10.07.2015 Views

An Overview of the Principles Established by the APEC Privacy ...

An Overview of the Principles Established by the APEC Privacy ...

An Overview of the Principles Established by the APEC Privacy ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

International <strong>Privacy</strong> Framework198019952004OECD GuidelinesRepresent internationalconsensus on <strong>the</strong> basicrules governing <strong>the</strong>protection <strong>of</strong> personaldata and privacyEU Directive95/46/ECEnsure <strong>the</strong> free movement<strong>of</strong> personal data betweenMember States in <strong>the</strong>European Community<strong>APEC</strong> <strong>Privacy</strong>FrameworkPromote a consistentapproach to informationprivacy protection as ameans <strong>of</strong> ensuring <strong>the</strong> freeflow <strong>of</strong> information in <strong>the</strong>Asia Pacific region3


International <strong>Privacy</strong> FrameworkA Common Theme“… . were very aware <strong>of</strong> <strong>the</strong> impact<strong>of</strong> automatic data processing (newtechnologies) upon personal dataprivacy and <strong>of</strong> <strong>the</strong> need to sustain<strong>the</strong> economic value <strong>of</strong> information<strong>by</strong> ensuring <strong>the</strong> transfer <strong>of</strong> data”4


<strong>APEC</strong> <strong>Privacy</strong> Framework: Development1998 <strong>APEC</strong> Blueprint for Actionon Electronic Commerce“The potential <strong>of</strong> electronic commerce could not be realized withoutgovernment and business cooperation to develop and implementtechnologies and policies, which build trust and confidence in safe,secure and reliable communication, information and delivery systems,and which address issues including privacy, security and consumerprotection.”5


<strong>APEC</strong> <strong>Privacy</strong> Framework: Milestones1998 <strong>APEC</strong> Ministers endorsed Blueprint1999 ECSG established2002 Mapping exercise on data protection approachesFeb 2003 Data <strong>Privacy</strong> Subgroup establishedMar 2004 Consultation draft Framework releasedNov 2004 <strong>APEC</strong> Leaders endorsed Framework6


<strong>APEC</strong> <strong>Privacy</strong> FrameworkPart IPreamble<strong>Principles</strong>-based<strong>Privacy</strong> FrameworkSets Sets out out <strong>the</strong> <strong>the</strong>focus focus and andobjectivesPart IIScopeMakes Makes clear clear<strong>the</strong> <strong>the</strong> extent extent <strong>of</strong> <strong>of</strong>coveragePart IIIInformation<strong>Privacy</strong> <strong>Principles</strong>Includescommentaryon on <strong>Principles</strong>Part IVImplementationGuidance on onmatters matters <strong>of</strong> <strong>of</strong>implementation7


<strong>APEC</strong> <strong>Privacy</strong> <strong>Principles</strong>: Focus“<strong>APEC</strong> economies realize <strong>the</strong> key part <strong>of</strong> efforts toimprove consumer confidence and ensure <strong>the</strong>growth <strong>of</strong> electronic commerce must becooperation to balance and promote both effectiveinformation privacy protection and <strong>the</strong> free flow <strong>of</strong>information in <strong>the</strong> Asia Pacific region”… …Part I - Preamble“The perceived value and benefits <strong>of</strong> e-commerce has become <strong>the</strong> drivingforce behind <strong>the</strong> quest to seek compatibility in privacy development”8


<strong>APEC</strong> <strong>Privacy</strong> <strong>Principles</strong>: Objectives– To develop appropriate privacyprotections for personal information– To prevent <strong>the</strong> creation <strong>of</strong> unnecessarybarriers to information flows– To enable multinational businesses to implement uniform approachesto <strong>the</strong> collection, use and processing <strong>of</strong> data– To facilitate both domestic and international efforts to promote andenforce information privacy protections“It encourages compatibility yet it respects <strong>the</strong> different cultural, social,economic requirements that exist within member economies”9


