SlideShare a Scribd company logo
Sirius Legal
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Privacy means many different things
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
The right to privacy between individuals
Nosy neighbours
EU Privacy law does not deal with this aspect of privacy
National (civil) law
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
The right to privacy in relationship to the government
NSA
Police
Tax authorities
Specific rules and regulations on international and national level
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Electronic processing of personal data
Electronic processing
Personal data
Usually –but not always- for commercial purposes
EU Data Protection Directive 95/46/EC
E-privacy Directive 2002/58
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New balls, please…
EU Data Protection Directive 95/46/EC
E-privacy Directive 2002/58
Have been around for 20 years
Principles no longer fit economical and technical reality
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New balls, please…
EU is working on new set of rules
Work in progress since 2012
End is not in sight…
Uniform rules based on EU Regulation (as opposed to Directive)
ETA: 2016 - 2017
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Based on EU Regulation
Transferred into national law by each member state
Set of rules dates back to nineties
Based on location of company and/or server
At the time most elaborate and progressive set of rules in the world
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
“Right to privacy” >< data processing
Definition of personal data is very large
ECJ 2015: Even IP address – browser history
Impact on data collection and big data is considerable
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Definition of personal data is very large
Cfr B2B vs B2C
ECJ 2015: Even IP address – browser history –information on
social media – payment history…
Impact on data collection for credit scoring is considerable
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
B2B market: very little impact
B2C market: considerable impact of privacy law
Almost all available data is ‘personal data’
Classic data sources: public data – statistical data – private data
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Almost all available data is ‘personal data’
Classic data sources: public data – statistical data – private data
Fact that data is publicly available does not in itself justify collection & treatment
Cfr: data available online remains “personal” data
Even at first sight “statistical” information can be “personal” data
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Public data Statistical data Private data
Court information Place of residence Payment history
“Kadaster” Age Order history
Social media Diploma Time at which order is usually placed
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Social media & Time at which order is usually placed
Cfr Schufa in Germany (credit rating bureau) uses data found on Facebook ever
since 2012: wrong friends – negative rating
Nightly orders online are considered sign of unemployment – negative rating
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Public data
Beware of limitations under copyright law & database law
Cfr. ECJ decision on Ryanair’s database (ECJ, C-30/14, 15 January 2015)
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Straight and simple:
Basic rule = prior “opt-in” for all processing
Or implicite opt-in if “legitimate grounds” for processing
“Free and informed” opt-in
Transfer of data to third party = additionnal opt-in
Cfr. Analytics tools, apps, cookies, database enrichment through mailings
and actions, …: always opt-in
Cfr. also social media content
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Opt-in
Prior opt-in is exception
Classic “justification” is “legitimate grounds”
Law does not define “legitimate grounds” (Privacy Commission: “cfr CRM”)
Justification for processing = compare interests of processor and data subject
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Transfer of data to third parties
Requires additional opt-in
Essential in credit rating/scoring
Cfr. Evolution towards big data processing
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Who is responsible?
Data controller vs. Data processor
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Impact on credit scoring
Who controls data?
Determines opt-in or justification requirements
What is roll of credit score supplier?
Service based on own data vs. Data processing
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Current Privacy Law
Rights of data subjects
opposition – access – correction - information
Obligations of data processor
Information – opt-in – data security – (export)
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New regulation
2016 – 2017
Regulation in stead of Directive
Work in pogress since 2012
Complex procedure in European Institutions
Heavy lobbying
Political slow down
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
New regulation
How the EU legislative process works…
2012 Proposal European Commission (Reding)
2012-2015 Parallel track in European Parliament and European Council
2014 Proposal Parliament accepted (Amendements “Michel”)
2015 Parallel proposal Council Work in progress
2016 Both proposals have to be merged into one final text…
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Commission Proposal
Heavily influenced by consumer protection activists in EP
LIBE Committee (protection of civil liberties)
Result:
Consumer friendly, but unrealistic for direct marketing sector, e-commerce
sector and especially credit scoring/rating…
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Commission Proposal
For all services offered in EU (even free services)
Personal data = also online identifiers, “pseudonymous data”
Explicite opt-in always required
Information obligation (icons)
Right not to be submitted to profiling
Warning obligations in case of data breach
“Data protection by design”
“Data protection officer”
Sanctions: LIBE: up to 5% of yearly turnover or 100 million euro
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Council Proposal
Work in progress
Last ammendments made in March 2015
Much more industry focused
Influence of direct marketing (through eg BDMA - FEDMA) is bigger
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
Council Proposal
Explicite opt-in
But opt-out or implicite opt-in has been put back in if “legitimate interest”
Next chapters discussed in upcoming months
To be expected:
Lower penalties and less strict obligations
Data protection officers obligation tuned down
Softer rules on profiling prohibition
Legal aspects of privacy and data protection
Risk scoring at customer acceptance, 23 April 2015
What should you do in the meantime?
Follow up on discussion (eg through our website www.siriuslegal.be)
Start review vendor contracts (in view of data security obligation)
Start to prepare for full update of policies, contracts, business processes
Put in place data breach notification procedure
Appoint (temporary) data security officer
Put in place impact assessment and/or risk analyses policy
Create compliance statements for annual business reports
Train staff
Sit back and wait for final text of regulation for final details…
Media & advertisement law
Copyright - trademarks - datebase - software - knowhow
Travel & consumer protection
Tax & tax planning
IT, Internet & e-commerce
Privacy & cookies
Gambling & gaming
Sirius Legal
www.websitecertifier.be
www.campaignchecker.be
bart@siriuslegal.be
www.siriuslegal.be
@BartVdBrande
Linkedin.com/in/bartvdb
Sirius Legal

