Dr. Hielke Hijmans Special Advisor European Data Protection Supervisor

Size: px
Start display at page:

Download "Dr. Hielke Hijmans Special Advisor European Data Protection Supervisor"

Transcription

1 Dr. Hielke Hijmans Special Advisor European Data Protection Supervisor Reforming the EU Rules on Privacy and Data Protection What Should Companies and Citizens Expect? 1

2 Outline Privacy in a global data driven economy The GDPR, the main legal EU instrument (from May 2018) One law for the whole EU The global reach of EU Privacy The EU-US Privacy Shield The companies perspective The citizen s perspective The relevance of privacy for test publishers and assessment service providers

3 Privacy in global data driven economy Big Data: data everywhere; economic value. Increasingly difficult to protect individuals' privacy. Privacy remains a value that is essential in our societies. In EU: recognised as fundamental right. Why is this so crucial? Nothing to hide -notion as fundamentally erroneous. People may become less private (by connecting to wide groups on Facebook), but have all reason to become more private. Anyone can find out anything about you, by combining information. Bridge to (pre-) employment testing.

4 GDPR: main instrument of EU privacy law Applicable: 25 May 2018 Fairness as core of the system. Other main principles: Consent or any other legal ground for processing. Purpose limitation, data minimisation. Data subjects rights. Obligations controllers and processors based on accountability. Independent supervisory authorities. NB: EU-US Privacy Shield contains similar principles.

5 One European space, one law Rationale of the internal market, one European legal space for companies. The glass half full, taking account of EU reality. Countries do not wish to give up national specificities. Employment context is an area where Member States can do more (Art 88 GDPR). Control with national authorities, but strong incentives for cooperation. Independence. One stop shop and lead authority. Article 29 Working Party and EDPB.

6 Global reach of EU privacy The internet, as a borderless zone. Effectiveness of protection of EU citizens as driver. Main link: place of establishment of controller, not place where data are processed. EU rules, also covering non EU companies: offering services to persons in EU, such as on line testing. Monitoring behaviour (e.g., search engines). For testing business: If data EU residents are processed: GDPR will in many cases apply. EU-US Privacy Shield.

7 EU-US Privacy Shield Safe Harbour annulled by EU Court, now Privacy Shield. Privacy Shield: commercial layer, law enforcement access and national security access. Self-Certification. Voluntary, but once an organisation adheres, subject to enforcement (in U.S.: by DoC and FTC). Privacy principles: Notice, Data integrity/purpose limitation, Security, Access, Recourse/Enforcement/Liability, Accountability for Onward Transfer.

8 Companies perspective: do the right thing Accountability as overall notion. Certification system is strengthened. Onward transfer. Obligations now also apply to controller-processor relation. Controller: make assessment before involving processor. Contracts with third parties should be revised. Much more should be laid down in contract. DoC guidance: Develop a Privacy Shield compliant Policy Statement.

9 EU-resident s perspective GDPR may apply directly, relevance Privacy Shield. Transparency. DOC maintains list of companies adhering. Redress mechanism for data subjects (pts 43-63). Direct towards self-certified companies. Independent dispute resolution body. DPAs: on a voluntary basis, or compulsory for human resources data. A panel of DPAs will be set up (in future, possibly role for EDPB), Procedure with DoC, which may ultimately remove organisation from Privacy Shield list. Investigation and enforcement by FTC. Arbitration panel. Pool of at least 20 arbitrators, admitted to practice law in the U.S. General issue: low threshold. Arbitration panel will be paid from fees. Ombudsperson, only dealing with National Security Access.

10 Business of on line testing Global information flows, with companies testing globally. Different types of processing activities and information. Educational context (e.g. for university admissions) or (pre)-employment context. Sensitive data? Two main issues: Sensitive data, e.g. psychological testing data revealing health. The link with employment context and the imbalance between employer and employee. Also: Privacy Shield: additional protection for human resources data (pt 48 Recitals Privacy Shield). In principle, consent not used in employment context, and probably neither in a recruitment process. Pre-employment data, where is the boundary? Does it cover additional information provided voluntarily?

11 THANK YOU!

COMMISSION IMPLEMENTING DECISION. of XXX

COMMISSION IMPLEMENTING DECISION. of XXX COMMISSION IMPLEMENTING DECISION of XXX pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the EU-U.S. Privacy Shield (Text with

More information

LEGAL BASIS OBJECTIVES ACHIEVEMENTS

LEGAL BASIS OBJECTIVES ACHIEVEMENTS PERSONAL DATA PROTECTION Protection of personal data and respect for private life are important fundamental rights. The European Parliament has always insisted on the need to strike a balance between enhancing

More information

Adequacy Referential (updated)

Adequacy Referential (updated) ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 254 Adequacy Referential (updated) Adopted on 28 November 2017 This Working Party was set up under Article 29 of Directive 95/46/EC. It is an independent

More information

Working Document Setting Forth a Co-Operation Procedure for the approval of Binding Corporate Rules for controllers and processors under the GDPR