<strong>APEC</strong> <strong>Privacy</strong> <strong>Principles</strong>: Scope• The principles should be interpreted as awhole ra<strong>the</strong>r than individually as <strong>the</strong>re isa close relationship among <strong>the</strong>m• Balancing privacy rights and <strong>the</strong> publicinterest– Not intended to impede governmental activitiesauthorized <strong>by</strong> law– Allow exceptions to <strong>the</strong> principles that suitparticular domestic circumstances10


<strong>APEC</strong> <strong>Privacy</strong> <strong>Principles</strong>: Application• Applies to information about living individuals– Personal information in connection with domesticaffairs are excluded– Limited exclusion to “publicly availableinformation”• Applies to persons or organizations in <strong>the</strong>public and private sectors– who control <strong>the</strong> collection, holding, processing oruse <strong>of</strong> personal information– Organizations acting as agents for o<strong>the</strong>rs areexcluded from compliance11


<strong>APEC</strong> Information <strong>Privacy</strong> <strong>Principles</strong>1 Preventing Harm2 Notice3 Collection Limitation4 Use <strong>of</strong> PersonalInformation5 Choice6 Integrity <strong>of</strong> PersonalInformation7 Security Safeguards8 Access & Correction9 Accountability12


<strong>APEC</strong> <strong>Privacy</strong> <strong>Principles</strong>: RelationshipUse <strong>of</strong>PersonalInformationPersonal Information ControllerCollectionLimitationIntegrity <strong>of</strong>PersonalInformationChoicePreventingHarmAccountabilityNoticeSecuritySafeguardsAccess andCorrection13


<strong>APEC</strong> Information <strong>Privacy</strong> <strong>Principles</strong>Principle 3 – Collection Limitation• This provides for <strong>the</strong> lawful and fair collection <strong>of</strong> personalinformation that is relevant to <strong>the</strong> purposes <strong>of</strong> collection, and whereappropriate, with notice to, or consent <strong>of</strong>, <strong>the</strong> individual concerned.Principle 4 – Use <strong>of</strong> Personal Information• This limits <strong>the</strong> use <strong>of</strong> personal information to fulfilling <strong>the</strong> purposes <strong>of</strong>collection and o<strong>the</strong>r compatible or related purposes.Principle 5 – Choice• This provides, where appropriate, for individuals to be providedwith mechanisms to exercise choice in relation to <strong>the</strong> collection,use and disclosure <strong>of</strong> <strong>the</strong>ir personal information.15


<strong>APEC</strong> Information <strong>Privacy</strong> <strong>Principles</strong>Principle 6 – Integrity <strong>of</strong> Personal Information• This provides that personal information should beaccurate, complete and kept up-to-date to <strong>the</strong> extentnecessary for <strong>the</strong> purpose <strong>of</strong> use.Principle 7 – Security Safeguards• This requires appropriate security safeguards to beapplied to personal information that are proportional to<strong>the</strong> likelihood and severity <strong>of</strong> <strong>the</strong> harm threatened, <strong>the</strong>sensitivity <strong>of</strong> <strong>the</strong> information and <strong>the</strong> context in which itis held.16


<strong>APEC</strong> Information <strong>Privacy</strong> <strong>Principles</strong>Principle 8 – Access and Correction• This provides for individuals to have rights <strong>of</strong>access to <strong>the</strong>ir personal information, tochallenge <strong>the</strong> accuracy <strong>of</strong> <strong>the</strong> information and,as appropriate, to request correction <strong>of</strong> suchinformation.Principle 9 – Accountability• This requires a personal information controller to be accountable forcomplying with measures that give effect to <strong>the</strong> <strong>Principles</strong>. Whentransferring personal information, reasonable steps should be taken to ensurerecipients protect <strong>the</strong> information in a manner consistent with <strong>the</strong>se<strong>Principles</strong>.17


Concluding Remarks• Observations presented reflect our understanding in <strong>the</strong>course <strong>of</strong> Subgroup discussions• Agreements are reached <strong>by</strong> open dialogue and consensus• A credible instrument that honours culturaldiversities and accords due regard to regionaldifferences – an essential ingredient in ensuringbroad-based acceptance and lasting utility• More work to be done18

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!