THE CNIL IN A NUTSHELL. Protect personal data Accompany innovations Preserve civil liberties.

Size: px
Start display at page:

Download "THE CNIL IN A NUTSHELL. Protect personal data Accompany innovations Preserve civil liberties."

Transcription

1 2017 THE CNIL IN A NUTSHELL Protect personal data Accompany innovations Preserve civil liberties

2 The CNIL in 2016 ADVISING AND REGULATING ADOPTED DECISIONS AND DELIBERATIONS OF WHICH: 190 AUTHORISATIONS 145 REQUESTS FOR AN OPINION The CNIL supports the development of new technologies on a daily basis and takes part in the construction of a digital ethic TRANSFER AUTHORISATIONS SIMPLIFIED FORMALITIES ACCOMPANYING COMPLIANCE FORMALITY FILES DECLARATIONS PROCESSED REGARDING VIDEO SURVEILLANCE SYSTEMS 97 PRIVACY SEALS DELIVERED 316 BIOMETRIC SYSTEM AUTHORISATIONS PROTECTING CITIZENS COMPLAINTS, OF WHICH: 33 % relate to prospecting 410 COMPLAINTS following the refusal of a request to be de-listed by search engines INVESTIGATING 430 INVESTIGATIONS 100 online investigations REQUESTS FOR ACCESS to police files, surveillance files, FICOBA, etc INSPECTIONS CARRIED OUT 94 INVESTIGATIONS REGARDING VIDEO SURVEILLANCE DECLARATIONS PROCESSED REGARDING GEOLOCATION DEVICES RENDERING ORDERS AND ISSUING SANCTIONS 82 ORDERS RENDERED THE CNIL WORKFORCE 195 JOBS 63 % female ORGANISATIONS HAVE APPOINTED A DATA PROTECTION OFFICER 13 SANCTIONS ISSUED: 9 WARNINGS 4 FINANCIAL SANCTIONS 37 % male

3 What is personal data? Personal data is any information relating to a natural person who may, directly or indirectly, potentially be identified by an identification number (i.e., social security number) or by one or more elements which are unique to that individual (i.e., first name and surname, date of birth, biometric elements, finger prints, DNA, etc.). STATUS & COMPOSITION AN INDEPENDANT ADMINISTRATIVE AUTHORITY Created in 1978, the CNIL is an independent administrative authority that exercises its functions in accordance with the French Data Protection Act dated 6th January 1978, amended on 6th August The CNIL s independence is guaranteed by its composition and its organisation. The eighteen members that form the commission are for the most part elected by the assemblies or jurisdictions to which they belong. The CNIL elects a Chair among its members and does not receive any instructions from any other authority. Isabelle Falque-Pierrotin, State council member, has been Chair of the CNIL since The CNIL s services are made up of 195 contract agents. 4 parliamentarians (2 assembly members, 2 senators). 2 members of the French Economic, Social and Environmental Council. 6 representatives of high jurisdictions (2 State council members, 2 members of the Court of cassation, 2 members of the Court of Audits). 5 qualified experts appointed by the President of the National Assembly (1 expert), the President of the Senate (1 expert), the French Cabinet (3 experts). The mandate of the commissioners is for 5 years, or, for parliamentarians, for an identical term to that of their mandate. The Chairman of the Freedom of Information Commission (CADA) (Commission d accès aux documents administratifs). FUNCTIONING PLENARY SESSIONS The members of the CNIL hold a plenary session once a week according to an agenda set by the Chair. A substantial part of these sessions is dedicated to the review of draft legislation and decrees submitted by the government for an official CNIL opinion. In addition, the CNIL also authorises highly sensitive processing operations, including those requiring the use of biometrics. It also analyses the consequences of new technologies on citizens private lives. RESTRICTED COMMITTEE The CNIL s restricted committee includes 5 members and a Chairman separate from the Chair of the CNIL. This committee can impose various sanctions on data controllers who do not respect the law. Financial sanctions can reach up to 3 million euros. These financial sanctions can be made public.

4 INFORMING, EDUCATING The CNIL has the general mission of informing individuals of the rights afforded to them by the French Data Protection Act. The CNIL responds to requests made by individuals and companies alike. In 2016, it received more than 166,500 phone calls. The CNIL leads communication campaigns which target the general public by means of either the press, its website, its presence on social networks or by providing learning resources. As well as being directly consulted by many organisations, companies or institutions for the purposes of conducting awareness campaigns and training programmes on the Data Protection Act, the CNIL also takes part in conferences, trade shows, and workshops in order to inform and be informed. It brings together a collective of over 60 organisations which run campaigns in favour of educating the public about digital technologies. PROTECTING CITIZENS RIGHTS Any individual can contact the CNIL upon experiencing difficulties in exercising their data protection rights. The CNIL ensures that citizens can effectively access their data contained in any processing operation. In 2016, the CNIL received 7,703 complaints regarding e-reputation (requests for the removal of internet content); commerce (objections to receiving marketing); human resources (supervision mechanisms: video surveillance, geo-location of vehicles); banks and loans (contesting their registration within the files of the Banque de France). Need help is available on cnil.fr This service offers 500 useful questions and answers as well as the opportunity to submit a request (over 12,000 requests received in 2016). WHAT ARE YOUR RIGHTS? The right of access You may ask the data controller directly if they possess information on you, and request that they disclose all of this data to you. The right to request rectification You may request the rectification of incorrect details about yourself. The right to request rectification complements the right of access. The right to object You may object to the filing of your data on legitimate grounds. You may also object to the distribution, transmission or storage of your data. The right to be de-listed You may request that a search engine de-list a website associated with your first name and surname. The right of access to Police files, surveillance files, FICOBA, etc. When it is not possible for you to request access to your data directly from the police, surveillance services or the tax authorities, the right of access is exercised indirectly through the CNIL.

