Www.informationpolicycenter.com Privacy: An International Perspective Marty Abrams August 18, 2008.

Slides:



Advertisements
Similar presentations
1 Prof. Dr. Josef Drexl Unit for Intellectual Property and Competition Law Max Planck Institute for Intellectual Property, Competition and Tax Law International.
Advertisements

Global Sourcing, Global Teaming Martin Abrams October
Yukiko Ko Binding Corporate Rules – Global Implications Conference on Cross Border Data Flows and Privacy October 16, 2007.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
International Privacy Laws Ashley Michele Green Sensitive Information in a Wired World October 30, 2003.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
Regulation and Risk Management for Cross-Border Insurance Groups
Section 4 Introduction-1
Competition provisions in plurilateral regional trade agreements Anestis Papadopoulos Hellenic Competition Commission.
Sarah Branam Mehmet MunurDino Tsibouris
© 2005 Morrison & Foerster LLP All Rights Reserved Data Security and Incident Notification: The Impact of Foreign Law Presented April 26, 2006 to EDUCAUSE.
The Geopolitics of Personal Data and the Governance of Privacy Colin J. Bennett Department of Political Science University of Victoria BC, Canada
Completing the EU internal energy market
The Trade and Labour Linkage: The Canadian Perspective LABOUR PROGRAM Pierre Bouchard Director Office for Inter-American Labour Cooperation Labour Branch,
Global Marketing Chapter 3
Managing Personal Information - Australian Companies Outsourcing to India and the Philippines Professor Margaret Jackson and Marita Shelly.
Harmonization and International Accounting Standards
©2004 Prentice Hall2-1 Chapter 2: Global Marketplaces and Business Centers International Business, 4 th Edition Griffin & Pustay.
High Technology Cooperation Group: Data Privacy The Indo-U.S. High Technology Cooperation Group November 18, Privacy and Cyber Security:
Transborder dataflows Flow of information across national borders Much of this data involves personal information.
Anomalous Aspects of Transfer of Personal Data from the E.U. to the U.S. Stephen R. Bell Willkie Farr & Gallagher ABA Section of International Law New.
Data Protection: International. Data Protection: a Human Right Part of Right to Personal Privacy Personal Privacy : necessary in a Democratic Society.
SERVICES TRADE RESTRICTIVENESS INDEX PROFESSIONAL SERVICES ARCHITECTURE Russell V. Keune Architect, USA.
 The Data Protection Act 1998 is an Act of Parliament which defines UK law on the processing of data on identifiable living people and it is the main.
The Sixth Annual African Consumer Protection Dialogue Conference
Internal Auditing and Outsourcing
Environmental Impact Assessment University of Santo Tomas College of Architecture SP2 Ecological Construction Environmental Architecture.
“Export Credit Agencies and Human Rights”
Privacy Codes of Conduct as a self- regulatory approach to cope with restrictions on transborder data flow Dr. Anja Miedbrodt Exemplified with the help.
1 Institute of Company Secretaries, India Keynote address : corporate governance + globalisation + the board Hong Kong, China 12 May 2008 Fianna Jesover.
A Perspective: Data Flow Governance in Asia Pacific & APEC Framework Martin Abrams October 21, 2008.
Moving Forward With the African Dialogue Cross-Border Principles By Mary Gurure Manager, Legal Services and Compliance COMESA Competition Commission Lilongwe,
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
© 2014 IBM Corporation Mapping APEC CBPRs onto EU BCRs Anick Fortin-Cousens Privacy Officer, Canada, Latin America, Middle East & Africa Program Director,
REGIONAL STANDARDS OF PRACTICE FOR CARIBBEAN EDUCATORS Background History and International Perspectives WEBINAR PART
Federal Trade Commission U.S. Rules on Privacy and Data Security Organization for International Investment General Counsel Conference October 16, 2009.
GOOD FLAG, BAD FLAG: Part 2 Around the World nava.org.
Global Business Environment
Malcolm Crompton APEC Information Privacy Framework: review, impact, & progress APEC Symposium on Information Privacy Protection in E Government & E Commerce.
What Institutional Researchers Should Know about the IRB Susan Thompson Senior Research Analyst Office of Institutional Research Presented at the Texas.
1 IAPP TRUSTe Symposium: Privacy Futures ASIAN PRIVACY AT THE CROSSROADS IAPP TRUSTe Symposium: Privacy Futures (Session 3.06 “International Privacy: A.
APEC vs APT?: The struggle for regional privacy standards Graham Greenleaf ‘Terrorists & Watchdogs’ Conference, 8 September 2003.
Asia-Pacific Economic Cooperation 1 Electronic Commerce in APEC: Policy issues Jesus ORTA MARTINEZ Chairman, APEC ECSG Deputy Director-General of Digital.
Culture and Conflict A Global Culture. Cultural Conflict: Economic and Political Roots Increase in Supranational organizations: Multi- national political.
Issues Related to Global Information Systems A business can’t just worry about its home- country laws, rules and regulations. If a business has global.
APEC Privacy Framework “The lack of consumer trust and confidence in the privacy and security of online transactions and information networks is one element.
Key Points for a Privacy Programme for Multinationals Steve Coope.
Centre for Tax Policy and Administration Organisation for Economic Co-operation and Development Promoting a Pro-Growth Tax Environment for Global Business.
The Possibility of Regional Integration in East Asia I37002 Park In Hong.
Commissioning Services: with the DPA in mind South Yorkshire Information and Data Sharing Group Sheffield 14 th August 2014 Lynne Shackley Lead Policy.
“…global multinationals have … viewed developing Asia [countries]…as an offshore-production platform. The offshore- efficiency solution is still an attractive.
Professional Engineering Practice
Barriers to entry and financial integration in Asia and RCEP countries
Globalization and BGS Relationships
GLOBALISATION.
Contingent Workforce: Global Privacy Laws Overview
Data Protection: EU & International
International Regulatory Trends
Information Governance and Data Privacy: A World of Risk
New Global Communities
Consumer Privacy An Introduction
Protection of Personal Information Bill: An International Perspective
Cross Border Data Transfers for Litigation and Investigation
OECD Guidelines Collection Limitation: should be limited to personal data, obtained by lawful and fair means, and (where appropriate) with knowledge and.
Data transfers to non-EU countries under the new GDPR
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
Foundations of Government
Name the 7 continents of the world.
New Global Communities
Presentation transcript:

