What if my organization conducts business across borders ? Your footnote Privacy and “Personal Information” have different meanings in different countries;

Slides:



Advertisements
Similar presentations
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
Advertisements

US Constitution and Right to Privacy Generally only protects against government action Doesn’t obligate government to do something, but rather to refrain.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
The Data Protection (Jersey) Law 2005.
Sarah Branam Mehmet MunurDino Tsibouris
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
Data Protection and Records Management
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
Chapter 9 Information Systems Controls for System Reliability— Part 2: Confidentiality and Privacy Copyright © 2012 Pearson Education, Inc. publishing.
Text Privacy and Data Protection in Sweden Christine Kirchberger.
DEED WorkForce Center Reception and Resource Area Certification Program Module 2 Unit 1b: WorkForce Center System II Learning Objectives III.
Information Privacy Policy in Canada Presented By: Sue Wu.
Class 13 Internet Privacy Law European Privacy.
Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection Act AS Module Heathcote Ch. 12.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Robert Guerra Director, CryptoRights Foundation Implementing Privacy Implementing Privacy: Rules of the Game for Developers Mac-Crypto Conference on Macintosh.
BC Public Libraries November, 2008 Privacy Principles.
IT Applications Theory Slideshows By Mark Kelly Vceit.com Privacy Laws.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Data Security & Privacy: Fundamental Risk Mitigation Tactics 360° of IT Compliance Anthony Perkins, Shareholder Business Law Practice Group Data Security.
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
CHAPTER SIXTEEN The Right to Privacy and Other Protections from Employer Intrusions.
Data protection act. During the second half of the 20th century, businesses, organisations and the government began using computers to store information.
UNHCR‘s Policy on the Protection of Personal Data of Persons of Concern - An introduction (October 2016)
Processing for archiving purposes in the GDPR
Data Protection GCSE ICT Mrs N Steventon-2005.
Data Protection and Confidentiality
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Privacy principles Individual written policies
Issues of personal data protection in scientific research
IT Applications Theory Slideshows
GDPR Overview Gydeline – October 2017
Data Protection Legislation
GDPR Overview Gydeline – October 2017
The European Union General Data Protection Regulation (GDPR)
GENERAL DATA PROTECTION REGULATION (GDPR)
The General Data Protection Regulation (GDPR)
G.D.P.R General Data Protection Regulations
Data Protection principles
Data Protection and You
Relocation CARNIVAL come one…come all
Report on data protection legislation Case of Romania
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
GDPR - New Data Protection Regulation
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR Workshop MEU Symposium Prague 2018
What is the Data Protection Act (DPA)? 1998
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Confidentiality Agreement
General Date Protection Regulation
General Data Protection Regulation Q & A Session
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
The supervision of personal data processing by EU institutions and bodies => data protection and privacy, why it matters, for you as citizens and as EU.
General Data Protection Regulation (GDPR)
The European Union’s General Data Protection Regulation (GDPR): Overview and Guidance SUNY Office of General Counsel Spring 2019.
Presentation transcript:

What if my organization conducts business across borders ? Your footnote Privacy and “Personal Information” have different meanings in different countries; however, you should be aware that privacy is regulated to one extent or another in most countries with which the U.S. does business. And regulation in this area is increasing and evolving rapidly. Privacy concerns come into play in any situation where uniquely identifiable information relating to a person is collected, processed and stored. These concerns apply regardless of whether an organization collects uniquely identifiable information in digital form or otherwise. Typical considerations for businesses and organizations that collect Personal Information may include: -how is Personal Information collected, stored, and associated? -who is given access to your customers’ Personal Information? -how is such information used? -does the individual have any ownership rights to such data, and/or the right to view, verify, and challenge that information?

Different Notions of “Privacy” Right to privacy primarily enforced as “consumer protection right” Privacy “balanced” against Free Speech; latter often prevails Implied (not express) right in U.S. Constitution Protection of people against Government overreaching, esp. at home Right to privacy as a “fundamental human right” Privacy as a “human dignity right” Art. 8 EU Convention of Human Rights: “…respect for…private and family life…home, and…correspondence”. Protection of people from having their lives exposed to public view, esp. mass media EUROPEAN UNION UNITED STATES Differences also stem from very different historical experiences

Privacy protection is privileged over economic efficiency and speech, even if this creates trade barriers Transfers of personal data in commerce, at work, etc. presumed to not be legitimate unless there is a “legal basis” (express consent; fulfillment of contractual or legal obligations) Data Protection Principles Most countries not deemed to offer “adequate protection” Free speech and interstate commerce privileged over privacy; protections crafted primarily for consumers Transfers of personal data are presumed legitimate and necessary (protections limited to situations of egregious misuse or unauthorized access) Regulation fragmented by economic sector (e.g., HIPAA, FCRA, HITECH, GLBA) not uniformly EUROPEAN UNIONUNITED STATES Different Approaches to Privacy Regulation

Canada often assumed to be similar to the U.S. with respect to business practices; but privacy regulation is another matter. Canadian approach to confidentiality and the transfer of Personal Information is much more in line with the European model than that of the U.S. Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) became effective in 2004 and provides a federal-level personal information protection regime Basic principles and obligations for organizations covered by PIPEDA: -obtain an individual's consent when they collect, use or disclose the individual's personal information. -the individual has a right to access personal information held by an organization and to challenge its accuracy, if need be. -personal information can only be used for the purposes for which it was collected. If purpose changes, consent must be obtained again. -individuals should also be assured that their information will be protected by specific safeguards, including measures such as locked cabinets, computer passwords or encryption. PRIVACY REGULATION IN CANADA Your footnote

Mexico enacted comprehensive data protection law in 2010, the “Law on the Protection of Personal Data in the Possession of Private Entities” (“LFPD”) LFPD regulates the processing of personal information by private companies (other than credit bureaus, which are regulated separately) and seeks to protect citizens’ rights to “privacy and to personal information self-determination”. The LFPD provides data subject s the right to give his/her consent to the processing of personal data, subject to certain statutory exceptions. The data controller must disclose to the data subject, through a privacy notice the information gathered about him/her and the use(s) to be given to said information. LFPD requires express written consent of the data subject for the disclosure of sensitive personal data (incl. ethnic origin, current or foreseeable health condition(s), genetic information, religious, philosophical or moral beliefs, labor union affiliation, political opinions and/or sexual orientation). The LFPD creates a right of civil action for data subjects for the data controllers’ breaches of the LFPD. PRIVACY REGULATION IN MEXICO Your footnote

How to Address Privacy Compliance Across National Borders with Different Constituencies Business Partners Employees Customers Service Providers B-2-B agreements regarding use of personal information Privacy Policy Terms and Conditions Representations made re: Use of Personal Information Internal policies and procedures regulating access to and use of personal information Agreements to use personal information only for your organization Your Organization Your Organization

s_2012/$FILE/Privacy-trends-2012_AU1064.pdf s_2012/$FILE/Privacy-trends-2012_AU1064.pdf ataProtection_326jpm.pdf ataProtection_326jpm.pdf Other Country Regulation & Select Resources Your footnote