5 Correspondant Informatique et Libertés ADVISING AND REGULATING Various tools are used to regulate personal data: authorisations for implementation of sensitive data processing, official opinions on the government s draft legislation involving data protection or the creation of new files, legal frameworks setting out good practices in certain domains, recommendations allowing the CNIL to justify its doctrine in different domains, requests for advice from data controllers, in increasing numbers, and notably through the medium of data protection officers. ACCOMPANYING COMPLIANCE The objective is to propose a compliance toolbox by using the different means of action at the CNIL s disposal: data protection officers (Correspondants Informatique et Libertés) who form the authoritative network of experts, development of privacy seals and BCR (Binding Corporate Rules) which govern the transfer of personal data within multinational companies outside the European Union, the creation of compliance packages that are sector-based reference models covering an entire sector or professional branch. Privacy Seals The CNIL is able to deliver privacy seals for products or procedures which deal with the protection of personal data. The activity report for 2016 demonstrates a sharp increase in activity in comparison with the previous year, with ADOPTED DECISIONS AND DELIBERATIONS The CNIL privacy seal allows a company to set itself apart from others by the quality of its services. For users, it is a confidence indicator for certified products, procedures and organisations which allows users to identify and favour organisations that guarantee a high level of protection for their personal data. Registered data protection officers 18,000 organisations have already appointed officers, of which there are 5,000. Their role as compliance managers is established by the European regulation. The appointment of a data protection officer (DPO) will be mandatory for numerous organisations, and particularly public bodies, in May WP29 guidelines (group of European data protection authorities) specify the criteria set out by the regulation on this new officer function. The CNIL helps DPOs to prepare for changes in their roles through dedicated tools: become an officer section on cnil.fr, new information workshops.

6 ANTICIPATING Within the framework of the CNIL s innovation and foresight activities, it strives to combine two objectives: the taking into consideration, at a very early stage, of new subjects such as trends, technologies or upcoming uses for data; and, the assessment of case studies and analyses through innovative projects and tools. LINC A new medium dedicated to digital innovation In order to contribute to discussions on digital technologies, the CNIL launched LINC, Laboratoire d Innovation Numérique de la CNIL (The CNIL Laboratory for Digital Innovation). Insights and forward thinking, sharing and experimenting are at the heart of this editorial space. INSPECTING AND SANCTIONING Ex-post investigations are considered to be a favoured method of intervention for personal data controllers. They allow the CNIL to ensure concrete implementation of the law. The investigations programme is established according to current events and core issues (current events, new technologies) which are brought before the CNIL. Regarding investigations or complaints, the CNIL s restricted committee (composed of 5 members and a Chairman separate to the CNIL s Chair) can issue various sanctions which include: A warning, which can be made public. If the Chair of the CNIL has already rendered an order, and the data protection officer did not conform to said order, the restrictive committee, through adversarial proceedings, may issue: A financial sanction (except for Government data processing) up to a maximum of 3 million euros. This sanction can be made public; moreover, the restricted committee can also demand that the sanction be published in the press at the costs of the sanctioned organisation. The total amount paid under the sanctions will be collected by the Public Treasury and not by the CNIL. A cease-and-desist injunction on data processing. A withdrawal of the prior authorisation given by the CNIL. The laboratory The CNIL created, within its walls, a laboratory with dedicated IT resources for the testing and experimentation of innovative products and applications. Through this laboratory, it is possible to obtain products as far ahead of their commercialisation as possible, in order to test their functions and evaluate their potential impact on the protection of privacy. In keeping with privacy by design, the CNIL intends to reinforce its consulting role for companies with regards to the integration of personal data protection requirements within their technological development processes. Finally, the CNIL aims to contribute to the development of technological solutions that protect citizens private lives. ETHICS AND DIGITAL TECHNOLOGY A new mission for the CNIL The Foresight Committee Comprised of 15 members from outside the CNIL, this committee strives to stimulate the CNIL s discussions on societal and ethical issues regarding digital technologies in order to better grasp their impact on the rights and freedoms of citizens. It is a constructive space for exchanges. In 2017, it will notably study the place of citizens in a Smart City. Since 2016, legislation has entrusted the CNIL with the mission to give further thought to ethical issues arising from the evolution of digital technologies. In 2017, the CNIL has decided to concentrate its thoughts on algorithms and artificial intelligence by calling for concerned parties to organise public debates, workshops or meetings. 30 partners participate in this CNIL initiative.

