Privacy and Access 20/20 Conference. Data Sovereignty and Data Localization. Does it matter?
|
|
|
- Audra Stone
- 9 years ago
- Views:
Transcription
1 Privacy and Access 20/20 Conference Data Sovereignty and Data Localization Does it matter? 13 November
2 Overview To focus the mind: Microsoft vs. USA 2015 Stepping back to leap forward: The basic notions of sovereignty and data localization The practical context: International national security and public safety enforcement coordination Storage in the cloud Setting realistic goals in a connected world 13 November
3 Microsoft vs US 2015 (Microsoft Ireland case) US search warrant against Microsoft for personal information held by Microsoft Services in Ireland Microsoft s refusal based on non-application of US law in Ireland thus requiring use of MLAT US DoJ argument that criteria is not residency of data but control and custody Ireland would be pleased to consider, as expeditiously as possible, a request under the treaty, should one be made. 13 November
4 Upshot Whoever wins, the data will be within US reach By U.S. warrant under U.S. Stored Communications Act or By Irish warrant through MLAT which Ireland is ready to concede What about data sovereignty and localization? 13 November
5 Sovereignty The power of a State to govern a defined territory Territorial link is defined by Physical location (of victim, act, parties, etc. ) Rules of international law (jurisdiction in the high seas, immunity of embassies ) In what territory is data localized? 13 November
6 Data localisation Local: on local servers Limited accessibility Multinational: on data centres held by multinationals Limited but wide accessibility International: on cloud Variable accessibility But does it matter? 13 November
7 The practical context Mutual legal assistance treaties (MLATs) allow State signatories to exchange personal information for law enforcement Letters rogatory, from foreign to Canadian court, seek assistance such as obtaining records, in the absence of an MLAT Inapplicability of the Canadian Charter of Rights and Freedoms to foreign authorities on information gathering U.S. vs Viscomi ONCA November
8 Multinational storage on cloud allows multinational accessibility Five Eyes intelligence alliance for joint cooperation in signals intelligence is an information sharing space for Canada, US, Australia, New Zealand and UK. So what about sovereignty and localisation? 13 November
9 Data sovereignty and data localisation in a connected world 1 International norms ISO Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors New Safe Harbor, models clauses and BCRs Technological protections Default encryption 13 November
10 Data sovereignty and data localisation in a connected world 2 Political protections Limitation of collection and sharing through legislative amendments Oversight of information sharing Supporting EU pressure on US law enforcement access Requiring compliance with ISO as an industry standard for privacy on the cloud Exclusion of States with dubious court records Justice O Connor, Arar Inquiry 13 November
11 In a word Data localization matters in process not outcomes In a democracy, process is the value Data protection in a connected world rests on process 13 November
12 Thank you Dentons Canada LLP 99 Bank Street Suite 1420 Ottawa, Ontario K1P 1H4 Canada Dentons is a global law firm driven to provide a competitive edge in an increasingly complex and interconnected world. A top 20 firm on the Acritas 2014 Global Elite Brand Index, Dentons is committed to challenging the status quo in delivering consistent and uncompromising quality in new and inventive ways. Dentons' clients now benefit from 3,000 lawyers and professionals in more than 80 locations spanning 50-plus countries. With a legacy of legal experience that dates back to 1742 and builds on the strengths of our foundational firms Salans, Fraser Milner Casgrain (FMC), SNR Denton and McKenna Long & Aldridge the Firm serves the local, regional and global needs of private and public clients Dentons. Dentons is a global legal practice providing client services worldwide through its member firms and affiliates. This document is not designed to provide legal or other advice and you should not take, or refrain from taking, action based on its content. We are providing information to you on the basis you agree to keep it confidential. If you give us confidential information but do not instruct or retain us, we may act for another client on any matter to which that confidential information may be relevant. Please see dentons.com for Legal Notices.
Protecting Saskatchewan data the USA Patriot Act
Protecting Saskatchewan data the USA Patriot Act Main points... 404 Introduction... 405 Standing Committee on Public Accounts motion... 405 Our response to the motion... 405 ITO, its service provider,
INFORMATION SECURITY GUIDE. Cloud Computing Outsourcing. Information Security Unit. Information Technology Services (ITS) July 2013
INFORMATION SECURITY GUIDE Cloud Computing Outsourcing Information Security Unit Information Technology Services (ITS) July 2013 CONTENTS 1. Background...2 2. Legislative and Policy Requirements...3 3.
