Top Banner
Reform of the EU data protection regime In house lawyers forum – spring 2013
27

Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Jul 30, 2015

Download

Data & Analytics

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Reform of the EU data protection regime In house lawyers forum – spring 2013

Page 2: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• key dates

– July 2009 – Commission’s online

consultation

– April 2010 – plans announced to prepare

a new comprehensive framework for

data protection

– November 2010 – issues approach to

revising framework and public

consultation launched

Page 3: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• key dates

– March 2011 – Council of EU published

conclusions on ‘approach’

– November 2011 – ICO issued briefing on

the future of the data protection in EU

– January 2012 – Commission proposals

published

Page 4: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• key dates

– January 2012 – Commission proposals

published

– February 2012 – ICO’s initial analysis of

proposals

– 7 March 2012 – opinion of the European

DP Supervisor

Page 5: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• key dates

– 23 March 2012 – Article 29 working party

opinion

– December 2012 – LIBE (Committee on

Civil Liberties, Justice and Home Affairs)

draft report

– February 2013 – ICO article-by-article

analysis of Commission’s proposal

Page 6: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• structure of the regulation

– general provisions

– data protection principles

– rights of data subjects

– obligations on controllers and processors

– transfer of personal data to third

countries or international organisations

Page 7: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• structure of the regulation

– nature, status, duties and powers of

national supervisory authorities

– co-operation and consistency between

member states

– remedies, liability and sanctions

– provisions relating to specific data

processing situations

Page 8: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• regulation

– two year implementation period

– intention is to harmonise

– ICO believes too detailed and

prescriptive

• power to adopt delegated acts

• interaction between regulation and

national laws

Page 9: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 1 to 4

• subject matter

• scope of regulation

• territorial scope

– some of most significant change to

current regime

Page 10: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 1 to 4

• definitions

– data subject and personal data

– online identifiers

– consent

– genetic and biometric data

– child

Page 11: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 5 to 10

• data protection principles

• legal grounds for processing

– legitimate interests conditions

– further incompatible processing

• sensitive personal data

• concept of consent

Page 12: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 11 to 21

• transparent information and

communication

• subject access

• rectification and erasure

– ‘the right to be forgotten’

• right to data portability

Page 13: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 11 to 21

• right to object

– burden of proof

– objecting to processing for the purpose

of direct marketing

• measures based on profiling

Page 14: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 22 to 39

• accountability principle

– document all processing (name, contact

details of controller, purposes of

processing, name of DPO, categories of

data subject, recipients, any transfers,

time limits for erasure of data)

Page 15: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 22 to 39

• data security breach notification

• data protection impact assessment

– before processing that presents ‘specific

privacy risk by virtue of its nature, scope

or purposes’

– appointment of Data Protection Officer

(DPO)

Page 16: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 22 to 39

• data protection by design and by default

• processors

Page 17: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 41 to 45

• commission finding of adequacy

• binding corporate rules

• standard contractual clauses

Page 18: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 41 to 45

• derogations

– consent

– necessary to…

perform a contract

important grounds of public interest

establishment, exercise or defence of

legal claims

protect the vital interests of data subject

or other person

Page 19: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 41 to 45

• derogations

– transfer made from public register

– one off infrequent transfers necessary

for legitimate interests of DC

Page 20: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 46 to 54

• independent

• duty to co-operate

• duties and powers of authorities

– to act as lead authority where DC or DP

established in several member states

– to sanction administrative offences

Page 21: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 55 to 72

• co-operation

• consistency

– creation of EDPB consisting of heads of

DPAs, and Euro Data Protection

Supervisor

Page 22: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas
Page 23: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 73 to 79

• written warning

• fines, up to

• EUR250,000 (or 0.5%) failure to operate

proper SAR mechanism

• EUR500,000 (or 1%) failure to respond to

SAR

• EUR1,000,000 (or 2%) other compliance

failures

Page 24: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 73 to 79

– amount fixed with regard to nature,

gravity and duration of the breach

– whether intentional or negligent

– degree of responsibility

– technical and organisational compliance

measures in place

– degree of cooperation with authorities to

remedy

Page 25: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Articles 80 to 85

• creates special rules for specific

situations:

– derogations from regulation for

journalism, literary or artistic

expression, freedom of expression

– health data

– employment context

– historical, statistical or scientific

research

Page 26: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

• EU: Commission proposes mandatory

notification of cyber incidents

Page 27: Reform of the EU data protection regime - In house lawyers forum 2013, Richard Nicholas

Get in touch if you have any questions or

would like further information.

t +(0)121 237 3992

e [email protected]