zaštita ličnih podataka iskustva iz republike slovenije podgorica, 7.2.2010 nataša pirc musar...

22
Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Upload: franklin-watts

Post on 01-Jan-2016

224 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Zaštita ličnih podatakaIskustva iz Republike Slovenije

Podgorica, 7.2.2010

Nataša Pirc MusarInformation Commissioner

Page 2: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

• Access to public information v. Data protection

Can one body handel both?

Page 3: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Situation in Slovenia

What we do and how we do it?

Page 4: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Trust in the Information Commissioner

(public poll Jan 2010)

Page 5: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Trust in supervisory authorities(public poll Oct 2010)

INFORMATION COMMISSIONER

OMBUDSMAN

POLICE GEN. DIRECTOR

STATE PROSECUTOR

DOES NOT TRUST / TRUSTS

Page 6: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Situation in Slovenia

Formal supervisory procedures

Page 7: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Informacijski povjerenik

• Poverenica, 3 zamjenika i vođa inspektora• 32 zaposlenih

18 na zaštiti osobnih podataka, 10 na pristupu informacijama, 4 u administraciji

• 9 (11) inspektora• Aktivan od 31.12.2005

(ujedinjenje Poverenika i Inspekcije za lične podatke)

Snažne komeptencije po Zakonu o inspekcijskom nadzoru Predlog za zatvaranje rukovalaca (ako ne plate kaznu), Novčane kazne, Podnošenje prijave krivičnog djela, Ulaz u kancelarije, pregled kompjutera...

Page 8: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Inspection procedures

Page 9: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Structure of procedures (2006-2009)

Page 10: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Misdemeanour procedures (2009)

Page 11: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Misdemeanour procedures (2009)

• 2009: 163 violation procedures– Public sector: 41 – Private sector: 70– Natural persons: 52

• 59 warnings• 93 decisions

– 67 cautions– 26 fines

• 12 payment orders• 21 appeals to the court

• Fines:– Legal person.: 4.170 to 12.510 EUR– Responsible person: 830 to 2.080 EUR

Largest fine:– 112.000 EUR for data controller– 20.000 EUR for responsible person

Page 12: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Data subject’s access

• 2009: 70 demands– 2008: 43 demands

• Some interesting cases, e.g. access to retained traffic data on telephone calls

Number of requests (complaints) for

access to individual’s own data

Page 13: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Situation in Slovenia

Awareness raising toolbox

Page 14: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Opinions

• 2009: 1334 requests for opinion– 2008: 853 requests for opinion

• On-line publication (2000 + opinions)

• Main areas:– Offcial procedures – judicial,

administrative and police procedures (67),

– Employment relationships (64),– Transfer of personal data between

data controllers(45),– Internet related(43),– Health data (33),

Page 15: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Guidelines

Page 16: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Identity theft – self assesment testadapted from NOR DPA original

Page 17: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Facebook profile

Page 18: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Data protection

The challenges

Page 19: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Data protection challenges– Location privacy

• Google Street View, Google Earth – what is next?– Probably other angles between vertical and horizontal pictures, higher frequency and

perhaps “real-time view-it-all?”

• Drivers’ privacy– Electronic toll collection and other location-based services

– Personal profiles and behavioural marketing• Personalized, customized ads• All media covered: internet, print, (digital TV)!• Smart videosurveillance, audience measurement…

– Changing attitudes towards privacy• DPA’s awareness raising toolbox• Can we influence it al all?

– REAL concern when statemets are made such as:• “Privacy as a social norm is a matter of past!” by____, CEO of______• “If you have something that you don't want anyone to know, maybe you

shouldn't be doing it in the first place.” by____, CEO of______

Page 20: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Data protection challenges cont.

– Worklapce privacy• Many complaints• Draft bill prepared

– Identity theft• Abuse of publicly available data• Abuse of private data

– Data business• Interconnection of databases• Outsourcing of personal data / cloud computing

– Digital dataveillance• e.g. automated analysis of computer and telephone network

traffic (i.e. Data retention ...)• Creation of extensive personal profiles and activity histories;

can be used for many reasons – can lead to errosion of privacy

– Let’s have a closer look at some of them …

Page 21: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

“The problem with the nothing to hide argument is with its underlying assumption that privacy is about hiding bad things.“

Daniel Solove

Page 22: Zaštita ličnih podataka Iskustva iz Republike Slovenije Podgorica, 7.2.2010 Nataša Pirc Musar Information Commissioner

Thank you for

your attention!IC website in English

www.ic-rs.si