SlideShare ist ein Scribd-Unternehmen logo
1 von 39
2nd of April 2014
CMS CEE Data Protection Webinar series
PART 2
Digital Legal Guardians
2nd of April 2014
Your
presenters
today
Hungary
Dóra Petrányi
Hungary
Márton Domokos
Poland
Marcin Lewoszewski
Romania
Marius Petroiu
Russia
Elena Baryshnikova
Ukraine
Nataliya
Nakonechna
Ukraine
Olga Belyakova
Poland
Russia
Countries covered
Ukraine
Bulgaria
Romania
Hungary
Slovakia
Czech
Republic
2nd of April 2014
Agenda
- Demystifying Big Data
- Cookie Compliance
- Rules on security breach
- Workplace Privacy
- The New EU Data Protection Regulation
- Check List
Cyber criminals hack smart fridge to
send out spam
Internet of Things will
impact law
”Big Data” gets bigger Big data, big legal trouble?
Complex & extensive
cloud computing
Targeting the
$100 Billion Cloud Market
Mobile content revolution
App Generation will lead to
$77bn in revenues by 2017
Wearable technologies
How Google Glass Is Redefining
Tech Etiquette
e-health
Oral B's smart toothbrush lets
dentists spy on your brushing
Introduction
Trends in privacy and the risk landscape
Microsoft Working On New Tracking
Technology To Replace Cookies
More personal advertising
Finalisation of the EU
Regulation
Reding: „Full Speed on EU Data
Protection Reform 2014”
Strong push on compliance
(whitleblowing)
New Whistleblowing Law Generates
New Data Privacy Issues in Hungary
Fines, recovery costs and
reputation
Facebook-WhatsApp Risks
Sparking Privacy Probes
Tarns-Atlantic tensions
EU data protection reform could
start 'trade war'
Introduction
Trends in privacy and the risk landscape
Demystifying Big Data
Source: IBM official website
Demystifying Big Data (1) “The next big thing”
− BIG = source, speed, volume - advanced algorithms
− New sources (e.g., web data, tweets, social media, email, text
messages, instant messages, chat)
− Unanticipated insights and low storage cost
− To revolutionize business, science, research and education
Legal guidance how to demonstrate legitimacy…
Fraud prevention Network security
Exploring consumer
expectations
Energy efficiency
Demystifying Big Data (2) Data privacy issues
Accountability
Does it require consent?
Any error in
the process?
Data security
measures?
How to minimise the data collection?
Legitimate data
processing purpose?
Prohibited decisions?
Demystifying Big Data (3) „Regulatory changes may
require recalibration” Big Data issues in our practice
1. Personalized recommendations, targeted marketing and other services to
identifiable users or mobile devices.
2. What is “personal data”? e.g. anonymous data, health, location
3. What shall the privacy notice contain?
4. What about reminders?
5. Get explicit opt-in or rely on implied consent?
6. Opt-out options?
7. Permitted combination of information?
8. No personalized services but still collecting data to improve algorithms?
Monitoring procedures relation Big Data projects
Cookie Compliance
Directive 2002/58/EC on Privacy
and Electronic Communications
WD 02/2013 Providing Guidance
on Obtaining Consent for Cookies
Opinion 04/2012 on Cookie
Consent Exemption
Opinion 2/2010 on Online
Behavioural Advertising
„The use of e-communications
networks to store information or
to gain access to information
stored in the terminal
equipment of a subscriber or
user is only allowed on
condition that the subscriber or
user concerned is provided
with clear and comprehensive
information.” (Article 5 (3))
Cookie Compliance (1)
Form Information
Exemptions? Term
Consent
Cookie Compliance (2)
Cookie Compliance (3) Verification of internal
practice
− Types of cookies?
− Purpose and technology?
− Personal data processing? How long?
− Further processing (pl.: combination of data)?
− Data transfer (third party cookies)?
− Is it necessary to obtain prior, informed consent?
− Data privacy notice?
− Separate policy + link, format, positioning?
− Third party agreements? (advertisement)
− Data Protection Registry?
− Handling users’ requests?
Poland: Russia: Romania: Ukraine:
Opt-in
Non specific guidance
DPA: brief privacy
information on cookie
placement is sufficient
No specific regulation
Companies place the
cookie policies on their
websites to protect
their interests
DPA: official position
is not present
Opt in: No specific
guidance. DPA: brief
privacy information
on cookie placement
is sufficient
No specific regulation
DPA:
- user’s consent on
processing of his personal
data using ‘cookies’
- clear privacy statement
with reference to detailed
privacy policy
Cookie Compliance (4) CEE Overview
Hungary: Slovakia: Bulgaria: Czech Republic:
Opt-in
Non specific guidance
DPA: brief privacy
information on cookie
placement is sufficient
Opt-in (the setting of
the internet browser
allowing cookies is
considered as previous
consent)
Brief privacy
information on cookie
placement is sufficient
No specific
regulation re
cookies
Failure to fully implement
opt-in scheme
Arguable if cookies are
considered as personal
data or not
Rules on security breach
17
Security Breach Notifications
Hungary Czech
Republic
Slovakia Bulgaria
Sector? Telcos only Telcos only Telcos only
Providers of publicly
available electronic
communications services
Specific
rules?
In line with Regulation
611/2013/EU
In line with Regulation
611/2013/EU.
In line with
Regulation
611/2013/EU
Electronic Communications
Act (notification to the Data
Protection Authority within 3
days vs 24 hours in the
Regulation 611/2013/EU)
Poland Romania Ukraine Russia
Sector?
Telcos only
Providers of Telco services N/A
N/A
Specific
rules?
In line with Regulation
611/2013/EU
Law 506/2004 on
processing personal data in