More Related Content

What's hot

GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
Frederick Penaud
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
Ramiro Cid
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
Jake DiMare
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
IT Governance Ltd
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers network
Bart Van Den Brande
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
Exove
 
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
Bart Van Den Brande
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
ESET
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
Benoît De Nayer
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
Sophos Benelux
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
Cliff Ashcroft
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
VYTIS MALECKAS
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
Pavol Balaj
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
IT Governance Ltd
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
Sabrina Kirrane
 

What's hot (15)

GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?GDPR security services - Areyou ready ?
GDPR security services - Areyou ready ?
 
EU General Data Protection Regulation
EU General Data Protection RegulationEU General Data Protection Regulation
EU General Data Protection Regulation
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Gdpr compliance. Presentation for Consulegis Lawyers network
Gdpr compliance.  Presentation  for Consulegis Lawyers networkGdpr compliance.  Presentation  for Consulegis Lawyers network
Gdpr compliance. Presentation for Consulegis Lawyers network
 
What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...What is the new data protection regulation GDPR and why should you care? Jesp...
What is the new data protection regulation GDPR and why should you care? Jesp...
 
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
DDMA Data Driven Monday: Privacy law for data driven marketing and the regula...
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
GDPR for dummies
GDPR for dummies  GDPR for dummies
GDPR for dummies
 
The EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to knowThe EU Data Protection Regulation - what you need to know
The EU Data Protection Regulation - what you need to know
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
Modelling the General Data Protection Regulation
Modelling the General Data Protection RegulationModelling the General Data Protection Regulation
Modelling the General Data Protection Regulation
 

Similar to Privacy and data protection in credit scoring

CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
The CMR Agency
 
Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013
Bart Van Den Brande
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
Krowdthink
 
20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation
Febelmar
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Bart Van Den Brande
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
Rachel Aldighieri
 
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
Michael Fanning
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
bhalasz
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
Dr. Donald Macfarlane
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Dr. Donald Macfarlane
 
Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016
Bart Van Den Brande
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
Jean-Michel Tyszka
 