7 THE EUROPEAN REGULATION The European regulation on general data protection was published on 4th May It shall provide for Europe s adaptation to the new realities of digital technology and be applicable from 25th May 2018 in all European Union countries. It reinforces European citizens rights and gives them more control over their personal data. It also simplifies formalities for companies and provides them with a unified framework. The reform of data protection rules has three objectives: Reinforce citizens rights, particularly by creating a right to data portability and provisions specific to minors; Holding data protection officers accountable (data controllers and data processors); Lending credibility to regulation through reinforced cooperation between data protection authorities, who will, notably, be able to make joint decisions regarding transnational data processing and issue reinforced sanctions. What will change for professionals While organisations requirements with regards to the French Data Protection Act rest primarily on prior formalities (declaration, authorisation), the European regulation on general data protection is based on accountability and transparency. This concept of accountability translates into: The taking into account of data protection, by default, right from the design of a service or a product; The implementation of an organisation, measures and tools, in-house, which guarantee an optimal protection of individuals whose data is being processed. In practice, the organisations will need to: Conduct an inventory of any data processing carried out; Assess practices and implement procedures (notifications of data protection offences, management of claims and complaints, etc.); Identify risks associated to data processing operations and take necessary measures to prevent their occurrence. Maintain documentation ensuring the traceability of measures taken. New tools for compliance From an operational viewpoint, compliance with the European regulation rests on various tools: Processing records and internal documentation; Privacy Impact Assessments (PIA) for processing presenting a risk; The notification of data protection offences. Implementation of these tools implies, in advance, the appointment of an internal manager: the data protection officer, a true conductor of data protection within the organisation. Beyond this, the principle of accountability must translate into a change in internal culture and mobilise internal or external skills (CIOs, providers, legal services, trade services). To assist in the coordination of organisations, the CNIL offers a dedicated section, a method and tools to prepare for the regulation in 6 steps. This allows organisations to ensure that they have anticipated and implemented the essential parts of the measures necessary in order to be ready in What will change for private individuals The European regulation consolidates the central role of the individual and reinforces the individual s control over his or her data. It shall apply as soon as a European resident is substantially affected by data processing. Global players will therefore be subject to European law if they offer a product or service to a European citizen, even remotely. This criterion, called targeting, represents a significant evolution: henceforth, the territoriality of European law regarding data protection is built around the individual, and no longer solely around a company s place of establishment. The regulation recognises the right of individuals to: Clearer and more accessible information; Reinforced protection of children by obtaining parents consent; A new right to data portability which allows individuals to retrieve their data in an easily reusable manner, and to then transfer that data to a third party; The right to compensation for material or moral damage, particularly as part of group actions. FRANCOPHONE COUNTRIES For about ten years, the CNIL has engaged itself in a data protection promotional campaign within francophone countries. These actions have given way to the creation of the Association Francophone des Autorités de Protection des Données Personnelles (Association for Francophone Data Protection Authorities) in 2007, in partnership with the International Organisation of La Francophonie (OIF), and has brought about the adoption of legislation regarding the right to privacy by francophone countries such as Burkina Faso, Tunisia, Morocco, Madagascar, and Mali. In 2016, 59 Francophone countries out of 84 have legislation on data protection and 51 have appointed a data protection authority. WP29 Since February 2014, the CNIL s Chair has presided over WP29, the working party which brings together the 28 European data protection authorities. In particular, the working party develops the guidelines which unify and clarify the interpretation of the regulation s essential provisions.

8 Contact the CNIL Commission Nationale de l Informatique et des Libertés 3 place de Fontenoy TSA PARIS CEDEX 07 FRANCE Tel. +33 (0) Fax +33 (0) AGENCE LINÉAL

CNPD Training: Data Protection Basics

CNPD Training: Data Protection Basics CNPD Training: Data Protection Basics The obligations of controllers and processors Esch-sur-Alzette Mathilde Stenersen 7-8 February 2018 Legal service Outline 1. Introduction 2. Basic elements 3. The

More information

Pursuant to Convention No. 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data;

Pursuant to Convention No. 108 of the Council of Europe for the protection of persons with regard to the automated processing of personal data; CNIL Decision No. 2011-315 dated 6 October 2011 adopting a standard for delivering privacy seals in matters of training covering the protection of persons with regard to the processing of personal data

More information

This document is meant purely as a documentation tool and the institutions do not assume any liability for its contents

This document is meant purely as a documentation tool and the institutions do not assume any liability for its contents 2012R1024 EN 17.06.2014 002.001 1 This document is meant purely as a documentation tool and the institutions do not assume any liability for its contents B REGULATION (EU) No 1024/2012 OF THE EUROPEAN

More information

COMMISSION OF THE EUROPEAN COMMUNITIES. Amended proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

COMMISSION OF THE EUROPEAN COMMUNITIES. Amended proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 7.3.2006 COM(2006) 94 final 2004/0168 (COD) Amended proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL establishing a European grouping

More information

GENERAL DATA PROTECTION REGULATION REPORT

GENERAL DATA PROTECTION REGULATION REPORT GENERAL DATA PROTECTION REGULATION REPORT 2016 Report -General Data Protection Regulation BACKGROUND P.4 ECIJA SOLUTIONS P.15 MAIN DEVELOPMENTS P.7 FAQS P.16 MEASURES AND TERMS P.12 Privacy and Data Protection

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP265 Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data Adopted on 11 April

