2014-04-16 protection of personal information act readiness workshop

47
2014-04-16 Responsible Data Processing Protection of Personal Information Act Workshop

Upload: paul-jacobson

Post on 22-Apr-2015

520 views

Category:

Law


0 download

DESCRIPTION

These are my slides for my presentation at the Protection of Personal Information Act Readiness Workshop at the OR Tambo Protea Hotel on 16 April 2014. My focus was on understanding data processing constraints; identifying key risk areas and the benefits of better data protection frameworks.

TRANSCRIPT

Page 1: 2014-04-16 Protection of Personal Information Act Readiness Workshop

2014-04-16

Responsible Data ProcessingProtection of Personal Information Act Workshop

Page 2: 2014-04-16 Protection of Personal Information Act Readiness Workshop

2014-04-16

Share your thoughtsYou can find me on Twitter as @pauljacobson

#POPIready

Page 3: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Understanding your data processing constraints

Page 4: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Lawful processing conditions

✤ Accountability!

✤ Purpose limitation!

✤ Purpose specification!

✤ Further processing limitation!

✤ Information quality!

✤ Openness!

✤ Security safeguards!

✤ Data subject participation

Page 5: 2014-04-16 Protection of Personal Information Act Readiness Workshop

There are exceptions

Page 6: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Personal or household activity

Page 7: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Anonymised and can’t be associated !with a data subject again

Page 8: 2014-04-16 Protection of Personal Information Act Readiness Workshop

By or on behalf of a!public body

National security Public defence Crime and money laundering

Page 9: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Cabinet or!Executive Councils Judicial proceedings

Page 10: 2014-04-16 Protection of Personal Information Act Readiness Workshop

01

Journalistic, literary or artistic purposes

Page 11: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“solely for the purpose of journalistic, literary or artistic expression to the extent that such an exclusion is necessary to

reconcile, as a matter of public interest, the right to privacy with the right to freedom of expression.”

– Section 7(1), Protection of Personal Information Act

Page 12: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Regulatory function delegated to a code of ethics that will apply to the exclusion of the Act*

* This is provided for elsewhere and forms part of a distributed enforcement mechanism

Page 13: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Conditions for lawful processing of personal information

Page 14: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Consent and data collection

Page 15: 2014-04-16 Protection of Personal Information Act Readiness Workshop

01Consent, justification and objection

Page 16: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“… it seems to be a sensible approach to say that the scope of a person’s privacy extends a fortiori only to those aspects in regard to which a legitimate expectation of privacy can be

harboured.”

– Bernstein and Others v Bester NO and Others

Page 17: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Options

Consent

Legitimate interests

Contractual conclusion or performance

Page 18: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Only in the case of consent may a data subject withdraw permission

Page 19: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“Legitimate interests” is vague, undefined and, yet, a very interesting justification

Page 20: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“The processing is necessary for the purposes of legitimate interests pursued by the data controller or by the third party or parties to whom the data are disclosed, except where the

processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of

the data subject.”

– Section 6, Schedule 2, UK Data Protection Act

Page 21: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Still, the “Lawful processing of personal information conditions” provide broad parameters and context for

“legitimate interests” arguments …

Page 22: 2014-04-16 Protection of Personal Information Act Readiness Workshop

01

Special personal information

Page 23: 2014-04-16 Protection of Personal Information Act Readiness Workshop

✤ Children’s personal information!

✤ Religious or philosophical beliefs*!

✤ Race or ethnic origin!

✤ Trade union membership*!

✤ Political persuasion!

✤ Health or sex life!

✤ Criminal behaviour or biometric information

Page 24: 2014-04-16 Protection of Personal Information Act Readiness Workshop

How transparent are you?

Page 25: 2014-04-16 Protection of Personal Information Act Readiness Workshop

‘‘consent’’ means any voluntary, specific and informed expression of will in terms of which permission is given for

the processing of personal information

Page 26: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“A responsible party must take reasonably practicable steps to ensure that the personal information is complete, accurate,

not misleading and updated where necessary.”

– Section 16, the Protection of Personal Information Act

Page 27: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Do you facilitate meaningful access to personal information you hold?

Page 28: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Data processing

Page 29: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“Personal information may only be processed if, given the purpose for which it is processed, it is adequate, relevant

and not excessive.”

– Section 10, the Protection of Personal Information Act

Page 30: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Purpose specification

“Personal information must be collected for a specific, explicitly defined and lawful purpose related to a function or activity of

the responsible party”

Be transparent about the purpose

Page 31: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Further processing must align with the original purpose*

* There are exceptions too

Page 32: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Data integrity and retention

Page 33: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“… records of personal information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed …”

– Section 13, Protection of Personal Information Act

Page 34: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Don’t lose sight of the bigger data retention compliance picture

Electronic Communications and Transactions Act

Protection of Personal Information Act

Everything else

Page 35: 2014-04-16 Protection of Personal Information Act Readiness Workshop

POPI places special emphasis on security safeguards

Page 36: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“A responsible party must secure the integrity and confidentiality of personal information in its possession or

under its control by taking appropriate, reasonable technical and organisational measures …”

– Section 19, Protection of Personal Information Act

Page 37: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that

the operator which processes personal information for the responsible party establishes and maintains the security

measures referred to in section 19 …”

– Section 21, Protection of Personal Information Act

Page 38: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Identifying key risk areas

Page 39: 2014-04-16 Protection of Personal Information Act Readiness Workshop

How do you process personal information?

Helpful questions

Are you the responsible party or the operator?

Is your reputation at risk and what could go wrong?

Page 40: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Do you engage in direct marketing?

Page 41: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Do you process personal information on your responsible party customers’ behalf?

Page 42: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Benefits of better protection frameworks

Page 43: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Clear privacy statements

Page 44: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Transparent dealings with stakeholders

2014 Heartbleed Bug

OpenSSL exploit came to light

Providers proactively contacted users and recommended password changes

Page 45: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Be responsible, reduce reputational harm risk in the process

Page 46: 2014-04-16 Protection of Personal Information Act Readiness Workshop

“The way to gain good reputation is to endeavor to be what you desire to appear”

– Socrates

Page 47: 2014-04-16 Protection of Personal Information Act Readiness Workshop

Thank you for your time.Please feel free to contact me if we can assist you or answer questions.

webtechlaw.com/contact

Paul Jacobson 083 444 8260