Friday, 20 March 2009

Frequently asked questions relating to transfers of personal data from the EU/EEA to third countries

The Data Protection Unit of the Directorate-General for Justice, Freedom and Security at the European Commission has published aswers to FAQs with a view to assisting EU/EEA entities, and more particularly SMEs, in understanding the EU legal framework applicable to transfers of personal data processed in the EU (and the EEA) to “third countries” (i.e. countries that are not members of the EU or the EEA).
Download the document here: http://ec.europa.eu/justice_home/fsj/privacy/docs/international_transfers_faq/international_transfers_faq.pdf

Tuesday, 17 March 2009

EDPS second Opinion on ePrivacy Directive review and security breach

On 9 January, the EDPS adopted an Opinion on the review of the Directive on Privacy and electronic communications ("ePrivacy Directive"). This Opinion follows upon a first EDPS Opinion (pdf), as well as Comments (pdf), in which recommendations were made to help ensure that the proposed changes effectively provide for the best possible protection of personal data.
This Second Opinion comes as a response to the Council's Common Position which, on a number of critical points, fails to endorse some of the data protection safeguards proposed by the European Parliament and the European Commission, or previously recommended by the EDPS.

The Opinion particularly focuses on the provisions relating to the setting up of a mandatory security breach notification system for which the Supervisor believes there is still some room for improvement. It also includes a number of recommendations covering the following issues:
scope of application : the EDPS supports the Parliament's approach to broaden the scope of application of the Directive to include publicly accessible private networks in the Community. He recommends to further clarify the types of services that would be covered by the broadened scope; processing of traffic data for security purposes : the EDPS considers the new article introduced by the Parliament - and maintained by the Council's Common Position and the Commission's Amended Proposal - legitimising the collection of traffic data for security purpose as being unnecessary. In the EDPS view, such a provision may be subject to risk of abuse, especially if adopted in a form that does not include the necessary data protection safeguards;
right of action against infringements to the Directive : the EDPS calls upon the Commission and the Council to endorse the provision introduced by the Parliament that gives the possibility to legal entities, such as consumer associations, to bring legal action against infringements of any provisions of the Directive.

> EDPS Opinion (pdf)

New mandate for the EDPS: Peter Hustinx reappointed as Supervisor, Giovanni Buttarelli appointed as Assistant Supervisor

In December 2008, The European Parliament and the Council have agreed to reappoint Peter Hustinx as European Data Protection Supervisor (EDPS) for a second term of office. They have also appointed Giovanni Buttarelli as Assistant Supervisor for the same five-year term. He replaces Joaquin Bayo Delgado who decided not to run for a second mandate.

The new EDPS and Assistant EDPS formally took office on 17 January 2009.

Peter Hustinx has served as EDPS since January 2004, contributing to the building of the new supervisory authority and developing its role at Community level. Information on Peter Hustinx's background is available on the EDPS website.

Giovanni Buttarelli has been a member of the Italian judiciary since 1986, and Secretary General of the Italian Data Protection Authority since 1997. In 2002-2003, he served as President of the Joint Supervisory Authority set up in pursuance of the Schengen Agreement, after being its Vice-President in 2000-2001. He has represented Italy in many committees and working groups operating in the field of data protection, both at the level of the European Union (EU) and at the Council of Europe.

> EDPS press release (pdf)

Wednesday, 25 February 2009

Strong opposition to UK data sharing clause

The UK government is facing strong opposition to the clause in a draft Bill currently being debated in Parliament that removes barriers to data sharing between government departments to support improved public services. Justice Secretary Jack Straw is being called upon to remove the 'information sharing orders', aka clause 152, from the Coroners and Justice Bill. The British Medical Association has said that the whole profession is concerned for doctor/patient confidentiality, because the clause allows information obtained for one purpose to be used for another, with limited justification. Opposition also comes from such weighty quarters as Liberty, GeneWatch UK, Patient Concern, the Royal College of Psychiatrists, and the British Computer Society. Further, the Information Commissioner wants 'much stronger safeguards' in the bill to protect sensitive data, particularly health records. He has made a number of criticisms in an updated commentary on the Coroners and Justice Bill (outlined in Volume 9, Issue 4 of Privacy & Data Protection.) A copy of the ICO's commentary is available from the ICO's website.

Source: PDP Data Protection News

Tuesday, 24 February 2009

Call for Comment: ARMA International's Generally Accepted Recordkeeping Principles

ARMA International’s Board of Directors has approved a set of generally accepted recordkeeping principles (GARP) for member and public comment. These principles will serve as a framework for guidance in implementing information management programs. The defined set of principles will help business leaders, legislators, the judiciary, and other stakeholders understand and adress the key components of records and information management as a discipline and as a best business practice.

You can view and comment on the proposed principles at www.arma.org/GARP. Please use the e-mail address at the bottom of each page (garp@arma.org) for any comments regarding the supporting principle narratives. The comment period for GARP will end on Friday, March 6.
On behalf of ARMA International and the profession, thank you in advance for your participation in this exciting endeavor.

Thursday, 19 February 2009

Offer to ARMA Members: Discounted Rate on RMS Conference

ARMA is pleased to announce that it is supporting the annual conference of the Record Management society of Great Britain which will take place on 19-21 April in Brighton (UK). As a result, ARMA members are able to register at the same rates as RMS members:


For more information on the conference and the conference programme, please visit http://www.rms-gb.org.uk/conference.To book, please visit http://www.rms-gb.org.uk/conference-delegates-2009, select the member rate and mention the word 'ARMA' when asked for a membership number on the booking form (only the word not the quotes). ARMA will also be present at the exhibition with a booth.

Wednesday, 18 February 2009

EU Data protection group publishes pre-trial discovery guidance

The Article 29 Working Party, an EU data protection watchdog, has published a guidance document on pre-trial discovery for cross border civil litigation.

This working document provides guidance to data controllers subject to EU Law in dealing
with requests to transfer personal data to another jurisdiction for use in civil litigation. The
Working Party has issued this document to address its concern that there are different applications of Directive 95/46 (Data Protection Directive) in part as a result of the variety of approaches to civil litigation across the Member States.

In the first section of this document the Working Party briefly sets out the differences in
attitudes to litigation and in particular the pre-trial discovery process between common law
jurisdictions such as the United States and the United Kingdom and civil code jurisdictions.

The document goes on to set out guidelines for EU data controllers when trying to reconcile the demands of the litigation process in a foreign jurisdiction with the data protection obligations of Directive 95/46.

Download the full document here: http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2009/wp158_en.pdf