SlideShare a Scribd company logo
What’s new in ICT law
Andrew Cormack
John Kelly
Safe Harbor/Privacy Shield
»EU Data Protection compliance for exports to US private sector
»Original Safe Harbor ruled inadequate by ECJ, Sept 2015
› Largely on basis of Snowden revelations of NSA activity
»US/EU Commission announce “Privacy Shield”, Feb 2016
› Article 29WP expected to report mid-April on PS and other provisions
› Further legal/diplomatic argument likely thereafter
»Model clauses, Binding Corporate Rules, Consent more stable
»Or keep data in EU
22/03/2016 What's new in network law?
» Background
» So what does it all mean? (Spring 2018)
» Controllers and processors
» Data that’s covered
» Pseudonymisation
» Territorial scope
» Notification
» One stop shop – how laws are supervised
» Penalties
» Filing and record keeping
GDPR - General Data Protection Regulation
22/03/2016 Networkshopp 44
» DPOs
» Breach reporting
» Consent
» Data protection impact assessments
» Data subject rights
» Privacy by design and purpose limitation
» Export outside EU
» Transfers
» Data processors
» Digital consent for minors
» Exceptions
Incident Response/Breach Notification
»GDPR says prevention/detection/response = legitimate interests
› So OK to process personal data subject to balance of interests
»Breach notification a requirement for all controllers & processors
› All breaches affecting PD: record breach & response
› Risk to rights & freedoms: notify regulator asap (72 hr expectation)
– Nature of breach, consequences, #affected, steps taken/proposed
› High risk to individuals: notify them, in consultation with regulator
– Including what they can do to protect themselves
»Also notification requirements on trust services, telcos,
infrastructures…
22/03/2016 What's new in network law?
Investigatory Powers Bill
»Covers existing RIPA interception and comms data disclosure
»Also data retention, equipment interference, “technical facilities”
› Now extended to any “telecommunications operator”
› Not just data you generate or process; only limited by feasibility
»Creates Government powers, not operator duties
› No requirement till you receive an order
› Then probably can’t discuss it with anyone else
»Lack of clarity much criticised, including by all Parl’t committees
»Now at Committee stage in House of Commons
22/03/2016 What's new in network law?
»2005 - Fees/cost, time limits, exemptions
»2015 - Review launched – 3 central proposed changes
»2016 - After 10 years FOI is working well – some recommendations
»IPR and disclosures under FOI – Guidance Feb 2016
»FOI and research information: guidance for HE - 2015
Freedom of information
22/03/2016 Networkshopp 44
jisc.ac.uk
Find out more…
22/03/2016 Networkshopp 44
Andrew Cormack
John Kelly
Andrew.Cormack@jisc.ac.uk
John.Kelly@jisc.ac.uk

More Related Content

PPTX
Jisc and janet network updates from network operations, operational services ...
PPTX
Jisc Monitor workshop - Jo Lambert and Brian Mitchell - Jisc Digital Festival...
PPTX
Information security at University of East London: the benefits (and pitfalls...
PPTX
Directions in research data management - Jisc Digital Festival 2015
PPTX
Collaboration through technology: moving from possibility to practice - Marti...
PPTX
Eduroam in portsmouth's wireless city - Networkshop44
PPTX
Good practice in learning analytics - Jisc Digital Festival 2015
PPTX
Parallel session: trust and identity
Jisc and janet network updates from network operations, operational services ...
Jisc Monitor workshop - Jo Lambert and Brian Mitchell - Jisc Digital Festival...
Information security at University of East London: the benefits (and pitfalls...
Directions in research data management - Jisc Digital Festival 2015
Collaboration through technology: moving from possibility to practice - Marti...
Eduroam in portsmouth's wireless city - Networkshop44
Good practice in learning analytics - Jisc Digital Festival 2015
Parallel session: trust and identity

What's hot (20)

