SlideShare a Scribd company logo
1 of 2
Download to read offline
DATA PROTECTION LEADER12
Obtaining consent
Recent cases investigated by SIC have
involved Colombian companies that
were accused of using personal data
to send direct marketing without first
obtaining the consent of data subjects
to process their data for such purposes.
Some companies used an opt-out
method rather than an opt-in method to
legalise their use of the personal data
they collected. However, Colombian law
prohibits the use of opt-out methods.
In the abovementioned cases, the
data subjects did not know about the
collection and use of their information
until they received marketing
communications from the companies.
Other investigated companies were
not able to provide any evidence
to support their claims that data
subjects had accepted the use of their
information for multiple purposes. Under
Colombian law, when the personal
data is collected for multiple purposes,
consent is required for each use and
must involve a clear affirmative action.
The cases
In the matter of SuperGiros S.A.S, SIC
found that the company, which provides
money transfer services, committed
unfair and deceptive acts when
collecting and using personal data for
multiple purposes. SuperGiros did not
obtain the informed consent of data
subjects, that is to say, data subjects did
not know that their personal information
would be used for purposes other than
the simple money transfer operation
they had ordered. SIC considered
such practices unfair and deceptive
under Article 4 of Decree 1377 of 2013
(June 27) Which Partially Regulates
Law 1581 of 2012 (‘the Decree’).
SIC stressed, ‘Consequently, SIC
has found that SuperGiros had been
undertaking deceptive practices through
its consent model, which had the goal
of inducing its clients to provide their
data to be used for purposes other than
those necessary in the ordinary course
of its business without the informed
knowledge of those clients. The model
even included the possibility of sharing
personal data with third parties.’
According to Article 12 of the Data
Protection Law, data subjects must
be informed, at a minimum, about:
• the identity of the controller;
• the intended purposes of the processing
of the provided personal data;
• the optional nature of the answer
given to the questions asked, when
they pertain to sensitive personal data
or to the personal data of children;
• the rights of information, access
and rectification or erasure of
their data, as well as the rights to
withdraw consent at any time and/
or to object to any processing; and
• the contact details of the
controller so that data subjects
may exercise their rights.
In addition, in the matter of Bilingual
School Clermont Ltda., SIC found
that the school collected and
maintained, among other categories
Complying with Colombian
data protection law: a
guide to consent
The main pillar of Statutory Law 1581 of 2012 (October 17) Which Issues General Provisions for the
Protection of Personal Data (‘the Data Protection Law’) is the requirement for data controllers to
obtain consent from data subjects to lawfully process their personal data. However, the Colombian
data protection authority (‘SIC’) has been faced with many cases of controllers not complying with
this obligation. Luis Alberto Montezuma Chavez, Privacy and Data Protection Specialist, outlines
SIC’s investigations into data subjects’ complaints, and the reasoning behind its imposition of
fines, in order to help organisations comply with the Data Protection Law’s requirements.
Luis Alberto Montezuma Chavez Privacy and Data Protection Specialist
luismontezumachavez@gmail.com
Bogotá
COLOMBIA
image: busypix / E+ / Getty Images
A Cecile Park Media Publication | November 2017 13
of data, children’s personal information
without explicit parental consent.
In this case, SIC highlighted, ‘[N]ot
only did the school use personal data
without obtaining the express and
informed consent of data subjects prior
to the processing, but also within that
group there were subjects with special
constitutional protection such as children.’
Under Article 12 of the Decree, collecting
information from children is lawful only if,
and to the extent that, consent is given by
their parents or guardians. Moreover, as
per Article 7 of the Data Protection Law, an
exception applies only to the processing
of data that are public in nature.
Finally, in the matter of L&F Consultorias
Legales y Financieras S.A.S., SIC found that
the company had obtained personal data
from different public sources, among them
the location of polling stations published on
the National Civil Registry’s website, with
the purpose of sending marketing to data
subjects’ postal address, without providing
evidence to SIC that they had gained the
