SlideShare uma empresa Scribd logo
1 de 33
DATA PROTECTION                  An Overview of Data
                                Protection Legislation in
                                       Guernsey
 Wednesday, 8 October 2008
    Friday, 10 October 2008   Jon Barclay, Advocate
  Monday, 13 October 2008
                              AO Hall Advocates
Background: The EC Directive

●  Sets out uniform standards for good data handling
practice.
●   Implemented in UK by Data Protection Act 1998.
●   Not binding on Guernsey, but implemented here for
    business reasons.
●   The Data Protection (Bailiwick of Guernsey) Law, 2001
    is modelled on the 1998 Act.
● European Commission Decision of 21 November
2003: Guernsey has “adequate” data protection.
Guernsey’s Data Protection
                Law

Main Features -
●   Notification Requirements for Data Controllers
●   Data Subject Rights
●   Good Data Handling Practices
●   Supervision and Enforcement Procedures
Definitions


●       “Data” – information stored or processed electronically,

or manually if stored on a “relevant filing system”.



●       “Relevant Filing System” – a set of information which

is structured, either by reference to individuals or by

reference to criteria related to individuals, in such a way that

specific information relating to a particular individual    is

readily accessible.
Definitions continued…

●      “Personal Data” – must relate to a living individual
       who can be identified from those data or from those
       data and other information which is in possession of the
       data controller.


●      “Data Controller” – a person who determines the
       manner in which personal data is processed.


●      “Data Processor” – any person other than an
employee who holds data on behalf of the data controller.
Definitions continued…

●       “Data Subject” – a living individual who is the subject
of personal data.


●       “Processing” – obtaining, recording or holding the data
or information and carrying out any operation in relation to it.


●       “Sensitive Personal Data” – personal data which
consists of information about the subject’s racial or         ethnic
origin, political opinions, religious beliefs, trade union affiliation,
physical or mental health, sex life,        criminal activities or
criminal record.
Scope

● All data controllers in the Bailiwick.

● All personal data.

● Foreign controllers who process data here.

● Focus on privacy.

● There is no Freedom of Information legislation in
  Guernsey.
Personal Data
●   Email and other addresses
●   Telephone subscriber details
●   Credit record
●   Banking details
●   Employment references
●   Criminal convictions
●   Biometric data
●   Medical data
●   CCTV footage
●   Records of personal telephone calls
●   Recorded expressions of personal opinion
●   etc
Notification Requirement

● Annual notification unless exempt


● Public register


● Transparency and openness
Notification Details

● Contact details
● General purposes of processing
● Types of data subject
● Types of data
● Potential recipients
● Other jurisdictions
● Security measures
Useful addresses



• www.dpr.gov.gg
• www.gov.gg
Data Subject Rights


●   Subject access
●   Rectification, blocking, erasure and destruction
●   To prevent processing likely to cause distress
●   To prevent processing for direct marketing
purposes
●   Compensation
●   Automated decision-making
●   Request for an assessment
Subject Access Requests

Individuals are entitled to request a data controller to provide
them with -
●   a description of any data which is being processed by
reference to them
●   a description of the purposes for which it is being
processed
●   a description of any potential recipients of the data
●   information as to the source of the data
Exemptions


●   Public Security
●   Investigation of Crime
●   Regulatory Activity
●   etc
Conflict of Subject Rights and Controller
                 Duties


•   STRs

•   Third party privacy

•   etc
Automated Decision Making



•   Significant?
Objections to Data Processing

• Damage or distress

•   Direct Marketing – Preference Services
Other Rights

• Rectification, blocking, erasure and destruction

•   Compensation

•   Assessments
Data controllers: duty to follow good data
           handling practices


•   All data controllers must observe the
    Data Protection Principles

•   Even if exempt from notification
The Data Protection Principles
Personal data must be :
   1. processed fairly and lawfully
   2. obtained for specified and lawful purposes only
   3. adequate, relevant and not excessive
   4. accurate and kept up to date
   5. kept for no longer than is necessary
   6. processed in accordance with the rights of data
      subjects
   7. kept secure
   8. transferred to third countries only if they ensure
      an adequate level of data protection
First and Second Principles: “Lawful”?


●   Breach of Privacy
●   Hacking
●   Breach of Confidentiality
●   Rehabilitation of Offenders
●   Theft
●   Obtaining by Deception (“Blagging”)
●   Unlawful Interception of Communications
First and Second Principles: “Fair”?

