How to handle data privacy issues in the car industry
|
|
|
- Nicholas Osborne
- 10 years ago
- Views:
Transcription
1 How to handle data privacy issues in the car industry Björn Kjellén Chief information security officer (CISO)
2 introduction The Automotive industry is now delivering vehicles with connectivity for exchange of information, provision of services, emergency assistance, support of road safety and traffic planning, etc.. Many of these services require the location being sent from the cars which is regarded as sensitive information in many cases. In addition, it s possible to calculate the speed along the trip which is a concern as well. What kind of data do the car companies collect and how must this information be handled? Customer provided personal data You as a customer provides contact, vehicle, purchase, preferences information to the car companies via dealers, customer centers, websites, etc. Vehicle generated and recorded data The vehicle is automatically collecting data from the car and the surroundings, and is mainly of technical nature. This data is connected to the identification number of the car and might be traceable to you. It can include data about safety, in car system status, driving data, location, etc. 2
3 Why Vehicle data privacy principles is needed! The connectivity technology will give a lot of opportunities to provide convenience and services to the customers which requires collection of personal related data from the cars and from the consumer directly. Customer trust is essential to the success of vehicle connectivity technologies and services. It s about not only following legal requirements but also being an ethical company. Vehicle data will also support common services such as traffic status and planning, road safety, parking optimization, etc. The car industry must ensure that these vehicle technologies and services can deliver benefits to the customers while respecting their privacy. Vehicle data might be collected and sent from the car in an emergency situatation (E-call) or used in a legal process. The car industry must, besides the vehicle legislation, also take laws about Data Privacy into account when developing cars. 3
4 Consumer Privacy protection principles Transparency Choice Consent Data use Data Security Disclosures to third parties Marketing On request, provide the customer with clear notices about what data for which purposes the car company processes (collection, use and sharing). The customer, Owner or Registered Driver, is in the possession of the car and by that owns the data in the car. It s the customer s choice to share the data or not. The request for consent to process the customer s data must be clear and explicit. The consent must always be possible to revoke when the customer wants to do so. In some cases data must be collected from the car without having the consent in order to provide car maintenance, enhance quality, manage warranty issues and for legal reasons. The collected personal data is used for providing information about products, services, updates, support, offerings, etc. The data is also used for improving vehicle performance, quality and safety, and to comply with legal requirements. The data must only be retained as long it s necessary to fulfill the purpose as outlined at collection. The car company must implement reasonable measures to protect the processed customer information against unauthorized access, maintain the integrity and ensure availablity when needed. The car company must only disclose the personal data to a third party, after the customer s consent, when needed to provide maintenance, product information, offerings, etc. It might also be required due to a legal process. The car company should not sell or trade the customer s personal data without a consent 4
5 references Volvo Cars Customer Privacy Policy Auto Alliance Privacy Principles 5
ACEA PRINCIPLES OF DATA PROTECTION IN RELATION TO CONNECTED VEHICLES AND SERVICES
ACEA PRINCIPLES OF DATA PROTECTION IN RELATION TO CONNECTED VEHICLES AND SERVICES September 2015 INTRODUCTION We, the member companies of ACEA, are committed to providing our customers with a high level
Volunteer Driver Application Form
Road to Recovery Volunteer Driver Application Form Please Print Name: Street Address: City State Zip: Other Address Information/ Email: Home Phone: Work Phone: Date of Birth: Occupation: Emergency Contact
DISASTER RECOVERY INSTITUTE CANADA WEBSITE PRIVACY POLICY (DRIC) UPDATED APRIL 2004
DISASTER RECOVERY INSTITUTE CANADA (DRIC) UPDATED APRIL 2004 This website privacy policy is intended to provide DRIC website visitors with information about how DRIC treats private and personal information
USE OF STATE VEHICLES
ILLINOIS PRISONER REVIEW BOARD POLICY, VEHICLE USAGE RESCINDS: N/A ESTABLISHED: 09/11/2014 RELATED DOCUMENTS: DISTRIBUTION: All PRB Board Members and employees Office/desk copy Employees working for the
Personal Information Protection Act ( PIPA ) Privacy-Proofing Your Retail Business Tips for Protecting Customers Personal Information 1
Personal Information Protection Act ( PIPA ) Tips for Protecting Customers Personal Information 1 More than ever before, retailers have to be prepared to deal with customers who ask questions about the
Advanced Diagnostics Limited ( We ) are committed to protecting and respecting your privacy.
