dumortier draft data protection regulation

18
Towards a New EU Legal Framework for Personal Data Processing? The European Commission’s Draft Data Protection Regulation

Upload: josdumortier

Post on 08-May-2015

1.114 views

Category:

Business


1 download

TRANSCRIPT

Page 1: Dumortier draft data protection regulation

Towards a New EU Legal Framework for Personal Data Processing?

The European Commission’s Draft Data Protection Regulation

Page 2: Dumortier draft data protection regulation

1970-1980

If you process personal data

- Only for explicit and legitimate purpose

- Remain proportional to this purpose

- Declare the purpose to the supervisory authority

- Implement state-of-the-art security

- Follow strict rules for export of personal data

- Inform the data subject and give him/her right of access and correction

- ....EC Directive 95/46

Page 3: Dumortier draft data protection regulation

1990 - 2000 : the Internet

Lindqvist case: do we have to apply all these rules to this situation?

Page 4: Dumortier draft data protection regulation

2010 - 2020

Page 5: Dumortier draft data protection regulation

On 25 January 2012 the European Commission has officially released a proposal for a comprehensive reform of the 1995 data protection rules on personal data processing.

Page 6: Dumortier draft data protection regulation

1. One single European law

If adopted, the proposed Regulation will be valid across the EU.

As a consequence, companies established in more than one EU country will no longer experience difficulties to cope with the divergent rules of the EU Member States.

Page 7: Dumortier draft data protection regulation

2. Every company supervised by one data protection commissioner

Personal data processing by companies established in more than one EU country will be monitored by one single supervisory authority.

In principle this will be the data protection commission of the country where the company has its main establishment.

Page 8: Dumortier draft data protection regulation

3. Also applicable to companies outside the EU

Theoretically the proposed Regulation claims to be applicable on the processing of personal data of data subjects residing in the EU by a controller not established in the EU,

… where the processing activities are related to the offering of goods or services to such data subjects, or to the monitoring of the behaviour of such data subjects.

Page 9: Dumortier draft data protection regulation

4. Basic rules remain but would be better implemented

The supervisory authorities will be empowered to fine companies that violate EU data protection rules.

This can lead to penalties of up to €1 million or up to 2% of the global annual turnover of a company.

Moreover responsibility and liability of the controller for any processing of personal data is more clearly established.

Page 10: Dumortier draft data protection regulation

5. Abolition of the general obligation to notify

The general notification obligation would be abolished, and replaced by procedures and mechanisms which focus instead on those processing operations which are likely to present specific risks.

Page 11: Dumortier draft data protection regulation

6. Data protection officers

The controller and the processor would in the future be requested to designate a data protection officer in any case where:

(a) the processing is carried out by a public authority or body; or

b) the processing is carried out by an enterprise employing 250 persons or more; or

(c) the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects.

Page 12: Dumortier draft data protection regulation

7. Consent: always explicit

Tacit consent will no longer be sufficient as a legal ground for personal data processing.

Moreover consent can no longer be integrated into terms and conditions but must be presented distinguishable in its appearance from this other matter.

Page 13: Dumortier draft data protection regulation

8. Right to be forgotten?

The right to erasure would be extended in such a way that a controller who has made the personal data public would be obliged to inform third parties which are processing such data that a data subject requests them to erase any links to, or copies or replications of that personal data.

Page 14: Dumortier draft data protection regulation

9. “Data portability”

The data subject would be allowed to transmit those data, which they have provided, from one automated application, such as a social network, into another one.

This should apply where the data subject provided the data to the automated processing system, based on their consent or in the performance of a contract.

Page 15: Dumortier draft data protection regulation

10. Security breach notification

As soon as a controller becomes aware that a personal data breach has occurred, he would be obliged to notify this breach to the supervisory authority without undue delay and, where feasible, within 24 hours.

The individuals whose personal data could be adversely affected by the breach would also have to be notified without undue delay in order to allow them to take the necessary precautions.

Page 16: Dumortier draft data protection regulation

Evaluation

Page 18: Dumortier draft data protection regulation

Jos DumortierK.U.Leuven – iMinds - ICRISint-Michielsstraat 6B-3000 Leuven(t) +32 (0)16 32 51 49www.icri.be / [email protected]

Jos Dumortiertime.lex - Information & Technology LawCongresstraat 35B-1000 Brussel(t) +32 (0)2 229 19 47www.timelex.eu / [email protected]