SlideShare une entreprise Scribd logo
1  sur  59
Information Compliance:FoI, Data Protection and librariesTerry O’Brien, tpobrien@wit.ieInformation Compliance OfficerWaterford Institute of TechnologyE/IIIUG June 2009Institute of Technology Blanchardstown
Freedom of information Data Protection
Context of information compliance What is information compliance – primarily compliance with legal obligations and responsibilities under FoI and DP Responsibilities in maintaining the confidentiality, integrity and availability of information (City University London) Privacy, ethics, copyright, ownership, censorship, connectivity,  intellectual property, re-use of public sector information, harvesting, data mining, blogging, IM, social networks, email policy, internet usage, surveillance, PII (Personally Identifiable Information), liability, obligations, legal requirements, plagiarism, information ethics,
Freedom of information  Sweden 1766, Finland 1951, Irish background – Government reform, Ethics in Public Office Act 1995, Public Service Management Act 1997, Strategic Management Initiative – delivery of better government Counterpoint to Official Secrets Act 1963 – government openness, accountability, public participation in government Beef Tribunal – disconnect between government and public access to information 1966 US FOI Act context of failure of govt to account to Congress re; Vietnam War
Freedom of Information 101 Legislation –FoI Act 1997, FoI (Amendment) Act 2003 Regulations (Statutory Instruments)  1998-2006 Dept. of Finance CPU Guidelines Establishment of OIC Principles – openness, transparency, accountability FoI Act imposes duty to assist requestor Role of FoI officer – honest broker, facilitator, encouraged to answer requests outside of FoI
FoI – what is a record A record is defined as including any memorandum, book, plan, map, drawing, diagram, pictorial or graphic work or other documents, any photograph, film or recording, or any form in which data are held This includes paper or electronic diaries, e-mails (not stored on a back-up system), draft records, electronic records, x-rays even post-it notes etc.
Freedom of Information FoI give power a face, i.e. about who makes the decisions and why – accountability Power without a face as represented by Kafka in ‘The Trial’
Freedom of information - current Current FOI requests in 2008 up to 12,672 (+18%), Depts. of Taoiseach, Finance, Enterprise HSE receives most requests Journalists represent 15% of all requests (+100%) e.g. FAS expense accounts Increase a by-product of downturn, “holding institutions to account” State bodies outside scope,– VECs, CAO, State Examinations Commission, An Garda, FSRAI, NTMA, Pensions Reserve Commission
FoI - statistics Requests to Public Bodies under FOI Act 1999 -2008
Freedom of information 140,000 requests since introduced 70% + granted 85,000 personal information  304 appealed to OIC 73% members of public or representative bodies, 15% journalists, 6% business, staff of public bodies 5%, others, members of Oireachtas 1% Release patterns: civil service lagging behind – 36%, 54% local authorities, HSE 70%, 3rd level 48% but trend very much downward
Freedom of information “Every person has a right to and must be offered access to any record held by a public body.  The right has been broadly interpreted and the exceptions have been narrowly interpreted” Reasons or motivation for seeking access are irrelevant Not limited to ‘interested’ parties (except in cases of personal information, but there are exemptions
FoI – key elements S28.5(a) Public interest test (harm test) 	“on balance, the public interest that the request should be granted outweighs the public interest that the right to privacy of the individual to whom the information relates should be upheld” “Public interest” is a vague concept - does not mean interesting to the public! S18 – right for reasons for decisions – if affected, material interest
FoI - types of requests Sample requests – tenders, financial information, travel claims / requests for access to personal records (interview feedback), shortlisting criteria, model answers, and scripts, medical records, reasons for decisions made etc. FoIexposed – 700m Bertie Bowl, Industrial schools, TD and Cllr expenses, Public funds – tendering, public procurement, interview notes and marks, references (potentially), inspection of nursing homes, crèches, schools inspection reports
FoI exemptions Section 10 – Records do not exist Section 11 – Deferral of access to records Section 12 – Manner of access to records Section 19 – Meetings of government Section 20 – Deliberations of public bodies Section 21 – Functions and negotiations of public bodies Section 24 – Security, defence, IR Section 26 – Information obtained in confidence Section 27 – Commercially sensitive Section 28 – Personal information Section 29 – 3rd party consultation Section 32 – Non-disclosure
FoI – ‘letting in the light?’ FOI – a brief review FoI amendments seen as a retrograde step, 2003 – “put genie back in the bottle”, rushed through, OIC resigns, no consultation Charging schedule seen in negative terms (up front fees etc.), Cabinet records – 10 years Many bodies still remain outside FoI Sign of  a mature liberal democracy
FoI	- summary Rationale in 70 countries essentially the same – empowerment of the public FoIrole in “changing social contract between public service and the public” Ongoing tensions between governments and FoI in Ireland and internationally  Reflects a rights-based approach – right to know what is being done by government in people’s name “governmental hygiene measure” – keep government honest, discourage corruption (FoI, The First Decade, OIC 2008)
FoI - International ALA annual event 16/3 James Madison  US FOI 1966 (74, 76, 78) – federal agencies access to all federal records 9 specific exemptions “with a deep sense of pride that the United States is an open society in which the peoples right to know is cherished and guarded” (LBJ, 1966)  UK / Scotland – separate legislation.  Scottish is seen as more progressive – more positive approach to access for children and those with disability - “ a person who requests information .. Is entitled to receive it”, “as much about culture as it is about legislation” (2004)  “we have clearly got the balance wrong when online business have higher standards of transparency than the public services” (Gordon Brown)
FoI	- the future “economic downturn will increase dependence of public on the state and government agencies” – state will be collecting, processing, maintaining more information about individuals (OIC Annual Report 2008) Comply with legal obligations in face of fewer resources, yet increased demand
FoI – some references Role of FoI office www.foi.gov.ie/ Office of Information Commissioner OIC www.oic.ie Central Policy Unit Section 23 notice Re-use of public sector information http://www.psi.gov.ie/ FoI Annual Report 2008 OIC decisions http://www.psi.gov.ie/ Bodies covered by FoI http://www.foi.gov.ie/bodies-covered-by-foi DCU FAQs http://www.dcu.ie/foi/faq.shtml#6
Barack Obama on 1st day in office “ A democracy requires accountability, and accountability requires transparency. As Justice Louis Brandeis wrote, "sunlight is said to be the best of disinfectants." In our democracy, the Freedom of Information Act (FOIA), which encourages accountability through transparency, is the most prominent expression of a profound national commitment to ensuring an open Government. At the heart of that commitment is the idea that accountability is in the interest of the Government and the citizenry alike.The Freedom of Information Act should be administered with a clear presumption: In the face of doubt, openness prevails. All agencies should adopt a presumption in favor of disclosure”
Data Protection Human right Personal privacy, affects every day life Not absolute - tension with freedom of expression, rights of others  LRC (1998)  “..basic human right .. Fundamental in a civilised legal system..” Constitution implicit right to personal privacy ECHR article 8 explicit right “right to respect for private and family life”
