SlideShare uma empresa Scribd logo
1 de 16
Baixar para ler offline
Personal Data Protection in Russia


Anastasiya Lemysh
Vsevolod Tyupa
7 December 2011

07/12/2011
Webinar schedule


I.   Legal framework for personal data protection in Russia


II. Personal data protection in the medicine field
Legal acts regulating personal data protection

 Constitution of the Russian Federation;

 Federal Law No. 152- FZ “On personal data”;

 Labour Code;

 Code for administrative offences;

 Federal Law No. 149 – FZ “On information, information technologies
  and protection of information;

 Resolutions of the Government;

 Acts issued by specialised ministries and services.
Definition of the term ‘personal data’
Personal data are any information relating to a directly or indirectly
identified or identifiable individual ("data subject").
This definition is in line with the Strasbourg Convention of 1981
     Text, graphic,
    biometrical, photo,                        May be identified with
   acoustic, digital …                      the use of accessible means




          Any                    relating
      information
The principles of personal data processing (1)

1. Legality and fairness
   “Processing personal data should be performed on a legal and fair basis.”
2. Purpose
   “Personal data processing should be limited to achieving specific
    purposes that should be specified preliminarily and be legal. It is
    prohibited to process personal data in a way that is not consistent with
    the purposes for which personal the data were collected”.
   “The content and scope of processed personal data have to comply with
    the purposes of processing personal data. Personal data that are
    processed must not be excessive with regard to the declared purposes of
    their processing.”
The principles for personal data processing (2)

3. Proportionality
   “Only data that correspond to the purposes of their processing should be
    processed .”
4. Data quality
   “(…) it is necessary to ensure that personal data are accurate, sufficient,
    and, if necessary, up-to-date in relation to the purposes of processing
    personal data.”
5. Term of processing
   “Personal data must not be stored longer than it is necessary for the
    purposes of personal data processing”
  (NB. A timeframe to process personal data may be also provided by the law
  or by an agreement with the data subject.)
Legal grounds for personal data processing

                                  Processing
                                 personal data

        upon consent                              without the consent of
      of the data subject                            the data subject


         form of consent

                                                   only in cases directly
 qualified form of consent:   any form proving      provided by the law
 For special categories of
 personal data, biometrical
                              that the consent
personal data, cross border   was duly obtained
  transfer of personal data
Processing personal data without the consent of
the data subject (1)

1. Requirements of the laws:
   Achievement of purposes provided by :
     international treaty signed by the Russian Federation;
     the Russian law;
   Execution by the operator of the obligations or functions provided by the
    law;
2. Execution of justice, and execution of the act of the court;
Processing personal data without the consent of
the data subject (2)
3. Providing state or municipal services;
4. Contract relations:
   execution of a contract:
     the data subject is a party, a beneficiary
    or a guarantor under the contract;
   signing of a contract:
     upon the initiative of the data subject;
     If the data subject is a beneficiary
    or guarantor under the contract;
5. Protection of life, health or other vital interests of the data
   subject, if it is impossible to obtain his/her consent;
Processing personal data without the consent of
the data subject (3)

6. Legal interests and socially important purposes:
   protecting the rights and legal interests of the operator and third parties;
   achieving socially important purposes;
  Condition: rights and freedoms of the data subject are not violated;
7. Particular types of activities:
   journalist or other legal activity of mass media;
   scientific work;
   literature (activity of writer);
   other creative activity;
  Condition: rights and interests of the data subject are not violated;
Processing personal data without the consent of
the data subject (4)

8. Statistics or other research purposes
  • Except for for promoting goods and services and political agitation;
  • Condition: mandatory depersonalisation of personal data;


9. If public access to personal data is
 provided by the data subject at his/her
request;
10. Processing personal data that should be made public under
    the law;
Obligations of a personal data operator

 Inform the Personal Data Authority of its intent to process
  personal data (must be done prior to processing of personal
  data). Exceptions: cases provided by the law;


 Do not disclose information to third persons without the
  consent of the data subject;


 Bear the burden of proof for obtaining the consent of a data
  subject;
Protection of employees’ personal data
 Purposes of processing employees’ personal data:
     compliance with the provisions of the law;
     recruitment;
     promotion;
     education;
     personal safety;
     control of work quality.
 Obligations of the employer:
     to ensure the confidentiality of personal data;
     not to disclose personal data without the consent of the employee.
The specifics of processing personal data in the
medicine field


1. Patients’ and doctors’ personal databases established by new
Russian Federal Law on Healthcare, dated 23 November 2011;


2. Processing of medical professionals’ personal data by the
pharmaceutical companies;


3. “Medical secrecy”
Personal data protection within clinical trials

The personal data of clinical trials patients are a “specific” type of
personal data because of information on the state of health.


The main legal issues are:
 Patient’s information list ;
 Transferring personal data to the Sponsor and its affiliates;
 Cross-border transfer of personal data in the case of international multi-
  centre clinical trials.
Thank you for your attention!

