The Changing Nature of Privacy 22 August 2018 1 Introduction - - PowerPoint PPT Presentation

the changing nature of privacy
SMART_READER_LITE
LIVE PREVIEW

The Changing Nature of Privacy 22 August 2018 1 Introduction - - PowerPoint PPT Presentation

The Changing Nature of Privacy 22 August 2018 1 Introduction Speaker: Juan-Jacques Jordaan Attorney BComm LLB (UKZN) juan@fpattorneysinc.co.za / 083 777 6893 2 Introduction 3 Privacy from your personal perspective 4 Privacy as a


slide-1
SLIDE 1

1

The Changing Nature of Privacy

22 August 2018

slide-2
SLIDE 2

2

Introduction

Speaker: Juan-Jacques Jordaan Attorney BComm LLB (UKZN) juan@fpattorneysinc.co.za / 083 777 6893

slide-3
SLIDE 3

3

Introduction

slide-4
SLIDE 4

4

Privacy from your personal perspective

slide-5
SLIDE 5

5

Privacy as a Concept

the right to be let alone the option to conceal any information from others self-identity and personal growth

the option to limit the access others have to one's personal information

control over others' use of information about oneself states of privacy (solitude, anonymity etc.)

slide-6
SLIDE 6

6

Current Law

  • Privacy Foundation in South Africa
  • The Constitution of the Republic of South Africa provides the following in section 14 of

the Bill of Rights: Privacy: Everyone has the right to privacy, which includes the right to not have: - (a) their possessions or home searched; (b) their property searched; (c) their possessions seized; or (d) the privacy of their communication infringed. These basic rights set out the foundation of the right to privacy in South Africa.

slide-7
SLIDE 7

7

Current Law

ECTA CPA RICA NCA

POPIA

slide-8
SLIDE 8

8

Protection of Personal Information Act

  • POPIA gives greater effect to the section 14 right to privacy contained in the Constitution

Promote protection of PI (Public & Private) Minimum Requirements for processing Information Regulator Codes of Conduct Unsolicited Communications and Automated Decision Making Cross-border transfers

slide-9
SLIDE 9

9

Data Protection Laws Globally

Source: CNIL https://www.cnil.fr/en/data-protection-around-the-world
slide-10
SLIDE 10

10

European Union

  • OECD → EU Data Protection Directive 95/46/EC (has been replaced)
  • GDPR has gone live
  • Now you have to ensure that you are looking after your EU data subject’s rights
  • Article 3 of the GDPR provides for extraterritoriality provisions in its application
  • GDPR → General Data Protection Regulation (effective 25 May 2018)
  • Single set of rules applicable to all EU member states (independent Supervisory Authority)
  • Right to question / fight decisions made automatically
  • DPO
slide-11
SLIDE 11

11

Trans-border Information Flows

slide-12
SLIDE 12

12

Personal information in different shapes

slide-13
SLIDE 13

13

Value of Data

01001101011110010010000001101110011000010110110101100101001000000110100101110011001 00000010010100111010101100001011011100010110000100000010010010010000001110111011000 01011100110010000001100010011011110111001001101110001000000110001001100101011101000 11101110110010101100101011011100010000000110001001110010011100000110000001000000110 00010110111001100100001000000011000100111001001110010011000000100000011000010110111 00110010000100000010010010010000001100001011011010010000001100001011011100010000001 10000101110100011101000110111101110010011011100110010101111001001000000110000101101 11001100100001000000100100100100000011011000110100101110110011001010010000001101001 01101110001000000101001101101111011101010111010001101000001000000100000101100110011 10010011010010110001101100001001000000110000101101110011001000010000001001001001000 00011001000111001001101001011101100110010100100000011101000110100001100101001000000 10011100011001000100000011101000110111100100000011101110110111101110010011010110010 00000110010101110110011001010111001001111001001000000110010001100001011110010000101

slide-14
SLIDE 14

14

Value of Information

My name is Juan, I was born between 1980 and 1990 and I am an attorney and I live in South Africa and I drive the N2 to work every day

slide-15
SLIDE 15

15

Value of Knowledge Subject Information: Name: Juan Occupation: Attorney Location: South Africa Age: 28 – 38 Commute: N2

slide-16
SLIDE 16

16

Value of Wisdom

Governments Companies Criminals Marketers

slide-17
SLIDE 17

17

DIKW Hierarchy

Data

Information

Knowledge

WISDOM

Source:

  • R. Ackoff
slide-18
SLIDE 18

18

We Love Data

slide-19
SLIDE 19

19

Value of Data

slide-20
SLIDE 20

20

But What About Data Protection?

Terms

  • f use

Terms of service Data use policy End user agreement

POPIA Compliant Meet GDPR Requirements

slide-21
SLIDE 21

21

We Are All Liars

  • “I have read and agree to the terms”

tosdr.org

“I have read”

slide-22
SLIDE 22

22

The Lie We Tell

TERMS OF SERVICE

✓ I totally read all that and I wholeheartedly agree!!!

slide-23
SLIDE 23

23

We (are beginning to) Hate Data

  • Struggling to keep personal data private
  • Hacking
  • Phishing
  • Data Loss
  • Surveillance
  • For every bit of information received, there was an opposite request sent
  • PRISM (Snowden)
  • SPAM
slide-24
SLIDE 24

24

Privacy from your business perspective

slide-25
SLIDE 25

25

Application of POPIA to Businesses

  • Every business processes Personal Information

Customer Employee Vendor 3rd Party

Security

Collection Processing Distribution Archiving Destruction

slide-26
SLIDE 26

26

Application of POPIA to Businesses

What?

