SlideShare una empresa de Scribd logo
1 de 12
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
EU Data Protection Legislation &
Certification
Prof. Paul de Hert
Vrije Universiteit Brussel (LSTS)
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
Outline
What is new with data protection legislation in
the EU?
What is the impact for the security industry?
Data protection and self-regulation
Data protection certification mechanisms
Relevance to CRISP
Conclusions and main points for discussion
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
 General Data Protection Regulation 679/2016
 Reform started in 2012 (EC public consultation in 2010)
 679/2016, adopted in 2016 – applicable from May 2018 onwards
 Replaces the Dir 95/46/EC.
 99 articles, 173 Recitals
 Aim to modernise the legal framework the fundamental right to
protection of personal data
 Directive 680/2016
 Reform of legislation on protection of privacy for electronic
communications (2017 Commission proposal for an ePrivacy
Regulation)
What is new with data protection legislation in
the EU?
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
What is the impact for the security industry?
 Security manufacturers and organisations that employ security
measures that collect, process, use, store, personal data (e.g.
images of persons) need to comply with the legislation.
 Example: surveillance cameras:
 Manufacturers need to implement measures to facilitate compliance with
the legislation. Such as: data protection by design and data protection
by default. Example: a CCTV system is designed to erase data
automatically or a drone used to blur the image of persons (e.g.
children)
 Organisations that employ security measures: most of the times are data
controllers. They need therefore to comply with the legal obligations
stemming from the data protection legislation.
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
Emerging field: Data protection and self-
regulation
 The General Data Protection Regulation includes several ‘self-
regulation’ provisions
 Codes of conduct (e.g. in specific sectors cloud computing industry,
marketing, or other)
 Certification
 Standardisation (limited references in the text, relates to certification)
 Data Protection Impact assessments
 Aim:
 help organisations comply with the legislation,
 offer transparency in relation to practices of organisations
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
Data protection certification mechanisms in the General
Data Protection Regulation
 Art. 42 and 43 GDPR
 Third party conformity assessment – external auditors.
 National data protection certification mechanisms AND possibility for
European Data Protection Seal.
 Main actors involved – controllers/processors, certification bodies,
supervisory authorities (DPAs).
 Emphasis on oversight and control.
 Unclear terminology – ‘certification’ , ‘seals’, ‘marks’ – could lead to legal
uncertainty and non-harmonised application.
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
Data protection certification mechanisms: Oversight by
data protection authorities
Type Content GDPR Provision
Tasks Encourage the establishment of data protection
certification mechanisms
57(1)(n)
Approve certification criteria 57(1)(n)
Draft and publish accreditation criteria 57(1)(p)
Conduct accreditation of certification bodies 57(1)(q)
Investigative Powers Review issued certifications 58(1)(c)
Corrective powers Withdraw certification 58(2)(h)
Order certification body not to issue or withdraw
certification
58(2)(h)
Authorisation powers Accredit certification body 58(3)(e)
Issue certifications 58(3)(f)
Approve certification criteria 58(3)(f)
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
General Data Protection Certification mechanisms:
effects and ‘rewards’
• Voluntary certification
• Certification based on the GDPR does not reduce the responsibility of
the controller or the processor for compliance with the GDPR. (art.
42(4))
• No presumption of conformity with the legal obligations stemming
from the GDPR. The authorities can conduct investigations to certified
organisations.
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
So why would organisations be interested to be certified in
line with the new EU data protection law?
 Art. 83 GDPR: supervisory authority, when deciding whether to
impose an administrative fine and deciding on the amount of the
administrative fine should give due regard on whether the controller
or processor has adhered to approved data protection mechanisms
of art. 42
 Data protection transfers (appropriate safeguard without requiring
any specific authorisation from a supervisory authority) – certification
+ binding and enforceable commitments, via contractual or other
legally binding instruments”. (art.44)
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
Where does CRISP fit in this development?
 CRISP: evaluation and certification of security technologies in
terms of 4 dimensions:
 Security
 Trust
 Efficiency
 Freedom infringement
 Freedom infringement dimension includes data protection
requirements based on the General Data Protection Regulation
 CRISP provides a good assessment to an organisation on
whether it complies with legal obligations.
 Builds on work done by other certification schemes such as
EuroPrise, adapted to new data protection legislation
CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels
Conclusions –open questions for the panel
discussion
 New EU legislation on data protection affects the security industry
 To what extent different security sectors are affected?
 Manufacturers and organisations need to comply with legal obligations stemming from data
protection law.
 Which obligations can be part of a certification scheme?
 Due to complexity of legal provisions and multitude of obligations, the General Data Protection
Regulation includes self-regulation tools that help organisations be accountable and comply (such
as certification)
 What is the relation of certification with the other tools in the data protection legislation? For instance, standards?
 GDPR Certification is voluntary, includes strong oversight mechanisms from public authorities (data
protection authorities).
 Should it be voluntary?
 CRISP has developed an evaluation methodology which, for its data protection part, takes into
account the new requirements of the new legislation.
 How CRISP’s different dimensions and requirements are interrelated? What happens in case of conflicting
 Going through the CRISP evaluation (and certification) shows to the organisation, and to external
parties, which is the level of data protection of the certified/evaluated organisation.
 Who is the target audience of CRISP certification?
Thank you
e:Paul.de.hert@vub.be
12