Working Document Setting Forth a Co-Operation Procedure for the approval of Binding Corporate Rules for controllers and processors under the GDPR 17/EN WP263 rev.01 Working Document Setting Forth a Co-Operation Procedure for the approval of Binding Corporate Rules for controllers and processors under the GDPR Adopted on 11 April 2018 protection

More information

MEMORANDUM. Internet Corporation for Assigned Names and Numbers. Thomas Nygren and Pontus Stenbeck, Hamilton Advokatbyrå

MEMORANDUM. Internet Corporation for Assigned Names and Numbers. Thomas Nygren and Pontus Stenbeck, Hamilton Advokatbyrå MEMORANDUM To From Internet Corporation for Assigned Names and Numbers Thomas Nygren and Pontus Stenbeck, Hamilton Advokatbyrå Date 15 December 2017 Subject gtld Registration Directory Services and the

More information

Helping Our Clients Conduct Globally Compliant Market Research. December 14, 2016

Helping Our Clients Conduct Globally Compliant Market Research. December 14, 2016 Helping Our Clients Conduct Globally Compliant Market Research December 14, 2016 The Affordable Care Act US Market Research Federal Affordable Care Act ObamaCare governs double-blind market research and

More information

Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection

Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70.1.b)) Adopted on 23 January

More information

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL. on the second annual review of the functioning of the EU-U.S.

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL. on the second annual review of the functioning of the EU-U.S. EUROPEAN COMMISSION Brussels, 19.12.2018 COM(2018) 860 final REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL on the second annual review of the functioning of the EU-U.S. Privacy

More information

18 January Comments

18 January Comments Comments by the Centre for Information Policy Leadership on the European Data Protection Board s Draft Guidelines 3/2018 on the Territorial Scope of the GDPR (Article 3) Adopted on 16 November 2018 On

More information

Cross-Border Application of EU s General Data Protection Regulation (GDPR) A private international law study on third state implications

Cross-Border Application of EU s General Data Protection Regulation (GDPR) A private international law study on third state implications Department of Law Spring Term 2017 Master s Thesis in Private International Law and EU Law, following an Internship at the Hague Conference on Private International Law 30 ECTS Cross-Border Application

More information

THE HIGH COURT COMMERCIAL

THE HIGH COURT COMMERCIAL THE HIGH COURT COMMERCIAL [2016 No. 4809 P.] BETWEEN THE DATA PROTECTION COMMISSIONER PLAINTIFF AND FACEBOOK IRELAND LIMITED AND MAXIMILLIAN SCHREMS DEFENDANTS Executive Summary of the Judgment 3 rd October,

More information

Presentation to IAPP November 18, EU Data Protection. Monday 18 November 13

Presentation to IAPP November 18, EU Data Protection. Monday 18 November 13 Presentation to IAPP November 18, 2013 EU Data Protection 1 Table of Contents 1. Introduction 2. Scope 3. Substantive Obligations 4. Formal Obligations 5. International Transfers 6. Enforcement 7. Sanctions,

More information

Opinion 6/2015. A further step towards comprehensive EU data protection

Opinion 6/2015. A further step towards comprehensive EU data protection Opinion 6/2015 A further step towards comprehensive EU data protection EDPS recommendations on the Directive for data protection in the police and justice sectors 28 October 2015 1 P a g e The European

More information

Consultation on the General Data Protection Regulation: CAP s evaluation of responses

Consultation on the General Data Protection Regulation: CAP s evaluation of responses Consultation on the General Data Protection Regulation: CAP s evaluation of responses 1. Introduction Following public consultation, the Committee of Advertising Practice (CAP) has decided to introduce

More information

Bitkom views on EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)

Bitkom views on EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) Bitkom views on EDPB Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) 18/01/2019 Page 1 1. Introduction Bitkom welcomes the opportunity to comment on the European Data Protection Board

More information

The European Union General Data Protection Regulation (GDPR) Barmak Nassirian, Federal Director Thursday, February 22, 2018

The European Union General Data Protection Regulation (GDPR) Barmak Nassirian, Federal Director Thursday, February 22, 2018 The European Union General Data Protection Regulation (GDPR) Barmak Nassirian, Federal Director Thursday, February 22, 2018 1 The European Union has set an effective date of May 25, 2018, for the General

More information

A Modern European Data Protection Framework Safeguarding Privacy in a Connected World

A Modern European Data Protection Framework Safeguarding Privacy in a Connected World A Modern European Data Protection Framework Safeguarding Privacy in a Connected World DG JUSTICE and CONSUMERS The Data Protection Reform Package Ø "General" Data Protection Regulation (GDPR) Ø Directive

More information

Irish Government Publishes Data Protection Bill 2018

Irish Government Publishes Data Protection Bill 2018 Irish Government Publishes Data Protection Bill 2018 The Government has published the eagerly awaited Data Protection Bill 2018. The Bill incorporates Ireland s national implementing measures required

