THE CHOICES WE MAKE THAT MATTER – International Data Privacy/Protection JILL L. UREY, ASSISTANT GENERAL COUNSEL MID-ATLANTIC CIO FORUM NOVEMBER 20, 2014.

Slides:



Advertisements
Similar presentations
EU Privacy Directive. What is a directive? A piece of European legislation, passed by bureaucrats, addressed to member states Member states must ensure.
Advertisements

Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
International Employment – latest Digital Employment issues Melanie Lane and Karine Audouze.
The Gathering Cloud computing - Legal considerations David Goodbrand, Partner 28 February 2013 Aberdeen Edinburgh Glasgow.
Data Protection.
© 2005 Morrison & Foerster LLP All Rights Reserved Data Security and Incident Notification: The Impact of Foreign Law Presented April 26, 2006 to EDUCAUSE.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
Hong Kong Privacy Code on Human Resource Management
Data Protection and Records Management
Managing Personal Information - Australian Companies Outsourcing to India and the Philippines Professor Margaret Jackson and Marita Shelly.
Lecture to Carleton University, Center for European Studies, December 1, 2010.
Per Anders Eriksson
The U.S.-E.U. Safe Harbor Framework The U.S.-E.U. Safe Harbor Framework New Developments in Data Flows, Standards, & Compliance Damon Greer U.S. Department.
Anomalous Aspects of Transfer of Personal Data from the E.U. to the U.S. Stephen R. Bell Willkie Farr & Gallagher ABA Section of International Law New.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
Kirkpatrick & Lockhart LLP Attorneys At Law Boston, Dallas, Harrisburg, Los Angeles, Miami, New York, Newark, Pittsburgh, San Francisco, Washington,
Class 13 Internet Privacy Law European Privacy.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
NCA guide for businesses Selling via a website An overview of the key rules if you sell online to consumers.
LegalTech Asia DATA PRIVACY LAWS UPDATE Edward Chatterton 4 March 2013.
European data protection and privacy regulations Johny GASSER Orange Business Services – Consulting & Solutions Integration International Cyber Center.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
E-COMMERCE AND PRIVACY LAWS IN THE UAE Rindala Beydoun Senior Legal Counsel Al Tamimi & Company.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
European Data Protection Supervisor Pharmaceutical Regulatory & Compliance Congress, Brussels, 7 June 2007 European Privacy and Data Protection Policy.
International Investigations: Issues to Consider When Conducting or Defending Against an FCPA Investigation Outside the United States Presented by: Sandee.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
WHOIS data The EU legal principles ICANN - GNSO meeting 2 March 2004 George Papapavlou, European Commission ICANN - GNSO meeting 2 March 2004 George Papapavlou,
Risky business legal tips for safe selling online Internet World Nigel Miller Partner, Fox Williams LLP 1 May 2008.
Dino Tsibouris (614) Updates on Cloud, Contracting, Privacy, Security, and International Privacy Issues Mehmet Munur (614)
1 TAIEX JHA Workshop on data protection and cloud computing Data transfers to third countries and standard contractual clauses Skopje, 29 May 2014.
Data protection—training materials [Name and details of speaker]
Key Points for a Privacy Programme for Multinationals Steve Coope.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Industry 4.0 – New ways of cooperative working – are we prepared?
Surveillance around the world
Data Protection: The Law
Contingent Workforce: Global Privacy Laws Overview
Data Protection: EU & International
Data Protection The Current Regime
General Data Protection Regulation
International Regulatory Trends
GDPR Readiness Project
Information Governance and Data Privacy: A World of Risk
The European Union General Data Protection Regulation (GDPR)
Bob Siegel President Privacy Ref, Inc.
The General Data Protection Regulation (GDPR)
Welcome to Glatfelter PEOPLE
G.D.P.R General Data Protection Regulations
Employee Privacy and Privacy of Employee Information
GDPR Overview and Use Cases.
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR Workshop MEU Symposium Prague 2018
Data transfers to non-EU countries under the new GDPR
GDPR & Accountability ISACA Ireland Annual Conference 2018
European Commission proposals for data protection
The European Union’s General Data Protection Regulation (GDPR): Overview and Guidance SUNY Office of General Counsel Spring 2019.
EU Data Protection Legislation
General Data Protection Regulation
Presentation transcript:

THE CHOICES WE MAKE THAT MATTER – International Data Privacy/Protection JILL L. UREY, ASSISTANT GENERAL COUNSEL MID-ATLANTIC CIO FORUM NOVEMBER 20, 2014

Agenda 1. Overview of Glatfelter 2. Data Privacy/Protection Introduction 3. European Union Requirements 4. Non-EU Highlights 5. Trends 6. Tips and Guidance 7. Questions 1. Overview of Glatfelter 2. Data Privacy/Protection Introduction 3. European Union Requirements 4. Non-EU Highlights 5. Trends 6. Tips and Guidance 7. Questions 1