    CMS, Russia
    Gogolevsky Blvd. 11, 119019 Moscow
    +7(495) 786 4000

    Vsevolod Tyupa, Senior Associate
    Vsevolod.Tyupa@cmslegal.ru
    +7 (495) 786 4097

    Anastasiya Lemysh, Associate, Avocat à la Cour
    Anastasiya.Lemysh@cmslegal.ru
    +7 (495) 786 3076




Защита персональных данных: согласие, обработка, трансграничная передача. 30 ноября 2011   16

Mais conteúdo relacionado

Mais procurados

Mais procurados (19)

Data Privacy Act of 2012 implication to cooperatives
Data Privacy Act of 2012 implication to cooperativesData Privacy Act of 2012 implication to cooperatives
Data Privacy Act of 2012 implication to cooperatives
 
Memorandum on Protection of Personal Data
Memorandum on Protection of Personal DataMemorandum on Protection of Personal Data
Memorandum on Protection of Personal Data
 
Processing of Personal Data. What’s new?
Processing of Personal Data. What’s new?Processing of Personal Data. What’s new?
Processing of Personal Data. What’s new?
 
Basic Data Privacy for Non Lawyers
Basic Data Privacy for Non LawyersBasic Data Privacy for Non Lawyers
Basic Data Privacy for Non Lawyers
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection Law
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal Information
 
GDPR compliance process and maturity/readiness assessment checklist
GDPR compliance process and maturity/readiness assessment checklistGDPR compliance process and maturity/readiness assessment checklist
GDPR compliance process and maturity/readiness assessment checklist
 
Bmc pio by shailesh gandhi
Bmc pio by shailesh gandhiBmc pio by shailesh gandhi
Bmc pio by shailesh gandhi
 
Rti beginners 5 nov '12 by shailesh gandhi
Rti  beginners 5 nov '12 by shailesh gandhiRti  beginners 5 nov '12 by shailesh gandhi
Rti beginners 5 nov '12 by shailesh gandhi
 
Data Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectData Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data Subject
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
Right to Access Information in Tunisia: Citizens' Guide
Right to Access Information in Tunisia: Citizens' GuideRight to Access Information in Tunisia: Citizens' Guide
Right to Access Information in Tunisia: Citizens' Guide
 
Data Privacy - Security of Personal Information
Data Privacy - Security of Personal InformationData Privacy - Security of Personal Information
Data Privacy - Security of Personal Information
 
Data Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-ComplianceData Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-Compliance
 
Note on data protection
Note on data protectionNote on data protection
Note on data protection
 
An analysis of george h cohen official statement in response to washington ex...
An analysis of george h cohen official statement in response to washington ex...An analysis of george h cohen official statement in response to washington ex...
An analysis of george h cohen official statement in response to washington ex...
 
Duites and Responsibilities of Public Information Officer under the Right To ...
Duites and Responsibilities of Public Information Officer under the Right To ...Duites and Responsibilities of Public Information Officer under the Right To ...
Duites and Responsibilities of Public Information Officer under the Right To ...
 
GDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, NottinghamGDPR for public sector DPO's, April 2018, Nottingham
GDPR for public sector DPO's, April 2018, Nottingham
 
DPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, BirminghamDPOs in the public sector, May 2018, Birmingham
DPOs in the public sector, May 2018, Birmingham
 

Semelhante a Personal Data Protection in Pharmaceutical Sector (webinar presentation)

M.Marusic Dzlp E Society En
M.Marusic Dzlp E Society EnM.Marusic Dzlp E Society En
M.Marusic Dzlp E Society En
Metamorphosis
 

Semelhante a Personal Data Protection in Pharmaceutical Sector (webinar presentation) (20)

China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPR
 
Hexagon presentation light.pptx
Hexagon presentation light.pptxHexagon presentation light.pptx
Hexagon presentation light.pptx
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptxDATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
EFA Skillshare - Jitty van Doodewaerd
EFA Skillshare - Jitty van DoodewaerdEFA Skillshare - Jitty van Doodewaerd
EFA Skillshare - Jitty van Doodewaerd
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal Data
 
Indonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfIndonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdf
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
 
Right to privacy on internet and Data Protection
Right to privacy on internet and Data ProtectionRight to privacy on internet and Data Protection
Right to privacy on internet and Data Protection
 
GDPR Presentation
GDPR PresentationGDPR Presentation
GDPR Presentation
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOWNEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
 
M.Marusic Dzlp E Society En
M.Marusic Dzlp E Society EnM.Marusic Dzlp E Society En
M.Marusic Dzlp E Society En
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 

Último

Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
lizamodels9
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
amitlee9823
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Matteo Carbone
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
lizamodels9
 

Último (20)

The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 

Personal Data Protection in Pharmaceutical Sector (webinar presentation)

