The Geopolitics of Personal Data and the Governance of Privacy Colin J. Bennett Department of Political Science University of Victoria BC, Canada www.colinbennett.ca.

Slides:



Advertisements
Similar presentations
EU Privacy Directive. What is a directive? A piece of European legislation, passed by bureaucrats, addressed to member states Member states must ensure.
Advertisements

PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
PROJECT Towards an Harmonised Approach for National Space Legislation in Europe Berlin, January 2004 NATIONAL SPACE LEGISLATION: THE BELGIAN.
Privacy and security: Is Europe going banana? Jean-Marc Van Gyseghem Head of Unit « Liberties in the information society » CRID – University.
Lecture to Carleton University, Center for European Studies, December 1, 2010.
Data Protection as Human Rights and International Legislation on Personal Data AFIN- DRI 1010 Lecture Stephen K. Karanja Senior Researcher.
The U.S.-E.U. Safe Harbor Framework The U.S.-E.U. Safe Harbor Framework New Developments in Data Flows, Standards, & Compliance Damon Greer U.S. Department.
High Technology Cooperation Group: Data Privacy The Indo-U.S. High Technology Cooperation Group November 18, Privacy and Cyber Security:
Transborder dataflows Flow of information across national borders Much of this data involves personal information.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
From European to international standards on data protection (1/2)
Class 13 Internet Privacy Law European Privacy.
Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.
Migration Law Schengen Information System by Konrad Wilk.
RESPECT Guidelines regarding data protection aspects whithin socio-economic research Y. Poullet, K. Rosier, I. Vereecken CRID-FUNDP in cooperation with.
Privacy, Data Protection and Lex Informatica -- lecture 4 Dr. Lee A. Bygrave,
European data protection and privacy regulations Johny GASSER Orange Business Services – Consulting & Solutions Integration International Cyber Center.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
A Perspective: Data Flow Governance in Asia Pacific & APEC Framework Martin Abrams October 21, 2008.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
June 1, st Asia Pacific Privacy Authorities (APPA) Forum – PHAEDRA Workshop Nr. 3: The EU Data Protection Regulation and regional perspectives.
An Overview of International Regulation of Data Protection AFIN- DRI 2002 Lecture Stephen K. Karanja.
Cloud Computing, Policy Management and Standardization Europe Identity Conference 2011 John Sabo, Director Global Government Relations, CA Technologies.
Privacy: An International Perspective Marty Abrams August 18, 2008.
Data protection and European citizens’ initiatives
The Governance of Privacy The Governance of Privacy: Policy Instruments in Global Perspective (Ashgate Press, 2003)
Data Protection Principles as Basic Foundation for Data Protection in EU/EEA Introduction to Data Protection Theory Seminar - AFIN Stephen.
Sophie Kwasny 16 June 2011 Seminar: New challenges in the protection of individuals’ privacy and personal data Reykjavik, 19 October 2012 The contribution.
1 Copyright © International Security, Trust & Privacy Alliance -All Rights Reserved Making Privacy Operational International Security, Trust.
Issues Related to Global Information Systems A business can’t just worry about its home- country laws, rules and regulations. If a business has global.
APEC Privacy Framework “The lack of consumer trust and confidence in the privacy and security of online transactions and information networks is one element.
1 Revising the Data Protection Directive Reinventing Data Protection? Lilian Mitrou, Ass. Professor University of the Aegean 4 th International Seminar.
1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.
Data Protection and Privacy. nTechnology and personal data – Immense power to process and store data nInformation economy – Driver of economic value:
Data Protection – the Lisbon Effect Billy Hawkes Data Protection Commissioner Institute of International and European Affairs Dublin, 17 September 2009.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
European Data Protection Supervisor TAIEX Seminar - Belgrade 9 February 2009 Principles of data protection and international legal framework Alfonso Scirocco.
Global Standards Linked to Global Value Jörg Polakiewicz Head of Human Rights Policy and Development Department Directorate General Human Rights and Rule.
Framework of engagement : big data for official use Roy D. Ibay AVP Regulatory PLDT – Smart.
Convention 108 and the EU framework: Differing while Converging
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Data Protection: EU & International
General Data Protection Regulation
Convention108 in a snapshot
Information Governance and Data Privacy: A World of Risk
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Bob Siegel President Privacy Ref, Inc.
Legal Framework in Identity Systems T Koshy
Iain McDonald Information Commissioner
State of the privacy union
Protection of Personal Information Bill: An International Perspective
Consumer Protection Online
Welcome!.
Analysis of Privacy and Data Protection Laws and Directives
The Modernisation of Convention108
GDPR & Accountability ISACA Ireland Annual Conference 2018
Is Data Protection a Fundamental Right Protecting the Individual?
Slide 1 The State of the State in Cyberspace The Hybrid Regulation of Global Data Protection Ralf Bendrath University of Bremen Collaborative Research.
Professor at Kyung Hee Univ.
Overview of the recommendations regarding approximation of the Law on personal data protection to the new EU General data protection regulation Valerija.
EU Data Protection Legislation
Presentation transcript:

The Geopolitics of Personal Data and the Governance of Privacy Colin J. Bennett Department of Political Science University of Victoria BC, Canada Presentation to Conference on “Power and Difference,” Tampere, Finland, August 29 th

Trends in Surveillance Practices – The “New Transparency”  Routinization and expansion of "everyday surveillance”  Ambiguity about the nature of personal information  Surveillance of mobility and location  Embedding of surveillance in material objects  Peer-to-peer (horizontal) surveillance  Globalization of surveillance practices and processes Is the concept and regime of “privacy” appropriate to meet these challenges?

Justifications for Privacy in the West As a Right of the Person – La Vie Privée (France) – Privatsphäre (Germany) – The “ Right to be Let Alone ” (United States) – “Integritet” (Sweden) As a Political Value: A Check against Powerful State and Private Organizations As an Instrumental Value – To ensure that the right data are used by the right people for the right purposes – To build “ trust ” in e-commerce and e-government – To manage “risk”

The Sociological Critique of “Privacy” Rooted in individualism A rights-based discourse Excessive use of spatial metaphors Insensitive to discrimination and “social sorting” Cultural relativism

The Information Privacy Principles Accountability Purpose identification at time of collection Informed consent for collection To limit use and disclosure (finality) Retention limitation Data quality Data security Openness about policies and practices Individual access and correction

A principled-based approach appears in : Comprehensive data protection laws in around 80 countries Sectoral Legislation in information intensive industries International agreements from Council of Europe, OECD, European Union, Asia- Pacific Economic Cooperation Self-regulatory codes and management and technical standards

International Policy Convergence International policy learning Elite networking Policy harmonization Policy penetration

EU DATA PROTECTION DIRECTIVE/REGULATION OECD GUIDLINES COUNCIL OF EUROPE CONVENTION INTERNATIONAL STANDARDIZAATION ORGANIZATION APEC PRIVACY PRINCIPLES

The European Union Directive 95/46/EC on Personal Data Protection – Harmonization of all European Data Protection laws to higher and common standard – Insistence on a “supervisory authority” with common powers in each state – An “adequate level of protection” in countries that receive European personal data Directive 2009/136/EC: The “Cookie Rules” Draft Regulation on Data Protection, January 2012

The EU’s “Adequacy Standards” Articles 25 and 26 of the EU Data Protection Directive (1995) 95/46/EC Personal data should not be transferred outside EU unless an “adequate level of protection” which requires: – Basic content principles: Purpose limitation; data quality and proportionality; transparency; security; rights of access, rectification and opposition; restrictions on onward transfers – Procedural/enforcement principles: good level of compliance with the rules; support and help provided to individual data subjects; appropriate redress provided to the injured party Administered by Article 29 Working Party of Supervisory authorities

The Council of Europe Regime 1981 Convention on the Protection of Individuals with Regard to the Automatic Processing of Personal Data (Treaty 108) – Ratified by 25 countries – Signed by 33 countries – Recommendations on specific practices

The OECD Regime Guidelines on the Protection of Privacy and Transborder Flows of Personal Data(1981) Guidelines for the Security of Information Systems (1992) Guidelines for Cryptography Policy (1997) 30 year anniversary of guidelines and analysis of their future?

The APEC Regime The APEC Privacy Principles (2005) Pathfinder process for accountable cross- border flows of personal data within APEC

International Standards Regime ISO series (Data Security) ISO (Biometric Information Protection) ISO –( Framework for Identity Management). ISO – (A Privacy Framework) ISO (Privacy Reference Architecture)

The Policy Dilemma ADEQUATE LAWS? The presence of key legal principles An independent supervisory authority A good level of compliance ACCOUNTABLE ORGANIZATIONS? Makes original collector of personal data ‘responsible’ – ‘liable?’ Evaluates the “due diligence” of the organization – Use of contracts – Binding corporate rules – Self-certification schemes – Third-party certification to management and technical standards

The Framing (Discursive) Dilemma The Protection of “Privacy”? The Minimization of “Surveillance”?

The Geo-Political Dilemma National Sovereignty Personal Identity and Subjectivity The “Anti-Geography” of the Internet