SlideShare uma empresa Scribd logo
1 de 17
e-Government Centre Moldova




Digital security for better governance
          and public services
    Digital information security trainings
                    2013
                   Chisinau


                                              12.03.2013
e-Government Centre Moldova




Role of Data Protection Inspectorate -
        protecting civic rights
             Hannes Astok
              Senior Expert
         eGovernmance Academy


                                            12.03.2013
Based on the lecture of
Dr. Viljar Peep
Director General
Estonian Data
Protection Inspectorate
What DPI protects?
1. Right to privacy (incl. right to limitation of usage of
  your personal information)
2. Right to access your personal information held by
   public and private entities
3. Right to ask for information about activities of public
   entities
4. Right to see important information of public sector
   on the web
                                              4
Right to privacy
Right to privacy: limitations to usage of personal
 information
Right to access your personal information
   - Convention, Directive, Constitution, national
      legislation (Personal Data Protection Act)
   - Direct marketing, e-commerce: special directives,
     national legislation



                                           5
Privacy limitations to usage of personal
data
 Right to give consent for processing of personal data, unless
  provided otherwise:
        - media, credit data, science and statistical researches etc.
 Right to appoint purposes of processing and transfer of data to third
  persons
 Right to prohibit direct marketing or in some cases only with prior
  consent
 Right to be informed about the data processing, if the data source is
  other than data subject
 Right to access personal data
 Right to demand for correction, deleting, termination of disclosing
   personal data etc.
                                                        6
Freedom of information
1st generation law: right to ask for information
2nd generation law: right to see on the web
   - Convention, PSI directive, constitution, national
      legislation (Public Information Act)




                                           7
Organization of DPI
 A supervisory authority for privacy and for Freedom of
  Information (FOI)
 Staff: 18 civil servants, mostly lawyers.
 Director General – appointed by Govt, 5-year term, judge-like
  position.
 Legislative drafting and financial audit in competence of
  Ministry of Justice.
 Independency in supervision activities. Active power:
  precepts, penalties etc.
 Right to direct reporting to Ombudsman (Legal Chancellor)
  and Constitutional Committee of Parliament.
                                                 8
How DPI works
1.Legal assistance, formation of good practice:
 – explanations (individual and public),
 – guidelines, recommendations,
 – round tables and conferences:
       –incl. the permanent round table of high level
        experts.




                                        9
How DPI works
2. Supervision:

 – complaint-based or ex officio,
 – right to demand explanations,
 – right to inspect on the spot,
 – right to access to the equipment, documents and
   databases,
 – right to issue precepts.


                                      10
How DPI works
3. Enforcement   and punishment:
 – compulsion payments (repeatedly),
 – urgency measures on expense of personal data
   processor,
 – misdemeanour procedure: fine as financial
   penalty (DPI is also quasi-judicative body).



                                         11
How DPI works
 4. Authorisation:

  – processing of sensitive personal data,
  – approval of public sector databases,
  – scientific data processing without the consent
    of the person,
  – transmission of personal data to foreign
    countries with insufficient level of privacy
    protection.
                                         12
Some annual figures
  – Explanations: thousands (paper- and e-mails, duty
    officer phone, public guidelines…)
  – Regist. of sensitive data processing: 960/1460
  – Approval of public sector databases 91/265
  – Complaints 358/306
  – Inspections on the spot 71/53
  – Warnings, precepts 247/508
  – Misdemeanour procedures 23/46
  – Penalties, fines 14/12
                                         13
Topics in privacy protection
• Commerce – using personal data without consent.
  Unwanted sales calls and spam emails. Debtors disclosure.
• Politics – using personal data without consent. Unwanted
  campaign calls and spam emails.
• New media – using pictures without consent. Disclosure
  of private life. Web cams. Identity theft
• Administration – police database, Schengen IS. use of
  databases for political purposes. Unclear retention terms.

