General Flashcards
Universal Declaration of Human Right - Right to private life
Article 12
Universal Declaration of Human Right - Freedom of Expression
Article 19
Universal Declaration of Human Right - Individual Rights are not absolute, and there are instances where a balance must be struck
Article 29
European Convention of Human Rights - When enacted?
Rome 1950
European Convention of Human Rights - Rights under the convention?
- right to life;
- prohibition of torture;
- prohibition of slavery and forced labour;
- right to liberty and security;
- right to a fair trial;
- no punishment without law;
- respect for private and family life;
- freedom of thought,
- conscience and religion;
- freedom of expression;
- freedom of assembly and association;
- right to marry;
- right to an effective remedy; an
- prohibition of discrimination.
European Convention of Human Rights - which article protects the tights of individuals for their personal information to remain private?
Article 8
European Convention of Human Rights - which article protects the right to freedom of expression?
Article 10
Early Laws and Regulations
1968 - recomendation 509 on human rights and modern scientific and technological developments
1973 - Resolutions 73/22 and 74/29 - principles for the protection of personal data in automated data banks.
1980s - OECD Guidelines on the protection of privacy and transborder flows of personal data
1981 - Convention 108 (The Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data) (first binding international instrument to set standards for the protection of individuals’ personal data)
Convention 108+
Data Protection Directive
Charter of Fundamental Rights
Lisbon Treaty
OECD Guidelines s on the Protection of Privacy and Transborder Flows of Personal Data - what are the principles introduced?
1) Collection limitation principle
2) data quality principle
3) purpose specification principle
4) use limitation principle
5) security safeguard principle
6) openness principle
7) individual participation principle
8) accountability principle
Convention 108 Principles
1) Fairly and lawfully
2) Adecuate, relavant and not excessive
3) Accurate and up to date
4) appropriate security measures
5) sets a definition for “Special categories of Data”
6) sets rights of communication, rectification and erasure
7) transfer between signatories: “countries shall not imposeany prohibitions or require any special authorisations for the purpose of the
protection of privacy before such transfers can take place”
8) Derogation from the provisions is permitted only where the exporting country hasin place specific rules in its national law for certain categories of personal data or ofa utomated personal data files and the importing country does not providee quivalent protection or where the transfer is to a country that is not a party to Convention 108.
The solution to this was the introduction of the concept (imported from the EU’s 1995 Data Protection Directive)11 of an adequate’ rather than an equivalent level of protection for personal information transferred to states falling outside the jurisdiction of the exporting party, subject to exceptions where the transfer is made in the legitimate interests of the individual, is in the public interest, or is based on contractual clauses approved by the supervisory authority.
9) Mutual assistance (supervisory authority)
Convention 108+
2018 - final protocol amending approved.
objective - introduce harmonized approach to to data protection on the basis of international agreement on principles - implementation left to member states.
Data Protection Directive (95/46/EC)
leaves implementation to member states
principles of convention 108 as benchmark
problem - differences of implementation between member states, creating difficulties for businesses to take full advantage of the benefits of the internal market.
Charter of Fundamental Rights
Processing must be fair processing must be carried for specific purposes must be a legitimate basis Rights to access and rectification must establish supervisory authority
Treaty of Lisbon
2007
General Data Protection Regulation (GDPR)
enforceable 25 May 2018