More information

16 March Purpose & Introduction

16 March Purpose & Introduction Factsheet on the key issues relating to the relationship between the proposed eprivacy Regulation (epr) and the General Data Protection Regulation (GDPR) 1. Purpose & Introduction As the eprivacy Regulation

More information

An overview of the EU General Data Protection Regulation ( GDPR ) for media organisations

An overview of the EU General Data Protection Regulation ( GDPR ) for media organisations An overview of the EU General Data Protection Regulation ( GDPR ) for media organisations The GDPR is a sweeping set of EU rules regulating the processing of personal data. It comes into force on 25 May

More information

PROLAW Student Journal of Rule of Law for Development SECURING US-EU PERSONAL DATA FLOWS: A CRITICAL OUTLOOK ON THE RECENT AGREEMENTS

PROLAW Student Journal of Rule of Law for Development SECURING US-EU PERSONAL DATA FLOWS: A CRITICAL OUTLOOK ON THE RECENT AGREEMENTS SECURING US-EU PERSONAL DATA FLOWS: A CRITICAL OUTLOOK ON THE RECENT AGREEMENTS No: 03 Email: giovanna.santori@yahoo.it By: Giovanna Santori 1 Abstract: The development of data exchanges in the modern

More information

In the present analysis, we cover the most problematic points of the Directive. For our views on the Regulation, please go to our document pool.

In the present analysis, we cover the most problematic points of the Directive. For our views on the Regulation, please go to our document pool. In light of the trialogue negotiations on the proposal for the Law Enforcement Data Protection Directive 1, EDRi, fipr and Panoptykon would like to provide comments on selected key elements the current

More information

Council of the European Union Brussels, 13 April 2015 (OR. en)

Council of the European Union Brussels, 13 April 2015 (OR. en) Conseil UE Council of the European Union Brussels, 13 April 2015 (OR. en) Interinstitutional File: 2012/0011 (COD) 7722/15 LIMITE PUBLIC DATAPROTECT 43 JAI 216 MI 209 DIGIT 13 DAPIX 52 FREMP 69 COMIX 154

More information

A Legal Overview of the Data Protection Act By: Mrs D. Madhub Data Protection Commissioner

A Legal Overview of the Data Protection Act By: Mrs D. Madhub Data Protection Commissioner A Legal Overview of the Data Protection Act 2017 By: Mrs D. Madhub Data Protection Commissioner 06.02.2018 Overview The Data Protection Act 2017 Aim of the Act Major changes brought in the new Act Key

More information

Appendix 1 Data Processing Agreement

Appendix 1 Data Processing Agreement Appendix 1 Data Processing Agreement Except as modified below, the terms of the Agreement shall remain in full force and effect. The Agreement and this DPA are connected and cannot be terminated separately.

More information

LIBE Committee Inquiry on electronic mass surveillance of EU citizens. Public Hearing, Strasbourg, 7 October 2013 Contribution of Peter Hustinx (EDPS)

LIBE Committee Inquiry on electronic mass surveillance of EU citizens. Public Hearing, Strasbourg, 7 October 2013 Contribution of Peter Hustinx (EDPS) LIBE Committee Inquiry on electronic mass surveillance of EU citizens Public Hearing, Strasbourg, 7 October 2013 Contribution of Peter Hustinx (EDPS) Thank you for the invitation. The focus of your programme

More information

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,7November /1/13 REV1. InterinstitutionalFile: 2012/0011(COD) LIMITE

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,7November /1/13 REV1. InterinstitutionalFile: 2012/0011(COD) LIMITE ConseilUE COUNCILOF THEEUROPEANUNION Brusels,7November2013 InterinstitutionalFile: 2012/0011(COD) PUBLIC 14863/1/13 REV1 LIMITE DATAPROTECT145 JAI899 MI881 DRS187 DAPIX128 FREMP150 COMIX561 CODEC2286 NOTE

More information

SIMON READHEAD Q.C. PRIVACY NOTICE

SIMON READHEAD Q.C. PRIVACY NOTICE SIMON READHEAD Q.C. PRIVACY NOTICE Introduction 1. I am committed to handling your personal information fairly, lawfully and securely in accordance with current data protection laws. This privacy notice

More information

EXECUTIVE SUMMARY. 3 P a g e

EXECUTIVE SUMMARY. 3 P a g e Opinion 1/2016 Preliminary Opinion on the agreement between the United States of America and the European Union on the protection of personal information relating to the prevention, investigation, detection

More information

Data class actions. The era of mass data litigation

Data class actions. The era of mass data litigation Data class actions The era of mass data litigation 2018 1 Hogan Lovells Data class actions The era of mass data litigation 3 Introduction Contents Class actions are commonplace in the United States but

More information

EVIDENCE ON THE DATA PROTECTION BILL. For the House of Commons Public Bill Committee by Open Rights Group and Chris Pounder

EVIDENCE ON THE DATA PROTECTION BILL. For the House of Commons Public Bill Committee by Open Rights Group and Chris Pounder EVIDENCE ON THE DATA PROTECTION BILL For the House of Commons Public Bill Committee by Open Rights Group and Chris Pounder March 2018 Open Rights Group is a digital rights campaigning organisation. Campaigning