Data Protection and the law Data Protection legislation – rights based 1988 Data Protection Act & 2003 Data Protection (amendment) Acts, DPC office est. 1989 Data Protection directive 95/46/EC EC Electronic privacy regulations Disability Act 2005 Good Friday Agreement Bunreacht na hEireann Convention on Human Rights Council of Europe DP convention EU Charter Fundamental rights fairness and consent Lisbon Treaty also makes reference
Data Protection Commissioner Role – codes of practice, guidance, advice, education and support, public register, reports, investigations, audits, work with other Regulators Powers – notice, enforcement, compliance, entry and inspection. Prosecute, fines up to €250,000  Role of commissioner in EU consistent – ombudsman (resolution), enforcer (compliance) educational (promote and advocacy) registration Article 29 Working Party – harmonise application of DP across EU
DPC role Approach of DPC – education and promotion, supportive, part of current Dept. of Justice review group  Audit resource for organisations ‘private I, public eye’ –  	DP competition on youtube Voluntary breach code (public and private) Awareness - Data Privacy Day
Data Protection - definitions Data controller  	“ a person who controls the contents and use of personal data” Data processor “ a person who processes personal data on behalf of a data controller”  Data subject “an individual who is the subject of personal data”
Personal and sensitive data Personal Name, address, age, date of birth, phones, assets, liabilities, financial statements, salary details, bank info., next of kin, holiday records, appraisal, staff disciplinary procedures, sick and medical certs, work history, quals, pps, skills, cv Sensitive Physical or mental health, trade union membership, racial origin, criminal convictions, religious or other beliefs, sexual life, alleged commission of offences, political opinions -extra conditions required when using it - explicit consent  ,[object Object],[object Object]
Data Protection – basic principles 101 Rights of individuals To fairness To get a copy of personal information (computer and organised manual)  To rectification of wrong information To opt out (phone and email) To complain to DPC
Data Protection Rights of access ,[object Object]
Satisfy identity
Data supplied in intelligible format
Controller must give subject description of personal data held, purpose and who it may be disclosed to Restrictions ,[object Object]
International relations of State
Legal privilege
Data kept by DP and OIC
Health and social work data – special provisions,[object Object]
Data processing is anything done with the life cycle of that data from collection to disposal
Data Protection Life-cycle Source: Data Protection Commissioner
Data protection and consent Consent generally required for release, but disclosed without for security of state, international relations, investigating offences, order of court, prevent injury or damage Presumption in favour of access to one's own data FoI generally has precedence in law over DP 3rd party access - Personal information is exempt from disclosure to third parties under the FoIActs, subject to a number of exceptions Under data protection, protection of the individual's privacy is paramount, but "public interest“ test does not apply
Data Protection/FoI
Data protection and … CCTV Proportionate, specific use, inform, 28 days, protocol for Garda access Direct marketing 40 days, opt-outs, unsolicited calls – fines, National Directory Database, consent Retention 	EU directive, ISP access (2 years), no content
More CCTV units in the UK than the entire population of RoI(CIA Fact  Book) Covers Courtesy of LibraryThing.com
Courtesy of flickr.com
Data Protection .. what to do
Data Protection .. what to do II
DP high profile breaches jobs.ie, Bank of Ireland, HSE, M50 toll company,  DPC active on enforcements, all complaints investigated High profile cases vs. Irish Rail, Sunday World, Dell, Revenue (staff accessing information on need-to-know basis), Ulster bank (bank and insurance cross marketing UK high profile DP case - 40 major companies facing legal action in construction industry for buying secret personal data and engaging in blacklisting – Laing O’Rourke, Balfour Beatty – intelligence database
Data Protection case studies  Prosecutions in text marketing sector in 2008 Prosecutions taken against – NTL, An Post, Tesco, Dell, Total Fitness Ireland Against Local Authority and Aer Rianta for excessive harvesting of PPS details Against Dept of Ed. for misuse of Trade Union details – to withhold pay (not fair obtaining) Code of practice around insurance and health sector problematic  Investigations listed publically – name and shame, reputational and business damage
Data Protection – some statistics (*source – Lansdowne Market Research 2008 on behalf of DP Commissioner’s office)
Data Protection - summary Duty of care Personal information should be accurate Retain no longer than necessary Right of access to personal data on computer and since 2003 to manual data in a relevant filing system Procedures in place before problems arise and protocols if problems arise – avoid negative publicity, potentially damaging liability, enforcement orders from DPC - Reputational damage could be worse! Only available to those that need to have it and used only used for specified purposes
Data Protection Data subject – (identifiable, living individual) Access rights complaints major increase in 2008 Under Disability Act genetic testing prohibited in relation to insurance, mortgages, pension  Outsourcing DP operations - obligations still apply (e.g. payroll, call-centres) – on data processors on their behalf  Security should be appropriate to potential harm and nature of data - Encryption – particularly important in case of financial and personal records and for vulnerable groups – e.g. BordGais, HSE, UK s/w Have regard to cost and technology available
Data Protection – be aware 3rd party opinions only exempt if given in confidence or understanding of  References not exempt Interview notes may be accessible Monitoring employees: YES, depending on policy, conditions of employment e.g. acceptable email policy, social media and internet usage
Data Protection - high privacy thresholds Consent is required for police / other vetting Automated decisions – e.g. creditworthiness must have human input Internet usage – ongoing monitoring is allowed should be proportionate, not unduly intrusive, on reasonable suspicion Monitoring without CONSENT can be legitimate  Call–recording without permission not allowed
Data protection - some trends Social networking, web 2.0 applications 	Increasing conflict and tensions, privacy issues, phising , hacking, disclosure, open model GPS / GIS  	Google street view, Microsoft VE - Issues of surveillance, private property, photographic data, image retention, trouble in Germany and Greece Patriot Act  & Libraries 	strong opposition from librarians Political awareness 	Increasingly topical, weekly high profile breaches 	Pirate Party in Sweden
Data protection – some trends Ethical issues 	Detailed trail of personal information across public and private systems – how to balance ‘needs’ of the state with our own ethical rights – TMI, WTMI Data sharing 	2008 data sharing deal with US – each country access to others fingerprint and DNA profiles + further sensitive data if necessary Electronic communications – principle of DP apply in relation to cookies, caller ID, spam, cold call opt-outs Biometrics – increasingly mainstream, compliant according to industry, DPC, unions disagree – argue for justification required prior to implementation – national gallery, schools etc.
‘BarackBerry’ “They’re going to have to pry it out of my hands.” First Blackberry president Connected Emails and electronic communication subject to Presidential Acts – stored and saved Mobile phone data accessed by Verizon employees

