Legal News – Privacy Design® / [protecting people by good design, solid security, efficient processes and trusted services] Mon, 30 Nov 2020 09:15:15 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.4 /wp-content/uploads/2018/02/cropped-favicon-32x32.jpg Legal News – Privacy Design® / 32 32 Germany: Referentenentwurf DVMPG /2020/11/30/germany-referentenentwurf-dvmpg/ Mon, 30 Nov 2020 09:15:00 +0000 /?p=2643 Continue reading "Germany: Referentenentwurf DVMPG"

]]>
Draft for new German law to modernize health care
(Digitale Versorgung und Pflege – Modernisierungs-Gesetz – DVPMG)

This includes important changes to DIGAV!
(See “Artikel 8”, page 44ff)

  • From 1.Jan 2023 DIGA (digital health applications) would need to be able to export data into a the electronic patient file (elektronische Patientenakte)
  • Also new requirements on certified information security management (from no later than 1 Jan 2022) and a BSI certificate on data security (from 1 Jan 2023). This also applies to digital health applications which are already registered.
  • Also new requirements on integrating with the electronic patient card for authentication (elektronische Gesundheitskarte) – unless the DIGA is purely web-based. (31 Dec 2020)
  • Also the vendor needs to ensure that the provided health information is kept up-to-date.

https://www.bundesgesundheitsministerium.de/fileadmin/Dateien/3_Downloads/Gesetze_und_Verordnungen/GuV/D/Referentenentwurf_DVPMG.pdf

]]>
Paper (in German): Data processing by Medical Services (of the company) /2020/10/21/paper-in-german-data-processing-by-medical-services-of-the-company/ Wed, 21 Oct 2020 09:49:24 +0000 /?p=2462 Die Datenverarbeitung des Betriebsarztes
Hinweise zum datenschutzgerechten Umgang mit Patientendaten durch Betriebsärzte und betriebsärztliche Dienste

https://www.netzwerk-datenschutzexpertise.de/sites/default/files/gut_2020_09_betriebsarzt_v1_0.pdf

(Medizinische Dienste)

]]>
Switzerland: New Data Protection Law passed parliament /2020/09/25/switzerland-new-data-protection-law-passed-parliament/ Fri, 25 Sep 2020 09:15:22 +0000 /?p=2367 Continue reading "Switzerland: New Data Protection Law passed parliament"

]]>
Next step, is waiting if there will be a referendum. (100 day period)
The FDPIC will make detailled statements on the new law once the referendum period has passed.

There is a good write-up in German by Noémi Ziegler at
https://datenrecht.ch/die-dsg-revision-ist-abgeschlossen/

David Rosenthal (VISCHER) has a summary at
https://www.vischer.com/know-how/blog/neues-datenschutzgesetz-das-muessen-sie-wissen-38752/

Final text (in parliament) is here:
https://www.parlament.ch/centers/eparl/curia/2017/20170059/Schluzssabstimmungstext%203%20NS%20D.pdf

The VUD published an overview here:
http://www.vud.ch/view/data/2124/vud_rohstoff_revidiertes_dsg.pdf

]]>
CNIL guidance on data deletion and retention /2020/09/08/cnil-guidance-on-data-deletion-and-retention/ Tue, 08 Sep 2020 04:51:06 +0000 /?p=2309 Continue reading "CNIL guidance on data deletion and retention"

]]>
In July 2020, the CNIL (DPA for France) published guidelines on data retention (Guide pratique – Les durées de conservation). https://www.cnil.fr/sites/default/files/atoms/files/guide_durees_de_conservation.pdf

These reflect early CNIL recommendations from 11-Oct-2005 on the archiving of personal data.
They aim to provide practical help to define the data retention rules and periods.
Similar to DIN-66398 (German industry standard on data retention/deletion) they don’t include guidance on specific data categories. https://din-66398.de/

However, CNIL does define data retention periods in separate dcouments (“Référentiel”). Up to now, two such Référentiels have been published for the health sector:

]]>
IAPP GDPR genius tool /2019/05/26/iapp-gdpr-genius-tool/ Sun, 26 May 2019 19:30:03 +0000 /?p=708 IAPP tool for members to look up GDPR-related references

https://iapp.org/resources/article/gdpr-genius/

]]>
Fieldfisher’s four parts blog on CCPA /2019/05/12/fieldfishers-four-parts-blog-on-ccpa/ Sun, 12 May 2019 15:30:43 +0000 /?p=686 Continue reading "Fieldfisher’s four parts blog on CCPA"

]]>

Fieldfisher has a very readable four parts blog on the California Consumer Privacy Act 2018 (CCPA)

]]>
European Commission adopts adequacy decision on Japan, creating the world’s largest area of safe data flows /2019/02/03/european-commission-adopts-adequacy-decision-on-japan-creating-the-worlds-largest-area-of-safe-data-flows/ Sun, 03 Feb 2019 22:38:34 +0000 /?p=674 http://europa.eu/rapid/press-release_IP-19-421_en.htm

Japan adequacy decision and related documents
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en

]]>
EU commission response on contractual form of data processing agreements /2018/09/09/eu-commission-response-on-contractual-form-of-data-processing-agreements/ Sun, 09 Sep 2018 16:46:40 +0000 /?p=626 Continue reading "EU commission response on contractual form of data processing agreements"

]]>
“The GDPR further provides that such contract or legal act shall be in writing, including in electronic form. [..] In principle, automated contract processes are lawful. It is not necessary to append an electronic signature to contracts for them to have legal effects. E-signatures are one of several means to prove their conclusion and terms.[..]”

Full text:
http://www.europarl.europa.eu/sides/getAllAnswers.do?reference=E-2018-003163&language=EN

]]>
Belgium: new Belgian Data Protection Act (September 5, 2018) /2018/09/09/belgium-new-belgian-data-protection-act-september-5-2018/ Sun, 09 Sep 2018 15:37:50 +0000 /?p=623 Continue reading "Belgium: new Belgian Data Protection Act (September 5, 2018)"

]]>
The new Belgian Data Protection Act
http://www.ejustice.just.fgov.be/eli/wet/2018/07/30/2018040581/staatsblad

Sidley has an article on it here:
https://datamatters.sidley.com/new-belgian-data-protection-act-takes-effect/

“Genetic, Biometric and Health-Related Data Processing

Additional organizational and security measures must be put in place by data controllers and/or processors that process genetic, biometric or health-related data. On the basis of the Belgian Act, they must designate specific personnel authorized to access such data, and identify their capacity in relation to the data processing. A list with this information should be compiled and kept at the disposal of the competent Supervisory Authority. In addition, they must ensure that these individuals are bound by confidentiality with regard to this data on the basis of either statutory or contractual requirements.”

]]>
Sidley article on the new privacy law in California /2018/06/30/sidley-article-on-the-new-privacy-law-in-california/ Sat, 30 Jun 2018 17:30:10 +0000 /?p=620 On June 28, 2018, California Gov. Jerry Brown signed into law the California Consumer Privacy Act of 2018 (AB 375).
AB 375 will go into effect on Jan. 1, 2020, unless changed in the interim.

While it has been compared with GDPR in news articles, there are significant differences.

https://datamatters.sidley.com/california-enacts-broad-privacy-protections-modeled-on-gdpr/

]]>