Data Protection and Records Management

Slides:



Advertisements
Similar presentations
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
Advertisements

Data Protection: Your Duties as a Data Controller
Data Protection Information Management / Jody McKenzie.
The Data Protection (Jersey) Law 2005.
Data Protection.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
1 Data Protection and Research – Implications for a National Out-of-Hospital Cardiac Arrest Register NUI Galway Dept of General Practice Lunchtime seminar.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Audiences NI Data Protection Workshop
Class 13 Internet Privacy Law European Privacy.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
Data Protection for Church of Scotland Congregations
Data Protection & Government Departments Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 2006.
Respecting the Consumer – the Data Protection Perspective Billy Hawkes Data Protection Commissioner Association of Advertisers in Ireland 3 June 2009.
Data Protection in the Health Sector. Survey Results (2005) (1) Is privacy important? important very important Crime Prevention 7%91% Personal Privacy9%89%
Data Protection & Law Enforcement Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 27 th 2006.
The Data Protection Act 1998 The Eight Principles.
The Freedom of Information and Data Protection Legislation An Overview Ann McKeon November 2014.
Data Protection & Commercial Sector Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 24 th 2006.
Managing Risks Associated With Privacy Alison Baker- Senior Associate Hall & Wilcox 24 November
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection and the Voluntary Sector: Respecting the Rights of the Individual Billy Hawkes Data Protection Commissioner Carmichael Centre Dublin, 2.
Data Protection & FOI Data Protection: Background Human Right to Privacy Unenumerated right under Irish Constitution Explicit right under European Convention.
Data Protection Act AS Module Heathcote Ch. 12.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
The Data Protection Act - Confidentiality and Associated Problems.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
DATA PROTECTION ACT 1998 Became law on 1 March 2000 Only applies to the use of personal data, that is data which relates to an identifiable living individual,
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data Protection and Records Management. Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for.
Data Protection for Church of Scotland Congregations.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
INTRODUCTION TO DATA PROTECTION An overview of the Irish Data Protection legislation.
Data Protection in a Workplace Context. Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
The Freedom of Information and Data Protection Legislation An Overview
Data Protection: The Law
Issues of personal data protection in scientific research
Data Protection: EU & International
Data Protection The Current Regime
Data protection issues in regulatory investigations
Data Protection Legislation
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection: Your Rights as a Data Subject
New Data Protection Legislation
G.D.P.R General Data Protection Regulations
Data Protection principles
Data Protection and You
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Presentation transcript:

Data Protection and Records Management

Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection Key Responsibilities of Record Managers Key information Points

Data Protection: Background Human Right to Privacy Unenumerated right under Irish Constitution Explicit right under European Convention on Human Rights ECHR Act 2003 EU Data Protection Directives

EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection Acts 1988 & 2003 EC Electronic Privacy Regulations 2003 (SI 535/2003) Corresponding Acts Good Friday Agreement Disability Act 2005

Definitions: Personal Data “Data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller “ (DP Act, Section 1) Applies to any data that is processed (includes hosting) using any medium by a legal entity. Therefore paper, computer, network, web, phone etc.

Definitions - Sensitive Personal Data Sensitive Personal Data (more protection) Racial/ethnic origin; political opinions; religious/philosophical beliefs; trade union membership; health; sexual life; criminal record

Definitions Data Controller a person who controls the contents and use of personal data Data Processor A person who processes personal data on behalf of a data controller

Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection Key Responsibilities of Record Managers Key information Points

Role of the Data Protection Commissioner Ombudsman Role: resolution of disputes between data subjects and data controllers or processors Enforcer Role: compliance by data controllers & processors Educational Role: Promotes DP rights and good practice Registration Authority: obligation on major holders of personal data to be placed on public register

How does DPC fulfill role? Investigations/Audits Arising from complaints On own initiative Maintains public register Codes of Practice Guidance booklets, website, presentations, advice, Annual Report

Penalties Fine of up to €100,000 Court may order deletion Enforcement notice prohibiting processing Data subject could pursue civil action for damages under section 7 of the Act

Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection Key Responsibilities of Record Managers Key information Points

