CNPD Course: Data Protection Basics

Similar documents
CNPD Course: Data Protection Basics

Data Protection System of Georgia. Nina Sarishvili Head of International Relations Department

ENFORCEMENT POWERS. The EU Perspective. Olivier Proust. Associate Hunton & Williams LLP

Motorola Mobility Binding Corporate Rules (BCRs)

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

Privacy by Design, Security by Design

NEWSFLASH GDPR N 8 - New Data Protection Obligations

EU Data Protection Triple Threat for May of 2018 What Inside Counsel Needs to Know

This procedure sets out the usage of mobile CCTV units within Arhag.

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

Policy on Privacy and Management of Personal Information

Liechtenstein. General I Data Protection Laws. Contributed by Wanger Advokaturbüro. National Legislation. National Regulatory Authority.

Developments in Global Data Protection & Transfer: How They Impact Third-Party Contracts

etning_2015_web.pdf

General Data Protection Regulation (GDPR) The impact of doing business in Asia

Element Finance Solutions Ltd Data Protection Policy

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Privacy Notice. General Information Protection Regulation ( GDPR )

Privacy and Data Protection Policy

A comprehensive approach on personal data protection in the European Union

General Data Protection Regulation (GDPR)

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

STATEMENT OF STRATEGY

GDPR Let s get operational

PRIVACY POLICY BACKGROUND:

GDPR - Are you ready?

VISTRA (CYPRUS) LTD. PRIVACY NOTICE

VISTRA NETHERLANDS PRIVACY NOTICE

Creative Funding Solutions Limited Data Protection Policy

Data Subject Access Request Form

Privacy Notice - General Data Protection Regulation ( GDPR )

Talenom Plc. Description of Data Protection and Descriptions of Registers

Data Processor Agreement

DISCLOSURE PURSUANT TO ART. 13 EU REGULATION No. 2016/679 (GDPR) Customers and prospects

POLICY. Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016

Privacy Notices under #GDPR: Have you noticed my notice?

Introductory guide to data sharing. lewissilkin.com

How icims Supports. Your Readiness for the European Union General Data Protection Regulation

1. Right of access. Last Approval Date: May 2018

A Modern European Data Protection Framework

Subject: Kier Group plc Data Protection Policy

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

Implementing the new GDPR: what does it mean for Universities?

How to Request Information from Cardiff Metropolitan University

The Role of the Data Protection Officer

Data Protection Policy

Vistra International Expansion Limited PRIVACY NOTICE

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

Data Protection Policy

NOTICE OF PERSONAL DATA PROCESSING

Government Resolution No of February 15, Resolution: Advancing National Regulation and Governmental Leadership in Cyber Security

CEM Benchmarking Privacy Policy

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov

PS Mailing Services Ltd Data Protection Policy May 2018

CHASE GRAMMAR SCHOOL PRIVACY STATEMENT General Data Protection Regulations (GDPR)

Privacy Policy for Trend Micro Products and Services for the European Union, the European Economic Area (EEA) and the United Kingdom

The legal basis for the data collection described above is user s consent in accordance with Article 6(1)(1)(a) of the GDPR.

Privacy Policy Hafliger Films SpA

Rights of Individuals under the General Data Protection Regulation

PREPARING FOR THE GDPR AT THE UNIVERSITY OF HELSINKI

Our Data Protection Officer is Andrew Garrett, Operations Manager

Resolution: Advancing the National Preparedness for Cyber Security

The British Museum. Data Protection Code of Practise. 1 Introduction

VISTRA ZURICH AG - PRIVACY NOTICE

Pathways CIC Privacy Policy. Date Issued: May Date to be Reviewed: May Issued by Yvonne Clarke

VISTRA MONACO PRIVACY NOTICE

SCHOOL SUPPLIERS. What schools should be asking!

Communication and Usage of Internet and Policy

RVC DATA PROTECTION POLICY

Office of John Howell MP Data Protection Policy

Privacy Policy GENERAL

Data Warehouse Risk Assessment (GDPR)

Technical Requirements of the GDPR

GLOBAL DATA PROTECTION POLICY

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy

General Data Protection Regulation (GDPR)

Islam21c.com Data Protection and Privacy Policy

Directive on security of network and information systems (NIS): State of Play

Brasenose College ICT Systems Privacy Notice (v1.2)

Data Protection Policy

S.C. FAST SUPPORT S.R.L Bucharest, 70 Jean Louis Calderon Street, 6 th Floor J40/8295/ , sole registration code no.

