© 2005 Morrison & Foerster LLP All Rights Reserved Data Security and Incident Notification: The Impact of Foreign Law Presented April 26, 2006 to EDUCAUSE.

Slides:



Advertisements
Similar presentations
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
Advertisements

29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Protection of privacy for all Students!
The Data Protection (Jersey) Law 2005.
Robert L. Rothman Donald A. Cohn
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
Franchising In China & Elsewhere in Asia Presented by: Philip F. Zeidman DLA Piper US LLP.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
6/1/2015MINISTRY OF ENERGY, COMMUNICATIONS AND MULTIMEDIA 1 PRESENTATION OF PERSONAL DATA PROTECTION BILL PRESENTATION OF PERSONAL DATA PROTECTION BILL.
Hong Kong Privacy Code on Human Resource Management
Managing Personal Information - Australian Companies Outsourcing to India and the Philippines Professor Margaret Jackson and Marita Shelly.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
2/16/2010 The Family Educational Records and Privacy Act.
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Per Anders Eriksson
Anomalous Aspects of Transfer of Personal Data from the E.U. to the U.S. Stephen R. Bell Willkie Farr & Gallagher ABA Section of International Law New.
Class 13 Internet Privacy Law European Privacy.
THE CHOICES WE MAKE THAT MATTER – International Data Privacy/Protection JILL L. UREY, ASSISTANT GENERAL COUNSEL MID-ATLANTIC CIO FORUM NOVEMBER 20, 2014.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
R&D incentives in South Africa: a sense check of policy implementation Presentation by Mohammed Jada to SCOF 27 August 2014.
Carly Nyst Head of International Advocacy A race to the bottom? Trends in privacy and surveillance in Asia, Africa and Latin America.
©2012 Morrison & Foerster LLP | All Rights Reserved | mofo.com Data Protection Masterclass VI: Global Privacy May 24, 2012 Ann Bevitt Karin Retzer Miriam.
Foreign Obligations and Annual Inventories Jessica Norles Savannah River National Laboratory.
Company Confidential How to implement privacy and security requirements in practice? Tobias Bräutigam, OTT Senior Legal Counsel, Nokia 8 October
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
HIPAA PRIVACY AND SECURITY AWARENESS.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
The Data Protection Act 1998 The Eight Principles.
E-COMMERCE AND PRIVACY LAWS IN THE UAE Rindala Beydoun Senior Legal Counsel Al Tamimi & Company.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
Supply Risk Monitoring Supply Risk Monitoring (SRM) Draws on global operational network, and analytical engine –SRM website provides quick overview.
Data Protection Act AS Module Heathcote Ch. 12.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Policies for Information Sharing April 10, 2006 Mark Frisse, MD, MBA, MSc Marcy Wilder, JD Janlori Goldman, JD Joseph Heyman, MD.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Privacy: An International Perspective Marty Abrams August 18, 2008.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
Dino Tsibouris (614) Updates on Cloud, Contracting, Privacy, Security, and International Privacy Issues Mehmet Munur (614)
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
-1- WORKSHOP ON DATA PROTECTION AND DATA TRANSFERS TO THIRD COUNTRIES Technical and organizational security measures Skopje, 16 May - 17 May 2011 María.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Nassau Association of School Technologists
Surveillance around the world
Privacy principles Individual written policies
General Data Protection Regulation
Information Governance and Data Privacy: A World of Risk
Data Protection Legislation
Campus Report Q Ipsos Training Center.
G.D.P.R General Data Protection Regulations
Protection of Personal Information Bill: An International Perspective
General Data Protection Regulation
GDPR Workshop MEU Symposium Prague 2018
Neopay Practical Guides #2 PSD2 (Should I be worried?)
Presentation transcript:

© 2005 Morrison & Foerster LLP All Rights Reserved Data Security and Incident Notification: The Impact of Foreign Law Presented April 26, 2006 to EDUCAUSE Policy Conference Session on Data Security and Incident Notification Charles H. Kennedy,

Non-U.S. Privacy Law: Overview Approximately 50 countries have privacy and data protection laws. Among other provisions, those laws generally require collectors of personal information to take reasonable measures to secure that information from unauthorized access, acquisition, use or destruction. Only the U.S. and Japan have laws that specifically require notification of data security breaches.

Non-U.S. Privacy Law: Overview Even in a foreign country without a breach-notification requirement, a data breach that becomes known to the host country’s authorities might establish a violation of that country’s data security laws. For this reason, U.S. educational institutions should protect all personal data collected or maintained in foreign countries. In today’s presentation, we focus on the EU and Japan.

When Is My School Subject to European Privacy Law? European Union Data Protection Directive applies to any collector of personal information that is “established” in a European member state or owns or controls facilities, located in a member state, that are used to collect personal information. The EU member state has jurisdiction, even if the information collected is not that of a resident of the state. You are not subject to the EU Directive when you collect personal information of a student or employee who is a resident of an EU member state, as long as the information is collected outside the EU. Note that the EU Directive is implemented by national laws that may vary in their terms. Spain, for example, has adopted an especially demanding privacy law.