the Telco field
N/A
Amendments to the Data
Protection Law providing
that data processors must
inform DPA on breaches are
being prepared now.
Workplace privacy
Workplace privacy
“Hot” data privacy topics (2)
− Russia
− Issue: Monitoring of private
correspondence on corporate
devices possible?
− Internal policies and notifications
on the monitoring to be signed by
employees
− Russia
− Issue: Monitoring of private
correspondence on corporate
devices possible?
− Internal policies and notifications
on the monitoring to be signed by
employees
Romania
− Interviews / background checks:
scope needs to be limited:
reasonable & necessary
− New DPA rules on CCTV
− Criminal Code: correspondence
secrecy
Romania
− Interviews / background checks:
scope needs to be limited:
reasonable & necessary
− New DPA rules on CCTV
− Criminal Code: correspondence
secrecy
Ukraine
− No specific regulation.
− CCTV and access to corporate e-
mail account require employee’s
consent
Ukraine
− No specific regulation.
− CCTV and access to corporate e-
mail account require employee’s
consent
Hungary
− Labour Code permits monitoring and
transfer to processors
− Updated employee privacy notices
− New rules on CCTV use
− DPA fine re employee laptop access
− New whistleblowing law
Hungary
− Labour Code permits monitoring and
transfer to processors
− Updated employee privacy notices
− New rules on CCTV use
− DPA fine re employee laptop access
− New whistleblowing law
Workplace privacy
“Hot” data privacy topics
Slovakia
− Emails or phone calls employees to
be informed of the extent of control
methods, implementation and
duration in advance.
− Discussion with the employees´
representative
Slovakia
− Emails or phone calls employees to
be informed of the extent of control
methods, implementation and
duration in advance.
− Discussion with the employees´
representative
Bulgaria
− Amendment on Labour Code
dated 2011 allow video
surveillance for monitoring work
process and observing working
time. Employees shall provide
their explicit consent!
Bulgaria
− Amendment on Labour Code
dated 2011 allow video
surveillance for monitoring work
process and observing working
time. Employees shall provide
their explicit consent!
− Czech Republic
− New case law on monitoring:
strengthening the position of
employers re breach of work
duties; stressing the duty of
loyalty of employees.
− Monitoring must not be excessive.
− Czech Republic
− New case law on monitoring:
strengthening the position of
employers re breach of work
duties; stressing the duty of
loyalty of employees.
− Monitoring must not be excessive.
Poland
− No specific regulation
− Good practice: information to
employees about monitoring
and its extent
Poland
− No specific regulation
− Good practice: information to
employees about monitoring
and its extent
Workplace privacy “Hot” data privacy topics:
Bring Your Own Device (BYOD) (1)
− Personal devices used for employment / professional purposes vs.
company devices
− Private and corporate data are accessed with one device
− Employer expects control over the data and the device
− Control = remote access + administration rights (mobile device
management’ security updates, lock access, data removal)
− Best practice:
• BYOD guidelines / update of existing policies (acceptable use, device
management) + training
• Separating corporate and private data + alternatives (virtual
solutions)
• ICO Guidance
Revise / review BYOD policies and watch out for regulatory developments
Workplace privacy “Hot” data privacy topics:
Bring Your Own Device (BYOD) (2)
Hungary Czech
Republic
Romania Ukraine
Consent? No Yes No Yes
Privacy notice? Yes Yes
Internal rules regulate
issues e.g. privacy,
security
Yes
Works council
involvement?
Yes No
Iimplemented in
consultation with
employees’
representatives
No
Poland Slovakia Bulgaria Russia
Consent? Yes Yes No N/A
Privacy notice? Yes Yes Yes N/A
Works Council
Involvement?
No No No
Internal rules on
privacy and security
may cover such use
Workplace privacy
“Hot” data privacy topics:
Whistleblowing (1) – best practices
Whistleblowing
Data privacy information
No encouragement of anonymity
Data transfer to advisors
Data transfer outside the EEA
Protection of whistleblowers’ identity
Accounting and auditing + related matters
Limited data collection and retention (2 months)
Rights of the incriminated
Notification to / approval by the DPA?
Consequences of misuse
24
Workplace privacy
“Hot” data privacy topics:
Whistleblowing (2)
– local requirements
Is there a specific
law on
whistleblowing
hotlines?
Act CLXV of 2013
on Complaints and
Public Interest
Disclosure
Proposed only for
the banking sector
(pending
parliament
procedure)
Only in the public
sector
(whistleblowing in
general)
NO
Is there a specific
regulatory
guidance on
whistleblowing
hotlines?
NO NO NO NO
Notification to /
approval by the
DPA?
YES
In non-regulated
sectors
YES NO
Hungary Czech Republic Romania Ukraine
Workplace privacy
“Hot” data privacy topics:
Whistleblowing (3)
– local requirements
Is there a specific
law on
whistleblowing
hotlines?
NO NO NO
NO
Is there a specific
regulatory
guidance on
whistleblowing
hotlines?
NO NO NO NO
Notification to /
approval by the
DPA?
Yes (notification) YES NO YES
Poland Slovakia Bulgaria Russia
26
Workplace privacy
“Hot” data privacy topics:
Whistleblowing (4)
- new law in Hungary
− Translation and publication of the internal rules
− Registration with the DPA
− Article 29 Working Party Opinion 1/2006
− Sensitive data shall not be processed
− Enhance permitted data transfers
− Outside the EEA: data transfer agreement + ‘adequate protection’