  • Information is

needed?

  • Information is

collected?

  • Purpose?
  • Protections are

in place?

  • Are your
  • bligations?
  • Do we do with

the information? How?

  • Do you collect

information?

  • Is the

information processed?

  • Do our

employees treat information?

  • Do we store the

information?

  • Do we ensure

compliance? Who?

  • Is responsible

for the information?

  • Do we share the

information with?

slide-27
SLIDE 27

27

Information Your Business Holds

  • Race, gender, pregnancy, marital status, national, ethnic or social origin,

age, physical or mental health, disability, religious, language, birth

  • Education, medical, financial, criminal or employment history
  • Identifying numbers, symbols, email addresses, physical addresses,

telephone numbers, biometric information

  • Correspondence sent by the person that is implicitly or explicitly private or

confidential

slide-28
SLIDE 28

28

Information Your Business Holds

  • The huge amount of data or information within your business:
  • Identifies opportunities
  • Drives innovation
  • Leverages strengths
  • Mitigates risk
  • Streamlines processes
  • Valuable asset that needs to be protected at all costs
slide-29
SLIDE 29

29

So Why Are We Intimidated By Data Protection Laws?

  • Penalties

Business Lens We ignore the fact that you and I as we sit here are all data subjects

  • Unnecessary
  • Compliance Costs
slide-30
SLIDE 30

30

How Compliance Assists Your Business

  • Data Subjects Right to Privacy
  • Better control of your own data
  • Better access to your data
  • License to use
  • Prepared for data subject access requests
  • Efficiency
  • Easier processes simplifies and streamlines business
  • Better understanding of applicable laws
  • Greater uses for the data
  • Algorithms can be used to improve services or products
  • Automated decision making
slide-31
SLIDE 31

31

How Compliance Assists Your Business

  • Quality of Data
  • Up to date data
  • Greater knowledge of financial position
  • Breach notification
  • Accurate view of customer base
  • Clear understanding of the types of data you need and use
slide-32
SLIDE 32

32

How Compliance Assists Your Business

  • Clients
  • Consent management
  • Enhanced privacy builds customer loyalty and trust
  • More engaged clients
  • Improved client satisfaction
  • Improved brand perception
  • Batter marketing practices with targeted messages
  • Transparency
  • Say what you do, and do what you say
  • Intended purpose
  • Storage periods
  • Right to access
  • Disclosure
slide-33
SLIDE 33

33

How Compliance Assists Your Business

  • Security
  • Stronger measures in place to protect your data
  • Accountability to users of data
  • SPAM
  • Prevention and limitation of SPAM
  • Not being a spammer
  • Cyber Crime
  • Handling incidents in a controlled and prepared manner
  • Prevention
slide-34
SLIDE 34

34

European Union

  • OECD → EU Data Protection Directive 95/46/EC (has been replaced)
  • GDPR has gone live
  • Now you have to ensure that you are looking after your EU data subject’s rights
  • Article 3 of the GDPR provides for extraterritoriality provisions in its application
  • GDPR → General Data Protection Regulation (effective 25 May 2018)
  • Single set of rules applicable to all EU member states (independent Supervisory Authority)
  • Right to question / fight decisions made automatically
  • DPO
  • Applies to South African data processors / companies if you:
  • process the personal information of EU residents
  • if you offer those EU residents goods or services; or
  • if you monitor the behaviour of EU residents
slide-35
SLIDE 35

35

Avoiding Risk

  • Process data in ways that are consistent with the

purpose for collection

  • Limit access to data containing personal information
  • Communicate data subject rights, purpose,

retention, cross-border transfers etc.

  • Contacts for policy or other privacy related issues
  • Ensure technological measures are in place to

mitigate risks

  • Evaluate vulnerabilities
  • Allow data subjects access and control of their data
slide-36
SLIDE 36

36

Data Privacy Scare Factor

slide-37
SLIDE 37

37

Breaches

  • Security
  • SA data breaches doubled in 2016

83 million users name, address, phone number and email address

145 million user details compromised Passwords, email addresses, birth dates, mailing addresses and

  • ther personal

information

45 million credit and debit card records 500 million user email accounts Foreign state 145 million U.S. customers data stolen

60 million ID numbers and other data

SA Master Deeds

slide-38
SLIDE 38

38

Breaches

slide-39
SLIDE 39

39

Check your status

https://haveibeenpwned.com/

slide-40
SLIDE 40

40

Information Privacy Officer

  • Delegation
  • Mandatory
  • CEO if not delegated
  • Responsible for all POPIA relevant issues

Information Privacy Officer

Compliance Training Responsibility

slide-41
SLIDE 41

Thank you.

41

juan@fpattorneysinc.co.za

https://www.linkedin.com/in/juanjacquesjordaan/