Basics of the EU Data Protection Directive The EU Directive applies to all “controllers” of personal data by any entity subject to an EU member state’s laws. Personal data may be collected only for specified, explicit and legitimate purposes. Personal data may be maintained only if it is relevant, accurate and up-to-date. Individuals must be given the option to provide requested information or not, by means of a notice and opt-out procedure. Individuals have the right of access to data; the right to know where the data originated; the right to have inaccurate data rectified; the right of recourse in the event of unlawful processing of data; and the right to withhold permission to use of their data in certain circumstances.

Basics of the EU Data Protection Directive (Continued) Personal data may not be transferred from an EU country to a non-EU country that does not provide an “adequate” level of data protection. When the Directive was adopted, the United States was identified as one of the “inadequate” destinations. The result is the “Safe Harbor” agreement between the EU and the U.S. Department of Commerce.

Basics of the EU Data Protection Directive (Continued) Article 17 – Security of Processing “Member states shall provide that the controller must implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing.”

When Is My School Subject to Japanese Privacy Law? Japan’s Privacy Laws include the Law Concerning the Protection of Personal Information (“PIPL”) and the Law Concerning the Protection of Personal Information Held by Independent Administrative Legal Entities (“IALE”). Both laws are relatively new. Both laws are highly general and are implemented by detailed guidelines issued by agencies having jurisdiction over particular businesses and institutions. Although there is some ambiguity, the PIPL appears to apply to private colleges and universities. The IALE appears to apply to public colleges and universities.

When Is My School Subject to Japanese Privacy Law? You may have obligations under Japanese privacy law if: You are affiliated with a Japanese company or institution. You use or have access to employee or student information maintained in Japan. A Japanese institution with which you are involved, for example, in a study-abroad program enters into a contract with you, according to which you assume privacy obligations under Japanese law.

Basics of Japanese Privacy Law Individuals are entitled to notice of the purpose of collection and use of personal information. Individual Ministry guidelines specify methods of notice required. Businesses must limit their use of information to the purposes disclosed. Businesses must respond to requests for access to personal information. Businesses must provide notice and obtain opt-in consent before sharing information with third parties. Information may be shared and used jointly by affiliates if prior notice is given to the affected individuals.

Basics of Japanese Privacy Law (Continued) Japanese businesses are responsible for unauthorized uses of data by agents and contractors. Businesses must adopt appropriate measures to prevent unauthorized disclosure, loss, or destruction of personal information. Ministry Guidelines require disclosure of any data leak or breach, including data that are merely lost or destroyed. Ministries have not yet announced how promptly notice must be given or how much detail is required. Also, some ministries require notice only to affected persons, while otherwise require notice to responsible ministry as well. The guidelines concerning data breach are still under development.

Breach Notification by Colleges and Universities in Japan Private colleges and universities are exempt from PIPL requirements when handling personal student information for “academic” purposes, such as grade reporting, but not when handling employee information or student information for managerial purposes other than strictly academic affairs. Public universities are fully subject to IALE requirements, as previously explained. Breach notification requirements apply.

When Is My School Subject to Other Foreign Privacy Law? Most countries other than Japan and the EU member states have less explicit privacy protections, but that is changing. A college or university should be aware of the privacy laws of any country in which it maintains a facility or from which it collects personal information of students, employees or others.

Principal Countries with Privacy Laws North America Canada Mexico (pending) United States Central and South America Argentina Brazil (pending) Chile Colombia (pending) Costa Rica (pending) Ecuador (pending) Paraguay (pending) Peru (pending) Uruguay (pending)

Principal Countries with Privacy Laws (Continued) Middle East Israel Africa South Africa (pending) Europe All EU member states

Principal Countries with Privacy Laws (Continued) Asia-Pacific Rim Australia China (pending) Hong Kong India (pending) Japan Malaysia (pending) New Zealand Philippines (pending) Singapore South Korea Taiwan Thailand (pending)

Practical Considerations It bears repeating that data security should be a priority for all organizations. U.S. breach notification laws complicate the picture for data breaches that also affect foreign persons or operations. If an institution reports a breach to affected residents of U.S. states, the advisability of reporting to affected residents of foreign jurisdictions, as well, should be considered for reputational, if not legal, reasons. Similarly, if a report to a foreign jurisdiction is required, reports to U.S. persons affected by the same incident should be considered, even where those persons do not reside in breach-notification states.

Practical Considerations (Continued) For both foreign and domestic reporting purposes, a breach notification plan should be in place before it is needed. Know the channels through which applicable laws require you to send notice, and have notices ready to go. Consider going beyond the bare minimum of notification requirements. Train your responsible employees.