                                              14
Freedom of Information topics
• Laziness of holders of public information:
   - requests are not answered within 1 week,
   - web-based document register (index of records) is not kept
      properly,
   - required information is not published on website.
• Legal disputes:
   - should the FOI Act be applied or not?
   - are restrictions applied correctly?
• A general problem – weak or missing unification of public sector
  information on the web.
                                                  15
How is provided the availability of public
sector information?
  Main tools:
 • Documents’ register of the authority
 • Webpage of the authority
 • Estonian State Portal, www.eesti.ee
  Ways to receive the information:
 • Request for information (to answer in 5 working days)
 • Direct access through documents’ register (in case of
   digital documents)
 • The information is made available on the webpage of the
   authority or www.eesti.ee
 • Emergency information through the mass media

                                              16
Q&A
                                   Learn more
                            http://www.aki.ee/eng/
                                          Hannes Astok
                     www.ega.ee | hannes@astok.ee| +372 5091366 | hannesastok
                      E-Governance Academy | Tõnismägi 2, 10112 Tallinn, Estonia




Presentation Title                                                                 12.03.2013

Mais conteúdo relacionado

Mais procurados

Intro to Freedom of Information (FOI)
Intro to Freedom of Information (FOI)Intro to Freedom of Information (FOI)
Intro to Freedom of Information (FOI)alaninbelfast
 
Internet user's rights and fundamental freedoms day
Internet user's rights and fundamental freedoms dayInternet user's rights and fundamental freedoms day
Internet user's rights and fundamental freedoms daymoldovaictsummit2016
 
Freedom of Information for Local Government Units
Freedom of Information for Local Government UnitsFreedom of Information for Local Government Units
Freedom of Information for Local Government UnitsLawrence Villamar
 
Keeping our secrets? Shaping Internet technologies for the public good
Keeping our secrets? Shaping Internet technologies for the public goodKeeping our secrets? Shaping Internet technologies for the public good
Keeping our secrets? Shaping Internet technologies for the public goodblogzilla
 
Freedom of Information, What do We Know?
Freedom of Information, What do We Know?Freedom of Information, What do We Know?
Freedom of Information, What do We Know?Kieran Lamb
 
The Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African JournalistsThe Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African JournalistsGabriella Razzano
 
Ubicomp challenges for privacy law
Ubicomp challenges for privacy lawUbicomp challenges for privacy law
Ubicomp challenges for privacy lawblogzilla
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Werksmans Attorneys
 
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...Jisc
 
Copyright and privacy by design - what lessons have we learned?
Copyright and privacy by design - what lessons have we learned?Copyright and privacy by design - what lessons have we learned?
Copyright and privacy by design - what lessons have we learned?blogzilla
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness WorkshopPaul Jacobson
 
Freedom of information
Freedom of informationFreedom of information
Freedom of informationSaroj Makwana
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Gopanagenda
 
'The UK Freedom of Information Act – A Practical Guide for Academic Research...
'The UK Freedom of Information Act – A Practical Guide for Academic Research...'The UK Freedom of Information Act – A Practical Guide for Academic Research...
'The UK Freedom of Information Act – A Practical Guide for Academic Research...Incremental2
 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Werksmans Attorneys
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
 
Clyrofor popia readiness webinar
Clyrofor  popia readiness webinarClyrofor  popia readiness webinar
Clyrofor popia readiness webinarLesedi Mnisi
 

Mais procurados (19)

Intro to Freedom of Information (FOI)
Intro to Freedom of Information (FOI)Intro to Freedom of Information (FOI)
Intro to Freedom of Information (FOI)
 
Internet user's rights and fundamental freedoms day
Internet user's rights and fundamental freedoms dayInternet user's rights and fundamental freedoms day
Internet user's rights and fundamental freedoms day
 
Freedom of Information for Local Government Units
Freedom of Information for Local Government UnitsFreedom of Information for Local Government Units
Freedom of Information for Local Government Units
 
Keeping our secrets? Shaping Internet technologies for the public good
Keeping our secrets? Shaping Internet technologies for the public goodKeeping our secrets? Shaping Internet technologies for the public good
Keeping our secrets? Shaping Internet technologies for the public good
 
Freedom of Information, What do We Know?
Freedom of Information, What do We Know?Freedom of Information, What do We Know?
Freedom of Information, What do We Know?
 
The Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African JournalistsThe Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African Journalists
 
Ubicomp challenges for privacy law
Ubicomp challenges for privacy lawUbicomp challenges for privacy law
Ubicomp challenges for privacy law
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...
 
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
 
Copyright and privacy by design - what lessons have we learned?
Copyright and privacy by design - what lessons have we learned?Copyright and privacy by design - what lessons have we learned?
Copyright and privacy by design - what lessons have we learned?
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
Freedom of information
Freedom of informationFreedom of information
Freedom of information
 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
 
Engage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To GoEngage 2018: GDPR Three Days To Go
Engage 2018: GDPR Three Days To Go
 
'The UK Freedom of Information Act – A Practical Guide for Academic Research...
'The UK Freedom of Information Act – A Practical Guide for Academic Research...'The UK Freedom of Information Act – A Practical Guide for Academic Research...
'The UK Freedom of Information Act – A Practical Guide for Academic Research...
 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...
 
Cybercrime convention
Cybercrime conventionCybercrime convention
Cybercrime convention
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
Clyrofor popia readiness webinar
Clyrofor  popia readiness webinarClyrofor  popia readiness webinar
Clyrofor popia readiness webinar
 

Destaque

Prezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariucPrezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariucE-Government Center Moldova
 
The nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data AnalyticsThe nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data AnalyticsE-Government Center Moldova
 
Государство и экономика: кто кого? 9.06.2
Государство и экономика: кто кого? 9.06.2Государство и экономика: кто кого? 9.06.2
Государство и экономика: кто кого? 9.06.2ВЦИОМ
 
PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)
PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)
PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)E-Government Center Moldova
 
Digital Economy Outlook 2015
Digital Economy Outlook 2015Digital Economy Outlook 2015
Digital Economy Outlook 2015innovationoecd
 

Destaque (10)

Presentation cert gov-md 05.03.2013
Presentation cert gov-md 05.03.2013Presentation cert gov-md 05.03.2013
Presentation cert gov-md 05.03.2013
 
Mpay&Mcloud
Mpay&McloudMpay&Mcloud
Mpay&Mcloud
 
Prezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariucPrezentare compartiment securitatea 05 03 2013 p sincariuc
Prezentare compartiment securitatea 05 03 2013 p sincariuc
 
The new era of smart
The new era of smart The new era of smart
The new era of smart
 
Digital Transformation by Richard Baird
Digital Transformation by Richard BairdDigital Transformation by Richard Baird
Digital Transformation by Richard Baird
 
The nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data AnalyticsThe nexus of Social, Mobile, Cloud and Big Data Analytics
The nexus of Social, Mobile, Cloud and Big Data Analytics
 
Государство и экономика: кто кого? 9.06.2
Государство и экономика: кто кого? 9.06.2Государство и экономика: кто кого? 9.06.2
Государство и экономика: кто кого? 9.06.2
 
PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)
PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)
PROGRAMUL STRATEGIC DE MODERNIZARE TEHNOLOGICĂ A GUVERNĂRII (E-TRANSFORMARE)
 
Hannes astok policy development
Hannes astok policy developmentHannes astok policy development
Hannes astok policy development
 
Digital Economy Outlook 2015
Digital Economy Outlook 2015Digital Economy Outlook 2015
Digital Economy Outlook 2015
 

Semelhante a Hannes astok data protection agency

"Information Compliance - Freedom of Information, Data Protection and Librari...
"Information Compliance - Freedom of Information, Data Protection and Librari..."Information Compliance - Freedom of Information, Data Protection and Librari...
"Information Compliance - Freedom of Information, Data Protection and Librari...Terry O'Brien
 