More information

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 1 PURPOSE OF THIS DOCUMENT 2 This document is to be used as a guide for advertisers on how they should work with their agencies,

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 17/EN WP264 rev.01 Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data Adopted on 11

More information

ASSOCIATION TECHNIQUE INTERNATIONALE DES BOIS TROPICAUX

ASSOCIATION TECHNIQUE INTERNATIONALE DES BOIS TROPICAUX ASSOCIATION TECHNIQUE INTERNATIONALE DES BOIS TROPICAUX Non-profit association Headquarters: Jardin Tropical de Paris 45 bis Avenue de la Belle Gabrielle 94130 NOGENT-SUR-MARNE (France) Nogent-sur-Marne

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

***I REPORT. EN United in diversity EN. European Parliament A8-0226/

***I REPORT. EN United in diversity EN. European Parliament A8-0226/ European Parliament 2014-2019 Plenary sitting A8-0226/2018 27.6.2018 ***I REPORT on the proposal for a regulation of the European Parliament and of the Council on the European citizens initiative (COM(2017)0482

More information

European Data Protection Supervisor (Controleur europeen de la protection des donnees)

European Data Protection Supervisor (Controleur europeen de la protection des donnees) European Data Protection Supervisor (Controleur europeen de la protection des donnees) APPLICATION FORM FOR ACCREDITATION As A DATA PROTECTION AUTHORITY Application to the Credentials Committee for accreditation

More information

Brasenose College Data Protection Policy Statement v1.2

Brasenose College Data Protection Policy Statement v1.2 Brasenose College Data Protection Policy Statement v1.2 1. Introduction All documents referred to in this policy can be found online at the address below: https://www.bnc.ox.ac.uk/privacypolicies 1.1 Background

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) The EU General Data Protection Regulation (GDPR) What is the GDPR? The General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) was adopted on 27 April,

More information

Data Protection Policy

Data Protection Policy Data Protection Policy This policy will be reviewed by the Trust Board three yearly or amended if there are any changes in legislation before that time. Date of last review: Autumn 2018 Date of next review:

More information

Departmental Disclosure Statement

Departmental Disclosure Statement Departmental Disclosure Statement Electronic Interactions Reform Bill The departmental disclosure statement for a government Bill seeks to bring together in one place a range of information to support

More information

Our position. AmCham EU Comments on the Working Party 29 guidelines on data Protection Impact Assessment (DPIA)

Our position. AmCham EU Comments on the Working Party 29 guidelines on data Protection Impact Assessment (DPIA) AmCham EU Comments on the Working Party 29 guidelines on data Protection Impact Assessment (DPIA) AmCham EU speaks for American companies committed to Europe on trade, investment and competitiveness issues.

More information

EU data protection reform

EU data protection reform EU data protection reform Background and insight A Whitepaper Executive summary The Irish Data Protection Acts 1988 and 2003 gave effect to the European Data Protection Directive 95/46/EC. The existing

More information

www.citizensforabetterbahamas.org 30 th January 2016 FREEDOM OF INFORMATION BILL, 2016 ASSESSMENT Nassau, Bahamas 1. INTRODUCTION The Freedom of Information Bill, 2016 (the 2016 Bill ) was tabled in Parliament

More information

EU GENERAL DATA PROTECTION REGULATION

EU GENERAL DATA PROTECTION REGULATION EU GENERAL DATA PROTECTION REGULATION GENERAL INFORMATION DOCUMENT This resource aims to provide a general factsheet to Asia Pacific Privacy Authorities (APPA) members, in order to understand the basic

More information

The European Citizens Initiative

The European Citizens Initiative The European Citizens Initiative What is Democracy International? Democracy International (DI) is a global coalition of individual citizens and non-governmental organisations promoting direct and participatory

More information

Page 1 of 7 Recommendation CM/Rec(2010)13 of the Committee of Ministers to member states on the protection of individuals with regard to automatic processing of personal data in the context of profiling

More information

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law.

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law. Buzescu Ca>Romanian Business Law>Romanian Data Protection Laws 12. ROMANIAN DATA PROTECTION LEGAL REGIME Updated October 2018 The relevant Romanian data protection laws are: European Regulation no. 679

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

GDPR - Salon Guide Contents

GDPR - Salon Guide Contents GDPR for salons INTRODUCTION 1 GDPR - Salon Guide Contents GDPR - Salon Guide 1. INTRODUCTION 1 a. Already comply with Data Protection? 1 b. What is personal data? 4 c. Who controls the data? 4 d. What

More information

The Committee of Ministers, under the terms of Article 15.b of the Statute of the Council of Europe,

The Committee of Ministers, under the terms of Article 15.b of the Statute of the Council of Europe, Recommendation CM/Rec(2015)5 of the Committee of Ministers to member States on the processing of personal data in the context of employment (Adopted by the Committee of Ministers on 1 April 2015, at the

More information

closer look at Definitions The General Data Protection Regulation

closer look at Definitions The General Data Protection Regulation A closer look at Definitions The General Data Protection Regulation September 2017 V1 www.inforights.im Important This document is part of a series, produced purely for guidance, and does not constitute

