33
DATA PROTECTION Wednesday, 8 October 2008 Friday, 10 October 2008 Monday, 13 October 2008 An Overview of Data Protection Legislation in Guernsey Jon Barclay, Advocate AO Hall Advocates

Guernsey Data Protection Legislation

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Guernsey Data Protection Legislation

DATA PROTECTION

Wednesday, 8 October 2008Friday, 10 October 2008

Monday, 13 October 2008

An Overview of Data Protection Legislation in

Guernsey

Jon Barclay, Advocate

AO Hall Advocates

Page 2: Guernsey Data Protection Legislation

Background: The EC Directive

● Sets out uniform standards for good data handling practice.

● Implemented in UK by Data Protection Act 1998.

● Not binding on Guernsey, but implemented here for business reasons.

● The Data Protection (Bailiwick of Guernsey) Law, 2001 is modelled on the 1998 Act.

● European Commission Decision of 21 November 2003: Guernsey has “adequate” data protection.

Page 3: Guernsey Data Protection Legislation

Main Features -

● Notification Requirements for Data

Controllers

● Data Subject Rights

● Good Data Handling Practices

● Supervision and Enforcement Procedures

Guernsey’s Data Protection Law

Page 4: Guernsey Data Protection Legislation

Definitions

● “Data” – information stored or processed electronically,

or manually if stored on a “relevant filing system”.

● “Relevant Filing System” – a set of information which

is structured, either by reference to individuals or by

reference to criteria related to individuals, in such a way that

specific information relating to a particular individual is

readily accessible.

Page 5: Guernsey Data Protection Legislation

Definitions continued…

● “Personal Data” – must relate to a living individual

who can be identified from those data or from those

data and other information which is in possession of the

data controller.

● “Data Controller” – a person who determines the

manner in which personal data is processed.

● “Data Processor” – any person other than an

employee who holds data on behalf of the data controller.

Page 6: Guernsey Data Protection Legislation

Definitions continued…

● “Data Subject” – a living individual who is the subject

of personal data.

● “Processing” – obtaining, recording or holding the data

or information and carrying out any operation in relation to it.

● “Sensitive Personal Data” – personal data which

consists of information about the subject’s racial or ethnic

origin, political opinions, religious beliefs, trade union affiliation,

physical or mental health, sex life, criminal activities or

criminal record.

Page 7: Guernsey Data Protection Legislation

Scope

● All data controllers in the Bailiwick.

● All personal data.

● Foreign controllers who process data here.

● Focus on privacy.

● There is no Freedom of Information legislation in Guernsey.

Page 8: Guernsey Data Protection Legislation

Personal Data

● Email and other addresses

● Telephone subscriber details

● Credit record

● Banking details

● Employment references

● Criminal convictions

● Biometric data

● Medical data

● CCTV footage

● Records of personal telephone calls

● Recorded expressions of personal opinion

● etc

Page 9: Guernsey Data Protection Legislation

Notification Requirement

● Annual notification unless exempt

● Public register

● Transparency and openness

Page 10: Guernsey Data Protection Legislation

Notification Details

● Contact details

● General purposes of processing

● Types of data subject

● Types of data

● Potential recipients

● Other jurisdictions

● Security measures

Page 11: Guernsey Data Protection Legislation

Useful addresses

• www.dpr.gov.gg

• www.gov.gg

Page 12: Guernsey Data Protection Legislation

Data Subject Rights

● Subject access

● Rectification, blocking, erasure and destruction

● To prevent processing likely to cause distress

● To prevent processing for direct marketing

purposes

● Compensation

● Automated decision-making

● Request for an assessment

Page 13: Guernsey Data Protection Legislation

Subject Access Requests

Individuals are entitled to request a data controller to provide

them with -

● a description of any data which is being processed by

reference to them

● a description of the purposes for which it is being

processed

● a description of any potential recipients of the data

● information as to the source of the data

Page 14: Guernsey Data Protection Legislation

Exemptions

● Public Security

● Investigation of Crime

● Regulatory Activity

● etc

Page 15: Guernsey Data Protection Legislation

Conflict of Subject Rights and Controller Duties

• STRs

• Third party privacy

• etc

Page 16: Guernsey Data Protection Legislation

Automated Decision Making

• Significant?

