SlideShare uma empresa Scribd logo
1 de 30
Sirius Legal
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Privacy means many different things
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
The right to privacy between individuals
Nosy neighbours
EU Privacy law does not deal with this aspect of privacy
National (civil) law
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
The right to privacy in relationship to the government
NSA
Police
Tax authorities
Specific rules and regulations on international and national level
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Electronic processing of personal data
Electronic processing
Personal data
Usually –but not always- for commercial purposes
EU Data Protection Directive 95/46/EC
E-privacy Directive 2002/58
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New balls, please…
EU Data Protection Directive 95/46/EC
E-privacy Directive 2002/58
Have been around for 20 years
Principles no longer fit economical and technical reality
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New balls, please…
EU is working on new set of rules
Work in progress since 2012
End is not in sight…
Uniform rules based on EU Regulation (as opposed to Directive)
ETA: 2016 - 2017
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Based on EU Regulation
Transferred into national law by each member state
Set of rules dates back to nineties
Based on location of company and/or server
At the time most elaborate and progressive set of rules in the world
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
“Right to privacy” >< data processing
Definition of personal data is very large
ECJ 2015: Even IP address – browser history
Impact on data collection and big data is considerable
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Definition of personal data is very large
Cfr B2B vs B2C
ECJ 2015: Even IP address – browser history –information on
social media – payment history…
Impact on data collection for credit scoring is considerable
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
B2B market: very little impact
B2C market: considerable impact of privacy law
Almost all available data is ‘personal data’
Classic data sources: public data – statistical data – private data
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Almost all available data is ‘personal data’
Classic data sources: public data – statistical data – private data
Fact that data is publicly available does not in itself justify collection & treatment
Cfr: data available online remains “personal” data
Even at first sight “statistical” information can be “personal” data
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Public data Statistical data Private data
Court information Place of residence Payment history
“Kadaster” Age Order history
Social media Diploma Time at which order is usually placed
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Social media & Time at which order is usually placed
Cfr Schufa in Germany (credit rating bureau) uses data found on Facebook ever
since 2012: wrong friends – negative rating
Nightly orders online are considered sign of unemployment – negative rating
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Public data
Beware of limitations under copyright law & database law
Cfr. ECJ decision on Ryanair’s database (ECJ, C-30/14, 15 January 2015)
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Straight and simple:
Basic rule = prior “opt-in” for all processing
Or implicite opt-in if “legitimate grounds” for processing
“Free and informed” opt-in
Transfer of data to third party = additionnal opt-in
Cfr. Analytics tools, apps, cookies, database enrichment through mailings
and actions, …: always opt-in
Cfr. also social media content
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Opt-in
Prior opt-in is exception
Classic “justification” is “legitimate grounds”
Law does not define “legitimate grounds” (Privacy Commission: “cfr CRM”)
Justification for processing = compare interests of processor and data subject
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Transfer of data to third parties
Requires additional opt-in
Essential in credit rating/scoring
Cfr. Evolution towards big data processing
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Who is responsible?
Data controller vs. Data processor
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Who controls data?
Determines opt-in or justification requirements
What is roll of credit score supplier?
Service based on own data vs. Data processing
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Rights of data subjects
opposition – access – correction - information
Obligations of data processor
Information – opt-in – data security – (export)
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New regulation
2016 – 2017
Regulation in stead of Directive
Work in pogress since 2012
Complex procedure in European Institutions
Heavy lobbying
Political slow down
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New regulation
How the EU legislative process works…
2012 Proposal European Commission (Reding)
2012-2015 Parallel track in European Parliament and European Council
2014 Proposal Parliament accepted (Amendements “Michel”)
2015 Parallel proposal Council Work in progress
2016 Both proposals have to be merged into one final text…
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Commission Proposal
Heavily influenced by consumer protection activists in EP
LIBE Committee (protection of civil liberties)
Result:
Consumer friendly, but unrealistic for direct marketing sector, e-commerce
sector and especially credit scoring/rating…
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Commission Proposal
For all services offered in EU (even free services)
Personal data = also online identifiers, “pseudonymous data”
Explicite opt-in always required
Information obligation (icons)
Right not to be submitted to profiling
Warning obligations in case of data breach
“Data protection by design”
“Data protection officer”
Sanctions: LIBE: up to 5% of yearly turnover or 100 million euro
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Council Proposal
Work in progress
Last ammendments made in March 2015
Much more industry focused
Influence of direct marketing (through eg BDMA - FEDMA) is bigger
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Council Proposal
Explicite opt-in
But opt-out or implicite opt-in has been put back in if “legitimate interest”
Next chapters discussed in upcoming months
To be expected:
Lower penalties and less strict obligations
Data protection officers obligation tuned down
Softer rules on profiling prohibition
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
What should you do in the meantime?
Follow up on discussion (eg through our website www.siriuslegal.be)
Start review vendor contracts (in view of data security obligation)
Start to prepare for full update of policies, contracts, business processes
Put in place data breach notification procedure
Appoint (temporary) data security officer
Put in place impact assessment and/or risk analyses policy
Create compliance statements for annual business reports
Train staff
Sit back and wait for final text of regulation for final details…
Media & advertisement law
Copyright - trademarks - datebase - software - knowhow
Travel & consumer protection
Tax & tax planning
IT, Internet & e-commerce
Privacy & cookies
Gambling & gaming
Sirius Legal
www.websitecertifier.be
www.campaignchecker.be
bart@siriuslegal.be
www.siriuslegal.be
@BartVdBrande
Linkedin.com/in/bartvdb
Sirius Legal