More information

APS Bank plc Data Privacy Policy

APS Bank plc Data Privacy Policy APS Bank plc Data Privacy Policy APS Bank plc APS Centre, Tower Street B Kara, BKR 4012, Malta Tel: (+356) 2560 3000 Fax: (+356) 2560 3001 Company Registration No. C2192 email: headoffice@apsbank.com.mt

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 05/EN WP108 Working Document Establishing a Model Checklist Application for Approval of Binding Corporate Rules Adopted on April 14 th, 2005 This Working Party

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

REPUBLIC OF LITHUANIA LAW ON PUBLIC ADMINISTRATION. 17 June 1999 No VIII-1234 Vilnius. (As last amended on 3 June 2014 No XII-903)

REPUBLIC OF LITHUANIA LAW ON PUBLIC ADMINISTRATION. 17 June 1999 No VIII-1234 Vilnius. (As last amended on 3 June 2014 No XII-903) REPUBLIC OF LITHUANIA LAW ON PUBLIC ADMINISTRATION 17 June 1999 No VIII-1234 Vilnius (As last amended on 3 June 2014 No XII-903) CHAPTER I GENERAL PROVISIONS Article 1. Purpose of the Law This Law shall

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

THE ETHICS AND LEGISLATION OF COMMUNICATION IN THE ROMANIAN PUBLIC ADMINISTRATION

THE ETHICS AND LEGISLATION OF COMMUNICATION IN THE ROMANIAN PUBLIC ADMINISTRATION PROFESSIONAL COMMUNICATION AND TRANSLATION STUDIES, 6 (1-2) / 2013 65 THE ETHICS AND LEGISLATION OF COMMUNICATION IN THE ROMANIAN PUBLIC ADMINISTRATION Sorin SUCIU, Vasile GHERHEȘ; Ciprian OBRAD Politehnica

More information

4. EU Charter of Fundamental Rights

4. EU Charter of Fundamental Rights C 377/329 58. Calls on the Commission to submit the proposals referred to above and to inform Parliament of the progress of the legislative programme and of any changes or delays, in order to improve both

More information

UNI Europa ICTS position on the European Single Market for electronic communications

UNI Europa ICTS position on the European Single Market for electronic communications UNI Europa ICTS position on the European Single Market for electronic communications As a trade union federation representing 1.2 million workers in 41 countries in the ICT sector in Europe, UNI Europa

More information

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction Introduction On April 2016 the European Parliament approved the General Data Protection Regulation (GDPR). This new regulation, with mandatory implementation by Member States (MS) and businesses that have

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

GRIFOLS STATUTES OF THE AUDIT COMMITTEE

GRIFOLS STATUTES OF THE AUDIT COMMITTEE GRIFOLS STATUTES OF THE AUDIT COMMITTEE GRIFOLS STATUTES OF THE AUDIT COMMITTEE Table of Contents 1. PURPOSE... 3 2. COMPOSITION... 3 3. FUNCTIONING... 3 4. FUNDING... 4 5. RESPONSIBILITIES... 4 A) In

More information

Preparing for the GDPR

Preparing for the GDPR Preparing for the GDPR Note: These slides and the accompanying presentation contain a general summary and are not legal advice. Niall Rooney 03/11/2017 (1) Data Protection The Right to Data Protection

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

The (Scheme) Actuary as a Data Controller

The (Scheme) Actuary as a Data Controller The (Scheme) Actuary as a Data Controller Keith Webster and Ian Stevens Partners, CMS Cameron McKenna LLP June 2014 Discussion Areas New IFOA guidance Data Protection Act refresher Compliance obligations

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

The Council of State. An overview. Protecting freedom and fundamental rights. Defending the interest of the people

The Council of State. An overview. Protecting freedom and fundamental rights. Defending the interest of the people The Council of State An overview Protecting freedom and fundamental rights Defending the interest of the people Promoting high standards of public governance R é p u b l i q u e F r a n ç a i s e Jean-Marc

More information

eni s proposals on Corporate Governance

eni s proposals on Corporate Governance eni s proposals on Corporate Governance eni s proposals on Corporate Governance 1. Introduction 5 1.1. Objective 5 1.2. Methodology 5 1.3. Proposals 6 2. Proposals 7 2.1. List of proposals 7 2.2.The proposals

More information

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR General Data Protection Regulation Philippe Roggeband Business Development, Manager, GSSO EMEAR Why should you care? Data Protection, and compliance with the General Data Protection regulation, is NOT

More information

AUSTRALIA: New South Wales: Privacy Commissioner

AUSTRALIA: New South Wales: Privacy Commissioner AUSTRALIA: New South Wales: Privacy Commissioner APPLICATION FORM FOR ACCREDITATION As A DATA PROTECTION AUTHORITY Application to the Credentials Committee for accreditation as a data protection authority

More information

EDPS - European Data Protection Supervisor CEPD - Contrôleur européen de la protection des données

EDPS - European Data Protection Supervisor CEPD - Contrôleur européen de la protection des données EDPS - European Data Protection Supervisor CEPD - Contrôleur européen de la protection des données Opinion on the notification for prior checking received from the Data Protection Officer at the Court

More information

Guidelines for establishing users committees and residents committees in health and social service institutions. February 2006

