DATA PROTECTION ISACA MALTA CHAPTER BIENNIAL CONFERENCE Saviour Cachia Commissioner for Information and Data Protection

Similar documents
Data Protection Policy

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

DATA PROTECTION POLICY THE HOLST GROUP

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy

Motorola Mobility Binding Corporate Rules (BCRs)

Islam21c.com Data Protection and Privacy Policy

General Data Protection Regulation (GDPR) Key Facts & FAQ s

Data Protection Policy

This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant.

Creative Funding Solutions Limited Data Protection Policy

Technical Requirements of the GDPR

Rights of Individuals under the General Data Protection Regulation

ADMA Briefing Summary March

UWC International Data Protection Policy

RVC DATA PROTECTION POLICY

The British Museum. Data Protection Code of Practise. 1 Introduction

PS Mailing Services Ltd Data Protection Policy May 2018

DATA PROTECTION POLICY

Element Finance Solutions Ltd Data Protection Policy

UWTSD Group Data Protection Policy

Brasenose College ICT Systems Privacy Notice (v1.2)

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

Data Protection Policy

GLOBAL DATA PROTECTION POLICY

INFORMATION TO BE GIVEN 2

GLOBAL DATA PROTECTION POLICY

Data Protection Policy

Introductory guide to data sharing. lewissilkin.com

Guardian Electrical Compliance Ltd DATA PROTECTION GDPR REGULATIONS POLICY

Data Privacy Notice. Madsen Advisory Limited ("Madsen") is committed to protecting and respecting your privacy.

1 Privacy Statement INDEX

Data Protection Policy

HOW WE USE YOUR INFORMATION

GDPR Data Protection Policy

Subject: Kier Group plc Data Protection Policy

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

INFORMATION TO BE GIVEN 2

Privacy Policy Hafliger Films SpA

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2

Made In Hackney Data Protection Policy Last Updated:

DATA PROTECTION A GUIDE FOR USERS

Data protection. Data protection. Kacper Szkalej 1. Structure. Data protection. Media Law, KTH. Definition? Data protection = data processing rules

Data Protection Policy

Requirements for a Managed System

DATA PROTECTION IN RESEARCH

Strasbourg, 21 December / décembre 2017

How the GDPR will impact your software delivery processes

Contract Services Europe

Vanderbilt Video Surveillance. EU General Data Protection Regulation A Compliance Guide

Arkadin Data protection & privacy white paper. Version May 2018

INNOVENT LEASING LIMITED. Privacy Notice

General Legal Requirements under the Act and Relevant Subsidiary Legislations. Personal data shall only be processed for purpose of the followings:

DATA PROTECTION POLICY

DATA PROTECTION POLICY

MBNL Landlord Privacy Notice. This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR).

EU GDPR: The General Data Protection Regulation

EU General Data Protection Regulation A Compliance Guide

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts

The isalon GDPR Guide Helping you understand and prepare for the legislation

VIACOM INC. PRIVACY SHIELD PRIVACY POLICY

PRIVACY POLICY PRIVACY POLICY

Catalent Inc. Privacy Policy v.1 Effective Date: May 25, 2018 Page 1

What is GDPR? Editorial: The Guardian: August 7th, EU Charter of Fundamental Rights, 2000

Privacy Notice. General Information Protection Regulation ( GDPR )

GDPR - Are you ready?

Preparing for the GDPR

GDPR effects on Gift Aid. Presented by Keren Caird Business Development Gift Aid Manager Sue Ryder

Data processing policy

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ):

Privacy Policy Inhouse Manager Ltd

the processing of personal data relating to him or her.

Privacy Policy. Data Controller - the entity that determines the purposes, conditions and means of the processing of personal data

CAPGEMINI BINDING CORPORATE RULES

Toucan Telemarketing Ltd.

PRIVACY NOTICE VOLUNTEER INFORMATION. Liverpool Women s NHS Foundation Trust

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms:

GDPR Privacy Policy. The data protection policy of AlphaMed Press is based on the terms found in the GDPR.

Privacy and Data Protection Policy

All you need to know and do to comply with the EU General Data Protection Regulation

"PPS" is Private Practice Software as developed and produced by Rushcliff Ltd.

Privacy Notice - Stora Enso s Supplier and Stakeholder Register. 1 Purpose

Data Processing Agreement DPA

Privacy Policy CARGOWAYS Logistik & Transport GmbH

Cognizant Careers Portal Privacy Policy ( Policy )

Learning Management System - Privacy Policy

Down Under Centre Employment Hub - Privacy Policy Introduction

This Privacy Policy governs our processing of all personal data provided to us at Environmental Essentials in relation to our E-learning services.

PRIVACY POLICY. 3.1 This policy does not apply to the collection, holding, use or disclosure of personal information that is an employee record.

PRINCIPLES OF PROTECTION OF PERSONAL DATA (GDPR) WITH EFFICIENCY FROM

Data Protection Policy & Procedures

A Homeopath Registered Homeopath

Privacy Shield Policy

A practical guide to using ScheduleOnce in a GDPR compliant manner

Privacy Policy. Company registry number: Budapest, Gönczy Pál utca em. Homepage: contact: Phone:

Building Trust in the Cloud Era - Protect, Respect Personal Data

Website Privacy Notice

Polemic is a business involved in the collection of personal data in the course of its business activities and on behalf of its clients.