The death of data protection
The death of data protection The death of data protection
The death of data protection Lilian Edwards
 
The death of data protection sans obama
The death of data protection sans obamaThe death of data protection sans obama
The death of data protection sans obamaLilian Edwards
 
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...EUDAT
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIKarel Holst
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORIKarel Holst
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrityAxon Lawyers
 
Legal aspects of data gathering and information exchange
Legal aspects of data gathering and information exchangeLegal aspects of data gathering and information exchange
Legal aspects of data gathering and information exchangeStevenSegaert
 
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...Amministratore Bluefactor
 
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...Amministratore Bluefactor
 
PLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics finalPLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics finalSofie van der Meulen
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Axon Lawyers
 
GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesGDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesLIBER Europe
 
Draft data protection regn 2012
Draft data protection regn 2012Draft data protection regn 2012
Draft data protection regn 2012lilianedwards
 
Legal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataLegal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataOpenAIRE
 
Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...
Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...
Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...bmanolea
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
IT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual PropertyIT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual PropertyCharles Mok
 

Semelhante a Hannes astok data protection agency (20)

"Information Compliance - Freedom of Information, Data Protection and Librari...
"Information Compliance - Freedom of Information, Data Protection and Librari..."Information Compliance - Freedom of Information, Data Protection and Librari...
"Information Compliance - Freedom of Information, Data Protection and Librari...
 
The death of data protection
The death of data protection The death of data protection
The death of data protection
 
The death of data protection sans obama
The death of data protection sans obamaThe death of data protection sans obama
The death of data protection sans obama
 
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
Ben soltane on Access to Information
Ben soltane on Access to InformationBen soltane on Access to Information
Ben soltane on Access to Information
 
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI2017 09 13_VOKA The Big Refresh - GDPR - IFORI
2017 09 13_VOKA The Big Refresh - GDPR - IFORI
 
Data protection and data integrity
 Data protection and data integrity Data protection and data integrity
Data protection and data integrity
 
Legal aspects of data gathering and information exchange
Legal aspects of data gathering and information exchangeLegal aspects of data gathering and information exchange
Legal aspects of data gathering and information exchange
 
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
 
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...Att. patrizia giannini   fordham university new york 19 july 2013 - electroni...
Att. patrizia giannini fordham university new york 19 july 2013 - electroni...
 
PLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics finalPLA Legal aspects of Big Data analytics final
PLA Legal aspects of Big Data analytics final
 
Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics' Paperless Lab Academy 'legal aspects of big data analytics'
Paperless Lab Academy 'legal aspects of big data analytics'
 
GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and LibrariesGDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
GDPR - Thoughts on the EU Data Protection Regulation, Research and Libraries
 
Draft data protection regn 2012
Draft data protection regn 2012Draft data protection regn 2012
Draft data protection regn 2012
 
Legal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research dataLegal and ethical considerations for sharing research data
Legal and ethical considerations for sharing research data
 
Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...
Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...
Privacy Report: Romania – from the DP Act to the Constitutional Court decisio...
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
IT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual PropertyIT Governance: Privacy and Intellectual Property
IT Governance: Privacy and Intellectual Property
 

Mais de E-Government Center Moldova

Can e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterCan e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterE-Government Center Moldova
 
Driving government efficiency and innovation through cloud computing k...
Driving government efficiency and  innovation through      cloud computing  k...Driving government efficiency and  innovation through      cloud computing  k...
Driving government efficiency and innovation through cloud computing k...E-Government Center Moldova
 
Unleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moranUnleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moranE-Government Center Moldova
 
Government innovation through cloud computing arthur riel
Government innovation through cloud computing arthur rielGovernment innovation through cloud computing arthur riel
Government innovation through cloud computing arthur rielE-Government Center Moldova
 
Government cloud services international experience laurence millar
Government cloud services international experience laurence millarGovernment cloud services international experience laurence millar
Government cloud services international experience laurence millarE-Government Center Moldova
 
Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1E-Government Center Moldova
 
Shuky peleg e_gov_cyber_presentation_information_sharing
Shuky peleg e_gov_cyber_presentation_information_sharingShuky peleg e_gov_cyber_presentation_information_sharing
Shuky peleg e_gov_cyber_presentation_information_sharingE-Government Center Moldova
 

Mais de E-Government Center Moldova (20)

Digital security hannes astok
Digital security hannes astokDigital security hannes astok
Digital security hannes astok
 
Assessing cybersecurity_Anto Veldre
Assessing cybersecurity_Anto VeldreAssessing cybersecurity_Anto Veldre
Assessing cybersecurity_Anto Veldre
 
MCloud operational framework
MCloud operational frameworkMCloud operational framework
MCloud operational framework
 
Arhitectura de securitate_MCloud
Arhitectura de securitate_MCloudArhitectura de securitate_MCloud
Arhitectura de securitate_MCloud
 
Ibm smart cloud solutions m-cloud
Ibm smart cloud solutions   m-cloudIbm smart cloud solutions   m-cloud
Ibm smart cloud solutions m-cloud
 
Ibm security virtual server protection
Ibm security virtual server protectionIbm security virtual server protection
Ibm security virtual server protection
 
Can e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterCan e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedter
 
Driving government efficiency and innovation through cloud computing k...
Driving government efficiency and  innovation through      cloud computing  k...Driving government efficiency and  innovation through      cloud computing  k...
Driving government efficiency and innovation through cloud computing k...
 
Star storage m cloud week
Star storage m cloud weekStar storage m cloud week
Star storage m cloud week
 
Unleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moranUnleashing the potential of cloud computing in europe francisco garcia moran
Unleashing the potential of cloud computing in europe francisco garcia moran
 
Government innovation through cloud computing arthur riel
Government innovation through cloud computing arthur rielGovernment innovation through cloud computing arthur riel
Government innovation through cloud computing arthur riel
 
4 francisco garcia_moran_moldova_2013
4 francisco garcia_moran_moldova_20134 francisco garcia_moran_moldova_2013
4 francisco garcia_moran_moldova_2013
 
3 platforma tehnologica_m-cloud
3 platforma tehnologica_m-cloud3 platforma tehnologica_m-cloud
3 platforma tehnologica_m-cloud
 
2 m cloud-iurie turcanu
2 m cloud-iurie turcanu2 m cloud-iurie turcanu
2 m cloud-iurie turcanu
 
Government cloud services international experience laurence millar
Government cloud services international experience laurence millarGovernment cloud services international experience laurence millar
Government cloud services international experience laurence millar
 
1 artur riel_sesiunea_1
1 artur riel_sesiunea_11 artur riel_sesiunea_1
1 artur riel_sesiunea_1
 
eGovernment in Israel
eGovernment in IsraeleGovernment in Israel
eGovernment in Israel
 
Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1
 
Shuky peleg e_gov_cyber_using_cloud_services
Shuky peleg e_gov_cyber_using_cloud_servicesShuky peleg e_gov_cyber_using_cloud_services
Shuky peleg e_gov_cyber_using_cloud_services
 
Shuky peleg e_gov_cyber_presentation_information_sharing
Shuky peleg e_gov_cyber_presentation_information_sharingShuky peleg e_gov_cyber_presentation_information_sharing
Shuky peleg e_gov_cyber_presentation_information_sharing
 