MOBILE APPLICATION PRIVACY POLICY Advanced Diagnostics Limited ( We ) are committed to protecting and respecting your privacy. SCOPE OF POLICY This policy (together with our end-user licence agreement
DARTFISH PRIVACY POLICY
OUR COMMITMENT TO PRIVACY DARTFISH PRIVACY POLICY Our Privacy Policy was developed as an extension of our commitment to combine the highestquality products and services with the highest level of integrity
PRIVACY POLICY. Last updated February 2, 2009 INTRODUCTION
PRIVACY POLICY Last updated February 2, 2009 INTRODUCTION This Privacy Policy explains how personal information about you may be collected, used, or disclosed by the Canadian Education and Research Institute
Sixty-fourth Legislative Assembly of North Dakota In Regular Session Commencing Tuesday, January 6, 2015
Sixty-fourth Legislative Assembly of North Dakota In Regular Session Commencing Tuesday, January 6, 2015 HOUSE BILL NO. 1144 (Representative Keiser) (Senator Klein) AN ACT to create and enact chapters
POLICY INVOLVING VEHICLE USE ON OFFICIAL COLLEGE BUSINESS AUTOMOBILES & OTHER MOTORIZED VEHICLES Last update: August 9, 2011
POLICY INVOLVING VEHICLE USE ON OFFICIAL COLLEGE BUSINESS AUTOMOBILES & OTHER MOTORIZED VEHICLES Last update: August 9, 2011 INTRODUCTION: Rollins College has many faculty, staff and students whose responsibilities
CHASE: YOUR RESOURCE FOR ALL YOUR FINANCIAL NEEDS
CHASE: YOUR RESOURCE FOR ALL YOUR FINANCIAL NEEDS With the financial strength of Chase, Jaguar Financial Group and Land Rover Financial Group have provided our customers and dealers competitive financial
A+ Financial Services, Inc., A+ Auto Insurance Agency, Inc., and A+ Loans, Inc. Privacy Policy (Last updated 03/05/2014)
A+ Financial Services, Inc., A+ Auto Insurance Agency, Inc., and A+ Loans, Inc. Privacy Policy (Last updated 03/05/2014) This Privacy Policy explains the policy statement of A+ Financial Services, Inc.,
OUR ACTIVITIES IN THE COMPANY
CHAPTER OUR ACTIVITIES IN THE COMPANY Based on a philosophy of Customer First, TOYOTA strives to provide attractive products and services that meet the needs of customers worldwide. TOYOTA also seeks to
Breakout A. Big Data
Breakout A Big Data Facilitator Jay Parmar, Director of Policy and Membership, BVRLA Speakers Niranjan Thiyagarajan, Frost and Sullivan Sheliah Mackie, Blake Morgan LLP Martin Drake, Drive Software Solutions
Iowa Student Loan Online Privacy Statement
Iowa Student Loan Online Privacy Statement Revision date: Jan.6, 2014 Iowa Student Loan Liquidity Corporation ("Iowa Student Loan") understands that you are concerned about the privacy and security of
Health Plan Select, Inc. Business Associate Privacy Addendum To The Service Agreement
This (hereinafter referred to as Addendum ) by and between Athens Area Health Plan Select, Inc. (hereinafter referred to as HPS ) a Covered Entity under HIPAA, and INSERT ORG NAME (hereinafter referred
Custom House USA, LLC and Western Union Business Solutions (USA), LLC. Privacy Statement
Custom House USA, LLC and Western Union Business Solutions (USA), LLC Privacy Statement FACTS CUSTOM HOUSE USA, LLC AND WESTERN UNION BUSINESS SOLUTIONS (USA), LLC OPERATE UNDER THE TRADE NAME OF WESTERN
myra Online Terms and Conditions
myra Online Terms and Conditions Welcome to myra Online ( Online Services ). In these Terms and Conditions ( Terms ): (a) you or your means the person(s) subscribing to or using Online Services; (b) we
Crampton Credit Reporting Policy
Crampton Credit Reporting Policy Crampton Automotive Pty Ltd (ACN 057 283 253), trading as Toowoomba Holden and its related bodies corporate (Crampton) is committed to protecting the privacy of individuals
Yuba County Administrative Policy & Procedures Manual
Yuba County Administrative Policy & Procedures Manual Subject: Policy Number: Page Number: D-3 Page 1 of 5 AUTOMOTIVE TRANSPORTATION Date Approved: Revised Date: 02/19/08 12/16/14 POLICY: It is County
NOTICE OF PRIVACY PRACTICES
NOTICE OF PRIVACY PRACTICES This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. A federal regulation,
Allstate Indemnity Company Important Notice
Allstate Indemnity Company Important Notice Special Notice to Minnesota Auto Insureds The following surcharge information effective as of 8/2/2010 is provided to help you better understand your auto insurance
