Class 13 Internet Privacy Law European Privacy.

19
Class 13 Internet Privacy Law European Privacy

Transcript of Class 13 Internet Privacy Law European Privacy.

Page 1: Class 13 Internet Privacy Law European Privacy.

Class 13

Internet Privacy Law

European Privacy

Page 2: Class 13 Internet Privacy Law European Privacy.
Page 3: Class 13 Internet Privacy Law European Privacy.

Differing Approaches

Europe United States

General Terms DATA PROTECTIONS PRIVACY

Data Protection Privacy is policies, laws, and regs

Data protection is privacy related laws and regulations

Treatment of Privacy

Fundamental human right. No processing of PI is

default, and processing must meet strict guidelines

Some constitutional rights to privacy. Commercial use is

acceptable. Processing limited by sector.

Privacy Protection Model

Comprehensive Sectoral

Sensitive Information

race/ethnic origin, political opinion, religion, health or sex

life, criminal history, union membership

SSN, Drivers License, Medical records, financial info

Page 4: Class 13 Internet Privacy Law European Privacy.

The Comprehensive Model

❖ EU data protection directive (1998)

❖ Parental consent before collecting data from under 13

❖ Companies with >250 employees must have data protection

Page 5: Class 13 Internet Privacy Law European Privacy.

Why the different approaches to privacy?

Page 6: Class 13 Internet Privacy Law European Privacy.

Defining what is private in EU

❖ EU definition of PI

❖ Any information relating to an identified or identifiable individual (includes name, address).

❖ Personal data

❖ Any information related to an identifiable natural person

Page 7: Class 13 Internet Privacy Law European Privacy.

EU Data Protection Roles

❖ DPA in each member state

❖ Data controller – individual in entity who directs data management (most laws are focused on data controller)

❖ Data processor – follows orders of data collector

❖ Data subject – user

❖ Processing - Under EU ANYTHING with PI is processing (even storage)

Page 8: Class 13 Internet Privacy Law European Privacy.

Generally

❖ Processing of PI prohibited unless:

❖ Notice

❖ Consent

❖ Data quality principles

❖ Other exceptions

❖ Special processing for

certain categories

❖ Right to access and object

❖ Controls on automated decisions

❖ Notice to DPAs

❖ Transfer restrictions

Page 9: Class 13 Internet Privacy Law European Privacy.

Legitimate Processing

❖ EXPRESS CONSENT unless

❖ Contract where data subject is subject of a contract

❖ Legal obligation

❖ Vital interests of data subjet

❖ Legitimate use

❖ Processing of Sensitive PI PROHIBITED unless:

❖ Explicit consent

❖ Vital interests

❖ Public information

Page 10: Class 13 Internet Privacy Law European Privacy.
Page 11: Class 13 Internet Privacy Law European Privacy.

Transferring Out of Europe

❖ Adequacy

❖ Andorra, Argentina, Canada (commercial organizations), Faeroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland, Uruguay and the US Department of Commerce's Safe Harbor Privacy Principles

❖ Safe-harbor (Between EU and US only)

❖ Model contracts

❖ Limited exceptions

❖ Binding corporate rules

Page 12: Class 13 Internet Privacy Law European Privacy.

Employee Privacy

❖ May not probe into past

❖ Employee monitoring ONLY with specific justification

❖ Background checks are limited

❖ Employers required to consult with trade unions agreements and regulations

Page 13: Class 13 Internet Privacy Law European Privacy.
Page 14: Class 13 Internet Privacy Law European Privacy.
Page 15: Class 13 Internet Privacy Law European Privacy.
Page 16: Class 13 Internet Privacy Law European Privacy.

EU Cookie Directive

❖ The ePrivacy directive – more specifically Article 5(3) – requires prior informed consent for storage of or access to information stored on a user's terminal equipment.

❖ In other words, you must ask users if they agree to most cookies and similar technologies … before the site starts to use them.

Page 17: Class 13 Internet Privacy Law European Privacy.

EU Cookie Directive❖ However, some cookies are

exempt from this requirement. Consent is not required if the cookie is:

❖ used for the sole purpose of carrying out the transmission of a communication, and

❖ strictly necessary in order for the provider of an information society service explicitly required by the user to provide that service.

Page 18: Class 13 Internet Privacy Law European Privacy.
Page 19: Class 13 Internet Privacy Law European Privacy.

Closing out the class