prior and informed consent of individuals.
SIC noted, ‘[T]he company processed
personal data to send commercial offers
to the postal addresses of data subjects
without complying with the Law. During
the investigation, the company did not
show any evidence of having obtained
the prior and express consent of the
individuals concerned to process their
data, or that it had informed them of
the existence of the processing and its
purposes and of their rights pursuant
to giving their consent. This information
must be provided before and in any event
at the moment of requesting consent.’
SIC therefore prohibited L&F Consultorias
from collecting personal data unless
it obtained the prior consent of
data subjects. It also required L&F
Consultorias to obtain valid forms of
consent in order to comply with the Law.
Recommendations
In order to obtain valid consent under the
Law, companies must take into account,
at a minimum, the following rules:
1. The consent given must be express
(or explicit), informed and obtained
before collecting personal data, unless
specific exemptions apply (e.g. to protect
the individual’s vital interests). Express
consent is the lawful basis for the use of
personal data. Moreover, explicit consent
is the way of legitimising the use of
special categories of data. Under Article
5 of the Data Protection Law, sensitive
personal data is defined as that relating
to ethnicity, political opinions, religion,
trade union membership, health and the
sexuality of data subjects, and includes
biometric data. Greater protections
apply to the collection of sensitive data
compared to other kinds of data.
2. It is important to identify the purposes
for collecting personal data in each
business and/or area of the company,
and evaluate the effectiveness of
implementing a unique consent model
for each specific category of individuals,
e.g. clients, providers or employees
(subject to certain exceptions, such
as children’s data). Conversely, using
multiple consent models can create
complications when aligning policies as
closely as possible so as not to hinder
cooperation between divisions.
The model for obtaining consent must
contain at least the following information:
• the forms of processing that
personal data will be subject to and
the purpose of the processing;
• the optional nature of answering
certain questions when they
pertain to sensitive personal
data or children’s data;
• the rights of data subjects; and
• the identification of the controller, as
well as their physical or electronic
address and telephone number.
3. The option should be given to data
subjects to consent separately to different
types of processing wherever appropriate.
Moreover, requests for consent must
be separate from an organisation’s
general terms and conditions.
4. Data subjects should be provided with
a clear, concise and easily accessible
privacy policy, which should be made
available online, via email or at the
business’ location when the consent is
obtained. This is particularly important
because data subjects should be
aware of and understand exactly how
companies are going to use their data.
5. Companies should ensure that
personnel are knowledgeable about
how to get a data subject’s express (or
explicit) consent. In addition, they should
ensure that the parties responsible
for requesting the consent are held
accountable for its acquisition.
6. Organisations should keep records
to demonstrate what the data subjects
have consented to, including what they
were told, and when and how they
consented to the processing of their data.
7. Consent models should be evaluated
and adjusted in light of relevant
circumstances that may change an
aspect of the authorisation given
by the data subject (e.g. changes
in the purposes of the processing,
technological developments,
organisational or societal developments,
regulations or privacy policies).
Conclusion
Based on the examination of the
sanctions imposed by SIC, we can
deduce that companies (the controllers)
employ unsatisfactory practices to collect
personal data from individuals (the
data subjects) in violation of the Law.
It is important to state, in conclusion,
that all companies must be accountable
for providing clear and real information
to data subjects about the processing
of their data, as well as obtaining
their consent before collecting any
information from them. This will help
companies to not only ensure a fair and
transparent collection of data subjects’
data, but also to avoid sanctions.
Companies should ensure that personnel are knowledgeable
about how to get a data subject’s express (or explicit) consent.
In addition, they should ensure that the parties responsible for
requesting the consent are held accountable for its acquisition.