Privacy: An International Perspective Marty Abrams August 18, 2008

Today’s Objectives  Introduce the international privacy environment  Give you a sense of the diversity and similarities  Alert you to risks  Perform some future forecasting 2

3  Traditional data protection law begins with the fundamental right for an individual to control information that pertains to him/her  US law consumer protection based, but individual autonomy a value  Lesson from China: Individual autonomy not part of the Chinese culture; same goes for much of Asia  However, protection of individuals from the harmful use of information or the negative effects of bad security are very relevant  Inter-operability require American globals to build on common interests, this tends to be accountability based International Differences are a Challenge

Privacy & Security  Privacy is the appropriate use of information  Security is the protection of information  One can’t have good privacy with bad security  For consumers, privacy includes security 4

5 Breaking Privacy into its Elements is Helpful  Pieces include:  Information security  Consumer protection  Cultural aspects, such as autonomy  Security and consumer protection are common from place to place, system to system  Autonomy is different everywhere  Global companies must build respect for those differences and be accountable for promises

The Privacy World is Divided Into Six Parts  United States  Europe  British Commonwealth  Latin America  Asia  Everything else 6

Privacy Enforcement Agencies  Privacy enforced as part of a consumer protection agenda  Key issue is unfair practices  Privacy enforced by independent data protection agency  Key issue is protection of individual autonomy 7

European Union  27 members, 27 different laws and authorities  EU Data Protection Directive “harmonizes those 27 laws (in your dreams)  Extremely process-driven  Key elements  Privacy a fundamental human right  Individual control – consent  Purpose limitation  Independent data protection authorities  Data may only be transferred to places with adequate protection 8

British Commonwealth  Canada, Hong Kong, Australia, New Zealand  Independent data protection authorities  More practical approach, but still rooted on individual consent  Only Canada has been found adequate by EU  All are part of the APEC process 9

Latin America  The battleground between the EU and US  Spain has attempted to recruit the region for Europe  Argentina passed a law, created an authority, and then funded it at a very minimal level  Mexico has been a continuing skirmish between independent agency model and consumer protection based approach  It is now part of the ecommerce discussion 10

Asia  Japan – one law enforced by 34 different agencies  Not culturally based  Security the real issue  South Korea – Consent-based law that is always in change  India – Data security and international respect are the issues  China – Want European adequacy, law is in the future  Clash between culture and adequacy  Southeast Asia  Outsourcing driven 11

The Rest  Privacy issues are frozen in Antarctica  Issues are emerging in Africa with outsourcing 12

Future Direction  Cross-border data transfers are part of standard business process – stopping flows is just not possible  Harmonization on security and preventing harm very possible; cultural aspects will be harmonized when pigs fly  However, mutual respect very possible  Based on organizational accountability 13

Accountability Rooted In Data Protection History  OECD Principle 8  APEC Principle 9  “A personal information controller should be accountable for complying with the measures that give effect to the Principles stated above. When personal information is to be transferred to another person or organization, whether domestically or internationally, the personal information controller should obtain the consent of the individual or exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with these Principles.”  Canadian Privacy Law 14

Examples of Accountability-Based Regulation in the United States  Red Flags Rule  Authentications Rule  Safe Guards Rule  Extension of Safe Guards to non-financial institutions through the Federal Trade Commission Act  Sarbanes Oxley 15

Links to Trends in Prioritization  Potential harms are defined  Organization must develop policies and processes to prevent those harms  Links to concepts articulated by the community of data protection commissioners  Links to trends in cross-border data transfers  Binding Corporate Rules  Cross Border Privacy Rules  Defining harms is a challenge 16

How to Reach Me hunton.com 17