Transcription:

DATA PROTECTION ISACA MALTA CHAPTER BIENNIAL CONFERENCE 2016 Saviour Cachia Commissioner for Information and Data Protection

Conception of DPA Council of Europe ETS 108 Convention on the protection of individuals with regard to automatic processing of personal data Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data Data Protection Act CAP. 440 (Laws of Malta)

Why Data Protection? The right to privacy is a fundamental human right. No right is absolute. Data Protection is a means to protect the privacy of persons The Data Protection Act provides for the protection of individuals against the violation of their privacy rights by the processing of personal data. CREATING THE RIGHT BALANCE BETWEEN RIGHTS OF DATA SUBJECTS NEED FOR DATA PROCESSING

What is Data Protection

Basic Definitions Personal Data information relating to an identified or identifiable person Sensitive Personal Data reveals race or ethnic origin, political opinions, religious or philosophical beleifs, trade union membership, health, or sex life Processing collection, recording, organisation, storage, alteration, retrieval, alignment or combination, disclosure, blocking, erasure, destruction Data Subject natural person to whom personal data relates Controller determines processing and means of processing of personal data Processor processes personal data on behalf of a controller

Who s involved Commissioner Data Controller Personal Data Representative Data Subject subject of the personal data - Member of Public - Supplier - Customer - Employee Processor Recipient Third Party

Responsibilities of Controllers Data Controller - has the following responsibilities: Determines the purpose, requirement and criteria. Ensures security measures related to processing. Maintains data quality. Interfaces with the Commissioner. Deals with the Data Subject.

Responsibilities of Processors Processor - processes data as follows: Solely under the authority of the Controller. In accordance with instructions from the controller. As governed by a contract or legal act in written form. Ensures adequate security measures with regards to processing of personal data. Data Controller ultimately responsible for Processor s actions.

Data Subject Rights Be informed of the processing operations (Business details, purpose, disclosure) Gives explicit consent where required Revokes consent on legitimate grounds. Access, rectify and erase data where applicable. Can complain to the Commissioner when aggrieved

Decisions & Appeals IDPC issues Decision/Ruling DP Complainant Appeals Tribunal gives Ruling Court on a point of law Parties aggrieved by a decision can always appeal.

Criteria for Processing DPA Article 9 1. Unambiguous consent or 2. Contract performance or 3. Legal obligation or 4. Vital interests of data subject or 5. Public Interest / Official Authority or 6. Legitimate interest

Data Protection Principles FINALITY Data to be collected for specific, explicit and legitimate purposes and processed in a way compatible with those purposes. TRANSPERANCY Individuals need to know: - what data is being collected about them; - the processing purpose. Transparency is also assured by the right of access and the data controller s obligation to notify the Commissioner about the processing operations.

Data Protection Principles PROPORTIONALITY Personal data must be adequate, relevant and not excessive in relation to the purpose for which such data is processed. ACCURACY Personal data must be kept correct, of good quality and up-to-date. RETENTION Personal data shall not be kept for a period longer than necessary having regard to the purposes for processing. Personal data of a historical value may be retained for a longer period, provided that this is not used for a decision concerning the individual.

Security Measures Technical and Organisational Personal data must be protected against accidental destruction or loss or unlawful forms of processing Adequate level of Security Technical possibilities available Implementation cost Special risks that exist in the processing operation Sensitivity of the personal data Data Protection Awareness training important

Security Measures Paper files: how are they stored overnight or long term? how are they passed around the organisation? how do you keep track of who has them and why? how are they safeguarded if they leave your premises? Computer files: what back up procedures are used for PCs? what procedures are used to manage passwords? who has what levels of access to centrally held computer records, and why? (RBAC model) access monitored by an audit trail?

Privacy Enhancement Technologies (PETS) Some examples of PETs : - Access rights and restrictions (e.g. Restricting copying on external storage devices); - Full audit trail, including, recording of any action performed on a system; - Encryption mechanisms; - Degree of anonymity (use of pseudonyms & anonymisation); - Data minimisation minimise the personal data collected; - Segregation of data (unlinkability); - Automatic deletion of data.

Escalation of DP Issues DP Issue DPO Tech/Legal Advice Solved? Yes No Stop IDPC

Data Protection Architecture Data Protection Act 2001 Data Protection Policy Data Protection Procedures and Guidelines Forms, Files, Records, Databases involving personal data

Implementation Approach Introduce standard procedures for: Recording of new systems to be developed. Providing for flags and audit trail within systems. Ensuring fair and lawful processing: - Manual Forms; - Electronically. Meeting the rights of the data subject. Notifying the Commissioner. Identify adequate security level. Carry out data protection audit. Rectify non-compliances. DP Impact Assessment for new processes.

Contact Details Thank you! Office of the Information and Data Protection Commissioner Tel: (+356) 2328 7100 E-Mail: idpc.info@gov.mt Portal: www.idpc.gov.mt