LENS Program Checklist LENS Check performed by: (FOR OFFICE USE ONLY) Signature. LENS Check Results: (Please check one) ACCEPTABLE (5 or few points)
Off Campus Trip LENS Check Packet The LENS check packet is required when a student is driving their personal car or driving a rental car to a University approved activity. Return the completed packet to
Coverage for Other People Using Your Car. Today s Lecture State Farm Car Policy. Other People s Use of Your Car - Example
Today s Lecture State Farm Car Policy Other people using your car Your using other cars Other people using other cars Coverage for Other People Using Your Car Anybody using your car with permission is
Information Security Policy
Information Security Policy Policy Title Responsible Executive Responsible Office Information Security Policy Vice President for Information Technology and CIO, Jay Dominick Office of Information Technology,
U.S. HOUSE OF REPRESENTATIVES COMMITTEE ON ENERGY AND COMMERCE
U.S. HOUSE OF REPRESENTATIVES COMMITTEE ON ENERGY AND COMMERCE October 19, 2015 To: Members, Subcommittee on Commerce, Manufacturing, and Trade From: Committee Majority Staff Re: Hearing entitled Examining
Independent Representative s Name: Code(s): Current AGA/MGA: The Applicant is requesting to Transfer to:
Request to Transfer Independent Representative s Name: Code(s): Current AGA/MGA: The Applicant is requesting to Transfer to: Does the Applicant have a debt with its current AGA/MGA? If yes, state the amount
Credit Union Board of Directors Introduction, Resolution and Code for the Protection of Personal Information
Credit Union Board of Directors Introduction, Resolution and Code for the Protection of Personal Information INTRODUCTION Privacy legislation establishes legal privacy rights for individuals and sets enforceable
1. TYPES OF INFORMATION WE COLLECT.
PRIVACY POLICY GLOBAL ASSESSOR POOL, LLC, DBA PINSIGHT ( Company or we or us ) is committed to protecting your privacy. We prepared this Privacy Policy to describe our practices regarding the information
ICC/ESOMAR INTERNATIONAL CODE ON MARKET AND SOCIAL RESEARCH
ICC/ESOMAR INTERNATIONAL CODE ON MARKET AND SOCIAL RESEARCH INTRODUCTION The first Code of Marketing and Social Research Practice was published by ESOMAR in 1948. This was followed by a number of codes
Estée Lauder Companies Global Jobs Website Privacy Policy
Effective Date: August 14, 2014 Estée Lauder Companies Global Jobs Website Privacy Policy The Estée Lauder Companies ( we, us, or our ) respects your concerns about privacy and value the relationship we
Green Pharm is committed to your privacy. We disclose our information practices below and we agree to notify you of:
Privacy Policy is committed to your privacy. We disclose our information practices below and we agree to notify you of: 1. What personally identifiable information of yours or third party personally identification
How to make Uber work in Hong Kong
Industry Report NOT RATED How to make work in Hong Kong Police Actions Sparked Controversial Topic On 11 th August, 2015, Hong Kong police had arrested 5 drivers and 3 office staffs allegedly for operating
PERSONAL INFORMATION PRIVACY POLICY FOR EMPLOYEES AND VOLUNTEERS [ABC SCHOOL]
[Insert Date of Policy] PERSONAL INFORMATION PRIVACY POLICY FOR EMPLOYEES AND VOLUNTEERS of [ABC SCHOOL] Address Independent schools in British Columbia are invited to adopt or adapt some or all of this
PIPEDA and Online Backup White Paper
PIPEDA and Online Backup White Paper The cloud computing era has seen a phenomenal growth of the data backup service industry. Backup service providers, by nature of their business, are compelled to collect
PRIVACY POLICY (Update 1) FOR ONLINE GIVING FOR THE UNITED METHODIST CHURCH
A. Overview PRIVACY POLICY (Update 1) FOR ONLINE GIVING FOR THE UNITED METHODIST CHURCH GENERAL COUNCIL ON FINANCE AND ADMINISTRATION OF THE UNITED METHODIST CHURCH, INC., an Illinois corporation 1 Music
Policy Implications: Privacy, Security and Liability Big Data in Telecom. June 7 2012 TIA 2012: INSIDE THE NETWORK Dallas TX
Policy Implications: Privacy, Security and Liability Big Data in Telecom June 7 2012 TIA 2012: INSIDE THE NETWORK Dallas TX Who We Are Leading trade association in support of information and communications
Please read this Policy carefully. Your continued use of our sites means that you understand and consent to the terms of this Policy.