Guidelines for establishing users committees and residents committees in health and social service institutions. February 2006 Guidelines for establishing users committees and residents committees in health and social service institutions February 2006 Produced by: Direction des communications, ministère de la Santé et des Services

More information

ON PREVENTION OF CONFLICT OF INTEREST IN DISCHARGE OF PUBLIC FUNCTIONS LAW ON PREVENTION OF CONFLICT OF INTEREST IN DISCHARGE OF PUBLIC FUNCTIONS

ON PREVENTION OF CONFLICT OF INTEREST IN DISCHARGE OF PUBLIC FUNCTIONS LAW ON PREVENTION OF CONFLICT OF INTEREST IN DISCHARGE OF PUBLIC FUNCTIONS Republika e Kosovës Republika Kosovo - Republic of Kosovo Kuvendi - Skupština - Assembly Law No. 04/L-051 ON PREVENTION OF CONFLICT OF INTEREST IN DISCHARGE OF PUBLIC FUNCTIONS Assembly of Republic of

More information

DATA PROTECTION POLICY VERSION 1.0

DATA PROTECTION POLICY VERSION 1.0 VERSION 1.0 1 Department of Education and Skills Last updated 21 May 2018 Table of Contents 1. Introduction... 4 2. Scope & purpose... 4 3. Responsibility for this policy... 5 4. Data protection principles...

More information

UNI Europa Guidelines on. European Works Councils

UNI Europa Guidelines on. European Works Councils UNI Europa Guidelines on European Works Councils Brussels, December 2010 Index 1 Introduction and Objectives of the Guidelines... 2 1.1 A common approach... 2 1.2 Focus on European Works Councils... 2

More information

EU General Data Protection Regulation in the digital age: Are you ready?

EU General Data Protection Regulation in the digital age: Are you ready? EU General Data Protection Regulation in the digital age: Are you ready? What do you need to know about the new EU General Data Protection Regulation? Data protection has entered a period of unprecedented

More information

GDPR Webinar 9: Automated Processing & Profiling

GDPR Webinar 9: Automated Processing & Profiling Webinar 9: Automated Processing & Profiling T-Minus 210 Days (October 26, 2017) Presenter: Peter Blenkinsop peter.blenkinsop@dbr.com 1 Agenda for Today Brief update on status of guidance and implementation

More information

CALRE AWARD Stars of Europe

CALRE AWARD Stars of Europe CALRE AWARD Stars of Europe Participation form Regional legislative assembly: ANDALUSIAN PARLIAMENT Country: SPAIN President: Mr. JUAN PABLO DURÁN SÁNCHEZ Contact person for the project: Name: SOL Surname:

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

The French energy regulatory framework. INOGATE seminar 10 October 2013

The French energy regulatory framework. INOGATE seminar 10 October 2013 The French energy regulatory framework INOGATE seminar 10 October 2013 CRE in a nutshell Created in 2000 as an independent administrative authority for electricity market regulation, CRE is also competent

More information

Network Rail internal privacy notice

Network Rail internal privacy notice Network Rail internal privacy notice Introduction This privacy notice describes in detail how Network Rail Infrastructure Limited (NR) and its subsidiaries use your personal information when you become

More information

Vice-President for the Euro and Social Dialogue

Vice-President for the Euro and Social Dialogue Jean-Claude Juncker, President of the European Commission Mission Letter Brussels, 1 November 2014 Valdis Dombrovskis Vice-President for the Euro and Social Dialogue Dear Valdis, You are becoming a Member

More information

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1 EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1 The EU General Data Protection Regulation (GDPR), which replaces Directive 95/46/EC

More information

Please read the following carefully in order to understand our policies and practices regarding your personal data and how we process them.

Please read the following carefully in order to understand our policies and practices regarding your personal data and how we process them. Jordan Kuwait Bank - Cyprus Branch Data privacy statement Version: 001 This privacy notice relates to the personal data collected and processed by the Jordan Kuwait Bank Cyprus Branch (referred to as we,

More information

Adopted by the State Duma on September 22, 1999

Adopted by the State Duma on September 22, 1999 FEDERAL LAW NO. 184-FZ OF OCTOBER 6, 1999 ON THE GENERAL PRINCIPLES OF THE ORGANIZATION OF THE LEGISLATIVE (REPRESENTATIVE) AND EXECUTIVE ORGANS OF STATE POWER OF THE SUBJECTS OF THE RUSSIAN FEDERATION

More information

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities

Robert Bond Partner 3/13/2015. EU Data Protection Officer: Roles and responsibilities EU Data Protection Officer: Roles and responsibilities Robert Bond, CCEP Head of Data Protection and Cyber Security Law and DPO charlesrussellspeechlys.com Robert Bond Partner Robert Bond has over 36 years'

More information

GDPR: What Every MSP Needs to Know

GDPR: What Every MSP Needs to Know Robert J. Scott GDPR: What Every MSP Needs to Know Speaker Robert J. Scott Agenda Purpose GDPR Intent & Obligations Applicability Subject-matter and objectives Material scope Territorial scope New Rights

More information

Data Protection Law: An Update

Data Protection Law: An Update Data Protection Law: An Update Billy Hawkes Data Protection Commissioner Matheson Dublin, 28 January 2014 Data Protection Day EU & Irish Legislation Data Protection Directive 95/46/EC Being updated Electronic