Hannes astok data protection agency

  • 1. e-Government Centre Moldova Digital security for better governance and public services Digital information security trainings 2013 Chisinau 12.03.2013
  • 2. e-Government Centre Moldova Role of Data Protection Inspectorate - protecting civic rights Hannes Astok Senior Expert eGovernmance Academy 12.03.2013
  • 3. Based on the lecture of Dr. Viljar Peep Director General Estonian Data Protection Inspectorate
  • 4. What DPI protects? 1. Right to privacy (incl. right to limitation of usage of your personal information) 2. Right to access your personal information held by public and private entities 3. Right to ask for information about activities of public entities 4. Right to see important information of public sector on the web 4
  • 5. Right to privacy Right to privacy: limitations to usage of personal information Right to access your personal information - Convention, Directive, Constitution, national legislation (Personal Data Protection Act) - Direct marketing, e-commerce: special directives, national legislation 5
  • 6. Privacy limitations to usage of personal data  Right to give consent for processing of personal data, unless provided otherwise: - media, credit data, science and statistical researches etc.  Right to appoint purposes of processing and transfer of data to third persons  Right to prohibit direct marketing or in some cases only with prior consent  Right to be informed about the data processing, if the data source is other than data subject  Right to access personal data  Right to demand for correction, deleting, termination of disclosing personal data etc. 6
  • 7. Freedom of information 1st generation law: right to ask for information 2nd generation law: right to see on the web - Convention, PSI directive, constitution, national legislation (Public Information Act) 7
  • 8. Organization of DPI  A supervisory authority for privacy and for Freedom of Information (FOI)  Staff: 18 civil servants, mostly lawyers.  Director General – appointed by Govt, 5-year term, judge-like position.  Legislative drafting and financial audit in competence of Ministry of Justice.  Independency in supervision activities. Active power: precepts, penalties etc.  Right to direct reporting to Ombudsman (Legal Chancellor) and Constitutional Committee of Parliament. 8
  • 9. How DPI works 1.Legal assistance, formation of good practice: – explanations (individual and public), – guidelines, recommendations, – round tables and conferences: –incl. the permanent round table of high level experts. 9
  • 10. How DPI works 2. Supervision: – complaint-based or ex officio, – right to demand explanations, – right to inspect on the spot, – right to access to the equipment, documents and databases, – right to issue precepts. 10
  • 11. How DPI works 3. Enforcement and punishment: – compulsion payments (repeatedly), – urgency measures on expense of personal data processor, – misdemeanour procedure: fine as financial penalty (DPI is also quasi-judicative body). 11
  • 12. How DPI works 4. Authorisation: – processing of sensitive personal data, – approval of public sector databases, – scientific data processing without the consent of the person, – transmission of personal data to foreign countries with insufficient level of privacy protection. 12
  • 13. Some annual figures – Explanations: thousands (paper- and e-mails, duty officer phone, public guidelines…) – Regist. of sensitive data processing: 960/1460 – Approval of public sector databases 91/265 – Complaints 358/306 – Inspections on the spot 71/53 – Warnings, precepts 247/508 – Misdemeanour procedures 23/46 – Penalties, fines 14/12 13
  • 14. Topics in privacy protection • Commerce – using personal data without consent. Unwanted sales calls and spam emails. Debtors disclosure. • Politics – using personal data without consent. Unwanted campaign calls and spam emails. • New media – using pictures without consent. Disclosure of private life. Web cams. Identity theft • Administration – police database, Schengen IS. use of databases for political purposes. Unclear retention terms. 14
  • 15. Freedom of Information topics • Laziness of holders of public information: - requests are not answered within 1 week, - web-based document register (index of records) is not kept properly, - required information is not published on website. • Legal disputes: - should the FOI Act be applied or not? - are restrictions applied correctly? • A general problem – weak or missing unification of public sector information on the web. 15
  • 16. How is provided the availability of public sector information?  Main tools: • Documents’ register of the authority • Webpage of the authority • Estonian State Portal, www.eesti.ee  Ways to receive the information: • Request for information (to answer in 5 working days) • Direct access through documents’ register (in case of digital documents) • The information is made available on the webpage of the authority or www.eesti.ee • Emergency information through the mass media 16
  • 17. Q&A Learn more http://www.aki.ee/eng/ Hannes Astok www.ega.ee | hannes@astok.ee| +372 5091366 | hannesastok E-Governance Academy | Tõnismägi 2, 10112 Tallinn, Estonia Presentation Title 12.03.2013