More information

LEGAL BASIS OBJECTIVES ACHIEVEMENTS

LEGAL BASIS OBJECTIVES ACHIEVEMENTS PERSONAL DATA PROTECTION Protection of personal data and respect for private life are important fundamental rights. The European Parliament has always insisted on the need to strike a balance between enhancing

More information

Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679

Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679 17/EN WP 253 Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679 Adopted on 3 October 2017 This Working Party was set up under Article 29 of Directive

More information

ANNEX CORRIGENDUM. (Official Journal of the European Union L 119 of 4 May 2016) On page 14, recital (71), fifth and sixth sentences: for:

ANNEX CORRIGENDUM. (Official Journal of the European Union L 119 of 4 May 2016) On page 14, recital (71), fifth and sixth sentences: for: ANNEX CORRIGENDUM to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the

More information

BSA The Software Alliance s Response to the EDPB Public Consultation on the Proposed Guidelines on the Territorial Scope of the GDPR

BSA The Software Alliance s Response to the EDPB Public Consultation on the Proposed Guidelines on the Territorial Scope of the GDPR Brussels, January 2019 BSA The Software Alliance s Response to the EDPB Public Consultation on the Proposed Guidelines on the Territorial Scope of the GDPR On 16 November 2018, the European Data Protection

More information

Interinstitutional File: 2012/0011 (COD)

Interinstitutional File: 2012/0011 (COD) Council of the European Union Brussels, 4 May 2015 (OR. en) Interinstitutional File: 2012/0011 (COD) 8371/15 LIMITE DATAPROTECT 63 JAI 259 MI 272 DIGIT 25 DAPIX 68 FREMP 88 COMIX 197 CODEC 610 NOTE From:

More information

Information exempt from the subject access right (section 40(4) and

Information exempt from the subject access right (section 40(4) and ICO lo Information exempt from the subject access right (section 40(4) and Freedom of Information Act Environmental Information Regulations Contents Introduction... 2 Overview... 3 What FOIA says... 4

More information

Council of the European Union Brussels, 31 March 2015 (OR. en)

Council of the European Union Brussels, 31 March 2015 (OR. en) Conseil UE Council of the European Union Brussels, 31 March 2015 (OR. en) Interinstitutional File: 2012/0011 (COD) 7586/15 ADD 1 LIMITE PUBLIC DATAPROTECT 40 JAI 197 MI 199 DIGIT 9 DAPIX 48 FREMP 62 COMIX

More information

COMMUNICATION FROM THE COMMISSION. On the global approach to transfers of Passenger Name Record (PNR) data to third countries

COMMUNICATION FROM THE COMMISSION. On the global approach to transfers of Passenger Name Record (PNR) data to third countries EUROPEAN COMMISSION Brussels, 21.9.2010 COM(2010) 492 final COMMUNICATION FROM THE COMMISSION On the global approach to transfers of Passenger Name Record (PNR) data to third countries EN EN COMMUNICATION

More information

European Data Protection Supervisor Transparency in the EU administration: Your right to access documents

European Data Protection Supervisor Transparency in the EU administration: Your right to access documents European Data Protection Supervisor Transparency in the EU administration: Your right to access documents EDPS factsheet 2 The European institutions and bodies make decisions and adopt legislation that

More information

EDPS Opinion on the proposal for a recast of Brussels IIa Regulation

EDPS Opinion on the proposal for a recast of Brussels IIa Regulation Opinion 01/2018 EDPS Opinion on the proposal for a recast of Brussels IIa Regulation (Council Regulation on jurisdiction, the recognition and enforcement of decisions in matrimonial matters and the matters

More information

Memorandum of Understanding. between. The Legal Aid Agency (LAA) and. Solicitors Regulation Authority (SRA)

Memorandum of Understanding. between. The Legal Aid Agency (LAA) and. Solicitors Regulation Authority (SRA) Memorandum of Understanding between The Legal Aid Agency (LAA) and Solicitors Regulation Authority (SRA) 1 Introduction 1. The Legal Aid Agency (LAA) and the Solicitors Regulation Authority (SRA) ( the

More information

PUBLIC LIMITE EN COUNCILOF THEEUROPEANUNION. Brusels,19December2013 (OR.en) 18031/13 LIMITE. InterinstitutionalFile: 2012/0011(COD)

PUBLIC LIMITE EN COUNCILOF THEEUROPEANUNION. Brusels,19December2013 (OR.en) 18031/13 LIMITE. InterinstitutionalFile: 2012/0011(COD) ConseilUE COUNCILOF THEEUROPEANUNION Brusels,19December2013 (OR.en) InterinstitutionalFile: 2012/0011(COD) PUBLIC 18031/13 LIMITE DOCUMENTPARTIALLY ACCESSIBLETOTHEPUBLIC (22.01.2014) JUR658 JAI1167 DAPIX160

More information

Data Protection Bill, House of Lords second reading Information Commissioner s briefing

