Information about Data Privacy

Data privacy refers to the evolving relationship between technology and the legal right to, or public expectation of privacy in the collection and sharing of data.

Privacy concerns exist wherever uniquely identifiable data relating to a person or persons are collected and stored, in digital form or otherwise. Improper or non-existent disclosure control can be the root cause for privacy issues. The most common sources of data privacy issues are:
  • Health information
  • Criminal justice
  • Financial information
  • Genetic information
  • Location information
  • In some cases even ethnic or gender information
The challenge in data privacy is to share data while protecting personally identifiable information. Consider the example of health data which are collected from hospitals in a district; it is standard practice to share this only in the aggregate. The idea of sharing the data in the aggregate is to ensure that only non-identifiable data are shared.

The legal protection of the right to privacy in general and of data privacy in particular varies greatly around the world.

The Universal Declaration of Human Rights states in its article 12 that:
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.

Protecting privacy in information systems

Increasingly, as heterogeneous information systems with different privacy rules are interconnected, technical control and logging mechanisms (policy appliances) will be required to reconcile, enforce and monitor privacy policy rules (and laws) as information is shared across systems and to ensure accountability for information use. There are several technologies to address privacy protection in enterprise IT systems. These fall into two categories: communication and enforcement.

Policy Communication
  • P3P - The Platform for Privacy Preferences. P3P is a standard for communicating privacy practices and comparing them to the preferences of individuals.
Policy Enforcement
  • XACML - The Extensible Access Control Markup Language together with its Privacy Profile is a standard for expressing privacy policies in a machine-readable language which a software system can use to enforce the policy in enterprise IT systems.
  • EPAL - The Enterprise Privacy Authorization Language is very similar to XACML, but is not yet a standard.
  • WS-Privacy - "Web Service Privacy" will be a specification for communicating privacy policy in web services. For example, it may specify how privacy policy information can be embedded in the SOAP envelope of a web service message.

United States

Data privacy is not highly legislated or regulated in the U.S.. In the United States, access to private data is culturally acceptable in many cases, such as credit reports for employment or housing purposes. Although partial regulations exist, for instance the Children's Online Privacy Protection Act and HIPAA, there is no all-encompassing law regulating the use of personal data. The culture of free speech in the U.S. may be a reason for the reluctance to trust the government to protect personal information. In the U.S. the first amendment protects free speech and in many instances privacy conflicts with this amendment. In many countries privacy has been used as a tool to suppress free speech.

The safe harbor arrangement was developed by the US Department of Commerce in order to provide a means for US companies to demonstrate compliance with European Commission directives and thus to simplify relations between them and European businesses.

The Supreme Court interpreted the Constitution to grant a right of privacy to individuals in Griswold v. Connecticut. Very few states, however, recognize an individual's right to privacy, a notable exception being California. An inalienable right to privacy is enshrined in the California Constitution's article 1, section 1, and the California legislature has enacted several pieces of legislation aimed at protecting this right. The California Online Privacy Protection Act (OPPA) of 2003 requires operators of commercial web sites or online services that collect personal information on California residents through a web site to conspicuously post a privacy policy on the site and to comply with its policy.

Canada

In Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) went into effect in relation to federally regulated organizations on 1 January 2001, and in relation to all other organizations on 1 January 2004. It brings Canada into compliance with the requirements of the European Commission's directive. For more information, visit the website of the Privacy Commissioner of Canada. The text of the Act may be found at [1].

Europe

The right to data privacy is heavily regulated and rigidly enforced in Europe. Article 8 of the European Convention on Human Rights (ECHR) provides a right to respect for one's "private and family life, his home and his correspondence", subject to certain restrictions. The European Court of Human Rights has given this article a very broad interpretation in its jurisprudence. According to the Court's case law the collection of information by officials of the state about an individual without his consent always falls within the scope of article 8. Thus, gathering information for the official census, recording fingerprints and photographs in a police register, collecting medical data or details of personal expenditures and implementing a system of personal identification have been judged to raise data privacy issues. Any state interference with a person's privacy is only acceptable for the Court if three conditions are fulfilled: (1) the interference is in accordance with the law, (2) pursues a legitimate goal and (3) is necessary in a democratic society. For more information, please refer to Human Rights Handbook no. 1 (PDF) or the Council of Europe data protection page.

The government isn't the only one who might pose a threat to data privacy, far from it. Other citizens, and private companies most importantly, engage in far more threatening activities, especially since the automated processing of data became widespread. The Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data was concluded within the Council of Europe in 1981. This convention obliges the signatories to enact legislation concerning the automatic processing of personal data, which many duly did.