Glatfelter products are marketed in over 90 countries around the world 2 GLATFELTER – Global supplier of choice for fiber-based engineered products Founded in 1864; Publicly traded on the NYSE as GLT Annual sales of $1.8 billion; 4,400 employees worldwide Manufacturing Facilities: U.S., Germany, U.K., Canada, France, Philippines Sales / Representative Offices: U.S., Germany, France, U.K., China, Russia

Specialty Papers Feminine Hygiene #1 Adult Incontinence #1 Specialty Wipes/Towels #2 Trade Book Publishing#1 Carbonless Products#1 Postal Applications#1 Playing Cards#1 Greeting Cards#2 Tea Bags/Coffee Filters #1 Nonwoven Wallcovering #1 Composite Laminates #1 Battery Pasting Papers #1 Metallized Products #2 Composite Fibers Advanced Airlaid Materials GLATFELTER – Leading Positions in Niche Markets 3 Total net sales of $1.8 billion

Supplier of Choice to a Well Respected Customer Base 4 Random House Specialty PapersComposite FibersAdvanced Airlaid Materials GLATFELTER – Strong Relationships with Global Customers

Introduction to Data Privacy/Protection PERSONAL DATA Any information that identifies or can be used to identify an individual:  Name  Address   Phone Number  ID Number  Date of Birth  Health Information  Banking Information  Marital Status, etc. PERSONAL DATA Any information that identifies or can be used to identify an individual:  Name  Address   Phone Number  ID Number  Date of Birth  Health Information  Banking Information  Marital Status, etc. 5 Data Privacy/Protection Laws regulate the Processing of Personal Data PROCESSING Includes the following:  Collection  Use  Storage  Sharing  Transmission  Alteration  Deletion PROCESSING Includes the following:  Collection  Use  Storage  Sharing  Transmission  Alteration  Deletion

European Union Data Protection EU Data Protection Directive (95/46/EC) Article 29 Working Party Laws: The collection, processing and use of Personal Data is banned unless an exception applies. Data Subjects have the right to know why and how their Personal Data is collected and processed. Principles: Consent of Data Subject Legal Obligation or Public Interest Performance of Contract Protection of Vital Interests of Data Subject Legitimate Interests of Data Collector Exceptions: 6

EU Data Protection – Personal Data Transfers Outside the EU Safe Harbor Certification 1.Joint EU Commission and US Department of Commerce Program 2. Companies certify compliance with EU data protection standards 3. Annual certification for employee personal data and third party personal data Corporate Binding Rules 1. Internal rules/policies of company meeting EU data protection standards 2. Approved by relevant EU member’s Data Protection Authority 3. Approval times vary 7

EU Data Protection - Controllers and Processors 8 Data Transfers:  Statutory Justification  Data Subject Consent  Data Processing Agreement  Safe Harbor Certification OR Corporate Binding Rules  Standard Contractual Clauses

EU Data Protection – Additional Member States’ Requirements Co-Determination Rights Data Protection Officers Individual Employee Consent Consultation with Works Councils Declaration filing with the Data Protection Authority (CNIL) Notification to U.K. Information Commissioner 9 Germany France United Kingdom

Highlights of Non-EU Data Protection Requirements Data Transfer Agreement Explicit Consent from Data Subjects National and Provincial Laws Data Transfer Agreements/Sharing Protocols Employee Notification of International Transfers Written Consent from Data Subjects Notification to Russian State Regulator if Processing Customer Data 10 China Canada Russia

Trends – Enforcement News · BRAZIL: Telecom company fined $1.59 million for violating users privacy. HONG KONG: Privacy Commissioner condemns employment agencies from collecting personal data for job applicants via blind recruitment advertisements. · U.K.: An individual awarded nominal damages for emotional distress due to data breach. IRELAND: Successfully prosecuted individual directors of a company for disclosures of personal data without the consent of the data controller. 11

Trends – EU Cookie Audits 12 EU ePrivacy (“Cookie”) Directive  Users must be informed about the use of cookies on a company’s website  Users have the right to consent to cookies prior to use  Exception for cookies that are strictly necessary to delivery of an on-line service  Jurisdictional split on consent: Express vs. Implied  Cookie sweeps and audits EU ePrivacy (“Cookie”) Directive  Users must be informed about the use of cookies on a company’s website  Users have the right to consent to cookies prior to use  Exception for cookies that are strictly necessary to delivery of an on-line service  Jurisdictional split on consent: Express vs. Implied  Cookie sweeps and audits

Trends – Proposed EU Data Protection Revisions Prior authorization of a national data protection authority required before personal data may be transferred to non- EU country. Fines increased to the greater of €100 million or 5% of annual worldwide turnover. Data Subjects have right to demand erasure of personal data. Internet service providers processing personal data must receive explicit consent from the data subject. 13

Tips and Guidance AssessmentTechnologyDocumentationCommunication 14

Thank you! Questions? 15