  • 1. Personal Data Protection in Russia Anastasiya Lemysh Vsevolod Tyupa 7 December 2011 07/12/2011
  • 2. Webinar schedule I. Legal framework for personal data protection in Russia II. Personal data protection in the medicine field
  • 3. Legal acts regulating personal data protection  Constitution of the Russian Federation;  Federal Law No. 152- FZ “On personal data”;  Labour Code;  Code for administrative offences;  Federal Law No. 149 – FZ “On information, information technologies and protection of information;  Resolutions of the Government;  Acts issued by specialised ministries and services.
  • 4. Definition of the term ‘personal data’ Personal data are any information relating to a directly or indirectly identified or identifiable individual ("data subject"). This definition is in line with the Strasbourg Convention of 1981 Text, graphic, biometrical, photo, May be identified with acoustic, digital … the use of accessible means Any relating information
  • 5. The principles of personal data processing (1) 1. Legality and fairness  “Processing personal data should be performed on a legal and fair basis.” 2. Purpose  “Personal data processing should be limited to achieving specific purposes that should be specified preliminarily and be legal. It is prohibited to process personal data in a way that is not consistent with the purposes for which personal the data were collected”.  “The content and scope of processed personal data have to comply with the purposes of processing personal data. Personal data that are processed must not be excessive with regard to the declared purposes of their processing.”
  • 6. The principles for personal data processing (2) 3. Proportionality  “Only data that correspond to the purposes of their processing should be processed .” 4. Data quality  “(…) it is necessary to ensure that personal data are accurate, sufficient, and, if necessary, up-to-date in relation to the purposes of processing personal data.” 5. Term of processing  “Personal data must not be stored longer than it is necessary for the purposes of personal data processing” (NB. A timeframe to process personal data may be also provided by the law or by an agreement with the data subject.)
  • 7. Legal grounds for personal data processing Processing personal data upon consent without the consent of of the data subject the data subject form of consent only in cases directly qualified form of consent: any form proving provided by the law For special categories of personal data, biometrical that the consent personal data, cross border was duly obtained transfer of personal data
  • 8. Processing personal data without the consent of the data subject (1) 1. Requirements of the laws:  Achievement of purposes provided by :  international treaty signed by the Russian Federation;  the Russian law;  Execution by the operator of the obligations or functions provided by the law; 2. Execution of justice, and execution of the act of the court;
  • 9. Processing personal data without the consent of the data subject (2) 3. Providing state or municipal services; 4. Contract relations:  execution of a contract:  the data subject is a party, a beneficiary or a guarantor under the contract;  signing of a contract:  upon the initiative of the data subject;  If the data subject is a beneficiary or guarantor under the contract; 5. Protection of life, health or other vital interests of the data subject, if it is impossible to obtain his/her consent;
  • 10. Processing personal data without the consent of the data subject (3) 6. Legal interests and socially important purposes:  protecting the rights and legal interests of the operator and third parties;  achieving socially important purposes; Condition: rights and freedoms of the data subject are not violated; 7. Particular types of activities:  journalist or other legal activity of mass media;  scientific work;  literature (activity of writer);  other creative activity; Condition: rights and interests of the data subject are not violated;
  • 11. Processing personal data without the consent of the data subject (4) 8. Statistics or other research purposes • Except for for promoting goods and services and political agitation; • Condition: mandatory depersonalisation of personal data; 9. If public access to personal data is provided by the data subject at his/her request; 10. Processing personal data that should be made public under the law;
  • 12. Obligations of a personal data operator  Inform the Personal Data Authority of its intent to process personal data (must be done prior to processing of personal data). Exceptions: cases provided by the law;  Do not disclose information to third persons without the consent of the data subject;  Bear the burden of proof for obtaining the consent of a data subject;
  • 13. Protection of employees’ personal data  Purposes of processing employees’ personal data:  compliance with the provisions of the law;  recruitment;  promotion;  education;  personal safety;  control of work quality.  Obligations of the employer:  to ensure the confidentiality of personal data;  not to disclose personal data without the consent of the employee.
  • 14. The specifics of processing personal data in the medicine field 1. Patients’ and doctors’ personal databases established by new Russian Federal Law on Healthcare, dated 23 November 2011; 2. Processing of medical professionals’ personal data by the pharmaceutical companies; 3. “Medical secrecy”
  • 15. Personal data protection within clinical trials The personal data of clinical trials patients are a “specific” type of personal data because of information on the state of health. The main legal issues are:  Patient’s information list ;  Transferring personal data to the Sponsor and its affiliates;  Cross-border transfer of personal data in the case of international multi- centre clinical trials.
  • 16. Thank you for your attention! CMS, Russia Gogolevsky Blvd. 11, 119019 Moscow +7(495) 786 4000 Vsevolod Tyupa, Senior Associate Vsevolod.Tyupa@cmslegal.ru +7 (495) 786 4097 Anastasiya Lemysh, Associate, Avocat à la Cour Anastasiya.Lemysh@cmslegal.ru +7 (495) 786 3076 Защита персональных данных: согласие, обработка, трансграничная передача. 30 ноября 2011 16