Más contenido relacionado

La actualidad más candente

Vlg Loss Prevention & Secruity Engels
Vlg Loss Prevention & Secruity EngelsVlg Loss Prevention & Secruity Engels
Vlg Loss Prevention & Secruity Engelspascalverbaten
 
Accountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudAccountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudMassimo Felici
 
Cp18 cyrail final conference en
Cp18 cyrail final conference enCp18 cyrail final conference en
Cp18 cyrail final conference enUICcom
 
Wrapping up and_next_steps_stansted
Wrapping up and_next_steps_stanstedWrapping up and_next_steps_stansted
Wrapping up and_next_steps_stanstedArchiver
 
Wrapping Up and Next Steps¶
Wrapping Up and Next Steps¶Wrapping Up and Next Steps¶
Wrapping Up and Next Steps¶Archiver
 
ESA recent developments seminar 9 feb 2018
ESA recent developments seminar 9 feb 2018ESA recent developments seminar 9 feb 2018
ESA recent developments seminar 9 feb 2018Albert Sanchez Graells
 
Collaborative procurement of Digital Services
Collaborative procurement of Digital Services Collaborative procurement of Digital Services
Collaborative procurement of Digital Services EOSC-hub project
 
Archiver 3rd omc_project_overview
Archiver 3rd omc_project_overviewArchiver 3rd omc_project_overview
Archiver 3rd omc_project_overviewArchiver
 
DHPOL INSPEC2T presentation at CEPOL
DHPOL INSPEC2T presentation at CEPOLDHPOL INSPEC2T presentation at CEPOL
DHPOL INSPEC2T presentation at CEPOLINSPEC2T Project
 
Post-Brexit public procurement: challenges and regulatory solutions
Post-Brexit public procurement: challenges and regulatory solutionsPost-Brexit public procurement: challenges and regulatory solutions
Post-Brexit public procurement: challenges and regulatory solutionsAlbert Sanchez Graells
 
1 archiver omc project_overview
1 archiver omc project_overview1 archiver omc project_overview
1 archiver omc project_overviewArchiver
 
New Product Introductions - InfoChem
New Product Introductions - InfoChemNew Product Introductions - InfoChem
New Product Introductions - InfoChemDr. Haxel Consult
 
IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999
IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999
IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999Dr. Haxel Consult
 
Call for papers - 11th International Conference on VLSI (VLSI 2020)
Call for papers - 11th International Conference on VLSI (VLSI 2020)Call for papers - 11th International Conference on VLSI (VLSI 2020)
Call for papers - 11th International Conference on VLSI (VLSI 2020)sipij
 
