SlideShare a Scribd company logo
1 of 15
Update on Data Protection in Anti-Doping


             Dr. Lars Mortsiefer
    Nationale Anti Doping Agentur Deutschland (NADA)
„I absolutely support the fight against doping.
But I would like to have a system which respects the Athlete`s
                         privacy more“
    (International basketball player, Heiko Schaffartzik, Oktober 2011)
Overview

•   Development of data protection rules within the WADA-Code and ISPPI



•   Problems and conflict of interests - four examples



•   Outlook on data protection within the WADA-Code 2015



•   Conclusion




                                                                          3
Historical Development




                         4
 
14.6  Data Privacy
 
When performing obligations under the Code, Anti-Doping 
Organizations may collect, store, process or disclose personal 
information relating to Athletes and third parties. 

Each Anti-Doping Organization shall ensure that it complies with 
applicable data protection and privacy laws with respect to their 
handling of such information, as well as the International 
Standard for the protection of privacy that WADA shall adopt to 
ensure Athletes and non-athletes are fully informed of and, where 
necessary, agree to the handling of their personal information 
in connection with anti-doping activities arising under the Code.
Art. 29 Data Protection Working Party


  – Legal form  

  – Roles and responsibilities

  – First and second opinion on WADA-Code and ISPPI

  – Conclusion




                                                      6
Problems


  – Legal basis

  – Transfer of data to third countries (via ADAMS)

  – Public disclosure of sanctions 

  – Proportionality




                                                      7
Legal Basis 


  - Law or (informed) consent

  - Athlete‘s given consent or legal provision

  - Europe!? 

  - Rest of the (sports) world?




                                                 8
Data Transfer via ADAMS

  - Anti-Doping Administration & Management System

  - Data transfer to third parties

  - Adequate level of data protection

  - Alternatives
         - Contractual solution
         - Sufficient guarantees


                                                     9
Public Disclosure of Sanctions

  - Internet

  - Art. 14.2.4

      For purposes of Article 14.2, publication shall be accomplished
      at a minimum by placing the required information on the Anti-
      Doping Organization’s Web site and leaving the information up
      for at least one (1) year.

  - For one year - or forever?!

  - Pillory effect and stigmatisation?!


                                                                        10
Proportionality

   First example:

   – High level athlete (RTP)
   – An average of 6 – 8 out-of-competition-controls per
     year – (blood and urine)
   – Whereabouts three month in advance
   – 1h-Time slot
   – 365 Days per year

                    Proportional?!

                                                           11
Proportionality


  Second example:

  Doping control under visual check (minors)




                                               12
WADA-Code Revision 2015


  - Art. 14 WADA-Code

  - Public disclosure as a sanction
    (Art. 10.12 WADA-Code)

  - Art. 22 WADA-Code

  - ISPPI



                                      13
Conclusion

  - Data protection is a very important issue

  - Protection of athletes‘ privacy and personal information
    is a major concern

  - But the doping control system must not be restricted

  - Athletes and DCOs do have a special relationsship of trust




                                                                 14
Thank you!
                 Dr. Lars Mortsiefer
                 Head of Legal Department /
             Member of the Executive Board
               phone: +49 228 / 812 92 -122
                  fax: +49 228 / 812 92 – 229
              lars.mortsiefer@nada-bonn.de
                          www.nada-bonn.de




                                                15

More Related Content

Similar to Lars Mortsiefer

The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIKarel Holst
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory TightropeDavid Erdos
 
CCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptCCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptSamir Jha
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)Napier University
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationJoseph V. Moreno
 
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...REVULN
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessEversheds Sutherland
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingIT Governance Ltd
 
ISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentMohammed J. Khan
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPRRobert Bond
 
'Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?''Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?'Lucy Woods
 
Hacking Health Camp Strasbourg health data & data protection in the Netherlands
Hacking Health Camp Strasbourg health data & data protection in the Netherlands Hacking Health Camp Strasbourg health data & data protection in the Netherlands
Hacking Health Camp Strasbourg health data & data protection in the Netherlands Axon Lawyers
 
The death of data protection
The death of data protection The death of data protection
The death of data protection Lilian Edwards
 
The death of data protection sans obama
The death of data protection sans obamaThe death of data protection sans obama
The death of data protection sans obamaLilian Edwards
 

Similar to Lars Mortsiefer (20)

The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
GDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORIGDPR presentation BE-Com - IFORI
GDPR presentation BE-Com - IFORI
 
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media:  Walking the Regulatory TightropeGDPR, DPAs and the Journalistic Media:  Walking the Regulatory Tightrope
GDPR, DPAs and the Journalistic Media: Walking the Regulatory Tightrope
 
CCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptCCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.ppt
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)EU Data Protection Legislation, Peter Ridley (HPE)
EU Data Protection Legislation, Peter Ridley (HPE)
 
GDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICOGDPR: The Regulator's Perspective, Peter Brown, ICO
GDPR: The Regulator's Perspective, Peter Brown, ICO
 
Board Priorities for GDPR Implementation
Board Priorities for GDPR ImplementationBoard Priorities for GDPR Implementation
Board Priorities for GDPR Implementation
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
 
Data Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your businessData Security Breach – knowing the risks and protecting your business
Data Security Breach – knowing the risks and protecting your business
 
Employee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdfEmployee Monitoring and Privacy.pdf
Employee Monitoring and Privacy.pdf
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
ISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP AlignmentISACA Journal Data Protection Act (UK) and GAPP Alignment
ISACA Journal Data Protection Act (UK) and GAPP Alignment
 
Sible 09
Sible 09Sible 09
Sible 09
 
SCCE Processors and GDPR
SCCE Processors and GDPRSCCE Processors and GDPR
SCCE Processors and GDPR
 
'Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?''Connected healthcare - connected to legality?'
'Connected healthcare - connected to legality?'
 
Hacking Health Camp Strasbourg health data & data protection in the Netherlands
Hacking Health Camp Strasbourg health data & data protection in the Netherlands Hacking Health Camp Strasbourg health data & data protection in the Netherlands
Hacking Health Camp Strasbourg health data & data protection in the Netherlands
 
The death of data protection
The death of data protection The death of data protection
The death of data protection
 
The death of data protection sans obama
The death of data protection sans obamaThe death of data protection sans obama
The death of data protection sans obama
 

More from Tackling Doping In Sport (7)

Stephen Watkins
Stephen WatkinsStephen Watkins
Stephen Watkins
 
Joseph de Pencier
Joseph de PencierJoseph de Pencier
Joseph de Pencier
 
Brett Clothier
Brett ClothierBrett Clothier
Brett Clothier
 
Rob Koehler
Rob KoehlerRob Koehler
Rob Koehler
 
Anders Solheim
Anders SolheimAnders Solheim
Anders Solheim
 
Volkan Topalli
Volkan TopalliVolkan Topalli
Volkan Topalli
 
Howard Jacobs
Howard JacobsHoward Jacobs
Howard Jacobs
 

Lars Mortsiefer