− Specific deadlines for the investigation and data retention
− Mandatory notifications to whistleblowers and the reported
− Mandatory notification to criminal authorities
Verify the operation of whistleblowing and watch out for regulatory developments
Workplace privacy
“Hot” data privacy topics:
Whistleblowing (5)
- new law in Hungary
Act CLXV of 2013 on Complaints and Public Interest Disclosures
Translation and publication of the
internal rules
Registration with the DPA
Sensitive data shall not be
processed
Works’ council consultation
Mandatory notification to criminal
authorities
Outside the EEA: data transfer
agreement + ‘adequate protection’
Specific deadlines for the
investigation and data retention
Enhances permitted data transfers
The Draft
EU Data Protection Regulation
The draft
EU Data Protection Regulation (1)
Status and next steps
March 2014
June 2013
October
2013
Trilogue
negotiations
November
2013
December
2013
January
2014
European Parliament's formal approval
NSA mass surveillance
activities: ”reforms vital to counter PRISM data access” (Reding)
„breakthrough”: EU LIBE compromise package
EC, Council and Euro MPs
EC calls for Safe Harbor reforms
Justice Ministers failed to agree on one-stop-shop:
”leading lawyers have public catfight”
EDPS calls Germany to take the lead in negotiating
New deadline: end of 2014
The draft
EU Data Protection Regulation (2)
− 18 months of ”intense negotiations and fierce
lobbying” - across sectors, B2B, B2C, 100 pages,
4,000 amendments
− Specific rules are not clear: further interpretation,
guidance, industry-specific measures (is it really a
Regulation?)
− Extra-territorial effect may cause trans-Atlantic tensions
− Likely to revolutionize and reshape privacy
− Direct effect
− ”data protection” or ”data protectionism”?
The draft
EU Data Protection Regulation (3)
− One-stop-shop: instead of regulatory patchwork of 28
countries, will make the life of company groups easier
BUT: what is the ”main establishment”? competence of
local DPAs will also remain
- More consumer rights & DPA Power: Fine up to EUR 100
million 5% of yearly worldwide turnover)
− Less administration: no more Data Protection Registry
BUT consultation obligation
− Explicit consent: Not required: contracting, compliance, legitimate
interests
BUT: ”significant imbalance” test
The draft
EU Data Protection Regulation (4)
− Profiling: only upon consent/contract; prohibited: only upon
sensitive data - may affect Big Data
- Data transfers outside the EU: More practical (e.g.: „Binding
Corporate Rules”, „European Data Protection Seal”), BUT
restricts ”frequent or massive” transfers + regulatory
requests.
− Data Protection Officer: mandatory: for companies processing
data more than 5,000 individuals/year; independent, 2-4
years
− Privacy Notices: More detailed than now + standardised
format using icons
The
draft
EU Data Protection
Regulation (5)
The draft
EU Data Protection Regulation (6)
adopt policies, implement measures, keep extensive
documentation, data security requirements, perform
privacy impact assessments, comply with prior
authorisation / consultation by DPA, designate a Data
Protection Officer, bi-annual update of policies
Risk assessment: e.g. data amount type,
automatics, industry (e-health!)
”to the entire lifecycle management of data”
bi-annual update
Accountability
Data privacy impact
assessment
The draft
EU Data Protection Regulation (7)
data, copy, link
Independently from the formatData Portability
Right to erasure
Data breach
notification
in all industries – to regulator: immediately; to
customers: only in serious cases
Documentation + database
Privacy By Design Privacy by Design / Default
Checklist (1)
(* - also to comply with DP Regulation)
− ”Data discovery” – reviewing the scope of data collected.
− Transparent / accessible policies and governance framework.*
− Documentation of data flows and processes.*
− Drafting / reviewing agreements, consents, NDAs and
confidentiality provisions re data processing and data transfer.
− Revise / review DPA notifications.
− ”Traditional” outsourcing. Make sure you are compliant with
”traditional” issues and watch out for the new trends and new
issues…
− New models of outsourcing – the Cloud. Watch out for regulatory
developments and the expectations in case of contracting.
Checklist (2)
- Big Data - watch out for regulatory developments and the
expectations in case of contracting.
- Ensure compliance in „usual” workplace privacy topics.
- Revise / review BYOD and social media policies.
- Verify whistleblowing hotlines, especially in Hungary.
- Reviewing access rights procedures.
- Data breach notifications: implementing internal rules.
- Data portability: identify security issues re transmission / access.
Any questions? Would like to know more?
Contact us!
Dóra Petrányi - Hungary
CEE Data Protection Lead Partner
dora.petranyi@cms-cmck.com
+36 1 483 4820
Márton Domokos – Hungary
marton.domokos@cms-cmck.com
+36 1 483 4824
Marcin Lewoszewski – Poland
marcin.lewoszewski@cms-cmck.com
+48 22 520 5525
Marius Petroiu – Romania
marius.petroiu@cms-cmck.com
+40 21 407 3 889
Elena Baryshnikova - Russia
elena.baryshnikova@cmslegal.ru
+7 495 786 40 99
Nataliya Nakonechna – Ukraine
nataliya.nakonechna@cms-cmck.com
+380 44 391 7 729
Olga Belyakova – Ukranie
olga.belyakova@cms-cmck.com
+380 44 391 7 727
Thank you for your attention!
Please complete our feedback box that opens automatically when this
presentation closes.
You can download our CMS CEE Guide to Data Protection
& webinar materials from our website
www.cms-cmck.com