UBA legal changes in marketing automation
UBA legal changes in marketing automation UBA legal changes in marketing automation
UBA legal changes in marketing automation
Bart Van Den Brande
 
How to Protect Your Data
How to Protect Your DataHow to Protect Your Data
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
Brian Matteson, CISSP CISA
 
Day 4 - Meet with BE DPA.pdf
Day 4 - Meet with BE DPA.pdfDay 4 - Meet with BE DPA.pdf
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
Yizi
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
Lumension
 
Gdpr presentation-february-24t
Gdpr presentation-february-24tGdpr presentation-february-24t
Gdpr presentation-february-24t
Mark Drinkwater
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
Jan Dhont
 

Similar to Privacy and data protection in credit scoring (20)

CMR - GDPR - general introduction for marketeers
CMR  -  GDPR - general introduction for marketeersCMR  -  GDPR - general introduction for marketeers
CMR - GDPR - general introduction for marketeers
 
Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013Privacy and cookies crm inspiration days 2013
Privacy and cookies crm inspiration days 2013
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation20150610 febelmar privacy matters eu regulation
20150610 febelmar privacy matters eu regulation
 
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
Gdpr compliance univ'air carslon wagon lit 5 oktober 2017
 
European Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMAEuropean Legal and Privacy Update with FEDMA
European Legal and Privacy Update with FEDMA
 
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
PSI in Europe – The Road(s) Ahead! Action plan 3: Legal, business and other i...
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
 
Data protection & security breakfast briefing master slides 28 june-final
Data protection & security breakfast briefing   master slides 28 june-finalData protection & security breakfast briefing   master slides 28 june-final
Data protection & security breakfast briefing master slides 28 june-final
 
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_finalData Protection & Security Breakfast Briefing - Master Slides_28 June_final
Data Protection & Security Breakfast Briefing - Master Slides_28 June_final
 
Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016Impact on e-commerce of the GDPR- Etrade Summit 2016
Impact on e-commerce of the GDPR- Etrade Summit 2016
 
GDPR (En) JM Tyszka
GDPR (En)  JM TyszkaGDPR (En)  JM Tyszka
GDPR (En) JM Tyszka
 
UBA legal changes in marketing automation
UBA legal changes in marketing automation UBA legal changes in marketing automation
UBA legal changes in marketing automation
 
How to Protect Your Data
How to Protect Your DataHow to Protect Your Data
How to Protect Your Data
 
2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final2017 10 26 webinar - gdpr final
2017 10 26 webinar - gdpr final
 
Day 4 - Meet with BE DPA.pdf
Day 4 - Meet with BE DPA.pdfDay 4 - Meet with BE DPA.pdf
Day 4 - Meet with BE DPA.pdf
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
Gdpr presentation-february-24t
Gdpr presentation-february-24tGdpr presentation-february-24t
Gdpr presentation-february-24t
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
 

More from Bart Van Den Brande

Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
Bart Van Den Brande
 
20481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 201920481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 2019
Bart Van Den Brande
 
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Bart Van Den Brande
 
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
Bart Van Den Brande
 
Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)
Bart Van Den Brande
 
20160226 ecommerce summit
20160226 ecommerce summit20160226 ecommerce summit
20160226 ecommerce summit
Bart Van Den Brande
 
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
Bart Van Den Brande
 
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
Bart Van Den Brande
 
/Fedipro PowerEvent 27/10/2015
/Fedipro PowerEvent 27/10/2015/Fedipro PowerEvent 27/10/2015
/Fedipro PowerEvent 27/10/2015
Bart Van Den Brande
 
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Bart Van Den Brande
 
Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015
Bart Van Den Brande
 
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Bart Van Den Brande
 
Unizo standaard 2014
Unizo standaard 2014Unizo standaard 2014
Unizo standaard 2014
Bart Van Den Brande
 