FACEBOOK STATEMENT RICHARD ALLAN NOVEMBER 11, 2013. My name is Richard Allan, and I am the Director of Public Policy
FACEBOOK STATEMENT RICHARD ALLAN NOVEMBER 11, 2013 [I. INTRODUCTION] My name is Richard Allan, and I am the Director of Public Policy for Facebook in Europe, the Middle East and Africa. I have been with
CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING?
CLOUD COMPUTING & THE PATRIOT ACT: A RED HERRING? Lindsey Finch Senior Global Privacy Counsel Salesforce.com [email protected] David T.S. Fraser Partner McInnes Cooper [email protected]
Safe Harbour Agreement no longer a valid basis for EEA to US transfers of personal data
Jisc Safe Harbour NOTE ON THE COURT OF JUSTICE OF THE EUROPEAN UNION'S JUDGMENT ON 'SAFE HARBOUR' ARRANGEMENTS FOR THE TRANSFER OF PERSONAL DATA FROM THE EEA TO THE USA KEY POINTS Safe Harbour Agreement
Global Privacy and Data Security in the Cloud September 14, 2011 Miriam Wugmeister
2011 Morrison & Foerster LLP All Rights Reserved mofo.com Global Privacy and Data Security in the Cloud September 14, 2011 Miriam Wugmeister Presenter Miriam Wugmeister Morrison & Foerster LLP New York
Context. To cloud or not to cloud, that is a very serious question. Legal challenges in a post Safe Harbour and pre GDPR cloud world
To cloud or not to cloud, that is a very serious question EEMA / TrustCore Legal challenges in a post Safe Harbour and pre GDPR cloud world 18 November 2015 [email protected] Context Major cloud providers
AUDITING AND ENFORCEMENT AT THE SPANISH DPA. EXPERIENCE WITH OUTSOURCING TO COUNTRIES WITH A NON ADEQUATE LEVEL OF PROTECTION
AUDITING AND ENFORCEMENT AT THE SPANISH DPA. EXPERIENCE WITH OUTSOURCING TO COUNTRIES WITH A NON ADEQUATE LEVEL OF PROTECTION CONFERENCE ON CROSS-BORDER DATA FLOW & PRIVACY October 15 16, 2007 Washington,
DSCI Inputs on TRAI Consultation on Regulatory Framework for OTT services
DSCI Inputs on TRAI Consultation on Regulatory Framework for OTT services April 24, 2015 DSCI Inputs on TRAI Consultation on Regulatory Framework for OTT Services 1 Question 6: How should the security
WHITE PAPER Meeting European Data Protection and Security Requirements with CipherCloud Solutions
WHITE PAPER Meeting European Data Protection and Security Requirements with CipherCloud Solutions Meeting European Data Protection and Security Requirements with CipherCloud Solutions 2015 1 TABLE OF CONTENTS
Future Proof Your ediscovery Practices
FEBRUARY 3 5, 2015 / THE HILTON NEW YORK Future Proof Your ediscovery Practices Plenary Session February 4, 2015 Patrick Collins, Partner, Perkins Coie Bruce Hartley, Vice President, Celerity Consulting
John O. Brennan Central Intelligence Agency Office of Public Affairs Washington, D.C. 20505. November 4, 2015. Mr. Brennan:
John O. Brennan Central Intelligence Agency Office of Public Affairs Washington, D.C. 20505 November 4, 2015 Mr. Brennan: On March 31, 2015 several organizations called on the Central Intelligence Agency
Using AWS in the context of Australian Privacy Considerations October 2015
Using AWS in the context of Australian Privacy Considerations October 2015 (Please consult https://aws.amazon.com/compliance/aws-whitepapers/for the latest version of this paper) Page 1 of 13 Overview
Legal Profession Amendment (Fixed Costs) Regulation 2013
New South Wales Legal Profession Amendment (Fixed Costs) Regulation 2013 under the Legal Profession Act 2004 Her Excellency the Governor, with the advice of the Executive Council, has made the following
LSSA Guidelines on the Use of Internet-Based Technologies in Legal Practice
LSSA Guidelines on the Use of Internet-Based Technologies in Legal Practice LSSA 2014 1 Use of Internet-Based Technologies in Legal Practice LSSA Guidelines Version 1.0 November 2014 2 Foreword Please
GSK Public policy positions
Safeguarding Personally Identifiable Information A Summary of GSK s Binding Corporate Rules The Issue The processing of Personally Identifiable Information (PII) 1 and Sensitive Personally Identifiable
CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS. White Paper
CANADIAN PRIVACY AND DATA RESIDENCY REQUIREMENTS White Paper Table of Contents Addressing compliance with privacy laws for cloud-based services through persistent encryption and key ownership... Section
CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING
CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING CCBE response regarding the European Commission Public Consultation on Cloud Computing The Council of Bars and Law
Cloud Computing Contracts. October 11, 2012
Cloud Computing Contracts October 11, 2012 Lorene Novakowski Karam Bayrakal Covering Cloud Computing Cloud Computing Defined Models Manage Cloud Computing Risk Mitigation Strategy Privacy Contracts Best
Cloud computing and personal data protection. Gwendal LE GRAND Director of technology and innovation CNIL
Cloud computing and personal data protection Gwendal LE GRAND Director of technology and innovation CNIL 1 Data protection in Europe Directive 95/46/EC Loi 78-17 du 6 janvier 1978 amended in 2004 (France)
Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad. Toronto, Ontario June 14, 2005
Data Management: Considerations for Integrating Compliance Requirements At Home and Abroad Toronto, Ontario June 14, 2005 Outsourcing Update: New Contractual Options and Risks Lisa K. Abe June 14, 2005
Privacy and data protection in a post-snowden world. Carly Nyst Head of International Advocacy
Privacy and data protection in a post-snowden world Carly Nyst Head of International Advocacy The great irony is that we re the only ones not spying on the American people. - Keith Alexander, head of the
M&T BANK CANADIAN PRIVACY POLICY
M&T BANK CANADIAN PRIVACY POLICY At M&T Bank, we are committed to safeguarding your personal information and maintaining your privacy. This has always been a priority for us and this is why M&T Bank (
The HR Skinny: Effectively managing international employee data flows
The HR Skinny: Effectively managing international employee data flows Topics we will cover today Laws affecting HR data flows HR international data protection challenges and strategic solutions Case study
Whistleblowers How to mitigate the multiplying threats to your business. +1 202 496 7528 +1 202 408 6410
Whistleblowers How to mitigate the multiplying threats to your business. Treazure Johnson Kirk Ruthenberg Partner Partner [email protected] [email protected] +1 202 496 7528 +1 202 408
THE TRANSFER OF PERSONAL DATA ABROAD
THE TRANSFER OF PERSONAL DATA ABROAD MARCH 2014 THIS NOTE CONSIDERS THE SITUATION OF AN IRISH ORGANISATION OR BUSINESS SEEKING TO TRANSFER PERSONAL DATA ABROAD FOR STORAGE OR PROCESSING, IN LIGHT OF THE
Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective
Cloud Computing: Privacy & Jurisdiction from a Canadian Perspective Professor Michael Geist Canada Research Chair in Internet and E-commerce Law University of Ottawa, Faculty of Law Cloud Computing - Canada
Government Surveillance, Hacking, and Network Security: What Can and Should Carriers Do? Kent Bressie PITA AGM, Tonga April 2015
Government Surveillance, Hacking, and Network Security: What Can and Should Carriers Do? Kent Bressie PITA AGM, Tonga April 2015 1 Network and cybersecurity vs. access Fundamental tension exists between:
The cloud thing: Privacy and cloud computing
The cloud thing: Privacy and cloud computing David T.S. Fraser ([email protected] / @privacylawyer) University of New Brunswick July 2011 Disclaimer What follows are the views of the author
The North Atlantic Treaty (1949)
The North Atlantic Treaty (1949) Washington D.C. - 4 April 1949 The Parties to this Treaty reaffirm their faith in the purposes and principles of the Charter of the United Nations and their desire to live
Cybersecurity and Data Breach: Mitigating Risk and How Government Policymakers Approach These Critical Issues
Cybersecurity and Data Breach: Mitigating Risk and How Government Policymakers Approach These Critical Issues Todd Bertoson Daniel Gibb Erin Sheppard Principal Senior Managing Associate Counsel [email protected]
Bill C-51, Anti-terrorism Act, 2015 Executive Summary
Bill C-51, Anti-terrorism Act, 2015 Executive Summary CANADIAN BAR ASSOCIATION March 2015 500-865 Carling Avenue, Ottawa, ON, Canada K1S 5S8 tel/tél : 613.237.2925 toll free/sans frais : 1.800.267.8860
Review of Building the Canadian Advantage: a Corporate Social Responsibility Strategy for the Canadian International Extractive Sector