Call for papers - 11th International Conference on VLSI (VLSI 2020)
Call for papers -  11th International Conference on VLSI (VLSI 2020)Call for papers -  11th International Conference on VLSI (VLSI 2020)
Call for papers - 11th International Conference on VLSI (VLSI 2020)sipij
 
The concept of “regulatory innovation zones” and the German SINTEG ordinance
The concept of “regulatory innovation zones” and the German SINTEG ordinanceThe concept of “regulatory innovation zones” and the German SINTEG ordinance
The concept of “regulatory innovation zones” and the German SINTEG ordinanceOeko-Institut
 

La actualidad más candente (18)

Vlg Loss Prevention & Secruity Engels
Vlg Loss Prevention & Secruity EngelsVlg Loss Prevention & Secruity Engels
Vlg Loss Prevention & Secruity Engels
 
Accountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudAccountability for Data Governance in the Cloud
Accountability for Data Governance in the Cloud
 
Cp18 cyrail final conference en
Cp18 cyrail final conference enCp18 cyrail final conference en
Cp18 cyrail final conference en
 
Wrapping up and_next_steps_stansted
Wrapping up and_next_steps_stanstedWrapping up and_next_steps_stansted
Wrapping up and_next_steps_stansted
 
Wrapping Up and Next Steps¶
Wrapping Up and Next Steps¶Wrapping Up and Next Steps¶
Wrapping Up and Next Steps¶
 
ESA recent developments seminar 9 feb 2018
ESA recent developments seminar 9 feb 2018ESA recent developments seminar 9 feb 2018
ESA recent developments seminar 9 feb 2018
 
Collaborative procurement of Digital Services
Collaborative procurement of Digital Services Collaborative procurement of Digital Services
Collaborative procurement of Digital Services
 
Archiver 3rd omc_project_overview
Archiver 3rd omc_project_overviewArchiver 3rd omc_project_overview
Archiver 3rd omc_project_overview
 
DHPOL INSPEC2T presentation at CEPOL
DHPOL INSPEC2T presentation at CEPOLDHPOL INSPEC2T presentation at CEPOL
DHPOL INSPEC2T presentation at CEPOL
 
Post-Brexit public procurement: challenges and regulatory solutions
Post-Brexit public procurement: challenges and regulatory solutionsPost-Brexit public procurement: challenges and regulatory solutions
Post-Brexit public procurement: challenges and regulatory solutions
 
1 archiver omc project_overview
1 archiver omc project_overview1 archiver omc project_overview
1 archiver omc project_overview
 
New Product Introductions - InfoChem
New Product Introductions - InfoChemNew Product Introductions - InfoChem
New Product Introductions - InfoChem
 
IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999
IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999
IC-SDV 2018: Emmanuelle Fortune (INPI) Tale of patents filed in France in 1999
 
EGI Operational Security
EGI Operational SecurityEGI Operational Security
EGI Operational Security
 
Call for papers - 11th International Conference on VLSI (VLSI 2020)
Call for papers - 11th International Conference on VLSI (VLSI 2020)Call for papers - 11th International Conference on VLSI (VLSI 2020)
Call for papers - 11th International Conference on VLSI (VLSI 2020)
 
Call for papers - 11th International Conference on VLSI (VLSI 2020)
Call for papers -  11th International Conference on VLSI (VLSI 2020)Call for papers -  11th International Conference on VLSI (VLSI 2020)
Call for papers - 11th International Conference on VLSI (VLSI 2020)
 
Brexit & NHS procurement in England
Brexit & NHS procurement in EnglandBrexit & NHS procurement in England
Brexit & NHS procurement in England
 
The concept of “regulatory innovation zones” and the German SINTEG ordinance
The concept of “regulatory innovation zones” and the German SINTEG ordinanceThe concept of “regulatory innovation zones” and the German SINTEG ordinance
The concept of “regulatory innovation zones” and the German SINTEG ordinance
 

Destacado

2. crisp final conf ste fi workshop_reflections iec-tc79 wg12
2. crisp final conf ste fi workshop_reflections iec-tc79 wg122. crisp final conf ste fi workshop_reflections iec-tc79 wg12
2. crisp final conf ste fi workshop_reflections iec-tc79 wg12CRISP Project
 
