Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April 2005

Slides:



Advertisements
Similar presentations
Re-use of PSI Data Protection Issues Cécile de Terwangne Professor at the Law Faculty, Research Director at CRIDS University of Namur (Belgium) 2 nd LAPSI.
Advertisements

PRIVACY ASPECTS OF RE-USE OF PSI: BETWEEN PRIVATE AND PUBLIC SECTOR
Data Protection & Privacy in the Information Age COMNET – Legal Frameworks for ICTs Malta 2013 Dr Antonio Ghio Dr Jeanine Rizzo.
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi David Cauchi Office of the Commissioner for Data Protection.
The data retention directive: data protection aspects Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg 375 B-1040.
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Convention for the protection of individual with regard to automatic processing of personal data “The purpose of this convention is to secure in the territory.
The Data Protection (Jersey) Law 2005.
Data Protection.
Legal issues linked to online recruitment Thibault Verbiest Attorney-at-law at the Brussels Bar and at the Paris Bar
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
The European Union legal framework for clinical data access: The European Union legal framework for clinical data access: potential challenges and opportunities.
1 Pertemuan 7 Points of Exposure Matakuliah:A0334/Pengendalian Lingkungan Online Tahun: 2005 Versi: 1/1.
Legal Liability & Data Protection Paul Van den Bulck Attorney-at-law at the Paris and Brussels Bars Partner Ulys Law Firm Lecturer at University Paris.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Audiences NI Data Protection Workshop
Data Protection Overview
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection for Church of Scotland Congregations
Lawyer at the Brussels Bar Lecturer at the University of Strasbourg Assistant at the University of Brussels Data Protection & Electronic Communications.
Copyright / Legal liability Paul Van den Bulck Brussels 28 November 2002 Law of : New Technologies Intellectual.
Ioannis Iglezakis Directive on privacy and electronic communications.
LexisNexis Confidential EU Privacy Framework Michael Lamb LexisNexis Risk Solutions Vice President and Lead Counsel: Regulatory, Privacy & Policy May 19,
Copyright / Legal liability Paul Van den Bulck Brussels 6 th of february 2004 Law of : New Technologies Intellectual.
The Data Protection Act 1998 The Eight Principles.
Copyright / Legal liability Paul Van den Bulck Brussels 6 th of june 2003 Law of : New Technologies Intellectual.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
Data Protection: An enabler? David Freeland, Senior Policy Officer 23 October 2014.
Data Protection Act AS Module Heathcote Ch. 12.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
Processing personal health data: the regulator’s perspective Ken Macdonald Assistant Commissioner Information Commissioner’s Office.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
DATA PROTECTION ACT DATA PROTECTION ACT  Gives rights to data subjects (i.e. people who have data stored about them on a computer)  Information.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Data protection—training materials [Name and details of speaker]
[ Direct marketing – an introduction to data protection and privacy] For [insert name of organisation] presented by [insert name of presenter] on [date]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
TRANSBORDER DATA FLOWS INA MEIRING. THE PROTECTION OF PERSONAL INFORMATION ACT (“POPI”) > 'personal information' means information relating to an identifiable,
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Data Protection: The Law
Data Protection and Confidentiality
Issues of personal data protection in scientific research
Data Protection The Current Regime
General Data Protection Regulation
Data Protection Legislation
GDPR Overview GDPR - General Data Protection Regulations
EU Directive 95/46/EC (Paragraph 2) “Whereas data-processing systems are designed to serve man; whereas they must Respect their fundamental rights.
Data Protection & Freedom of Information- An Introduction
The General Data Protection Regulation (GDPR)
G.D.P.R General Data Protection Regulations
GDPR Overview and Use Cases.
Data Protection principles
Data Protection and You
Relocation CARNIVAL come one…come all
Report on data protection legislation Case of Romania
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
Mathew Norman, Policy & Public Affairs Officer, RLA Wales
GDPR Workshop MEU Symposium Prague 2018
The EDPS: competences and processing of personal data in EU funds
Dr Elizabeth Lomas The General Data Protection Regulation (GDPR): Changing the data protection landscape Dr Elizabeth Lomas
EU Data Protection Legislation
Presentation transcript:

Attorney at the Bars of Paris and Brussels Database exploitation & Data protection Thibault Verbiest Amsterdam 1 April