Consider:
●       The method by which the data was obtained

●       Statutory authority or requirement

●       Informed consent

Also:

    ●   Is a Schedule 2 condition met?

    ● Sensitive personal data: Is a Schedule 3
    condition met?
Quality Standards


Third Principle:      relevant, adequate and not
                      excessive.

Fourth Principle:     accurate and kept up to date.

Fifth Principle:      kept for no longer than is
                      necessary.
Sixth Principle: Data Subject Rights



● Subject access rights
● Privacy
● Security
Seventh Principle: Security
Security Measures –
●   Passwords (which should be changed regularly)
●   Careful location of computer screens
●   Procedures to verify caller identity
●   Clear, written data protection procedures
●   Making breach of data protection procedures a disciplinary
    offence
●   Use of encryption
●   Other technical and operational measures
Eighth Principle: Data export




•   EEA
•   “Adequate” Countries
•   Elsewhere
      •Data Transfer Agreements
      •Model Clauses
Enforcement Authorities

•The Commissioner
•The Police
•The Courts
The Data Protection Commissioner



  ● Role

  ● Enforcement Powers

  ● Requests for Assessment
Offences

•   Failure to notify
•   Unauthorised disclosure, selling or obtaining
•   Failure to comply with a notice
•   Blagging
•   Unsolicited communications
•   Enforced SARs
The Commissioner’s Role

•   Promote good information handling practices
•   Encourage respect for privacy
•   Enforce the legislation
•   Inform and direct policy
The Commissioner’s Powers

• Limited
• Enforcement notices
• Encouragement and Education rather than
  coersion
Requests for Assessment

•   Unverified
•   Verified
•   Enforcement Notices
•   Information Notices and Warrants
DATA PROTECTION                  An Overview of Data
                                Protection Legislation in
                                       Guernsey
 Wednesday, 8 October 2008
    Friday, 10 October 2008   Jon Barclay, Advocate
  Monday, 13 October 2008
                              AO Hall Advocates

Mais conteúdo relacionado

Mais procurados

DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamBrowne Jacobson LLP
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamBrowne Jacobson LLP
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonBrowne Jacobson LLP
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterBrowne Jacobson LLP
 
WB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillWB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillTrustArc
 
Aleksandra kuczerawy privacy issues in future internet - seserv se workshop...
Aleksandra kuczerawy   privacy issues in future internet - seserv se workshop...Aleksandra kuczerawy   privacy issues in future internet - seserv se workshop...
Aleksandra kuczerawy privacy issues in future internet - seserv se workshop...ictseserv
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillAntaraa Vasudev
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillTrustArc
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidancePrivacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidanceAmy Purcell
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?TAG Alliances
 
Data protection-training
Data protection-trainingData protection-training
Data protection-trainingJames Wright
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4Wynthorpe
 
IT Perspectives in Implementing Privacy Framework
IT Perspectives in Implementing Privacy FrameworkIT Perspectives in Implementing Privacy Framework
IT Perspectives in Implementing Privacy FrameworkShankar Subramaniyan
 

Mais procurados (20)

DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, LondonDPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, London
 
GDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, ManchesterGDPR for public sector DPO's seminar, April 2018, Manchester
GDPR for public sector DPO's seminar, April 2018, Manchester
 
WB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection BillWB-2022-01-25-India's Data Protection Bill
WB-2022-01-25-India's Data Protection Bill
 
Aleksandra kuczerawy privacy issues in future internet - seserv se workshop...
Aleksandra kuczerawy   privacy issues in future internet - seserv se workshop...Aleksandra kuczerawy   privacy issues in future internet - seserv se workshop...
Aleksandra kuczerawy privacy issues in future internet - seserv se workshop...
 
Data Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection BillData Decoded: Understanding India's Draft Data Protection Bill
Data Decoded: Understanding India's Draft Data Protection Bill
 
WB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection BillWB-2022-01-25-India Data Protection Bill
WB-2022-01-25-India Data Protection Bill
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
Overview Data Privacy Bill India
Overview Data Privacy Bill IndiaOverview Data Privacy Bill India
Overview Data Privacy Bill India
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
Privacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and AvoidancePrivacy and Data Security: Risk Management and Avoidance
Privacy and Data Security: Risk Management and Avoidance
 
What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?What is the General Data Protection Regulation (GDPR)?
What is the General Data Protection Regulation (GDPR)?
 
