Data Protection & FOI Data Protection: Background Human Right to Privacy Unenumerated right under Irish Constitution Explicit right under European Convention.

Slides:



Advertisements
Similar presentations
Centre for Freedom of Information The childhood leukaemia case – learning points in dealing with the balance between access to information and privacy.
Advertisements

Data Protection Billy Hawkes Data Protection Commissioner Irish Human Rights Commission 20 November 2010.
PUBLIC PROCUREMENT & FREEDOM OF INFORMATION ACT Presented by : SIOBHAN KENNY.
The Data Protection Act - an absolute right to ask but a qualified right to receive Maureen H Falconer Senior Policy Officer, ICO CELCIS, Scottish University.
Data Protection Information Management / Jody McKenzie.
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
DATA PRIVACY IN SOUTH AFRICAN LAW Brendan Hughes 2 nd International Direct Marketing Conference September 2006.
BC Freedom of Information and Protection of Privacy Act
Data Protection and Records Management
1 Data Protection and Research – Implications for a National Out-of-Hospital Cardiac Arrest Register NUI Galway Dept of General Practice Lunchtime seminar.
The Family Educational Rights and Privacy Act (FERPA) The Importance of Protecting Student Records This session will help you better understand the law.
Transparency in Public Administration – FOI and EIR
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Data Protection: The Law. EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection.
Data Protection Overview
"Can I give this out?" What Frontline Staff Need to Know About FOI and Privacy 2010 LGMA Administrative Professionals' Conference Paul Hancock, City of.
European Data Protection Supervisor Freedom of Information Day, Budapest, 28 September 2010 Data Protection and Freedom of Information at EU level Peter.
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
APPLICATION FOR ACCESS (PAIA) Mandatory protection (which must be refused in terms of Chap 4 subject to S46) DENIAL OF ACCESS (PAIA) Internal Appeal to.
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
Data Protection & Law Enforcement Seán Sweeney Assistant Commissioner Office of the Data Protection Commissioner Ireland Gibraltar January 27 th 2006.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
The Freedom of Information and Data Protection Legislation An Overview Ann McKeon November 2014.
DATA PROTECTION OFFICE {PMO} “OVERVIEW OF THE FUNDAMENTAL ASPECTS OF THE RIGHT OF ACCESS“ Presented by The Commissioner Mrs D. Madhub To Mutual Aid Association.
The Eighth Asian Bioethics Conference Biotechnology, Culture, and Human Values in Asia and Beyond Confidentiality and Genetic data: Ethical and Legal Rights.
Established in 1996 to enforce standards for electronic health information & enhance the security and privacy of health information.
Data Protection Act AS Module Heathcote Ch. 12.
H I P A A T R A I N I N G Self Directed Module 7 Research Disclosures For Data Custodians START Click to begin…
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
Data Protection Corporate training Data Protection Act 1998 Replaces DPA 1994 EC directive 94/46/EC The Information Commissioner The courts.
INTERNATIONAL E-DISCOVERY: WHEN CULTURES COLLIDE Alvin F. Lindsay Hogan & Hartson LLP.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
PROTECTING CLIENT DATA HIPAA, HITECH AND PIPA PART 1B.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
OPEN UP! Introduction to handling Freedom of Information requests.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Introduction Data protection is relevant to every individual, business or organisation today, not just Local Government. As well as protecting privacy,
Data Protection in a Workplace Context. Layout of Presentation Background to Data Protection Role of Data Protection Commissioner Principles of Data Protection.
1 The Public Interest Disclosure (Whistleblower Protection) Act.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
Your Rights! An overview of Special Education Laws Presented by: The Individual Needs Department.
The Health Information Protection Act. What is the Health Information Protection Act (HIPA)? HIPA is legislation that speaks to access to, and protection.
Record Keeping CPCAB LEVEL 4 THERAPEUTIC COUNSELLING.
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
Improving Compliance with ISAs Presenters: Al Johnson & Pat Hayle.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
František Nonnemann Skopje, 10th October 2012 JHA Data protection and re-use of PSI as a tool for public control–CZ approach.
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
František Nonnemann Skopje, 9th October 2012 JHA DP aspects related to provision of information about public figures in CZ.
The Freedom of Information and Data Protection Legislation An Overview
Fair and proportionate……?
The Protection of Confidential Commercial or Industrial Information in Environmental Law: Analysis and Call for a Graded Concept of Protection Prof. Dr.
Situation Analysis Access to Court Decisions in Georgia
Data Protection: The Law
Issues of personal data protection in scientific research
Data protection issues in regulatory investigations
Data Protection Legislation
GENERAL DATA PROTECTION REGULATION (GDPR)
Data Protection: Your Rights as a Data Subject
Data Protection and FOI
Move this to online module slides 11-56
G.D.P.R General Data Protection Regulations
How we use Your Health Records
Freedom of Information Act 2014
The Freedom of Information and Data Protection Legislation An Overview
Presentation transcript:

Data Protection & FOI

Data Protection: Background Human Right to Privacy Unenumerated right under Irish Constitution Explicit right under European Convention on Human Rights ECHR Act 2003 EU Data Protection Directives

EU & Irish Legislation Data Protection Directive 95/46/EC Electronic Privacy Directive 2002/58/EC EUROPOL etc Data Protection Acts 1988 & 2003 EC Electronic Privacy Regulations 2003 (SI 535/2003) Corresponding Acts Good Friday Agreement Disability Act 2005

Definitions: DP Personal Data  “Data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller “ (DP Act, Section 1)  Applies to any data that is processed (includes hosting) using any medium by a legal entity. Therefore paper, computer, network, web, phone etc.

FOI Personal Information (narrower) means information about an identifiable individual that_ (a) would, in the ordinary course of events, be known only to the individual or members of the family, or friends, of the individual, or (b) is held by a public body on the understanding that it would be treated by it as confidential, and, without prejudice to the generality of the foregoing, includes etc………….

DPFOI Information relating to the living individual only Information held on a relevant filling system Some potential to claim “disproportionate effort” in rare circumstances Also relates to the deceased Need to search for information No provision for not retrieving documents

DP/FOI Access to Personal Information DP and FOI Acts reinforce one another in relation to personal access in the public sector Defending access to personal information as human (DP) and citizen (FOI) right

Access to personal info: DP v FOI ? New Circular no 23 from D/Finance Where a request is made to a public body by, or behalf of, a person seeking access to their own personal information under the Freedom of Information Act, this request should also be taken as a request under the Data Protection Acts

Legislative Basis Section 1(5) of the Data Protection Act 1988 and 2003 requires co-operation between Data Protection and Information Commissioners Section 7(7) of the FOI Act imposes a duty on public bodies to assist people who request information or access to a record from a public body otherwise than under FOI.

Procedural Arrangements Decision should be made in shortest time possible under the Acts. Usually FOI at 20 Working days Suggest that public bodies review information on hand under each legislative framework and give the person the maximum amount of their personal data

Procedural Arrangements (2) if the decision is to grant access in full, there is no necessity to mention the other Act in the decision issued to the requester. If the decision is to refuse an individual access to some or all of her/his personal information, the decision letter should refer to the individual's tight to internal review under the FOI Acts and to the right to complain to the Data Protection Commissioner under the Data Protection Acts.

The Right of Access (1) Data subject must apply in writing & provide sufficient information  to satisfy data controller of his/her identity …  … and to locate any relevant data Data controller must give data subject a description of personal data held, its purpose and to whom it may be disclosed Data controller must supply a copy of the data  in intelligible format

Right of Access(2): Restrictions Investigation of crime, or assessing tax  Subject to case-by-case “prejudice” test International relations of the State legal professional privilege estimate of liability for damages or compo. data kept by DP or Info Commissioners for their functions Health and Social Work data: special provisions

Disclosure of Personal info to Third Parties DP No provision for release of personal information to third parties No obligation to release information in relation to third parties when responding to access request FOI Where a public interest outweighs the individual’s right to privacy consent