Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.

Slides:



Advertisements
Similar presentations
MAKING SENSE OF IT:- WHAT IS DATA PROTECTION? Presented by the Data Protection Commissioner (Mrs D. Madhub) To the Truth and Justice Commission on
Advertisements

The Data Protection (Jersey) Law 2005.
Data Protection.
Legislation & ICT By Savannah Inkster. By Savannah Computer Laws 1.Data Protection ActData Protection Act 2.Computer Misuse ActComputer Misuse Act 3.Copyright,
DATA PROTECTION and Research University Research Ethics Committee – David Cauchi Office of the Data Protection Commissioner.
What does the Data Protection Act do? It sets standards which must be satisfied when obtaining, recording, holding, using, disclosing or disposing of.
Training at Ministry of Industry, Commerce and Consumer Protection Presented By: Mrs Dodah Pravina Mr Dookee Padaruth Date : 11 September 2014 Explaining.
Duncan Woodhouse – Assistant Registrar for Information Security, Risk Management and Business Continuity Helen Wollerton – Administrative Officer (Legal.
TITLE:- “How To Ensure Effective compliance with the Data Protection Act” PRESENTED BY:- The Commissioner, {Mrs D. Madhub} TO:- Lamco Insurance Ltd ON.
Data protection office(PMO)
4 TH FLOOR, E MMANUEL A NQUETIL B UILDING, P ORT L OUIS TEL: FAX: mail.gov.mu 8/12/
Audiences NI Data Protection Workshop
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Overview
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The Data Protection Act
Data Protection Act. Lesson Objectives To understand the data protection act.
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
Data Protection for Church of Scotland Congregations
DATA PROTECTION OFFICE
The Information Commissioner’s Office David Evans.
HIPAA PRIVACY AND SECURITY AWARENESS.
Elma Graham. To understand what data protection is To reflect on how data protection affects you To consider how you would safeguard the data of others.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection STFC Presentation to PPD Senior Staff 26/11/2009 FoI/DP team.
Data Protection Act AS Module Heathcote Ch. 12.
Data protection office (PMO) Title:- An overview of the Data Protection Act and its implications as regards registration and data subject access requests.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
The Data Protection Act (1998). The Data Protection Act allows you to Check if any organisation keeps information about you on computer or in paper form.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
The Data Protection Act - Confidentiality and Associated Problems.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
IT Applications Theory Slideshows By Mark Kelly Vceit.com Privacy Laws.
Data Protection for Church of Scotland Congregations.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
THE DATA PROTECTION ACT Data Protection Act 1998 DPA 1. Reasons2. People3. Principles 4. Exemptions 4 key points you need to learn/understand/revise.
Data Protection Act The Data Protection Act (DPA) is a balance between rights of the DATA SUBJECT and obligations of the DATA CONTROLLER DATA CONTROLLER.
Data Protection and research Rachael Maguire Records Manager.
DATA PROTECTION ACT (DPA). WHAT IS THE DATA PROTECTION ACT?  The Data Protection Act The Data Protection Act (DPA) gives individuals the right.
DATA PROTECTION ACT INTRODUCTION The Data Protection Act 1998 came into force on the 1 st March It is more far reaching than its predecessor,
GCSE ICT Data and you: The Data Protection Act. Loyalty cards Many companies use loyalty cards to encourage consumers to use their shops and services.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Data protection—training materials [Name and details of speaker]
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Clark Holt Limited (Co. No ), Hardwick House, Prospect Place, Swindon, SN1 3LJ Authorised and regulated by the Solicitors Regulation.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
Data protection act. During the second half of the 20th century, businesses, organisations and the government began using computers to store information.
Students’ Unions 2011 Data Protection and Students’ Unions Mairead O’Reilly 19 July 2011.
Data Protection GCSE ICT Mrs N Steventon-2005.
Data Protection and Confidentiality
FUNCTIONS OF THE Data Protection OFFICE
Managing Data Protection
Data Protection in AN organisation
Data Protection The Current Regime
Data Protection Legislation
PERSONAL DATA PROTECTION ACT 2010
Data Protection & Freedom of Information- An Introduction
GENERAL DATA PROTECTION REGULATION (GDPR)
New Data Protection Legislation
G.D.P.R General Data Protection Regulations
Data Protection principles
Data Protection and You
Identify the laws and guidelines that affect day-to-day use of IT.
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
General Data Protection Regulations (GDPR) Training
DATA PROTECTION OFFICE{PMO}
Presentation transcript:

Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please consult the Data Protection Office for further queries.

How does data protection concern me? And why it matters?

