香港六合彩 » SlideShare

18
Privacy and Security in the Information Privacy and Security in the Information Age Age Conference, Melbourne, Australia Conference, Melbourne, Australia August 16, 2001 August 16, 2001 The United States Government’s The United States Government’s Approach to Privacy: Approach to Privacy: The EU Directive and the The EU Directive and the Safe Harbor Framework Safe Harbor Framework Patricia M. Sefcik Patricia M. Sefcik U.S. Department of Commerce U.S. Department of Commerce

description

香港六合彩搞不清楚,这究竟是一种什么样的奇怪疾病。香港六合彩有许多话要说,而且香港六合彩自信自己所说的话,一句一句都是超凡脱俗、与众不同的。香港六合彩觉得自己的头脑十分清晰,并且异常的敏捷与敏锐。然而,那不绝如缕的思绪,那惊天动地的想法,一旦要变成语言说出时,却忽然地遇到了阻碍。大坝,坚不可摧的大坝。心中、脑中的滚滚语流,被一道坚实的闸门闸住了,再也不能自由奔放。汹涌的语流,就在闸门的另一边,喧嚣着,蹦跳着,但却又十分无奈地不能一泻而去。它就这样不停地呜咽着,最终,勉强地有一股水流从闸门的缝隙或漏洞中挣扎了出去。每逢此时,香港六合彩心中满是紧张与焦急,而越是紧张与焦急,就越是不能流畅。香港六合彩会感觉到自己的脑袋要憋爆了,热乎乎的血猛烈地撞击着脑门,脖子因血管的涨满而变粗。香港六合彩知道,那一刻,香港六合彩的形象是丑陋的。香港六合彩简直不想活了。事后,香港六合彩会联想到一个香港六合彩便秘:这个香港六合彩蹲在粪坑上,眼珠外凸,眼神定定的,脸红脖子粗地在排泄,随着肛门的一次又一次地向外鼓胀,干硬的大便,一点一点地屙了出来。结巴时,香港六合彩看到听众在替香港六合彩着急———着急了一阵而终于失望时,香港六合彩一口咬掉自己舌头的心思都有。无香港六合彩时,香港六合彩曾许多次地练习过讲话,在全神贯注的状态下,其情形虽然不是口齿伶俐,但还算是一句一句地成句。可一旦出现在公众场合时,这结巴就像是一个存心要作弄香港六合彩的魔鬼悄然出现了。此番情景,一次又一次地出现之后,杜元潮终于失去了信心。香港六合彩冷静下来,思索着:你不能再讲话了。香港六合彩知道,与其那样,还不如尽量不去说话,这样,对自己的形象倒好一些。然而,这样的选择,给香港六合彩带来的可能是更大的痛苦。当香港六合彩看到邱子东因香港六合彩的后退而走上前台去滔滔不绝、口若悬河、一派汪洋恣肆,将一副能说会道、精明强干的形象凸现给油麻地的百姓以及油麻地以外的世界时,香港六合彩的内心一点一点集聚起来的是嫉妒,甚至是怨毒。这些东西,在香港六合彩暗无天日的心里,一拱一拱地生长着。当邱子东处处显出一副春风得意的样子时,杜元潮却始终平静而宽厚地微笑着。这年夏天,县里来了一支庞大的参观队伍,是县委书记带队,从县城一路下来,也没有一个明确的目的地。坐着县委书记的那辆吉普车在前头停了,后面的两辆大轿车也就会跟着停下来。县委书记看哪儿,纯粹是兴之所致,一停就停在了油麻地镇前的公路上。县委书记走在前头,后面呼呼啦啦地跟了一支长长的队伍。地方上的领导,也在队伍之中,见此情形,立即派香港六合彩抄近路跑到镇上,通知杜元潮赶快出来到路口迎接,并告知,县委书记很可能要听汇报。此时,杜元潮立即本能地显出无助的样子。一旁的邱子东,神情平淡。杜元潮一下子意识到了邱子东就在香港六合彩身旁,说:走,去……去路……路口……路上,杜元潮对邱子东说:你……你……你来汇报吧……邱子东将烟蒂扔在脚下,踩了踩:也行。县委书记一路看着庄稼,不时地站住,掉头向后面的香港六合彩指指点点,香港六合彩香港六合彩都连连称是。杜元潮、邱子东一行,一路小跑迎了过来。谁是这里的负责香港六合彩?县委书记问。杜元潮走上前去:是……是我,杜……杜元潮。县委书记对杜元潮的结巴

Transcript of 香港六合彩 » SlideShare

Page 1: 香港六合彩 » SlideShare

Privacy and Security in the Information Privacy and Security in the Information AgeAge

Conference, Melbourne, Australia Conference, Melbourne, Australia August 16, 2001August 16, 2001

The United States Government’s The United States Government’s Approach to Privacy:Approach to Privacy:

The EU Directive and the The EU Directive and the Safe Harbor FrameworkSafe Harbor Framework

Patricia M. SefcikPatricia M. Sefcik

U.S. Department of CommerceU.S. Department of Commerce

Page 2: 香港六合彩 » SlideShare

2

Privacy in Europe and the U.S.Privacy in Europe and the U.S.