Data Protection Bill, House of Lords second reading Information Commissioner s briefing Data Protection Bill, House of Lords second reading Information Commissioner s briefing Introduction... 2 Overview... 2 Derogations... 4 Commissioner s part-by- part commentary on the Bill... 5 Part one:

More information

Executive summary. We will continue to pursue any actions still outstanding at the time of writing. Regulatory action taken to date:

Executive summary. We will continue to pursue any actions still outstanding at the time of writing. Regulatory action taken to date: Executive summary The Information Commissioner announced in May 2017 that she was launching a formal investigation into the use of data analytics for political purposes after allegations were made about

More information

DocuSign Envelope ID: D3C1EE91-4BC9-4BA9-B2CF-C0DE318DB461

DocuSign Envelope ID: D3C1EE91-4BC9-4BA9-B2CF-C0DE318DB461 Spanning Data Protection Addendum and Incorporating Standard Contractual Clauses for Controller to Processor Transfers of Personal Data from the EEA to a Third Country This Data Protection Addendum ("

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY WORKING PARTY ON POLICE AND JUSTICE

ARTICLE 29 DATA PROTECTION WORKING PARTY WORKING PARTY ON POLICE AND JUSTICE ARTICLE 29 DATA PROTECTION WORKING PARTY WORKING PARTY ON POLICE AND JUSTICE JOINT CONTRIBUTION OF THE EUROPEAN DATA PROTECTION AUTHORITIES AS REPRESENTED IN THE WORKING PARTY ON POLICE AND JUSTICE AND

More information

AMENDMENTS EN United in diversity EN. European Parliament. PE v

AMENDMENTS EN United in diversity EN. European Parliament. PE v European Parliament 2014-2019 Committee on Civil Liberties, Justice and Home Affairs 2.10.2018 PE628.470v01-00 AMDMTS 1-100 Claude Moraes (PE627.833v02-00) to wind up the debate on the statement by the

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 18/EN WP 257 rev.01 Working Document setting up a table with the elements and principles to be found in Processor Binding Corporate Rules Adopted on 28 November

More information

EQUALITIES AND DIVERSITY POLICY

EQUALITIES AND DIVERSITY POLICY EQUALITIES AND DIVERSITY POLICY SCHOOL MISSION STATEMENT Guided by Jesus Christ, our teacher, we journey together, learning to dream, believe and achieve 2010 EQUALITY ACT BACKGROUND The 2010 Equality

More information

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 16 thereof, Opinion of the European Data Protection Supervisor on the proposal for a Council Decision on the position to be adopted, on behalf of the European Union, in the EU-China Joint Customs Cooperation Committee

More information

1. WHY THE PROPOSAL? Improving the national enforcement of the rules on Free Movement of Workers. 1. Why this proposal? 2. What are the main elements?

1. WHY THE PROPOSAL? Improving the national enforcement of the rules on Free Movement of Workers. 1. Why this proposal? 2. What are the main elements? Proposal for a Directive to facilitate the exercise of rights conferred on workers in the context of freedom of movement for workers Gillian MORE European Commission DG Employment, Social Affairs and Inclusion

More information

A Modern European Data Protection Framework. Bruno Gencarelli DG JUSTICE and CONSUMERS

A Modern European Data Protection Framework. Bruno Gencarelli DG JUSTICE and CONSUMERS A Modern European Data Protection Framework Bruno Gencarelli DG JUSTICE and CONSUMERS Outline I. The EU Data Protection Reform: objectives, main elements, implementation a harmonised and simplified framework

More information

Data Protection Bill: Collective Redress

Data Protection Bill: Collective Redress Bill Committee Evidence Data Protection Bill: Collective Redress Which? is the largest consumer organisation in the UK with more than 1.7 million members and supporters. We operate as an independent, a-political,

More information

NHS ENGLAND Standard Personal Medical Services Agreement Variation Notice May 2018

NHS ENGLAND Standard Personal Medical Services Agreement Variation Notice May 2018 Standard Personal Medical Services Agreement Variation Notice May 2018 Standard Personal Medical Services Agreement Variation Notice May 2018 NHS England INFORMATION READER BOX Directorate Medical Operations

More information

GDPR and India. By ADITI CHATURVEDI Edited by AMBER SINHA. The Centre for Internet and Society, India

GDPR and India. By ADITI CHATURVEDI Edited by AMBER SINHA. The Centre for Internet and Society, India GDPR and India By ADITI CHATURVEDI Edited by AMBER SINHA The Centre for Internet and Society, India Designed by Saumyaa Naidu Shared under Creative Commons Attribution 4.0 International license At present,

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement This Data Processing Agreement ( DPA ) forms an integral part of, and is subject to, the AppsFlyer Services Agreement or the AppsFlyer Terms of Use available at https://www.appsflyer.com/terms-use,

More information

60 th UIA CONGRESS Budapest / Hungary October 28 November 1, UIA Biotechnology Law Commission Sunday, October 30, 2016