Privacy in simple
Privacy in simplePrivacy in simple
Privacy in simple
 
Data protection-training
Data protection-trainingData protection-training
Data protection-training
 
Safety And Security Of Data 4
Safety And Security Of Data 4Safety And Security Of Data 4
Safety And Security Of Data 4
 
IT Perspectives in Implementing Privacy Framework
IT Perspectives in Implementing Privacy FrameworkIT Perspectives in Implementing Privacy Framework
IT Perspectives in Implementing Privacy Framework
 
POPI_Overview_E
POPI_Overview_EPOPI_Overview_E
POPI_Overview_E
 
POPI_Overview_E
POPI_Overview_EPOPI_Overview_E
POPI_Overview_E
 

Semelhante a Guernsey Data Protection Legislation

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulationJames Mulhern
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityARDC
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Data protection compliance for tech startups
Data protection compliance for tech startupsData protection compliance for tech startups
Data protection compliance for tech startupsEkoInnovationCentre
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterBrowne Jacobson LLP
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...Brian Miller, Solicitor
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protectionRachel Aldighieri
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...CILIPScotland
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)Kimberly Simon MBA
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Burton Lee
 
Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006Kimberly Verska
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Michael Adamberry
 

Semelhante a Guernsey Data Protection Legislation (20)

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Gdpr demystified - making sense of the regulation
Gdpr demystified  - making sense of the regulationGdpr demystified  - making sense of the regulation
Gdpr demystified - making sense of the regulation
 
Data Protection and IDEA
Data Protection and IDEAData Protection and IDEA
Data Protection and IDEA
 
The Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research communityThe Privacy Law Landscape: Issues for the research community
The Privacy Law Landscape: Issues for the research community
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Data protection compliance for tech startups
Data protection compliance for tech startupsData protection compliance for tech startups
Data protection compliance for tech startups
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...What All Organisations Need to Know About Data Protection and Cloud Computing...
What All Organisations Need to Know About Data Protection and Cloud Computing...
 
Introduction to data protection
Introduction to data protectionIntroduction to data protection
Introduction to data protection
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...Changing legislation – General Data Protection Regulation (GDPR) and librarie...
Changing legislation – General Data Protection Regulation (GDPR) and librarie...
 
EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)EU's General Data Protection Regulation (GDPR)
EU's General Data Protection Regulation (GDPR)
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 
Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006Worldwide Laws Privacy Presentation 2006
Worldwide Laws Privacy Presentation 2006
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
Data Protection Seminar 2_Marketing & GDPR_ISOLAS LLP_26-07-17
 