As all the member states of the European Union are also signatories of the European Convention on Human Rights and the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, the European Commission was concerned that diverging data protection legislation would emerge and impede the free flow of data within the EU zone. Therefore the European Commission decided to harmonize data protection regulation and proposed the Directive on the protection of personal data, which member states had to transpose into law by the end of 1998.

The directive contains a number of key principles which must be complied with. Anyone processing personal data must comply with the eight enforceable principles of good practice.
They say that data must be:
  • Fairly and lawfully processed.
  • Processed for limited purposes.
  • Adequate, relevant and not excessive.
  • Accurate.
  • Not kept longer than necessary.
  • Processed in accordance with the data subject's rights.
  • Secure.
  • Not transferred to countries without adequate protection.
Personal data covers both facts and opinions about the individual. It also includes information regarding the intentions of the data controller towards the individual, although in some limited circumstances exemptions will apply. With processing, the definition is far wider than before. For example, it incorporates the concepts of 'obtaining', 'holding' and 'disclosing'. For more details on these data principles, read the article about the directive on the protection of personal data or visit the EU data protection page.

All EU member states adopted legislation pursuant this directive or adapted their existing laws. Each country also has its own supervisory authority to monitor the level of protection.

Safe Harbor Program

The US Department of Commerce created the Safe Harbor certification program in response to the 1995 Directive on Data Protection (Directive 95/46/EC) of the European Commission. Directive 95/46/EC declares in Chapter IV Article 25 that personal data may only be transferred from the EU to countries which provide a level of privacy protection equivalent to that of the EU. This introduced a legal risk to organizations which transfer the personal data of European citizens to servers in the USA. Such organizations could be penalized under EU laws if the privacy protection of the USA were to be deemed weaker than that of the EU. The Safe Harbor program addresses this issue. Under this program, the European Commission agreed to forbid European citizens from suing US companies for transmitting personal data into the USA. ICT

See also

External links

International Australia U.S. Canada Europe
  • Council of Europe data protection page
  • EU data protection page - The European Commission provides elaborate information on the following subjects:
  • Legislative documents
  • Transposition and implementation of Directive 95/46/EC
  • European Data Protection Supervisor
  • National Data Protection Commissioners
  • Art. 29 Data protection Working Party
  • Adequacy of protection in third countries and model contracts for the transfer of personal data to third countries
  • International links
  • Commission nationale de l'informatique et des libertés, the regulatory body enforcing privacy rules in data bases in France.

Resources



The open fields doctrine is a U.S. legal doctrine created judicially for purposes of evaluating claims of an unreasonable search by the government in violation of the Fourth Amendment of the U.S.
..... Click the link for more information.
For other uses, see Data (disambiguation).


Debt, AIDS, Trade in Africa (or DATA) is a multinational non-government organization founded in January 2002 in London by U2's Bono along with Bobby Shriver and activists from the Jubilee 2000 Drop
..... Click the link for more information.
Privacy has no definite boundaries and it has different meanings for different people. It is the ability of an individual or group to keep their lives and personal affairs out of public view, or to control the flow of information about themselves.
..... Click the link for more information.
The Universal Declaration of Human Rights (abbreviated UDHR) is an advisory declaration adopted by the United Nations General Assembly (A/RES/217, 10 December 1948 at Palais de Chaillot, Paris).
..... Click the link for more information.
Policy appliances are technical control and logging mechanisms to enforce or reconcile policy rules (information use rules) and to ensure accountability in information systems.
..... Click the link for more information.
The Platform for Privacy Preferences Project, or P3P, is a protocol allowing websites to declare their intended use of information they collect about browsing users.
..... Click the link for more information.
XACML stands for eXtensible Access Control Markup Language. It is a declarative access control policy language implemented in XML and a processing model, describing how to interpret the policies.

Latest version 2.
..... Click the link for more information.
The W3C defines a Web service (many sources also capitalize the second word, as in Web Services) as "a software system designed to support interoperable Machine to Machine interaction over a network.
..... Click the link for more information.
Simple Object Access Protocol, and lately also Service Oriented Architecture Protocol, but is now simply SOAP. The original acronym was dropped with Version 1.2 of the standard, which became a W3C Recommendation on June 24 2003, as it was considered to be misleading.
..... Click the link for more information.
Motto
"In God We Trust"   (since 1956)
"E Pluribus Unum"   ("From Many, One"; Latin, traditional)
Anthem
..... Click the link for more information.
Children's Online Privacy Protection Act of 1998[1] (COPPA)[2] is a United States federal law, located at Title 15, Section 6501, et seq., of the United States Code.
..... Click the link for more information.
The Health Insurance Portability and Accountability Act (HIPAA) was enacted by the U.S. Congress in 1996.