PPTX
Open access - a guide to Jisc's evolving offer to universities - Jisc Digital...
PPTX
Application of Assent in the safe - Networkshop44
PPTX
End to end performance - Networkshop44
PPTX
Repository and preservation systems
PPTX
Closing plenary - John Wilkin and David Maguire
PPTX
Kit-Catalogue - Discovering the Value of Equipment Sharing - Universities UK ...
PPTX
Next gen insight networkshop44
PPTX
Jisc Support for Asset Sharing - Kit-Catalogue National User Group November 2014
PPTX
Jisc's international strategy
PDF
Working with other sectors
PPTX
Helping you shape infrastructure to implement open access efficiently
PPTX
Something amazing from the University Library - libraries and research workin...
PPTX
Collaboration through technology: moving from possibility to practice
PPTX
Trust and identity services and architecture - Networkshop44
PPTX
Showcasing research data tools - Jisc Digifest 2016
PPTX
Collaboration through technology: moving from possibility to practice - Tim B...
PPTX
Challenges in end-to-end performance
PPTX
Stakeholder strategic update webinar - research
PPTX
Leveraging change through digital capability - James Clay, Chris Roberts, Tim...
PDF
The Kent PSN, govroam and HSCN
Open access - a guide to Jisc's evolving offer to universities - Jisc Digital...
Application of Assent in the safe - Networkshop44
End to end performance - Networkshop44
Repository and preservation systems
Closing plenary - John Wilkin and David Maguire
Kit-Catalogue - Discovering the Value of Equipment Sharing - Universities UK ...
Next gen insight networkshop44
Jisc Support for Asset Sharing - Kit-Catalogue National User Group November 2014
Jisc's international strategy
Working with other sectors
Helping you shape infrastructure to implement open access efficiently
Something amazing from the University Library - libraries and research workin...
Collaboration through technology: moving from possibility to practice
Trust and identity services and architecture - Networkshop44
Showcasing research data tools - Jisc Digifest 2016
Collaboration through technology: moving from possibility to practice - Tim B...
Challenges in end-to-end performance
Stakeholder strategic update webinar - research
Leveraging change through digital capability - James Clay, Chris Roberts, Tim...
The Kent PSN, govroam and HSCN
Ad

Viewers also liked (20)

PPTX
Eduroam seminar - Networkshop44 2016
PPTX
Welcome to Networkshop44 - Networkshop44
PPTX
Edupert best practices in supporting end users - Networkshop44
PPTX
Find out about Jisc - Networkshop44 2016
PPTX
Jisc update janet6 upgrade networkshop44
PPTX
End to end performance networkshop44
PPTX
Dealing with pervasive monitoring - Networkshop44
PPTX
Eduroam workshop nic mitev probes - networkshop44
PPTX
Network performance lessons from the coal face - Networkshop44
PPTX
Managing and monitoring large scale data transfers - Networkshop44
PPTX
Eduroam workshop nic mitev proactive learning - networkshop44
PPTX
Solving access for hybrid it Axians (introducing pulse secure) - Networkshop44
PPTX
Eduroam workshop nic mitev loughborough uni - networkshop44
PPTX
Multiprotocol label switching (mpls) - Networkshop44
PPTX
Hyper efficient data centres – key ingredient intelligence networkshop44
PPTX
Dev ops, noops or hypeops - Networkshop44
PPTX
Tv white space reusing old spectrum in innovative ways - Networkshop44
PPTX
Readying the campus for the internet of things (io t) - Networkshop44
PPTX
Campus network refresh - Networkshop44
PPTX
Using sdn to secure the campus - Networkshop44
Eduroam seminar - Networkshop44 2016
Welcome to Networkshop44 - Networkshop44
Edupert best practices in supporting end users - Networkshop44
Find out about Jisc - Networkshop44 2016
Jisc update janet6 upgrade networkshop44
End to end performance networkshop44
Dealing with pervasive monitoring - Networkshop44
Eduroam workshop nic mitev probes - networkshop44
Network performance lessons from the coal face - Networkshop44
Managing and monitoring large scale data transfers - Networkshop44
Eduroam workshop nic mitev proactive learning - networkshop44
Solving access for hybrid it Axians (introducing pulse secure) - Networkshop44
Eduroam workshop nic mitev loughborough uni - networkshop44
Multiprotocol label switching (mpls) - Networkshop44
Hyper efficient data centres – key ingredient intelligence networkshop44
Dev ops, noops or hypeops - Networkshop44
Tv white space reusing old spectrum in innovative ways - Networkshop44
Readying the campus for the internet of things (io t) - Networkshop44
Campus network refresh - Networkshop44
Using sdn to secure the campus - Networkshop44
Ad

Similar to Whats new in ict law - Networkshop44 (20)