Contenu connexe

Tendances

Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...Amministratore Bluefactor
 
Rti resoucebook for cs os workers & media
Rti resoucebook for cs os workers & mediaRti resoucebook for cs os workers & media
Rti resoucebook for cs os workers & mediaMohammad Ismail
 
Bortoletti, corruption and sunshine laws, commissione europea, ipa zagabria ...
Bortoletti,  corruption and sunshine laws, commissione europea, ipa zagabria ...Bortoletti,  corruption and sunshine laws, commissione europea, ipa zagabria ...
Bortoletti, corruption and sunshine laws, commissione europea, ipa zagabria ...Maurizio Bortoletti
 
Press publishers’right: expanding copyright on news and information on the in...
Press publishers’right: expanding copyright on news and information on the in...Press publishers’right: expanding copyright on news and information on the in...
Press publishers’right: expanding copyright on news and information on the in...Centre for Media Pluralism and Media Freedom
 
Thomas M. Susman,Ppt
Thomas M. Susman,PptThomas M. Susman,Ppt
Thomas M. Susman,Pptguestbc7697
 
Dan l. Burk on privacy.
Dan l. Burk on privacy.Dan l. Burk on privacy.
Dan l. Burk on privacy.Renelio
 
Open legislation in Romania
Open legislation in RomaniaOpen legislation in Romania
Open legislation in Romaniabmanolea
 
ICEGOV - Tutorial 1 - Information Policy Concepts and Principles
ICEGOV - Tutorial 1 - Information Policy Concepts and PrinciplesICEGOV - Tutorial 1 - Information Policy Concepts and Principles
ICEGOV - Tutorial 1 - Information Policy Concepts and PrinciplesICEGOV
 
Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013
Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013
Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013Jarmo Koponen
 
Introduction to Information Policy
Introduction to Information PolicyIntroduction to Information Policy
Introduction to Information PolicyNiamh Headon
 
Internet freedom: a comparative assessment
Internet freedom: a comparative assessmentInternet freedom: a comparative assessment
Internet freedom: a comparative assessmentblogzilla
 
Openlaws LAPSI2 meeting Amsterdam 4/9/14
Openlaws LAPSI2 meeting Amsterdam 4/9/14Openlaws LAPSI2 meeting Amsterdam 4/9/14
Openlaws LAPSI2 meeting Amsterdam 4/9/14Chris Marsden
 
Information policy sunil sir
Information policy sunil sirInformation policy sunil sir
Information policy sunil sirbgshalini
 
UNESCO’s Division for Freedom of Expression, Democracy and Peace Report
UNESCO’s Division for Freedom of  Expression, Democracy and Peace ReportUNESCO’s Division for Freedom of  Expression, Democracy and Peace Report
UNESCO’s Division for Freedom of Expression, Democracy and Peace ReportAnax Fotopoulos
 

Tendances (20)

Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...Att. patrizia giannini   ggi lisbon conference 19 april 2013 - electronic dis...
Att. patrizia giannini ggi lisbon conference 19 april 2013 - electronic dis...
 
Are you compliant?
Are you compliant?Are you compliant?
Are you compliant?
 
Rti resoucebook for cs os workers & media
Rti resoucebook for cs os workers & mediaRti resoucebook for cs os workers & media
Rti resoucebook for cs os workers & media
 
Bortoletti, corruption and sunshine laws, commissione europea, ipa zagabria ...
Bortoletti,  corruption and sunshine laws, commissione europea, ipa zagabria ...Bortoletti,  corruption and sunshine laws, commissione europea, ipa zagabria ...
Bortoletti, corruption and sunshine laws, commissione europea, ipa zagabria ...
 
Is the algorithm reliable? The collaboration between technology and humans in...
Is the algorithm reliable? The collaboration between technology and humans in...Is the algorithm reliable? The collaboration between technology and humans in...
Is the algorithm reliable? The collaboration between technology and humans in...
 
Governing Communications Online - German Perspective
Governing Communications Online - German PerspectiveGoverning Communications Online - German Perspective
Governing Communications Online - German Perspective
 
Strengthening news media in the digital era: the EU approach
Strengthening news media in the digital era: the EU approachStrengthening news media in the digital era: the EU approach
Strengthening news media in the digital era: the EU approach
 
Press publishers’right: expanding copyright on news and information on the in...
Press publishers’right: expanding copyright on news and information on the in...Press publishers’right: expanding copyright on news and information on the in...
Press publishers’right: expanding copyright on news and information on the in...
 
Journalism, Democracy, and the New Political Campaigns
Journalism, Democracy, and the New Political CampaignsJournalism, Democracy, and the New Political Campaigns
Journalism, Democracy, and the New Political Campaigns
 
Thomas M. Susman,Ppt
Thomas M. Susman,PptThomas M. Susman,Ppt
Thomas M. Susman,Ppt
 
Dan l. Burk on privacy.
Dan l. Burk on privacy.Dan l. Burk on privacy.
Dan l. Burk on privacy.
 
Open legislation in Romania
Open legislation in RomaniaOpen legislation in Romania
Open legislation in Romania
 
ICEGOV - Tutorial 1 - Information Policy Concepts and Principles
ICEGOV - Tutorial 1 - Information Policy Concepts and PrinciplesICEGOV - Tutorial 1 - Information Policy Concepts and Principles
ICEGOV - Tutorial 1 - Information Policy Concepts and Principles
 
Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013
Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013
Practical recommendations on the draft-law Uzbekistan/Unesco 06042013 10072013
 
Introduction to Information Policy
Introduction to Information PolicyIntroduction to Information Policy
Introduction to Information Policy
 
Internet freedom: a comparative assessment
Internet freedom: a comparative assessmentInternet freedom: a comparative assessment
Internet freedom: a comparative assessment
 
PL&B _UK_80
PL&B _UK_80PL&B _UK_80
PL&B _UK_80
 
Openlaws LAPSI2 meeting Amsterdam 4/9/14
Openlaws LAPSI2 meeting Amsterdam 4/9/14Openlaws LAPSI2 meeting Amsterdam 4/9/14
Openlaws LAPSI2 meeting Amsterdam 4/9/14
 
Information policy sunil sir
Information policy sunil sirInformation policy sunil sir
Information policy sunil sir
 
UNESCO’s Division for Freedom of Expression, Democracy and Peace Report
UNESCO’s Division for Freedom of  Expression, Democracy and Peace ReportUNESCO’s Division for Freedom of  Expression, Democracy and Peace Report
UNESCO’s Division for Freedom of Expression, Democracy and Peace Report
 

Similaire à "Information Compliance - Freedom of Information, Data Protection and Libraries".

Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...Jisc
 
Guardian Masterclass Investigative Journalism FOI Training 10 Tips
Guardian Masterclass Investigative Journalism FOI Training 10 TipsGuardian Masterclass Investigative Journalism FOI Training 10 Tips
Guardian Masterclass Investigative Journalism FOI Training 10 TipsHelenDarbishire
 
The Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African JournalistsThe Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African JournalistsGabriella Razzano
 
Trusted government access to private sector data
Trusted government access to private sector dataTrusted government access to private sector data
Trusted government access to private sector datablogzilla
 
TI Georgia - presentation for NGO delegation - may 16 2011
TI Georgia - presentation for NGO delegation - may 16 2011TI Georgia - presentation for NGO delegation - may 16 2011
TI Georgia - presentation for NGO delegation - may 16 2011Alianta INFONET
 
presentation on Rti
presentation on Rti presentation on Rti
presentation on Rti Dipesh Karade
 
Laszlo Majtenyis Presentation
Laszlo Majtenyis PresentationLaszlo Majtenyis Presentation
Laszlo Majtenyis Presentationguestbc7697
 
Shifting the finnish mindset
Shifting the finnish mindsetShifting the finnish mindset
Shifting the finnish mindsetJyrki Kasvi
 
Presentation 4.3 Use of FOI acts
Presentation 4.3 Use of FOI actsPresentation 4.3 Use of FOI acts
Presentation 4.3 Use of FOI actsjohnabutterworth
 
Right to information act
Right to information actRight to information act
Right to information actRajesh Thakur
 
Police surveillance of social media - do you have a reasonable expectation of...
Police surveillance of social media - do you have a reasonable expectation of...Police surveillance of social media - do you have a reasonable expectation of...
Police surveillance of social media - do you have a reasonable expectation of...Lilian Edwards
 
Francesca Fanucci 06 Nov
Francesca Fanucci 06 NovFrancesca Fanucci 06 Nov
Francesca Fanucci 06 Novguestbc7697
 
Introduction to Information Policy
Introduction to Information PolicyIntroduction to Information Policy
Introduction to Information PolicyNiamh Walker-Headon
 
41 rti-sali.feature
41 rti-sali.feature41 rti-sali.feature
41 rti-sali.featureDivya Gigy
 
NORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATION
NORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATIONNORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATION
NORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATIONJamaity
 

Similaire à "Information Compliance - Freedom of Information, Data Protection and Libraries". (20)

Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
Victoria Cetinkaya - Research Integrity: Legal and policy obligations to shar...
 
Hannes astok data protection agency
Hannes astok data protection agencyHannes astok data protection agency
Hannes astok data protection agency
 
Guardian Masterclass Investigative Journalism FOI Training 10 Tips
Guardian Masterclass Investigative Journalism FOI Training 10 TipsGuardian Masterclass Investigative Journalism FOI Training 10 Tips
Guardian Masterclass Investigative Journalism FOI Training 10 Tips
 
The Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African JournalistsThe Promotion of Access to Information Act for South African Journalists
The Promotion of Access to Information Act for South African Journalists
 
Trusted government access to private sector data
Trusted government access to private sector dataTrusted government access to private sector data
Trusted government access to private sector data
 
TI Georgia - presentation for NGO delegation - may 16 2011
TI Georgia - presentation for NGO delegation - may 16 2011TI Georgia - presentation for NGO delegation - may 16 2011
TI Georgia - presentation for NGO delegation - may 16 2011
 
presentation on Rti
presentation on Rti presentation on Rti
presentation on Rti
 
Laszlo Majtenyis Presentation
Laszlo Majtenyis PresentationLaszlo Majtenyis Presentation
Laszlo Majtenyis Presentation
 
Ben soltane on Access to Information
Ben soltane on Access to InformationBen soltane on Access to Information
Ben soltane on Access to Information
 
Shifting the finnish mindset
Shifting the finnish mindsetShifting the finnish mindset
Shifting the finnish mindset
 
Right to information act
Right to information actRight to information act
Right to information act
 
Presentation 4.3 Use of FOI acts
Presentation 4.3 Use of FOI actsPresentation 4.3 Use of FOI acts
Presentation 4.3 Use of FOI acts
 
Chap 4 (1)
Chap 4 (1)Chap 4 (1)
Chap 4 (1)
 
Right to information act
Right to information actRight to information act
Right to information act
 
Police surveillance of social media - do you have a reasonable expectation of...
Police surveillance of social media - do you have a reasonable expectation of...Police surveillance of social media - do you have a reasonable expectation of...
Police surveillance of social media - do you have a reasonable expectation of...
 