Weitere ähnliche Inhalte

Was ist angesagt?

Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORIKarel Holst
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoKeithBudden3
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIKarel Holst
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)Nordic APIs
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015Rachel Aldighieri
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
GIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataGIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataIAB Europe
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)Napier University
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 

Was ist angesagt? (20)

Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
Gdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seoGdpr brexit presentation for brighton seo
Gdpr brexit presentation for brighton seo
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
Legal update - Leeds
Legal update - LeedsLegal update - Leeds
Legal update - Leeds
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)New General Data Protection Regulation (Agnes Andersson Hammarstrand)
New General Data Protection Regulation (Agnes Andersson Hammarstrand)
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...Using Social Business Software and being compliant with EU data protection la...
Using Social Business Software and being compliant with EU data protection la...
 
An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015An introduction to data protection - 2/09/2015
An introduction to data protection - 2/09/2015
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
GIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataGIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal Data
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
ILP Durham webinar: GDPR in the Lighting Industry
ILP Durham webinar: GDPR in the Lighting IndustryILP Durham webinar: GDPR in the Lighting Industry
ILP Durham webinar: GDPR in the Lighting Industry
 
Case by case - moving data centres to Romania
Case by case - moving data centres to RomaniaCase by case - moving data centres to Romania
Case by case - moving data centres to Romania
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 

Ähnlich wie CEE CMS Data Protection webinar series - Part 2

Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data OpportunityiCrossing
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Lumension
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowSymantec
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013
Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013
Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013Blake Morgan
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014 Rachel Aldighieri
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...Symantec
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationJoseph V. Moreno
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPiwik PRO
 
Presentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissiePresentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissieEuropadialoog
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberRachel Aldighieri
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European unionRohana K Amarakoon
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-finalDr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberRachel Aldighieri
 
Wsgr eu data protection briefing march 20 2013 - final
Wsgr   eu data protection briefing march 20 2013 - finalWsgr   eu data protection briefing march 20 2013 - final
Wsgr eu data protection briefing march 20 2013 - finalValentin Korobkov
 
