Terra Incognita Auditing for Privacy Workshop: Chairman’s Remarks

Slides:



Advertisements
Similar presentations
The organisation of labour inspection in France. Labour inspection within the Ministry of Labour Centre C Competition Consumer spending Fraud prevention.
Advertisements

VOLUNTARY PRINCIPLES ON SECURITY & HUMAN RIGHTS. What are the Voluntary Principles? Tripartite, multi-stakeholder initiative Initiated in 2000 by UK Foreign.
1 INTERNATIONAL STANDARDS on data protection & privacy Artemi Rallo Lombarte Director Agencia Española de Protección de Datos.
1 Agencia Española de Protección de Datos AUDITING AND ENFORCEMENT AT THE SPANISH DPA. EXPERIENCE WITH OUTSOURCING TO COUNTRIES WITH A NON ADEQUATE LEVEL.
1 Enforcement Powers of National Data Protection Authorities and Experience gained of the Data Protection Directive Safe Harbour Conference Washington.
Yukiko Ko Binding Corporate Rules – Global Implications Conference on Cross Border Data Flows and Privacy October 16, 2007.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
STRATEGIC PLANNING FOR Post-Clearance Audit (PCA)
The importance of a Compliance program is to ensure that our agency meets the highest possible standards for all relevant federal, state and local regulations,
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
Developing a Records & Information Retention & Disposition Program:
Europol’s tailor-made data protection framework
Information Systems Security Officer
Evaluation of the Role of Audit to Detect Corruption in Thailand Prepared by Dr. Sutthi Suntharanurak Office of the Auditor General of Thailand.
1 Regulatory Challenges During and Following a Major Safety or Security Event Muhammad Iqbal Pakistan Nuclear Regulatory Authority Presentation at General.
Human Rights Advocacy “Never doubt that a small group of thoughtful, committed citizens can change the world; indeed, it’s the only thing that ever has.”
ZHRC/HTI Financial Management Training
STRATEGIC PLANNING FOR Post-Clearance Audit (PCA)
FDA Recalls Risk Communication Advisory Committee David K. Elder Director, Office of Enforcement.
The Sixth Annual African Consumer Protection Dialogue Conference
National Workshop on Labour Inspection and Undeclared Work Budapest, October 2009 Collaboration between the GLI EA and Other National Bodies to Address.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
Wetlands Reserve Program Case Study An Overview of the External Audit Process Helping People Help The Land.
Institutional Research Compliance Juliann Tenney, JD Research Compliance and Privacy Officer Director, Institutional Research Compliance Program.
Grosu-Axenti Diana Financial Inspection Director Financial Inspection vs External & Internal audit in Republic of Moldova.
Internet Governance and Regulation Internet Safety : Concrete Ways Forward For Government-Industry Partnerships Baltic IT&T 2005 David Finn Senior Attorney.
Why the Office of Compliance and Ethics was Created
© OECD A joint initiative of the OECD and the European Union, principally financed by the EU Co-operation Between the Ministry of Finance and the Court.
Proposed plan to implement Capacity Development for CDM project in the forthcoming period Dr. DAO DUC TUAN Eng. NGUYEN KHAC HIEU National Office for Climate.
1 Information Sharing Environment (ISE) Privacy Guidelines Jane Horvath Chief Privacy and Civil Liberties Officer.
EU perspective on occupational health and safety - role and place of unions Károly György Kiev, December December Károly György, MSZOSZ.
International Cooperation and Capacity Building on Competition: A Swiss Perspective 7up2 Project Final Meeting Bangkok, June 28, 2006 Dr. Patrick Krauskopf.
June 1, st Asia Pacific Privacy Authorities (APPA) Forum – PHAEDRA Workshop Nr. 3: The EU Data Protection Regulation and regional perspectives.
MOSCOW, NOVEMBER 12 – 14, THE RESEARCH 1.Respondents 8 respondents from SAI Indonesia : auditor, investigator, R &D 2.Time 3 weeks (Sept to Oct.
OMB Memorandum M Implementation of the Government Charge Card Abuse Prevention Act of 2012 (Charge Card Act) September 2013.
Fred Carter Senior Policy & Technology Advisor Information and Privacy Commissioner Ontario, Canada MISA Ontario Cloud Computing Transformation Workshop.
Occupational Safety and Health Reps, their role and functions in the EU.
Implementing the New EU General Data Protection Regulation Conference 2016 Preparing for a DP audit Ashley Roughton Nabarro LLP.
© 2007 Her Majesty the Queen in Right of Canada (Canadian Food Inspection Agency), all rights reserved. Use without permission is prohibited. Summary of.
Practical Analysis of Obstacles Encountered by Legal Services as Part of Access to Information Requests Presentation to the Canadian Institute at the Conference.
Surveillance around the world
The Spanish experience of enforcing privacy norms Two decades of evolution from sticks to carrots Dr. Artemi Rallo Constitucional Law Professor Regulator's.
CPA Gilberto Rivera, VP Compliance and Operational Risk
Bob Siegel President Privacy Ref, Inc.
Presentation transcript:

29e Confrence internationale des commissaires à la protection de la vie prive

Terra Incognita Auditing for Privacy Workshop: Chairman’s Remarks 2007 International Data Protection and Privacy Commissioner’s Conference Montreal, Quebec, Canada Workshop # 3 – Audit Wednesday, September 26, 2007 1:30 – 4:00 pm Dr. Artemi Rallo Lombarte Director, Spanish Data Protection Agency 29e Confrence internationale des commissaires à la protection de la vie prive

What is Auditing? Audit vs. Inspection Audit – initiated by DPA or data controller proactive overview to establish general compliance, usually results in recommendations Inspection – in response to a complaint or DPA concern investigation of a specific area of suspected breach, can result in sanctions Effective enforcement requires both proactive and reactive components In the context of this panel, we’ll refer generally to “auditing” – an inclusive idea 29e Confrence internationale des commissaires à la protection de la vie prive

Spanish Auditing Process 20% Preventive Enforcement Systematic audits – public and private sectors Results in recommendations, but issue a Resolution too Includes non-audit actions: guidelines, consultations, publicity 80% Reactive Enforcement Law mandates AEPD to resolve every citizen complaint Usually resolved with request for voluntary information submission can search in situ or issue subpoenas fines assessed for violations – based on nature of infraction as minor, serious, or very serious as defined by law  Inspection by IT experts - submit factual report to Legal Department  Legal Department analyzes report, initiates sanction procedures if needed, makes recommendation for Resolution  Director approves Resolution; appealable in court 29e Confrence internationale des commissaires à la protection de la vie prive

Collaborative Enforcement: Bilateral Cooperation in the EU 2000 – AEPD fines a content provider for posting personal data of police officers on its website No fine to ISP – content removed immediately upon injunction 2006 – notification that content still exists on a Dutch mirror site Collaboration with NL DPA (CBP) to remove content CBP sent an information request to the Dutch ISP, with attached AEPD Resolution on illegality of data Immediate removal of content by ISP Cooperative strategy and tools Exchange of information on Spanish action and outcomes Investigation of site by CBP, factual (whois) and legal analysis Collaborative development of enforcement strategy Consistent communication of actions and status 29e Confrence internationale des commissaires à la protection de la vie prive

Collaborative Enforcement: Why Synchronized Auditing? Enforcement’s goal is to increase compliance Biggest enforcement obstacle is resource limitations Synchronized enforcement can harmonize DP practices Information sharing and cooperation to reduce divergence in MS simplify enforcement, use best practices, more efficient enforcement Unified practices to permit self-regulation like BCR diminish enforcement burdens improve compliance sector-wide Vital to refine approach and pursue joint action 29e Confrence internationale des commissaires à la protection de la vie prive

Collaborative Enforcement: Multilateral Cooperation in the EU Overall positive compliance, with some areas of concern Moving forward: Recommendations to correct gaps in compliance Non-participant data controllers should note findings Analyze and refine methodology for future actions Continue to coordinate joint enforcement with representative organizations like CEA Properly equip DPAs for effective enforcement Improve survey instrument – clearer questions, more focused Pursue in-depth follow-up investigations to improve compliance, not just take its temperature 29e Confrence internationale des commissaires à la protection de la vie prive

Collaborative Enforcement: Cooperation with Third Countries Unprecedented enforcement action outside the EU: in situ inspections of data transferred to Colombia Legal basis: model contract clause for international data transfers Where data is transferred internationally, DPA may conduct audits of the importer, using the same techniques and tools that are available for audits of the exporter in the DPA’s jurisdiction Telecom company included clause in contract for Colombian tech support outsourcing AEPD awareness that data might be at risk of misuse or vulnerable to security breaches; decision to audit in situ 29e Confrence internationale des commissaires à la protection de la vie prive

Collaborative Enforcement: Cooperation with Third Countries Cooperation and facilitation by exporter (data controller) Coordinated inspections Served as contact point for audits Audited all involved data importers in Colombia 5 days of auditing in Colombia 3 inspectors + Inspection Subdirector Document access and examination in situ checks of technical systems Access to and evaluation of information stored in the system in situ verification of security measures Findings: general compliance with technical and organizational security requirements Importers saw audit as a helpful experience to improve practices 29e Confrence internationale des commissaires à la protection de la vie prive

Dr. Artemi Rallo Lombarte Director, Spanish Data Protection Agency http://www.aepd.es 29e Confrence internationale des commissaires à la protection de la vie prive

Workshop 3 Panelists Mr. Chris Turner Mr. Joel Winston Head of Audit and Remedies, Office of the Information Commissioner, UK Mr. Joel Winston Associate Director of Privacy and Identity Protection Branch, FTC Consumer Protection Bureau, USA Mr. Nicholas Cheung Principal, Assurance Services Development of the Canadian Institute of Chartered Accountants Ms. Yim Chan Global Privacy Executive, IBM and Chief Privacy Officer, IBM Canada 29e Confrence internationale des commissaires à la protection de la vie prive