Can Trust In Security TEchnologies be Enhanced through Certification?
Can Trust In Security TEchnologies be Enhanced through Certification?Can Trust In Security TEchnologies be Enhanced through Certification?
Can Trust In Security TEchnologies be Enhanced through Certification?CRISP Project
 
Crisp kaleidoscope presentation 13112015
Crisp kaleidoscope presentation 13112015Crisp kaleidoscope presentation 13112015
Crisp kaleidoscope presentation 13112015CRISP Project
 
Smart Video Surveillance and Privacy - CRISP Final Conference
Smart Video Surveillance and Privacy - CRISP Final ConferenceSmart Video Surveillance and Privacy - CRISP Final Conference
Smart Video Surveillance and Privacy - CRISP Final ConferenceCRISP Project
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Lumension
 
CRISP Work package 4 Key Outcomes
CRISP Work package 4 Key OutcomesCRISP Work package 4 Key Outcomes
CRISP Work package 4 Key OutcomesCRISP Project
 
CRISP Stakeholder Analysis
CRISP Stakeholder AnalysisCRISP Stakeholder Analysis
CRISP Stakeholder AnalysisCRISP Project
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? Desynit
 
eHealth and mhealth presentation
eHealth and mhealth presentationeHealth and mhealth presentation
eHealth and mhealth presentationErik Vollebregt
 

Destacado (13)

2. crisp final conf ste fi workshop_reflections iec-tc79 wg12
2. crisp final conf ste fi workshop_reflections iec-tc79 wg122. crisp final conf ste fi workshop_reflections iec-tc79 wg12
2. crisp final conf ste fi workshop_reflections iec-tc79 wg12
 
Can Trust In Security TEchnologies be Enhanced through Certification?
Can Trust In Security TEchnologies be Enhanced through Certification?Can Trust In Security TEchnologies be Enhanced through Certification?
Can Trust In Security TEchnologies be Enhanced through Certification?
 
Crisp kaleidoscope presentation 13112015
Crisp kaleidoscope presentation 13112015Crisp kaleidoscope presentation 13112015
Crisp kaleidoscope presentation 13112015
 
Smart Video Surveillance and Privacy - CRISP Final Conference
Smart Video Surveillance and Privacy - CRISP Final ConferenceSmart Video Surveillance and Privacy - CRISP Final Conference
Smart Video Surveillance and Privacy - CRISP Final Conference
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
CRISP Work package 4 Key Outcomes
CRISP Work package 4 Key OutcomesCRISP Work package 4 Key Outcomes
CRISP Work package 4 Key Outcomes
 
CRISP Stakeholder Analysis
CRISP Stakeholder AnalysisCRISP Stakeholder Analysis
CRISP Stakeholder Analysis
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me? What is GDPR and why does it matter to me?
What is GDPR and why does it matter to me?
 
e-health
e-healthe-health
e-health
 
eHealth and mhealth presentation
eHealth and mhealth presentationeHealth and mhealth presentation
eHealth and mhealth presentation
 
Coshh training stage 2 2014
Coshh training stage 2 2014Coshh training stage 2 2014
Coshh training stage 2 2014
 
Banking in India
Banking in IndiaBanking in India
Banking in India
 

Similar a EU Data Protection, Legislation and Certification

EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016bhalasz
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
EU–US Privacy Shield has Flaws
EU–US Privacy Shield has FlawsEU–US Privacy Shield has Flaws
EU–US Privacy Shield has FlawsThierry Debels
 
Trust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory FrameworkTrust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory FrameworkFrancoise Gilbert
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protectionInterlogica
 
Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project DEFeND Project
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationIBM Security
 
EuroPriSe and ISDP 10003 2015
EuroPriSe and ISDP 10003 2015EuroPriSe and ISDP 10003 2015
EuroPriSe and ISDP 10003 2015Marco Moreschini
 
