)

8 June 2011