The European privacy system is The European privacy system is based on comprehensive based on comprehensive legislation.legislation.

The U.S. privacy system is based on The U.S. privacy system is based on self regulation and sector specific self regulation and sector specific legislation in highly sensitive areas legislation in highly sensitive areas such as financial, medical, such as financial, medical, children’s and genetic information.children’s and genetic information.

Page 3: 香港六合彩 » SlideShare

3

Historical Overview: Safe HarborHistorical Overview: Safe Harbor

OCTOBER 1998– EU’s sweeping privacy directive went into effect

JULY 2000– Safe Harbor principles are deemed adequate

NOVEMBER 1, 2000– Safe Harbor becomes effective– DOC launches safe harbor website

http://www.export.gov/safeharbor JANUARY 4, 2001

– Official Department of Commerce roll-out JANUARY-AUGUST, 2001

– Outreach events

Page 4: 香港六合彩 » SlideShare

4

Safe Harbor ImplementationSafe Harbor Implementation

What are the Benefits? What are the Benefits?

Who Can Join and How?Who Can Join and How?

How and Where will Safe Harbor be How and Where will Safe Harbor be Enforced?Enforced?

Page 5: 香港六合彩 » SlideShare

5

The Safe Harbor FrameworkThe Safe Harbor Framework

• 7 Privacy Principles7 Privacy Principles• 15 FAQ’s15 FAQ’s• European Commission’s adequacy European Commission’s adequacy

determination determination• Letters between U.S. Dept. of Letters between U.S. Dept. of

Commerce and the European Commerce and the European CommissionCommission

• Letters from U.S. Dept. of Letters from U.S. Dept. of Transportation and Federal Trade Transportation and Federal Trade CommissionCommission

Page 6: 香港六合彩 » SlideShare

6

The 7 Safe Harbor PrinciplesThe 7 Safe Harbor Principles

1)1) NoticeNotice

2)2) ChoiceChoice

3)3) Onward TransferOnward Transfer

4)4) SecuritySecurity

5)5) Data IntegrityData Integrity

6)6) AccessAccess

7)7) EnforcementEnforcement

Page 7: 香港六合彩 » SlideShare

7

The Safe Harbor PrinciplesThe Safe Harbor Principles

(1) NOTICE(1) NOTICE Inform individuals about the purpose for which Inform individuals about the purpose for which

the information is being collected.the information is being collected.

Inform individuals about how to contact the Inform individuals about how to contact the organizations with inquiries or complaints.organizations with inquiries or complaints.

Provide information on the types of third Provide information on the types of third parties to which information is being disclosed, parties to which information is being disclosed, and the choices and means offered for limiting and the choices and means offered for limiting its use and disclosure.its use and disclosure.

Page 8: 香港六合彩 » SlideShare

8

The Safe Harbor PrinciplesThe Safe Harbor Principles

(2) CHOICE (2) CHOICE

An organization must offer individuals the opportunity An organization must offer individuals the opportunity to choose (opt out) whether their personal information to choose (opt out) whether their personal information is (a) to be disclosed to a third party, or (b) to be used is (a) to be disclosed to a third party, or (b) to be used for a purpose that is incompatible with the purposes for a purpose that is incompatible with the purposes for which it was originally collected or subsequently for which it was originally collected or subsequently authorized by the individual. authorized by the individual.

Individuals must be provided with clear and Individuals must be provided with clear and conspicuous, readily available, and affordable conspicuous, readily available, and affordable mechanisms to exercise choice.mechanisms to exercise choice.

Page 9: 香港六合彩 » SlideShare

9

The Safe Harbor PrinciplesThe Safe Harbor Principles

CHOICE: Sensitive InformationCHOICE: Sensitive Information

For sensitive information (i.e. medical/ health For sensitive information (i.e. medical/ health conditions; racial/ethnic origin; political conditions; racial/ethnic origin; political opinions; religious/ philosophical beliefs; trade opinions; religious/ philosophical beliefs; trade union membership; sex life), individuals must union membership; sex life), individuals must be given affirmative or explicit (opt in) choice be given affirmative or explicit (opt in) choice if the information is to be disclosed to a third if the information is to be disclosed to a third party or used for a purpose other than those party or used for a purpose other than those for which it was originally collected or for which it was originally collected or subsequently authorized.subsequently authorized.

Page 10: 香港六合彩 » SlideShare

10

The Safe Harbor PrinciplesThe Safe Harbor Principles

(3) ONWARD TRANSFER(3) ONWARD TRANSFER

To disclose information to a third party, To disclose information to a third party, organizations must apply the notice and choice organizations must apply the notice and choice principles.principles.

