SlideShare a Scribd company logo
EU Privacy
Regulation
Update
Dr. Ville Oksanen 18.4.2014
18. maaliskuuta 14
Who’s talking..
• L.LM. , Ph.D. (Technology law)
• At TKK (Aalto) since 2001
• At Helsinki University since 2009
• Partner, Turre Legal
• Founder, Electronic Frontier Finland
- Currently Vice Chairman
• Blogger - “Lex Oksanen”
18. maaliskuuta 14
Privacy regulation updata
18. maaliskuuta 14
Original goal
• To update the existing regulation to meet
the change in technologies
• To give more rights to both citizens and
also data protection authorities
18. maaliskuuta 14
However..
• “Regulatory capture” in action
• Heavy lobbying from e.g.
• U.S Government
• Facebook, Google etc.
• To water down the proposal
18. maaliskuuta 14
Current State?
18. maaliskuuta 14
Case Snowden
18. maaliskuuta 14
18. maaliskuuta 14
(http://euobserver.com/justice/121817)
18. maaliskuuta 14
Key features
• “Clarified definitions
• Data protection by Design
• Accountability + Notification of breaches
• Portability + Right to Access (for free)
• Right to Erasure
• International regulatory scope?
18. maaliskuuta 14
Sensitive data (Article 9)
• ...revealing race or ethnic origin, political opinions,
religion or philosophical beliefs, sexual orientation or
gender identity, trade-union membership and activities ,
and the processing of genetic or biometric
data or data concerning health or sex life,
administrative sanctions, judgments, criminal or suspected
offences, convictions or related security measures
• (h) processing of data concerning health is necessary for
health purposes and subject to the conditions and safeguards
referred to in Article 81; or
• (i) processing is necessary for historical, statistical or scientific
research purposes subject to the conditions and safeguards
referred to in Article 83; or
18. maaliskuuta 14
Right to access and to
obtain data
2a.  Where the data subject has provided the personal
data where the personal data are processed by electronic
means, the data subject shall have the right to obtain from
the controller a copy of the provided personal data in an
electronic and interoperable format which is
commonly used and allows for further use by
the data subject without hindrance from the
controller from whom the personal data are
withdrawn.Where technically feasible and available, the
data shall be transferred directly from controller to
controller at the request of the data subject.
18. maaliskuuta 14
Profiling
• Highly visible notification about right to object
• Definition:“ 'profiling' means any form of automated
processing of personal data intended to evaluate
certain personal aspects relating to a natural person
or to analyse or predict in particular that natural
person’s performance at work, economic situation,
location, health, personal preferences, reliability or
behaviour;
18. maaliskuuta 14
Data protection by Design
Article 23: ”...Data protection by design shall have
particular regard to the entire lifecycle
management of personal data from collection to
processing to deletion, systematically focusing on
comprehensive procedural safeguards regarding
the accuracy, confidentiality, integrity, physical
security and deletion of personal data.”
18. maaliskuuta 14
Right to Erasure
• Most controversial feature
• Many open questions
• Practical (backups? Who pays the costs)
• Content spesific (photographs?
Discussions?)
• Application to data given to 3rd parties?
18. maaliskuuta 14
Respect to Risk
• “The controller .. shall carry out a risk analysis of
the potential impact of the intended data
processing on the rights and freedoms of the data
subjects, assessing whether its processing
operations are likely to present specific risks.”
• “(d) processing of personal data for the
provision of health care,
epidemiological researches, or
surveys of mental or infectious
diseases, where the data are processed for
taking measures or decisions regarding specific
individuals on a large scale;”
18. maaliskuuta 14
Designation of the data
protection officer
• 1.  The controller and the processor shall
designate a data protection officer in any case
where:
• ..d) the core activities of the controller or
the processor consist of processing special
categories of data pursuant to Article
9(1), location data or data on children or
employees in large scale filing systems.
18. maaliskuuta 14
Penalties
18. maaliskuuta 14
Penalties
• “At least”
18. maaliskuuta 14
Penalties
• “At least”
• “a warning in writing in cases of first
and non-intentional non-compliance;
18. maaliskuuta 14
Penalties
• “At least”
• “a warning in writing in cases of first
and non-intentional non-compliance;
• regular periodic data protection
audits;
18. maaliskuuta 14
Penalties
• “At least”
• “a warning in writing in cases of first
and non-intentional non-compliance;
• regular periodic data protection
audits;
• a fine up to 100 000 000 EUR or up
to 5% of the annual worldwide
turnover in case of an enterprise,
whichever is higher.
18. maaliskuuta 14
Article 80a: Access to
documents
• National law
• “Reconciles the right to the protection of
personal data with the principle of public
access to official documents.”
• Notification to the Commission
18. maaliskuuta 14
Processing of personal
data concerning health
• Based on law (EU or national)
• “consistent, and specific measures to
safeguard the data subject's interests and
fundamental rights, to the extent that
these are necessary and proportionate ,
and of which the effects shall be
foreseeable by the data subject”
18. maaliskuuta 14
3 categories of data
• “preventive or occupational medicine, medical
diagnosis, the provision of care or treatment or the
management of health-care services”
• “reasons of public interest in the area of public health,
such as protecting against serious cross-border threats
to health or ensuring high standards of quality and
safety
• “other reasons of public interest in areas such as social
protection, especially in order to ensure the quality and
cost-effectiveness of the procedures used for settling
claims for benefits and services in the health insurance
system”
18. maaliskuuta 14
Research exceptions
• Consent required
• “Where the data subject's consent is required for the
processing of medical data exclusively for public health
purposes of scientific research, the consent may be given
for one or more specific and similar researches.”
• Anonymisation or pseudonymisation under the highest
technical standards
18. maaliskuuta 14
Article 83
Processing for historical, statistical and scientific research
purposes
1. In accordance with the rules set out in this Regulation, personal
data may be processed for historical, statistical or scientific research
purposes only if:
(a) these purposes cannot be otherwise fulfilled by processing data
which does not permit or not any longer permit the identification of
the data subject;
(b) data enabling the attribution of information to an identified or
identifiable data subject is kept separately from the other
information under the highest technical standards, and all necessary
measures are taken to prevent unwarranted re-identification of the
data subjects.
18. maaliskuuta 14
18. maaliskuuta 14
Questions?
Comments?
ville.oksanen@aalto.fi-- twitter: villoks
18. maaliskuuta 14