20131009 aon security breach legislation
20131009 aon security breach legislation20131009 aon security breach legislation
20131009 aon security breach legislationJos Dumortier
 
Draft data protection regn 2012
Draft data protection regn 2012Draft data protection regn 2012
Draft data protection regn 2012lilianedwards
 
Impact of GDPR on the pre dominant business model for digital economies
Impact of GDPR on the pre dominant business model for digital economiesImpact of GDPR on the pre dominant business model for digital economies
Impact of GDPR on the pre dominant business model for digital economiesEquiGov Institute
 
Data security and cyber risks - In house lawyers forum 2013, Richard Nicholas
Data security and cyber risks - In house lawyers forum 2013, Richard NicholasData security and cyber risks - In house lawyers forum 2013, Richard Nicholas
Data security and cyber risks - In house lawyers forum 2013, Richard NicholasBrowne Jacobson LLP
 

Ähnlich wie CEE CMS Data Protection webinar series - Part 2 (20)

Your Big Data Opportunity
Your Big Data OpportunityYour Big Data Opportunity
Your Big Data Opportunity
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
The Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t knowThe Evolution of Data Privacy: 3 things you didn’t know
The Evolution of Data Privacy: 3 things you didn’t know
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013
Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013
Blake Lapthorn's In-House Lawyer and Decision Maker's forum - 12 September 2013
 
The dma legal update summer 2014
The dma legal update summer 2014 The dma legal update summer 2014
The dma legal update summer 2014
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
Privacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital SetupPrivacy Regulations and Your Digital Setup
Privacy Regulations and Your Digital Setup
 
Presentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese CommissiePresentatie Giorgos Rossides, Europese Commissie
Presentatie Giorgos Rossides, Europese Commissie
 
DMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 OctoberDMA Legal update: autumn 2013 - Tuesday 1 October
DMA Legal update: autumn 2013 - Tuesday 1 October
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
DMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 decemberDMA Legal update winter 2013 - 17 december
DMA Legal update winter 2013 - 17 december
 
Wsgr eu data protection briefing march 20 2013 - final
Wsgr   eu data protection briefing march 20 2013 - finalWsgr   eu data protection briefing march 20 2013 - final
Wsgr eu data protection briefing march 20 2013 - final
 
20131009 aon security breach legislation
20131009 aon security breach legislation20131009 aon security breach legislation
20131009 aon security breach legislation
 
Draft data protection regn 2012
Draft data protection regn 2012Draft data protection regn 2012
Draft data protection regn 2012
 
Impact of GDPR on the pre dominant business model for digital economies
Impact of GDPR on the pre dominant business model for digital economiesImpact of GDPR on the pre dominant business model for digital economies
Impact of GDPR on the pre dominant business model for digital economies
 
Data security and cyber risks - In house lawyers forum 2013, Richard Nicholas
Data security and cyber risks - In house lawyers forum 2013, Richard NicholasData security and cyber risks - In house lawyers forum 2013, Richard Nicholas
Data security and cyber risks - In house lawyers forum 2013, Richard Nicholas
 

Kürzlich hochgeladen

Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 
INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxnyabatejosphat1
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书SS A
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书E LSS
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm2020000445musaib
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书Fir L
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书Sir Lt
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书Fir L
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书Fir L
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx2020000445musaib
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 

Kürzlich hochgeladen (20)

Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptx
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书如何办理澳洲南澳大学(UniSA)毕业证学位证书
如何办理澳洲南澳大学(UniSA)毕业证学位证书
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书 如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
如何办理(Michigan文凭证书)密歇根大学毕业证学位证书
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 