EFFECTIVE: February 2016 Version 1.2 CHECK 'N GO PRIVACY POLICY This Privacy Policy ("Policy") applies to the use of Check 'n Go (the "Company") online sites and any Company affiliate or subsidiary sites.
NATIONAL CONFERENCE OF INSURANCE LEGISLATORS (NCOIL) Proposed Model Act Regarding Motor Vehicle Crash Parts and Repair
NATIONAL CONFERENCE OF INSURANCE LEGISLATORS (NCOIL) Proposed Model Act Regarding Motor Vehicle Crash Parts and Repair This working draft incorporates changes that the Committee made to the proposed model
Burke and Herbert Bank 100 S. Fairfax Street Alexandria, VA 22314 (703) 684-1655 www.burkeandherbertbank.com ELECTRONIC FUND TRANSFER DISCLOSURE
Burke and Herbert Bank 100 S. Fairfax Street Alexandria, VA 22314 (703) 684-1655 www.burkeandherbertbank.com ELECTRONIC FUND TRANSFER DISCLOSURE For purposes of this disclosure the terms "we", "us" and
4.7 Website Privacy Policy
Policy Statement The is committed to ensuring that its departments, offices, agencies, boards, and commissions adhere to the privacy protection provisions of the Freedom of Information and Protection of
Packerland Broadband Subscriber Privacy Notice
Packerland Broadband Subscriber Privacy Notice What This Privacy Notice Covers This Notice describes our practices with respect to your "personally identifiable information" and certain other information.
HOME TRUST COMPANY PRIVACY NOTICE/PRIVACY CODE for Creditworx/Home Owner Merchant Express
HOME TRUST COMPANY PRIVACY NOTICE/PRIVACY CODE for Creditworx/Home Owner Merchant Express This Privacy Notice and Privacy Code detail how Home Trust Company ( Home Trust, we, us, our ) collects, uses and
What to do When Faced With a Privacy Breach: Guidelines for the Health Sector ANN CAVOUKIAN, PH.D. COMMISSIONER
What to do When Faced With a Privacy Breach: Guidelines for the Health Sector ANN CAVOUKIAN, PH.D. COMMISSIONER INFORMATION AND PRIVACY COMMISSIONER/ONTARIO Table of Contents What is a privacy breach?...1
Connected car, big data, big brother?
Connected car, big data, big brother? Using geolocation in a trustworthy and compliant way [email protected] Trends that threaten trust 2 Connected cars with downloadable apps Location services, cloud,
Explanation where the company has partially applied or not applied King III principles
King Code of Corporate Governance for South Africa, 2009 (King III) checklist The Board of Directors (the Board) of Famous Brands Limited (Famous Brands or the company) is fully committed to business integrity,
LIDL PRIVACY POLICY. Effective Date: June 11, 2015
LIDL PRIVACY POLICY Effective Date: June 11, 2015 Thank you for visiting Lidl US, LLC's (3500 S. Clark Street, Arlington, VA 22202) website (collectively, "Lidl," "we," or "us"). We are committed to providing
Application to access Chesters Trade
Application to access Chesters Trade Please fill in all details below: Account Number Company Name Company Phone Number Fax Number Contact Name Mobile Number Email Address Please review the Terms of Use
Exhibit 2. Business Associate Addendum
Exhibit 2 Business Associate Addendum This Business Associate Addendum ( Addendum ) governs the use and disclosure of Protected Health Information by EOHHS when functioning as a Business Associate in performing
Regulation P: Privacy of Consumer Financial Information. Frequently Asked Questions
Regulation P: Privacy of Consumer Financial Information Frequently Asked Questions December 2001 Contents A. Financial institutions, products, and services that are covered under the Privacy Rule (Q.