More information

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie

Get ready. A Guide to the General Data Protection Regulation (GDPR) elavon.ie Get ready A Guide to the General Data Protection Regulation (GDPR) elavon.ie The General Data Protection Regulation (GDPR) will regulate the privacy and handling of the personal data of individuals in

More information

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) The first IBM Personal Computer was introduced just over 35 years ago, on August 12, 1981. The first-generation iphone was introduced in the

More information

WORKING DOCUMENT. EN United in diversity EN. European Parliament

WORKING DOCUMENT. EN United in diversity EN. European Parliament European Parliament 2014-2019 Committee on Constitutional Affairs 5.10.2017 WORKING DOCUMT on the implementation of the Treaty provisions concerning national parliaments Committee on Constitutional Affairs

More information

Foundation trust membership and GDPR

Foundation trust membership and GDPR 05 April 2018 Foundation trust membership and GDPR In the last few weeks, we have received a number of enquiries from foundation trusts concerned about the implications of the new General Data Protection

More information

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Legal02#67236978v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Notes: We recommend that any business looking to comply with the

More information

A data processor is responsible for processing personal data on behalf of a data controller.

A data processor is responsible for processing personal data on behalf of a data controller. AfrAsia Bank Limited (we, us, our) is committed to safeguarding the privacy of your personal data. We understand that the protection of your personal data is an essential requirement for you and that you

More information

Association LATVIAN PERFORMERS AND PRODUCERS ASSOCIATION ARTICLES OF ASSOCIATION

Association LATVIAN PERFORMERS AND PRODUCERS ASSOCIATION ARTICLES OF ASSOCIATION Translation from Latvian into English Association LATVIAN PERFORMERS AND PRODUCERS ASSOCIATION ARTICLES OF ASSOCIATION 2017 I GENERAL PROVISIONS 1. Latvian Performers and Producers Association (hereinafter

More information

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General

Data Protection. Document Detail Type of Document (Stat Policy/Policy/Procedure) Category of Document (Trust HR-Fin-FM-Gen/Academy) General Data Protection Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) General Index reference number Approved 26/04/18 Approved by Trust

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

GDPR factsheet Key provisions and steps for compliance

GDPR factsheet Key provisions and steps for compliance GDPR factsheet Key provisions and steps for compliance Organisations hold vast amounts of personal data relating to customers, employees, and suppliers as well as within marketing databases. Compliance

More information

EU General Data Protection Regulation: Are you ready?

EU General Data Protection Regulation: Are you ready? EU General Data Protection Regulation: Are you ready? Powered by Global Markets EY Knowledge Contents What do you need to know about the new EU General Data Protection Regulation? Are organisations ready

More information

Final May Corporate Governance Guideline

Final May Corporate Governance Guideline Final May 2006 Corporate Governance Guideline Table of Contents 1. INTRODUCTION 1 2. PURPOSES OF GUIDELINE 1 3. APPLICATION AND SCOPE 2 4. DEFINITIONS OF KEY TERMS 2 5. FRAMEWORK USED BY CENTRAL BANK TO

More information

Rigorous, efficient and timely access to information is an important pillar of accountability for government.

Rigorous, efficient and timely access to information is an important pillar of accountability for government. Open and Accessible Government - Modernizing the Freedom of Information and Protection of Privacy Act Rigorous, efficient and timely access to information is an important pillar of accountability for government.

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Version Date Revision Author Summary of Changes 1.0 21 st May 2018 Ashleigh Morrow EXECUTIVE STATEMENT At CASTLEREAGH NURSERY SCHOOL (the School ), we believe privacy is important.

More information

The objectives of the Association are, at the national and the international level:

The objectives of the Association are, at the national and the international level: ARRIGE BY-LAWS Nota bene : This is an English translation of the original bylaws filed in French, which consist in the only valid bylaws in any event. In other words, this translated version is for better

More information

Privacy Policy Policy App Subscription Dongle REMOTO REMOTO Package Bright Box Hungary Korlátolt Felelősségű Társaság Bright Box our Group

Privacy Policy Policy App Subscription Dongle REMOTO REMOTO Package Bright Box Hungary Korlátolt Felelősségű Társaság Bright Box our Group Privacy Policy This Privacy Policy ( Policy ) applies to your use of the REMOTO telematics based mobile phone application (the App ) whose features are made available to you on a subscription basis (the

More information

Draft Federal Law On Amendment of Selected Legislative Acts of the Russian Federation

Draft Federal Law On Amendment of Selected Legislative Acts of the Russian Federation Draft Federal Law On Amendment of Selected Legislative Acts of the Russian Federation Published on 10.28.2005 Article 1 Para 4 of Article 8 of the RF law, On Closed Administrative Territories (#3297-1

More information

June PUBLIC OVERSIGHT OF THE AUDIT PROFESSION: Enhancing Credibility and Supporting Cooperation

June PUBLIC OVERSIGHT OF THE AUDIT PROFESSION: Enhancing Credibility and Supporting Cooperation Federation of European Accountants Fédération des Experts comptables Européens Briefing Paper Standing for trust and integrity June 2014 PUBLIC OVERSIGHT OF THE AUDIT PROFESSION: Enhancing Credibility

More information

RIGHT TO INFORMATION IN INTERNATIONAL ORGANIZATIONS

RIGHT TO INFORMATION IN INTERNATIONAL ORGANIZATIONS RIGHT TO INFORMATION IN INTERNATIONAL ORGANIZATIONS Nepomuceno A. Malaluan Co-Director, Institute for Freedom of Information Presented at Panel on Building Community through Information Access Strategizing

More information

Discussions within the Group made it possible to reach consensus on certain approaches and principles (Part I).