CEE CMS Data Protection webinar series - Part 2

  • 1. 2nd of April 2014 CMS CEE Data Protection Webinar series PART 2 Digital Legal Guardians
  • 2. 2nd of April 2014 Your presenters today Hungary Dóra Petrányi Hungary Márton Domokos Poland Marcin Lewoszewski Romania Marius Petroiu Russia Elena Baryshnikova Ukraine Nataliya Nakonechna Ukraine Olga Belyakova
  • 4. 2nd of April 2014 Agenda - Demystifying Big Data - Cookie Compliance - Rules on security breach - Workplace Privacy - The New EU Data Protection Regulation - Check List
  • 5. Cyber criminals hack smart fridge to send out spam Internet of Things will impact law ”Big Data” gets bigger Big data, big legal trouble? Complex & extensive cloud computing Targeting the $100 Billion Cloud Market Mobile content revolution App Generation will lead to $77bn in revenues by 2017 Wearable technologies How Google Glass Is Redefining Tech Etiquette e-health Oral B's smart toothbrush lets dentists spy on your brushing Introduction Trends in privacy and the risk landscape
  • 6. Microsoft Working On New Tracking Technology To Replace Cookies More personal advertising Finalisation of the EU Regulation Reding: „Full Speed on EU Data Protection Reform 2014” Strong push on compliance (whitleblowing) New Whistleblowing Law Generates New Data Privacy Issues in Hungary Fines, recovery costs and reputation Facebook-WhatsApp Risks Sparking Privacy Probes Tarns-Atlantic tensions EU data protection reform could start 'trade war' Introduction Trends in privacy and the risk landscape
  • 7. Demystifying Big Data Source: IBM official website
  • 8. Demystifying Big Data (1) “The next big thing” − BIG = source, speed, volume - advanced algorithms − New sources (e.g., web data, tweets, social media, email, text messages, instant messages, chat) − Unanticipated insights and low storage cost − To revolutionize business, science, research and education Legal guidance how to demonstrate legitimacy… Fraud prevention Network security Exploring consumer expectations Energy efficiency
  • 9. Demystifying Big Data (2) Data privacy issues Accountability Does it require consent? Any error in the process? Data security measures? How to minimise the data collection? Legitimate data processing purpose? Prohibited decisions?
  • 10. Demystifying Big Data (3) „Regulatory changes may require recalibration” Big Data issues in our practice 1. Personalized recommendations, targeted marketing and other services to identifiable users or mobile devices. 2. What is “personal data”? e.g. anonymous data, health, location 3. What shall the privacy notice contain? 4. What about reminders? 5. Get explicit opt-in or rely on implied consent? 6. Opt-out options? 7. Permitted combination of information? 8. No personalized services but still collecting data to improve algorithms? Monitoring procedures relation Big Data projects
  • 12. Directive 2002/58/EC on Privacy and Electronic Communications WD 02/2013 Providing Guidance on Obtaining Consent for Cookies Opinion 04/2012 on Cookie Consent Exemption Opinion 2/2010 on Online Behavioural Advertising „The use of e-communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information.” (Article 5 (3)) Cookie Compliance (1)
  • 14. Cookie Compliance (3) Verification of internal practice − Types of cookies? − Purpose and technology? − Personal data processing? How long? − Further processing (pl.: combination of data)? − Data transfer (third party cookies)? − Is it necessary to obtain prior, informed consent? − Data privacy notice? − Separate policy + link, format, positioning? − Third party agreements? (advertisement) − Data Protection Registry? − Handling users’ requests?
  • 15. Poland: Russia: Romania: Ukraine: Opt-in Non specific guidance DPA: brief privacy information on cookie placement is sufficient No specific regulation Companies place the cookie policies on their websites to protect their interests DPA: official position is not present Opt in: No specific guidance. DPA: brief privacy information on cookie placement is sufficient No specific regulation DPA: - user’s consent on processing of his personal data using ‘cookies’ - clear privacy statement with reference to detailed privacy policy Cookie Compliance (4) CEE Overview Hungary: Slovakia: Bulgaria: Czech Republic: Opt-in Non specific guidance DPA: brief privacy information on cookie placement is sufficient Opt-in (the setting of the internet browser allowing cookies is considered as previous consent) Brief privacy information on cookie placement is sufficient No specific regulation re cookies Failure to fully implement opt-in scheme Arguable if cookies are considered as personal data or not
  • 17. 17 Security Breach Notifications Hungary Czech Republic Slovakia Bulgaria Sector? Telcos only Telcos only Telcos only Providers of publicly available electronic communications services Specific rules? In line with Regulation 611/2013/EU In line with Regulation 611/2013/EU. In line with Regulation 611/2013/EU Electronic Communications Act (notification to the Data Protection Authority within 3 days vs 24 hours in the Regulation 611/2013/EU) Poland Romania Ukraine Russia Sector? Telcos only Providers of Telco services N/A N/A Specific rules? In line with Regulation 611/2013/EU Law 506/2004 on processing personal data in the Telco field N/A Amendments to the Data Protection Law providing that data processors must inform DPA on breaches are being prepared now.