More Related Content

PPTX
Privacy by Design: legal perspective
PDF
Course 5: GDPR & Big Data by Sari Depreeuw
PPTX
Medical device data protection and security
PDF
Legal and ethical considerations for sharing research data
PPTX
POPH: Archival Research and Data Protection: Why are some archives closed? - ...
PDF
Browne Jacobson - Administrative and public law - October 2017
PDF
Prep your app for gdpr compliance
DOCX
Privacy by Design: legal perspective
Course 5: GDPR & Big Data by Sari Depreeuw
Medical device data protection and security
Legal and ethical considerations for sharing research data
POPH: Archival Research and Data Protection: Why are some archives closed? - ...
Browne Jacobson - Administrative and public law - October 2017
Prep your app for gdpr compliance

What's hot (20)

PDF
"Towards Value-Centric Big Data" e-SIDES Workshop - "A win-win initiative for...
DOCX
PPTX
GDPR, Data Privacy.
PPTX
3d printing and biofabrication
PPTX
Medica 21 november 2013
PPTX
Health Database and Regulations in Taiwan (APrIGF2018)
PPT
Dataprotectionactnew13 12-11-111213033116-phpapp02
PPTX
Security & Privacy - Lecture E
PDF
GDPR for public sector DPO's seminar, April 2018, Manchester
PPT
What are health-y data and why are they tricky to publish?
PDF
GDPR for public sector DPO's, April 2018, Nottingham
PDF
DPOs in the public sector, May 2018, London
PDF
DPOs in the public sector, May 2018, Birmingham
PPTX
Privacy preserving on
PPTX
Basic principles to information privacy in data mining & data warehouse
PDF
Data Privacy, Ethics and Protection. A Guidance Note on Big Data for Achievem...
PPTX
What is the GDPR & What does it mean for YOUR business?
PPTX
ICAANZ VPDSS presentation by Paul O'Connor
PPTX
Are You GDPR Ready?
PPT
Securing_Medical_Devices_v3
"Towards Value-Centric Big Data" e-SIDES Workshop - "A win-win initiative for...
GDPR, Data Privacy.
3d printing and biofabrication
Medica 21 november 2013
Health Database and Regulations in Taiwan (APrIGF2018)
Dataprotectionactnew13 12-11-111213033116-phpapp02
Security & Privacy - Lecture E
GDPR for public sector DPO's seminar, April 2018, Manchester
What are health-y data and why are they tricky to publish?
GDPR for public sector DPO's, April 2018, Nottingham
DPOs in the public sector, May 2018, London
DPOs in the public sector, May 2018, Birmingham
Privacy preserving on
Basic principles to information privacy in data mining & data warehouse
Data Privacy, Ethics and Protection. A Guidance Note on Big Data for Achievem...
What is the GDPR & What does it mean for YOUR business?
ICAANZ VPDSS presentation by Paul O'Connor
Are You GDPR Ready?
Securing_Medical_Devices_v3
Ad