60 th UIA CONGRESS Budapest / Hungary October 28 November 1, UIA Biotechnology Law Commission Sunday, October 30, 2016 60 th UIA CONGRESS Budapest / Hungary October 28 November 1, 2016 UIA Biotechnology Law Commission Sunday, October 30, 2016 Hacking Pacemakers and Beyond: Cybersecurity Issues in Healthcare Cyber Security

More information

AmCham EU Proposed Amendments on the General Data Protection Regulation

AmCham EU Proposed Amendments on the General Data Protection Regulation AmCham EU Proposed Amendments on the General Data Protection Regulation Page 1 of 89 CONTENTS 1. CONSENT AND PROFILING 3 2. DEFINITION OF PERSONAL DATA / PROCESSING FOR SECURITY AND ANTI-ABUSE PURPOSES

More information

Free and Fair elections GUIDANCE DOCUMENT. Commission guidance on the application of Union data protection law in the electoral context

Free and Fair elections GUIDANCE DOCUMENT. Commission guidance on the application of Union data protection law in the electoral context EUROPEAN COMMISSION Brussels, 12.9.2018 COM(2018) 638 final Free and Fair elections GUIDANCE DOCUMENT Commission guidance on the application of Union data protection law in the electoral context A contribution

More information

The BRIBERY ACT 2010: Sanctions & Incentives. Roderick Macauley

The BRIBERY ACT 2010: Sanctions & Incentives. Roderick Macauley The BRIBERY ACT 2010: Sanctions & Incentives Roderick Macauley OUTLINE Bribery Act as a legislative model Incentives theory S.7 corporate failure to prevent BA enforcement and incentives Deferred Prosecution

More information

Council of the European Union Brussels, 24 July 2017 (OR. en)

Council of the European Union Brussels, 24 July 2017 (OR. en) Council of the European Union Brussels, 24 July 2017 (OR. en) Interinstitutional File: 2016/0176 (COD) 10552/17 LIMITE MIGR 113 SOC 498 CODEC 1110 NOTE From: Presidency To: Permanent Representatives Committee

More information

EUROPEAN PARLIAMENT Committee on the Internal Market and Consumer Protection

EUROPEAN PARLIAMENT Committee on the Internal Market and Consumer Protection EUROPEAN PARLIAMT 2009-2014 Committee on the Internal Market and Consumer Protection 2012/0011(COD) 28.1.2013 OPINION of the Committee on the Internal Market and Consumer Protection for the Committee on

More information

Media Regulation Roundtable:

Media Regulation Roundtable: Media Regulation Roundtable: A PROPOSAL FOR FUTURE REGULATION OF THE MEDIA: A MEDIA STANDARDS AUTHORITY Introduction 1. This proposal outlines a model for media regulation which is independent, voluntary

More information

THE PERSONAL DATA PROTECTION BILL, 2018: A SUMMARY

THE PERSONAL DATA PROTECTION BILL, 2018: A SUMMARY July 30, 2018 THE PERSONAL DATA PROTECTION BILL, 2018: A SUMMARY The report issued by the Committee of Experts under the Chairmanship of Justice B.N. Srikrishna (Report) 1 and the draft of the Personal

More information

EUROPEAN GENERAL DATA PROTECTION REGULATION CONSEQUENCES FOR DATA-DRIVEN MARKETING

EUROPEAN GENERAL DATA PROTECTION REGULATION CONSEQUENCES FOR DATA-DRIVEN MARKETING Practice Guide Data-Driven Marketing EUROPEAN GENERAL DATA PROTECTION REGULATION CONSEQUENCES FOR DATA-DRIVEN MARKETING Compliance Transparency Service Provider Implementation Cross-border Processing Publisher

More information

32000D0520. Official Journal L 215, 25/08/2000 P

32000D0520. Official Journal L 215, 25/08/2000 P 32000D0520 2000/520/EC: Commission Decision of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the safe harbour privacy

More information

Legal Insights. Discovery under the GDPR. Introduction

Legal Insights. Discovery under the GDPR. Introduction Discovery under the GDPR By Cynthia J. Cole and Neil Coulson*, Baker Botts LLP This is part of a continuing series of articles by Cynthia J. Cole and Neil Coulson on the legal developments and implications

More information

Data protection anno 2014: how to restore trust? An introduction. Hielke Hijmans and Herke Kranenborg

Data protection anno 2014: how to restore trust? An introduction. Hielke Hijmans and Herke Kranenborg 1. Introduction Data protection anno 2014: how to restore trust? An introduction Hielke Hijmans and Herke Kranenborg In the five decades during which Peter Hustinx has worked in the field of privacy and

More information

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,6June2014 (OR.en) 10615/14 InterinstitutionalFile: 2012/0011(COD) LIMITE

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,6June2014 (OR.en) 10615/14 InterinstitutionalFile: 2012/0011(COD) LIMITE ConseilUE COUNCILOF THEEUROPEANUNION Brusels,6June2014 (OR.en) PUBLIC 10615/14 InterinstitutionalFile: 2012/0011(COD) LIMITE DATAPROTECT91 JAI434 MI484 DRS78 DAPIX81 FREMP115 COMIX303 CODEC1407 NOTE From:

More information

Having regard to the Treaty establishing the European Community, and in particular its Article 286,

Having regard to the Treaty establishing the European Community, and in particular its Article 286, Opinion of the European Data Protection Supervisor on the Proposal for a Regulation of the European Parliament and the Council establishing the criteria and mechanisms for determining the Member State

More information

MEMORANDUM OF UNDERSTANDING

MEMORANDUM OF UNDERSTANDING 1 April 2014 MEMORANDUM OF UNDERSTANDING Republic of Korea Financial Services Commission Financial Supervisory Service UNITED KINGDOM Prudential Regulation Authority Bank ofengland Contents RECITALS 2

More information

EU Data Protection Law - Current State and Future Perspectives

EU Data Protection Law - Current State and Future Perspectives High Level Conference: "Ethical Dimensions of Data Protection and Privacy" Centre for Ethics, University of Tartu / Data Protection Inspectorate Tallinn, Estonia, 9 January 2013 EU Data Protection Law

More information

Indian data protection regime Close to reality? Personal Data Protection Bill, 2018

Indian data protection regime Close to reality? Personal Data Protection Bill, 2018 Indian data protection regime Close to reality? Personal Data Protection Bill, 2018 Overview India has taken another step towards realising its dream of becoming a truly digital economy. Nearly a year

More information

EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS

EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS Who? This Data Processing Addendum ( DPA, Addendum ) has been prepared for those customers of CDNetworks that are data controllers

More information

Leicestershire Police Guidance. Freedom of Information Act 2000 Requests for Information

Leicestershire Police Guidance. Freedom of Information Act 2000 Requests for Information Leicestershire Police Guidance Freedom of Information Act 2000 Requests for Information 1. Introduction 1.1 Leicestershire Police is committed to ensuring that officers, staff and agents are conversant

More information

TECHNOLOGY AND DATA PRIVACY. Investigative Powers of the Data Protection Commissioner. by Peter Bolger, Jeanne Kelly

TECHNOLOGY AND DATA PRIVACY. Investigative Powers of the Data Protection Commissioner. by Peter Bolger, Jeanne Kelly TECHNOLOGY AND DATA PRIVACY Investigative Powers of the Data Protection Commissioner by Peter Bolger, Jeanne Kelly Investigative Powers of the Data Protection Commissioner 18th September 2017 by Peter

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 02072/07/EN WP 141 Opinion 8/2007 on the level of protection of personal data in Jersey Adopted on 9 October 2007 This Working Party was set up under Article 29

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY. Article 29 Working Party Guidelines on consent under Regulation 2016/679

ARTICLE 29 DATA PROTECTION WORKING PARTY. Article 29 Working Party Guidelines on consent under Regulation 2016/679 ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP259 rev.01 Article 29 Working Party Guidelines on consent under Regulation 2016/679 Adopted on 28 November 2017 As last Revised and Adopted on

More information

Law Enforcement processing (Part 3 of the DPA 2018)

Law Enforcement processing (Part 3 of the DPA 2018) Law Enforcement processing (Part 3 of the DPA 2018) Introduction This part of the Act transposes the EU Data Protection Directive 2016/680 (Law Enforcement Directive) into domestic UK law. The Directive

More information

Code of Conduct under the Provision of The Education (Penalty Notices) Regulation 2004 and Subsection (1) Section 23 Anti-Social Behaviour Act 2003

Code of Conduct under the Provision of The Education (Penalty Notices) Regulation 2004 and Subsection (1) Section 23 Anti-Social Behaviour Act 2003 Code of Conduct under the Provision of The Education (Penalty Notices) Regulation 2004 and Subsection (1) Section 23 Anti-Social Behaviour Act 2003 This code of conduct relates to Penalty Notices for absences.

More information

General Data Protection Regulation

General Data Protection Regulation General Data Protection Regulation Bar Council Guide for Barristers and Chambers Purpose: Scope of application: Issued by: To assist barristers and sets of chambers in their compliance with the GDPR All

More information

Supreme Court of the United States

Supreme Court of the United States No. 17-2 IN THE Supreme Court of the United States IN THE MATTER OF A WARRANT TO SEARCH A CERTAIN E-MAIL ACCOUNT CONTROLLED AND MAINTAINED BY MICROSOFT CORPORATION UNITED STATES OF AMERICA, Petitioner,

More information

The modernised Convention 108: novelties in a nutshell

The modernised Convention 108: novelties in a nutshell The modernised Convention 108: novelties in a nutshell With the modernisation of the 1981 Convention 108, its original principles have been reaffirmed, some have been strengthened and some new safeguards

More information

Q. What do the Law Commission and the Ministry of Justice recommend?

Q. What do the Law Commission and the Ministry of Justice recommend? Review of the Search and Surveillance Act 2012 Questions and Answers The Act Q. What does the Search and Surveillance Act do? A. The Act outlines rules for how New Zealand Police and some other government

More information

Implementation of GDPR and control mechanisms of data protection institutions in Germany

Implementation of GDPR and control mechanisms of data protection institutions in Germany Regulation (EU) 2016/679 Implementation of GDPR and control mechanisms of data protection institutions in Germany Mr. Bernhard Bannasch Deputy Saxon Data Protection Commissioner, Head of Division Employees

More information

Is information about legal entities personal data? No. The DPA only applies to information about individuals as opposed to legal entities.