More Related Content

What's hot

E Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal ProtectionE Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal Protection
ijtsrd
 
State Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork QuiltState Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork Quilt
Rochester Security Summit
 
Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...
Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...
Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...
YogeshIJTSRD
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_india
Altacit Global
 
Research on Legal Protection of Data Rights of E Commerce Platform Operators
Research on Legal Protection of Data Rights of E Commerce Platform OperatorsResearch on Legal Protection of Data Rights of E Commerce Platform Operators
Research on Legal Protection of Data Rights of E Commerce Platform Operators
YogeshIJTSRD
 

What's hot (20)

E Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal ProtectionE Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal Protection
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to Compliance
 
State Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork QuiltState Data Breach Laws - A National Patchwork Quilt
State Data Breach Laws - A National Patchwork Quilt
 
Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...
Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...
Research on Electronic Commerce Platform Consumer Data Rights and Legal Prote...
 
GDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATIONGDPR- GENERAL DATA PROTECTION REGULATION
GDPR- GENERAL DATA PROTECTION REGULATION
 
California Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - KloudlearnCalifornia Consumer Privacy Act (CCPA) - Kloudlearn
California Consumer Privacy Act (CCPA) - Kloudlearn
 
Data theft rules and regulations things you should know (pt.1)
Data theft rules and regulations  things you should know (pt.1)Data theft rules and regulations  things you should know (pt.1)
Data theft rules and regulations things you should know (pt.1)
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
Relationship between data protection and m&a (1)
Relationship between data protection and m&a (1)Relationship between data protection and m&a (1)
Relationship between data protection and m&a (1)
 
California Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to knowCalifornia Consumer Privacy Act: What your brand needs to know
California Consumer Privacy Act: What your brand needs to know
 
GDPR: New Privacy Rules, Digital Communications, Marketing Opportunities
GDPR: New Privacy Rules, Digital Communications, Marketing OpportunitiesGDPR: New Privacy Rules, Digital Communications, Marketing Opportunities
GDPR: New Privacy Rules, Digital Communications, Marketing Opportunities
 
Data Protection in India
Data Protection in IndiaData Protection in India
Data Protection in India
 
Pdpa(kewal)
Pdpa(kewal)Pdpa(kewal)
Pdpa(kewal)
 
Data protection in_india
Data protection in_indiaData protection in_india
Data protection in_india
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
 
Artificial Intelligence and Machine Learning
Artificial Intelligence and Machine LearningArtificial Intelligence and Machine Learning
Artificial Intelligence and Machine Learning
 
Research on Legal Protection of Data Rights of E Commerce Platform Operators
Research on Legal Protection of Data Rights of E Commerce Platform OperatorsResearch on Legal Protection of Data Rights of E Commerce Platform Operators
Research on Legal Protection of Data Rights of E Commerce Platform Operators
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
 

Similar to Dpl november colombia

Ch 17 data protections act
Ch 17 data protections actCh 17 data protections act
Ch 17 data protections act
Khan Yousafzai
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
Dmcenter
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!
catherinecoulter
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!
catherinecoulter
 
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
Hanaysha
 

Similar to Dpl november colombia (20)

Privacy and Civil Liberties
Privacy and Civil LibertiesPrivacy and Civil Liberties
Privacy and Civil Liberties
 
Can we ask that
Can we ask thatCan we ask that
Can we ask that
 
Top 10 GDPR Requirements
Top 10 GDPR RequirementsTop 10 GDPR Requirements
Top 10 GDPR Requirements
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
 
Ch 17 data protections act
Ch 17 data protections actCh 17 data protections act
Ch 17 data protections act
 
CSR PII White Paper
CSR PII White PaperCSR PII White Paper
CSR PII White Paper
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!
 
What You Need To Know About Privacy Now!
What You Need To Know About Privacy   Now!What You Need To Know About Privacy   Now!
What You Need To Know About Privacy Now!
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Asia Counsel Insights May 2023
Asia Counsel Insights May 2023
 
DIRECT MARKETING UNDER INDIA’S NEW DIGITAL DATA PROTECTION LAW
DIRECT MARKETING UNDER INDIA’S NEW DIGITAL DATA PROTECTION LAWDIRECT MARKETING UNDER INDIA’S NEW DIGITAL DATA PROTECTION LAW
DIRECT MARKETING UNDER INDIA’S NEW DIGITAL DATA PROTECTION LAW
 
Bipartisan_Privacy_Discussion_Draft_Section_by_Section39.pdf
Bipartisan_Privacy_Discussion_Draft_Section_by_Section39.pdfBipartisan_Privacy_Discussion_Draft_Section_by_Section39.pdf
Bipartisan_Privacy_Discussion_Draft_Section_by_Section39.pdf
 
China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
POPI Seminar FINAL
POPI Seminar FINALPOPI Seminar FINAL
POPI Seminar FINAL
 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
GDPR Whitepaper
GDPR WhitepaperGDPR Whitepaper
GDPR Whitepaper
 
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
GOVERNMENT OF AB ACTS ON PRIVACY COMPLIANCE FOR (PIPA) & (FOIP) INSTITUTION -...
 