ECSA EuroCloud Star Audit Data Privacy Audit Guide
ECSA EuroCloud Star Audit Data Privacy Audit Guide Page 1 of 15 Table of contents Introduction... 3 ECSA Data Privacy Rules... 4 Governing Law... 6 Sub processing... 6 A. TOMs: Cloud Service... 7 TOMs:
ORIGINAL HOUSE BILL NO. 0193 ENROLLED ACT NO. 31, HOUSE OF REPRESENTATIVES FIFTY-SEVENTH LEGISLATURE OF THE STATE OF WYOMING 2003 GENERAL SESSION
AN ACT relating to insurance; authorizing the department of insurance to regulate the issuance of rental car insurance, as specified; providing for fees; providing a compliance date; and providing for
Substantive Requirements for a Registered Investment Adviser under the U.S. Investment Advisers Act of 1940
Substantive Requirements for a Registered Investment Adviser under the U.S. Investment Advisers Act of 1940 Alternative investment fund managers and other investment advisory firms that are registered
Pulaski Bank. www.pulaskibankstl.com. Electronic Funds Transfer ELECTRONIC FUND TRANSFER AGREEMENT AND DISCLOSURE
www.pulaskibankstl.com Electronic Funds Transfer ELECTRONIC FUND TRANSFER AGREEMENT AND DISCLOSURE For purposes of this disclosure and agreement the terms "we", "us" and "our" refer to. The terms "you"
Part II Corporate Governance System and the Duties of the Board of Directors, etc
Note: This is a translation of the Japanese language original for convenience purposes only, and in the event of any discrepancy, the Japanese language original shall prevail. Corporate Governance Policy
DATA RETENTION POLICY
DATA RETENTION POLICY Contents 1. Key Principles... 3 2. Introduction to the Policy and Guidelines... 3 3. Policy and Guidelines... 4 4. Scottish Ministers Requirements... 5 5. Access to information...
FINANCING 101234 567890 123456
FINANCING 101234 567890 123456 FINANCING 101 With a typical Hyundai Finance lease, you re covered for normal wear and use without having to pay additional charges at the end of the term. And while it s
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential
The Manitoba Child Care Association PRIVACY POLICY
The Manitoba Child Care Association PRIVACY POLICY BACKGROUND The Manitoba Child Care Association is committed to comply with the legal obligations imposed by the federal government's Personal Information
Privacy Policy and Notice of Information Practices
Privacy Policy and Notice of Information Practices Effective Date: April 27, 2015 BioMarin Pharmaceutical Inc. ("BioMarin") respects the privacy of visitors to its websites and online services and values
1 LAWS of MINNESOTA 2015 Ch 67, s 2. CHAPTER 67--S.F.No. 86 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF MINNESOTA:
1 LAWS of MINNESOTA 2015 Ch 67, s 2 CHAPTER 67--S.F.No. 86 An act relating to data practices; classifying data related to automated license plate readers and requiring a governing policy; requiring a log
Best Practices for the Use of RF-Enabled Technology in Identity Management. January 2007. Developed by: Smart Card Alliance Identity Council
Best Practices for the Use of RF-Enabled Technology in Identity Management January 2007 Developed by: Smart Card Alliance Identity Council Best Practices for the Use of RF-Enabled Technology in Identity
Privacy Policy. Effective Date: November 20, 2014
Privacy Policy Effective Date: November 20, 2014 Welcome to the American Born Moonshine website (this Site ). This policy describes the Privacy Policy (this Policy ) for this Site and describes how Windy
Loan Application. Applicant 2 Co-borrower. Applicant 1 The borrower. Personal Details. Member Number. Title. Surname. Given names.
Cairns Penny Loan Application Thank you for considering Cairns Penny for your loan. To enable us to action your application as quickly as possible, we will need the following information along with your
FIDO: Fast Identity Online Alliance Privacy Principles Whitepaper vfeb2014
FIDO: Fast Identity Online Alliance Privacy Principles Whitepaper vfeb2014 The FIDO Alliance: Privacy Principles Whitepaper Page 1 of 7 FIDO Privacy Principles Introduction The FIDO Alliance is a non-profit