Data Protection  General: Directive 95/46  Particular: Directive 2002/58 Overview legal aspects of databases Intellectual Property:  « Traditional copyright » protection for the structure  « Sui generis » protection for the content -Database: collection of independent data arranged in a systematic or methodical way and individually accessible by electronic or other means. - Substantial investment - Maker of a database has an exclusive right to prevent extraction and/or re-utilization

General & sector specific regulations General: 95/46 Protection of personal data General data protection principles Scope? Online and offline Public & private networks Specific 2002/58 Privacy & electronic communications Specific obligations (e.g., cookies, spam) Scope? Communication service Public networks

1. General Protection: Directive 95/46  Scope:  9 Principles of Data protection  Sensitive data Member States shall prohibit the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and the processing of data concerning health or sex life.  Case Studies Privacy Policy Collection of information Disclosure of data via webapplication

Scope: Directive 95/46  « Processing of personal data »  personal data: Information concerning a data subject identifiable natural person Direct or indirect Controller or third party Legal entity: SME? IP address?  Processing: Any operation performed upon personal data In the EU? Outsourcing to non-EU countries?

Data Protection Principles Data must be:  fairly and lawfully processed;  processed for specified, detailed and legitimate purposes;  adequate, relevant and not excessive;  accurate;  not kept longer than necessary;  processed in accordance with the data subject's rights;  Secure and remain confidential;  not transferred to countries without adequate protection (outside EU);  Processing activities « must » be notified to the supervisory authority.

Case study 1: Privacy Policy  Legally required?  Contents The name and address of the controller and processor (contract) Purposes of the processing activity The kind of data processed: « sensitive data » The means to collect and process data (cf. cookies) Inform the data subject on his/her rights and the way he/she can exercise them The technical and organizational measures adopted to ensure the secure and confidential character (cf. disclusure) Reference to general information on data protection legislation, e.g., FAQ, or the contact details privacy officer

Case Study 2: collection of information

 Processing « shall mean any operation … whether or not by automatic means, such as collection, recording, organization, storage, disclosure by transmission, dissemination or otherwise making available, etc. »  Means of collection: Data subject is aware,e.g., webform/ trade fairs Data subject is not aware, e.g., spy ware

Case Study 3: disclosure of personal data  Web database or online database  Database query to retrieve all persons with certain properties  Broad an open notion of « processing » includes « disclosure by transmission, dissemination or otherwise making available »  Pay attention to unauthorized disclosures  Personal details on website: Lindqvist case  Unauthorized access and retrieval of information  Transfer to third parties, e.g, business partners or other DB

2. Sector Specific regulation  Directive 2002/58/EC on privacy and electronic communication  One of the Directives of the new « Telecom Package »  Update of Directive 97/66 on privacy and telecommunications  Overview: scope contents Articulation with general framework

Scope: sector specific regulation  « This Directive shall apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Community. » Public networks: no private or corporate networks: « Individual » communication: no broadcasting Online exploitation, ASP? Includes: Protection of the legitimate interests of subscribers who are legal persons (SME). Scope is not always very clear & distinction sometimes too academic.

Sector specific regulation Contents: clarification of some principles  Cookies, spy ware  Security and confidentiality  Traffic & location data  Directories of subscribers, e.g., yellow pages  SPAM: collection and use of !

Sector Specific regulation  Pragmatic Approach and articulation:  Directive 95/46 applies to all networks  Obligations imposed by Directive 2002/58/EC, “covered” by Directive 95/46/EC  Example: Security: 2002/58 (art 4) The provider of a publicly available electronic communications service must take appropriate technical and organisational measures to safeguard security of its services, if necessary in conjunction with…. 95/46 (art.17) The controller must implement appropriate technical and organizational measures to protect personal data against … all other unlawful forms of processing.

Cookies – online identifiers  Online exploitation of database requires the identification of customers  Processing of personal data Directive 95/46  Directive 2002/58:  Legitimate purposes  User must be informed on the installation, on its purposes:  Users should have the opportunity to refuse to have a cookie  User should receive user-friendly information on how to refuse installation  Consequences of refusal – conditional access

Use of electronic contact details ( ) Unsolicited Communications: article 13 :  Principle: OPT IN : addresses must give their prior consent  How to obtain a prior valid consent?  Electronic mail: , sms, mms…pop up?  Exception: OPT-OUT if :  Existing commercial relationship  Same natural or legal person  Similar products or services  Consumer is given the opportunity to refuse reception (opt-out)  Opt-in data bases?

& Q UESTIONS c OMMENTS