Similar to Osio workshop: Data Protection Regulation and Health Care (20)

PPTX
Data protection and data integrity
PPTX
GDPR and eHealth for the pharma industry (VFenR presentation)
PDF
LSA19: What Europe Can Teach U.S. Companies About Location and Data Privacy W...
PPTX
Seminar General Data Protection Regulation
PPTX
Presentation gdpr ahti
PPTX
EU Medical Device Clinical Research under the General Data Protection Regulation
PPTX
Paperless Lab Academy 'legal aspects of big data analytics'
PPTX
PLA Legal aspects of Big Data analytics final
PPTX
20200504_Research Data & the GDPR: How Open is Open?
PDF
GDPR and Research Data Management
PPTX
An itinerary for FAIR and privacy respecting data-driven innovation and research
PDF
Administrative and public law seminar
PDF
GDPR 11/1/2017
PDF
Be careful what you wish for: the great Data Protection law reform - Lilian E...
PPTX
The GDPR for Techies
PPTX
0303 Julius Zaleskis - GDPR and data protection for cancer advocates
PDF
EU GDPR and you: requirements for marketing
PPTX
EU General Data Protection Regulation top 8 operational impacts in personal c...
PPTX
20200429_Research Data & the GDPR: How Open is Open? (updated version)
PDF
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Data protection and data integrity
GDPR and eHealth for the pharma industry (VFenR presentation)
LSA19: What Europe Can Teach U.S. Companies About Location and Data Privacy W...
Seminar General Data Protection Regulation
Presentation gdpr ahti
EU Medical Device Clinical Research under the General Data Protection Regulation
Paperless Lab Academy 'legal aspects of big data analytics'
PLA Legal aspects of Big Data analytics final
20200504_Research Data & the GDPR: How Open is Open?
GDPR and Research Data Management
An itinerary for FAIR and privacy respecting data-driven innovation and research
Administrative and public law seminar
GDPR 11/1/2017
Be careful what you wish for: the great Data Protection law reform - Lilian E...
The GDPR for Techies
0303 Julius Zaleskis - GDPR and data protection for cancer advocates
EU GDPR and you: requirements for marketing
EU General Data Protection Regulation top 8 operational impacts in personal c...
20200429_Research Data & the GDPR: How Open is Open? (updated version)
Personal data: Legal Issues in Research Data Collection and Sharing by EUDAT ...
Ad

More from Ville Oksanen (20)

PDF
WIPO and EUDAT
PDF
105. #bisnestreffit: Tieto suojassa 10.10.2014
PDF
Tekijänoikeuskoulutus - Tampereen eOppimisen klusteri
PDF
Espoo lukiot II - Verkko - vaikuttamisen väline
PDF
Espoo lukio - DRAFT
PDF
Turku 10.3.2014 Normaalikoulu
PDF
Tekijänoikeus perusteet - 2014- Tampere
PDF
Ylläpidon Vastuukysymykset 2014 Tampere
PDF
Tietosuoja - 04022014
PDF
Digi.fi: Suomi, tietosuojan Sveitsi?
PDF
Trust & security - seminaari
PDF
Mindtrek 2013 - Citizens’ privacy and cloud services - heavenly opportunity
PDF
Verkot Vesille - Turku 11.10.2013
PDF
Turku- TVT Vesotori - 12.10.1013
PDF
Turku 6.3.2013
PDF
Virtuaaliopetuspäivät - Tekiijänoikeus
PDF
Veso271012
PDF
Okl221012
PDF
OKL - Turku - Tekijänoikeus
PDF
Tek l110512
WIPO and EUDAT
105. #bisnestreffit: Tieto suojassa 10.10.2014
Tekijänoikeuskoulutus - Tampereen eOppimisen klusteri
Espoo lukiot II - Verkko - vaikuttamisen väline
Espoo lukio - DRAFT
Turku 10.3.2014 Normaalikoulu
Tekijänoikeus perusteet - 2014- Tampere
Ylläpidon Vastuukysymykset 2014 Tampere
Tietosuoja - 04022014
Digi.fi: Suomi, tietosuojan Sveitsi?
Trust & security - seminaari
Mindtrek 2013 - Citizens’ privacy and cloud services - heavenly opportunity
Verkot Vesille - Turku 11.10.2013
Turku- TVT Vesotori - 12.10.1013
Turku 6.3.2013
Virtuaaliopetuspäivät - Tekiijänoikeus
Veso271012
Okl221012
OKL - Turku - Tekijänoikeus
Tek l110512

