Data Protection.

Slides:



Advertisements
Similar presentations
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Advertisements

Data Protection: Your Duties as a Data Controller
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
Data Protection Information Management / Jody McKenzie.
The Data Protection (Jersey) Law 2005.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Data Protection and Records Management
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The Data Protection Act
CENTRAL SCOTLAND POLICE Data Protection & Information Security Stuart Macfarlane Information Governance Unit Police Service of Scotland.
Data Protection & Government Departments Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 2006.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
Data Protection & Law Enforcement Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 27 th 2006.
The Data Protection Act 1998 The Eight Principles.
The Freedom of Information and Data Protection Legislation An Overview Ann McKeon November 2014.
Data Protection & Commercial Sector Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 24 th 2006.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection and the Voluntary Sector: Respecting the Rights of the Individual Billy Hawkes Data Protection Commissioner Carmichael Centre Dublin, 2.
Data Protection STFC Presentation to PPD Senior Staff 26/11/2009 FoI/DP team.
Data Protection Act AS Module Heathcote Ch. 12.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
DATA PROTECTION ACT 1998 Became law on 1 March 2000 Only applies to the use of personal data, that is data which relates to an identifiable living individual,
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data Protection and Records Management. Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
1 Data Protection & Confidentiality Young Carers Workers Conference, Harrogate, 25 March 2009 Paul Ticher
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
INTRODUCTION TO DATA PROTECTION An overview of the Irish Data Protection legislation.
Data Protection in a Workplace Context. Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Session 11 Data protection. 1 Contents Part 1: Introduction Part 2: Applicability and responsibility Part 3: Our procedures on data protection Part 4:
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Understanding Privacy An Overview of our Responsibilities.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Data protection act. During the second half of the 20th century, businesses, organisations and the government began using computers to store information.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Data Protection: The Law
Data Protection and Confidentiality
Data Protection The Current Regime
GDPR Overview Gydeline – October 2017
Data Protection Act 1988 and Data Protection (Amendment) Act 2003
GDPR Overview Gydeline – October 2017
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection: Your Rights as a Data Subject
New Data Protection Legislation
G.D.P.R General Data Protection Regulations
Data Protection principles
Data Protection and You
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
GDPR Workshop MEU Symposium Prague 2018
Data Protection Act 1988 and Data Protection (Amendment) Act 2003
Data Protection for SDS Employers Alison Johnston Lead Policy Officer (Scotland) Information Commissioner’s Office.
Presentation transcript:

Data Protection

The Data Protection Rules Fair obtaining & processing Consent Specified purpose No disclosure unless “compatible” Safe and secure Accurate, up-to-date Relevant, not excessive Retention period Right of access

The Acts create: Background Data Protection Acts, 1998 RIGHTS for individuals RESPONSIBILITIES users of personal data

Rights and Obligations Rights of “data subject” (= identifiable, living individual) to control the use of their “personal data” Obligations on “data controllers” (“a person who controls the contents and use of personal data”) and “data processors” (“A person who processes personal data on behalf of a data controller”)

Definitions(1) Personal Data Data Manual Data Any Data relating to a living identifiable individual Data Automated data or structured manual data Manual Data Structured by reference to individuals in a way that makes data readily accessible

Definitions(2) Data Controller Data Processor a person who controls the contents and use of personal data Data Processor A person who processes personal data on behalf of a data controller

Definitions(3) Data Subject Processing an individual who is the subject of personal data Processing Anything done with personal data, from collection to disposal

Sensitive Data (special protection) Physical or mental health Racial origin Political opinions Religious or other beliefs Criminal convictions Alleged commission of offence Trade Union membership

Rights of Individuals to fairness when giving information to get a copy of their personal information – includes both computer and certain manual files to have wrong information corrected to opt out of marketing - includes mail & phone to complain to the Data Commissioner

Obtain & Process Fairly I Rule 1 Obtain & Process Fairly I Data controller must give full information about identity purposes disclosees any other data necessary for “fairness” Third party data controllers must contact data subject to provide these details must give name of original data controller

Obtain & Process Fairly II Rule 1 Obtain & Process Fairly II One of these conditions required: Consent Legal obligation Contract with individual Necessary to protect vital interests Necessary for a public function (Justice) necessary for ‘legitimate interests’

Processing Sensitive Data Rule 1 Processing Sensitive Data One of these additional conditions is required Explicit consent Necessary under employment law To prevent injury or protect vital interests Process the data of members/clients of non-profit orgs. Legal advice For Medical Purposes Statutory function

Disclosure Policy The Data Controller should have a policy in place to determine how requests for data from third parties are handled. This policy should be consulted by appropriate staff members

Keep Safe and Secure Rule 4 Appropriate security measures Appropriate to the harm that might result.. Appropriate to the nature of the data May have regard to cost of implementation May have regard to the current state of technology Staff must know and comply with measures Internal review of security measures-part of Internal Audit function ?

Security - practical Care must also be taken regarding paper records, especially sensitive or financial data. Ideally data not left in a way that non-relevant staff can access files. Attention paid to how visitors move around an office.

Data Protection Training. Obligation on employer to ensure staff are aware of data protection obligations. Training Policy. A Code of Practice. Person in charge

Accurate, Complete and Up-to-Date Rule 5 Accurate, Complete and Up-to-Date Longer personal data is held, more likely it will be inaccurate and out-of-date Right to have errors rectified (see later)

Relevant and not Excessive Rule 6 Relevant and not Excessive No right to ask for, or hold, information not relevant to service etc being provided Challenge: who do you need all this personal data ?

Retain no longer than necessary Rule 7 Retain no longer than necessary Legal obligations to hold data? Customer files Do you need to hold all that data? Payment records might have one retention period Exam results might have longer retention period Credit card details retained with consent Must have policy thought through Defend retention as necessary for purpose.

Right of Access: Empowerment Rule 8 Right of Access: Empowerment The Right of Access empowers individuals by enabling them to supervise the processing of their personal data.

Right of erasure Doesn’t apply if you have a lawful purpose in retaining data Such as auditing or accreditation purposes