When is it OK to share information about other people?

Similar documents
Data Protection: Fair processing of student personal information Contents

Welcome To Your Data Protection Journey. Paula Tighe Information Governance Executive

Fitzwilliam College Data Protection Policy

The following guidelines have been developed to assist all staff with the adherence to the Privacy & Data Protection Act (Vic) 2014 (the PDP Act ).

This information, or "personal data" as it is often referred to, must be processed according to the principles contained within the Regulation.

Privacy Policy. Responsible Officer. General Counsel Approved by

Legal Compliance Education and Awareness. Privacy Act (Commonwealth)

POSITIVE SOLUTIONS FAIR PROCESSING NOTICE

Fair Processing Notice

What is a Fair Processing Notice (FPN)? To ensure that we process your personal data fairly and lawfully we are required to inform you:

GUIDELINES FOR THE CONTRACTING OUT OF RESEARCH ACTIVITIES

ASTRAZENECA GLOBAL POLICY DATA PRIVACY

Inteum EU or Switzerland Safe Harbor Policy

Privacy. Policy. Purpose. Coverage. Policy. Code and version control:

Privacy Notice. 1. Who we are and our approach to your privacy

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software

Hydro Building Systems UK Limited ( the Company )

DATA PROTECTION POLICY

Data Protection Policy. Newbury Academy Trust

* Unless otherwise indicated, this policy will still apply beyond the review date.

Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy

Privacy Statement for Intermediaries

General Data Protection Regulations Briefing (the presentation you ve all been waiting for)

TEREX CORPORATION DATA PROTECTION POLICY

DDB. EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy

PRIVACY POLICY OF BPO INSOLVENCY LIMITED (COMPANY REGISTRATION NO ) REGISTERED OFFICE 37 WALTER ROAD SWANSEA SA1 5NW

To confirm Bendigo Kangan Institutes efforts to meet its obligations under State and Federal legislation to manage personal and private information.

PROPFIN LTD. Data Protection Policy

Application for a site senior executive certificate of competence

TIFFANY AND COMPANY: EU-U.S. PRIVACY SHIELD PRIVACY POLICY - CONSUMER DATA

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ).

Privacy Notice Student Loans Company Ltd

The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy

Southern Golden Retriever Rescue Data Protection Policy

Chartered Accountants Australia and New Zealand Application for a Certificate of Public Practice by a New Zealand resident member

CONTRACTUAL PURPOSES. Last Updated: 8 Oct 18

We are committed to safeguarding your personal information in accordance with the requirements of the Privacy Act 1988.

CREDIT REPORTING POLICY

DATA PRIVACY & FAIR PROCESSING NOTICE

Appropriate Policy Document

PRIVACY NOTICE LAST UPDATED: SEPT. 2018

CPI PROPERTY GROUP. Group Data Protection Policy. 25 May Summary

Ark Syndicate Management Limited. Privacy and Transparency Notice. Version 1

Privacy Statement. Key Definitions. Data Controller. Processing

We take privacy and security of your information seriously and will only use such personal information as set out in this Privacy Notice.

DATA PROTECTION POLICY

European Union General Data Protection Regulation

DATA PROCESSING AGREEMENT

MONASH UNIVERSITY PRIVACY COMPLIANCE MANUAL

KATOEN NATIE ANTI-BRIBERY AND CORRUPTION POLICY

Please retain this for your files. ONLINE REFERENCE NUMBER Smartform number

Data protection and transfer

DATA PROTECTION AND PERSONAL INFORMATION FAIR PROCESSING POLICY

EU Data Processing Addendum

For commission eligibility and FCA product sales data purposes: if you did not provide advice on this sale please tick

Privacy Policy. Brambles Limited. Instituted: 30 April 2014 {EXT }

Please retain this for your files. ONLINE REFERENCE NUMBER Smartform number

Institutional Investment Advisors Limited

ROSETTA STONE LTD. PROCESSING ADDENDUM

Privacy & Data Protection Procedure-Box Hill Institute Group

DATA PROTECTION INSURANCE MARKET CORE USES INFORMATION NOTICE

JPMorgan recognises the importance of the personal information we hold about individuals and the trust they place in us.

Privacy Policy. For the purposes of Data Protection Legislation the data controller is the Company.

Adopted on 12 July 2010

BINDING CORPORATE RULES

Example Authorisation Clauses

Privacy Policy and. Credit Reporting Policy

ERGO Versicherung AG UK Branch Data Privacy Notice

Standard contractual clauses for the transfer of personal data to third countries - Frequently asked questions

DATA PRIVACY I. POLICY DEFINITIONS

EQUAL ACCESS FUNDING PTY LTD PRIVACY POLICY

Mobius Life Limited Data Privacy Notice

Counter Theft, Fraud and Corruption Policy

Data Processing Appendix

2. TASK OF DPO IN INTERNATIONAL DATA TRANSFERS

Best Practice: Responding to a Privacy Breach

All Sorts UK Limited Data Protection Policy 17 th May 2018

A PDF version of this policy is also published on the Ballarat Clarendon College website.