According to the Centers for Medicare and Medicaid Services (CMS) website, Title I of HIPAA protects health insurance coverage for workers and their families when
..... Click the link for more information.
The US Safe Harbor Arrangement is a streamlined process for US companies to comply with EU Directive 95/46/EC on the protection of personal data, developed by the US Department of Commerce in consultation with EU.
..... Click the link for more information.
Untied States
Department of Commerce


Seal of the Department of Commerce
Agency overview
Formed February 14, 1903

Employees 36,000 (2004)
Annual Budget $9.
..... Click the link for more information.
Griswold v. Connecticut
Supreme Court of the United States
Argued March 29, 1965
Decided June 7, 1965

Full case name: Estelle T. Griswold and C. Lee Buxton v. Connecticut

Citations: &page=479 381 U.S. 479 ; 85 S. Ct. 1678; 14 L.
..... Click the link for more information.
Editing of this page by unregistered or newly registered users is currently disabled due to vandalism.
If you are prevented from editing this page, and you wish to make a change, please discuss changes on the talk page, request unprotection, log in, or .
..... Click the link for more information.
California Constitution is the document that establishes and describes the duties, powers, structure and function of the government of the U.S. state of California. The original constitution, adopted in November 1849 in the U.S.
..... Click the link for more information.
This page is currently protected from editing until disputes have been resolved.
Protection is not an endorsement of the current [ version] ([ protection log]).
..... Click the link for more information.
The Personal Information Protection and Electronic Documents Act (abbreviated PIPEDA or PIPED Act) is a Canadian law relating to data privacy. It governs how private-sector organizations collect, use and disclose personal information in the course of commercial
..... Click the link for more information.
January 1 is the 1st day of the year (2nd in leap years) in the Gregorian calendar. There are 0 days remaining. The preceding day is December 31 of the previous year.
..... Click the link for more information.
21st century - 22nd century
1970s  1980s  1990s  - 2000s -  2010s  2020s  2030s
1998 1999 2000 - 2001 - 2002 2003 2004

2001 by topic:
News by month
Jan - Feb - Mar - Apr - May - Jun
..... Click the link for more information.
January 1 is the 1st day of the year (2nd in leap years) in the Gregorian calendar. There are 0 days remaining. The preceding day is December 31 of the previous year.
..... Click the link for more information.
20th century - 21st century - 22nd century
1970s  1980s  1990s  - 2000s -  2010s  2020s  2030s
2001 2002 2003 - 2004 - 2005 2006 2007

2004 by topic:
News by month
Jan - Feb - Mar - Apr - May - Jun
..... Click the link for more information.
Convention for the Protection of Human Rights and Fundamental Freedoms, also known as the European Convention on Human Rights (ECHR), was adopted under the auspices of the Council of Europe[1] in 1950 to protect human rights and fundamental freedoms.
..... Click the link for more information.
European Court of Human Rights (ECtHR) in Strasbourg was set up under the European Convention on Human Rights of 1950 in order to monitor compliance by Signatory Parties.
..... Click the link for more information.
Jurisprudence is the theory and philosophy of law. Scholars of jurisprudence, or legal philosophers, hope to obtain a deeper understanding of the nature of law, of legal reasoning, legal systems and of legal institutions.
..... Click the link for more information.
A census is the process of obtaining information about every member of a population (not necessarily a human population). The term is mostly used in connection with national 'population and housing censuses' (to be taken every 10 years according to United Nations recommendations);
..... Click the link for more information.
fingerprint is an impression of the friction ridges of all or any part of the finger.[1] A friction ridge is a raised portion of the epidermis on the palmar (palm and fingers) or plantar (sole and toes) skin, consisting of one or more connected ridge units of friction
..... Click the link for more information.
photograph (often shortened to photo) is an image created by light falling on a light-sensitive surface, usually photographic film or an electronic imager such as a CCD or a CMOS chip.
..... Click the link for more information.
Anthem
Ode to Joy (orchestral)


..... Click the link for more information.


This article is copied from an article on Wikipedia.org - the free encyclopedia created and edited by online user community. The text was not checked or edited by anyone on our staff. Although the vast majority of the wikipedia encyclopedia articles provide accurate and timely information please do not assume the accuracy of any particular article. This article is distributed under the terms of GNU Free Documentation License.
Herod_Archelaus


page counter