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary

Link Exhibitions Privacy Policy

Guardian Electrical Compliance Ltd DATA PROTECTION GDPR REGULATIONS POLICY

WEBSITE PRIVACY POLICY

OPD PRESS/PUBLIC COMMENT/LEGISLATIVE/GUBERNATORIAL/ COMMENT POLICY (rev )

EU General Data Protection Regulation (GDPR) A Point of View for Technology Sector Organisations. For private circulation only.

Requirements on new data protection regulations and current changing needs from the view of the EDPS

DATA PROTECTION A GUIDE FOR USERS

Extension Architecture Privacy Notice

Creation and Evolution of the Colombian DPA

The GDPR Are you ready?

FileFacets for GDPR. Solution Overview for Compliance. Copyright 2017 FileFacets Corporation. All rights reserved

Data Processing Agreement

Cardiff University Security & Portering Services (SECTY) CCTV Code of Practice

GLOBAL DATA PROTECTION POLICY

The types of personal information we collect and hold

The Corporate Website and the Product Websites are together referred to hereafter as the website.

Transcription:

CNPD Course: Data Protection Basics Presentation of Luxembourg s data protection authority Esch-sur-Alzette (Belval) Dani Jeitz 4-6 July 2017 Legal department

Introduction to data protection 1. Introduction 2. Basic concepts Programme 3. The rights of data subjects 4. The role of the CNPD 5. The obligations of controllers 6. Main innovations introduced by the new European data protection regulation CNPD - July 2017 2

Outline Luxembourg s data protection authority Organisational structure Missions Recent trends Statistics 3

Luxembourg s data protection authority independent authority created by the Act of 2002 public institution with financial and administrative autonomy verifies if personal data is processed in accordance with the law ensures the respect of personal freedoms and fundamental rights with regard to data protection and privacy ensures the protection of privacy in the sector of electronic communications 4

Organisational structure (2017) Secretariat 1 employee Collegiate body 3 commissioners General administration, budget and finances Legal department 11 employees Notifications 1 employee IT department 3 employees Prior authorisations 2 employee Communications department 1 employee Guidance and investigations 5

Missions Ensure the application of the Data Protection Law and verify the lawfulness of processing by: 1. prior formalities: prior notifications (art. 12) prior authorizations (art. 14 + 19) 2. receiving and examining complaints 3. carrying out investigations (direct access to data) 4. taking disciplinary sanctions + engaging in legal proceedings 5. cooperating with other DPA s of the European Union + representing Luxembourg in the Article 29 WP 6

Missions Advise the legislator and give data protection recommendations to the government Approve sectoral codes of conduct Raise public awareness + inform the general public Provide guidance to data controllers, data processors and users Keep a public register of processing operations Write and publish an annual report 7

Missions Surveillance of processing operations by competent authorities for criminal purposes: Current situation : control authority «article 17» (State Prosecutor + 2 members of the CNPD) Directive 2016/680 Processing carried out by competent authorities for criminal purposes Exception for processing operations of courts when acting in their judicial capacity: judicial control authority New missions for the CNPD by the GDPR 8

Recent trends An increasing number of highly technological and sophisticated cases with cross-border implications: Approval of BCRs as lead authority: ebay (2009), Arcelor Mittal (2013), Rakuten (2017) A significant increase of: complaints and requests for information authorization requests and opinions on legal texts Internal reorganization and progressive reinforcement of staff to be ready for 25 May 2018 9

250 Presentation of the CNPD Increase of complaints (2016) Evolution of the number of complaints 200 150 100 50 0 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016 1% 1% Motifs (2016) Lawfullness of certain administrative/commercial practises (24%) 8% Refusal of the data subjet's right of access (19%) 15% 24% Illegal communication to third parties (16%) Supervision at the workplace (16%) 16% 19% Requests of erasure of rectification of data (15%) Objection for marketing purposes (8%) 16% Right to be forgotten (1%) Other (1%)

Increase of written information requests (2016) 500 450 400 350 300 250 200 150 100 50 0 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016

1600 1400 1200 1000 800 600 400 200 Increase of authorization requests (2016) 0 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016

Autorization requests Processing operations (2016) Surveillance (66%) International transfers of data (33%) Other purposes (<1%) 13

Increase of legal opinions - 2016 35 30 25 20 15 10 5 0 2009 2010 2011 2012 2013 2014 2015 2016 14

Thank you for your attention!

Commission nationale pour la protection des données 1, avenue du Rock n Roll L-4361 Esch-sur-Alzette (Belval) 261060-1 www.cnpd.lu info@cnpd.lu