PDF
Data Breaches and the EU GDPR
PDF
FINAL REPORT
PPTX
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
PPTX
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
PPTX
Internet and eCommerce Law Review 2016
PPTX
EU GDPR: The role of the data protection officer
PDF
Privacy Year In Preview
PPTX
EU Data Protection Regulation 26 June 2012
PDF
Flight East 2018 Presentation–Data Breaches and the Law
PPTX
Big data needs big protection
PPTX
20 Years of Internet law @Gikii
PPT
New Security Legislation & It's Implications for OSS Management
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
PPTX
Cyber Security Conference 2017
PPTX
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
PDF
20140317eyinformationsupp
PDF
Data_Privacy_Protection_brochure_UK
PDF
No Man is an Island: The Battle for Data Privacy
PDF
Privacy & Analytics: Yeti or Snow Fairy?
PDF
2017: Privacy Issues on the Horizon
Data Breaches and the EU GDPR
FINAL REPORT
Internet of Things (IotT) Legal Issues Privacy and Cybersecurity
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
Internet and eCommerce Law Review 2016
EU GDPR: The role of the data protection officer
Privacy Year In Preview
EU Data Protection Regulation 26 June 2012
Flight East 2018 Presentation–Data Breaches and the Law
Big data needs big protection
20 Years of Internet law @Gikii
New Security Legislation & It's Implications for OSS Management
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
Cyber Security Conference 2017
Pronti per la legge sulla data protection GDPR? No Panic! - Domenico Maracci,...
20140317eyinformationsupp
Data_Privacy_Protection_brochure_UK
No Man is an Island: The Battle for Data Privacy
Privacy & Analytics: Yeti or Snow Fairy?
2017: Privacy Issues on the Horizon

More from Jisc (20)

PPTX
Strengthening open access through collaboration: building connections with OP...
PPTX
Andrew-Brown-JUSP-showcase-20240730.pptx
PPTX
JUSP Showcase - Rebuilding Data presentation
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
FE Accessibility training matrix partnership - information session
PPTX
Procuring a research management system: why is it so hard?
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
How libraries can support authors with open access requirements for UKRI fund...
PPTX
Supporting (UKRI) OA monographs at Salford.pptx
PPTX
The approach at University of Liverpool.pptx
PPTX
Jisc's value to HE: the University of Sheffield
PPTX
Towards a code of practice for AI in AT.pptx
PPTX
Jamworks pilot and AI at Jisc (20/03/2024)
PPTX
Wellbeing inclusion and digital dystopias.pptx
PPTX
Accessible Digital Futures project (20/03/2024)
PPTX
Procuring digital preservation CAN be quick and painless with our new dynamic...
PPTX
International students’ digital experience: understanding and mitigating the ...
PPTX
Digital Storytelling Community Launch!.pptx
PPTX
Open Access book publishing understanding your options (1).pptx
PPTX
Scottish Universities Press supporting authors with requirements for open acc...
Strengthening open access through collaboration: building connections with OP...
Andrew-Brown-JUSP-showcase-20240730.pptx
JUSP Showcase - Rebuilding Data presentation
Adobe Express Engagement Webinar (Delegate).pptx
FE Accessibility training matrix partnership - information session
Procuring a research management system: why is it so hard?
Adobe Express Engagement Webinar (Delegate).pptx
How libraries can support authors with open access requirements for UKRI fund...
Supporting (UKRI) OA monographs at Salford.pptx
The approach at University of Liverpool.pptx
Jisc's value to HE: the University of Sheffield
Towards a code of practice for AI in AT.pptx
Jamworks pilot and AI at Jisc (20/03/2024)
Wellbeing inclusion and digital dystopias.pptx
Accessible Digital Futures project (20/03/2024)
Procuring digital preservation CAN be quick and painless with our new dynamic...
International students’ digital experience: understanding and mitigating the ...
Digital Storytelling Community Launch!.pptx
Open Access book publishing understanding your options (1).pptx
Scottish Universities Press supporting authors with requirements for open acc...

Recently uploaded (20)

PDF
Sports Quiz easy sports quiz sports quiz
PPTX
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
PPTX
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
PPTX
Final Presentation General Medicine 03-08-2024.pptx
PDF
VCE English Exam - Section C Student Revision Booklet
PPTX
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
PPTX
Institutional Correction lecture only . . .
PDF
TR - Agricultural Crops Production NC III.pdf
PPTX
Lesson notes of climatology university.
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PDF
Classroom Observation Tools for Teachers
PDF
Chapter 2 Heredity, Prenatal Development, and Birth.pdf
PDF
O7-L3 Supply Chain Operations - ICLT Program
PDF
Computing-Curriculum for Schools in Ghana
PDF
Basic Mud Logging Guide for educational purpose
PDF
01-Introduction-to-Information-Management.pdf
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PDF
Complications of Minimal Access Surgery at WLH
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
Sports Quiz easy sports quiz sports quiz
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
Final Presentation General Medicine 03-08-2024.pptx
VCE English Exam - Section C Student Revision Booklet
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
Institutional Correction lecture only . . .
TR - Agricultural Crops Production NC III.pdf
Lesson notes of climatology university.
O5-L3 Freight Transport Ops (International) V1.pdf
Classroom Observation Tools for Teachers
Chapter 2 Heredity, Prenatal Development, and Birth.pdf
O7-L3 Supply Chain Operations - ICLT Program
Computing-Curriculum for Schools in Ghana
Basic Mud Logging Guide for educational purpose
01-Introduction-to-Information-Management.pdf
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
Complications of Minimal Access Surgery at WLH
Module 4: Burden of Disease Tutorial Slides S2 2025
3rd Neelam Sanjeevareddy Memorial Lecture.pdf

