The prospects for data breach laws in 22 European countries



Similar documents
Delegation in human resource management

OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES

Keeping European Consumers safe Rapid Alert System for dangerous non-food products 2014

Adobe Public Relations (PR) Guidelines

4. We understand this to mean that each provider state will need to ensure indemnity arrangements are in place to cover healthcare provided in that

ORGANISATION FOR ECONOMIC CO-OPERATION AND DEVELOPMENT

Preventing fraud and corruption in public procurement

Data Protection Policy Information for Clients

Camden Asset Recovery Inter-Agency Network (CARIN)

Education at a Glance. OECD Indicators. Annex: UOE Data Collection Sources

ESC-ERC Recommendations for the Use of. Automated External Defibrillators (AEDs) in Europe

Central Securities Depository Regulation

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person.

Labour Force Survey 2014 Almost 10 million part-time workers in the EU would have preferred to work more Two-thirds were women

Planned Healthcare in Europe for Lothian residents

ERASMUS+ MASTER LOANS

Data Transfer Policy London Borough of Barnet

HSE HR Circular 005/ th February 2010.

Review of R&D Tax Credit. Invitation for Submissions

TPI: Traffic Psychology International on a common European curriculum for postgraduate education in traffic psychology

Guide. Axis Webinar User Guide

Group 1 Group 2 Group 3 Group 4

TOWARDS PUBLIC PROCUREMENT KEY PERFORMANCE INDICATORS. Paulo Magina Public Sector Integrity Division

Genuine BMW Accessories. The Ultimate Driving Machine. BMW Trackstar. tracked. recovered. BMW TRACKSTAR.

Visa Information 2012

Achieving Global Cyber Security Through Collaboration

EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update. By Stephen H. LaCount, Esq.

1. Perception of the Bancruptcy System Perception of In-court Reorganisation... 4

Single Euro Payments Area

Crime and Criminal Justice

Expenditure and Outputs in the Irish Health System: A Cross Country Comparison

SunGard Best Practice Guide

ERASMUS+ MASTER LOANS

Statewatch Briefing ID Cards in the EU: Current state of play

Higher education institutions as places to integrate individual lifelong learning strategies

International Call Services

E-Justice and E-Law Conference. Rome October Corte di Cassazione. Madalina Adam (Ministry of Justice, Romania)

Health care in Sweden for foreign students [Sjukvård i Sverige för utländska studenter]

Drink Driving in Europe

Energy prices in the EU Household electricity prices in the EU rose by 2.9% in 2014 Gas prices up by 2.0% in the EU

Canada GO 2535 TM World Traveller's edition Maps of North America (Canada, US, Mexico), Western and Central Europe (including Russia) CAD 349,95

Business Mobile Plans

Electricity, Gas and Water: The European Market Report 2014

PUBLIC VS. PRIVATE HEALTH CARE IN CANADA. Norma Kozhaya, Ph.D Economist, Montreal economic Institute CPBI, Winnipeg June 15, 2007

Crystal Clear Contract Services Limited Application Form CIS/Sole Trader

relating to household s disposable income. A Gini Coefficient of zero indicates

The European Union Savings Tax Directive. An historic guide

EU Competition Law. Article 101 and Article 102. January Contents

UNCITRAL legislative standards on electronic communications and electronic signatures: an introduction

PUBLIC & PRIVATE HEALTH CARE IN CANADA

10. Driving in Ireland

Trends in Digitally-Enabled Trade in Services. by Maria Borga and Jennifer Koncz-Bruner

Fostering Entrepreneurship among young people through education: a EU perspective. Simone Baldassarri Unit Entrepreneurship

MARGARET HADDOCK PRESIDENT EUROPEAN UNION FOR SUPPORTED EMPLOYMENT (EUSE) DEPUTY CHIEF EXECUTIVE THE ORCHARDVILLE SOCIETY. Brussels June 2014

The Act imposes foreign exchange restrictions, i.e. performance of certain actions requires a relevant foreign exchange permit.

Family benefits Information about health insurance country. Udbetaling Danmark Kongens Vænge Hillerød. A. Personal data

A clean and open Internet: Public consultation on procedures for notifying and acting on illegal content hosted by online intermediaries

LANDWELL. Solicitors. Life Sciences Unit

Report on Government Information Requests

41 T Korea, Rep T Netherlands T Japan E Bulgaria T Argentina T Czech Republic T Greece 50.

Employee eligibility to work in the UK

I have asked for asylum in the EU which country will handle my claim?

PERMANENT AND TEMPORARY WORKERS

Global Effective Tax Rates

Information Security Risks when going cloud. How to deal with data security: an EU perspective.

Office Rents map EUROPE, MIDDLE EAST AND AFRICA. Accelerating success.

About us. As our customer you will be able to take advantage of the following benefits: One Provider. Flexible Billing. Our Portal.