Mais conteúdo relacionado

Mais procurados

GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?Frederick Penaud
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection RegulationRamiro Cid
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers networkBart Van Den Brande
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...Exove
 
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...Bart Van Den Brande
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowSophos Benelux
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?VYTIS MALECKAS
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRIT Governance Ltd
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection RegulationSabrina Kirrane
 

Mais procurados (15)

GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers network
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 

Semelhante a Privacy and data protection in credit scoring

CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeersThe CMR Agency
 
Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013Bart Van Den Brande
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
 
20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulationFebelmar
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Bart Van Den Brande
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMARachel Aldighieri
 
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...Michael Fanning
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016bhalasz
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-finalDr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalDr. Donald Macfarlane
 
Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016Bart Van Den Brande
 
UBA legal changes in marketing automation
UBA legal changes in marketing automation UBA legal changes in marketing automation
UBA legal changes in marketing automation Bart Van Den Brande
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection ActYizi
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Lumension
 
Gdpr presentation-february-24t
Gdpr presentation-february-24tGdpr presentation-february-24t
Gdpr presentation-february-24tMark Drinkwater
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015Jan Dhont
 

Semelhante a Privacy and data protection in credit scoring (20)

CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
 
Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
 
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
UBA legal changes in marketing automation
UBA legal changes in marketing automation UBA legal changes in marketing automation
UBA legal changes in marketing automation
 
How to Protect Your Data
How to Protect Your DataHow to Protect Your Data
How to Protect Your Data
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
Day 4 - Meet with BE DPA.pdf
Day 4 - Meet with BE DPA.pdfDay 4 - Meet with BE DPA.pdf
Day 4 - Meet with BE DPA.pdf
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
Gdpr presentation-february-24t
Gdpr presentation-february-24tGdpr presentation-february-24t
Gdpr presentation-february-24t
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
 

Mais de Bart Van Den Brande

20481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 201920481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 2019Bart Van Den Brande
 
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Bart Van Den Brande
 
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...Bart Van Den Brande
 
Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)Bart Van Den Brande
 
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...Bart Van Den Brande
 
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijdenBart Van Den Brande
 
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015Bart Van Den Brande
 
Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015Bart Van Den Brande
 
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015Bart Van Den Brande
 
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...Bart Van Den Brande
 
20140228 Sirius Friday seminarie Privacy & cookies
20140228 Sirius Friday seminarie   Privacy & cookies20140228 Sirius Friday seminarie   Privacy & cookies
20140228 Sirius Friday seminarie Privacy & cookiesBart Van Den Brande
 
Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220Bart Van Den Brande
 
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...Bart Van Den Brande
 
Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra Bart Van Den Brande
 

Mais de Bart Van Den Brande (20)

Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
 
20481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 201920481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 2019
 
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
 
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
 
Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)
 
20160226 ecommerce summit
20160226 ecommerce summit20160226 ecommerce summit
20160226 ecommerce summit
 
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
 
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
 
/Fedipro PowerEvent 27/10/2015
/Fedipro PowerEvent 27/10/2015/Fedipro PowerEvent 27/10/2015
/Fedipro PowerEvent 27/10/2015
 
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
 
Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015
 
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
 
Unizo standaard 2014
Unizo standaard 2014Unizo standaard 2014
Unizo standaard 2014
 
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
 
20140228 Sirius Friday seminarie Privacy & cookies
20140228 Sirius Friday seminarie   Privacy & cookies20140228 Sirius Friday seminarie   Privacy & cookies
20140228 Sirius Friday seminarie Privacy & cookies
 
Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220
 
Safe shops.be 20140205
Safe shops.be 20140205Safe shops.be 20140205
Safe shops.be 20140205
 
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
 
Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra
 
Fot 2011 powerpoint
Fot 2011 powerpointFot 2011 powerpoint
Fot 2011 powerpoint
 

Último

BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdflaysamaeguardiano
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdfSUSHMITAPOTHAL
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULEsreeramsaipranitha
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书Fs Las
 
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in IndiaLegal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in IndiaFinlaw Consultancy Pvt Ltd
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881mayurchatre90
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhaiShashankKumar441258
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxRRR Chambers
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxRRR Chambers
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionAnuragMishra811030
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx2020000445musaib
 
Debt Collection in India - General Procedure
Debt Collection in India  - General ProcedureDebt Collection in India  - General Procedure
Debt Collection in India - General ProcedureBridgeWest.eu
 
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxMunicipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxSHIVAMGUPTA671167
 

Último (20)

BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
 
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
如何办理(SFSta文凭证书)美国旧金山州立大学毕业证学位证书
 
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in IndiaLegal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
Debt Collection in India - General Procedure
Debt Collection in India  - General ProcedureDebt Collection in India  - General Procedure
Debt Collection in India - General Procedure
 
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxMunicipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
 