Notice and Choice are not required for data Notice and Choice are not required for data

transfers to an agent (someone who acts on behalf transfers to an agent (someone who acts on behalf of the transferor) if it is first determined by the of the transferor) if it is first determined by the organization that the agent complies with the safe organization that the agent complies with the safe harbor principles, or is subject to the directive or harbor principles, or is subject to the directive or another adequacy finding, or enters into a written another adequacy finding, or enters into a written agreement with the organizationagreement with the organization..

Page 11: 香港六合彩 » SlideShare

11

The Safe Harbor PrinciplesThe Safe Harbor Principles

(4) SECURITY(4) SECURITY Organizations creating, maintaining, using or Organizations creating, maintaining, using or

disseminating personal information must take disseminating personal information must take reasonable precautions to protect it from loss, reasonable precautions to protect it from loss, misuse and unauthorized access, disclosure, misuse and unauthorized access, disclosure, alteration and destruction.alteration and destruction.

Organizations must take more care to protect Organizations must take more care to protect

sensitive information, as it is defined in the sensitive information, as it is defined in the principles.principles.

Page 12: 香港六合彩 » SlideShare

12

The Safe Harbor PrinciplesThe Safe Harbor Principles

(5) DATA INTEGRITY(5) DATA INTEGRITY

Personal information must be relevant for the Personal information must be relevant for the purposes for which it is to be used. An purposes for which it is to be used. An organization may not process personal organization may not process personal information in a way that is incompatible with information in a way that is incompatible with the purposes for which it has been collected or the purposes for which it has been collected or subsequently authorized by the individual. subsequently authorized by the individual.

To the extent necessary for those purposes, an To the extent necessary for those purposes, an organization should take reasonable steps to organization should take reasonable steps to ensure that data is reliable for its intended use, ensure that data is reliable for its intended use, accurate, complete, and current.accurate, complete, and current.

Page 13: 香港六合彩 » SlideShare

13

The Safe Harbor PrinciplesThe Safe Harbor Principles

(6) ACCESS (6) ACCESS

Individuals must have access to personal Individuals must have access to personal information about them that an organization information about them that an organization holds and be able to correct, amend, or delete holds and be able to correct, amend, or delete that information where it is inaccurate, except that information where it is inaccurate, except where the burden or expense of providing where the burden or expense of providing access would be disproportionate to the risks access would be disproportionate to the risks to the individual’s privacy in the case in to the individual’s privacy in the case in question, or where the rights of persons other question, or where the rights of persons other than the individual would be violated.than the individual would be violated.

Page 14: 香港六合彩 » SlideShare

14

The Safe Harbor PrinciplesThe Safe Harbor Principles

(7) ENFORCEMENT(7) ENFORCEMENT

1.1. Follow-up procedures for Follow-up procedures for verifyingverifying that safe that safe harbor policies and mechanisms have been harbor policies and mechanisms have been implemented;implemented;

2.2. Readily available and affordable independent Readily available and affordable independent recourse mechanismsrecourse mechanisms to investigate and resolve to investigate and resolve complaints brought by individuals;complaints brought by individuals;

3.3. Obligations to Obligations to remedyremedy problems arising out of a problems arising out of a failure by the organization to comply with the failure by the organization to comply with the principles.principles.

Page 15: 香港六合彩 » SlideShare

15

DIRECT COMPLIANCE WITH DIRECT COMPLIANCE WITH

THE EU DIRECTIVETHE EU DIRECTIVE

CONSENTCONSENT

ENTERING INTO A MODEL ENTERING INTO A MODEL

CONTRACTCONTRACT

Other Ways To Comply Other Ways To Comply With The Directive:With The Directive:

Page 16: 香港六合彩 » SlideShare

16

Safe Harbor: Safe Harbor: Next StepsNext Steps

Mid-Year ReviewMid-Year Review ““Visual” ComplianceVisual” Compliance Financial Service NegotiationsFinancial Service Negotiations DPA VisitDPA Visit EU Directive ReviewEU Directive Review

Page 17: 香港六合彩 » SlideShare

17

CONCLUSIONCONCLUSION

Additional resources are available on Additional resources are available on the safe harbor website the safe harbor website www.export.gov/safeharborwww.export.gov/safeharbor

• Safe Harbor List (updated regularly)Safe Harbor List (updated regularly)• Safe Harbor WorkbookSafe Harbor Workbook• Safe Harbor Documents (including Safe Harbor Documents (including

Principles, FAQ’s, correspondence)Principles, FAQ’s, correspondence)• Historical Documents (including Historical Documents (including

public comment) public comment)

Page 18: 香港六合彩 » SlideShare

18

Contact InformationContact Information

Patricia Sefcik, DirectorPatricia Sefcik, Director

Office of Electronic Commerce Office of Electronic Commerce International Trade Administration International Trade Administration

U.S. Department of CommerceU.S. Department of CommerceRoom 2003Room 200314th & Constitution Avenues, NW14th & Constitution Avenues, NWWashington, DC 20230Washington, DC 20230

Tel: (202) 482-0216Tel: (202) 482-0216Fax: (202) 482-5522Fax: (202) 482-5522E-Mail: [email protected]: [email protected]