Francesca Fanucci 06 Nov
Francesca Fanucci 06 NovFrancesca Fanucci 06 Nov
Francesca Fanucci 06 Nov
 
Hashim haswira
Hashim haswiraHashim haswira
Hashim haswira
 
Introduction to Information Policy
Introduction to Information PolicyIntroduction to Information Policy
Introduction to Information Policy
 
41 rti-sali.feature
41 rti-sali.feature41 rti-sali.feature
41 rti-sali.feature
 
NORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATION
NORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATIONNORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATION
NORMES INTERNATIONALES SUR LA TRANSPARENCE ET LA RESPONSABILISATION
 

Dernier

Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhikauryashika82
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfAdmir Softic
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...EduSkills OECD
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphThiyagu K
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docxPoojaSen20
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdfQucHHunhnh
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfAyushMahapatra5
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxDenish Jangid
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxVishalSingh1417
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...christianmathematics
 
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Shubhangi Sonawane
 
Making and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdfMaking and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdfChris Hunter
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsTechSoup
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxRamakrishna Reddy Bijjam
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...Nguyen Thanh Tu Collection
 

Dernier (20)

Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot Graph
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docx
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdf
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
 
Making and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdfMaking and Justifying Mathematical Decisions.pdf
Making and Justifying Mathematical Decisions.pdf
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docx
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 

"Information Compliance - Freedom of Information, Data Protection and Libraries".