  • 19. Workplace privacy “Hot” data privacy topics (2) − Russia − Issue: Monitoring of private correspondence on corporate devices possible? − Internal policies and notifications on the monitoring to be signed by employees − Russia − Issue: Monitoring of private correspondence on corporate devices possible? − Internal policies and notifications on the monitoring to be signed by employees Romania − Interviews / background checks: scope needs to be limited: reasonable & necessary − New DPA rules on CCTV − Criminal Code: correspondence secrecy Romania − Interviews / background checks: scope needs to be limited: reasonable & necessary − New DPA rules on CCTV − Criminal Code: correspondence secrecy Ukraine − No specific regulation. − CCTV and access to corporate e- mail account require employee’s consent Ukraine − No specific regulation. − CCTV and access to corporate e- mail account require employee’s consent Hungary − Labour Code permits monitoring and transfer to processors − Updated employee privacy notices − New rules on CCTV use − DPA fine re employee laptop access − New whistleblowing law Hungary − Labour Code permits monitoring and transfer to processors − Updated employee privacy notices − New rules on CCTV use − DPA fine re employee laptop access − New whistleblowing law
  • 20. Workplace privacy “Hot” data privacy topics Slovakia − Emails or phone calls employees to be informed of the extent of control methods, implementation and duration in advance. − Discussion with the employees´ representative Slovakia − Emails or phone calls employees to be informed of the extent of control methods, implementation and duration in advance. − Discussion with the employees´ representative Bulgaria − Amendment on Labour Code dated 2011 allow video surveillance for monitoring work process and observing working time. Employees shall provide their explicit consent! Bulgaria − Amendment on Labour Code dated 2011 allow video surveillance for monitoring work process and observing working time. Employees shall provide their explicit consent! − Czech Republic − New case law on monitoring: strengthening the position of employers re breach of work duties; stressing the duty of loyalty of employees. − Monitoring must not be excessive. − Czech Republic − New case law on monitoring: strengthening the position of employers re breach of work duties; stressing the duty of loyalty of employees. − Monitoring must not be excessive. Poland − No specific regulation − Good practice: information to employees about monitoring and its extent Poland − No specific regulation − Good practice: information to employees about monitoring and its extent
  • 21. Workplace privacy “Hot” data privacy topics: Bring Your Own Device (BYOD) (1) − Personal devices used for employment / professional purposes vs. company devices − Private and corporate data are accessed with one device − Employer expects control over the data and the device − Control = remote access + administration rights (mobile device management’ security updates, lock access, data removal) − Best practice: • BYOD guidelines / update of existing policies (acceptable use, device management) + training • Separating corporate and private data + alternatives (virtual solutions) • ICO Guidance Revise / review BYOD policies and watch out for regulatory developments
  • 22. Workplace privacy “Hot” data privacy topics: Bring Your Own Device (BYOD) (2) Hungary Czech Republic Romania Ukraine Consent? No Yes No Yes Privacy notice? Yes Yes Internal rules regulate issues e.g. privacy, security Yes Works council involvement? Yes No Iimplemented in consultation with employees’ representatives No Poland Slovakia Bulgaria Russia Consent? Yes Yes No N/A Privacy notice? Yes Yes Yes N/A Works Council Involvement? No No No Internal rules on privacy and security may cover such use
  • 23. Workplace privacy “Hot” data privacy topics: Whistleblowing (1) – best practices Whistleblowing Data privacy information No encouragement of anonymity Data transfer to advisors Data transfer outside the EEA Protection of whistleblowers’ identity Accounting and auditing + related matters Limited data collection and retention (2 months) Rights of the incriminated Notification to / approval by the DPA? Consequences of misuse
  • 24. 24 Workplace privacy “Hot” data privacy topics: Whistleblowing (2) – local requirements Is there a specific law on whistleblowing hotlines? Act CLXV of 2013 on Complaints and Public Interest Disclosure Proposed only for the banking sector (pending parliament procedure) Only in the public sector (whistleblowing in general) NO Is there a specific regulatory guidance on whistleblowing hotlines? NO NO NO NO Notification to / approval by the DPA? YES In non-regulated sectors YES NO Hungary Czech Republic Romania Ukraine
  • 25. Workplace privacy “Hot” data privacy topics: Whistleblowing (3) – local requirements Is there a specific law on whistleblowing hotlines? NO NO NO NO Is there a specific regulatory guidance on whistleblowing hotlines? NO NO NO NO Notification to / approval by the DPA? Yes (notification) YES NO YES Poland Slovakia Bulgaria Russia
  • 26. 26 Workplace privacy “Hot” data privacy topics: Whistleblowing (4) - new law in Hungary − Translation and publication of the internal rules − Registration with the DPA − Article 29 Working Party Opinion 1/2006 − Sensitive data shall not be processed − Enhance permitted data transfers − Outside the EEA: data transfer agreement + ‘adequate protection’ − Specific deadlines for the investigation and data retention − Mandatory notifications to whistleblowers and the reported − Mandatory notification to criminal authorities Verify the operation of whistleblowing and watch out for regulatory developments