Whats new in ict law - Networkshop44

  • 1. What’s new in ICT law Andrew Cormack John Kelly
  • 2. Safe Harbor/Privacy Shield »EU Data Protection compliance for exports to US private sector »Original Safe Harbor ruled inadequate by ECJ, Sept 2015 › Largely on basis of Snowden revelations of NSA activity »US/EU Commission announce “Privacy Shield”, Feb 2016 › Article 29WP expected to report mid-April on PS and other provisions › Further legal/diplomatic argument likely thereafter »Model clauses, Binding Corporate Rules, Consent more stable »Or keep data in EU 22/03/2016 What's new in network law?
  • 3. » Background » So what does it all mean? (Spring 2018) » Controllers and processors » Data that’s covered » Pseudonymisation » Territorial scope » Notification » One stop shop – how laws are supervised » Penalties » Filing and record keeping GDPR - General Data Protection Regulation 22/03/2016 Networkshopp 44 » DPOs » Breach reporting » Consent » Data protection impact assessments » Data subject rights » Privacy by design and purpose limitation » Export outside EU » Transfers » Data processors » Digital consent for minors » Exceptions
  • 4. Incident Response/Breach Notification »GDPR says prevention/detection/response = legitimate interests › So OK to process personal data subject to balance of interests »Breach notification a requirement for all controllers & processors › All breaches affecting PD: record breach & response › Risk to rights & freedoms: notify regulator asap (72 hr expectation) – Nature of breach, consequences, #affected, steps taken/proposed › High risk to individuals: notify them, in consultation with regulator – Including what they can do to protect themselves »Also notification requirements on trust services, telcos, infrastructures… 22/03/2016 What's new in network law?
  • 5. Investigatory Powers Bill »Covers existing RIPA interception and comms data disclosure »Also data retention, equipment interference, “technical facilities” › Now extended to any “telecommunications operator” › Not just data you generate or process; only limited by feasibility »Creates Government powers, not operator duties › No requirement till you receive an order › Then probably can’t discuss it with anyone else »Lack of clarity much criticised, including by all Parl’t committees »Now at Committee stage in House of Commons 22/03/2016 What's new in network law?
  • 6. »2005 - Fees/cost, time limits, exemptions »2015 - Review launched – 3 central proposed changes »2016 - After 10 years FOI is working well – some recommendations »IPR and disclosures under FOI – Guidance Feb 2016 »FOI and research information: guidance for HE - 2015 Freedom of information 22/03/2016 Networkshopp 44
  • 7. jisc.ac.uk Find out more… 22/03/2016 Networkshopp 44 Andrew Cormack John Kelly Andrew.Cormack@jisc.ac.uk John.Kelly@jisc.ac.uk

Editor's Notes

  • #4: Pseudonymised Data is created by taking identifying fields within a database and replacing them with artificial identifiers, or pseudonyms.
  • #7: 1. Some History – Is anyone here directly involved in responding to FOI requests on a regular basis? I confess to being an FOI nerd not just because it causes embarrassment to public officials about the cost of refurbishing their offices or the fact that it is used to prise information out of Government such as the fact that British pilots are bombing Syria – But because it has made us all more conscious of records management and information Governance – good information practice and categorisation. 2. Three central proposed changes: charging for the requests, making it easier to refuse requests on cost grounds and giving ministers more powers to veto disclosures so that Whitehall has a safe place where civil servants and ministers can devise policy out of the public eye 3. We were not kept in suspense very long - Commission instigated by Matthew Hancock, the Cabinet Office minister, found that after 10 years, FoI is working well - Some recommendations publish all requests and responses where they provide information to a requestor publish statistics 4. IPR and disclosures under FOI – Guidance Feb 2016 Once disclosed, the information is still protected by IP Intellectual property rights 5. How FOI should be applied to scientific research – particularly pre-publication research information - Different types of information are held by HEIs – information may be of particular public interest; of commercial interest; provided in confidence; or sometimes controversial This guidance provides practical case examples derived from ICO decision notices and Information Rights Tribunal decisions