Recently uploaded (20)

PPTX
NUCLEAR-MEDICINE-Copy.pptxbabaabahahahaahha
PPTX
Electrolyte Disturbance in Paediatric - Nitthi.pptx
PDF
Comparison of Swim-Up and Microfluidic Sperm Sorting.pdf
PPT
neurology Member of Royal College of Physicians (MRCP).ppt
PDF
The Digestive System Science Educational Presentation in Dark Orange, Blue, a...
PPTX
09. Diabetes in Pregnancy/ gestational.pptx
PPTX
Reading between the Rings: Imaging in Brain Infections
PDF
OSCE Series ( Questions & Answers ) - Set 6.pdf
PDF
focused on the development and application of glycoHILIC, pepHILIC, and comm...
PDF
Lecture on Anesthesia for ENT surgery 2025pptx.pdf
PPTX
Neonate anatomy and physiology presentation
PPTX
Wheat allergies and Disease in gastroenterology
PDF
OSCE SERIES - Set 7 ( Questions & Answers ).pdf
PPTX
Acute Coronary Syndrome for Cardiology Conference
PPTX
thio and propofol mechanism and uses.pptx
PDF
Plant-Based Antimicrobials: A New Hope for Treating Diarrhea in HIV Patients...
PPTX
HYPERSENSITIVITY REACTIONS - Pathophysiology Notes for Second Year Pharm D St...
PPT
Infections Member of Royal College of Physicians.ppt
PPTX
Post Op complications in general surgery
PDF
OSCE Series Set 1 ( Questions & Answers ).pdf
NUCLEAR-MEDICINE-Copy.pptxbabaabahahahaahha
Electrolyte Disturbance in Paediatric - Nitthi.pptx
Comparison of Swim-Up and Microfluidic Sperm Sorting.pdf
neurology Member of Royal College of Physicians (MRCP).ppt
The Digestive System Science Educational Presentation in Dark Orange, Blue, a...
09. Diabetes in Pregnancy/ gestational.pptx
Reading between the Rings: Imaging in Brain Infections
OSCE Series ( Questions & Answers ) - Set 6.pdf
focused on the development and application of glycoHILIC, pepHILIC, and comm...
Lecture on Anesthesia for ENT surgery 2025pptx.pdf
Neonate anatomy and physiology presentation
Wheat allergies and Disease in gastroenterology
OSCE SERIES - Set 7 ( Questions & Answers ).pdf
Acute Coronary Syndrome for Cardiology Conference
thio and propofol mechanism and uses.pptx
Plant-Based Antimicrobials: A New Hope for Treating Diarrhea in HIV Patients...
HYPERSENSITIVITY REACTIONS - Pathophysiology Notes for Second Year Pharm D St...
Infections Member of Royal College of Physicians.ppt
Post Op complications in general surgery
OSCE Series Set 1 ( Questions & Answers ).pdf