Discussions within the Group made it possible to reach consensus on certain approaches and principles (Part I). THE EUROPEAN CONVTION THE SECRETARIAT Brussels, 23 September 2002 (24.09) (OR. fr) CONV 286/02 WGI 15 REPORT from : to Subject : Chairman of Working Group I on the Principle of Subsidiarity Members of

More information

WELMEC European cooperation in legal metrology

WELMEC European cooperation in legal metrology WELMEC 8.0 Issue 1 WELMEC European cooperation in legal metrology Measuring Instruments Directive 2004/22/EC Generalities on the Assessment and Operation of Notified Bodies performing Conformity Assessment

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

Danske Bank International Privacy Notice

Danske Bank International Privacy Notice Danske Bank International Privacy Notice INTRODUCTION Danske Bank International S.A. is a financial institution that offers financial advice and services to its customers. As part of our business, we register

More information

Danske Bank International Privacy Notice

Danske Bank International Privacy Notice Danske Bank International Privacy Notice INTRODUCTION Danske Bank International S.A. is a financial institution that offers financial advice and services to its customers. We protect your data and privacy

More information

This privacy policy (the 'conditions') was last amended in May 2016.

This privacy policy (the 'conditions') was last amended in May 2016. ARVAL PRIVACY POLICY This privacy policy (the 'conditions') was last amended in May 2016. These conditions generally apply to your relationship with Arval in conjunction with your use of Arval's services

More information

Review of the Electronic Communications Regulatory Framework. Executive Summary 6: NRAs and BEREC

Review of the Electronic Communications Regulatory Framework. Executive Summary 6: NRAs and BEREC Review of the Electronic Communications Regulatory Framework Executive Summary 6: NRAs and BEREC 1. General context and objectives An efficient governance with modernised institutions is essential in order

More information

Commissioner for Research, Science and Innovation

Commissioner for Research, Science and Innovation Jean-Claude Juncker, President of the European Commission Mission Letter Brussels, 1 November 2014 Carlos Moedas Commissioner for Research, Science and Innovation Dear Carlos, You are becoming a Member

More information

CONFERENCE. Training to Leadership: going to the concrete problems

CONFERENCE. Training to Leadership: going to the concrete problems CONFERENCE Training to Leadership: going to the concrete problems José Miguel García Moreno Head of International Relations Spanish General Council for the Judiciary TRAINING TO LEADERSHIP IN THE JUDICIARY

More information

SURVEY OF ANTI-CORRUPTION MEASURES IN THE PUBLIC SECTOR IN OECD COUNTRIES: KOREA

SURVEY OF ANTI-CORRUPTION MEASURES IN THE PUBLIC SECTOR IN OECD COUNTRIES: KOREA SURVEY OF ANTI-CORRUPTION MEASURES IN THE PUBLIC SECTOR IN OECD COUNTRIES: KOREA 1. What anti-corruption mechanisms exist for the public sector in your country? a) Legislation proscribing corrupt activities

More information

Brussels, 7 May 2009 (Case ) 1. Procedure

Brussels, 7 May 2009 (Case ) 1. Procedure Opinion on notifications for prior checking received from the Data Protection Officers of certain Community agencies concerning the "Staff recruitment procedures". Brussels, 7 May 2009 (Case 2009-287)

More information

Northern Territory: Information Commissioner

Northern Territory: Information Commissioner Northern Territory: Information Commissioner APPLICATION FORM FOR ACCREDITATION As A DATA PROTECTION AUTHORITY Application to the Credentials Committee for accreditation as a data protection authority

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

Committee on Rules of Procedure, Immunities and Institutional Affairs

Committee on Rules of Procedure, Immunities and Institutional Affairs Committee on Rules of Procedure, Immunities and Institutional Affairs Commission du Règlement, des immunités et des affaires institutionnelles DECLASSIFIED 1 AS/Pro (2018) 20 def 11 December 2018 ardoc20_2018

More information

MALIN CORPORATION PLC CORPORATE GOVERNANCE GUIDELINES. Adopted on 3 March 2015 and Amended on 26 May 2015

MALIN CORPORATION PLC CORPORATE GOVERNANCE GUIDELINES. Adopted on 3 March 2015 and Amended on 26 May 2015 MALIN CORPORATION PLC CORPORATE GOVERNANCE GUIDELINES Adopted on 3 March 2015 and Amended on 26 May 2015 The following Corporate Governance Guidelines (the "Guidelines") and Schedule of Matters reserved

More information

EU Charter of Fundamental Rights

EU Charter of Fundamental Rights EU Charter of Fundamental Rights A5-0064/2000 European Parliament resolution on the drafting of a European Union Charter of Fundamental Rights (C5-0058/1999 1999/2064(COS)) The European Parliament, - having

More information