Recently uploaded

6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
ShashankKumar441258
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
Airst S
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
ca2or2tx
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
RRR Chambers
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
Airst S
 

Recently uploaded (20)

BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
 
The doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statuteThe doctrine of harmonious construction under Interpretation of statute
The doctrine of harmonious construction under Interpretation of statute
 
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
6th sem cpc notes for 6th semester students samjhe. Padhlo bhai
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptxPresentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
Presentation on Corporate SOCIAL RESPONSIBILITY- PPT.pptx
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptxMunicipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
Municipal-Council-Ratlam-vs-Vardi-Chand-A-Landmark-Writ-Case.pptx
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
Jim Eiberger Redacted Copy Of Tenant Lease.pdf
Jim Eiberger Redacted Copy Of Tenant Lease.pdfJim Eiberger Redacted Copy Of Tenant Lease.pdf
Jim Eiberger Redacted Copy Of Tenant Lease.pdf
 
3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt3 Formation of Company.www.seribangash.com.ppt
3 Formation of Company.www.seribangash.com.ppt
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理一比一原版赫瑞瓦特大学毕业证如何办理
一比一原版赫瑞瓦特大学毕业证如何办理
 

Dpl november colombia

  • 1. DATA PROTECTION LEADER12 Obtaining consent Recent cases investigated by SIC have involved Colombian companies that were accused of using personal data to send direct marketing without first obtaining the consent of data subjects to process their data for such purposes. Some companies used an opt-out method rather than an opt-in method to legalise their use of the personal data they collected. However, Colombian law prohibits the use of opt-out methods. In the abovementioned cases, the data subjects did not know about the collection and use of their information until they received marketing communications from the companies. Other investigated companies were not able to provide any evidence to support their claims that data subjects had accepted the use of their information for multiple purposes. Under Colombian law, when the personal data is collected for multiple purposes, consent is required for each use and must involve a clear affirmative action. The cases In the matter of SuperGiros S.A.S, SIC found that the company, which provides money transfer services, committed unfair and deceptive acts when collecting and using personal data for multiple purposes. SuperGiros did not obtain the informed consent of data subjects, that is to say, data subjects did not know that their personal information would be used for purposes other than the simple money transfer operation they had ordered. SIC considered such practices unfair and deceptive under Article 4 of Decree 1377 of 2013 (June 27) Which Partially Regulates Law 1581 of 2012 (‘the Decree’). SIC stressed, ‘Consequently, SIC has found that SuperGiros had been undertaking deceptive practices through its consent model, which had the goal of inducing its clients to provide their data to be used for purposes other than those necessary in the ordinary course of its business without the informed knowledge of those clients. The model even included the possibility of sharing personal data with third parties.’ According to Article 12 of the Data Protection Law, data subjects must be informed, at a minimum, about: • the identity of the controller; • the intended purposes of the processing of the provided personal data; • the optional nature of the answer given to the questions asked, when they pertain to sensitive personal data or to the personal data of children; • the rights of information, access and rectification or erasure of their data, as well as the rights to withdraw consent at any time and/ or to object to any processing; and • the contact details of the controller so that data subjects may exercise their rights. In addition, in the matter of Bilingual School Clermont Ltda., SIC found that the school collected and maintained, among other categories Complying with Colombian data protection law: a guide to consent The main pillar of Statutory Law 1581 of 2012 (October 17) Which Issues General Provisions for the Protection of Personal Data (‘the Data Protection Law’) is the requirement for data controllers to obtain consent from data subjects to lawfully process their personal data. However, the Colombian data protection authority (‘SIC’) has been faced with many cases of controllers not complying with this obligation. Luis Alberto Montezuma Chavez, Privacy and Data Protection Specialist, outlines SIC’s investigations into data subjects’ complaints, and the reasoning behind its imposition of fines, in order to help organisations comply with the Data Protection Law’s requirements. Luis Alberto Montezuma Chavez Privacy and Data Protection Specialist luismontezumachavez@gmail.com Bogotá COLOMBIA image: busypix / E+ / Getty Images