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Bart Van Den Brande
 
20140228 Sirius Friday seminarie Privacy & cookies
20140228 Sirius Friday seminarie   Privacy & cookies20140228 Sirius Friday seminarie   Privacy & cookies
20140228 Sirius Friday seminarie Privacy & cookiesBart Van Den Brande
 
Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220Bart Van Den Brande
 
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...Bart Van Den Brande
 
Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra Bart Van Den Brande
 

More from Bart Van Den Brande (20)

Gdpr and smart cities
Gdpr and smart citiesGdpr and smart cities
Gdpr and smart cities
 
20481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 201920481112 travelmedia congres gdpr in de travelindustrie in 2019
20481112 travelmedia congres gdpr in de travelindustrie in 2019
 
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
Data and personalisation Duval Union Academy breakfastsessions.be 9 June 2016
 
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
20160518 if forum kennislunch: de ontwerpen van richtlijn en verordening van ...
 
Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)Legal aspects of real time and trigger based marketing (privacy and cookies)
Legal aspects of real time and trigger based marketing (privacy and cookies)
 
20160226 ecommerce summit
20160226 ecommerce summit20160226 ecommerce summit
20160226 ecommerce summit
 
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
20160216 Fedustria: juridische aspecten van e commerce voor producenten en gr...
 
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
20151030 Sirius Friday seminar: Legal aspecten van sociale media wedstrijden
 
/Fedipro PowerEvent 27/10/2015
/Fedipro PowerEvent 27/10/2015/Fedipro PowerEvent 27/10/2015
/Fedipro PowerEvent 27/10/2015
 
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
Juridische aspecten van digital marketing - gastles HoGent 28 april 2015
 
Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015Eshop expo 2015: Legal changes in e-commerce for 2015
Eshop expo 2015: Legal changes in e-commerce for 2015
 
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
Legal aspects of social commerce Sirius Legal at BDMA Legal Day 2015
 
Unizo standaard 2014
Unizo standaard 2014Unizo standaard 2014
Unizo standaard 2014
 
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
Sirius Friday seminarie nieuwe consumentenbescherming in e-commerce 20140228 ...
 
20140228 Sirius Friday seminarie Privacy & cookies
20140228 Sirius Friday seminarie   Privacy & cookies20140228 Sirius Friday seminarie   Privacy & cookies
20140228 Sirius Friday seminarie Privacy & cookies
 
Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220Social media academy de juridische aspecten van social commerce 20140220
Social media academy de juridische aspecten van social commerce 20140220
 
Safe shops.be 20140205
Safe shops.be 20140205Safe shops.be 20140205
Safe shops.be 20140205
 
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
5 juridische redenen waarom e-commerce nog steeds niet internationaal (genoeg...
 
Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra Reclame online en e-commerce - Gastles voor Syntra
Reclame online en e-commerce - Gastles voor Syntra
 
Fot 2011 powerpoint
Fot 2011 powerpointFot 2011 powerpoint
Fot 2011 powerpoint
 

Recently uploaded

Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
MasoudZamani13
 
The Future of Criminal Defense Lawyer in India.pdf
The Future of Criminal Defense Lawyer in India.pdfThe Future of Criminal Defense Lawyer in India.pdf
The Future of Criminal Defense Lawyer in India.pdf
veteranlegal
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
osenwakm
 
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
ssuser559494
 
The Art and Science of Cryptoforensic Investigation: Best Practices and Tools
The Art and Science of Cryptoforensic Investigation: Best Practices and ToolsThe Art and Science of Cryptoforensic Investigation: Best Practices and Tools
The Art and Science of Cryptoforensic Investigation: Best Practices and Tools
Milind Agarwal
 
Receivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptxReceivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptx
Godwin Emmanuel Oyedokun MBA MSc PhD FCA FCTI FCNA CFE FFAR
 
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdfV.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
bhavenpr
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
MattGardner52
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Massimo Talia
 