EuroPriSe and ISDP10003 2015 -
EuroPriSe and ISDP10003  2015 - EuroPriSe and ISDP10003  2015 -
EuroPriSe and ISDP10003 2015 - Marco Moreschini
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
GIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataGIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataIAB Europe
 

Similar a EU Data Protection, Legislation and Certification (20)

2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
Quick guide gdpr
Quick guide gdprQuick guide gdpr
Quick guide gdpr
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
EU–US Privacy Shield has Flaws
EU–US Privacy Shield has FlawsEU–US Privacy Shield has Flaws
EU–US Privacy Shield has Flaws
 
Trust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory FrameworkTrust in the Cloud: Legal and Regulatory Framework
Trust in the Cloud: Legal and Regulatory Framework
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protection
 
Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project Mcis 2018 DEFeND Project
Mcis 2018 DEFeND Project
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
Day 1 - EDPB Priorities and work programme.pdf
Day 1 - EDPB Priorities and work programme.pdfDay 1 - EDPB Priorities and work programme.pdf
Day 1 - EDPB Priorities and work programme.pdf
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
 
EuroPriSe and ISDP 10003 2015
EuroPriSe and ISDP 10003 2015EuroPriSe and ISDP 10003 2015
EuroPriSe and ISDP 10003 2015
 
EuroPriSe and ISDP10003 2015 -
EuroPriSe and ISDP10003  2015 - EuroPriSe and ISDP10003  2015 -
EuroPriSe and ISDP10003 2015 -
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
GIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal DataGIG Working Paper 02/2017 - The Definition of Personal Data
GIG Working Paper 02/2017 - The Definition of Personal Data
 

Último

VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSDr. Oliver Massmann
 
Understanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesUnderstanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesFinlaw Associates
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...James Watkins, III JD CFP®
 
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书Fir sss
 
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书Fir L
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书Fs Las
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝soniya singh
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGPRAKHARGUPTA419620
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULEsreeramsaipranitha
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaBridgeWest.eu
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书Fir L
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书E LSS
 

Último (20)

Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTSVIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
VIETNAM – LATEST GUIDE TO CONTRACT MANUFACTURING AND TOLLING AGREEMENTS
 
Understanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and ChallengesUnderstanding Social Media Bullying: Legal Implications and Challenges
Understanding Social Media Bullying: Legal Implications and Challenges
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书 如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
如何办理(KPU毕业证书)加拿大昆特兰理工大学毕业证学位证书
 
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
如何办理新西兰奥克兰商学院毕业证(本硕)AIS学位证书
 
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
如何办理(Lincoln文凭证书)林肯大学毕业证学位证书
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
Model Call Girl in Haqiqat Nagar Delhi reach out to us at 🔝8264348440🔝
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 
Offences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKINGOffences against property (TRESPASS, BREAKING
Offences against property (TRESPASS, BREAKING
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad Visa
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书
 