Osio workshop: Data Protection Regulation and Health Care

  • 1. EU Privacy Regulation Update Dr. Ville Oksanen 18.4.2014 18. maaliskuuta 14
  • 2. Who’s talking.. • L.LM. , Ph.D. (Technology law) • At TKK (Aalto) since 2001 • At Helsinki University since 2009 • Partner, Turre Legal • Founder, Electronic Frontier Finland - Currently Vice Chairman • Blogger - “Lex Oksanen” 18. maaliskuuta 14
  • 4. Original goal • To update the existing regulation to meet the change in technologies • To give more rights to both citizens and also data protection authorities 18. maaliskuuta 14
  • 5. However.. • “Regulatory capture” in action • Heavy lobbying from e.g. • U.S Government • Facebook, Google etc. • To water down the proposal 18. maaliskuuta 14
  • 10. Key features • “Clarified definitions • Data protection by Design • Accountability + Notification of breaches • Portability + Right to Access (for free) • Right to Erasure • International regulatory scope? 18. maaliskuuta 14
  • 11. Sensitive data (Article 9) • ...revealing race or ethnic origin, political opinions, religion or philosophical beliefs, sexual orientation or gender identity, trade-union membership and activities , and the processing of genetic or biometric data or data concerning health or sex life, administrative sanctions, judgments, criminal or suspected offences, convictions or related security measures • (h) processing of data concerning health is necessary for health purposes and subject to the conditions and safeguards referred to in Article 81; or • (i) processing is necessary for historical, statistical or scientific research purposes subject to the conditions and safeguards referred to in Article 83; or 18. maaliskuuta 14
  • 12. Right to access and to obtain data 2a.  Where the data subject has provided the personal data where the personal data are processed by electronic means, the data subject shall have the right to obtain from the controller a copy of the provided personal data in an electronic and interoperable format which is commonly used and allows for further use by the data subject without hindrance from the controller from whom the personal data are withdrawn.Where technically feasible and available, the data shall be transferred directly from controller to controller at the request of the data subject. 18. maaliskuuta 14
  • 13. Profiling • Highly visible notification about right to object • Definition:“ 'profiling' means any form of automated processing of personal data intended to evaluate certain personal aspects relating to a natural person or to analyse or predict in particular that natural person’s performance at work, economic situation, location, health, personal preferences, reliability or behaviour; 18. maaliskuuta 14
  • 14. Data protection by Design Article 23: ”...Data protection by design shall have particular regard to the entire lifecycle management of personal data from collection to processing to deletion, systematically focusing on comprehensive procedural safeguards regarding the accuracy, confidentiality, integrity, physical security and deletion of personal data.” 18. maaliskuuta 14
  • 15. Right to Erasure • Most controversial feature • Many open questions • Practical (backups? Who pays the costs) • Content spesific (photographs? Discussions?) • Application to data given to 3rd parties? 18. maaliskuuta 14
  • 16. Respect to Risk • “The controller .. shall carry out a risk analysis of the potential impact of the intended data processing on the rights and freedoms of the data subjects, assessing whether its processing operations are likely to present specific risks.” • “(d) processing of personal data for the provision of health care, epidemiological researches, or surveys of mental or infectious diseases, where the data are processed for taking measures or decisions regarding specific individuals on a large scale;” 18. maaliskuuta 14
  • 17. Designation of the data protection officer • 1.  The controller and the processor shall designate a data protection officer in any case where: • ..d) the core activities of the controller or the processor consist of processing special categories of data pursuant to Article 9(1), location data or data on children or employees in large scale filing systems. 18. maaliskuuta 14
  • 20. Penalties • “At least” • “a warning in writing in cases of first and non-intentional non-compliance; 18. maaliskuuta 14
  • 21. Penalties • “At least” • “a warning in writing in cases of first and non-intentional non-compliance; • regular periodic data protection audits; 18. maaliskuuta 14
  • 22. Penalties • “At least” • “a warning in writing in cases of first and non-intentional non-compliance; • regular periodic data protection audits; • a fine up to 100 000 000 EUR or up to 5% of the annual worldwide turnover in case of an enterprise, whichever is higher. 18. maaliskuuta 14
  • 23. Article 80a: Access to documents • National law • “Reconciles the right to the protection of personal data with the principle of public access to official documents.” • Notification to the Commission 18. maaliskuuta 14
  • 24. Processing of personal data concerning health • Based on law (EU or national) • “consistent, and specific measures to safeguard the data subject's interests and fundamental rights, to the extent that these are necessary and proportionate , and of which the effects shall be foreseeable by the data subject” 18. maaliskuuta 14
  • 25. 3 categories of data • “preventive or occupational medicine, medical diagnosis, the provision of care or treatment or the management of health-care services” • “reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety • “other reasons of public interest in areas such as social protection, especially in order to ensure the quality and cost-effectiveness of the procedures used for settling claims for benefits and services in the health insurance system” 18. maaliskuuta 14
  • 26. Research exceptions • Consent required • “Where the data subject's consent is required for the processing of medical data exclusively for public health purposes of scientific research, the consent may be given for one or more specific and similar researches.” • Anonymisation or pseudonymisation under the highest technical standards 18. maaliskuuta 14
  • 27. Article 83 Processing for historical, statistical and scientific research purposes 1. In accordance with the rules set out in this Regulation, personal data may be processed for historical, statistical or scientific research purposes only if: (a) these purposes cannot be otherwise fulfilled by processing data which does not permit or not any longer permit the identification of the data subject; (b) data enabling the attribution of information to an identified or identifiable data subject is kept separately from the other information under the highest technical standards, and all necessary measures are taken to prevent unwarranted re-identification of the data subjects. 18. maaliskuuta 14