  • 1. Information Compliance:FoI, Data Protection and librariesTerry O’Brien, tpobrien@wit.ieInformation Compliance OfficerWaterford Institute of TechnologyE/IIIUG June 2009Institute of Technology Blanchardstown
  • 2. Freedom of information Data Protection
  • 3. Context of information compliance What is information compliance – primarily compliance with legal obligations and responsibilities under FoI and DP Responsibilities in maintaining the confidentiality, integrity and availability of information (City University London) Privacy, ethics, copyright, ownership, censorship, connectivity, intellectual property, re-use of public sector information, harvesting, data mining, blogging, IM, social networks, email policy, internet usage, surveillance, PII (Personally Identifiable Information), liability, obligations, legal requirements, plagiarism, information ethics,
  • 4. Freedom of information Sweden 1766, Finland 1951, Irish background – Government reform, Ethics in Public Office Act 1995, Public Service Management Act 1997, Strategic Management Initiative – delivery of better government Counterpoint to Official Secrets Act 1963 – government openness, accountability, public participation in government Beef Tribunal – disconnect between government and public access to information 1966 US FOI Act context of failure of govt to account to Congress re; Vietnam War
  • 5. Freedom of Information 101 Legislation –FoI Act 1997, FoI (Amendment) Act 2003 Regulations (Statutory Instruments) 1998-2006 Dept. of Finance CPU Guidelines Establishment of OIC Principles – openness, transparency, accountability FoI Act imposes duty to assist requestor Role of FoI officer – honest broker, facilitator, encouraged to answer requests outside of FoI
  • 6.
  • 7.
  • 8. FoI – what is a record A record is defined as including any memorandum, book, plan, map, drawing, diagram, pictorial or graphic work or other documents, any photograph, film or recording, or any form in which data are held This includes paper or electronic diaries, e-mails (not stored on a back-up system), draft records, electronic records, x-rays even post-it notes etc.
  • 9. Freedom of Information FoI give power a face, i.e. about who makes the decisions and why – accountability Power without a face as represented by Kafka in ‘The Trial’
  • 10. Freedom of information - current Current FOI requests in 2008 up to 12,672 (+18%), Depts. of Taoiseach, Finance, Enterprise HSE receives most requests Journalists represent 15% of all requests (+100%) e.g. FAS expense accounts Increase a by-product of downturn, “holding institutions to account” State bodies outside scope,– VECs, CAO, State Examinations Commission, An Garda, FSRAI, NTMA, Pensions Reserve Commission
  • 11. FoI - statistics Requests to Public Bodies under FOI Act 1999 -2008
  • 12. Freedom of information 140,000 requests since introduced 70% + granted 85,000 personal information 304 appealed to OIC 73% members of public or representative bodies, 15% journalists, 6% business, staff of public bodies 5%, others, members of Oireachtas 1% Release patterns: civil service lagging behind – 36%, 54% local authorities, HSE 70%, 3rd level 48% but trend very much downward
  • 13.
  • 14. Freedom of information “Every person has a right to and must be offered access to any record held by a public body. The right has been broadly interpreted and the exceptions have been narrowly interpreted” Reasons or motivation for seeking access are irrelevant Not limited to ‘interested’ parties (except in cases of personal information, but there are exemptions
  • 15. FoI – key elements S28.5(a) Public interest test (harm test) “on balance, the public interest that the request should be granted outweighs the public interest that the right to privacy of the individual to whom the information relates should be upheld” “Public interest” is a vague concept - does not mean interesting to the public! S18 – right for reasons for decisions – if affected, material interest
  • 16. FoI - types of requests Sample requests – tenders, financial information, travel claims / requests for access to personal records (interview feedback), shortlisting criteria, model answers, and scripts, medical records, reasons for decisions made etc. FoIexposed – 700m Bertie Bowl, Industrial schools, TD and Cllr expenses, Public funds – tendering, public procurement, interview notes and marks, references (potentially), inspection of nursing homes, crèches, schools inspection reports
  • 17. FoI exemptions Section 10 – Records do not exist Section 11 – Deferral of access to records Section 12 – Manner of access to records Section 19 – Meetings of government Section 20 – Deliberations of public bodies Section 21 – Functions and negotiations of public bodies Section 24 – Security, defence, IR Section 26 – Information obtained in confidence Section 27 – Commercially sensitive Section 28 – Personal information Section 29 – 3rd party consultation Section 32 – Non-disclosure
  • 18. FoI – ‘letting in the light?’ FOI – a brief review FoI amendments seen as a retrograde step, 2003 – “put genie back in the bottle”, rushed through, OIC resigns, no consultation Charging schedule seen in negative terms (up front fees etc.), Cabinet records – 10 years Many bodies still remain outside FoI Sign of a mature liberal democracy
  • 19. FoI - summary Rationale in 70 countries essentially the same – empowerment of the public FoIrole in “changing social contract between public service and the public” Ongoing tensions between governments and FoI in Ireland and internationally Reflects a rights-based approach – right to know what is being done by government in people’s name “governmental hygiene measure” – keep government honest, discourage corruption (FoI, The First Decade, OIC 2008)
  • 20. FoI - International ALA annual event 16/3 James Madison US FOI 1966 (74, 76, 78) – federal agencies access to all federal records 9 specific exemptions “with a deep sense of pride that the United States is an open society in which the peoples right to know is cherished and guarded” (LBJ, 1966) UK / Scotland – separate legislation. Scottish is seen as more progressive – more positive approach to access for children and those with disability - “ a person who requests information .. Is entitled to receive it”, “as much about culture as it is about legislation” (2004) “we have clearly got the balance wrong when online business have higher standards of transparency than the public services” (Gordon Brown)
  • 21. FoI - the future “economic downturn will increase dependence of public on the state and government agencies” – state will be collecting, processing, maintaining more information about individuals (OIC Annual Report 2008) Comply with legal obligations in face of fewer resources, yet increased demand
  • 22. FoI – some references Role of FoI office www.foi.gov.ie/ Office of Information Commissioner OIC www.oic.ie Central Policy Unit Section 23 notice Re-use of public sector information http://www.psi.gov.ie/ FoI Annual Report 2008 OIC decisions http://www.psi.gov.ie/ Bodies covered by FoI http://www.foi.gov.ie/bodies-covered-by-foi DCU FAQs http://www.dcu.ie/foi/faq.shtml#6
  • 23. Barack Obama on 1st day in office “ A democracy requires accountability, and accountability requires transparency. As Justice Louis Brandeis wrote, "sunlight is said to be the best of disinfectants." In our democracy, the Freedom of Information Act (FOIA), which encourages accountability through transparency, is the most prominent expression of a profound national commitment to ensuring an open Government. At the heart of that commitment is the idea that accountability is in the interest of the Government and the citizenry alike.The Freedom of Information Act should be administered with a clear presumption: In the face of doubt, openness prevails. All agencies should adopt a presumption in favor of disclosure”
  • 24. Data Protection Human right Personal privacy, affects every day life Not absolute - tension with freedom of expression, rights of others LRC (1998) “..basic human right .. Fundamental in a civilised legal system..” Constitution implicit right to personal privacy ECHR article 8 explicit right “right to respect for private and family life”