Incometax Compliance_PF_ ESI- June 2024
Incometax  Compliance_PF_ ESI- June 2024Incometax  Compliance_PF_ ESI- June 2024
Incometax Compliance_PF_ ESI- June 2024
EbizfilingIndia
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
osenwakm
 
Search Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement OfficersSearch Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement Officers
RichardTheberge
 
San Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at SeaSan Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at Sea
Justin Ordoyo
 
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
CIkumparan
 
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
ssusera97a2f
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
PelayoGilbert
 
Lifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point PresentationLifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point Presentation
seri bangash
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
lawyersonia
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Syed Muhammad Humza Hussain
 

Recently uploaded (20)

Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
 
The Future of Criminal Defense Lawyer in India.pdf
The Future of Criminal Defense Lawyer in India.pdfThe Future of Criminal Defense Lawyer in India.pdf
The Future of Criminal Defense Lawyer in India.pdf
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
 
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
 
The Art and Science of Cryptoforensic Investigation: Best Practices and Tools
The Art and Science of Cryptoforensic Investigation: Best Practices and ToolsThe Art and Science of Cryptoforensic Investigation: Best Practices and Tools
The Art and Science of Cryptoforensic Investigation: Best Practices and Tools
 
Receivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptxReceivership and liquidation Accounts Prof. Oyedokun.pptx
Receivership and liquidation Accounts Prof. Oyedokun.pptx
 
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdfV.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
 
Matthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government LiaisonMatthew Professional CV experienced Government Liaison
Matthew Professional CV experienced Government Liaison
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
 
Incometax Compliance_PF_ ESI- June 2024
Incometax  Compliance_PF_ ESI- June 2024Incometax  Compliance_PF_ ESI- June 2024
Incometax Compliance_PF_ ESI- June 2024
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
 
Search Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement OfficersSearch Warrants for NH Law Enforcement Officers
Search Warrants for NH Law Enforcement Officers
 
San Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at SeaSan Remo Manual on International Law Applicable to Armed Conflict at Sea
San Remo Manual on International Law Applicable to Armed Conflict at Sea
 
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
 
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
 
Lifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point PresentationLifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point Presentation
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
 