The Data Protection Rules Fair obtaining & processing Consent Specified purpose No disclosure unless “compatible” Safe and secure Accurate, up-to-date Relevant, not excessive Retention period Right of access

Responsibilities on Data Controllers –record managers - at the different stages Beginning Getting the Data Middle While you have the data End Disposing of data

Keep accurate Have a retention policy Inform and get consent Justification to process Beginning Getting the Data Middle While you have the data End Disposing of data Specify purpose Disclose only if compatible or allowable exception Keep secure and dispose securely Respond to access requests Only gather what is required

Keep accurate Have a retention policy Inform and get consent Justification to process Beginning Getting the Data Middle While you have the data End Disposing of data Specify purpose Disclose only if compatible or allowable exception Keep secure and dispose securely Respond to access requests Only gather what is required

Keep accurate Have a retention policy Inform and get consent Justification to process Beginning Getting the Data Middle While you have the data End Disposing of data Specify purpose Disclose only if compatible or allowable exception Keep secure and dispose securely Respond to access requests Only gather what is required

Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection Key Responsibilities of Record Managers Key information Points

Key Responsibilities - Record Management Keep Information Accurate Disclose only if compatible with purpose for which given Keep secure Have a retention policy Dispose and retain in line with retention policy

1. Accurate Good business practice Best achieved at point of collection Ongoing requirement if intended to be used. Ask the data subject if needed

2. Non-Disclosure General rule – no disclosure for different purpose Exceptions made, to balance other interests of society Stricter conditions for sensitive data Main exceptions: Investigation of crime Collection of taxes Security of the State Protect life & limb Required by Law Intl Relations Consent

2. Non-Disclosure The Data Controller should have a policy in place to determine how requests for data from third parties are handled. This policy should be consulted by appropriate staff members

3. Keep secure Internal Access controls– physical,technical, Tracking of activity on files– to see if appropriate Internet Connectivity/networks -anti-virus software/firewalls/encryption Access- need to know and relevant to purpose Third party interception

3. Keep secure Accidental disclosure to third parties, PC in public area, non-secure fax External-robust encryption, online forms, technical measures Audit trails, reviews, logs, unusual events Manual Files ! Individual is the biggest risk- NB Training

4. Retention Policy Legal obligations to hold data? Customer files Do you need to hold all that data? Personnel files Revenue requirement? Must have policy thought through Defend retention as necessary for purpose.

4. Retention Policy – Public Bodies Overlap between data protection rights of identifiable persons and obligation to keep data for passing to the National Archives in 30 years Balance between rights of the person and public interest. In discussion with National Archives and D/Education Option of Regulations under the DP Acts specifying the appropriate period that such records may be held

5. Follow Retention Policy A method appropriate to each organisation to review files Assign Responsibility Reporting structure Delete personal data that is outside terms of policy. Keep a record of deletions

Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection Key Responsibilities of Record Managers Key information Points

Key Information Points Right of Access Right of Correction/Erasure Manual Data Exemption

Right of Access A fundamental rights granted to individuals as a means of granting them control over how their data are processed – transparency Applies to all manual and electronic records in existence at the time of receipt of an access request – regardless of when the record was created.

Right of Access Every person has the right to access their data held by any organisation subject to very limited exemption outlined in Sections 4 & 5 of the Data Protection Acts Commissioner takes this right very seriously and is now using legal enforcement powers to enforce rights

Right of correction/erasure Section 6 of the Act Data Subject makes a written request Personal data must be: Corrected, if inaccurate; or Deleted, if should not be held. Data Controller has 40 days to respond No fee

Manual data Manual data on file on October 2003 has been exempt from some rules until 24 October 2007 section 2 (identity of Data Controller, purposes of processing, any disclosees) sections 2A (legitimate processing) and 2B (sensitive data) – see over All other provisions – including right of access and correction – apply already

Manual Data -Process Fairly One of these conditions required: Consent Legal obligation Contract with individual Necessary to protect vital interests Necessary for a public function (Justice) necessary for ‘legitimate interests’

Manual Data - Process Sensitive Data fairly One of these additional conditions is required Explicit consent Necessary under employment law To prevent injury or protect vital interests Process the data of members/clients of non-profit orgs. Legal advice For Medical Purposes Statutory function