  • 27. Workplace privacy “Hot” data privacy topics: Whistleblowing (5) - new law in Hungary Act CLXV of 2013 on Complaints and Public Interest Disclosures Translation and publication of the internal rules Registration with the DPA Sensitive data shall not be processed Works’ council consultation Mandatory notification to criminal authorities Outside the EEA: data transfer agreement + ‘adequate protection’ Specific deadlines for the investigation and data retention Enhances permitted data transfers
  • 28. The Draft EU Data Protection Regulation
  • 29. The draft EU Data Protection Regulation (1) Status and next steps March 2014 June 2013 October 2013 Trilogue negotiations November 2013 December 2013 January 2014 European Parliament's formal approval NSA mass surveillance activities: ”reforms vital to counter PRISM data access” (Reding) „breakthrough”: EU LIBE compromise package EC, Council and Euro MPs EC calls for Safe Harbor reforms Justice Ministers failed to agree on one-stop-shop: ”leading lawyers have public catfight” EDPS calls Germany to take the lead in negotiating New deadline: end of 2014
  • 30. The draft EU Data Protection Regulation (2) − 18 months of ”intense negotiations and fierce lobbying” - across sectors, B2B, B2C, 100 pages, 4,000 amendments − Specific rules are not clear: further interpretation, guidance, industry-specific measures (is it really a Regulation?) − Extra-territorial effect may cause trans-Atlantic tensions − Likely to revolutionize and reshape privacy − Direct effect − ”data protection” or ”data protectionism”?
  • 31. The draft EU Data Protection Regulation (3) − One-stop-shop: instead of regulatory patchwork of 28 countries, will make the life of company groups easier BUT: what is the ”main establishment”? competence of local DPAs will also remain - More consumer rights & DPA Power: Fine up to EUR 100 million 5% of yearly worldwide turnover) − Less administration: no more Data Protection Registry BUT consultation obligation − Explicit consent: Not required: contracting, compliance, legitimate interests BUT: ”significant imbalance” test
  • 32. The draft EU Data Protection Regulation (4) − Profiling: only upon consent/contract; prohibited: only upon sensitive data - may affect Big Data - Data transfers outside the EU: More practical (e.g.: „Binding Corporate Rules”, „European Data Protection Seal”), BUT restricts ”frequent or massive” transfers + regulatory requests. − Data Protection Officer: mandatory: for companies processing data more than 5,000 individuals/year; independent, 2-4 years − Privacy Notices: More detailed than now + standardised format using icons
  • 34. The draft EU Data Protection Regulation (6) adopt policies, implement measures, keep extensive documentation, data security requirements, perform privacy impact assessments, comply with prior authorisation / consultation by DPA, designate a Data Protection Officer, bi-annual update of policies Risk assessment: e.g. data amount type, automatics, industry (e-health!) ”to the entire lifecycle management of data” bi-annual update Accountability Data privacy impact assessment
  • 35. The draft EU Data Protection Regulation (7) data, copy, link Independently from the formatData Portability Right to erasure Data breach notification in all industries – to regulator: immediately; to customers: only in serious cases Documentation + database Privacy By Design Privacy by Design / Default
  • 36. Checklist (1) (* - also to comply with DP Regulation) − ”Data discovery” – reviewing the scope of data collected. − Transparent / accessible policies and governance framework.* − Documentation of data flows and processes.* − Drafting / reviewing agreements, consents, NDAs and confidentiality provisions re data processing and data transfer. − Revise / review DPA notifications. − ”Traditional” outsourcing. Make sure you are compliant with ”traditional” issues and watch out for the new trends and new issues… − New models of outsourcing – the Cloud. Watch out for regulatory developments and the expectations in case of contracting.
  • 37. Checklist (2) - Big Data - watch out for regulatory developments and the expectations in case of contracting. - Ensure compliance in „usual” workplace privacy topics. - Revise / review BYOD and social media policies. - Verify whistleblowing hotlines, especially in Hungary. - Reviewing access rights procedures. - Data breach notifications: implementing internal rules. - Data portability: identify security issues re transmission / access.
  • 38. Any questions? Would like to know more? Contact us! Dóra Petrányi - Hungary CEE Data Protection Lead Partner dora.petranyi@cms-cmck.com +36 1 483 4820 Márton Domokos – Hungary marton.domokos@cms-cmck.com +36 1 483 4824 Marcin Lewoszewski – Poland marcin.lewoszewski@cms-cmck.com +48 22 520 5525 Marius Petroiu – Romania marius.petroiu@cms-cmck.com +40 21 407 3 889 Elena Baryshnikova - Russia elena.baryshnikova@cmslegal.ru +7 495 786 40 99 Nataliya Nakonechna – Ukraine nataliya.nakonechna@cms-cmck.com +380 44 391 7 729 Olga Belyakova – Ukranie olga.belyakova@cms-cmck.com +380 44 391 7 727
  • 39. Thank you for your attention! Please complete our feedback box that opens automatically when this presentation closes. You can download our CMS CEE Guide to Data Protection & webinar materials from our website www.cms-cmck.com