Privacy Policy. Who we are. Definitions

FINANCIAL SERVICES OPPORTUNITIES INVESTMENT FUND LIMITED Company Registration Number: PRIVACY NOTICE

Data protection clauses in commercial contracts. Amy Chandler & Paul Jonson

GLOBAL DATA PROTECTION POLICY URUP

Kent and Medway Information Sharing Agreement v4 2014/15

University of Sunderland Business Assurance Information Classification Policy

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL

Corporate Finance Terms of Business Terms Client DEFINITIONS Anti-Bribery and Corruption Law Applicable Law BaFin Bank Business Day Clearing System

Management of Personal Information Policy (Privacy Policy)

PRIVACY STATEMENT. There are terms in bold with specific meanings. Those meanings can be found in the attached Glossary.

GUIDANCE NOTE ON THE DATA PROTECTION ACT Information for clubs & county associations

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES

PRIVACY STATEMENT. For further details on PCB s privacy policy contact:

DIRECTORS AND OFFICERS LIABILITY INSURANCE INCLUDING CORPORATE INDEMNITY POLICY APPLICATION PROFIT CORPORATIONS

GDPR: Frequently Asked Questions to Brokers Ireland, February 2018.

Transborder data transfers briefly explained

The EU s General Data Protection Regulation enters into force on 25 May 2018

Westpac Banking Corporation Level 16, 275 Kent St Sydney NSW th January Mandatory Data Breach Notification

Voyages Privacy Policy

2. FROM WHICH SOURCES THE BANK COLLECTS YOUR PERSONAL DATA?

INFORMATION ON THE PROCESSING OF PERSONAL DATA

privacy notice who is responsible for processing your personal data and who you can contact in this regard reasons for processing your data

Transcription:

When is it OK to share information about other people? Max Todd, Council Secretariat Geoff Hemmings, Legal Services Wednesday 1 October 2014

What is personal data? Data that relates to a living person, who can be identified from that data, on its own or in combination with other data e.g. email address student or staff number photos Sensitive personal data : Data relating to health, race/ethnicity, religious/political beliefs, trade union membership, sexual life, criminal record

What is sharing? Disclosure of personal data to a third party (individual or organisation) or sharing of data between different parts of the same organisation Disclosure of student data by University to a college (or vice-versa) Disclosure of data to the Police or council Disclosure of data to a service provider e.g. mailing house, IT contractor

Data Protection Act: Key Requirements Sharing must satisfy all 8 data protection principles. But certain principles are particularly relevant to question of whether data can be shared. Principle 1 Fair and lawful processing Principle 2 Limited purpose

Principle 1 Fair and lawful processing Provide a Privacy notice, indicating: Who is processing the data? What will be done with the data? Any other information needed for processing to be fair e.g. disclosures to 3 rd parties Consider impact of processing on individual: Will any adverse effect be justified?

Principle 2 Purpose limitation Personal data shall not be used for a purpose incompatible with the purposes for which it was originally collected i.e. beyond the reasonable expectations of the individual

University privacy notices Generic Staff www.admin.ox.ac.uk/councilsec/compliance/dataprotection/staffinfo Student www.ox.ac.uk/students/life/it/studentrecord/data Alumni: www.alumni.ox.ac.uk/data_protection Ad-hoc purposes e.g. research, libraries, online shop

Can I share? Checklist (1) What is the objective? What is the sharing meant to achieve? Does that objective require personal data or could it be achieved with anonymised data?

Can I share? Checklist (2) Does the privacy notice give me authority to share? For internal sharing, consider purpose only For external sharing, consider disclosure provisions, as well as purpose

Can I share? Checklist (3) If not authorised by a privacy notice, is the sharing something the individual would expect me to do? Would it have an adverse effect on individual? If outside reasonable expectations, seek the individual s consent Disclosure to a 3 rd party will usually require consent, unless specifically authorised in privacy notice

Exemptions Exemptions allow sharing when not authorised in a privacy notice or no consent is sought To prevent or detect crime To assess or collect tax To meet a legal requirement For the purpose of legal proceedings

How can I share? Once you have established that data can be shared, certain principles are relevant to how data is shared. Principles 3 & 4 quality of data Principle 7 security & integrity Principle 8 transfers outside the EEA

Principles 3 & 4 quality of data Shared data must be: adequate, relevant and not excessive accurate and (where necessary) up-to-date

Principles 7 security & integrity (1) Appropriate measures against: Misuse Loss Destruction Damage In transit and at destination.

Principles 7 security & integrity (2) Ensure reliability of employees who have access to data Where subcontracting: Sufficient guarantees Written agreement specific provisions Ensure compliance

Principles 8 transfers outside EEA Prohibited unless to a country providing adequate protections Approved countries list very short does not include USA Exemptions consent & appropriate contracts Don t rely on US-EU Safe Harbor

How can I share? - Checklist Specific agreement required? Due diligence on the recipient Quality of data shared Transfer outside the EEA?

Further information Email Data.protection@admin.ox.ac.uk

QUESTIONS?