Review of Building the Canadian Advantage: a Corporate Social Responsibility Strategy for the Canadian International Extractive Sector Submission to the Department of Foreign Affairs, Trade & Development
AskAvanade: Answering the Burning Questions around Cloud Computing
AskAvanade: Answering the Burning Questions around Cloud Computing There is a great deal of interest in better leveraging the benefits of cloud computing. While there is a lot of excitement about the cloud,
Acquia Comments on EU Recommendations for Data Processing in the Cloud
Acquia Comments on EU Recommendations for Data Processing in the Cloud Executive Summary On July 1, 2012, European Union (EU) data protection regulators provided guidelines for service providers processing
SUBMISSION TO THE SPECIAL COMMITTEE TO REVIEW TRANSBORDER DATA FLOWS AND THEIR REGULATION THE FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY ACT
SUBMISSION TO THE SPECIAL COMMITTEE TO REVIEW THE FREEDOM OF INFORMATION AND PROTECTION OF PRIVACY ACT TRANSBORDER DATA FLOWS AND THEIR REGULATION Authored by Kris Klein from the Law Office of Kris Klein,
Brad Smith, General Counsel & Executive Vice President, Legal and Corporate Affairs, Microsoft
Brad Smith, General Counsel & Executive Vice President, Legal and Corporate Affairs, Microsoft 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows and other product names are or may be
Cloud Security Trust Cisco to Protect Your Data
Trust Cisco to Protect Your Data As cloud adoption accelerates, organizations are increasingly placing their trust in third-party cloud service providers (CSPs). But can you fully trust your most sensitive
As part of their course on law and/or sociology in this module, participants will be able to:
Correctional Service Service correctionnel Service correctionnel Correctional Service Law Correctional Service : At the Heart of Criminal Justice Description The Correctional Service of : At the Heart
THE PHONE RINGS FROM DOWN SOUTH: WHAT ISSUES SHOULD I CONSIDER FOR EXPANDING MY U.S. FRANCHISE INTO CANADA?
THE PHONE RINGS FROM DOWN SOUTH: WHAT ISSUES SHOULD I CONSIDER FOR EXPANDING MY U.S. FRANCHISE INTO CANADA? By Leonard H. Polsky Gowling Lafleur Henderson LLP Vancouver, British Columbia SYNOPSIS Canadian
Doing Business. A Practical Guide. casselsbrock.com. Canada. Dispute Resolution. Foreign Investment. Aboriginal. Securities and Corporate Finance
About Canada Dispute Resolution Forms of Business Organization Aboriginal Law Competition Law Real Estate Securities and Corporate Finance Foreign Investment Public- Private Partnerships Restructuring
Joint Innovate UK and CW Legal SIG Event - Internet of Things Workshop - 17th March 2015. Contracting for IoT
Joint Innovate UK and CW Legal SIG Event - Internet of Things Workshop - 17th March 2015 Contracting for IoT Professor Ian Walden Institute of Computer and Communications Law Centre for Commercial Law
Privacy vs Data Protection. PRESENTATION TITLE GOES HERE Eric A. Hibbard, CISSP, CISA Hitachi Data Systems
Privacy vs Data Protection PRESENTATION TITLE GOES HERE Eric A. Hibbard, CISSP, CISA Hitachi Data Systems Introduction The terms privacy and data protection are often used interchangeable In reality they
Committee on Civil Liberties, Justice and Home Affairs - The Secretariat - Background Note on
Committee on Civil Liberties, Justice and Home Affairs - The Secretariat - Background Note on US Legal Instruments for Access and Electronic Surveillance of EU Citizens Introduction This note presents
Irish Tax Institute. Response to OECD Discussion Draft: Make Dispute Resolution Mechanisms More Effective
Irish Tax Institute Response to OECD Discussion Draft: Make Dispute Resolution Mechanisms More Effective January 2015 About the Irish Tax Institute The Irish Tax Institute is the leading representative
Cloud Computing: Privacy and Other Risks
December 2013 Cloud Computing: Privacy and Other Risks by George Waggott, Michael Reid and Mitch Koczerginski, McMillan LLP Introduction While the benefits of outsourcing organizational data storage to
Industry Engagement Event. CLOUD COMPUTING SOLUTIONS CONSULTATION EN578 151297/A November 13 th, 2014 Delta Hotel, Ottawa.
