Security Best Practices in Hospital and Lab environment
https://www.lda.bayern.de/media/best_practice_cybersicherheit_medizin_baylda.pdf
EMA Big data web page
https://www.ema.europa.eu/en/about-us/how-we-work/big-data#data-protection-section
also “Discussion paper on the general data protection regulation: secondary use of data for medicines and public health purposes” at
http://www.encepp.eu/events/documents/Discussionpaper.pdf
AEPD/EDPS: 14 equívocos con relación a la identificación y autenticación biométrica
14 misconceptions regarding biometric identification and authentication
https://www.aepd.es/sites/default/files/2020-06/nota-equivocos-biometria.pdf
Germany: DSK position paper on email encryption
The DSK is the coordination body of the German Data Protection Authorities.
(published 13-March-2020, in German)
- normal risk -> mandatory transport encryption (with specific requirements)
- high risk -> qualified transport encryption and end-to-end (S/MIME, OpenPGP) – with specific requirements
Are cookie banners indeed compliant with the law? Deciphering EU legal requirements on consent and technical means to verify compliance of cookie banners
https://hal.inria.fr/hal-02875447/document
by Cristiana Santos, Nataliia Bielova and Célestin Matte
includes 22 legal and technical requirements for valid cookie banners!
(e.g. see page 15)
DPA Liechtenstein – Verfahrensbeschreibung für Datenschutzüberprüfungen
Process description for data protection inspections / privacy inspections / audits.
In a first step, the DPA is gathering information and statements based on a questionnaire.
In addition, the DPA regularly requests the following information in an electronic format or on paper:
- Records of processing activities (GDPR Art. 30 (4));
- Information to the affected persons (GDPR Art. 13 and 14);
- Templates of consent forms (GDPR Art. 7);
- Information about data protection trainings of employees;
- Contracts with processors (GDPR Art. 28 (3)) or other current contracts with external parties that get in touch with personal data, such as hardware and software partners, software vendors, application service providers, in which the applicable data protection controls need to be emphasized;
- Documentation of data breaches (GDPR Art. (5));
- Data protection impact assessments (GDPR Art. (35)).
In order to assess compliance to GDPR and the effectiveness of the controls, the DPA regularly asks for
- Organisational structure
- Privacy directive (privacy policy), security policy, emergency planning
- Review and audit reports – esp. in context of IT in scope
- Basic documentation of the IT infrastructure (hardware and software in use)
- Access control concept, especially access rights of administrators, external staff, sub-processors and other external parties
- Policies, instructions to users for the use of IT
- Non-disclosure, confidentiality agreements and other relevant instructions/agreements
- Controls and arrangements regarding the retention time and deletion of personal data (deletion concept)
Book (also free online): Law for Computer Scientists and Other Folk
By Mireille Hildebrandt
which includes e.g. sections on Machine Learning, Dsitributed Ledger and Legal by Design…
https://www.cohubicol.com/about/publications/law-for-computer-scientists-and-other-folk/
Available on OpenReview at MIT’s pubpub
https://lawforcomputerscientists.pubpub.org/
and as a PDF download
https://www.cohubicol.com/assets/uploads/law_for_computer_scientists.pdf
as well as hardcopy.
New Zealand: National Ethical Standards for Health and Disability Research and Quality Improvement
Belgian DPA fines social media platform Twoo 50,000 EUR over ‘tell-a-friend’ feature
GDPRhub – a free and open wiki on GDPR insights across Europe
powered by noyb.eu and others
From their Welcome page:
“In the decisions section we collect summaries of decisions by national DPAs and courts in English. The summaries can be searched by relevant GDPR article, issuing DPA or deciding court. Every day we monitor more than 50 webpages in each Member State. This page currently contains 300+ decisions and the goal is to reach 500+ by the end of 2020. We believe a good overview of national decisions is a key to a pan-European debate on the interpretation of contentious GDPR issues. Get all new decisions delivered right to your mailbox and subscribe to the GDPRtoday newsletter!
In the knowledge section we collect commentaries on GDPR articles, DPA profiles, and 32 GDPR jurisdictions (EU + EEA). In this database you can find anything from the phone number of the Icelandic DPA to a deep dive into each article of the GDPR.”