EU Data Protection, Legislation and Certification

  • 1. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels EU Data Protection Legislation & Certification Prof. Paul de Hert Vrije Universiteit Brussel (LSTS)
  • 2. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels Outline What is new with data protection legislation in the EU? What is the impact for the security industry? Data protection and self-regulation Data protection certification mechanisms Relevance to CRISP Conclusions and main points for discussion
  • 3. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels  General Data Protection Regulation 679/2016  Reform started in 2012 (EC public consultation in 2010)  679/2016, adopted in 2016 – applicable from May 2018 onwards  Replaces the Dir 95/46/EC.  99 articles, 173 Recitals  Aim to modernise the legal framework the fundamental right to protection of personal data  Directive 680/2016  Reform of legislation on protection of privacy for electronic communications (2017 Commission proposal for an ePrivacy Regulation) What is new with data protection legislation in the EU?
  • 4. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels What is the impact for the security industry?  Security manufacturers and organisations that employ security measures that collect, process, use, store, personal data (e.g. images of persons) need to comply with the legislation.  Example: surveillance cameras:  Manufacturers need to implement measures to facilitate compliance with the legislation. Such as: data protection by design and data protection by default. Example: a CCTV system is designed to erase data automatically or a drone used to blur the image of persons (e.g. children)  Organisations that employ security measures: most of the times are data controllers. They need therefore to comply with the legal obligations stemming from the data protection legislation.
  • 5. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels Emerging field: Data protection and self- regulation  The General Data Protection Regulation includes several ‘self- regulation’ provisions  Codes of conduct (e.g. in specific sectors cloud computing industry, marketing, or other)  Certification  Standardisation (limited references in the text, relates to certification)  Data Protection Impact assessments  Aim:  help organisations comply with the legislation,  offer transparency in relation to practices of organisations
  • 6. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels Data protection certification mechanisms in the General Data Protection Regulation  Art. 42 and 43 GDPR  Third party conformity assessment – external auditors.  National data protection certification mechanisms AND possibility for European Data Protection Seal.  Main actors involved – controllers/processors, certification bodies, supervisory authorities (DPAs).  Emphasis on oversight and control.  Unclear terminology – ‘certification’ , ‘seals’, ‘marks’ – could lead to legal uncertainty and non-harmonised application.
  • 7. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels Data protection certification mechanisms: Oversight by data protection authorities Type Content GDPR Provision Tasks Encourage the establishment of data protection certification mechanisms 57(1)(n) Approve certification criteria 57(1)(n) Draft and publish accreditation criteria 57(1)(p) Conduct accreditation of certification bodies 57(1)(q) Investigative Powers Review issued certifications 58(1)(c) Corrective powers Withdraw certification 58(2)(h) Order certification body not to issue or withdraw certification 58(2)(h) Authorisation powers Accredit certification body 58(3)(e) Issue certifications 58(3)(f) Approve certification criteria 58(3)(f)
  • 8. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels General Data Protection Certification mechanisms: effects and ‘rewards’ • Voluntary certification • Certification based on the GDPR does not reduce the responsibility of the controller or the processor for compliance with the GDPR. (art. 42(4)) • No presumption of conformity with the legal obligations stemming from the GDPR. The authorities can conduct investigations to certified organisations.
  • 9. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels So why would organisations be interested to be certified in line with the new EU data protection law?  Art. 83 GDPR: supervisory authority, when deciding whether to impose an administrative fine and deciding on the amount of the administrative fine should give due regard on whether the controller or processor has adhered to approved data protection mechanisms of art. 42  Data protection transfers (appropriate safeguard without requiring any specific authorisation from a supervisory authority) – certification + binding and enforceable commitments, via contractual or other legally binding instruments”. (art.44)
  • 10. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels Where does CRISP fit in this development?  CRISP: evaluation and certification of security technologies in terms of 4 dimensions:  Security  Trust  Efficiency  Freedom infringement  Freedom infringement dimension includes data protection requirements based on the General Data Protection Regulation  CRISP provides a good assessment to an organisation on whether it complies with legal obligations.  Builds on work done by other certification schemes such as EuroPrise, adapted to new data protection legislation
  • 11. CRISP Final Conference – 16 March 2017 6th CoU Meeting, Brussels Conclusions –open questions for the panel discussion  New EU legislation on data protection affects the security industry  To what extent different security sectors are affected?  Manufacturers and organisations need to comply with legal obligations stemming from data protection law.  Which obligations can be part of a certification scheme?  Due to complexity of legal provisions and multitude of obligations, the General Data Protection Regulation includes self-regulation tools that help organisations be accountable and comply (such as certification)  What is the relation of certification with the other tools in the data protection legislation? For instance, standards?  GDPR Certification is voluntary, includes strong oversight mechanisms from public authorities (data protection authorities).  Should it be voluntary?  CRISP has developed an evaluation methodology which, for its data protection part, takes into account the new requirements of the new legislation.  How CRISP’s different dimensions and requirements are interrelated? What happens in case of conflicting  Going through the CRISP evaluation (and certification) shows to the organisation, and to external parties, which is the level of data protection of the certified/evaluated organisation.  Who is the target audience of CRISP certification?