W o u l d y o u h a v e t h o u g h t t h a t … t h e s e d i g i t a l c o d e s m i g h t r e p r e s e n t I N F O a b o u t Y O U ! ! ! Data Protection & You

Bank Data Protection & You

Personal Sensitive Data Data Protection & You

Name Address Telephone Data Protection & You

Sensitive Racial/Ethnic Origin Political Opinion / Adherence Religious / Similar Belief Membership to Trade Union Physical / Mental Health Sexual Preferences / Practices Criminal Convictions Data Protection & You

Did You Know More than 50 countries have Laws related to International Data Privacy*. * Data Protection & You

Did You Know Identity theft cases and data breaches are increasing worldwide*. * Data Protection & You

TRUE or FALSE? Are data breaches also prevalent in Mauritius? Data Protection & You

You might be the next Victim, so it is important to know what Data Protection is about… Data Protection & You

As individuals, you should have control over your personal data. Your Rights & The Law

Enacted in 2004, Proclaimed in DPA provides a legal framework to ensure that your personal information is handled properly. Your Rights & The Law

But… Who Holds Info about Me? Your Rights & The Law

Data Controllers are: People who decide how to use personal data of living individuals A medical practitioner Human Resource Manager A sports club manager A public librarian Your Rights & The Law

Can data controllers do anything with my personal info??? Your Rights & The Law

The Data Protection Office (DPO) enforces the provisions of the Data Protection Act Mission of DPO: Safeguard the privacy rights of all individuals with regard to the processing of their personal data. Your Rights & The Law

Data Protection Commissioner Investigative Unit Finance Unit IT Database Unit Administrative Unit Your Rights & The Law

Register all data controllers and data processors in Mauritius Conduct periodical security checks and data protection compliance audits Research on data processing & computer technology Investigate Complaints Exercise control on all data protection issues Your Rights & The Law

1.Fairly and lawfully processed. 2.Collected for specified & lawful purpose/s. 3.Adequate, relevant and not excessive. 4.Accurate. 5.Not kept longer than necessary. 6.Processed in accordance with data subjects rights. 7.Secure. 8.Not transferred to countries without adequate data protection law. Data collected must be: Your Rights & The Law

How do I register as a data controller? 1 for Employee 1 for Non-Employee Non-employee is any personal information pertaining to clients/suppliers/creditors/debtors/shareholders/board of directors (non-salaried) or any other categories of persons who are not employees, e.g subcontractors Registration Basics

Online Registration at gov.mu gov.mu 1. Log-in with your Username and password Note: for 1 st time users, a user account must be created using the guidelines online 2. Complete 2 separate forms & submit online 3. Await validation from DPO 4. Make payment at DPO Get a copy of the application form at gov.mu gov.mu or at the DPO 1. Fill in 2 separate forms 2. Validate application forms at DPO 3. Make payment at DPO

Section 1 - Provide details about the organisation: public/private organisations, professionals, sole traders, partnerships, societes, etc... Section 2 – Provide details of a contact person Section 3 – List down only the TYPE of information and NOT the data being held for: (1)employee in the employee form and (2)non-employee in the non-employee form Note: ‘Name’ is a type but ‘John’ is the data. For registration purposes, only specify the type, i.e ‘Name’ Section 4 – Fill in for any sensitive data being held Section 5 – Describe nature of business Section 6 - Fill in for any disclosure to entities e.g National Pension Fund Section 7 – Fill in for any transfer of data abroad Section 8 – Confirm if information is disclosed to public Registration Basics

Make payments for BOTH forms. Payment for non-employee form will bear the same amount as the employee form. First time registrations for: Above 25 employees = Rs 2000 for employee + Rs 2000 for non-employee 1-25 employees = Rs 1000 for employee + Rs 1000 for non-employee Zero employee = Rs 800 for non-employee Registration Basics

Registrations have to be renewed annually by filling both employee and non-employee application forms with respective payments. Renewal fees for: Above 25 employees = Rs 1750 for employee + Rs 1750 for non-employee 1-25 employees = Rs 750 for employee + Rs 750 for non-employee Zero employee = Rs 550 for non-employee Registration Basics

Other Activities

Who can make a complaint to the Data Protection Office? Any individual who feels that the privacy rights with regard to his/her personal data may have been affected. Other Activities

1. Download and fill in a complaint form available on the Data Protection Office website. 2. Investigation is carried out on complaint unless complaint is of frivolous or vexatious nature. 3. Commissioner notifies complainant of the decision which has been taken. 4. Complainant can appeal to ICT tribunal if he/she is not satisfied with the decision. Other Activities

1. Download and fill in a Request for Access form found on the Data Protection Office website. 2. Submit the form along with a payment of Rs 75 to the data controller from whom the information is being requested. 3. Data controller must comply with a request not later than 28 days after receipt of request. Other Activities

Data Protection Act Enacted in 2004, proclaimed in 2009 D P O Data Protection Office Data Personal and Sensitive information Complaint Form Available from DPO Website Registration For both employee and non-employee Other Activities

Is the Data Protection Office a public one? Yes. Other Activities

What can the Data Protection Office do when a data controller contravenes the Data Protection Act? The Commissioner may serve an enforcement notice requiring the data controller to take steps and implement measures within a specified period of time. Other Activities

Is it an offence not to comply with the enforcement notice? Yes. Any person who does not comply with the enforcement notice and does not have a reasonable excuse for not complying, will commit an offence, the penalty of which will be a fine not exceeding Rs 50,000 and imprisonment not exceeding 2 years. Other Activities

DATA PROTECTION OFFICE 4 th Floor, Emmanuel Anquetil Building, Port Louis Website: Telephone: ,