Size and Development of the Shadow Economy of 31 European and 5 other OECD Countries from 2003 to 2015: Different Developments

Summary of Data Protection Requirements When transferring Data Outside the UK End Users

New environmental liabilities for EU companies

ERASMUS FOR YOUNG ENTREPRENEURS : A NEW EXCHANGE PROGRAMME

The Guardianship Service

Re: Intern recruitment process at IPPR

TREATY MAKING - EXPRESSION OF CONSENT BY STATES TO BE BOUND BY A TREATY

INTERNATIONAL TRACKED POSTAGE SERVICE

THINK Global: Risk and return

Offshore outsourcing of business services Threat or Opportunity

In May and July 2014 UK Visas and Immigration (UKVI) introduced changes to the right to work checks employers are required to carry out.

ORGANISATION FOR ECONOMIC CO-OPERATION AND DEVELOPMENT

Analysis on European landscape & Match making tool for Photonics Industry & Research

T R A V E L A N D A C C O M M O D A T I O N E X P E N S E S

Response to the European Commission s consultation on the legal framework for the fundamental right to protection of personal data

(Only available if you have applied for a Decreasing Mortgage Cover Plan or a Level Protection Plan).

MALTA TRADING COMPANIES

International Hints and Tips

This Webcast Will Begin Shortly

Pan-European opinion poll on occupational safety and health

INSOL Europe. The professional association for European restructuring and insolvency specialists. Become a member

School Security Assessment Programme in Australia

Transcription:

The prospects for data breach laws in 22 European countries Stewart Dresner, Chief Executive Privacy Laws & Business Wednesday, 4 November 2009 16 30-17 45: PARALLEL SESSION A: Ooopsss!!!!! Where did I leave my computer? Prevention and reaction in light of security breaches 31 st International Conference of Data Protection and Privacy Commissioners, Madrid 1

2

The prospects for data breach laws in 22 European countries: Contents 1. Privacy Laws & Business s knowledge base and contacts 2. Rationale and scope for data breach research 3. The research method 4. Common themes 5. Current data breach laws and demand for new laws 6. Results: DPAs views and preferred policies 7. Advantages and disadvantages of a data breach law for DPAs, companies and individuals* 8. Recommendations by DPAs and companies* 9. Privacy Laws & Business s conclusions 10. What next? * Slides available on request 3

4

5

6

Privacy Laws & Business 23 rd Annual International Conference July 5 th 7 th 2010 St John s College Cambridge United Kingdom 7

8

EPON Data Protection Commissioner Roundtables Madrid, Spain (2003) Rome, Italy (2003) Czech Republic, Hungary and Poland in Prague (2004) Paris, France (2005) Berlin, Germany (2005) Dublin, Ireland (2006) Russia, Greece, Portugal in London (2006) Stockholm, Sweden (2007) Helsinki, Finland (2007) Brussels, Belgium (2007) Hague, Netherlands (2007) Madrid, Spain (2008) Luxembourg (2008) Warsaw, Poland (2008) Zurich, Switzerland (2009) Rome, Italy (2009) 9

IPON Roundtables Argentina s DP Commissioner/Australia s DP Commissioner in Montreux, Switzerland - 2005 Binding Corporate Rules, Washington DC - 2006 European HR issues in Washington DC - 2006 Canadian HR issues in Toronto - 2007 Asia-Pacific Briefing, London - 2007 Asia-Pacific Conference, Strasbourg 2008 Madrid, November 3 rd 2009 Employee surveillance in Europe: Balancing privacy rights and management control 10

11

12

EPON/IPON Participants include: Accenture Arnold & Porter Barclays Bank Boeing BP BT Citigroup CSC Deutsche Bank ebay Eli Lilly ExxonMobil FIFA Fujitsu General Electric General Motors Google Halliburton HBOS IBM IMS Health Intel Johnson & Johnson Kodak Lloyds Register Manpower Nestle Novartis Oracle Pfizer PwC Procter & Gamble Schering-Plough Sony Total Walt Disney Western Union Wyeth 13

EPON/IPON Meeting Hosts

Other PL&B Services Consulting Data Protection Audits Recruitment Advice on job descriptions Interim managers Training 15

Rationale for data breach research USA: data breach laws in most states. Have these US laws set a trend for Europe or are current data protection laws enough? US laws role in helping raise awareness Lack of research linking data breaches to ID theft, credit card fraud etc. But a consensus that increased data losses should be tackled DP and privacy laws in the EU and US cover data security Is there a need for specific provisions on action to be taken when data is lost or stolen? 16

Scope & Geographical Context 27 EU member states All other countries within the European Economic Area: Norway, Iceland, Liechtenstein Switzerland Jersey, Guernsey, Isle of Man 17

Research Timeline 1 2008 January: Questionnaire by email to DPAs Follow-up telephone calls and emails Responses from: Czech Republic, Denmark, Finland, Guernsey, Hungary, Iceland, Ireland, Jersey, Slovak Republic, Sweden & United Kingdom European Privacy Officers Network members survey and results February: Report in PL&B s International newsletter (available on request) March: Detailed report for DPAs and feedback 18