Page 17: Guernsey Data Protection Legislation

Objections to Data Processing

• Damage or distress

• Direct Marketing – Preference Services

Page 18: Guernsey Data Protection Legislation

Other Rights

• Rectification, blocking, erasure and destruction

• Compensation

• Assessments

Page 19: Guernsey Data Protection Legislation

Data controllers: duty to follow good data handling practices

• All data controllers must observe the Data Protection Principles

• Even if exempt from notification

Page 20: Guernsey Data Protection Legislation

The Data Protection Principles

Personal data must be :

1. processed fairly and lawfully

2. obtained for specified and lawful purposes only

3. adequate, relevant and not excessive

4. accurate and kept up to date

5. kept for no longer than is necessary

6. processed in accordance with the rights of data subjects

7. kept secure

8. transferred to third countries only if they ensure an adequate level of data protection

Page 21: Guernsey Data Protection Legislation

First and Second Principles: “Lawful”?

● Breach of Privacy

● Hacking

● Breach of Confidentiality

● Rehabilitation of Offenders

● Theft

● Obtaining by Deception (“Blagging”)

● Unlawful Interception of Communications

Page 22: Guernsey Data Protection Legislation

First and Second Principles: “Fair”?

Consider:

● The method by which the data was obtained

● Statutory authority or requirement

● Informed consent

Also:

● Is a Schedule 2 condition met?

● Sensitive personal data: Is a Schedule 3

condition met?

Page 23: Guernsey Data Protection Legislation

Quality Standards

Third Principle: relevant, adequate and not

excessive.

Fourth Principle: accurate and kept up to

date.

Fifth Principle: kept for no longer than is

necessary.

Page 24: Guernsey Data Protection Legislation

Sixth Principle: Data Subject Rights

● Subject access rights

● Privacy

● Security

Page 25: Guernsey Data Protection Legislation

Seventh Principle: Security

Security Measures –

● Passwords (which should be changed regularly)

● Careful location of computer screens

● Procedures to verify caller identity

● Clear, written data protection procedures

● Making breach of data protection procedures a disciplinary

offence

● Use of encryption

● Other technical and operational measures

Page 26: Guernsey Data Protection Legislation

Eighth Principle: Data export

• EEA• “Adequate” Countries• Elsewhere

•Data Transfer Agreements•Model Clauses

Page 27: Guernsey Data Protection Legislation

Enforcement Authorities

•The Commissioner•The Police•The Courts

Page 28: Guernsey Data Protection Legislation

The Data Protection Commissioner

● Role

● Enforcement Powers

● Requests for Assessment

Page 29: Guernsey Data Protection Legislation

Offences

• Failure to notify• Unauthorised disclosure, selling or obtaining• Failure to comply with a notice• Blagging• Unsolicited communications• Enforced SARs

Page 30: Guernsey Data Protection Legislation

The Commissioner’s Role

• Promote good information handling practices• Encourage respect for privacy• Enforce the legislation• Inform and direct policy

Page 31: Guernsey Data Protection Legislation

The Commissioner’s Powers

• Limited• Enforcement notices• Encouragement and Education rather than

coersion

Page 32: Guernsey Data Protection Legislation

Requests for Assessment

• Unverified• Verified• Enforcement Notices• Information Notices and Warrants

Page 33: Guernsey Data Protection Legislation

An Overview of Data Protection Legislation in

Guernsey

Jon Barclay, Advocate

AO Hall Advocates

DATA PROTECTION

Wednesday, 8 October 2008Friday, 10 October 2008

Monday, 13 October 2008