European Commission Website: Obligations of Data Controllers
Hi All, A few last summaries coming into the subgroup. Sorry for the delay! Busy days... Best, Kathy (below and attached) Document Name: *European Commission Website: Obligations of Data Controllers* Document Link: http://ec.europa.eu/justice/data-protection/data-collection/obligations/inde... Summary: This is a key question about whether ICANN is a data controller under the laws of the European Data Protection Directive? Data Controllers “determine 'the purposes and the means of the processing of personal data'” and it is a term that applies to both public and private sectors. See /Who can collect and process personal data?, /http://ec.europa.eu/justice/data-protection/data-collection/index_en.htm (submitted as a separate document) The EU Data Protection Directive requires Data Controllers to abide by certain principles when they process personal data. According to the European Commission: “Each *data controller* must respect the following rules as set out in the Directive: Personal Data must be processed legally and fairly; It must be collected for explicit and legitimate purposes and used accordingly; It must be adequate, relevant and not excessive in relation to the purposes for which it is collected and/or further processed; It must be accurate, and updated where necessary; Data controllers must ensure that data subjects can rectify, remove or block incorrect data about themselves; Data that identifies individuals (personal data) must not be kept any longer than strictly necessary; Data controllers must protect personal data against accidental or unlawful destruction, loss, alteration and disclosure, particularly when processing involves data transmission over networks. They shall implement the appropriate security measures; These protection measures must ensure a level of protection appropriate to the data.” Additional information: It is hard to put it more succinctly, so I quoted directly from the European Commission webpage.
Lisa, I would recommend adding this document to our list as it is directly relevant to other documents we are discussing. Summary below and attached. Many tx! Kathy Document Name: *European Commission Website: Data Controllers Defined* Document Link: http://ec.europa.eu/justice/data-protection/data-collection/index_en.htm Summary: The European Commission website provides information to define what is a Data Contoller. Data controllers are the persons or entities “which collect and process personal data.” Data controllers are also the persons or entities who “determine ‘the purposes and the means of the processing of personal data.’” This applies to both public and private sectors. According to the European Commission: Data controllers must respect the privacy and data protection rights of those whose personal data is entrusted to them. They must: * collect and process personal data only when this is legally permitted <http://ec.europa.eu/justice/data-protection/data-collection/legal/index_en.h...>; * respect certain obligations <http://ec.europa.eu/justice/data-protection/data-collection/obligations/inde...> regarding the processing of personal data; * respond to complaints <http://ec.europa.eu/justice/data-protection/data-collection/handling-complai...> regarding breaches of data protection rules; * collaborate with national data protection supervisory authorities <http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm>. Additional information: Obligations of data controllers are discussed on the European Commission website, http://ec.europa.eu/justice/data-protection/data-collection/obligations/inde..., and as a separate document on our privacy list.
participants (1)
-
Kathy Kleiman