Research Timeline 2 April: Target larger/more experienced countries DPAs May-June: Responses from Italy, Spain, Portugal, Poland, Luxembourg, France and Belgium July: Presentation of results at PL&B s Annual Conference, Cambridge Aug-Nov: Drafting report Jan-Mar 2009: Responses from Austr, Germ, Neths Feb-April 2009: DPAs check reports. Updates April/May 2009: Conference and Report published 19

Research Methods Email responses from most countries. Face-to-face interviews (Italy, Portugal, Luxembourg) Telephone interviews (Jersey, Guernsey, Germany) Other Methods National expert s comments in Switzerland (David Rosenthal, Special Counsel, IT & Telecommunications, Homburger, Zurich) 20

Questions to DPAs 16 questions covering the following areas: 1. Current laws 2. Demand for data breach laws 3. Purpose and scope of legislation 4. Regulatory options and preferred policies 21

Common themes 1. Definitions what is a data breach? 2. Breach notification: How, when and who should companies notify? 3. Lack of research particularly on impact of data breaches on individuals 4. Always a risk attached to the processing of personal data 5. Criminal liability for organisations? 22

Current data breach laws Data protection legislation in all European countries but only general application of this legislation to the unauthorised access, loss or theft of personal data Data breaches covered by DP laws, criminal & civil codes and additional e-communication legislation Some reporting requirements and guidance but no specific mention in law of action to be taken, except Specific data breach law in Germany (2009) where individuals suffer considerable damage and for specific data: professional secrecy, criminal or administrative offences and bank or credit card data 23

Demand for data breach laws Increase in reported data breach incidents Hot topic for the media and growing political interest. Differing pressures in different countries - more in the Netherlands, less in Portugal Trend for data controllers to contact the authorities where data has been inappropriately released No Europe-wide demand for a specific data breach law as current legislation is sometimes enough 24

DPAs views on purpose and scope of specific data breach rules 1. Harmonisation within the EU but national implementation to reflect national needs 2. Any new data breach provisions to include: data controllers and data processors the public and private sectors 3. Problems with breach notification in the US discourage Europe e.g. over-notification and inconsistency of reporting rules 4. Responsibilities and tasks must be stated clearly 25

Regulatory Options Agreement that some form of a data breach regulation would be a good idea. Four options or a combination: 1. Insert data breach provisions into existing related legislation 2. EU Member States insert mandatory breach notification requirement as a specific national law 3. Amend EU e-comms or general DP Directive 4. Practical Guidelines by the EU Art. 29 Data Protection Working Party 26

Driving factors behind a separate data breach law 1. Increase the protection of personal data 2. Make organisations more accountable for data security 3. Force organisations to improve security standards 4. Restore individuals confidence in data controllers 27

DPAs views on possible data breach laws Some consistency is needed across Europe in this area EU should regulate first DPAs favouring amending their current data protection or other law to cover data breaches (UK, Jersey, Finland, Poland, Portugal, Luxembourg, Italy, Netherlands and Germany) 28

DPAs Preferred Policies 1 1. More human and financial resources 2. Notification of data breaches. 3. Orders from DPAs to data controllers and processors to act in a specific way in response to a data breach. 4. Discretion to impose sanctions and appropriate fines 5. Compensation to individuals (in conjunction with civil law provisions) 6. Power to conduct audits when necessary 7. Power to publicly name and shame organisations 29

DPAs Preferred Policies 2 8. Support new provisions covering both the public and private sectors (All) 9. Favouring new provisions to cover both data processors and controllers (All DPAs apart from UK, Ireland, Guernsey, Germany and the Netherlands) 10. Want companies to notify them of data breaches (UK,Jersey, Czech Republic, Guernsey, Ireland, Finland, France, Portugal, Luxembourg, Italy, and Germany) 11. Favouring companies paying compensation to individuals where appropriate (Poland, UK, Finland, France, Italy, and Austria) 11. Offering data breach guidance (UK and Ireland) 12. Some form of redress for data subjects 30

PL&B s Conclusions The ideal is a synthesis of DPAs and companies views which are also practical for data subjects. A data breach plan should be: 1. proportionate 2. an alert to a DPA when there is substantive rather than a procedural problem 3. have more emphasis on a remedy to a problem, and 4. less emphasis on sanctions. 31

What next? EU Level 1. Extension of EU e-communications directive to include data breach legislation for ISPs, other sectors? 2. Amend general EU Data Protection Directive? 3. Practical guidelines by the EU Art.29 Working Party? National Level 1. Modest amendments to national laws e.g. Luxembourg amending DP code to include responsibilities of processors as well as controllers Company Level 1. Broader breach management programmes 2. Continuing improvement of internal systems e.g. reporting mechanisms 32

Report from Privacy Laws & Business Data Breach Dossier on request Questions? Research Director and Editor: Stewart Dresner Researcher: Amy Norcup 33

Contact details Stewart Dresner, Chief Executive Adèle Kendler, Project Manager Privacy Laws & Business 2nd floor, Monument House, 215, Marsh Road, Pinner, Middlesex,HA5 5NE, United Kingdom Tel: + 44 208 868 9200 Fax: + 44 208 868 5215 www.privacylaws.com 34

35