data protection and you your rights & the law registration basics other activities disclaimer:...

42
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please consult the Data Protection Office for further queries.

Upload: jordan-woods

Post on 27-Dec-2015

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Data Protection and You

Your Rights & The LawRegistration Basics

Other ActivitiesDisclaimer: This presentation only provides an introductory info. Please consult the Data Protection Office for further queries.

Page 2: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

How does data

protection concern me? And

why it matters?

Page 3: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Would you have th

ought that…

these digita

l codes

might

represent

INFO about Y

OU!!!

Data Protection & You

Page 4: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Bank

Data Protection & You

Page 5: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Data Protection & You

Page 6: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Data Protection & You

Page 7: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Name

Address

Telephone

Data Protection & You

Page 8: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Data Protection & You

Page 9: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Did You Know

• More than 50 countries have Laws related to International Data Privacy*.

* http://www.informationshield.com/intprivacylaws.html

Data Protection & You

Page 10: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Did You Know

• Identity theft cases and data breaches are increasing worldwide*.

* http://www.identitytheft.infoData Protection & You

Page 11: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Are data breaches also prevalent in Mauritius?

Data Protection & You

Page 12: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

You might be the next Victim, so it is

important to know what Data Protection is

about…

Data Protection & You

Page 13: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please
Page 14: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

As individuals, you should have control over your personal data.

Your Rights & The Law

Page 15: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Enacted in 2004, Proclaimed in 2009.

DPA provides a legal framework to ensure that your personal information is handled properly.

Your Rights & The Law

Page 16: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

But…

Who Holds Info about Me?

Your Rights & The Law

Page 17: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Your Rights & The Law

Page 18: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Data Controllers are: People who decide how to use

personal data of living individuals

A medical practitioner

Human Resource Manager

A sports club manager

A public librarian

Your Rights & The Law

Page 19: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Can data controllers do

anything with my personal info???

Your Rights & The Law

Page 20: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

The Data Protection Office (DPO) enforces the provisions of the Data Protection Act

Mission of DPO:

Safeguard the privacy rights of all individuals with regard to the processing of their personal data.

Your Rights & The Law

Page 21: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Your Rights & The Law

Page 22: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Your Rights & The Law

Page 23: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

1. Fairly and lawfully processed.2. Collected for specified & lawful purpose/s.3. Adequate, relevant and not excessive.4. Accurate.5. Not kept longer than necessary.6. Processed in accordance with data subjects

rights.7. Secure.8. Not transferred to countries without

adequate data protection law.

Data collected must be:

Your Rights & The Law

Page 24: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please
Page 25: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

How do I register as a data controller?

1 for Employee

1 for Non-EmployeeNon-employee is any personal information pertaining to clients/suppliers/creditors/debtors/shareholders/board of directors (non-salaried) or any other categories of persons who are not employees, e.g subcontractors

Registration Basics

Page 26: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Registration Basics

Online Registration at

http://dataprotection.gov.mu

1. Log-in with your Username and password

Note: for 1st time users, a user account must be created using the guidelines online

2. Complete 2 separate forms & submit online

3. Await validation from DPO

4. Make payment at DPO

Get a copy of the application form at

http://dataprotection.gov.mu

or at the DPO

1. Fill in 2 separate forms2. Validate application forms at DPO

3. Make payment at DPO

Page 27: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Section 1 - Provide details about the organisation: public/private organisations, professionals, sole traders, partnerships, societes, etc...

Section 2 – Provide details of a contact person

Section 3 – List down only the TYPE of information and NOT the data being held for: (1)employee in the employee form and (2)non-employee in the non-employee form Note: ‘Name’ is a type but ‘John’ is the data. For registration purposes, only specify the type, i.e ‘Name’

Section 4 – Fill in for any sensitive data being held

Section 5 – Describe nature of business

Section 6 - Fill in for any disclosure to entities e.g National Pension Fund

Section 7 – Fill in for any transfer of data abroad

Section 8 – Confirm if information is disclosed to public

Registration Basics

Page 28: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Make payments for BOTH forms. Payment for non-employee form will bear the same amount as the employee form.

First time registrations for:Above 25 employees = Rs 2000 for employee + Rs 2000 for non-

employee

1-25 employees = Rs 1000 for employee + Rs 1000 for non-employee

Zero employee = Rs 800 for non-employee

Registration Basics

Page 29: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Registrations have to be renewed annually

by filling both employee and non-employee

application forms with respective payments.

Renewal fees for:Above 25 employees = Rs 1750 for employee + Rs 1750 for

non-employee

1-25 employees = Rs 750 for employee + Rs 750 for non-employee

Zero employee = Rs 550 for non-employee

Registration Basics

Page 30: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please
Page 31: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Other Activities

Page 32: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Who can make a complaint to the Data Protection Office?

Any individual who feels that the privacy rights with regard to his/her personal data may have been affected.

Other Activities

Page 33: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

1. Download and fill in a complaint form available on the Data Protection Office website.

2. Investigation is carried out on complaint unless complaint is of frivolous or vexatious nature.

3. Commissioner notifies complainant of the decision which has been taken.

4. Complainant can appeal to ICT tribunal if he/she is not satisfied with the decision.

Other Activities

Page 34: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Other Activities

Page 35: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

1. Download and fill in a Request for Access form found on the Data Protection Office website.

2. Submit the form along with a payment of Rs 75 to the data controller from whom the information is being requested.

3. Data controller must comply with a request not later than 28 days after receipt of request.

Other Activities

Page 36: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Data Protection Act

Data Protection Act

Enacted in 2004, proclaimed in 2009

D P OD P O Data Protection Office

DataData Personal and Sensitive information

Complaint FormComplaint Form Available from DPO Website

RegistrationRegistration For both employee and non-employee

Other Activities

Page 37: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Is the Data Protection Office a public one?

Yes.

Other Activities

Page 38: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

What can the Data Protection Office do when a data controller contravenes the Data Protection Act?

The Commissioner may serve an enforcement notice requiring the data controller to take steps and implement measures within a specified period of time.

Other Activities

Page 39: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

Is it an offence not to comply with the enforcement notice?

Yes. Any person who does not comply with the enforcement notice and does not have a reasonable excuse for not complying, will commit an offence, the penalty of which will be a fine not exceeding Rs 50,000 and imprisonment not exceeding 2 years.

Other Activities

Page 40: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

DATA PROTECTION OFFICE 4th Floor, Emmanuel Anquetil Building,

Port Louis

Website: http://dataprotection.gov.mu

Telephone: 201 3962, 201 2182

Page 41: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please

http://templateswise.com

http://www.infotheft.info

http://www.linkedin.com

http://www.facebook.com

http://office.microsoft.com

http://www.iconarchive.com

http://dataprotection.gov.mu

http://www.informationshield.com

Page 42: Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please