Guernsey Data Protection Legislation

  • 1. DATA PROTECTION An Overview of Data Protection Legislation in Guernsey Wednesday, 8 October 2008 Friday, 10 October 2008 Jon Barclay, Advocate Monday, 13 October 2008 AO Hall Advocates
  • 2. Background: The EC Directive ● Sets out uniform standards for good data handling practice. ● Implemented in UK by Data Protection Act 1998. ● Not binding on Guernsey, but implemented here for business reasons. ● The Data Protection (Bailiwick of Guernsey) Law, 2001 is modelled on the 1998 Act. ● European Commission Decision of 21 November 2003: Guernsey has “adequate” data protection.
  • 3. Guernsey’s Data Protection Law Main Features - ● Notification Requirements for Data Controllers ● Data Subject Rights ● Good Data Handling Practices ● Supervision and Enforcement Procedures
  • 4. Definitions ● “Data” – information stored or processed electronically, or manually if stored on a “relevant filing system”. ● “Relevant Filing System” – a set of information which is structured, either by reference to individuals or by reference to criteria related to individuals, in such a way that specific information relating to a particular individual is readily accessible.
  • 5. Definitions continued… ● “Personal Data” – must relate to a living individual who can be identified from those data or from those data and other information which is in possession of the data controller. ● “Data Controller” – a person who determines the manner in which personal data is processed. ● “Data Processor” – any person other than an employee who holds data on behalf of the data controller.
  • 6. Definitions continued… ● “Data Subject” – a living individual who is the subject of personal data. ● “Processing” – obtaining, recording or holding the data or information and carrying out any operation in relation to it. ● “Sensitive Personal Data” – personal data which consists of information about the subject’s racial or ethnic origin, political opinions, religious beliefs, trade union affiliation, physical or mental health, sex life, criminal activities or criminal record.
  • 7. Scope ● All data controllers in the Bailiwick. ● All personal data. ● Foreign controllers who process data here. ● Focus on privacy. ● There is no Freedom of Information legislation in Guernsey.
  • 8. Personal Data ● Email and other addresses ● Telephone subscriber details ● Credit record ● Banking details ● Employment references ● Criminal convictions ● Biometric data ● Medical data ● CCTV footage ● Records of personal telephone calls ● Recorded expressions of personal opinion ● etc
  • 9. Notification Requirement ● Annual notification unless exempt ● Public register ● Transparency and openness
  • 10. Notification Details ● Contact details ● General purposes of processing ● Types of data subject ● Types of data ● Potential recipients ● Other jurisdictions ● Security measures
  • 12. Data Subject Rights ● Subject access ● Rectification, blocking, erasure and destruction ● To prevent processing likely to cause distress ● To prevent processing for direct marketing purposes ● Compensation ● Automated decision-making ● Request for an assessment
  • 13. Subject Access Requests Individuals are entitled to request a data controller to provide them with - ● a description of any data which is being processed by reference to them ● a description of the purposes for which it is being processed ● a description of any potential recipients of the data ● information as to the source of the data
  • 14. Exemptions ● Public Security ● Investigation of Crime ● Regulatory Activity ● etc
  • 15. Conflict of Subject Rights and Controller Duties • STRs • Third party privacy • etc
  • 17. Objections to Data Processing • Damage or distress • Direct Marketing – Preference Services
  • 18. Other Rights • Rectification, blocking, erasure and destruction • Compensation • Assessments
  • 19. Data controllers: duty to follow good data handling practices • All data controllers must observe the Data Protection Principles • Even if exempt from notification
  • 20. The Data Protection Principles Personal data must be : 1. processed fairly and lawfully 2. obtained for specified and lawful purposes only 3. adequate, relevant and not excessive 4. accurate and kept up to date 5. kept for no longer than is necessary 6. processed in accordance with the rights of data subjects 7. kept secure 8. transferred to third countries only if they ensure an adequate level of data protection
  • 21. First and Second Principles: “Lawful”? ● Breach of Privacy ● Hacking ● Breach of Confidentiality ● Rehabilitation of Offenders ● Theft ● Obtaining by Deception (“Blagging”) ● Unlawful Interception of Communications
  • 22. First and Second Principles: “Fair”? Consider: ● The method by which the data was obtained ● Statutory authority or requirement ● Informed consent Also: ● Is a Schedule 2 condition met? ● Sensitive personal data: Is a Schedule 3 condition met?
  • 23. Quality Standards Third Principle: relevant, adequate and not excessive. Fourth Principle: accurate and kept up to date. Fifth Principle: kept for no longer than is necessary.
  • 24. Sixth Principle: Data Subject Rights ● Subject access rights ● Privacy ● Security
  • 25. Seventh Principle: Security Security Measures – ● Passwords (which should be changed regularly) ● Careful location of computer screens ● Procedures to verify caller identity ● Clear, written data protection procedures ● Making breach of data protection procedures a disciplinary offence ● Use of encryption ● Other technical and operational measures
  • 26. Eighth Principle: Data export • EEA • “Adequate” Countries • Elsewhere •Data Transfer Agreements •Model Clauses
  • 28. The Data Protection Commissioner ● Role ● Enforcement Powers ● Requests for Assessment
  • 29. Offences • Failure to notify • Unauthorised disclosure, selling or obtaining • Failure to comply with a notice • Blagging • Unsolicited communications • Enforced SARs
  • 30. The Commissioner’s Role • Promote good information handling practices • Encourage respect for privacy • Enforce the legislation • Inform and direct policy
  • 31. The Commissioner’s Powers • Limited • Enforcement notices • Encouragement and Education rather than coersion
  • 32. Requests for Assessment • Unverified • Verified • Enforcement Notices • Information Notices and Warrants
  • 33. DATA PROTECTION An Overview of Data Protection Legislation in Guernsey Wednesday, 8 October 2008 Friday, 10 October 2008 Jon Barclay, Advocate Monday, 13 October 2008 AO Hall Advocates