Privacy and data protection in credit scoring

  • 1. Sirius Legal Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015
  • 2. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Privacy means many different things
  • 3. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 The right to privacy between individuals Nosy neighbours EU Privacy law does not deal with this aspect of privacy National (civil) law
  • 4. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 The right to privacy in relationship to the government NSA Police Tax authorities Specific rules and regulations on international and national level
  • 5. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Electronic processing of personal data Electronic processing Personal data Usually –but not always- for commercial purposes EU Data Protection Directive 95/46/EC E-privacy Directive 2002/58
  • 6. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New balls, please… EU Data Protection Directive 95/46/EC E-privacy Directive 2002/58 Have been around for 20 years Principles no longer fit economical and technical reality
  • 7. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New balls, please… EU is working on new set of rules Work in progress since 2012 End is not in sight… Uniform rules based on EU Regulation (as opposed to Directive) ETA: 2016 - 2017
  • 8. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Based on EU Regulation Transferred into national law by each member state Set of rules dates back to nineties Based on location of company and/or server At the time most elaborate and progressive set of rules in the world
  • 9. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law “Right to privacy” >< data processing Definition of personal data is very large ECJ 2015: Even IP address – browser history Impact on data collection and big data is considerable
  • 10. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Definition of personal data is very large Cfr B2B vs B2C ECJ 2015: Even IP address – browser history –information on social media – payment history… Impact on data collection for credit scoring is considerable
  • 11. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring B2B market: very little impact B2C market: considerable impact of privacy law Almost all available data is ‘personal data’ Classic data sources: public data – statistical data – private data
  • 12. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Almost all available data is ‘personal data’ Classic data sources: public data – statistical data – private data Fact that data is publicly available does not in itself justify collection & treatment Cfr: data available online remains “personal” data Even at first sight “statistical” information can be “personal” data
  • 13. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Public data Statistical data Private data Court information Place of residence Payment history “Kadaster” Age Order history Social media Diploma Time at which order is usually placed
  • 14. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Social media & Time at which order is usually placed Cfr Schufa in Germany (credit rating bureau) uses data found on Facebook ever since 2012: wrong friends – negative rating Nightly orders online are considered sign of unemployment – negative rating
  • 15. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Public data Beware of limitations under copyright law & database law Cfr. ECJ decision on Ryanair’s database (ECJ, C-30/14, 15 January 2015)
  • 16. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Straight and simple: Basic rule = prior “opt-in” for all processing Or implicite opt-in if “legitimate grounds” for processing “Free and informed” opt-in Transfer of data to third party = additionnal opt-in Cfr. Analytics tools, apps, cookies, database enrichment through mailings and actions, …: always opt-in Cfr. also social media content
  • 17. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Opt-in Prior opt-in is exception Classic “justification” is “legitimate grounds” Law does not define “legitimate grounds” (Privacy Commission: “cfr CRM”) Justification for processing = compare interests of processor and data subject
  • 18. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Transfer of data to third parties Requires additional opt-in Essential in credit rating/scoring Cfr. Evolution towards big data processing
  • 19. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Who is responsible? Data controller vs. Data processor
  • 20. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Who controls data? Determines opt-in or justification requirements What is roll of credit score supplier? Service based on own data vs. Data processing
  • 21. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Rights of data subjects opposition – access – correction - information Obligations of data processor Information – opt-in – data security – (export)
  • 22. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New regulation 2016 – 2017 Regulation in stead of Directive Work in pogress since 2012 Complex procedure in European Institutions Heavy lobbying Political slow down
  • 23. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New regulation How the EU legislative process works… 2012 Proposal European Commission (Reding) 2012-2015 Parallel track in European Parliament and European Council 2014 Proposal Parliament accepted (Amendements “Michel”) 2015 Parallel proposal Council Work in progress 2016 Both proposals have to be merged into one final text…
  • 24. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Commission Proposal Heavily influenced by consumer protection activists in EP LIBE Committee (protection of civil liberties) Result: Consumer friendly, but unrealistic for direct marketing sector, e-commerce sector and especially credit scoring/rating…
  • 25. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Commission Proposal For all services offered in EU (even free services) Personal data = also online identifiers, “pseudonymous data” Explicite opt-in always required Information obligation (icons) Right not to be submitted to profiling Warning obligations in case of data breach “Data protection by design” “Data protection officer” Sanctions: LIBE: up to 5% of yearly turnover or 100 million euro
  • 26. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Council Proposal Work in progress Last ammendments made in March 2015 Much more industry focused Influence of direct marketing (through eg BDMA - FEDMA) is bigger
  • 27. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Council Proposal Explicite opt-in But opt-out or implicite opt-in has been put back in if “legitimate interest” Next chapters discussed in upcoming months To be expected: Lower penalties and less strict obligations Data protection officers obligation tuned down Softer rules on profiling prohibition
  • 28. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 What should you do in the meantime? Follow up on discussion (eg through our website www.siriuslegal.be) Start review vendor contracts (in view of data security obligation) Start to prepare for full update of policies, contracts, business processes Put in place data breach notification procedure Appoint (temporary) data security officer Put in place impact assessment and/or risk analyses policy Create compliance statements for annual business reports Train staff Sit back and wait for final text of regulation for final details…
  • 29. Media & advertisement law Copyright - trademarks - datebase - software - knowhow Travel & consumer protection Tax & tax planning IT, Internet & e-commerce Privacy & cookies Gambling & gaming Sirius Legal