  • 25. Data Protection and the law Data Protection legislation – rights based 1988 Data Protection Act & 2003 Data Protection (amendment) Acts, DPC office est. 1989 Data Protection directive 95/46/EC EC Electronic privacy regulations Disability Act 2005 Good Friday Agreement Bunreacht na hEireann Convention on Human Rights Council of Europe DP convention EU Charter Fundamental rights fairness and consent Lisbon Treaty also makes reference
  • 26. Data Protection Commissioner Role – codes of practice, guidance, advice, education and support, public register, reports, investigations, audits, work with other Regulators Powers – notice, enforcement, compliance, entry and inspection. Prosecute, fines up to €250,000 Role of commissioner in EU consistent – ombudsman (resolution), enforcer (compliance) educational (promote and advocacy) registration Article 29 Working Party – harmonise application of DP across EU
  • 27. DPC role Approach of DPC – education and promotion, supportive, part of current Dept. of Justice review group Audit resource for organisations ‘private I, public eye’ – DP competition on youtube Voluntary breach code (public and private) Awareness - Data Privacy Day
  • 28.
  • 29. Data Protection - definitions Data controller “ a person who controls the contents and use of personal data” Data processor “ a person who processes personal data on behalf of a data controller” Data subject “an individual who is the subject of personal data”
  • 30.
  • 31. Data Protection – basic principles 101 Rights of individuals To fairness To get a copy of personal information (computer and organised manual) To rectification of wrong information To opt out (phone and email) To complain to DPC
  • 32.
  • 34. Data supplied in intelligible format
  • 35.
  • 38. Data kept by DP and OIC
  • 39.
  • 40. Data processing is anything done with the life cycle of that data from collection to disposal
  • 41. Data Protection Life-cycle Source: Data Protection Commissioner
  • 42. Data protection and consent Consent generally required for release, but disclosed without for security of state, international relations, investigating offences, order of court, prevent injury or damage Presumption in favour of access to one's own data FoI generally has precedence in law over DP 3rd party access - Personal information is exempt from disclosure to third parties under the FoIActs, subject to a number of exceptions Under data protection, protection of the individual's privacy is paramount, but "public interest“ test does not apply
  • 44. Data protection and … CCTV Proportionate, specific use, inform, 28 days, protocol for Garda access Direct marketing 40 days, opt-outs, unsolicited calls – fines, National Directory Database, consent Retention EU directive, ISP access (2 years), no content
  • 45. More CCTV units in the UK than the entire population of RoI(CIA Fact Book) Covers Courtesy of LibraryThing.com
  • 47. Data Protection .. what to do
  • 48. Data Protection .. what to do II
  • 49. DP high profile breaches jobs.ie, Bank of Ireland, HSE, M50 toll company, DPC active on enforcements, all complaints investigated High profile cases vs. Irish Rail, Sunday World, Dell, Revenue (staff accessing information on need-to-know basis), Ulster bank (bank and insurance cross marketing UK high profile DP case - 40 major companies facing legal action in construction industry for buying secret personal data and engaging in blacklisting – Laing O’Rourke, Balfour Beatty – intelligence database
  • 50. Data Protection case studies Prosecutions in text marketing sector in 2008 Prosecutions taken against – NTL, An Post, Tesco, Dell, Total Fitness Ireland Against Local Authority and Aer Rianta for excessive harvesting of PPS details Against Dept of Ed. for misuse of Trade Union details – to withhold pay (not fair obtaining) Code of practice around insurance and health sector problematic Investigations listed publically – name and shame, reputational and business damage
  • 51. Data Protection – some statistics (*source – Lansdowne Market Research 2008 on behalf of DP Commissioner’s office)
  • 52. Data Protection - summary Duty of care Personal information should be accurate Retain no longer than necessary Right of access to personal data on computer and since 2003 to manual data in a relevant filing system Procedures in place before problems arise and protocols if problems arise – avoid negative publicity, potentially damaging liability, enforcement orders from DPC - Reputational damage could be worse! Only available to those that need to have it and used only used for specified purposes
  • 53. Data Protection Data subject – (identifiable, living individual) Access rights complaints major increase in 2008 Under Disability Act genetic testing prohibited in relation to insurance, mortgages, pension Outsourcing DP operations - obligations still apply (e.g. payroll, call-centres) – on data processors on their behalf Security should be appropriate to potential harm and nature of data - Encryption – particularly important in case of financial and personal records and for vulnerable groups – e.g. BordGais, HSE, UK s/w Have regard to cost and technology available
  • 54. Data Protection – be aware 3rd party opinions only exempt if given in confidence or understanding of References not exempt Interview notes may be accessible Monitoring employees: YES, depending on policy, conditions of employment e.g. acceptable email policy, social media and internet usage
  • 55. Data Protection - high privacy thresholds Consent is required for police / other vetting Automated decisions – e.g. creditworthiness must have human input Internet usage – ongoing monitoring is allowed should be proportionate, not unduly intrusive, on reasonable suspicion Monitoring without CONSENT can be legitimate Call–recording without permission not allowed
  • 56. Data protection - some trends Social networking, web 2.0 applications Increasing conflict and tensions, privacy issues, phising , hacking, disclosure, open model GPS / GIS Google street view, Microsoft VE - Issues of surveillance, private property, photographic data, image retention, trouble in Germany and Greece Patriot Act & Libraries strong opposition from librarians Political awareness Increasingly topical, weekly high profile breaches Pirate Party in Sweden
  • 57. Data protection – some trends Ethical issues Detailed trail of personal information across public and private systems – how to balance ‘needs’ of the state with our own ethical rights – TMI, WTMI Data sharing 2008 data sharing deal with US – each country access to others fingerprint and DNA profiles + further sensitive data if necessary Electronic communications – principle of DP apply in relation to cookies, caller ID, spam, cold call opt-outs Biometrics – increasingly mainstream, compliant according to industry, DPC, unions disagree – argue for justification required prior to implementation – national gallery, schools etc.
  • 58.
  • 59. ‘BarackBerry’ “They’re going to have to pry it out of my hands.” First Blackberry president Connected Emails and electronic communication subject to Presidential Acts – stored and saved Mobile phone data accessed by Verizon employees
  • 60. Is this important to libraries
  • 61.
  • 62. Is this important to libraries Libraries accumulate huge data banks from library systems and services – how this is potentially utilized is often outside of our control, particularly where library is used as an intermediary to access externally provided content Advent of participatory web – huge amounts of PII willingly displayed but do people understand (or care) about implications. Do libraries? Libraries traditionally have a culture of privacy, control, this is shifting … do we have a role in this???
  • 63. Sources / references DPC presentation to IoT network 11/03/2009 www.dataprotection.ie http://www.ico.gov.uk/ Information Commissioners Office - UK that personal privacy is a right, take steps to protect it – winner of DP YouTube competition 2009 Case studies 2008 DP channel
  • 64. Terry O’Brien,Information Compliance officerWaterford Institute of Technology Thank you tpobrien@wit.ie www.wit.ie