Privacy and data protection in credit scoring

  • 1. Sirius Legal Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015
  • 2. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Privacy means many different things
  • 3. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 The right to privacy between individuals Nosy neighbours EU Privacy law does not deal with this aspect of privacy National (civil) law
  • 4. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 The right to privacy in relationship to the government NSA Police Tax authorities Specific rules and regulations on international and national level
  • 5. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Electronic processing of personal data Electronic processing Personal data Usually –but not always- for commercial purposes EU Data Protection Directive 95/46/EC E-privacy Directive 2002/58
  • 6. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New balls, please… EU Data Protection Directive 95/46/EC E-privacy Directive 2002/58 Have been around for 20 years Principles no longer fit economical and technical reality
  • 7. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New balls, please… EU is working on new set of rules Work in progress since 2012 End is not in sight… Uniform rules based on EU Regulation (as opposed to Directive) ETA: 2016 - 2017
  • 8. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Based on EU Regulation Transferred into national law by each member state Set of rules dates back to nineties Based on location of company and/or server At the time most elaborate and progressive set of rules in the world
  • 9. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law “Right to privacy” >< data processing Definition of personal data is very large ECJ 2015: Even IP address – browser history Impact on data collection and big data is considerable
  • 10. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Definition of personal data is very large Cfr B2B vs B2C ECJ 2015: Even IP address – browser history –information on social media – payment history… Impact on data collection for credit scoring is considerable
  • 11. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring B2B market: very little impact B2C market: considerable impact of privacy law Almost all available data is ‘personal data’ Classic data sources: public data – statistical data – private data
  • 12. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Almost all available data is ‘personal data’ Classic data sources: public data – statistical data – private data Fact that data is publicly available does not in itself justify collection & treatment Cfr: data available online remains “personal” data Even at first sight “statistical” information can be “personal” data
  • 13. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Public data Statistical data Private data Court information Place of residence Payment history “Kadaster” Age Order history Social media Diploma Time at which order is usually placed
  • 14. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Social media & Time at which order is usually placed Cfr Schufa in Germany (credit rating bureau) uses data found on Facebook ever since 2012: wrong friends – negative rating Nightly orders online are considered sign of unemployment – negative rating
  • 15. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Public data Beware of limitations under copyright law & database law Cfr. ECJ decision on Ryanair’s database (ECJ, C-30/14, 15 January 2015)
  • 16. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Straight and simple: Basic rule = prior “opt-in” for all processing Or implicite opt-in if “legitimate grounds” for processing “Free and informed” opt-in Transfer of data to third party = additionnal opt-in Cfr. Analytics tools, apps, cookies, database enrichment through mailings and actions, …: always opt-in Cfr. also social media content
  • 17. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Opt-in Prior opt-in is exception Classic “justification” is “legitimate grounds” Law does not define “legitimate grounds” (Privacy Commission: “cfr CRM”) Justification for processing = compare interests of processor and data subject
  • 18. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Transfer of data to third parties Requires additional opt-in Essential in credit rating/scoring Cfr. Evolution towards big data processing
  • 19. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Who is responsible? Data controller vs. Data processor
  • 20. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Impact on credit scoring Who controls data? Determines opt-in or justification requirements What is roll of credit score supplier? Service based on own data vs. Data processing
  • 21. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Current Privacy Law Rights of data subjects opposition – access – correction - information Obligations of data processor Information – opt-in – data security – (export)
  • 22. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New regulation 2016 – 2017 Regulation in stead of Directive Work in pogress since 2012 Complex procedure in European Institutions Heavy lobbying Political slow down
  • 23. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 New regulation How the EU legislative process works… 2012 Proposal European Commission (Reding) 2012-2015 Parallel track in European Parliament and European Council 2014 Proposal Parliament accepted (Amendements “Michel”) 2015 Parallel proposal Council Work in progress 2016 Both proposals have to be merged into one final text…
  • 24. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Commission Proposal Heavily influenced by consumer protection activists in EP LIBE Committee (protection of civil liberties) Result: Consumer friendly, but unrealistic for direct marketing sector, e-commerce sector and especially credit scoring/rating…
  • 25. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Commission Proposal For all services offered in EU (even free services) Personal data = also online identifiers, “pseudonymous data” Explicite opt-in always required Information obligation (icons) Right not to be submitted to profiling Warning obligations in case of data breach “Data protection by design” “Data protection officer” Sanctions: LIBE: up to 5% of yearly turnover or 100 million euro
  • 26. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Council Proposal Work in progress Last ammendments made in March 2015 Much more industry focused Influence of direct marketing (through eg BDMA - FEDMA) is bigger
  • 27. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 Council Proposal Explicite opt-in But opt-out or implicite opt-in has been put back in if “legitimate interest” Next chapters discussed in upcoming months To be expected: Lower penalties and less strict obligations Data protection officers obligation tuned down Softer rules on profiling prohibition
  • 28. Legal aspects of privacy and data protection Risk scoring at customer acceptance, 23 April 2015 What should you do in the meantime? Follow up on discussion (eg through our website www.siriuslegal.be) Start review vendor contracts (in view of data security obligation) Start to prepare for full update of policies, contracts, business processes Put in place data breach notification procedure Appoint (temporary) data security officer Put in place impact assessment and/or risk analyses policy Create compliance statements for annual business reports Train staff Sit back and wait for final text of regulation for final details…
  • 29. Media & advertisement law Copyright - trademarks - datebase - software - knowhow Travel & consumer protection Tax & tax planning IT, Internet & e-commerce Privacy & cookies Gambling & gaming Sirius Legal