Industry Engagement Event CLOUD COMPUTING SOLUTIONS CONSULTATION EN578 151297/A November 13 th, 2014 Delta Hotel, Ottawa. Safe Harbour Statement This presentation contains information regarding potential
FORM 31-103F1 Calculation of Excess Working Capital. Firm Name. Capital Calculation (as at with comparative figures as at )
FORM 31-103F1 Calculation of Excess Working Capital Firm Name Capital Calculation (as at with comparative figures as at ) Component Current period Prior period 1. Current assets 2. Less current assets
Minister Shatter presents Presidency priorities in the JHA area to European Parliament
Minister Shatter presents Presidency priorities in the JHA area to European Parliament 22 nd January 2013 The Minister for Justice, Equality and Defence, Alan Shatter TD, today presented the Irish Presidency
White paper Reaping Business Value from a Hybrid Cloud Strategy
White paper Fujitsu Hybrid Cloud Services White paper Reaping Business Value from a Hybrid Cloud Strategy How to embrace a hybrid cloud model to maximize the benefits of public and private cloud services
Data Privacy in the Cloud: A Dozen Myths & Facts
Data Privacy in the Cloud: A Dozen Myths & Facts March 7-9 Washington DC Presented by: Barbara Cosgrove, Chief Security Officer, Workday, Inc. Lothar Determann, Partner, Baker & McKenzie LLP We re taking
SASKATCHEWAN OFFICE OF THE INFORMATION AND PRIVACY COMMISSIONER INVESTIGATION REPORT F-2012 003. Saskatchewan Workers Compensation Board
Date: August 29, 2012 File No.: 2008/101 SASKATCHEWAN OFFICE OF THE INFORMATION AND PRIVACY COMMISSIONER INVESTIGATION REPORT F-2012 003 Saskatchewan Workers Compensation Board Summary: The Commissioner
FACTORING AND FINANCING IN CANADA WHAT EVERY U.S. FACTOR AND LAWYER WANTS TO KNOW ABOUT PURCHASING AND TAKING SECURITY ON CANADIAN RECEIVABLES
FACTORING AND FINANCING IN CANADA WHAT EVERY U.S. FACTOR AND LAWYER WANTS TO KNOW ABOUT PURCHASING AND TAKING SECURITY ON CANADIAN RECEIVABLES Cross-border transactions involving U.S. and Canadian parties
ANGUILLA FINANCIAL SERVICES COMMISSION
GUIDELINESON ACCEPTABILITY OF AN AUDITOR (Issued under Section 49 of the Financial Services Commission Act, R.S.A. c.f28 (as amended)) 1. Statement of objectives These guidelines set out conditions with
Intellectual Property Rights In China
Intellectual Property Rights In China Intellectual Property Office is an operating name of the Patent Office Contents Intellectual Property Rights In China What Are Intellectual Property Rights? International
The United States Federal Trade Commission ("FTC") and the Office of the Data Protection Commissioner of Ireland (collectively, "the Participants"),
MEMORANDUM OF UNDERSTANDING BETWEEN THE UNITED STATES FEDERAL TRADE COMMISSION AND THE OFFICE OF THE DATA PROTECTION COMMISSIONER OF IRELAND ON MUTUAL ASSISTANCE IN THE ENFORCEMENT OF LAWS PROTECTING PERSONAL
Civil Antitrust Litigation in the United States: Implications for Ireland and the European Community
Civil Antitrust Litigation in the United States: Implications for Ireland and the European Community Joseph T. McLaughlin Heller Ehrman, LLP Prepared with the assistance of: August T. Horvath Daniel Sheridan
(U) Appendix E: Case for Developing an International Cybersecurity Policy Framework
(U) Appendix E: Case for Developing an International Cybersecurity Policy Framework (U//FOUO) The United States lacks a comprehensive strategic international policy framework and coordinated engagement
AlixPartners, LLP. General Data Protection Statement
AlixPartners, LLP General Data Protection Statement GENERAL DATA PROTECTION STATEMENT 1. INTRODUCTION 1.1 AlixPartners, LLP ( AlixPartners ) is committed to fulfilling its obligations under the data protection
Credit Union Liability with Third-Party Processors
World Council of Credit Unions Annual Conference Credit Union Liability with Third-Party Processors Andrew (Andy) Poprawa CEO, Deposit Insurance Corporation of Ontario Canada 1 Credit Union Liability with
Privacy & Data Security: The Future of the US-EU Safe Harbor
Privacy & Data Security: The Future of the US-EU Safe Harbor NAOMI MCBRIDE, LISA J. SOTTO AND BRIDGET TREACY, HUNTON & WILLIAMS LLP, WITH PRACTICAL LAW US INTELLECTUAL PROPERTY & TECHNOLOGY AND UK IP&IT
PRINCIPLES OF INTERNATIONAL LAW
RIR6007/RIO7009, 2. Nov. 2010 PRINCIPLES OF INTERNATIONAL LAW 1 Sovereignty Equality Consent Duty of States to co-operate Non-intervention Settlement of international disputes by peaceful means Prohibition
WILLS AND CROSS-BORDER ASSETS
WILLS AND CROSS-BORDER ASSETS Is it better to have one will covering multiple jurisdictions? Or Is it better to have a separate will for each jurisdiction? Many people hold assets in different jurisdictions.