  • 2. A Cecile Park Media Publication | November 2017 13 of data, children’s personal information without explicit parental consent. In this case, SIC highlighted, ‘[N]ot only did the school use personal data without obtaining the express and informed consent of data subjects prior to the processing, but also within that group there were subjects with special constitutional protection such as children.’ Under Article 12 of the Decree, collecting information from children is lawful only if, and to the extent that, consent is given by their parents or guardians. Moreover, as per Article 7 of the Data Protection Law, an exception applies only to the processing of data that are public in nature. Finally, in the matter of L&F Consultorias Legales y Financieras S.A.S., SIC found that the company had obtained personal data from different public sources, among them the location of polling stations published on the National Civil Registry’s website, with the purpose of sending marketing to data subjects’ postal address, without providing evidence to SIC that they had gained the prior and informed consent of individuals. SIC noted, ‘[T]he company processed personal data to send commercial offers to the postal addresses of data subjects without complying with the Law. During the investigation, the company did not show any evidence of having obtained the prior and express consent of the individuals concerned to process their data, or that it had informed them of the existence of the processing and its purposes and of their rights pursuant to giving their consent. This information must be provided before and in any event at the moment of requesting consent.’ SIC therefore prohibited L&F Consultorias from collecting personal data unless it obtained the prior consent of data subjects. It also required L&F Consultorias to obtain valid forms of consent in order to comply with the Law. Recommendations In order to obtain valid consent under the Law, companies must take into account, at a minimum, the following rules: 1. The consent given must be express (or explicit), informed and obtained before collecting personal data, unless specific exemptions apply (e.g. to protect the individual’s vital interests). Express consent is the lawful basis for the use of personal data. Moreover, explicit consent is the way of legitimising the use of special categories of data. Under Article 5 of the Data Protection Law, sensitive personal data is defined as that relating to ethnicity, political opinions, religion, trade union membership, health and the sexuality of data subjects, and includes biometric data. Greater protections apply to the collection of sensitive data compared to other kinds of data. 2. It is important to identify the purposes for collecting personal data in each business and/or area of the company, and evaluate the effectiveness of implementing a unique consent model for each specific category of individuals, e.g. clients, providers or employees (subject to certain exceptions, such as children’s data). Conversely, using multiple consent models can create complications when aligning policies as closely as possible so as not to hinder cooperation between divisions. The model for obtaining consent must contain at least the following information: • the forms of processing that personal data will be subject to and the purpose of the processing; • the optional nature of answering certain questions when they pertain to sensitive personal data or children’s data; • the rights of data subjects; and • the identification of the controller, as well as their physical or electronic address and telephone number. 3. The option should be given to data subjects to consent separately to different types of processing wherever appropriate. Moreover, requests for consent must be separate from an organisation’s general terms and conditions. 4. Data subjects should be provided with a clear, concise and easily accessible privacy policy, which should be made available online, via email or at the business’ location when the consent is obtained. This is particularly important because data subjects should be aware of and understand exactly how companies are going to use their data. 5. Companies should ensure that personnel are knowledgeable about how to get a data subject’s express (or explicit) consent. In addition, they should ensure that the parties responsible for requesting the consent are held accountable for its acquisition. 6. Organisations should keep records to demonstrate what the data subjects have consented to, including what they were told, and when and how they consented to the processing of their data. 7. Consent models should be evaluated and adjusted in light of relevant circumstances that may change an aspect of the authorisation given by the data subject (e.g. changes in the purposes of the processing, technological developments, organisational or societal developments, regulations or privacy policies). Conclusion Based on the examination of the sanctions imposed by SIC, we can deduce that companies (the controllers) employ unsatisfactory practices to collect personal data from individuals (the data subjects) in violation of the Law. It is important to state, in conclusion, that all companies must be accountable for providing clear and real information to data subjects about the processing of their data, as well as obtaining their consent before collecting any information from them. This will help companies to not only ensure a fair and transparent collection of data subjects’ data, but also to avoid sanctions. Companies should ensure that personnel are knowledgeable about how to get a data subject’s express (or explicit) consent. In addition, they should ensure that the parties responsible for requesting the consent are held accountable for its acquisition.