Is information about legal entities personal data? No. The DPA only applies to information about individuals as opposed to legal entities. General I Data Protection Laws National Legislation General data protection laws The amended law of 2 August 2002 on the protection of persons with regard to the processing of personal data (the DPA )

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP259 Guidelines on Consent under Regulation 2016/679 Adopted on 28 November 2017 1 THE WORKING PARTY ON THE PROTECTION OF INDIVIDUALS WITH REGARD TO THE

More information

AMENDMENTS EN United in diversity EN. European Parliament Draft motion for a resolution Claude Moraes (PE595.

AMENDMENTS EN United in diversity EN. European Parliament Draft motion for a resolution Claude Moraes (PE595. European Parliament 2014-2019 Committee on Civil Liberties, Justice and Home Affairs 2016/3018(RSP) 30.1.2017 AMDMTS 1-71 Claude Moraes (PE595.560v01-00) Adequacy of the protection afforded by the EU-U.S.

More information

Ashley Green Sensitive Information in a Wired World Professor Joan Feigenbaum Yale University December 12, 2003

Ashley Green Sensitive Information in a Wired World Professor Joan Feigenbaum Yale University December 12, 2003 Ashley Green Sensitive Information in a Wired World Professor Joan Feigenbaum Yale University December 12, 2003 Over the past decade the world has gotten much smaller due to the electronic communication

More information

closer look at Rights & remedies

closer look at Rights & remedies A closer look at Rights & remedies November 2017 V1 www.inforights.im Important This document is part of a series, produced purely for guidance, and does not constitute legal advice or legal analysis.

More information

Pastoral Care and Redress Process Information Document

Pastoral Care and Redress Process Information Document Pastoral Care and Redress Process Information Document For Claimants of Child Sexual Abuse or Sexual Misconduct by a Church Worker Professional Standards Unit Anglican Diocese of Perth 2017 Diocesan Policy

More information

COMPUTERS ON WHEELS WHO OWNS WHICH DATA?

COMPUTERS ON WHEELS WHO OWNS WHICH DATA? Ve COMPUTERS ON WHEELS WHO OWNS WHICH DATA? Prof. Niko Härting Berlin, January, 19th, 2017 3 Connected Cars 5 DATA OWNERSHIP PRESENT HURDLES Ownership: Data on a hard disk is owned by the owener of the

More information

Derbyshire Constabulary VICTIM S RIGHT TO REVIEW POLICY POLICY REFERENCE 15/330. This policy is suitable for Public Disclosure

Derbyshire Constabulary VICTIM S RIGHT TO REVIEW POLICY POLICY REFERENCE 15/330. This policy is suitable for Public Disclosure Derbyshire Constabulary VICTIM S RIGHT TO REVIEW POLICY POLICY REFERENCE 15/330 This policy is suitable for Public Disclosure Owner of Doc: Head of Department, Criminal Justice Date Approved: 13 May 2015

More information

MEMORANDUM OF UNDERSTANDING

MEMORANDUM OF UNDERSTANDING 9 OCTOBER 2003 MEMORANDUM OF UNDERSTANDING The Insurance Authority of The Hong Kong Special Administrative Region of the People s Republic of China Financial Services Authority United Kingdom Contents

More information

Privacy and Protection of Personal Data in the EU Transfers of Personal Data to third Countries

Privacy and Protection of Personal Data in the EU Transfers of Personal Data to third Countries Privacy and Protection of Personal Data in the EU Transfers of Personal Data to third Countries European Commission Hana Pecháckova/Dr. Barbara Rhode Directorate-General Justice, Freedom and Security,

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement This Data Protection Addendum ("Addendum") forms part of the Master Subscription Agreement ("Principal Agreement") between: (i) Inspectlet ("Vendor") acting on its own behalf

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 1576-00-00-08/EN WP 156 Opinion 3/2008 on the World Anti-Doping Code Draft International Standard for the Protection of Privacy Adopted on 1 August 2008 This Working

More information

Data Protection Bill, House of Commons Second Reading Information Commissioner s briefing

Data Protection Bill, House of Commons Second Reading Information Commissioner s briefing Data Protection Bill, House of Commons Second Reading Information Commissioner s briefing Introduction 1. The Information Commissioner has responsibility in the UK for promoting and enforcing the Data

More information

Data Processing Agreement. <<Health Service Provider>> The National Message Broker Service known as Healthlink

Data Processing Agreement. <<Health Service Provider>> The National Message Broker Service known as Healthlink Between And The National Message Broker Service known as Healthlink THIS AGREEMENT is dated and made between: (1) , which has its principle administrative

More information